Web application firewall security defense method and system

By building a multimodal deep neural network attack detection model and triggering a multi-level deep defense mechanism, the problem that existing web application firewalls are difficult to cope with new and unknown attacks is solved, and more efficient and flexible network security protection is achieved.

CN120074950AActive Publication Date: 2025-05-30NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD +1

Patent Information

Application Number
CN202510512814.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-05-30
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

Existing web application firewalls are difficult to effectively deal with new and unknown attacks, and lack multi-level and in-depth defense integration, resulting in poor defense effects.

Method used

By collecting and preprocessing network traffic data in real time, a multi-modal deep neural network attack detection model is built, attack behavior is identified, and attack behavior maps are automatically generated, multi-level deep defense mechanisms are triggered, model parameters are updated in real time, and model online learning and version management are realized.

Benefits of technology

It improves the intelligence level of network security protection, enhances the flexibility and adaptability of network security defense, can continuously and effectively deal with changing network threats, and provide more comprehensive and reliable network security guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074950A_ABST
    Figure CN120074950A_ABST
Patent Text Reader

Abstract

The invention discloses a Web application firewall security defense method and system, and belongs to the technical field of network security, and the method specifically comprises the steps: collecting and preprocessing network flow data in real time, constructing standardized data input, and training a multi-modal deep neural network attack detection model to recognize attack behaviors in a network; in the real-time detection process, the model outputs an attack type and a probability, and when an attack is detected, the firewall automatically generates an attack behavior graph, triggers a multi-level depth defense mechanism and feeds back a result to the model management module; and the model management module updates model parameters in real time through online learning, realizes version management, and performs model optimization in combination with a rapid rollback mode, thereby improving the network security protection capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and specifically relates to a Web application firewall security defense method and system. Background Art

[0002] With the rapid development of the Internet, Web applications have become an important tool for enterprise and individual users. However, Web applications are also facing more and more security threats. Traditional Web Application Firewalls (WAFs) mainly defend against attacks through rule matching and signature detection. However, this method has the following problems: The attack means are constantly evolving, and it is difficult to update the rule base in a timely manner, resulting in poor defense effects; the false alarm rate is high, and rule matching is prone to false alarms, affecting the access experience of normal users; it is difficult to detect and defend against new or unknown attacks; in addition, existing WAF technologies lack the integration of multi-level security protection and cannot achieve the effect of in-depth defense. Therefore, there is an urgent need for a multi-level and in-depth defense Web application firewall security defense method to improve the security of Web applications in the cloud environment.

[0003] As disclosed in the Chinese patent with the authorization announcement number CN114205073B, a password reverse firewall and its security defense method are provided. The password reverse firewall includes a first password reverse firewall and a second password reverse firewall. Each password reverse firewall is used to process messages transmitted between an entity and external information. The method includes the following steps: extracting a random number from the first public key to obtain a first random number; performing public key re-randomization processing on the first public key according to the first random number to obtain a second public key; extracting a random number from the first ciphertext to obtain a second random number, and performing ciphertext re-randomization processing on the first ciphertext according to the second random number to obtain a second ciphertext; processing the second ciphertext according to the first random number to obtain a third ciphertext. Thereby, the number of random numbers generated during the operation of the password reverse firewall is effectively reduced, the dependence on a trusted random source is reduced, and the feasibility is improved.

[0004] The above existing technologies have the following problems: They focus on static cryptographic processing and may be difficult to effectively cope with newly emerging attack means; they lack corresponding mechanisms to cope with changes in the security environment and require more frequent manual updates and maintenance; they rely on the password reverse firewall itself for defense and lack the flexibility of multi-level and in-depth defense. Summary of the Invention

[0005] In view of the deficiencies of the prior art, the present invention proposes a Web application firewall security defense method and system. By collecting and preprocessing network traffic data in real time, constructing standardized data inputs, and training a multi-modal deep neural network attack detection model to identify attack behaviors in the network; during real-time detection, the model outputs the attack type and probability. When an attack is detected, the firewall automatically generates an attack behavior graph, triggers a multi-level in-depth defense mechanism, and feeds back the results to the model management module; the model management module updates the model parameters in real time through online learning, implements version management, and combines a fast rollback method for model optimization, thereby enhancing the network security protection ability.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A Web application firewall security defense method, comprising:

[0008] Collecting network traffic data in real time through a Web application firewall, and constructing a multi-modal deep neural network attack detection model based on the network traffic data;

[0009] Inputting the preprocessed standardized network traffic data in real time into the multi-modal deep neural network attack detection model, and outputting the attack type and attack probability;

[0010] When an attack behavior is detected, triggering a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluating the execution result of the multi-level in-depth defense mechanism;

[0011] Updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism, and implementing a model deployment strategy based on fast version rollback.

