Method and device for enhancing security of original interface based on confusion interface and medium

By obfuscating the interface information, the parameters in the request path are updated to the request header and the request body, and the request method and path are obfuscated, which solves the security risks existing in the existing interface design and significantly improves the security and defense capabilities of the interface.

CN120017413AActive Publication Date: 2025-05-16SHENZHEN SMARTCITY TECH DEV GRP CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510457585.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-05-16
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

Due to its intuitiveness and ease of use, existing interface designs have security risks. Attackers can guess business logic by analyzing the interface structure and conduct attacks. The lack of effective security protection when the authorized system fails, resulting in unauthorized access risks.

Method used

Using an enhanced method based on obfuscation interface, by obtaining the interface information to be obfuscated and processing it according to preset obfuscated rules, the parameters in the request path are updated to the request header parameters and request body parameters, and the request method and path are obfuscated, and the obfuscated interface information is exposed to the caller.

Benefits of technology

It effectively hides the real structure and data of the interface, reduces the risk of attackers' identification and utilization, improves the system's defense capabilities, and ensures the security and function balance of the interface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017413A_ABST
    Figure CN120017413A_ABST
Patent Text Reader

Abstract

The invention discloses a method and device for enhancing the security of an original interface based on a confusion interface and a medium, and relates to the technical field of network security, the method comprises the following steps: obtaining to-be-confused interface information, the to-be-confused interface information comprising a request mode, a request path, a request header parameter and a request body parameter; performing confusion processing on the interface information according to a preset confusion rule to obtain confused interface information, the confusion rule being used for updating parameters in the request path to request header parameters and request body parameters, and performing confusion processing on the request mode and the request path; and exposing the confused interface information to a calling party, so that the calling party calls an interface corresponding to the confused interface information to carry out data transmission. According to the invention, the interface access risk is reduced, and the interface access security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, device and medium for enhancing the security of an original interface based on an obfuscated interface. Background Art

[0002] With the rapid development of Internet technology, application programming interfaces (APIs) are an important means of data exchange and function calls between different software systems, and their security and confidentiality are increasingly valued. Traditional interface design usually uses intuitive and easy-to-understand naming rules to define request methods, path parameters, and query parameters in order to facilitate developers to understand and use. However, although this clear field meaning improves the readability and ease of use of the interface, it also brings potential security risks. Malicious attackers can guess the internal business logic by analyzing the interface structure, and even use automated tools to brute force or leak information to the interface. In order to solve these problems, some measures to enhance the security of the interface have been proposed in the prior art, such as adding an authorization mechanism to verify the call permission before the actual business occurs. However, this method has limitations. If the authorization system fails, the original interface lacks other effective security protection measures, which may lead to unauthorized access risks. Summary of the invention

[0003] The main purpose of this application is to provide a method, device and medium for enhancing the security of the original interface based on an obfuscated interface, aiming to reduce the risk of interface access and improve the security of interface access.

[0004] To achieve the above objectives, the present application proposes a method for enhancing the security of an original interface based on an obfuscated interface, comprising: Obtaining the interface information to be obfuscated, wherein the interface information includes the request method, request path, request header parameters, and request body parameters; According to the preset obfuscation rules, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and to obfuscate the request method and the request path; The obfuscated interface information is exposed to the caller so that the caller can call the interface corresponding to the obfuscated interface information for data transmission.

[0005] In one embodiment, the obfuscation process includes an update process, and the interface information is obfuscated according to a preset obfuscation rule, and the steps of obtaining the obfuscated interface information include: Update the request method to the corresponding preset request method; Update the authorization key parameters in the request path to the request header parameters, and update the common parameters in the request path to the request body parameters; Update the request path to the corresponding preset request path; The updated interface information is used as obfuscated interface information, wherein the updated interface information includes an updated request method, request path, request header parameters, and request body parameters.

[0006] In one embodiment, the step of updating the authorization key parameters in the request path into the request header parameters and updating the common parameters in the request path into the request body parameters further includes: Input the interface information into a preset classification model to obtain the categories output by the classification model, wherein the categories include high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance; According to the category, the authorization key parameters are updated to the request header parameters, and the common parameters are updated to the request body parameters.

[0007] In one embodiment, the steps of updating the authorization key parameters into the request header parameters and updating the common parameters into the request body parameters according to the category include: If the category is high risk and high performance, then obtain the first ASCII code value of each character in the string converted from the normal parameter, and obtain the second ASCII code value of each character in the string converted from the authorization key parameter; Encrypt each first ASCII code value once using a preset encryption function, and combine all the encrypted first ASCII code values ​​to obtain a first encrypted string; Use a preset encryption function to encrypt each second ASCII code value multiple times, and combine all the encrypted second ASCII code values ​​to obtain a second encrypted string; The first encrypted string is updated to the request body parameter, and the second encrypted string is updated to the request header parameter.

[0008] In one embodiment, the steps of updating the authorization key parameters into the request header parameters and updating the common parameters into the request body parameters according to the category include: If the category is high risk and low performance, the character string of the authorization key parameter is processed in blocks to obtain a first block, and the character string of the common parameter is processed in blocks to obtain a second block; Encrypt each first block, aggregate each encrypted first block to obtain a third encrypted string, and update the third encrypted string to the request header parameter; Each second block is encrypted, and each encrypted second block is aggregated to obtain a fourth encrypted string, and the fourth encrypted string is updated to the request body parameter.

[0009] In one embodiment, the step of updating the authorization key parameters into the request header parameters and updating the common parameters into the request body parameters according to the category further includes: If the category is low risk high performance or low risk low performance, the authorization key parameters are updated to the request header parameters; Update the normal parameters converted to strings into the request body parameters.

