Method, apparatus and device for processing service traffic
By using client-server collaboration to filter and forward risky traffic using a set of units generated by multiple hash functions, the security and efficiency issues in business traffic forwarding are resolved. This achieves accurate filtering and forwarding, reduces the burden on both parties, and enhances privacy protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-02
- Publication Date
- 2026-03-24
AI Technical Summary
In business traffic forwarding scenarios, how to balance business security and efficiency, especially how to efficiently filter and forward risky traffic that only requires further security verification between the client and the server, while protecting server privacy and reducing the burden on both parties.
The client and server work together to process business traffic. The client uses a set of units generated by multiple hash functions to filter and forward potentially risky traffic to the server for processing, avoiding direct exposure of server risk characteristics. The mapping relationship of multiple hash functions is used to improve the efficiency and accuracy of analysis.
It enables precise filtering and forwarding of business traffic, reduces the burden on the server and the forwarding of irrelevant traffic from the client, improves overall efficiency, and enhances server-side privacy protection, achieving a triple benefit.
Smart Images

Figure CN115034595B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present specification relates to the technical field of Internet security, and in particular, to a business traffic processing method, device and equipment. BACKGROUND
[0002] With the rapid popularization of the Internet and mobile terminals, a large number of applications have emerged, and users can conveniently install various application clients on mobile terminals. The corresponding server provides online services for the client, and the user thus obtains the corresponding service.
[0003] Convenience also faces more risks. In order to better control risks, security verification needs to be performed on business traffic. In actual applications, some security verifications are relatively complex and may need the support of server data. Moreover, the client, as the main entrance of the current business, is weak in computing power, capacity and security, etc., which also makes many security verifications unable to be performed on the client. Therefore, the business traffic of the client is often forwarded to the server for verification.
[0004] Based on this, in the above traffic forwarding scenario, how to balance the security and efficiency of the business becomes a problem to be solved. SUMMARY
[0005] One or more embodiments of the present specification provide a business traffic processing method, device, equipment and storage medium to solve the technical problem of how to balance the security and efficiency of the business in the above traffic forwarding scenario.
[0006] To solve the above technical problem, one or more embodiments of the present specification are implemented as follows:
[0007] One of the embodiments of the present specification provides a business traffic processing method applied to a client, and the method comprises:
[0008] Obtaining a unit set containing multiple units issued by a server, wherein the unit set is mapped by the server according to multiple hash functions, and each risk feature is respectively mapped into a corresponding part of the unit set.
[0009] Extracting a target feature from the current business traffic.
[0010] According to the multiple hash functions, determining all units in the unit set to which the target feature can be mapped.
[0011] Judging whether the risk features have been mapped in all the units.
[0012] If yes, forwarding the business traffic to the server for processing.
[0013] The one or more embodiments of the specification provide a service traffic processing method, applied to a server, and the method comprises:
[0014] initializing a unit set comprising a plurality of units;
[0015] mapping each of specified risk features into a corresponding part of units in the unit set according to a plurality of hash functions;
[0016] downloading the mapped unit set to a client, so that the client determines whether to forward current service traffic of the client to the server according to the plurality of hash functions and the unit set;
[0017] if the service traffic forwarded by the client is received, processing the service traffic.
[0018] The one or more embodiments of the specification provide a service traffic processing device, applied to a client, and the device comprises:
[0019] a unit set obtaining module, obtaining a unit set comprising a plurality of units, which is downloaded by a server, and the unit set is mapped by the server according to a plurality of hash functions, each of specified risk features being mapped into a corresponding part of units in the unit set;
[0020] a target feature extracting module, extracting a target feature from current service traffic;
[0021] a multi-hash mapping module, determining all units in the unit set to which the target feature can be mapped according to the plurality of hash functions;
[0022] a risk hit determining module, determining whether all the risk features have been mapped in the all units;
[0023] a service traffic forwarding module, if yes, forwarding the service traffic to the server for processing.
[0024] The one or more embodiments of the specification provide a service traffic processing device, applied to a server, and the device comprises:
[0025] a unit set initializing module, initializing a unit set comprising a plurality of units;
[0026] a multi-hash mapping module, mapping each of specified risk features into a corresponding part of units in the unit set according to a plurality of hash functions;
[0027] The unit set issuing module issues the mapped unit set to the client, so that the client determines whether to forward the current service flow of the client to the server according to the plurality of hash functions and the unit set.
[0028] The flow forwarding processing module processes the service flow if the service flow forwarded by the client is received.
[0029] The one or more embodiments of the present specification provide a service flow processing device applied to a client, the device comprising:
[0030] at least one processor; and
[0031] a memory in communication connection with the at least one processor; wherein
[0032] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:
[0033] obtain a unit set containing a plurality of units issued by a server, wherein the unit set is mapped by the server according to a plurality of hash functions, and each risk feature is respectively mapped into a corresponding part of the unit set.
[0034] extract a target feature from the current service flow;
[0035] determine all units in the unit set to which the target feature can be mapped according to the plurality of hash functions;
[0036] determine whether the risk feature has been mapped in all the units;
[0037] If yes, the service flow is forwarded to the server for processing.
[0038] The one or more embodiments of the present specification provide a service flow processing device applied to a server, the device comprising:
[0039] at least one processor; and
[0040] a memory in communication connection with the at least one processor; wherein
[0041] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:
[0042] initialize a unit set containing a plurality of units;
[0043] According to a plurality of hash functions, each of the specified risk features is respectively mapped into a corresponding part of units in the unit set;
[0044] The mapped unit set is sent to the client, so that the client determines whether to forward the current service flow of the client to the server according to the plurality of hash functions and the unit set;
[0045] If the service flow forwarded by the client is received, the service flow is processed.
[0046] One or more embodiments of the present specification provide a non-volatile computer storage medium applied to a client, the medium stores computer executable instructions, the computer executable instructions are configured to:
[0047] Obtain a unit set containing a plurality of units sent by a server, the unit set is mapped by the server according to a plurality of hash functions, each of the specified risk features is respectively mapped into a corresponding part of units in the unit set;
[0048] Extract target features from the current service flow;
[0049] According to the plurality of hash functions, determine all units in the unit set that the target features can be mapped to;
[0050] Determine whether the risk features have been mapped in all the units;
[0051] If yes, the service flow is forwarded to the server for processing.
