A method for secure access based on web middleware

By constructing and matching feature vectors of web middleware, the problem of lack of protection for middleware network access is solved, achieving higher access security and protection effect.

CN117040802BActive Publication Date: 2025-11-28HUANENG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310872879.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-17
Publication Date
2025-11-28
Estimated Expiration
2043-07-17

AI Technical Summary

Technical Problem

Currently, middleware-based network access lacks sufficient protection measures and is vulnerable to threats such as hackers and computer viruses, leading to information and property losses.

Method used

By using historical access records and access information based on web middleware, feature vectors are constructed to classify historical access records, determine the encryption method for each category, and match the current access request. If successful, feature extraction is performed; otherwise, access is denied. The feature vector of the current access request is constructed and matched with the feature vector of the historical access record. If successful, access is allowed; otherwise, access is denied.

Benefits of technology

It improves network access security by intercepting unauthorized access through multiple matching processes, thereby enhancing the system's protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117040802B_ABST
    Figure CN117040802B_ABST
Patent Text Reader

Abstract

The application provides a kind of based on web middleware's security access method, it is related to network access technical field, its method includes: obtaining based on web middleware's historical access record, determines the characteristic information of each historical access record, constructs corresponding feature vector;Classify historical access record, obtain the encryption mode of each class result;Current access request is obtained, and first matching is carried out with encryption mode, if matching is successful, the feature extraction of current access request is carried out, otherwise, this access is prohibited;Based on the extracted feature, the feature vector of current access request is constructed, and second matching is carried out with the feature vector of historical access record, if matching is successful, it is determined that access channel carries out access, otherwise, this access is prohibited, multiple interception accesses are carried out, and the security of access is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the network access technical field, in particular to a kind of safe access method based on Web middleware. BACKGROUND

[0002] Middleware is a kind of software between application system and system software, it includes a set of services to facilitate the interaction between software components.

[0003] At present, along with the continuous development of computer technology, network has become an indispensable part of people's life, brings a lot of convenience to people.But, network also has many threats, such as hacker, computer virus, etc., can bring immeasurable loss to information, property etc.At present, network access based on middleware lacks enough protection measures.

[0004] Therefore, the present application provides a kind of safe access method based on Web middleware. SUMMARY

[0005] The present application provides a kind of safe access method based on Web middleware, to construct corresponding feature vector by based on Web middleware's history access record and access information, classify history access record, determine the encryption mode of each class, match current access request with encryption mode, match successfully and extract features, otherwise, access is prohibited, according to the extracted features, construct feature vector, and match with the feature vector of history access record, match successfully and access, otherwise, access is prohibited, use two matching procedures, access is intercepted multiple times, improve the security of access.

[0006] The present application provides a kind of safe access method based on Web middleware, including:

[0007] Step 1: obtain the history access record based on Web middleware, determine the feature information of each history access record, construct corresponding feature vector;

[0008] Step 2: classify the history access record, obtain the encryption mode of each class result;

[0009] Step 3: obtain current access request, and first match with the encryption mode, if match successfully, extract features for current access request, otherwise, prohibit this access;

[0010] Step 4: based on the extracted features, construct the feature vector of current access request, and second match with the feature vector of history access record, if match successfully, determine access channel and access, otherwise, prohibit this access.

[0011] Preferably, the historical access records based on the Web middleware are acquired, feature information of each historical access record is determined, a corresponding feature vector is constructed, including:

[0012] The historical access records based on the Web middleware are acquired, the access process and device information of the access request device are determined;

[0013] According to the device information and the corresponding access process, the feature information of the corresponding historical access record is determined;

[0014] According to the feature information of the historical access record, a corresponding feature vector is constructed.

[0015] Preferably, the historical access records are classified, and the encryption mode of each category result is acquired, including:

[0016] According to the feature vector of the historical access record, the historical access records are classified;

[0017] According to the category-encryption table, the encryption mode of each category result is determined.

