A control method and device for the access frequency of distributed network users

By dynamically updating the observation and banning user list in a distributed system, the real-time and in-depth analysis of the access frequency control of distributed systems in a high concurrency environment is solved, efficient and flexible access frequency control is achieved, and the system availability and multi-layer management capabilities are improved.

CN119363490BActive Publication Date: 2025-05-30BEIJING CHAITIN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411933375.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-30
Estimated Expiration
2044-12-26

AI Technical Summary

Technical Problem

The existing distributed system access frequency control technology is difficult to achieve real-time control in high-concurrency and high-traffic environments, and lacks in-depth analysis of attacking users, resulting in poor multi-level control effects in the system.

Method used

By receiving threat information reported by the proxy server node at the controller node, combining the user traffic sampling information of the observation user list, generating a hash table, identifying whether the user should be maintained, added, removed or blocked, dynamically update the observation and blocked user list, and issuing it to the proxy server node for execution.

Benefits of technology

It realizes multi-dimensional and in-depth analysis of access traffic with low memory footprint and high real-time, improves the system availability and multi-layer management capabilities, and reduces data consistency conflicts and memory overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363490B_ABST
    Figure CN119363490B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for controlling the access frequency of distributed network users, which relates to the field of network security technology. The method includes: receiving threat information reported by each proxy server node in the network; sending the list of blocked users to all proxy server nodes, and generating a hash table with the user ID as the keyword and the user traffic sampling information as the value; traversing the hash table to determine whether the user should be maintained in the list of observed users, added to the list of observed users, removed from the list of observed users, or blocked; sending the latest list of observed users and the latest list of blocked users to all proxy server nodes. The present invention can perform multi-dimensional and in-depth analysis on access traffic on the premise of low memory occupancy and high real-time performance, and provide a more friendly and flexible deployment method to improve the availability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method and device for controlling the access frequency of distributed network users. Background Art

[0002] The system access frequency control in network security technology observes or restricts users who access the system too frequently or maliciously. The access frequency control can be simply divided into two types: single-machine and distributed. The implementation of single-machine access frequency control is relatively simple and does not require synchronizing the consistency of user data. In the case of low single-machine traffic, access frequency control can be completely achieved through simple statistical algorithms. The access frequency control of distributed systems is relatively more complex. Currently, it is mainly achieved through simple reporting of access times. For example, the rolling time windows of all proxy server nodes are unified, and the user access times are regularly reported to a certain core system for warning or handling.

[0003] The need for access frequency control exists more in high-concurrency and high-traffic distributed systems. For distributed systems, the reporting of rolling time windows by all nodes lacks real-time performance and is often difficult to resist short-term burst traffic. When further adopting a sliding window, it will bring the problem of difficult data synchronization because it is difficult to make the reported sliding time windows consistent in the time interval. In addition, the existing distributed system access frequency control technology lacks in-depth analysis of attacking users, such as features in the time dimension, space dimension, attack feature dimension, and features generated by the combination of these dimensions. The lack of such in-depth analysis is not conducive to the multi-level management and control of the system. Summary of the Invention

[0004] In view of the above-mentioned defects or deficiencies in the prior art, the present invention provides a method and device for controlling the access frequency of distributed network users, which can perform multi-dimensional and in-depth analysis on access traffic on the premise of low memory occupancy and high real-time performance, and provide a more friendly and flexible deployment method to improve the availability of the system.

[0005] One aspect of the present invention provides a method for controlling the access frequency of distributed network users for a controller node, including: receiving threat information reported by each proxy server node in the network, where the threat information includes user traffic sampling information of users not on the observed user list, user traffic sampling information of users on the observed user list, and the banned user list; sending the banned user list to all proxy server nodes, and at the same time merging the user traffic sampling information of the observed user list reported by each proxy server node to obtain a hash table with the user ID as the key and the user traffic sampling information as the value; traversing the hash table to identify whether the user is on the current observed user list, and judging whether the user should be maintained on the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result to obtain the latest observed user list and the latest banned user list; sending the latest observed user list and the latest banned user list to all proxy server nodes, so that each proxy server node takes effect the banning action according to the latest banned user list, and stores the latest observed user list in the local memory to wait for reporting again.

