API call sequence identification method, device, equipment and storage medium

By identifying and grouping the API traffic of the network API interface, extracting and patterning the API call sequence, the problem of the API interface not being fully sorted and tested in the existing technology is solved, and the complete sorting of the WEB application API call sequence and the determination of the business logic relationship is realized, reducing security risks.

CN119561938BActive Publication Date: 2025-06-06BEIJING CYBER KUNLUN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510112725.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-06-06
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

In the prior art, WEB application vendors fail to complete the API interface they apply and sufficiently test, resulting in potential security risks for the API interface.

Method used

By obtaining the API traffic of the network API interface, identifying the session ID and grouping the API traffic, extracting valid API call sequences, and processing based on sequence pattern to realize the identification of the API call sequence.

Benefits of technology

It realizes a complete review of the API call sequence in WEB applications, determines the business logic relationship between WEB APIs, helps enterprises quickly understand the potential business logic in the business system, and reduces the security risks of the WEB API interface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561938B_ABST
    Figure CN119561938B_ABST
Patent Text Reader

Abstract

The present application provides an API call sequence identification method, device, equipment and storage medium, which relates to the field of computer technology. The method includes: obtaining the API traffic of the network API interface; identifying the session ID present in the API traffic, grouping the API traffic according to the session ID, and obtaining multiple API traffic groups, wherein one session ID corresponds to one API traffic group; for each API traffic group, extracting the valid API call sequence; performing sequence pattern processing based on the valid API call sequence of each API traffic group, and obtaining the identification result of the API call sequence. The embodiment of the present application realizes the complete combing of the API call sequence in the WEB application, which can help enterprise personnel quickly understand the potential business logic in the business system, and help security operation personnel quickly analyze all behaviors of accessing the WEB API interface, and reduce the overall hidden dangers of the WEB API interface.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, apparatus, computer device and readable storage medium for identifying an API call sequence. Background Art

[0002] With the rapid development of information technology, API (Application Programming Interface) interfaces play an increasingly important role in all walks of life. API interfaces provide standardized interfaces for data exchange between different systems. However, most WEB (network) application providers have not fully sorted out and fully tested the API interfaces of their applications, resulting in potential security risks in the exposed API interfaces. Summary of the invention

[0003] In view of this, the present application provides a method, apparatus, computer device and readable storage medium for identifying an API call sequence, which achieves a complete combing of the API call sequence in a WEB application and determines the business logic relationship between WEB APIs.

[0004] In a first aspect, an embodiment of the present application provides a method for identifying an API call sequence, comprising:

[0005] Get the API traffic of the network API interface;

[0006] Identify the session ID in the API traffic, group the API traffic according to the session ID to obtain a plurality of API traffic groups, wherein one of the session IDs corresponds to one of the API traffic groups;

[0007] For each of the API traffic groups, extract a valid API call sequence; wherein the method for extracting a valid API call sequence includes: for any of the API traffic groups, sorting the API call sequences contained in the API traffic group based on the collection timestamp of the API call sequence, wherein the sorting method includes arranging in ascending order or descending order according to the collection timestamp; according to the sorting order, aggregating the API call sequences according to a preset rule to obtain multiple API call sequence sets, wherein the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set; obtaining the sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold; taking the API call sequence set within the target time period as a valid API call sequence set, and taking the API call sequence included in the valid API call sequence set as the valid API call sequence;

[0008] Sequence pattern processing is performed based on the valid API call sequence of each of the API traffic groups to obtain an identification result of the API call sequence.

[0009] In a second aspect, an embodiment of the present application provides a device for identifying an API call sequence, including:

[0010] Traffic acquisition module, used to obtain API traffic of network API interface;

[0011] A session identification module, used to identify the session ID present in the API traffic;

[0012] A sequence extraction module, for grouping the API traffic according to the session ID to obtain multiple API traffic groups, wherein one of the session IDs corresponds to one of the API traffic groups; and for each of the API traffic groups, extracting a valid API call sequence; wherein the method for extracting a valid API call sequence includes: for any of the API traffic groups, sorting the API call sequences contained in the API traffic group based on the acquisition timestamp of the API call sequence, wherein the sorting method includes arranging in ascending order or descending order according to the acquisition timestamp; aggregating the API call sequences according to a preset rule in the sorting order to obtain multiple API call sequence sets, wherein the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set; obtaining the sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold; taking the API call sequence set within the target time period as a valid API call sequence set, and taking the API call sequence included in the valid API call sequence set as the valid API call sequence;

[0013] The identification and processing module is used to perform sequence pattern processing based on the valid API call sequence of each of the API traffic groups to obtain an identification result of the API call sequence.

