Processing method and device for flow detection model, storage medium and processor

By obtaining preset conditions and duration, the traffic detection model is learned and trained and updated in real time, the problem of low accuracy of traffic detection models in the prior art is solved, the accuracy of detection of malicious traffic is improved, and the risk of server attacks is reduced.

CN115550011BActive Publication Date: 2025-05-20HILLSTONE NETWORKS CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211158193.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-22
Publication Date
2025-05-20
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

In the prior art, the traffic detection model is learned and trained based on empirical values, and it is difficult to update the trained traffic detection model in real time, resulting in the traffic detection model that detects whether the traffic accessing the server is malicious traffic, which leads to the server being easily attacked.

Method used

By obtaining a plurality of preset conditions and preset durations, each first model is learned and trained according to these conditions, a plurality of second models are obtained, and a first flow detection model is constructed based on these second models. Then, the second model is updated according to the target log, the updated second model is obtained, and the first traffic detection model is updated to the second traffic detection model to improve the accuracy and real-timeness of the model.

Benefits of technology

By learning and training and real-time update of the traffic detection model based on preset conditions and duration, the accuracy of the traffic detection model detects malicious traffic is improved, reducing the risk of the server being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550011B_ABST
    Figure CN115550011B_ABST
Patent Text Reader

Abstract

The present application discloses a method and device for processing a flow detection model, a storage medium, and a processor. The method includes: obtaining multiple preset conditions and preset durations; learning and training each first model according to any preset condition and preset duration among the multiple preset conditions to obtain multiple second models; constructing a first flow detection model based on the multiple second models; updating the multiple second models according to the target log to obtain multiple updated second models, and updating the first flow detection model to a second flow detection model based on the multiple updated second models. Through the present application, the problem in the related art that the flow detection model is learned and trained according to empirical values, and it is difficult to update the trained flow detection model in real time, resulting in low accuracy of the flow detection model in detecting whether the flow accessing the server is malicious flow, which in turn makes the server vulnerable to attacks, is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network data security technology. Specifically, it relates to a processing method and device for a traffic detection model, a storage medium, and a processor. Background Art

[0002] The most traditional means of WEB security protection is rule-based protection based on feature matching. Moreover, rule-based protection relies on prior knowledge, requires analyzing the traffic characteristics and behavior characteristics of WEB attacks, summarizing and refining protection rules on this basis, and then applying them to WEB security protection products, such as WEB application firewalls, to protect the server. Since WEB attack methods emerge in an endless stream and new attack methods constantly appear, this method belongs to passive defense and has a certain lag.

[0003] Therefore, in response to this problem, self-learning protection has emerged. Self-learning is an active defense. By learning and modeling the traffic model of the protected object, using the learned model as a baseline, it discovers suspicious traffic that violates the model, thereby preventing unknown attacks.

[0004] In addition, Figure 1 is a schematic diagram of self-learning protection provided according to the prior art. As Figure 1 shown, self-learning protection generally consists of two processes: a model training stage and a protection stage. In the model training stage, the client initiates an HTTP request to access the server. The traffic passes through the WEB application firewall in the middle, and the WEB application firewall will collect secure traffic to train the server traffic model. After the model training is completed, in the protection stage, when the traffic of the client initiating an HTTP request to access the server passes through the WEB application firewall, the WEB application firewall detects whether the traffic characteristics conform to the constructed model. If they conform, the client can be allowed to continue accessing the server, and the server returns an HTTP response to the client; if they do not conform, the access to the server can be blocked.

[0005] The traffic model of the protected object is the basis for self-learning protection. Therefore, the key to self-learning protection is how to establish an accurate and highly robust traffic model. Self-learning learns the traffic characteristics of the protected server, that is, the characteristics of the URL resources of the protected server. Therefore, the establishment of the entire server traffic model can be refined into the establishment of the models of each URL resource of the server.

[0006] In the related art, the learning duration or the number of samples is used as the determination basis for the completion of model learning. Figure 2 is a schematic diagram of the determination conditions for learning and training a traffic detection model in the prior art. As Figure 2As shown in the figure, to determine whether a certain URL resource has been sufficiently learned, the number of samples is generally used as the determination condition, including the number of times the URL is accessed and the number of clients accessing the URL. When the URL resource is accessed multiple times and by a large number of different clients, it is considered that the learning of the URL resource is sufficient and the model is accurate and reliable. In addition, to prevent the situation where the access volume of some URLs is inherently small and it is difficult to reach a unified sample number threshold, resulting in the inability to complete the modeling of such URLs, the learning duration is generally referred to to determine whether the learning is sufficient. When the URL has been learned for a sufficient long time, it can also be considered that the learning is sufficient. That is, either the duration dimension or the sample number dimension satisfies the condition.

[0007] Moreover, after the relevant technology learning is completed, the URL model and the server resource model composed of all URLs are constructed. Unless re-learned, the model will not change.

[0008] However, there are two defects in the relevant technology:

[0009] (1) The setting of the thresholds for learning duration and sample number depends on experience. If the thresholds are set too small, it may cause the model to not reflect the traffic characteristics of all normal accesses in the network, resulting in underfitting; if the thresholds are set too large, it may cause waste of resources such as learning duration or cause overfitting of the model.

[0010] (2) After the learning is completed, the model is fixed. When the server resources change, it is easy to cause many false alarms. At this time, the WEB application firewall administrator needs to manually delete the old model and re-learn to generate a new model for protection. Generally, the WEB application firewall administrator and the server developer are different people, so the requirement for information synchronization between the two is relatively high.

[0011] Regarding the problem in the related technology that the traffic detection model is learned and trained according to empirical values and it is difficult to update the trained traffic detection model in real time, resulting in a low accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and thus the server is easily attacked, no effective solution has been proposed yet. Summary of the Invention

[0012] The main purpose of this application is to provide a processing method, device, storage medium and processor for a traffic detection model, so as to solve the problem in the related technology that the traffic detection model is learned and trained according to empirical values and it is difficult to update the trained traffic detection model in real time, resulting in a low accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and thus the server is easily attacked.

