Safety protection method, system and equipment based on API identity portrait and medium

By building a multi-dimensional risk assessment system for API identity portraits, using FP-Growth and PrefixSpan algorithms to mine interface association patterns, and dynamically calculating the total risk score, we solve the problems of resource waste and missed detection in existing API security protection and achieve efficient and accurate API security protection.

CN120768677AInactive Publication Date: 2025-10-10SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Patent Information

Application Number
CN202511255654.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2025-10-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing API security protection system lacks a fine-grained grading mechanism, resulting in resource waste and missed detection of high-risk traffic in high-concurrency scenarios, and is unable to strike a balance between accurately identifying high-risk operations and quickly releasing low-risk requests.

Method used

By building a multi-dimensional risk assessment system based on API identity portraits, including basic, behavioral, relationship and attack risk assessments, using FP-Growth and PrefixSpan algorithms to mine interface association patterns, combining historical data and real-time traffic analysis, and dynamically calculating the total risk score to achieve hierarchical protection.

Benefits of technology

It improves the accuracy and efficiency of API security testing, reduces resource consumption, accurately identifies high-risk requests, and avoids excessive intervention in normal requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768677A_ABST
    Figure CN120768677A_ABST
Patent Text Reader

Abstract

The invention provides a security protection method, system and device based on an API identity portrait and a medium, and belongs to the technical field of network security. The method comprises the steps of obtaining static attributes of a target API, including a data operation type, a transaction integrity requirement and a sensitive field, and determining a basic risk score B according to a preset coefficient; historical request logs are collected and analyzed, traffic baselines at different time points are determined, and the current traffic and the baselines are compared in real time to obtain behavior risk scores A; the method comprises the following steps: acquiring a call log, mining an API co-occurrence set by using FP-Growth, constructing a high-frequency sequence pattern through a PrefixSpan algorithm, and comparing a current session request to obtain a relation risk score N; summarizing attack frequencies and types in a preset time period, and obtaining an attack risk score R in combination with a historical statistical value; a total risk score W is determined based on the above scores, and whether to trigger detection is determined with reference to a preset threshold.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and more specifically relates to a security protection method, system, equipment and medium based on API identity profiling. Background Art

[0002] With the prevalence of microservices and cloud-native architectures, APIs have become core channels for business interactions, and their number is growing exponentially. However, existing API security systems generally adopt a "one-size-fits-all" detection strategy: performing the same level of log auditing, signature verification, rule matching, and behavioral analysis on all requests. This indiscriminate processing rapidly consumes computing, storage, and network resources in high-concurrency scenarios, leading to increased latency and frequent false positives. This dilution of resources can also lead to missed detection of high-risk traffic that actually carries attack signatures, significantly inadequate overall protection efficiency.

[0003] One of the fundamental reasons for this inefficiency is the lack of a fine-grained grading mechanism that can dynamically quantify "risk levels." While the industry has proposed the concept of "API behavior baselines," existing implementations only model the timing statistics of a single interface (such as the call frequency and peak bandwidth of an independent interface), ignoring the data dependencies, call timing, and co-occurrence relationships between multiple interfaces within the same business session. The result is that a seemingly "low-frequency" core write interface, if embedded in an abnormal call chain, can severely underestimate its true threat. Meanwhile, high-frequency but harmless read interfaces are continuously and deeply inspected, leading to resource misallocation.

[0004] Furthermore, traditional solutions lack systematic, quantitative assessments of API static attributes (data operation types, transaction integrity requirements, and sensitive field exposure), making it impossible to prioritize risk weights. Learning attack signatures also relies solely on fixed rules, failing to integrate recent attack frequency, type, and source into a real-time, iterative threat profile. These shortcomings collectively make it difficult for existing technologies to strike a balance between accurately identifying high-risk operations and quickly approving low-risk requests. Summary of the Invention

[0005] In response to the above problems, the purpose of the present invention is to provide a security protection method, system, equipment and medium based on API identity portrait. By proposing a targeted protection mechanism based on identity portrait and constructing a multi-dimensional API risk portrait grading system, abnormal requests arriving on the website can be discovered in a timely manner. At the same time, intelligent scheduling of detection resources can be realized, thereby improving the accuracy of API security detection and reducing the resource consumption caused by API security detection.

