Network access request identification method and device, computer equipment, storage medium and computer program product
By combining the Web application fire prevention system and the pre-trained exception request identification model, network access requests are double-identified, and the protection rule set is optimized through manual auditing, the problem of traditional technology being difficult to identify new attacks is solved, and efficient and accurate network security detection is achieved.
Patent Information
- Application Number
- CN202510466334.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The rules engine of traditional web application firewalls is difficult to efficiently identify new or variant attacks, and it is difficult to adapt in time when the attack mode is updated.
Double-identify network access requests by combining the Web Application Fire Protection System (WAF) and the pre-trained exception request identification model. First, WAF uses its protection rule set to identify the request to obtain the first recognition result; second, the pre-trained exception request recognition model uses deep learning technology to identify the request to obtain the second recognition result. When the result of identification is mismatched, a manual audit is performed, and the exception request identification model and WAF protection rule set is optimized based on the audit result.
It realizes flexible, efficient and accurate identification of network access requests, and can identify known and new types of network security attacks, improving detection efficiency and accuracy.
Smart Images

Figure CN119996088A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, apparatus, computer equipment, storage medium, and computer program product for identifying a network access request. Background Art
[0002] A Web Application Firewall (WAF) is a crucial tool for protecting web applications from attacks. It primarily uses a rules engine to identify and block malicious requests. This engine relies on a predefined set of protection rules, developed based on known attack patterns and threat intelligence, to effectively address common attacks.
[0003] Currently, the transparency and predictability of rule engines are crucial for businesses with specific security and compliance requirements, as they allow precise control over which requests are allowed and which are denied. However, because rule engines rely on known attack patterns, they can struggle to identify new or evolving attacks. Furthermore, they can be difficult to adapt to new attacks if they are not updated in a timely manner.
[0004] Therefore, there is a problem in traditional technologies that the rule engine of the Web application firewall cannot efficiently identify attacks. Summary of the Invention
[0005] Based on this, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium and computer program product for efficiently identifying attack network access requests in response to the above technical problems.
[0006] A method for identifying a network access request, the method comprising:
[0007] receiving a network access request for a target Web application, identifying the network access request using a Web application firewall system, and obtaining a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request;
[0008] Using a pre-trained abnormal request recognition model to identify the network access request, a second recognition result is obtained; the second recognition result is used to indicate whether the network access request is a preset type of network attack pattern;
[0009] In the case where the comparison result of the first recognition result and the second recognition result does not match, receiving recognition result review information returned by the web application firewall control center; the recognition result review information includes manual review results of the first recognition result and the second recognition result;
[0010] Based on the identification result audit information, the abnormal request identification model and / or the protection rule set of the Web application fire protection system are optimized, and the step of receiving the network access request for the target Web application is returned to identify the new network access request.
[0011] In one embodiment, a web application firewall system is used to identify a network access request to obtain a first identification result, including:
[0012] Through the multiple protection functions integrated into the Web application fire prevention system, abnormal network access requests are identified and the identification results output by each protection function are obtained;
[0013] When the identification results output by each protection function indicate that the network access request does not have any anomaly, the absence of anomaly in the network access request is taken as the first identification result;
[0014] When the identification result output by any protection function indicates that there is an abnormality in the network access request, the network attack pattern targeted by the protection function is used as the first identification result.
[0015] In one embodiment, a pre-trained abnormal request recognition model is used to recognize a network access request to obtain a second recognition result, including:
[0016] generating a request information sequence of the network access request based on the request information of the network access request;
[0017] Input the request information sequence into the before-after time sequence feature extraction network in the abnormal request recognition model to obtain the before-after time sequence features corresponding to the request information sequence;
[0018] Input the preceding and following time series features into the multi-layer perceptron of the abnormal request recognition model to obtain the classification results for the network access request;
[0019] Input the classification results into the activation layer of the abnormal request recognition model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal and the probability that the network access request belongs to each preset type of network attack mode;
[0020] In a case where the probability that the network access request is normal is the highest, taking the network access request as having no abnormality as the second identification result;
[0021] When the probability that the network access request is normal is not the highest, the network attack pattern of the preset type with the highest probability is used as the second identification result.
[0022] In one embodiment, generating a request information sequence of a network access request based on the request information of the network access request includes:
[0023] Decoding the request information of the network access request to obtain decoded request information;
[0024] extracting field information corresponding to at least one field associated with the network attack from the decoded request information;
[0025] Perform character conversion on the field information corresponding to each field to obtain the character conversion result corresponding to each field;
[0026] Based on the character conversion results corresponding to each field, a request information sequence of the network access request is generated.
[0027] In one embodiment, based on the recognition result audit information, the abnormal request recognition model and / or the protection rule set of the web application firewall system are optimized, including:
[0028] When the identification result review information indicates that the first identification result is erroneous, determining the target network attack pattern to which the network access request belongs;
[0029] Add protection rules targeting target network attack patterns to the protection rule set to optimize the protection rule set.
[0030] In one embodiment, based on the recognition result audit information, the abnormal request recognition model and / or the protection rule set of the web application firewall system are optimized, including:
[0031] When the recognition result audit information indicates that the second recognition result is erroneous, collecting false positive data or missed negative data;
[0032] False positive data or missed negative data are used to fine-tune the abnormal request recognition model to optimize the abnormal request recognition model.
