Security protection system and method based on network API calling image
By protecting the network API interface of the image system, embedding invisible digital watermarks and implementing multi-layer security protection measures, the security problem of the image system when sharing under the open network API interface is solved, and traceability and security protection of image flow are achieved.
Patent Information
- Application Number
- CN202311575343.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-23
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art is difficult to effectively protect the security of image systems when shared under open network API interfaces, especially the source of leaked information cannot be traced back to, and traditional security protection methods cannot cope with the security challenges brought by mobile and post-NAT access.
By parsing and processing HTTP/HTTPS messages between the caller and the image system, combining the frequency domain and compression domain algorithms, invisible digital watermarks are embedded, and DOS/DDOS defense of API requests, strict API request checking, and hiding, desensitizing and watermark processing of response data.
It realizes invisible digital watermark embedding of images shared through network API calls, which plays the role of traceability of image flow without affecting the extraction and analysis of image features by the intelligent algorithm, enhancing the security protection capabilities of the image system.
Smart Images

Figure CN120030580A_ABST
Abstract
Description
Technical Field
[0001] The present invention provides a security protection system and method for calling images based on a network API. When an image system provides an open network API interface for other users to call for image sharing and transmission, the API interface security can be protected, and hidden digital watermark information can be embedded in the shared and sent images. The information is invisible to the naked eye and can be extracted through software, thereby realizing the tracing of the shared flow of the called image.
[0002] Abbreviations and glossary:
[0003] IP address: full name Internet Protocol Address.
[0004] HTTP: The full name is Hyper Text Transfer Protocol, which is a simple request-response protocol.
[0005] HTTPS: The full name is Hyper Text Transfer Protocol Secure, a secure hypertext transfer protocol that ensures the security of the transmission process through transmission encryption and identity authentication based on HTTP.
[0006] API: The full name is Application Programming Interface, which is a collection of definitions, programs and protocols that enable mutual communication between computer software through the API interface.
[0007] JPEG: The full name is Joint Photographic Experts Group, which is a standard for continuous-tone static image compression. The file suffix is .jpg or .jpeg, and it is the most commonly used image file format.
[0008] PNG: The full name is Portable Network Graphics, which is a bitmap format that uses a lossless compression algorithm.
[0009] BMP: It is the abbreviation of Bitmap in English and is the standard image file format in the Windows operating system.
[0010] RGB: It is a color standard in the industry. A variety of colors are obtained by changing the three color channels of red (R), green (G), and blue (B) and superimposing them on each other.
[0011] YUV: It is a color encoding method, where Y represents brightness and U and V store the chrominance part.
[0012] URL: The full name is Uniform Resource Locator, which is a method of indicating the location of information on the World Wide Web service program of the Internet. Background Art
[0013] With the implementation of the national big data strategy, the sharing, opening and development of data resources are accelerated, and the transformation and upgrading of industries and innovation in social governance are promoted. Public video surveillance resources are also facing the challenge of how to maximize the application efficiency. The image system converts the continuous video stream into an image information stream, and then shares the image with other systems, using intelligent algorithms to analyze and extract the image features. On this basis, intelligent applications can be carried out, such as trajectory query of people and vehicles, target tracking, relationship analysis, etc. With the popularization of intelligent applications, the demand for image sharing is increasing, but after the image is shared, the caller's use behavior cannot be controlled. For example, the caller can download and export the image and send it to other people or the Internet. The images of faces, vehicles, etc. may involve the privacy of citizens, and the source of the leaked information cannot be traced.
[0014] Existing network security protection measures, such as firewalls, can only prevent hackers from illegally accessing the image system at the IP level, and encrypt image transmission to prevent images from being stolen during transmission. However, there are more and more mobile terminals or NAT access. Due to the characteristics of IP conversion, mobile terminals have multiple visitors sharing the same IP address. Security attacks on data and images mostly come from the leakage and unauthorized data acquisition of normal callers, or cracking or hijacking normal callers. Therefore, traditional security protection measures are powerless against such attacks. For example, API security protection products basically only perform security protection and inspection on access requests, and rarely check and process the content carried in the shared response messages. Generally, they only check the format. For example, whether it carries unnecessary sensitive data or whether the image data will be leaked maliciously, no protection measures are taken. Existing image invisible watermarking technology is usually deployed in the client APP mode, using a dot matrix watermark mode, mapping the information into a symbol dot matrix through a code table and embedding it into the image. When it needs to be extracted, it is translated again according to the code table composed of the dot matrix. It is not a completely invisible watermark, and the convenience of deployment in the client APP mode is greatly reduced. Summary of the invention
[0015] The present invention provides a security protection system and method based on network API calling images. When applied to image system sharing images, the system can implement HTTP / HTTPS message protocol parsing, image processing technology, frequency domain and compression domain algorithm processing between the caller and the image system to achieve invisible digital watermark superimposition on the image shared by network API calling, thereby tracing the flow of images without affecting the extraction and analysis of image features by intelligent algorithms.