[0006] To achieve the above-mentioned purpose, the present invention is implemented through the following technical solutions: In a first aspect, an embodiment of the present application provides a security protection method based on API identity profiling, including: Obtain static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine a basic risk score B based on preset attribute coefficients; Collect and analyze the historical request logs of the target API to determine the traffic baseline of the target API at different time points. Determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time. Obtain the target API call log, use FP-Growth to conduct interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. In real time, compare the current session request to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determine the relationship risk score N based on the comparison results. Summarize the frequency and types of attacks on the target API within a preset time period, combine them with historical statistics, and determine the attack risk score R; The total risk score W is determined based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and the preset threshold is referred to determine whether to trigger detection.

[0007] In an optional embodiment, obtaining static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determining a basic risk score B based on preset attribute coefficients, includes: Collect the data operation types and transaction integrity requirements of the target API; data operation types include read operations, write operations, and delete operations. Transaction integrity requirements include token verification, cookie verification, and two-factor authentication. Identify sensitive fields in target API request data and return data through data flow analysis; Determine the operation type risk coefficient o based on the data operation type; if the data operation type is a read operation, o=0.1; if the data operation type is a write operation, o=0.7; if the data operation type is a delete operation, o=1.0; The transaction integrity requirement determines the transaction integrity requirement coefficient t. If the transaction integrity requirement is token verification, t=0.6; if the transaction integrity requirement is cookie verification, t=0.3; if the transaction integrity requirement is two-factor authentication, t=0.8; The hierarchical sensitivity coefficient s is determined based on the data type of the sensitive field; if the sensitive field is public data, s=0.1; if the sensitive field is internal business data, s=0.3; if the sensitive field is personal identity information, s=0.7; if the sensitive field is confidential data, s=1.0; The basic risk score B is calculated using the formula B=o+t+s.

[0008] In an optional embodiment, collecting and analyzing historical request logs of the target API, determining traffic baselines of the target API at different time points, and determining a behavior risk score A by comparing current traffic with the corresponding traffic baseline in real time include: Collect the target API's call logs in the last n days and extract the timestamp and unit time granularity traffic value; Establish traffic baselines for the target API at different time points based on the unit time granularity traffic value; Get the flow value p at the current time point T in real time T , and obtain the flow baseline l at the current time point T T ; When p T >l T When the behavioral risk score ;in, is the score coefficient; When p T ≤l T When , the behavioral risk score A=0.

[0009] In an optional embodiment, obtaining the target API call log, using FP-Growth to perform interface co-occurrence mining, determining the API co-occurrence set, and constructing a high-frequency sequence pattern of page jumps using the PrefixSpa algorithm include: Obtain the target API call log, pre-process the call log, extract the session identifier session_id, session timestamp timestamp and interface URI endpoint, and remove invalid requests; Using session_id as the aggregation key, the FP-Growth algorithm is used to mine frequent itemsets, setting the minimum support to 0.7, and obtaining the API co-occurrence set; Based on the frequent itemsets obtained from co-occurrence analysis, the PrefixSpan sequence mining algorithm is combined with the session timestamp to construct a high-frequency sequence pattern of page jumps.

[0010] In an optional embodiment, the real-time comparison of whether the current session request matches the API co-occurrence set and the high-frequency sequence pattern, and determining the relationship risk score N based on the comparison result, includes: Get the current session request in real time and store it temporarily; Determine whether the current session's request matches the API co-occurrence set and high-frequency sequence pattern; If so, the relationship risk score N=0, otherwise N is a preset non-zero value.

[0011] In an optional embodiment, the summarizing the attack frequency and type against the target API within a preset time period and combining historical statistical values ​​to determine the attack risk score R includes: Count the number of attacks on the target API in time period t0 in the past week f t0 and the number of attack types k t0 , and obtain the number of historical attacks during the same period F t0 and the number of attack types K t0 ; By formula Calculate the attack risk score R, where 、 is the preset weight coefficient.

[0012] In an optional embodiment, determining the total risk score W based on the basic risk score B, the behavioral risk score A, the relationship risk score N, and the attack risk score R, and determining whether to trigger detection with reference to a preset threshold, includes: Set the score threshold m and calculate the total risk score W using the formula W=B+A+N+R; If W>m, it is determined that the current session request of the target API needs to be detected; if W≤m, it is determined that the current session request of the target API does not need to be detected.

