Anti-cheating system for CTF competition
Patent Information
- Application Number
- CN202610955198.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-09-25
AI Technical Summary
2.缺乏多源数据融合与行为关联分析能力
与现有主要依赖 IP 限制、浏览器指纹识别或简单提交频率检测的 CTF 防作弊方案相比,本发明采用多维度实时行为建模与环境一致性校验的协同机制,使每个参赛选手的操作序列、解题轨迹、设备环境与访问上下文形成独立的安全画像,从根本上避免了传统方案难以识别的 Flag 共享、远程协助、云主机代打及自动化脚本模拟行为。本发明以行为分析引擎与环境可信度度量为核心,使系统能够在选手提交请求进入平台后即时评估其行为合法性,从而在不影响正常参赛体验的前提下实现高精度、低误报的作弊识别能力。
Smart Images

Figure CN122824447A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to anti-cheating systems, and more particularly to an anti-cheating system for CTF competitions. Background Technology
[0002] CTF (Capture the Flag) cybersecurity competitions, as an important form of cybersecurity talent cultivation, teaching assessment, and technology selection, are widely used in university cybersecurity courses, corporate security training, industry competitions, and various large-scale international events. CTF competitions typically include various types of challenges such as web security, reverse engineering, binary vulnerability exploitation, cryptography, and miscellaneous topics. Participants obtain challenge flags through analysis, attack / defense, and debugging, and submit them to the competition platform to earn points. Because CTF competitions emphasize individual ability and technical skill, fairness and impartiality are crucial to ensuring the quality of the competition.
[0003] However, with the expansion of competition scale, the increased complexity of participants, and the prevalence of online competitions, cheating has become increasingly prominent. Common forms of cheating include: sharing flags among different participants, collaborative answering, logging into the same device with multiple accounts, automating batch submissions using scripts, using simulated environments to forge behavioral patterns, and obtaining answers from illegitimate sources. Such cheating not only disrupts the competition order and affects the experience of legitimate participants, but also significantly reduces the platform's authority in selection, instruction, and evaluation.
[0004] Currently, most CTF competition platforms on the market and in the open-source community offer basic anti-cheating features, but their design focuses primarily on question management, scoring mechanisms, and page rendering, with limited development of cheat detection modules. Existing solutions closest to this invention mainly include the following directions: The first type is a simple anti-cheating mechanism based on "static rule constraints," such as: restricting access from multiple accounts with the same IP address, limiting submission frequency, detecting rapid duplicate submissions of the same flag, and basic judgment based on HTTP User-Agent. This type of solution is low-cost to implement, but relies on a single feature and cannot effectively cope with changes in network conditions such as VPNs, proxies, and switching between multiple devices, and has almost no ability to detect collaborative cheating.
[0005] The second type is the post-competition inspection mechanism based on log auditing. Some platforms manually or semi-automatically compare contestants' access logs, submission records, and problem-solving timelines after the competition to identify abnormal behavior. However, this method has a significant lag and cannot intervene in a timely manner during the competition. Moreover, manual review has problems such as strong subjectivity, large workload, and difficulty in identifying complex behavioral patterns.
[0006] Existing CTF competition platforms still have significant shortcomings in preventing cheating, and their core deficiencies are mainly reflected in the following aspects: 1. The detection dimensions are limited, relying on static rules (most platforms only use simple rules such as IP restrictions, submission frequency limits, and User-Agent determination. Such single-dimensional strategies are easily bypassed by proxies, VPNs, virtual machines, and scripting tools, and lack effective constraints on participants who are aware of the need to circumvent these rules). 2. Lack of multi-source data fusion and behavioral correlation analysis capabilities. (Most existing solutions are unable to comprehensively model multi-dimensional data such as device fingerprints, access logs, page dwell times, problem-solving steps, and submission characteristics. This results in the platform only being able to detect explicit cheating, but unable to identify covert, distributed, or collaborative cheating behaviors.) 3. Inability to monitor the contestant's problem-solving process in a granular manner (most platforms only focus on the final Flag submission behavior, ignoring the contestant's problem-solving path, operation trajectory, access mode, and other behavioral process data, making it difficult to determine whether the contestant has engaged in abnormal behavior such as "submitting without operation" or "copy-and-paste submission"). 4. Lack of real-time capability, relying on post-competition manual auditing (Currently, many platforms' cheating analysis can only be retrospectively checked after the competition, unable to detect anomalies in time during the competition, let alone immediately block cheating behavior, affecting the fairness of the competition and the real-time reliability of scoring.) Summary of the Invention
[0007] This invention provides an anti-cheating system for CTF competitions. By collecting, modeling, and analyzing multi-dimensional data on participants' device environment, behavioral patterns, access patterns, and flag submission characteristics, it achieves real-time identification, risk assessment, and handling of various cheating behaviors. To achieve the above objectives, this invention constructs a complete anti-cheating system including a data collection layer, a behavior analysis layer, a risk assessment layer, and a handling audit layer. Each layer collaborates through modular design to achieve comprehensive prevention and control.
