Abnormality detection method and related equipment
By using a model set composed of the first model and the second model for abnormal detection, the problem of difficult to detect unknown bursts of increased traffic attacks in the prior art is solved, and higher detection accuracy and lower false alarm rates and missed alarm rates are achieved.
Patent Information
- Application Number
- CN202311616059.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to detect unknown sudden increase in traffic attacks in WEB applications, resulting in a high missed rate.
Anomaly detection is performed using a model set composed of the first model and the second model. By using the output of the first model as the input of the second model, or the output of the second model as the input of the first model, the learning ability of the model is enhanced and the detection accuracy is improved.
The false alarm rate and missed alarm rate of abnormal detection are reduced, and the accuracy of abnormal detection results is improved.
Smart Images

Figure CN120074844A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular, to an anomaly detection method and related devices. Background Art
[0002] With the development of the Internet and the wide application of encryption technology, the network security problem of encrypted traffic has attracted more and more attention. Among them, the sudden increase in encrypted traffic attacks in WEB applications (such as: CC attacks, malicious crawlers, mass scans, etc.) is a common attack method. This attack method will cause the server load to be too high, and in severe cases, it will cause the system to crash. Therefore, how to detect this attack method has become an important issue in the field of network security.
[0003] Currently, anomaly detection can be performed on access behaviors based on signature rules. Specifically, traffic data is matched with signature rules to identify whether there are known attack characteristics. However, this solution can only detect known attack characteristics and cannot detect unknown attack characteristics, resulting in a relatively high false negative rate. Summary of the Invention
[0004] This application provides an anomaly detection method and related devices, which can reduce the false positive rate of anomaly detection.
[0005] In a first aspect, this application provides an anomaly detection method, including:
[0006] Obtain first information from a client, where the first information is used to identify the identity information of the client; input the first information into a first model set to obtain an anomaly detection result of the access behavior of the client, where the first model set includes a first model and a second model, and the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
[0007] Based on the above technical solution, compared with using a single model, this application uses a first model set to perform anomaly detection on the access behavior of the client, taking the output of the first model as the input of the second model, or taking the output of the second model as the input of the first model, which can further enhance the learning ability of the model, improve the accuracy of anomaly detection, and reduce the false positive rate and false negative rate of anomaly detection.
[0008] In a possible implementation manner of the first aspect, both the first model and the second model include a first parameter, where the first parameter is used to indicate the degree of coincidence with historical model data, the size of the first parameter is directly proportional to the degree of coincidence with historical model data, the first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1;
[0009] Input the first information into the first model set to obtain the anomaly detection result of the client's access behavior, including:
[0010] Input the first information into the first model to obtain the first detection result;
[0011] Input the first detection result into the second model to obtain the second detection result;
[0012] Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
[0013] Based on the above technical solution, since the magnitude of the first parameter is directly proportional to the degree of coincidence with the historical model data, when the first parameter of the first model is less than the first parameter of the second model, compared with the first detection result output by the first model, the second detection result output by the second model will be more consistent with the historical model data, that is, the second model is more inclined to learn historical data, the second model has stronger memory ability, and the change trend of the second detection result is more stable and smooth. On this basis, comparing the first detection result with the second detection result can obtain a judgment result with higher stability, making the anomaly detection result more accurate and reducing the false alarm rate or missed alarm rate of anomaly detection.
[0014] In a possible implementation manner of the first aspect, both the first model and the second model include a second parameter, the second parameter is used to indicate the interference degree of the burr, the magnitude of the second parameter is inversely proportional to the interference degree of the burr, the second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1;
[0015] Input the first information into the first model set to obtain the anomaly detection result of the client's access behavior, including:
[0016] Input the first information into the first model to obtain the first detection result;
[0017] Input the first detection result into the second model to obtain the second detection result;
[0018] Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
[0019] Based on the above technical solution, since the magnitude of the second parameter is inversely proportional to the interference degree of the burr, when the second parameter of the first model is greater than the second parameter of the second model, compared with the second detection result, the first detection result is less likely to be interfered by the burr, the interference degree of the burr is lower, and the proportion of the burr or distorted data filtered after being input into the first model is larger, thereby reducing the probability of false triggering and false alarms.
[0020] Optionally, the glitch can be replaced with other terms, such as distorted data, data with a lower occurrence probability, etc.
[0021] In a possible implementation of the first aspect, determining the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result includes:
[0022] When the first detection result is greater than the second detection result, determine that the access behavior of the client is abnormal;
[0023] When the first detection result is less than or equal to the second detection result, determine that the access behavior of the client is normal.
[0024] Based on the above technical solution, since the first parameter of the first model is greater than the second parameter of the second model, the second detection result output by the second model will be more consistent with the historical model data, and the change trend of the second detection result will be more stable and smooth. On this basis, the stability of the comparison result between the first detection result and the second detection result is relatively high, and the obtained detection result is also more accurate.
[0025] In a possible implementation of the first aspect, the first information includes Transport Layer Security (TLS) fingerprint information.
[0026] Based on the above technical solution, when the client accesses the protected objects corresponding to different domain names, the corresponding TLS fingerprint information is also different. Using the TLS fingerprint to characterize the access characteristics of the client can perform targeted anomaly detection on the access behaviors of different protected objects.
[0027] In a possible implementation of the first aspect, the first information includes the mapping information between the TLS fingerprint information and the histogram bins.
[0028] Based on the above technical solution, mapping the TLS fingerprint information of the protected objects corresponding to different domain names to the histogram bins can, when the number of access behaviors and TLS fingerprints of the client is large, map the TLS fingerprint information to the statistical information in the histogram bins as the input of the first model set, thereby reducing the memory occupancy and also improving the data processing efficiency.
[0029] In a possible implementation of the first aspect, the first information includes canvas fingerprint information.
[0030] Based on the above technical solution, different clients correspond to different canvas fingerprint information. Characterizing the access characteristics of the client as canvas fingerprint information can indicate the unique identity of the client.
[0031] In a possible implementation of the first aspect, the first model set further includes a third model, and the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
[0032] Based on the above technical solution, compared with using a single model to detect abnormal behaviors, using the first model set with at least three models in series to detect abnormal behaviors can continuously optimize the results output by a single model, thereby further improving the detection accuracy of the model.
[0033] In a second aspect, the present application provides an abnormal detection device, and its beneficial effects can be referred to the description of the first aspect and will not be elaborated here. The device has the function of implementing the behaviors in the method example of the first aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The device includes:
[0034] A receiving module, including obtaining first information from a client, where the first information is used to identify the identity information of the client;
[0035] A processing module, configured to input the first information into the first model set to obtain an abnormal detection result of the access behavior of the client, where the first model set includes a first model and a second model, and the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
[0036] In a possible implementation of the second aspect, both the first model and the second model include a first parameter, where the first parameter is used to indicate the degree of coincidence with historical model data, and the size of the first parameter is in a direct proportional relationship with the degree of coincidence with historical model data. The first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1;
[0037] The processing module is further configured to:
[0038] Input the first information into the first model to obtain a first detection result;
[0039] Input the first detection result into the second model to obtain a second detection result;
[0040] Determine the abnormal detection result according to the magnitude relationship between the first detection result and the second detection result.