[0033] A device for identifying a network access request, the device comprising:
[0034] a first identification module, configured to receive a network access request for a target Web application, identify the network access request using a Web application firewall system, and obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request;
[0035] a second identification module, configured to identify the network access request using a pre-trained abnormal request identification model to obtain a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack pattern;
[0036] An audit module, configured to receive, when a comparison result between the first recognition result and the second recognition result does not match, recognition result audit information returned by the web application firewall control center; the recognition result audit information includes a manual audit result of the first recognition result and the second recognition result;
[0037] The optimization module is used to review the information based on the identification results, optimize the abnormal request identification model and / or the protection rule set of the Web application fire protection system, and return to the step of receiving the network access request for the target Web application to identify the new network access request.
[0038] A computer device includes a memory and a processor, wherein the memory stores a computer program and the processor implements the steps of the above method when executing the computer program.
[0039] A computer-readable storage medium stores a computer program, which implements the steps of the above method when executed by a processor.
[0040] A computer program product comprises a computer program, which implements the steps of the above method when executed by a processor.
[0041] The above-mentioned network access request identification method, device, computer equipment, storage medium and computer program product receive a network access request for a target Web application, use a Web application firewall system to identify the network access request, and obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request; use a pre-trained abnormal request identification model to identify the network access request to obtain a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack pattern; when the comparison result of the first identification result and the second identification result does not match, receive identification result review information returned by the Web application firewall control center; the identification result review information includes the manual review result of the first identification result and the second identification result. result; based on the recognition result audit information, the abnormal request recognition model and / or the protection rule set of the Web application fire protection system are optimized, and the step of receiving the network access request for the target Web application is returned to identify the new network access request; in this way, by comparing the recognition results of the Web application fire protection system with the abnormal request recognition model, and optimizing the protection rule set of the Web application fire protection system and fine-tuning the model parameters of the abnormal request recognition model after manual review, a dynamic tuning mechanism is formed, which can comprehensively integrate the interception rate of the Web application fire protection system for abnormal network access requests and the accuracy of the abnormal request recognition model in identifying complex network security attacks, and realize flexible, efficient and accurate identification of known network security attacks and new network security attacks as a whole, thereby improving the detection efficiency and accuracy of network access requests. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 A diagram illustrating an application environment of a method for identifying a network access request in one embodiment;
[0044] Figure 2 A schematic flow chart of a method for identifying a network access request in one embodiment;
[0045] Figure 3 A diagram of an architecture of a network access request identification system in one embodiment;
[0046] Figure 4is a flow chart of a method for identifying an HTTP request in one embodiment;
[0047] Figure 5 A flowchart of a method for identifying a network access request according to another embodiment;
[0048] Figure 6 A structural block diagram of a device for identifying a network access request in one embodiment;
[0049] Figure 7 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical solutions and advantages of this application more clear, the following is a detailed description of this application scheme in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain this application and are not used to limit this application.
[0051] A web application firewall (WAF) is a crucial tool for protecting web applications from attacks, primarily relying on a rules engine to identify and block malicious requests. These rules engines rely on predefined rule sets, developed by security experts based on known attack patterns and threat intelligence, to effectively address common attacks. The transparency and predictability of rules engines are advantageous for organizations with specific security and compliance requirements, as they provide precise control over which requests are allowed or denied. However, because rules engines rely on known attack patterns, they can struggle to identify new or evolving attacks. Furthermore, rules engines require regular updates to adapt to new threats.
[0052] Artificial intelligence (AI)-based WAF detection methods can automatically extract features by learning from large amounts of HTTP request data, potentially detecting unknown attacks while reducing reliance on rule updates. However, AI models suffer from poor interpretability, meaning their decision-making processes lack transparency, making it difficult for operations personnel to quickly locate and resolve issues when false positives or negatives occur.
[0053] The rule engines and AI models of existing technologies usually work independently, failing to fully combine the advantages of both to achieve efficient identification of abnormal traffic.
[0054] The network access request identification method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The server 104 receives a network access request for a target Web application, uses the Web application fire protection system to identify the network access request, and obtains a first identification result; the first identification result is used to instruct the Web application fire protection system to intercept or release the network access request; the server 104 uses a pre-trained abnormal request identification model to identify the network access request, and obtains a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack pattern; if the comparison result of the first identification result and the second identification result does not match, the server 104 receives the identification result review information returned by the Web application firewall control center; the identification result review information includes the manual review result of the first identification result and the second identification result; the server 104 optimizes the abnormal request identification model and / or the protection rule set of the Web application fire protection system based on the identification result review information, and returns to the step of receiving the network access request for the target Web application to identify the new network access request. Terminal 102 may include, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, and smart car devices. Portable wearable devices may include smart watches, smart bracelets, and head-mounted devices. Server 104 may be implemented as a standalone server or a server cluster consisting of multiple servers.
[0055] In an exemplary embodiment, Figure 2 As shown, a method for identifying a network access request is provided, and the method is applied to Figure 1 The server 104 in the example is used as an example to illustrate the method, which includes the following steps S202 to S208.
[0056] Step S202: receiving a network access request for a target Web application, and identifying the network access request using a Web application firewall system to obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request.
[0057] The target web application can be any web application.
[0058] The network access request may be an HTTP request corresponding to a user accessing a target Web application.
[0059] Among them, the web application fire protection system can be a WAF (Web Application Firewall) system. The WAF system can monitor and filter HTTP requests to protect web applications from common attacks, such as SQL injection and cross-site scripting (XSS).
[0060] Among them, the first identification result can be the result obtained when the Web application fire protection system filters the HTTP request. The first identification result can be the identification result that the Web application fire protection system determines that there is no attack on the HTTP request, determines that the HTTP request is a CC attack, determines that the number of accesses to the initiating ID of the HTTP request is too high, determines that the login of the initiating ID of the HTTP request is abnormal, etc.