[0014] In a third aspect, an embodiment of the present application provides a computer device, which includes a processor and a memory, wherein the memory stores programs or instructions that can be executed on the processor, and when the programs or instructions are executed by the processor, the steps of the method of the first aspect are implemented.

[0015] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the method of the first aspect are implemented.

[0016] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, wherein the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the method of the first aspect.

[0017] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method of the first aspect.

[0018] In an embodiment of the present application, the API traffic of the network API interface is obtained; the session ID present in the API traffic is identified, and the API traffic is grouped according to the session ID to obtain multiple API traffic groups, wherein one session ID corresponds to one API traffic group; for each API traffic group, a valid API call sequence is extracted; sequence pattern processing is performed based on the valid API call sequence of each API traffic group to obtain an identification result of the API call sequence. The embodiment of the present application can realize the identification of the API call sequence in the WEB application, that is, realize the complete combing of the API call sequence in the WEB application, determine the business logic relationship between the WEB APIs, which can help enterprise personnel quickly understand the potential business logic in the business system, and help security operations personnel quickly analyze all behaviors of accessing the WEB API interface, and reduce the overall hidden dangers of the WEB API interface.

[0019] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0021] Figure 1 One of the flowcharts of the method for identifying an API call sequence according to an embodiment of the present application is shown;

[0022] Figure 2 A schematic diagram showing the aggregation of API call sequences according to an embodiment of the present application is shown;

[0023] Figure 3 A schematic diagram showing the intersection of a valid API call sequence set set according to an embodiment of the present application is shown;

[0024] Figure 4 A schematic diagram showing a valid API call sequence set group union according to an embodiment of the present application is shown;

[0025] Figure 5 The second flowchart of the method for identifying an API call sequence according to an embodiment of the present application is shown;

[0026] Figure 6 A schematic diagram showing the recognition result of an embodiment of the present application;

[0027] Figure 7 A structural block diagram of an API call sequence recognition device according to an embodiment of the present application is shown;

[0028] Figure 8 A structural block diagram of a computer device according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0029] The following will be combined with the drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the present application belong to the scope of protection of this application.

[0030] The terms "first", "second", etc. in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0031] In conjunction with the accompanying drawings, the following detailed description is given of the API call sequence recognition method, apparatus, computer device and readable storage medium provided in the embodiments of the present application through specific embodiments and their application scenarios.

[0032] The present application embodiment provides a method for identifying an API call sequence, such as Figure 1 As shown, the method includes:

[0033] Step 101, obtaining the API traffic of the network API interface;

[0034] Step 102, identifying the session ID in the API traffic, grouping the API traffic according to the session ID to obtain multiple API traffic groups, where one session ID corresponds to one API traffic group;

[0035] Step 103, for each API traffic group, extract a valid API call sequence;

[0036] Step 104 , performing sequence pattern processing based on the valid API call sequence of each API traffic group to obtain an identification result of the API call sequence.

[0037] In this embodiment, a real-time monitoring system is deployed to perform real-time traffic monitoring on the network API interface to obtain the network traffic of the network API interface, and then obtain the API traffic based on the network traffic. The network API interface, also known as the WEB API interface, refers to an application program interface based on a WEB application, and the network traffic refers to the amount of data transmitted through a computer network (such as a local area network, a metropolitan area network, a wide area network or the Internet, etc.), which can be any form of information, including transmission data or access requests, such as emails, web page requests, file transfers, audio and video streams, database queries, etc.

[0038] Identify and mark the session ID (Identity Document) corresponding to each API traffic accessing the WEB application, and group the API traffic by session ID. Each session ID can represent a user or device, and is used to identify and track the user or device's session. By grouping API traffic from the same user or device into the same session ID, you can better understand the user's behavior pattern.

[0039] Furthermore, for each API traffic group, extract the valid API call sequence within the API traffic group, where the API call sequence is a one-way sequence built based on the logical order between APIs. The sequence density (also known as data density) can be used to extract valid API call sequences, where sequence density refers to the density of the series over a period of time, and valid API call sequences refer to those API call sequences corresponding to higher sequence density. Further, based on the valid API call sequence of each API traffic group, sequence pattern processing is performed to obtain the recognition result of the API call sequence for the network API interface, and the noise is filtered out by extracting valid data to ensure that the recognition result is more accurate and more targeted.

[0040] The embodiments of the present application can identify the API call sequence in the WEB application, that is, completely comb through the API call sequence in the WEB application, determine the business logic relationship between the WEB APIs, and help enterprise personnel quickly understand the potential business logic in the business system, and help security operations personnel quickly analyze all behaviors of accessing the WEB API interface, thereby reducing the overall risks of the WEB API interface.

