API traffic data risk prediction method and device, equipment and medium

By updating the edge and node weight values ​​in the community network topology graph and inputting them into the community discovery model, the problem that the existing technology cannot discover API traffic data risks in a timely manner is solved, and accurate identification of complex data security attacks and prediction of risk nodes is achieved.

CN120151046APending Publication Date: 2025-06-13CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510330425.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In the face of complex data security attacks, the prior art cannot detect risks in API traffic data in a timely manner.

Method used

By determining whether there is risk in the received API traffic data, and updating the edge weight value and node risk weight value in the community network topology graph based on the carried interface information, source IP and other information, it is input into the community discovery model to predict whether there is risk in the API traffic data and the target risk node.

Benefits of technology

It can accurately identify whether there is a risk when facing complex data security attacks, and find potentially specific relationship attack organizations by determining the target risk nodes, which facilitates security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151046A_ABST
    Figure CN120151046A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an API (Application Program Interface) traffic data risk prediction method, device and equipment and a medium, which are used for solving the problem that the risk cannot be found in time when facing complex data security attacks in the prior art. The method comprises the following steps: determining whether API flow data has a candidate result of risk or not; based on the information carried by the API flow data and the candidate result, updating a weight value of an edge connected between corresponding nodes in the community network topological graph and a risk weight value of each node; and inputting the community network topological graph, the updated edge weight value in the community network topological graph and the risk weight value of each node into a community discovery model, obtaining whether the output API flow data has a risk or not, and if the output API flow data has the risk, outputting a prediction result of a target risk node with the risk and a corresponding associated risk node. Whether the risk exists or not can be accurately identified in the face of complex data security attacks, and security protection can be conveniently carried out by determining the target risk node with the risk.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method, apparatus, device, and medium for predicting risks of Application Programming Interface (API) traffic data. Background Art

[0002] In the digital age, APIs are widely used in the interaction between major software systems, such as Representational State Transfer (RESTful), Google Remote Procedure Call (gRPC), etc. However, with the rapid increase in API data volume, data security risks have also risen. Traditional security monitoring methods (such as database auditing, data masking, etc.) can no longer adapt to complex network environments, resulting in potential risks being difficult to detect.

[0003] To solve the problem that traditional security monitoring methods cannot adapt to complex network environments, currently, point-to-point security risk monitoring means are mainly adopted, that is, directly targeting a piece of API traffic data to detect risk problems existing in the API traffic data, such as risks of Structured Query Language (SQL) injection, plaintext password transmission, etc.

[0004] Since this monitoring means can usually only determine the existing risks for a specific piece of API traffic data and avoid some simple attacks based on this risk, but in fact, the data is flowing, and data security attacks are often one-to-many, penetrate layer by layer, or even gang attacks, that is, attackers or gangs use the data leaked in a certain link of the process to find the next vulnerability. Therefore, based on this monitoring means, only the risks of a specific link can be found, and in the face of complex data security attacks, risks cannot be detected in time. Summary of the Invention

[0005] Embodiments of the present application provide a method, apparatus, device, and medium for predicting risks of API traffic data to solve the problem that the existing point-to-point security risk monitoring means cannot detect risks in time in the face of complex data security attacks.

[0006] In a first aspect, embodiments of the present application provide a method for predicting risks of API traffic data, the method including:

[0007] Determining a candidate result of whether the received API traffic data has risks;

[0008] Update the weight values of the edges connecting corresponding nodes in the community network topology graph and the risk weight values of each node based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate results for the API traffic data;

[0009] Input the community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node into the community discovery model, and obtain the prediction results of whether there is a risk in the API traffic data output by the community discovery model, and if there is a risk, the target risk nodes with risks and the corresponding associated risk nodes output;

[0010] In a second aspect, an embodiment of the present application provides an API traffic data risk prediction device, and the device includes:

[0011] A determination module, configured to determine candidate results of whether there is a risk in the received API traffic data;

[0012] An update module, configured to update the weight values of the edges connecting corresponding nodes in the community network topology graph and the risk weight values of each node based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate results for the API traffic data;

[0013] A prediction module, configured to input the community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node into the community discovery model, and obtain the prediction results of whether there is a risk in the API traffic data output by the community discovery model, and if there is a risk, the target risk nodes with risks and the corresponding associated risk nodes output;

[0014] In a third aspect, an embodiment of the present application further provides an electronic device, and the electronic device includes at least a processor and a memory. When the processor executes the computer program stored in the memory, the steps of any one of the above API traffic data risk prediction methods are implemented.

[0015] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of any one of the above API traffic data risk prediction methods are implemented.

[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, and the computer program product includes: computer program code. When the computer program code runs on a computer, the computer is caused to execute the steps of any one of the above API traffic data risk prediction methods described in the first aspect.

[0017] In the embodiments of the present application, candidate results for determining whether there are risks in the received API traffic data are determined; based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate results of the API traffic data, the weight values of the edges connecting the corresponding nodes in the community network topology diagram and the risk weight values of each node are updated; the community network topology diagram, the updated weight values of the edges in the community network topology diagram, and the risk weight values of each node are input into the community discovery model to obtain the prediction results of whether there are risks in the API traffic data output by the community discovery model, and if there are risks, the target risk nodes with risks and the corresponding associated risk nodes output. Since the community network topology diagram contains the risk situations of each node in the corresponding community network, by combining the community network topology diagram and the candidate results of whether there are risks in the received API traffic data, not only can it accurately identify whether there are risks in the face of complex data security attacks, but also by determining the target risk nodes with risks, it can find the attacking organizations with potential specific relationships, which is convenient for security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0019] Figure 1 A schematic diagram of a risk prediction process for API traffic data provided by an embodiment of the present application;

[0020] Figure 2 A schematic diagram of a community network topology diagram provided by an embodiment of the present application;

[0021] Figure 3 A schematic diagram of a traceability topology diagram provided by an embodiment of the present application;

[0022] Figure 4 A schematic diagram of a risk prediction process for API traffic data provided by an embodiment of the present application;

[0023] Figure 5 A schematic diagram of the structure of an API traffic data risk prediction device provided by an embodiment of the present application;

[0024] Figure 6 A schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To make the objectives and implementation manners of this application clearer, the following will clearly and completely describe the exemplary implementation manners of this application in conjunction with the accompanying drawings in the exemplary embodiments of this application. Obviously, the described exemplary embodiments are only a part of the embodiments of this application, rather than all of the embodiments.

[0026] It should be noted that the brief descriptions of the terms in this application are only for facilitating the understanding of the following described implementation manners, rather than intending to limit the implementation manners of this application. Unless otherwise specified, these terms should be understood in their ordinary and common meanings.

[0027] The terms "first", "second", "third", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar or like objects or entities, and do not necessarily mean to limit a specific order or sequence, unless otherwise noted. It should be understood that such terms can be interchanged under appropriate circumstances.

[0028] The terms "comprising" and "having" and any variations thereof are intended to cover but not exclude inclusion. For example, a product or device comprising a series of components does not necessarily have to be limited to all the components clearly listed, but may include other components not clearly listed or inherent to these products or devices.

[0029] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic or a combination of hardware or / and software code that can perform functions related to that element.

[0030] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of this application.