[0061] Optionally, a user accesses a target Web application, a server receives an HTTP request for the Web application, and uses a WAF application fire protection system to identify the HTTP request to obtain a first identification result. If the first identification result indicates that a network attack exists in the HTTP request, the Web application fire protection system will intercept the HTTP request. If the first identification result indicates that no network attack exists in the HTTP request, the Web application fire protection system will release the HTTP request.
[0062] Step S204 , using a pre-trained abnormal request recognition model to recognize the network access request, and obtaining a second recognition result; the second recognition result is used to indicate whether the network access request is a preset type of network attack pattern.
[0063] The pre-trained abnormal request recognition model can be a pre-trained neural network model for identifying abnormal HTTP requests. For example, the pre-trained abnormal request recognition model can be a BiLSTM-MLP model. Bidirectional Long Short-Term Memory (BiLSTM) is a recurrent neural network that can simultaneously capture temporal information before and after the input sequence and is suitable for processing sequential data. Multilayer Perceptron (MLP) is a neural network model with multiple fully connected layers and is widely used in classification tasks. MLPs typically consist of an input layer, hidden layers, and an output layer, and the activation function can be a nonlinear function such as ReLU.
[0064] Among them, the second identification result can be the result output by the abnormal request identification model after analyzing the request information of the HTTP request. The second identification result can be the identification result of determining that there is no attack on the HTTP request, determining that the network access request is a CC attack, determining that the number of accesses of the initiating ID of the network access request is too high, determining that the login of the initiating ID of the network access request is abnormal, etc.
[0065] The preset type of network attack pattern may be a network attack pattern that can be identified by the abnormal request recognition model, and there may be multiple preset types of network attack patterns.
[0066] Optionally, the server uses a pre-trained abnormal request recognition model to identify the HTTP request to obtain a second recognition result, thereby determining whether the HTTP request is a preset type of network attack pattern.
[0067] Step S206, when the comparison results of the first recognition result and the second recognition result do not match, receive the recognition result review information returned by the Web application firewall control center; the recognition result review information includes the manual review results of the first recognition result and the second recognition result.
[0068] Among them, the mismatch between the comparison results of the first identification result and the second identification result may mean that the network attack pattern identified by the Web application fire protection system is inconsistent with the network attack pattern identified by the abnormal request identification model, or it may mean that the Web application fire protection system did not identify the existence of an attack while the abnormal request identification model identified the existence of an attack, or it may mean that the Web application fire protection system identified the existence of an attack while the abnormal request identification model did not identify the existence of an attack.
[0069] The Web Application Firewall control center may refer to the control center of a WAF (Web Application Firewall) system.
[0070] The recognition result review information may be a manual review result obtained after manually reviewing and evaluating the first recognition result of the Web application firewall for the HTTP request and the second recognition result of the abnormal request recognition model for the HTTP request.
[0071] Among them, the manual review result can be that the first recognition result has errors and the second recognition result does not have errors, the first recognition result does not have errors and the second recognition result has errors, or both the first recognition result and the second recognition result have errors.
[0072] Optionally, when the network attack pattern of the HTTP request identified by the WAF application fire protection system is inconsistent with the network attack pattern of the HTTP request identified by the abnormal request identification model, or when the WAF application fire protection system does not identify the presence of a network attack on the HTTP request while the abnormal request identification model identifies the presence of a network attack on the HTTP request, or when the WAF application fire protection system identifies the presence of a network attack on the HTTP request while the abnormal request identification model does not identify the presence of a network attack on the HTTP request, the server uploads the first identification result output by the WAF application fire protection system for the HTTP request and the second identification result output by the abnormal request identification model for the HTTP request to the control center of the WAF application fire protection system for manual review by the administrator, thereby obtaining the identification result review information containing the manual review result sent by the control center of the WAF application fire protection system.
[0073] Step S208 , based on the identification result audit information, optimize the abnormal request identification model and / or the protection rule set of the Web application firewall system, and return to the step of receiving the network access request for the target Web application to identify the new network access request.
[0074] Among them, the protection rule set is applied to the rule engine of the Web application firewall system. In actual applications, malicious requests can be identified and blocked based on the rule engine. The rule engine relies on predefined protection rule sets. These protection rules are formulated by security experts based on known attack patterns and threat intelligence, and can effectively deal with common attacks.
[0075] Optionally, the server determines, based on the recognition result review information, whether there is an error in the first recognition result output by the Web application fire protection system or in the second recognition result output by the abnormal request recognition model. If there is an error in the first recognition result output by the Web application fire protection system, the server updates the protection rule set of the Web application fire protection system to obtain an updated protection rule set. If there is an error in the second recognition result output by the abnormal request recognition model, the server fine-tunes the abnormal request recognition model to obtain a fine-tuned abnormal request recognition model. Then, the server returns to step S202, so that the fine-tuned abnormal request recognition model and the updated protection rule set of the Web application fire protection system can more accurately identify new HTTP requests.
[0076] In the above-mentioned method for identifying network access requests, a network access request for a target Web application is received, and the network access request is identified by a Web application firewall system to obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request; the network access request is identified by a pre-trained abnormal request identification model to obtain a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack pattern; in the case where the comparison result of the first identification result and the second identification result does not match, the identification result review information returned by the Web application firewall control center is received; the identification result review information includes the manual review results of the first identification result and the second identification result; according to the identification result review The system optimizes the protection rule set of the abnormal request identification model and / or the Web application fire protection system, and returns to the step of receiving the network access request for the target Web application to identify the new network access request. In this way, by comparing the recognition results of the Web application fire protection system with those of the abnormal request identification model, optimizing the protection rule set of the Web application fire protection system and fine-tuning the model parameters of the abnormal request identification model after manual review, a dynamic tuning mechanism is formed, which can comprehensively integrate the interception rate of the Web application fire protection system for abnormal network access requests and the accuracy of the abnormal request identification model in identifying complex network security attacks, thereby realizing flexible, efficient and accurate identification of known network security attacks and new network security attacks as a whole, and improving the detection efficiency and accuracy of network access requests.
