Method, device and medium for enhancing the security of an original interface based on an obfuscated interface

By obscuring interface information through encryption and adaptive security measures, the method fortifies interface security against unauthorized access and information leakage, ensuring both functionality and safety.

CN120017413BActive Publication Date: 2025-07-15SHENZHEN SMARTCITY TECH DEV GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510457585.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-15
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

Traditional interface designs have insufficient security due to clear naming rules and are easily analyzed and cracked by malicious attackers. The existing enhancement measures lack effective protection when authorizing system failures.

Method used

By obtaining interface information and updating the parameters in the request path to the request header parameters and request body parameters according to preset obfuscation rules, hiding the interface structure using encryption and encoding techniques, combining classification models and dynamic obfuscation rules to enhance security.

Benefits of technology

Effectively hide the real structure of the interface, prevent information leakage, improve system defense capabilities, achieve a balance between security and function, and reduce interface access risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017413B_ABST
    Figure CN120017413B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device and medium for enhancing the security of the original interface based on a confused interface, which relates to the field of network security technology. The method includes: obtaining interface information to be confused, where the interface information includes a request method, a request path, request header parameters, and request body parameters; performing confusion processing on the interface information according to a preset confusion rule to obtain confused interface information, where the confusion rule is used to update the parameters in the request path to the request header parameters and the request body parameters, and perform confusion processing on the request method and the request path; exposing the confused interface information to a calling party so that the calling party can call the interface corresponding to the confused interface information for data transmission. The present application reduces the risk of interface access and improves the security of interface access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly to a method, device, and medium for enhancing the security of the original interface based on a confused interface. Background Art

[0002] With the rapid development of Internet technology, as an important means for data exchange and function call between different software systems, the security and confidentiality of application programming interfaces have received increasing attention. Traditional interface designs usually adopt intuitive and easy-to-understand naming rules to define request methods, path parameters, query parameters, etc. for the convenience of developers to understand and use. However, although the clear field meanings improve the readability and usability of the interfaces, they also bring potential security risks. Malicious attackers can guess the internal business logic by analyzing the interface structure and even use automated tools to brute-force crack the interfaces or launch information leakage attacks. To solve these problems, some measures to enhance interface security have been proposed in the prior art, such as adding an authorization mechanism to verify the call permission before the actual business occurs. However, this method has limitations. If the authorization system fails and the original interface lacks other effective security protection measures, it may lead to the risk of unauthorized access. Summary of the Invention

[0003] The main purpose of this application is to provide a method, device, and medium for enhancing the security of the original interface based on a confused interface, aiming to reduce the interface access risk and improve the interface access security.

[0004] To achieve the above object, this application proposes a method for enhancing the security of the original interface based on a confused interface, including:

[0005] Obtain the interface information to be confused, where the interface information includes the request method, request path, request header parameters, and request body parameters;

[0006] According to the preset confusion rules, perform confusion processing on the interface information to obtain confused interface information, where the confusion rules are used to update the parameters in the request path to the request header parameters and request body parameters, and perform confusion processing on the request method and request path;

[0007] Expose the confused interface information to the calling party so that the calling party can call the interface corresponding to the confused interface information for data transmission.

[0008] In one embodiment, the confusion processing includes an update process. The step of performing confusion processing on the interface information according to the preset confusion rules to obtain confused interface information includes:

[0009] Update the request method to the corresponding preset request method;

[0010] Update the authorization key parameters in the request path to the request header parameters, and update the general parameters in the request path to the request body parameters;

[0011] Update the request path to the corresponding preset request path;

[0012] Use the updated interface information as the obfuscated interface information, where the updated interface information includes the updated request method, request path, request header parameters, and request body parameters.

[0013] In one embodiment, the step of updating the authorization key parameters in the request path to the request header parameters and updating the general parameters in the request path to the request body parameters further includes:

[0014] Input the interface information into a preset classification model to obtain the category output by the classification model, where the category includes high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance;

[0015] According to the category, update the authorization key parameters to the request header parameters and update the general parameters to the request body parameters.

[0016] In one embodiment, the step of updating the authorization key parameters to the request header parameters and updating the general parameters to the request body parameters according to the category includes:

[0017] If the category is high risk and high performance, obtain the first ASCII code value of each character in the string converted from the general parameters, and obtain the second ASCII code value of each character in the string converted from the authorization key parameters;

[0018] Use a preset encryption function to encrypt each first ASCII code value once, and combine all the encrypted first ASCII code values to obtain a first encrypted string;

[0019] Use a preset encryption function to encrypt each second ASCII code value multiple times, and combine all the encrypted second ASCII code values to obtain a second encrypted string;

[0020] Update the first encrypted string to the request body parameters and update the second encrypted string to the request header parameters.

[0021] In one embodiment, the step of updating the authorization key parameters to the request header parameters and updating the general parameters to the request body parameters according to the category includes:

[0022] If the category is high risk and low performance, perform block processing on the string of the authorization key parameters to obtain a first block, and perform block processing on the string of the general parameters to obtain a second block;

[0023] Encrypt each first block, and aggregate each encrypted first block to obtain a third encrypted string, and update the third encrypted string to the request header parameter;

[0024] Encrypt each second block, and aggregate each encrypted second block to obtain a fourth encrypted string, and update the fourth encrypted string to the request body parameter.

[0025] In one embodiment, the step of updating the authorization key parameter to the request header parameter and updating the ordinary parameter to the request body parameter according to the category further includes:

[0026] If the category is low risk and high performance or low risk and low performance, update the authorization key parameter to the request header parameter;

[0027] Update the ordinary parameter converted to a string to the request body parameter.

[0028] In one embodiment, before the step of inputting the interface information into the preset classification model, it further includes:

[0029] Collect historical interface data, where the historical interface data includes historical interface information, as well as historical performance data and historical security data of the interface corresponding to the historical interface information;

[0030] Label the interfaces in the historical interface data as different categories according to the historical performance data and historical security data to obtain labeled data;

[0031] According to the labeled data, use the preset random forest algorithm to train the preset initial model to obtain a classification model.

