A generation management method for API
By adjusting the cleanup cycle, mechanism and scale of the API cache, combining sensitive information and requester characteristics, and adopting circular caching and encryption hiding, the API cache security issue is solved and efficient and secure cache management is achieved.
Patent Information
- Application Number
- CN202510765053.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-06-10
AI Technical Summary
Although API caching in existing technologies improves response speed, it fails to effectively protect the security of front-end cache data and easily leads to cache information leakage.
By determining the target call status based on the activity balance and call interval of active APIs, adjusting the cache cleaning cycle, mechanism and scale, combining the sensitive information status and the risk factor of the requester's operation characteristics, and adopting circular caching, proportional caching and encryption hiding, cache security is enhanced.
It improves the efficiency and security of API generation management, avoids cache information leakage, and enhances protection against malicious attacks.
Smart Images

Figure CN120315784B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data management, and in particular to a method for managing the generation of an API. Background Art
[0002] API (Application Programming Interface) is a software middle layer that allows different programs, systems or services to interact and communicate with each other. It defines a set of rules, protocols and tools for building or integrating software applications. Malicious programs calling APIs is a common attack method. Attackers use the API interfaces provided by operating systems, applications or third-party libraries to implement malicious functions, such as stealing data, controlling systems, and spreading malware. In the existing technology, in order to avoid the problem of poor time efficiency caused by repeated API calls, a cache module is often set up to cache the request data corresponding to the API. Although this reduces the time loss caused by repeated calls, it also increases the risk of impact from malicious programs and easily leads to cache information leakage. Therefore, how to effectively cache data while protecting the security of API call information is a technical problem that needs to be solved by those skilled in the art.
[0003] Chinese patent publication number CN117472952A discloses a method and system for caching API interfaces, which includes the following steps: caching pre-configured or post-configured API interfaces; caching legal interface return values, and effectively refreshing data according to a timed refresh or manual refresh strategy; caching data in a database including but not limited to a relational database, NoSql, a graph database, a time series database, or a combination of different types of databases. It can be seen that the above technical solution has the following problems: although it can improve the response speed of the API interface, it does not take into account the security protection of the API-related data cached on the front end, which can easily lead to the leakage of front-end cache information. Summary of the Invention
[0004] To this end, the present invention provides a generation and management method for API, which is used to overcome the problem that the API caching method in the prior art improves the response speed of the API interface, but does not consider the security protection of the API-related data cached in the front-end, which easily leads to the leakage of front-end cache information.
[0005] To achieve the above objectives, the present invention provides a method for managing the generation of an API, comprising:
[0006] Determine the target call state based on the activity balance and call interval of active APIs, and determine the cache adjustment method based on the target call state, such as adjusting the cache cleanup cycle, setting the cache mechanism, or adjusting the cache size;
[0007] When setting up a cache mechanism, the sensitive information status is detected and the cache mechanism is determined to be a circular cache or a weighted cache based on the sensitive information status;
[0008] When adjusting the cache size, a warning score is determined based on the risk factor of the target requester's operational characteristics, and a proportional adjustment or regular adjustment of the cache size is determined based on the comparison result between the warning score and the preset warning score;
[0009] In the proportional adjustment, the encryption or hiding of the API front-end cache is determined based on the comparison result between the level diversity value and the preset level diversity value.
[0010] Furthermore, a target call state is determined based on the activity balance and call interval of the active APIs, and a cache adjustment method is determined based on the target call state;
[0011] If the target call status is that the active balance is less than the preset active balance and the call interval is less than the preset call interval, the cache adjustment method is to adjust the cache cleaning cycle;
[0012] If the target call status is that the active balance is greater than or equal to the preset active balance or the call interval is greater than or equal to the preset call interval, the cache adjustment method is to set the cache mechanism or adjust the cache size.