[0006] Another aspect of the present invention provides a device for controlling the access frequency of distributed network users for a controller node, including:

[0007] A receiving module, configured to receive threat information reported by each proxy server node in the network, where the threat information includes user traffic sampling information of users not on the observed user list, user traffic sampling information of users on the observed user list, and the banned user list;

[0008] A hash table generation module, configured to send the banned user list to all proxy server nodes, and at the same time merge the user traffic sampling information of the observed user list reported by each proxy server node to obtain a hash table with the user ID as the key and the user traffic sampling information as the value;

[0009] A user list generation module, configured to traverse the hash table to identify whether the user is on the current observed user list, and judge whether the user should be maintained on the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result to obtain the latest observed user list and the latest banned user list;

[0010] A data sending module, configured to send the latest observed user list and the latest banned user list to all proxy server nodes, so that each proxy server node takes effect the banning action according to the latest banned user list, and stores the latest observed user list in the local memory to wait for reporting again.

[0011] The method and device for controlling the access frequency of distributed network users provided by the present invention have the following beneficial effects:

[0012] (1) Low memory overhead. Since there is no need to fully synchronize the sliding time window and the corresponding data structures (such as hash tables) among all nodes, there are almost no data consistency conflict problems among nodes. At the same time, each node only maintains the user access information of its own forwarded traffic and does not need to maintain replicas, greatly reducing the memory overhead;

[0013] (2) High response speed. For proxy server nodes not disposed by iptables, queries at the log n level can be achieved, and nodes disposed by iptables do not need to be processed at the application layer, resulting in faster speeds.

[0014] (3) High accuracy. Whether it is global disposal or local disposal, there will be no false alarms. Only information may be lost when nodes report, or very few traffic may be missed when estimating user access frequencies, that is, traffic in a critical state needs to wait for the next round of reporting, but this kind of traffic itself does not impose much pressure on the system.

[0015] (4) Easy scalability and good fault tolerance. Each proxy server node can be deployed arbitrarily and communicate with each other. If reported information is lost, it will not cause false alarms and will not affect normal operations.

[0016] (5) Achieve multi-dimensional and in-depth analysis of access traffic, which helps the system to conduct multi-level control. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives and advantages of the present application will become more obvious:

[0018] Figure 1 is a schematic flowchart of a method for controlling the access frequency of distributed network users provided by an embodiment of the present application;

[0019] Figure 2 is a schematic structural diagram of a device for controlling the access frequency of distributed network users provided by an embodiment of the present application;

[0020] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0022] The terms used in the embodiments of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The singular forms "a", "said", and "the" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.

[0023] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present invention to describe the acquisition modules, these acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.

[0024] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detected (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detected (stated condition or event)" or "in response to detecting (stated condition or event)".

[0025] It should be noted that the orientation terms such as "upper", "lower", "left", "right", etc. described in the embodiments of the present invention are described from the angles shown in the drawings and should not be construed as limiting the embodiments of the present invention. In addition, in the context, it should also be understood that when it is mentioned that one element is formed "on" or "under" another element, it can not only be directly formed "on" or "under" another element, but also be indirectly formed "on" or "under" another element through an intermediate element.

[0026] The nodes of the distributed service system can be divided into proxy server nodes and controller nodes. At the same time, the distributed service system also depends on some cache clusters such as redis, etc. The proxy server nodes and the controller nodes do not conflict, so they can be deployed on the same device. The proxy server nodes are used to forward or count the service traffic, and the controller nodes are used to synchronize information and issue rules.

[0027] The traffic handling strategies of the distributed service system are divided into local handling and global handling. Global access frequency control is applicable to scenarios where it is necessary to strictly control the access frequencies of all interfaces, such as preventing DDoS attacks and protecting system resources, etc. Local access frequency control is applicable to scenarios where it is only necessary to control the frequencies of specific interfaces, such as certain sensitive operations or high-traffic interfaces. By reasonably configuring global and local access frequency controls, the system security can be effectively protected, malicious attacks can be prevented, and at the same time, the user experience and system performance can be optimized.

[0028] When the client uses the consistent hashing algorithm for load balancing, only local handling is used. When the client uses a non-consistent hashing algorithm, both local handling and global handling take effect, and a user may be intercepted due to local handling or global handling. The method and device for controlling the access frequency of distributed network users according to the present invention are applicable to the case of non-consistent hashing algorithms.

[0029] See Figure 1 , an embodiment of the present application provides a method for controlling the access frequency of distributed network users. This method is a process in which the controller node receives the reported information of all proxy server nodes, performs centralized processing, and issues new blocking rules, including the following steps:

[0030] Step S101, receiving the threat information reported by each proxy server node in the network. The threat information includes user traffic sampling information of users not on the observed user list, user traffic sampling information of users on the observed user list, and the blocked user list.

