API behavior prediction and security policy management and control method based on machine learning

Through real-time data processing and dynamic model optimization, the problem that traditional API security policies cannot adapt to API behavior changes is solved, efficient anomaly detection and dynamic strategy adjustment are achieved, and the accuracy and security of API behavior prediction are improved.

CN120567461AActive Publication Date: 2025-08-29应急管理部大数据中心 +1

Patent Information

Application Number
CN202510663535.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-08-29
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

Traditional API security policies are difficult to adapt to the dynamic changes in API behavior, resulting in inefficient detection and processing of abnormal behaviors, and the model cannot respond in a timely manner when facing complex and changing API scenarios.

Method used

By obtaining API raw data in real time, preprocessing and feature extraction, establishing a collaborative architecture based on the multi-head temporal attention mechanism and dynamic graph neural network, generating an API behavior prediction model, and generating dynamic security control strategies in real time through the strategy engine, combining the feedback mechanism for iterative optimization.

Benefits of technology

Real-time prediction and dynamic strategy adjustment of API behavior are realized, the coverage rate of anomaly detection and the real-timeness of policies are improved, model maintenance costs are reduced, and behavior prediction is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567461A_ABST
    Figure CN120567461A_ABST
Patent Text Reader

Abstract

The invention provides an API behavior prediction and security policy management and control method based on machine learning, and relates to the field of computer network security, and the method comprises the steps: obtaining API original data in real time, preprocessing the original data, obtaining the preprocessed original data, obtaining API dimension features in real time based on the preprocessed original data, and fusing the API dimension features to obtain unstructured data, establishing a dynamic feature validity verification rule to pre-process the unstructured data to obtain a standardized feature tensor of a unified dimension; joint modeling of API behavior spatio-temporal characteristics is carried out through a collaborative architecture of a multi-head time attention mechanism and a dynamic graph neural network, API behavior prediction is carried out, an API dynamic security management and control strategy is generated in real time through a strategy engine, strategy execution is carried out, a security strategy execution effect is monitored in real time, and iterative optimization is carried out. According to the invention, the problems that the security control strategy of the traditional API gateway is fixed and rigid, and the security strategy is difficult to dynamically adjust according to the real-time access condition and behavior are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network security, and in particular to a method for API behavior prediction and security policy management based on machine learning. Background Art

[0002] With the acceleration of digital transformation, API (Application Programming Interface) has become a key bridge connecting different software systems, realizing data sharing and functional interaction. In today's Internet ecosystem, whether it is e-commerce platforms, financial institutions, social media, IoT devices, etc., they all rely heavily on APIs to implement various business functions. For example, e-commerce platforms connect with logistics systems and payment systems through APIs to realize order delivery and payment processing; financial institutions use APIs to provide customers with online financial management, loan application and other services; social media platforms use APIs to allow third-party developers to develop related applications to enrich platform functions and user experience; IoT devices transmit collected data to the cloud through APIs for analysis and processing.

[0003] Static API security solutions based on rule engines are currently a widely used solution. They filter and verify API requests by establishing a series of rules. However, these rules are often based on known security risks, making it difficult to quickly respond to and address emerging abnormal behaviors and security threats. Furthermore, the maintenance cost of these rules is high, requiring constant updates and adjustments based on new security situations.

[0004] API anomaly detection solutions based on traditional machine learning models attempt to use machine learning techniques to detect abnormal API behavior. Common models include decision trees and support vector machines. These models learn from historical API call data to build models of normal behavior patterns, and then use this model to determine whether new API requests are abnormal. These simple machine learning models still face problems such as feature dimension limitations and model drift failure when faced with complex and changing API behaviors. When the API usage scenario undergoes significant changes, the model may require a long time to retrain and adjust, which cannot meet the more real-time risk control requirements. In addition, it may not be able to accurately identify some subtle abnormal behavior patterns.

[0005] However, the widespread use of APIs has also brought many challenges in security and stability. API behavior has become complex and changeable due to various factors such as user groups, business scenarios, and network environments. Traditional static and lagging security strategies are difficult to adapt to its dynamic changes, and the efficiency of abnormal behavior detection and processing is extremely low. Summary of the Invention

[0006] The present invention provides an API behavior prediction and security policy management method based on machine learning, which is used to solve the problem that the security management policy of traditional API gateways in the prior art is fixed and rigid, and it is difficult to dynamically adjust the security policy according to real-time access conditions and behaviors.

[0007] In one aspect, the present invention provides a method for API behavior prediction and security policy management based on machine learning, comprising:

[0008] Acquire API raw data in real time, pre-process the raw data, and obtain pre-processed raw data, wherein the raw data includes API access logs, network traffic data, and system operation status information;

[0009] Based on the pre-processed raw data, API dimensional features are acquired in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features.

[0010] Establish dynamic feature validity verification rules to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions;

[0011] Based on the standardized feature tensor, the multi-head temporal attention mechanism and the collaborative architecture of the dynamic graph neural network are used to jointly model the spatiotemporal features of API behavior, generate an API behavior prediction model, and perform API behavior prediction to obtain prediction results.

[0012] Based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time and executes the policies to obtain the security policy execution effect;

[0013] Monitor the effectiveness of security policy execution in real time, and iteratively optimize model parameters and policy rules through feedback mechanisms.

[0014] Furthermore, API raw data is acquired in real time and preprocessed to obtain preprocessed raw data. The raw data includes API access logs, network traffic data, and system operation status information, including:

[0015] At the API gateway layer, data collection components are used to obtain API raw data, including API access logs, network traffic data, and system operation status information. API access logs obtain request metadata in real time through the gateway log interface. Network traffic data is extracted by parsing the protocol payload. System status information is collected through integrated monitoring tools to collect runtime indicators such as gateway CPU, memory, and connection pool.

[0016] Integrate the collected API access logs, network traffic data, and system operation status information to obtain a multi-dimensional data source;

[0017] Clean the multidimensional data source to obtain the preprocessed raw data.