[0012] Specifically, the specific process of constructing the multi-modal deep neural network attack detection model includes:

[0013] A1: Collecting network traffic data in real time through a Web application firewall and performing preprocessing to obtain preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic;

[0014] A2: Separating the preprocessed standardized network traffic data according to the modal type to obtain network traffic data of different modalities;

[0015] A3: For the normal traffic data of each modality, generating adversarial samples by adding an adaptive perturbation in the gradient direction of the loss function with respect to the normal traffic and combining a random perturbation term;

[0016] A4: Merge network traffic data of different modalities and the generated adversarial samples to obtain an enhanced training dataset;

[0017] A5: Load the neural network model, set the cross-entropy loss function and optimizer, input the enhanced training dataset into the pre-loaded neural network model, and adjust the parameters of the neural network model through the backpropagation algorithm to obtain a trained multi-modal deep neural network attack detection model.

[0018] Specifically, inputting the real-time preprocessed standardized network traffic data into the multi-modal deep neural network attack detection model and outputting the attack type and attack probability includes:

[0019] B1: Obtain the real-time preprocessed standardized network traffic data and load the trained multi-modal deep neural network attack detection model;

[0020] B2: Input the real-time preprocessed standardized network traffic data into the trained multi-modal deep neural network attack detection model for inference, and calculate the probability of each attack category;

[0021] B3: Set the attack threshold;

[0022] If the probability of the attack category is greater than the threshold, it is determined as attack traffic;

[0023] If the probability of the attack category is less than or equal to the threshold, it is determined as normal traffic;

[0024] B4: Select the category corresponding to the maximum probability as the attack type and output the probability of the corresponding attack category.

[0025] Specifically, when an attack behavior is detected, trigger a multi-level in-depth defense mechanism according to the attack type and the attack behavior graph pre-constructed by the Web application firewall, and evaluate the execution result of the multi-level in-depth defense mechanism, including:

[0026] C1: Obtain attack behavior information based on the output result of the multi-modal deep neural network attack detection model;

[0027] C2: Extract attack behavior characteristics according to the attack behavior information and organize the extracted attack behavior characteristics into structured data; the attack behavior characteristics include the attack source, attack target, attack time, attack type, and attack frequency;

[0028] C3: Define each extracted attack behavior characteristic as a node in the graph and define the relationship between nodes as an edge;

[0029] C4: Construct the defined node and edge set into a graph structure to form an attack behavior graph;

[0030] C5: In the attack behavior graph, use graph algorithms to analyze the relationships between attack behavior features, and combine community detection algorithms to divide the attack behavior graph into M subgraphs, with each subgraph corresponding to an attack pattern;

[0031] C6: Obtain the attack patterns based on the attack patterns divided in step C5 and the characteristics of the attack behavior graph;

[0032] For frequent attacks from a single attacking source IP, identify the attack behavior by analyzing the attacking source IP or attack frequency, and directly trigger the corresponding defense mechanisms, including IP banning and traffic cleaning;

[0033] For multi-stage attack behaviors, analyze by combining the attacking source IP, attacking target IP, and attack type to identify the attack behavior and trigger a multi-level in-depth defense mechanism;

[0034] C7: During the process of triggering the multi-level in-depth defense mechanism in step C6, adjust the preset protection strategy in real time according to the dynamic changes of the attack behavior graph; the protection strategy includes, for high-frequency attack nodes, giving priority to triggering the defense mechanism; for low-frequency attack nodes, delaying the triggering of the defense mechanism;

[0035] C8: Define the state of the protection process, and dynamically adjust the analysis and protection strategy of the attack behavior graph according to the state of the protection process;

[0036] C9: Update the attack behavior graph according to the execution results of the multi-level in-depth defense mechanism;

[0037] If an attacking source IP is successfully banned, remove it from the graph;

[0038] If the frequency of an attack type decreases, adjust the weight of its node;

[0039] C10: Feed the updated attack behavior graph back to the multi-modal deep neural network attack detection model, and optimize the parameters of the multi-modal deep neural network attack detection model and the multi-level in-depth defense mechanism according to the feedback results.

[0040] Specifically, the parameters of the multi-modal deep neural network attack detection model are updated in real time according to the execution results of the defense mechanism, and a model deployment strategy based on fast version rollback is implemented, including:

[0041] D1: After executing the multi-level in-depth defense mechanism, collect the quantitative data of the defense effect, and store the collected quantitative data of the defense effect in the defense effect database; the quantitative data of the defense effect includes the attack blocking rate, false alarm rate, and response time;

[0042] D2: Calculate the loss function value of the multi-modal deep neural network attack detection model based on the defense effect quantification data and in combination with the prediction output of the multi-modal deep neural network attack detection model;

[0043] D3: Update the parameters of the multi-modal deep neural network attack detection model using the gradient descent method. After each update of the model parameters, generate a new model version, record the update time, the updated parameter values, and the defense effect evaluation results. At the same time, store the new version model in the model repository.