[0013] To achieve the above object, according to one aspect of the present application, a method for processing a traffic detection model is provided. The method includes: obtaining a plurality of preset conditions and a preset duration, where the plurality of preset conditions at least include: a first preset condition and a second preset condition, the first preset condition is used to represent the quantity of sample data corresponding to each uniform resource locator, the second preset condition is used to represent the learning duration of each uniform resource locator, each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time consumed to meet each preset condition; learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the features of each resource in the server; constructing a first traffic detection model based on the plurality of second models, where the first traffic detection model is used to detect the traffic accessing the server; updating the plurality of second models according to the target log to obtain a plurality of updated second models, and based on the plurality of updated second models, updating the first traffic detection model to a second traffic detection model, where the target log is used to record the traffic that does not match the first traffic detection model.

[0014] Further, learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models includes: obtaining the feature values of a plurality of traffic flows, where the plurality of traffic flows are the traffic flows corresponding to each resource in the server; after meeting any one of the plurality of preset conditions and within the range of the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0015] Further, after determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, the method further includes: if there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, continuing to learn and train each first model, and obtaining the first duration of continuing to learn and train each first model; when the first duration reaches the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0016] Further, updating the plurality of second models according to the target log to obtain a plurality of updated second models includes: parsing multiple log records in the target log to determine the target model among the plurality of second models; updating the target model to obtain a third model; using the third model and the models other than the target model among the plurality of second models as the plurality of updated second models.

[0017] Further, parsing multiple log records in the target log to determine the target model among multiple second models includes: when accessing the server through multiple clients within a target time period, determining whether there are a target number of identical log records in the target log; if there are a target number of identical log records in the target log, determining the target model among multiple second models based on the identical log records in the target log.

[0018] Further, after updating multiple second models according to the target log, before obtaining multiple updated second models and updating the first traffic detection model to a second traffic detection model based on the multiple updated second models, the method further includes: determining whether the number of models updated among multiple second models is less than a preset threshold; if the number of models updated among multiple second models is not less than the preset threshold, deleting the first traffic detection model and constructing a third traffic detection model; if the number of models updated among multiple second models is less than the preset threshold, performing the steps of constructing multiple updated second models and updating the first traffic detection model to the second traffic detection model based on the multiple updated second models.

[0019] Further, the preset duration is obtained through the following steps: obtaining a first time-consuming duration that meets the first preset condition; obtaining a second time-consuming duration that meets the second preset condition; determining the preset duration based on the first time-consuming duration and the second time-consuming duration.

[0020] To achieve the above object, according to another aspect of the present application, there is provided a processing device for a traffic detection model. The device includes: a first acquisition module, configured to acquire a plurality of preset conditions and a preset duration, wherein the plurality of preset conditions at least include: a first preset condition and a second preset condition, the first preset condition is used to represent the number of sample data corresponding to each uniform resource locator, the second preset condition is used to represent the learning duration of each uniform resource locator, each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time consumed to satisfy each preset condition; a first training module, configured to perform learning and training on each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, wherein each first model is used to detect the characteristics of each resource in the server; a first construction module, configured to construct a first traffic detection model based on the plurality of second models, wherein the first traffic detection model is used to detect the traffic accessing the server; a first update module, configured to update the plurality of second models according to the target log to obtain a plurality of updated second models, and update the first traffic detection model to a second traffic detection model based on the plurality of updated second models, wherein the target log is used to record the traffic that does not match the first traffic detection model.

[0021] Further, the first training module includes: a first acquisition unit, configured to acquire the characteristic values of a plurality of traffic flows, wherein the plurality of traffic flows are the traffic flows corresponding to each resource in the server; a first judgment unit, configured to judge whether there are characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows after satisfying any one of the plurality of preset conditions and within the range of the preset duration; a first construction unit, configured to construct a plurality of second models if there are no characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows.

[0022] Further, the device further includes: a first processing module, configured to, after judging whether there are characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows, if there are characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows, continue to perform learning and training on each first model and acquire the first duration of continuing to perform learning and training on each first model; a first judgment module, configured to judge whether there are characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows when the first duration reaches the preset duration; a second construction module, configured to construct a plurality of second models if there are no characteristic values that do not conform to the first model among the characteristic values of the plurality of traffic flows.

[0023] Further, the first update module includes: a first parsing unit configured to parse multiple log records in the target log to determine a target model among multiple second models; a first update unit configured to update the target model to obtain a third model; and a first determination unit configured to use the third model and the models among the multiple second models other than the target model as multiple updated second models.

[0024] Further, the first parsing unit includes: a first judgment sub-module configured to judge whether there are a target number of identical log records in the target log when accessing the server through multiple clients within a target time period; and a first determination sub-module configured to, if there are a target number of identical log records in the target log, determine the target model among the multiple second models according to the identical log records in the target log.

[0025] Further, the apparatus further includes: a second judgment module configured to judge whether the number of models updated among the multiple second models is less than a preset threshold after updating the multiple second models according to the target log, before obtaining multiple updated second models and updating the first traffic detection model to a second traffic detection model based on the multiple updated second models; a second processing module configured to, if the number of models updated among the multiple second models is not less than the preset threshold, delete the first traffic detection model and construct a third traffic detection model; and a third processing module configured to, if the number of models updated among the multiple second models is less than the preset threshold, perform the steps of constructing multiple updated second models and updating the first traffic detection model to the second traffic detection model based on the multiple updated second models.

[0026] Further, the first acquisition module includes: a second acquisition unit configured to acquire a first duration satisfying the first preset condition; a third acquisition unit configured to acquire a second duration satisfying the second preset condition; and a second determination unit configured to determine the preset duration according to the first duration and the second duration.

[0027] To achieve the above object, according to another aspect of the present application, there is provided a computer-readable storage medium storing a program, wherein the program executes the processing method of the traffic detection model described in any one of the above.

[0028] To achieve the above object, according to another aspect of the present application, there is provided a processor for running a program, wherein the program executes the processing method of the traffic detection model described in any one of the above when running.