[0031] Specifically, each proxy server node in the distributed service system reports threat information to the controller node. Among them, the threat information includes user traffic sampling information of users not on the observed user list, user traffic sampling information of users on the observed user list, and the blocked user list. Among them, non-observed users refer to users who have not been found to be threatened and are not on the observed user list; observed users refer to users who have threats but are not serious enough to be blocked and are on the observed user list; blocked users refer to users who have triggered the threat threshold (such as the access frequency reaching the threshold) and have been blocked. Some proxy server nodes have performed local or global handling on some users before, so some users have been included in the observed user list and / or the blocked user list, and these lists will be transmitted to the controller node in the next report. Further, the user sampling information of the observed user list / non-observed user list includes, but is not limited to, access information such as the observed list / non-observed list IP, timestamp, request body, request header, etc. The reported blocked user list includes the blocked list of local handling, which is used to synchronize the blocked status of the entire network and avoid the occasional failure of blocking.

[0032] Exemplarily, assume that it is the nth second of the system time now, and a certain proxy server node is required to report threat information. Then, the information in the interval [n - k, n] is taken to construct a max heap (a max heap is a binary tree, which can be functionally understood as an ordered queue sorted from largest to smallest according to the value of the key). The first p bits of the max heap are taken out, and the size of the k value is also reported together. These reported information are called sampling information.

[0033] Among them, the k value is the reporting time interval of the proxy server node. The reporting time interval k of each proxy server node is determined based on the time point of the last report, the preset maximum reporting cycle, the preset minimum reporting cycle, the node load and the node CPU processing speed. The loop will not be executed if the conditions are not met. When the CPU processing of the entire node is fast enough, nk is the time of the last report. If the load is particularly high, the CPU will not be able to handle it. At this time, the proxy server node will choose to report only part of it. For example, the last time was the 10th second, and the current time is the 20th second. If the load is too high, it may only report threat information in the interval [15, 20].

[0034] The p value is the effectiveness of the information reported by each node, which is issued by the controller node and depends on the generation

[0035] The validity of the information previously reported by the proxy server node. The higher the validity of the p value, the more likely it is that this node is frequently visited by attackers, or that this node has more traffic than other nodes. The higher the validity of the p value, the more traffic this node should randomly sample. If more than the first predetermined proportion of users in the threat information reported by each proxy server node are banned, the validity p of the information reported by the proxy server node is increased; if less than the second predetermined proportion of users in the threat information reported by each proxy server node are banned, the validity of the information reported by the proxy server node is lowered; the validity of the information reported by the proxy server node is used to determine the proportion of the threat information reported by the proxy server node each time to all threat information in the reporting period. Exemplarily, if more than 10% (not limited to this example) of users in a batch of sampled information reported by a node are banned, then the p value of this node should increase; if less than 1% (not limited to this example) of users in the reported sampled information are banned, then the p value of this node should decrease; if the banned users are between 1% and 9% (not limited to this example), the p value does not change. The specific range of p-value changes can be calculated by the following formula:

[0036] p = p + (percentage of banned users - 10%) k p, when the percentage of banned users > 10%; p = p - (1% - percentage of banned users) k p, when the percentage of banned users is < 1%;

[0037] Among them, the k value can be 0.1.

[0038] Step S102: Send the banned user list to all proxy server nodes, and merge the user traffic sampling information of the observed user list reported by each proxy server node to obtain a hash table with user ID as the keyword and user traffic sampling information as the value.

[0039] Specifically, the controller node synchronizes the blocked list to the redis cluster, generates the blocking rules for the users in the blocked list, and distributes the blocked list and the blocking rules to all proxy server nodes. The controller node needs to integrate the reported information of all proxy server nodes, merge the sampling information and the observed user list of all proxy server nodes, and generate a total table of the observed list. The total table of the observed list is a hash table with the user ID as the key and the user traffic sampling information as the value, and the total table of the observed list is distributed to each proxy server node. Among them, the user ID can be a certain field value in the HTTP header or Cookies, or the user's socket ip, or the first value of the X-Forwarded-For field, which can be set according to needs and the customer environment.