[0044] Specifically, the method of updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism and implementing a model deployment strategy based on fast version rollback further includes:

[0045] D4: Monitor the new version model in real time, read the defense effect quantification data of the new version model from the defense effect database, and compare the defense effect quantification data of the new version model with the defense effect quantification data of the multi-modal deep neural network attack detection model before the update;

[0046] If the attack blocking rate of the new version model is less than the attack blocking rate of the multi-modal deep neural network attack detection model before the update or the false alarm rate of the new version model is greater than the false alarm rate of the multi-modal deep neural network attack detection model before the update, trigger the fast rollback mechanism;

[0047] D5: Select the multi-modal deep neural network attack detection model with the shortest distance from the current time and an attack blocking rate higher than the current new version model in the model repository as the rollback target model;

[0048] D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the defense effect quantification data before and after the rollback.

[0049] Specifically, the network traffic data includes HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters; the multi-level in-depth defense mechanism includes blocking attack requests, flow limiting control, dynamic rule generation, and alarm and logging.

[0050] A Web application firewall security defense system, including: a data collection module, a model construction module, an attack detection module, a defense module, and a model management module;

[0051] The data collection module is used to collect network traffic data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network traffic data;

[0052] The model construction module is used to construct and train a multi-modal deep neural network attack detection model;

[0053] The attack detection module is used to input the preprocessed real-time standardized network traffic data into the trained multi-modal deep neural network attack detection model, determine whether there is an attack behavior, and output the attack type and probability;

[0054] The defense module is used to automatically construct an attack behavior graph and trigger a multi-level in-depth defense mechanism when an attack is detected;

[0055] The model management module is used to update the parameters of the multi-modal deep neural network attack detection model in real time through an online learning method, and perform version management and fast rollback.

[0056] Specifically, the defense module includes: a graph construction unit, a defense mechanism trigger unit, and an execution result feedback unit;

[0057] The graph construction unit is used to construct a graph according to the attack type and characteristics, and visualize the attack path;

[0058] The defense mechanism trigger unit is used to trigger the corresponding defense mechanism according to the attack type and the graph;

[0059] The execution result feedback unit is used to feedback the execution result of the defense mechanism to the model update module.

[0060] Compared with the prior art, the beneficial effects of the present invention are:

[0061] 1. The present invention proposes a Web application firewall security defense system, and has optimized and improved the architecture, operation steps and processes. The system has the advantages of simple process, low investment and operation costs, and low production work costs.

[0062] 2. The present invention proposes a Web application firewall security defense method. By collecting network traffic data in real time and using an improved adversarial sample generation algorithm to construct a multi-modal deep neural network attack detection model, this method can efficiently and accurately identify attack behaviors in the network, including attack types and attack probabilities, thereby improving the intelligent level of network security protection; it also realizes the automatic trigger and feedback of a multi-level in-depth defense mechanism, as well as the online update and version management of model parameters, which not only enhances the flexibility and adaptability of network security defense, but also ensures that the attack detection model can continuously and effectively respond to changing network threats, providing a more comprehensive and reliable guarantee for network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a schematic diagram of the Web application firewall security defense method of the present invention;

[0064] Figure 2 This is the principle flow chart of the security defense method of the Web application firewall of the present invention;

[0065] Figure 3 This is the flow chart for model selection of the security defense method of the Web application firewall of the present invention;

[0066] Figure 4 This is the architecture diagram of the security defense system of the Web application firewall of the present invention. Detailed implementation manners

[0067] Embodiment 1

[0068] Please refer to Figure 1 and Figure 2 A Web application firewall security defense method provided by the present invention, the method includes steps S1 to S4, and the specific steps are as follows:

[0069] S1: Real-time collect network traffic data through the Web application firewall, and construct a multi-modal deep neural network attack detection model according to the network traffic data;

[0070] The network traffic data includes HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters.

[0071] Among them, HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters can be specifically summarized into two categories: normal traffic and attack traffic, and attack traffic usually appears in the form of abnormal requests.

[0072] Furthermore, the specific steps for collecting network traffic data include:

[0073] (1) Real-time capture network traffic data through the Web application firewall;

[0074] (2) Extract features from the real-time captured network traffic data to obtain network traffic feature data; the network traffic feature data includes user behavior features, request frequencies, request body sizes, response times, request path features, and request parameter features;

[0075] Among them, the request frequency refers to the number of requests per unit time;

[0076] The request body size includes the size of the request body or the response body;

[0077] The response time includes the time difference from request to response;

[0078] The request path features include the length, depth of the URL path, and whether it contains sensitive paths;

[0079] The request parameter features include the number of parameters, the length of parameter values, and whether special characters are included;

[0080] The user behavior features include session duration and statistical features of the operation sequence;

[0081] (3)Use an automated feature selection algorithm to screen the extracted features to obtain network attack features;

[0082] (4)Perform standardization processing on the network attack features to obtain the preprocessed standardized network traffic data, and store it in the database.

