Method for detecting interface attack based on request parameter association number features

By setting interface request parameter access rules and continuously detecting interface access frequency and parameter changes, the problem of difficult to identify and block camouflage parameter traversal attacks in the existing technology is solved, real-time monitoring and analysis of interface abnormal access is realized, and detection performance and alarm timeliness are improved.

CN120223369APending Publication Date: 2025-06-27HAIER CONSUMER FINANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510288205.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When facing attacks on dynamic changes in interface parameters and business logic-related features, the existing security protection system is difficult to identify and block the disguised parameter traversal attacks in real time, and the update of the rule base lags behind the evolution of attack methods, increasing the risk of being attacked.

Method used

By setting interface request parameter access rules, recording interface access logs, and setting interface access thresholds, continuously detecting interface access frequency and parameter changes, extracting access behaviors that meet specific parameter transformation rules for alarms, and restricting malicious access behaviors.

Benefits of technology

Real-time monitoring and analysis and handling of abnormal interface access is realized, effectively identifying and blocking malicious access traffic, improving detection performance, saving computing resources, and ensuring detection alarm timeliness.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses a method for detecting an interface attack based on request parameter association number characteristics, which comprises the following steps of: setting an interface request parameter access rule for an interface needing security detection, recording an access log of an application system interface, setting an interface access threshold value m, continuously detecting interface access frequency, and when the request frequency exceeds the interface access threshold value m, executing the step of executing the step of executing the step of executing the step of executing the step of executing the step of executing the step of executing the step of executing the step. Obtaining an access record log corresponding to the detection interface, extracting a request parameter in an access record, comparing the request parameter with a preset interface request parameter access rule, calculating and comparing access characteristics of the access parameter, and giving an alarm for an interface access behavior conforming to a specific parameter transformation rule. According to the method, malicious behaviors such as black production attacks and data capture possibly caused by access through abnormal change of the interface parameters can be detected, and the malicious access traffic of the interface can be effectively identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security, and particularly to a method for detecting interface attacks based on the correlation number characteristics of request parameters. Background Art

[0002] With the rapid development of Internet applications, data interaction based on API interfaces has become the main form of the core capability output of application systems. However, black production organizations have also begun to use automated tools to detect and attack interfaces. Attackers use distributed low-frequency requests or parameter randomization combinations to avoid traditional access frequency-based defense mechanisms. By using the correspondence between multi-dimensional parameter combinations and return results, they reverse-deduce privacy information such as user behavior trajectories and account statuses. The data obtained can be used to build accurate user portraits, providing support for illegal activities such as fraud, credential stuffing, and data reselling.

[0003] Existing security protection systems have significant defects when facing such attacks. Using conventional risk control strategies only focuses on single-dimensional data such as access frequency and parameter format, and easily ignores the correlation characteristics between the dynamic changes of interface parameters and business logic, resulting in difficulty in identifying disguised parameter traversal attacks and lacking systematic tracking of the parameter evolution rules between multiple requests. As a result, real-time blocking during the attack process is often impossible. If relying on post-event log analysis to train a parameter change model based on historical logs, a large amount of labeled data is required, and the model training cycle is long. The consequence of this is that the rule library update is easily lagged behind the evolution of attack means, greatly increasing the risk of being attacked. Summary of the Invention

[0004] The purpose of the present invention is to provide a method for detecting interface attacks based on the correlation number characteristics of request parameters, which can not only detect malicious behaviors such as black production attacks and data scraping that may be caused by abnormal changes in interface parameters, but also timely discover interface abnormal access risks and perform corresponding analysis and handling.

[0005] To achieve the above object, the present invention is realized through the following technical solutions: A method for detecting interface attacks based on the correlation number characteristics of request parameters, comprising the steps of: Setting interface request parameter access rules for the interfaces that need security detection; Recording the access logs of the application system interfaces and setting an interface access threshold m; Continuously detecting the interface access frequency. When the request frequency exceeds the interface access threshold m, obtaining the access record logs corresponding to the detected interfaces; Extracting the request parameters in the access records, comparing them with the preset interface request parameter access rules, calculating the access characteristics of the comparison access parameters, and alarming the interface access behaviors that conform to specific parameter transformation rules.

[0006] Furthermore, the interface request parameter access rules include: Based on the importance of the system and the interface characteristics, select the key information query interfaces of the application systems to be detected, and select the interface parameters to be detected; Sort out the request parameters of the interface or the combined query scenarios of the parameters, and select the parameters to be detected according to the query scenarios; Divide the parameters into invariant parameters x and variable parameters a according to whether the parameter values are fixed or variable; Set the access frequency threshold n for the invariant parameter x, and mark the variable parameter a as the analysis parameter; Statistically count the access frequency of the invariant parameter x, and when it exceeds the access frequency threshold n, give an abnormal alarm.

[0007] Furthermore, it also includes the steps: After receiving the abnormal alarm, extract the value of the variable parameter a when the current detected interface meets the invariant parameter x; Analyze the change law of the variable parameter a. If there are multiple highly similar characteristics in the variable parameter a, it is considered that there is malicious access behavior for the current interface, and the request for the invariant parameter x of the current interface is restricted.

[0008] Furthermore, the highly similar characteristics include regular increase or decrease, and randomly changing individual characters.

[0009] Furthermore, the determination of the interface access threshold m includes the steps: Conduct statistical learning on the interface access volume, and obtain the access traffic of the interface by querying the historical normal access volume of the interface; Set the interface access threshold m according to the statistically historical normal business access volume.