[0052] One or more embodiments of the present specification provide a non-volatile computer storage medium applied to a server, the medium stores computer executable instructions, the computer executable instructions are configured to:
[0053] Initialize a unit set containing a plurality of units;
[0054] According to a plurality of hash functions, each of the specified risk features is respectively mapped into a corresponding part of units in the unit set;
[0055] The mapped unit set is sent to the client, so that the client determines whether to forward the current service flow of the client to the server according to the plurality of hash functions and the unit set;
[0056] If the service flow forwarded by the client is received, the service flow is processed.
[0057] The at least one technical scheme adopted by one or more embodiments of the present specification can achieve the following beneficial effects: the server is responsible for calculation and issues a unit set based on multiple hash functions to the client, avoiding direct exposure of the risk features concerned by the server, and the client can efficiently filter risk traffic that the server really expects to focus on and further security check from local business traffic based on the multiple hash functions and the unit set, and then accurately forward the risk traffic that only accounts for a small part of the total traffic to the server for processing. Through this way of cooperative processing of the client and the server and intelligent scheduling of business traffic, the safety of business traffic and the privacy of the server is ensured, and the client avoids forwarding a large amount of irrelevant traffic to the server, thereby reducing the burden of both parties and improving the overall efficiency. Furthermore, the way that the client analyzes local business traffic based on the unit set based on multiple hash functions helps to reduce the amount of data issued by the server to the client, has a small storage cost, can more accurately analyze business traffic based on as little issued data as possible, and the relationship between the forwarded traffic and the risk features is a fuzzy correspondence, thereby strengthening the protection of the privacy of the server, achieving a stone that can kill three birds. BRIEF DESCRIPTION OF DRAWINGS
[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present specification, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0059] Figure 1 A flowchart of a business traffic processing method of a client provided by one or more embodiments of the present specification;
[0060] Figure 2 A flowchart of a business traffic processing method of a server provided by one or more embodiments of the present specification;
[0061] Figure 3 An architecture diagram of a specific implementation scheme of a client and a server in an application scenario provided by one or more embodiments of the present specification;
[0062] Figure 4 A structural diagram of a business traffic processing device of a client provided by one or more embodiments of the present specification;
[0063] Figure 5 A structural diagram of a business traffic processing device of a server provided by one or more embodiments of the present specification;
[0064] Figure 6 A structural schematic diagram of a service flow processing device of a client is provided for one or more embodiments of the present specification.
[0065] Figure 7 A structural schematic diagram of a service flow processing device of a server is provided for one or more embodiments of the present specification. DETAILED DESCRIPTION
[0066] The embodiments of the present specification provide a service flow processing method, device, equipment and storage medium.
[0067] In order for those skilled in the art to better understand the technical solutions in the present specification, the technical solutions in the embodiments of the present specification will be described clearly and completely in conjunction with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments of the present specification, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0068] Due to the weaknesses of the client itself mentioned in the background art, it is necessary to forward the client traffic to the server for some relatively complex verification. During the traffic forwarding process, since the client cannot perceive the required traffic in advance, in order to avoid missing risks, only full-traffic forwarding can be performed. This way will cause a large amount of irrelevant traffic to be forwarded, which not only causes a huge pressure on the server, but also drags the business performance on the client, and more likely causes unnecessary stability risks. In actual application, it is also considered to subdivide the traffic in the business dimension based on the business identifier in the business traffic, and the client only forwards the traffic of a specific business dimension, and the server only receives these specific traffic for verification. Although this scheme helps to reduce irrelevant traffic forwarding, the precision is still relatively rough, and there is still a large amount of irrelevant traffic forwarding problem.
[0069] In view of such a situation, a client and server based on multiple hash functions are proposed to analyze and filter the business traffic on the client to guide traffic forwarding, which can balance the security and efficiency of the client traffic forwarding scheme, realize the accurate delineation of traffic, avoid most (up to 90%) irrelevant traffic forwarding, maximize the performance pressure of the server, and avoid unnecessary stability risks.
[0070] The scheme involves both the client and the server. In some embodiments below, the process of one end will be described from the perspective of the other end. In order to facilitate the understanding of the cooperation of the two ends, the actions of the two ends will be further described.
[0071] Figure 1A flowchart of a method for processing business traffic of a client is provided for one or more embodiments of the present specification. The method can be applied in different business fields, such as electronic payment business field, e-commerce business field, instant messaging business field, game business field, public service business field, etc. The flowchart can be executed by a client device, such as a smart phone, a tablet computer, etc. Some input parameters or intermediate results in the flowchart allow manual intervention to adjust, so as to improve accuracy.
[0072] Figure 1 The flowchart in the present specification can include the following steps:
[0073] S102: Obtain a unit set containing multiple units issued by a server, wherein the unit set is mapped by the server according to multiple hash functions, and each risk feature is mapped into a corresponding part of the unit set.
[0074] In one or more embodiments of the present specification, according to the actual needs of a service provider, a plurality of risk features are pre-specified on the server. If the business traffic on the client has at least one of the risk features, the server further processes the traffic to ensure business security, such as security check, termination of the corresponding business, diversion to other servers, etc.
[0075] A single risk feature can be represented by a string (numeric string, alphabetic string, vector, etc.). For example, a certain username, a batch of usernames with common characteristics, and other business attributes or rules (such as regular expressions) can also be used as risk features. Traffic with these risk features is of interest to the server, and the client needs to forward such traffic to the server for processing.
[0076] For example, if a certain username is used as a risk feature, it means that the user corresponding to the username has certain risks, and may be an illegal user. Therefore, if the current business traffic on the client is an order placed by the user, the server needs to perform security check on the order, and therefore the client needs to forward the order to the server.
[0077] In one or more embodiments of the present specification, the server does not directly issue each risk feature to the client, which may expose the server's privacy and be easily avoided by attackers. In addition to this disadvantage, if the risk features are directly issued, the client needs to try to match the business traffic with the risk features one by one, which is too low in efficiency.
[0078] Based on this, the server uses a unit set that maps risk features in one direction to protect risk features from being exposed in plaintext to the client. The specific representation of the unit set is diverse, such as being represented in the form of a bit array, referred to as a feature mapping bit array, where the bits in the feature mapping bit array correspond to units, and such as being represented in the form of a string, referred to as a feature mapping string, where the characters in the feature mapping string correspond to units. Of course, a larger granularity can also be used to represent units, such as representing the unit set in the form of a linked list, where the nodes of the linked list correspond to units, and the like. The units in the unit set are in order to facilitate subsequent more efficient matching of business traffic based on units representing risk features (i.e., units that map risk features).