[0013] In a second aspect, the present application also provides a security protection system based on API identity profiling, including: The basic profile construction module is used to obtain the static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine the basic risk score B based on preset attribute coefficients; The behavior profile construction module is used to collect and analyze the historical request logs of the target API, determine the traffic baseline of the target API at different time points, and determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time; The relationship profile construction module is used to obtain the call logs of the target API, use FP-Growth to conduct interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. It then compares the current session request in real time to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determines the relationship risk score N based on the comparison results. The risk profile construction module is used to summarize the frequency and types of attacks on the target API within a preset time period, and combine historical statistical values ​​to determine the attack risk score R; The comprehensive risk assessment and decision-making module is used to determine the total risk score W based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and refer to the preset threshold to determine whether to trigger detection.

[0014] In a third aspect, an embodiment of the present application also provides an electronic device comprising a memory, a processor, and a computer program stored on the memory and runnable on the processor. When the processor executes the program, the steps of the security protection method based on API identity portrait as described in any one of the above items are implemented.

[0015] In a fourth aspect, an embodiment of the present application further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the security protection method based on API identity portrait as described in any one of the above items are implemented.

[0016] It can be seen from the above technical solutions that the present invention has the following advantages: In the security protection method based on API identity profiling provided in this application, inherent risks are quantified through static attribute analysis and preset coefficient models, traffic baselines are built based on historical logs and deviations are calculated in real time to capture sudden risks, FP-Growth and PrefixSpan algorithms are used to mine interface association patterns and identify logical anomalies through session matching, and threats are dynamically tracked based on periodic attack feature statistics and weighted models. Finally, multi-dimensional score aggregation and threshold judgment are combined to achieve hierarchical protection, which avoids excessive intervention while accurately detecting high-risk requests, significantly improving the pertinence, accuracy and efficiency of API security protection. This application constructs a scoring system for API basic profiling, behavioral profiling, relationship profiling, and risk profiling, which enables a level-based classification of API security testing. It strengthens security protection for higher-risk APIs and moderately relaxes protection for lower-risk APIs, thereby improving the accuracy of API security testing and reducing resource consumption caused by API security testing.

[0017] This application uses a detailed analysis of API static properties in basic risk assessment, combined with preset operation types, transaction integrity, and sensitive field coefficient models, to accurately quantify the risks of read / write / delete operations, the strength of authentication mechanisms such as tokens / cookies, and the sensitivity levels of public / confidential data. This builds a comprehensive and scientific risk assessment foundation for security protection, ensuring early identification and quantification of risks from the inherent properties of the API.

[0018] The application establishes a traffic baseline of multiple time granularities by behavior risk assessment relying on historical request logs, dynamically captures abnormal fluctuation of traffic by comparing deviation value of current traffic with baseline in real time and using specific calculation formula, and discovers sudden traffic exceeding normal range in time, thereby significantly improving response sensitivity and monitoring accuracy of dynamic behavior risk in API calling process.

[0019] The application uses FP-Growth algorithm to perform session aggregation and frequent item set mining on calling logs through relationship risk assessment, analyzes time sequence association to construct high-frequency sequence pattern by using PrefixSpan algorithm, and performs real-time session request and pattern matching verification, thereby effectively identifying abnormal requests deviating from normal interface calling logic and strengthening deep prevention and control of associated calling risk between APIs.

[0020] The application uses a week as a period to statistically count attack frequency and types through attack risk assessment, calculates threat score by using a weighted model in combination with historical same-period data, and finally compares the aggregated basic, behavior, relationship and attack risk scores with a preset threshold to realize graded protection, thereby accurately locking high-risk requests and triggering detection while avoiding excessive intervention on normal requests, and significantly improving the pertinence and overall efficiency of API security protection. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the present application, the drawings needed in the description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0022] Figure 1 The flowchart of the security protection method based on API identity portrait provided by the present application.

[0023] Figure 2 The structural diagram of the security protection system based on API identity portrait provided by the present application.

[0024] Figure 3 The structural diagram of the electronic device provided by the present application. DETAILED DESCRIPTION

[0025] In the following detailed description of the specific steps of the security protection method based on API identity portrait, various embodiments of the present disclosure will be described more fully. The present disclosure can have various embodiments, and adjustments and changes can be made therein. However, it should be understood that there is no intention to limit various embodiments of the present disclosure to specific embodiments disclosed herein, but the present disclosure should be understood to cover all adjustments, equivalents and / or alternatives falling within the spirit and scope of various embodiments of the present disclosure.

