A Method for API Abnormal Access Detection and Encryption Protection Based on Behavior Analysis

By building a behavior analysis graph and using PageRank and Louvain algorithms, identifying API abnormal access behavior and evaluating risks, the problem of the existing technology not being able to identify new attacks and multi-node collaborative attacks is solved, and more efficient and accurate API security protection is achieved.

CN119906582BActive Publication Date: 2025-06-10HANGZHOU DAZHUO INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510324399.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-10
Estimated Expiration
2045-03-19

Smart Images

  • Figure CN119906582B_ABST
    Figure CN119906582B_ABST
Patent Text Reader

Abstract

The present invention discloses an API abnormal access detection and encryption protection method based on behavior analysis, which relates to the technical field of API security protection, and includes: receiving API access log data, and extracting access behavior feature information from the API access log data; constructing a behavior analysis graph based on the access behavior feature information; analyzing the behavior analysis graph to identify abnormal behaviors in the access behavior; performing risk assessment on the abnormal behaviors, and implementing encryption protection measures. The API abnormal access detection and encryption protection method based on behavior analysis provided by the present invention constructs a dynamic behavior analysis graph, combines the PageRank algorithm to perform centrality analysis on the API access behavior, so as to accurately identify potential abnormal nodes. Compared with the existing detection methods based on rules or simple feature matching, the present invention can avoid the limitations of relying on static rules and has stronger adaptability and accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of API security protection, and specifically provides a method for detecting and encrypting abnormal API access based on behavior analysis. Background Art

[0002] With the continuous development of information technology, APIs (Application Programming Interfaces) have become important tools for data interaction and function calls between various software and services. However, as a key link in inter-system communication, the security of APIs has attracted increasing attention. Existing API security protection technologies mainly focus on ensuring API security through means such as authentication, encryption, and access control. Common protection methods include static rule restrictions based on IP addresses, user identities, or request frequencies, as well as intrusion detection systems (IDSs) for detecting known attack patterns.

[0003] Although these traditional security protection measures are effective to a certain extent, there are still significant deficiencies. First, many existing systems rely on rule bases and signature matching. When attackers use new attack techniques or forge normal traffic, these static methods cannot identify abnormal behaviors. In addition, existing security technologies usually adopt single-dimensional protection means and lack in-depth analysis of multi-node collaborative attacks (such as DDoS attacks, distributed attacks, etc.), resulting in the inability to comprehensively prevent complex attack patterns such as distributed attacks.

[0004] Another problem is that most existing behavior analysis methods rely on machine learning models. Although these models can handle relatively complex attack patterns, when faced with large-scale traffic, they often encounter performance bottlenecks, resulting in processing delays. On the other hand, many machine learning-based detection methods rely on a large amount of historical data, which may lead to a high false alarm rate and affect the accuracy of the detection system.

[0005] Existing technologies also lack real-time dynamic analysis of API access behaviors and cannot comprehensively judge the risk level of access based on various factors such as request frequency and time interval. For the detection of abnormal access, existing technologies often rely on simple rules and fail to effectively combine complex behavior analysis and risk assessment, lacking the ability to flexibly respond to different types of attacks. Summary of the Invention

[0006] In view of the above problems, the present invention is proposed.

[0007] Therefore, the technical problem solved by the present invention is that the prior art usually relies on static rules, single-dimensional analysis or feature matching methods, and cannot effectively identify new attacks or abnormal behaviors that disguise normal traffic. At the same time, traditional methods mostly rely on fixed thresholds and rules, and do not comprehensively consider various factors, such as request frequency, time interval, etc., resulting in an inability to accurately evaluate the risk level of access behaviors.

[0008] To solve the above technical problems, the present invention provides the following technical solution: An API abnormal access detection and encryption protection method based on behavior analysis, including:

[0009] Receiving API access log data, and extracting access behavior feature information from the API access log data; constructing a behavior analysis graph based on the access behavior feature information; analyzing the behavior analysis graph to identify abnormal behaviors in the access behavior; performing risk assessment on the abnormal behaviors, and executing encryption protection measures.

[0010] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, wherein: the access behavior feature information includes user identification, IP address, API identifier, access timestamp, and request frequency.