[0040] In step S103, traverse the hash table to identify whether the user is in the current observed user list, and judge whether the user should be maintained in the observed user list, added to the observed user list, removed from the observed user list, or blocked according to the identification result, so as to obtain the latest observed user list and the latest blocked user list.

[0041] Specifically, for each user, traverse the generated hash table to judge whether the user is an observed user, and then calculate the access frequency and threat level of the user. The specific judgment process is as follows:

[0042] In step S1031, if it is traversed through the hash table and confirmed that the user is not in the current observed user list, then calculate the access frequency of the user according to the following formula :

[0043] = sum(c) / avg(k)

[0044] where c is the number of times the user accesses, k is the reporting time interval of the proxy server node, sum() represents summation, and avg() represents averaging;

[0045] Then calculate the access frequency threshold according to the following formula _threshold:

[0046] _threshold = P / Q

[0047] where P represents the highest value of the number of user accesses within the specified time in the set blocking policy; Q represents the specified time in the set blocking policy;

[0048] If the access frequency of the user is greater than or equal to the access frequency threshold _threshold, and if k is greater than or equal to Q, then directly include this user in the list of banned users; if the access frequency of the user is greater than or equal to the access frequency threshold which is the product of _threshold and coefficient a, and coefficient a is less than 1, then add this user to the list of observed users according to the rule, and cache the total number of previous accesses sum(c) of this user and the average value avg(k) of the reporting period of the proxy server node.

[0049] Step S1032, traverse the hash table to confirm that the user is in the current list of observed users, then calculate the access frequency of the user according to the following formula :

[0050] = (sum(c)+c_cache) / avg(k) + k_cache

[0051] where c is the number of accesses of this user, k is the reporting time interval of the proxy server node, sum() represents summation, avg() represents averaging, c_cache represents the total number of accesses of the user in the current cache, and k_cache represents the average value of the reporting time interval of the proxy server node in the current cache;

[0052] Then calculate the access frequency threshold _threshold according to the following formula:

[0053] _threshold = P / Q

[0054] where P represents the highest value of the number of user accesses within the specified time in the set banning policy; Q represents the specified time in the set banning policy;

[0055] If >= _threshold, and k is greater than or equal to Q, then directly include this user in the list of banned users; if the access frequency of the user is greater than or equal to the product of the access frequency threshold _threshold and coefficient a, coefficient a is less than 1, and k is less than Q, then keep this user in the list of observed users; if is less than _threshold, and k is greater than or equal to Q, then remove this user from the list of observed users.

[0056] Step S1033: If the user is included in the list of observed users in the threat information reported in two adjacent rounds and is not blocked, then judge the threat level of the user. If the threat level of the user is greater than the threat level threshold, then directly include the user in the list of blocked users, which specifically includes:

[0057] Obtain the geographical location information and timestamp information of the user's multiple visits, calculate the path distance of multiple geographical location coordinate points, calculate the average moving speed v_temp of the user according to the path distance and timestamp information. If the average moving speed v_temp of the user is greater than the speed threshold v_threshold, then take the product of the average moving speed v_temp of the user and the preset first weight coefficient w1 as the first threat level T1 of the user. Among them, the empirical value of the speed threshold v_threshold is usually 36 km / h, and the empirical value of the first weight coefficient w1 is usually 0.4.

[0058] Calculate the Euclidean distance between any two geographical location coordinate points visited by the user according to the following formula:

[0059]

[0060] Among them, represents the actual geographical distance of the geographical location coordinate point , represents the actual geographical distance of the geographical location coordinate point ; represents the access time of the geographical location coordinate point ; represents the access time of the geographical location coordinate point ;

[0061] According to the Euclidean distance between any two geographical location coordinate points visited by the user, cluster the geographical location coordinate points with relatively close distances, divide the geographical location coordinate points visited by the user into multiple clusters, and set the maximum value of the number of members for each cluster (depending on the total number of users, it is recommended to set it to 400 for 100,000 users). Whenever a new geographical location coordinate point is added, recalculate the division of the cluster; calculate the threat level of all users within the cluster according to the calculation method of the first threat level, divide the calculated threat level of all users within the cluster by the number of users within the cluster to obtain the average threat level of the cluster, and take the average threat level of the cluster as the second threat level T2 of the user.