[0008] This invention is achieved through the following technical solution: A cheating prevention system for CTF competitions includes a data acquisition layer, a behavior analysis layer, a risk assessment layer, and a handling and auditing layer. The modular collaboration of each layer enables real-time identification, risk assessment, and handling of cheating behavior in CTF competitions. The data acquisition layer is used to collect contestants' device environment data, network characteristic data, competition behavior data, and Flag submission data in real time. The behavior analysis layer connects to the data acquisition layer to complete data preprocessing and feature extraction, and combines the rule engine and behavior model to carry out multi-dimensional abnormal behavior analysis. The risk assessment layer integrates the output of the behavior analysis layer to classify the risk of participating accounts and generate risk tags. The handling audit layer executes corresponding handling operations according to the risk level and completes the audit and retention of all process behavior data and judgment records.
[0009] Furthermore, the data acquisition layer includes a user identity and environment acquisition module, a behavior data acquisition module, and a flag feature analysis module; The user identity and environment collection module is used to collect three types of data: device fingerprint, network characteristics, and login environment. Device fingerprint includes browser fingerprint, hardware digest, screen resolution, font set, and WebGL characteristics. Network characteristics include IP address, carrier ASN, network latency, and proxy and VPN identification characteristics. Login environment includes operating system, browser version, time zone, and language settings. The behavioral data acquisition module is used to collect the access path and order of questions, page dwell time and jump behavior, key operation trajectory of solving questions, submission time of Flag, submission result and error Flag pattern characteristics; The Flag feature analysis module is used to standardize the submitted Flag content, perform Flag similarity detection, submission time series analysis, Flag propagation chain analysis, and construct a directed time graph with account, IP, device fingerprint, question, Flag, and submission record as nodes to reconstruct the Flag propagation path.
[0010] Furthermore, the behavior analysis layer is divided into a feature processing layer, a behavior modeling layer, and a decision output layer in sequence; The feature processing layer cleans, deduplicates, completes, normalizes, and filters outliers from the original collected data, unifies the timestamp accuracy and data format, and summarizes and generates behavioral indicators according to account, question, and time window dimensions. The behavior modeling layer has a built-in rule engine, statistical analysis module, and machine learning analysis module. The rule engine uses threshold rules, association rules, and time-series rules to screen for explicit cheating behavior. The statistical analysis module calculates indicators such as submission frequency, page dwell time, and number of erroneous submissions to judge the rationality of the behavior. The machine learning analysis module uses clustering algorithms, outlier detection algorithms, and similar behavior analysis algorithms to identify hidden cheating behavior. The judgment output layer integrates the analysis results of each module and outputs preliminary abnormal markers and behavioral characteristic data for the account.
[0011] Furthermore, the rule engine, statistical analysis module, and machine learning analysis module share the same unified feature pool. The rule engine first completes rapid screening and generates risk labels. The risk labels are synchronously input into the machine learning analysis module to participate in in-depth analysis. Finally, the judgment output layer integrates the rule judgment results and the model analysis results.
[0012] Furthermore, the machine learning analysis module uses K-Means and DBSCAN clustering algorithms to divide player behavior groups, uses the isolated forest algorithm to detect outliers, and identifies collaborative cheating accounts by calculating the similarity of operation sequences and submission rhythms between accounts. When an account's submission frequency, time spent on questions, number of device switches, or other metrics exceed the normal percentile of its behavioral group, or when its behavioral chain is missing and it cannot be classified into a normal behavioral group, it is determined to be an abnormal out-of-group account.
[0013] Furthermore, the system is also configured with a dynamically expandable cheating feature library, an incremental model training system, and a rule plugin framework; The cheating feature library is used to store known cheating features, rule templates, statistical features and related features. It supports online updates, version management and the input of new cheating mode features. New cheating features that are manually confirmed or automatically clustered can be sent to the behavior analysis layer in real time. The incremental training system for the model is based on the behavioral data and anomaly detection results continuously collected during the competition to complete the iterative optimization of the model.
[0014] Furthermore, the risk assessment layer combines multiple indicators such as the integrity of the behavior chain, the consistency of the device environment, the relevance of Flag submission, and the similarity of multi-account behavior to classify account risks into three levels: low risk, medium risk, and high risk, and generates corresponding risk labels.
[0015] Furthermore, the handling audit layer has functions such as real-time alarms, submission limit, temporary account freezing / banning, and push notifications for manual review of abnormal behavior; at the same time, it performs structured storage of raw data, feature data, analysis logs, risk assessment results, and handling records throughout the entire process, forming a traceable audit chain.
[0016] Furthermore, the Flag feature analysis module performs standardization processing on Flags, including removing spaces, unifying capitalization, unifying encoding format, and eliminating irrelevant separators; it identifies completely identical or highly similar Flag content through edit distance, common prefix and suffix comparison, and error pattern consistency comparison; and it uses a sliding time window to detect the behavior of multiple accounts simultaneously submitting the same Flag within a specified time range.
[0017] Furthermore, the system implements multi-module data flow based on an event bus and middleware. It can classify load levels according to the number of online contestants, request concurrency, and system resource usage, automatically adapt to the scale of competition concurrency, and ensure the stability and timeliness of the detection link in high-concurrency scenarios.