[0010] In one embodiment, before the step of inputting the interface information into a preset classification model, the method further includes: Collecting historical interface data, wherein the historical interface data includes historical interface information, and historical performance data and historical security data of the interface corresponding to the historical interface information; According to the historical performance data and the historical security data, the interfaces in the historical interface data are marked into different categories to obtain marked data; According to the labeled data, the preset initial model is trained using the preset random forest algorithm to obtain a classification model.

[0011] In one embodiment, the step of exposing the obfuscated interface information to the caller includes: Receive the interface call request from the caller, and convert the interface call request into the corresponding original interface call request according to the interface call request and the obfuscation rule; The original interface call request is sent to the corresponding server for processing, and the processing result is returned to the caller.

[0012] In addition, to achieve the above-mentioned purpose, the present application also proposes a device for enhancing the security of the original interface based on an obfuscated interface. The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the method for enhancing the security of the original interface based on an obfuscated interface as described above.

[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a medium, which is a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for enhancing the security of the original interface based on an obfuscated interface as described above are implemented.

[0014] One or more technical solutions proposed in this application have at least the following technical effects: The present application significantly enhances the security of interface information through a series of steps. First, the interface information to be obfuscated is obtained, wherein the interface information includes the request mode, request path, request header parameters and request body parameters. This step provides a comprehensive and detailed data basis for the subsequent obfuscation process. Then, according to the preset obfuscation rules, the interface information is obfuscated to obtain the obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and the request mode and the request path are obfuscated. This process effectively hides the real structure and data of the interface, making it difficult for potential attackers to spy on and use the interface information, greatly improving the defense capability of the system. Finally, the obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission, which not only ensures the normal use of the interface, but also avoids the direct exposure of sensitive information, and achieves a perfect balance between security and function. This series of measures together constitute a solid security line of defense, which provides a strong guarantee for the stable operation and data security of the system, reduces the risk of interface access, and improves the security of interface access. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 This is a flow chart of Embodiment 1 of the method for enhancing the security of an original interface based on an obfuscated interface according to the present application; Figure 2 This is another flow chart of the method for enhancing the security of the original interface based on the obfuscated interface of the present application; Figure 3 This is another flow chart of the method for enhancing the security of the original interface based on the obfuscated interface of the present application; Figure 4 This is a schematic diagram of the module structure of a device for enhancing the security of an original interface based on an obfuscated interface according to an embodiment of the present application; Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the method for enhancing the security of the original interface based on the obfuscated interface in the embodiment of the present application.

[0018] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0019] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0020] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0021] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of realizing the above functions, a terminal system, etc. The following takes the system as an example to illustrate this embodiment and the following embodiments.

[0022] Based on this, this embodiment provides a method for enhancing the security of the original interface based on the obfuscated interface. Figure 1 , Figure 1 This is a flow chart of a method for enhancing the security of an original interface based on an obfuscated interface in this application. The method for enhancing the security of an original interface based on an obfuscated interface includes steps S10 to S30: Step S10, obtaining the interface information to be obfuscated, wherein the interface information includes the request method, request path, request header parameters, and request body parameters; Step S20, according to the preset obfuscation rules, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and to obfuscate the request method and the request path; Step S30, the obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission.

[0023] It should be noted that the interface information to be obfuscated refers to a detailed description of the network interface that needs to be securely processed, including the request method (such as GET (an interface transmission method), POST (an interface transmission method)), the request path (URL of the API (Application Programming Interface)), the request header parameters (such as HTTP (Hypertext Transfer Protocol) header information such as authentication tokens and content types), and the request body parameters (such as JSON (a file format) data in a POST request). Obfuscation rules are a series of pre-set conversion and encryption instructions used to change the original form of interface information to enhance security. Obfuscated interface information is interface information processed by obfuscation rules, and its purpose is to prevent the caller of the interface from easily identifying the true structure of the interface and the meaning of the parameters. The caller refers to the client or server that initiates the interface request.

[0024] First, the system obtains the interface information to be obfuscated. This process involves collecting and organizing the various components of the interface, namely the request method, request path, request header parameters, and request body parameters. For example, a typical API request may have a GET request method, a / api / user / profile request path, a request header parameter containing authorization key parameters, and a QUERY parameter containing user information.

[0025] Next, the system processes the interface information according to the preset obfuscation rules. Obfuscation rules may include, but are not limited to, changing the request method (e.g., changing GET to POST), renaming the request path (e.g., changing / api / user / profile to / api / xyx / abc), encrypting request header parameters, and encoding or encrypting request body parameters. The principle of these operations is to use encryption algorithms and data conversion technologies to make the interface information difficult to understand and parse during transmission. For example, use the AES (Advanced Encryption Standard) encryption algorithm to encrypt sensitive information in the request body, or use Base64 encoding to encode the request header parameters.

[0026] Finally, the system exposes the obfuscated interface information to the caller. This means that the caller will initiate a request based on the obfuscated interface definition. For example, the caller will use a new POST request method, a new request path / api / xyx / abc, encrypted request header parameters, and encoded request body parameters to send a request. The purpose of this is to increase the security of the interface without affecting the interface function and prevent the interface information from being maliciously exploited.

[0027] Furthermore, in order to cope with the ever-changing security threats, the obfuscation rules should be updated regularly. For example, the obfuscation rules can be updated quarterly or semi-annually to ensure that the security of the interface is always maintained at a high level. In addition to obfuscating interface information, access control mechanisms can also be combined to restrict access to specific IP addresses or user groups. For example, a whitelist can be set to allow only specific IP addresses to access sensitive interfaces. Audit and alert behaviors that frequently access interfaces. For example, if a certain IP address initiates a large number of requests in a short period of time, the system can automatically send an alarm to notify the administrator so that timely measures can be taken. When obfuscating request body parameters, more advanced encryption algorithms, such as the RSA (Rivest-Shamir-Adleman) asymmetric encryption algorithm, can be used to provide stronger security. The RSA algorithm uses a pair of public and private keys to ensure that only the recipient holding the private key can decrypt the data, thereby further enhancing the security of the data.