[0018] Furthermore, based on the pre-processed raw data, API dimensional features are obtained in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features, including:

[0019] Based on the pre-processed raw data, real-time statistics of API path distribution and request entropy calculation, standard deviation of intervals between adjacent API calls, and periodic analysis of request patterns of long-term sessions are performed to obtain the aforementioned temporal behavior characteristics;

[0020] Based on the pre-processed raw data, the mobile SDK collects device hardware parameters, network environment fingerprints, and behavioral biometrics to generate a tamper-resistant unique device identifier, namely the device fingerprint feature;

[0021] Based on the pre-processed raw data, the pre-trained NLP model is used to convert API parameter values ​​into semantic vectors, capturing the underlying intent of the parameter values ​​and obtaining semantic deep parsing features.

[0022] Based on the preprocessed raw data, business context features are obtained by recording the state migration trajectory of user permission groups, collecting the call chain topology relationship across microservices, and detecting the deviation between resource access frequency and historical baseline:

[0023] The acquired temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features are fused to obtain a multi-dimensional feature vector, i.e., unstructured data.

[0024] Furthermore, dynamic feature validity verification rules are established to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions, including:

[0025] Based on the preset dynamic feature validity verification rules, remove erroneous records, duplicate data, and data that does not meet format requirements from unstructured data to obtain cleaned data;

[0026] Based on the cleaned data, outliers are identified and processed through statistical methods and machine learning algorithms, while time series data is smoothed to obtain denoised data.

[0027] Based on the denoised data, normalization is used to convert numerical data into a unified scale and to convert coded categorical data into a form suitable for machine learning model input to obtain normalized data.

[0028] Based on the normalized data, the time series data is transformed by translation, scaling, etc. to obtain the expanded data, i.e. the preprocessed data;

[0029] The preprocessed data is standardized to obtain a standardized feature tensor of uniform dimension.

[0030] Furthermore, based on the standardized feature tensor, the spatiotemporal features of API behavior are jointly modeled through the collaborative architecture of the multi-head temporal attention mechanism and the dynamic graph neural network. The API behavior prediction model is generated and API behavior prediction is performed to obtain prediction results, including:

[0031] Based on the standardized feature tensor, a multi-head self-attention mechanism is used to capture the local timing patterns and global abnormal fluctuations of the API call sequence. Each attention head is used to independently learn features at different time scales to obtain a multi-dimensional time embedding vector.

[0032] Based on the standardized feature tensor, the real-time call relationship of API endpoints is obtained to build a dynamic graph structure. The graph attention network is used to aggregate neighbor node features and capture implicit dependencies to generate spatial structure embeddings.

[0033] The multi-dimensional temporal embedding vector is fused with the spatial structure embedding through cross-dimensional attention, and the spatiotemporal feature weights are dynamically adjusted through a gating mechanism to generate a joint spatiotemporal feature representation.

[0034] Based on joint spatiotemporal feature representation, an incremental learning framework combining elastic weight solidification and sliding window retraining is used to achieve minute-level model updates and generate API behavior prediction models.

[0035] Use the generated API behavior prediction model to perform API behavior prediction to obtain prediction results.

[0036] Furthermore, based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time and executes the policies to obtain the security policy execution effects, including:

[0037] Based on the prediction results of the API behavior prediction model, a two-branch strategy network is constructed. The prediction results and environmental status are input to generate the probability distribution of API behavior actions.

[0038] The prediction result and the current environment state are concatenated into a state vector. The dual-branch policy network samples actions based on the state vector and generates dynamic policy instructions.

[0039] Inject policy instructions into the API gateway, adjust the current limiting threshold or trigger secondary authentication in real time to achieve security policy execution effect.

[0040] Furthermore, the security policy execution effect is monitored in real time, and the model parameters and policy rules are iteratively optimized through the feedback mechanism, including:

[0041] Use the monitoring module to collect key indicators after the strategy is executed to form an effect evaluation;

[0042] Generate feedback signals based on preset thresholds and effect evaluations;

[0043] Collect feedback signals and store them in the replay pool;

[0044] Data is sampled from the replay pool periodically and iteratively optimized.

[0045] On the other hand, a machine learning-based API behavior prediction and security policy management system includes:

[0046] An acquisition module is used to acquire API raw data in real time and preprocess the raw data to obtain preprocessed raw data, wherein the raw data includes API access logs, network traffic data, and system operation status information;

[0047] The processing module is used to obtain API dimensional features in real time based on the preprocessed raw data, and fuse them to obtain multi-dimensional feature vectors, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features; establish dynamic feature validity verification rules to preprocess unstructured data to obtain a standardized feature tensor of unified dimension; based on the standardized feature tensor, jointly model the spatiotemporal features of API behavior through the collaborative architecture of multi-head temporal attention mechanism and dynamic graph neural network, generate an API behavior prediction model and perform API behavior prediction to obtain prediction results; based on the prediction results of the API behavior prediction model, generate API dynamic security management and control policies in real time through the policy engine, and execute the policies to obtain the security policy execution effect; monitor the security policy execution effect in real time, and iteratively optimize the model parameters and policy rules through the feedback mechanism.

[0048] On the other hand, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the program, it implements any of the machine learning-based API behavior prediction and security policy management methods described above.

[0049] On the other hand, the present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements any of the machine learning-based API behavior prediction and security policy management methods described above.

[0050] On the other hand, the present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements any of the machine learning-based API behavior prediction and security policy management methods described above.

[0051] The machine learning-based API behavior prediction and security policy management method provided by this invention significantly improves coverage, anti-counterfeiting, and real-time performance based on feature dimensions and collection timeliness, providing high-quality input for subsequent behavior prediction engines and addressing the data collection limitations of traditional solutions.

[0052] Joint spatiotemporal modeling and efficient incremental learning enable real-time prediction of API dynamic behavior, enabling more timely responses to changes in API business scenarios and dynamic behavior. This addresses the issues of poor adaptability and model drift of traditional models.

[0053] High-quality data collection and input can effectively improve the accuracy of behavior predictions. Building a policy network, relying on behavior prediction input, can more automatically collect strategies with a higher probability of accuracy. At the same time, based on the timeliness of incremental learning, it can more effectively ensure the real-time and security of dynamic strategies.

