Staged multi-dimensional Web security detection system
Through a staged and multi-dimensional web security detection system, multi-level detection is performed using access control and detection engines, the problem of insufficient protection in the face of complex attacks is solved, and more efficient security protection and stability is achieved.
Patent Information
- Application Number
- CN202510135948.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-07
AI Technical Summary
The existing Web Application Firewall (WAF) has a weak protection mechanism when facing complex and diverse attack methods, and has insufficient detection and response speed, accuracy and flexibility, so it cannot effectively deal with emerging security threats.
A staged and multi-dimensional web security detection system is proposed. Through the access control engine and the detection engine, multiple detection stages are performed successively, including access control, website tamper protection, web basic protection, CC attack protection, BOT management and API security protection, etc., to provide multi-level security detection and protection.
It significantly improves the protection and security of web applications, enhances the stability and flexibility of the system, can effectively deal with complex and diverse attack methods, and improves its response capabilities to emerging security threats.
Smart Images

Figure CN119995976A_ABST
Abstract
Description
Technical Field
[0001] The invention discloses a phased and multi-dimensional Web security detection system, and relates to the technical field of Web management. Background Art
[0002] With the rapid development of Internet technology, Web applications have become one of the main ways for various enterprises and institutions to provide services. However, the accompanying Web security issues are becoming increasingly serious. Attackers use various means to attack Web applications, resulting in data leakage, business interruption and economic losses. Common Web attacks include SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), distributed denial of service (DDoS) attacks, and abuse and malicious calls of API interfaces. Although the existing Web Application Firewall (WAF) can provide a certain degree of protection, in the face of increasingly complex and diverse attack methods, the protection mechanism seems to be unable to cope with it. In addition, the existing WAF has deficiencies in detection and response speed, accuracy and flexibility, and cannot effectively deal with emerging security threats. Summary of the invention
[0003] In view of the problems of the prior art, the present invention provides a phased and multi-dimensional Web security detection system to improve the protection capability of Web applications and enhance the security and stability of Web applications.
[0004] The specific scheme proposed by the present invention is:
[0005] The present invention provides a phased and multi-dimensional Web security detection method, which performs detection in each phase on a request to access a Web application in sequence:
[0006] Step 1: First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address.
[0007] Based on the extracted information, the access control engine is used to match the blacklist. If the IP blacklist or regional blacklist is matched, the access request is immediately denied. Otherwise, the speed limit detection is performed.
[0008] Through the speed limit detection, it is determined whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied, otherwise it enters the whitelist detection.
[0009] The whitelist is used to check whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining checks and be forwarded directly to the origin server. Otherwise, it enters the detection engine to perform the remaining various checks.
[0010] Step 2: Receive client requests that are not in the whitelist through the detection engine, first determine whether the client request has a cache of the content to be accessed, and if so, perform tampering identification on the URI related information. If tampering information is identified, deny the request access, otherwise perform subsequent Web basic protection detection. If there is no cache of the content to be accessed, skip tampering identification and directly perform subsequent Web basic protection detection.
[0011] Step 3: Perform Web basic protection detection: Extract request features, including URL parameters, request body content, and HTTP header information, and match the features with the predefined attack pattern library. If the match is successful, the request access is denied, otherwise CC security protection detection is performed.
[0012] Step 4: Perform CC security protection detection and analyze the behavior characteristics of the request, which include request frequency, source IP address, and request mode. According to the behavior characteristics of the request, identify whether the request has potential CC attack. If so, deny the request access. Otherwise, perform the detection in the BOT management stage.
[0013] Step 5: Perform detection in the BOT management phase, and identify whether the request is from a malicious BOT source based on the behavioral characteristics of the request. If so, deny the request access. Otherwise, perform API security protection detection.
[0014] Step 6: Perform API security protection detection to classify the API usage, monitor API risks, and detect API vulnerabilities of the requested API. If the request fails the detection, the access request will be denied. If the request passes the detection, the request will be forwarded to the origin server.
[0015] Further, step 3 of the phased multi-dimensional Web security detection method specifically includes:
[0016] Extract the requested features,
[0017] Predefined attack pattern library, which stores SQL injection attack strategies, cross-site scripting attack strategies, and cross-site request forgery attack strategies.
[0018] Match the signature with the attack strategy in the predefined attack pattern library. If the match is successful, the access request is denied. Otherwise, CC security protection detection is performed.
[0019] Further, step 4 of the phased multi-dimensional Web security detection method specifically includes:
[0020] Use anomaly detection algorithms to analyze request behavior characteristics.
