Web Application Firewall Security Defense Method and System

By building a multimodal deep neural network attack detection model and real-time update mechanism, the problem of poor defense of existing web applications is solved, efficient and flexible multi-level in-depth defense is achieved, and network security protection capabilities are improved.

CN120074950BActive Publication Date: 2025-07-11NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510512814.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-11
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

The existing web application firewall is difficult to effectively deal with new attacks, lacks the flexibility of multi-level and in-depth defense, and the untimely update of the rule base leads to poor defense effects, high false alarm rates, and in-depth defense cannot be achieved.

Method used

By collecting network traffic data in real time, a multi-modal deep neural network attack detection model is built, attack behavior is detected in real time and multi-level deep defense mechanism is triggered, and model parameters are updated in combination with online learning and fast rollback mechanisms to achieve adversarial sample generation and model optimization.

Benefits of technology

It improves the intelligence level and flexibility of network security protection, can efficiently identify attack behaviors, achieve multi-level in-depth defense, continuously adapt to network threats, reduce false alarm rates and improve defense effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074950B_ABST
    Figure CN120074950B_ABST
Patent Text Reader

Abstract

The present invention discloses a Web application firewall security defense method and system, belonging to the field of network security technology, which specifically includes: collecting and preprocessing network traffic data in real time, constructing a standardized data input, and training a multi-modal deep neural network attack detection model to identify attack behaviors in the network; during the real-time detection process, the model outputs the attack type and probability. When an attack is detected, the firewall automatically generates an attack behavior map, triggers a multi-level in-depth defense mechanism, and feeds the results back to the model management module; the model management module updates the model parameters in real time through online learning, realizes version management, and combines a fast rollback method for model optimization, improving the network security protection ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and more specifically, it is a Web application firewall security defense method and system. Background Art

[0002] With the rapid development of the Internet, Web applications have become an important tool for enterprise and individual users. However, Web applications are also facing more and more security threats. Traditional Web Application Firewalls (WAFs) mainly defend against attacks through rule matching and signature detection. However, this method has the following problems: Attack methods are constantly evolving, and it is difficult to update the rule base in a timely manner, resulting in poor defense effects; The false positive rate is high, and rule matching is prone to false positives, affecting the access experience of normal users; It is difficult to detect and defend against new or unknown attacks; In addition, existing WAF technologies lack the integration of multi-level security protection and cannot achieve the effect of in-depth defense. Therefore, there is an urgent need for a multi-level and in-depth defense Web application firewall security defense method to improve the security of Web applications in the cloud environment.

[0003] As disclosed in the Chinese patent with the authorization announcement number CN114205073B, a password reverse firewall and its security defense method are provided. The password reverse firewall includes a first password reverse firewall and a second password reverse firewall. Each password reverse firewall is used to process messages transmitted between an entity and external information. The method includes the following steps: Extracting a random number from the first public key to obtain a first random number; Performing public key re-randomization processing on the first public key according to the first random number to obtain a second public key; Extracting a random number from the first ciphertext to obtain a second random number, and performing ciphertext re-randomization processing on the first ciphertext according to the second random number to obtain a second ciphertext; Processing the second ciphertext according to the first random number to obtain a third ciphertext. Thereby, the number of random numbers generated during the operation of the password reverse firewall is effectively reduced, the dependence on a trusted random source is reduced, and the feasibility is improved.

[0004] The above existing technologies have the following problems: They focus on static cryptographic processing and may be difficult to effectively cope with newly emerging attack methods; They lack corresponding mechanisms to cope with changes in the security environment and require more frequent manual updates and maintenance; They rely on the password reverse firewall itself for defense and lack the flexibility of multi-level and in-depth defense. Summary of the Invention

[0005] In view of the deficiencies of the prior art, the present invention proposes a Web application firewall security defense method and system. By collecting and preprocessing network traffic data in real time, constructing standardized data inputs, and training a multi-modal deep neural network attack detection model to identify attack behaviors in the network; during real-time detection, the model outputs the attack type and probability. When an attack is detected, the firewall automatically generates an attack behavior graph, triggers a multi-level in-depth defense mechanism, and feeds back the results to the model management module; the model management module updates the model parameters in real time through online learning, realizes version management, and combines a fast rollback method for model optimization, improving the network security protection ability.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A Web application firewall security defense method, including:

[0008] Collecting network traffic data in real time through a Web application firewall, and constructing a multi-modal deep neural network attack detection model based on the network traffic data;

[0009] Inputting the preprocessed standardized network traffic data in real time into the multi-modal deep neural network attack detection model, and outputting the attack type and attack probability;

[0010] When an attack behavior is detected, triggering a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluating the execution result of the multi-level in-depth defense mechanism;

[0011] Updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism, and implementing a model deployment strategy based on fast version rollback.