[0054] The monitoring and feedback module monitors the operating status of the API, the accuracy of the prediction model, and the execution effect of the security policy in real time; collects relevant data such as real-time data of API requests, system logs, model prediction results, etc., and evaluates the prediction model and security policy; once it finds inaccurate predictions or poor security policy execution, it sends feedback information to the data preprocessing module, machine learning model module, and security policy management module, prompting each module to make corresponding adjustments and optimizations to form a closed-loop optimization system. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0056] Figure 1 This is a flow chart of a method for API behavior prediction and security policy management based on machine learning provided by an embodiment of the present invention;

[0057] Figure 2 Schematic diagram of a machine learning-based API behavior prediction and security policy management system provided by an embodiment of the present invention;

[0058] Figure 3It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0059] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0060] Figure 1 This is one of the flow charts of the API behavior prediction and security policy management method based on machine learning provided in an embodiment of the present invention.

[0061] like Figure 1 As shown, the API behavior prediction and security policy management method based on machine learning provided by the embodiment of the present invention mainly includes the following steps:

[0062] 11. Acquire API raw data in real time and pre-process the raw data to obtain pre-processed raw data, which includes API access logs, network traffic data, and system operation status information;

[0063] 12. Based on the pre-processed raw data, API dimensional features are obtained in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features.

[0064] 13. Establish dynamic feature validity verification rules to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions;

[0065] 14. Based on the standardized feature tensor, the multi-head temporal attention mechanism and the collaborative architecture of the dynamic graph neural network are used to jointly model the spatiotemporal features of API behavior, generate an API behavior prediction model, and perform API behavior prediction to obtain prediction results;

[0066] 15. Based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time, executes the policies, and obtains the security policy execution effect;

[0067] 16. Monitor the effectiveness of security policy execution in real time, and iteratively optimize model parameters and policy rules through feedback mechanisms.

[0068] In the embodiment of the present invention, as the data cornerstone of the entire protection system, it ensures the real-time and comprehensiveness of subsequent analysis, and through full-flow non-intrusive monitoring, it captures API access logs, network traffic and system status in real time, providing a high-fidelity data source for feature extraction and model training, solving the problems of data collection lag and single dimension in traditional solutions; extracting key behavior patterns from raw data, constructing a multi-dimensional feature space, integrating four major types of features: time series behavior (such as request entropy to capture call randomness), device fingerprint (anti-tampering identification to block simulated attacks), semantic analysis (parameter intent recognition logic abuse), and business context (authority migration trajectory to prevent overreach), forming a high-dimensional feature vector, providing holographic input for the prediction model, and significantly improving the anomaly detection coverage; ensuring the quality of feature data, eliminating noise and redundancy, automatically filtering collection noise (such as crawler interference) through a dynamic rule engine, standardizing feature dimensions, and generating feature tensors in a unified format, so that the signal-to-noise ratio of the model input signal is improved and the training efficiency is improved; breaking through the limitations of traditional models in spatiotemporal correlation modeling, achieving accurate threat prediction, the spatiotemporal gating network (TSGN) uses multiple Attention captures millisecond-level call fluctuations (such as DDoS attacks), and a dynamic graph neural network reconstructs microservice dependency topology (such as container drift) in real time, reducing the response time for new threat detection from days to minutes and improving the threat interception rate. Prediction results are converted into executable security actions to achieve closed-loop protection. The policy network automatically outputs throttling thresholds or secondary authentication instructions based on risk scores. Policy execution latency is less than 100ms, reducing false alarm rates compared to traditional solutions and significantly reducing manual intervention costs. A continuously evolving closed loop is formed to adapt to dynamic changes in API behavior. By monitoring policy execution effectiveness (such as interception rate and service availability), incremental learning (EWC + sliding window) and dynamic rule adjustments are triggered. This reduces the amount of data required for model updates, reduces the time cost of adapting to business changes from weeks to minutes, and lowers the total cost of ownership (TCO). From data collection to policy execution, end-to-end latency is controlled at milliseconds, meeting the extreme performance requirements of cloud-native API gateways. Through the "perception-decision-execution-learning" cycle, it achieves a transition from passive to active defense, providing fundamental technical support for business continuity in the API economy.

[0069] like Figure 1 As shown, 11, real-time acquisition of API raw data, pre-processing of the raw data, and obtaining pre-processed raw data, the raw data including API access logs, network traffic data and system operation status information, including:

[0070] 111. Use the data collection component at the API gateway layer to obtain API raw data. The raw data includes API access logs, network traffic data, and system operation status information. The API access logs obtain request metadata in real time through the gateway log interface. Network traffic data is extracted by parsing the protocol payload. System status information is collected through integrated monitoring tools to collect runtime indicators such as gateway CPU, memory, and connection pool.

[0071] 112, integrating the collected API access logs, network traffic data, and system operation status information to obtain a multi-dimensional data source;

[0072] 113, cleaning the multidimensional data source to obtain pre-processed raw data.

[0073] In the embodiment of the present invention, by embedding a lightweight data collection component in the API gateway layer, full traffic monitoring is achieved, and API access logs (request metadata), network traffic data (protocol parsing load) and system status information (CPU / memory / connection pool indicators) are captured in real time, solving the problem of single data source in traditional solutions; using memory computing technology, it ensures that the end-to-end delay of data collection and preprocessing is less than 500μs, and the impact on gateway performance is less than 2%, avoiding the service delay caused by intrusive collection in traditional solutions; the three types of data, logs, traffic and system status, are correlated and integrated. For example, the user ID in the access log is combined with the network traffic data. Device fingerprints can accurately identify simulated login attacks, analyze the correlation between system status indicators (such as connection pool full load) and traffic surges, and provide early warning of DDoS attacks; covering three-dimensional data of the request layer (log), transport layer (traffic), and resource layer (system status), it solves the problem of underreporting caused by traditional solutions relying only on a single dimension; through dynamic feature validity verification rules, it filters noisy data, automatically removes collection noise (such as crawler interference), and repairs format errors (such as missing log fields), thereby improving the signal-to-noise ratio of feature inputs and outputting standardized feature tensors, solving model compatibility issues caused by data format confusion in traditional solutions and reducing subsequent feature engineering costs.