[0018] Compared with the prior art, the advantages of the present invention are as follows: Compared to existing CTF anti-cheating solutions that primarily rely on IP restrictions, browser fingerprinting, or simple submission frequency detection, this invention employs a collaborative mechanism of multi-dimensional real-time behavioral modeling and environment consistency verification. This allows each participant's operation sequence, problem-solving trajectory, device environment, and access context to form an independent security profile, fundamentally avoiding flag sharing, remote assistance, cloud server proxying, and automated script simulation behaviors that are difficult to detect with traditional solutions. This invention uses a behavioral analysis engine and environment credibility measurement as its core, enabling the system to instantly assess the legality of a participant's behavior after submitting a request to enter the platform. This achieves high-precision, low-false-positive cheating detection capabilities without affecting the normal competition experience.
[0019] At the system execution level, this invention automatically completes multi-source data collection, behavior sequence reconstruction, risk scoring, environmental consistency calculation, and automated handling strategy distribution through an event bus and middleware link. This avoids the highly coupled mode of traditional solutions where each module builds its own log system and maintains its own detection scripts. This mechanism enables the platform to maintain the stability and high throughput of the detection link even under large-scale competition concurrent access, and ensures that cheating identification will not be delayed or missed due to increased system load.
[0020] Furthermore, this invention constructs a dynamically expandable cheating feature library, an incremental model training system, and a rule plugin framework, enabling cheating detection capabilities to continuously evolve with changes in competition scale, question types, and the emergence of new cheating methods. Compared to existing technologies that rely on manual rule configuration and frequent manual review, this invention's automated detection and strategy-based handling significantly reduce the management costs for both the referee team and the platform, improving the fairness, controllability, and operational security of the competition. Attached Figure Description
[0021] The invention will now be further described with reference to the accompanying drawings.
[0022] Figure 1 This is a flowchart of the present invention. Detailed Implementation
[0023] The invention will now be further described with reference to the accompanying drawings.
[0024] Example 1
[0025] This invention provides an anti-cheating system for CTF competitions. By collecting, modeling, and analyzing multi-dimensional data on participants' device environment, behavioral patterns, access patterns, and Flag submission characteristics, it achieves real-time identification, risk assessment, and handling of various cheating behaviors. To achieve the above objectives, this invention constructs a complete anti-cheating system comprising a data collection layer, a behavior analysis layer, a risk assessment layer, and a handling audit layer. Each layer collaborates through modular design to achieve comprehensive prevention and control.
[0026] The multi-dimensional real-time behavior modeling adopts a layered architecture design, mainly including a data acquisition layer, a feature processing layer, a behavior modeling layer, and a judgment output layer. The data acquisition layer is used to acquire raw behavioral data in real time, such as the contestant's keyboard input rhythm, mouse movement trajectory, page access path, window switching behavior, and Flag submission records. The feature processing layer cleans and processes the above data, extracting time series features, frequency features, and operation pattern features. The behavior modeling layer constructs a contestant behavior model based on these features, employing time series analysis models, anomaly detection models, or clustering models to perform pattern recognition and deviation analysis on the contestant's behavior. The judgment output layer performs a comprehensive evaluation based on the model output results and preset rules, generating a behavior risk score and anomaly markers.
[0027] The more detailed process is as follows: Data cleaning: The system performs integrity checks on browser fingerprints, IP addresses, User-Agents, page access records, mouse and keyboard events, window switching records, and Flag submission records, removing empty fields, duplicate events, abnormal timestamps, and obviously forged data.
[0028] After receiving the collected data such as browser fingerprints, IP addresses, ASNs, User-Agents, page access paths, question dwell time, window switching, Flag submission time, and submission results, the feature processing layer first performs deduplication, completion, normalization, and outlier filtering. For example, consecutive accesses by the same account to the same question are merged into a single solving session, millisecond-level timestamps are unified into second-level time windows, and User-Agents are parsed into browser type, browser version, operating system, and device type.
[0029] The processed data is summarized according to "account dimension, question dimension, and time window dimension" to form behavioral indicators that can be used for detection, such as: number of submissions per unit time, number of accounts with the same IP address, number of device fingerprint changes, interval between accessing the question and submission, number of times the error flag is repeated, and number of times the same flag appears between different accounts.
[0030] The various models are connected in a pipeline manner: the rule engine first performs a quick screening to identify obvious anomalies such as multiple accounts on the same IP, high frequency of submissions in a short period of time, and submissions without accessing the questions; the statistical analysis module then calculates whether the submission frequency, dwell time, number of errors, etc. exceed the normal range; the clustering or outlier detection module further determines whether the account deviates from the normal group of contestants; finally, the judgment output layer summarizes the results of each module and generates low-risk, medium-risk, or high-risk labels.
[0031] For example, if the same account repeatedly reports the same mouse trajectory event within a very short period, only one instance is retained; events with timestamps earlier than the login time or later than the competition end time are marked as abnormal. Time series feature extraction: The system reassembles player behavior chronologically, forming a behavioral chain from login, accessing the problem, downloading attachments, viewing hints, accessing the target machine, to submitting the flag. The system calculates the time intervals between adjacent actions, such as "the interval between accessing the problem and the first submission," "the interval between two flag submissions," and "the duration of time spent on the same problem page," to determine if there are anomalies such as submissions without a solution process or concentrated submissions within a short period.