[0031] For the convenience of explanation, the above descriptions have been made in conjunction with specific implementation manners. However, the above exemplary discussions are not intended to be exhaustive or to limit the implementation manners to the specific forms disclosed above. According to the above teachings, various modifications and variations can be obtained. The selection and description of the above implementation manners are for better explaining the principles and actual applications, so that those skilled in the art can better use the implementation manners and various different modified implementation manners suitable for specific use considerations.

[0032] The embodiments of the present application provide a method, apparatus, device, and medium for predicting risks of API traffic data. The method includes: determining a candidate result of whether the received API traffic data has risks; based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate result of the API traffic data, updating the weight value of the edge connecting corresponding nodes in the community network topology diagram and the risk weight value of each node; inputting the community network topology diagram, the updated weight value of the edge in the community network topology diagram, and the risk weight value of each node into the community discovery model, and obtaining the prediction result of whether the API traffic data has risks output by the community discovery model, and if there are risks, the target risk nodes with risks and the corresponding associated risk nodes. Since the community network topology diagram contains the risk situations of each node in the corresponding community network, by combining the community network topology diagram and the candidate result of whether the received API traffic data has risks, it is not only possible to accurately identify whether there are risks in the face of complex data security attacks, but also possible to find the attacking organizations with potential specific relationships by determining the target risk nodes with risks, which is convenient for security protection.

[0033] Embodiment 1:

[0034] Figure 1 FIG. is a schematic diagram of a process for predicting risks of API traffic data provided by an embodiment of the present application. The process includes:

[0035] S101: Determine a candidate result of whether the received API traffic data has risks.

[0036] The method for predicting risks of API traffic data provided by the embodiments of the present application is applied to an electronic device, which may be a computer (Personal Computer, PC), a server, etc.

[0037] The electronic device deploys API data collection probes in each application business system it contains, and collects the API traffic data received by the application business system through the probes.

[0038] Among them, the API traffic data includes interface information, source Internet Protocol (IP), access account, access terminal identification information, application identification information, destination IP, and destination port. Among them, the interface information may be interface identification information or interface name, and no specific limitation is made here. And the API traffic data also includes access parameters (i.e., request messages), return parameters (i.e., return messages), etc.

[0039] After receiving the API traffic data, noise reduction is performed on the API traffic data through a preset noise reduction rule.

[0040] Among them, since the source IP and destination IP of the internal call requests within each application business system are fixed, that is, they are both the internal network IPs of the server cluster of the application business system, and the internal call requests cannot be forged. Therefore, in the embodiments of the present application, the preset noise reduction rules generally include, but are not limited to, filtering the API traffic data exposed internally according to the saved traffic whitelist, filtering the API traffic data with access failures, etc., and no specific limitations are made here.

[0041] Use a risk detection engine to detect the noise-reduced API traffic data to determine whether there is a candidate result of risk for the API traffic data.

[0042] Among them, the risk detection engine includes, but is not limited to, a regular detection engine, an API detection engine, etc. Preferably, since the API detection engine can only detect whether there is a risk in the API traffic data, but cannot determine the type of risk in the API traffic data, while the regular detection engine can not only detect whether there is a risk in the API traffic data but also determine the risk type. Therefore, in the embodiments of the present application, a regular detection engine is usually used to analyze the API traffic data.

[0043] In addition, after receiving the API traffic data, in order to facilitate displaying the source of the API traffic data to the operation personnel, so that the operation personnel can further determine whether there is a risk in the API traffic data based on the source of the API traffic data and combined with experience after receiving the risk prompt information of the API traffic data. Therefore, in the embodiments of the present application, the traceability data of the API traffic data is saved in a columnar database management system (ClickHouse) for subsequent operation personnel to view.

[0044] Among them, the traceability data at least includes the source IP, destination IP, destination port, access interface identification information, transmitted data, request header, request body, response header, response body, etc. of the API traffic data.

[0045] S102: Based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data and the candidate result, update the weight value of the edge connecting the corresponding nodes in the community network topology diagram and the risk weight value of each node.

[0046] The community network topology diagram is saved in the electronic device, and the community network topology diagram includes community nodes and edges for connecting the community nodes with connection relationships.

[0047] Among them, the community nodes include account nodes, source IP nodes, terminal nodes, interface nodes, application nodes, etc. And there is a set connection order among the community nodes, such as Figure 2As shown, the edge nodes in the community network topology diagram are account nodes. It can be understood that if there are no account nodes in the community network topology diagram, the source IP node is used as the edge node, and each community node from the outside to the inside is an account node, a source IP node, a terminal node (such as Figure 2 Huawei and simulator shown in

[0048] ), an interface node (API interface A, API interface B, API interface C, API interface D), and an application node (Application A). That is to say, there is a connection relationship between the account node and the source IP node and they are connected by the corresponding edge, there is a connection relationship between the source IP node and the terminal node and they are connected by the corresponding edge, there is a connection relationship between the terminal node and the interface node and they are connected by the corresponding edge, and there is a connection relationship between the interface node and the application node and they are connected by the corresponding edge.

[0049] Another example is that the edge corresponding to the source IP node - terminal node can be used to indicate whether there is a risk with the terminal corresponding to the terminal node. For example, if there are multiple connected source IP nodes for the same terminal node in a short period of time, it is determined that there may be risks such as gray production organizations using an IP pool to operate data.

[0050] Another example is that the edge corresponding to the interface node - application node can be used to indicate whether there are unregistered interfaces for the application corresponding to the application node. Since the registered interface information of the application corresponding to the application node is stored in the electronic device, for each interface node connected to the application node, it can be determined whether the interface information corresponding to the interface node is any of the registered interface information. If so, it is determined that the interface corresponding to the interface node is a registered interface; if not, it is determined that the interface corresponding to the interface node is an unregistered interface.

[0051] In addition, the electronic device stores the initial weight values corresponding to each edge in the community network topology diagram, and the initial weight value is the current risk count. Since the candidate results will affect the risk counts corresponding to each edge in the community network topology diagram, in the embodiments of the present application, after receiving the API traffic data and determining the candidate results of whether the API traffic data has risks, based on the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data, the corresponding target interface node, target source IP node, target account node, target terminal node, target application node in the community network topology diagram, and the edges corresponding to the connections between the above nodes are determined.

[0052] According to the target interface node, target source IP node, target account node, target terminal node, target application node in the community network topology diagram corresponding to the API traffic data, and the edges corresponding to the connections between the above nodes, the Louvain (Fast unfolding of communities in large networks) algorithm is used to update the community network topology diagram.

[0053] Moreover, since the electronic device stores the update values corresponding to the candidate results, in the embodiments of the present application, according to the edges corresponding to the connections between the target interface node, target source IP node, target account node, target terminal node, target application node in the community network topology diagram corresponding to the API traffic data, the update values corresponding to the candidate results of whether the API traffic data has risks, and the current risk counts corresponding to each edge in the community network topology diagram, the updated weight values of each edge in the updated community network topology diagram are determined.

[0054] After determining the updated weight values of each edge in the community network topology diagram, according to the preset node weight determination rule, based on the updated weight values of each edge in the updated community network topology diagram, the updated risk weight values of each node are determined.