[0079] In one or more embodiments of the present specification, the number of this part of units is greater than the number of the plurality of hash functions, and is less than or even much less than the number of units contained in the unit set. The greater the degree of less than, the less likely it is that different risk features are mapped to the same unit. In a typical scheme, the number of this part of units is equal to the number of the plurality of hash functions. Each hash function in the plurality of hash functions is used to map the same risk feature into one unit (or multiple units) in its corresponding part of units. The server performs such mapping operations for each risk feature, and each risk feature is mapped to multiple units in the unit set. The units mapped by different risk features may partially overlap.
[0080] S104: Extract the target feature from the current business traffic.
[0081] In one or more embodiments of the present specification, the client does not know the specific risk features of the server, but it can determine in advance which features are likely to be risk features, and extract such features as target features. One or more different target features may be extracted from the same business traffic, and the subsequent steps can be performed for each target feature.
[0082] Still taking a certain type of common username (referred to as: risk user set) as one or more risk features as an example, in this case, the client determines in advance that the username contained in the business traffic should be extracted as the target feature, but the client does not know the specific risk user set, nor does it know the specific commonality. These are the privacy of the server that does not want to be exposed to the client. By matching the target feature (representing the corresponding traffic for matching) in the unit set, it can be determined whether the target feature belongs to the risk user set without exposing the privacy.
[0083] In one or more embodiments of the present specification, how the service traffic is specifically divided can be predefined, such as by order, by query request, by user, etc. Taking division by order as an example, the current service traffic is, for example, a current order, and the target feature is, for example, a username or other business attributes that can be at risk extracted from the order, and the client will perform S104-S110 on each order in turn, respectively.
[0084] S106: According to the plurality of hash functions, determine all units in the unit set to which the target feature can be mapped.
[0085] After determining the target feature, the target feature can be mapped to the unit set by trying to map the target feature to the unit set in a consistent manner of the server. It should be noted that the actual mapping result of the target feature does not need to be landed (such as corresponding filling in the feature mapping bit array) in the unit set, but only needs to determine which units the target feature will be mapped to if the target feature is mapped in the unit set. Otherwise, it can affect the reliability of the unit set, because the target feature is not necessarily a risk feature.
[0086] In one or more embodiments of the present specification, specifically, for each hash function, the target feature is converted into a fixed-length digest using the hash function, and the corresponding unit of the digest in the unit set is determined (for example, by taking modulo calculation on the digest, if the modulo result matches one of the units, then the unit is the corresponding unit), as a unit in all units in the unit set to which the target feature can be mapped.
[0087] S108: Determine whether the risk feature has been mapped in all the units.
[0088] In one or more embodiments of the present specification, if the risk feature has been mapped in all the units (not necessarily the same risk feature), it means that the target feature is very likely to match one or more risk features, and the corresponding traffic is very likely to be risk traffic, which can be considered to be forwarded to the server. If at least one unit in the all units has not mapped the risk feature, it means that the target feature is not the risk feature represented by the unit set, which can be considered to be released and not forwarded to the server.
[0089] This way of analyzing the risk of traffic based on multi-hash function mapping is efficient, has low time complexity, and can better cope with continuous traffic on the client.
[0090] In one or more embodiments of the present specification, S106 and S108 can be alternately partially executed, for example, after determining that the target feature can be mapped to a cell in the cell set, it is determined whether the risk features have been mapped in the cell, and if so, the next cell is determined.
[0091] S110: If yes, the service traffic is forwarded to the server for processing.
[0092] In one or more embodiments of the present specification, even if the result of S108 is yes, the target feature is not necessarily a risk feature, but there is a greater chance that it is a risk feature, so a proper tolerance can be given here, considering that the target feature in this case is a risk feature, and the additional burden actually brought will not be too large, thereby, it may cause a small amount of actual traffic without risk features to be forwarded to the server. Such a situation is called an acceptable false negative.
[0093] It should be noted that it is also possible to use only one hash function to map each designated risk feature into a corresponding cell in the cell set for the above analysis. However, this approach has significant drawbacks in terms of storage space utilization, reliability, and privacy protection, as analyzed below:
[0094] In the scenario of the present application, there are often many risk features, so when mapping, different risk features may be mapped into the same cell, which has low reliability. In order to consider the reliability, the cell set can be set to be very large, but if the cell set is set to be large, most of the cells will not be mapped, and the mapping data will be very sparse in the cell set, so the storage space utilization is very low. Moreover, since a single risk feature is only mapped in a single cell, although the risk feature is not directly exposed, it is easy to use some traffic to infer the exact mapping relationship between the risk feature and the cell, thereby indirectly exposing the privacy of the server to some extent, and then the evildoer may use this point to evade risk control.
[0095] Based on this, the present application adopts a scheme of using multiple hash functions to map the same risk feature in multiple cells, which can effectively solve the problem in the previous paragraph.
[0096] The principle mainly lies in: subsequent multi-unit matching for service traffic has higher fault tolerance and reliability than single-unit matching (the probability of complete coincidence of different risk features in multiple units is too small, effectively reducing conflicts), and because of this, the unit set can be set not too large, which can more effectively save and utilize storage space, and the sparsity of mapping data in the unit set will also be effectively improved; Furthermore, this approach deliberately creates an acceptable false positive (if all the above units have not mapped the risk feature, the target feature is considered a risk feature, and then the corresponding traffic is forwarded to the server) possibility. This false positive has a positive effect, which is used to strengthen the protection of the server's privacy. For matched traffic, multiple units it may map all map risk features, but not necessarily the same risk feature. In this case, the correspondence between the traffic and the risk feature is relatively ambiguous, and it cannot be determined which risk feature it corresponds to. The traffic may not even correspond to any risk feature. In this way, it is conducive to hindering the malicious reasoning of the evildoer.
[0097] In one or more embodiments of the present specification, if the result of S108 is no, it is considered that the current service traffic is temporarily not risky, and the traffic can be processed normally on the client according to the predetermined subsequent business logic without forwarding to the server for processing.
[0098] For the traffic forwarded by the client to the server, the server can perform relatively more complex security checks on the traffic to further analyze the more detailed risk situation of the traffic.
[0099] In one or more embodiments of the present specification, in actual application, all the above units do not necessarily need to be determined to decide whether to forward the service traffic. As long as the target feature has not been mapped to a risk feature in a certain unit that can be mapped in the unit set, it can be directly decided not to forward the service traffic to the server for processing.
[0100] Specifically, for example, before determining all the units that the target feature can be mapped to in the unit set according to multiple hash functions, if according to one of the hash functions, it is determined that the target feature has not been mapped to a risk feature in any one of the units that can be mapped in the unit set (as long as one), the service traffic will be processed normally on the client according to the predetermined subsequent business logic, without forwarding the traffic to the server.