[0010] The advantages of the present invention are as follows: By refining the detection of the change of the interface request parameter values, refined monitoring of abnormal access to the application system interfaces is realized, and malicious access traffic of the interfaces is effectively identified.

[0011] By setting double interface access frequency thresholds, the detection performance is improved, computing resources are effectively saved, and the detection and alarm timeliness is guaranteed. Specific implementation manners

[0012] Next, the technical solutions in the embodiments of the present invention will be described clearly and completely.

[0013] This embodiment proposes a solution for malicious access to the application system interfaces by changing specified parameters, including the following steps.

[0014] Embodiment 1 First, determine the detection interface. According to the importance of the system and the interface characteristics, select the key information query interface of the application system to be detected, and select the interface parameters to be detected.

[0015] Perform statistical learning on the interface access volume. By querying the historical normal access volume of the interface, obtain the access traffic of the interface, and set the interface access threshold m according to the statistically normal business access volume.

[0016] Sort out the request parameters of the interface or the combined query scenarios of the parameters. Select the parameters to be detected according to the query scenarios, and divide the parameters into invariant parameters x and variable parameters a according to whether the parameter values are fixed or changed.

[0017] According to the normal access logic of the business, set the access frequency threshold n of the invariant parameter x, and mark the variable parameter a as the analysis parameter.

[0018] Continuously detect the interface access frequency. When the request frequency exceeds the interface access threshold m, obtain the access record log corresponding to the detection interface.

[0019] Extract the request parameters of the interface in the access log record, compare them with the preset interface request parameter access rules, and calculate the access characteristics of the comparison access parameters. Perform statistical analysis on the access frequency of the invariant parameter x. When the access frequency exceeds the threshold n, an abnormal alarm is issued.

[0020] After receiving the abnormal alarm, extract the value of the variable parameter a when the current detection interface meets the invariant parameter x; Analyze the change rule of the variable parameter a. If the variable parameter a has highly similar characteristics such as multiple regular increases and decreases, randomly changing individual characters, etc., it is considered that there is a malicious access behavior for the current interface, and the request for the invariant parameter x of the current interface is restricted.

[0021] If the value of the parameter a has highly similar characteristics, it is detected that there is a malicious access behavior for the interface.

[0022] Embodiment 2 I. System Interface and Detection Rule Setting 1. This embodiment discloses a method for detecting attacks on important interfaces of an information system named System-A. Set the name of the important interface to be detected as api-a, and this interface has 3 parameters, namely param1, param2, and param3.

[0023] 2. The security detection scenario is that the access frequency of api-a is m times per second, the frequency of the fixed request for the value of parameter param1 + param2 is n, and it is judged whether there is abnormal access according to the change rule of parameter param3.

[0024] II. Rule Detection 3. Detect the access frequency of the detection interface api-a. When it exceeds m times per second, extract the values of parameters param1 and param2. When it is determined that the values of param1 and param2 are the same each time and the access frequency of the same param1 and param2 parameters exceeds n times per second, extract the value of parameter param3.

[0025] 4. Judge param3. If the value of param3 changes regularly in increase and decrease, detect that there is a malicious access behavior in the api-a interface, and block this access behavior after research and judgment.

[0026] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for detecting interface attacks based on request parameter correlation coefficient features, characterized in that: Includes steps: Set interface request parameter access rules for interfaces that require security testing; Record the access log of the application system interface and set the interface access threshold m; Continuously detect the interface access frequency, and when the request frequency exceeds the interface access threshold m, obtain the access record log corresponding to the detection interface; Extract request parameters from access records, compare them with preset interface request parameter access rules, calculate and compare access characteristics of access parameters, and issue alarms for interface access behaviors that conform to specific parameter change rules.

2. The method for detecting interface attacks based on request parameter correlation coefficient characteristics according to claim 1, characterized in that: The interface request parameter access rules include: According to the importance of the system and the interface characteristics, select the key information query interface of the application system that needs to be tested, and select the interface parameters that need to be tested; Sort out the request parameters of the interface or the combined query scenarios of the parameters, and select the parameters to be tested according to the query scenarios; Divide the parameters into constant parameters x and variable parameters a according to whether the parameter values ​​are fixed or variable; Set the access frequency threshold n of the constant parameter x and mark the variable parameter a as the analysis parameter; The access frequency of the constant parameter x is counted, and when it exceeds the access frequency threshold n, an abnormal alarm is issued.

3. The method for detecting interface attacks based on request parameter correlation coefficient characteristics according to claim 2, characterized in that: Also includes the steps: After receiving the abnormal alarm, extract the value of the variable parameter a when the current detection interface meets the constant parameter x; Analyze the changing pattern of the variable parameter a. If the variable parameter a has multiple highly similar features, it is considered that there is malicious access behavior on the current interface, and the request for the invariant parameter x of the current interface is restricted.

4. The method for detecting interface attacks based on request parameter correlation coefficient characteristics according to claim 3 is characterized in that: The highly similar features include regular additions and subtractions, and random changes to individual characters.

5. The method for detecting interface attacks based on request parameter correlation coefficient characteristics according to claim 1, characterized in that: The determination of the interface access threshold m comprises the steps of: Conduct statistical learning on the access volume of the interface and obtain the access flow of the interface by querying the historical normal access volume of the interface; Set the interface access threshold m based on the historical statistics of normal business access volume.