[0012] Specifically, the specific process of constructing the multi-modal deep neural network attack detection model includes:

[0013] A1: Collecting network traffic data in real time through a Web application firewall and performing preprocessing to obtain preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic;

[0014] A2: Separating the preprocessed standardized network traffic data according to the modal type to obtain network traffic data of different modalities;

[0015] A3: For the normal traffic data of each modality, generating adversarial samples by adding an adaptive perturbation in the gradient direction of the loss function with respect to the normal traffic and combining a random perturbation term;

[0016] A4: Combine network traffic data of different modalities and the generated adversarial samples to obtain an enhanced training dataset;

[0017] A5: Load the neural network model, set the cross-entropy loss function and the optimizer, input the enhanced training dataset into the pre-loaded neural network model, and adjust the parameters of the neural network model through the backpropagation algorithm to obtain a trained multi-modal deep neural network attack detection model.

[0018] Specifically, inputting the real-time preprocessed standardized network traffic data into the multi-modal deep neural network attack detection model and outputting the attack type and attack probability includes:

[0019] B1: Obtain the real-time preprocessed standardized network traffic data and load the trained multi-modal deep neural network attack detection model;

[0020] B2: Input the real-time preprocessed standardized network traffic data into the trained multi-modal deep neural network attack detection model for inference, and calculate the probability of each attack category;

[0021] B3: Set the attack threshold;

[0022] If the probability of the attack category is greater than the threshold, it is determined as attack traffic;

[0023] If the probability of the attack category is less than or equal to the threshold, it is determined as normal traffic;

[0024] B4: Select the category corresponding to the maximum probability as the attack type and output the probability of the corresponding attack category.

[0025] Specifically, when an attack behavior is detected, trigger a multi-level in-depth defense mechanism according to the attack type and the attack behavior graph pre-built by the Web application firewall, and evaluate the execution result of the multi-level in-depth defense mechanism, including:

[0026] C1: Obtain attack behavior information based on the output result of the multi-modal deep neural network attack detection model;

[0027] C2: Extract attack behavior features according to the attack behavior information and organize the extracted attack behavior features into structured data; the attack behavior features include the attack source, attack target, attack time, attack type, and attack frequency;

[0028] C3: Define each extracted attack behavior feature as a node in the graph and define the relationship between nodes as an edge;

[0029] C4: Construct the defined node and edge set into a graph structure to form an attack behavior graph;

[0030] C5: In the attack behavior graph, use graph algorithms to analyze the relationships between attack behavior features, and combine community detection algorithms to divide the attack behavior graph into M subgraphs, with each subgraph corresponding to an attack pattern;

[0031] C6: Obtain the attack patterns based on the attack patterns divided in step C5 and the characteristics of the attack behavior graph;

[0032] For frequent attacks from a single attacking source IP, identify the attack behavior by analyzing the attacking source IP or attack frequency, and directly trigger the corresponding defense mechanisms, including IP banning and traffic cleaning;

[0033] For multi-stage attack behaviors, analyze by combining the attacking source IP, attacking target IP, and attack type to identify the attack behavior and trigger a multi-level in-depth defense mechanism;

[0034] C7: During the process of triggering the multi-level in-depth defense mechanism in step C6, adjust the preset protection strategy in real time according to the dynamic changes of the attack behavior graph; the protection strategy includes, for high-frequency attack nodes, giving priority to triggering the defense mechanism; for low-frequency attack nodes, delaying the triggering of the defense mechanism;

[0035] C8: Define the state of the protection process, and dynamically adjust the analysis and protection strategy of the attack behavior graph according to the state of the protection process;

[0036] C9: Update the attack behavior graph according to the execution results of the multi-level in-depth defense mechanism;

[0037] If an attacking source IP is successfully banned, remove it from the graph;

[0038] If the frequency of an attack type decreases, adjust the weight of its node;

[0039] C10: Feed back the updated attack behavior graph to the multi-modal deep neural network attack detection model, and optimize the parameters of the multi-modal deep neural network attack detection model and the multi-level in-depth defense mechanism according to the feedback results.

[0040] Specifically, updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution results of the defense mechanism, and implementing a model deployment strategy based on fast version rollback, including:

[0041] D1: After executing the multi-level in-depth defense mechanism, collect the quantitative data of the defense effect, and store the collected quantitative data of the defense effect in the defense effect database; the quantitative data of the defense effect includes the attack blocking rate, false alarm rate, and response time;

[0042] D2: Calculate the loss function value of the multi-modal deep neural network attack detection model based on the defense effect quantization data and in combination with the prediction output of the multi-modal deep neural network attack detection model;

[0043] D3: Update the parameters of the multi-modal deep neural network attack detection model using the gradient descent method. After each update of the model parameters, generate a new model version, record the update time, the updated parameter values, and the defense effect evaluation results. At the same time, store the new version model in the model repository.