[0041] In a possible implementation of the second aspect, both the first model and the second model include a second parameter, where the second parameter is used to indicate the degree of interference of burrs, and the size of the second parameter is in an inverse proportional relationship with the degree of interference of burrs. The second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1;
[0042] The processing module is further configured to:
[0043] Input the first information into the first model to obtain a first detection result;
[0044] Input the first detection result into the second model to obtain a second detection result;
[0045] Determine an anomaly detection result based on the magnitude relationship between the first detection result and the second detection result.
[0046] In a possible implementation manner of the second aspect, the processing module is further configured to:
[0047] When the first detection result is greater than the second detection result, determine that the access behavior of the client is abnormal;
[0048] When the first detection result is less than or equal to the second detection result, determine that the access behavior of the client is normal.
[0049] In a possible implementation manner of the second aspect, the first information includes Transport Layer Security (TLS) fingerprint information.
[0050] In a possible implementation manner of the second aspect, the first information includes mapping information between TLS fingerprint information and histogram bins.
[0051] In a possible implementation manner of the second aspect, the first information includes canvas fingerprint information.
[0052] In a possible implementation manner of the second aspect, the first model set further includes a third model, and the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
[0053] In a third aspect, the present application provides a computing device cluster, including at least one computing device, and each computing device includes a processor and a memory; the processor of at least one computing device is configured to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation manner of the first aspect.
[0054] In a fourth aspect, the present application provides a computer program product containing instructions, characterized in that when the instructions are run by a computing device cluster, the computing device cluster is caused to execute the method in the first aspect or any possible implementation manner of the first aspect.
[0055] Fifth aspect, the present application provides a chip system, which includes a processor for implementing the method in the above first aspect or any possible implementation manner of the first aspect. In a possible design, the chip system further includes a memory for storing program instructions and / or data. The chip system may be composed of chips or may include chips and other discrete devices.
[0056] Sixth aspect, the present application provides a computer-readable storage medium, which is characterized by including computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method in the above first aspect or any possible implementation manner of the first aspect.
[0057] The solutions of the above second to sixth aspects are used to implement or cooperate with the implementation of the method in the above first aspect or any one of its possible implementation manners, and thus can achieve the same or corresponding beneficial effects as the first aspect, which will not be elaborated here. Description of the Drawings
[0058] Figure 1 It is a schematic structural diagram of a computing device provided by an embodiment of the present application;
[0059] Figure 2 It is a schematic diagram of an application scenario of an abnormal detection method for access behavior provided by an embodiment of the present application;
[0060] Figure 3 It is another schematic diagram of an application scenario of the abnormal detection method provided by an embodiment of the present application;
[0061] Figure 4 It is a schematic flowchart of an abnormal detection method provided by an embodiment of the present application;
[0062] Figure 5 It is a schematic diagram of the mapping relationship between TLS fingerprints and histogram bins provided by an embodiment of the present application;
[0063] Figure 6 It is another schematic diagram of the mapping relationship between TLS fingerprints and histogram bins provided by an embodiment of the present application;
[0064] Figure 7 It is a schematic architecture diagram of an abnormal detection method provided by an embodiment of the present application;
[0065] Figure 8 It is a schematic diagram of the model learning process of the first model pair provided by an embodiment of the present application;
[0066] Figure 9 It is a schematic structural diagram of an abnormal detection device provided by an embodiment of the present application;
[0067] Figure 10A schematic structural diagram of a computing device cluster provided by an embodiment of the present application;
[0068] Figure 11 Another schematic structural diagram of a computing device cluster provided by an embodiment of the present application. Detailed implementation manners
[0069] First, some terms in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0070] (1) Transport layer security (TLS) fingerprint: A technology used to identify and verify TLS connections. It is a fingerprint generated based on some client characteristics (such as TLS version, acceptable ciphers, extension list, elliptic curve cryptography, and elliptic curve cryptography formats, etc.) during the TLS handshake process.
[0071] (2) Exponential weighted moving average (EWMA) model: A time series analysis-based model used to predict future trends and their changes, and is widely applied to the field of anomaly detection. In anomaly detection, the EWMA model can be used to detect the deviation degree of data. Specifically, the EWMA model can be used to calculate the mean and standard deviation of data, and then judge whether the data is abnormal according to these statistics. If the value of a data point differs significantly from the value predicted by the EWMA model, it can be determined as abnormal.
[0072] (3) Single-layer perceptron: A neural network model composed of an input layer and an output layer. The input layer receives input signals, and the output layer calculates an output value based on the input signals. The output value of the single-layer perceptron is calculated by a linear combination of the input signals and the weight values corresponding to each input signal, and then undergoes a non-linear transformation through an activation function to finally obtain the output value. The single-layer perceptron is often used in binary classification problems, such as classifying users' WEB access behaviors into normal behaviors and abnormal behaviors.
[0073] (4) The terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order other than that shown or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or modules does not have to be limited to those steps or modules clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products or devices.
[0074] The term "and / or" appearing in this application can be a relationship describing associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this application generally represents an "or" relationship between the associated objects before and after.
[0075] It should also be noted that in some alternative embodiments, the indicated functions / actions may not occur in the order shown in the drawings. For example, depending on the functions / actions involved, in fact, they may occur substantially simultaneously or may sometimes be executed in the reverse order for two consecutive drawings shown.
[0076] In the embodiments of this application, unless otherwise specified, the meaning of "at least one" refers to one or more, and the meaning of "a plurality" refers to two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single item(s) or plural item(s). For example, "at least one of A, B and C" includes A, B, C, AB, AC, BC or ABC. Also, unless otherwise specified, the ordinal numbers such as "first", "second", etc. mentioned in the embodiments of this application are used to distinguish multiple objects and are not used to limit the order, timing, priority or importance of multiple objects. It can be understood that in this application, "when", "if" and "in case" all refer to the device will make corresponding processing under certain objective circumstances, which does not limit the time, and it is not required that the device must have a judgment action when implemented, nor does it mean that there are other limitations. In addition, the special word "exemplary" means "serving as an example, embodiment or illustration". Any embodiment described as "exemplary" does not have to be interpreted as superior to or better than other embodiments.
[0077] (5) In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information (such as the indication information described below) is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated; it is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, the arrangement order of each piece of information pre-agreed (such as protocol pre-definition) can be used to indicate specific information, thereby reducing the indication overhead to a certain extent. The present application does not limit the specific manner of indication. It can be understood that for the sender of the indication information, the indication information can be used to indicate the information to be indicated, and for the receiver of the indication information, the indication information can be used to determine the information to be indicated.