[0032] In one embodiment, after the step of exposing the obfuscated interface information to the caller, it includes:

[0033] Receive the interface call request from the caller, and convert the interface call request into a corresponding original interface call request according to the interface call request and the obfuscation rule;

[0034] Send the original interface call request to the corresponding server for processing, and return the processing result to the caller.

[0035] In addition, to achieve the above object, the present application also proposes a device for enhancing the security of the original interface based on the obfuscated interface. The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. The computer program is configured to implement the steps of the method for enhancing the security of the original interface based on the obfuscated interface as described above.

[0036] In addition, to achieve the above-mentioned purpose, the present application also proposes a medium, which is a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for enhancing the security of the original interface based on an obfuscated interface as described above are implemented.

[0037] One or more technical solutions proposed in this application have at least the following technical effects:

[0038] The present application significantly enhances the security of interface information through a series of steps. First, the interface information to be obfuscated is obtained, wherein the interface information includes the request mode, request path, request header parameters and request body parameters. This step provides a comprehensive and detailed data basis for the subsequent obfuscation process. Then, according to the preset obfuscation rules, the interface information is obfuscated to obtain the obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and the request body parameters, and the request mode and request path are obfuscated. This process effectively hides the real structure and data of the interface, making it difficult for potential attackers to spy on and use the interface information, greatly improving the defense capability of the system. Finally, the obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission, which not only ensures the normal use of the interface, but also avoids the direct exposure of sensitive information, and achieves a perfect balance between security and function. This series of measures together constitute a solid security line of defense, which provides a strong guarantee for the stable operation and data security of the system, reduces the risk of interface access, and improves the security of interface access. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0041] Figure 1 This is a flow chart of Embodiment 1 of the method for enhancing the security of an original interface based on an obfuscated interface according to the present application;

[0042] Figure 2 This is another flow chart of the method for enhancing the security of the original interface based on the obfuscated interface of the present application;

[0043] Figure 3 This is another flow chart of the method for enhancing the security of the original interface based on the obfuscated interface of the present application;

[0044] Figure 4 This is a schematic diagram of the module structure of the device for enhancing the security of the original interface based on the obfuscated interface in the embodiments of the present application;

[0045] Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the method for enhancing the security of the original interface based on the obfuscated interface in the embodiments of the present application.

[0046] The implementation, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners

[0047] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.

[0048] For a better understanding of the technical solutions of the present application, the following will be described in detail in conjunction with the drawings in the specification and the specific implementation manners.

[0049] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device or a terminal system that can implement the above functions. The following takes the system as an example to describe this embodiment and the following embodiments.

[0050] Based on this, this embodiment provides a method for enhancing the security of the original interface based on the obfuscated interface. Refer to Figure 1 , Figure 1 This is a flowchart of the method for enhancing the security of the original interface based on the obfuscated interface in the present application. The method for enhancing the security of the original interface based on the obfuscated interface includes steps S10 to S30:

[0051] Step S10, obtain the interface information to be obfuscated, where the interface information includes the request method, request path, request header parameters, and request body parameters;

[0052] Step S20, perform obfuscation processing on the interface information according to the preset obfuscation rules to obtain obfuscated interface information, where the obfuscation rules are used to update the parameters in the request path to the request header parameters and request body parameters, and perform obfuscation processing on the request method and request path; Step S30, expose the obfuscated interface information to the calling party so that the calling party can call the interface corresponding to the obfuscated interface information for data transmission.

[0053] It should be noted that the interface information to be obfuscated refers to the detailed description of the network interface that needs to be secured. Specifically, it includes the request method (such as GET (a type of interface transmission method), POST (a type of interface transmission method)), the request path (the URL of the API (Application Programming Interface)), the request header parameters (such as authentication tokens, content types, etc., which are HTTP (Hypertext Transfer Protocol) header information), and the request body parameters (such as JSON (a file format) data in a POST request). The obfuscation rules are a series of predefined transformation and encryption instructions used to change the original form of the interface information to enhance security. The obfuscated interface information is the interface information processed by the obfuscation rules, and its purpose is to make it difficult for the interface callers to easily identify the true structure and parameter meanings of the interface. The calling party refers to the client or server that initiates the interface request.

[0054] First, the system retrieves the interface information to be obfuscated. This process involves collecting and organizing the various components of the interface, namely the request method, the request path, the request header parameters, and the request body parameters. For example, a typical API request may have a GET request method, a request path of / api / user / profile, request header parameters containing authorization key parameters, and request body parameters containing user information QUERY parameters.

[0055] Next, the system processes these interface information according to the preset obfuscation rules. The obfuscation rules can include but are not limited to changing the request method (for example, changing GET to POST), renaming the request path (such as changing / api / user / profile to / api / xyx / abc), encrypting the request header parameters, and encoding or encrypting the request body parameters. The principle of these operations is to use encryption algorithms and data transformation techniques to make the interface information difficult to understand and parse during transmission. For example, using the AES (Advanced Encryption Standard) encryption algorithm to encrypt sensitive information in the request body, or using Base64 encoding to encode the request header parameters.

[0056] Finally, the system exposes the obfuscated interface information to the calling party. This means that the calling party will initiate requests based on the obfuscated interface definition. For example, the calling party will use the new POST request method, the new request path / api / xyx / abc, the encrypted request header parameters, and the encoded request body parameters to send requests. The purpose of doing this is to increase the security of the interface without affecting its functionality and prevent the interface information from being maliciously exploited.

[0057] Furthermore, to address evolving security threats, the obfuscation rules should be updated regularly. For example, the obfuscation rules can be updated quarterly or semi-annually to ensure that the security of the interface remains at a high level. In addition to obfuscating interface information, an access control mechanism can be incorporated to restrict access from specific IP addresses or user groups. For example, a whitelist can be set up to allow access to sensitive interfaces only from specific IP addresses. Audit and alert on behaviors of frequent interface accesses. For example, if a certain IP address initiates a large number of requests within a short period, the system can automatically send an alert notification to the administrator for timely measures. When obfuscating request body parameters, more advanced encryption algorithms such as the RSA (Rivest-Shamir-Adleman) asymmetric encryption algorithm can be used to provide stronger security. The RSA algorithm uses a pair of public and private keys to ensure that only the recipient holding the private key can decrypt the data, thereby further enhancing data security.