[0013] Furthermore, under the mechanism adjustment conditions, settings are made for the cache mechanism, including:
[0014] Detect sensitive information status and determine caching mechanism based on the sensitive information status;
[0015] If the sensitive information status is that the retrieval bias is greater than the preset retrieval bias or the information relevance is greater than the preset information relevance, the cache mechanism is set to circular cache;
[0016] If the sensitive information status is that the retrieval bias is less than or equal to the preset retrieval bias and the information relevance is less than or equal to the preset information relevance, the cache mechanism is set to proportional cache.
[0017] Furthermore, the circular cache includes:
[0018] Generate several API combinations based on the information relevance of active APIs, where a single API combination includes two active APIs and the information relevance corresponding to the two active APIs is the maximum information relevance corresponding to at least one of the active APIs;
[0019] At the same time, there is only one active API in any API combination for front-end caching.
[0020] Furthermore, a cache period is set in the circular cache, and the duration of a single cache period is determined according to the bias difference;
[0021] The duration of the cache period is positively correlated with the bias difference;
[0022] The bias difference is the difference between the adjusted bias and the preset adjusted bias.
[0023] Furthermore, the weight cache includes:
[0024] Determine the weight coefficient of each active API based on the frequency of usage and activity;
[0025] Detect the weight coefficient of each active API and sort them in descending order to obtain a weight sequence. Periodically select a preset number of active APIs and corresponding frequency-related APIs in descending order of weight coefficient for front-end caching.
[0026] The API weight coefficient is positively correlated with the frequency and activity of API usage.
[0027] Furthermore, under the scale adjustment condition, a risk analysis is conducted on the target requester's operation behavior, including:
[0028] Detect the risk factor of the target requester's operational characteristics;
[0029] Determine the warning score based on the target requester's operational characteristic risk factor;
[0030] If the warning score is greater than the preset warning score, the cache size is proportionally adjusted;
[0031] If the warning score is less than or equal to the preset warning score, regular adjustments are made to the cache size.
[0032] Furthermore, the operation feature risk factor is determined based on trajectory similarity and key input similarity;
[0033] The characteristic risk coefficient is positively correlated with the trajectory similarity and key input similarity;
[0034] The trajectory similarity is determined based on the trajectory movement frequency and the number of trajectory disconnections;
[0035] The key input similarity is determined based on the unified proportion of keywords.
[0036] Furthermore, the cache size is proportionally adjusted, including:
[0037] Obtain the early warning score difference, and determine the hidden ratio based on the obtained score difference;
[0038] The hidden ratio is positively correlated with the difference in warning scores;
[0039] Perform hierarchical diversity analysis on each active API to obtain the hierarchical diversity value. If the hierarchical diversity value is less than the preset hierarchical diversity value, encrypt the front-end cache of the API with the hidden proportion.
[0040] If the level diversity value is greater than or equal to the preset level diversity value, the API front-end cache with the hidden ratio will be hidden.
[0041] Furthermore, regular adjustments to cache size include:
[0042] Encrypt the API front-end cache that accounts for a certain proportion.
[0043] Compared with the prior art, the beneficial effect of the present invention lies in that the technical solution of the present invention determines the target call state according to the activity balance and call interval of the active API, effectively reflects the balance of the current number of calls of each API and the density of the call time through the target call state, and determines the cache adjustment method according to the target call state, so that the selection of the cache adjustment method is more in line with the actual working scenario, avoiding the problem of poor actual cache effect caused by the single cache processing method in the prior art being unable to adapt to dynamic scenarios, thereby improving the efficiency of API generation management.
[0044] Furthermore, when setting up the cache mechanism in the technical solution of the present invention, the sensitive information status is detected and the cache mechanism is determined according to the sensitive information status; the cache mechanism is selected according to the distribution of sensitive information corresponding to the API in the actual scenario and the relevance of the information corresponding to each API, taking into account the security of the cached information. The selectable cache mechanism enhances the security of the cached information, avoids the leakage of cached information, and thereby improves the efficiency of API generation management.