[0011] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, wherein: the behavior analysis graph includes nodes and edges; the nodes include user nodes, API nodes, and IP nodes; the edges represent the access behaviors between the nodes, and the attributes of the edges include access timestamp and request frequency; for each access behavior, according to the access timestamp, calculate the access interval time, and adjust the weight of the edge based on the request frequency and the access interval time.

[0012] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, wherein: the identifying abnormal behaviors in the access behavior includes calculating the centrality of each node in the behavior analysis graph based on the PageRank algorithm, identifying potential abnormal nodes, if the PageRank value of the node exceeds a preset threshold, marking it as a potential abnormal node; performing weight change analysis on the edges of the potential abnormal nodes, if the weight change is greater than the preset threshold, determining that the node has abnormal access behavior; using the Louvain algorithm for community detection to identify whether there is a behavior of multiple nodes collaborating to launch an attack in the abnormal access behavior.

[0013] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, wherein: the PageRank algorithm is expressed as,

[0014] ;

[0015] Among them, represents the PageRank value of node . represents the damping factor, represents the total number of nodes in the graph, represents the set of neighbor nodes directly connected to node . represents the PageRank value of node . represents node 's out-degree.

[0016] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, among them: the weight change analysis is expressed as,

[0017] ;

[0018] Among them, represents the weight of the edge between node and node at time , represents the request frequency between node and node , represents the access timestamp between node and node at time , represents the access timestamp between node and node at time , represents the time threshold.

[0019] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis according to the present invention, among them: the Louvain algorithm is expressed as,

[0020] ;

[0021] ;

[0022] Among them, represents modularity, represents the total number of edges in the graph, represents the adjacency matrix, which is the connection strength between node and node in the graph, and are respectively node and node degree of represents the indicator function, and respectively represent the communities to which nodes and node belong, represents the weighted adjacency matrix, represents the maximum value of the request frequency between all node pairs, and respectively represent the adjustment factors, represents the time interval between nodes and node and represents a constant.

[0023] As a preferred solution of the API abnormal access detection and encryption protection method based on behavior analysis described in the present invention, wherein: the risk assessment of abnormal behaviors and the execution of encryption protection measures include:

[0024] If there is no behavior of multiple nodes collaborating to launch an attack, and it is only a single node abnormality, it is judged as the first risk level; if there is a behavior of multiple nodes collaborating to launch an attack, it is judged as the second risk level; when judged as the first risk level, limit the request frequency of a single node, adopt a flow limiting mechanism, limit the number of requests of a single node per unit time, and trigger an access warning; monitor the access behavior of a single node in real time, record the behavior log, and establish a blacklist mechanism to limit the access permission; use Token authentication for encryption protection; when judged as the second risk level, adopt multi-factor authentication and require the user of the attack source or attack node to perform secondary authentication; use AES encryption to encrypt all sensitive data transmissions; isolate the nodes of the attack source, identify and isolate all collaborating attack source nodes through a traffic filtering system, and limit the mutual communication between malicious nodes.

[0025] A computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, it implements the steps of the API abnormal access detection and encryption protection method based on behavior analysis as described above.

[0026] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the API abnormal access detection and encryption protection method based on behavior analysis as described above.

[0027] Advantages of the present invention: The method for API abnormal access detection and encryption protection based on behavior analysis provided by the present invention constructs a dynamic behavior analysis graph and combines the PageRank algorithm to perform centrality analysis on API access behaviors, thereby accurately identifying potential abnormal nodes. Compared with the existing detection methods based on rules or simple feature matching, the present invention can avoid the limitations of relying on static rules, has stronger adaptability and accuracy, and can effectively identify abnormal access behaviors especially when facing new attack means or attacks disguising as normal traffic.

[0028] By comprehensively considering multi-dimensional access features, a dynamic risk assessment of API access behaviors is realized. Different from the traditional single-dimensional analysis method, the present invention can comprehensively evaluate each access behavior, and then judge its abnormal degree and potential risk. This multi-dimensional and dynamic assessment method not only improves the accuracy of abnormal behavior identification, but also makes the security protection of APIs more flexible and adaptable, and can take targeted encryption protection measures according to different risk levels.