[0018] Preferably, the current access request is acquired, matched with the encryption mode, if the matching is successful, the current access request is feature extracted, otherwise, the access is prohibited, including:

[0019] The current access request is intercepted in a preset mode, the intercepted segment is preprocessed, and the feature value corresponding to the preprocessed segment is extracted;

[0020] The feature value is matched with the standard value of each encryption mode for the first time;

[0021] If there is an encryption mode with a first matching value greater than a first preset value, the matching is successful, and the current access request is decrypted based on the matched encryption mode;

[0022] The decrypted current access request is feature extracted;

[0023] Otherwise, the access is prohibited.

[0024] 9、Preferably, the feature value is matched with the standard value of each encryption mode for the first time, including:

[0025] ; wherein, The first matching value of the current access request and the encryption mode is represented. The first feature value of the current access request is represented. The first standard value of the encryption mode is represented. The number of feature values of the current access request is represented. ​​

[0026] Preferably, based on the extracted features, a feature vector of the current access request is constructed, and a second matching is performed with the feature vector of the historical access record. If the matching is successful, it is determined that the access channel is allowed to access, otherwise, the access is prohibited, comprising:

[0027] According to the feature frame selection model, the current access request is pre- framed to determine a pre-frame of the current access request, wherein the pre-frame includes a frame size and a frame color;

[0028] The pre-frame of the current access request is sorted by the first sorting result and the second sorting result, and based on the first sorting result and the second sorting result, a request level corresponding to the current access request is calculated;

[0029] ; wherein, represents a first importance value based on the first sorting result; represents a second importance value based on the second sorting result; represents the maximum number of frame color levels determined from all frame color level numbers ; represents the maximum number of frame size levels determined from all frame size level numbers ; represents the maximum number of frame size levels determined from all frame size level numbers ; represents the maximum number of frame size levels determined from all frame size level numbers ; represents the corresponding request level; represents the number of frame color levels; represents the number of frame size levels; represents the weight of the th frame color level; represents the weight of the th frame size level;

[0030] According to the request level, and based on a level-number mapping table, a required number of features of the request level is determined;

[0031] The extracted features are obtained and pre-analyzed to determine the importance of each extracted feature, and the extracted features are filtered according to the required number of features and the importance sorting;

[0032] Based on the feature points contained in each filtered feature and the feature representation of each feature point, a first representation vector is constructed and input into a blank tree to obtain a feature tree;

[0033] Based on the positional tracing relationship between the trunk and branches in the feature tree, the association relationship of different screening features is determined, and then the fusionability of different screening features is determined.

[0034] Based on the fusionability, the corresponding filtering features are fused to obtain fused features, and combined with the unfused features, a feature vector of the current access request is constructed.

[0035] Perform a second matching between the feature vector of the current access request and the feature vector of the historical access records;

[0036] ;in, This represents the second matching value between the feature vector of the current access request and the feature vector of the historical access record; This represents the first feature vector of the current access request. Each feature element; The first feature vector representing the historical access record Each feature element; This indicates the number of elements in the feature vector of the current access request; The number of feature elements in the feature vector of the historical access record; Indicates the symbol for the exponential function; This represents the error adjustment factor, and its value range is... ;

[0037] If the second matching value is greater than the second preset value, the matching is successful. Based on the feature vector of the historical access record, the access channel is determined and access is granted.

[0038] Otherwise, the access will be denied.

[0039] Preferably, features are acquired and pre-analyzed to determine the importance of each feature, including:

[0040] Pre-analyze the extracted features to determine the complexity of the corresponding extracted features;

[0041] Based on the complexity, the importance of the corresponding extracted features is determined, and the extracted features are ranked according to their importance.

[0042] Preferably, based on the positional origination relationship between the trunk and branches in the feature tree, the association relationship of different screening features is determined, and then the fusionability of different screening features is determined, including:

[0043] Obtain the structure of the trunk and branches in the feature tree, and determine the positional origin relationship of the trunk and branches in the feature tree;

[0044] Based on the location tracing relationship, the association relationship of the corresponding screening features is determined;

[0045] According to the correlation of different screening features, a strong correlation is determined;

[0046] According to the strong correlation, the fusibility of the corresponding screening features is determined.