[0021] Establish a baseline behavior model, and record normal traffic patterns through the baseline behavior model.
[0022] Monitor and analyze current traffic in real time, compare it with the baseline behavior model, identify abnormal traffic peaks and abnormal behavior patterns,
[0023] Determine whether there is a potential CC attack based on abnormal traffic peaks and abnormal behavior patterns. If so, deny the access request. Otherwise, perform the BOT management stage detection.
[0024] Further, step 5 of the phased multi-dimensional Web security detection method specifically includes:
[0025] Analyze the behavioral characteristics of the request,
[0026] Identify abnormal automation behaviors through machine learning algorithms and predefined BOT feature libraries.
[0027] For suspicious requests with abnormal automated behavior, CAPTCHA challenges are used to distinguish between human users and automated programs. At the same time, the access patterns of specific IP addresses are monitored to identify whether there are malicious BOT sources. If so, the request access is denied. Otherwise, API security protection detection is performed.
[0028] Further, step 6 of the phased multi-dimensional Web security detection method specifically includes:
[0029] Classify the requested APIs, identify the uses of different APIs, and assign corresponding security policies to different categories of API applications.
[0030] Perform identity authentication and permission checks to ensure that authorized users have access to specific API interfaces.
[0031] Monitor API risks: Analyze request content and parameters, detect abnormal patterns and illegal calling behaviors,
[0032] Perform API vulnerability detection: Perform regular scanning and testing to identify and fix security vulnerabilities in APIs and prevent known vulnerabilities from being maliciously exploited.
[0033] The present invention also provides a phased and multi-dimensional Web security detection system, which sequentially performs phased detection on requests for accessing Web applications, including an access control engine and a detection engine.
[0034] First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address.
[0035] The access control engine uses the extracted information to match the blacklist. If it matches the IP blacklist or regional blacklist, the access request is immediately denied. Otherwise, it enters the speed limit detection.
[0036] The access control engine performs rate limit detection to determine whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied. Otherwise, it enters the whitelist detection.
[0037] The access control engine performs whitelist detection to match whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining detection and be forwarded directly to the origin server. Otherwise, it enters the detection engine to perform various remaining detections.
[0038] The detection engine receives client requests that are not in the whitelist and first determines whether there is a cache of the content to be accessed by the client request. If so, tampering identification is performed on the URI related information. If tampering information is identified, the request access is denied. Otherwise, subsequent Web basic protection detection is performed. If there is no cache of the content to be accessed, tampering identification is skipped and subsequent Web basic protection detection is performed directly.
[0039] Perform Web basic protection detection through the detection engine: extract request features, including URL parameters, request body content and HTTP header information, match the features with the predefined attack pattern library, and deny the request access if the match is successful, otherwise perform CC security protection detection.
[0040] The detection engine performs CC security protection detection and analyzes the behavior characteristics of the request, including request frequency, source IP address, and request mode. Based on the behavior characteristics of the request, it identifies whether the request has potential CC attack. If so, the request access is denied. Otherwise, the BOT management stage detection is performed.
[0041] The detection engine performs detection in the BOT management phase, and identifies whether the request is from a malicious BOT source based on the behavior characteristics of the request. If so, the request access is denied. Otherwise, API security protection detection is performed.
[0042] API security protection detection is performed through the detection engine to classify the API usage, monitor API risks and detect API vulnerabilities of the requested API. If it fails the detection, the request access is denied. If it passes the detection, the request is forwarded to the source server.
[0043] Furthermore, the detection engine of the phased multi-dimensional Web security detection system extracts request features and a predefined attack pattern library, which stores SQL injection attack strategies, cross-site scripting attack strategies, and cross-site request forgery attack strategies. The attack strategies in the predefined attack pattern library are matched according to the features. If the match is successful, the request access is denied, otherwise CC security protection detection is performed.
[0044] Furthermore, the detection engine of the phased multi-dimensional Web security detection system adopts an anomaly detection algorithm to analyze request behavior characteristics, establish a baseline behavior model, record normal traffic patterns through the baseline behavior model, monitor and analyze current traffic in real time, compare it with the baseline behavior model, identify abnormal traffic peaks and abnormal behavior patterns, and determine whether there is a potential CC attack based on the abnormal traffic peaks and abnormal behavior patterns. If so, the request access is denied, otherwise, the BOT management stage detection is performed.