[0074] like Figure 1 As shown in 12, based on the pre-processed raw data, API dimension features are obtained in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimension features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features, including:

[0075] 121. Based on the pre-processed raw data, real-time statistics of API path distribution are performed, and entropy value calculation is performed on the request, the standard deviation of the interval between adjacent API calls is calculated, and the request pattern of long-term sessions is periodically analyzed to obtain the temporal behavior characteristics;

[0076] 122. Based on the pre-processed raw data, the mobile SDK collects device hardware parameters, network environment fingerprints, and behavioral biometrics to generate a tamper-resistant device unique identifier, namely the device fingerprint feature;

[0077] 123. Based on the pre-processed raw data, use the pre-trained NLP model to convert API parameter values ​​into semantic vectors, capture the potential intent of the parameter values, and obtain semantic deep analysis features;

[0078] 124. Based on the pre-processed raw data, business context features are obtained by recording the state migration trajectory of user permission groups, collecting the call chain topology relationship across microservices, and detecting the deviation between resource access frequency and historical baseline:

[0079] 125. The acquired temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features are fused to obtain a multi-dimensional feature vector, i.e., unstructured data.

[0080] In an embodiment of the present invention, by statistically analyzing API path distribution, request entropy, call interval standard deviation and long-term session pattern, the API call timing regularity is characterized. A sudden increase in request entropy can identify brute force attacks (such as trying a large number of API paths), and abnormal fluctuations in call interval standard deviation can capture DDoS attacks (such as request intervals approaching 0). Fourier transform analysis is performed on long-term sessions (such as daily scheduled tasks) to accurately identify business logic anomalies (such as API calls during non-working hours); an anti-tampering device identifier is constructed based on hardware parameters, network fingerprints and behavioral biometrics, and 30+ dimensional features such as hardware UUID, TLS fingerprints, and mouse movement trajectories are integrated to generate a device hash value, thereby increasing the recognition rate of simulator attacks. The legitimacy of the device is verified in real time through behavioral biometrics (such as keystroke rhythm and sliding speed), blocking attacks by automated tools (such as API scanners); a pre-trained NLP model (such as BERT) is used to identify API calls. PI parameter values ​​are converted into semantic vectors, and SQL injection parameters (such as 'OR1=1--) are mapped into malicious semantic vectors. Even if the parameters are obfuscated by encoding, they can still be identified. Semantic analysis is performed on the amount parameters of the financial transaction API to identify abnormal large transactions (such as those exceeding the user's historical average by 3σ); through user permission migration trajectory, microservice call chain topology and resource access baseline analysis, business logic correlation is characterized, and the user permission group change history (such as sudden change from ordinary user to administrator) is recorded. Combined with the call chain topology, illegal API access paths are identified, and sudden increases in CPU / memory usage of containerized APIs are detected, thus blocking cryptocurrency mining attacks in advance; the four types of features, namely timing, device, semantics, and business, are integrated into high-dimensional feature vectors, covering the four-dimensional attack surface of the request layer, device layer, data layer, and business layer, solving the problem of single-dimensional detection omissions in traditional solutions. For example, combining device fingerprint anomalies with semantic parsing anomalies can accurately identify complex attacks.

[0081] like Figure 1 As shown in 13, dynamic feature validity verification rules are established to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions, including:

[0082] 131. Based on the preset dynamic feature validity verification rules, remove erroneous records, duplicate data, and data that does not meet format requirements from unstructured data to obtain cleaned data;

[0083] 132. Based on the cleaned data, outliers are identified and processed through statistical methods and machine learning algorithms, and time series data is smoothed to obtain denoised data;

[0084] 133. Based on the denoised data, the numerical data is converted to a unified scale through normalization, and the coded categorical data is converted into a form suitable for machine learning model input to obtain normalized data;

[0085] 134. Based on the normalized data, the time series data is transformed by translation, scaling, etc. to obtain the expanded data, i.e. the preprocessed data;

[0086] 135. Standardize the preprocessed data to obtain a standardized feature tensor of uniform dimension.

[0087] In the embodiment of the present invention, invalid data is automatically filtered through a preset rule engine to ensure input quality, dynamically detect and eliminate collection noise, format errors and repeated requests, and the data cleaning rate is increased; based on the incremental learning framework, the rule engine can automatically adapt to newly emerging abnormal patterns to solve the problem of high maintenance costs of traditional hard-coded rules; random fluctuations and outliers in the data are eliminated, the real business model is retained, and the number of identifiable abnormal calls is increased by combining statistical methods and the isolation forest algorithm; the call interval is smoothed using an exponentially weighted moving average to eliminate short-term fluctuation interference and improve the accuracy of long-term session pattern analysis; the numerical scale and encoding format are unified to eliminate feature dimension differences, and the CPU utilization (0-100%) and request entropy value (0-1) are mapped to [ 0,1] interval, which speeds up model convergence. Hash embedding is used for API paths to map millions of categories to low-dimensional dense vectors, reducing memory usage. Time series transformation is used to increase data diversity and improve model generalization. Random time shifts (such as ±10% offset) are performed on call interval sequences to improve the model's robustness to timing phase changes. Dynamic time regularization is used to generate call sequences of different speeds to effectively defend against slow attacks. Structured feature tensors are constructed to adapt to deep learning model inputs, and timing behavior, device fingerprints, semantic analysis, and business context features are spliced ​​into a 480-dimensional tensor to solve the feature splicing confusion problem of traditional solutions. Through tensor blocking and parallel computing, the feature standardization processing delay is reduced to <200μs, supporting real-time inference of 100,000 QPS-level API gateways.