[0029] Through this application, the following steps are adopted: obtaining a plurality of preset conditions and a preset duration, where the plurality of preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the quantity of sample data corresponding to each uniform resource locator, and the second preset condition is used to represent the learning duration of each uniform resource locator. Each uniform resource locator is used to represent the location information of each resource in the server. The preset duration is determined according to the time consumed to meet each preset condition; learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the characteristics of each resource in the server; constructing a first traffic detection model based on the plurality of second models, where the first traffic detection model is used to detect the traffic accessing the server; updating the plurality of second models according to the target log to obtain a plurality of updated second models, and updating the first traffic detection model to a second traffic detection model based on the plurality of updated second models, where the target log is used to record the traffic that does not match the first traffic detection model, solving the problem in the related art that the traffic detection model is learned and trained according to empirical values and it is difficult to update the trained traffic detection model in real time, resulting in a low accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and further leading to the server being easily attacked. By learning and training each first model used to detect the characteristics of each resource in the server according to any one of the obtained plurality of preset conditions and the preset duration to obtain a plurality of second models, constructing a first traffic detection model based on the plurality of second models, and then updating the plurality of second models according to the log used to record the traffic that does not match the first traffic detection model to obtain a plurality of updated second models, and updating the first traffic detection model to a second traffic detection model based on the plurality of updated second models, the accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic is improved, and further the effect of protecting the server from being easily attacked is achieved. Description of the Drawings

[0030] The drawings constituting a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:

[0031] Figure 1 is a schematic diagram of self-learning protection provided according to the prior art;

[0032] Figure 2 is a schematic diagram of the determination conditions for learning and training the traffic detection model in the prior art;

[0033] Figure 3 is a flowchart of the processing method of the traffic detection model provided according to the embodiment of this application;

[0034] Figure 4 It is a schematic diagram for judging the convergence of the judgment model in the embodiment of the present application;

[0035] Figure 5 It is a schematic diagram for automatically detecting changes in URL resources and automatically updating the URL model in the embodiment of the present application;

[0036] Figure 6 It is the flow of the processing method of the traffic detection model provided according to the embodiment of the present application Figure 1 ;

[0037] Figure 7 It is a schematic diagram of the processing device of the traffic detection model provided according to the embodiment of the present application. Detailed implementation manners

[0038] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0039] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0040] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances for the embodiments of the present application described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0041] For the convenience of description, some nouns or terms related to the embodiments of the present application are described below:

[0042] A WEB application firewall refers to a product used to protect a server.

[0043] An HTTP request refers to a request message from a client to a server.

[0044] The Hyper Text Transfer Protocol (HTTP) is a simple request-response protocol that specifies what kind of messages a client can send to a server and what kind of responses it can receive.

[0045] The uniform resource locator (URL) is a representation method used on the World Wide Web service program of the Internet to specify the location of information.

[0046] Example 1

[0047] The present invention will be described below in conjunction with preferred implementation steps. Figure 3 It is a flowchart of a processing method for a traffic detection model provided according to an embodiment of the present application, as Figure 3 shown. The method includes the following steps:

[0048] Step S301, obtain a plurality of preset conditions and a preset duration. Among them, the plurality of preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the number of sample data corresponding to each uniform resource locator, and the second preset condition is used to represent the learning duration of each uniform resource locator. Each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time taken to meet each preset condition.

[0049] For example, Condition 1 is that the number of times a URL is accessed reaches M and the number of clients accessing the URL reaches N (the above-mentioned first preset condition), and Condition 2 is that the learning duration of the URL reaches T (the above-mentioned second preset condition). And assume that it takes T1 to meet Condition 1 and T to meet Condition 2, and then calculate the above-mentioned preset duration T2 according to T1 and T.

[0050] Step S302, perform learning and training on each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the characteristics of each resource in the server.

[0051] For example, within the T2 duration range starting from the moment when Condition 1 or Condition 2 is satisfied, perform learning and training on the URL model (the above-mentioned first model) and obtain a plurality of learned and trained URL models (the above-mentioned second models).

[0052] Step S303, construct a first traffic detection model based on the plurality of second models, where the first traffic detection model is used to detect the traffic accessing the server.

[0053] For example, according to multiple URL models trained through learning, a traffic detection model (the above-mentioned first traffic detection model) is constructed to detect whether the traffic accessing the server is malicious traffic.

[0054] Step S304: Update multiple second models according to the target log to obtain multiple updated second models, and based on the multiple updated second models, update the first traffic detection model to a second traffic detection model, where the target log is used to record traffic that does not match the first traffic detection model.

[0055] For example, during the protection phase, traffic that violates the model is recorded in a log, and the outdated models among the multiple URL models trained through learning are updated according to the log. Then, based on the updated outdated models and the non-updated models among the multiple URL models trained through learning, the traffic detection model (the above-mentioned first traffic detection model) is updated to obtain an updated traffic detection model (the above-mentioned second traffic detection model).

[0056] Through the above steps S301 to S304, by learning and training each first model for detecting the characteristics of each resource in the server according to any one of the multiple preset conditions and the preset duration obtained, multiple second models are obtained. Based on the multiple second models, a first traffic detection model is constructed. Then, according to the log for recording traffic that does not match the first traffic detection model, the multiple second models are updated to obtain multiple updated second models, and based on the multiple updated second models, the first traffic detection model is updated to a second traffic detection model, thereby improving the accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and further achieving the effect of protecting the server from being easily attacked.

[0057] In order to determine the preset duration quickly and accurately, in the traffic detection model processing method provided in the embodiments of the present application, the preset duration can also be determined through the following steps: Obtain a first elapsed duration that satisfies a first preset condition; obtain a second elapsed duration that satisfies a second preset condition; determine the preset duration based on the first elapsed duration and the second elapsed duration.

[0058] For example, Figure 4 is a schematic diagram for judging model convergence in the embodiments of the present application. As Figure 4 shown, condition 1 is that the number of times the URL is accessed reaches M and the number of clients accessing the URL reaches N (the above-mentioned first preset condition), and condition 2 is that the learning duration of the URL reaches T (the above-mentioned second preset condition). And it is assumed that it takes T1 to satisfy condition 1 and T to satisfy condition 2, and then take T2 = 0.2 * min(T, T1).

[0059] Through the above solution, the preset duration can be calculated quickly and accurately according to the time consumption of each condition.