[0045] Furthermore, the detection engine of the phased and multi-dimensional Web security detection system analyzes the behavioral characteristics of the request, identifies abnormal automated behavior through machine learning algorithms and a predefined BOT feature library, and uses CAPTCHA challenges to distinguish between human users and automated programs for suspicious requests with abnormal automated behavior. At the same time, it monitors the access pattern of specific IP addresses to identify whether there is a malicious BOT source. If so, the request access is denied, otherwise API security protection detection is performed.
[0046] Furthermore, the detection engine of the phased and multi-dimensional Web security detection system classifies the requested APIs, identifies the uses of different APIs, and assigns corresponding security policies to different categories of API applications, performs identity authentication and permission checks, ensures that authorized users access specific API interfaces, and monitors API risks: analyzes request content and parameters, detects abnormal patterns and illegal calling behaviors, and performs API vulnerability detection: regularly scans and tests, identifies and fixes security vulnerabilities in APIs, and prevents known vulnerabilities from being maliciously exploited.
[0047] The benefits of the present invention are:
[0048] The present invention conducts multi-dimensional Web security detection in stages. By dividing multiple independent detection stages, one or more stages can be flexibly selected and executed according to business needs, thereby significantly improving the stability and protection effect of the system. Each stage includes access control, website anti-tampering, Web basic protection, CC attack protection, BOT management, API security protection and sensitive information leakage prevention, etc. Each stage focuses on different security dimensions and provides targeted detection and protection measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a schematic diagram of the application process of the access control engine of the present invention.
[0050] Figure 2 It is a schematic diagram of the application process of the website access tampering engine of the present invention.
[0051] Figure 3 It is a schematic diagram of the application process of the detection engine of the present invention.
[0052] Figure 4 It is a timing diagram of each detection stage of the present invention. DETAILED DESCRIPTION
[0053] The present invention is further described below in conjunction with the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it, but the embodiments are not intended to limit the present invention.
[0054] Example 1
[0055] The present invention provides a phased and multi-dimensional Web security detection method, which performs detection in each phase on a request to access a Web application in sequence:
[0056] Step 1: First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address.
[0057] Based on the extracted information, the access control engine is used to match the blacklist. If the IP blacklist or regional blacklist is matched, the access request is immediately denied. Otherwise, the speed limit detection is performed.
[0058] Through the speed limit detection, it is determined whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied, otherwise it enters the whitelist detection.
[0059] The whitelist is used to detect whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining checks and be forwarded directly to the source server. Otherwise, it enters the detection engine to perform various remaining checks.
[0060] Step 2: Receive client requests that are not in the whitelist through the detection engine, first determine whether the client request has a cache of the content to be accessed, and if so, perform tampering identification on the URI related information. If tampering information is identified, deny the request access, otherwise perform subsequent Web basic protection detection. If there is no cache of the content to be accessed, skip tampering identification and directly perform subsequent Web basic protection detection.
[0061] Step 3: Perform basic Web protection detection: Extract request features, including URL parameters, request body content, and HTTP header information, and match the features with the predefined attack pattern library. If the match is successful, the request access is denied, otherwise CC security protection detection is performed.
[0062] Specifically, they may include:
[0063] Extract the requested features,
[0064] Predefined attack pattern library, which stores SQL injection attack strategies, cross-site scripting attack strategies, and cross-site request forgery attack strategies.
[0065] Match the signature with the attack strategy in the predefined attack pattern library. If the match is successful, the access request is denied. Otherwise, CC security protection detection is performed.
[0066] Step 4: Perform CC security protection detection and analyze the behavioral characteristics of the request, which include request frequency, source IP address, and request mode. Identify whether the request has potential CC attacks based on the behavioral characteristics of the request. If so, deny the request access. Otherwise, perform detection in the BOT management stage.
[0067] Specifically, they may include:
[0068] Use anomaly detection algorithms to analyze request behavior characteristics.
[0069] Establish a baseline behavior model, and record normal traffic patterns through the baseline behavior model.
[0070] Monitor and analyze current traffic in real time, compare it with the baseline behavior model, identify abnormal traffic peaks and abnormal behavior patterns,
[0071] Determine whether there is a potential CC attack based on abnormal traffic peaks and abnormal behavior patterns. If so, deny the access request. Otherwise, perform the BOT management stage detection.
[0072] The detection strategy can be adjusted dynamically to enhance the protection against complex attacks. Once a CC attack is confirmed, the system will immediately take protective measures, such as limiting the request frequency, rejecting malicious IP addresses and triggering alarms, while recording attack logs for subsequent analysis and optimization of protection strategies.