[0029] By introducing the Louvain algorithm for community detection, it is possible to identify attack behaviors initiated by multiple nodes in cooperation, effectively preventing the problem of insufficient ability to identify cooperative attacks in the prior art. This method can timely detect signs of joint attacks by multiple nodes in the case of abnormal network traffic, thereby providing a higher level of security protection for the system. This accurate identification of cooperative attacks not only enhances the security of APIs, but also improves the ability to identify complex attack patterns.

[0030] Combined with the refined risk assessment results, corresponding encryption protection measures can be executed according to different attack patterns and risk levels, effectively improving the security of APIs, and ensuring that in the face of various attack scenarios, it can respond flexibly and minimize potential security threats to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0032] Figure 1 It is the overall flowchart of a method for API abnormal access detection and encryption protection based on behavior analysis provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0034] In the following description, many specific details are set forth to facilitate a thorough understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0035] Embodiment 1

[0036] Referring to Figure 1 , for an embodiment of the present invention, there is provided an API abnormal access detection and encryption protection method based on behavior analysis, including:

[0037] Receiving API access log data, and extracting access behavior feature information from the API access log data; constructing a behavior analysis graph based on the access behavior feature information; analyzing the behavior analysis graph to identify abnormal behaviors in the access behavior; performing risk assessment on the abnormal behaviors, and executing encryption protection measures.

[0038] The access behavior feature information includes user identification, IP address, API identifier, access timestamp, and request frequency.

[0039] Specifically, the present invention realizes the extraction of access behavior feature information through an efficient log analysis framework. It can monitor each access request of the API interface in real time, and dynamically identify and extract key information affecting the security of the API interface by obtaining features such as request frequency, time interval, and access source IP. This feature information extraction mechanism does not rely on static rules, but combines real-time analysis and machine learning models to ensure strong adaptability to changing access behaviors. This method significantly improves the efficiency of feature extraction through the application of parallel processing and distributed computing, and is suitable for large-scale API environments.

[0040] It should be noted that this step is particularly suitable for the current API scenarios with high concurrency and high-frequency requests. In traditional security mechanisms, behavior feature extraction often relies on static models and is difficult to respond to changes in attackers' strategies in real time. However, through real-time data flow analysis, the present invention enables the extraction of behavior patterns to be continuously optimized over time. The effectiveness of this method has been verified based on historical data, significantly reducing the false alarm rate and missed alarm rate.

[0041] Furthermore, by accurately extracting access behavior features, the present invention can provide highly reliable data support for subsequent anomaly detection. By embedding time-sensitive behavior analysis in the feature information, the system of the present invention can identify subtle differences between different access patterns in real time, thereby providing more precise security protection. This method improves the ability of the API interface to respond to various abnormal access behaviors, significantly enhances the overall security of the API, and reduces the impact of common attacks such as brute force cracking and DDoS attacks on the system.

[0042] The behavior analysis graph includes nodes and edges; the nodes include user nodes, API nodes, and IP nodes; the edges represent access behaviors between nodes, and the attributes of the edges include access timestamps and request frequencies; for each access behavior, according to the access timestamp, the access interval time is calculated, and the weight of the edge is adjusted based on the request frequency and the access interval time.

[0043] Specifically, when constructing the behavior analysis graph, the present invention takes user nodes, API nodes, and IP nodes as core elements, and represents the interaction between different access behaviors through the edges between these nodes. Each node contains rich access data features, and each edge is weighted by information such as access timestamp and frequency, forming a graph structure that can dynamically reflect changes in system behavior. This structure supports efficient graph traversal and query, ensuring that access behaviors and anomaly detection can still be quickly calculated under large-scale API calls.

[0044] It should be noted that the innovation of the behavior analysis graph lies in its multi-dimensional modeling of access behaviors. Different from traditional behavior analysis methods, the behavior analysis graph does not simply rely on single-dimensional features (such as IP addresses or request frequencies), but establishes a richer access behavior map by comprehensively considering multi-level associations between nodes. This enables the present invention to accurately identify potential connections between different attack patterns when dealing with complex attack scenarios, thereby improving the accuracy and timeliness of attack recognition.

[0045] Furthermore, through the construction of the behavior analysis graph, the present invention can not only clearly display the access associations between nodes, but also dynamically adjust the graph structure to adapt to real-time changing access patterns. This mechanism ensures that the update of the graph is synchronized with the evolution of actual attack behaviors, providing real-time and accurate data support for subsequent anomaly detection and collaborative attack recognition. Finally, this dynamic behavior analysis graph provides a more three-dimensional and refined security monitoring for the protection system of the API interface, and can effectively identify and defend potential complex attacks.