[0088] like Figure 1 As shown in 14, based on the standardized feature tensor, the spatiotemporal features of API behavior are jointly modeled through the collaborative architecture of the multi-head temporal attention mechanism and the dynamic graph neural network, an API behavior prediction model is generated, and API behavior prediction is performed to obtain prediction results, including:

[0089] 141. Based on the standardized feature tensor, a multi-head self-attention mechanism is used to capture the local timing patterns and global abnormal fluctuations of the API call sequence, and each attention head is used to independently learn different time scale features to obtain a multi-dimensional time embedding vector;

[0090] 142. Based on the standardized feature tensor, the real-time call relationship of API endpoints is obtained to build a dynamic graph structure, and the graph attention network is used to aggregate neighbor node features and capture implicit dependencies to generate spatial structure embedding;

[0091] 143. The multi-dimensional time embedding vector and the spatial structure embedding are fused with cross-dimensional attention, and the spatiotemporal feature weights are dynamically adjusted through a gating mechanism to generate a joint spatiotemporal feature representation;

[0092] 144. Based on joint spatiotemporal feature representation, an incremental learning framework combining elastic weight solidification and sliding window retraining is used to achieve minute-level model updates and generate API behavior prediction models;

[0093] 145. Use the generated API behavior prediction model to predict API behavior and obtain prediction results.

[0094] In an embodiment of the present invention, a multi-head temporal attention mechanism and a dynamic graph neural network are used to jointly model the spatiotemporal characteristics of API behavior, breaking through the limitations of traditional time series models in capturing insufficient periodic patterns and relying on manual definition of graph structures. The multi-head temporal attention mechanism captures multi-scale periodic patterns and abnormal fluctuations in API call sequences, solving the problem of insufficient modeling capabilities of traditional LSTM / GRU for long-term dependencies. The dynamic graph neural network models the implicit dependencies between API endpoints, solving the problem that static graph structures cannot adapt to dynamic business topologies.

[0095] Existing technologies make it difficult to update models in a timely manner based on changes in API operation data and business scenarios. This invention uses incremental learning, employing a framework that combines elastic weight solidification with sliding window retraining, to achieve minute-level model updates. This allows for timely capture of dynamic changes in API behavior, maintaining accurate predictions of API behavior, and effectively reducing model maintenance costs by addressing concept drift.

[0096] Behavior prediction first obtains the API call sequence X={x1,x2,x3,...,x T}∈R T×d , where T is the time step, d is the API call feature dimension, X is the sequence, and R represents the matrix dimension; the adjacency matrix A0 is generated based on the call relationship of the API endpoints in the initial window, or dynamically constructed through feature similarity to initialize the dynamic graph;

[0097] The multi-head temporal attention mechanism divides the input sequence X into subsequences of different time granularities (such as hours, days, weeks): Among them, X (k) is a subsequence, X is a sequence, R represents the matrix dimension, w k is the time window length of the kth attention head, N k It is based on the time window length w of the k-th attention head k The calculated number of columns is Where T is the time step;

[0098] For each subsequence X (k) , calculate the query Q (k) , key K (k) , value V (k) :

[0099] Q (k) =X (k) W Q (k) , K (k) =X (k) W k (k) , V (k) =X (k) W v (k)

[0100] in, is a learnable parameter, X (k) is a subsequence;

[0101] The attention output is Among them, Attn (k) represents the weighted sum of the attention of the kth attention head on the input sequence, Q (k) is the query, T is the time step, d h Indicates the dimension of data processed by each attention head, V (k) is value;

[0102] Concatenate all attention outputs and project:

[0103] H time =Concat(Attn (1) ,...,Attn (k) )W o ∈R T×d , where H time Represents the time feature after attention mechanism processing, T is the number of time steps, d is the feature dimension, Attn (k) represents the weighted sum of the attention of the kth attention head on the input sequence, W o The matrix used to project the concatenated attention output into the target feature space, where R represents the matrix dimension;

[0104] Based on the current time node feature H time , calculate the similarity between nodes:

[0105] A ij =δ(MLP(h i ||h j )),h i , h j ∈H time , where A ij For node h i and node h jThe similarity between nodes, δ is the Sigmoid function, which is used to map the similarity between nodes to the interval (0,1), indicating the probability of the existence of connections between nodes, so that the generated adjacency matrix has probabilistic interpretation, || is the identification feature splicing, H time is the time node feature;

[0106] Message passing using a dynamic adjacency matrix A: H space =ReLU(AH time W G )∈R T×d Among them, W G ∈R T×d is the graph convolution weight, A is the dynamic adjacency matrix, which is composed of the similarity between nodes and represents the connection relationship between nodes, ReLU is the activation function, and H time is the time node feature, H space is the spatial feature;

[0107] Fusion of temporal and spatial features through spatiotemporal gating mechanism:

[0108] H space =G⊙H time +(1-G)⊙H space , where G is the gating signal, generated by the spatiotemporal gating mechanism, and is used to control the fusion ratio of temporal features and spatial features, δ is the Sigmoid function, and W g is the weight matrix of the spatiotemporal gating mechanism, W g ∈R 2d×d , ⊙ is element-by-element multiplication, H time is the time node feature, H space is the spatial feature;

[0109] The behavior prediction output steps are: first, H final To perform a connection projection: Output API behavior category (such as normal / abnormal) or regression value (such as number of calls), where H final Represents the final feature representation obtained after a series of processing in the behavior prediction process. is the prediction result of API behavior, W p is the weight parameter, h t is the input hidden state, b p is the bias parameter;

[0110] Maintain a dynamic sliding window D window ={X t-M+1 ,...,X t}, the window size M is set according to business needs (such as minute / hour / day update), where D windowRepresents a dynamic sliding window, containing data from time t-M+1 to time t;

[0111] The steps of elastic weight curing (EWC) regularization are as follows:

[0112] The loss function is Among them, L EWC is the loss function of elastic weight curing (EWC) regularization, L NEW is the cross entropy loss of new data, is an important parameter of historical tasks, F i is the diagonal term of the Fisher information matrix, θ is the model parameter, and λ is a hyperparameter representing the regularization strength;

[0113] The incremental model update steps are: first, perform sliding window retraining, and use D window Data calculation loss L NEW , combined with the EWC regularization term, update the model parameters Among them, η is the learning rate, θ is the model parameter, L EWC is the loss function of elastic weight curing (EWC) regularization, L NEW The cross entropy loss of new data is used. The updated model is used to predict new API behaviors. The above steps are continuously iterated to achieve minute-level model updates to address the problem of concept drift.