[0101] By Figure 1The method involves the server calculating and sending a set of units based on multiple hash functions to the client, avoiding direct exposure of risk characteristics that the server is concerned about. Based on these hash functions and unit sets, the client can efficiently filter out the risky traffic that the server truly wants to focus on and further verify from its local business traffic. This allows for the precise forwarding of this risky traffic, which often only accounts for a small portion of the total traffic, to the server for processing. This collaborative processing between the client and server, along with intelligent scheduling of business traffic, ensures the security of both business traffic and server privacy while preventing the client from forwarding large amounts of irrelevant traffic to the server, thus reducing the burden on both parties and improving overall efficiency. Furthermore, the client's analysis of local business traffic based on unit sets using multiple hash functions helps reduce the amount of data sent from the server to the client, resulting in lower storage costs. It allows for more accurate analysis of business traffic with minimal data transmission, and the fuzzy correspondence between the forwarded traffic and risk characteristics strengthens the protection of server privacy, achieving a triple benefit.
[0102] based on Figure 1 In addition to the method described herein, this specification also provides some specific implementation schemes and extension schemes of this method, which will be further explained below.
[0103] In one or more embodiments of this specification, a feature mapping bit array or a feature mapping string (the two are essentially the same, only their forms of representation) is used to represent the unit set. The feature mapping bit array is used for specific processing at both ends, and the feature mapping string is used for transmission between the two ends, thus taking into account the convenience of processing and transmission.
[0104] The server pre-initializes the feature mapping bit array, with bits in an unfilled state. Multiple hash functions are then used to map specified risk features to multiple bits within the feature mapping bit array. For example, a bit is filled with a specified value (assuming a value of 1; if not mapped, the bit can be left empty or filled with 0) to indicate that a corresponding risk feature is set within that bit. If another risk feature later needs to be mapped to that bit, and it is found that the bit is already filled with 1, the re-filling action is not performed, and it is directly assumed that the other risk feature has also been mapped. Because of this, the same bit (unit) can potentially map to multiple risk features.
[0105] In one or more embodiments of this specification, as business operations progress, the server may add new risk features. Therefore, the server can update the corresponding unit set and reissue it. Alternatively, a lightweight update scheme is provided for this situation, eliminating the need for the server to update and reissue a new unit set to the client.
[0106] Specifically, the server can use multiple hash functions to determine all units that the new risk feature can be mapped to in the previous unit set, and then record the serial numbers of these units, for example, the bit serial numbers of the feature mapping bit array. Then, the server sends the recorded bit serial numbers to the client, and the client receives the bit serial numbers and determines the bits indicated by the bit serial numbers in the local feature mapping bit array, and fills the values of the indicated bits (for example, the filled value is 1) to indicate that the indicated bits map the new risk feature. In this way, the update process minimizes the burden on both ends and has very small computational cost.
[0107] In one or more embodiments of the present specification, when matching the target feature in the unit set, it is necessary to determine the units that the target feature can be mapped to in the unit set using the above-mentioned hash functions respectively. In practical applications, this is the highest cost and time cost step in the present scheme. In order to reduce the cost here, the present scheme further explores improvement. The following analysis is made.
[0108] In the unit set, the mapping of risk features is uneven. Similarly, the units that map risk features may be biased towards a particular field as a whole on the same client, while these flows may differ among each other, and the flows on different clients may also differ significantly. Therefore, when matching the flows on each client for a long period of time, both the units themselves and the clients will have some personalized performance, for example, for a certain client, some units may be more likely to be hit by the flow during the matching process, while some units may be more difficult to be hit by the flow, and for different clients, these units may differ significantly.
[0109] For the situation in the last paragraph, consider the following idea: if a small probability event reflecting possible risks occurs, it can be approximately considered that there is indeed a risk at this time without further consideration. Although this may also lead to misjudgment, it can help reduce the cost of risk control as a whole. Based on this idea, an example is given.
[0110] The client can record all the units in the unit set to which the current service traffic can be mapped, determine the respective accumulative degree and / or frequency of each unit in the unit set according to the record of the historical traffic including the current service traffic, grade each unit according to the accumulative degree and / or frequency, and determine whether to forward the subsequent service traffic to the server for processing according to the grading result. Different clients have different traffic conditions, so the grading of the same unit can be different. The graded levels may, for example, include difficult to hit, easy to hit, etc. For example, the lower the accumulative degree and / or frequency, the more difficult to hit, and vice versa, the easier to hit. Of course, this is only an example and more detailed and comprehensive grading can also be performed. According to the grading result, it is sufficient to determine whether to forward the traffic by using only a part of the hash functions instead of using all the hash functions to process the target feature.
[0111] For example, according to the grading result, the difficult-to-hit units are determined in each unit, and whether the target feature of the subsequent service traffic (for example, the next order) can be mapped to a specified difficult-to-hit unit in the unit set according to a part of the hash functions (which can be tried in sequence) is determined. The specified difficult-to-hit unit has mapped the risk feature. If yes, it is considered that the above one reflects a small probability event of a possible risk, and the subsequent service traffic can be directly forwarded to the server for processing without the remaining hash functions.
[0112] For another example, based on similar ideas, according to the grading result, the easy-to-hit units and their corresponding hash functions are determined in each unit as low-priority functions, and the remaining other hash functions are used to process the subsequent service traffic. When the traffic is large, the processing result is considered to directly determine whether to forward the traffic, and the low-priority functions are temporarily on leave, thereby helping to improve efficiency.
[0113] Based on the same idea, one or more embodiments of the present specification also provide a flowchart of a service traffic processing method of a server, as shown in Figure 2 The flowchart is executed by a server in a corresponding business field, such as a risk control server in an electronic payment business field.
[0114] Figure 2 The flowchart in the above embodiment can include the following steps:
[0115] S202: Initialize a unit set containing a plurality of units.
[0116] Initially, no risk feature is mapped in the unit set. For example, in the feature mapping bit array, initially, no corresponding value is filled in each bit.
[0117] S204: According to the plurality of hash functions, the specified risk features are respectively mapped into the corresponding part of the unit set.
[0118] S206: The mapped unit set is sent to the client, so that the client determines whether to forward the current service flow of the client to the server according to the plurality of hash functions and the unit set.
[0119] S208: If the service flow forwarded by the client is received, the service flow is processed.
[0120] Some specific actions of the server have been described above, and will not be repeated here.
[0121] Based on the above description, the actions of both ends are more intuitively combined exemplarily to see the overall scheme. Figure 3 An architecture schematic diagram of a specific implementation scheme of the client and the server in an application scenario of one or more embodiments of the present specification.