[0028] For example, first, we need to clarify the interface information to be obfuscated. There are URL parameters (ordinary parameters) and QUERY parameters (authorization key parameters) in the request path: 1) URL parameters: for example / api / users / 123, where 123 is the user ID; 2) QUERY parameter: It starts with ? at the end of the URL, followed by a series of parameters in the form of key-value pairs, which are used to pass query conditions, paging information, etc. to the server, such as / api / users / 123?page=2&pageSize=10; 3) Request header parameters: Set specific parameters in the HTTP request header to pass some request-related metadata or authorization information, such as Bearer token_value; 4) Request body parameters: When using methods such as POST or PUT to submit data to create or update resources, you can put parameters in the request body. The request body can be data in JSON, XML, or other formats, such as {"userId":"123"}; Based on the above parameters, API obfuscation is performed. Referring to Table 1 below, the obfuscated content is: 1. Update the request method, such as changing GET request to POST; 2. Update the request path, such as / api / user / 123 to / api / qeuryBase; 3. Package and convert the parameters in the request path, such as converting URL parameters into ID parameters in the body; Table 1:

[0029] This embodiment significantly enhances the security of interface information through a series of steps. First, the interface information to be obfuscated is obtained, wherein the interface information includes the request mode, request path, request header parameters and request body parameters. This step provides a comprehensive and detailed data basis for the subsequent obfuscation process. Then, according to the preset obfuscation rules, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and request body parameters, and the request mode and request path are obfuscated. This process effectively hides the real structure and data of the interface, making it difficult for potential attackers to spy on and use the interface information, greatly improving the defense capability of the system. Finally, the obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission, which not only ensures the normal use of the interface, but also avoids the direct exposure of sensitive information, and achieves a perfect balance between security and function. This series of measures together constitute a solid security line of defense, which provides a strong guarantee for the stable operation and data security of the system, reduces the risk of interface access, and improves the security of interface access.

[0030] In a feasible implementation manner, the steps in step S30 may include steps T10 to T20: Step T10, receiving the interface call request from the caller, and converting the interface call request into the corresponding original interface call request according to the interface call request and the obfuscation rule; Step T20, sending the original interface call request to the corresponding server for processing, and returning the processing result to the caller.

[0031] It should be noted that the interface call request initiated by the caller refers to the request sent by the client or server to the server, which contains the interface information that has been obfuscated, such as the request method, request path, request header parameters and request body parameters. The obfuscation rules are a series of pre-set conversion and encryption instructions used to convert the original interface information into obfuscated interface information. The original interface call request refers to the interface request that the caller originally needed to send before the obfuscation process, which contains the actual request method, request path, request header parameters and request body parameters. The server refers to the server that processes the interface request, which is responsible for processing the interface call request and returning the processing result.

[0032] First, the system receives the interface call request sent by the caller. This request contains obfuscated interface information, for example, the request method may be changed from GET to POST, the request path may be changed from / api / user / profile to / api / xyx / abc, the Authorization field (key authorization parameter) in the request header parameter may have been encrypted, and the JSON data in the request body parameter may have been encoded or encrypted.

[0033] Next, the system converts the received obfuscated interface call request into the corresponding original interface call request according to the preset obfuscation rules. This conversion process involves decryption and reverse conversion operations. For example, if the request method is obfuscated as POST, the system will restore it to the original GET method; if the request path is obfuscated as / api / xyx / abc, the system will restore it to the original / api / user / profile path; if the Authorization field in the request header parameter is encrypted, the system will use the corresponding decryption algorithm to decrypt it; if the JSON data in the request body parameter is encoded, the system will perform a decoding operation.

[0034] Specifically, assuming that the obfuscation rule contains an instruction to change the request method from GET to POST, when the system receives a POST request, it will restore the request method to GET according to the reverse instruction in the obfuscation rule. Similarly, if the request path is obfuscated as / api / xyx / abc, the system will restore the path to / api / user / profile according to the mapping relationship in the obfuscation rule. For encrypted request header parameters, the system will use a pre-set decryption algorithm (such as the AES decryption algorithm) for decryption. For encoded request body parameters, the system will use the corresponding decoding algorithm (such as Base64 decoding) for decoding.

[0035] After the conversion is completed, the system sends the original interface call request to the corresponding server for processing. After receiving the original interface call request, the server processes it according to normal business logic and generates a processing result. The processing result may be a JSON response, which contains the status code, message and data of the request processing. Finally, the system returns the processing result to the caller, and the caller performs subsequent operations based on the returned result.

[0036] Furthermore, in order to improve security, obfuscation rules can be generated dynamically, and different obfuscation rules are used for each interface call. For example, a unique obfuscation rule can be generated by combining timestamp, user ID and random number, and a new rule is used for obfuscation and conversion for each request. When obfuscating request body parameters, a multi-layer encryption algorithm can be used, such as first encrypting with a symmetric encryption algorithm (such as AES), and then using an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. Before the server processes the original interface call request, a request verification mechanism can be added to verify the legitimacy and integrity of the request. For example, the interface call request can be signed using digital signature technology, and the server verifies the validity of the signature before processing the request. In order to reduce the impact of the obfuscation and conversion process on performance, an efficient encryption and decryption algorithm can be used, such as the AES encryption algorithm accelerated by hardware. At the same time, commonly used obfuscation rules and decryption results can be cached to reduce repeated calculations.

[0037] After exposing the obfuscated interface information, this embodiment can accurately convert the caller's request into the original interface call request and send it to the server for processing, ensuring the availability and compatibility of the interface. At the same time, through the reverse conversion of the obfuscation rules, the security and accuracy of the interface call are guaranteed.