[0058] Exemplarily, first, it is necessary to clarify the interface information to be obfuscated. There are URL parameters (ordinary parameters) and QUERY parameters (authorization critical parameters) in the request path:

[0059] 1) URL parameters: For example, / api / users / 123, where 123 is the user ID;

[0060] 2) QUERY parameters: Start with? at the end of the URL, followed by a series of key-value pair parameters used to pass query conditions, pagination information, etc. to the server, such as / api / users / 123?page=2&pageSize=10;

[0061] 3) Request header parameters: Set specific parameters in the header of the HTTP request to pass some request-related metadata or authorization information, etc., such as Bearer token_value;

[0062] 4) Request body parameters: When using methods such as POST or PUT to submit data to create or update resources, the parameters can be placed in the request body. The request body can be data in JSON, XML, or other formats, such as {"userId":"123"};

[0063] Based on the above parameters, for API obfuscation, referring to Table 1 below, the obfuscated content is:

[0064] 1. Update the request method, for example, change the GET request to a POST;

[0065] 2. Update the request path, for example, change / api / user / 123 to / api / qeuryBase;

[0066] 3. Package and convert the parameters in the request path, such as converting URL parameters into ID parameters in the body;

[0067] Table 1:

[0068]

[0069] This embodiment significantly enhances the security of interface information through a series of steps. First, the interface information to be obfuscated is obtained, wherein the interface information includes the request mode, request path, request header parameters and request body parameters. This step provides a comprehensive and detailed data basis for the subsequent obfuscation process. Then, according to the preset obfuscation rules, the interface information is obfuscated to obtain obfuscated interface information, wherein the obfuscation rules are used to update the parameters in the request path to the request header parameters and request body parameters, and the request mode and request path are obfuscated. This process effectively hides the real structure and data of the interface, making it difficult for potential attackers to spy on and use the interface information, greatly improving the defense capability of the system. Finally, the obfuscated interface information is exposed to the caller so that the caller calls the interface corresponding to the obfuscated interface information for data transmission, which not only ensures the normal use of the interface, but also avoids the direct exposure of sensitive information, and achieves a perfect balance between security and function. This series of measures together constitute a solid security line of defense, which provides a strong guarantee for the stable operation and data security of the system, reduces the risk of interface access, and improves the security of interface access.

[0070] In a feasible implementation manner, the steps in step S30 may include steps T10 to T20:

[0071] Step T10, receiving the interface call request from the caller, and converting the interface call request into the corresponding original interface call request according to the interface call request and the obfuscation rule;

[0072] Step T20, sending the original interface call request to the corresponding server for processing, and returning the processing result to the caller.

[0073] It should be noted that the interface call request initiated by the caller refers to the request sent by the client or server to the server, which contains the interface information that has been obfuscated, such as the request method, request path, request header parameters and request body parameters. The obfuscation rules are a series of pre-set conversion and encryption instructions used to convert the original interface information into obfuscated interface information. The original interface call request refers to the interface request that the caller originally needed to send before the obfuscation process, which contains the actual request method, request path, request header parameters and request body parameters. The server refers to the server that processes the interface request, which is responsible for processing the interface call request and returning the processing result.

[0074] First, the system receives an interface call request sent by the caller. This request contains obfuscated interface information. For example, the request method may be changed from GET to POST, the request path may be changed from / api / user / profile to / api / xyx / abc, the Authorization field (authorization key parameter) in the request header parameters may have been encrypted, and the JSON data in the request body parameters may also have been encoded or encrypted.

[0075] Next, the system converts the received obfuscated interface call request into the corresponding original interface call request according to the preset obfuscation rules. This conversion process involves decryption and reverse conversion operations. For example, if the request method is obfuscated to POST, the system will restore it to the original GET method; if the request path is obfuscated to / api / xyx / abc, the system will restore it to the original / api / user / profile path; if the Authorization field in the request header parameters is encrypted, the system will use the corresponding decryption algorithm for decryption; if the JSON data in the request body parameters is encoded, the system will perform a decoding operation.

[0076] Specifically, assuming that the obfuscation rules contain an instruction to change the request method from GET to POST, when the system receives a POST request, it will restore the request method to GET according to the reverse instruction in the obfuscation rules. Similarly, if the request path is obfuscated to / api / xyx / abc, the system will restore the path to / api / user / profile according to the mapping relationship in the obfuscation rules. For encrypted request header parameters, the system will use a preset decryption algorithm (such as the AES decryption algorithm) for decryption. For encoded request body parameters, the system will use the corresponding decoding algorithm (such as Base64 decoding) for decoding.

[0077] After the conversion is completed, the system sends the original interface call request to the corresponding server for processing. After receiving the original interface call request, the server processes it according to the normal business logic and generates a processing result. The processing result may be a JSON response, containing the status code, message, and data of the request processing. Finally, the system returns the processing result to the caller, and the caller performs subsequent operations based on the returned result.

[0078] Furthermore, to improve security, the obfuscation rules can be dynamically generated, and different obfuscation rules are used for each interface call. For example, a unique obfuscation rule can be generated by combining a timestamp, user identifier, and random number, and a new rule is used for obfuscation and conversion for each request. When obfuscating the request body parameters, multi-layer encryption algorithms can be used. For example, first use a symmetric encryption algorithm (such as AES) for encryption, and then use an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. Before the server processes the original interface call request, a request verification mechanism can be added to verify the legality and integrity of the request. For example, digital signature technology can be used to sign the interface call request, and the server verifies the validity of the signature before processing the request. To reduce the impact of the obfuscation and conversion process on performance, efficient encryption and decryption algorithms can be adopted, such as using a hardware-accelerated AES encryption algorithm. At the same time, commonly used obfuscation rules and decryption results can be cached to reduce repeated calculations.

[0079] After exposing the obfuscated interface information, this embodiment can accurately convert the caller's request into the original interface call request and send it to the server for processing, ensuring the availability and compatibility of the interface. At the same time, through the reverse conversion of the obfuscation rules, the security and accuracy of the interface call are guaranteed.

