计算机科学 ›› 2026, Vol. 53 ›› Issue (6A): 250600030-11.doi: 10.11896/jsjkx.250600030

• 信息安全 • 上一篇    下一篇

基于多重SimHash和数字特征快照的Web应用指纹识别方法

顾显俊1, 黄梦琦1, 刘铭2, 韩福济4, 田聪1, 朱东君2,3   

  1. 1 国网湖北省电力有限公司武汉供电公司 武汉 430010
    2 武汉金银湖实验室 武汉 430040
    3 华中科技大学网络空间安全学院 武汉 430040
    4 浙江大学控制科学与工程学院 杭州 310058
  • 出版日期:2026-06-16 发布日期:2026-06-12
  • 通讯作者: 朱东君(zhudongjun@hust.edu.cn)
  • 作者简介:(22965112@qq.com)
  • 基金资助:
    面向石油炼化装置的攻击检测及动态安全失效分析仪器(62127808);网络空间中基于泛配置类数据的协作性恶意行为识别研究(62172176);国家重点研发计划(2022YFB3103400)

Web Application Fingerprinting Method Based on Multi-level SimHash and Digital FeatureSnapshots

GU Xianjun1, HUANG Mengqi1, LIU Ming2, HAN Fuji4, TIAN Cong1 , ZHU Dongjun2,3   

  1. 1 Wuhan Power Supply Company of State Grid Hubei Electric Power Co.,Ltd.,Wuhan 430010,China
    2 JinYinHu Laboratory,Wuhan 430040,China
    3 School of Cyberspace Security,Huazhong University of Science and Technology,Wuhan 430040,China
    4 College of Control Science and Engineering,Zhejiang University,Hangzhou 310058,China
  • Published:2026-06-16 Online:2026-06-12
  • About author:GU Xianjun,born in 1981,master,se-nior engineer.His main research in-terests include cybersecurity,digital system construction and artificial intelligence.
    ZHU Dongjun,born in 1987,doctoral engineer.His main research interests include penetration testing,big data security and cyber space mapping.
  • Supported by:
    Attack Detection and Dynamic Security Failure Analysis Instrument for Petrochemical(62127808),Research on Collaborative Malicious Behavior Recognition Based on General Configuration Data in Cyberspace(62172176) and National Key R&D Program of China(2022YFB3103400).

摘要: Web应用指纹识别是网络空间测绘、Web漏洞利用以及网络安全态势感知等关键技术的基础环节。现有主流方法大多依赖人工构建文本规则,通过正则表达式进行匹配来识别Web应用。这类方法存在诸多局限,如规则提取难度大、难以区分相近子版本、页面内容稍作修改即可能导致识别失败,严重制约了其准确性与鲁棒性。针对这些问题,提出一种基于多重SimHash算法与数字特征快照的Web应用指纹识别模型。该方法以能表征Web应用核心特征的页面内容为基础,采用多重SimHash算法将其转换为高维数字指纹,构成可计算、可比较的特征快照。在此基础上,构建了一种通用的Web指纹识别模型,并对模型结构、关键算法和参数设计进行了系统定义。进一步地,本文基于HTML页面文本信息,设计并实现了该模型的具体应用框架,并通过对多个主流Web应用的识别实验,验证了模型的有效性和准确性。实验结果表明,该方法不仅在识别精度上优于传统规则匹配方式,还具备自动生成指纹与识别Web应用子版本的能力,能够在一定程度上适应页面变动。

关键词: 数字特征快照, Web应用, 指纹识别, 子版本识别, 多重SimHash

Abstract: Web application fingerprinting is a fundamental technique in cyberspace mapping,Web vulnerability exploitation,and cybersecurity situational awareness.Existing mainstream approaches primarily rely on manually crafted text-based rules and regular expression matching to identify Web applications.However,these methods face several limitations,such as the difficulty of rule extraction,challenges in distinguishing between similar sub-versions,and susceptibility to failure when page content changes.To address these issues,this paper proposes a Web application fingerprinting model based on a multi-level SimHash algorithm and digital feature snapshots.The method extracts representative page content that reflects core characteristics of Web applications,and maps it into high-dimensional digital fingerprints using multiple SimHash calculations to form computable and comparable feature snapshots.On this basis,a general fingerprinting model is constructed,with systematic definitions of its structure,key algorithms,and parameters.Furthermore,a practical implementation of the model is developed using HTML page content,and a series of experiments are conducted on various mainstream Web applications.Experimental results demonstrate that the proposed method outperforms traditional rule-based approaches in recognition accuracy,supports automatic fingerprint generation and sub-version identification,and exhibits robustness to page modifications to a certain extent.