[0060] In order to build multiple second models quickly and accurately, in the processing method of the traffic detection model provided in the embodiments of the present application, multiple second models can also be built through the following steps: obtain the eigenvalue of multiple traffic flows, where the multiple traffic flows are the traffic flows corresponding to each resource in the server; after any one of the multiple preset conditions is satisfied and within the range of the preset duration, determine whether there is an eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows; if there is no eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows, build multiple second models.

[0061] For example, the self-learning function of the WEB application firewall generally requires the administrator to configure the learning duration, the number of times the URL is accessed, and the number of clients accessing the URL. These configurations directly affect the model learning result and require the administrator to have a full understanding of the traffic of the server, and the configuration requirements are high.

[0062] For example, Figure 4 is a schematic diagram for judging model convergence in the embodiments of the present application. As Figure 4 shown, after calculating the preset duration T2, within the T2 duration range from the moment when condition 1 or condition 2 is satisfied, if the newly collected URL traffic eigenvalue conforms to the calculated URL model (the above-mentioned first model), it is considered that the learning result has converged, and the calculated URL model is used as the learned and trained model (the above-mentioned second model).

[0063] Through the above solution, the empirical requirements for setting the model learning threshold are reduced, the fault tolerance of the configuration is increased, the model convergence is adaptively judged, and the influence of the configuration on the model training result is reduced.

[0064] In order to build multiple second models quickly and accurately, in the processing method of the traffic detection model provided in the embodiments of the present application, multiple second models can also be built through the following steps: if there is an eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows, continue to learn and train each first model, and obtain the first duration of continuing to learn and train each first model; when the first duration reaches the preset duration, determine whether there is an eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows; if there is no eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows, build multiple second models.

[0065] For example, Figure 4 is a schematic diagram for judging model convergence in the embodiments of the present application. As Figure 4As shown, if the newly collected URL traffic characteristics do not match the trained URL model (the first model above), it is necessary to restart the timing until the duration is T2 and the model remains unchanged, then it is considered that the learning is completed and the result converges.

[0066] In summary, by restarting the timing and training the model, the training effect of the traffic detection model is improved.

[0067] In order to quickly and accurately determine the target model among multiple second models, in the processing method of the traffic detection model provided in the embodiments of the present application, the target model among multiple second models can also be determined through the following steps: when multiple clients access the server within the target time period, determine whether there are target numbers of the same log records in the target log; if there are target numbers of the same log records in the target log, determine the target model among multiple second models based on the same log records in the target log.

[0068] For example, during the protection stage, the traffic that violates the model is logged, and the model automatic update module regularly detects the log. Taking the URL as a unit, if it is found that multiple clients have multiple similar logs within a long period of time, it is considered that the URL model (the target model above) is outdated and needs to be updated.

[0069] Through the above solution, according to the log records, the outdated and URL models that need to be updated can be quickly and accurately determined.

[0070] In order to quickly and accurately determine multiple updated second models, in the processing method of the traffic detection model provided in the embodiments of the present application, the multiple updated second models can also be determined through the following steps: parse multiple log records in the target log to determine the target model among multiple second models; update the target model to obtain a third model; use the third model and the models among multiple second models except the target model as multiple updated second models.

[0071] For example, when the server URL resource characteristics change, the new traffic characteristics may deviate from the original model. If the existing model is used to filter the client traffic, there will be more false alarms. This embodiment supports detecting whether the URL resources have changed.

[0072] For example, Figure 5 is a schematic diagram of automatically detecting URL resource changes and automatically updating the URL model in the embodiments of the present application, as Figure 5As shown, based on the model training stage and the protection stage, a model update stage is added. The model automatic update module is used to detect whether each URL model is outdated. In the protection stage, the traffic that violates the model is logged. The model automatic update module regularly detects the logs. Taking the URL as a unit, if it is found that multiple clients have had multiple similar logs for a long time, it is considered that the URL model is outdated and needs to be updated. This part of the log data is used as a sample to extract features and update the URL model.

[0073] Through the above solution, the update of server resources can be discovered in a timely manner, without the need for website administrators to frequently check the logs or confirm the server update situation with server developers.

[0074] Figure 6 is the flow of the processing method of the traffic detection model provided by the embodiment of the present application Figure 1 , such as Figure 6 shown, in the processing method of the traffic detection model provided by the embodiment of the present application, after updating multiple second models according to the target logs, after obtaining multiple updated second models, and before updating the first traffic detection model to the second traffic detection model based on the multiple updated second models, the method further includes:

[0075] Step S601, determining whether the number of models updated in the multiple second models is less than a preset threshold;

[0076] Step S602, if the number of models updated in the multiple second models is not less than the preset threshold, delete the first traffic detection model and construct a third traffic detection model;

[0077] Step S603, if the number of models updated in the multiple second models is less than the preset threshold, execute the steps of constructing multiple updated second models and updating the first traffic detection model to the second traffic detection model based on the multiple updated second models.

[0078] For example, automatic detection of URL resource changes is applicable to the situation where individual URL resources on the server are found to have changed. When the server is upgraded and replaced, most resources have changed, and it is not advisable to only gradually modify each URL model. In addition, due to its performance limitations, the number of URLs that the Web application firewall can learn has a capacity limit. In the learning results before the server upgrade, the old URL resources may occupy the vast majority of the capacity. If these URLs become new URL paths after the upgrade, then the URL resources included in the old model are no longer applicable to the scenario after the server upgrade.

[0079] Therefore, it is necessary to regularly check the number of URLs that need to be updated recently. For example, if the number of URLs to be updated reaches 1 / 3 of the total server URL resources, it is considered that the server has been upgraded, and the model automatic update module will delete the self-learning model corresponding to this server and retrain to generate a new model for protection; if the number of URLs to be updated does not reach 1 / 3 of the total server URL resources, it is considered that the server does not need to be upgraded, and a traffic detection model will be directly obtained based on multiple trained URL models.

[0080] Through the above solution, it is possible to automatically detect whether the server has been upgraded and reconstruct the model.