[0078] In the present application, unless otherwise specified, the same or similar parts between various embodiments can be referred to each other. In each embodiment of the present application, as well as in each method / design / implementation manner in each embodiment, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments, as well as between each method / design / implementation manner in each embodiment, are consistent and can be mutually referred to. The technical features in different embodiments, as well as in each method / design / implementation manner in each embodiment, can be combined according to their inherent logical relationships to form new embodiments, methods, or implementation manners. The embodiments of the present application described below do not constitute a limitation on the protection scope of the present application.
[0079] The embodiments of the present application will be described below with reference to the accompanying drawings. Those of ordinary skill in the art will know that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0080] First, in order to better understand the solutions of the embodiments of the present application, the application scenarios of the embodiments of the present application will be described below.
[0081] The computing device to which the anomaly detection method provided by the embodiments of the present application is applicable can be a server, or deployed on a server, or can be independent of the client and the server and connected to the client and / or the server. For example, the computing device can be a security detection device such as a gateway or a firewall, or deployed on a gateway or a firewall. It can be specifically set according to actual needs and is not limited here.
[0082] Exemplarily, please refer to Figure 1 , Figure 1A schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 1 shown, the computing device 100 includes: a bus 102, a processor 104, a memory 106, and a communication interface 108. The processor 104, the memory 106, and the communication interface 108 communicate with each other through the bus 102.
[0083] It should be understood that the present application does not limit the number of processors and memories in the computing device 100.
[0084] Optionally, the computing device 100 further includes a display. The display includes a display panel, and the display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a quantum dot light-emitting diode (QLED), etc. The display can be used to display the abnormal detection result.
[0085] The bus 102 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 1 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus. The bus 102 can include a path for transmitting information between various components of the computing device 100 (for example, the memory 106, the processor 104, the communication interface 108).
[0086] The processor 104 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.
[0087] The memory 106 may include disks such as a hard disk drive (HDD) and a solid state drive (SSD).
[0088] Optionally, the memory 106 stores data created during the use of the computing device 100, such as data files like internet protocol (IP) addresses and access times.
[0089] The memory 106 stores executable program code, and the processor 104 executes the executable program code to respectively implement the functions of the foregoing data parsing module 901 and data transmission module 902, thereby implementing the data migration method for the virtual machine. That is, the memory 106 stores instructions for executing the data migration method for the virtual machine.
[0090] The communication interface 108 uses a transceiver module such as, but not limited to, a network interface card and a transceiver to implement the communication between the computing device 100 and other devices or communication networks.
[0091] The technical solution provided by this application can be applied to the computing device 100 as Figure 1 shown. It can be understood that Figure 1 the structure of the computing device shown is only one example, and the anomaly detection method provided by the embodiments of this application can be, but is not limited to, applied to the structures described above, and is not limited here.
[0092] This application can be applied to the field of network security. For example, due to the interconnection between devices, after an attacker invades a server through means such as weak passwords, security vulnerabilities, and system backdoors, other devices interacting with the server may be at risk of security. Therefore, it is necessary to detect abnormal access in network devices to improve security. Corresponding to actual scenarios, for example, it can be applied to the enterprise's security monitoring of the network behavior of internal employees, or the enterprise's security monitoring of business devices in the production environment, or the cloud service provider's security monitoring of internal and / or external tenants, etc.
[0093] In a possible implementation manner, the anomaly detection method provided by the embodiments of this application can be used for an enterprise to perform security monitoring on the network behavior of internal employees.
[0094] Exemplarily, please refer to Figure 2 , Figure 2 which is a schematic diagram of an application scenario of the anomaly detection method for access behavior provided by the embodiments of this application. As Figure 2As shown, the application scenarios include a computing device 201 deployed in a monitoring center and a terminal device 202 deployed at the user end (for example, including terminal devices 2021 to 202N, etc., where N is a natural number), and the number of computing devices 201 and terminal devices 202 can be one or more. The structure of the computing device applicable to the embodiments of the present application can be as Figure 1 shown, which will not be elaborated here. Optionally, the computing device 201 is deployed on a server or is a server, and is used to detect one or more access requests sent by the terminal device 202 to the computing device 201, and obtain the anomaly detection results of the one or more access requests.
[0095] Optionally, the computing device 201 is a security device such as a gateway or a firewall, or is deployed on a security device such as a gateway or a firewall, and is deployed between the terminal device and the server. The computing device 201 detects the access requests of the terminal device 202 to the server, outputs the anomaly detection results, and then reports the anomaly detection results to maintenance personnel or the monitoring center.
[0096] Optionally, the terminal device 202 can be any form of terminal of an internal user. For example, it can include mobile phones, computers, tablets, etc. The embodiments of the present application do not make specific limitations on the terminal device.
[0097] The computing device 201 can provide a memory, and the memory can include a program storage area and a data storage area. Among them, the program storage area can store one or more application programs, such as an application program for detecting abnormal access behaviors. The data storage area can store log data, etc. Exemplarily, the log data can reflect information such as source IP, destination IP, and access times. The computing device 201 obtains network access log data, detects it using the anomaly detection method of this embodiment, and transmits the detection results to the monitoring center to realize the monitoring of the internal network behavior of the company.
[0098] In the above implementation manner, the anomaly detection method provided by the embodiments of the present application can be used to analyze the behaviors of users or clients, focusing on internal threats within an enterprise. In one possible understanding, internal threats can be abnormal access behaviors of internal users, which can be divided into two parts: internal abnormal access behaviors and external abnormal access behaviors. Among them, internal abnormal access behaviors can include deliberate data collection, abnormal and illegal access, account abuse, etc., and external abnormal access behaviors can include data leakage, continuous data transmission, abnormal website access, etc.
[0099] Optionally, the anomaly detection method provided by the embodiments of the present application can be used by an enterprise to perform security monitoring on business devices in a production environment. In this scenario, the terminal device can be a machine for an enterprise to provide services externally.
[0100] In one possible implementation, the anomaly detection method according to the embodiment of the present application may be used by a cloud service provider to perform security monitoring on internal tenants and / or external tenants.
[0101] For example, Figure 3 Schematic diagram of another application scenario of the anomaly detection method provided in an embodiment of the present application. The application scenario includes a cloud service provider 301, an internal tenant 302 (for example, including internal tenants 3021 to 302N, etc., N is a natural number) and an external tenant 303 (for example, including external tenants 3031 to 303N, etc., N is a natural number), wherein the number of internal tenants 302 and external tenants 303 can be one or more. In a possible way of understanding, internal tenants are users used for internal deployment of services in a company, and external tenants are users who use machines rented from external companies.
[0102] Optionally, the cloud service provider 301 is a device such as a gateway, a firewall or a cloud server, or is deployed on a device such as a gateway, a firewall or a cloud server. Based on this application scenario, the method of the embodiment of the present application can be applied to the cloud server (elastic compute service, ECS) security monitoring software to ensure the security of the service while monitoring whether the tenant has any illegal operations. It can also be applied to the situation awareness platform, using probes to collect terminal data, and the functional departments such as the security operations center (SOC) will uniformly monitor and analyze it.