[0016] The security protection system and method based on network API calling images described in the present invention can provide security protection for the image system from the following aspects:
[0017] 1. DOS / DDOS defense for API requests
[0018] By analyzing the caller authentication method and process, the successfully registered caller is bound to the user identity and IP address as a trusted caller. The trusted callers and untrusted callers are handled separately, and the image server is effectively protected from DOS / DDOS attacks by the API interface. The access time of a single caller is controlled according to the user configuration for trusted callers, and different levels of access rate control are performed according to the configured interface priority. For untrusted callers, a strict security protection mechanism is adopted. First, the access time and access interface type (identity authentication interface and query interface, image and data access classes are not allowed to be accessed by untrusted users) are strictly managed according to the configuration. Then, the message information is analyzed to establish a data table entry of a temporary IP+caller identity. For IP+callers, the API interface access rate of a single untrusted caller is controlled. Finally, for all There are untrusted callers who are aggregated for total rate control. The total rate control here is divided into two levels. First, a certain number of hashes are established, and a certain number of accesses are preset for each hash. Hash is hashed into different hash buckets according to the IP+caller identity information, and the rate of each hash bucket is controlled. Then, a total rate control is performed on the messages released by all hash buckets. This protection concept and method can effectively identify and filter out DOS attacks from single illegal callers. At the same time, the hash rate control mechanism ensures that each single trusted caller has an equal access rate opportunity. Therefore, the malicious attacks of high-speed DOS / DDOS attackers will not occupy all server resources, resulting in the inability of normal single trusted callers to access and fail to pass the authentication to become trusted callers. The overall architecture and process can be seen in Figure 2 .
[0019] 2. Strict inspection of API requests
[0020] Through online automatic learning of the API open to the image system in learning mode, the learned API is classified and displayed. At the same time, users are supported to configure protection strategies based on three levels: API interface range, format (optional and required fields), and attributes and content carried by the message body. The protection strategy strictly verifies the interface range, access format, attributes and content in the request message sent by the caller, and blocks and discards messages that do not meet the rules, preventing hackers from transmitting illegal content or launching attacks through open API interfaces.
[0021] 3. Data hiding of API response
[0022] For the content information carried in the outbound response message shared by the image system server, three levels of protection processing are performed through online learning and configuration rules: hiding, desensitization and watermarking. First, the hiding processing (1) is based on the self-learned regular content and format of each API interface response message based on the caller level, and combined with user configuration, the shared data is strictly checked, and unauthorized and unconventional shared data segments are removed to ensure that the data content outside the control is transmitted and sent out. (2) The HTTP header field information is strictly checked, and the content containing the image system server information and internal IP network information is completely replaced with legal general information to avoid leakage of images. Internal information and vulnerability information of the IP network where the system server and the image system are located are exploited by criminals; secondly, desensitization automatically identifies sensitive fields based on field attributes and user configuration, and uses irreversible transformations such as character replacement and reversible transformations based on caller information transformation to ensure that callers can use the data but cannot see the complete content or the patched content; thirdly, watermark processing can automatically identify non-operation fields based on user configuration, and automatically identify field attributes to perform watermark superposition operations, such as adding digits after the decimal point to numbers and adding invisible characters to text, to prevent the leakage of sensitive data and tracing after the leakage.
[0023] 4. Hide watermarks on images of API responses
[0024] For the image data contained in the image system response message, a hidden digital watermark is inserted into the shared image through message parsing - image format processing - image decoding - frequency domain / compression domain / time domain watermark embedding technology - image encoding - message reassembly processing. At the same time, the inserted watermark information does not affect the caller's calculation and analysis through the AI algorithm. While ensuring that the image availability is not reduced, the leaked image can be traced.
[0025] Figure 1The security protection system based on network API calling image described in the present invention includes a function configuration module, a network processing module, a protocol parsing module, a content verification module, a security protection module, an information hiding module, an image watermark processing module, a database module and a log alarm module.