[0045] Furthermore, in the technical solution of the present invention, a warning score is determined based on the risk factor of the target requester's operation characteristics, and when the warning score is greater than the preset warning score, the cache size is proportionally adjusted. The operation characteristic risk factor is obtained by analyzing the target requester's mouse operation behavior and information input behavior. The actual operation behavior of the target requester is used to characterize whether there is a risk of malicious malware attack, thereby avoiding the problem of information theft through multiple IDs or malicious programs, and improving the data security of the API's cached data.
[0046] Furthermore, the technical solution of the present invention is provided with a caching mechanism of circular caching, which periodically changes the cached data of the current cache through circular caching to prevent the cached data from being attacked, and generates several API combinations based on the information relevance of active APIs. The information relevance reflects the degree of correlation between APIs, and there is only one active API in any API combination for front-end caching, which further enhances the security management of the API. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 Schematic diagram of the method for managing API generation according to the present invention;
[0048] Figure 2 This is a flow chart of the present invention for determining a cache adjustment method according to a target call state;
[0049] Figure 3 This is a flow chart of the present invention for determining a cache mechanism based on the state of sensitive information;
[0050] Figure 4 This is a flow chart of the present invention for determining proportional adjustment or conventional adjustment of cache size according to the early warning score. DETAILED DESCRIPTION
[0051] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.
[0052] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0053] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside", and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.
[0054] Furthermore, it should be noted that, in the description of the present invention, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0055] See also Figures 1 to 4 As shown, the present invention provides a method for managing the generation of an API, comprising:
[0056] Determine the target call state based on the activity balance and call interval of active APIs, and determine the cache adjustment method based on the target call state, such as adjusting the cache cleanup cycle, setting the cache mechanism, or adjusting the cache size;
[0057] When setting up a cache mechanism, the sensitive information status is detected and the cache mechanism is determined to be a circular cache or a weighted cache based on the sensitive information status;
[0058] When adjusting the cache size, a warning score is determined based on the risk factor of the target requester's operational characteristics, and a proportional adjustment or regular adjustment of the cache size is determined based on the comparison result between the warning score and the preset warning score;
[0059] In the proportional adjustment, the encryption or hiding of the API front-end cache is determined based on the comparison result between the level diversity value and the preset level diversity value.
[0060] The present invention is applied to the cache generation management of API. In the present invention, the target requester can make an API request to the API server through a client (such as a browser) to request an API call. The client is provided with a storage module for front-end caching of the request results of the API request. This is content that is easy for technical personnel in this field to understand and will not be elaborated here. The target requester is the user who currently makes an API request on the client. The present invention also corresponds to a management personnel for managing the API server, such as managing the configuration of the API in the API server.
[0061] The present invention applies historical records, and a single historical record includes at least active balance, call interval, retrieval bias, information relevance, matching frequency, activity and warning score, and the historical record is correspondingly provided with a qualified mark, which records whether the historical record meets the needs of the manager. Among them, whether a historical record meets the needs of the manager can be determined based on, but not limited to, the retrieval processing speed. Determining whether the historical record meets the needs of the manager based on the retrieval processing speed index set by the manager is content that has been mastered by those skilled in the art and is not limited here.
[0062] Specifically, the target call state is determined based on the activity balance and call interval of active APIs, and the cache adjustment method is determined based on the target call state;
[0063] If the target call status is that the active balance is less than the preset active balance and the call interval is less than the preset call interval, the cache adjustment method is to adjust the cache cleaning cycle;
[0064] If the target call status is that the active balance is greater than or equal to the preset active balance or the call interval is greater than or equal to the preset call interval, the cache adjustment method is to set the cache mechanism or adjust the cache size.
[0065] An active API is an API that has made more than a preset number of API requests in the most recent monitoring cycle. The present invention is provided with a cyclic monitoring cycle, and a cache adjustment method is determined at the end of each monitoring cycle. If the number of active APIs is less than or equal to 1, there is no need to determine the target call status, and wait for the end of the next monitoring cycle. The length of a single monitoring cycle is set by the administrator. The greater the administrator's determination accuracy of the active API, the longer the monitoring cycle. A monitoring cycle length is provided, which is 15 minutes. The value of the preset number can be set by the administrator according to the actual application scenario. It can be understood that the greater the administrator's demand for API security management, the smaller the value of the preset number. A method for determining the value of the preset number is provided, and the average number of API requests in the most recent monitoring cycle corresponding to each API that has been requested in the most recent monitoring cycle is recorded as the preset number.