Key words: Digital feature snapshot, Web application, Fingerprint recognition, Subversion recognition, Multi-level SimHash

中图分类号: 

  • TP393
[1] UPATHILAKE R,LI Y K,MATRAWY A.A classification of web browser fingerprinting techniques[C]//2015 7th International Conference on New Technologies,Mobility and Security(NTMS).IEEE,2015.
[2] WANGEN G B.Information Security Risk Assessment:AMethod Comparison[J].Computer,2017,50(4):52-61.
[3] BUI S,SHRIVASTAVA M.A case study of testing a web-based application using an open-source testing tool[J].Journal of Information Technology Management,2015,XXVI:19-30.
[4] JIN Y F,XIA B S.Research on Process of Web Security Penetration Testing[J].Network Security Technology & Application,2021(12):5-6.
[5] WANG C D,GUO Y B,ZHEN S H et al.Research on Network Asset DetectionTechnology[J].Computer Science,2018,45(12):24-31.
[6] KUMAR G.An improved ensemble approach for effective intrusion detection[J].The Journal of Supercomputing,2020,76(1):275-291.
[7] PAPAMARTZIVANOS D,GÓMEZ MÁRMOL F,KAMBOU-RAKIS G.Dendron:Genetic trees driven rule induction for network intrusion detection systems[J].Future Generation Computer Systems,2018,79:558-574.
[8] ZHOU S F.Research on Web Fingerprint Identification[D].Chongqing:Chongqing University of Posts and Telecommunications,2020.
[9] CAI D.Research on Network Security Level Protection Technology for Electronic Information Engineering[J].Cybersecurity &Informatization,2025(4):133-135.
[10] XIAO X,ZHOU X,YANG Z Y,et al.A comprehensive analysis of website fingerprinting defenses on Tor[J].Computers & Security,2024(136):103577.
[11] WANG W W.Reasearch on Web Recognition and ConfusionTechnology Based on Website Fingerprint[D].Wuhan:Wuhan University,2017.
[12] SHI Y M,YU W,ZHAO Y X.A Web Application Fingerprint Recognition Method Based on Machine Learning[J].Computer Modeling in Engineering & Sciences,2024,140(1):887-906.
[13] PATHIRAGE G S,MANATHUNGA K.Machine Learning and Browser Fingerprinting Based Approach for Web Bot Detection[C]//2024 6th International Conference on Advancements in Computing(ICAC).IEEE,2024.
[14] SADOWSKI C,GREG L.Simhash:Hash-based similarity de-tection[J/OL].https://www.webrankinfo.com/dossiers/wp-content/uploads/simhash.pdf.
[15] YAN S J,WANG W J,ZHANG Y Q.An effective web fingerprinting method[J].Journal of University of Chinese Academy of Sciences,2016,33(5):679-685.
[16] CAO L C,ZHAO J J,CUI X et al.Cyberspace device identification based on K-means with cosine distance measure[J].Journal of University of Chinese Academy of Sciences,2016,33(4):562-569.
[17] ZHAO D M,LI H,CUI X,et al.Approach to network security situational element extraction based on parallel reduction[J].Journal of Computer Applications,2017,37(4):1008-1013.
[18] TANG W L,TANG S F,ZHANG P.Research and improvement of Web fingerprint recognitionalgorithm based on cosine measurement[J].Computer Science,2019,46(10):295-298.
[19] ZHANG L H.Research on fingerprint generation methodof Internet of Things device based on web information[J].Modern Computer,2021(15):94-99,107.
[20] HONG X S,LI S Y,MA X K,et al.A website fingerprintingtechnology with time-sampling[J].Peer-to-Peer Networking and Applications,2024,17(2):944-960.
[21] TAN X B,PENG C,XIE P,et al.Inter-flow spatio-temporal correlation analysis based website fingerprinting using graph neural network[J].IEEE Transactions on Information Forensics and Security,2024,19:7169-7632.
[22] HUI Z H,ZHAI J T,WANG S Z,et al.A New Website Fingerprinting Method for Tor Hidden Service[J].IEEE Access,2024,13:8886-8897.
[23] KARTHIK R,RAGHAVENDRA K .W3-Scrape-A Windowsbased Reconnaissance Tool for Web Application Fingerprinting[C]//Proceedings of ICECIT-2012.Elsevier,2012:8-13.
[24] CHARIKAR M S.Similarity Estimation Techniques from Rounding Algorithms[C]//Proceedings of the thiry-fourth annual ACM symposium on Theory of computing(STOC '02).Canada,Montreal,2002:380-388.
[25] AO Z M.Research on the Improvement of Search AlgorithmBased on Web Page Similarity[D].Shanghai:Shanghai Normal University,2015.
[26] HAN F J,ZHU D J.Intelligent Recognition Method of Web Application Categories Based on Multi-Layer Simhash Algorithm[C]//2022 IEEE International Conference on Trust,Security and Privacy in Computing and Communications.2022.
[27] LLOYD S.Least squares quantization in PCM[J].IEEE Transactions on Information Theory,1982,28(2):129-137.
[28] ESTER M,KRIEGEL H P,XU X.A Density-Based Algorithm for Discovering Clusters in Large Spatial Databases with Noise[C]//Proceedings of the Second International Conference on Knowledge Discovery and Data Mining(KDD'96).1996:226-231.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!