[0083] Furthermore, the specific steps of using an automated feature selection algorithm to screen the extracted features include:

[0084] 1)Obtain network traffic feature data and historical attack data;

[0085] 2)For each feature, calculate its mutual information with the historical attack data;

[0086] 3)Sort all features according to the mutual information values, and select the top k features with the highest mutual information values as network attack features.

[0087] S2: Input the preprocessed standardized network traffic data in real time into a multi-modal deep neural network attack detection model, and output the attack type and attack probability;

[0088] S3: When an attack behavior is detected, trigger a multi-level in-depth defense mechanism according to the attack type and the attack behavior graph pre-built by the Web application firewall, and evaluate the execution result of the multi-level in-depth defense mechanism;

[0089] The multi-level in-depth defense mechanism includes blocking attack requests, traffic limiting control, dynamic rule generation, alarm and logging.

[0090] S4: Update the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism, and implement a model deployment strategy based on fast version rollback.

[0091] The specific process of constructing the multi-modal deep neural network attack detection model includes:

[0092] A1: Real-time collect network traffic data through the Web application firewall and perform preprocessing to obtain the preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic;

[0093] A2: Separate the preprocessed standardized network traffic data according to the modal type to obtain network traffic data of different modalities;

[0094] Among them, the process of separating according to the modal type includes:

[0095] Obtain a standardized network traffic dataset with labels;

[0096] Separate the data according to modal types, such as numerical features, sequence features, and text features;

[0097] Obtain network traffic datasets of different modalities.

[0098] A3: For the normal traffic data of each modality, by adding an adaptive perturbation in the gradient direction of the loss function L with respect to the normal traffic x , combined with a random perturbation term, generate adversarial samples , and satisfy , where represents the adaptive perturbation weight function, represents the gradient of the loss function L with respect to the normal traffic x, represents the sign function of represents the random perturbation weight function, represents the random perturbation vector, and follows a Gaussian distribution, e represents the exponential, k represents the slope parameter, represents the norm of the normal traffic x, represents the threshold parameter, represents the maximum value function;

[0099] A4: Combine the network traffic data of different modalities and the generated adversarial samples to obtain an enhanced training dataset;

[0100] A5: Load the neural network model, set the cross-entropy loss function and the optimizer, input the enhanced training dataset into the pre-loaded neural network model, and adjust the parameters of the neural network model through the backpropagation algorithm to obtain a trained multi-modal deep neural network attack detection model. Among them, the neural network model is the prior art content in this field and is not the creative solution of this application, so it will not be elaborated here.

[0101] The specific steps of the said S2 include:

[0102] B1: Obtain the standardized network traffic data after real-time preprocessing and load the trained multi-modal deep neural network attack detection model;

[0103] B2: Input the standardized network traffic data after real-time preprocessing into the trained multi-modal deep neural network attack detection model for inference, and calculate the probability of each attack category;

[0104] Furthermore, the specific steps of B2 include:

[0105] (1) Taking the real-time preprocessed standardized network traffic data as input and inputting it into the trained multi-modal deep neural network attack detection model;

[0106] (2) In each layer of the convolutional layer, fully connected layer, and attention mechanism layer of the multi-modal deep neural network, calculating the output value through forward propagation according to the input data and model parameters. The forward propagation calculation formula is the prior art content in the field and is not the creative solution of this application, so it will not be elaborated here;

[0107] (3) Fusing the features of different modalities and using the attention mechanism to dynamically allocate the weights of different modality features to ensure that the key features contribute more to the final output;

[0108] (4) In the output layer, calculating the score of each attack category , and using the Softmax function to convert the score into a probability score. The formula is: , where represents the probability that the input belongs to the j-th attack category, y represents the attack category, represents the real-time preprocessed standardized network traffic data, N represents the total number of attack categories, represents the exponential function;

[0109] (5) According to the output of the Softmax function, obtaining the probability of each attack category , and selecting the attack category with the highest probability as the final prediction result;

[0110] (6) Outputting the probability of each attack category and the final attack category prediction result.

[0111] B3: Setting the attack threshold;

[0112] If the probability of the attack category is greater than the threshold, it is determined as attack traffic;

[0113] If the probability of the attack category is less than or equal to the threshold, it is determined as normal traffic;

[0114] B4: Selecting the category corresponding to the maximum probability as the attack type and outputting the probability of the corresponding attack category.