[0041] In one embodiment of the present application, for each API traffic group, a valid API call sequence is extracted, including:

[0042] For any API traffic group, the API call sequences contained in the API traffic group are sorted based on the collection timestamp of the API call sequences. The sorting method includes ascending or descending order according to the collection timestamp.

[0043] According to the sorting order, the API call sequences are aggregated according to a preset rule to obtain multiple API call sequence sets, where the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set;

[0044] Obtaining a sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold;

[0045] The API call sequence set within the target time period is taken as the valid API call sequence set, and the API call sequences included in the valid API call sequence set are taken as the valid API call sequences.

[0046] In this embodiment, after grouping, in any API traffic group, the API call sequences contained in the API traffic group are arranged in ascending order or descending order based on the collection timestamps of the API call sequences, so that the API call sequences in an API traffic group are arranged in chronological order. It should be noted that before the arrangement, the timestamp alignment is performed, that is, the format of the timestamp is unified, for example, the timestamp is unified to minutes, seconds or milliseconds, etc., to improve the accuracy of the arrangement.

[0047] By sorting in chronological order, the timeline of the subsequently identified API call sequence is clear, which helps developers and operation and maintenance personnel to quickly locate the time point when the problem occurs, and makes the causal relationship between each API call sequence clearer, which helps to analyze the cause of call failure or exception.

[0048] After sorting, the API call sequences are aggregated according to the time interval of the first time period, that is, the API call sequences whose time difference (i.e., time interval) of the collection timestamps of adjacent API call sequences is less than or equal to the preset time interval are aggregated into one API call sequence set, thereby obtaining multiple API call sequence sets. For example, Figure 2As shown, for the data of the same session ID session_a, the API call sequences with a time interval not greater than the preset time interval time are organized into an ordered API call sequence set api list1, and the API call sequences with a time interval greater than time are split into another API call sequence set api list2. In the embodiment of the present application, a large API call sequence can be divided into multiple ordered and easy-to-manage sets, each set containing data within a specific time period, so that the organizational structure of the data is clearer, which helps to quickly locate the data in a specific time period and facilitates subsequent analysis and processing.

[0049] Obtain the sequence density of the API call sequence set corresponding to each preset time period, that is, the sequence density of the API call sequence corresponding to the preset time period, and determine the target time period in which the sequence density is greater than the first preset threshold. Further, the API call sequence included in the API call sequence set (that is, the valid API call sequence set) within the target time period is determined as a valid API call sequence. For example, if there are three preset time periods, and the sequence density corresponding to the second preset time period and the third preset time period is greater than the first preset threshold, then the API call sequence included in the API call sequence set within the second preset time period and the third preset time period is determined as a valid API call sequence.

[0050] The embodiments of the present application can significantly reduce the amount of data that needs to be processed by extracting valid data to reduce noise, improve the accuracy of recognition results, and further extract valid data on the basis of grouping.

[0051] In one embodiment of the present application, obtaining API traffic of a network API interface includes:

[0052] According to the distributed mode, the network traffic passing through the network API interface is obtained, and the network traffic is filtered and screened for HTTP traffic to obtain HTTP traffic;

[0053] Construct multimodal fusion features, and based on the multimodal fusion features and the traffic identification model, identify API traffic in HTTP traffic. The multimodal fusion features include request time, request method, user behavior characteristics, system resource usage, and at least one of external environmental factors. The traffic identification model includes at least one of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network.

[0054] In this embodiment, the network traffic passing through the network API interface is obtained, and the HTTP (Hypertext Transfer Protocol) traffic in the network traffic is extracted by filtering and screening the network traffic. Multimodal fusion features are constructed, and the HTTP traffic is deeply analyzed based on the multimodal fusion features to determine the API traffic present therein.

[0055] Specifically, a multimodal fusion feature is constructed, including request time, request method, user behavior characteristics, system resource usage, and external environmental factors. User behavior characteristics include user login frequency, operation habits, etc. System resource usage includes CPU occupancy, memory usage, etc. External environmental factors include network traffic, geographic location, etc. By introducing more diversified features, this application can more accurately identify API call behaviors hidden in complex network environments.

[0056] Input the multimodal fusion features into the pre-built traffic identification model to determine the API traffic in the HTTP traffic. The traffic identification model includes at least one of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network. It is a model that is pre-trained and deployed in the production environment, and is used to classify HTTP traffic in real time to obtain API traffic. When training the model, capture HTTP traffic data, mark the HTTP traffic data as API traffic or other HTTP traffic, and extract relevant features of API traffic and relevant features of other HTTP traffic. Clean the extracted relevant features, such as processing missing values, outliers, or duplicate values, and normalize or standardize the relevant features to ensure that the scales of different features are consistent. Divide the HTTP traffic data into a training data set, a validation data set, and a test data set.