[0062] When accessing a website, attackers often use a dynamic user agent (UA) to forge requests. Therefore, the user agent and time information themselves also contain attack features. Considering daily scenarios, a user usually only accesses services using a fixed browser on one mobile phone, or alternates between one mobile phone and one PC to access services. There are few cases where multiple mobile phones are used to access the same set of services simultaneously. Based on this, common user agents (UAs) can be counted, and the distance between two user agents (UAs) can be estimated. For example, the distance between the browser of an iPhone and the browser of an iPad should be relatively far, which is a reasonable usage scenario. The distance between browsers of different Android versions on Android phones should be relatively close. The closer the user agents (UAs) are, the more they should be excluded. Based on the above principle, the third threat level of the user is calculated according to the following formula :

[0063]

[0064] where is the preset second weight coefficient, is the time difference in the change of the user agent (UA), () represents the distance between two user agents, represents two adjacent user agents, represents the sum of all distances between user agents.

[0065] The sum of the first threat level T1, the second threat level T2, and the third threat level T3 is used as the final threat level T. If the final threat level is greater than the threat level threshold T_threshold, the user will be directly included in the banned user list.

[0066] Step S104: Send the latest observed user list and the latest banned user list to all proxy server nodes, so that each proxy server node can make the banning action effective according to the latest banned user list, and store the latest observed user list in the local memory to wait for re-reporting.

[0067] See Figure 2 Another embodiment of the present invention also provides a control device 200 for the access frequency of distributed network users, including a receiving module 201, a hash table generation module 202, a user list generation module 203, and a data distribution module 204. The control device 200 for the access frequency of distributed network users can execute the control method for the access frequency of distributed network users in the method embodiment.

[0068] Specifically, the control device 200 for the access frequency of distributed network users is configured to include:

[0069] A receiving module 201, configured to receive threat information reported by each proxy server node in the network, where the threat information includes user traffic sampling information of users not on the observed user list, user traffic sampling information of users on the observed user list, and a blocked user list;

[0070] A hash table generation module 202, configured to send the blocked user list to all proxy server nodes, and at the same time merge the user traffic sampling information of the observed user list reported by each proxy server node to obtain a hash table with the user ID as the key and the user traffic sampling information as the value;

[0071] A user list generation module 203, configured to traverse the hash table, identify whether a user is on the current observed user list, and determine whether the user should be maintained on the observed user list, added to the observed user list, removed from the observed user list, or blocked according to the identification result, so as to obtain an updated observed user list and an updated blocked user list;

[0072] A data sending module 204, configured to send the updated observed user list and the updated blocked user list to all proxy server nodes, so that each proxy server node takes effect the blocking action according to the updated blocked user list, and stores the updated observed user list in the local memory to wait for reporting again.

[0073] It should be noted that the distributed network user access frequency control device 200 provided in this embodiment can be used to execute the technical solutions of the method embodiments. Its implementation principle and technical effects are similar to those of the method, and will not be elaborated here.

[0074] See Figure 3 , another embodiment of the present invention provides a structural schematic diagram of an electronic device 300, and this electronic device is used to implement the distributed network user access frequency control method in the method embodiment. The electronic device 300 in the embodiment of the present invention may include, but is not limited to, a PC and a server. Figure 3 The shown electronic device 300 is only an example, and should not bring any limitation to the functions and usage scope of the embodiments of the present invention.

[0075] As Figure 3As shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage device 308 into the random access memory (RAM) 303 to implement the method of the embodiments described in the present invention. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.

[0076] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 an electronic device 300 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0077] The above description is only a preferred embodiment of the present invention. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present invention.