[0055] In addition, in the embodiments of the present application, the community network topology diagram can also be displayed to the operation personnel, avoiding the operation personnel from analyzing potential risks from a large number of access logs generated by the system, and enabling the operation personnel to be observable and measurable, facilitating the operation personnel to subjectively judge whether there are risks.

[0056] S103: Input the community network topology diagram, the updated weight values of the edges in the community network topology diagram, and the risk weight values of each node into the community discovery model, and obtain the prediction results output by the community discovery model on whether the API traffic data has risks, and if there are risks, the target risk nodes with risks and the corresponding associated risk nodes.

[0057] After obtaining the updated community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node, input the updated community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node into the community discovery model.

[0058] Among them, the community discovery model is a pre-trained model, and this community discovery model is usually used to receive the community network topology graph input within each preset time period, and capture the structure and weight dependence relationship of each node in the community network topology graph with the time window corresponding to this time period as the sequence and the corresponding time interval as the step length. Based on the structure and weight dependence relationship of each node, predict potential risks. Among them, the structure of each node represents other nodes and edges connected to this node; the weight dependence relationship of each node represents the risk weight value of this node.

[0059] Therefore, in the embodiment of the present application, based on the community discovery model, obtain the prediction result of whether there is a risk in the API traffic data output by the community discovery model, and if it is determined that there is a risk, the information of the target risk node with risk output by this community discovery model will also be obtained. Since the reason for the risk of this target risk node may not only include the target risk node itself, but may also include other nodes (i.e., associated risk nodes) connected to this target risk node, therefore, in the embodiment of the present application, when the prediction result is that there is a risk in this API traffic data, not only the information of the target risk node with risk will be output, but also the information of the associated risk nodes connected to this target risk node will be output.

[0060] In the embodiment of the present application, since the community network topology graph contains the risk situations of each node in the corresponding community network, therefore, by combining the community network topology graph and the candidate result of whether there is a risk in the received API traffic data, it is not only possible to accurately identify whether there is a risk in the face of complex data security attacks, but also possible to find the attack organization with potential specific relationships by determining the target risk node with risk, which is convenient for security protection.

[0061] Embodiment 2:

[0062] In order to further accurately identify whether there is a risk in the face of complex data security attacks, on the basis of the above embodiment, in the embodiment of the present application, based on the interface information, source IP, access account, access terminal identification information, application identification information carried in the API traffic data, and the candidate result of the API traffic data, update the weight value of the edge connected between the corresponding nodes in the community network topology graph, including:

[0063] Determine the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology diagram according to the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data;

[0064] Obtain the current risk count corresponding to each edge in the saved community network topology diagram;

[0065] According to the updated value corresponding to the candidate result and the current risk count of the edge corresponding to the connection between the target interface node, target source IP node, target account node, target terminal node, and target application node, obtain the target risk count of the corresponding edge after update;

[0066] For each edge included in the community network topology diagram, determine the updated weight value corresponding to the edge according to the target risk count corresponding to the edge and the total target risk count of all edges included in the community network topology diagram.

[0067] In the embodiment of the present application, after receiving the API traffic data, according to the interface information carried in the API traffic data, determine whether there is an interface node corresponding to the interface information in the community network topology diagram. If it exists, determine the interface node as the target interface node corresponding to the API traffic data in the community network topology diagram; if it does not exist, add the interface node corresponding to the interface information to the community network topology diagram and use it as the target interface node corresponding to the API traffic data.

[0068] According to the source IP carried in the API traffic data, determine whether there is a source IP node corresponding to the source IP in the community network topology diagram. If it exists, determine the source IP node as the target source IP node corresponding to the API traffic data in the community network topology diagram; if it does not exist, add the source IP node corresponding to the source IP to the community network topology diagram and use it as the target source IP node corresponding to the API traffic data.

[0069] According to the access account carried in the API traffic data, determine whether there is an account node corresponding to the access account in the community network topology diagram. If it exists, determine the account node as the target account node corresponding to the API traffic data in the community network topology diagram; if it does not exist, add the account node corresponding to the access account to the community network topology diagram and use it as the target account node corresponding to the API traffic data.

[0070] According to the access terminal identification information carried in the API traffic data, determine whether there is a terminal node corresponding to the access terminal identification information in the community network topology diagram. If it exists, determine this terminal node as the target terminal node corresponding to the API traffic data in the community network topology diagram; if it does not exist, add the terminal node corresponding to the access terminal identification information to the community network topology diagram and use it as the target terminal node corresponding to the API traffic data.

[0071] Since a unique corresponding application can be determined according to the destination IP and destination port, in the embodiments of the present application, according to the destination IP and destination port carried in the API traffic data, determine whether there is an application node corresponding to the destination IP and destination port in the community network topology diagram. If it exists, determine this application node as the target application node corresponding to the API traffic data in the community network topology diagram; if it does not exist, add the application node corresponding to the destination IP and destination port to the community network topology diagram and use it as the target application node corresponding to the API traffic data.

[0072] Since there is a set connection order among the community nodes in the community network topology diagram, after determining the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology diagram, according to the set connection order, determine the edges corresponding to the connections among the target interface node, target source IP node, target account node, target terminal node, and target application node.

[0073] Among them, the corresponding connected edges are respectively: the edge connecting the target account node and the target source IP node, the edge connecting the target source IP node and the target terminal node, the edge connecting the target terminal node and the target interface node, and the edge connecting the target interface node and the target application node.

[0074] The electronic device obtains the current risk count of the weaknesses in the links corresponding to the edges in the community network topology diagram saved by itself. And since the candidate results include that the API traffic data has risks or does not have risks, and different candidate results will have different impacts on the weight values corresponding to the edges in the community network topology diagram, in the embodiments of the present application, the electronic device stores the updated values of the edges corresponding to the candidate results.

[0075] Specifically, if the candidate result is that the API traffic data has risks, the edges in the community network topology diagram correspond to the first updated value; if the candidate result is that the API traffic data does not have risks, the edges in the community network topology diagram correspond to the second updated value. Among them, the first updated value is greater than the second updated value.

[0076] For example, if it is determined that the API traffic data is at risk, the risk count of the edge corresponding to the API traffic data in the community network topology diagram will increase by one accordingly. Therefore, the first update value is determined to be 1. If it is determined that the API traffic data is not at risk, the risk count of the edge corresponding to the API traffic data in the community network topology diagram will not change. Therefore, the second update value is determined to be 0.

[0077] Therefore, in the embodiment of the present application, according to the update value corresponding to the candidate result, and the current risk counts of the edges connecting the target account node and the target source IP node, the current risk counts of the edges connecting the target source IP node and the target terminal node, the current risk counts of the edges connecting the target terminal node and the target interface node, and the current risk counts of the edges connecting the target interface node and the target application node, the target risk counts of the edges connecting the target account node and the target source IP node after update, the target risk counts of the edges connecting the target source IP node and the target terminal node after update, the target risk counts of the edges connecting the target terminal node and the target interface node after update, and the target risk counts of the edges connecting the target interface node and the target application node after update are determined.