[0038] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the first embodiment can be referred to the above introduction, and will not be repeated in the following. Figure 2 , step S20 also includes steps A10 to A40: Step A10, updating the request mode to a corresponding preset request mode; Step A20, updating the authorization key parameters in the request path into the request header parameters, and updating the common parameters in the request path into the request body parameters; Step A30, updating the request path to the corresponding preset request path; Step A40, using the updated interface information as obfuscated interface information, wherein the updated interface information includes an updated request method, request path, request header parameters, and request body parameters.

[0039] It should be noted that the request method refers to the type of HTTP request, such as GET, POST, etc. Authorization key parameters refer to the parameters used for authentication and authorization in the request path, which usually contain sensitive information. Common parameters refer to other parameters in the request path except for the authorization key parameters. The preset request method refers to the new request method selected according to the obfuscation rules. The preset request path refers to the new request path selected according to the obfuscation rules. Obfuscated interface information refers to the interface information processed by the obfuscation rules, and its purpose is to prevent the caller of the interface from easily identifying the true structure of the interface and the meaning of the parameters.

[0040] First, according to the obfuscation rules, the request method is updated to the corresponding preset request method. For example, if the original request method is GET, it can be updated to POST according to the obfuscation rules. The purpose of this process is to change the appearance of the request, making it difficult for attackers to identify the true type of the request.

[0041] Next, update the authorization key parameters in the request path to the request header parameters, and update the common parameters in the request path to the request body parameters. For example, assume that the request path is / api / user / {userId}, where {userId} is the authorization key parameter, and other parameters such as ?page=1&size=10 are common parameters. According to the obfuscation rules, move {userId} to the request header, such as Authorization: UserId {userId}, and move page and size to the request body, such as { "page": 1, "size": 10}. The purpose of this process is to hide sensitive information and prevent them from being exposed in the URL (Uniform Resource Locator Path Parameters).

[0042] Then, according to the obfuscation rules, the request path is updated to the corresponding preset request path. For example, the original path / api / user / {userId} is updated to / api / xyx / abc. The purpose of this process is to further obfuscate the request path, making it difficult for attackers to identify the real target of the request.

[0043] Finally, the updated interface information is used as the obfuscated interface information. This means that the interface information processed by the above steps will be used for the actual request call. For example, the original request GET / api / user / 123?page=1&size=10 becomes POST / api / xyx / abc after obfuscation, the request header contains Authorization: UserId 123, and the request body contains { "page": 1, "size": 10}. In this way, the obfuscated interface information is more secure during transmission and difficult to be parsed and used by attackers.

[0044] Furthermore, in order to improve security, obfuscation rules can be generated dynamically, and different obfuscation rules can be used for each interface call. For example, a unique obfuscation rule can be generated by combining timestamp, user ID and random number, and new rules are used for obfuscation and conversion each time a request is made. When obfuscating request body parameters, multi-layer encryption algorithms can be used, such as first encrypting with a symmetric encryption algorithm (such as AES), and then using an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. Before the server processes the original interface call request, a request verification mechanism can be added to verify the legitimacy and integrity of the request. For example, digital signature technology can be used to sign the interface call request, and the server verifies the validity of the signature before processing the request.

[0045] Performance optimization: In order to reduce the impact of the obfuscation and conversion process on performance, efficient encryption and decryption algorithms can be used, such as the AES encryption algorithm with hardware acceleration. At the same time, commonly used obfuscation rules and decryption results can be cached to reduce repeated calculations.

[0046] By obfuscating the interface information according to preset obfuscation rules, this embodiment effectively improves the security of the interface and prevents the leakage of sensitive information. For example, the request method, path parameters, etc. are updated to preset values, making it difficult for attackers to directly identify the real functions and parameters of the interface, thereby enhancing the system's defense capabilities.

[0047] In one possible implementation, reference Figure 3 , step A20 also includes steps A201~A202: Step A201, inputting the interface information into a preset classification model, and obtaining the categories output by the classification model, wherein the categories include high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance; Step A202, according to the category, updates the authorization key parameters into the request header parameters, and updates the common parameters into the request body parameters.

[0048] It should be noted that the preset classification model is a trained machine learning model used to classify interface information to determine its risk and performance level. Authorization key parameters refer to the parameters used for authentication and authorization in the request path, which usually contain sensitive information. Common parameters refer to other parameters in the request path except for the authorization key parameters. Category refers to the risk and performance level output by the classification model, including high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance.

[0049] First, the interface information is input into a preset classification model. This process involves inputting a detailed description of the interface, including the request method, request path, request header parameters, and request body parameters, into a trained machine learning model. The purpose of the model is to classify the risk and performance of the interface based on this information.

[0050] Next, the authorization key parameters and common parameters are processed according to the category output by the classification model. Specifically, if the category output by the classification model is high risk and high performance, the authorization key parameters and common parameters are converted into strings respectively, the ASCII (American Standard Code for Information Interchange) code value of each character is obtained, and each ASCII code value is calculated using a preset function, and all the calculated ASCII code values ​​are combined to obtain an encrypted string. Then, the encrypted authorization key parameters are updated to the request header parameters, and the encrypted common parameters are updated to the request body parameters.

[0051] If the classification model outputs the category of high risk and low performance, the authorization key parameters and common parameters are converted into strings respectively, the strings are divided into blocks, and each block is encrypted, and all the encrypted blocks are combined to obtain the encrypted string. Then, the encrypted authorization key parameters are updated to the request header parameters, and the encrypted common parameters are updated to the request body parameters.

[0052] If the category output by the classification model is low risk and high performance or low risk and low performance, then the common parameters are converted into strings, the authorization key parameters are updated into the request header parameters, and the converted common parameters are updated into the request body parameters.