[0047] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by the structure particularly pointed out in the written description and the accompanying drawings.

[0048] The technical solutions of the present application will be further described in detail below with the help of the accompanying drawings and examples. BRIEF DESCRIPTION OF DRAWINGS

[0049] The accompanying drawings are used to provide a further understanding of the present application, and constitute a part of the specification, together with the embodiments of the present application, used to explain the present application, and do not constitute a limitation of the present application. In the drawings:

[0050] Figure 1 A flowchart of a security access method based on Web middleware in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The preferred embodiments of the present application will be described below in conjunction with the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to explain and illustrate the present application, and do not constitute a limitation of the present application.

[0052] An embodiment of the present application provides a security access method based on Web middleware, as shown in Figure 1 The security access method based on Web middleware comprises the following steps:

[0053] Step 1: Obtain historical access records based on Web middleware, determine the feature information of each historical access record, and construct a corresponding feature vector;

[0054] Step 2: Classify the historical access records, and obtain the encryption mode of each type of result;

[0055] Step 3: Obtain a current access request, and perform a first matching with the encryption mode, if the matching is successful, perform feature extraction on the current access request, otherwise, prohibit the access;

[0056] Step 4: Based on the extracted features, construct a feature vector of the current access request, and perform a second matching with the feature vector of the historical access record, if the matching is successful, determine an access channel to access, otherwise, prohibit the access.

[0057] In the embodiment, the historical access record is a record determined by the server and including information such as an access object and an accessed object, the feature information is feature information of an access request device of the historical access record and feature information determined based on an access process, such as a network IP of the device, and the feature vector of the historical access record is (a, b, c), wherein a, b, and c are the feature information.

[0058] In the embodiment, the classification is classified according to the number of elements of the feature vector, for example, the feature vector (a, b, c) and the feature vector (a, b) are different categories, and the encryption mode is determined according to the category-encryption table.

[0059] In the embodiment, the first matching is matched according to the feature value of the current access request and the standard feature value of the encryption mode, and if there is an encryption mode with a first matching value greater than a first preset value, the matching is successful.

[0060] In the embodiment, the feature vector of the current access request is similar to the feature vector of the historical access record, the second matching is matched according to the elements of the feature vector of the current access request and the feature vector of the historical access record, and if there is a second matching value greater than a second preset value, the matching is successful, and the access channel is an access path obtained according to the historical access path of the matched historical access record.

[0061] The beneficial effects of the above technical solution are: based on the historical access record and access information of the Web middleware, a corresponding feature vector is constructed, the historical access record is classified, the encryption mode of each category is determined, the current access request is matched with the encryption mode, the feature extraction is performed if the matching is successful, otherwise, the access is prohibited, the feature vector is constructed according to the extracted feature, and the feature vector is matched with the feature vector of the historical access record, the access is performed if the matching is successful, otherwise, the access is prohibited, two matching programs are used to intercept the access multiple times, and the security of the access is improved.

[0062] The embodiment of the application provides a secure access method based on Web middleware, obtains historical access records based on Web middleware, determines feature information of each historical access record, and constructs a corresponding feature vector, including:

[0063] Obtain historical access records based on Web middleware, determine device information of an access request device and an access process;

[0064] Determine feature information of the corresponding historical access record according to the device information and the corresponding access process;

[0065] Construct a corresponding feature vector according to the feature information of the historical access record.

[0066] In this embodiment, the device information includes device model, device network IP, etc.

[0067] In this embodiment, the access process refers to the complete access process after the access request device sends an access request, such as a web browser-server (hardware)-web container-web application server-database server.

[0068] In this embodiment, the feature information refers to the feature information of the device information and the feature information of the access process, such as the network IP of the device and the servers experienced in the access process.