[0057] Select a machine learning model or deep learning model, including bidirectional long short-term memory network, converter network, long short-term memory network, recurrent neural network, etc. Use the training dataset to train the machine learning model, and use the validation dataset to adjust the hyperparameters of the machine learning model or deep learning model. Use the test dataset to evaluate the performance of the machine learning model or deep learning model. If the performance of the machine learning model is not good, you can try to adjust the features, choose a different model, or optimize the model's hyperparameters to get a machine learning model with better performance. Over time, the pattern of HTTP traffic may change, so the model needs to be retrained regularly to adapt to these changes.

[0058] This application not only uses traditional deep learning models, such as RNN (Recurrent Neural Network) and LSTM (Long Short-Term Memory), but also innovatively designs the model structure based on the characteristics of WEB API call sequences. For example, Bi-LSTM (Bidirectional Long Short-Term Memory) is introduced to simultaneously capture the forward and backward dependencies of the sequence, so as to more comprehensively understand the API call context. Alternatively, the Transformer (converter network) is used to further improve the processing effect of long API call sequence data by taking advantage of its powerful sequence modeling capabilities.

[0059] Through the above method, accurate identification of API traffic can be achieved, providing a data basis for subsequent identification of API call sequences.

[0060] It is worth noting that the embodiment of the present application acquires and subsequently processes API traffic in a distributed mode, ensuring a balance between real-time performance and scalability. Specifically, while ensuring real-time detection performance, the present application also fully considers the scalability of the system. By adopting a distributed computing architecture and efficient model compression technology, it can easily cope with the processing needs of large-scale WEB API call sequence data without sacrificing detection speed.

[0061] In one embodiment of the present application, if the traffic identification model includes multiple items of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network, then based on the multimodal fusion features and the traffic identification model, API traffic is identified in HTTP traffic, including:

[0062] Based on multimodal fusion features and multiple traffic identification models, multiple prediction results for API traffic are obtained respectively;

[0063] Multiple prediction results are combined to obtain API traffic.

[0064] In this embodiment, in order to further improve the robustness and accuracy of detection, the present application adopts an integrated learning framework to fuse the prediction results of multiple models. In this way, the present application can make full use of the advantages of different models, reduce the deviation and variance of a single model, and thus obtain more reliable detection results.

[0065] In one embodiment of the present application, identifying a session ID in API traffic includes: identifying request information of the API traffic, obtaining the session ID in the API traffic, the request information of the API traffic including at least one of the following cookie values ​​and request headers.

[0066] In this embodiment, some web applications use Cookies to store session IDs. Cookies are small text files sent by the server to the client's browser and sent back to the server by the browser in subsequent requests. The session ID can be obtained based on the Cookie value.

[0067] The HTTP request header contains various metadata about the request, including a possible session ID, so you can traverse each field in the HTTP request header to find the session ID. For example, you can find the session ID in Authorization.

[0068] Through the above method, the session ID can be accurately obtained, providing a data basis for subsequent group identification of API call sequences.

[0069] In one embodiment of the present application, sequence pattern processing is performed based on the valid API call sequence of each API traffic group to obtain an identification result of the API call sequence, including:

[0070] For the API traffic group with the same session ID, intersection processing of the valid API call sequences is performed, and for the API traffic groups with different session IDs, union processing of the valid API call sequences is performed to obtain the identification results of the API call sequences; wherein, intersection processing is used to obtain the same valid API call sequence under the same session ID, and union processing is used to fuse different valid API call sequences under different session IDs.

[0071] Among them, for the API traffic group with the same session ID, the intersection processing of the valid API call sequence is performed, including: obtaining the same valid API call sequence in any two API traffic groups under the same session ID, and outputting a new set of API traffic groups;

[0072] For API traffic groups with different session IDs, a union process of valid API call sequences is performed, including: obtaining different valid API call sequences in any two API traffic groups with different session IDs, and outputting a new set of API traffic groups;

[0073] All new API traffic groups are the identification results of API call sequences.

[0074] In this embodiment, for the valid API call sequence set in the API traffic group corresponding to the same session ID, the intersection processing of the valid API call sequence is performed to obtain a first recognition result. For the valid API call sequence set in the API traffic group corresponding to different session IDs, the union processing of the valid API call sequence is performed to obtain a second recognition result. The first recognition result and the second recognition result are the final recognition results of the API call sequence. For example, Figure 3 As shown in the figure, the valid API call sequence set of the same session ID session_a takes the intersection, that is, any two API lists are intersected to output a new set of API lists. The valid API call sequences of different session IDs are concatenated, such as Figure 4 As shown, session ID session_a and session ID session_b are concatenated into a valid API call sequence.