[0044] Specifically, the step of updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism and implementing a model deployment strategy based on fast version rollback further includes:

[0045] D4: Monitor the new version model in real time, read the defense effect quantization data of the new version model from the defense effect database, and compare the defense effect quantization data of the new version model with the defense effect quantization data of the multi-modal deep neural network attack detection model before the update;

[0046] If the attack blocking rate of the new version model is less than the attack blocking rate of the multi-modal deep neural network attack detection model before the update or the false alarm rate of the new version model is greater than the false alarm rate of the multi-modal deep neural network attack detection model before the update, trigger the fast rollback mechanism;

[0047] D5: Select, from the model repository, the multi-modal deep neural network attack detection model with the shortest distance to the current time and an attack blocking rate higher than that of the current new version model as the rollback target model;

[0048] D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the defense effect quantization data before and after the rollback.

[0049] Specifically, the network traffic data includes HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters; the multi-level in-depth defense mechanism includes blocking attack requests, flow limiting control, dynamic rule generation, and alarm and logging.

[0050] A Web application firewall security defense system includes: a data collection module, a model construction module, an attack detection module, a defense module, and a model management module;

[0051] The data collection module is used to collect network traffic data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network traffic data;

[0052] The model construction module is used to construct and train a multi-modal deep neural network attack detection model;

[0053] The attack detection module is used to input the preprocessed real-time standardized network traffic data into the trained multi-modal deep neural network attack detection model, determine whether there is an attack behavior, and output the attack type and probability;

[0054] The defense module is used to automatically construct an attack behavior graph and trigger a multi-level in-depth defense mechanism when an attack is detected;

[0055] The model management module is used to update the parameters of the multi-modal deep neural network attack detection model in real time through an online learning method, and perform version management and quick rollback.

[0056] Specifically, the defense module includes: a graph construction unit, a defense mechanism trigger unit, and an execution result feedback unit;

[0057] The graph construction unit is used to construct a graph based on the attack type and characteristics, and visualize the attack path;

[0058] The defense mechanism trigger unit is used to trigger the corresponding defense mechanism according to the attack type and the graph;

[0059] The execution result feedback unit is used to feedback the execution result of the defense mechanism to the model update module.

[0060] Compared with the prior art, the beneficial effects of the present invention are:

[0061] 1. The present invention proposes a Web application firewall security defense system, and has optimized improvements in architecture, operation steps and processes. The system has the advantages of simple process, low investment and operation costs, and low production work costs.

[0062] 2. The present invention proposes a Web application firewall security defense method. By collecting network traffic data in real time and using an improved adversarial sample generation algorithm to construct a multi-modal deep neural network attack detection model, this method can efficiently and accurately identify attack behaviors in the network, including attack types and attack probabilities, thus improving the intelligent level of network security protection; it also realizes the automatic trigger and feedback of a multi-level in-depth defense mechanism, as well as the online update and version management of model parameters. It not only enhances the flexibility and adaptability of network security defense, but also ensures that the attack detection model can continuously and effectively respond to changing network threats, providing a more comprehensive and reliable guarantee for network security. Description of the Drawings

[0063] Figure 1 It is a schematic diagram of the Web application firewall security defense method of the present invention;

[0064] Figure 2 This is the principle flow chart of the security defense method of the Web application firewall of the present invention;

[0065] Figure 3 This is the flow chart of model selection for the security defense method of the Web application firewall of the present invention;

[0066] Figure 4 This is the architecture diagram of the security defense system of the Web application firewall of the present invention. Specific implementation manners

[0067] Example 1

[0068] Please refer to Figure 1 and Figure 2 A Web application firewall security defense method provided by the present invention, the method includes steps S1 to S4, and the specific steps include:

[0069] S1: Real-time collect network traffic data through the Web application firewall, and construct a multi-modal deep neural network attack detection model according to the network traffic data;

[0070] The network traffic data includes HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters.

[0071] Among them, HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters can be specifically summarized into two categories: normal traffic and attack traffic, and attack traffic usually appears in the form of abnormal requests.

[0072] Further, the specific steps for collecting network traffic data include:

[0073] (1) Real-time capture network traffic data through the Web application firewall;

[0074] (2) Extract features from the real-time captured network traffic data to obtain network traffic feature data; the network traffic feature data includes user behavior features, request frequencies, request body sizes, response times, request path features, and request parameter features;

[0075] Among them, the request frequency refers to the number of requests per unit time;

[0076] The request body size includes the size of the request body or the response body;

[0077] The response time includes the time difference from request to response;

[0078] The request path features include the length, depth, and whether it contains sensitive paths of the URL path;

[0079] The request parameter features include the number of parameters, the length of parameter values, and whether special characters are included;

[0080] The user behavior features include session duration and statistical features of the operation sequence;

[0081] (3)Use an automated feature selection algorithm to screen the extracted features to obtain network attack features;

[0082] (4)Standardize the network attack features to obtain preprocessed standardized network traffic data and store it in the database.