[0122] In the application scenario of Figure 3 , the unit set is represented as a feature mapping bit array (denoted as bitSet) or a feature mapping string (denoted as BFStr), and the service flow includes a request on the client, which is referred to as an end request.
[0123] The workflow of the architecture includes the following steps, for example:
[0124] On the server:
[0125] An array, referred to as a hash array, is initialized to save the plurality of hash functions to be used, and a bitSet is initialized; a risk feature library is constructed in advance as the plurality of risk features, which includes a string representing at least one of the following libraries: a user library, a device library, an address library, and other service attribute libraries, and new features can be added to the risk feature library as needed.
[0126] For each hash function in the hash array, the following is performed: each risk feature is converted into a fixed-length digest using the hash function, the corresponding bit of the digest in the bitSet is determined, and if the corresponding bit has not been filled with a value indicating that the risk feature has been mapped, the value is filled in the corresponding bit.
[0127] Serialize the filled bitSet to obtain a BFStr, and issue the BFStr to the client.
[0128] On the client side:
[0129] Initialize a hash array consistent with the server, receive the BFStr issued by the server, and restore the BFStr by deserialization to obtain a bitSet.
[0130] Extract the target feature from the current end request, convert the target feature into a fixed-length digest using each hash function in the hash array, determine the corresponding bit of the digest in the bitSet, and determine whether the risk feature hits according to the bit filling value of all such bits, that is, whether all such bits have been mapped to the risk feature, if so, forward the end request to the server for verification, if not or if the verification is passed, continue to process the end request locally according to the subsequent normal business logic.
[0131] On the server side:
[0132] If the end request forwarded by the client is received, the end request is verified according to the predetermined security verification strategy, and the client is responded with the verification result.
[0133] Thus, in this application scenario, the client traffic intelligent forwarding scheme is realized, which constructs the client traffic accurate forwarding capability with very small storage cost (less than 1KB), and high reliability and privacy security, solves the performance problem caused by the massive traffic forwarding of the client. By continuously adding the risk features to be concerned, a new BFStr can be generated based on the original BFStr, and the calculation cost required when adding the risk features is also very small.
[0134] Based on the same idea, one or more embodiments of the present specification also provide an apparatus and a device corresponding to the above method, as shown in Figures 4-7 The dashed box represents an optional module.
[0135] Figure 4 A structural schematic diagram of a business traffic processing apparatus of a client provided by one or more embodiments of the present specification, the apparatus comprising:
[0136] A unit set acquisition module 402 acquires a unit set containing multiple units issued by a server, wherein the unit set is mapped by the server according to multiple hash functions, and each risk feature is mapped into a corresponding part of the unit set.
[0137] A target feature extraction module 404 extracts a target feature from the current business traffic.
[0138] The multi-hash mapping module 406 determines, according to the plurality of hash functions, all cells in which the target feature can be mapped in the cell set;
[0139] The risk hit judgment module 408 judges whether the risk feature has been mapped in all the cells.
[0140] The business traffic forwarding module 410 forwards the business traffic to the server for processing if the risk feature has been mapped in all the cells.
[0141] Optionally, the cell set is represented as a feature mapping bit array or a feature mapping string, and the bits in the feature mapping bit array and the characters in the feature mapping string represent the cells.
[0142] The cell set acquisition module 402 receives the feature mapping string issued by the server.
[0143] The feature mapping string is deserialized to obtain the feature mapping bit array, so as to judge whether the risk feature has been mapped in all the cells according to the bit filling values corresponding to the all cells in the feature mapping bit array.
[0144] Optionally, the method further comprises:
[0145] The bit value increment filling module 412 receives the bit sequence number sent by the server after acquiring the cell set containing a plurality of cells issued by the server.
[0146] In the feature mapping bit array locally, the bit indicated by the bit sequence number is determined, and the value of the indicated bit is filled to represent that the indicated bit maps the newly added risk feature.
[0147] Optionally, the multi-hash mapping module 406 respectively executes, for each hash function: converting the target feature into a fixed-length digest by using the hash function, determining the cell corresponding to the digest in the cell set as the cell in the all cells in which the target feature can be mapped in the cell set.
[0148] Optionally, the number of the part of cells has a plurality of values, which is not greater than the number of the plurality of hash functions and much smaller than the number of cells contained in the cell set.
[0149] Each hash function in the plurality of hash functions is used to respectively map the same risk feature into one of the part of cells corresponding to the hash function.
[0150] Optionally, the method further comprises:
[0151] The mapping unit grading module 414 records all units in the unit set to which the current service flow can be mapped;
[0152] According to the record of historical flow including the current service flow, determine the respective accumulative degree and / or frequency of the record hitting each unit in the unit set;
[0153] According to the accumulative degree and / or frequency, grade the units;
[0154] The risk hit judgment module 408 judges whether to forward subsequent service flow to the server for processing according to the grading result.
[0155] Optionally, the risk hit judgment module 408 determines a difficult-to-hit unit in the units according to the grading result;
[0156] According to a part of the plurality of hash functions, determine whether the target feature of subsequent service flow can be mapped to a specified difficult-to-hit unit in the unit set, and the specified difficult-to-hit unit has mapped a risk feature;
[0157] If yes, the subsequent service flow is forwarded to the server for processing.
[0158] Optionally, further comprising: a local normal processing module 416;
[0159] The risk hit judgment module 408, before determining all units in the unit set to which the target feature can be mapped according to the plurality of hash functions, according to the hash function, if it is determined that the target feature has not been mapped in any one of the units to which the target feature can be mapped in the unit set, the local normal processing module 416 continues to normally process the service flow on the client according to the predetermined subsequent service logic, and the service flow forwarding module 410 does not forward the service flow to the server;
[0160] The local normal processing module 416, after forwarding the service flow to the server for processing, if it receives a response from the server that the service flow is safe, continues to normally process the service flow on the client according to the predetermined subsequent service logic.
[0161] Figure 5 A structural schematic diagram of a service flow processing device of a server is provided for one or more embodiments of the present specification, and the device comprises:
[0162] The unit set initialization module 502 initializes a unit set containing a plurality of units.
[0163] The multi-hash mapping module 504 maps each of the specified risk features into a corresponding part of the unit set according to a plurality of hash functions.
[0164] The unit set delivery module 506 delivers the mapped unit set to a client, so that the client determines whether to forward current service traffic of the client to the server according to the plurality of hash functions and the unit set.
[0165] The forwarded traffic processing module 508 processes the service traffic if the service traffic forwarded by the client is received.