[0046] The identification of abnormal behaviors in the access behavior includes calculating the centrality of each node in the behavior analysis graph based on the PageRank algorithm, identifying potential abnormal nodes. If the PageRank value of a node exceeds the preset threshold, it is marked as a potential abnormal node; analyzing the weight change of the edges of the potential abnormal nodes. If the weight change is greater than the preset threshold, it is determined that the node has abnormal access behavior; using the Louvain algorithm for community detection to identify whether there is a behavior of multiple nodes collaborating to launch an attack in the abnormal access behavior.

[0047] Specifically, the identification of abnormal behaviors relies on fine-grained node centrality analysis. By using the PageRank algorithm, the present invention can calculate the centrality of each node in the behavior analysis graph and accurately identify those nodes that deviate from the normal behavior pattern. These nodes are characterized by abnormal activity or abnormal frequent access and become potential attack targets. By setting a reasonable centrality threshold, the system can flexibly identify and classify abnormal accesses at an early stage, ensuring the system's response speed to attacks.

[0048] It should be noted that the innovation of this abnormal behavior identification method lies in the combination of the network graph structure and node importance analysis, enabling the selection of those nodes that may have abnormal behaviors even among a large number of legitimate access requests. This method breaks through the limitations of traditional reliance on static rules or simple threshold judgments and can adaptively handle different types of abnormal behaviors, such as brute force cracking, IP spoofing, etc., thereby reducing false positives and false negatives.

[0049] Furthermore, by accurately identifying abnormal nodes, the present invention can not only detect abnormal behaviors at an early stage of the attack but also further reveal the potential patterns of the attack through in-depth analysis of the relationships between nodes. For example, by further calculating the behavioral characteristics such as the request frequency and time interval of abnormal nodes, the system can accurately determine whether it is an abnormal access of a single node or an attack behavior jointly launched by multiple nodes, providing a decision basis for subsequent risk assessment and protection strategies.

[0050] The PageRank algorithm is expressed as

[0051] ;

[0052] where represents the PageRank value of node and represents the importance or centrality of node in the behavior analysis graph. Node can be a user node, an API node, or an IP node. represents the damping factor, set to 0.85, which represents the probability of random jump and avoids all PageRank values concentrating on one node. denotes the total number of nodes in the graph. In the present invention, the graph contains three nodes representing a user node, an API node, and an IP node. denotes the set of neighbor nodes directly connected to the node, that is, all nodes directly connected to the node by an edge. In the present invention, the nodes are connected by access behavior edges, and each edge has attributes of access timestamp and request frequency. denotes the node 's PageRank value. denotes the node 's out-degree.

[0053] Specifically, at the beginning stage of the algorithm, the PageRank value of each node is equal and set to:

[0054] ;

[0055] where is the total number of nodes in the graph (3 in this embodiment, namely the user node, the API node, and the IP node).

[0056] Specifically, the present invention uses the PageRank algorithm to calculate the centrality of each node in the behavior analysis graph, aiming to determine whether there is abnormal access behavior according to the relative importance of the node in the access graph. By comprehensively considering the connection strength between the node and its adjacent nodes, the PageRank algorithm can effectively distinguish normal users from potential attackers. Especially when facing a large-scale and complex access graph, it can quickly locate the nodes with abnormal centrality.

[0057] It should be noted that the advantage of the PageRank algorithm lies in its strong robustness and scalability, and it can still maintain a high calculation efficiency when facing a large amount of data. Different from other simple centrality measurement methods, PageRank not only focuses on the direct connections of nodes, but also considers the entire network structure, making the recognition of complex attack behaviors more accurate. It can effectively cope with the situation where node relationships are complex and attackers adopt decentralized strategies, thereby improving the comprehensiveness and accuracy of abnormal behavior recognition.

[0058] Furthermore, the PageRank algorithm can significantly improve the recognition rate of abnormal behaviors, especially in an environment with multiple users and multiple API calls. Through the refined analysis of node centrality, the present invention can accurately identify the key nodes used by attackers to launch attacks, so as to take appropriate protection measures before the attack spreads and prevent the attack from causing system crashes or data leaks.

