Security verification method, device, equipment and storage medium

By waking up higher security level rules for verification when the proportion of business requests in the set reaches a preset ratio, the problem of single and inefficient security policies in the existing technology is solved, and more efficient security verification is achieved.

CN115913678BActive Publication Date: 2025-09-19MIGU CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211378944.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-04
Publication Date
2025-09-19
Estimated Expiration
2042-11-04

AI Technical Summary

Technical Problem

When facing abnormal business requests, the existing protection system has a single and inefficient security policy, which easily leads to performance bottlenecks and affects the business system.

Method used

By determining whether the proportion of business requests that have touched the first security rule in the request set reaches a preset ratio, when the preset ratio is reached, the second security rule with a higher security level is awakened for verification, and verification is performed in combination with multi-level security rules.

Benefits of technology

The efficiency of security verification is improved, making verification more suitable for the current network environment and ensuring the accuracy and efficiency of security verification of business requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913678B_ABST
    Figure CN115913678B_ABST
Patent Text Reader

Abstract

The present invention discloses a security verification method, apparatus, device, and storage medium. The method comprises: determining whether the proportion of service requests that have triggered a first security rule in a set of service requests reaches a preset first ratio; when the preset first ratio is reached, invoking security verification of a second security rule, where the security level of the second security rule is higher than that of the first security rule; and performing security verification of the first and second security rules on the received service request. The present invention improves the efficiency of security verification of service requests.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a security verification method, apparatus, device and storage medium. Background Art

[0002] With the rapid development of internet technology, information networks have become a vital component of social development, and cybersecurity has long been closely tied to everyone's daily lives. Information stored on the internet is crucial for businesses and individuals. For example, core corporate information and personal privacy are vulnerable to various cyberattacks, resulting in information leaks, theft, and data tampering.

[0003] In response to abnormal business requests, most protection systems will configure a series of security rules. In order to strengthen website security, they will even configure all security policies and verify each business request in a serial manner. Such security policies are simple and inefficient. In extreme cases, performance bottlenecks will occur in the protection system, affecting the business system. Summary of the Invention

[0004] The main purpose of the present invention is to provide a security verification method, apparatus, device and storage medium, aiming to solve the problem of how to improve the security verification efficiency of security policies.

[0005] To achieve the above object, the present invention provides a security verification method, which includes the following steps:

[0006] Determine whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset first proportion;

[0007] When a preset first ratio is reached, a security verification of a second security rule is activated, wherein the security level of the second security rule is higher than the security level of the first security rule;

[0008] Perform security verification of the first security rule and the second security rule on the received service request.

[0009] Optionally, the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset first proportion includes:

[0010] Grouping service requests according to their area information and / or traffic time period;

[0011] Determine the ratio of the service requests in the current group that have triggered the first security rule verification to the service request set of the current group;

[0012] It is determined whether the proportion of business requests that have triggered the first security rule verification has reached a preset first proportion.

[0013] Optionally, before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset first proportion, the step further includes:

[0014] Grouping historical service requests according to their region information and / or traffic time period;

[0015] Determine the proportion of historical service requests in the current group that have triggered the first security rule in the set of historical service requests in the current group;

[0016] Determine the number of wake-up times at which a ratio of historical business requests that have triggered a first security rule reaches a first target ratio, where the first target ratio is a plurality of ratios;

[0017] A preset first ratio is determined from a plurality of first target ratios according to the number of wake-up times.

[0018] Optionally, the step of determining a preset first ratio from a plurality of first target ratios according to the number of wake-up times includes:

[0019] Determining an average value of the number of wake-up times for each of the first target ratios in a preset time period;

[0020] determining a discrete degree of the number of wake-up times corresponding to each first target ratio according to the average value;

[0021] A preset first ratio is determined among a plurality of first target ratios according to the discrete degree.

[0022] Optionally, the step of determining a preset first ratio from a plurality of first target ratios according to the discreteness includes:

[0023] When there are multiple security sub-rules corresponding to the first security rule, determining the to-be-determined ratio corresponding to each security sub-rule among the multiple first target ratios according to the discrete degree of the wake-up times corresponding to each security sub-rule;

[0024] A preset first ratio is determined according to the weight value of each of the security sub-rules and the corresponding ratio to be determined.

[0025] Optionally, the method further includes:

[0026] Determining whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset second proportion;

[0027] When the preset second ratio is not reached, the safety verification of the second safety rule is dormant;

[0028] Perform security verification of the first security rule on the received service request.

[0029] Optionally, before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset second proportion, the step further includes:

[0030] Grouping historical service requests according to their region information and / or traffic time period;

[0031] Determine the number of dormancy times during which the percentage of historical service requests that have triggered the first security rule in the current group does not reach a second target ratio in the set of historical service requests of the current group, where the second target ratio is multiple;

[0032] A preset second ratio is determined from a plurality of second target ratios according to the number of sleep times.

[0033] To achieve the above object, the present invention further provides a security verification device, comprising:

[0034] a determination module, configured to determine whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset first proportion;

[0035] A wake-up module, configured to wake up the security verification of a second security rule when a preset first ratio is reached, wherein the security level of the second security rule is higher than the security level of the first security rule;

[0036] The verification module is used to perform security verification of the first security rule and the second security rule on the received service request.