[0026] Hereinafter, the terms "include" or "may include" as used in various embodiments of the present disclosure indicate the presence of disclosed functions, operations, or elements, and do not limit the addition of one or more functions, operations, or elements. In addition, as used in various embodiments of the present disclosure, the terms "include," "have," and their cognates are intended only to indicate specific features, numbers, steps, operations, elements, components, or combinations of the foregoing, and should not be understood as excluding the presence of one or more other features, numbers, steps, operations, elements, components, or combinations of the foregoing, or the possibility of adding one or more features, numbers, steps, operations, elements, components, or combinations of the foregoing.

[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0028] See also Figure 1 The figure shows a method flow chart of a security protection method based on API identity profiling in a specific embodiment, the method comprising: S1: Obtain static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine a basic risk score B based on preset attribute coefficients.

[0029] In a specific implementation, this step extracts static API attributes, constructs a basic profile, and quantifies the inherent risks of API functionality and data processing. The specific implementation process is as follows: First, perform static attribute collection, including: Data operation type identification: By parsing API interface documents (such as the OpenAPI specification) or static code analysis, the API's data operation type (read / write / delete) is determined. For example, an API that queries user information is a read operation, an API that modifies order status is a write operation, and an API that deletes account data is a delete operation.

[0030] Transaction integrity requirements extraction: Check the API request authentication mechanism to determine the transaction integrity requirements it uses (token verification / cookie verification / two-factor authentication). For example, APIs that require a JWT in the request header use token verification, APIs that rely solely on browser cookies use cookie verification, and APIs that require both an SMS verification code and a password use two-factor authentication.

[0031] Sensitive field identification: Data flow analysis tools (such as API gateway log auditing systems) are used to capture API request parameters and response data. Based on pre-defined data classification specifications, sensitive field types can be identified. For example, ID numbers in requests and bank card balances in responses are considered personal identity information, internal sales data is considered internal business data, product prices are considered public data, and core algorithm parameters are considered confidential data.

[0032] Then, the risk factor is calculated. Specifically, based on the data operation type, the operation type risk factor o is determined; for read operations, o=0.1, for write operations, o=0.7, and for delete operations, o=1.0. Based on transaction integrity requirements, the transaction integrity factor t is determined, with t=0.6 for token verification, t=0.3 for cookie verification, and t=0.8 for two-factor authentication. Based on the sensitive field type, the hierarchical sensitivity factor s is determined, with s=0.1 for public data, s=0.3 for internal business data, s=0.7 for personal identity information, and s=1.0 for confidential data (if multiple sensitive fields exist, the highest sensitivity factor is used).

[0033] Finally, the basic risk score is calculated.

[0034] The basic risk score is calculated using the formula B = o + t + s, forming the core indicators of the basic profile (ranging from 0.5 to 2.8). For example, a write API (o = 0.7) that uses token authentication (t = 0.6) and processes personal identity information (s = 0.7) has a basic risk score of B = 0.7 + 0.6 + 0.7 = 2.0.

[0035] S2: Collect and analyze the historical request logs of the target API to determine the traffic baseline of the target API at different time points. Determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time.

[0036] In a specific implementation, this step analyzes the time series characteristics of API calls, constructs a behavioral profile, and quantifies the risk of deviation of real-time traffic from the historical baseline. The specific implementation process is as follows: First, we build a historical traffic baseline. Specifically, we collect the target API's call logs for the last 30 days (n=30) and extract the timestamp (accurate to the minute) and traffic value (number of calls) per unit time granularity (e.g., every 5 minutes) for each log entry.

[0037] At this time, traffic data is aggregated by time dimension (hourly / daily), and periodic characteristics (such as peak traffic from 9:00 to 18:00 on weekdays and decreased traffic on weekends) and time distribution stability (such as standard deviation of traffic fluctuation at 12:00 every day) are analyzed to establish traffic baselines at different time points. TFor example, a 5-minute granularity baseline at 10:00 on weekdays T = 120 beats / 5 minutes, baseline at 3:00 AM T =10 times / 5 minutes.

[0038] Then, perform real-time traffic comparison and score calculation. Specifically: Real-time monitoring of the flow value p at the current time point T T (For example, 150 calls within 5 minutes of the current 10:00).