[0026] 1. Function configuration module:
[0027] Provide users with a flexible security policy configuration interface, which can be a graphical interface or a command line. Users can configure the IP address and transport layer port of the image system server, the IP addresses of users and devices allowed to make call requests, the processing method of hidden digital watermarks, the content contained in the watermark, such as time, user information, custom text content, the format / content rules of the API interface, and the various rates of trusted / untrusted channels in the security protection mechanism, etc. according to the actual networking situation.
[0028] 2. Network processing module:
[0029] (1) Monitor network messages passing through the system in real time, and obtain HTTP / HTTPS protocol messages that meet access rules and whose destination IP address is the IP address of the called image system;
[0030] (2) The proxy image system establishes an HTTP / HTTPS connection with the caller to receive and send messages from the caller.
[0031] (3) The proxy caller and the called image system establish an HTTP / HTTPS connection to receive and send messages sent from the image system.
[0032] (4) Send the message to the following protocol analysis module for processing.
[0033] 3. Protocol analysis module:
[0034] Responsible for receiving messages transferred from the network processing module, reorganizing and parsing the header information and message content in HTTP / HTTPS / WebSocket protocol and XML / JSON / SOAP format, and determining if it is a request message and sending it to the attack protection module for processing; if it is a response message, sending it to the information hiding module for processing.
[0035] 4. Security protection module:
[0036] Receive messages from the protocol parsing module, and according to the dual-channel anti-DOS / DDOS security protection mechanism of trusted / untrusted callers, adopt API interface range filtering, single caller flow control, image data system balance qualification flow control and total rate flow control for untrusted callers; adopt single caller flow control for trusted callers; after completion, send the message to the content verification module for verification.
[0037] 5. Content verification module:
[0038] According to the API interface dictionary imported in the function configuration module, the request and response contents parsed in the protocol parsing module are strictly checked according to the field format, length, attribute, and content in the dictionary. At the same time, the optional / mandatory fields of the interface are automatically identified, and the messages carrying fields that do not comply with the rules in the request are discarded.
[0039] 6. Information hiding module:
[0040] Replace the leaked information in the header field of the response, hide the fields in the header field and Body content of the response that do not conform to the rules, record the field information and send an alarm message to the log alarm module; desensitize the sensitive information that the caller wants to use but not calculate; watermark the sensitive information that the caller wants to use or calculate; after unification, send the data to the image watermark processing module.
[0041] 7. Image watermark processing module:
[0042] Responsible for extracting the image content from the received binary data, and restoring it to a standard format image according to the image encoding format, such as JPEG, PNG, BMP, etc.; judging whether to use frequency domain watermark / compression domain watermark / time domain watermark according to the configuration issued by the function configuration module; decoding / transforming / AI edge recognition of the image according to the watermark type, and obtaining the area to be embedded with the watermark; converting the caller's identity information, time and custom text content into the watermark content to be embedded, and superimposing it into the area to be embedded with the watermark to complete the embedding of the hidden watermark; after the watermark processing module returns the image stream after superimposing the watermark, re-encode the image, convert it into binary format data, and then send it to the network processing module for transmission.
[0043] 8. Database module:
[0044] Responsible for persistent storage of function configuration data to ensure that the system can run normally after restart without reconfiguration.
[0045] 9. Log alarm module:
[0046] Log records are kept for users who make legitimate calls, which can be used for subsequent audits. Alarm analysis / query / display are performed on the IP addresses, API interface types / contents / behaviors / times of illegal calls, and the caller user information to trace illegal attack incidents.
[0047] The present invention also provides a security protection method based on network API calling images, which adopts the security protection system based on network API calling images described in the present invention, and the system can be deployed independently.
[0048] After startup, you need to configure the IP address and transport layer port of the image system server through the function configuration module. After the configuration is completed, the configuration data will be stored in the database module. The network processing module will monitor the IP packets passing through the device on the network in real time. When it finds the request packet sent by the caller to the image system, it will intercept the packet and send it to the protocol parsing module; the protocol parsing module will parse the content in the packet according to the HTTP / HTTPS protocol, and then reassemble it into a request packet according to the image information called in the protocol request, and send it to the security protection module. The security protection module performs security defense according to non-trusted users, and the packets that meet the rules of security defense are sent to the content verification module. The content verification module verifies the format, length, and content of the packet. The verified correct packets are sent to the network processing module and sent to the image system server.