[0037] To achieve the above-mentioned purpose, the present invention also provides a security verification device, which includes a memory, a processor, and a security verification program stored in the memory and executable on the processor. When the security verification program is executed by the processor, the various steps of the security verification method described above are implemented.

[0038] To achieve the above objectives, the present invention also provides a computer-readable storage medium, which stores a security verification program. When the security verification program is executed by a processor, it implements the various steps of the security verification method described above.

[0039] The present invention provides a security verification method, apparatus, device, and storage medium, which determine whether the proportion of business requests that have touched a first security rule in a business request set has reached a preset first proportion; when the preset first proportion is reached, the security verification of a second security rule is awakened, and the security level of the second security rule is higher than the security level of the first security rule; and the first and second security rules are security verified for the received business requests. By awakening the second security rule with a higher security level when the proportion of business requests that have touched the first security rule reaches a first proportion, the received business requests are security verified with multi-level security rules, so that the security verification of the business requests is more in line with the current network environment, the accuracy of the security verification of the business requests is guaranteed, and the efficiency of the security verification of the business requests is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 A schematic diagram of the hardware structure of a security verification device according to an embodiment of the present invention;

[0041] Figure 2 A schematic diagram of a flow chart of an embodiment of a security verification method of the present invention;

[0042] Figure 3 A schematic flow chart of another embodiment of the security verification method of the present invention;

[0043] Figure 4 A schematic diagram of a curve corresponding to the first target ratio in another embodiment of the safety verification method of the present invention;

[0044] Figure 5 A schematic flow chart of another embodiment of the security verification method of the present invention;

[0045] Figure 6 A schematic flow chart of another embodiment of the security verification method of the present invention;

[0046] Figure 7 A schematic flow chart of another embodiment of the security verification method of the present invention;

[0047] Figure 8 Schematic diagram of the logical structure of the security verification device involved in an embodiment of the present invention.

[0048] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0049] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0050] The main solution of an embodiment of the present invention is: to determine whether the proportion of business requests that have touched the first security rule in the business request set reaches a preset first proportion; when the preset first proportion is reached, to wake up the security verification of the second security rule, and the security level of the second security rule is higher than the security level of the first security rule; to perform security verification of the first security rule and the second security rule on the received business request.

[0051] By waking up the second security rule with a higher security level when the proportion of business requests that have touched the first security rule reaches a first proportion, and performing security verification of multi-level security rules on the received business requests, the security verification of the business requests is more in line with the current network environment, ensuring the accuracy of the security verification of the business requests and improving the efficiency of the security verification of the business requests.

[0052] As an implementation solution, the security verification device can be Figure 1 shown.

[0053] The embodiment of the present invention relates to a security verification device, which includes a processor 101, such as a CPU, a memory 102, and a communication bus 103. The communication bus 103 is used to implement connection and communication between these components.

[0054] The memory 102 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. Figure 1 As shown, the memory 102 as a computer-readable storage medium may include a security verification program; and the processor 101 may be used to call the security verification program stored in the memory 102 and perform the following operations:

[0055] Determine whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset first proportion;

[0056] When a preset first ratio is reached, a security verification of a second security rule is activated, wherein the security level of the second security rule is higher than the security level of the first security rule;

[0057] Perform security verification of the first security rule and the second security rule on the received service request.

[0058] Based on the hardware architecture of the above-mentioned security verification device, an embodiment of the security verification method of the present invention is proposed.

[0059] Reference Figure 2 , Figure 2 This is a first embodiment of the security verification method of the present invention, and the security verification method includes the following steps:

[0060] Step S10 , determining whether the proportion of the business requests that have triggered the first security rule in the business request set reaches a preset first proportion.

[0061] Optionally, security rules are used to perform security verification on business requests to determine whether the business requests will cause attacks on the network. Security verification security rules are classified into multiple security levels. Taking three security levels as an example, but not limited to three security levels, the three security levels are primary security rules, intermediate security rules, and advanced security rules. Primary security rules may include honeypot traps, scanning tool detection, program detection, browser driver verification, etc.; intermediate security rules may include dynamic passwords, high-frequency restrictions, etc.; advanced security rules may include profiling analysis, behavior tracking, etc.

[0062] Optionally, the service request may be an HTTP (Hyper Text Transfer Protocol) request.

[0063] Optionally, the first security rule is a security rule in the security rule chain except for the security rule of the highest security level, for example, a primary security rule or an intermediate security rule.

[0064] Optionally, the service requests are grouped according to the regional information and traffic time period of the service requests. For example, the regional information corresponding to the service request is determined based on the IP address of the service request, where the regional information may be a province. The traffic time period corresponding to the service request is determined, where the traffic time period may be a low, medium, or high traffic time period. The service requests within traffic time period C are divided into service requests for Province A according to the regional information. The proportion of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in Province A that has triggered the first security rule verification is a1, and the set of service requests in Province A is a2, with a proportion of a1 / a2. The determination is made as to whether the proportion reaches a preset first ratio.

[0065] Optionally, the service requests are grouped according to their regional information. For example, the regional information corresponding to the service requests is determined based on their IP addresses. The regional information may be a province, and the service requests are divided into service requests for Province A. The proportion of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in Province A that has triggered the first security rule verification is b1, and the set of service requests in Province A is b2, with a proportion of b1 / b2. It is then determined whether the proportion reaches a preset first ratio.