[0077] In an exemplary embodiment, a Web application fire protection system is used to identify network access requests to obtain a first identification result, including: using multiple protection functions integrated in the Web application fire protection system to identify anomalies in the network access request and obtain identification results output by each protection function; when the identification results output by each protection function indicate that there is no anomaly in the network access request, the absence of anomaly in the network access request is taken as the first identification result; when the identification result output by any protection function indicates that there is an anomaly in the network access request, the network attack pattern targeted by the protection function is taken as the first identification result.
[0078] Among them, the multiple protection functions integrated in the Web application fire protection system may include CC protection function, frequency control function, database collision protection function and rule engine-based protection function.
[0079] Among them, the CC protection function sets up corresponding protection measures for CC attacks (Challenge Collapsar attacks). It identifies and blocks abnormal high-frequency requests by limiting the request frequency of a single IP or user and setting access rules, thereby protecting the normal operation of the server.
[0080] Among them, the frequency control function is used in network protection to limit the number of visits of a certain IP address, user or request within a unit of time, so as to prevent a certain IP from occupying too many server resources through frequent requests, thereby affecting the performance and stability of the server.
[0081] Credential Stuffing Prevention prevents attackers from exploiting lists of usernames and passcodes (often leaked through other means) to conduct batch login attempts on target systems in an attempt to obtain legitimate user account information. Credential Stuffing Prevention identifies and blocks anomalous login behavior by monitoring login request frequency, source IP addresses, and username and passcode patterns.
[0082] A rules engine is a rule-based, automated decision-making tool that processes and judges data or requests based on pre-set protection rules. In network security, the filtering function of a rules engine is used to screen and filter network traffic based on a series of defined protection rules, such as request characteristics, sources, and behavior patterns. This helps identify and block malicious requests or traffic that doesn't comply with security policies, thereby protecting the system from various attacks.
[0083] Optionally, when receiving an HTTP request, the server filters the HTTP request in sequence through the CC protection function, frequency control function, credential stuffing protection function and rule-engine-based protection function of the WAF application fire protection system, intercepts abnormal HTTP requests, and releases normal HTTP requests. When the CC protection function, frequency control function, credential stuffing protection function and rule-engine-based protection function do not intercept the HTTP request, the absence of abnormality in the HTTP request is taken as the first identification result. When any one of the CC protection function, frequency control function, credential stuffing protection function and rule-engine-based protection function intercepts the HTTP request, the network attack pattern targeted by the protection function that intercepts the HTTP request is determined as the first identification result.
[0084] In this embodiment, the network access request is identified for anomalies through the multiple protection functions integrated in the Web application fire protection system, and the identification results output by each protection function are obtained; when the identification results output by each protection function indicate that there is no anomaly in the network access request, the absence of anomaly in the network access request is taken as the first identification result; when the identification result output by any protection function indicates that there is an anomaly in the network access request, the network attack pattern targeted by the protection function is taken as the first identification result; in this way, the multiple protection functions of the Web application fire protection system can be used to quickly identify the network access request, thereby improving the identification rate of the network access request.
[0085] In an exemplary embodiment, a pre-trained abnormal request recognition model is used to recognize a network access request to obtain a second recognition result, including: generating a request information sequence of the network access request based on the request information of the network access request; inputting the request information sequence into the front-end and back-end temporal feature extraction network in the abnormal request recognition model to obtain the front-end and back-end temporal features corresponding to the request information sequence; inputting the front-end and back-end temporal features into the multi-layer perceptron of the abnormal request recognition model to obtain a classification result for the network access request; inputting the classification result into the activation layer of the abnormal request recognition model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal, and the probability that the network access request belongs to each preset type of network attack mode; when the probability that the network access request is normal is the highest, the network access request is not abnormal as the second recognition result; when the probability that the network access request is normal is not the highest, the network attack mode of the preset type with the highest probability is taken as the second recognition result.
[0086] The request information of the network access request may refer to the request information of the HTTP request.
[0087] The request information sequence of the network access request may be an information sequence generated by pre-processing the request information of the HTTP request.
[0088] The front-to-back temporal feature extraction network may refer to a bidirectional long short-term memory network (BiLSTM, Bi-directional Long Short-Term Memory).
[0089] The preceding and following temporal features corresponding to the request information sequence may be sequence features of the request information sequence extracted by a bidirectional long short-term memory network.
[0090] Here, the multi-layer perceptron may refer to an MLP layer.
[0091] The classification result may be the classification result output by the MLP layer.
[0092] Among them, the activation layer can be a Softmax layer.
[0093] Among these, the preset network attack patterns can include SQL injection attacks, XSS injection attacks, or other injection attacks. SQL injection is a common network security vulnerability in which attackers insert malicious SQL code into application user input, attempting to trick the database into executing unintended queries. XSS injection attacks (cross-site scripting) involve injecting malicious code into a target website. This code is executed when the user (the victim) logs in to the website. These scripts can then read cookies, session tokens, or other sensitive website information.
[0094] The probability distribution result may refer to the probability that the network access request output by the Softmax layer is normal traffic, SQL attack, XSS attack, or other injection attack.