[0080] Based on Embodiment 1 of this application, in Embodiment 2 of this application, the same or similar content as the above Embodiment 1 can be referred to the above introduction and will not be repeated hereinafter. On this basis, referring to Figure 2 , the steps of Step S20 further include steps A10 to A40:

[0081] Step A10, update the request method to the corresponding preset request method;

[0082] Step A20, update the authorization key parameters in the request path to the request header parameters, and update the ordinary parameters in the request path to the request body parameters;

[0083] Step A30, update the request path to the corresponding preset request path;

[0084] Step A40, use the updated interface information as the obfuscated interface information, where the updated interface information includes the updated request method, request path, request header parameters, and request body parameters.

[0085] It should be noted that the request method refers to the type of HTTP request, such as GET, POST, etc. The authorization key parameters refer to the parameters used for authentication and authorization in the request path, and these parameters usually contain sensitive information. The ordinary parameters refer to the other parameters in the request path except the authorization key parameters. The preset request method refers to the new request method selected according to the obfuscation rules. The preset request path refers to the new request path selected according to the obfuscation rules. The obfuscated interface information refers to the interface information processed by the obfuscation rules, and its purpose is to make it difficult for the interface callers to easily identify the true structure and parameter meanings of the interface.

[0086] First, according to the obfuscation rules, update the request method to the corresponding preset request method. For example, if the original request method is GET, according to the obfuscation rules, it can be updated to POST. The purpose of this process is to change the appearance of the request and make it difficult for attackers to identify the true type of the request.

[0087] Next, update the authorization key parameters in the request path to the request header parameters, and update the ordinary parameters in the request path to the request body parameters. For example, assume the request path is / api / user / {userId}, where {userId} is the authorization key parameter, and other parameters such as?page=1&size=10 are ordinary parameters. According to the obfuscation rules, move {userId} to the request header, such as Authorization: UserId {userId}, and move page and size to the request body, such as { "page": 1, "size": 10}. The purpose of this process is to hide sensitive information and prevent them from being exposed in the URL (Uniform Resource Locator Path Parameters).

[0088] Then, according to the obfuscation rules, update the request path to the corresponding preset request path. For example, update the original path / api / user / {userId} to / api / xyx / abc. The purpose of this process is to further obfuscate the request path and make it difficult for attackers to identify the true target of the request.

[0089] Finally, the updated interface information is used as the obfuscated interface information. This means that the interface information processed through the above steps will be used for actual request calls. For example, the original request GET / api / user / 123?page=1&size=10 becomes POST / api / xyx / abc after obfuscation, the request header contains Authorization: UserId 123, and the request body contains { "page": 1, "size": 10}. In this way, the obfuscated interface information is more secure during transmission and is difficult for attackers to parse and utilize.

[0090] Furthermore, to improve security, the obfuscation rules can be generated dynamically, and different obfuscation rules are used for each interface call. For example, a unique obfuscation rule can be generated by combining a timestamp, a user identifier, and a random number, and a new rule is used for obfuscation and conversion for each request. When obfuscating the request body parameters, multi-layer encryption algorithms can be used. For example, first use a symmetric encryption algorithm (such as AES) for encryption, and then use an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. Before the server processes the original interface call request, a request verification mechanism can be added to verify the legality and integrity of the request. For example, digital signature technology can be used to sign the interface call request, and the server verifies the validity of the signature before processing the request.

[0091] Performance optimization: To reduce the impact of the obfuscation and conversion process on performance, efficient encryption and decryption algorithms can be adopted, such as using a hardware-accelerated AES encryption algorithm. At the same time, commonly used obfuscation rules and decryption results can be cached to reduce repeated calculations.

[0092] By obfuscating the interface information according to the preset obfuscation rules, this embodiment effectively improves the security of the interface, prevents the leakage of sensitive information. For example, the request method, path parameters, etc. are updated to preset values, making it difficult for attackers to directly identify the true functions and parameters of the interface, and enhancing the defense ability of the system.

[0093] In a feasible implementation, referring to Figure 3 , the steps of step A20 further include steps A201~A202:

[0094] Step A201, input the interface information into a preset classification model, and obtain the category output by the classification model. Among them, the categories include high-risk high-performance, high-risk low-performance, low-risk high-performance, and low-risk low-performance;

[0095] Step A202, according to the category, update the authorization key parameters to the request header parameters, and update the ordinary parameters to the request body parameters.

[0096] It should be noted that the preset classification model is a trained machine learning model used to classify interface information to determine its risk and performance levels. The authorization key parameters refer to the parameters used for authentication and authorization in the request path, and these parameters usually contain sensitive information. The ordinary parameters refer to the other parameters in the request path except the authorization key parameters. The category refers to the risk and performance levels output by the classification model, including high risk and high performance, high risk and low performance, low risk and high performance, and low risk and low performance.

[0097] First, input the interface information into the preset classification model. This process involves inputting the detailed description of the interface, including the request method, request path, request header parameters, and request body parameters, into a trained machine learning model. The purpose of this model is to classify the risk and performance of the interface based on this information.

[0098] Next, process the authorization key parameters and ordinary parameters according to the category output by the classification model. Specifically, if the category output by the classification model is high risk and high performance, then convert the authorization key parameters and ordinary parameters into strings respectively, obtain the ASCII (American Standard Code for Information Interchange) code value of each character, and use a preset function to perform operations on each ASCII code value. Combine all the calculated ASCII code values to obtain the encrypted string. Then, update the encrypted authorization key parameters to the request header parameters and update the encrypted ordinary parameters to the request body parameters.

[0099] If the category output by the classification model is high risk and low performance, then convert the authorization key parameters and ordinary parameters into strings respectively, divide the strings into chunks, and perform encryption processing on each chunk. Combine all the encrypted chunks to obtain the encrypted string. Then, update the encrypted authorization key parameters to the request header parameters and update the encrypted ordinary parameters to the request body parameters.

[0100] If the category output by the classification model is low risk and high performance or low risk and low performance, then convert the ordinary parameters into strings, update the authorization key parameters to the request header parameters, and update the converted ordinary parameters to the request body parameters.