[0069] The beneficial effects of the above technical solution are: based on the historical access records and access information of the Web middleware, the device information and the access process of the access request device are determined, the corresponding feature information is determined, and the feature vector of the historical access record is constructed, which lays a foundation for subsequent vector matching.

[0070] The embodiment of the application provides a secure access method based on Web middleware, which classifies the historical access records and obtains the encryption mode of each result, including:

[0071] According to the feature vector of the historical access record, the historical access record is classified;

[0072] According to the category-encryption table, the encryption mode of each result is determined.

[0073] In this embodiment, the classification is classified according to the number of elements of the feature vector.

[0074] In this embodiment, the category-encryption table contains historical access records of different categories and different encryption modes, and is mainly used to determine the available encryption mode of the historical access records of different categories.

[0075] The beneficial effects of the above technical solution are: by classifying the historical access records, determining the encryption mode of each result based on the category-encryption table, and laying a foundation for subsequent first matching.

[0076] The embodiment of the application provides a secure access method based on Web middleware, which obtains a current access request and matches the encryption mode, if the matching is successful, extracts features of the current access request, otherwise, prohibits the access, including:

[0077] The current access request is intercepted in a preset mode, the intercepted segment is preprocessed, and the feature value corresponding to the preprocessed segment is extracted;

[0078] The feature value is matched with the standard value of each encryption mode for the first time;

[0079] If the first matching value is greater than the first preset value, the matching is successful, and the current access request is decrypted based on the matched encryption mode;

[0080] The decrypted current access request is feature extracted;

[0081] Otherwise, the access is prohibited.

[0082] In this embodiment, the preset mode is set in advance, which can be intercepted according to a preset character number, the preprocessing is to characterize the intercepted segment, and the feature value is a feature value corresponding to the feature of the preprocessed segment.

[0083] In this embodiment, the first preset value is set in advance, which can be 0.9.

[0084] In this embodiment, the decryption is performed according to the encryption-decryption table, the encryption-decryption table contains different encryption modes and decryption modes, and is mainly used to determine the corresponding decryption mode for the encryption mode.

[0085] In this embodiment, the feature extraction is performed according to the request device feature and request mode of the current access request.

[0086] The beneficial effects of the above technical solution are: the current access request is intercepted and processed, the feature value is determined, and the standard value of the encryption mode is matched, the feature extraction is performed if the matching is successful, otherwise, the access is prohibited, the access request is intercepted through the encryption mode, and the security of the access is improved.

[0087] 10. The embodiment of the application provides a secure access method based on a Web middleware, first matching is performed according to the feature value and the standard value of each encryption mode, and the method comprises the following steps:

[0088] ; wherein, The first matching value of the current access request and the encryption mode is represented by M (x, y) ; The first feature value of the current access request is represented by x i ; The first standard value of the encryption mode is represented by y i ; The number of feature values of the current access request is represented by n. The beneficial effects of the above technical solution are: the feature value of the current access request is matched with the standard value of the encryption mode, which lays a foundation for subsequent security interception.

[0089]

[0090] ​​The embodiment of the application provides a security access method based on a Web middleware, based on extracted features, a feature vector of a current access request is constructed, and a second matching is performed on the feature vector of the current access request and a feature vector of a historical access record, if the matching is successful, it is determined that an access channel is accessed, otherwise, the access is prohibited, comprising:

[0091] According to the feature frame selection model, the current access request is pre-frameselected to determine a pre-selected frame of the current access request, wherein the pre-selected frame comprises a frame size and a frame color;

[0092] The pre-selected frame of the current access request is first sorted by frame color and second sorted by frame size, and based on the first sorting result and the second sorting result, a request level corresponding to the current access request is calculated;

[0093] ; wherein, represents a first important value based on the first sorting result; represents a second important value based on the second sorting result; represents a frame color level in a maximum number determined from all frame color level numbers ; represents a maximum level of the frame color determined based on the first sorting result; represents a frame size level in a maximum number determined from all frame size level numbers ; represents a maximum level of the frame size determined based on the second sorting result; represents a corresponding request level; represents a frame color level number; represents a frame size level number; represents the weight of the frame color level; represents the weight of the frame size level;