[0053] Furthermore, in order to improve the accuracy and adaptability of classification, the classification model can be retrained regularly to include the latest interface usage data and security events. For example, the model can be retrained with a new data set every month or quarter to ensure that the model can accurately identify new security threats and performance changes. When dealing with high-risk interfaces, a multi-level encryption strategy can be adopted, such as first encrypting with a symmetric encryption algorithm (such as AES) and then using an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategies are adjusted in time. For example, if the performance of an interface is found to suddenly drop, the encryption strategy can be temporarily adjusted to reduce the complexity of encryption to restore performance. Combined with user behavior analysis, the security of the interface can be further enhanced. For example, if a user frequently calls a high-risk interface, its behavior can be analyzed to determine whether there is abnormal behavior and take corresponding security measures.

[0054] By introducing a classification model before obfuscation processing, this embodiment can adopt different processing strategies for interface information of different risk levels, thereby improving processing efficiency and security. Through precise classification, customized protection of different interface information is achieved, thereby reducing security risks.

[0055] In a feasible implementation manner, the step A10 also includes steps A001 to A003: Step A001, collecting historical interface data, wherein the historical interface data includes historical interface information, and historical performance data and historical security data of the interface corresponding to the historical interface information; Step A002, marking interfaces in the historical interface data into different categories according to the historical performance data and the historical security data, to obtain marked data; Step A003: Based on the labeled data, a preset random forest algorithm is used to perform model training on the preset initial model to obtain a classification model.

[0056] It should be noted that historical interface data refers to information related to interface calls recorded by the system in the past, including historical interface information, historical performance data, and historical security data. Historical interface information covers details such as the interface request method, request path, request header parameters, and request body parameters. Historical performance data records the performance indicators of interface calls, such as response time, throughput, and error rate. Historical security data records events related to interface security, such as attack type, attack source IP, and attack time. Annotated data is data obtained by classifying and annotating historical interface data, which is used for model training. The random forest algorithm is an ensemble learning algorithm that improves the accuracy and robustness of the model by constructing multiple decision trees and synthesizing their prediction results. The preset initial model refers to the model structure and parameters set before the training starts. The classification model is a trained model that can classify interface data.

[0057] First, the system collects historical interface data, which includes historical interface information, historical performance data, and historical security data. For example, historical interface information may include a request method of POST, a request path of / api / user / profile, and a request header parameter of Authorization: Bearer. <token>, the request body parameter is { "userId": "123"}. Historical performance data may record that the average response time of the interface is 200 milliseconds, the throughput is 100 requests per second, and the error rate is 0.1%. Historical security data may record that the interface has suffered 10 SQL (Structured Query Language) injection attacks in the past month, and the attack source IPs are mainly from a specific region.

[0058] Next, based on the historical performance data and historical security data, the interfaces in the historical interface data are labeled into different categories to obtain labeled data. For example, based on the performance data and the frequency of security events, the interfaces are labeled as high-risk high performance, high-risk low performance, low-risk high performance, or low-risk low performance. The purpose of this process is to provide clear classification targets for model training.

[0059] Then, based on the labeled data, the random forest algorithm is used to train the preset initial model to obtain a classification model. The random forest algorithm builds multiple decision trees and combines their prediction results to improve the accuracy and robustness of the model. During the training process, the algorithm learns from the labeled data how to classify based on the characteristics of the interface (such as request method, request path, performance indicators, security events, etc.). For example, the algorithm may find that interfaces with short response times and no attacks usually belong to the low-risk high-performance category, while interfaces with long response times and frequent attacks usually belong to the high-risk low-performance category.

[0060] Furthermore, in order to improve the timeliness and accuracy of the model, the collection of historical interface data can be carried out dynamically. For example, the system can collect the latest interface call data in real time and regularly update the historical data set to ensure that the model training uses the latest data. In order to cope with the ever-changing security threats and performance changes, the classification model can be retrained regularly. For example, the model can be retrained monthly or quarterly using the latest historical interface data to ensure that the model can accurately identify new security threats and performance issues. In addition to the random forest algorithm, other machine learning algorithms, such as support vector machines or neural networks, can be combined to build a multi-model integration system. For example, through a voting mechanism or stacking method, the prediction results of multiple models are combined to further improve the accuracy and robustness of the classification. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the model parameters and classification strategies are adjusted in a timely manner. For example, if it is found that the classification result of a certain interface does not match the actual performance, the model parameters can be adjusted in a timely manner and the model can be retrained.

[0061] By collecting historical interface data and training the classification model, this embodiment can accurately identify the risk level of the interface, provide strong support for subsequent security processing, and improve the pertinence and effectiveness of security processing.

[0062] Based on the first or second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the first or second embodiment can be referred to the above description, and will not be described in detail later. Step A202 also includes steps B10 to B40: Step B10, if the category is high risk and high performance, obtaining the first ASCII code value of each character in the string converted from the common parameters, and obtaining the second ASCII code value of each character in the string converted from the authorization key parameters; Step B20, encrypt each first ASCII code value once using a preset encryption function, and combine all the encrypted first ASCII code values ​​to obtain a first encrypted string; Step B30, encrypt each second ASCII code value multiple times using a preset encryption function, and combine all the encrypted second ASCII code values ​​to obtain a second encrypted string; Step B40, update the first encrypted string into the request body parameter, and update the second encrypted string into the request header parameter.

[0063] It should be noted that the first ASCII code value refers to the ASCII code value of each character in the string converted from the ordinary parameters. The second ASCII code value refers to the ASCII code value of each character in the string converted from the authorization key parameters. The preset encryption function refers to a specific function used to encrypt the ASCII code value. The first encrypted string refers to the string obtained by encrypting the first ASCII code value through the preset encryption function. The second encrypted string refers to the string obtained by encrypting the second ASCII code value multiple times through the preset encryption function. The request header parameter refers to the parameter in the HTTP request header, which is used to pass metadata such as authentication information. The request body parameter refers to the parameter in the HTTP request body, which is used to pass the specific data of the request.