[0073] Step 5: Perform detection in the BOT management phase, and identify whether the request has a malicious BOT source based on the behavioral characteristics of the request. If so, deny the request access; otherwise, perform API security protection detection.
[0074] Specifically, they may include:
[0075] Analyze the behavioral characteristics of the request,
[0076] Identify abnormal automation behaviors through machine learning algorithms and predefined BOT feature libraries.
[0077] For suspicious requests with abnormal automated behavior, CAPTCHA challenges are used to distinguish between human users and automated programs. At the same time, the access patterns of specific IP addresses are monitored to identify whether there are malicious BOT sources. If so, the request access is denied. Otherwise, API security protection detection is performed.
[0078] The detection strategy can be adjusted dynamically to respond to new BOT attacks in a timely manner. All detected BOT behaviors and measures taken will be recorded in detail for subsequent analysis and optimization of protection strategies. Through this series of steps, the BOT management stage can effectively identify and manage the behavior of automated programs, prevent malicious crawlers and automated attacks, and ensure the normal operation of Web applications and data security.
[0079] Step 6: Perform API security protection detection to classify the API usage, monitor API risks, and detect API vulnerabilities of the requested API. If the request fails the detection, the access request will be denied. If the request passes the detection, the request will be forwarded to the origin server.
[0080] Specifically, they may include:
[0081] Classify the requested APIs, identify the uses of different APIs, and assign corresponding security policies to different categories of API applications.
[0082] Perform identity authentication and permission checks to ensure that authorized users have access to specific API interfaces.
[0083] Monitor API risks: Analyze request content and parameters, detect abnormal patterns and illegal calling behaviors,
[0084] Perform API vulnerability detection: Perform regular scanning and testing to identify and fix security vulnerabilities in APIs and prevent known vulnerabilities from being maliciously exploited.
[0085] In addition, sensitive information can be filtered and processed for the response content from the source server to the client to ensure that sensitive data is not leaked. Specifically, the response content returned by the server is fully scanned to identify potential sensitive information, such as ID number, mobile phone number, credit card number, etc. Then, according to the predefined security policy, the detected sensitive information is processed, including data desensitization, display shielding, etc., to ensure that this information is not transmitted and exposed in plain text. The sensitive information leakage prevention stage can effectively protect user privacy and data security, prevent sensitive information leakage, and ensure the security and compliance of Web applications in data processing and transmission.
[0086] The present invention also provides a phased and multi-dimensional Web security detection system, which sequentially performs phased detection on requests for accessing Web applications, including an access control engine and a detection engine.
[0087] First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address.
[0088] The access control engine uses the extracted information to match the blacklist. If it matches the IP blacklist or regional blacklist, the access request is immediately denied. Otherwise, it enters the speed limit detection.
[0089] The access control engine performs rate limit detection to determine whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied. Otherwise, it enters the whitelist detection.
[0090] The access control engine performs whitelist detection to match whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining detection and be forwarded directly to the origin server. Otherwise, it enters the detection engine to perform various remaining detections.
[0091] The detection engine receives client requests that are not in the whitelist and first determines whether there is a cache of the content to be accessed by the client request. If so, tampering identification is performed on the URI related information. If tampering information is identified, the request access is denied. Otherwise, subsequent Web basic protection detection is performed. If there is no cache of the content to be accessed, tampering identification is skipped and subsequent Web basic protection detection is performed directly.
[0092] Perform Web basic protection detection through the detection engine: extract request features, including URL parameters, request body content and HTTP header information, match the features with the predefined attack pattern library, and deny the request access if the match is successful, otherwise perform CC security protection detection.
[0093] The detection engine performs CC security protection detection and analyzes the behavior characteristics of the request, including request frequency, source IP address, and request mode. Based on the behavior characteristics of the request, it identifies whether the request has potential CC attack. If so, the request access is denied. Otherwise, the BOT management stage detection is performed.
[0094] The detection engine performs detection in the BOT management phase, and identifies whether the request is from a malicious BOT source based on the behavior characteristics of the request. If so, the request access is denied. Otherwise, API security protection detection is performed.
[0095] API security protection detection is performed through the detection engine to classify the API usage, monitor API risks and detect API vulnerabilities of the requested API. If it fails the detection, the request access is denied. If it passes the detection, the request is forwarded to the source server.