[0166] Optionally, the initialized unit set is represented as a feature mapping bit array, and a bit in the feature mapping bit array represents the unit.
[0167] The multi-hash mapping module 504, for each hash function, performs: converting each risk feature into a fixed-length digest by using the hash function, determining a corresponding bit of the digest in the feature mapping bit array, and filling a value representing that the risk feature has been mapped into the corresponding bit if the corresponding bit has not been filled with the value.
[0168] Figure 5 The method executable by the apparatus of the above embodiment can refer to the description of the method of the above embodiment. Figure 2 For brevity, the above method is not listed in detail.
[0169] Figure 6 A structural diagram of a service traffic processing device of a client according to one or more embodiments of the present specification is provided, and the device includes:
[0170] At least one processor; and
[0171] The memory is in communication connection with the at least one processor; wherein
[0172] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:
[0173] Obtain a unit set containing a plurality of units delivered by a server, and the unit set is mapped by the server according to a plurality of hash functions, and each of the specified risk features is mapped into a corresponding part of the unit set.
[0174] Extract a target feature from current service traffic.
[0175] According to the plurality of hash functions, determine all cells in the cell set that the target feature can be mapped to;
[0176] Determine whether the risk feature has been mapped in all the cells;
[0177] If yes, forward the service flow to the server for processing.
[0178] The processor and the memory can communicate through a bus, and the device can also include an input / output interface for communicating with other devices.
[0179] Figure 7 A structural diagram of a service flow processing device of a server is provided for one or more embodiments of the present specification, and the device includes:
[0180] At least one processor; and,
[0181] A memory in communication connection with the at least one processor; wherein,
[0182] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to:
[0183] Initialize a cell set containing a plurality of cells;
[0184] According to a plurality of hash functions, map each specified risk feature into a corresponding part of cells in the cell set;
[0185] Downlink the mapped cell set to the client, so that the client determines whether to forward the current service flow of the client to the server according to the plurality of hash functions and the cell set;
[0186] If the service flow forwarded by the client is received, process the service flow.
[0187] Based on the same idea, one or more embodiments of the present specification also provide a corresponding Figure 1 A non-volatile computer storage medium stores computer executable instructions, and the computer executable instructions are set to:
[0188] Obtain a cell set containing a plurality of cells downlinked by a server, and the cell set is mapped by the server according to a plurality of hash functions, and each specified risk feature is mapped into a corresponding part of cells in the cell set;
[0189] Extract a target feature from the current service flow;
[0190] According to the plurality of hash functions, determine all units in the unit set that the target feature can be mapped to;
[0191] Determine whether the risk feature has been mapped in all the units;
[0192] If yes, forward the service traffic to the server for processing.
[0193] Based on the same idea, one or more embodiments of the present specification also provide a method corresponding to Figure 2 A non-volatile computer storage medium for storing computer executable instructions, the computer executable instructions are configured to:
[0194] Initialize a unit set containing a plurality of units;
[0195] According to a plurality of hash functions, respectively map each risk feature to a corresponding part of the unit set;
[0196] Distribute the mapped unit set to the client, so that the client determines whether to forward the current service traffic of the client to the server according to the plurality of hash functions and the unit set;
[0197] If the service traffic forwarded by the client is received, process the service traffic.
[0198] In the 1990s, it was quite obvious to distinguish whether an improvement in a technology was in hardware (e.g., improvement in circuit structures of diodes, transistors, switches, etc.) or in software (improvement in method flow). However, as technology has evolved, many improvements in method flow today can be considered as direct improvements in hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method flow into hardware circuits. Therefore, it cannot be said that an improvement in a method flow cannot be implemented by hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming it, rather than by asking a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented by "logic compiler" software, which is similar to software compilers used in program development, and the original code to be compiled is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that, as long as the method flow is logically programmed in the above-mentioned hardware description languages and programmed into an integrated circuit, a hardware circuit implementing the logical method flow can be easily obtained.
[0199] The controller can be implemented in any suitable way, e.g. the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, e.g. software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of controllers include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91 SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to being implemented in pure computer readable program code form, the controller can perfectly well be implemented by means of logic programmed into logic gates, switches, application specific integrated circuits, programmable logic controllers and embedded microcontrollers, etc. to perform the same functions. The controller can thus be considered as a hardware component, and the means comprised therein for performing various functions can be considered as structures within the hardware component. Alternatively, or even additionally, the means for performing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0200] The systems, apparatuses, modules or units illustrated by the above embodiments can be implemented by computer chips or entities, or products with certain functions. A typical implementation device is a computer. Specifically, the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0201] For the sake of description, the above apparatuses are described in various units by functions respectively. Of course, the functions of the units can be implemented in one or more software and / or hardware in implementing the present specification.
[0202] Those skilled in the art will understand that the embodiments of the present specification can be provided as a method, a system or a computer program product. Therefore, the embodiments of the present specification can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0203] The specification can be described with reference to flow diagrams and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 The flow diagram and / or block diagram in the flow diagrams and / or block diagrams can also represent code modules, segments, or the like, which can be executed by a computer, by way of illustrations. Additionally, each flow diagram and / or block diagram in the flow diagrams and / or block diagrams can represent one or more applications, programs, functions, or the like, which when executed perform tasks or implement various aspects of the specification, as desired. Figure 1 The flow diagram and / or block diagram in the flow diagrams and / or block diagrams can also represent code modules, segments, or the like, which can be executed by a computer, by way of illustrations. Additionally, each flow diagram and / or block diagram in the flow diagrams and / or block diagrams can represent one or more applications, programs, functions, or the like, which when executed perform tasks or implement various aspects of the specification, as desired.
[0204] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flow diagrams and / or block diagrams flow or flows and / or block or blocks specified in the flow diagrams and / or block diagrams. Figure 1 The flow diagram and / or block diagram in the flow diagrams and / or block diagrams can also represent code modules, segments, or the like, which can be executed by a computer, by way of illustrations. Additionally, each flow diagram and / or block diagram in the flow diagrams and / or block diagrams can represent one or more applications, programs, functions, or the like, which when executed perform tasks or implement various aspects of the specification, as desired. Figure 1 The flow diagram and / or block diagram in the flow diagrams and / or block diagrams can also represent code modules, segments, or the like, which can be executed by a computer, by way of illustrations. Additionally, each flow diagram and / or block diagram in the flow diagrams and / or block diagrams can represent one or more applications, programs, functions, or the like, which when executed perform tasks or implement various aspects of the specification, as desired.
[0205] It should also be noted that the terms "comprising," "including," or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the recited element.