[0066] The active balance is recorded as S, , randomly sort all active APIs, and record the number of API requests corresponding to the i-th active API in the most recent monitoring period as Si, S0 is the average number of API requests corresponding to the active API in the most recent monitoring period, i = 1, 2, 3, ..., n, where n is the total number of active APIs.
[0067] The call interval is the call time corresponding to each active API in the most recent monitoring period. The call times are arranged in chronological order from earliest to latest, and the time intervals between adjacent call times are calculated. The average time interval between adjacent call times is recorded as the call interval. The call time is the time when the API request for the active API is made to the API server.
[0068] The values of the preset active balance and the preset call interval can be set by managers according to actual application scenarios. It can be understood that the present invention effectively characterizes the frequency of API calls in terms of time and frequency through the active balance and the call interval. The values of the preset active balance and the preset call interval reflect the manager's security management needs for the API. The greater the manager's security management needs for the API, the smaller the values of the preset active balance and the preset call interval. A value of the preset active balance and the preset call interval is provided, and the active balance and call interval corresponding to the historical records that meet the needs of the manager are extracted, and the outliers are removed. The average values of the active balance and the call interval after removing the outliers are recorded as the preset active balance and the preset call interval respectively. The method for removing outliers can select the standard deviation method (3σ principle) and the IQR method according to actual conditions, but is not limited to the above-mentioned method for removing outliers.
[0069] Specifically, the cache mechanism is configured, including:
[0070] Detect sensitive information status and determine caching mechanism based on the sensitive information status;
[0071] If the sensitive information status is that the retrieval bias is greater than the preset retrieval bias or the information relevance is greater than the preset information relevance, the cache mechanism is set to circular cache;
[0072] If the sensitive information status is that the retrieval bias is less than or equal to the preset retrieval bias and the information relevance is less than or equal to the preset information relevance, the cache mechanism is set to proportional cache.
[0073] The method for confirming the call bias is to detect the sensitivity coefficients corresponding to each active API in the most recent monitoring period, and record the average value of the sensitivity coefficients as the call bias;
[0074] For a single active API, the corresponding sensitivity coefficient is determined by detecting the percentage of sensitive data in the request results corresponding to each API request for the active API during the most recent monitoring period, calculating the average percentage of sensitive data, and detecting the sensitive data similarity of the sensitive data in the request results corresponding to each API request. Sensitivity coefficient = (average percentage of sensitive data / average percentage of preset sensitive data) + (sensitive data similarity / preset sensitive data similarity);
[0075] The average value of the sensitive data ratio reflects the overall data sensitivity of the request result, and the sensitive data similarity reflects the retrieval similarity between the request results. Administrators can set the preset average value of the sensitive data ratio and the preset sensitive data similarity based on actual needs. It is understandable that the greater the administrator's security requirements for the sensitive data of the request result, the smaller the average value of the preset sensitive data ratio and the smaller the preset sensitive data similarity. A value is provided, the average value of the preset sensitive data ratio is 35%, and the preset sensitive data similarity is 15.
[0076] For a single request result, all fields in the request result are analyzed, and the proportion of sensitive data is recorded as the number of sensitive fields / total number of fields. The request result of the present invention is presented in the form of JSON or XML data. Sensitive fields are marked in advance by the administrator. It is understandable that the administrator can set his own data classification standards based on the importance he attaches to each API and related data, so as to determine which fields are sensitive fields;
[0077] For a single active API, the method for confirming the similarity of sensitive data is to extract the sensitive data in the request result returned by the active API in the most recent monitoring cycle, detect sensitive fields that appear more than the preset number of times, and record the number of sensitive fields that appear more than the preset number of times as the sensitive data similarity. For example, in the most recent monitoring cycle, the number of occurrences of 5 sensitive fields in the results for the northern region returned by the API exceeds the preset number of occurrences, then the sensitive data similarity is 5. It can be understood that the more attention managers pay to sensitive fields, the smaller the value of the preset number of occurrences, and a value of the preset number of occurrences is provided, and the preset number of occurrences is 5 times.