[0101] Furthermore, to improve the accuracy and adaptability of classification, the classification model can be retrained regularly to incorporate the latest interface usage data and security events. For example, the model can be retrained monthly or quarterly using new datasets to ensure that it can accurately identify new security threats and performance changes. When dealing with high-risk interfaces, a multi-level encryption strategy can be adopted. For example, symmetric encryption algorithms (such as AES) can be used for encryption first, and then asymmetric encryption algorithms (such as RSA) can be used for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategies are adjusted in a timely manner. For example, if the performance of a certain interface suddenly drops, the encryption strategy can be temporarily adjusted to reduce the encryption complexity to restore performance. Combining user behavior analysis further enhances the security of the interface. For example, if a certain user frequently calls high-risk interfaces, their behavior can be analyzed to determine whether there are abnormal behaviors and corresponding security measures can be taken.

[0102] By introducing the classification model before obfuscation processing, this embodiment can adopt different processing strategies for interface information with different risk levels, improving the processing efficiency and security. Through precise classification, customized protection for different interface information is achieved, reducing the security risk.

[0103] In a feasible implementation manner, before step A10, there are also steps A001~A003:

[0104] Step A001, collect historical interface data, where the historical interface data includes historical interface information, as well as the historical performance data and historical security data of the interface corresponding to the historical interface information;

[0105] Step A002, based on the historical performance data and historical security data, label the interfaces in the historical interface data as different categories to obtain labeled data;

[0106] Step A003, according to the labeled data, use the preset random forest algorithm to train the preset initial model to obtain a classification model.

[0107] It should be noted that historical interface data refers to the information related to interface calls recorded by the system in the past, including historical interface information, historical performance data, and historical security data. Historical interface information covers details such as the request method, request path, request header parameters, and request body parameters of the interface. Historical performance data records the performance metrics of interface calls, such as response time, throughput, and error rate. Historical security data records events related to interface security, such as attack type, attack source IP, and attack time. The labeled data is obtained by classifying and labeling the historical interface data and is used for model training. The random forest algorithm is an ensemble learning algorithm that improves the accuracy and robustness of the model by constructing multiple decision trees and integrating their prediction results. The preset initial model refers to the model structure and parameters set before the start of training. The classification model is a trained model that can classify interface data.

[0108] First, the system collects historical interface data, which includes historical interface information, historical performance data, and historical security data. For example, the historical interface information may include that the request method is POST, the request path is / api / user / profile, and the request header parameter is Authorization: Bearer <token>, the request body parameter is { "userId": "123"}. Historical performance data may record that the average response time of this interface is 200 milliseconds, the throughput is 100 requests per second, and the error rate is 0.1%. Historical security data may record that this interface has suffered 10 SQL (Structured Query Language) injection attacks in the past month, and the source IP of the attacks mainly comes from a specific region.

[0109] Next, based on the historical performance data and historical security data, the interfaces in the historical interface data are labeled into different categories to obtain labeled data. For example, according to the frequency of performance data and security events, the interfaces are labeled as high-risk high-performance, high-risk low-performance, low-risk high-performance, or low-risk low-performance. The purpose of this process is to provide clear classification targets for model training.

[0110] Then, according to the labeled data, the random forest algorithm is used to train the preset initial model to obtain a classification model. The random forest algorithm improves the accuracy and robustness of the model by constructing multiple decision trees and integrating their prediction results. During the training process, the algorithm learns from the labeled data how to classify according to the characteristics of the interface (such as request method, request path, performance metrics, security events, etc.). For example, the algorithm may find that interfaces with short response times and no attacks usually belong to the low-risk high-performance category, while interfaces with long response times and frequent attacks usually belong to the high-risk low-performance category.

[0111] Furthermore, to improve the timeliness and accuracy of the model, the collection of historical interface data can be carried out dynamically. For example, the system can collect the latest interface call data in real time and update the historical data set regularly to ensure that the data used for model training is the latest. To cope with the constantly changing security threats and performance changes, the classification model can be retrained regularly. For example, the model can be retrained monthly or quarterly using the latest historical interface data to ensure that the model can accurately identify new security threats and performance issues. In addition to the random forest algorithm, other machine learning algorithms, such as support vector machines or neural networks, can be combined to build a multi-model integration system. For example, by voting mechanism or stacking method, the prediction results of multiple models are combined to further improve the accuracy and robustness of classification. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the model parameters and classification strategies are adjusted in a timely manner. For example, if it is found that the classification result of an interface does not match the actual performance, the model parameters can be adjusted in a timely manner and the model can be retrained.

[0112] By collecting historical interface data and training a classification model, this embodiment can accurately identify the risk level of the interface, provide strong support for subsequent security processing, and improve the pertinence and effectiveness of security processing.

[0113] Based on Embodiment 1 or Embodiment 2 of this application, in Embodiment 3 of this application, the content that is the same as or similar to the above Embodiment 1 or Embodiment 2 can be referred to the above introduction and will not be repeated hereinafter. The steps of Step A202 further include Steps B10 to B40:

[0114] Step B10, if the category is high risk and high performance, obtain the first ASCII code value of each character in the string converted from the ordinary parameter, and obtain the second ASCII code value of each character in the string converted from the authorized key parameter;

[0115] Step B20, use a preset encryption function to encrypt each first ASCII code value once, and combine all the encrypted first ASCII code values to obtain a first encrypted string;

[0116] Step B30, use a preset encryption function to encrypt each second ASCII code value multiple times, and combine all the encrypted second ASCII code values to obtain a second encrypted string;

[0117] Step B40, update the first encrypted string to the request body parameter, and update the second encrypted string to the request header parameter.

[0118] It should be noted that the first ASCII code value refers to the ASCII code value of each character in the string converted from the ordinary parameter. The second ASCII code value refers to the ASCII code value of each character in the string converted from the authorized key parameter. The preset encryption function refers to a specific function used to encrypt the ASCII code value. The first encrypted string refers to the string obtained by encrypting the first ASCII code value through the preset encryption function. The second encrypted string refers to the string obtained by encrypting the second ASCII code value multiple times through the preset encryption function. The request header parameter refers to the parameter in the HTTP request header, which is used to transmit metadata such as authentication information. The request body parameter refers to the parameter in the HTTP request body, which is used to transmit the specific data of the request.