[0095] Optionally, the server generates a request information sequence of the HTTP request based on the request information of the HTTP request, and then inputs the request information sequence into the bidirectional long short-term memory network BiLSTM in the abnormal request recognition model to obtain the front and back time series features corresponding to the request information sequence, and then inputs the front and back time series features into the MLP layer of the abnormal request recognition model to obtain a classification result for the HTTP request, and then inputs the classification result into the Softmax layer of the abnormal request recognition model to obtain the probability that the HTTP request is normal, and the probability that the HTTP request belongs to each network attack mode, wherein, when the probability that the HTTP request is normal is the highest, the HTTP request is regarded as a normal request as the second recognition result, and when the probability that the HTTP request is normal is not the highest, the network attack mode with the highest probability is regarded as the second recognition result, for example, if the network attack mode with the highest probability is a SQL injection attack, then the HTTP request is recognized as a SQL injection attack as the second recognition result.
[0096] In this embodiment, a request information sequence of a network access request is generated based on request information of the network access request; the request information sequence is input into a front-to-back temporal feature extraction network in an abnormal request recognition model to obtain front-to-back temporal features corresponding to the request information sequence; the front-to-back temporal features are input into a multi-layer perceptron of the abnormal request recognition model to obtain a classification result for the network access request; the classification result is input into an activation layer of the abnormal request recognition model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal and the probability that the network access request belongs to each preset type of network attack mode; when the probability that the network access request is normal is the highest, the absence of an abnormality in the network access request is taken as the second recognition result; when the probability that the network access request is normal is not the highest, the network attack mode of the preset type with the highest probability is taken as the second recognition result; in this way, the temporal features in the network access request can be effectively processed by the front-to-back temporal feature extraction network, the features can be further extracted and classified by the multi-layer perceptron, and the efficiency of the network access request belonging to each network attack mode is obtained by the activation layer. The network combination structure of this model can more accurately identify complex network attack modes.
[0097] In an exemplary embodiment, based on the request information of the network access request, a request information sequence of the network access request is generated, including: decoding the request information of the network access request to obtain decoded request information; extracting field information corresponding to at least one field associated with the network attack from the decoded request information; performing character conversion on the field information corresponding to each field to obtain a character conversion result corresponding to each field; and generating a request information sequence of the network access request based on the character conversion result corresponding to each field.
[0098] The decoded request information may refer to information obtained by decoding URL-encoded data in the request information of the network access request.
[0099] Among them, fields associated with network attacks can refer to the URL corresponding to the HTTP request (used to detect whether it contains abnormal characters, such as SQL keywords, XSS patterns, etc.), request parameters (such as parameters in GET / POST), HTTP methods that may contain attack vectors (such as GET, POST, PUT, etc.), request headers (such as User-Agent, Referer, etc.) and request bodies (such as data in POST requests, especially form and JSON data).
[0100] The field information corresponding to the field may be the field value corresponding to the field.
[0101] The character conversion result corresponding to each field may refer to a Unicode string corresponding to the field information corresponding to each field (eg, UTF-8 encoded data) after character conversion.
[0102] Optionally, the server decodes the URL-encoded data in the request information of the HTTP request. For example, %20 is converted to a space to obtain the decoded HTTP request information. The decoded HTTP request information is then filtered to remove unnecessary HTTP request information and retain only the field information corresponding to each field related to the network attack (e.g., URL, request parameters, HTTP methods that may contain attack vectors, request headers, request body, etc.). The UTF-8-encoded data in the field information corresponding to each field is then converted into a Unicode string to ensure that special characters and internationalized characters can be correctly processed. The character conversion results corresponding to each field are obtained. Finally, each word can be separated by a space, so that the HTTP request is divided into n tokens. Based on these n tokens, a request information sequence of the HTTP request is generated.
[0103] In this embodiment, request information of a network access request is decoded to obtain decoded request information; field information corresponding to at least one field associated with a network attack is extracted from the decoded request information; field information corresponding to each field is character-converted to obtain a character conversion result corresponding to each field; and a request information sequence of the network access request is generated based on the character conversion result corresponding to each field; in this way, the request information of the network access request can be effectively processed, and information that helps identify attack patterns can be extracted, thereby generating a request information sequence that can characterize the characteristics of the network access request.
[0104] In an exemplary embodiment, the abnormal request recognition model and / or the protection rule set of the Web application fire protection system are optimized based on the recognition result audit information, including: when the recognition result audit information indicates that there is an error in the first recognition result, determining the target network attack pattern to which the network access request belongs; adding the protection rules for the target network attack pattern to the protection rule set to optimize the protection rule set.
[0105] Among them, the target network attack pattern may refer to the actual network attack pattern corresponding to the HTTP request. The target network attack pattern is different from the first identification result output by the Web application fire protection system. For example, the first identification result output by the Web application fire protection system may be that the HTTP request is a SQL injection attack, while the audit result determines that the actual network attack pattern of the HTTP request is an XSS injection attack.
[0106] The protection rules for the target network attack pattern can be protection rules set for the actual network attack pattern corresponding to the HTTP request. For example, if the audit results determine that the actual attack pattern of the HTTP request is an XSS injection attack, the protection rules for the target network attack pattern are protection rules set for XSS injection attacks.
[0107] Optionally, when the first identification result output by the Web application fire protection system is "the HTTP request belongs to an SQL injection attack" and the audit result shows "the actual network attack mode of the HTTP request is an XSS injection attack", the server determines that the HTTP request belongs to an XSS injection attack. Then, the server obtains the protection rules against the XSS injection attack, and adds the protection rules against the XSS injection attack to the protection rule set of the rule engine of the Web application fire protection system to obtain an updated protection rule set to optimize the protection rule set.