[0094] According to the request level, and based on a level-number mapping table, a required feature number of the request level is determined;

[0095] Extracted features are obtained and pre-analyzed to determine the importance of each extracted feature, and the extracted features are screened according to the required feature number and the importance sorting;

[0096] Based on feature points contained in each screened feature and feature representations of each feature point, a first representation vector is constructed and input into a blank tree to obtain a feature tree;

[0097] Determine the association of different screening features based on the position tracing relationship between the trunk and branches in the feature tree, and further determine the fusibility of different screening features;

[0098] Fuse the corresponding screening features according to the fusibility, obtain the fused features, and construct the feature vector of the current access request in combination with the unfused features;

[0099] Secondly, match the feature vector of the current access request with the feature vector of the historical access record;

[0100] ; wherein, represents the second matching value of the feature vector of the current access request and the feature vector of the historical access record; represents the i-th feature element in the feature vector of the current access request; represents the i-th feature element in the feature vector of the historical access record; represents the i-th feature element in the feature vector of the historical access record; represents the number of elements in the feature vector of the current access request; represents the number of feature elements in the feature vector of the historical access record; represents the exponential function symbol; represents the error adjustment coefficient, and the value range is ;

[0101] If the second matching value is greater than the second preset value, it is determined that the matching is successful, and the access channel is determined to be accessed according to the matched feature vector of the historical access record.

[0102] Otherwise, the access is prohibited.

[0103] In this embodiment, the feature frame selection model is set in advance, and the purpose is to select the feature frame of the current access request. According to the different features of the access request, the preselected frame also has different colors and sizes.

[0104] In this embodiment, the first sorting is to arrange all frame colors in red, orange, yellow, green, blue, indigo and purple, and the second sorting is to arrange the frame sizes from large to small.

[0105] In this embodiment, the level-number mapping table contains different request levels and required feature numbers, and the purpose is to determine the feature number according to the request level.

[0106] ​In this embodiment, the pre-analysis refers to analyzing the extracted features, determining the dimensionality contained in the extracted features, and taking the dimensionality as the complexity of the corresponding extracted feature. For example, the extracted feature 1 contains the physical address and network address of the access device, the dimensionality is 2 dimensions, and the importance is determined according to the ratio of the complexity to the maximum complexity. For example, the complexity is 2, the maximum complexity is 5, and the importance of the corresponding extracted feature is 0.4. For example, the required number of features is 5, and the importance ranking is arranged in descending order of importance. The importance ranking is extracted feature 1, extracted feature 3, extracted feature 5, extracted feature 4, extracted feature 6, extracted feature 8, extracted feature 9, and extracted feature 7. The top 5 extracted features are extracted feature 1, extracted feature 3, extracted feature 5, extracted feature 4, and extracted feature 6.

[0107] In this embodiment, the feature representation refers to the coordinate representation of the corresponding feature point, and the feature tree is obtained by inputting the corresponding screening feature into the blank tree according to the corresponding feature representation.

[0108] In this embodiment, the position tracing relationship refers to the position flow direction of the trunk and branches determined according to the structure of the trunk and branches. For example, the position tracing relationship of branch 1 and the trunk is that branch 1 needs to pass through branch 2 and branch 3 to reach the trunk. The association relationship is that the screening feature corresponding to branch 1 and the screening feature corresponding to branch 2 have a direct association relationship, and the screening feature corresponding to branch 1 and the screening feature corresponding to branch 3 have an indirect association relationship. The fusing property is determined according to the proportion of the overlapping part between the screening features. For example, the proportion of the overlapping part between screening feature 1 and screening feature 2 is 50%, and the fusing property of screening feature 1 and screening feature 2 is 50%.