[0032] The simple calculation method is as follows: Behavior interval = Time of occurrence of the next behavior - Time of occurrence of the previous behavior Duration spent on the question = Time spent leaving the question page - Time spent entering the question page Submission interval = Current submission time - Last submission time In this invention, data collection is not simply based on existing log recording methods, but rather an improvement upon existing technology. During the contestant's access to the platform and participation in the competition, the system collects real-time information on their device environment (such as device fingerprint, operating system, and network environment), operational behavior data (such as mouse movement, keyboard rhythm, and page interaction), access path data (such as the order of question access, dwell time, and jump relationships), and Flag submission data (such as submission time, submission frequency, and results). The collected data first enters a preprocessing stage (the system extracts behavioral patterns based on the contestant's operation sequence and combination, such as "submitting immediately after accessing a question," "submitting directly without downloading attachments," "continuous submissions despite prolonged inactivity," "multiple accounts submitting in the same question order," and "multiple accounts with highly consistent error Flag content," etc.). These patterns are converted into identifiable tags, such as "missing solution path," "abnormally high-frequency submissions," "suspected script submissions," and "suspected shared Flags." Abnormal data is filtered, data from different sources is standardized, and the data is stored in a structured format according to a unified format.
[0033] Device fingerprinting, log collection, and IP recording are conventional methods, but the improvement of this invention lies not in collecting a single type of data, but in combining browser fingerprinting, network environment identification, and automated behavior identification commonly used in anti-scraping fields with the CTF platform's unique problem access links, flag submission links, and contestant problem-solving processes for CTF competition scenarios.
[0034] Specifically, while conventional anti-scraping systems primarily determine whether a visitor is using an automated script, this invention further determines whether "the account has a reasonable problem-solving process." For example, even if an account has a normal browser fingerprint, if it submits the correct flag without downloading attachments, viewing question details, or spending very little time on the page, the system will still determine that it poses a risk of sharing answers or submitting on behalf of others. Therefore, the technical point of this invention is to link environmental credibility with the reasonableness of CTF problem-solving behavior, rather than simply recording logs.
[0035] (a) User Identity and Environment Collection Module This module is used to collect basic environmental information from the participants, including: 1. Device fingerprinting: browser fingerprint, hardware summary, screen resolution, font set, WebGL features; 2. Network characteristics: IP address, carrier ASN, network latency, proxy traces, VPN identification features; 3. Login environment: operating system type, browser version, time zone and language settings.
[0036] By integrating the above information, the system can generate stable device environment identifiers to identify abnormal behaviors such as multiple accounts sharing devices and the same account frequently switching devices.
[0037] (ii) Behavioral data collection module This module is responsible for monitoring the contestants' behavior throughout the entire competition process, and the data collected includes: 1. The access path and order of the questions; 2. Page dwell time and redirection behavior; 3. Key operational steps in the problem-solving process, such as the analysis of the problem's attachments and the frequency of reading the hints. 4. Flag commit behavior, including commit time, commit result, and pattern characteristics of error flags.
[0038] This module enables fine-grained capture of contestants' behavior processes, thereby providing a data foundation for subsequent judgments on whether contestants' behavior is reasonable.
[0039] (III) Flag Feature Analysis Module This module performs in-depth analysis of the submitted Flag content and submission behavior, including: 1. Flag Similarity Detection: Identifies highly consistent or similar flags between different accounts; During the Flag submission phase, the system preprocesses each submission, including removing irrelevant characters, standardizing capitalization, and regulating encoding formats for rapid subsequent comparison. In the propagation chain analysis, the system constructs a directed time graph based on the relationship between submission time and similarity. For example, if an account submits a correct Flag for the first time, and multiple accounts subsequently submit similar Flags within a short period, differentiated processing is applied. At low risk, only logs are recorded, risk tags are generated, and continuous monitoring is performed. At medium risk, alerts are triggered, Flag submission frequency or number of submissions is limited, secondary verification is required, and the submission is pushed to a judge or administrator for review. At high risk, accounts can be temporarily frozen or banned, scoring is suspended, abnormal submissions are revoked, and further submissions are blocked. The original data, feature data, judgment results, and handling records are structurally stored.
[0040] Flag similarity detection first standardizes the submitted content, including removing spaces, unifying capitalization, standardizing encoding, and removing irrelevant delimiters. The system then determines whether two flags are completely identical or differ only slightly in characters. For completely identical flags, the system considers submission time, account relationship, and access path to determine if they were shared. For similar flags, the system uses edit distance, common prefixes and suffixes, and error pattern consistency to determine if they were copied and slightly modified.
[0041] Submission time series analysis uses a sliding time window. For example, if multiple accounts submit the same or highly similar flags for the same question within 1 to 3 minutes, and these accounts lack reasonable access, download, or dwell behavior before submission, the system raises the risk level.
[0042] Directed time graphs can draw on existing graph analysis techniques, but the improvement of this invention lies in the design of graph nodes and edges geared towards CTF competitions. The system uses accounts, IPs, device fingerprints, questions, flags, and submission records as nodes, and uses relationships such as "same device," "same IP," "same flag," "short-term consecutive submissions," and "similar access paths" as edges, thereby reconstructing the propagation path of suspected flags.
[0043] 2. Submission Time Series Analysis: Detects flags where multiple accounts simultaneously submit the same problem within a short time window; 3. Propagation chain analysis: Construct a time graph of submission behavior to identify possible sharing paths.
[0044] This module can identify the most common cheating behaviors such as sharing answers, group collaborative submissions, and plagiarism.