[0083] Furthermore, the specific steps of using an automated feature selection algorithm to screen the extracted features include:

[0084] 1)Obtain network traffic feature data and historical attack data;

[0085] 2)For each feature, calculate its mutual information with the historical attack data;

[0086] 3)Sort all features according to the mutual information values and select the top k features with the highest mutual information values as network attack features.

[0087] S2: Input the preprocessed standardized network traffic data in real time into a multi-modal deep neural network attack detection model and output the attack type and attack probability;

[0088] S3: When an attack behavior is detected, trigger a multi-level in-depth defense mechanism according to the attack type and the attack behavior graph pre-built by the Web application firewall, and evaluate the execution result of the multi-level in-depth defense mechanism;

[0089] The multi-level in-depth defense mechanism includes blocking attack requests, flow limiting control, dynamic rule generation, warning and logging.

[0090] S4: Update the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism and implement a model deployment strategy based on fast version rollback.

[0091] The specific process of constructing the multi-modal deep neural network attack detection model includes:

[0092] A1: Real-time collect network traffic data through the Web application firewall and perform preprocessing to obtain preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic;

[0093] A2: Separate the preprocessed standardized network traffic data according to the modal type to obtain network traffic data of different modalities;

[0094] Among them, the process of separating according to the modal type includes:

[0095] Obtain a standardized network traffic data set with labels;

[0096] Separate the data according to modal types, such as numerical features, sequence features, and text features;

[0097] Obtain network traffic data sets of different modalities.

[0098] A3: For the normal traffic data of each modality, by adding an adaptive perturbation in the gradient direction of the loss function L with respect to the normal traffic x , combined with a random perturbation term, generate adversarial samples , and satisfy , where represents the adaptive perturbation weight function, represents the gradient of the loss function L with respect to the normal traffic x, represents the sign function of represents the random perturbation weight function, represents the random perturbation vector, and obeys the Gaussian distribution, e represents the exponential, k represents the slope parameter, represents the norm of the normal traffic x, represents the threshold parameter, represents the maximum value function;

[0099] A4: Combine the network traffic data of different modalities and the generated adversarial samples to obtain an enhanced training data set;

[0100] A5: Load the neural network model, set the cross-entropy loss function and the optimizer, input the enhanced training data set into the pre-loaded neural network model, and adjust the parameters of the neural network model through the backpropagation algorithm to obtain a trained multi-modal deep neural network attack detection model. Among them, the neural network model is the prior art content in this field and is not the creative solution of this application, so it will not be elaborated here.

[0101] The specific steps of the said S2 include:

[0102] B1: Obtain the standardized network traffic data after real-time preprocessing, and load the trained multi-modal deep neural network attack detection model;

[0103] B2: Input the standardized network traffic data after real-time preprocessing into the trained multi-modal deep neural network attack detection model for inference, and calculate the probability of each attack category;

[0104] Furthermore, the specific steps of B2 include:

[0105] (1) Take the real-time preprocessed standardized network traffic data as input and input it into the trained multi-modal deep neural network attack detection model;

[0106] (2) In each layer of the convolutional layer, fully connected layer, and attention mechanism layer of the multi-modal deep neural network, calculate the output value through forward propagation according to the input data and model parameters. The forward propagation calculation formula is the prior art content in this field and is not the creative solution of this application, so it will not be elaborated here;

[0107] (3) Fuse the features of different modalities and use the attention mechanism to dynamically allocate the weights of different modality features to ensure that key features contribute more to the final output;

[0108] (4) At the output layer, calculate the score of each attack category , and use the Softmax function to convert the score into a probability score. The formula is: , where represents the probability that the input belongs to the j-th attack category, y represents the attack category, represents the real-time preprocessed standardized network traffic data, N represents the total number of attack categories, represents the exponential function;

[0109] (5) According to the output of the Softmax function, obtain the probability of each attack category , and select the attack category with the highest probability as the final prediction result;

[0110] (6) Output the probability of each attack category and the final attack category prediction result.

[0111] B3: Set the attack threshold;

[0112] If the probability of the attack category is greater than the threshold, it is determined as attack traffic;

[0113] If the probability of the attack category is less than or equal to the threshold, it is determined as normal traffic;

[0114] B4: Select the category corresponding to the maximum probability as the attack type and output the probability of the corresponding attack category.