[0206] The specification can be described with reference to flow diagrams and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks.
[0207] The various embodiments in this specification describe the application in progressive stages. Each stage builds upon the previous stages, and each stage can be described in terms of the differences between that stage and the previous stage. For example, the device, apparatus, and non-transitory computer storage medium embodiments are described more quickly because they are substantially similar to the method embodiments. The relevant portions of the method embodiments are referenced.
[0208] The above description describes certain embodiments of the application. Other embodiments are within the scope of the following claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve desirable results. In certain implementations, multitasking and parallel processing can be advantageous.
[0209] The above description is of one or more embodiments of the application and is not intended to limit the application. Those skilled in the art will be able to make various changes and modifications without departing from the spirit and scope of the one or more embodiments of the application. Any further modifications, equivalents and / or alternatives come within the scope of the claims of the application.
Claims
1. A business traffic processing method, applied to a client, the method comprising: Obtain a set of units containing multiple units issued by the server. The set of units is obtained by the server mapping each specified risk feature to a corresponding set of units in the set according to multiple hash functions. Extract target features from current business traffic; Based on the multiple hash functions, determine all the units that the target feature can be mapped to in the unit set; Determine whether the risk feature has been mapped in all of the units; If so, the business traffic is forwarded to the server for processing; Also includes: Record all units that the current service traffic can be mapped to in the unit set; Based on the records of historical traffic, including the current business traffic, determine the cumulative degree and / or frequency of the hits of the records on each unit in the unit set. The units are classified according to the degree of accumulation and / or frequency. Based on the classification results, a hard-to-hit unit is identified in each unit of the unit set; based on a subset of the multiple hash functions, it is determined whether the target characteristics of subsequent business traffic can be mapped to the specified hard-to-hit unit in the unit set, and whether the specified hard-to-hit unit has been mapped with risk characteristics; if so, the subsequent business traffic is forwarded to the server for processing. The lower the cumulative degree and / or frequency, the more difficult it is to hit.
2. The method as described in claim 1, wherein the set of units is represented as a feature mapping bit array or a feature mapping string, and the bits in the feature mapping bit array and the characters in the feature mapping string represent the units; The acquisition of the unit set containing multiple units issued by the server specifically includes: Receive the feature mapping string sent by the server; The feature mapping string is deserialized to obtain the feature mapping bit array, so as to determine whether the risk feature has been mapped in all units based on the bit filling values corresponding to all units in the feature mapping bit array.
3. The method as described in claim 2, after obtaining the unit set containing multiple units issued by the server, the method further includes: Receive the sequence number sent by the server; In the local feature mapping bit array, the bit indicated by the bit number is determined, and the indicated bit is filled with a value to indicate that the indicated bit maps to a new risk feature.
4. The method as described in claim 1, wherein determining, based on the plurality of hash functions, all units to which the target feature can be mapped in the unit set specifically includes: For each of the hash functions, the following steps are performed: the target feature is converted into a fixed-length digest using the hash function, and the unit corresponding to the digest in the unit set is determined as the unit among all the units to which the target feature can be mapped in the unit set.
5. The method as described in claim 1, wherein the number of the subset of units is multiple, which is no greater than the number of the multiple hash functions and much smaller than the number of units contained in the unit set; Each of the plurality of hash functions is used to map the same risk feature to one of the corresponding subsets of units.
6. The method of claim 1, wherein before determining all units in the unit set to which the target feature can be mapped based on the plurality of hash functions, the method further comprises: According to the hash function, if it is determined that the target feature has not yet been mapped to any of the units in the unit set, the business traffic will continue to be processed normally on the client according to the predetermined subsequent business logic, instead of forwarding the business traffic to the server. After forwarding the service traffic to the server for processing, the method further includes: If the server receives a response confirming that the security verification of the service traffic has passed, the service traffic will continue to be processed normally on the client according to the predetermined subsequent business logic.
7. A business traffic processing method, applied on a server side, the method comprising: Initialize a set of cells containing multiple cells; Based on multiple hash functions, each specified risk feature is mapped to a corresponding subset of units in the unit set; The mapped unit set is sent to the client so that the client can determine whether to forward the client's current business traffic to the server based on the multiple hash functions and the unit set. If the service traffic forwarded by the client is received, the service traffic is processed. The client records all units that the current service traffic can be mapped to in the unit set; based on the records of historical traffic, including the current service traffic, it determines the cumulative degree and / or frequency of the records hitting each unit in the unit set; based on the cumulative degree and / or frequency, it classifies each unit; based on the classification result, it identifies hard-to-hit units among the units in the unit set; based on a portion of the multiple hash functions, it determines whether the target characteristics of subsequent service traffic can be mapped to the specified hard-to-hit unit in the unit set, and whether the specified hard-to-hit unit has been mapped with risk characteristics; if so, the subsequent service traffic is forwarded to the server for processing. The lower the cumulative degree and / or frequency, the more difficult it is to hit.
8. The method of claim 7, wherein the initialized set of units is represented as a feature mapping bit array, and the bits in the feature mapping bit array represent the units; The step of mapping each specified risk feature to a corresponding subset of units in the unit set according to multiple hash functions specifically includes: For each of the hash functions, the following steps are performed: convert each risk feature into a fixed-length digest using the hash function, determine the corresponding bit in the feature mapping bit array, and if the corresponding bit is not yet filled, it indicates that the risk feature value has been mapped, then fill the corresponding bit with the value.
9. The method of claim 8, wherein the set of units can be represented by a feature mapping string, and the characters in the feature mapping string represent the units; Sending the mapped set of units to the client specifically includes: The mapped set of units is serialized to obtain the feature mapping string; The feature mapping string is sent to the client.
10. The method of claim 7, wherein processing the service traffic specifically includes: The service traffic is subjected to security verification according to the predetermined security verification strategy; If the security check passes, the system responds accordingly to the client, allowing the client to continue processing the business traffic locally according to the predetermined subsequent business logic.
11. The method according to any one of claims 7 to 10, wherein the risk feature includes a string for representing content in at least one of the following libraries: user library, device library, address library, and other business attribute library.