[0045] The system constructs a directed temporal graph based on the relationship between submission time and similarity. Instead of simply using general feature engineering or a single rule for judgment, it establishes a dedicated feature pool around the real problem-solving process of CTF competitions, associating information such as account, IP, device fingerprint, problem access, attachment download, target machine access, page dwell time, operation trajectory, flag submission, and error patterns. At the same time, it constructs a temporal relationship graph between account, device, problem, flag, and submission record to identify flag propagation, collaborative submission, proxy submission, and scripted behavior.
[0046] The cheating detection capability can automatically scale with the number of participants and the system's concurrency. The specific process is as follows: the system first obtains the current competition scale parameters in real time through the monitoring module, including the number of online participants, request concurrency, submission frequency, and system resource usage; then, according to preset strategies or thresholds, the competition status is divided into low load, medium load, and high load levels.
[0047] A dynamically expandable cheating feature library is used to uniformly manage various known and newly discovered cheating features. The specific process is as follows: During operation, the system continuously collects player behavior data and anomaly detection results. Suspicious behavior samples (such as abnormal submission patterns, synchronous operation features, environment switching features, etc.) undergo structured extraction (structured extraction refers to converting raw logs into reusable cheating feature entries. For example, the raw log might only record "Account A submitted a Flag at 10:01," but the system will further extract structured fields such as "submission interval 8 seconds, no access to attachments, content identical to account B's submission, 4 accounts under the same IP address," etc.), and store them in the feature library in the form of feature vectors or rule templates. Simultaneously, the feature library supports online updates and version management. When a new cheating pattern is identified, new feature entries can be generated through manual confirmation or automatic clustering analysis and sent to the detection module in real time for subsequent judgment (one is rule templates, such as "more than N accounts from the same IP submitted the same question within 5 minutes"; the other is statistical features, such as "an account's submission frequency is 3 times higher than the average of normal players"). The feature library supports version management, recording the version number, effective time, applicable competition, triggering conditions, and handling suggestions each time a new rule or model feature is added, facilitating backtracking. The feature library also includes features such as "more than twice the number of times ...
[0048] (iv) Behavioral Model and Rule Engine Module This module combines rule-based algorithms and behavioral analysis models to significantly improve the accuracy of cheat detection: The rule-based algorithms mainly include threshold rules, association rules, and time-series rules. Threshold rules are used to determine whether a behavior exceeds the normal range, such as the same account submitting a Flag more than a preset number of times within 1 minute, or multiple accounts logging in from the same IP within 5 minutes. Association rules are used to determine whether there is a shared environment or shared results between accounts, such as multiple accounts using the same device fingerprint, the same IP, the same User-Agent, or submitting the same Flag. Time-series rules are used to determine whether the order of behavior is reasonable, such as a contestant submitting the correct Flag without accessing the question, downloading the attachment, or accessing the target machine.
[0049] The behavioral analysis model mainly includes a behavioral baseline model, an anomaly detection model, and a similar behavior analysis model. The behavioral baseline model records the common problem-solving process of normal players, such as accessing the problem, reading the problem, downloading attachments, analyzing for a period of time, and attempting to submit a flag. The anomaly detection model identifies behaviors that significantly deviate from the normal process, such as extremely short page dwell time but correct submission, continuous submissions despite prolonged periods of no page interaction, and a highly consistent submission rhythm. The similar behavior analysis model compares the access paths, submission times, error flag content, and environmental characteristics of multiple accounts to determine their consistency.
[0050] 1. Explicit cheating detection based on rule engine, such as multiple accounts from the same IP address, abnormal submission frequency, etc.; 2. Statistical Model-Based Behavioral Anomaly Analysis (primarily focusing on scenarios such as the same IP address, multiple account logins, abnormally high-frequency submissions, repeated incorrect attempts within a short period, and submitting the same flag. For example, a normal contestant typically goes through the process of "accessing the problem, reading the instructions, downloading attachments or accessing the target machine, analyzing for a period of time, and attempting to submit." If an account submits the correct flag without exhibiting the above behavior, or if multiple accounts submit the same flag within a very short period, the system can determine that the behavioral chain is missing or abnormal) (primarily analyzing scenarios such as the same IP address, multiple account logins, abnormally high-frequency submissions, repeated incorrect attempts within a short period, and submitting the same flag), such as contradictions between page dwell time and submission time, and missing problem-solving behaviors. 3. Behavioral clustering, outlier detection, and similar user behavior analysis based on machine learning models (the unified feature processing itself borrows from conventional feature engineering methods in machine learning, but the improvement of this invention lies in the fact that the feature fields are specifically constructed around the CTF competition process. The system does not generalize the analysis of web page visits, but extracts fields related to the credibility of the solution, such as the number of times the question is viewed, the number of times attachments are downloaded, the number of times the target machine is accessed, the submission interval, the accuracy rate, the repetition rate of error flags, the number of times the device is switched, the number of times the IP is switched, and the number of accounts that submit the same question at the same time, etc.).
[0051] First, in the behavioral data preparation phase, the system performs unified feature processing on multi-dimensional data such as contestants' operational behaviors, access paths, and submission records to construct behavioral feature vectors for each user. These vectors comprehensively reflect contestants' problem-solving habits, operational rhythm, and access patterns, providing foundational data for subsequent model analysis.