[0078] For example, if the candidate result is that the API traffic data is determined to be at risk, the update value corresponding to the candidate result is 1, and the target risk counts of the edges connecting the target account node and the target source IP node, the edges connecting the target source IP node and the target terminal node, the edges connecting the target terminal node and the target interface node, and the edges connecting the target interface node and the target application node corresponding to the API traffic data are respectively determined to be (the corresponding current risk count + 1).

[0079] Another example is that if the candidate result is that the API traffic data is determined not to be at risk, the update value corresponding to the candidate result is 0, and the current risk counts of the edges connecting the target account node and the target source IP node, the edges connecting the target source IP node and the target terminal node, the edges connecting the target terminal node and the target interface node, and the edges connecting the target interface node and the target application node corresponding to the API traffic data are respectively determined to be the target risk counts after update.

[0080] After obtaining the target risk counts of the corresponding edges updated based on the API traffic data, for each edge included in the community network topology diagram, according to the target risk count corresponding to the edge and the total target risk count of all the edges included in the community network topology diagram, the ratio of the target risk count corresponding to the edge to the total target risk count is determined, and this ratio is determined to be the updated weight value corresponding to the edge.

[0081] Specifically, the updated weight value corresponding to the edge can satisfy the following formula:

[0082]

[0083] Among them, w ′ (e) is the updated weight value corresponding to this edge, w(e) is the target risk count corresponding to this edge, and E(v) represents the set of edges in the community network topology graph.

[0084] In the embodiments of the present application, by updating the weight values of each edge in the community network topology graph, it is possible to determine the impact on the community network topology graph when receiving API traffic data, as well as the change in the risk level corresponding to each edge, which is convenient for accurately identifying whether there is a risk when facing complex data security attacks in the follow-up.

[0085] Embodiment 3:

[0086] In order to further accurately identify whether there is a risk when facing complex data security attacks, on the basis of the above embodiments, in the embodiments of the present application, the risk weight values of each node in the community network topology graph are updated, including:

[0087] For any node, determine the other nodes connected to this node, and determine the updated risk weight value of this node according to the updated weight values corresponding to the edges connected to this node and the updated weight values corresponding to the edges connected to the other node.

[0088] In the embodiments of the present application, after obtaining the updated weight values corresponding to each edge in the community network topology graph, for any node in the community network topology graph, determine the other nodes connected to this node, and determine the sum of the updated weight values corresponding to the edges directly connected to this node (self-loop edges) and the updated weight values corresponding to the edges connected to the other node, and determine this sum as the updated risk weight value of this node.

[0089] Exemplarily, if node a in the community network topology diagram is connected to node b and node c respectively, and node b is further connected to node d, and node c is further connected to node e, then for this node a, the other nodes connected to this node are determined to be node b and node c. According to the updated weight values corresponding to each edge directly connected to this node a (including the edge corresponding to node a - node b and the edge corresponding to node a - node c), as well as the updated weight values corresponding to each edge connected to node b (i.e., other nodes) (including the edge corresponding to node b - node d), and the updated weight values corresponding to each edge connected to node c (i.e., other nodes) (including the edge corresponding to node c - node e), the sum value of the updated weight values corresponding to the edge corresponding to node a - node b, the edge corresponding to node a - node c, the edge corresponding to node b - node d, and the edge corresponding to node c - node e is determined, and this sum value is determined as the updated risk weight value of node a.

[0090] In addition, in the embodiments of the present application, the community weight value corresponding to the community network topology diagram can also be determined. Specifically, according to the risk weight values of each node in the community network topology diagram, the sum value of the risk weight values of each node is determined as the community weight value corresponding to the community network topology diagram.

[0091] In the embodiments of the present application, when determining the risk weight values of each node in the community network topology diagram, not only the weight values of the edges directly connected to this node are considered, but also the weight values of the edges respectively connected to the other nodes connected to this node are combined, so as to more accurately determine the risk weight value of this node in the community network topology diagram, which is convenient for accurately identifying whether there is a risk in the face of complex data security attacks subsequently.

[0092] Embodiment 4:

[0093] Based on the above embodiments, in the embodiments of the present application, if it is determined that the candidate result is that the API traffic data is at risk, the method further includes:

[0094] Determine the risk type existing in the API traffic data;

[0095] Input the community network topology diagram, the updated edge weight values in the community network topology diagram, and the risk weight values of each node into the community discovery model, including:

[0096] Input the community network topology diagram, the updated edge weight values in the community network topology diagram, the risk weight values of each node, and the risk type into the community discovery model.

[0097] In the embodiments of the present application, while analyzing whether the API traffic data is at risk by using the regular detection engine, if it is determined that the API traffic data is at risk, the risk type existing in the API traffic data can also be determined.

[0098] Exemplarily, the risk types include but are not limited to: plaintext password transmission, SQL injection, etc.

[0099] After determining the risk types existing in the API traffic data and obtaining the updated edge weight values and the risk weight values of each node in the community network topology diagram, the community network topology diagram, the updated edge weight values in the community network topology diagram, the risk weight values of each node, and the risk types are input into the community discovery model. Based on this community discovery model, the potential risks in the API traffic data are predicted.

[0100] Embodiment 5:

[0101] In order to implement the detection of complex data security risk monitoring, based on the above embodiments, in the embodiments of the present application, the community discovery model includes evolution units corresponding to each node. Obtaining the prediction results of whether there are risks in the API traffic data output by the community discovery model, and if there are risks, the target risk nodes with risks and the corresponding associated risk nodes output, including:

[0102] For the evolution units corresponding to each node included in the community discovery model, based on this evolution unit, obtain other nodes and edges connected to this node in the community network topology diagram, the risk weight value of this node, and the information of whether it is connected to the first target node, where the first target node is the target interface node, target source IP node, target account node, target terminal node, target application node corresponding to the API traffic data;

[0103] According to the risk types and the information of other nodes and edges connected to each node, the risk weight value of this node, and whether it is connected to the first target node, determine the probability of each node having risks;

[0104] If the probability of any node having risks is greater than the preset threshold, it is determined that the API traffic data has risks, and the node with risks is determined as the target risk node, and the node connected to the target risk node is determined as the associated risk node.

[0105] In the embodiments of the present application, the community discovery model includes evolution units corresponding to each node, a convolutional neural network, a gated integration module, a classifier, etc. Exemplarily, the community discovery model includes m evolution units, and one evolution unit is used to process the information of one node in the community network topology diagram, where m is a positive integer greater than the total number of all nodes in the community network topology diagram. It can be understood that when constructing the community discovery model, the operator can determine the maximum total number of all nodes included in the community network topology diagram according to experience, and construct evolution units greater than the maximum number in the community discovery model.

[0106] Therefore, the community network topology graph, the updated weight values of the edges in the community network topology graph, the risk weight values and risk types of each node are input into each evolution unit in the community discovery model. Each evolution unit determines the node corresponding to the identification information in the community network topology graph according to the identification information of the node corresponding to this evolution unit, and captures at least one other node connected to this node and the edges connected to this other node in this community network topology graph.

[0107] Moreover, each evolution unit can also determine the risk weight value of the node with this identification information according to the updated risk weight values of each node in the input community network topology graph.

[0108] In addition, each evolution unit can also determine whether the node with this identification information is connected to the first target node corresponding to the API traffic data according to the identification information of the node corresponding to this evolution unit.

[0109] Among them, the first target node corresponding to the API traffic data includes the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data.