[0064] When the classification model outputs the category of high risk and high performance, the system converts the common parameters into a string and obtains the first ASCII code value of each character in the string. For example, the common parameter page=1&size=10 is converted to the string "1,10", and its ASCII code values ​​are 49, 44, 49, 48 respectively. The authorization key parameter is converted into a string and the second ASCII code value of each character in the string is obtained. For example, the authorization key parameter userId=123 is converted to the string "123", and its ASCII code values ​​are 49, 50, 51 respectively. Each first ASCII code value is encrypted once using the preset encryption function. For example, if the preset encryption function is f(x) = x + 10, the encrypted first ASCII code values ​​are 59, 54, 59, 58 respectively. Each second ASCII code value is encrypted multiple times using the preset encryption function. For example, the preset encryption function is f(x) = x +10, and the second ASCII code values ​​after two encryptions are 69, 70, 71 (59, 60, 61 after the first encryption, and 69, 70, 71 after the second encryption). Combine all the encrypted first ASCII code values ​​into the first encrypted string. For example, the encrypted first ASCII code values ​​59, 54, 59, 58 are combined into the string "59,54,59,58". Combine all the encrypted second ASCII code values ​​into the second encrypted string. For example, the encrypted second ASCII code values ​​69, 70, 71 are combined into the string "69,70,71". Update the first encrypted string to the request body parameters. For example, update "59,54,59,58" to the request body parameters { "page": "59", "size": "54"}. Update the second encrypted string to the request header parameters. For example, update "69,70,71" to the request header parameter Authorization: EncryptedUserId 69,70,71.

[0065] Furthermore, in order to improve security and flexibility, preset encryption functions can be generated dynamically. For example, a unique preset encryption function is generated based on the timestamp, user ID and random number of the request, and a new function is used for encryption each time a request is made. When dealing with high-risk interfaces, a multi-level encryption strategy can be adopted, such as first using a symmetric encryption algorithm (such as AES) for encryption, and then using an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategies are adjusted in time. For example, if the performance of an interface is found to suddenly drop, the encryption strategy can be temporarily adjusted to reduce the complexity of encryption to restore performance. Combined with user behavior analysis, the security of the interface can be further enhanced. For example, if a user frequently calls a high-risk interface, its behavior can be analyzed to determine whether there is abnormal behavior, and corresponding security measures can be taken.

[0066] For high-risk and high-performance interface information, string conversion and ASCII code operation encryption are adopted. This embodiment significantly enhances the confidentiality of the interface information. Even if the information is intercepted, it is difficult for attackers to crack it, thus effectively ensuring the security of the interface.

[0067] In a feasible implementation manner, step A202 further includes steps C10 to C30: Step C10: if the category is high risk and low performance, the character string of the authorization key parameter is processed in blocks to obtain a first block, and the character string of the common parameter is processed in blocks to obtain a second block; Step C20, encrypting each first block, and aggregating each first block after encryption to obtain a third encrypted string, and updating the third encrypted string to the request header parameter; Step C30, encrypt each second block, aggregate each encrypted second block to obtain a fourth encrypted string, and update the fourth encrypted string to the request body parameter.

[0068] It should be noted that block processing refers to dividing a string into multiple small blocks, each of which contains a certain number of characters. Encryption processing refers to encrypting data using an encryption algorithm to protect the confidentiality of the data. Aggregation processing refers to combining multiple encrypted blocks into a new string. The third encrypted string refers to the encrypted string obtained after encryption processing and aggregation processing, which is used to update the request header parameters. The fourth encrypted string refers to the encrypted string obtained after encryption processing and aggregation processing, which is used to update the request body parameters.

[0069] When the classification model outputs the category of high risk and low performance, the system will block the string of the key authorization parameter to obtain the first block. For example, the key authorization parameter userId=123456 is converted to the string "123456", and after block processing, ["123", "456"] is obtained.

[0070] The string of the common parameter is divided into blocks to obtain the second block. For example, the common parameter page=1&size=10 is converted to the string "1,10", and the block is obtained ["1", "10"]. Each first block is encrypted. A symmetric encryption algorithm (such as AES) or an asymmetric encryption algorithm (such as RSA) can be used. For example, "123" and "456" are encrypted using the AES algorithm to obtain encrypted blocks ["encrypted123", "encrypted456"]. Each second block is encrypted. Similarly, "1" and "10" are encrypted using the encryption algorithm to obtain encrypted blocks ["encrypted1", "encrypted10"]. Each first block after encryption is aggregated to obtain a third encrypted string. For example, ["encrypted123", "encrypted456"] are combined into the string "encrypted123,encrypted456". Each second block after encryption is aggregated to obtain a fourth encrypted string. For example, combine ["encrypted1","encrypted10"] into the string "encrypted1,encrypted10". Update the third encrypted string to the request header parameter. For example, update "encrypted123,encrypted456" to the request header parameter Authorization:EncryptedUserId encrypted123,encrypted456. Update the fourth encrypted string to the request body parameter. For example, update "encrypted1,encrypted10" to the request body parameter { "page": "encrypted1", "size": "encrypted10"}.

[0071] Furthermore, in order to improve security and flexibility, the size of the block can be adjusted dynamically. For example, according to the complexity and performance requirements of the request, the block size is dynamically selected, and a different block size is used for encryption each time a request is made. When dealing with high-risk interfaces, a multi-level encryption strategy can be adopted, such as first using a symmetric encryption algorithm (such as AES) for encryption, and then using an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategies are adjusted in time. For example, if the performance of an interface is found to suddenly drop, the encryption strategy can be temporarily adjusted to reduce the complexity of encryption to restore performance. Combined with user behavior analysis, the security of the interface can be further enhanced. For example, if a user frequently calls a high-risk interface, its behavior can be analyzed to determine whether there is abnormal behavior, and corresponding security measures can be taken.

[0072] For high-risk and low-performance interface information, block encryption processing is adopted. This embodiment reduces the impact on system performance by optimizing the encryption method while ensuring security, thus achieving a balance between security and performance.