Claims

1. A method for controlling the access frequency of distributed network users, used in a controller node, characterized in that include: Receiving threat information reported by each proxy server node in the network, the threat information including user traffic sampling information of a non-observed user list, user traffic sampling information of an observed user list, and a banned user list; Send the banned user list to all proxy server nodes, and merge the user traffic sampling information of the observed user list reported by each proxy server node to obtain a hash table with user ID as the keyword and user traffic sampling information as the value; Traversing the hash table to identify whether the user is in the current observed user list, and determining whether the user should be maintained in the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result, so as to obtain the latest observed user list and the latest banned user list; Obtaining geographic location information and timestamp information of multiple visits by the user, calculating the path distance of multiple geographic location coordinate points, and calculating the average moving speed of the user according to the path distance and timestamp information. If the average moving speed of the user is greater than a speed threshold, the product of the average moving speed of the user and a preset first weight coefficient is used as the first threat level of the user; The Euclidean distance between any two geographic coordinate points visited by a user is calculated according to the following formula: in, Represents the geographic location coordinate point The actual geographical distance Represents the geographic location coordinate point The actual geographical distance Represents the geographic location coordinate point The access time, Represents the geographic location coordinate point The time of visit; According to the Euclidean distance between the geographic location coordinate points visited by any two users, cluster the geographic location coordinate points that are closer to each other, divide the geographic location coordinate points visited by the users into multiple clusters, and set a maximum number of members for each cluster. Whenever a new geographic location coordinate point is added, recalculate the cluster division; calculate the threat level of all users in the cluster according to the calculation method of the first threat level, divide the calculated threat level of all users in the cluster by the number of users in the cluster to obtain the average threat level of the cluster, and use the average threat level of the cluster as the second threat level of the user; Calculate the user's third threat level according to the following formula : in, is the preset second weight coefficient, The time difference for user agent changes. () indicates the distance between two user agents. Indicates two adjacent user agents. represents the sum of all distances between user agents; The sum of the first threat level, the second threat level, and the third threat level is taken as the final threat level. If the final threat level is greater than the threat level threshold, the user is directly included in the banned user list; The latest observed user list and the latest banned user list are sent to all proxy server nodes, so that each proxy server node will take effect the ban action according to the latest banned user list, and store the latest observed user list in the local storage to wait for reporting again.

2. A method for controlling the access frequency of distributed network users according to claim 1, characterized in that: The step of traversing the hash table, identifying whether the user is in the current observed user list, and determining whether the user should be maintained in the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result includes: If the user is not in the current list of observed users, the user's access frequency is calculated according to the following formula: : = sum(c) / avg(k) Where c is the number of visits by the user, k is the reporting time interval of the proxy server node, sum() means sum, and avg() means average; Then calculate the access frequency threshold according to the following formula: _threshold: _threshold = P / Q Wherein, P represents the maximum value of the number of user accesses within the specified time in the set blocking policy; Q represents the specified time in the set blocking policy; If the user's access frequency Greater than or equal to the access frequency threshold _threshold, and k is greater than or equal to Q, the user is directly included in the banned user list; if the user's access frequency Greater than or equal to the access frequency threshold The product of _threshold and coefficient a, and coefficient a is less than 1, then the user is added to the rule of the observed user list, and the total number of previous visits of the user sum(c) and the average value avg(k) of the proxy server node reporting period are cached.

3. A method for controlling the access frequency of distributed network users according to claim 2, characterized in that: The step of traversing the hash table to identify whether the user is in the current observed user list, and judging whether the user should be maintained in the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result also includes: If the user is in the current list of observed users, the user's access frequency is calculated according to the following formula: : = (sum(c)+c_cache) / avg(k) + k_cache Where c is the number of visits by the user, k is the reporting time interval of the proxy server node, sum() represents summing, avg() represents averaging, c_cache represents the total number of visits by the user in the current cache, and k_cache represents the average of the reporting time intervals of the proxy server nodes in the current cache; Then calculate the access frequency threshold according to the following formula: _threshold: _threshold = P / Q Wherein, P represents the maximum value of the number of user accesses within the specified time in the set blocking policy; Q represents the specified time in the set blocking policy; like >= _threshold, and k is greater than or equal to Q, the user is directly included in the banned user list; if the user's access frequency Greater than or equal to the access frequency threshold The product of _threshold and coefficient a, coefficient a is less than 1, and k is less than Q, then the user is maintained in the list of observed users; if Less than _threshold, and k is greater than or equal to Q, the user is removed from the list of observed users.

4. A method for controlling the access frequency of distributed network users according to claim 1, characterized in that: The reporting time interval k of each proxy server node is determined according to a preset maximum reporting period, a preset minimum reporting period, the node load, and the node CPU processing speed.

5. A method for controlling the access frequency of distributed network users according to claim 1, characterized in that: Also includes: If users whose threat information reported by each proxy server node exceeds a first predetermined ratio are banned, the validity of the information reported by the proxy server node is increased; If less than a second predetermined proportion of users in the threat information reported by each proxy server node are banned, the validity of the information reported by the proxy server node is lowered; The validity of the information reported by the proxy server node is used to determine the proportion of the threat information reported by the proxy server node each time to the total threat information in a reporting period.