[0110] The risk type, the information of the other nodes and edges connected to each node output by each evolution unit, and the risk weight value of this node are input into the convolutional neural network. The convolutional neural network can extract and learn the features of each node according to the contribution of this node and the other nodes connected to this node.

[0111] Specifically, the convolutional neural network is a w-layer relationship adaptive convolutional network, and there are multiple convolutional layers in this convolutional neural network. Each convolutional layer can determine the embedding relationship of this node output in this convolutional layer according to the embedding relationship output by the previous convolutional layer of this node and the embedding relationship output by the previous convolutional layer of the other nodes connected to this node, and input this embedding relationship into the next convolutional layer, so as to realize combining the features of the other nodes connected to this node to determine the corresponding features of this node.

[0112] Among them, the embedding relationship of this node output in this convolutional layer includes:

[0113]

[0114] Among them, u represents this node; v represents the other node connected to this node; t represents the current moment. represents the embedding relationship of this node output in the l-th layer of this convolutional layer at the t-th moment (that is, the embedding relationship input into the (l + 1)-th convolutional layer in the next layer). represents the embedding relationship of this node input into the l-th layer of this convolutional layer at the t-th moment (that is, the embedding relationship output by the previous convolutional layer). Represents the embedding relationship of other nodes connected to this node at time t in the input of the l-th convolutional layer (i.e., the embedding relationship output in the previous convolutional layer); Represents the embedding of the relationship (u, v) at time t; (u, v) represents the edge connecting this node to other nodes; c u Represents the degree of node u, and c u Is a constant; f(·) is an activation function; and Represents the feature weight matrix of the l-th convolutional layer.

[0115] Among them, when using the community discovery model to process the community network topology graph, a feature seed bank storing multiple high-risk factors also needs to be input into the community discovery model, so that the community discovery model can determine the feature weight matrix of each convolutional layer in the convolutional neural network according to the node information with risks stored in the feature seed bank and

[0116] Through the above process, the convolutional neural network outputs the risk features of each node at time t, and inputs the risk features of each node at time t into the gated integration module. The gated integration module fuses, for each node, the risk feature of this node at time t and the historical risk feature of this node at time t - 1 saved when the community discovery model processes the historical community network topology graph at the previous preset time, to obtain the fused risk feature of this node, so as to be able to consider the risks between the features adjacent in time and grasp the context and rules of time development.

[0117] Among them, the determination process of the fused feature risk can satisfy the following formula:

[0118]

[0119] Among them, H t Is the fused risk feature of this node at time t, Is the risk feature of this node at time t, H t-1 Is the historical risk feature of this node at time t - 1, Represents the Hadamard product; U t Is the gating factor, and U t Determines the proportion of the risk feature at time t and the historical risk feature at time t - 1, endowing the model with the ability to dynamically adjust according to the time context.

[0120] Specifically, U t Can satisfy the following formula:

[0121] U t = σ(W 3 H t-1 + b)

[0122] Among them, σ represents the activation function, usually the Sigmoid activation function, and the output range is [0, 1]; b is the bias term; W 3 represents the weight matrix; U t is generated through the feature H at the previous moment t-1 and linear transformation. After passing through the Sigmoid activation function, it is mapped between 0 and 1, indicating the degree of fusion between the risk feature at time t and the historical risk feature at time t - 1. The closer U t is to 1, the better the degree of fusion.

[0123] After inputting the fusion risk features of each node into the classifier in the community discovery model, based on this classifier, the classification result is output, where the classification result includes the probability that each node has a risk (i.e., each node is a risk node).

[0124] Based on the classification result output by the classifier, it is judged whether there is any node whose risk probability is greater than the preset threshold. If so, it is determined that the API traffic data has a risk, and the node with a risk (i.e., the node whose risk probability is greater than the preset threshold) is determined as the target risk node, and the node connected to this target risk node is determined as the associated risk node, and the prediction result of whether the API traffic data has a risk, and if there is a risk, the output target risk node with a risk and the corresponding associated risk node is output.

[0125] On the basis of the above embodiments, when training the community discovery model, for each training community network topology graph in the training set, determine the true label corresponding to each node in this training community network topology graph (i.e., whether this node is a risk node), input this training community network topology graph, the weight values of each edge in this training community network topology graph, and the risk weight values of each node into the community discovery model to be trained. After being processed by each module in the community discovery model to be trained, obtain the predicted probability that each node in this training community network topology graph has a risk output by the classifier.

[0126] According to the true label and predicted probability of each node in the training community network topology graph, based on the loss function, determine the loss value, and train the community discovery model to be trained based on this loss value until the training function meets the preset requirements, then it is determined that the training of the community discovery model to be trained is completed, and the trained community discovery model is obtained.

[0127] Among them, the loss value can satisfy the following formula:

[0128]

[0129] Among them, L is the loss value, N is the number of samples (i.e., the number of nodes included in the training community network topology graph), yi represents the true label of the i-th sample (i.e., the i-th node), represents the predicted probability of the i-th sample.

[0130] In addition, based on the above embodiments, in the embodiments of the present application, when it is obtained that the output result of the community discovery model is that the API traffic data is at risk, the target risk nodes with risks and the prediction results of the corresponding associated risk nodes output by the community discovery model are obtained.

[0131] In a possible implementation, the information of the target risk node and the corresponding associated risk node is updated to the feature seed library.

[0132] In another possible implementation, in order to more accurately determine whether the target risk node and the corresponding associated risk node are high-risk factors, the electronic device outputs a prompt message, and the prompt message carries the identification information of the target risk node and the corresponding associated risk node, so that the operator can combine experience and the traceability topology diagram to determine whether the target risk node and the corresponding associated risk node are high-risk factors. If a correct instruction input by the operator is received, it is determined that the target risk node and the corresponding associated risk node are high-risk factors, and the information of the target risk node and the corresponding associated risk node is updated to the feature seed library; if an incorrect instruction input by the operator is received, it is determined that the target risk node and the corresponding associated risk node are not high-risk factors.

[0133] Among them, the traceability topology diagram is determined according to the traceability data of each API traffic data stored in clickhouse.

[0134] Exemplarily, as Figure 3 shown, according to the source IP, access interface identification information, destination IP, destination port and other information in the traceability data of each API traffic data stored in clickhouse, corresponding source IP nodes, API interface nodes, and application nodes are constructed in the traceability topology diagram, and the source IP node is used as the edge node, and they are connected in sequence according to the order of the source IP node, API interface node, and application node, that is, there is a connection relationship between the source IP node and the API interface node, and there is a connection relationship between the API interface node and the application node. In addition, it can be understood that Figure 3 the shown traceability topology diagram is only an example. In fact, in the traceability topology diagram, in addition to the source IP node, API interface node, and application node, it may also include account nodes, terminal nodes, etc., and various types of nodes are connected in the same connection order as the community network topology diagram.

[0135] After obtaining the updated feature seed library, input the updated feature seed library into the community discovery model, so that the community discovery model can combine the updated feature seed library to predict the risks of each node in the subsequent input community network topology graph.

[0136] In the embodiments of the present application, when each module in the community discovery model processes the community network topology graph, when processing each node, the features of other nodes connected to the node and the features of the node at the previous moment are also combined. Therefore, data risks can be predicted, and complex data security risk monitoring can be realized.