[0119] When the category output by the classification model is high-risk and high-performance, the system converts the ordinary parameters into a string and obtains the first ASCII code value of each character in the string. For example, the ordinary parameter page=1&size=10 is converted into the string "1,10", and its ASCII code values are 49, 44, 49, 48 respectively. The authorization key parameter is converted into a string, and the second ASCII code value of each character in the string is obtained. For example, the authorization key parameter userId=123 is converted into the string "123", and its ASCII code values are 49, 50, 51 respectively. Use a preset encryption function to encrypt each first ASCII code value once. For example, if the preset encryption function is f(x) = x + 10, the encrypted first ASCII code values are 59, 54, 59, 58 respectively. Use a preset encryption function to encrypt each second ASCII code value multiple times. For example, if the preset encryption function is f(x) = x +10, the second ASCII code values after two encryptions are 69, 70, 71 respectively (after the first encryption they are 59, 60, 61, and after the second encryption they are 69, 70, 71). Combine all the encrypted first ASCII code values into a first encrypted string. For example, the encrypted first ASCII code values 59, 54, 59, 58 are combined into the string "59,54,59,58". Combine all the encrypted second ASCII code values into a second encrypted string. For example, the encrypted second ASCII code values 69, 70, 71 are combined into the string "69,70,71". Update the first encrypted string to the request body parameters. For example, update "59,54,59,58" to the request body parameters { "page": "59", "size": "54"}. Update the second encrypted string to the request header parameters. For example, update "69,70,71" to the request header parameter Authorization: EncryptedUserId 69,70,71.

[0120] Furthermore, to improve security and flexibility, the preset encryption function can be dynamically generated. For example, a unique preset encryption function can be generated based on the request timestamp, user identification, and random number, and a new function is used for encryption each time a request is made. When dealing with high-risk interfaces, a multi-level encryption strategy can be adopted. For example, first use a symmetric encryption algorithm (such as AES) for encryption, and then use an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategy are adjusted in a timely manner. For example, if it is found that the performance of a certain interface suddenly drops, the encryption strategy can be temporarily adjusted to reduce the encryption complexity to restore performance. Combining user behavior analysis further enhances the security of the interface. For example, if a certain user frequently calls high-risk interfaces, their behavior can be analyzed to determine whether there are abnormal behaviors and corresponding security measures can be taken.

[0121] For the interface information with high risk and high performance, string conversion and ASCII code operation encryption are adopted. This embodiment significantly enhances the confidentiality of the interface information. Even if the information is intercepted, it is difficult for attackers to crack, effectively ensuring the security of the interface.

[0122] In a feasible implementation manner, the steps of step A202 further include steps C10~C30:

[0123] Step C10, if the category is high risk and low performance, the string of the authorization key parameter is block-processed to obtain a first block, and the string of the ordinary parameter is block-processed to obtain a second block;

[0124] Step C20, encrypt each first block, and aggregate the encrypted first blocks to obtain a third encrypted string, and update the third encrypted string to the request header parameter;

[0125] Step C30, encrypt each second block, and aggregate the encrypted second blocks to obtain a fourth encrypted string, and update the fourth encrypted string to the request body parameter.

[0126] It should be noted that block processing refers to splitting a string into multiple small blocks, each small block containing a certain number of characters. Encryption processing refers to using an encryption algorithm to encrypt data to protect the confidentiality of the data. Aggregation processing refers to combining multiple encrypted blocks into a new string. The third encrypted string refers to the encrypted string obtained through encryption processing and aggregation processing, which is used to update the request header parameter. The fourth encrypted string refers to the encrypted string obtained through encryption processing and aggregation processing, which is used to update the request body parameter.

[0127] When the category output by the classification model is high risk and low performance, the system will perform chunking on the string of the authorization key parameters to obtain the first chunk. For example, the authorization key parameter userId=123456 is converted into the string "123456", and after chunking, it gets ["123", "456"].

[0128] Perform chunking on the string of the ordinary parameters to obtain the second chunk. For example, the ordinary parameters page=1&size=10 are converted into the string "1,10", and after chunking, it gets ["1", "10"]. Encrypt each first chunk. A symmetric encryption algorithm (such as AES) or an asymmetric encryption algorithm (such as RSA) can be used. For example, use the AES algorithm to encrypt "123" and "456" to obtain the encrypted chunks ["encrypted123", "encrypted456"]. Encrypt each second chunk. Also use the encryption algorithm to encrypt "1" and "10" to obtain the encrypted chunks ["encrypted1", "encrypted10"]. Aggregate each encrypted first chunk to obtain the third encrypted string. For example, combine ["encrypted123", "encrypted456"] into the string "encrypted123,encrypted456". Aggregate each encrypted second chunk to obtain the fourth encrypted string. For example, combine ["encrypted1","encrypted10"] into the string "encrypted1,encrypted10". Update the third encrypted string to the request header parameter. For example, update "encrypted123,encrypted456" to the request header parameter Authorization:EncryptedUserId encrypted123,encrypted456. Update the fourth encrypted string to the request body parameter. For example, update "encrypted1,encrypted10" to the request body parameter { "page": "encrypted1", "size": "encrypted10"}.

[0129] Furthermore, to improve security and flexibility, the block size can be dynamically adjusted. For example, according to the complexity of the request and performance requirements, the block size is dynamically selected, and different block sizes are used for encryption each time a request is made. When processing high-risk interfaces, a multi-level encryption strategy can be adopted. For example, first use a symmetric encryption algorithm (such as AES) for encryption, and then use an asymmetric encryption algorithm (such as RSA) for secondary encryption to provide stronger security. During the interface call process, the output of the classification model and the performance of the interface are monitored in real time, and the obfuscation rules and encryption strategies are adjusted in a timely manner. For example, if it is found that the performance of a certain interface suddenly drops, the encryption strategy can be temporarily adjusted to reduce the encryption complexity to restore performance. Combining user behavior analysis further enhances the security of the interface. For example, if a certain user frequently calls high-risk interfaces, their behavior can be analyzed to determine whether there are abnormal behaviors and corresponding security measures can be taken.