[0108] In this embodiment, when the identification result audit information indicates that the first identification result is erroneous, the target network attack pattern to which the network access request belongs is determined; the protection rules for the target network attack pattern are added to the protection rule set to optimize the protection rule set; in this way, the protection rule set of the Web application fire protection system can be expanded, so that the protection rule set of the Web application fire protection system can be kept updated in real time, so that the rule engine of the Web application fire protection system can be updated in time to adapt to the identification of new attacks, which is conducive to improving the recognition accuracy of the Web application fire protection system for network access requests.
[0109] In an exemplary embodiment, the abnormal request recognition model and / or the protection rule set of the Web application fire protection system are optimized based on the recognition result review information, including: when the recognition result review information indicates that the second recognition result is erroneous, collecting false positive data or missed negative data; using the false positive data or missed negative data to fine-tune the abnormal request recognition model to optimize the abnormal request recognition model.
[0110] False positive data may refer to an abnormal request recognition model incorrectly identifying an abnormal HTTP request. For example, a false positive data may refer to an abnormal request recognition model incorrectly identifying an HTTP request that is an XSS injection attack as an SQL injection attack.
[0111] Missing data may refer to HTTP requests that are not identified as abnormal by the abnormal request recognition model. For example, missing data may refer to HTTP requests that are not identified as XSS injection attacks by the abnormal request recognition model, or HTTP requests that are not identified as other attack patterns.
[0112] Optionally, when the second recognition result output by the abnormal request recognition model is "the HTTP request belongs to a SQL injection attack" and the audit result shows that "the actual attack mode of the HTTP request is an XSS injection attack", the server collects false positive data of the abnormal request recognition model, or, when the second recognition result output by the abnormal request recognition model is "the HTTP request is a normal request" and the audit result shows that "the actual attack mode of the HTTP request is an XSS injection attack", the server collects missed negative data of the abnormal request recognition model. Then, the server uses the false positive data or the missed negative data to fine-tune the abnormal request recognition model, thereby obtaining the fine-tuned abnormal request recognition model to optimize the abnormal request recognition model.
[0113] In this embodiment, when the recognition result audit information indicates that the second recognition result is erroneous, false alarm data or missed alarm data is collected; the false alarm data or missed alarm data is used to fine-tune the abnormal request recognition model to optimize the abnormal request recognition model; in this way, the abnormal request recognition model can adjust parameters in a timely manner based on the false alarm data or missed alarm data to obtain a more accurate abnormal request recognition model, thereby improving the accuracy of identifying complex network security attacks.
[0114] To facilitate understanding by those skilled in the art, Figure 3 Provides a network access request identification system architecture diagram, Figure 4 A flowchart of a method for identifying HTTP requests is provided. Figure 3 System framework diagram and Figure 4 The implementation steps of this application scheme are further described, and the implementation steps include:
[0115] Step 1: When a user accesses a web application, the HTTP request is filtered by the WAF application firewall system, and then passes through CC protection, frequency control, credential stuffing protection, and rule engine filtering in sequence. Abnormal HTTP requests are intercepted, and normal HTTP requests are released.
[0116] Step 2: Mark the intercepted abnormal HTTP requests and normal HTTP requests, collect various types of HTTP requests and the corresponding identification result tags of various types of HTTP requests, and the identification result tags mark the HTTP requests as abnormal or normal.
[0117] Step 3: Cleanse and preprocess the HTTP request and the corresponding identification result tags to obtain n tokens corresponding to the HTTP request. Specifically, decode the URL-encoded data in the HTTP request (for example, convert %20 to spaces), filter out unnecessary information, and retain only attack-related fields (for example, the URL, request parameters, HTTP methods that may contain attack vectors, request headers, and request body). Convert the UTF-8-encoded data to a Unicode string, ensuring that special characters and internationalized characters can be properly handled. Separate each word with a space, so that the HTTP request is divided into n tokens.
[0118] Step 4: Use Word2Vec to convert the n tokens corresponding to the HTTP request into a vector sequence. Specifically, use the Skip-gram model (a model for computing word embeddings) in Word2Vec to map each word into a vector space, capturing the semantic relationships between words. For example, the Skip-gram model maps the n tokens in an HTTP request (such as ['HTTP', 'example', 'com', 'login', 'username', ...]) into a d-dimensional vector, with an output shape of (n, d).
[0119] Step 5: Input the vector sequence into the abnormal request recognition model to obtain the recognition result. Specifically, the vector sequence is input into the Bidirectional Long Short-Term Memory (BiLSTM) layer. BiLSTM can simultaneously capture the sequential information before and after the HTTP request, effectively detecting attack patterns. The output of the last time step of the BiLSTM layer is obtained. After being flattened by the Flatten layer, the output of the BiLSTM layer is input into an MLP model consisting of three fully connected layers. Each fully connected layer uses ReLU as the activation function. Finally, the Softmax layer outputs the probabilities of normal traffic, SQL attacks, XSS attacks, and other injection attacks. The type with the highest probability is selected as the final recognition result.
[0120] Step 6: Compare the recognition results of the application fire protection system's rule engine with those of the abnormal request recognition model, and provide feedback for optimization. Specifically, the recognition results of the application fire protection system's rule engine are compared with those of the abnormal request recognition model. If the two judgments are inconsistent, they are uploaded to the WAF control center for administrator review. After the review, the rule engine's protection rule set is optimized and distributed to the WAF. At the same time, false positive and false negative data of the abnormal request recognition model are collected, and the abnormal request recognition model is fine-tuned. The adjusted model parameters of the abnormal request recognition model are distributed to the system to improve overall detection performance.