[0103] Based on the above application scenarios, it should be understood that with the development of the Internet and the widespread application of encryption technology, the network security issues of encrypted traffic have received more and more attention. Among them, the sudden increase of encrypted traffic attacks in WEB applications (such as CC attacks, malicious crawlers, large-scale scanning, etc.) is a common attack method. This attack method will cause the server load to be too high, and in severe cases, it will cause the system to crash. Therefore, how to detect this attack method has become an important issue in the field of network security.
[0104] Currently, there are many methods to attack sudden and dense traffic in WEB applications. The following are the most common ones.
[0105] 1. Detection method based on signature rules
[0106] This method matches traffic data with signature rules to identify whether there are known attack features. Specifically, first collect known attack features, formulate signature rules based on the collected attack features, match traffic data with signature rules, and identify whether there are known attack features. If it is identified as a known attack feature, corresponding measures can be taken, such as limiting access speed, banning IP, etc.
[0107] However, this method can only detect known attack features and cannot detect unknown attack features. Therefore, this method usually has a high false negative rate.
[0108] 2. Detection method based on deep learning
[0109] This method uses deep learning algorithms to analyze traffic and identify abnormal traffic. Specifically, a classification model that can determine whether traffic is abnormal can be established by training normal traffic and abnormal traffic. If it is determined to be abnormal, corresponding measures can be taken, such as restricting the access speed, blocking the IP, etc.
[0110] However, this method generally uses a supervised learning model and the feature extraction of data packets is not complete and sufficient. Therefore, this method has a high false positive rate and low accuracy.
[0111] 3. Detection method based on behavior analysis
[0112] This method analyzes WEB access behaviors to identify abnormal behaviors and processes them. Specifically, it can analyze access frequency, access path, access time, etc. to determine whether there are abnormal behaviors.
[0113] However, this method usually counts access behaviors with the client IP as the granularity and usually cannot detect attacks with dispersed client IPs. Therefore, this method has a high false negative rate.
[0114] To solve the above problems, the embodiments of the present application provide an anomaly detection method. Please refer to Figure 4 , Figure 4 which is a schematic flowchart of the anomaly detection method provided by the embodiments of the present application. It should be noted that in Figure 4 , the computing device is taken as the execution subject as an example to illustrate this method, but the present application does not limit the execution subject of this interaction schematic. For example, in Figure 4 , the execution subject of the method can be replaced by a chip, a chip system, a processor, a logic module or software in the computing device, etc. This method includes the following steps. It should be understood that the computing device can be deployed on a server, or be a security detection device such as a gateway or a firewall, or be deployed on a gateway or a firewall, etc.
[0115] Optionally, abnormal access behaviors in the security field may include one or more of targeted attack behaviors, abnormal login behaviors, or unauthorized access behaviors.
[0116] Exemplarily, a targeted attack behavior may refer to an attack launched by an attacker against a specified target. For example, the attacker conducts port scanning, distributed denial of service attack (DDoS), structured query language (SQL) injection, cross site script attack (XSS), etc. on a machine exposed to the public network for vulnerability mining.
[0117] Exemplarily, an abnormal login behavior may refer to a user attempting to log in to a website application or server using an account that is not theirs. This abnormal login behavior may be caused by the leakage, theft, or successful brute force cracking of the account password, and is used to bypass the identification and verification of the user's identity. The data that can be abnormally accessed (or may be referred to as abnormal points) in the abnormal login behavior includes the login IP, login location, login time, number of login failures, login operations, etc.
[0118] Exemplarily, an unauthorized access behavior may refer to an attacker initiating a connection request to a machine that they have no right to access or no need to access. The unauthorized access behavior may be a lateral penetration and / or vertical penetration initiated after an internal threat or a successful external network intrusion, and is used to increase the user's privileges in the server and expand the attack surface. In a possible way of understanding, lateral penetration may refer to an attacker attempting to access the resources of a user with the same privileges as theirs, and vertical penetration may refer to a low-level attacker attempting to access the resources of a high-level user.
[0119] The data that can be abnormally accessed (or may be referred to as abnormal points) in the unauthorized access behavior includes the IP address, user information, service attributes, etc. In a possible way of understanding, user information may refer to the user's login account, login time, number of logins, etc., and service attributes may refer to the characteristics shown under the support of network or terminal capabilities and their hierarchical functions.
[0120] S401. The computing device obtains first information from the client, and the first information is used to identify the identity information of the client.
[0121] In this step, the computing device can obtain the first information from the client to parse the access behaviors for different domains from different clients and perform anomaly detection.
[0122] In a possible implementation manner, the first information includes the Transport Layer Security (TLS) fingerprint information.
[0123] Optionally, the computing device receives a TLS handshake packet from the client and obtains TLS fingerprint information from the TLS handshake packet. Specifically, the computing device extracts the server name indication (SNI) domain name and the client field from the TLS handshake packet for generating the TLS fingerprint. The SNI domain name is the specified protected object.
[0124] Optionally, after the computing device extracts the SNI domain name and the client field from the TLS handshake packet, for the SNI domain name, the computing device concatenates the values of the client fields (e.g., string concatenation), and then inputs the concatenated value into a hash function. The output value of the hash function is the TLS fingerprint.
[0125] Based on the above technical solution, the computing device can perform targeted anomaly detection on the access behaviors of different protected objects according to the SNI domain name. It should be understood that the embodiments of the present application may adopt the reverse proxy method, so the computing device can protect several domain names. To distinguish the access requests from different clients for different protected objects, the computing device obtains the TLS fingerprint information according to the SNI domain name and the client field. Among them, different clients correspond to different TLS fingerprint information, so the computing device can determine the information of the client and the protected object according to the TLS fingerprint information.
[0126] Optionally, the TLS handshake packet is a web packet transmitted by the client to the server based on the application layer protocol. For example, the client sends a Client Hello message to the server.
[0127] Optionally, the application layer protocol includes protocols based on the secure sockets layer (SSL) / TLS, such as the hyper text transfer protocol over SSL / TLS (HTTPS), the file transfer protocol over SSL / TLS (FTPS), or the simple mail transfer protocol over SSL / TLS (SMTPS).
[0128] Optionally, the client fields include one or more of TLS version, acceptable ciphers, extension list, elliptic curves, elliptic curve point formats, handshake version, cipher suite list, compression method list, extension list, elliptic curve list, EC point format list, and signature algorithm list.
[0129] In one possible implementation, the first information includes the mapping information between the TLS fingerprint information and the histogram bins.
[0130] Optionally, the computing device maps the TLS fingerprint information to the histogram bins to obtain the statistics of the TLS fingerprint information within a specified time period.