[0066] Optionally, the service requests are grouped according to their traffic time periods. For example, the traffic time period corresponding to the service requests is determined, where the regional information may be low, medium, or high traffic time periods. The service requests in traffic time period C are grouped together. The ratio of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in traffic time period C that has triggered the first security rule verification is c1, and the set of service requests in traffic time period C is c2, with a ratio of c1 / c2. It is then determined whether the ratio reaches a preset first ratio.

[0067] Optionally, in a preset security rule chain, it is determined whether the proportion of business requests that have touched the first security rule in the business request set of the preset security rule chain reaches a preset first proportion. The security rule chain includes security rules of multiple security levels, and each security level security rule can correspond to one or more security sub-rules. Optionally, there can be one security rule chain. For example, the security rule chain A includes security rules of three security levels: primary security rules, intermediate security rules, and advanced security rules. The security sub-rules in the primary security rules include honeypot traps, program detection, and scanning tool detection. The security sub-rules in the intermediate security rules include high-frequency restrictions. The security sub-rules in the advanced security rules include behavior tracking. Optionally, there can be at least two security rule chains. For example, the security rule chain includes chain A and chain B. Chain A includes security rules of three security levels: primary security rules, intermediate security rules, and advanced security rules. The security sub-rules in the primary security rules include honeypot traps, program detection, and scanning tool detection. The security sub-rules in the intermediate security rules include high-frequency restrictions. The security sub-rules in the advanced security rules include behavior tracking. The B chain includes security rules at three security levels: primary security rules, intermediate security rules and advanced security rules. Among them, the security sub-rules in the primary security rules include driver inspection and program detection, the security sub-rules in the intermediate security rules include dynamic passwords, and the security sub-rules in the advanced security rules include portrait analysis.

[0068] Step S20: When the preset first ratio is reached, the security verification of the second security rule is activated, and the security level of the second security rule is higher than the security level of the first security rule.

[0069] Optionally, the preset first ratio may be dynamically changed according to current service request conditions.

[0070] Optionally, the security level of the second security rule is higher than that of the first security rule. For example, when the first security rule is a primary security rule, the second security rule is an intermediate security rule; when the first security rule is an intermediate security rule, the second security rule is a high security rule.

[0071] Optionally, when the protection system of the business system is started, one or more security rule chains will be initialized, as well as the trigger mechanism for waking up or sleeping for each security rule chain. Exemplarily, in the initialized security rule chain, the primary security rule is in the awakened state, and the intermediate security rule and the advanced security rule are temporarily in the dormant state. When a user accesses the business system, the business request wakes up the intermediate security rule when performing the security verification of the primary security rule. For example, the proportion of business requests that have touched the primary security rule in the business request set reaches a preset first proportion, and the intermediate security rule is awakened, and the security verification of the primary security rule and the intermediate security rule is performed on the business request received thereafter; if the intermediate security rule is not awakened, the security verification of the intermediate security rule and the advanced security rule is directly skipped, and the security verification of the primary security rule is performed on the received business request. When a business request is undergoing security verification of the intermediate security rules, the advanced security rules are awakened. If the proportion of business requests that have touched the intermediate security rules in the business request set reaches the preset first proportion, the advanced security rules are awakened, and the business requests received thereafter are subjected to security verification of the primary security rules, intermediate security rules, and advanced security rules. If the advanced security rules are not awakened, the security verification of the advanced security rules is skipped directly, and the received business requests are subjected to security verification of the primary security rules and intermediate security rules.

[0072] Optionally, the preset first ratios for awakening security rules of different security levels may be different. For example, in primary security rules, the preset first ratio for awakening intermediate security rules is b1; in intermediate security rules, the preset first ratio for awakening advanced security rules is b2. Optionally, b1≥b2.

[0073] Optionally, different business requests correspond to different security rule chains. Taking two security rule chains as an example, security rule chain A and security rule chain B, security rule chains A and B include primary security rules, intermediate security rules and advanced security rules, respectively.

[0074] Optionally, in security rule chain A, if the proportion of service requests that have triggered primary security rules in the service request set reaches a preset first ratio, such as 40%, then the intermediate security rules are activated for protection. In security rule chain A, if the proportion of service requests that have triggered intermediate security rules in the service request set reaches a preset first ratio, such as 20%, then the advanced security rules are activated for protection.

[0075] Optionally, in security rule chain B, if the proportion of service requests that have triggered primary security rules in the service request set reaches a preset first ratio, such as 30%, then the intermediate security rules are activated for protection. In security rule chain A, if the proportion of service requests that have triggered intermediate security rules in the service request set reaches a preset first ratio, such as 20%, then the advanced security rules are activated for protection.

[0076] Step S30: Perform security verification of the first security rule and the second security rule on the received service request.

[0077] Optionally, after receiving a business request, the pre-processed business request data is stored on disk and backed up to provide data support for subsequent model stability training and policy pool update tasks. At the same time, the received business request is security verified according to the corresponding security rules.