[0130] For high-risk and low-performance interface information, block encryption processing is adopted. In this embodiment, while ensuring security, by optimizing the encryption method, the impact on system performance is reduced, achieving a balance between security and performance.

[0131] In a feasible implementation manner, the steps of step A202 further include steps D10~D20:

[0132] Step D10, if the category is low-risk and high-performance or low-risk and low-performance, update the authorization key parameters to the request header parameters;

[0133] Step D20, update the ordinary parameters converted into a string to the request body parameters.

[0134] It should be noted that the third string refers to the string form after converting the ordinary parameters. The request header parameters refer to the parameters in the HTTP request header, which are used to transmit metadata such as authentication information. The request body parameters refer to the parameters in the HTTP request body, which are used to transmit the specific data of the request.

[0135] When the category output by the classification model is low-risk high-performance or low-risk low-performance, the system will execute the following steps to process ordinary parameters: Convert ordinary parameters into string form. For example, the ordinary parameters page=1&size=10 are converted into the string "1,10". The purpose of this process is to convert ordinary parameters from key-value pair form into a simple string form for subsequent processing. Update the authorization key parameters to the request header parameters. For example, update userId=123 to the request header parameter Authorization: UserId 123. The purpose of this process is to move the authorization key parameters from the request path to the request header to enhance security and prevent sensitive information from being exposed in the URL. Update the third string to the request body parameters. For example, update "1,10" to the request body parameter { "page": "1", "size": "10"}. The purpose of this process is to move the ordinary parameters from the request path to the request body to further hide the details of the parameters and prevent information leakage.

[0136] Furthermore, to improve security and flexibility, the conversion of ordinary parameters can be performed dynamically. For example, according to the context information of the request (such as user role, request time, etc.), the conversion rules are dynamically selected, and different conversion rules are used for processing each time a request is made. When processing low-risk interfaces, multi-layer security policies can be adopted, such as combining IP whitelisting, request frequency limiting, etc. measures to further enhance the security of the interface. For example, only allow specific IP addresses to access sensitive interfaces and limit the number of requests per IP address within a unit time. During the interface call process, monitor the output of the classification model and the performance of the interface in real time, and adjust the obfuscation rules and parameter processing strategies in a timely manner. For example, if it is found that the performance of a certain interface suddenly drops, the parameter processing strategy can be temporarily adjusted to reduce the processing complexity to restore performance. Combine user behavior analysis to further enhance the security of the interface. For example, if a certain user frequently calls low-risk interfaces but the behavior pattern is abnormal (such as irregular request time intervals, abnormal request parameters, etc.), their behavior can be analyzed to determine whether there is a potential security threat and take corresponding security measures.

[0137] For the interface information of low-risk high-performance or low-risk low-performance, the processing flow is simplified. Under the premise of ensuring basic security, this embodiment improves the processing efficiency, reduces unnecessary resource consumption, and enhances the overall performance of the system.

[0138] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the method for enhancing the security of the original interface based on obfuscated interfaces. Any simple transformation in more forms based on this technical concept is within the protection scope of this application.

[0139] The present application also provides a device for enhancing the security of an original interface based on an obfuscated interface. Please refer to Figure 4 , the device for enhancing the security of an original interface based on an obfuscated interface includes:

[0140] An interface acquisition module 10, which acquires interface information to be obfuscated. Among them, the interface information includes a request method, a request path, request header parameters, and request body parameters;

[0141] An obfuscated interface module 20, which performs obfuscation processing on the interface information according to a preset obfuscation rule to obtain obfuscated interface information. Among them, the obfuscation rule is used to update the parameters in the request path to the request header parameters and the request body parameters, and perform obfuscation processing on the request method and the request path;

[0142] An exposed interface module 30, which exposes the obfuscated interface information to a calling party so that the calling party can call the interface corresponding to the obfuscated interface information for data transmission.

[0143] The device for enhancing the security of an original interface based on an obfuscated interface provided by the present application adopts the method for enhancing the security of an original interface based on an obfuscated interface in the above embodiment, and can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the device for enhancing the security of an original interface based on an obfuscated interface provided by the present application are the same as those of the method for enhancing the security of an original interface based on an obfuscated interface provided by the above embodiment, and other technical features in the device for enhancing the security of an original interface based on an obfuscated interface are the same as the features disclosed in the method of the above embodiment, and will not be elaborated here.

[0144] The present application provides a device for enhancing the security of an original interface based on an obfuscated interface. The device for enhancing the security of an original interface based on an obfuscated interface includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for enhancing the security of an original interface based on an obfuscated interface in the first embodiment above.

[0145] Next, refer to Figure 5 , which shows a schematic structural diagram of a device for enhancing the security of an original interface based on an obfuscated interface suitable for implementing the embodiments of the present application. The device for enhancing the security of an original interface based on an obfuscated interface in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The shown device for enhancing the security of an original interface based on an obfuscated interface is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present application.

[0146] As Figure 5 shown, the device for enhancing the security of an original interface based on an obfuscated interface may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the device for enhancing the security of an original interface based on an obfuscated interface are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the device for enhancing the security of an original interface based on an obfuscated interface to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a device for enhancing the security of an original interface based on an obfuscated interface having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.

[0147] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0148] The device for enhancing the security of an original interface based on an obfuscated interface provided by the present application adopts the method for enhancing the security of an original interface based on an obfuscated interface in the above embodiments, which can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the device for enhancing the security of an original interface based on an obfuscated interface provided by the present application are the same as those of the method for enhancing the security of an original interface based on an obfuscated interface provided by the above embodiments, and other technical features in the device for enhancing the security of an original interface based on an obfuscated interface are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.

[0149] It should be understood that each part disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0150] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0151] The present application provides a medium, which is a computer-readable storage medium and has computer-readable program instructions (i.e., computer programs) stored thereon. The computer-readable program instructions are used to execute the method for enhancing the security of an original interface based on an obfuscated interface in the above embodiments.

[0152] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM: Random Access Memory), read-only memory (ROM: Read Only Memory), erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (RadioFrequency), etc., or any suitable combination of the above.

