Feature code blocking file upload defense system and method capable of automatically learning and updating

A file uploading and automatic learning technology, applied in transmission systems, electrical components, platform integrity maintenance, etc., can solve problems such as server security threats, failure to detect Trojans or malicious codes in time, and failure to better meet usage requirements. achieve high efficiency

Active Publication Date: 2021-08-06
SICHUAN CHANGHONG ELECTRIC CO LTD
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Then when the uploaded file is loaded by the business system script, for the current file upload filtering rules, due to the diversity of Trojans or malicious codes, Trojans or malicious codes are usually not found in time, which may easily lead to illegal users uploading malicious codes or Trojans. It is detected by the file upload filtering rule file in time and passed the verification, and the data file is transmitted to the server, thus posing a threat to the security of the server
[0006] Therefore, the existing file upload defense filtering mechanism has certain limitations and cannot better meet the needs of use

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Feature code blocking file upload defense system and method capable of automatically learning and updating

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0047] Such as figure 1As shown, a feature code blocking file upload defense system that can automatically learn and update is communicated with the business system to be tested. Among them, the file upload defense system includes several clouds, and the cloud includes a data monitoring module and a packet size judgment module. , a data discrimination module, a feature code extraction module, a data analysis module, a learning update module, a data deletion module and a large message cache module, and a file upload filtering rule file is saved on the cloud.

[0048] Specifically, the file upload filter rule file is used to collect feature codes that can characterize file upload vulnerabilities, and several feature code units corresponding to illegal messages are stored in the file upload filter rule file.

[0049] The data monitoring module can manage the corresponding data message of the request message for file upload in the business system to be tested. The request message ...

Embodiment 2

[0062] A feature code blocking file upload defense method that can automatically learn and update is mainly based on the file upload defense system of Embodiment 1, and specifically includes the following steps:

[0063] Step 1: Upload the file and establish a communication connection between the defense system and the business system to be tested, and install or integrate the cloud in the form of a code plug-in on the business system to be tested, wherein the business system to be tested includes a request report text, and the request message specifically includes response data and data flow information.

[0064] The second step: the data monitoring module judges whether there is a file upload message by monitoring the response data of the message of the file upload request in the business system to be tested, and grabs the message when the message is monitored;

[0065] Step 3: The message size judging module judges whether the message captured by the data monitoring module ...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a feature code blocking file upload defense system and method that can automatically learn and update. The system includes several clouds, and the cloud includes sequentially connected data monitoring modules, data discrimination modules, feature code extraction modules, A data analysis module, a learning update module, a data deletion module, and a file upload filter rule file which is continuously updated by the learning update module is stored on the cloud. The technical scheme of the invention can effectively defend and learn malicious file uploads, thereby preventing the server system from being controlled by malicious personnel through malicious files, so as to form an efficient, fast and accurate security defense mechanism for file uploads.

Description

technical field [0001] The invention relates to the field of computer software information technology, in particular to a feature code blocking file upload defense system and method that can automatically learn and update. Background technique [0002] During the rapid development of the Internet, computer software has also sprung up like mushrooms. With the rapid development of computer software, the security problems of computer software information have been exposed more and more. [0003] Among them, the file upload vulnerability of computer software is very common, and it is also one of the necessary vulnerability tests in security testing. Security testers generally attack the website by simulating the file upload function. By simulating a hacker attack, they test whether there is a file upload vulnerability on the website, and verify whether the file upload module code of the website under test filters the file data submitted by the user. Bypassed, it can lead to dan...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L29/08G06F21/55
CPCG06F21/55H04L63/0263H04L63/1441H04L63/30H04L67/06
Inventor 陈辉丁锐
Owner SICHUAN CHANGHONG ELECTRIC CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products