[0109] In this embodiment, the fused feature is obtained by fusing the overlapping or intersecting part of the corresponding screening feature according to the fusing property greater than the preset fusing property. The preset fusing property is set in advance and can be 80%. The feature vector of the current access request is [fused feature 1 fused feature 2... un-fused feature 01 un-fused feature 02...].

[0110] In this embodiment, the second preset value is set in advance and can be 0.95.

[0111] The beneficial effects of the above technical solution are: by pre-framing the current access request, determining the request level of the current access request, and then determining the required number of features, and based on the importance of the extracted features, screening the extracted features, constructing a feature tree with the screening features, determining the fusing property of different screening features for fusion, and constructing a feature vector of the current access request with the fused features, and matching the feature vector with the historical access record, the security of the access is improved.

[0112] The embodiment of the present application provides a kind of based on Web middleware's security access method, obtains extraction feature and carries out pre-analysis, determines the importance of each extraction feature, including:

[0113] Pre-analysis is carried out to extraction feature, and the complexity of corresponding extraction feature is determined;

[0114] According to the complexity, the importance of corresponding extraction feature is determined, and based on the importance, the importance of extraction feature is sorted.

[0115] The beneficial effects of the above technical solution are: by analyzing extraction feature, the complexity of extraction feature is determined, and then the importance of extraction feature is determined, and the importance is sorted, which lays a foundation for subsequent extraction feature screening.

[0116] The embodiment of the present application provides a kind of based on Web middleware's security access method, determines the association relationship of different screening features based on the position tracing relationship of trunk and branch in the feature tree, and then determines the fusibility of different screening features, including:

[0117] The structure of trunk and branch in the feature tree is obtained, and the position tracing relationship of trunk and branch in the feature tree is determined;

[0118] Based on the position tracing relationship, the association relationship of corresponding screening feature is determined;

[0119] According to the association relationship of different screening features, strong association relationship is determined;

[0120] According to the strong association relationship, the fusibility of corresponding screening feature is determined.

[0121] In the embodiment, strong association relationship refers to the association relationship in which association exceeds preset association, and the preset association is set by extraction.

[0122] The beneficial effects of the above technical solution are: by the structure of trunk and branch in the feature tree, the position tracing relationship of trunk and branch is determined, and then the association relationship of corresponding screening feature is determined, the strong association relationship is determined, and the fusibility of corresponding screening feature is determined, which lays a foundation for subsequent construction of the feature vector of current access request.