[0078] Detect each active API corresponding to the most recent monitoring cycle. The method for confirming the information relevance is to detect the total update events of each active API (the number of active APIs is at least 2) within the preset update period (there is no need to consider whether the active API remains in the active API status within the preset update period), and record the number of total update events as the information relevance. The total update event is that there are at least two active APIs updated and the time between the timestamps corresponding to the updates is less than the preset delay time. Among them, the greater the management personnel's demand for the accuracy of information relevance judgment, the longer the preset update time and the preset delay time. How to update the API and the timestamp mark of the update time are all contents that technical personnel in this field have mastered and will not be elaborated here. The preset update time is the time before the current time as the starting point, that is, if the preset update time is 100h, count the total update events within 100h before the current time.
[0079] The preset values of the retrieval bias and the preset information relevance can be set by managers according to actual application scenarios. It can be understood that the present invention reflects the manager's security management needs for the API through the correlation and sensitivity between the retrieval bias and information relevance request results. The greater the manager's security management needs for the API, the smaller the values of the preset retrieval bias and the preset information relevance. A value of the preset retrieval bias and the preset information relevance is provided, and the retrieval bias and information relevance corresponding to the historical records that meet the manager's needs are extracted, the outliers therein are removed, and the average values of the retrieval bias and information relevance after removing the outliers are recorded as the preset retrieval bias and the preset information relevance, respectively.
[0080] Specifically, the circular cache includes:
[0081] Generate several API combinations based on the information relevance of active APIs, where a single API combination includes two active APIs and the information relevance corresponding to the two active APIs is the maximum information relevance corresponding to at least one of the active APIs;
[0082] At the same time, there is only one active API in any API combination for front-end caching.
[0083] It can be understood that the process of generating several API combinations includes performing combination analysis on each active API in order of sensitivity coefficient from large to small. The combination analysis of a single active API includes detecting the active API that is not included in the API combination and corresponds to the maximum information relevance of the active API, and recording the two active APIs as an API combination. If the number of active APIs corresponding to the maximum information relevance is 2, any one of them is randomly selected and recorded in the combination.
[0084] When front-end caching is performed for an active API, the data of the three most recent corresponding request results returned by the active API are stored in the client's storage module.
[0085] Specifically, a cache period is set in the circular cache, and the duration of a single cache period is determined according to the bias difference;
[0086] The duration of the cache period is positively correlated with the bias difference;
[0087] The bias difference is the difference between the adjusted bias and the preset adjusted bias.
[0088] Preferably, in the specific implementation of the present invention, the duration of a single cache cycle = reference duration × [1 + (bias difference / preset bias)]. The value of the reference duration can be set by the administrator based on the maximum cache capacity of the actual front-end cache. The larger the maximum cache capacity, the larger the reference duration. A value of the reference duration is provided, and the reference duration is 8 minutes.
[0089] For any two active APIs in an API combination, the duration that each active API is cached on the front end is the cache period. For example, for two active APIs in an API combination, they are randomly recorded as API-A and API-B respectively. Any API is randomly selected to be cached in the client's storage module first. After the cache period, API-B is replaced with API-B in the client's storage module for caching, and the above actions are repeated; bias difference = retrieval bias - preset retrieval bias.
[0090] Specifically, the weight cache includes:
[0091] Determine the weight coefficient of each active API based on the frequency of usage and activity;
[0092] Detect the weight coefficient of each active API and sort them in descending order to obtain a weight sequence. Periodically select a preset number of active APIs and corresponding frequency-related APIs in descending order of weight coefficient for front-end caching.
[0093] The API weight coefficient is positively correlated with the frequency and activity of API usage.