[0078] Optionally, after receiving a service request, all service requests within a preset time period are pre-processed, and group inspections are performed based on the regional information and / or traffic period of the service request. For example, the awakening of higher-level security rules in different regions does not affect each other. For example, the service request from Province A awakens the second security rule, and the service request received from Province A will be subject to security verification of the first security rule and the second security rule. However, the request from Province B does not awaken the second security rule, and all request inspections from Province B will not awaken the security verification of the second security rule, and the service request received from Province B will be subject to security verification of the first security rule.

[0079] In the technical solution of this embodiment, it is determined whether the proportion of business requests that have touched the first security rule in the business request set has reached a preset first proportion; when the preset first proportion is reached, the security verification of the second security rule is awakened, and the security level of the second security rule is higher than the security level of the first security rule; the received business request is subjected to security verification of the first security rule and the second security rule. By awakening the second security rule with a higher security level when the proportion of business requests that have touched the first security rule reaches the first proportion, the received business request is subjected to security verification of multi-level security rules, so that the security verification of the business request is more in line with the current network environment, the accuracy of the security verification of the business request is guaranteed, and the efficiency of the security verification of the business request is improved.

[0080] Reference Figure 3 , Figure 3 This is a second embodiment of the security verification method of the present invention, based on the first embodiment, and before step S10, further comprising:

[0081] Step S40, grouping historical service requests according to their area information and / or traffic time period;

[0082] Step S50, determining the proportion of historical service requests in the current group that have triggered the first security rule in the historical service request set of the current group;

[0083] Step S60, determining the number of wake-up times at which the ratio of historical business requests that have triggered the first security rule reaches a first target ratio, wherein the first target ratio is a plurality of ratios;

[0084] Step S70: determining a preset first ratio among a plurality of first target ratios according to the number of wake-up times.

[0085] Optionally, in order to reduce the frequency of continuously waking up higher-level security rules within a unit period and to more efficiently ensure the network security of the business system, it is necessary to find a balanced preset first ratio between the two to make the protection system stable.

[0086] Alternatively, historical business requests can be actual online business access data. Historical business requests are grouped according to regional information and / or traffic time periods to obtain a set of historical business requests. The data for a day is divided into peak, off-peak, and low-peak periods. After grouping according to each time period and / or regional information, each group of historical business requests is trained separately. Different groups of historical business requests can correspond to different training models, and each training model is trained separately based on various security rules, such as primary and intermediate security rules. For example, when training primary security rules, the first target ratios are set as "over 1% of requests hitting security rules," "over 2% of requests hitting security rules," ..., "over 98% of requests hitting security rules," and "99% of requests hitting security rules." A preset time interval is used as a time verification benchmark, for example, the preset time interval can be 1 minute. If a next-level security rule is woken up once within the preset time interval, the wakeup count is 1; otherwise, it is 0. For each first target ratio, within a preset time period, determine the number of wake-up times required for the percentage of historical business requests that have triggered the first security rule to reach the first target ratio. The preset time period includes multiple preset time intervals. For example, the preset time period is 10 minutes. For each first target ratio, the number of wake-up times can be the number of wake-up times corresponding to "over 1% of requests triggering the security rule," "over 2% of requests triggering the security rule," ..., "over 98% of requests triggering the security rule," and "over 99% of requests triggering the security rule," respectively.

[0087] Optionally, a preset first ratio is determined in the first target ratio based on the number of wake-ups, and the average number of wake-ups for each first target ratio in the preset time period is determined; the discrete degree of the wake-up number corresponding to each first target ratio is determined based on the average value; and the preset first ratio is determined in multiple first target ratios based on the discrete degree. Optionally, the preset first ratio is determined based on the first target ratio corresponding to the minimum discrete degree. For example, for the first target ratio of 1%, within a preset time period of 10 minutes, including 10 preset time intervals of 1 minute, 10 wake-up times can be obtained, for example, the wake-up times are h1 to h10, and the average value of the 10 wake-up times is calculated, for example, the average value Calculate the standard deviation of the number of wake-up times of the first target ratio based on the average value. For example, the standard deviation is By analogy, the standard deviation corresponding to each target ratio from 2% to 99% is obtained respectively, and the standard deviation is used to represent the discrete degree of the number of awakening times corresponding to each first target ratio.

[0088] Optionally, historical business requests are trained separately. Different groups of historical business requests can correspond to different training models. Each training model is trained separately according to the security rules of each security level to obtain a preset first ratio. For example, primary security rules and intermediate security rules are trained separately to obtain the corresponding preset first ratio. The training between training models does not affect each other, and the training between security rules of different security levels does not affect each other. For example, the training model is trained on the historical business requests of Province A. The trained model can predict the preset first ratio of the primary security rules of Province A.