[0059] The weight change analysis is expressed as

[0060] ;

[0061] Among them, represents the weight of the edge between node and node at time , that is, the intensity of the access behavior between node and node . The weight of the edge reflects the change of the request frequency and the time interval. The larger the weight value of the edge, the more frequent or abnormal the access behavior between node and node . represents the request frequency between node and node , that is, within the time period , the number of accesses from node to node . The request frequency reflects the intensity of the access behavior. represents the access timestamp between node and node at time , that is, the specific time when the access from node to node occurs. represents the access timestamp between node and node at time . represents the time threshold, which is used to control the sensitivity of the change of the access time and determine whether the change of the time interval will have a significant impact on the weight of the edge. If the access time interval is large, it may be considered an abnormal behavior.

[0062] Specifically, the weight change analysis formula is based on the time series data of API access behavior, and adjusts the weight of the edge by using the change of the request frequency and the time interval. The formula represents the change of the intensity of the access behavior through the dynamically changing weight, enabling the system to effectively distinguish normal access from abnormal behavior. In the request pattern of high frequency and low time interval, the formula can timely identify potential brute force cracking or DDoS attacks.

[0063] It should be noted that the weight change analysis formula has extremely high adaptability and can continuously adjust the threshold and calculation method according to real-time data to cope with different attack patterns. Traditional methods often rely on static rules and are easily circumvented by attackers, while the formula of the present invention can be dynamically adjusted according to the actual access situation, thereby improving the real-time performance and accuracy of abnormal behavior identification, especially when facing diverse attack methods.

[0064] Furthermore, through the weight change analysis performed by this formula, the anomaly detection system of the present invention has the ability of dynamic recognition and self-adjustment. When the system detects an abnormal pattern, it can quickly adjust the edge weights in the graph, and combined with subsequent abnormal behavior judgment and attack pattern recognition, timely implement targeted protection measures such as flow limiting and dynamic encryption, greatly reducing the impact on normal users.

[0065] The Louvain algorithm is expressed as

[0066] ;

[0067] ;

[0068] where represents modularity, represents the total number of edges in the graph, reflecting the overall scale of the graph, represents the adjacency matrix, which is the connection strength between nodes and node in the graph. If there is an edge between node and node , then , otherwise it is 0. and are the degrees of nodes and node respectively, that is, the number of edges connected to them. represents the indicator function. If nodes and node belong to the same community, it is 1; otherwise it is 0. represents the weighted adjacency matrix, which is the connection relationship between nodes and node . If there is a direct connection between nodes and node , then , otherwise . represents the maximum value of the request frequencies between all node pairs, which is used to normalize the request frequency so that the request frequencies between different node pairs can be compared under the same standard. and represent the adjustment factors respectively, which are used to control the influence of the request frequency on the weighting of the adjacency matrix. The role of this factor is to ensure that the influence of the request frequency on the calculation is within an adjustable range. represents the time interval between nodes and node , that is, the time interval between node and node The time difference after the most recent interaction between them. The value of the time interval reflects the periodicity of interactions between nodes. A shorter time interval usually indicates a high-frequency access behavior. Represents a constant.

[0069] First, each node (user node, API node, IP node) in the behavior analysis graph reflects different access entities and access patterns. The centrality of a node is a key metric for measuring the importance of that node in the network. In the present invention, the PageRank algorithm is used to evaluate the centrality of each node by calculating the PageRank value of each node to determine its relative importance in the access behavior. The PageRank algorithm evaluates the influence of a node by considering the in-degree of each node and its connection with other nodes. If the PageRank value of a certain node exceeds a preset threshold, that node is regarded as a potential abnormal node, indicating that the node has a high abnormal risk in the access behavior.

[0070] After identifying potential abnormal nodes, the next step is to analyze the change in the weight of the edges between that node and other nodes. The edges in the access behavior graph represent the interaction behaviors between different nodes, and the weights of the edges change with different access behaviors. For each access behavior between nodes, the weight of the edge will be adjusted according to the access timestamp and request frequency. If the change in the weight of the edge of a certain node exceeds a preset threshold, it indicates that the access behavior of that node is abnormal, which may be caused by malicious behavior or abnormal requests. This step further refines the connection relationship between nodes to ensure an accurate judgment of abnormal behaviors.