[0131] Optionally, the computing device maps the TLS fingerprint information (i.e., the hash value), and maps the remainder result to different histogram bins. Among them, the mapping method can be, for example, taking the remainder.
[0132] Specifically, a histogram bin corresponds to the statistics of the TLS fingerprint information scattered into different bins within the same time period. For example, the computing device maps the TLS fingerprint information with a remainder result of 1 to bin 1, and the computing device maps the TLS fingerprint information with a remainder result of 2 to bin 2. Among them, the value of the bin represents the mapping times of the TLS fingerprint information.
[0133] Exemplarily, please refer to Figure 5 , Figure 5 which is a schematic diagram of the mapping relationship between the TLS fingerprint and the histogram bins provided by the embodiments of the present application. As Figure 5 shown, the computing device collects or obtains a number of TLS fingerprint information within a period of time, and maps the number of TLS fingerprint information to different bins. Within the specified time period, the specific content of the mapping times between the TLS fingerprint information and the histogram bins can be seen in Table 1 below.
[0134] Table 1
[0135] Sample Status Sequence Values of Histogram Sample One {"bin1":23,"bin2":35,"bin3":18,"bin4":28,"bin5":21,"bin6":17,"bin7":19} Sample Two {"bin1":23,"bin2":35,"bin3":18,"bin4":28,"bin5":300,"bin6":17,"bin7":19}
[0136] As shown in Table 1 above, in Sample 2, within the specified time period, compared with other bins, the number of TLS fingerprint information mapped to bin 5 is very large. In this case, the computing device can determine that Sample 2 is an abnormal sample, and correspondingly, Sample 1 is a normal sample. Correspondingly, please refer to Figure 6 , Figure 6Another schematic diagram of the mapping relationship between the TLS fingerprint and the histogram bucket provided by the embodiment of the present application. As analyzed above, (a) represents Sample 1 which is a normal sample, and (b) represents Sample 2 which is an abnormal sample. In Figure 6 it, the abscissa is different bins, and the ordinate is the corresponding number / frequency of the TLS fingerprint information mapped to different bins.
[0137] It should be understood that compared with the computing device using one SNI domain name corresponding to one bin, or using one client corresponding to one bin. When the computing device maps the TLS fingerprint information to the histogram bucket, it can map the TLS fingerprint information with the same statistical characteristics to the same bin when the number of clients and the number of generated TLS fingerprint information are large, thereby reducing the memory occupancy and facilitating subsequent calculations.
[0138] In addition, when the number of data packets sent by the client is small, the client may experience a disconnection, and the learning accuracy of the baseline model will also decrease. By adopting the method of mapping the TLS fingerprint information to the histogram bucket, and using the statistic of the TLS fingerprint information within a specified time period as the input of the baseline model, the learning ability of the baseline model can be enhanced and the false alarm rate can be reduced.
[0139] It should be understood that during the actual execution process, for the convenience of statistics and calculation, the computing device can scale down or up the values in all corresponding bins within the same time period by the same proportion.
[0140] In a possible implementation manner, the first information includes canvas fingerprint information.
[0141] Specifically, the TLS fingerprint information can also be replaced by other types of device fingerprints. Since different clients correspond to different canvas fingerprint information, the computing device characterizes the access characteristics of the client as canvas fingerprint information, which can also indicate the unique identity of the client
[0142] S402. The computing device inputs the first information into the first model set to obtain the abnormal detection result of the access behavior of the client, where the first model set includes a first model and a second model, the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
[0143] In a possible implementation manner, the first model set further includes a third model, the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
[0144] In this implementation manner, the first model set may further include a third model, and the computing device may detect abnormal behaviors by using the first model set in which at least three models are connected in series.
[0145] It should be understood that the number of models in the first model set is not the more the better. On the basis of ensuring the existence of the first model and the second model, whether the computing device adds more models to the first model set needs to be determined according to actual requirements or test results, and no limitation is made here.
[0146] In a possible implementation manner, both the first model and the second model include a first parameter, and the first parameter is used to indicate the degree of coincidence with historical model data. The magnitude of the first parameter is directly proportional to the degree of coincidence with historical model data. The first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1;
[0147] The computing device inputs the first information into the first model set to obtain the abnormal detection result of the client's access behavior, including: the computing device inputs the first information into the first model to obtain a first detection result; the computing device inputs the first detection result into the second model to obtain a second detection result; the computing device determines the abnormal detection result according to the magnitude relationship between the first detection result and the second detection result.
[0148] In this implementation manner, since the magnitude of the first parameter is directly proportional to the degree of coincidence with historical model data, when the first parameter of the first model is less than the first parameter of the second model, compared with the first detection result output by the first model, the second detection result output by the second model will be more consistent with historical model data, that is, the second model is more inclined to learn historical data, the memory ability of the second model is stronger, and the change trend of the second detection result is more stable and smooth. On this basis, comparing the first detection result with the second detection result can obtain a judgment result with higher stability, making the abnormal detection result more accurate and also reducing the false alarm rate or missed alarm rate of abnormal detection.
[0149] In a possible implementation manner, both the first model and the second model include a second parameter, and the second parameter is used to indicate the degree of interference of the glitch. The magnitude of the second parameter is inversely proportional to the degree of interference of the glitch. The second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1
[0150] The computing device inputs the first information into the first model set to obtain the abnormal detection result of the client's access behavior, including: the computing device inputs the first information into the first model to obtain a first detection result; the computing device inputs the first detection result into the second model to obtain a second detection result; the computing device determines the abnormal detection result according to the magnitude relationship between the first detection result and the second detection result.
[0151] Based on the above technical solution, since the magnitude of the second parameter is inversely proportional to the degree of interference of the glitch, when the second parameter of the first model is greater than that of the second model, compared with the second detection result, the first detection result is less likely to be interfered by the glitch, and the degree of interference of the glitch is lower. Then, when the glitch or distorted data is input into the first model, a larger proportion is filtered, thereby reducing the probability of false triggering and the probability of false alarms.
[0152] Optionally, the glitch can be replaced with other terms, such as distorted data, data with a small occurrence probability, etc.
[0153] Optionally, both the first model and the second model are EWMA models.
[0154] Optionally, the computing device uses the start or end moment of a specified time period as the equivalent moment of the specified time period. For example, the time period [t, t + 1] is equivalent to the moment t or the moment t + 1.
[0155] For the sake of convenience of explanation, hereinafter, the output of the first model is used as the input of the second model as an example for explanation.
[0156] Exemplarily, the formula of the EWMA model is as follows:
[0157] f(X t ) = α t *f(X t-1 )+(1 - α t )*X t (1)
[0158] Where α t represents the weighting coefficient at time t, and the smaller its value, the faster the weight drops. X t represents the model input value at time t. Using the start moment of the specified time period as the equivalent moment of the specified time period, f(X t ) represents the estimated value of the output of the EWMA model of X t at time t.