[0121] The network access request identification method of this application uses a BiLSTM-MLP model to perform deep learning analysis on HTTP requests, combined with the detection results of the rule engine to improve the ability to identify unknown attacks; by comparing the recognition results of the rule engine and the AI model, manually reviewing and optimizing the rule engine, and continuously improving the detection accuracy. This application combines the clarity of the rule engine with the capabilities of the deep learning model to automatically extract features from HTTP requests and improve the WAF's detection capabilities for unknown attacks. At the same time, the recognition results generated by the deep learning model are compared with the detection results of the WAF rule engine. By reviewing and optimizing the rules, a feedback mechanism is introduced to dynamically adjust the rule engine and deep learning model, solving the problems of complex rule updates and poor interpretability of AI models in the existing technology.
[0122] In another embodiment, Figure 5 As shown, a method for identifying a network access request is provided, and the method is applied to Figure 1 Taking the server 104 in the example as an example, the following steps are included:
[0123] Step S502: Receive a network access request for a target Web application, and use a Web application firewall system to identify the network access request to obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request.
[0124] Step S504: Generate a request information sequence of the network access request based on the request information of the network access request.
[0125] Step S506 : Input the request information sequence into the before-after time sequence feature extraction network in the abnormal request recognition model to obtain the before-after time sequence features corresponding to the request information sequence.
[0126] Step S508: Input the preceding and following time series features into the multi-layer perceptron of the abnormal request recognition model to obtain a classification result for the network access request.
[0127] In step S510, the classification result is input into the activation layer of the abnormal request recognition model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal, and the probability that the network access request belongs to each preset type of network attack mode.
[0128] Step S512: When the probability that the network access request is normal is the highest, the second identification result is that there is no abnormality in the network access request.
[0129] Step S514: When the probability that the network access request is normal is not the highest, the network attack pattern of the preset type with the highest probability is used as the second recognition result; the second recognition result is used to indicate whether the network access request is a network attack pattern of the preset type.
[0130] Step S516, when the comparison results of the first recognition result and the second recognition result do not match, receive the recognition result review information returned by the Web application firewall control center; the recognition result review information includes the manual review results of the first recognition result and the second recognition result.
[0131] Step S518: Based on the identification result review information, optimize the abnormal request identification model and / or the protection rule set of the Web application firewall system, and return to the step of receiving the network access request for the target Web application to identify the new network access request.
[0132] It should be noted that the specific definition of the above steps can refer to the specific definition of the method for identifying a network access request above.
[0133] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0134] Based on the same inventive concept, embodiments of the present application also provide a network access request identification device for implementing the aforementioned network access request identification method. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of the one or more network access request identification device embodiments provided below can be found in the above-mentioned limitations of the network access request identification method and will not be repeated here.
[0135] In an exemplary embodiment, Figure 6 As shown, a device for identifying a network access request is provided, comprising: a first identification module 602, a second identification module 604, an audit module 606 and an optimization module 608, wherein:
[0136] A first identification module 602 is configured to receive a network access request for a target web application, identify the network access request using a web application firewall system, and obtain a first identification result; the first identification result is used to instruct the web application firewall system to intercept or release the network access request;
[0137] A second identification module 604 is configured to identify the network access request using a pre-trained abnormal request identification model to obtain a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack pattern;
[0138] An audit module 606 is configured to receive, when the comparison result of the first recognition result and the second recognition result does not match, recognition result audit information returned by the web application firewall control center; the recognition result audit information includes a manual audit result of the first recognition result and the second recognition result;
[0139] The optimization module 608 is used to optimize the abnormal request identification model and / or the protection rule set of the Web application firewall system based on the identification result audit information, and return to the step of receiving the network access request for the target Web application to identify the new network access request.
[0140] In one embodiment, the first identification module 602 is specifically used to identify anomalies in network access requests through multiple protection functions integrated in the Web application fire protection system, and obtain identification results output by each protection function; when the identification results output by each protection function indicate that there is no anomaly in the network access request, the absence of anomaly in the network access request is taken as the first identification result; when the identification result output by any protection function indicates that there is an anomaly in the network access request, the network attack pattern targeted by the protection function is taken as the first identification result.
[0141] In one embodiment, the second identification module 604 is specifically used to generate a request information sequence of the network access request based on the request information of the network access request; input the request information sequence into the front and back time series feature extraction network in the abnormal request identification model to obtain the front and back time series features corresponding to the request information sequence; input the front and back time series features into the multi-layer perceptron of the abnormal request identification model to obtain a classification result for the network access request; input the classification result into the activation layer of the abnormal request identification model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal, and the probability that the network access request belongs to each preset type of network attack mode; when the probability that the network access request is normal is the highest, the network access request is not abnormal as the second identification result; when the probability that the network access request is normal is not the highest, the network attack mode of the preset type with the highest probability is used as the second identification result.
[0142] In one embodiment, the second identification module 604 is specifically used to decode the request information of the network access request to obtain decoded request information; extract field information corresponding to at least one field associated with the network attack from the decoded request information; perform character conversion on the field information corresponding to each field to obtain a character conversion result corresponding to each field; and generate a request information sequence of the network access request based on the character conversion result corresponding to each field.
[0143] In one embodiment, the optimization module 608 is specifically used to determine the target network attack pattern to which the network access request belongs when the recognition result audit information indicates that the first recognition result is erroneous; and add the protection rules for the target network attack pattern to the protection rule set to optimize the protection rule set.