[0052] While unified feature processing is a standard technique in data analysis and machine learning, this invention does not simply employ general feature engineering. Instead, it applies and improves this method to the anti-cheating scenario of CTF competitions. The improvement lies in the fact that the feature fields are not ordinary webpage access metrics, but are designed around "whether the contestant has a genuine and reasonable problem-solving process." Operational behavior, access paths, flag submissions, device environment, and account association information are uniformly converted into comparable and analyzable competition behavior features.
[0053] Specific technical means include: First, the system uniformly identifies and binds data from different sources. Mouse and keyboard events, page access records, problem access order, attachment download records, target machine access records, flag submission records, IP addresses, browser fingerprints, and User-Agent information are uniformly bound to account ID, session ID, competition ID, problem ID, and timestamp to avoid discrepancies between different log sources.
[0054] Second, the original fields are formatted and normalized. For example, the User-Agent is resolved into browser type, browser version, operating system, and device type; the IP address is resolved into region, carrier ASN, and proxy / VPN tag; the Flag submission content is standardized in terms of capitalization, encoding, and spaces; and the timestamps are standardized to the same time zone and precision.
[0055] Third, convert raw behaviors into statistical metrics. For example, convert page access logs into "number of times the question was accessed, access order, and page dwell time"; convert submission records into "number of submissions, accuracy rate, number of errors, and interval between two submissions"; convert device environment into "number of times device fingerprints changed and number of accounts associated with the same device"; and convert network environment into "number of times IP addresses were switched and number of accounts with the same IP address".
[0056] Fourth, the behavioral chain is converted into pattern tags. For example, the system determines whether a contestant has "submitted without accessing the question", "submitted without downloading the attachment", "submitted continuously in a short period of time", "submitted the same flag with multiple accounts", or "had a highly consistent access path", and marks them with tags such as missing solution chain, abnormally high frequency of submission, suspected shared flag, and suspected script behavior.
[0057] Fifth, generate unified feature results for each user. Each account ultimately forms a set of standardized behavioral features, including device environment features, network environment features, access path features, submission behavior features, and account association features. Subsequent rule engines, clustering models, outlier detection models, and similar user analysis models are all based on these unified feature results.
[0058] Therefore, the basic idea of unified feature processing can refer to existing technologies, but the technical contribution of this invention is: it designs dedicated feature fields and association methods for the business process of CTF competitions, so that the originally scattered logs, browser fingerprints, IP information and Flag submission records can be analyzed in a unified manner, thereby identifying cheating behaviors such as shared Flags, proxy playing, multi-account collaboration and automated submission.
[0059] During the behavior clustering process, the system employs unsupervised learning methods (such as distance-based clustering or density-based clustering) to divide participants with similar behavioral patterns into several groups (clustering can use unsupervised methods such as DBSCAN and K-Means. Normal participants will form several groups based on their different problem-solving habits, such as "slow and stable," "high-level and fast," and "multiple-attempts." If certain accounts exhibit highly consistent submission paths, identical error flags, or similar submission times, they may form anomalous small clusters; if an account is far from all normal groups, it is marked as an outlier). Normal participants typically form multiple stable behavioral groups, while accounts using the same cheating methods (such as batch script submissions or shared problem-solving paths) tend to cluster in the same cluster, exhibiting highly consistent behavioral characteristics. The system identifies anomalous clustering phenomena by analyzing the size, density, and internal similarity of each cluster.
[0060] During outlier detection, the system evaluates each participant's position within their group. A participant is identified as an outlier when their behavior significantly deviates from their group (e.g., submission frequency, device switching frequency, number of accounts associated with the same flag, time spent on problems, etc., exceed the 95th percentile or fall below the 5th percentile of the normal group), or when they cannot be categorized into any stable group. This type of behavior typically manifests as abnormal problem-solving speed, highly illogical operation paths, or abrupt behavioral patterns, and can be used to identify instances of using automated tools or temporarily switching cheating strategies.
[0061] The system evaluates each contestant's position within their group, primarily through techniques such as group center distance, neighborhood density, quantile threshold, and behavioral label consistency.
[0062] Specifically, the system first categorizes participants with similar problem-solving habits and access patterns into several groups based on their shared characteristics. For example, there are groups focused on normal, slow problem-solving, high-frequency trial-and-error, and high-level, fast problem-solving. Each group then defines a corresponding range of normal behavior, including average submission frequency, average page dwell time, common access paths, range of device switching frequency, and range of incorrect submissions.
[0063] The system then compares the candidate to be evaluated with their respective group: First, compare the contestant's distance from the group center. If the contestant's submission frequency, time spent on problems, number of errors, number of IP changes, and number of device fingerprint changes differ significantly from the group average, the risk of them leaving the group increases.
[0064] Second, compare the number of neighboring samples of the contestant in the group. If there are few other normal contestants with similar behavior around the contestant, it indicates that their behavior pattern is relatively isolated and they may not be able to be classified into a stable group.
[0065] Third, compare whether the contestant exceeds the normal range of the group. For example, a submission frequency higher than the 95th percentile of the group, a time spent on a problem lower than the 5th percentile of the group, or a number of device switches higher than the normal upper limit of the group can all be considered deviations.