[0089] Optionally, the first target ratio can be 1%, 2%...99%, that is, "the ratio of requests exceeding 1% that touch the safety rules", "the ratio of requests exceeding 2% that touch the safety rules", ..., "the ratio of requests exceeding 98% that touch the safety rules", "the ratio of requests exceeding 99% that touch the safety rules", and the first target ratio is represented by a curve, such as Figure 4As shown, curve a represents the "percentage of requests exceeding 10% that touch safety rules," curve b represents the "percentage of requests exceeding 20% ​​that touch safety rules," curve c represents the "percentage of requests exceeding 40% that touch safety rules," curve d represents the "percentage of requests exceeding 50% that touch safety rules," and curve e represents the "percentage of requests exceeding 60% that touch safety rules," etc. The average value of each curve is represented by Mn, i.e., M1, M2, M3...M98, M99. The mean values ​​of all curves are added together and divided by the number of curves to obtain the mean M of the entire set of business request data. The standard deviation calculation formula is used to determine the degree of dispersion of each line. The closer the standard deviation S of a line is to 0, the more stable the number of wake-up times for the next level of security rules on this line during this period. The first target ratio with the smallest degree of dispersion, i.e., the standard deviation close to 0, is used as the preset first ratio. For example, the standard deviation calculation formula is as follows:

[0090]

[0091] Where S represents the standard deviation of a certain security rule; n represents the number of time nodes; x n Represents the number of wake-up times corresponding to the current traffic period and / or area information; M represents the average value of the entire set of service request data.

[0092] Optionally, when the first security rule corresponds to multiple security sub-rules, the to-be-determined ratio corresponding to each security sub-rule is determined from multiple first target ratios based on the degree of dispersion of the wake-up counts corresponding to each security sub-rule. The preset first ratio is determined based on the weight value of each security sub-rule and the corresponding to-be-determined ratio. Exemplarily, the mean M of the wake-up counts for the multiple security sub-rules is determined, the standard deviations corresponding to the multiple security sub-rules are calculated, and the stable value of the standard deviation for the first security rule that is most close to 0 is obtained. The weighted average of the corresponding to-be-determined ratios is determined as the preset first ratio.

[0093] In the technical solution of this embodiment, historical business requests are grouped according to their regional information and / or traffic time period; the proportion of historical business requests in the current group that have triggered the first security rule in the current group's historical business request set is determined; the number of wake-up times at which the proportion of historical business requests that have triggered the first security rule reaches a first target ratio is determined, where the first target ratio is multiple; and based on the number of wake-up times, a preset first ratio is determined from the multiple first target ratios. This reduces the frequency of continuously waking up higher-level security rules within a unit cycle, and can more efficiently ensure the network security of the business system, making the protection system stable.

[0094] Reference Figure 5 , Figure 5This is a third embodiment of the security verification method of the present invention, based on the first or second embodiment, the method further includes:

[0095] Step S80, determining whether the proportion of the business requests that have triggered the first security rule in the business request set reaches a preset second proportion;

[0096] Step S90, when the preset second ratio is not reached, dormant the security verification of the second security rule;

[0097] Step S100: Perform security verification of the first security rule on the received service request.

[0098] Optionally, the service requests are grouped according to the regional information and traffic time period of the service requests. For example, the regional information corresponding to the service request is determined based on the IP address of the service request, where the regional information may be a province. The traffic time period corresponding to the service request is determined, where the regional information may be low, medium, or high traffic time periods. The service requests within traffic time period C are divided into service requests for Province A according to the province. The proportion of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in Province A that has triggered the first security rule verification is a1, and the set of service requests in Province A is a2, with a proportion of a1 / a2. It is then determined whether the proportion reaches a preset second ratio.

[0099] Optionally, the service requests are grouped according to their regional information. For example, the regional information corresponding to the service requests is determined based on their IP addresses. The regional information may be a province, and the service requests are divided into service requests for Province A. The proportion of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in Province A that has triggered the first security rule verification is b1, and the set of service requests in Province A is b2, with a proportion of b1 / b2. It is then determined whether the proportion reaches a preset second ratio.

[0100] Optionally, the service requests are grouped according to their traffic time periods. For example, the traffic time period corresponding to the service requests is determined, where the regional information may be low, medium, or high traffic time periods. The service requests in traffic time period C are grouped together. The ratio of the service requests in the current group that have triggered the first security rule verification to the set of service requests in the current group is determined. For example, the service request in traffic time period C that has triggered the first security rule verification is c1, and the set of service requests in traffic time period C is c2, with a ratio of c1 / c2. It is then determined whether the ratio reaches a preset second ratio.

[0101] Optionally, the preset second ratio is less than or equal to the preset first ratio.

[0102] Optionally, when the business system's protection system is started, one or more security rule chains are initialized, along with a trigger mechanism for waking up or dormant each security rule chain. For example, in the initialized security rule chain, primary security rules are awakened, while intermediate and advanced security rules are temporarily dormant. When a user accesses the business system, verification conditions for a higher security level may be activated. Over time, security verification for a higher security level may no longer be required, and in this case, the higher security level needs to be dormant.

[0103] Optionally, if the proportion of business requests that have touched the first security rule in the business request set does not reach the preset second proportion, the second security rule needs to be dormant, and the business requests are subject to security verification according to the first security rule, skipping the security verification according to the higher second security rule. Optionally, when the business requests are undergoing security verification according to the primary security rule and the intermediate security rule, if the proportion of business requests that have touched the primary security rule in the business request set does not reach the preset second proportion, the security verification according to the intermediate security rule can be dormant, and the security verification according to the primary security rule will be performed on the business requests received subsequently; if the proportion of business requests that have touched the primary security rule in the business request set reaches the preset second proportion, the security verification according to the intermediate security rule does not need to be dormant, and the security verification according to the primary security rule and the intermediate security rule will be performed on the business requests received subsequently. Optionally, when a business request is undergoing security verification of primary security rules, intermediate security rules, and advanced security rules, if the proportion of business requests that have touched the intermediate security rules in the business request set does not reach a preset second proportion, the security verification of the advanced security rules will be dormant, and the security verification of the intermediate security rules will be performed on the business requests received subsequently; if the proportion of business requests that have touched the primary security rules in the business request set reaches a preset second proportion, the security verification of the advanced security rules does not need to be dormant, and the security verification of the primary security rules, intermediate security rules, and advanced security rules will continue to be performed on the business requests received subsequently.