[0123] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A method for secure access based on Web middleware, characterized in that, The method comprises the following steps: Step 1: obtaining historical access records based on Web middleware, determining feature information of each historical access record, and constructing a corresponding feature vector; Step 2: classifying the historical access records and obtaining an encryption method of each class of results; Step 3: obtaining a current access request, performing a first matching with the encryption method, if the matching is successful, performing feature extraction on the current access request, otherwise, prohibiting the access; and Step 4: based on the extracted features, constructing a feature vector of the current access request, and performing a second matching with the feature vector of the historical access record, if the matching is successful, determining an access channel for access, otherwise, prohibiting the access, comprising: performing pre-framing on the current access request according to a feature frame selection model to determine a pre-frame of the current access request, wherein the pre-frame comprises a frame size and a frame color; ; wherein, represents a first importance value based on the first ranking result; represents a second importance value based on the second ranking result; represents a maximum number of box color levels determined from all box color level numbers box color levels under the maximum number represents a maximum level of box color determined based on the first ranking result; represents a maximum number of box size levels determined from all box size level numbers box size levels under the maximum number represents a maximum level of box size determined based on the second ranking result; represents a corresponding request level; represents a number of box color levels; represents a number of box size levels; represents a weight of the th box color level; represents a weight of the th box size level;​​ performing a first sorting of the frame color and a second sorting of the frame size on the pre-frame of the current access request, and based on the first sorting result and the second sorting result, calculating a request level of the corresponding current access request; determining a required number of features of the request level based on a level-number mapping table according to the request level; extracting features and performing pre-analysis to determine the importance of each extracted feature, and filtering the extracted features according to the required number of features and the importance; based on the feature points contained in each filtered feature and the feature representation of each feature point, constructing a first representation vector and inputting it into a blank tree to obtain a feature tree; determining the association relationship of different filtered features based on the position tracing relationship of the trunk and branches in the feature tree, and further determining the fusibility of different filtered features; based on the fusibility, fusing the corresponding filtered features to obtain fused features, and combining the unfused features to construct a feature vector of the current access request; ; wherein, represents a second matching value of the feature vector of the current access request and the feature vector of the historical access record; represents the i-th feature element in the feature vector of the current access request; represents the i-th feature element in the feature vector of the historical access record; represents the i-th feature element in the feature vector of the current access request; represents the i-th feature element in the feature vector of the historical access record; represents the number of elements in the feature vector of the current access request; represents the number of feature elements in the feature vector of the historical access record; represents the exponential function symbol; represents an error adjustment coefficient, and the value range is ; performing a second matching of the feature vector of the current access request with the feature vector of the historical access record; if the second matching value is greater than a second preset value, it is determined that the matching is successful, and the access channel is determined for access according to the matched feature vector of the historical access record; 2. The method for secure access based on Web middleware according to claim 1, wherein, otherwise, the access is prohibited. Obtaining historical access records based on Web middleware, determining feature information of each historical access record, and constructing a corresponding feature vector, comprising: obtaining historical access records based on Web middleware, determining device information of an access process and an access request device; determining feature information of the corresponding historical access record according to the device information and the corresponding access process; 3. The method for secure access based on Web middleware of claim 1, wherein, constructing a corresponding feature vector according to the feature information of the historical access record. Classifying the historical access records and obtaining an encryption method of each class of results, comprising: classifying the historical access records according to the feature vectors of the historical access records; 4. The method for secure access based on Web middleware of claim 1, wherein, determining the encryption method of each class of results according to a class-encryption table. Obtaining a current access request, matching with the encryption method, if the matching is successful, performing feature extraction on the current access request, otherwise, prohibiting the access, comprising: performing a preset mode interception on the current access request, pre-processing the intercepted segment, and extracting feature values corresponding to the pre-processed segment; According to the characteristic value and the standard value of each encryption mode, first matching is performed; If there is an encryption mode with a first matching value greater than a first preset value, the matching is successful, and the current access request is decrypted based on the matched encryption mode; Feature extraction is performed on the decrypted current access request; Otherwise, the access is prohibited.

5. The method for secure access based on Web middleware of claim 4, wherein, According to the characteristic value and the standard value of each encryption mode, first matching is performed, including: ; wherein, represents a first matching value of the current access request and the encryption method; represents a first characteristic value of the current access request; represents a first characteristic value of the current access request; represents a first standard value of the encryption method; represents a first standard value of the encryption method; represents the number of characteristic values of the current access request.

6. The method for secure access based on Web middleware of claim 1, wherein, The extracted features are obtained and pre-analyzed to determine the importance of each extracted feature, including: The extracted features are pre-analyzed to determine the complexity of the corresponding extracted features; According to the complexity, the importance of the corresponding extracted features is determined, and the extracted features are sorted based on the importance.

7. The method for secure access based on Web middleware of claim 1, wherein, Based on the location tracing relationship between the trunk and branches in the feature tree, the association relationship between different screening features is determined, and the fusibility of different screening features is determined, including: The structure of the trunk and branches in the feature tree is obtained, and the location tracing relationship between the trunk and branches in the feature tree is determined; Based on the location tracing relationship, the association relationship between the corresponding screening features is determined; According to the association relationship between different screening features, a strong association relationship is determined; According to the strong association relationship, the fusibility of the corresponding screening features is determined.

Citation Information

Patent Citations

  • Cache utilization system and method of web cluster

    CN109165096A

  • Abnormal access detection method and device, electronic equipment and storage medium

    CN114244618A