[0075] In the embodiment of the present application, the same session ID uses the intersection as the identification result, and different session IDs use the union as the identification result, so as to achieve complete sorting of the API call sequence in the WEB application.

[0076] As a refinement and extension of the above embodiment, the embodiment of the present invention provides another method for identifying an API call sequence, such as Figure 5 As shown, the method includes:

[0077] Step 501, obtaining the API traffic of the network API interface;

[0078] Step 502, identifying the session ID in the API traffic, grouping the API traffic according to the session ID to obtain multiple API traffic groups, where one session ID corresponds to one API traffic group;

[0079] Step 503, for each API traffic group, extract the valid API call sequence;

[0080] Step 504, performing sequence pattern processing based on the valid API call sequence of each API traffic group to obtain an identification result of the API call sequence;

[0081] Step 505: Calculate the confidence and / or similarity of the identified API call sequence, and display the confidence and / or similarity of the API call sequence.

[0082] Among them, step 501 to step 504 are the same as or similar to step 101 to step 104 in the above embodiment, and are not described again here.

[0083] In this embodiment, after all recognition results (that is, all recognized API call sequences) are summarized, the confidence and / or similarity of each API call sequence is calculated, and the API call sequence is visualized according to the confidence and / or similarity, so that the recognized API call sequence is provided to enterprise personnel and security operation personnel in a more intuitive manner, which can help enterprise personnel quickly understand the potential business logic in the business system, and help security operation personnel quickly analyze all behaviors of accessing the WEB API interface, thereby reducing the overall hidden dangers of the WEB API interface.

[0084] In one embodiment of the present application, the method of calculating the confidence of the API call sequence includes: determining the prior probability of the API call sequence; counting the occurrence frequency and repetition of the API call sequence, and determining the likelihood function of the API call sequence according to the occurrence frequency and repetition; determining the posterior probability of the API call sequence according to the prior probability and the likelihood function; determining the confidence corresponding to the posterior probability according to a preset mapping relationship between the posterior probability and the confidence;

[0085] The method of calculating the similarity of the API call sequence includes: calculating the ratio between the number of intersection elements and the number of union elements of the API call sequence and other API call sequences, and determining the similarity between the API call sequence and other API call sequences according to the size of the ratio.

[0086] In this embodiment, the confidence of the API call sequence is evaluated by counting the frequency and repetition of the API call sequence, and the confidence of each API call sequence is calculated using probabilistic statistical methods such as Bayesian inference. The confidence score can be set between 0 and 100, and the specific confidence score of the API call sequence can be directly displayed during visualization. Figure 6 As shown, the specific confidence level of the API call sequence can also be displayed during visualization. Specifically, multiple confidence levels are set, corresponding to different score intervals, for example, the confidence level is divided into three levels: high, medium, and low, and the corresponding score intervals are 100-80, 79-50, and 49-0, respectively. The score interval corresponding to the API call sequence obtained by calculation is determined, and then the confidence level of the API call sequence is determined and displayed. In one embodiment, API call sequences of different confidence levels can be displayed in different colors. For example, API call sequences with medium or high confidence levels can be displayed in green, and API call sequences with low confidence levels can be displayed in red, thereby providing an obvious warning.

[0087] The similarity can be calculated using the Jaccard similarity algorithm, that is, the ratio between the number of intersection elements and the number of union elements of an API call sequence and other API call sequences is calculated, and the similarity between the API call sequence and other API call sequences is determined based on the size of the ratio. The calculation of similarity helps identify and analyze business logic. Figure 6 In the above figure, the similarity of API call sequences under the same branch is high, while the similarity of API call sequences under different branches is low.

[0088] In one embodiment of the present application, an analysis process of an API call sequence or a network API interface is performed based on the recognition result, and the analysis process includes:

[0089] (1) Frequency analysis of API call sequences: Analyze which API call sequences are called most frequently and understand the calling relationships between different API call sequences, such as which API call sequences are often called together.

[0090] (2) Performance analysis of network API interfaces: Analyze the response time of network API interface calls to identify possible performance bottlenecks or latency issues.

[0091] (3) Error and exception analysis: Identify and analyze errors and exceptions that occur during API calls, understand which API call sequences are more prone to errors, and optimize error handling and retry strategies accordingly.

[0092] (4) User behavior analysis: By analyzing the API call sequence, we can understand how users use WEB applications and identify common user operation paths and patterns.

[0093] (5) Security analysis: Look for clues to possible security vulnerabilities or sensitive information leakage, and analyze whether API calls follow expected security protocols and best practices.