[0115] When an attack behavior is detected, triggering a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluating the execution result of the multi-level in-depth defense mechanism, including:

[0116] C1: Obtain attack behavior information based on the output result of the multi-modal deep neural network attack detection model;

[0117] Further, the specific process of obtaining attack behavior information according to the output result of the multi-modal deep neural network attack detection model includes:

[0118] Obtain the output result of the multi-modal deep neural network attack detection model and the probability of each attack category;

[0119] Determine the most likely attack category according to the probability distribution, and extract the attack behavior information;

[0120] Store the attack behavior information in the database.

[0121] C2: Extract attack behavior features according to the attack behavior information, and organize the extracted attack behavior features into structured data; the attack behavior features include attack source, attack target, attack time, attack type, attack frequency;

[0122] Further, the specific steps of C2 include:

[0123] (1) Attack behavior information parsing: Extract key fields from the attack behavior information, including attack source, attack target, attack time, attack type, attack frequency, and organize the extracted fields into structured data for subsequent analysis;

[0124] (2) Attack source feature extraction: Extract the attack source IP address, and count the number of attacks of each attack source to obtain the attack frequency of the attack source, that is, the number of attacks per unit time;

[0125] (3) Attack target feature extraction: Extract the attack target IP address, and count the number of times each attack target is attacked to obtain the attack frequency of the attack target, that is, the number of times attacked per unit time;

[0126] (4) Attack time feature extraction: Extract the attack timestamp, and analyze the time distribution of the attacks, such as the peak period of the attacks, to obtain the time interval of the attacks, such as the time difference between two attacks;

[0127] (5) Attack type feature extraction: Extract the attack type, and count the number of occurrences of each attack type to obtain the distribution ratio of the attack types;

[0128] (6) Attack frequency feature extraction: Count the total number of attacks per unit time, and calculate the change trend of the attack frequency, such as the time series of the number of attacks;

[0129] (7) Store the extracted attack behavior features in the database for subsequent analysis and decision-making.

[0130] C3: Define each extracted attack behavior feature as a node in the graph, and define the relationship between nodes as an edge;

[0131] Exemplarily, being defined as a node in the graph includes:

[0132] Node 1: Attack source IP;

[0133] Node 2: Attack target IP;

[0134] Node 3: Attack time;

[0135] Node 4: Attack type;

[0136] Node 5: Attack frequency.

[0137] Exemplarily, defining the relationship between nodes as an edge includes:

[0138] Edge 1: Attack source IP → Attack target IP, indicating the attack behavior of the attack source on the attack target;

[0139] Edge 2: Attack source IP → Attack type, indicating the attack type initiated by the attack source;

[0140] Edge 3: Attack target IP → Attack time, indicating the attacks received by the attack target at different times;

[0141] Edge 4: Attack type → Attack frequency, indicating the occurrence frequency of a certain attack type.

[0142] C4: Construct the defined node and edge sets into a graph structure to form an attack behavior graph;

[0143] C5: In the attack behavior graph, use graph algorithms to analyze the relationships between attack behavior features, and combine community detection algorithms to divide the attack behavior graph into M subgraphs, with each subgraph corresponding to an attack pattern;

[0144] C6: Obtain the attack pattern based on the attack patterns divided in step C5 and the characteristics of the attack behavior graph;

[0145] For frequent attacks from a single attack source IP, identify the attack behavior by analyzing the attack source IP or attack frequency, and directly trigger the corresponding defense mechanisms, including IP banning and traffic cleaning;

[0146] For multi-stage attack behaviors, jointly analyze the attack source IP, attack target IP, and attack type to identify the attack behavior, and trigger a multi-level in-depth defense mechanism;

[0147] C7: During the process of triggering the multi - level in - depth defense mechanism in step C6, according to the dynamic changes of the attack behavior graph, the preset protection strategy is adjusted in real - time; the protection strategy includes: for high - frequency attack nodes, the defense mechanism is triggered preferentially; for low - frequency attack nodes, the triggering of the defense mechanism is delayed.

[0148] C8: Define the state of the protection process, and according to the state of the protection process, dynamically adjust the analysis of the attack behavior graph and the protection strategy.

[0149] Among them, the states of the protection process include:

[0150] Initial state: No attack is detected by the attack behavior graph.

[0151] Detection state: An attack is detected by the attack behavior graph, but the defense mechanism is not triggered.

[0152] Protection state: The defense mechanism is triggered by the attack behavior graph, and protection is in progress.

[0153] Completion state: The defense mechanism has completed its execution, and the attack has been successfully blocked.

[0154] C9: Update the attack behavior graph according to the execution results of the multi - level in - depth defense mechanism.

[0155] If an attack source IP is successfully blocked, it is removed from the graph.

[0156] If the frequency of an attack type decreases, adjust the weight of its node.