[0104] Optionally, the preset second ratios for dormant security rules of different security levels may be different. For example, the preset second ratio for dormant intermediate security rules is b1; the preset second ratio for dormant advanced security rules is b2. Optionally, b1≥b2.

[0105] Optionally, different business requests correspond to different security rule chains. Taking two security rule chains as an example, security rule chain A and security rule chain B, security rule chains A and B include primary security rules, intermediate security rules and advanced security rules, respectively.

[0106] Optionally, in security rule chain A, if the proportion of service requests that have triggered primary security rules in the service request set does not reach a preset second ratio, such as 40%, then the intermediate security rules are dormant. In security rule chain A, if the proportion of service requests that have triggered intermediate security rules in the service request set does not reach a preset second ratio, such as 20%, then the advanced security rules are dormant.

[0107] Optionally, in security rule chain B, if the proportion of service requests that have triggered primary security rules in the service request set does not reach a preset second ratio, such as 30%, then the intermediate security rules are dormant. In security rule chain B, if the proportion of service requests that have triggered intermediate security rules in the service request set does not reach a preset second ratio, such as 20%, then the advanced security rules are dormant.

[0108] In order to reduce the frequency of dormant higher-level security rules within a unit cycle and more efficiently ensure the network security of the business system, it is necessary to find a balanced preset second ratio between the two to make the protection system stable.

[0109] Optionally, historical business requests are grouped according to their regional information and / or traffic time periods; the number of dormancy times of historical business requests in the current group that have touched the first security rule and whose proportion in the historical business request set of the current group does not reach a second target ratio is determined, and the second target ratio is multiple; based on the number of dormancy times, a preset second ratio is determined among the multiple second target ratios.

[0110] Optionally, historical business requests can be real online business access data. Historical business requests are grouped according to regional information and / or traffic time periods to obtain a historical business request set. The data of one day is divided into peak period, off-peak period and low-peak period in units of days. After grouping according to each traffic period and / or regional information, each group of historical business requests is trained separately. Historical business requests in different groups can correspond to different training models. Each training model is trained separately according to each security rule, for example, primary security rules and intermediate security rules are trained separately. For example, when training primary security rules, the second target ratios are set as "over 1% of requests hitting the security rule," "over 2% of requests hitting the security rule," ..., "over 98% of requests hitting the security rule," and "over 99% of requests hitting the security rule." A preset time interval is used as a time verification benchmark. For example, the preset time interval can be 1 minute. If a security rule of the next level is dormant once within the preset time interval, the dormancy count is 1; otherwise, it is 0. For each first target ratio, within a preset time period, the number of dormancy counts during which the percentage of historical business requests that have hit the first security rule does not reach the second target ratio is determined. The preset time period includes multiple preset time intervals, for example, a preset time period of 10 minutes. For each first target ratio, the dormancy count can be the number of dormancy counts corresponding to "over 1% of requests hitting the security rule," "over 2% of requests hitting the security rule," ..., "over 98% of requests hitting the security rule," and "over 99% of requests hitting the security rule," respectively.

[0111] Optionally, a preset first ratio is determined in the second target ratio based on the number of sleep times, and the average number of sleep times for each second target ratio in the preset time period is determined; the discrete degree of the sleep times corresponding to each second target ratio is determined based on the average value; and the preset second ratio is determined in multiple second target ratios based on the discrete degree. Optionally, the preset second ratio is determined based on the second target ratio corresponding to the minimum discrete degree. For example, for the second target ratio of 1%, within a preset time period of 10 minutes, including 10 preset time intervals of 1 minute, 10 wake-up times can be obtained, for example, the wake-up times are h1 to h10, and the average value of the 10 wake-up times is calculated, for example, the average value Calculate the standard deviation of the number of wake-up times of the second target ratio based on the average value. For example, the standard deviation is By analogy, the standard deviation corresponding to each target ratio from 2% to 99% of the second target ratio is obtained respectively, and the standard deviation is used to represent the discrete degree of the number of awakening times corresponding to each second target ratio.

[0112] Optionally, historical business requests are trained separately. Different groups of historical business requests can correspond to different training models. Each training model is trained separately according to the security rules of each security level to obtain a preset second ratio. For example, primary security rules and intermediate security rules are trained separately to obtain the corresponding preset second ratio. The training between training models does not affect each other, and the training between security rules of different security levels does not affect each other. For example, the training model is trained on the historical business requests of Province A. The trained model can predict the preset second ratio of the primary security rules of Province A.