[0066] Fourth, compare whether the behavioral tags are abnormal. For example, if most contestants in the group follow a complete chain of "accessing the question, downloading the attachment, analyzing, and submitting," while this contestant exhibits behaviors such as "submitting directly without accessing the question," "submitting correctly without downloading the attachment," and "submitting multiple correct flags in a short period of time," then their behavioral position in the group is determined to be abnormal.
[0067] Through the above methods, the system not only determines whether a single indicator is abnormal, but also whether the contestant's overall behavior deviates from the normal group of contestants. This technology can be implemented by combining existing clustering or outlier detection methods such as DBSCAN, K-Means, and Isolation Forest, but the improvement of this invention lies in limiting the judgment indicators to the problem-solving process, flag submission, device environment, and account association characteristics in CTF competitions.
[0068] In the analysis of similar user behavior, the system further performs correlation analysis on highly similar accounts. By calculating the behavioral similarity between different accounts (such as consistency of operation sequence, consistency of submission rhythm, etc.), it identifies a set of accounts with highly consistent behavior. When multiple accounts exhibit continuous consistency across multiple dimensions, it can be determined that they may be collaborating or sharing resources.
[0069] Based on the above analysis, the system integrates clustering results, outlier markers, and similarity analysis results to generate behavioral risk labels for each account and transmits the relevant results to the risk assessment module. Using this method, the present invention can effectively identify covert cheating behaviors that are difficult to cover with traditional rules, such as automated script operations, team collaborative submissions, and cross-account behavior replication, thereby significantly improving the overall detection capability.
[0070] This module integrates static rules and dynamic behavior modeling (the rule layer mainly consists of a rule engine, which incorporates multiple types of static rules and dynamic threshold rules, including environment rules (such as IP address and multi-device switching), behavior rules (such as abnormal submission frequency and extremely short solution time), and correlation rules (such as multi-account synchronous operation). This layer performs rapid matching and preliminary screening of input data and outputs rule hit results and corresponding risk tags), effectively identifying covert and complex cheating patterns.
[0071] Furthermore, in this invention, the behavior model and the rule engine do not operate independently, but rather participate in the cheating detection process through a collaborative mechanism. The rule engine is mainly used to handle explicit cheating behaviors that can be clearly described, such as multiple account logins under the same IP, abnormally high frequency submissions, and repeated erroneous attempts within a short period of time. These types of rules can be quickly determined through preset thresholds or logical conditions, and have the characteristics of fast response speed and strong interpretability.
[0072] The behavior model and rule engine do not run independently, but rather participate in the cheating detection process through a collaborative mechanism as follows: The system first establishes a unified feature pool. The data acquisition layer and feature processing layer process data such as browser fingerprints, IP addresses, User-Agents, page access paths, question dwell time, Flag submission records, window switching behavior, and number of erroneous submissions into a unified format. Both the rule engine and the behavior model read data from the same feature pool to avoid inconsistencies in judgments due to different data sources.
[0073] Secondly, the rules engine performs a quick match. The system determines whether there are multiple accounts on the same IP address, multiple accounts on the same device, abnormally high frequency of submissions, repeated erroneous attempts in a short period of time, submissions without accessing the question, or submissions with the same flag, based on preset rules. Each rule match generates a corresponding risk label, such as "related to the same IP address," "high frequency of submissions," "missing solution path," or "suspected shared flag."
[0074] Then, the behavioral model uses the rule matching results as one of its inputs for further analysis. In other words, rule tags are not only used for direct alerts but also enter the behavioral model, participating in anomaly detection along with features such as page dwell time, access path, submission frequency, and device switching frequency. For example, if an account matches the "high-frequency submission" rule, the behavioral model will continue to analyze whether it also exhibits issues such as excessively short page dwell times, repeated error flag patterns, or missing access paths.
[0075] Finally, the comprehensive judgment module integrates the rule results and model results. If only a single low-risk rule is hit, the system may only log the results; if multiple rules are hit simultaneously, or if the rule results corroborate the abnormal results of the behavior model, the risk level is increased and submission restrictions, secondary verification, alarms, or manual review are triggered.
[0076] (v) Disposal and Audit Module This module is responsible for automatically or semi-automatically handling high-risk behaviors, including 1. Real-time alarm notification 2. Limit the number of Flag submissions 3. Temporarily freeze or ban accounts 4. Submit the abnormal behavior to the referee for manual review. 5. Record all detection and judgment information to form a traceable audit chain.
[0077] This module ensures that the platform can immediately block obvious cheating and provides complete evidence for human review.
[0078] Example 2
[0079] During a CTF competition, the system detected that account A successfully submitted the correct flag for a highly difficult challenge for the first time. Subsequently, within a short period of time, accounts B, C, and D successively submitted the same or highly similar flags.
[0080] During the detection process, the rule engine first triggers the "multiple accounts submitting the same content within a short period" rule, marking accounts B, C, and D as initial risk targets. Simultaneously, the behavior modeling layer analyzes the problem-solving process of these accounts, discovering that account A had a complete access path and operational behavior before submission, while accounts B, C, and D had almost no access records to related questions before submission, or only a very short period of time spent on them; their behavioral paths clearly do not conform to normal problem-solving logic. This allows the backend to see relevant alerts, enabling administrators to take appropriate action against these accounts.