[0094] (6) Version compatibility analysis: If a WEB API has multiple versions, you can analyze how different versions of the API are used and understand which versions of the API are still widely used, so as to decide when to abandon the old version.

[0095] (7) Data correlation analysis: By correlating API call sequences with business data, we can analyze which API call sequences are related to specific transactions, user activities, or business events.

[0096] At present, the security issues of WEB API are becoming increasingly prominent, especially abnormal behaviors in API call sequences, which may lead to serious consequences such as data leakage and service interruption. In one embodiment of the present application, after obtaining the recognition result of the API call sequence, the method also includes:

[0097] The calling frequency of the API calling sequence is compared with a second preset threshold, and the API calling sequence corresponding to the calling frequency greater than the second preset threshold is marked as an abnormal API calling sequence.

[0098] In this embodiment, after the API call sequence is identified, the call frequency of the API call sequence is compared with a second preset threshold, and if the call frequency exceeds the second preset threshold, it is determined to be an abnormal API call sequence. The embodiment of the present application implements the detection function of abnormal API call sequences.

[0099] In one embodiment of the present application, the method further includes: dynamically adjusting the second preset threshold value according to historical API call data and current network environment information.

[0100] In view of the limitations of fixed threshold settings, this application proposes an adaptive threshold setting mechanism. Under this mechanism, the second preset threshold of anomaly detection can be dynamically adjusted according to historical API call data and current network environment information, so as to maintain stable detection performance under different conditions.

[0101] In one embodiment, the application can combine data visualization technology and intelligent early warning mechanism. Through an intuitive graphical interface, the API call status and anomaly detection results are displayed, and machine learning algorithms are used to intelligently analyze and classify early warning information, helping operation and maintenance personnel locate and solve problems faster.

[0102] Furthermore, as a specific implementation of the above-mentioned method for identifying an API call sequence, an embodiment of the present application provides an apparatus for identifying an API call sequence. Figure 7 As shown, the API call sequence identification device 700 includes: a traffic acquisition module 701, a session identification module 702, a sequence extraction module 703 and an identification processing module 704.

[0103] The traffic acquisition module 701 is used to acquire the API traffic of the network API interface;

[0104] A session identification module 702, used to identify the session ID present in the API traffic;

[0105] The sequence extraction module 703 is used to group the API traffic according to the session ID to obtain multiple API traffic groups, wherein one session ID corresponds to one API traffic group; and for each API traffic group, extract a valid API call sequence; wherein the method of extracting the valid API call sequence includes: for any API traffic group, based on the acquisition timestamp of the API call sequence, sorting the API call sequences contained in the API traffic group, wherein the sorting method includes arranging in ascending order or descending order according to the acquisition timestamp; according to the sorting order, aggregating the API call sequences according to a preset rule to obtain multiple API call sequence sets, wherein the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set; obtaining the sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold; taking the API call sequence set within the target time period as a valid API call sequence set, and taking the API call sequence included in the valid API call sequence set as a valid API call sequence;

[0106] The identification processing module 704 is used to perform sequence pattern processing based on the valid API call sequence of each API traffic group to obtain an identification result of the API call sequence.

[0107] The embodiments of the present application can identify the API call sequence in the WEB application, that is, completely comb through the API call sequence in the WEB application, determine the business logic relationship between the WEB APIs, and help enterprise personnel quickly understand the potential business logic in the business system, and help security operations personnel quickly analyze all behaviors of accessing the WEB API interface, thereby reducing the overall risks of the WEB API interface.

[0108] Furthermore, the traffic acquisition module 701 is specifically used for:

[0109] According to the distributed mode, the network traffic passing through the network API interface is obtained, and the network traffic is filtered and screened for HTTP traffic to obtain HTTP traffic;

[0110] Construct multimodal fusion features, and based on the multimodal fusion features and the traffic identification model, identify API traffic in HTTP traffic. The multimodal fusion features include request time, request method, user behavior characteristics, system resource usage, and at least one of external environmental factors. The traffic identification model includes at least one of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network.

[0111] Furthermore, if the traffic identification model includes multiple items of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network, the traffic acquisition module 701 is specifically used to:

[0112] Based on multimodal fusion features and multiple traffic identification models, multiple prediction results for API traffic are obtained respectively;

[0113] Multiple prediction results are combined to obtain API traffic.

[0114] Furthermore, the identification processing module 704 is specifically used to perform intersection processing of valid API call sequences for the API traffic group with the same session ID, and to perform union processing of valid API call sequences for the API traffic groups with different session IDs, so as to obtain identification results of the API call sequences; wherein, the intersection processing is used to obtain the same valid API call sequence under the same session ID, and the union processing is used to fuse different valid API call sequences under different session IDs.