[0137] Embodiment 6:

[0138] Based on the above embodiments, in the embodiments of the present application, the evolution unit includes a graph convolutional neural network and a gated integration component. Then, based on the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph, the risk weight value of the node, and the information on whether it is connected to the first target node, including:

[0139] Based on the graph convolutional neural network in the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph, and the risk weight value of the node;

[0140] Based on the gated integration component in the evolution unit, determine whether there is a first target node among other nodes connected to the node.

[0141] In the embodiments of the present application, each evolution unit includes a graph convolutional neural network and a gated integration component. It can be understood that the gated integration component and the gated integration module mentioned above are two different modules.

[0142] Therefore, after inputting the community network topology graph, the updated weight values of the edges in the community network topology graph, the risk weight values and risk types of each node into each evolution unit in the community discovery model, the graph convolutional neural network in the evolution unit determines the node corresponding to the identification information in the community network topology graph according to the identification information of the node corresponding to the evolution unit, and captures at least one other node connected to the node and the edges connected to the other node in the community network topology graph; and determines the risk weight value of the node corresponding to the identification information according to the updated risk weight values of each node in the input community network topology graph.

[0143] The gated integration component in the evolution unit determines whether the node corresponding to the identification information is connected to the first target node corresponding to the API traffic data according to the identification information of the node corresponding to the evolution unit. If so, it is determined that the node corresponding to the identification information has the above risk type. If not, it is determined that the node corresponding to the identification information does not have the above risk type.

[0144] In addition, it can be understood that, based on the above embodiments, the API traffic data risk prediction method provided by the embodiments of the present application is applicable to various scenarios. For example:

[0145] In Scenario 1, the API system of the company is poorly managed and unable to perceive the ongoing data security risks. The API traffic data risk prediction method provided by the embodiments of the present application can be used to manage all API traffic data in the API system. And for companies that already have data security analysis tools but lack comprehensive monitoring capabilities, this method can be integrated into the existing system to improve the comprehensiveness of risk detection through the community network topology map and overcome the limitations of traditional algorithms.

[0146] In Scenario 2, a data element transfer platform is constructed. With the promulgation of the Data Security Law, each company has started to construct a data element transfer platform. As the most important link in data transfer, API traffic data can be observable and measurable through the API traffic data monitoring in the API traffic data risk prediction method provided by the embodiments of the present application. And in large enterprises, in the face of complex and changeable network traffic, this method can efficiently analyze the data flow link, timely identify potential security risks, and ensure the security of the business system.

[0147] In Scenario 3, for some highly sensitive systems, such as classified and sensitive systems, the API traffic data risk prediction method provided by the embodiments of the present application can be used for real-time early warning, to perceive the message returned by each system call in real time, and can timely warn of risks through the community discovery model, which can help operation personnel discover and timely block the ongoing data security risks. In the face of real data theft or illegal operation scenarios, this API traffic data risk prediction method can quickly identify and block potential security events through the intelligent early warning mechanism, protecting sensitive data from threats.

[0148] The following uses a specific embodiment to illustrate the above embodiments. Refer to Figure 4 the schematic diagram of the API traffic data risk prediction process, including the following steps:

[0149] Step 1, collect API traffic data and save the traceability data in the API traffic data to ClickHouse.

[0150] Step 2: Denoise the collected API traffic data. Among them, the API traffic data can be filtered according to the saved traffic whitelist to achieve denoising of the API traffic. Analyze the denoised API traffic data using a regular detection engine to determine whether there are candidate results of vulnerability risks in the API traffic data, and if there are risks, determine the corresponding risk types. Parse the denoised API traffic data to extract the access account, interface information, source IP, access terminal identification information, application identification information, destination IP, and destination port included in the API traffic data.

[0151] Step 3: Update the community network topology graph using Louvain.

[0152] According to the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data, determine the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology graph. Obtain the current risk count corresponding to each edge in the saved community network topology graph. According to the update value corresponding to the candidate result and the current risk count of the edges corresponding to the connections between the target interface node, target source IP node, target account node, target terminal node, and target application node, obtain the target risk count of the corresponding edge after update. For each edge included in the community network topology graph, determine the updated weight value of the edge according to the target risk count of the edge and the total target risk count of all edges included in the community network topology graph.

[0153] For any node in the community network topology graph, determine the other nodes connected to the node, and according to the updated weight values of the edges corresponding to the connections to the node and the updated weight values of the edges corresponding to the connections to the other nodes, determine the updated risk weight value of the node.

[0154] Based on whether there are candidate results of vulnerability risks in the API traffic data of the electronic device, determine the research and judgment results of the risks of each node, and obtain the high-risk nodes input by the operation personnel based on experience judgment. According to the research and judgment results and the high-risk nodes input by the operation personnel, determine the characteristic seed library storing high-risk communities. Among them, the high-risk community includes high-risk nodes and other nodes connected to the high-risk nodes.

[0155] Step 4: According to the community network topology graph in each preset access time period, determine the evolution graph of the integrated entity relationship. The evolution graph includes multiple preset access time periods and the corresponding community network topology graphs, which is convenient for training the community discovery model according to the community network topology graph corresponding to each preset access time period.

[0156] Input the community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node into the community discovery model to obtain whether there is a risk in the API traffic data output by the community discovery model, and the prediction results of the target risk nodes with risks and the corresponding associated risk nodes output if there are risks.

[0157] Embodiment 7:

[0158] Based on the same technical concept, on the basis of the above embodiments, the present application provides an API traffic data risk prediction device. Figure 5 As shown in the structure schematic diagram of an API traffic data risk prediction device provided by an embodiment of the present application, Figure 5 As shown, the device includes:

[0159] A determination module 501, configured to determine a candidate result of whether there is a risk in the received API traffic data;

[0160] An update module 502, configured to update the weight values of the edges connecting the corresponding nodes in the community network topology graph and the risk weight values of each node based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate result of the API traffic data;

[0161] A prediction module 503, configured to input the community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of each node into the community discovery model to obtain whether there is a risk in the API traffic data output by the community discovery model, and the prediction results of the target risk nodes with risks and the corresponding associated risk nodes output if there are risks.

[0162] In a possible implementation manner, the update module 502 is specifically configured to determine, according to the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data, the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology graph; obtain the current risk times corresponding to each edge in the saved community network topology graph; obtain the target risk times of the updated corresponding edges according to the update value corresponding to the candidate result and the current risk times of the edges corresponding to the connection between the target interface node, target source IP node, target account node, target terminal node, and target application node; for each edge included in the community network topology graph, determine the updated weight value corresponding to the edge according to the target risk times corresponding to the edge and the total target risk times of all the edges included in the community network topology graph.

[0163] In a possible implementation, the update module 502 is specifically configured to, for any node, determine other nodes connected to the node, and determine the updated risk weight value of the node according to the updated weight values corresponding to the edges connected to the node and the updated weight values corresponding to the edges connected to the other node.

[0164] In a possible implementation, the determination module 501 is further configured to, if it is determined that the candidate result is that the API traffic data is at risk, determine the type of risk existing in the API traffic data;

[0165] The prediction module 503 is specifically configured to input the community network topology graph, the updated weight values of the edges in the community network topology graph, the risk weight values and risk types of each node into the community discovery model.