[0115] When an attack behavior is detected, trigger a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluate the execution result of the multi-level in-depth defense mechanism, including:

[0116] C1: Obtain attack behavior information based on the output result of the multi-modal deep neural network attack detection model;

[0117] Further, the specific process of obtaining attack behavior information according to the output result of the multi-modal deep neural network attack detection model includes:

[0118] Obtain the output result of the multi-modal deep neural network attack detection model and the probability of each attack category;

[0119] Determine the most likely attack category according to the probability distribution, and extract the attack behavior information;

[0120] Store the attack behavior information in the database.

[0121] C2: Extract attack behavior features according to the attack behavior information, and organize the extracted attack behavior features into structured data; the attack behavior features include attack source, attack target, attack time, attack type, attack frequency;

[0122] Further, the specific steps of C2 include:

[0123] (1) Attack behavior information parsing: Extract key fields from the attack behavior information, including attack source, attack target, attack time, attack type, attack frequency, and organize the extracted fields into structured data for subsequent analysis;

[0124] (2) Attack source feature extraction: Extract the attack source IP address, and count the number of attacks of each attack source to obtain the attack frequency of the attack source, that is, the number of attacks per unit time;

[0125] (3) Attack target feature extraction: Extract the attack target IP address, and count the number of times each attack target is attacked to obtain the attack frequency of the attack target, that is, the number of times attacked per unit time;

[0126] (4) Attack time feature extraction: Extract the attack timestamp, and analyze the time distribution of the attacks, such as the peak period of the attacks, to obtain the time interval of the attacks, such as the time difference between two attacks;

[0127] (5) Attack type feature extraction: Extract the attack type, and count the number of occurrences of each attack type to obtain the distribution ratio of the attack type;

[0128] (6) Attack frequency feature extraction: Count the total number of attacks per unit time, and calculate the change trend of the attack frequency, such as the time series of the number of attacks;

[0129] (7) Store the extracted attack behavior features in the database for subsequent analysis and decision-making.

[0130] C3: Define each extracted attack behavior feature as a node in a graph, and define the relationship between nodes as an edge;

[0131] Exemplarily, being defined as a node in the graph includes:

[0132] Node 1: Attack source IP;

[0133] Node 2: Attack target IP;

[0134] Node 3: Attack time;

[0135] Node 4: Attack type;

[0136] Node 5: Attack frequency.

[0137] Exemplarily, defining the relationship between nodes as an edge includes:

[0138] Edge 1: Attack source IP → Attack target IP, indicating the attack behavior of the attack source against the attack target;

[0139] Edge 2: Attack source IP → Attack type, indicating the attack type initiated by the attack source;

[0140] Edge 3: Attack target IP → Attack time, indicating the attacks received by the attack target at different times;

[0141] Edge 4: Attack type → Attack frequency, indicating the occurrence frequency of a certain attack type.

[0142] C4: Construct the defined node and edge sets into a graph structure to form an attack behavior graph;

[0143] C5: In the attack behavior graph, use graph algorithms to analyze the relationships between attack behavior features, and combine community detection algorithms to divide the attack behavior graph into M subgraphs, with each subgraph corresponding to an attack pattern;

[0144] C6: Obtain the attack pattern based on the attack patterns divided in step C5 and the characteristics of the attack behavior graph;

[0145] For frequent attacks from a single attack source IP, identify the attack behavior by analyzing the attack source IP or attack frequency, and directly trigger the corresponding defense mechanisms, including IP banning and traffic cleaning;

[0146] For multi-stage attack behaviors, analyze by combining the attack source IP, attack target IP, and attack type to identify the attack behavior and trigger a multi-level in-depth defense mechanism;

[0147] C7: During the process of triggering the multi-level in-depth defense mechanism in step C6, according to the dynamic changes of the attack behavior graph, the preset protection strategy is adjusted in real time; the protection strategy includes that for high-frequency attack nodes, the defense mechanism is triggered preferentially; for low-frequency attack nodes, the triggering of the defense mechanism is delayed;

[0148] C8: Define the state of the protection process, and according to the state of the protection process, dynamically adjust the analysis and protection strategy of the attack behavior graph;

[0149] Among them, the state of the protection process includes:

[0150] Initial state: No attack is detected by the attack behavior graph;

[0151] Detection state: An attack is detected by the attack behavior graph, but the defense mechanism is not triggered;

[0152] Protection state: The defense mechanism is triggered by the attack behavior graph and protection is in progress;

[0153] Completion state: The defense mechanism has been executed and the attack has been successfully blocked.

[0154] C9: Update the attack behavior graph according to the execution result of the multi-level in-depth defense mechanism;

[0155] If an attack source IP is successfully blocked, it is removed from the graph;

[0156] If the frequency of an attack type decreases, adjust the weight of its node;

[0157] C10: Feed the updated attack behavior graph back to the multi-modal deep neural network attack detection model, and according to the feedback result, optimize the parameters of the multi-modal deep neural network attack detection model and the multi-level in-depth defense mechanism.