[0071] After confirming potential abnormal nodes, these nodes are further analyzed through a community detection algorithm. In the present invention, the Louvain algorithm is used to identify the community structure between nodes. The purpose of community detection is to identify the relationship patterns between nodes and analyze whether there are attack behaviors initiated collaboratively by multiple nodes. Through the Louvain algorithm, the nodes in the behavior analysis graph will be divided into different communities according to the similarity of their access behaviors. Each community represents a group of nodes that are somewhat related in access behavior, and these nodes may be normal or malicious nodes conducting collaborative attacks.

[0072] If multiple nodes are in the same community and there are abnormal access behavior patterns, this may indicate some form of collaborative attack between these nodes. For example, multiple IP nodes frequently request the same API node, and there are obvious abnormal patterns in the access time and frequency of these requests, indicating that these IP nodes may have initiated a DDoS attack or other forms of distributed attacks collaboratively. By identifying these signs of collaborative attacks, the Louvain algorithm can effectively reveal the abnormal behaviors and potential attack patterns between multiple nodes.

[0073] Specifically, the Louvain algorithm performs community detection by optimizing the modularity Q value, thereby discovering potential collaborative attack behaviors in the behavior analysis graph. By dividing nodes into different communities, the algorithm can automatically identify which nodes may jointly initiate attacks, providing reliable data support for subsequent collaborative attack detection.

[0074] It should be noted that the advantage of the Louvain algorithm lies in its high degree of automation and unsupervised learning ability. When faced with large-scale data, it can automatically identify the distributed attack strategies that attackers may adopt, avoiding the over-reliance of traditional methods on specific attack patterns. Through precise community partitioning, the system can identify abnormal collaborative attack patterns at the initial stage of attack behavior, so as to take preventive measures before the attack spreads.

[0075] Furthermore, the application of the Louvain algorithm enables the present invention to effectively identify attack behaviors jointly initiated by multiple nodes. Especially in complex scenarios such as distributed attacks (such as DDoS, distributed crawler attacks), it can quickly identify and adopt defense strategies. Based on the results of community detection, the present invention can efficiently determine the attack source and take countermeasures at an early stage, greatly improving the protection ability of the API.

[0076] Performing risk assessment on abnormal behaviors and implementing encryption protection measures includes: if there is no behavior of multiple nodes jointly initiating attacks and only a single node is abnormal, it is judged as the first risk level; if there is a behavior of multiple nodes jointly initiating attacks, it is judged as the second risk level; when judged as the first risk level: restricting the request frequency of a single node, adopting a flow-limiting mechanism to limit the number of requests of this node per unit time, and triggering an access warning; real-time monitoring of the access behavior of a single node, recording behavior logs, and establishing a blacklist mechanism to restrict the access rights of this node; using encryption protection based on Token authentication to encrypt the requests of this node; when judged as the second risk level: adopting multi-factor authentication, requiring users of the attack source or attack nodes to perform secondary authentication; using the Advanced Encryption Standard (AES) to encrypt and protect all sensitive data transmissions; isolating the attack source node, using traffic monitoring and filtering devices to identify and isolate all collaborative attack source nodes, restricting the mutual communication between these nodes, preventing the spread of attacks; implementing a distributed defense mechanism to perform load balancing and traffic diversion on abnormal traffic, ensuring that the traffic borne by the server is within a controllable range, avoiding server paralysis due to excessive traffic, and ensuring the stable operation of the API service.

[0077] Embodiment 2

[0078] An embodiment of the present invention, which is different from the first embodiment in that:

[0079] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0080] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0081] More specific examples (non-exhaustive list) of computer-readable media include the following: electrical connection parts with one or more wirings (electronic devices), portable computer disk cartridges (magnetic devices), random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memories), fiber optic devices, and portable compact disc read-only memories (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or processing it in other suitable ways if necessary, and then storing it in a computer memory.

[0082] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0083] Embodiment 3

[0084] An embodiment of the present invention provides a method for API abnormal access detection and encryption protection based on behavior analysis. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through simulation experiments.