[0081] Through the method provided by the embodiments of the present application, for example, during the training stage of the traffic detection model, it adaptively judges the convergence of the model. The specific process is as follows: Assume that it takes T1 to satisfy condition 1 and T to satisfy condition 2. Let T2 = 0.2 * min(T, T1). Within the T2 time range starting from the moment when condition 1 or condition 2 is satisfied, if the newly collected URL traffic characteristics match the calculated URL model, it is considered that the learning result has converged; if they do not match the trained URL model, it is necessary to start timing again until the duration is T2 and the model has not changed, then it is considered that the learning is completed and the result has converged. Then, during the protection stage of the traffic detection model, it automatically detects changes in URL resources. The specific process is as follows: The traffic that violates the model is recorded through logs. The model automatic update module regularly checks the logs. Taking the URL as the unit, if it is found that multiple clients have appeared multiple similar logs within a long period of time, it is considered that the URL model is outdated and needs to be updated, and the feature of this part of the log data is extracted as a sample to update the URL model. In addition, during the protection stage of the traffic detection model, it automatically detects the upgrade situation of the server, that is, regularly checks the number of URLs that need to be updated recently. If it reaches 1 / 3 of the total server URL resources, it is considered that the server has been upgraded, and the model automatic update module will delete the self-learning model corresponding to this server and retrain to generate a new model for protection.

[0082] In summary, the processing method of the traffic detection model provided by the embodiments of the present application obtains multiple preset conditions and a preset duration. Among them, the multiple preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the quantity of sample data corresponding to each Uniform Resource Locator (URL), and the second preset condition is used to represent the learning duration of each URL. Each URL is used to represent the location information of each resource in the server. The preset duration is determined according to the time consumed to meet each preset condition. Each first model for detecting the characteristics of each resource in the server is learned and trained according to any one of the multiple preset conditions and the preset duration to obtain multiple second models. Based on the multiple second models, a first traffic detection model is constructed, where the first traffic detection model is used to detect the traffic accessing the server. The multiple second models are updated according to the target log to obtain multiple updated second models, and based on the multiple updated second models, the first traffic detection model is updated to a second traffic detection model. The target log is used to record the traffic that does not match the first traffic detection model, which solves the problem in the related art that the traffic detection model is learned and trained according to empirical values and it is difficult to update the trained traffic detection model in real time, resulting in low accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and further leading to the server being easily attacked. By learning and training each first model for detecting the characteristics of each resource in the server according to any one of the multiple obtained preset conditions and the preset duration to obtain multiple second models, and based on the multiple second models, constructing a first traffic detection model, and then updating the multiple second models according to the log for recording the traffic that does not match the first traffic detection model to obtain multiple updated second models, and based on the multiple updated second models, updating the first traffic detection model to a second traffic detection model, the accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic is improved, and the effect of protecting the server from being easily attacked is achieved.

[0083] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0084] Example 2

[0085] The embodiments of the present application also provide a processing device for a traffic detection model. It should be noted that the processing device for the traffic detection model in the embodiments of the present application can be used to execute the processing method for the traffic detection model provided by the embodiments of the present application. The following introduces the processing device for the traffic detection model provided by the embodiments of the present application.

[0086] Figure 7 It is a schematic diagram of a processing device for a traffic detection model according to an embodiment of the present application. As Figure 7 shown, the device includes: a first acquisition module 701, a first training module 702, a first construction module 703, and a first update module 704.

[0087] Specifically, the first acquisition module 701 is configured to acquire a plurality of preset conditions and a preset duration. Among them, the plurality of preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the quantity of sample data corresponding to each uniform resource locator, and the second preset condition is used to represent the learning duration of each uniform resource locator. Each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time consumed to meet each preset condition;

[0088] The first training module 702 is configured to perform learning and training on each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the characteristics of each resource in the server;

[0089] The first construction module 703 is configured to construct a first traffic detection model based on the plurality of second models, where the first traffic detection model is used to detect the traffic accessing the server;

[0090] The first update module 704 is configured to update the plurality of second models according to the target log to obtain a plurality of updated second models, and based on the plurality of updated second models, update the first traffic detection model to a second traffic detection model, where the target log is used to record the traffic that does not match the first traffic detection model.

[0091] In summary, the processing device of the traffic detection model provided by the embodiments of the present application obtains a plurality of preset conditions and a preset duration through the first acquisition module 701. Among them, the plurality of preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the number of sample data corresponding to each uniform resource locator, and the second preset condition is used to represent the learning duration of each uniform resource locator. Each uniform resource locator is used to represent the location information of each resource in the server. The preset duration is determined according to the time consumption for satisfying each preset condition. The first training module 702 performs learning and training on each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the characteristics of each resource in the server. The first construction module 703 constructs a first traffic detection model based on the plurality of second models, where the first traffic detection model is used to detect the traffic accessing the server. The first update module 704 updates the plurality of second models according to the target log to obtain a plurality of updated second models, and based on the plurality of updated second models, updates the first traffic detection model to a second traffic detection model, where the target log is used to record the traffic that does not match the first traffic detection model, solving the problem in the related art that the traffic detection model is learned and trained according to empirical values and it is difficult to update the trained traffic detection model in real time, resulting in a low accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic, and further resulting in the server being easily attacked. By performing learning and training on each first model for detecting the characteristics of each resource in the server according to any one of the obtained plurality of preset conditions and the preset duration to obtain a plurality of second models, constructing a first traffic detection model based on the plurality of second models, and then updating the plurality of second models according to the log for recording the traffic that does not match the first traffic detection model to obtain a plurality of updated second models, and based on the plurality of updated second models, updating the first traffic detection model to a second traffic detection model, the accuracy of the traffic detection model in detecting whether the traffic accessing the server is malicious traffic is improved, and thus the effect of protecting the server from being easily attacked is achieved.

[0092] Optionally, in the processing device of the traffic detection model provided by the embodiments of the present application, the first acquisition module includes: a second acquisition unit, configured to acquire a first time duration for satisfying the first preset condition; a third acquisition unit, configured to acquire a second time duration for satisfying the second preset condition; and a second determination unit, configured to determine the preset duration according to the first time duration and the second time duration.