[0094] Weighting coefficient = (pair usage frequency / preset pair frequency) + (activity / preset activity). The activity of an active API is the number of API requests initiated for that active API within the most recent monitoring cycle. For a single active API, the frequency of paired usage is determined by marking that active API as the target active API, detecting the number of paired active APIs corresponding to the target active API, and recording the number of paired active APIs as the target active API's frequency of paired usage. A paired active API is an active API whose number of paired requests with the target active API within the most recent monitoring cycle exceeds the preset number of paired requests. The number of paired requests is determined by counting the interval between an API request for the target active API and an API request for the paired active API within the most recent monitoring cycle as less than the preset interval. It is understood that a greater number of paired requests increases the probability of simultaneous API requests. Therefore, the greater the administrator's demand for API request processing speed, the smaller the preset number of paired requests. A preset number of paired requests is 3. The frequency-related API corresponding to an API is the paired active API with the largest number of paired requests for that API.
[0095] Administrators can set the values of preset pairing frequency and preset activity according to actual application scenarios, provide a preset pairing frequency and preset activity value, extract the pairing frequency and activity corresponding to the historical records that meet the needs of the administrator, remove the outliers, and record the average values of the pairing frequency and activity after removing the outliers as the preset pairing frequency and preset activity respectively.
[0096] Specifically, conduct a risk analysis on the target requester's operational behavior, including:
[0097] Detect the risk factor of the target requester's operational characteristics;
[0098] Determine the warning score based on the target requester's operational characteristic risk factor;
[0099] If the warning score is greater than the preset warning score, the cache size is proportionally adjusted;
[0100] If the warning score is less than or equal to the preset warning score, regular adjustments are made to the cache size.
[0101] Specifically, the operation feature risk factor is determined based on trajectory similarity and key input similarity;
[0102] The characteristic risk coefficient is positively correlated with the trajectory similarity and the key input similarity. A calculation method for the characteristic risk coefficient is provided: characteristic risk coefficient = trajectory similarity × β1 + key input similarity × β2;
[0103] The trajectory similarity is determined based on the trajectory movement frequency and the number of trajectory disconnections;
[0104] The key input similarity is determined based on the unified proportion of keywords.
[0105] Among them, the value of the preset warning score can be set by the manager according to the actual scenario. It can be understood that the greater the manager's demand for data security, the smaller the value of the preset warning score. A method for setting the value of the preset warning score is provided to extract the warning score corresponding to the historical records that meet the needs of the manager, remove the outliers, and record the average value of the warning score after removing the outliers as the preset warning score.
[0106] β1 is the first similarity weight, β12 is the second similarity weight, and the values of β1 and β2 can be set according to the actual scenario. It can be understood that, for example, the greater the importance the manager attaches to the trajectory similarity, the larger the value of β1, β1+β2=1, and β1 and β2 are both greater than 0. A value of β=0.7, β2=0.3 is provided. The method for confirming the trajectory similarity is to extract the sub-trajectory similarity of the target requester and the related target requester in the most recent monitoring cycle, and record the maximum sub-trajectory similarity as the trajectory similarity. The method for confirming the sub-trajectory similarity of the target requester and any related target requester is to extract the mouse operation trajectory of the target requester and the related target requester in the most recent monitoring cycle, and respectively calculate the absolute value H1 of the difference between the minimum enclosing rectangle area, the number of inflection points, and the dwell time of each mouse operation trajectory, the absolute value H2 of the difference in the number of inflection points, and the absolute value H3 of the difference in the dwell time corresponding to the two mouse operation trajectories. For the value H3, the sub-trajectory similarity = H1×α1+H1×α2+H1×α3, where α1 is the first weight coefficient, α2 is the second weight coefficient, and α3 is the third weight coefficient. The values of α1, α2, and α3 can be set according to the actual scenario. It is understandable that, for example, the greater the importance the manager attaches to the similarity of the minimum bounding rectangle area, the larger the value of α1. α1+α2+α3=1, and α1, α2, and α3 are all greater than 0. Provided are values of α1=0.4, α2=0.3, and α3=0.3. The inflection point of the mouse trajectory refers to the point in the trajectory where the direction of movement changes significantly. The method for determining the inflection point provided by the present invention is that the curvature at the inflection point is greater than the curvature of any point on the adjacent line segment. The adjacent line segment is a trajectory segment with a length of 5 cm and a length centered at the inflection point. It should be noted that there is not a single method for determining the inflection point. It is sufficient to only indicate that the direction of movement of the inflection point of the mouse trajectory changes significantly. The dwell time is the total time the mouse remains stable and motionless.