[0115] Further, the identification processing module 704 is specifically used to: obtain the same valid API call sequence in any two API traffic groups under the same session ID, and output a new set of API traffic groups;

[0116] The identification processing module 704 is specifically used to obtain different valid API call sequences in any two API traffic groups under different session IDs, and output a new set of API traffic groups; wherein the output new API traffic group is the identification result of the API call sequence.

[0117] Furthermore, the recognition processing module 704 is also used to calculate the confidence and / or similarity of the recognized API call sequence;

[0118] The device also includes: a display module, used to display the confidence and / or similarity of the API call sequence.

[0119] Further, the method of calculating the confidence of the API call sequence includes: determining the prior probability of the API call sequence; counting the occurrence frequency and repetition of the API call sequence, and determining the likelihood function of the API call sequence according to the occurrence frequency and repetition; determining the posterior probability of the API call sequence according to the prior probability and the likelihood function; and determining the confidence corresponding to the posterior probability according to a preset mapping relationship between the posterior probability and the confidence;

[0120] The method of calculating the similarity of the API call sequence includes: calculating the ratio between the number of intersection elements and the number of union elements of the API call sequence and other API call sequences, and determining the similarity between the API call sequence and other API call sequences according to the size of the ratio.

[0121] Furthermore, the device also includes: an abnormality detection module, which is used to:

[0122] Compare the calling frequency of the API calling sequence with a second preset threshold, and mark the API calling sequence corresponding to the calling frequency greater than the second preset threshold as an abnormal API calling sequence;

[0123] The anomaly detection module is also used to dynamically adjust the second preset threshold value according to historical API call data and current network environment information.

[0124] The API call sequence recognition device 700 in the embodiment of the present application can be a computer device, or a component in a computer device, such as an integrated circuit or a chip. Figure 1 and Figure 5 To avoid repetition, the various processes implemented in the embodiment of the method for identifying an API call sequence are not described here.

[0125] The present application also provides a computer device, such as Figure 8 As shown, the computer device 800 includes a processor 801 and a memory 802. The memory 802 stores programs or instructions that can be executed on the processor 801. When the program or instruction is executed by the processor 801, the various steps of the above-mentioned API call sequence recognition method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0126] The memory 802 can be used to store software programs and various data. The memory 802 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, an application program or instructions required for at least one function (such as a sound playback function, an image playback function, etc.), etc. In addition, the memory 802 may include a volatile memory or a non-volatile memory, or the memory 802 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM). The memory 802 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0127] The processor 801 may include one or more processing units; optionally, the processor 801 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 801.

[0128] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned API call sequence recognition method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0129] An embodiment of the present application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned API call sequence recognition method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0130] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0131] An embodiment of the present application also provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the various processes of the above-mentioned API call sequence recognition method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0132] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0133] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims

1. A method for identifying an API call sequence, characterized in that: include: Get the API traffic of the network API interface; Identify the session ID in the API traffic, group the API traffic according to the session ID to obtain a plurality of API traffic groups, wherein one of the session IDs corresponds to one of the API traffic groups; For each of the API traffic groups, extract a valid API call sequence; wherein the method for extracting a valid API call sequence includes: for any of the API traffic groups, sorting the API call sequences contained in the API traffic group based on the collection timestamp of the API call sequence, wherein the sorting method includes arranging in ascending order or descending order according to the collection timestamp; according to the sorting order, aggregating the API call sequences according to a preset rule to obtain multiple API call sequence sets, wherein the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set; obtaining the sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold; taking the API call sequence set within the target time period as a valid API call sequence set, and taking the API call sequence included in the valid API call sequence set as the valid API call sequence; Performing sequence pattern processing based on the valid API call sequence of each of the API traffic groups to obtain an identification result of the API call sequence; The step of performing sequence pattern processing based on the valid API call sequence of each of the API traffic groups to obtain the recognition result of the API call sequence includes: For the API traffic group with the same session ID, an intersection process of the valid API call sequence is performed, and for the API traffic groups with different session IDs, a union process of the valid API call sequence is performed to obtain the identification result of the API call sequence; wherein the intersection process is used to obtain the same valid API call sequence under the same session ID, and the union process is used to merge different valid API call sequences under different session IDs; The intersection processing of valid API call sequences for the API traffic group with the same session ID includes: Obtain the same valid API call sequence in any two API traffic groups under the same session ID, and output a new set of API traffic groups; The process of performing a union process of valid API call sequences for API traffic groups with different session IDs includes: Obtain different valid API call sequences in any two API traffic groups under different session IDs, and output a new set of API traffic groups; The output new API traffic group is the identification result of the API call sequence.