[0153] The above computer-readable storage medium can be included in a device that enhances the security of the original interface based on a confusion interface; it can also exist separately without being assembled into a device that enhances the security of the original interface based on a confusion interface.

[0154] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by a device that enhances the security of the original interface based on a confusion interface, the device that enhances the security of the original interface based on a confusion interface is caused to:

[0155] Obtain interface information to be confused, where the interface information includes a request method, a request path, request header parameters, and request body parameters;

[0156] According to a preset confusion rule, perform confusion processing on the interface information to obtain confused interface information, where the confusion rule is used to update the parameters in the request path to the request header parameters and the request body parameters, and perform confusion processing on the request method and the request path;

[0157] Expose the confused interface information to the caller so that the caller can call the interface corresponding to the confused interface information for data transmission.

[0158] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0159] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0160] The modules involved in the embodiments described in this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0161] The readable storage medium provided in this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned method for enhancing the security of the original interface based on the obfuscated interface, which can reduce the risk of interface access and improve the security of interface access. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the method for enhancing the security of the original interface based on the obfuscated interface provided in the above embodiments, and will not be elaborated here.

[0162] The present application also provides a product, which is a computer program product including a computer program. When the computer program is executed by a processor, it implements the steps of the method for enhancing the security of the original interface based on the obfuscated interface as described above.

[0163] The computer program product provided by the present application can reduce the interface access risk and improve the interface access security. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the method for enhancing the security of the original interface based on the obfuscated interface provided in the above embodiments, and will not be elaborated herein.

[0164] The above are only partial embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structural transformation made by using the content of the specification and drawings of the present application under the technical concept of the present application, or any direct / indirect application in other related technical fields shall be included in the patent protection scope of the present application.< / token>

Claims

1. A method for enhancing the security of the original interface based on an obfuscated interface, characterized in that The method for enhancing the security of the original interface based on the obfuscation interface includes: Obtain the interface information to be obfuscated, where the interface information includes the request method, request path, request header parameters, and request body parameters; According to the preset obfuscation rules, perform obfuscation processing on the interface information to obtain obfuscated interface information, where the obfuscation rules are used to obfuscate the request method and the request path, and update the parameters in the request path to the request header parameters and the request body parameters; Expose the obfuscated interface information to the calling party so that the calling party can call the interface corresponding to the obfuscated interface information for data transmission. After the step of exposing the obfuscated interface information to the calling party, the following steps are included: Adjust the obfuscation rules according to the category output by the classification model and the performance of the interface, where The obfuscation processing includes update processing. The step of performing obfuscation processing on the interface information according to the preset obfuscation rules to obtain obfuscated interface information includes: Update the request method to the corresponding preset request method; Input the interface information into a preset classification model to obtain the category output by the classification model, where the category includes high-risk high-performance, high-risk low-performance, low-risk high-performance, and low-risk low-performance; According to the category, update the query parameters in the request path to the request header parameters, and update the ordinary parameters in the request path to the request body parameters, where the ordinary parameters include the parameters in the request path other than the query parameters; Update the request path to the corresponding preset request path; Use the updated interface information as the obfuscated interface information, where the updated interface information includes the updated request method, request path, request header parameters, and request body parameters. Before the step of inputting the interface information into the preset classification model, the following steps are also included: Collect historical interface data, where the historical interface data includes historical interface information, as well as the historical performance data and historical security data of the interface corresponding to the historical interface information; According to the historical performance data and historical security data, label the interfaces in the historical interface data as different categories to obtain labeled data; According to the labeled data, use the preset random forest algorithm to train the preset initial model to obtain the classification model.

2. The method for enhancing the security of the original interface based on the obfuscated interface according to claim 1, wherein The step of updating the query parameters in the request path to the request header parameters and updating the ordinary parameters in the request path to the request body parameters according to the category includes: If the category is high-risk high-performance, obtain the first ASCII code value of each character in the string converted from the ordinary parameters, and obtain the second ASCII code value of each character in the string converted from the query parameters; Use the preset encryption function to encrypt each of the first ASCII code values once, and combine all the encrypted first ASCII code values to obtain the first encrypted string; Encrypt each of the second ASCII code values multiple times using a preset encryption function, and combine all the encrypted second ASCII code values to obtain a second encrypted string; Update the first encrypted string to the request body parameter, and update the second encrypted string to the request header parameter.

3. The method for enhancing the security of the original interface based on the obfuscated interface according to claim 1, characterized in that, The step of updating the query parameter in the request path to the request header parameter and updating the ordinary parameter in the request path to the request body parameter according to the category includes: If the category is high risk and low performance, perform block processing on the string of the query parameter to obtain a first block, and perform block processing on the string of the ordinary parameter to obtain a second block; Perform encryption processing on each of the first blocks, and perform aggregation processing on each of the encrypted first blocks to obtain a third encrypted string, and update the third encrypted string to the request header parameter; Perform encryption processing on each of the second blocks, and perform aggregation processing on each of the encrypted second blocks to obtain a fourth encrypted string, and update the fourth encrypted string to the request body parameter.

4. The method for enhancing the security of the original interface based on the obfuscated interface according to claim 1, wherein The step of updating the query parameter in the request path to the request header parameter and updating the ordinary parameter in the request path to the request body parameter according to the category further includes: If the category is low risk and high performance or low risk and low performance, update the query parameter to the request header parameter; Update the ordinary parameter converted to a string to the request body parameter.

5. The method for enhancing the security of the original interface based on the obfuscated interface according to claim 1, wherein After the step of exposing the obfuscated interface information to the caller, it includes: Receive the interface call request from the caller, and convert the interface call request into a corresponding original interface call request according to the interface call request and the obfuscation rule; Send the original interface call request to the corresponding server for processing, and return the processing result to the caller.

6. A device for enhancing the security of an original interface based on a confusion interface, characterized in that, The device for enhancing the security of the original interface based on the obfuscated interface includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the method for enhancing the security of the original interface based on the obfuscated interface according to any one of claims 1 to 5.

7. A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the method for enhancing the security of the original interface based on the obfuscated interface according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • API gateway security protection method and system based on interface mapping

    CN114553410A