[0039] If p T >l T , then the behavioral risk score ( is the score coefficient, usually set to 0.5 to limit the score range). For example, p T =150,l T =120, then A=(150-120) / 120×0.5=0.125.

[0040] If p T ≤l T , then A=0, indicating that the traffic is within the normal behavior baseline.

[0041] S3: Obtain the target API call log, use FP-Growth to perform interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. In real time, compare the current session request to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determine the relationship risk score N based on the comparison results.

[0042] In a specific implementation, this step mines the co-occurrence and temporal correlation of API calls to construct a relationship profile and quantify the risk of deviation of the current session from the normal calling pattern. The specific implementation process is as follows: S301: Log preprocessing and correlation analysis.

[0043] Log cleaning: Extract the session identifier session_id, session timestamp, and interface URI endpoint from the API gateway log, and remove invalid requests with status codes ≥ 400, timed requests, and monitoring probe requests (such as health check interfaces).

[0044] Co-occurrence mining: Using session_id as the aggregation key, we group API calls within the same user session and use the FP-Growth algorithm to mine frequent itemsets (minimum support 0.7) to obtain the API co-occurrence set. For example, when a user visits a product detail page, the co-occurrence frequency of / api / goods / detail (core API), / api / recommend (auxiliary API), and / api / user / profile (dependent API) reaches 70%, forming a co-occurrence set.

[0045] Time series pattern construction: Based on co-occurrence sets and timestamps, the PrefixSpan algorithm is used to mine high-frequency sequential patterns. For example, the call sequence " / api / login → / api / cart → / api / order" appears in 70% of payment sessions, forming a time series pattern.

[0046] S302: Real-time conversation comparison and score calculation.

[0047] The request sequence of the current session_id is stored in real time (such as / api / cart→ / api / order, missing / api / login).

[0048] Compare the current sequence with the co-occurrence set and high-frequency sequence pattern: if there is a perfect match (such as conforming to the co-occurrence set and following the time sequence), the relationship risk score N=0; if there is a mismatch (such as missing necessary dependent interfaces or the order is reversed), N=1.0 (this value is a preset non-zero value and can be adjusted according to the degree of deviation).

[0049] S4: Summarize the frequency and types of attacks on the target API within a preset time period, combine them with historical statistical values, and determine the attack risk score R.

[0050] In a specific implementation, this step analyzes the attack characteristics suffered by the API, builds a risk profile, and quantifies the real-time threat intensity. The specific implementation process is as follows: First, use WAF (Web Application Firewall) and Intrusion Detection System (IDS) to collect the target API's attack logs for the past week, and classify and record the attack types (such as SQL injection, XSS, brute force cracking, etc.).

[0051] Then, count the number of attacks f within the time period t0 (e.g., 9:00-18:00 every day) t0 and the number of attack types k t0 ; At the same time, retrieve the number of attacks F during the same period in history (such as the same period last week) t0 and the number of attack types K t0 (If it is a new API, the historical value is the industry average).

[0052] Finally, through the formula Calculate the score R, where =0.6, =0.4 is the preset weight, balancing the impact of attack frequency and type. For example, if within t0 this week, f t0 =20, F t0 =10,k t0 =3, K t0 =2, then R=0.6×(20 / 10)+0.4×(3 / 2)=1.2+0.6=1.8.

[0053] S5: Determine the total risk score W based on the basic risk score B, the behavioral risk score A, the relationship risk score N, and the attack risk score R, and refer to the preset threshold to determine whether to trigger detection.

[0054] In a specific implementation, this step integrates multi-dimensional portrait scores to determine whether enhanced detection is needed. The specific implementation process is as follows: First, calculate the total risk score W using the formula W = B + A + N + R. Then, preset the score threshold m, where m can be adjusted based on the importance of the API, such as m = 3.0 for core payment APIs and m = 4 for general query APIs.

[0055] If W>m: The current session request is judged to be high-risk, triggering enhanced detection (such as real-time interception, verification code verification, and manual review).

[0056] If W≤m: the risk is determined to be within an acceptable range and does not need to be detected.

[0057] Through the above implementation process, a multi-dimensional identity portrait is formed based on the API's basic portrait, behavioral portrait, relationship portrait, and risk portrait. Finally, the detection intensity is dynamically adjusted through the total risk score to achieve accurate API security protection.