[0096] As the contents of information interaction and execution process between modules in the above-mentioned system are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0097] Similarly, the system of the present invention conducts multi-dimensional Web security detection in stages. By dividing the detection into multiple independent stages, one or more stages can be flexibly selected and executed according to business needs, thereby significantly improving the stability and protection effect of the system. Each stage includes access control, website anti-tampering, Web basic protection, CC attack protection, BOT management, API security protection and sensitive information leakage prevention, etc. Each stage focuses on different security dimensions and provides targeted detection and protection measures.
[0098] These detection stages can be run as independent components, supporting independent testing, development, and iterative upgrades, ensuring that the system can quickly adapt to emerging security threats and business needs. This not only improves the flexibility of the system, but also simplifies the maintenance and upgrade process, making the optimization and expansion of each stage more convenient. At the same time, the modular architecture of the system enables it to be personalized according to different scenarios and needs, providing more accurate and efficient security protection.
[0099] It should be noted that not all steps and modules in the above-mentioned processes and system structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or some components in multiple independent devices may be implemented together.
[0100] The above-described embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or changes made by those skilled in the art based on the present invention are within the protection scope of the present invention. The protection scope of the present invention shall be subject to the claims.
Claims
1. A phased and multi-dimensional Web security detection method, characterized by Requests to access the Web application are tested in each stage in turn: Step 1: First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address. Based on the extracted information, the access control engine is used to match the blacklist. If the IP blacklist or regional blacklist is matched, the access request is immediately denied. Otherwise, the speed limit detection is performed. Through the speed limit detection, it is determined whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied, otherwise it enters the whitelist detection. The whitelist is used to check whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining checks and be forwarded directly to the origin server. Otherwise, it enters the detection engine to perform the remaining various checks. Step 2: Receive client requests that are not in the whitelist through the detection engine, first determine whether the client request has a cache of the content to be accessed, and if so, perform tampering identification on the URI related information. If tampering information is identified, deny the request access, otherwise perform subsequent Web basic protection detection. If there is no cache of the content to be accessed, skip tampering identification and directly perform subsequent Web basic protection detection. Step 3: Perform Web basic protection detection: Extract request features, including URL parameters, request body content, and HTTP header information, and match the features with the predefined attack pattern library. If the match is successful, the request access is denied, otherwise CC security protection detection is performed. Step 4: Perform CC security protection detection and analyze the behavior characteristics of the request, which include request frequency, source IP address, and request mode. According to the behavior characteristics of the request, identify whether the request has potential CC attack. If so, deny the request access. Otherwise, perform the detection in the BOT management stage. Step 5: Perform detection in the BOT management phase, and identify whether the request is from a malicious BOT source based on the behavioral characteristics of the request. If so, deny the request access. Otherwise, perform API security protection detection. Step 6: Perform API security protection detection to classify the API usage, monitor API risks, and detect API vulnerabilities of the requested API. If the request fails the detection, the access request will be denied. If the request passes the detection, the request will be forwarded to the origin server.
2. According to the method of claim 1, the method is characterized by: Step 3 specifically includes: Extract the requested features, Predefined attack pattern library, which stores SQL injection attack strategies, cross-site scripting attack strategies, and cross-site request forgery attack strategies. Match the signature with the attack strategy in the predefined attack pattern library. If the match is successful, the access request is denied. Otherwise, CC security protection detection is performed.
3. According to the method of claim 1, the method is characterized by: Step 4 specifically includes: Use anomaly detection algorithms to analyze request behavior characteristics. Establish a baseline behavior model, and record normal traffic patterns through the baseline behavior model. Monitor and analyze current traffic in real time, compare it with the baseline behavior model, identify abnormal traffic peaks and abnormal behavior patterns, Determine whether there is a potential CC attack based on abnormal traffic peaks and abnormal behavior patterns. If so, deny the access request. Otherwise, perform the BOT management stage detection.
4. According to claim 1, a phased and multi-dimensional Web security detection method is characterized by: Step 5 specifically includes: Analyze the behavioral characteristics of the request, Identify abnormal automation behaviors through machine learning algorithms and predefined BOT feature libraries. For suspicious requests with abnormal automated behavior, CAPTCHA challenges are used to distinguish between human users and automated programs. At the same time, the access patterns of specific IP addresses are monitored to identify whether there are malicious BOT sources. If so, the request access is denied. Otherwise, API security protection detection is performed.