[0113] Optionally, the second target ratio can be 1%, 2%...99%, that is, "the ratio of requests exceeding 1% that touch the security rules", "the ratio of requests exceeding 2% that touch the security rules", ..., "the ratio of requests exceeding 98% that touch the security rules", "the ratio of requests exceeding 99% that touch the security rules", and the second target ratio is represented by a curve. The average value of each curve is represented by Mn, that is, M1, M2, M3...M98, M99, and the mean of all curves is added and divided by the number of curves to obtain the mean M of the entire set of business request data. The standard deviation calculation formula is used to determine the degree of dispersion of each line. If the standard deviation S of a line is closer to 0, it means that during this period, the number of awakenings of the next level of security rules on this line is more stable during this period. The second target ratio with the smallest degree of dispersion, that is, the standard deviation close to 0, is used as the preset second ratio. For example, the standard deviation calculation formula is as follows:

[0114]

[0115] Where S represents the standard deviation of a certain security level or security rule; n represents the number of time nodes; x n Represents the number of sleep times corresponding to the current traffic period and / or area information; M represents the average value of the entire set of business request data.

[0116] Optionally, when the first security rule corresponds to multiple security sub-rules, the to-be-determined ratio corresponding to each security sub-rule is determined from multiple second target ratios based on the degree of discreteness of the sleep times corresponding to each security sub-rule, and the preset second ratio is determined based on the weight value of each security sub-rule and the corresponding to-be-determined ratio. Exemplarily, the mean M of the wake-up times for the multiple security sub-rules is determined, the standard deviations corresponding to the multiple security sub-rules are calculated, and the stable value of the standard deviation for the first security rule that is most close to 0 is obtained. The weighted average of the corresponding to-be-determined ratios is determined as the preset second ratio.

[0117] In the technical solution of this embodiment, the next security level is put into hibernation by presetting a second ratio, and the hibernation conditions of each security level do not affect each other, so that the security verification of business requests is more in line with the current operating environment, ensuring the accuracy of business request security verification while improving the efficiency of business request security verification, which can not only ensure the security of online business, but also reduce the risks brought by the protection system to the business system.

[0118] In one embodiment, reference Figure 6 When a client initiates a service request, the protection system will first pre-process the service request. The service request data will be divided into two links. One link will store the pre-processed data on the disk, which is the data backup. This will provide data support for subsequent model stability training and policy pool update tasks. The model is trained based on the service request data to obtain a policy model. The policy model is used to determine whether to enable a higher level of verification or to put a higher level of verification in hibernation. The other link will enter the first level verification. Optionally, the first level verification is a security verification of the primary security rules. The policy pool is queried to see if the second level verification is enabled. Optionally, the second level verification is a security verification of the intermediate security rules. If the second level verification is not enabled, the verification will be terminated directly. If the second level verification is enabled, the service request will continue to be subjected to the second level verification and the policy pool will be queried to see if the third level verification is enabled. Optionally, the third level verification is a security verification of the advanced security rules. If the third level verification is not enabled, the verification will be terminated directly. If the third level verification is enabled, the service request will continue to be subjected to the third level verification, and so on.

[0119] The policy pool update process is as follows Figure 7 As shown, the protection system executes scheduled tasks every N minutes, based on the service access situation during the previous time period, using the most stable activation / sleep strategy provided by the stability training model to update the security policy information in the policy pool. The policy model determines whether to enable or disable level 2 verification based on regional information and traffic time groups. It also determines whether to enable or disable level 3 verification based on regional information and / or traffic time groups, and updates the policy pool.

[0120] Reference Figure 8 The present invention also proposes a security verification device, which includes:

[0121] A determination module 100 is configured to determine whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset first proportion;

[0122] A wake-up module 200 is configured to wake up the security verification of a second security rule when a preset first ratio is reached, wherein the security level of the second security rule is higher than the security level of the first security rule;

[0123] The verification module 300 is used to perform security verification of the first security rule and the second security rule on the received service request.

[0124] Optionally, the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset first proportion includes:

[0125] Grouping service requests according to their area information and / or traffic time period;

[0126] Determine the ratio of the service requests in the current group that have triggered the first security rule verification to the service request set of the current group;

[0127] It is determined whether the proportion of business requests that have triggered the first security rule verification has reached a preset first proportion.

[0128] Optionally, before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset first proportion, the step further includes:

[0129] Grouping historical service requests according to their region information and / or traffic time period;

[0130] Determine the proportion of historical service requests in the current group that have triggered the first security rule in the set of historical service requests in the current group;

[0131] Determine the number of wake-up times at which a ratio of historical business requests that have triggered a first security rule reaches a first target ratio, where the first target ratio is a plurality of ratios;

[0132] A preset first ratio is determined from a plurality of first target ratios according to the number of wake-up times.

[0133] Optionally, the step of determining a preset first ratio from a plurality of first target ratios according to the number of wake-up times includes:

[0134] Determining an average value of the number of wake-up times for each of the first target ratios in a preset time period;

[0135] determining a discrete degree of the number of wake-up times corresponding to each first target ratio according to the average value;

[0136] A preset first ratio is determined among a plurality of first target ratios according to the discrete degree.

[0137] Optionally, the step of determining a preset first ratio from a plurality of first target ratios according to the discreteness includes:

[0138] When there are multiple security sub-rules corresponding to the first security rule, determining the to-be-determined ratio corresponding to each security sub-rule among the multiple first target ratios according to the discrete degree of the wake-up times corresponding to each security sub-rule;

[0139] A preset first ratio is determined according to the weight value of each of the security sub-rules and the corresponding ratio to be determined.