[0166] In a possible implementation, the community discovery model includes an evolution unit corresponding to each node. The prediction module 503 is specifically configured to, for the evolution unit corresponding to each node included in the community discovery model, based on the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph, the risk weight value of the node, and information on whether it is connected to a first target node, where the first target node is the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data; determine the probability of each node being at risk according to the risk type and the information on other nodes and edges connected to each node, the risk weight value of the node, and whether it is connected to the first target node; if the probability of any node being at risk is greater than a preset threshold, determine that the API traffic data is at risk, determine the node with risk as the target risk node, and determine the node connected to the target risk node as the associated risk node.

[0167] In a possible implementation, the evolution unit includes a graph convolutional neural network and a gated integration component. The prediction module 503 is specifically configured to, based on the graph convolutional neural network in the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph and the risk weight value of the node; based on the gated integration component in the evolution unit, determine whether there is a first target node among the other nodes connected to the node.

[0168] Example 8:

[0169] Based on the same technical concept, the present application further provides an electronic device, Figure 6 which is a schematic structural diagram of an electronic device provided in an embodiment of the present application. As Figure 6 shown, it includes: a processor 601, a communication interface 602, a memory 603, and a communication bus 604. Among them, the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604;

[0170] A computer program is stored in the memory 603. When the program is executed by the processor 601, the processor 601 is caused to perform the following steps:

[0171] Determine whether there is a candidate result of risk in the received API traffic data;

[0172] Based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate result of the API traffic data, update the weight value of the edge connecting the corresponding nodes in the community network topology graph and the risk weight value of each node.

[0173] Input the community network topology graph, the updated weight value of the edge in the community network topology graph, and the risk weight value of each node into the community discovery model, and obtain the prediction result of whether there is a risk in the API traffic data output by the community discovery model, and if there is a risk, the target risk node with risk and the corresponding associated risk node output.

[0174] In a possible implementation manner, the processor 601 is specifically configured to determine, according to the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology graph; obtain the current risk times corresponding to each edge in the saved community network topology graph; and obtain the target risk times of the corresponding updated edge according to the update value corresponding to the candidate result and the current risk times of the edges corresponding to the connections between the target interface node, target source IP node, target account node, target terminal node, and target application node. For each edge included in the community network topology graph, determine the updated weight value corresponding to the edge according to the target risk times corresponding to the edge and the total target risk times of all the edges included in the community network topology graph.

[0175] In a possible implementation manner, the processor 601 is specifically configured to, for any node, determine the other nodes connected to the node, and determine the updated risk weight value of the node according to the updated weight values of the edges corresponding to the connections to the node and the updated weight values of the edges corresponding to the connections to the other nodes.

[0176] In a possible implementation manner, the processor 601 is further configured to, if it is determined that the candidate result is that there is a risk in the API traffic data, determine the type of risk existing in the API traffic data;

[0177] The processor 601 is specifically configured to input the community network topology graph, the weight values of the updated edges in the community network topology graph, the risk weight values of each node, and the risk types into the community discovery model.

[0178] In a possible implementation manner, the processor 601 is specifically configured to, for each evolution unit corresponding to a node included in the community discovery model, based on the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph, the risk weight value of the node, and information on whether the node is connected to a first target node, where the first target node is a target interface node, a target source IP node, a target account node, a target terminal node, or a target application node corresponding to the API traffic data; determine the probability of risk for each node according to the risk type, the other nodes and edges connected to each node, the risk weight value of the node, and the information on whether the node is connected to the first target node; if the probability of risk for any node is greater than a preset threshold, determine that the API traffic data is at risk, determine the node with risk as the target risk node, and determine the nodes connected to the target risk node as associated risk nodes.

[0179] In a possible implementation manner, the processor 601 is specifically configured to, based on the graph convolutional neural network in the evolution unit, obtain other nodes and edges connected to the node in the community network topology graph, and the risk weight value of the node; based on the gated integration component in the evolution unit, determine whether there is a first target node among the other nodes connected to the node.

[0180] The communication bus mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0181] The communication interface 602 is used for communication between the above electronic device and other devices.

[0182] The memory may include a Random Access Memory (RAM), and may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0183] The above-mentioned processor may be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0184] Embodiment 9:

[0185] Based on the same technical concept, an embodiment of the present application provides a computer-readable storage medium, in which a computer program executable by an electronic device is stored. When the program runs on the electronic device, the electronic device is caused to execute the following steps when executing:

[0186] Determine whether there is a candidate result of risk in the received API traffic data;

[0187] Based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, and the candidate result of the API traffic data, update the weight value of the edge connecting the corresponding nodes in the community network topology diagram and the risk weight value of each node;

[0188] Input the community network topology diagram, the updated weight value of the edge in the community network topology diagram, and the risk weight value of each node into the community discovery model, and obtain the prediction result of whether there is a risk in the API traffic data output by the community discovery model, and if there is a risk, the target risk node and the corresponding associated risk node output;

[0189] In a possible implementation manner, based on the interface information, source IP, access account, access terminal identification information, application identification information carried in the API traffic data, and the candidate result of the API traffic data, updating the weight value of the edge connecting the corresponding nodes in the community network topology diagram includes:

[0190] According to the interface information, source IP, access account, access terminal identification information, destination IP, destination port carried in the API traffic data, determine the target interface node, target source IP node, target account node, target terminal node, target application node corresponding to the API traffic data in the community network topology diagram;

[0191] Obtain the current risk count corresponding to each edge in the saved community network topology diagram;

[0192] Based on the updated value corresponding to the candidate result and the current risk count of the edges connecting the target interface node, target source IP node, target account node, target terminal node, and target application node, obtain the target risk count of the corresponding edge after the update;

[0193] For each edge included in the community network topology graph, determine the updated weight value corresponding to the edge according to the target risk count corresponding to the edge and the total target risk count of all the edges included in the community network topology graph.

[0194] In a possible implementation manner, updating the risk weight values of the nodes in the community network topology graph includes:

[0195] For any node, determine the other nodes connected to the node, and determine the updated risk weight value of the node according to the updated weight values of the edges connected to the node and the updated weight values of the edges connected to the other node.

[0196] In a possible implementation manner, if it is determined that the candidate result is that the API traffic data is at risk, the method further includes:

[0197] Determine the risk type existing in the API traffic data;

[0198] Input the community network topology graph, the updated weight values of the edges in the community network topology graph, and the risk weight values of the nodes into the community discovery model, including:

[0199] Input the community network topology graph, the updated weight values of the edges in the community network topology graph, the risk weight values of the nodes, and the risk type into the community discovery model.

[0200] In a possible implementation manner, the community discovery model contains evolution units corresponding to each node. Obtain the prediction result of whether the API traffic data is at risk output by the community discovery model, and if there is a risk, the target risk nodes and the corresponding associated risk nodes output, including:

[0201] For the evolution units corresponding to each node included in the community discovery model, based on the evolution unit, obtain the other nodes and edges connected to the node in the community network topology graph, the risk weight value of the node, and the information on whether it is connected to the first target node, where the first target node is the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data;

[0202] According to the risk type and the information on the other nodes and edges connected to each node, the risk weight value of the node, and whether it is connected to the first target node, determine the probability of each node being at risk;

[0203] If the probability that any node has a risk is greater than a preset threshold, it is determined that the API traffic data has a risk, the node with the risk is determined as the target risk node, and the nodes connected to the target risk node are determined as associated risk nodes.