[0073] In a feasible implementation manner, step A202 further includes steps D10 to D20: Step D10, if the category is low risk high performance or low risk low performance, the authorization key parameters are updated to the request header parameters; Step D20, updating the common parameters converted into character strings into the request body parameters.

[0074] It should be noted that the third string refers to the string form after the ordinary parameter is converted. The request header parameter refers to the parameter in the HTTP request header, which is used to pass metadata such as authentication information. The request body parameter refers to the parameter in the HTTP request body, which is used to pass the specific data of the request.

[0075] When the classification model outputs the category of low risk high performance or low risk low performance, the system will perform the following steps to process common parameters: Convert common parameters to string form. For example, the common parameter page=1&size=10 is converted to the string "1,10". The purpose of this process is to convert common parameters from key-value pairs to simple string form for subsequent processing. Update the authorization key parameter to the request header parameter. For example, update userId=123 to the request header parameter Authorization: UserId 123. The purpose of this process is to move the authorization key parameter from the request path to the request header to enhance security and prevent sensitive information from being exposed in the URL. Update the third string to the request body parameter. For example, update "1,10" to the request body parameter { "page": "1", "size": "10"}. The purpose of this process is to move common parameters from the request path to the request body, further hiding the details of the parameters and preventing information leakage.

[0076] Furthermore, in order to improve security and flexibility, the conversion of common parameters can be performed dynamically. For example, according to the context information of the request (such as user role, request time, etc.), the conversion rule is dynamically selected, and different conversion rules are used for processing each request. When processing low-risk interfaces, multi-layer security strategies can be adopted, such as combining IP whitelists, request frequency restrictions and other measures to further enhance the security of the interface. For example, only specific IP addresses are allowed to access sensitive interfaces, and the number of requests per IP address per unit time is limited. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and parameter processing strategies are adjusted in time. For example, if the performance of an interface is found to suddenly drop, the parameter processing strategy can be temporarily adjusted to reduce the complexity of processing to restore performance. Combined with user behavior analysis, the security of the interface is further enhanced. For example, if a user frequently calls a low-risk interface, but the behavior pattern is abnormal (such as irregular request time intervals, abnormal request parameters, etc.), its behavior can be analyzed to determine whether there is a potential security threat, and corresponding security measures can be taken.

[0077] For low-risk and high-performance or low-risk and low-performance interface information, the processing flow is simplified. This embodiment improves processing efficiency, reduces unnecessary resource consumption, and improves overall system performance while ensuring basic security.

[0078] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the method of enhancing the security of the original interface based on the obfuscated interface of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0079] This application also provides a device for enhancing the security of the original interface based on the obfuscated interface. Please refer to Figure 4 The device for enhancing the security of the original interface based on the obfuscated interface includes: The interface acquisition module 10 acquires the interface information to be obfuscated, wherein the interface information includes the request mode, the request path, the request header parameters and the request body parameters; The obfuscation interface module 20 performs obfuscation processing on the interface information according to the preset obfuscation rules to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and to perform obfuscation processing on the request method and the request path; The interface exposure module 30 exposes the obfuscated interface information to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission.

[0080] The device for enhancing the security of the original interface based on the obfuscated interface provided by the present application adopts the method for enhancing the security of the original interface based on the obfuscated interface in the above-mentioned embodiment, which can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the device for enhancing the security of the original interface based on the obfuscated interface provided by the present application are the same as the beneficial effects of the method for enhancing the security of the original interface based on the obfuscated interface provided by the above-mentioned embodiment, and other technical features in the device for enhancing the security of the original interface based on the obfuscated interface are the same as the features disclosed in the above-mentioned embodiment method, which will not be repeated here.

[0081] The present application provides a device for enhancing the security of an original interface based on an obfuscated interface. The device for enhancing the security of an original interface based on an obfuscated interface includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for enhancing the security of an original interface based on an obfuscated interface in the above-mentioned embodiment 1.

[0082] Reference below Figure 5 , which shows a schematic diagram of the structure of a device for enhancing the security of the original interface based on the obfuscated interface suitable for implementing the embodiment of the present application. The device for enhancing the security of the original interface based on the obfuscated interface in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The device for enhancing the security of the original interface based on the obfuscated interface shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0083] like Figure 5 As shown, the device for enhancing the original interface security based on the obfuscated interface may include a processing device 1001 (such as a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 to the random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the device for enhancing the original interface security based on the obfuscated interface are also stored. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 1003 including, for example, a magnetic tape, a hard disk, etc.; and communication devices 1009. The communication device 1009 can allow the original interface security device based on the obfuscated interface to communicate wirelessly or wired with other devices to exchange data. Although the figure shows the original interface security device based on the obfuscated interface with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.

[0084] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.

[0085] The device for enhancing the security of the original interface based on the obfuscated interface provided by the present application adopts the method for enhancing the security of the original interface based on the obfuscated interface in the above embodiment, which can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the device for enhancing the security of the original interface based on the obfuscated interface provided by the present application are the same as the beneficial effects of the method for enhancing the security of the original interface based on the obfuscated interface provided by the above embodiment, and the other technical features of the device for enhancing the security of the original interface based on the obfuscated interface are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.

[0086] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0087] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0088] The present application provides a medium, which is a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the method for enhancing the security of an original interface based on an obfuscated interface in the above-mentioned embodiment.

[0089] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM: Random Access Memory), a read-only memory (ROM: Read Only Memory), an erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency: Radio Frequency), etc., or any suitable combination of the above.

[0090] The computer-readable storage medium may be included in the device for enhancing the security of the original interface based on the obfuscated interface; or may exist independently without being assembled into the device for enhancing the security of the original interface based on the obfuscated interface.