[0114] like Figure 1 As shown in Figure 15, based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time and executes the policies to obtain the security policy execution effects, including:

[0115] Based on the prediction results of the API behavior prediction model, a two-branch strategy network is constructed. The prediction results and environmental status are input to generate the probability distribution of API behavior actions.

[0116] The prediction result and the current environment state are concatenated into a state vector. The dual-branch policy network samples actions based on the state vector and generates dynamic policy instructions.

[0117] Inject policy instructions into the API gateway, adjust the current limiting threshold or trigger secondary authentication in real time to achieve security policy execution effect.

[0118] In an embodiment of the present invention, dynamic security policy generation based on the PPO algorithm is implemented by constructing a policy network system to generate a probability distribution of security policy actions based on current state information. The policy network automatically adopts different security policies such as rate limiting, circuit breaking, and verification based on the output of the API behavior engine. As new API behavior data and system environment data are continuously input, the policy network is continuously updated using the PPO algorithm, enabling the policy network to dynamically generate security policies that better meet current security needs and system performance requirements based on real-time state information.

[0119] State vector It consists of two parts. The API behavior prediction result is the output of the spatiotemporal gating network (TSGN) (such as abnormal call counts, resource abuse, suspected risks, etc.), system environment data includes real-time load l t , historical action feedback a t-1 API endpoint availability t The action space includes discrete or continuous sets of executable security policy actions such as current limiting, circuit breaking, verification, and release. The formula is

[0120] Based on the state t Generate action probability distribution π(a|s t ), parameterized as a deep neural network: π θ (a|s t )=Softmax(MLP θ (S t )), the mean and variance of the Gaussian distribution are output for continuous actions to describe the probability distribution of continuous actions, where s t is the state vector, π(a|s t ) is the action probability distribution, which means the policy network with parameter θ is in state s t The probability of taking action a under

[0121] State value estimate V φ (s t ), used to calculate the advantage function, evaluate in state s t The system value under , that is, the expected value of the cumulative reward that may be obtained after executing a series of actions starting from this state, provides important reference information for the optimization of the policy network, helps to judge the quality of the current state, and thus knows how the policy network generates a better action probability distribution;

[0122] Calculate the odds value A using the generalized odds estimate (GAE) t , δ t =r t +γV θ (st+1 )-V θ (S t ), where A t is the advantage value, γ is the discount factor, λ is the GAE smoothing coefficient, which measures the impact of the current action on future returns, δ t It usually represents the difference or increment between the reward at time step t and the estimated state value, V(s t ) and V(s t+1 ) are respectively in state s t and s t+1 The state value estimation under the ... CLIP (θ)=E t [min(ρ t (θ)A t ,clip(ρ t (θ),1-ε,1+ε)A t ],in, is the importance sampling rate, ε is the clipping threshold, and the probability ratio of the new and old strategies is limited by ρ t (θ), balances strategy exploration and exploitation, and optimizes the policy network parameters θ;

[0123] Combining policy loss, value function loss and entropy regularization to L(θ,φ)=L CLIP (θ)-c1L VF (φ)+c2H(π θ (·|s t )),

[0124] The value function loss is L VF (φ)=E t [(V φ (s t )-V target (s t ) 2 ],

[0125] Entropy regularization is H(π θ )=-∑ a π θ (a|s t )logπ θ (a|s t ),

[0126] Among them, the strategy network (parameter θ) and the value network (parameter φ) are collaboratively optimized to ensure that the strategy is both efficient and exploratory. c1 and c2 are constant coefficients, and L CLIP为 Policy loss, L VF is the value function loss, H is the entropy regularization term, π(a|s t ) is the action probability distribution, V φ (st ) is the state value estimate, V target is the preset state value target value;

[0127] According to the probability distribution π output by the policy network θ (a|s t ) Sampling action a t , execute security policies (such as current limiting threshold adjustment, circuit breaker triggering), reward r t Need to consider both security and system performance: t =α·Security(a t )+β.Performance(a t ), where r t is the reward, α and β are weight coefficients, Security(a t ) is action a t Safety performance, Performance (a t ) is action a t system performance;

[0128] Security rewards are the number of times abnormal API calls are blocked and the feedback on successful attacks is reduced; performance rewards are the percentage of system load reduction and the amount of API response time reduction.

[0129] like Figure 1 As shown in 16, the security policy execution effect is monitored in real time, and the model parameters and policy rules are iteratively optimized through the feedback mechanism, including:

[0130] 161. Use the monitoring module to collect key indicators after the strategy is executed and form an effect evaluation;

[0131] 162. Generate a feedback signal based on a preset threshold and effect evaluation;

[0132] 163. Collect feedback signals and store them in the replay pool;

[0133] 164. Regularly sample data from the replay pool and perform iterative optimization.