[0085] The experiment was carried out on a server configured with an 8-core CPU, 64GB of memory, and a 2TB hard drive. The experimental dataset was real API access logs, including 50 million pieces of data, covering various scenarios such as normal access, brute-force attack, DDoS attack, etc. In the method of the present invention, the damping factor of PageRank was set to 0.85, the modularity optimization parameters λ1 and λ2 in the Louvain algorithm were set to 0.5 and 0.2 respectively, the time interval threshold was set to 10 seconds, and the frequency threshold was 100 times / minute.

[0086] At the beginning of the experiment, the traditional method first collected API access log data and selected a 50GB dataset containing normal requests and various attack patterns (including DDoS attacks, brute-force attacks, etc.). Then, a traditional rule-based anomaly detection method was used to perform anomaly detection by setting thresholds. First, the request frequency and time interval of each user or IP were calculated. When the request frequency exceeded the set threshold, it was marked as a frequency anomaly; if the time interval between adjacent accesses was less than a certain preset value, it was determined as a time interval anomaly. Next, the system detected the anomalies through the log records and output the detailed information of the abnormal requests. After the anomaly detection, the system executed corresponding encryption protection measures according to the preset rules. For example, if an anomaly of a single node was found, the system would limit the request frequency of that node through a flow-limiting mechanism. If the IP address or user of an abnormal request was detected, the system would add it to the blacklist and prevent subsequent abnormal requests through a simple Token authentication encryption method. Finally, the system monitored the access behavior of the abnormal nodes and restricted the abnormal traffic accordingly.

[0087] At the beginning of the experiment, the method of the present invention first collects the same API access log data as the traditional method. Then, a dynamic user-API-IP behavior analysis graph is constructed through the technical solution of the present invention, with each user, API, and IP address as nodes respectively, and the access behavior as edges. The edge weights between nodes are adjusted by access timestamps and request frequencies. First, calculate the PageRank value of each node in the behavior analysis graph, and identify potential abnormal nodes based on the centrality of the nodes. If the PageRank value of a certain node exceeds the set threshold, mark this node as a potential abnormal node. Then, analyze the changes in the edge weights of these potential abnormal nodes, calculate the changes in request frequencies and time intervals. If the changes exceed the preset range, confirm the abnormal behavior of this node. To identify collaborative attack behaviors, further use the Louvain algorithm to perform community detection on the behavior analysis graph to check whether there are multiple nodes initiating abnormal requests within a similar time. If signs of multiple nodes collaborating to launch an attack are found, conduct a risk assessment on them and execute different encryption protection measures according to the assessment results. If a single node abnormality is detected, limit its request frequency through a rate limiting mechanism and use simple Token authentication for encryption protection; if a collaborative attack is found, strengthen security protection, require multi-factor authentication for the attacking source IP or user, and at the same time enhance the encryption protocol, use the Advanced Encryption Standard (AES) to encrypt and transmit sensitive data to prevent data leakage. The experimental results are shown in Table 1.

[0088] Table 1 Comparison Table of Experimental Results

[0089] Detection accuracy False alarm rate Processing time (seconds) Abnormality detection rate Risk assessment accuracy Traditional method 81% 10% 13 74% 78% Method of the present invention 94% 4% 8 92% 96%

[0090] Compared with the traditional method, the method of the present invention comprehensively captures and analyzes multi-dimensional feature information in API access by constructing a dynamic user-API-IP behavior analysis graph, including the relationships between user, IP, and API nodes, as well as the access behaviors between nodes. The graph-based modeling method enables the identification of abnormal access in a higher dimension, while the traditional method only relies on static rules and simple thresholds and cannot adapt to complex and changing attack patterns. By using the PageRank algorithm to perform centrality analysis on the nodes in the behavior analysis graph, potential abnormal nodes can be effectively identified. By calculating the request frequencies, time intervals, and changes in edge weights of the nodes, the present invention can accurately determine potential abnormal behaviors, avoiding the rough judgment of abnormal behaviors in the traditional method. The traditional method relies on fixed thresholds and is easily affected by fluctuations in normal user access behaviors, resulting in false positives or false negatives. The present invention greatly improves the detection accuracy of abnormal access through the dynamic adjustment of the behavior graph and multi-level data analysis.

[0091] In addition, based on the detection of abnormal behaviors, the method of the present invention also introduces the Louvain algorithm for community detection, which can effectively identify collaborative attack behaviors. Through the division of the community structure, it is possible to accurately identify whether there is a collaborative attack pattern among multiple nodes, which cannot be achieved by traditional methods. Traditional methods cannot effectively identify in the case of the collaborative action of multiple attack sources and are prone to missing some complex attack behaviors such as distributed attacks or account takeovers.