[0144] In one embodiment, the optimization module 608 is specifically used to collect false positive data or missed negative data when the recognition result audit information indicates that the second recognition result is erroneous; and use the false positive data or missed negative data to fine-tune the abnormal request recognition model to optimize the abnormal request recognition model.
[0145] Each module in the aforementioned network access request identification device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0146] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 7As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store identification data of network access requests. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for identifying a network access request is implemented.
[0147] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0148] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When executed by the processor, the computer program causes the processor to perform the steps of the method for identifying a network access request described above. The steps of the method for identifying a network access request may be the steps of the method for identifying a network access request described in each of the above embodiments.
[0149] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When executed by a processor, the computer program causes the processor to perform the steps of the method for identifying a network access request described above. The steps of the method for identifying a network access request may be the steps of the method for identifying a network access request described in each of the above embodiments.
[0150] In one embodiment, a computer program product is provided, including a computer program. When executed by a processor, the computer program causes the processor to perform the steps of the method for identifying a network access request described above. The steps of the method for identifying a network access request may be the steps of the method for identifying a network access request described in each of the above embodiments.
[0151] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.
[0152] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0153] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for identifying a network access request, characterized in that: The method comprises: Receiving a network access request for a target Web application, identifying the network access request using a Web application firewall system, and obtaining a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request; Using a pre-trained abnormal request recognition model to recognize the network access request, and obtaining a second recognition result; the second recognition result is used to indicate whether the network access request is a preset type of network attack mode; In the case where the comparison result of the first recognition result and the second recognition result does not match, receiving recognition result review information returned by the Web application firewall control center; the recognition result review information includes manual review results of the first recognition result and the second recognition result; According to the identification result audit information, the abnormal request identification model and / or the protection rule set of the Web application firewall system are optimized, and the step of receiving the network access request for the target Web application is returned to identify the new network access request.
2. The method according to claim 1, characterized in that The adopting of the Web application firewall system to identify the network access request to obtain a first identification result includes: Through the multiple protection functions integrated in the Web application firewall system, the network access request is identified as abnormal, and the identification results output by each protection function are obtained; When the identification results output by each of the protection functions indicate that the network access request does not have any abnormality, taking the network access request not having any abnormality as the first identification result; In the case where the identification result output by any of the protection functions indicates that the network access request is abnormal, the network attack pattern targeted by the protection function is used as the first identification result.
3. The method according to claim 1, characterized in that The using of the pre-trained abnormal request recognition model to recognize the network access request to obtain a second recognition result includes: generating a request information sequence of the network access request based on the request information of the network access request; Inputting the request information sequence into the before-after time sequence feature extraction network in the abnormal request recognition model to obtain the before-after time sequence features corresponding to the request information sequence; Inputting the preceding and following time series features into the multi-layer perceptron of the abnormal request recognition model to obtain a classification result for the network access request; Inputting the classification result into the activation layer of the abnormal request recognition model to obtain a probability distribution result; the probability distribution result includes the probability that the network access request is normal, and the probability that the network access request belongs to each of the preset types of network attack modes; In a case where the probability that the network access request is normal is the highest, taking the network access request as having no abnormality as the second identification result; When the probability that the network access request is normal is not the highest, the network attack pattern of the preset type with the highest probability is taken as the second identification result.
4. The method according to claim 3, characterized in that The step of generating a request information sequence of the network access request based on the request information of the network access request includes: Decoding the request information of the network access request to obtain decoded request information; Extracting field information corresponding to at least one field associated with the network attack from the decoded request information; Performing character conversion on the field information corresponding to each of the fields to obtain a character conversion result corresponding to each of the fields; Based on the character conversion results corresponding to the fields, a request information sequence of the network access request is generated.
5. The method according to claim 1, characterized in that The optimizing the abnormal request recognition model and / or the protection rule set of the Web application fire protection system according to the recognition result audit information includes: In a case where the identification result review information indicates that the first identification result is erroneous, determining a target network attack mode to which the network access request belongs; Adding protection rules for the target network attack pattern to the protection rule set to optimize the protection rule set.
6. The method according to claim 1, characterized in that The optimizing the abnormal request recognition model and / or the protection rule set of the Web application fire protection system according to the recognition result audit information includes: In the case where the recognition result review information indicates that the second recognition result is erroneous, collecting false positive data or missed negative data; The abnormal request recognition model is fine-tuned using the false positive data or the missed negative data to optimize the abnormal request recognition model.
7. A network access request identification device, characterized in that: The device comprises: A first identification module is used to receive a network access request for a target Web application, and use a Web application firewall system to identify the network access request to obtain a first identification result; the first identification result is used to instruct the Web application firewall system to intercept or release the network access request; a second identification module, configured to identify the network access request using a pre-trained abnormal request identification model to obtain a second identification result; the second identification result is used to indicate whether the network access request is a preset type of network attack mode; An audit module, configured to receive, when the comparison result between the first recognition result and the second recognition result does not match, recognition result audit information returned by the Web application firewall control center; the recognition result audit information includes manual audit results of the first recognition result and the second recognition result; The optimization module is used to optimize the abnormal request recognition model and / or the protection rule set of the Web application fire protection system according to the recognition result audit information, and return to the step of receiving the network access request for the target Web application to identify the new network access request.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Abnormal behavior analysis method and device with privacy protection function
CN115865487A
Identification method and device of application access request and computer equipment
CN115913707A
Automatic optimization Web application firewall rule matching system and method
CN116015724A
Network traffic anomaly detection method and system
CN116668083A
Multi-scale fusion fast network traffic anomaly detection method based on comparative learning
CN119583133A