[0049] When the network processing module receives the response reply message returned from the image system, the message is sent to the protocol parsing module. The protocol parsing module completes the message content parsing and sends the message to the security protection module. The security protection module identifies the interface type of the message. If it is an authentication success message, the trusted caller table entry of the trusted user + IP address is maintained to ensure that the caller is protected according to the trusted caller defense mechanism when visiting again. After the processing is completed, the message is sent to the information hiding module. After the information hiding module performs three levels of protection processing, including hiding, desensitization and watermarking, it is sent to the image watermark processing module. The image watermark processing module checks whether the message carries image content information. If so, the image content is extracted. At the same time, watermark encoding is implemented according to the configuration and caller identity information, and the hidden watermark is embedded. After completion, the image with embedded watermark is re-encapsulated into the response message and sent to the network processing module. If it does not carry image content, it is directly sent to the network processing module. After receiving the processed response message, the network processing module sends it to the caller.
[0050] The security protection module processes the request messages sent to the image system. Regardless of whether the caller is trusted or untrusted, once the threshold of the security rate control is exceeded, the request message that exceeds the threshold will be directly discarded to prevent the API's DOS / DDOS illegal traffic from impacting the image system. At the same time, the recorded information is sent to the log alarm module for alarm analysis and display.
[0051] The content verification module monitors the request message sent to the image system. If it contains fields or content in an irregular format, the request message will be discarded directly to prevent the caller from using the open API interface to obtain illegal content, and the information will be sent to the log alarm module to report an alarm.
[0052] The information hiding module monitors the response message returned by the image system to the calling user, and completes three-level protection processing of response message hiding, desensitization and watermarking according to the configured API interface dictionary, to prevent the leakage of internal information of the image system (such as component information, protocol version information, etc.) and the IP network information where the image system is located, and to prevent criminals from using this information to identify vulnerabilities and launch intrusion attacks. Description of the drawings:
[0053] Figure 1 Schematic diagram of the security protection system based on network API calling image according to the present invention
[0054] Figure 2 Schematic diagram of the trusted / untrusted defense architecture of the security protection module of the present invention
[0055] Figure 3 Schematic diagram of the transparent proxy deployment implementation of the present invention
[0056] Figure 4 Schematic diagram of the deployment and implementation of the configuration proxy method described in the present invention Specific implementation method:
[0057] This system is deployed in the network between the image system visitor and the image system server. The operation of the system is explained by taking the communication between the two systems through the HTTP / HTTPS / Websocket protocol as an example. This system protects the image system server.
[0058] This system starts when the Linux operating system starts. After startup, the watermark content and watermark format, as well as the IP address and transport layer port of the image system are configured; the configuration data is saved to the database module to ensure that after restarting again, there is no need to reconfigure and the functions can be used normally.
[0059] The network processing module of this system monitors the sending and receiving of messages at the network layer through the configured IP address and port of the image system server. When it monitors the image system access request sent by the viewer, it intercepts it and sends it to the image system server after security protection and content inspection. When it receives the response message sent back by the image system server, it intercepts it again, hides, desensitizes and watermarks the data in the response, adds a hidden digital watermark to the image carried in the response, and then sends it back to the caller.
[0060] The network proxy module described in the present invention runs on the network side, supports bypass policy routing deployment, and also supports transparent proxy mode (the original docking parties are not aware of it) and configured proxy mode (the IP address information of the image system can be hidden), and receives and forwards HTTP / HTTPS / Websocket requests by configuring the proxy service.
Claims
1. A security protection system based on network API calling images, Features The system can be deployed independently in the image system network by transparent proxy or configuration proxy, and provide security protection for the network API interface opened by the image system, including function configuration module, network processing module, protocol analysis module, content verification module, security protection module, information hiding module, image processing module, watermark processing module, database module and log alarm module, among which: A. The function configuration module provides users with a flexible security policy configuration interface. Users can configure functions based on IP address, transport layer port, digital watermark processing method and watermark content, and then send the configuration to the network processing and watermark processing modules; B. The network processing module monitors the network messages passing through the device in real time, obtains HTTP / HTTPS protocol messages that meet the access rules and whose destination IP address is the IP address of the called image system, blocks messages sent to the video image system by users or devices that do not meet the access security list, and acts as an intermediate proxy to establish HTTP / HTTPS connections with the image system and the caller respectively; C. The protocol parsing module is responsible for receiving the messages transferred from the network processing module, parsing and reorganizing the HTTP / HTTPS protocol messages, and then parsing out the specific content according to the field format defined in the protocol; D. The security protection module is responsible for implementing anti-DOS / DDOS attack defense for caller request messages according to the dual-channel security protection mechanism of trusted / untrusted callers; E. The content verification module performs format verification on the content parsed by the protocol parsing module in strict accordance with the field format, length, attributes, and content in the dictionary based on the interface dictionary imported in the function configuration module; F. The information hiding module automatically identifies the optional / mandatory fields of the protocol, and performs three-level security protection processing on the data in the response message, namely hiding, desensitizing, and watermarking, according to the message rules configured in the function configuration module. This can prevent information leakage and prevent the exposure of unnecessary information and thus vulnerabilities; G. The image watermark module is responsible for extracting the image content from the received data according to the image encoding format, decoding / transforming / AI edge recognition of the image according to the configuration of the frequency domain watermark / compression domain watermark / time domain watermark issued by the function configuration module, obtaining the area to be embedded with the watermark, converting the caller's identity information, time and custom text content into the watermark content to be embedded, and superimposing it on the area to be embedded with the watermark to complete the embedding of the hidden watermark; H. The database module is responsible for persistent storage of function configuration data to ensure that the system can run normally without reconfiguration after restart; I. Log alarm module: Logs are recorded for users who make legal calls, which can be used for subsequent audits; alarms are issued for users who make illegal calls, and illegal attack incidents can be traced.