[0134] In the embodiment of the present invention, by deploying a monitoring module, it is possible to collect key indicators after the execution of security policies in real time, measure the proportion of policies that successfully prevent malicious attacks, evaluate the accuracy of policy judgments, avoid affecting normal business or missing real threats, monitor the impact of policy execution on system performance, avoid excessive resource consumption, understand the frequency of policy triggering, and judge the security situation; real-time monitoring enables the security team to grasp the effect of policy execution in a timely manner, avoid the operation of "policy black box", and provide a data basis for subsequent effect evaluation and policy adjustment, ensuring that the policy execution is visible and measurable; based on the collected key indicators, a quantitative evaluation of the execution effect of the security policy is carried out, which is not just a simple data collection, but also an analysis and In the process of interpretation, we observe the changing trend of indicators over time, judge whether the policy effect is improving, stable or declining, compare with historical data, baselines or different policy versions, highlight policy improvements or problems, explore the correlation between different indicators, and find potential problems or optimization points in policy execution; effect evaluation converts raw monitoring data into valuable insights, helping the security team to objectively and comprehensively understand the actual effectiveness of the policy, avoid subjective assumptions, and provide a decision-making basis for generating feedback signals and formulating optimization strategies; based on preset thresholds (for example, the maximum allowed false alarm rate) and effect evaluation results, feedback signals are automatically or manually generated. The signals indicate whether the policy execution effect meets expectations and how adjustments need to be made. Feedback signals can be: positive; negative ... A positive signal indicates that the strategy is executing well and the effect is as expected, so no immediate adjustment is required. A negative signal indicates that the strategy is executing poorly and the effect is not as expected, so adjustment and optimization are required. Specific adjustment instructions directly indicate the direction or parameters that the strategy needs to adjust. Feedback signals are the bridge connecting the strategy execution effect and strategy optimization and adjustment, so that the strategy is no longer static, but can be dynamically adjusted according to actual conditions to achieve the strategy's adaptive ability. The generated feedback signals are collected and stored to form a replay pool. The role of the replay pool is not just a simple signal storage, but also accumulates historical feedback signals to form an experience library for strategy optimization, providing a reference for future strategy adjustments. Historical data can be resampled from the replay pool for offline analysis and model training. Or strategy backtesting improves data utilization and optimization efficiency, prevents the loss of valuable feedback signals, and ensures that the strategy optimization process is traceable and reproducible. The establishment of a replay pool makes the strategy optimization process no longer a "one-time" process, but enables continuous learning and improvement, providing an infrastructure for long-term strategy optimization and knowledge accumulation. Data is sampled from the replay pool regularly (rather than just once), and security policies are iteratively optimized based on the latest security threat intelligence and business needs. Optimization can include: adjusting policy parameters such as thresholds and weights to improve policy effectiveness, updating or adding policy rules to respond to new attack methods or business changes, and if the policy is based on a machine learning model, the model needs to be retrained or updated to improve model performance.Regular iterative optimization is key to maintaining the long-term effectiveness of security policies. Through continuous learning and improvement, policies can adapt to changing security threats and business environments, maintaining optimal protection. Iterative optimization is also a gradual improvement process that can gradually enhance the intelligence and automation level of policies.

[0135] Experience replay is to store experience tuples (s t , a t , T t , S t+1 ) to the buffer D, and the batch update is to resample the small batch data from D every K isolation steps and calculate the advantage A t and target value V target , optimize L(θ, φ) by gradient ascent: θ←θ+η θ ▽ θ L(θ,φ),φ←φ+η φ ▽ φ L(θ, φ), where η θ , η φ is the learning rate, A t For the advantage, V target is the target value, θ, φ are the policy network parameters, S t+1 is the next state, indicating that the agent takes action a at time step t t After that, the environment is transferred to the new state, T t As the target value, continuously improve the policy network's ability to generate security policies.

[0136] like Figure 2 As shown, a machine learning-based API behavior prediction and security policy management system 20 includes:

[0137] An acquisition module 21 is used to acquire API raw data in real time and preprocess the raw data to obtain preprocessed raw data, wherein the raw data includes API access logs, network traffic data, and system operation status information;

[0138] The processing module 22 is used to obtain API dimensional features in real time based on the preprocessed original data, and fuse them to obtain a multi-dimensional feature vector, that is, unstructured data, where the dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features; establish dynamic feature validity verification rules to preprocess the unstructured data to obtain a standardized feature tensor of unified dimension; based on the standardized feature tensor, jointly model the spatiotemporal features of API behavior through the collaborative architecture of the multi-head temporal attention mechanism and the dynamic graph neural network, generate an API behavior prediction model and perform API behavior prediction to obtain prediction results; based on the prediction results of the API behavior prediction model, generate an API dynamic security management and control strategy in real time through the policy engine, and execute the strategy to obtain the security strategy execution effect; monitor the security strategy execution effect in real time, and iteratively optimize the model parameters and strategy rules through the feedback mechanism.

[0139] Figure 3 It is a structural diagram of an electronic device provided by an embodiment of the present invention.

[0140] like Figure 3 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 may call the logic instructions in the memory 630 to execute the API behavior prediction and security policy management method based on machine learning.

[0141] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0142] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the machine learning-based API behavior prediction and security policy management methods provided by the above methods.

[0143] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the machine learning-based API behavior prediction and security policy management method provided by the above-mentioned methods.

[0144] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0145] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0146] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A machine learning-based API behavior prediction and security policy management method, characterized by: include: Acquire API raw data in real time, pre-process the raw data, and obtain pre-processed raw data, wherein the raw data includes API access logs, network traffic data, and system operation status information; Based on the pre-processed raw data, API dimensional features are acquired in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features. Establish dynamic feature validity verification rules to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions; Based on the standardized feature tensor, the multi-head temporal attention mechanism and the collaborative architecture of the dynamic graph neural network are used to jointly model the spatiotemporal features of API behavior, generate an API behavior prediction model, and perform API behavior prediction to obtain prediction results. Based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time and executes the policies to obtain the security policy execution effect; Monitor the effectiveness of security policy execution in real time, and iteratively optimize model parameters and policy rules through feedback mechanisms.

2. The API behavior prediction and security policy management method based on machine learning according to claim 1 is characterized in that: Acquire API raw data in real time and preprocess the raw data to obtain preprocessed raw data. The raw data includes API access logs, network traffic data, and system operation status information, including: At the API gateway layer, data collection components are used to obtain API raw data, including API access logs, network traffic data, and system operation status information. API access logs obtain request metadata in real time through the gateway log interface. Network traffic data is extracted by parsing the protocol payload. System status information is collected through integrated monitoring tools to collect runtime indicators such as gateway CPU, memory, and connection pool. Integrate the collected API access logs, network traffic data, and system operation status information to obtain a multi-dimensional data source; Clean the multidimensional data source to obtain the preprocessed raw data.