[0107] The key input similarity is confirmed by extracting the sub-key input similarities between the target requester and the related target requesters within the most recent monitoring period, and recording the maximum sub-key input similarity as the key input similarity. The sub-key input similarity between the target requester and any related target requester is confirmed by extracting the cross-zone input speeds of the target requester and the related target requester within the most recent monitoring period, and recording the absolute value of the difference between the cross-zone input speeds of the target requester and the related target requester as the sub-key input similarity. The cross-zone input speed is calculated as the number of cross-zone inputs within the monitoring period divided by the monitoring period duration. A cross-zone input is recorded as one key position where the interval between two adjacent keys in the input sequence is greater than a preset interval. The interval distance between any two keys is pre-set. For example, the administrator sets the interval distance between the A and S keys to 1 and the interval distance between the A and D keys to 2. The size relationship of the interval distances can be satisfied as long as it meets the size relationship of an actual keyboard, and there is no need to specifically limit the values. For example, the administrator sets the interval distance between the A and S keys to 2 and the interval distance between the A and D keys to 3, which can also implement the technical solution of the present invention.
[0108] Specifically, the cache size is adjusted proportionally, including:
[0109] Obtain the early warning score difference, and determine the hidden ratio based on the obtained score difference;
[0110] The hidden ratio is positively correlated with the difference in warning scores;
[0111] Perform hierarchical diversity analysis on each active API to obtain the hierarchical diversity value. If the hierarchical diversity value is less than the preset hierarchical diversity value, encrypt the front-end cache of the API with the hidden proportion.
[0112] If the level diversity value is greater than or equal to the preset level diversity value, the API front-end cache with the hidden ratio will be hidden.
[0113] The early warning score difference is the absolute value of the difference between the early warning score and the preset early warning score;
[0114] Hidden proportion = regular proportion + warning score difference / preset warning score. The units of regular proportion and hidden proportion are both %. The API level diversity value is the number of different active APIs among the active APIs requested by the target requester and all corresponding relevant target requesters. For the front-end cache of APIs with hidden proportion, that is, randomly selecting APIs with hidden proportion from the active APIs requested by the target requester and all corresponding relevant target requesters to hide, and the hiding means that no front-end caching is performed.
[0115] Specifically, regular adjustments to cache size include:
[0116] Encrypt the API front-end cache that accounts for a certain proportion.
[0117] The specific encryption method is not limited and may be, but not limited to, AES (Advanced Encryption Standard) symmetric encryption, RSA asymmetric encryption, and sensitive field desensitization encryption;
[0118] Administrators can set the value of the regular ratio based on actual scenarios. It is understandable that the greater the administrator's demand for data security, the smaller the regular ratio will be; the greater the administrator's demand for data retrieval efficiency, the larger the regular ratio will be. A regular ratio value is provided, which is 50%.