[0157] C10: Feed the updated attack behavior graph back to the multi - modal deep neural network attack detection model, and according to the feedback results, optimize the parameters of the multi - modal deep neural network attack detection model and the multi - level in - depth defense mechanism.

[0158] In summary, the attack behavior graph can effectively identify and protect various attack behaviors. A single node can handle simple attacks, while complex attacks require multiple nodes to be combined for analysis and protection. By optimizing the joint recognition strategy and dynamically adjusting the protection process, a protection effect with low load and high efficiency can be achieved. The whole process from attack behavior information acquisition to graph update and feedback forms a complete closed - loop logic.

[0159] Embodiment 2

[0160] Please refer to Figure 3 , the specific steps of S4 in this embodiment include:

[0161] D1: After implementing the multi-level in-depth defense mechanism, collect the quantitative data of the defense effect and store the collected quantitative data of the defense effect in the defense effect database; the quantitative data of the defense effect includes the attack blocking rate, false alarm rate, and response time.

[0162] D2: According to the quantitative data of the defense effect , combined with the prediction output of the multi-modal deep neural network attack detection model, calculate the loss function value of the multi-modal deep neural network attack detection model , where represents the output result of the multi-modal deep neural network attack detection model, represents the parameters of the multi-modal deep neural network attack detection model, including weights and biases, represents the i-th pre-processed and standardized network traffic data in real time, represents the regularization coefficient, and n represents the number of pre-processed and standardized network traffic data in real time;

[0163] D3: Use the gradient descent method to update the parameters of the multi-modal deep neural network attack detection model. After each update of the model parameters, generate a new model version, record the update time, the updated parameter values, and the defense effect evaluation results. At the same time, store the new version model in the model warehouse. Among them, the gradient descent method is the prior art content in this field and is not the creative solution of this application, so it will not be elaborated here;

[0164] In the present invention, the comprehensive evaluation formula for the defense effect is: , where , , represent the weight coefficients, ABR represents the attack blocking rate, FPR represents the false alarm rate, and RT represents the response time.

[0165] D4: Monitor the new version model in real time, read the quantitative data of the defense effect of the new version model from the defense effect database, and compare the quantitative data of the defense effect of the new version model with the quantitative data of the defense effect of the multi-modal deep neural network attack detection model before the update;

[0166] If the attack blocking rate of the new version model is less than the attack blocking rate of the multi-modal deep neural network attack detection model before the update or the false alarm rate of the new version model is greater than the false alarm rate of the multi-modal deep neural network attack detection model before the update, then trigger the fast rollback mechanism;

[0167] D5: Select the multi-modal deep neural network attack detection model with the shortest distance from the current time and an attack blocking rate higher than the current new version model in the model warehouse as the rollback target model;

[0168] D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the quantitative defense effect data before and after the rollback.

[0169] Embodiment 3

[0170] Please refer to Figure 4 , another embodiment provided by the present invention: a Web application firewall security defense system, including:

[0171] A data collection module, a model construction module, an attack detection module, a defense module, and a model management module;

[0172] The data collection module is used to collect network traffic data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network traffic data for subsequent modules to use;

[0173] The model construction module is used to construct and train a multi-modal deep neural network attack detection model, and improve the model robustness by combining adversarial sample generation technology;

[0174] The attack detection module is used to input the real-time preprocessed standardized network traffic data into the trained multi-modal deep neural network attack detection model, judge whether there is an attack behavior, and output the attack type and probability;

[0175] The defense module is used to automatically construct an attack behavior graph and trigger a multi-level in-depth defense mechanism when an attack is detected;

[0176] The model management module is used to update the parameters of the multi-modal deep neural network attack detection model in real time through an online learning method, and perform version management and fast rollback.

[0177] The data collection module includes: a data collection unit and a feature selection unit;

[0178] The data collection unit is used to collect network traffic data in real time through the Web application firewall;

[0179] The feature selection unit is used to perform feature selection using an automated feature selection algorithm to reduce redundant data.

[0180] The attack detection module includes: a real-time data input unit, an attack detection unit, and an output unit;

[0181] The real-time data input unit is used to receive the preprocessed standardized network traffic data;

[0182] The attack detection unit is used to judge whether there is an attack behavior through the trained multi-modal deep neural network attack detection model;

[0183] An output unit for outputting the attack type and probability.

[0184] The defense module includes: a graph construction unit, a defense mechanism trigger unit, and an execution result feedback unit;

[0185] The graph construction unit is used to construct a graph based on the attack type and characteristics and visualize the attack path;

[0186] The defense mechanism trigger unit is used to trigger the corresponding defense mechanism according to the attack type and the graph;

[0187] The execution result feedback unit is used to feedback the execution result of the defense mechanism to the model update module.