3. The API behavior prediction and security policy management method based on machine learning according to claim 2 is characterized in that: Based on the pre-processed raw data, API dimensional features are acquired in real time and fused to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features, including: Based on the pre-processed raw data, real-time statistics of API path distribution and request entropy calculation, standard deviation of intervals between adjacent API calls, and periodic analysis of request patterns of long-term sessions are performed to obtain the aforementioned temporal behavior characteristics; Based on the pre-processed raw data, the mobile SDK collects device hardware parameters, network environment fingerprints, and behavioral biometrics to generate a tamper-resistant unique device identifier, namely the device fingerprint feature; Based on the pre-processed raw data, the pre-trained NLP model is used to convert API parameter values ​​into semantic vectors, capturing the underlying intent of the parameter values ​​and obtaining semantic deep parsing features. Based on the preprocessed raw data, business context features are obtained by recording the state migration trajectory of user permission groups, collecting the call chain topology relationship across microservices, and detecting the deviation between resource access frequency and historical baseline: The acquired temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features are fused to obtain a multi-dimensional feature vector, i.e., unstructured data.

4. The API behavior prediction and security policy management method based on machine learning according to claim 3 is characterized in that: Establish dynamic feature validity verification rules to preprocess unstructured data and obtain standardized feature tensors of uniform dimensions, including: Based on the preset dynamic feature validity verification rules, remove erroneous records, duplicate data, and data that does not meet format requirements from unstructured data to obtain cleaned data; Based on the cleaned data, outliers are identified and processed through statistical methods and machine learning algorithms, while time series data is smoothed to obtain denoised data. Based on the denoised data, normalization is used to convert numerical data into a unified scale and to convert coded categorical data into a form suitable for machine learning model input to obtain normalized data. Based on the normalized data, the time series data is transformed by translation, scaling, etc. to obtain the expanded data, i.e. the preprocessed data; The preprocessed data is standardized to obtain a standardized feature tensor of uniform dimension.

5. The API behavior prediction and security policy management method based on machine learning according to claim 4 is characterized in that: Based on the standardized feature tensor, the multi-head temporal attention mechanism and the collaborative architecture of the dynamic graph neural network are used to jointly model the spatiotemporal features of API behavior, generate an API behavior prediction model, and perform API behavior prediction to obtain prediction results, including: Based on the standardized feature tensor, a multi-head self-attention mechanism is used to capture the local timing patterns and global abnormal fluctuations of the API call sequence. Each attention head is used to independently learn features at different time scales to obtain a multi-dimensional time embedding vector. Based on the standardized feature tensor, the real-time call relationship of API endpoints is obtained to build a dynamic graph structure. The graph attention network is used to aggregate neighbor node features and capture implicit dependencies to generate spatial structure embeddings. The multi-dimensional temporal embedding vector is fused with the spatial structure embedding through cross-dimensional attention, and the spatiotemporal feature weights are dynamically adjusted through a gating mechanism to generate a joint spatiotemporal feature representation. Based on joint spatiotemporal feature representation, an incremental learning framework combining elastic weight solidification and sliding window retraining is used to achieve minute-level model updates and generate API behavior prediction models. Use the generated API behavior prediction model to perform API behavior prediction to obtain prediction results.

6. The API behavior prediction and security policy management method based on machine learning according to claim 5 is characterized in that: Based on the prediction results of the API behavior prediction model, the policy engine generates API dynamic security control policies in real time and executes the policies to obtain the security policy execution effects, including: Based on the prediction results of the API behavior prediction model, a two-branch strategy network is constructed. The prediction results and environmental status are input to generate the probability distribution of API behavior actions. The prediction result and the current environment state are concatenated into a state vector. The dual-branch policy network samples actions based on the state vector and generates dynamic policy instructions. Inject policy instructions into the API gateway, adjust the current limiting threshold or trigger secondary authentication in real time to achieve security policy execution effect.

7. The API behavior prediction and security policy management method based on machine learning according to claim 6 is characterized in that: Monitor security policy execution effectiveness in real time and iteratively optimize model parameters and policy rules through feedback mechanisms, including: Use the monitoring module to collect key indicators after the strategy is executed to form an effect evaluation; Generate feedback signals based on preset thresholds and effect evaluations; Collect feedback signals and store them in the replay pool; Data is sampled from the replay pool periodically and iteratively optimized.

8. A machine learning-based API behavior prediction and security policy management system, characterized by: include: An acquisition module is used to acquire API raw data in real time and preprocess the raw data to obtain preprocessed raw data, wherein the raw data includes API access logs, network traffic data, and system operation status information; The processing module is used to obtain API dimensional features in real time based on the preprocessed raw data, and fuse them to obtain a multi-dimensional feature vector, i.e., unstructured data. The dimensional features include temporal behavior features, device fingerprint features, semantic depth analysis features, and business context features; establish dynamic feature validity verification rules to preprocess the unstructured data to obtain a standardized feature tensor of unified dimensions; based on the standardized feature tensor, jointly model the spatiotemporal features of API behavior through the collaborative architecture of the multi-head temporal attention mechanism and the dynamic graph neural network, generate an API behavior prediction model, and perform API behavior prediction to obtain prediction results; based on the prediction results of the API behavior prediction model, generate API dynamic security management and control policies in real time through the policy engine, and execute the policies to obtain security policy execution effects; Monitor the effectiveness of security policy execution in real time, and iteratively optimize model parameters and policy rules through feedback mechanisms.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the API behavior prediction and security policy management method based on machine learning as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for API behavior prediction and security policy management based on machine learning as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Zero-trust API gateway dynamic trust evaluation and access control method and system based on machine learning

    CN114465807A

  • Internal network zero-trust architecture based on large model

    CN118432921A

  • Multi-dimensional combined API gateway flow control method and system

    CN119011453A

  • Cross-domain network security policy automatic generation and protection policy collaboration method and system

    CN119449428A

  • Machine Learning Techniques for Detecting Anomalous API Call Behavior

    US20230409714A1

Cited By

  • Notebook software vulnerability scanning method and system based on security policy

    CN120832670A

  • Large model API management and control method and system based on digital certificate

    CN120896789A

  • A large model API management method and system based on digital certificates

    CN120896789B

  • Intelligent caching method and device based on self-adaptive caching strategy

    CN121579388A

  • An artificial intelligence-based API security policy optimization method and system

    CN122578343B