5. A phased and multi-dimensional Web security detection method according to claim 1, characterized in that Step 6 specifically includes: Classify the requested APIs, identify the uses of different APIs, and assign corresponding security policies to different categories of API applications. Perform identity authentication and permission checks to ensure that authorized users have access to specific API interfaces. Monitor API risks: Analyze request content and parameters, detect abnormal patterns and illegal calling behaviors, Perform API vulnerability detection: Regularly scan and test to identify and fix security vulnerabilities in APIs to prevent known vulnerabilities from being maliciously exploited.
6. A phased and multi-dimensional Web security detection system, characterized by The system performs various phases of detection on requests to access Web applications, including an access control engine and a detection engine. First, the access control engine receives the request for the origin service initiated by the client, parses the request content, extracts the client IP and URI related information, and identifies the regional information of the client IP address. The access control engine uses the extracted information to match the blacklist. If it matches the IP blacklist or regional blacklist, the access request is immediately denied. Otherwise, it enters the speed limit detection. The access control engine performs rate limit detection to determine whether the client request frequency exceeds the preset maximum number of requests that each client can initiate per second. If yes, the request access is denied. Otherwise, it enters the whitelist detection. The access control engine performs whitelist detection to match whether the client request is in the whitelist. If it is, the client request is allowed to skip the remaining detection and be forwarded directly to the origin server. Otherwise, it enters the detection engine to perform various remaining detections. The detection engine receives client requests that are not in the whitelist and first determines whether there is a cache of the content to be accessed by the client request. If so, tampering identification is performed on the URI related information. If tampering information is identified, the request access is denied. Otherwise, subsequent Web basic protection detection is performed. If there is no cache of the content to be accessed, tampering identification is skipped and subsequent Web basic protection detection is performed directly. Perform Web basic protection detection through the detection engine: extract request features, including URL parameters, request body content and HTTP header information, match the features with the predefined attack pattern library, and deny the request access if the match is successful, otherwise perform CC security protection detection. The detection engine performs CC security protection detection and analyzes the behavior characteristics of the request, including request frequency, source IP address, and request mode. Based on the behavior characteristics of the request, it identifies whether the request has potential CC attack. If so, the request access is denied. Otherwise, the BOT management stage detection is performed. The detection engine performs detection in the BOT management phase, and identifies whether the request is from a malicious BOT source based on the behavior characteristics of the request. If so, the request access is denied. Otherwise, API security protection detection is performed. API security protection detection is performed through the detection engine to classify the API usage, monitor API risks and detect API vulnerabilities of the requested API. If it fails the detection, the request access is denied. If it passes the detection, the request is forwarded to the source server.
7. A phased and multi-dimensional Web security detection system according to claim 6, characterized in that The detection engine extracts the features of the request and the predefined attack pattern library. The attack pattern library stores SQL injection attack strategies, cross-site scripting attack strategies, and cross-site request forgery attack strategies. The features are matched with the attack strategies in the predefined attack pattern library. If the match is successful, the request access is denied. Otherwise, CC security protection detection is performed.
8. A phased and multi-dimensional Web security detection system according to claim 6, characterized in that The detection engine uses anomaly detection algorithms to analyze request behavior characteristics, establish a baseline behavior model, record normal traffic patterns through the baseline behavior model, monitor and analyze current traffic in real time, compare it with the baseline behavior model, identify abnormal traffic peaks and abnormal behavior patterns, and determine whether there is a potential CC attack based on the abnormal traffic peaks and abnormal behavior patterns. If so, deny the request access. Otherwise, perform BOT management stage detection.
9. A phased and multi-dimensional Web security detection system according to claim 6, characterized in that The detection engine analyzes the behavioral characteristics of requests, and uses machine learning algorithms and a predefined BOT feature library to identify abnormal automated behaviors. For suspicious requests with abnormal automated behaviors, CAPTCHA challenges are used to distinguish between human users and automated programs. At the same time, the access patterns of specific IP addresses are monitored to identify whether there are malicious BOT sources. If so, the request access is denied. Otherwise, API security protection detection is performed.
10. A phased and multi-dimensional Web security detection system according to claim 6, characterized in that The detection engine classifies the requested APIs, identifies the purposes of different APIs, and assigns corresponding security policies to different categories of API applications. It performs identity authentication and permission checks to ensure that authorized users access specific API interfaces and monitor API risks: analyze request content and parameters, detect abnormal patterns and illegal calling behaviors, and perform API vulnerability detection: regularly scan and test to identify and fix security vulnerabilities in APIs to prevent known vulnerabilities from being maliciously exploited.
Citation Information
Patent Citations
CC (Communication Center) attack protective method and system thereof
CN101834866A
Evaluating URLS For Malicious Content
US20150326599A1