[0159] The weighting coefficient α t will be adaptively updated with the model input value X t . The adaptive update formula of this coefficient is as follows:
[0160] α t = α + β*(1 - p t )*(1 - α) (2)
[0161] Where the constant α represents the weighting coefficient, the constant β represents the adjustment coefficient of the adaptive update ability, and the larger its value, the stronger the adaptive update ability. p tIt represents the weighted coefficient of adaptive update at time t, whose value range is [0, 1], and the larger its value, the faster the weight decreases.
[0162] The weighted coefficient p t is an exponential function with base e, and its formula is as follows:
[0163]
[0164] Among them, σ t represents the standard deviation at time t, and its formula is as follows:
[0165]
[0166] Among them, represents the estimated value of the output of the EWMA model at time t - 1. The formula of
[0167]
[0168] Among them, α here t is equal to α in formula (1); t is equal; represents X in formula (1) t squared.
[0169] Based on the above formula, the baseline calculation formula of the adaptive baseline model is as follows:
[0170] BL(X t ) = f(X t ) + θ * σ t (6)
[0171] Among them, f(X t ) represents the estimated value of the output of the EWMA model described in formula (1); σ t represents the standard deviation described in formula (4); the constant θ represents a multiple of the standard deviation σ t According to the 3σ rule, usually σ t is set to 3.
[0172] It should be understood that the first parameter of the first model and the second model corresponds to α in formulas (1) - (6), and the second parameter of the first model and the second model corresponds to β in formulas (1) - (6). Among them, p t represents the probability of the occurrence of real data. If p t = 1, it means that all the data input into the model are real data, and (1 - p t ) represents the probability of the occurrence of spikes. Corresponding to formula (2), since p tIf the value range of is [0, 1], then the smaller the β, the greater the interference of the glitch on the result of anomaly detection.
[0173] Next, the value magnitudes of the first parameter and the second parameter in the first model and the second model will be described.
[0174] 1. The β of the first model is greater than the β of the second model
[0175] Since the input of the second model is the output of the first model, and the input of the first model is the collected sample data, therefore, the probability of glitches appearing in the sample data input to the first model is greater. In this application, by setting the β of the first model to be greater than the β of the second model, when β is larger, the interference of the anomaly detection result by glitches is smaller, that is, the proportion of glitches filtered is higher, thereby reducing the risk of false triggering and the false alarm rate.
[0176] Correspondingly, since the input of the second model is the output of the first model, and the first model has filtered the glitches in the sample data, therefore, compared with the β in the first model, the computing device can set the β in the second model to a smaller value.
[0177] 2. The α of the first model is less than the α of the second model
[0178] For the first model, β is relatively large and α is relatively small. Corresponding to formula (2), the α of the first model t is relatively small, and (1 - α t ) is relatively large. Corresponding to formula (1), when (1 - α t ) is relatively large, the result output by the model is more inclined to learn the data of X t , that is, more inclined to learn the data input to the real-time input model.
[0179] For the second model, β is relatively small and α is relatively large. Corresponding to formula (2), the α of the first model t is relatively large, and (1 - α t ) is relatively small. Corresponding to formula (1), when (1 - α t ) is relatively small, the result output by the model is more inclined to learn the data of f(X t-1 ), that is, more inclined to learn the historical model data.
[0180] It should be understood that in the first model, since β is relatively large and α is relatively small, therefore, compared with the second model, the forgetting speed of the first model is faster. The first model is mainly used to filter glitches and white noise to reduce false triggering. And in the second model, since β is relatively small and α is relatively large, therefore, the second model is more inclined to learn the historical model data, and the change trend of the output result is also smoother and more stable.
[0181] Optionally, the first parameter of the first model and the second model are equal, and the second parameter of the first model is greater than the second parameter of the second model. Specifically, when β of the first model is greater than β of the second model, the first model is mainly used to filter out glitches and reduce false triggers.
[0182] Optionally, the second parameters of the first model and the second model are equal, and the first parameter of the first model is less than the first parameter of the second model. Specifically, when α of the first model is less than α of the second model, the change trend of the output result of the second model is more stable and smooth, and thus the result of anomaly detection is also more accurate.
[0183] In a possible implementation, the computing device determines the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result, including:
[0184] When the first detection result is greater than the second detection result, the computing device determines that the access behavior of the client is abnormal;
[0185] When the first detection result is less than or equal to the second detection result, the computing device determines that the access behavior of the client is normal.
[0186] In this implementation, taking the output of the first model as the input of the second model, the first model and the second model can form a model pair with a series structure, and the output formula of this model pair is as follows:
[0187]
[0188] Taking the first information as the mapping information between the TLS fingerprint information and the histogram bucket as an example, the specific steps of the automatic learning of this model pair are as follows:
[0189] 1. After the computing device obtains the statistics of the TLS fingerprint information corresponding to N buckets, it takes the statistics of the TLS fingerprint information corresponding to each extracted bucket as the input of the first model, denoted as X short =[X short,1 , X short,2 , …, X short,N , and updates the relevant parameters of the model, and the estimated value of the output is Y short =[Y short,1 , Y short,2 , …, Y short,N .
[0190] For the i-th short time window model, it outputs the estimated value Y short,i of this model for the current input value X short,i , where the subscript "short,i" is the serial number i of this first model.
[0191] 2. The computing device uses the estimated values output by each first model as the inputs to N second models (denoted as X long =[X long,1 , X long,2 , …, X long,N ), and updates the relevant parameters of the model.
[0192] For the i-th second model, it outputs the estimated value Y long,i and the standard deviation σ long,i for the current input value X long,i , where the subscript "long,i" is the sequence number i of this second model. The subscript "i" of the second model and the subscript "i" of the first model described in step 1 correspond one by one. Therefore, the first / second models with equal subscripts "i" form a model pair, denoted as {Model short,i |Model long,i}.
[0193] 3. For the i model pairs {Model short,i |Model long,i}, the computing device uses the output of Model long,i as the input to formula (6) to obtain the baseline of this model pair, denoted as BL i .
[0194] 4. The computing device uses the output of Model short,i and BL i as the input to formula (7) to obtain the output of this model pair, denoted as P i . Among them, P i (X t ) = 1 indicates that the access behavior of the client within the specified time period [t, t + 1] is abnormal, and P i (X t ) = 0 indicates that the access behavior of the client within the specified time period [t, t + 1] is normal.
[0195] It should be understood that the computing device compares the first detection result output by the first model with the second detection result output by the second model. Based on the above analysis, it can be seen that when the change trend of the second detection result is relatively stable and smooth, the output judgment result P i is closer to the actual anomaly detection result, and the obtained anomaly detection result is more accurate.
[0196] It should be understood that what the computing device outputs through formula (7) are the anomaly detection results corresponding to the statistics of the TLS fingerprint information mapped to different bins within the specified time period [t, t + 1]. In order to comprehensively determine the anomaly detection results corresponding to each bin, in one possible implementation, the computing device takes the statistics of each bin as the input of the first model set and outputs the result as the input of the fourth model, and outputs the comprehensive determination result of the anomaly detection result.