[0058] In this embodiment, by constructing basic API profiles, behavioral profiles, relationship profiles, and risk profiles, a multi-dimensional risk quantification assessment is achieved from four dimensions: static attributes, dynamic behavior, correlation patterns, and attack threats. On the one hand, static attribute analysis clarifies the inherent risk base of the API, combines real-time traffic baseline comparison to capture abnormal behavior, relies on co-occurrence and temporal correlation mining to identify abnormal call patterns, and correlates historical attack data to quantify threat intensity, forming a comprehensive and dynamic risk assessment system. On the other hand, by comparing the total risk score with the preset threshold, differentiated detection intensity can be accurately triggered, effectively identifying high-risk requests to strengthen security protection, while avoiding performance loss caused by excessive detection of normal requests, ultimately achieving the unity of precision, dynamism, and efficiency in API security protection.

[0059] like Figure 2As shown, the following is an embodiment of the security protection system based on API identity portrait provided by the embodiment of the present disclosure. The system and the security protection method based on API identity portrait in the above embodiments belong to the same inventive concept. For details not described in detail in the embodiment of the security protection system based on API identity portrait, please refer to the embodiment of the security protection method based on API identity portrait.

[0060] A security protection system based on API identity profiling, including: The basic profile construction module is used to obtain the static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine the basic risk score B based on preset attribute coefficients.

[0061] The behavior profile construction module is used to collect and analyze the historical request logs of the target API, determine the traffic baseline of the target API at different time points, and determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time.

[0062] The relationship profile construction module is used to obtain the call log of the target API, use FP-Growth to mine interface co-occurrence, determine the API co-occurrence set, and construct the high-frequency sequence pattern of page jumps through the PrefixSpa algorithm; compare the current session request in real time to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determine the relationship risk score N based on the comparison results.

[0063] The risk profile construction module is used to summarize the frequency and types of attacks on the target API within a preset time period, and combine historical statistical values ​​to determine the attack risk score R.

[0064] The comprehensive risk assessment and decision-making module is used to determine the total risk score W based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and refer to the preset threshold to determine whether to trigger detection.

[0065] The API identity profiling-based security protection system provided in this embodiment achieves a comprehensive upgrade of API security protection through multi-dimensional risk assessment: basic risk assessment uses static attribute analysis and coefficient models to accurately quantify API inherent risks and build a scientific assessment basis; behavioral risk assessment relies on historical logs to establish a traffic baseline and dynamically captures abnormal traffic through deviation calculation to improve response sensitivity and accuracy; relationship risk assessment uses FP-Growth and PrefixSpan algorithms to mine interface association patterns, and effectively identifies abnormal requests that deviate from normal logic through session matching; attack risk assessment uses periodic statistics combined with weighted models to calculate threat scores, and finally implements hierarchical protection through multi-dimensional score aggregation and threshold judgment, accurately locking high-risk requests while avoiding excessive intervention, greatly improving the targetedness and overall efficiency of API security protection.

[0066] Figure 3 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present invention.

[0067] The security protection method based on API identity portrait provided in the embodiment of the present application can be applied to electronic devices. Those skilled in the art will understand that the electronic device structure involved in the embodiment of the present invention does not constitute a limitation on the electronic device, and the electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. In the embodiment of the present invention, the electronic device includes but is not limited to laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of the present application described and / or required herein.

[0068] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, a button, a camera, a display, and a SIM card interface, etc.

[0069] A processor may include one or more processing units, such as a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors.

[0070] The processor can be the nerve center and command center of the electronic device. The controller can generate operation control signals based on the instruction opcode and timing signal to complete the control of instruction fetching and execution.

[0071] The processor may also include a memory for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. This memory can store instructions or data that the processor has just used or is reusing. If the processor needs to use the instruction or data again, it can directly call it from the memory. This avoids repeated accesses, reduces processor latency, and thus improves system efficiency.

[0072] The external memory interface can be used to connect an external memory card, such as a MicroSD card, to expand the storage capacity of an electronic device. The external memory card communicates with the processor through the external memory interface, enabling data storage. For example, files such as music and videos can be stored on the external memory card.

[0073] Internal memory can be used to store computer-executable program code, which includes instructions. The processor executes the instructions stored in the internal memory to perform various functional applications and data processing of the electronic device. The internal memory can include a program storage area and a data storage area. The internal memory can include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.