[0091] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the device for enhancing the security of the original interface based on the obfuscated interface, the device for enhancing the security of the original interface based on the obfuscated interface: Obtaining the interface information to be obfuscated, wherein the interface information includes the request method, request path, request header parameters, and request body parameters; According to the preset obfuscation rules, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and to obfuscate the request method and the request path; The obfuscated interface information is exposed to the caller so that the caller can call the interface corresponding to the obfuscated interface information for data transmission.

[0092] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0093] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0094] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.

[0095] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned method for enhancing the security of the original interface based on the obfuscated interface, which can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the method for enhancing the security of the original interface based on the obfuscated interface provided by the above-mentioned embodiment, and will not be repeated here.

[0096] The present application also provides a product, which is a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the method for enhancing the security of an original interface based on an obfuscated interface as described above are implemented.

[0097] The computer program product provided by the present application can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as the beneficial effects of the method for enhancing the security of the original interface based on the obfuscated interface provided by the above embodiment, and will not be repeated here.

[0098] The above are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.< / token>

Claims

1. A method for enhancing the security of an original interface based on an obfuscated interface, characterized in that: The method for enhancing the security of the original interface based on the obfuscated interface includes: Obtaining interface information to be obfuscated, wherein the interface information includes request mode, request path, request header parameters, and request body parameters; According to a preset obfuscation rule, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rule is used to update the parameters in the request path to the request header parameters and the request body parameters, and to obfuscate the request method and the request path; The obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information to perform data transmission.

2. The method for enhancing the security of the original interface based on the obfuscated interface according to claim 1, characterized in that: The obfuscation process includes an update process, and the step of performing obfuscation process on the interface information according to a preset obfuscation rule to obtain the obfuscated interface information includes: Updating the request mode to a corresponding preset request mode; Update the authorization key parameters in the request path into the request header parameters, and update the common parameters in the request path into the request body parameters; Updating the request path to a corresponding preset request path; The updated interface information is used as obfuscated interface information, wherein the updated interface information includes an updated request method, request path, request header parameters, and request body parameters.

3. The method for enhancing the security of the original interface based on the obfuscated interface as claimed in claim 2, characterized in that: The step of updating the authorization key parameters in the request path into the request header parameters, and updating the common parameters in the request path into the request body parameters, further includes: Inputting the interface information into a preset classification model to obtain categories output by the classification model, wherein the categories include high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance; According to the category, the authorization key parameter is updated into the request header parameter, and the common parameter is updated into the request body parameter.

4. The method for enhancing the security of the original interface based on the obfuscated interface as claimed in claim 3 is characterized in that: The step of updating the authorization key parameter into the request header parameter and updating the common parameter into the request body parameter according to the category comprises: If the category is high risk and high performance, obtaining the first ASCII code value of each character in the string converted from the common parameter, and obtaining the second ASCII code value of each character in the string converted from the authorization key parameter; Encrypt each of the first ASCII code values ​​once using a preset encryption function, and combine all the encrypted first ASCII code values ​​to obtain a first encrypted string; Use a preset encryption function to encrypt each of the second ASCII code values ​​multiple times, and combine all the encrypted second ASCII code values ​​to obtain a second encrypted string; The first encrypted string is updated into the request body parameter, and the second encrypted string is updated into the request header parameter.

5. The method for enhancing the security of the original interface based on the obfuscated interface as claimed in claim 3 is characterized in that: The step of updating the authorization key parameter into the request header parameter and updating the common parameter into the request body parameter according to the category comprises: If the category is high risk and low performance, the character string of the authorization key parameter is processed in blocks to obtain a first block, and the character string of the common parameter is processed in blocks to obtain a second block; Encrypt each of the first blocks, aggregate each of the encrypted first blocks to obtain a third encrypted string, and update the third encrypted string to the request header parameter; Each of the second blocks is encrypted, and each of the encrypted second blocks is aggregated to obtain a fourth encrypted string, and the fourth encrypted string is updated to the request body parameter.

6. The method for enhancing the security of the original interface based on the obfuscated interface as claimed in claim 3, characterized in that: The step of updating the authorization key parameter into the request header parameter and updating the common parameter into the request body parameter according to the category further includes: If the category is low risk high performance or low risk low performance, updating the authorization key parameter to the request header parameter; Update the common parameters converted into strings into the request body parameters.

7. The method for enhancing the security of the original interface based on the obfuscated interface as claimed in claim 3, characterized in that: Before the step of inputting the interface information into a preset classification model, the method further includes: Collecting historical interface data, wherein the historical interface data includes historical interface information, and historical performance data and historical security data of the interface corresponding to the historical interface information; According to the historical performance data and the historical security data, the interfaces in the historical interface data are marked into different categories to obtain marked data; According to the labeled data, a preset initial model is trained using a preset random forest algorithm to obtain the classification model.

8. The method for enhancing the security of an original interface based on an obfuscated interface as claimed in claim 1, characterized in that: The step of exposing the obfuscated interface information to the caller includes: Receiving the interface call request from the caller, and converting the interface call request into a corresponding original interface call request according to the interface call request and the obfuscation rule; The original interface call request is sent to the corresponding server for processing, and the processing result is returned to the caller.

9. A device for enhancing the security of an original interface based on an obfuscated interface, characterized in that: The device for enhancing the security of the original interface based on an obfuscated interface comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for enhancing the security of the original interface based on an obfuscated interface as described in any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method for enhancing the security of an original interface based on an obfuscated interface as claimed in any one of claims 1 to 8.

Citation Information

Patent Citations

  • API gateway security protection method and system based on interface mapping

    CN114553410A

  • API (Application Program Interface) secure access method and device, electronic equipment and storage medium

    CN117640109A

  • Rear-end interface calling protection method and device, electronic equipment and storage medium

    CN118827163A

  • Performance test method for encryption interface

    CN118939537A

  • Systems and methods for secure high speed data generation and access

    US20180276408A1