[0188] The model management module includes: an online learning unit, a version management unit, and a quick rollback unit;

[0189] The online learning unit is used to update the model parameters in real time to adapt to new attack patterns;

[0190] The version management unit is used to manage the model versions and record the update history;

[0191] The quick rollback unit is used to quickly roll back to a stable version when the model performance deteriorates.

[0192] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments without departing from the purpose and scope of the present invention, and these all fall within the protection scope of the present invention.

[0193] If the technical solution of the present disclosure involves personal information, before the product applying the technical solution of the present disclosure processes personal information, it has clearly informed the personal information processing rules and obtained the individual's autonomous consent. If the technical solution of the present disclosure involves sensitive personal information, before the product applying the technical solution of the present disclosure processes sensitive personal information, it has obtained the individual's separate consent and at the same time meets the requirement of "express consent". For example, at a personal information collection device such as a camera, a clear and prominent sign is set to inform that the personal information collection range has been entered and personal information will be collected. If an individual voluntarily enters the collection range, it is regarded as consenting to the collection of their personal information; or on the personal information processing device, when the personal information processing rules are informed by obvious signs / information, personal authorization is obtained through pop-up messages or by asking the individual to upload their personal information by themselves, etc.; among them, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.

Claims

1. A Web application firewall security defense method, characterized in that: include: Collect network traffic data in real time through a Web application firewall, and build a multimodal deep neural network attack detection model based on the network traffic data; Input the standardized network traffic data after real-time preprocessing into the multimodal deep neural network attack detection model, and output the attack type and attack probability; When an attack behavior is detected, a multi-level defense-in-depth mechanism is triggered according to the attack type and the attack behavior map pre-built by the Web application firewall, and the execution result of the multi-level defense-in-depth mechanism is evaluated; The parameters of the multimodal deep neural network attack detection model are updated in real time according to the execution results of the defense mechanism, and a model deployment strategy based on rapid version rollback is implemented.

2. The Web application firewall security defense method according to claim 1, characterized in that: The specific process of constructing the multimodal deep neural network attack detection model includes: A1: The network traffic data is collected in real time through the Web application firewall, and preprocessed to obtain the preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic; A2: Separate the preprocessed standardized network traffic data according to the modality type to obtain network traffic data of different modalities; A3: For the normal traffic data of each modality, an adaptive perturbation is added in the gradient direction of the loss function with respect to the normal traffic, combined with a random perturbation term, to generate adversarial samples; A4: Combine network traffic data of different modalities and generated adversarial samples to obtain an enhanced training dataset; A5: Load the neural network model, set the cross entropy loss function and optimizer, input the enhanced training data set into the pre-loaded neural network model, adjust the neural network model parameters through the back propagation algorithm, and obtain the trained multimodal deep neural network attack detection model.

3. The Web application firewall security defense method according to claim 2, characterized in that: The real-time preprocessed standardized network traffic data is input into the multimodal deep neural network attack detection model, and the attack type and attack probability are output, including: B1: Obtain the standardized network traffic data after real-time preprocessing and load the trained multimodal deep neural network attack detection model; B2: Input the real-time preprocessed standardized network traffic data into the trained multimodal deep neural network attack detection model for inference and calculate the probability of each attack category; B3: Set the attack threshold; If the probability of the attack category is greater than the threshold, it is determined to be attack traffic; If the probability of the attack category is less than or equal to the threshold, it is judged as normal traffic; B4: Select the category corresponding to the maximum probability as the attack type, and output the probability of the corresponding attack category.

4. The Web application firewall security defense method according to claim 3, characterized in that: When an attack behavior is detected, a multi-level defense-in-depth mechanism is triggered according to the attack type and the attack behavior map pre-built by the Web application firewall, and the execution result of the multi-level defense-in-depth mechanism is evaluated, including: C1: Obtain attack behavior information based on the output results of the multimodal deep neural network attack detection model; C2: Extract attack behavior features based on attack behavior information, and organize the extracted attack behavior features into structured data; the attack behavior features include attack source, attack target, attack time, attack type, and attack frequency; C3: Define each extracted attack behavior feature as a node in the graph, and define the relationship between nodes as edges; C4: Construct the defined node and edge sets into a graph structure to form an attack behavior graph; C5: In the attack behavior graph, use graph algorithms to analyze the relationship between attack behavior features, and combine community detection algorithms to divide the attack behavior graph into M subgraphs, each of which corresponds to an attack mode; C6: Obtain the attack mode according to the characteristics of the attack mode and attack behavior map divided in step C5; For frequent attacks from a single attack source IP, we can identify the attack behavior by analyzing the attack source IP or attack frequency, and directly trigger the corresponding defense mechanism, including IP blocking and traffic cleaning. For multi-stage attacks, we analyze the attack source IP, target IP, and attack type to identify the attack and trigger a multi-layered defense-in-depth mechanism. C7: In the process of triggering the multi-level defense-in-depth mechanism in step C6, the preset protection strategy is adjusted in real time according to the dynamic changes of the attack behavior map; the protection strategy includes triggering the defense mechanism first for high-frequency attack nodes and delaying the triggering of the defense mechanism for low-frequency attack nodes; C8: Define the status of the protection process and dynamically adjust the attack behavior graph analysis and protection strategy based on the status of the protection process; C9: Update the attack behavior map based on the execution results of the multi-level in-depth defense mechanism; If an attack source IP is successfully blocked, it will be removed from the graph; If the frequency of an attack type decreases, adjust the weight of its node; C10: Feedback the updated attack behavior graph to the multimodal deep neural network attack detection model, and optimize the multimodal deep neural network attack detection model parameters and multi-level in-depth defense mechanism based on the feedback results.