[0158] In summary, the attack behavior graph can effectively identify and protect various attack behaviors. A single node can solve simple attacks, while complex attacks require multiple nodes to be combined for analysis and protection. By optimizing the joint recognition strategy and dynamically adjusting the protection process, a protection effect with low load and high efficiency can be achieved. The whole process forms a complete closed-loop logic from the acquisition of attack behavior information to the update and feedback of the graph.

[0159] Embodiment 2

[0160] Please refer to Figure 3 , in this embodiment, the specific steps of S4 include:

[0161] D1: After implementing the multi - level in - depth defense mechanism, collect the quantified data of the defense effect, and store the collected quantified data of the defense effect in the defense effect database; the quantified data of the defense effect includes the attack blocking rate, false alarm rate, and response time.

[0162] D2: According to the quantified data of the defense effect , combined with the prediction output of the multi - modal deep neural network attack detection model, calculate the loss function value of the multi - modal deep neural network attack detection model , where represents the output result of the multi - modal deep neural network attack detection model, represents the parameters of the multi - modal deep neural network attack detection model, including weights and biases, represents the i - th real - time pre - processed standardized network traffic data, represents the regularization coefficient, and n represents the number of real - time pre - processed standardized network traffic data;

[0163] D3: Use the gradient descent method to update the parameters of the multi - modal deep neural network attack detection model. After each update of the model parameters, generate a new model version, record the update time, the updated parameter values, and the defense effect evaluation results. At the same time, store the new version model in the model repository. The gradient descent method is the prior art content in this field and is not the creative solution of this application, so it will not be elaborated here;

[0164] In the present invention, the comprehensive evaluation formula for the defense effect is: , where , , represent the weight coefficients, ABR represents the attack blocking rate, FPR represents the false alarm rate, and RT represents the response time.

[0165] D4: Monitor the new version model in real - time, read the quantified data of the defense effect of the new version model from the defense effect database, and compare the quantified data of the defense effect of the new version model with the quantified data of the defense effect of the multi - modal deep neural network attack detection model before the update;

[0166] If the attack blocking rate of the new version model is less than the attack blocking rate of the multi - modal deep neural network attack detection model before the update or the false alarm rate of the new version model is greater than the false alarm rate of the multi - modal deep neural network attack detection model before the update, trigger the fast rollback mechanism;

[0167] D5: Select the multi - modal deep neural network attack detection model with the shortest distance from the current time and an attack blocking rate higher than the current new version model in the model repository as the rollback target model;

[0168] D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the quantitative defense effect data before and after the rollback.

[0169] Embodiment 3

[0170] Please refer to Figure 4 , another embodiment provided by the present invention: a Web application firewall security defense system, including:

[0171] A data collection module, a model construction module, an attack detection module, a defense module, and a model management module;

[0172] The data collection module is used to collect network traffic data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network traffic data for subsequent modules to use;

[0173] The model construction module is used to construct and train a multi-modal deep neural network attack detection model, and improve the model robustness by combining adversarial sample generation technology;

[0174] The attack detection module is used to input the real-time preprocessed standardized network traffic data into the trained multi-modal deep neural network attack detection model, determine whether there is an attack behavior, and output the attack type and probability;

[0175] The defense module is used to automatically construct an attack behavior graph and trigger a multi-level in-depth defense mechanism when an attack is detected;

[0176] The model management module is used to update the parameters of the multi-modal deep neural network attack detection model in real time through an online learning method, and perform version management and quick rollback.

[0177] The data collection module includes: a data collection unit and a feature selection unit;

[0178] The data collection unit is used to collect network traffic data in real time through the Web application firewall;

[0179] The feature selection unit is used to perform feature selection using an automated feature selection algorithm to reduce redundant data.

[0180] The attack detection module includes: a real-time data input unit, an attack detection unit, and an output unit;

[0181] The real-time data input unit is used to receive the preprocessed standardized network traffic data;

[0182] The attack detection unit is used to determine whether there is an attack behavior through the trained multi-modal deep neural network attack detection model;

[0183] An output unit for outputting the attack type and probability.

[0184] The defense module includes: a graph construction unit, a defense mechanism trigger unit, and an execution result feedback unit;

[0185] The graph construction unit is used to construct a graph based on the attack type and characteristics and visualize the attack path;

[0186] The defense mechanism trigger unit is used to trigger corresponding defense mechanisms based on the attack type and the graph;

[0187] The execution result feedback unit is used to feedback the execution result of the defense mechanism to the model update module.