[0093] For example, Condition 1 is that the number of times the URL is accessed reaches M and the number of clients accessing the URL reaches N (the first preset condition above), and Condition 2 is that the learning duration of the URL reaches T (the second preset condition above). Then, the obtaining unit respectively obtains the time consumption T1 that satisfies Condition 1 and the time consumption T that satisfies Condition 2, and then the determining unit takes T2 = 0.2 * min(T, T1).

[0094] In summary, according to the time consumption of each condition, the preset duration can be calculated quickly and accurately.

[0095] Optionally, in the processing device of the traffic detection model provided in the embodiment of the present application, the first training module includes: a first obtaining unit, configured to obtain the eigenvalue of multiple traffic flows, where the multiple traffic flows are the traffic flows corresponding to each resource in the server; a first judging unit, configured to judge whether there is an eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows after any one of the multiple preset conditions is satisfied and within the range of the preset duration; a first constructing unit, configured to construct multiple second models if there is no eigenvalue that does not conform to the first model among the eigenvalues of the multiple traffic flows.

[0096] For example, for the self-learning function of the WEB application firewall, generally, the administrator is required to configure the learning duration, the number of times the URL is accessed, and the number of clients accessing the URL. These configurations directly affect the model learning result and require the administrator to have a full understanding of the traffic of the server, with high configuration requirements.

[0097] For example, after calculating the preset duration T2, within the T2 duration range starting from the moment when Condition 1 or Condition 2 is satisfied, if the URL traffic characteristics newly collected by the obtaining unit conform to the calculated URL model (the first model above), it is considered that the learning result has converged, and the calculating unit takes the calculated URL model as the trained model (the second model above).

[0098] In summary, the empirical requirements for setting the model learning threshold are reduced, the fault tolerance of the configuration is increased, the convergence of the model is adaptively judged, and the influence of the configuration on the model training result is reduced.

[0099] Optionally, in the processing device of the traffic detection model provided in the embodiments of the present application, the device further includes: a first processing module, configured to, after determining whether there are eigenvalue that do not conform to the first model among the eigenvalues of multiple traffic flows, if there are eigenvalue that do not conform to the first model among the eigenvalues of multiple traffic flows, continue to learn and train each first model, and obtain a first duration for continuing to learn and train each first model; a first judgment module, configured to determine whether there are eigenvalue that do not conform to the first model among the eigenvalues of multiple traffic flows when the first duration reaches a preset duration; a second construction module, configured to construct multiple second models if there are no eigenvalue that do not conform to the first model among the eigenvalues of multiple traffic flows.

[0100] For example, if the URL traffic characteristics newly collected do not match the trained URL model (the first model above), the processing module restarts the timing until the continuous duration is T2, and if the judgment module determines that the model has not changed, it is considered that the learning is completed and the result converges.

[0101] In summary, by restarting the timing and training the model, the training effect of the traffic detection model is improved.

[0102] Optionally, in the processing device of the traffic detection model provided in the embodiments of the present application, the first parsing unit includes: a first judgment sub-module, configured to determine whether there are a target number of identical log records in the target log when accessing the server through multiple clients within a target time period; a first determination sub-module, configured to, if there are a target number of identical log records in the target log, determine a target model among the multiple second models according to the identical log records in the target log.

[0103] For example, during the protection phase, the traffic that violates the model is logged, and the model automatic update module periodically detects the log. Taking the URL as a unit, if the judgment sub-module finds that multiple clients have multiple similar logs within a long time, the determination sub-module determines that the URL model (the target model above) is outdated and needs to be updated.

[0104] In summary, according to the log records, the outdated and URL models that need to be updated can be quickly and accurately determined.

[0105] Optionally, in the processing device of the traffic detection model provided in the embodiments of the present application, the first update module includes: a first parsing unit, configured to parse multiple log records in the target log to determine a target model among the multiple second models; a first update unit, configured to update the target model to obtain a third model; a first determination unit, configured to use the third model and the models other than the target model among the multiple second models as the multiple updated second models.

[0106] For example, when the characteristics of the server URL resource change, the new traffic characteristics may deviate from the original model. If the existing model is used to filter the client traffic, there will be more false alarms. This embodiment supports detecting whether the URL resource has changed.

[0107] For example, on the basis of the model training stage and the protection stage, a model update stage is added. The model automatic update module is used to detect whether each URL model is outdated. In the protection stage, the traffic that violates the model is recorded through logs. The model automatic update module regularly detects the logs. Taking the URL as a unit, if it is found that multiple clients have appeared multiple similar logs within a long time, it is considered that the URL model is outdated and needs to be updated. The update unit extracts features from this part of the log data as samples to update the URL model.

[0108] In summary, the update of the server resources can be detected in time, without the need for the website administrator to often check the logs or confirm the update situation of the server with the server developer.

[0109] Optionally, in the processing device of the traffic detection model provided in the embodiment of the present application, the device further includes: a second judgment module, configured to judge whether the number of models updated in multiple second models is less than a preset threshold after updating multiple second models according to the target log, and before obtaining multiple updated second models and updating the first traffic detection model to the second traffic detection model based on the multiple updated second models; a second processing module, configured to delete the first traffic detection model and construct a third traffic detection model if the number of models updated in multiple second models is not less than the preset threshold; a third processing module, configured to execute the steps of constructing multiple updated second models and updating the first traffic detection model to the second traffic detection model based on the multiple updated second models if the number of models updated in multiple second models is less than the preset threshold.

[0110] For example, the automatic detection of URL resource changes is applicable to the situation where individual URL resources of the server are found to have changed. When the server is upgraded, most resources have changed, and it is not advisable to only gradually modify each URL model. In addition, due to its performance limitations, the number of URLs that the Web application firewall can learn has a capacity limit. In the learning result before the server upgrade, the old URL resources may occupy most of the capacity. If these URLs become new URL paths after the upgrade, the URL resources included in the old model are no longer applicable to the scenario after the server upgrade.

[0111] Therefore, it is necessary to regularly check the number of URLs that need to be updated recently. For example, if the number of URLs that need to be updated reaches 1 / 3 of the total server URL resources, it is considered that the server has been upgraded, and the model automatic update module will delete the self-learning model corresponding to the server and retrain to generate a new model for protection; if the number of URLs that need to be updated does not reach 1 / 3 of the total server URL resources, it is considered that the server does not need to be upgraded, and the processing module will directly obtain the traffic detection model based on multiple trained URL models.