[0074] The wireless communication function of an electronic device can be implemented through an antenna, a wireless communication module, a modem processor, and a baseband processor.

[0075] Wireless communication modules can provide wireless communication solutions for electronic devices, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc.

[0076] Electronic devices can implement audio functions through audio modules, speakers, receivers, microphones, headphone jacks, and application processors.

[0077] Electronic devices can achieve shooting functions through ISP, camera, video codec, GPU, display and application processor.

[0078] Electronic devices can achieve display functions through GPU, display screen and application processor.

[0079] A GPU is a microprocessor for image processing that connects the display screen to the application processor. The GPU performs mathematical and geometric calculations for graphics rendering. A processor may include one or more GPUs, which execute program instructions to generate or modify display information.

[0080] The display screen is used to display images, videos, etc. The display screen includes a display panel.

[0081] The above-mentioned electronic device implements the security protection method based on API identity portrait of this application through static attribute analysis and coefficient model of basic risk assessment, traffic baseline construction and deviation calculation of behavioral risk assessment, FP-Growth and PrefixSpan algorithm mining and session matching of relationship risk assessment, and periodic statistics and weighted model calculation of attack risk assessment, and realizes hierarchical protection through multi-dimensional score aggregation and threshold judgment, achieving the beneficial effect of accurately locking high-risk requests, avoiding excessive intervention, and greatly improving the targetedness and overall efficiency of API security protection.

[0082] The storage medium provided in this application stores a program product that can implement a security protection method based on API identity profiling.

[0083] Security protection methods based on API identity profiling include: Obtain static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine a basic risk score B based on preset attribute coefficients; Collect and analyze the historical request logs of the target API to determine the traffic baseline of the target API at different time points. Determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time. Obtain the target API call log, use FP-Growth to conduct interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. In real time, compare the current session request to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determine the relationship risk score N based on the comparison results. Summarize the frequency and types of attacks on the target API within a preset time period, combine them with historical statistics, and determine the attack risk score R; The total risk score W is determined based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and the preset threshold is referred to determine whether to trigger detection.

[0084] In some possible implementations, the API identity portrait-based security protection method disclosed herein can be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps described in the above "Exemplary Method" section of this specification according to various exemplary implementations of the present disclosure.

[0085] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0086] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security protection method based on API identity profiling, characterized in that: include: Obtain static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine a basic risk score B based on preset attribute coefficients; Collect and analyze the historical request logs of the target API to determine the traffic baseline of the target API at different time points. Determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time. Obtain the target API call log, use FP-Growth to conduct interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. In real time, compare the current session request to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determine the relationship risk score N based on the comparison results. Summarize the frequency and types of attacks on the target API within a preset time period, combine them with historical statistics, and determine the attack risk score R; The total risk score W is determined based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and the preset threshold is referred to determine whether to trigger detection.

2. The security protection method based on API identity profiling according to claim 1 is characterized in that: The static attributes of the target API are obtained, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and a basic risk score B is determined based on preset attribute coefficients, including: Collect the data operation types and transaction integrity requirements of the target API; data operation types include read operations, write operations, and delete operations. Transaction integrity requirements include token verification, cookie verification, and two-factor authentication. Identify sensitive fields in target API request data and return data through data flow analysis; Determine the operation type risk coefficient o based on the data operation type; if the data operation type is a read operation, o=0.1; if the data operation type is a write operation, o=0.7; if the data operation type is a delete operation, o=1.0; The transaction integrity requirement determines the transaction integrity requirement coefficient t. If the transaction integrity requirement is token verification, t=0.6; if the transaction integrity requirement is cookie verification, t=0.3; if the transaction integrity requirement is two-factor authentication, t=0.8; The hierarchical sensitivity coefficient s is determined based on the data type of the sensitive field; if the sensitive field is public data, s=0.1; if the sensitive field is internal business data, s=0.3; if the sensitive field is personal identity information, s=0.7; if the sensitive field is confidential data, s=1.0; The basic risk score B is calculated using the formula B=o+t+s.