6. A distributed network user access frequency control device, used for a controller node, characterized in that include: A receiving module, configured to receive threat information reported by each proxy server node in the network, wherein the threat information includes user traffic sampling information of a non-observed user list, user traffic sampling information of an observed user list, and a banned user list; A hash table generation module is used to send the banned user list to all proxy server nodes, and merge the user flow sampling information of the observed user list reported by each proxy server node to obtain a hash table with user ID as the keyword and user flow sampling information as the value; A user list generation module, used to traverse the hash table, identify whether the user is in the current observed user list, and determine whether the user should be maintained in the observed user list, added to the observed user list, removed from the observed user list, or banned according to the identification result, so as to obtain the latest observed user list and the latest banned user list; Obtaining geographic location information and timestamp information of multiple visits by the user, calculating the path distance of multiple geographic location coordinate points, and calculating the average moving speed of the user according to the path distance and timestamp information. If the average moving speed of the user is greater than a speed threshold, the product of the average moving speed of the user and a preset first weight coefficient is used as the first threat level of the user; The Euclidean distance between any two geographic coordinate points visited by a user is calculated according to the following formula: in, Represents the geographic coordinate point The actual geographical distance Represents the geographic coordinate point The actual geographical distance Represents the geographic location coordinate point The access time, Represents the geographic location coordinate point The time of visit; According to the Euclidean distance between the geographic location coordinate points visited by any two users, cluster the geographic location coordinate points that are closer to each other, divide the geographic location coordinate points visited by the users into multiple clusters, and set a maximum number of members for each cluster. Whenever a new geographic location coordinate point is added, recalculate the cluster division; calculate the threat level of all users in the cluster according to the calculation method of the first threat level, divide the calculated threat level of all users in the cluster by the number of users in the cluster to obtain the average threat level of the cluster, and use the average threat level of the cluster as the second threat level of the user; Calculate the user's third threat level according to the following formula : in, is the preset second weight coefficient, The time difference for the user agent to change. () indicates the distance between two user agents. Indicates two adjacent user agents. represents the sum of all distances between user agents; The sum of the first threat level, the second threat level, and the third threat level is taken as the final threat level. If the final threat level is greater than the threat level threshold, the user is directly included in the banned user list; The data sending module is used to send the latest observed user list and the latest banned user list to all proxy server nodes, so that each proxy server node will take effect the ban action according to the latest banned user list, and store the latest observed user list in the local storage to wait for re-reporting.

7. A device for controlling the access frequency of distributed network users according to claim 6, characterized in that: The user list generation module is also used for: If the user is not in the current list of observed users, the user's access frequency is calculated according to the following formula: : = sum(c) / avg(k) Where c is the number of visits by the user, k is the reporting time interval of the proxy server node, sum() means sum, and avg() means average; Then calculate the access frequency threshold according to the following formula: _threshold: _threshold = P / Q Wherein, P represents the maximum value of the number of user accesses within the specified time in the set blocking policy; Q represents the specified time in the set blocking policy; If the user's access frequency Greater than or equal to the access frequency threshold _threshold, and k is greater than or equal to Q, the user is directly included in the banned user list; if the user's access frequency Greater than or equal to the access frequency threshold The product of _threshold and coefficient a, and coefficient a is less than 1, then the user is added to the rule of the observed user list, and the total number of previous visits of the user sum(c) and the average value avg(k) of the proxy server node reporting period are cached.

8. A device for controlling the access frequency of distributed network users according to claim 7, characterized in that: The user list generation module is also used for: If the user is in the current list of observed users, the user's access frequency is calculated according to the following formula: : = (sum(c)+c_cache) / avg(k) + k_cache Where c is the number of visits by the user, k is the reporting time interval of the proxy server node, sum() represents summing, avg() represents averaging, c_cache represents the total number of visits by the user in the current cache, and k_cache represents the average of the reporting time intervals of the proxy server nodes in the current cache; Then calculate the access frequency threshold according to the following formula: _threshold: _threshold = P / Q Wherein, P represents the maximum value of the number of user accesses within the specified time in the set blocking policy; Q represents the specified time in the set blocking policy; like >= _threshold, and k is greater than or equal to Q, the user is directly included in the banned user list; if the user's access frequency Greater than or equal to the access frequency threshold The product of _threshold and coefficient a, coefficient a is less than 1, and k is less than Q, then the user is maintained in the list of observed users; if Less than _threshold, and k is greater than or equal to Q, the user is removed from the list of observed users.

Citation Information

Patent Citations

  • Abnormal access detection method and device

    CN111597419A

  • Access interception control method and device, equipment and medium

    CN114640534A