[0112] In summary, it is possible to automatically detect whether the server is upgraded and reconstruct the model.

[0113] The processing device of the traffic detection model includes a processor and a memory. The above first acquisition module 701, first training module 702, first construction module 703, first update module 704, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above program units stored in the memory.

[0114] The processor contains a kernel, and the kernel retrieves the corresponding program units from the memory. One or more kernels can be set, and the server can be protected from being attacked by adjusting the kernel parameters.

[0115] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0116] An embodiment of the present invention provides a computer-readable storage medium, on which a program is stored, and when the program is executed by a processor, the processing method of the traffic detection model is implemented.

[0117] An embodiment of the present invention provides a processor, and the processor is used to run a program, wherein when the program runs, the processing method of the traffic detection model is executed.

[0118] An embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, the following steps are implemented: obtaining a plurality of preset conditions and a preset duration, where the plurality of preset conditions at least include: a first preset condition and a second preset condition. The first preset condition is used to represent the quantity of sample data corresponding to each uniform resource locator, and the second preset condition is used to represent the learning duration of each uniform resource locator. Each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time consumed to meet each preset condition; learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, where each first model is used to detect the features of each resource in the server; based on the plurality of second models, constructing a first traffic detection model, where the first traffic detection model is used to detect the traffic accessing the server; updating the plurality of second models according to the target log to obtain a plurality of updated second models, and based on the plurality of updated second models, updating the first traffic detection model to a second traffic detection model, where the target log is used to record the traffic that does not match the first traffic detection model.

[0119] When the processor executes the program, the following steps are further implemented: learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, including: obtaining the feature values of a plurality of traffic flows, where the plurality of traffic flows are the traffic flows corresponding to each resource in the server; after meeting any one of the plurality of preset conditions and within the range of the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0120] When the processor executes the program, the following steps are further implemented: after determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, the method further includes: if there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, continuing to learn and train each first model, and obtaining the first duration of continuing to learn and train each first model; when the first duration reaches the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0121] When the processor executes the program, the following steps are also implemented: updating a plurality of second models according to the target log to obtain a plurality of updated second models, including: parsing a plurality of log records in the target log to determine a target model among the plurality of second models; updating the target model to obtain a third model; and using the third model and the models other than the target model among the plurality of second models as the plurality of updated second models.

[0122] When the processor executes the program, the following steps are also implemented: parsing a plurality of log records in the target log to determine a target model among the plurality of second models, including: when accessing the server through a plurality of clients within a target time period, determining whether there are a target number of identical log records in the target log; if there are a target number of identical log records in the target log, determining the target model among the plurality of second models according to the identical log records in the target log.

[0123] When the processor executes the program, the following steps are also implemented: after updating a plurality of second models according to the target log, before obtaining a plurality of updated second models and updating the first traffic detection model to a second traffic detection model based on the plurality of updated second models, the method further includes: determining whether the number of models updated among the plurality of second models is less than a preset threshold; if the number of models updated among the plurality of second models is not less than the preset threshold, deleting the first traffic detection model and constructing a third traffic detection model; if the number of models updated among the plurality of second models is less than the preset threshold, performing the steps of constructing a plurality of updated second models and updating the first traffic detection model to the second traffic detection model based on the plurality of updated second models.

[0124] When the processor executes the program, the following steps are also implemented to obtain a preset duration: obtaining a first elapsed time satisfying the first preset condition; obtaining a second elapsed time satisfying the second preset condition; and determining the preset duration based on the first elapsed time and the second elapsed time.

[0125] The device in this article can be a server, a PC, a PAD, a mobile phone, etc.

[0126] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program initialized with the following method steps: obtaining a plurality of preset conditions and a preset duration, wherein the plurality of preset conditions at least include: a first preset condition and a second preset condition, the first preset condition is used to represent the quantity of sample data corresponding to each uniform resource locator, the second preset condition is used to represent the learning duration of each uniform resource locator, each uniform resource locator is used to represent the location information of each resource in the server, and the preset duration is determined according to the time consumed to meet each preset condition; learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, wherein each first model is used to detect the features of each resource in the server; constructing a first traffic detection model based on the plurality of second models, wherein the first traffic detection model is used to detect the traffic accessing the server; updating the plurality of second models according to the target log to obtain a plurality of updated second models, and updating the first traffic detection model to a second traffic detection model based on the plurality of updated second models, wherein the target log is used to record the traffic that does not match the first traffic detection model.

[0127] When executed on a data processing device, it is also adapted to execute a program initialized with the following method steps: learning and training each first model according to any one of the plurality of preset conditions and the preset duration to obtain a plurality of second models, including: obtaining the feature values of a plurality of traffic flows, wherein the plurality of traffic flows are the traffic flows corresponding to each resource in the server; after meeting any one of the plurality of preset conditions and within the range of the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0128] When executed on a data processing device, it is also adapted to execute a program initialized with the following method steps: after determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, the method further includes: if there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows, continuing to learn and train each first model, and obtaining the first duration of continuing to learn and train each first model; when the first duration reaches the preset duration, determining whether there are feature values that do not conform to the first model among the feature values of the plurality of traffic flows; if there are no feature values that do not conform to the first model among the feature values of the plurality of traffic flows, constructing a plurality of second models.

[0129] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: updating a plurality of second models according to a target log to obtain a plurality of updated second models, including: parsing a plurality of log records in the target log to determine a target model among the plurality of second models; updating the target model to obtain a third model; and using the third model and the models among the plurality of second models other than the target model as the plurality of updated second models.

[0130] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: parsing a plurality of log records in the target log to determine a target model among the plurality of second models, including: when accessing the server through a plurality of clients within a target time period, determining whether there are a target number of identical log records in the target log; if there are a target number of identical log records in the target log, determining the target model among the plurality of second models according to the identical log records in the target log.