12. A service traffic processing device, applied to a client, the device comprising: The unit set acquisition module acquires a unit set containing multiple units issued by the server. The unit set is obtained by the server mapping each specified risk feature to a corresponding subset of units in the unit set according to multiple hash functions. The target feature extraction module extracts target features from the current business traffic; The multi-hash mapping module determines, based on the multiple hash functions, all units that the target feature can be mapped to in the unit set; The risk hit determination module determines whether the risk feature has been mapped in all the units. If so, the business traffic forwarding module forwards the business traffic to the server for processing. The mapping unit hierarchical module records all units that the current service traffic can be mapped to in the unit set; based on the records of historical traffic, including the current service traffic, it determines the cumulative degree and / or frequency of the records hitting each unit in the unit set. The units are classified according to the degree of accumulation and / or frequency. The risk hit determination module determines the hard-hit unit in each unit based on the result of the classification; and determines whether the target characteristics of subsequent business traffic can be mapped to the specified hard-hit unit in the unit set based on a portion of the multiple hash functions, and whether the specified hard-hit unit has been mapped with risk characteristics. If so, the subsequent business traffic will be forwarded to the server for processing; The lower the cumulative degree and / or frequency, the more difficult it is to hit.
13. The apparatus of claim 12, wherein the set of units is represented as a feature mapping bit array or a feature mapping string, wherein the bits in the feature mapping bit array and the characters in the feature mapping string represent the units; The unit set acquisition module receives the feature mapping string sent by the server; The feature mapping string is deserialized to obtain the feature mapping bit array, so as to determine whether the risk feature has been mapped in all units based on the bit filling values corresponding to all units in the feature mapping bit array.
14. The apparatus of claim 13, further comprising: The bit value increment filling module receives the bit sequence number sent by the server after obtaining the unit set containing multiple units sent by the server. In the local feature mapping bit array, the bit indicated by the bit number is determined, and the indicated bit is filled with a value to indicate that the indicated bit maps to a new risk feature.
15. The apparatus of claim 12, wherein the multi-hash mapping module performs the following for each hash function: converting the target feature into a fixed-length digest using the hash function, determining the unit corresponding to the digest in the unit set as the unit among all units to which the target feature can be mapped in the unit set.
16. The apparatus of claim 12, wherein the number of the subset of units is multiple, which is no greater than the number of the plurality of hash functions and much smaller than the number of units contained in the unit set; Each of the plurality of hash functions is used to map the same risk feature to one of the corresponding subsets of units.
17. The apparatus of claim 12, further comprising: Local normal processing module; Before the risk hit determination module determines all units in the unit set that the target feature can be mapped to according to the multiple hash functions, if it is determined according to the hash function that the risk feature has not yet been mapped in any unit in the unit set that the target feature can be mapped to, then the local normal processing module continues to process the business traffic normally on the client according to the predetermined subsequent business logic, while the business traffic forwarding module does not forward the business traffic to the server. After forwarding the service traffic to the server for processing, if the local normal processing module receives a response from the server confirming that the service traffic has passed security verification, it will continue to process the service traffic normally on the client according to the predetermined subsequent business logic.
18. A service traffic processing device, applied to a server, the device comprising: The cell set initialization module initializes a cell set containing multiple cells. The multi-hash mapping module maps each specified risk feature to a corresponding subset of units in the unit set according to multiple hash functions. The unit set distribution module distributes the mapped unit set to the client, so that the client can determine whether to forward the client's current business traffic to the server based on the multiple hash functions and the unit set. The forwarding traffic processing module processes the service traffic if it receives the service traffic forwarded by the client. The client records all units that the current service traffic can be mapped to in the unit set; based on the records of historical traffic, including the current service traffic, it determines the cumulative degree and / or frequency of the records hitting each unit in the unit set; based on the cumulative degree and / or frequency, it classifies each unit; based on the classification result, it identifies hard-to-hit units among the units in the unit set; based on a portion of the multiple hash functions, it determines whether the target characteristics of subsequent service traffic can be mapped to the specified hard-to-hit unit in the unit set, and whether the specified hard-to-hit unit has been mapped with risk characteristics; if so, the subsequent service traffic is forwarded to the server for processing. The lower the cumulative degree and / or frequency, the more difficult it is to hit.
19. The apparatus of claim 18, wherein the initialized set of units is represented as a feature mapping bit array, wherein bits in the feature mapping bit array represent the units; The multi-hash mapping module performs the following for each hash function: converting each risk feature into a fixed-length digest using the hash function, determining the corresponding bit in the feature mapping bit array, and filling the corresponding bit with the value if the corresponding bit is not yet filled, indicating that the risk feature has been mapped.
20. A service traffic processing device, applied to a client, the device comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: Obtain a set of units containing multiple units issued by the server. The set of units is obtained by the server mapping each specified risk feature to a corresponding set of units in the set according to multiple hash functions. Extract target features from current business traffic; Based on the multiple hash functions, determine all the units that the target feature can be mapped to in the unit set; Determine whether the risk feature has been mapped in all of the units; If so, the business traffic is forwarded to the server for processing; Also includes: Record all units that the current service traffic can be mapped to in the unit set; Based on the records of historical traffic, including the current business traffic, determine the cumulative degree and / or frequency of the hits of the records on each unit in the unit set. The units are classified according to the degree of accumulation and / or frequency. The lower the degree of accumulation and / or frequency, the more difficult it is to hit. Based on the classification results, a hard-to-hit unit is identified in each unit of the unit set; based on a subset of the multiple hash functions, it is determined whether the target characteristics of subsequent business traffic can be mapped to the specified hard-to-hit unit in the unit set, and whether the specified hard-to-hit unit has been mapped with risk characteristics; if so, the subsequent business traffic is forwarded to the server for processing. The lower the cumulative degree and / or frequency, the more difficult it is to hit.
21. A business traffic processing device, applied on a server side, the device comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: Initialize a set of cells containing multiple cells; Based on multiple hash functions, each specified risk feature is mapped to a corresponding subset of units in the unit set; The mapped unit set is sent to the client so that the client can determine whether to forward the client's current business traffic to the server based on the multiple hash functions and the unit set. If the service traffic forwarded by the client is received, the service traffic is processed. The client records all units that the current service traffic can be mapped to in the unit set; based on the records of historical traffic, including the current service traffic, it determines the cumulative degree and / or frequency of the records hitting each unit in the unit set; based on the cumulative degree and / or frequency, it classifies each unit; based on the classification result, it identifies hard-to-hit units among the units in the unit set; based on a portion of the multiple hash functions, it determines whether the target characteristics of subsequent service traffic can be mapped to the specified hard-to-hit unit in the unit set, and whether the specified hard-to-hit unit has been mapped with risk characteristics; if so, the subsequent service traffic is forwarded to the server for processing. The lower the cumulative degree and / or frequency, the more difficult it is to hit.
Citation Information
Patent Citations
Decision-making method and device for suspected risk business and processing equipment
CN111489098A
Content security identification method and device, storage medium and electronic equipment
CN112600834A