[0092] In terms of risk assessment and the implementation of encryption protection measures, the processing method of the present invention also far exceeds that of traditional methods. Traditional methods only perform single processing on abnormal behaviors according to static rules, while the present invention can flexibly adjust the encryption protection intensity and security protection measures according to the specific characteristics and attack patterns of abnormal behaviors.

[0093] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A method for detecting and encrypting API access abnormality based on behavior analysis, characterized in that: include: Receive API access log data, and extract access behavior feature information from the API access log data; Constructing a behavior analysis graph based on the access behavior feature information; Analyzing the behavior analysis graph to identify abnormal behaviors in access behaviors; Conduct risk assessments on abnormal behavior and implement encryption protection measures; The identifying of abnormal behavior in access behavior includes calculating the centrality of each node in the behavior analysis graph based on the PageRank algorithm, identifying potential abnormal nodes, and marking the node as a potential abnormal node if the PageRank value of the node exceeds a preset threshold; Analyze the weight changes of the edges of potential abnormal nodes. If the weight change is greater than the preset threshold, it is determined that the node has abnormal access behavior. Use the Louvain algorithm to perform community detection and identify whether abnormal access behavior involves multiple nodes cooperating to launch attacks; The PageRank algorithm is expressed as, ; in, Representation Node The PageRank value, represents the damping factor, represents the total number of nodes in the graph, Representation and Node The set of directly connected neighbor nodes, Representation Node The PageRank value, Representation Node The out-degree of The weight change analysis is expressed as, ; in, Representation Node With Node The edge between the The weight of Representation Node With Node The request frequency between Representation Node With Node Between time The access timestamp is Representation Node With Node Between time The access timestamp is Indicates the time threshold; The Louvain algorithm is expressed as, ; ; in, represents modularity, represents the total number of edges in the graph, Represents the adjacency matrix, which is the node in the graph and nodes The connection strength between and Node and nodes The degree of represents the indicator function, and Node and nodes The community you belong to, represents the weighted adjacency matrix, Indicates the maximum value of the request frequency between all node pairs, and They represent the adjustment factors, Representation Node and nodes The time interval between Represents a constant.

2. The method for detecting and encrypting API access abnormality based on behavior analysis as claimed in claim 1, characterized in that: The access behavior characteristic information includes user identification, IP address, API identifier, access timestamp and request frequency.

3. The method for detecting and encrypting API access abnormality based on behavior analysis as claimed in claim 2, characterized in that: The behavior analysis graph includes nodes and edges; The nodes include user nodes, API nodes and IP nodes; The edge represents the access behavior between nodes, and the attributes of the edge include access timestamp and request frequency; For each access behavior, the access interval is calculated according to the access timestamp, and the weight of the edge is adjusted based on the request frequency and access interval.

4. The method for detecting abnormal API access and encrypting it based on behavior analysis as claimed in claim 3, characterized in that: The risk assessment of abnormal behavior and the implementation of encryption protection measures include: If there is no coordinated attack by multiple nodes, and only a single node is abnormal, it is judged as the first risk level; If there are multiple nodes cooperating to launch an attack, it is judged as the second risk level; When it is judged as the first risk level, the request frequency of a single node is limited, and a current limiting mechanism is adopted to limit the number of requests per unit time of a single node, and an access warning is triggered; the access behavior of a single node is monitored in real time, the behavior log is recorded, and a blacklist mechanism is established to limit access rights; Token authentication is used for encryption protection; When it is judged to be the second risk level, multi-factor authentication is used to require users of the attack source or attack node to perform secondary authentication; AES encryption is used to encrypt all sensitive data transmissions; the nodes of the attack source are isolated, and all collaborative attack source nodes are identified and isolated through the traffic filtering system to limit the mutual communication between malicious nodes.

5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the API abnormal access detection and encryption protection method based on behavior analysis described in any one of claims 1 to 4 are implemented.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the API abnormal access detection and encryption protection method based on behavior analysis described in any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Data safety monitoring system

    CN112560027A

  • Abnormal access detection method and device, electronic equipment and storage medium

    CN114650187A