[0188] The model management module includes: an online learning unit, a version management unit, and a quick rollback unit;

[0189] The online learning unit is used to update model parameters in real time to adapt to new attack patterns;

[0190] The version management unit is used to manage model versions and record update histories;

[0191] The quick rollback unit is used to quickly roll back to a stable version when the model performance deteriorates.

[0192] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make changes, modifications, substitutions, and variations to the above embodiments without departing from the purpose and scope protected by the present invention. These all fall within the protection scope of the present invention.

[0193] If the technical solution of the present disclosure involves personal information, before the product applying the technical solution of the present disclosure processes personal information, it has clearly informed the personal information processing rules and obtained the personal's autonomous consent. If the technical solution of the present disclosure involves sensitive personal information, before the product applying the technical solution of the present disclosure processes sensitive personal information, it has obtained the personal's separate consent and at the same time meets the requirement of "express consent". For example, at a personal information collection device such as a camera, a clear and prominent identifier is set to inform that the personal information collection scope has been entered and personal information will be collected. If a person voluntarily enters the collection scope, it is regarded as consenting to the collection of their personal information; or on the personal information processing device, when the personal information processing rules are informed by obvious identifiers / information, personal authorization is obtained through pop-up messages or by asking the person to upload their personal information by themselves. Among them, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.

Claims

1. A security defense method for a web application firewall, characterized in that, Including: Collecting network traffic data in real time through a Web application firewall, and constructing a multi-modal deep neural network attack detection model based on the network traffic data; Inputting the pre-processed standardized network traffic data in real time into the multi-modal deep neural network attack detection model, and outputting the attack type and attack probability; When an attack behavior is detected, triggering a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluating the execution result of the multi-level in-depth defense mechanism; Updating the parameters of the multi-modal deep neural network attack detection model in real time according to the execution result of the defense mechanism, and implementing a model deployment strategy based on fast version rollback; When an attack behavior is detected, triggering a multi-level in-depth defense mechanism according to the attack type and the pre-constructed attack behavior graph of the Web application firewall, and evaluating the execution result of the multi-level in-depth defense mechanism, including: C1: Obtaining attack behavior information based on the output result of the multi-modal deep neural network attack detection model; C2: Extracting attack behavior characteristics according to the attack behavior information, and organizing the extracted attack behavior characteristics into structured data; the attack behavior characteristics include attack source, attack target, attack time, attack type, attack frequency; C3: Defining each extracted attack behavior characteristic as a node in the graph, and defining the relationship between nodes as edges; C4: Constructing a graph structure from the defined set of nodes and edges to form an attack behavior graph; C5: In the attack behavior graph, using graph algorithms to analyze the relationship between attack behavior characteristics, and dividing the attack behavior graph into M sub-graphs by combining community detection algorithms, with each sub-graph corresponding to an attack pattern; C6: Obtaining the attack pattern according to the attack pattern divided in step C5 and the characteristics of the attack behavior graph; For frequent attacks from a single attack source IP, identify the attack behavior by analyzing the attack source IP or attack frequency, and directly trigger the corresponding defense mechanisms, including IP banning and traffic cleaning; For multi-stage attack behaviors, jointly analyze the attack source IP, attack target IP, and attack type to identify the attack behavior, and trigger a multi-level in-depth defense mechanism; C7: During the process of triggering the multi-level in-depth defense mechanism in step C6, adjust the preset protection strategy in real time according to the dynamic changes of the attack behavior graph; the protection strategy includes giving priority to triggering the defense mechanism for high-frequency attack nodes, and delaying the triggering of the defense mechanism for low-frequency attack nodes; C8: Defining the state of the protection process, and dynamically adjusting the analysis and protection strategy of the attack behavior graph according to the state of the protection process; C9: Updating the attack behavior graph according to the execution result of the multi-level in-depth defense mechanism; If an attack source IP is successfully banned, remove it from the graph; If the frequency of an attack type decreases, adjust the weight of its node; C10: Feed back the updated attack behavior graph to the multi-modal deep neural network attack detection model, and optimize the parameters of the multi-modal deep neural network attack detection model and the multi-level in-depth defense mechanism according to the feedback result.

2. The Web application firewall security defense method according to claim 1, characterized in that The specific process of constructing the multi-modal deep neural network attack detection model includes: A1: Real-time collect network traffic data through a Web application firewall and perform preprocessing to obtain preprocessed standardized network traffic data; the preprocessed standardized network traffic data includes normal traffic and attack traffic; A2: Separate the preprocessed standardized network traffic data according to the modal type to obtain network traffic data of different modalities; A3: For the normal traffic data of each modality, generate adversarial samples by adding an adaptive perturbation in the gradient direction of the loss function with respect to the normal traffic, combined with a random perturbation term; A4: Combine the network traffic data of different modalities and the generated adversarial samples to obtain an enhanced training dataset; A5: Load the neural network model, set the cross-entropy loss function and optimizer, input the enhanced training dataset into the pre-loaded neural network model, and adjust the parameters of the neural network model through the backpropagation algorithm to obtain a trained multi-modal deep neural network attack detection model.