3. The security protection method based on API identity profiling according to claim 2 is characterized in that: The process of collecting and analyzing the historical request logs of the target API, determining the traffic baselines of the target API at different time points, and determining the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time includes: Collect the target API's call logs in the last n days and extract the timestamp and unit time granularity traffic value; Establish traffic baselines for the target API at different time points based on the unit time granularity traffic value; Get the flow value p at the current time point T in real time T , and obtain the flow baseline l at the current time point T T ; When p T >l T When the behavioral risk score ;in, is the score coefficient; When p T ≤l T When , the behavioral risk score A=0.

4. The security protection method based on API identity profiling according to claim 3 is characterized in that: The method involves obtaining the target API call log, using FP-Growth to perform interface co-occurrence mining, determining the API co-occurrence set, and constructing a high-frequency sequence pattern of page jumps using the PrefixSpa algorithm, including: Obtain the target API call log, pre-process the call log, extract the session identifier session_id, session timestamp timestamp and interface URI endpoint, and remove invalid requests; Using session_id as the aggregation key, the FP-Growth algorithm is used to mine frequent itemsets, setting the minimum support to 0.7, and obtaining the API co-occurrence set; Based on the frequent itemsets obtained from co-occurrence analysis, the PrefixSpan sequence mining algorithm is combined with the session timestamp to construct a high-frequency sequence pattern of page jumps.

5. The security protection method based on API identity profiling according to claim 4 is characterized in that: The real-time comparison of whether the current session request matches the API co-occurrence set and the high-frequency sequence pattern, and determining the relationship risk score N based on the comparison result, includes: Get the current session request in real time and store it temporarily; Determine whether the current session's request matches the API co-occurrence set and high-frequency sequence pattern; If so, the relationship risk score N=0, otherwise N is a preset non-zero value.

6. The security protection method based on API identity profiling according to claim 5 is characterized in that: The attack risk score R is determined by summarizing the attack frequency and type against the target API within a preset time period and combining it with historical statistical values, including: Count the number of attacks on the target API in time period t0 in the past week f t0 and the number of attack types k t0 , and obtain the number of historical attacks during the same period F t0 and the number of attack types K t0 ; By formula Calculate the attack risk score R, where 、 is the preset weight coefficient.

7. The security protection method based on API identity profiling according to claim 6 is characterized in that: The method of determining the total risk score W based on the basic risk score B, the behavioral risk score A, the relationship risk score N, and the attack risk score R, and determining whether to trigger detection by referring to a preset threshold, includes: Set the score threshold m and calculate the total risk score W using the formula W=B+A+N+R; If W>m, it is determined that the current session request of the target API needs to be detected; if W≤m, it is determined that the current session request of the target API does not need to be detected.

8. A security protection system based on API identity profiling, characterized in that: The system adopts the security protection method based on API identity profiling as described in any one of claims 1 to 7; The system comprises: The basic profile construction module is used to obtain the static attributes of the target API, including data operation type, transaction integrity requirements, and sensitive fields in requests and responses, and determine the basic risk score B based on preset attribute coefficients; The behavior profile construction module is used to collect and analyze the historical request logs of the target API, determine the traffic baseline of the target API at different time points, and determine the behavior risk score A by comparing the current traffic with the corresponding traffic baseline in real time; The relationship profile construction module is used to obtain the call logs of the target API, use FP-Growth to conduct interface co-occurrence mining, determine the API co-occurrence set, and use the PrefixSpa algorithm to construct the high-frequency sequence pattern of page jumps. It then compares the current session request in real time to see if it matches the API co-occurrence set and the high-frequency sequence pattern, and determines the relationship risk score N based on the comparison results. The risk profile construction module is used to summarize the frequency and types of attacks on the target API within a preset time period, and combine historical statistical values ​​to determine the attack risk score R; The comprehensive risk assessment and decision-making module is used to determine the total risk score W based on the basic risk score B, behavioral risk score A, relationship risk score N, and attack risk score R, and refer to the preset threshold to determine whether to trigger detection.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the security protection method based on API identity portrait as described in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the security protection method based on API identity profiling as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Information security risk assessment method and system based on API

    CN119788309A

  • Network security analysis method and system based on big data

    CN120415850A

  • Command detection and processing method and device, equipment and storage medium

    CN120546945A

  • Anti-fraud method and system based on complex relation network

    CN120579974A

  • Active high-risk IP dynamic monitoring method and device based on optimized FP-Growth algorithm

    CN120582847A

Cited By

  • Intelligent protection portraying method for data service interface

    CN121603258A