[0119] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
[0120] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A method for API generation management, characterized in that: include: Determine the target call state based on the activity balance and call interval of active APIs, and determine the cache adjustment method based on the target call state, such as adjusting the cache cleanup cycle, setting the cache mechanism, or adjusting the cache size; When setting up a cache mechanism, the sensitive information status is detected and the cache mechanism is determined to be a circular cache or a weighted cache based on the sensitive information status; When adjusting the cache size, a warning score is determined based on the risk factor of the target requester's operational characteristics, and a proportional adjustment or regular adjustment of the cache size is determined based on the comparison result between the warning score and the preset warning score; In the proportional adjustment, the API front-end cache is encrypted or hidden according to the comparison result between the level diversity value and the preset level diversity value; If the target call status is that the active balance is less than the preset active balance and the call interval is less than the preset call interval, the cache adjustment method is to adjust the cache cleaning cycle; If the target call status is that the active balance is greater than or equal to the preset active balance or the call interval is greater than or equal to the preset call interval, the cache adjustment method is to set the cache mechanism or adjust the cache size; If the sensitive information status is that the retrieval bias is greater than the preset retrieval bias or the information relevance is greater than the preset information relevance, the cache mechanism is set to circular cache; If the sensitive information status is that the retrieval bias is less than or equal to the preset retrieval bias and the information relevance is less than or equal to the preset information relevance, the cache mechanism is set to proportional cache; The active balance is recorded as S, , randomly sort all active APIs, and record the number of API requests made by the i-th active API in the most recent monitoring period as Si, S0 is the average number of API requests made by the active API in the most recent monitoring period, i = 1, 2, 3, ..., n, where n is the total number of active APIs; The operation feature risk factor is determined based on trajectory similarity and key input similarity; The characteristic risk coefficient is positively correlated with the trajectory similarity and key input similarity; The trajectory similarity is determined based on the trajectory movement frequency and the number of trajectory disconnections; The key input similarity is determined based on the unified proportion of keywords.
2. The method for managing the generation of an API according to claim 1, wherein: The target call status is determined based on the activity balance and call interval of active APIs, and the cache adjustment method is determined based on the target call status.
3. The method for managing the generation of an API according to claim 2, wherein: Under the mechanism adjustment conditions, set up the cache mechanism, including: Detect sensitive information status and determine the caching mechanism based on the sensitive information status.
4. The method for managing the generation of an API according to claim 3, wherein: The circular buffer comprises: Generate several API combinations based on the information relevance of active APIs, where a single API combination includes two active APIs and the information relevance corresponding to the two active APIs is the maximum information relevance corresponding to at least one of the active APIs; At the same time, there is only one active API in any API combination for front-end caching.
5. The method for managing the generation of an API according to claim 4, wherein: A cache period is set in the circular cache, and the duration of a single cache period is determined according to the bias difference; The duration of the cache period is positively correlated with the bias difference; The bias difference is the difference between the adjusted bias and the preset adjusted bias.
6. The method for managing the generation of an API according to claim 5, wherein: The weight cache includes: Determine the weight coefficient of each active API based on the frequency of usage and activity; Detect the weight coefficient of each active API and sort them in descending order to obtain a weight sequence. Periodically select a preset number of active APIs and corresponding frequency-related APIs in descending order of weight coefficient for front-end caching. The API weight coefficient is positively correlated with the frequency and activity of API usage.
7. The method for managing the generation of an API according to claim 6, wherein: Under scale adjustment conditions, conduct risk analysis on the target requester's operational behavior, including: Detect the risk factor of the target requester's operational characteristics; Determine the warning score based on the target requester's operational characteristic risk factor; If the warning score is greater than the preset warning score, the cache size is proportionally adjusted; If the warning score is less than or equal to the preset warning score, regular adjustments are made to the cache size.
8. The method for managing the generation of an API according to claim 7, wherein: Scaling the cache size includes: Obtain the early warning score difference, and determine the hidden ratio based on the obtained score difference; The hidden ratio is positively correlated with the difference in warning scores; Perform hierarchical diversity analysis on each active API to obtain the hierarchical diversity value. If the hierarchical diversity value is less than the preset hierarchical diversity value, encrypt the front-end cache of the API with the hidden proportion. If the level diversity value is greater than or equal to the preset level diversity value, the API front-end cache with the hidden ratio will be hidden.
9. The method for managing the generation of an API according to claim 8, wherein: General tuning for cache sizing includes: Encrypt the API front-end cache that accounts for a certain proportion.
Citation Information
Patent Citations
Method and system for caching API (Application Program Interface)
CN117472952A
Power data prefetching and caching method with active defense influence range
CN112561197A
Data caching time setting method and device, computer equipment and storage medium
CN114327672A