[0131] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: after updating a plurality of second models according to a target log, before obtaining a plurality of updated second models and updating the first traffic detection model to a second traffic detection model based on the plurality of updated second models, the method further includes: determining whether the number of models updated among the plurality of second models is less than a preset threshold; if the number of models updated among the plurality of second models is not less than the preset threshold, deleting the first traffic detection model and constructing a third traffic detection model; if the number of models updated among the plurality of second models is less than the preset threshold, performing the steps of constructing the plurality of updated second models and updating the first traffic detection model to the second traffic detection model based on the plurality of updated second models.

[0132] When executed on a data processing device, it is also suitable for executing a program initialized with the following method steps: obtaining a preset duration through the following steps: obtaining a first elapsed time satisfying the first preset condition; obtaining a second elapsed time satisfying the second preset condition; and determining the preset duration based on the first elapsed time and the second elapsed time.

[0133] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0134] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0135] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0136] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0137] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0138] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.

[0139] Computer readable media include permanent and non-permanent, removable and non-removable media that can implement information storage by any method or technology. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0140] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device that includes a series of elements includes not only those elements, but also other elements that are not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises one..." do not exclude the existence of other identical elements in the process, method, commodity or device that includes the elements.

[0141] It should be understood by those skilled in the art that the embodiments of the present application can be provided as methods, systems or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0142] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of the claims of the present application.

Claims

1. A method for processing a flow detection model, characterized in that: include: Acquire multiple preset conditions and preset durations, wherein the multiple preset conditions at least include: a first preset condition and a second preset condition, the first preset condition is used to indicate the number of sample data corresponding to each uniform resource locator, the second preset condition is used to indicate the learning duration of each uniform resource locator, each uniform resource locator is used to indicate the location information of each resource in the server, and the preset duration is determined according to the time taken to meet each preset condition; Performing learning and training on each first model according to any one of a plurality of preset conditions and the preset duration to obtain a plurality of second models, wherein each first model is used to detect the characteristics of each resource in the server; Based on the multiple second models, construct a first traffic detection model, wherein the first traffic detection model is used to detect traffic accessing the server; Multiple second models are updated according to the target log to obtain multiple updated second models, and based on the multiple updated second models, the first traffic detection model is updated to a second traffic detection model, wherein the target log is used to record traffic that does not match the first traffic detection model.

2. The method according to claim 1, characterized in that Each first model is trained according to any one of the plurality of preset conditions and the preset time to obtain a plurality of second models including: Acquire characteristic values ​​of multiple flows, wherein the multiple flows are flows corresponding to each resource in the server; After any one of the plurality of preset conditions is satisfied and within the preset time period, determining whether there is a characteristic value in the plurality of flow characteristic values ​​that does not conform to the first model; If there is no characteristic value that does not conform to the first model among the characteristic values ​​of the multiple flows, multiple second models are constructed.

3. The method according to claim 2, characterized in that After determining whether there is a characteristic value that does not conform to the first model among the characteristic values ​​of the plurality of flows, the method further includes: If there is a characteristic value among the characteristic values ​​of the multiple flows that does not conform to the first model, continue to learn and train each first model, and obtain a first duration for continuing to learn and train each first model; When the first time period reaches the preset time period, determining whether there is a feature value that does not conform to the first model among the feature values ​​of the plurality of flows; If there is no characteristic value that does not conform to the first model among the characteristic values ​​of the multiple flows, multiple second models are constructed.

4. The method according to claim 1, characterized in that The multiple second models are updated according to the target log, and the multiple updated second models are obtained, including: Parsing multiple log records in the target log to determine a target model among multiple second models; Updating the target model to obtain a third model; The third model and models of the plurality of second models excluding the target model are used as a plurality of updated second models.

5. The method according to claim 4, characterized in that Parsing multiple log records in the target log to determine a target model among multiple second models includes: When the server is accessed by multiple clients within a target time period, determining whether there are the same number of log records in the target log; If there are log records with the same target number in the target log, a target model among the plurality of second models is determined according to the same log records in the target log.

6. The method according to claim 1, characterized in that After updating the plurality of second models according to the target log, before obtaining the plurality of updated second models and updating the first flow detection model to the second flow detection model based on the plurality of updated second models, the method further includes: Determining whether the number of models to be updated among the plurality of second models is less than a preset threshold; If the number of models updated in the plurality of second models is not less than the preset threshold, deleting the first flow detection model and constructing a third flow detection model; If the number of models updated in the multiple second models is less than the preset threshold, the step of constructing multiple updated second models and updating the first flow detection model to the second flow detection model based on the multiple updated second models is executed.

7. The method according to claim 1, characterized in that To obtain the preset duration, follow these steps: Obtaining a first time-consuming duration that satisfies the first preset condition; Obtaining a second time duration that satisfies the second preset condition; The preset duration is determined according to the first time-consuming duration and the second time-consuming duration.

8. A processing device for a flow detection model, characterized in that: include: A first acquisition module, used to acquire multiple preset conditions and preset durations, wherein the multiple preset conditions at least include: a first preset condition and a second preset condition, the first preset condition is used to indicate the number of sample data corresponding to each uniform resource locator, the second preset condition is used to indicate the learning duration of each uniform resource locator, each uniform resource locator is used to indicate the location information of each resource in the server, and the preset duration is determined according to the time taken to meet each preset condition; A first training module is used to perform learning and training on each first model according to any one of a plurality of preset conditions and the preset duration to obtain a plurality of second models, wherein each first model is used to detect a feature of each resource in the server; A first building module, configured to build a first traffic detection model based on a plurality of second models, wherein the first traffic detection model is used to detect traffic accessing the server; The first update module is used to update the multiple second models according to the target log to obtain multiple updated second models, and based on the multiple updated second models, update the first traffic detection model to a second traffic detection model, wherein the target log is used to record the traffic that does not match the first traffic detection model.

9. A computer-readable storage medium, characterized in that: The storage medium stores a program, wherein the program executes the processing method of the flow detection model according to any one of claims 1 to 7.

10. A processor for a method for processing a flow detection model, characterized in that: The processor is used to run a program, wherein the program, when run by the processor, executes the processing method of the flow detection model described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network attack detection method and device, electronic equipment and readable storage medium

    CN110808968A

  • Phishing website URL detection method and system based on machine learning

    CN112948725A