2. According to claim 1, a security protection system based on network API calling images, It is characterized in that The security protection module implements dual-channel flow control protection for trusted and untrusted callers by analyzing the API interface protocol authentication method and process. A loose protection mechanism is adopted for trusted callers, and different levels of access rate control are performed according to the user configuration to control the access time of a single caller and the configured interface priority. A strict protection mechanism is adopted for untrusted callers, and a four-level flow control mechanism is adopted based on strict management of access time and API interface type, access rate control of a single untrusted caller, Hash bucket rate control of all untrusted callers, and total rate control to achieve security protection against malicious DOS / DDOS attacks at the API interface level.
3. According to claim 1, a security protection system based on network API calling images, It is characterized in that The content verification module completes the security protection of the three levels of API interface scope, format, and attributes and content carried by the message Body through strict verification based on the API interface dictionary configured in the function configuration module, thereby realizing attack protection against attacks and intrusions that exploit interface vulnerabilities and implant unnecessary fields.
4. According to claim 1, a security protection system based on network API calling images, It is characterized in that The information hiding module implements three levels of security protection, namely hiding, desensitizing and watermarking, according to the API interface dictionary configured in the function configuration module. It prevents unauthorized content from being sent out, internal image system servers from being leaked, and vulnerability information from being disclosed by strictly checking the format and information of the HTTP response message header field and content.
5. According to claim 1, a security protection system based on network API calling images, It is characterized in that The image watermark module can automatically select frequency domain watermark / compression domain watermark / time domain watermark, decode / transform / AI edge recognize the image according to the watermark type, obtain the area to be embedded with the watermark, convert the caller's identity information, time and custom text content into the watermark content to be embedded, and superimpose it on the area to be embedded with the watermark to complete the embedding of the hidden watermark.
6. A security protection method based on network API calling images, Features By adopting the security protection system based on network API calling image as described in any one of claims 1 to 5, the system can be independently deployed in the network where the image system server is located. When the network processing module finds that the caller sends a request message to the image system, the message will be intercepted and sent to the protocol parsing module. The protocol parsing module will parse the content in the message according to the HTTP / HTTPS protocol, and then reassemble it into a request message according to the image information of the request call in the protocol, and send it to the security protection module. The security protection module performs security defense according to non-trusted users, and sends the message that complies with the rules of security defense to the content verification module. The content verification module performs format, length, and content normative verification on the message, and the verified correct message is sent to the network processing module and sent to the image system server; when the network processing module receives a response reply message returned from the image system, it sends the message to the protocol parsing module. The protocol parsing module The analysis module completes the parsing of the message content and sends the message to the security protection module. The security protection module identifies the interface type of the message. If it is a successful authentication message, the trusted caller table entry of the trusted user + IP address is maintained to ensure that the caller is protected according to the trusted caller defense mechanism when visiting again. After the processing is completed, the message is sent to the information hiding module. After the information hiding module performs three levels of protection processing, including hiding, desensitization and watermarking, it is sent to the image watermark processing module. The image watermark processing module checks whether the message carries image content information. If it does, it extracts the image content and implements watermark encoding according to the configuration and caller identity information, and embeds the hidden watermark. After completion, the image with embedded watermark is re-encapsulated into the response message and sent to the network processing module. If it does not carry image content, it is directly sent to the network processing module. After receiving the processed response message, the network processing module sends it to the caller.