[0204] In a possible implementation manner, the evolution unit includes a graph convolutional neural network and a gated integration component. Based on this evolution unit, other nodes and edges connected to this node in the community network topology graph, the risk weight value of this node, and the information on whether it is connected to the first target node are obtained, including:

[0205] Based on the graph convolutional neural network in this evolution unit, other nodes and edges connected to this node in the community network topology graph, and the risk weight value of this node are obtained;

[0206] Based on the gated integration component in this evolution unit, it is determined whether there is a first target node among the other nodes connected to this node.

[0207] The above computer-readable storage medium can be any available medium or data storage device accessible by the processor in the electronic device, including but not limited to magnetic memories such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc., optical memories such as CDs, DVDs, BDs, HVDs, etc., and semiconductor memories such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid-state drives (SSD), etc.

[0208] Based on the same technical concept, the embodiment of the present application also provides a computer program product, which includes: computer program code. When the computer program code runs on a computer, it causes the computer to execute any of the above embodiments. Since the principle of solving problems by the above computer program product is similar to that of the API traffic data risk prediction method, the implementation of the above computer program product can refer to the implementation of the method, and the repeated parts will not be described again.

[0209] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0210] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to the application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0211] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0212] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0213] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. A method for predicting risk of application programming interface (API) traffic data, characterized in that: The method comprises: Determine whether the received API traffic data is a candidate for risk; Based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port and candidate results of the API traffic data carried in the API traffic data, the weight values ​​of the edges connecting the corresponding nodes in the community network topology diagram and the risk weight value of each node are updated; The community network topology map, the updated edge weight values ​​in the community network topology map, and the risk weight values ​​of each node are input into the community discovery model to obtain whether the API traffic data output by the community discovery model has risks, and if there is a risk, the prediction results of the target risk nodes with risks and the corresponding associated risk nodes are output.

2. The method according to claim 1, characterized in that The updating of the weight values ​​of the edges connecting the corresponding nodes in the community network topology diagram based on the interface information, source IP, access account, access terminal identification information, application identification information carried in the API traffic data and the candidate results of the API traffic data includes: According to the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data, determine the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology diagram; Obtaining the current risk count corresponding to each edge in the saved community network topology graph; According to the updated value corresponding to the candidate result and the current risk number of the edge corresponding to the connection between the target interface node, the target source IP node, the target account node, the target terminal node, and the target application node, the target risk number of the corresponding edge after update is obtained; For each edge included in the community network topology graph, an updated weight value corresponding to the edge is determined according to the target risk number corresponding to the edge and the total target risk number of all edges included in the community network topology graph.

3. The method according to claim 1 or 2, characterized in that: The updating of the risk weight value of each node in the community network topology diagram includes: For any node, determine the other nodes connected to the node, and determine the updated risk weight value of the node based on the updated weight values ​​corresponding to the edges connected to the node and the updated weight values ​​corresponding to the edges connected to the other nodes.

4. The method according to claim 1, characterized in that: If it is determined that the candidate result is that the API traffic data has a risk, the method further includes: Determine the type of risk present in the API traffic data; The step of inputting the community network topology graph, the updated edge weight values ​​in the community network topology graph, and the risk weight values ​​of each node into the community discovery model includes: The community network topology graph, the updated edge weight values ​​in the community network topology graph, the risk weight value of each node and the risk type are input into the community discovery model.

5. The method according to claim 4, characterized in that The community discovery model includes an evolution unit corresponding to each node, and the step of obtaining whether the API traffic data output by the community discovery model has a risk, and if there is a risk, outputting a prediction result of a target risk node with a risk and a corresponding associated risk node, includes: For each evolution unit corresponding to each node included in the community discovery model, based on the evolution unit, obtain other nodes and edges connected to the node in the community network topology diagram, the risk weight value of the node, and information on whether the node is connected to a first target node, wherein the first target node is a target interface node, a target source IP node, a target account node, a target terminal node, and a target application node corresponding to the API traffic data; Determine the probability that each node has a risk according to the risk type, other nodes and edges connected to each node, the risk weight value of the node, and information on whether the node is connected to the first target node; If the probability that any node is at risk is greater than a preset threshold, the API traffic data is determined to be at risk, and the node at risk is determined as the target risk node, and the node connected to the target risk node is determined as the associated risk node.

6. The method according to claim 5, characterized in that The evolution unit includes a graph convolutional neural network and a gated integration component, and the acquisition of other nodes and edges connected to the node in the community network topology graph, the risk weight value of the node, and information on whether the node is connected to the first target node based on the evolution unit includes: Based on the graph convolutional neural network in the evolution unit, other nodes and edges connected to the node in the community network topology graph and the risk weight value of the node are obtained; Based on the gating integration component in the evolution unit, it is determined whether there is a first target node among other nodes connected to the node.

7. An API flow data risk prediction device, characterized in that: The device comprises: A determination module, used to determine whether the received API traffic data contains risky candidate results; An updating module, configured to update the weight values ​​of the edges connecting the corresponding nodes in the community network topology diagram and the risk weight value of each node based on the interface information, source IP, access account, access terminal identification information, destination IP, destination port and candidate results of the API traffic data carried in the API traffic data; The prediction module is used to input the community network topology map, the updated edge weight values ​​in the community network topology map and the risk weight values ​​of each node into the community discovery model, obtain whether the API traffic data output by the community discovery model has risks, and if there is a risk, output the prediction results of the target risk nodes with risks and the corresponding associated risk nodes.

8. The device according to claim 7, characterized in that The update module is specifically used to determine the target interface node, target source IP node, target account node, target terminal node, and target application node corresponding to the API traffic data in the community network topology diagram according to the interface information, source IP, access account, access terminal identification information, destination IP, and destination port carried in the API traffic data; Obtaining the current risk count corresponding to each edge in the saved community network topology graph; According to the updated value corresponding to the candidate result and the current risk number of the edge corresponding to the connection between the target interface node, the target source IP node, the target account node, the target terminal node, and the target application node, the target risk number of the corresponding edge after update is obtained; For each edge included in the community network topology graph, an updated weight value corresponding to the edge is determined according to the target risk number corresponding to the edge and the total target risk number of all edges included in the community network topology graph.

9. An electronic device, characterized in that: The electronic device includes at least a processor and a memory, and the processor is used to implement the steps of the API traffic data risk prediction method as described in any one of claims 1-6 when executing the computer program stored in the memory.

10. A computer storage medium, characterized in that: It stores a computer program that can be executed by an electronic device. When the program runs on the electronic device, the electronic device executes the steps of the API traffic data risk prediction method described in any one of claims 1-6.

Citation Information

Cited By

  • System and method for dynamically evaluating social risk of community correction object

    CN120851612A

  • Method and device for constructing API topological relation graph, equipment and medium

    CN121350516A

  • A method, apparatus, device, and medium for constructing API topology graphs

    CN121350516B