[0197] In this implementation, optionally, the fourth model is a single-layer perceptron or a multi-layer perceptron.
[0198] Taking the fourth model as a single-layer perceptron as an example for illustration, exemplarily, in order for the computing device to obtain the final determination result for the statistics after mapping the TLS fingerprint information, a single-layer perceptron can be used to comprehensively determine the output of the first model set. Among them, the input of the single-layer perceptron is P = [P 1 , P 2 , …, P N , where P i represents the output of the i-th first model set. The formula of the single-layer perceptron is as follows:
[0199]
[0200] Among them, w i represents the weight coefficient, b represents the bias term, represents the activation function.
[0201] Optionally, the value of w i is 1. Optionally, the value of b is 0.
[0202] The formula of the activation function here is as follows:
[0203]
[0204] It should be understood that the output f(P) of the single-layer perceptron is a scalar, which is used to obtain the unique determination result corresponding to all access behaviors within the specified time period [t, t + 1] for statistics and monitoring. If f(P) = 1, the computing device determines that the access behavior of the client within the specified time period [t, t + 1] is abnormal; if f(P) = 0, it is determined that the access behavior of the client within the specified time period [t, t + 1] is normal.
[0205] Optionally, the TLS fingerprint information corresponding to N buckets can be input into the first model in parallel or input into the first model in a loop. Specifically, please refer to Figure 7 , Figure 7 which is a schematic diagram of an architecture of the anomaly detection method provided by an embodiment of this application.
[0206] The output of the first model is used as the input of the second model, the first model set is a model pair including the first model and the second model, and the fourth model is a single-layer perceptron as an example for explanation. Figure 7 As shown, the computing device collects TLS handshake packets sent by the client for the SNI domain name within a specified time period, maps the TLS fingerprint information corresponding to the TLS handshake packets to different bins, and uses the statistics of the TLS fingerprint information in each bin as the input of the first model pair, and outputs the anomaly detection results corresponding to the TLS statistics in N bins. The computing device inputs the N anomaly detection results into a single-layer perceptron, uses the single-layer perceptron to make a comprehensive judgment on the WEB access behavior of the SNI domain name, and gives whether the SNI domain name has abnormal WEB access behavior.
[0207] It should be understood that the present application constructs an effective feature expression based on the corresponding TLS fingerprint generated by the TLS handshake request, and constructs multiple adaptive baseline models for each protected object (such as SNI domain name) based on these feature expressions. These models can automatically learn the access behavior of the protected object and form a baseline to achieve personalized protection. Compared with the currently used baseline model, the first model set used in this application enables the learned baseline to have better stability, smoothness, reliability and adaptability. Subsequently, the present application uses the adaptively learned baseline model and a single-layer perceptron to make a comprehensive judgment on the same protected object, thereby improving the problems of high false alarm rate or high missed alarm rate in the current detection scheme.
[0208] Optionally, each model in the first model set is an unsupervised model. Specifically, the present application adopts an unsupervised model, which does not require labeling, thereby reducing the workload.
[0209] In one possible implementation, for example, see Figure 8 , Figure 8 A schematic diagram of the model learning process of the first model pair provided in the embodiment of the present application. Taking the first model set as the first model pair as an example, the process of training the first model pair is specifically introduced.
[0210] 1. Dataset construction
[0211] In the existing network environment, the computing device selects a SNI domain name, uses OpenResty to capture T minutes of TLS handshake packets of normal WEB access behavior to form a pre-learning data set, and uses continuously captured TLS handshake packets of normal WEB access behavior and abnormal WEB access behavior to construct a data set.
[0212] 2. Pre-learning process (or pre-training process)
[0213] The computing device preprocesses the above dataset to obtain statistics in the form of a histogram. The computing device uses the data of this statistic as the input for the first model during pre-learning. After the computing device pre-learns the first model for T minutes continuously, it saves the model parameters for use in the automatic learning process.
[0214] 3. Automatic learning process
[0215] The computing device preprocesses the dataset used in the automatic learning phase to obtain statistics in the form of a histogram. The computing device uses the model parameters obtained in the pre-learning phase as the initial values of the model parameters, and then uses the data of these histogram statistics to continuously learn the first model pair. Finally, the computing device uses a single-layer perceptron to continuously determine the output result of the first model pair to obtain the final anomaly detection result.
[0216] In Figures 1 to 8 Based on the corresponding embodiments, in order to better implement the above solutions of the embodiments of the present application, the following also provides related devices for implementing the above solutions. Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of an anomaly detection device provided by an embodiment of the present application.
[0217] The anomaly detection device 9000 can be located in a computing device such as Figure 1 shown. The anomaly detection device 9000 includes:
[0218] A receiving module 9001, including obtaining first information from a client, where the first information is used to identify the identity information of the client;
[0219] A processing module 9002, configured to input the first information into a first model set to obtain an anomaly detection result of the access behavior of the client, where the first model set includes a first model and a second model, the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
[0220] As an example of a software functional unit, the processing module 9002 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance may be one or more. For example, the processing module 9002 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running the code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Usually, one region may include multiple AZs.
[0221] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, one VPC is set up within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0222] As an example of a hardware functional unit, the processing module 9002 may include at least one computing device, such as a server. Alternatively, the processing module 9002 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0223] The multiple computing devices included in the processing module 9002 can be distributed in the same region or in different regions. The multiple computing devices included in the processing module 9002 can be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the processing module 9002 can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), and generic array logic (GALs).
[0224] It should be noted that in other embodiments, the processing module 9002 can be used to execute any step in the anomaly detection method, and the receiving module 9001 can be used to execute any step in the anomaly detection method. The steps to be implemented by the receiving module 9001 and the processing module 9002 can be specified as needed. The entire function of the anomaly detection device is realized by the receiving module 9001 and the processing module 9002 respectively implementing different steps in the anomaly detection method.
[0225] In a possible implementation manner, both the first model and the second model include a first parameter. The first parameter is used to indicate the degree of agreement with the historical model data. The magnitude of the first parameter is directly proportional to the degree of agreement with the historical model data. The first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1;
[0226] The processing module 9002 is further configured to:
[0227] Input the first information into the first model to obtain a first detection result;
[0228] Input the first detection result into the second model to obtain a second detection result;
[0229] Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
[0230] In a possible implementation manner, both the first model and the second model include a second parameter. The second parameter is used to indicate the degree of interference of the glitch. The magnitude of the second parameter is inversely proportional to the degree of interference of the glitch. The second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1;
[0231] The processing module 9002 is further configured to:
[0232] Input the first information into the first model to obtain a first detection result;
[0233] Input the first detection result into the second model to obtain a second detection result;
[0234] Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
[0235] In a possible implementation, the processing module 9002 is further configured to:
[0236] When the first detection result is greater than the second detection result, determine that the access behavior of the client is abnormal;
[0237] When the first detection result is less than or equal to the second detection result, determine that the access behavior of the client is normal.