Claims
1. An anti-cheating system for CTF competitions, characterized in that, It includes a data acquisition layer, a behavior analysis layer, a risk assessment layer, and a handling and auditing layer. Each layer collaborates in a modular fashion to achieve real-time identification, risk assessment, and handling of cheating behavior in CTF competitions. The data acquisition layer is used to collect contestants' device environment data, network characteristic data, competition behavior data, and Flag submission data in real time. The behavior analysis layer connects to the data acquisition layer to complete data preprocessing and feature extraction, and combines the rule engine and behavior model to carry out multi-dimensional abnormal behavior analysis. The risk assessment layer integrates the output of the behavior analysis layer to classify the risk of participating accounts and generate risk tags. The handling audit layer executes corresponding handling operations according to the risk level and completes the audit and retention of all process behavior data and judgment records.
2. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The data acquisition layer includes a user identity and environment acquisition module, a behavior data acquisition module, and a flag feature analysis module; The user identity and environment collection module is used to collect three types of data: device fingerprint, network characteristics, and login environment. Device fingerprint includes browser fingerprint, hardware digest, screen resolution, font set, and WebGL characteristics. Network characteristics include IP address, carrier ASN, network latency, and proxy and VPN identification characteristics. Login environment includes operating system, browser version, time zone, and language settings. The behavioral data acquisition module is used to collect the access path and order of questions, page dwell time and jump behavior, key operation trajectory of solving questions, submission time of Flag, submission result and error Flag pattern characteristics; The Flag feature analysis module is used to standardize the submitted Flag content, perform Flag similarity detection, submission time series analysis, Flag propagation chain analysis, and construct a directed time graph with account, IP, device fingerprint, question, Flag, and submission record as nodes to reconstruct the Flag propagation path.
3. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The behavior analysis layer is divided into a feature processing layer, a behavior modeling layer, and a decision output layer in sequence. The feature processing layer cleans, deduplicates, completes, normalizes, and filters outliers from the original collected data, unifies the timestamp accuracy and data format, and summarizes and generates behavioral indicators according to account, question, and time window dimensions. The behavior modeling layer has a built-in rule engine, statistical analysis module, and machine learning analysis module. The rule engine uses threshold rules, association rules, and time-series rules to screen for explicit cheating behavior. The statistical analysis module calculates indicators such as submission frequency, page dwell time, and number of erroneous submissions to judge the rationality of the behavior. The machine learning analysis module uses clustering algorithms, outlier detection algorithms, and similar behavior analysis algorithms to identify hidden cheating behavior. The judgment output layer integrates the analysis results of each module and outputs preliminary abnormal markers and behavioral characteristic data for the account.
4. The anti-cheating system for CTF competitions according to claim 3, characterized in that, The rule engine, statistical analysis module, and machine learning analysis module share the same unified feature pool. The rule engine first completes rapid screening and generates risk labels. The risk labels are synchronously input into the machine learning analysis module to participate in in-depth analysis. Finally, the judgment output layer integrates the rule judgment results and the model analysis results.
5. The anti-cheating system for CTF competitions according to claim 3, characterized in that, The machine learning analysis module uses K-Means and DBSCAN clustering algorithms to divide player behavior groups, uses the isolated forest algorithm to detect outliers, and identifies collaborative cheating accounts by calculating the similarity of operation sequences and submission rhythms between accounts. When an account's submission frequency, time spent on questions, number of device switches, or other metrics exceed the normal percentile of its behavioral group, or when its behavioral chain is missing and it cannot be classified into a normal behavioral group, it is determined to be an abnormal out-of-group account.
6. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The system is also configured with a dynamically expandable cheating feature library, an incremental model training system, and a rule plugin framework. The cheating feature library is used to store known cheating features, rule templates, statistical features and related features. It supports online updates, version management and the input of new cheating mode features. New cheating features that are manually confirmed or automatically clustered can be sent to the behavior analysis layer in real time. The incremental training system for the model is based on the behavioral data and anomaly detection results continuously collected during the competition to complete the iterative optimization of the model.
7. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The risk assessment layer combines multiple indicators, including the integrity of the behavior chain, the consistency of the device environment, the relevance of Flag submission, and the similarity of behavior across multiple accounts, to classify account risks into three levels: low risk, medium risk, and high risk, and generates corresponding risk tags.
8. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The aforementioned handling audit layer has functions such as real-time alarms, submission limit, temporary account freezing / banning, and push notifications for manual review of abnormal behavior; at the same time, it stores the original data, feature data, analysis logs, risk assessment results, and handling records of the entire process in a structured manner to form a traceable audit chain.
9. The anti-cheating system for CTF competitions according to claim 2, characterized in that, The Flag feature analysis module performs standardization processing on Flags, including removing spaces, unifying capitalization, unifying encoding format, and eliminating irrelevant separators; it identifies completely identical or highly similar Flag content through edit distance, common prefix and suffix comparison, and error pattern consistency comparison; and it uses a sliding time window to detect the behavior of multiple accounts simultaneously submitting the same Flag within a specified time range.
10. The anti-cheating system for CTF competitions according to claim 1, characterized in that, The system is based on an event bus and middleware to realize multi-module data flow. It can divide the load level according to the number of online contestants, the number of concurrent requests, and the system resource usage, and automatically adapt to the scale of competition concurrency to ensure the stability and timeliness of the detection link in high-concurrency scenarios.