5. The Web application firewall security defense method according to claim 4, characterized in that: The real-time updating of multimodal deep neural network attack detection model parameters according to the execution results of the defense mechanism and the implementation of a model deployment strategy based on rapid version rollback include: D1: After executing the multi-level defense-in-depth mechanism, collect defense effect quantitative data, and store the collected defense effect quantitative data in the defense effect database; the defense effect quantitative data includes attack blocking rate, false alarm rate and response time; D2: Calculate the loss function value of the multimodal deep neural network attack detection model based on the defense effect quantification data and the predicted output of the multimodal deep neural network attack detection model; D3: Use the gradient descent method to update the parameters of the multimodal deep neural network attack detection model. After each model parameter update, generate a new model version and record the update time, updated parameter values ​​and defense effect evaluation results. At the same time, store the new version model in the model warehouse.

6. The Web application firewall security defense method according to claim 5, characterized in that: The method of updating the multimodal deep neural network attack detection model parameters in real time according to the execution results of the defense mechanism and implementing a model deployment strategy based on rapid version rollback also includes: D4: Monitor the new version model in real time, read the defense effect quantitative data of the new version model from the defense effect database, and compare the defense effect quantitative data of the new version model with the defense effect quantitative data of the multimodal deep neural network attack detection model before the update; If the attack blocking rate of the new version model is lower than the attack blocking rate of the multimodal deep neural network attack detection model before the update, or the false alarm rate of the new version model is higher than the false alarm rate of the multimodal deep neural network attack detection model before the update, the rapid rollback mechanism is triggered; D5: Select the multimodal deep neural network attack detection model with the shortest time from the current version and a higher attack blocking rate than the current new version model from the model repository as the rollback target model; D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the quantitative data of the defense effect before and after the rollback.

7. The Web application firewall security defense method according to claim 6, characterized in that: The network traffic data includes HTTP requests, response data, user behavior data, IP address, request frequency, request time, request path, and request parameters; the multi-level in-depth defense mechanism includes blocking attack requests, current limiting control, dynamic rule generation, alarms, and log records.

8. A Web application firewall security defense system, which is used to implement the Web application firewall security defense method according to any one of claims 1 to 7, characterized in that: include: Data collection module, model building module, attack detection module, defense module, model management module; The data collection module is used to collect network flow data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network flow data; The model building module is used to build and train a multimodal deep neural network attack detection model; The attack detection module is used to input the standardized network traffic data after real-time preprocessing into the trained multimodal deep neural network attack detection model, determine whether there is an attack behavior, and output the attack type and probability; The defense module is used to automatically build an attack behavior map and trigger a multi-level defense-in-depth mechanism when an attack is detected; The model management module is used to update the multimodal deep neural network attack detection model parameters in real time through an online learning method, and to perform version management and rapid rollback.

9. The Web application firewall security defense system according to claim 8, characterized in that: The defense module includes: a graph construction unit, a defense mechanism triggering unit, and an execution result feedback unit; The graph construction unit is used to construct a graph according to the attack type and characteristics to visualize the attack path; The defense mechanism triggering unit is used to trigger the corresponding defense mechanism according to the attack type and the graph; The execution result feedback unit is used to feed back the execution result of the defense mechanism to the model updating module.

Citation Information

Patent Citations

  • Password Reverse Firewall and its Security Defense Methods

    CN114205073B

  • Deep learning backdoor defense method based on model pruning and reverse engineering

    CN113204745A

  • Intelligent sensing network security protection system

    CN118827161A

  • Intrusion detection and response method and system of satellite internet target range

    CN119155101A

  • Commercial credit evaluation and supervision method based on multi-modal coevolution algorithm

    CN119250963A

Cited By

  • Industrial Internet of Things LDoS attack intelligent detection method and device

    CN120639415A

  • Power grid network attack chain risk assessment and threat situation awareness blocking method

    CN120750651A

  • Large model cue word attack detection method and system, terminal and medium

    CN121217372A

  • Dynamic network security defense method and system for real-time network state adaptation

    CN121239489A