2. The method according to claim 1, characterized in that The method of obtaining the API traffic of the network API interface includes: According to the distributed mode, the network traffic passing through the network API interface is obtained, and the network traffic is filtered and screened for HTTP traffic to obtain HTTP traffic; Construct a multimodal fusion feature, and based on the multimodal fusion feature and a traffic identification model, identify the API traffic in the HTTP traffic, the multimodal fusion feature includes at least one of request time, request method, user behavior characteristics, system resource usage, and external environmental factors, and the traffic identification model includes at least one of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network.

3. The method according to claim 2, characterized in that If the traffic identification model includes multiple items of a bidirectional long short-term memory network, a converter network, a long short-term memory network, and a recurrent neural network, then the API traffic is identified in the HTTP traffic based on the multimodal fusion feature and the traffic identification model, including: Based on the multimodal fusion features and the multiple traffic identification models, multiple prediction results for API traffic are obtained respectively; The multiple prediction results are merged to obtain the API traffic.

4. The method according to claim 1, characterized in that: After obtaining the recognition result of the API call sequence, the method further includes: The confidence and / or similarity of the identified API call sequence is calculated, and the confidence and / or similarity of the API call sequence is displayed.

5. The method according to claim 4, characterized in that The method of calculating the confidence of the API call sequence includes: Determine the prior probability of the API call sequence; count the occurrence frequency and repetition of the API call sequence, and determine the likelihood function of the API call sequence according to the occurrence frequency and the repetition; determine the posterior probability of the API call sequence according to the prior probability and the likelihood function; determine the confidence corresponding to the posterior probability according to a preset mapping relationship between the posterior probability and the confidence; The method of calculating the similarity of the API call sequence includes: The ratio between the number of intersection elements and the number of union elements of the API call sequence and other API call sequences is calculated, and the similarity between the API call sequence and other API call sequences is determined according to the size of the ratio.

6. The method according to any one of claims 1 to 5, characterized in that After obtaining the recognition result of the API call sequence, the method further includes: Comparing the calling frequency of the API calling sequence with a second preset threshold, marking the API calling sequence corresponding to the calling frequency greater than the second preset threshold as an abnormal API calling sequence; The method further comprises: The second preset threshold is dynamically adjusted according to historical API call data and current network environment information.

7. An API call sequence recognition device, characterized in that: include: Traffic acquisition module, used to obtain API traffic of network API interface; A session identification module, used to identify the session ID present in the API traffic; A sequence extraction module, used for grouping the API traffic according to the session ID to obtain a plurality of API traffic groups, wherein one of the session IDs corresponds to one of the API traffic groups; And for each of the API traffic groups, extract a valid API call sequence; wherein the method of extracting the valid API call sequence includes: for any of the API traffic groups, based on the collection timestamp of the API call sequence, sorting the API call sequences contained in the API traffic group, the sorting method includes arranging in ascending order or descending order according to the collection timestamp; according to the sorting order, aggregating the API call sequences according to a preset rule to obtain multiple API call sequence sets, the preset rule is to aggregate API call sequences that are less than or equal to a preset time interval into one API call sequence set; obtaining the sequence density of the API call sequence set corresponding to each preset time period, and determining a target time period in which the sequence density is greater than a first preset threshold; taking the API call sequence set within the target time period as a valid API call sequence set, and the API call sequence included in the valid API call sequence set as the valid API call sequence; An identification processing module, used for performing sequence pattern processing based on the valid API call sequence of each of the API traffic groups to obtain an identification result of the API call sequence; Wherein, the identification processing module is specifically used for: For the API traffic group with the same session ID, an intersection process of the valid API call sequence is performed, and for the API traffic groups with different session IDs, a union process of the valid API call sequence is performed to obtain the identification result of the API call sequence; wherein the intersection process is used to obtain the same valid API call sequence under the same session ID, and the union process is used to merge different valid API call sequences under different session IDs; The identification processing module is specifically used to: obtain the same valid API call sequence in any two API traffic groups under the same session ID, and output a new set of API traffic groups; The identification processing module is specifically used to: obtain different valid API call sequences in any two API traffic groups under different session IDs, and output a new set of API traffic groups; The output new API traffic group is the identification result of the API call sequence.

8. A computer device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction running on the processor, and when the program or instruction is executed by the processor, the steps of the method for identifying an API call sequence as described in any one of claims 1 to 6 are implemented.

9. A readable storage medium having a program or instruction stored thereon, characterized in that: When the program or instruction is executed by a processor, the steps of the method for identifying an API call sequence according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Interface traffic security detection method, device, equipment, medium and program product

    CN119071070A