3. The Web application firewall security defense method according to claim 2, characterized in that, Inputting the preprocessed standardized network traffic data in real time into the multi-modal deep neural network attack detection model and outputting the attack type and attack probability includes: B1: Obtain the preprocessed standardized network traffic data in real time and load the trained multi-modal deep neural network attack detection model; B2: Input the preprocessed standardized network traffic data in real time into the trained multi-modal deep neural network attack detection model for inference, and calculate the probability of each attack category; B3: Set the attack threshold; If the probability of the attack category is greater than the threshold, it is determined as attack traffic; If the probability of the attack category is less than or equal to the threshold, it is determined as normal traffic; B4: Select the category corresponding to the maximum probability as the attack type and output the probability of the corresponding attack category.

4. The Web application firewall security defense method according to claim 3, characterized in that, According to the execution result of the defense mechanism, updating the parameters of the multi-modal deep neural network attack detection model in real time and implementing a model deployment strategy based on fast version rollback includes: D1: After executing the multi-level in-depth defense mechanism, collect the quantified defense effect data and store the collected quantified defense effect data in the defense effect database; the quantified defense effect data includes the attack blocking rate, false alarm rate, and response time; D2: According to the quantified defense effect data, combined with the prediction output of the multi-modal deep neural network attack detection model, calculate the loss function value of the multi-modal deep neural network attack detection model; D3: Use the gradient descent method to update the parameters of the multi-modal deep neural network attack detection model. After each update of the model parameters, generate a new model version, record the update time, the updated parameter values, and the defense effect evaluation results, and at the same time, store the new version model in the model repository.

5. The Web application firewall security defense method according to claim 4, wherein According to the execution result of the defense mechanism, updating the parameters of the multi-modal deep neural network attack detection model in real time and implementing a model deployment strategy based on fast version rollback also includes: D4: Monitor the new version model in real time, read the quantitative data of the defense effect of the new version model from the defense effect database, and compare the quantitative data of the defense effect of the new version model with the quantitative data of the defense effect of the multi-modal deep neural network attack detection model before the update; If the attack blocking rate of the new version model is less than the attack blocking rate of the multi-modal deep neural network attack detection model before the update or the false alarm rate of the new version model is greater than the false alarm rate of the multi-modal deep neural network attack detection model before the update, trigger the fast rollback mechanism; D5: Select, from the model repository, a multi-modal deep neural network attack detection model with the shortest distance to the current time and an attack blocking rate higher than that of the current new version model as the rollback target model; D6: Deploy the rollback target model to the Web application firewall to replace the current new version model, and record the rollback event; the rollback event includes the rollback time, the rollback reason, and the quantitative data of the defense effect before and after the rollback.

6. The Web application firewall security defense method according to claim 5, wherein, The network traffic data includes HTTP requests, response data, user behavior data, IP addresses, request frequencies, request times, request paths, and request parameters; the multi-level in-depth defense mechanism includes blocking attack requests, traffic limiting control, dynamic rule generation, and alarm and logging.

7. A Web application firewall security defense system for implementing the Web application firewall security defense method according to any one of claims 1-6, characterized in that, Including: Data collection module, model construction module, attack detection module, defense module, model management module; The data collection module is used to collect network traffic data in real time and perform preprocessing through an automated feature selection algorithm to generate standardized network traffic data; The model construction module is used to construct and train a multi-modal deep neural network attack detection model; The attack detection module is used to input the real-time preprocessed standardized network traffic data into the trained multi-modal deep neural network attack detection model, determine whether there is an attack behavior, and output the attack type and probability; The defense module is used to automatically construct an attack behavior graph and trigger a multi-level in-depth defense mechanism when an attack is detected; The model management module is used to update the parameters of the multi-modal deep neural network attack detection model in real time through an online learning method and perform version management and fast rollback.

8. The Web application firewall security defense system according to claim 7, characterized in that, The defense module includes: a graph construction unit, a defense mechanism trigger unit, and an execution result feedback unit; The graph construction unit is used to construct a graph based on the attack type and features and visualize the attack path; The defense mechanism trigger unit is used to trigger the corresponding defense mechanism according to the attack type and the graph; The execution result feedback unit is used to feedback the execution result of the defense mechanism to the model update module.

Citation Information

Patent Citations

  • Password Reverse Firewall and its Security Defense Methods

    CN114205073B

  • Deep learning backdoor defense method based on model pruning and reverse engineering

    CN113204745A

  • Intelligent sensing network security protection system

    CN118827161A