[0238] In a possible implementation, the first information includes Transport Layer Security (TLS) fingerprint information.
[0239] In a possible implementation, the first information includes mapping information between TLS fingerprint information and histogram bins.
[0240] In a possible implementation, the first information includes canvas fingerprint information.
[0241] In a possible implementation, the first model set further includes a third model, and the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
[0242] In this embodiment, the operations performed by each unit in the anomaly detection device 9000 are similar to those described in the foregoing Figure 4 method embodiment shown, and can be used to implement the functions of the computing device in the foregoing method embodiment, and can also achieve the beneficial effects of the foregoing method embodiment, which will not be elaborated here. Among them, the receiving module 9001 and the processing module 9002 can both be implemented by software or can be implemented by hardware.
[0243] This application embodiment also provides a computing device cluster. The computing device cluster includes at least one computing device as Figure 1 shown. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0244] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of the computing device cluster provided by this application embodiment. As Figure 10 shown, the computing device cluster includes at least one computing device 100. Instructions for executing the anomaly detection method that are the same can be stored in the memory 106 of one or more computing devices 100 in the computing device cluster.
[0245] In some possible implementations, the memories 106 of one or more computing devices 100 in the computing device cluster may also store some instructions for executing the anomaly detection method respectively. In other words, the combination of one or more computing devices 100 may jointly execute the instructions for executing the anomaly detection method.
[0246] It should be noted that the memories 106 in different computing devices 100 in the computing device cluster may store different instructions for executing some functions of the anomaly detection device respectively. That is to say, the instructions stored in the memories 106 of different computing devices 100 may implement the functions of one or more modules in the receiving module 9001 and the processing module 9002.
[0247] In some possible implementations, one or more computing devices in the computing device cluster may be connected through a network. Among them, the network may be a wide area network or a local area network, etc. Figure 11 A possible implementation is shown. Please refer to Figure 11 , Figure 11 which is another structural schematic diagram of the computing device cluster provided by the embodiment of the present application. As Figure 11 shown, two computing devices 100A and 100B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the memory 106 in the computing device 100A stores instructions for executing the function of the processing module 9002. At the same time, the memory 106 in the computing device 100B stores instructions for executing the function of the receiving module 9001.
[0248] It should be understood that Figure 11 the function of the computing device 100A shown in
[0249] The embodiment of the present application also provides a computer program product containing instructions. The computer program product may be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the anomaly detection method.
[0250] Embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions that direct the computing device to execute the anomaly detection method, or direct the computing device to execute the anomaly detection method.
[0251] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0252] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0253] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0254] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0255] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
Claims
1. An anomaly detection method, characterized in that, comprising: obtaining first information from a client, where the first information is used to identify the identity information of the client; inputting the first information into a first model set to obtain an anomaly detection result of the access behavior of the client, where the first model set includes a first model and a second model, and the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
2. The method according to claim 1, characterized in that, both the first model and the second model include a first parameter, where the first parameter is used to indicate the degree of coincidence with historical model data, and the magnitude of the first parameter is directly proportional to the degree of coincidence with the historical model data. The first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1; inputting the first information into the first model set to obtain an anomaly detection result of the access behavior of the client includes: inputting the first information into the first model to obtain a first detection result; inputting the first detection result into the second model to obtain a second detection result; determining the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
3. The method according to claim 1 or 2, characterized in that, both the first model and the second model include a second parameter, where the second parameter is used to indicate the degree of interference of spikes, and the magnitude of the second parameter is inversely proportional to the degree of interference of the spikes. The second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1; inputting the first information into the first model set to obtain an anomaly detection result of the access behavior of the client includes: inputting the first information into the first model to obtain a first detection result; inputting the first detection result into the second model to obtain a second detection result; determining the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
4. The method according to claim 2 or 3, characterized in that, determining the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result includes: when the first detection result is greater than the second detection result, determining that the access behavior of the client is abnormal; when the first detection result is less than or equal to the second detection result, determining that the access behavior of the client is normal.
5. The method according to any one of claims 1 to 4, characterized in that, the first information includes Secure Transport Layer Protocol (TLS) fingerprint information.
6. The method according to any one of claims 1 to 5, where the first information includes mapping information between TLS fingerprint information and histogram bins.
7. The method according to any one of claims 1 to 4, characterized in that, the first information includes canvas fingerprint information.
8. The method according to any one of claims 1 to 7, characterized in that, The first model set further includes a third model, where the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
9. An anomaly detection device, characterized in that, it includes: A receiving module, including obtaining first information from a client, where the first information is used to identify the identity information of the client; A processing module, configured to input the first information into a first model set to obtain an anomaly detection result of the access behavior of the client, where the first model set includes a first model and a second model, and the input of the second model includes the output of the first model, or the output of the second model includes the input of the first model.
10. The device according to claim 9, characterized in that, Both the first model and the second model include a first parameter, where the first parameter is used to indicate the degree of coincidence with historical model data, and the magnitude of the first parameter is directly proportional to the degree of coincidence with the historical model data. The first parameter of the first model is less than the first parameter of the second model, and the value range of the first parameter is between 0 and 1; The processing module is further configured to: Input the first information into the first model to obtain a first detection result; Input the first detection result into the second model to obtain a second detection result; Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
11. The device according to claim 9 or 10, characterized in that, Both the first model and the second model include a second parameter, where the second parameter is used to indicate the degree of interference of burrs, and the magnitude of the second parameter is inversely proportional to the degree of interference of the burrs. The second parameter of the first model is greater than the second parameter of the second model, and the value range of the second parameter is between 0 and 1; The processing module is further configured to: Input the first information into the first model to obtain a first detection result; Input the first detection result into the second model to obtain a second detection result; Determine the anomaly detection result according to the magnitude relationship between the first detection result and the second detection result.
12. The device according to claim 10 or 11, characterized in that, The processing module is further configured to: When the first detection result is greater than the second detection result, determine that the access behavior of the client is abnormal; When the first detection result is less than or equal to the second detection result, determine that the access behavior of the client is normal.
13. The device according to any one of claims 9 to 12, characterized in that, The first information includes Transport Layer Security (TLS) fingerprint information.
14. The device according to any one of claims 9 to 13, where the first information includes mapping information between TLS fingerprint information and histogram bins.
15. The device according to any one of claims 9 to 12, characterized in that, The first information includes canvas fingerprint information.
16. The device according to any one of claims 9 to 15, characterized in that, The first model set further includes a third model, and the input of the third model includes the output of the second model, or the input of the third model includes the output of the first model.
17. A computing device cluster characterized in that it includes at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 8.
18. A computer program product containing instructions characterized in that when the instructions are run by a computing device cluster, the computing device cluster is caused to execute the method according to any one of claims 1 to 8.
19. A computer-readable storage medium characterized in that it includes computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 8.