[0140] Optionally, the device further comprises:

[0141] The dormancy module 400 is configured to determine whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset second proportion;

[0142] When the preset second ratio is not reached, the safety verification of the second safety rule is dormant;

[0143] Perform security verification of the first security rule on the received service request.

[0144] Optionally, before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset second proportion, the step further includes:

[0145] Grouping historical service requests according to their region information and / or traffic time period;

[0146] Determine the number of dormancy times during which the percentage of historical service requests that have triggered the first security rule in the current group does not reach a second target ratio in the set of historical service requests of the current group, where the second target ratio is multiple;

[0147] A preset second ratio is determined from a plurality of second target ratios according to the number of sleep times.

[0148] The present invention also provides a security verification device, which includes a memory, a processor, and a security verification program stored in the memory and executable on the processor. When the security verification program is executed by the processor, the various steps of the security verification method described in the above embodiment are implemented.

[0149] The present invention also provides a computer-readable storage medium, which stores a security verification program. When the security verification program is executed by a processor, the various steps of the security verification method described in the above embodiment are implemented.

[0150] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0151] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, system, article, or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, system, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, system, article, or device comprising the element.

[0152] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment system can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the existing technology, can be embodied in the form of a software product. The computer software product is stored in a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, parking management equipment, air conditioner, or network equipment, etc.) to execute the system described in each embodiment of the present invention.

[0153] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A security verification method, characterized in that: The security verification method includes: Determine whether the proportion of business requests that have touched the first security rule in the business request set reaches a preset first proportion, wherein the business requests are grouped according to the regional information and / or traffic time period of the business requests; determine the proportion of business requests that have touched the first security rule verification in the current group to the business request set of the current group; determine whether the proportion of business requests that have touched the first security rule verification reaches a preset first proportion, wherein multiple security levels are pre-set, and the preset first proportions of security rules awakening at different security levels are different; When a preset first ratio is reached, a security verification of a second security rule is activated, wherein the security level of the second security rule is higher than the security level of the first security rule; Perform security verification of the first security rule and the second security rule on the received service request.

2. The security verification method according to claim 1, wherein: Before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset first proportion, the method further includes: Grouping historical service requests according to their region information and / or traffic time period; Determine the proportion of historical service requests in the current group that have triggered the first security rule in the set of historical service requests in the current group; Determine the number of wake-up times at which a ratio of historical business requests that have triggered a first security rule reaches a first target ratio, where the first target ratio is a plurality of ratios; A preset first ratio is determined from a plurality of first target ratios according to the number of wake-up times.

3. The security verification method according to claim 2, wherein: The step of determining a preset first ratio from a plurality of first target ratios according to the number of wake-up times includes: Determining an average value of the number of wake-up times for each of the first target ratios in a preset time period; determining a discrete degree of the number of wake-up times corresponding to each first target ratio according to the average value; A preset first ratio is determined among a plurality of first target ratios according to the discrete degree.

4. The security verification method according to claim 3, wherein: The step of determining a preset first ratio from a plurality of first target ratios according to the discrete degree includes: When there are multiple security sub-rules corresponding to the first security rule, determining the to-be-determined ratio corresponding to each security sub-rule among the multiple first target ratios according to the discrete degree of the wake-up times corresponding to each security sub-rule; A preset first ratio is determined according to the weight value of each of the security sub-rules and the corresponding ratio to be determined.

5. The security verification method according to claim 1, wherein: The method further comprises: Determining whether the proportion of business requests that have triggered the first security rule in the business request set reaches a preset second proportion; When the preset second ratio is not reached, the safety verification of the second safety rule is dormant; Perform security verification of the first security rule on the received service request.

6. The security verification method according to claim 5, wherein: Before the step of determining whether the proportion of the service requests that have triggered the first security rule in the service request set reaches a preset second proportion, the method further includes: Grouping historical service requests according to their region information and / or traffic time period; Determine the number of dormancy times during which the percentage of historical service requests that have triggered the first security rule in the current group does not reach a second target ratio in the set of historical service requests of the current group, where the second target ratio is multiple; A preset second ratio is determined from a plurality of second target ratios according to the number of sleep times.

7. A security verification device, characterized in that: The safety verification device comprises: A determination module is used to determine whether the proportion of business requests that have touched the first security rule in the business request set reaches a preset first proportion, wherein the business requests are grouped according to the regional information and / or traffic time period of the business requests; determine the proportion of business requests that have touched the first security rule verification in the current group to the business request set of the current group; determine whether the proportion of business requests that have touched the first security rule verification reaches a preset first proportion, wherein multiple security levels are pre-set, and the preset first proportions of security rules awakening at different security levels are different; A wake-up module, configured to wake up the security verification of a second security rule when a preset first ratio is reached, wherein the security level of the second security rule is higher than the security level of the first security rule; The verification module is used to perform security verification of the first security rule and the second security rule on the received service request.

8. A security verification device, characterized in that: The security verification device includes a memory, a processor, and a security verification program stored in the memory and executable on the processor. When the security verification program is executed by the processor, the various steps of the security verification method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a security verification program, and when the security verification program is executed by a processor, each step of the security verification method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Verification security strategy dynamic updating method and system, server and storage medium

    CN108965343A