Dynamic front-end safety protection method and device based on behavior analysis

Through real-time monitoring and behavioral analysis, front-end security policies are dynamically adjusted, and the problems of false alarms and underreports in the existing technology are solved, more flexible and intelligent protection is achieved, and security and user experience are enhanced.

CN120296725APending Publication Date: 2025-07-11PING AN HEALTH INSURANCE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510346888.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, dynamic front-end security protection strategies are prone to false alarms and missed reports, and cannot effectively deal with complex and emerging attack modes, affecting user experience and security.

Method used

By receiving user equipment to monitor user interaction data in real time, detect abnormal data based on behavioral analysis, formulate and execute adjustment plans, and issue early warning information to dynamically generate and adjust security policies.

Benefits of technology

Improve the detection capabilities of complex and emerging attacks, reduce false alarms and missed reports, ensure that normal user operations are not affected, improve user experience, reduce the burden of manual maintenance, and improve the level of system automation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296725A_ABST
    Figure CN120296725A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of financial science and technology and front-end security, and discloses a dynamic front-end security protection method, device, equipment and medium based on behavior analysis, and the method comprises the steps: receiving real-time interaction data collected by a user equipment real-timely monitored user through a browser in a user side, and detecting abnormal data based on the real-time interaction data; the detected abnormal data reason is analyzed, and an abnormal data adjustment scheme is formulated; and executing the abnormal data adjustment scheme and issuing early warning information. And through real-time behavior analysis and dynamic adjustment strategies, the detection capability on complex and emerging attacks is improved, and the overall security is enhanced. And the security policy is dynamically generated and adjusted, and the complexity and error risk of static configuration are reduced. The system can adapt to new attack modes and threat changes in real time, and more flexible and intelligent protection is provided. By reducing false alarms and missing alarms, normal user operation is ensured not to be affected, and user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of fintech and front-end security, and particularly to a dynamic front-end security protection method, device, equipment and medium based on behavior analysis. Background Art

[0002] In the prior art, the strategy of dynamic front-end security protection mainly prevents XSS attacks (Cross-Site Scripting) by defining the allowed content sources to be loaded. However, improper configuration may lead to security vulnerabilities. Usually relying on static configuration, it cannot dynamically respond to new attack patterns and complex attack scenarios. Or, through the configuration of CSP (Content Security Policy) and HTTP (HyperText Transfer Protocol) security headers in the user device page, such as X-Frame-Options and Strict-Transport-Security, to prevent clickjacking and enforce the use of HTTPS. However, these strategies may not be able to cope with complex attack techniques. The above prior arts may all lead to false positives and false negatives, affecting user experience and security. Summary of the Invention

[0003] The present invention provides a dynamic front-end security protection method, device, computer equipment and medium based on behavior analysis to solve the technical problem that the strategies of dynamic front-end security protection in the prior art are prone to false positives and false negatives.

[0004] In a first aspect, a dynamic front-end security protection method based on behavior analysis is provided, including:

[0005] Receiving real-time interaction data collected by real-time monitoring of a user device by a user, and detecting abnormal data based on the real-time interaction data;

[0006] Analyzing the cause of the detected abnormal data and formulating an adjustment plan for the abnormal data;

[0007] Executing the adjustment plan for the abnormal data and issuing a warning message.

[0008] In a second aspect, a dynamic front-end security protection device based on behavior analysis is provided, including:

[0009] A receiving module, configured to receive real-time interaction data collected by real-time monitoring of a user device by a user, and detect abnormal data based on the real-time interaction data;

[0010] An analyzing module, configured to analyze the cause of the detected abnormal data and formulate an adjustment plan for the abnormal data;

[0011] An execution module for executing an abnormal data adjustment plan and issuing a warning message.

[0012] In a third aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned dynamic front-end security protection method based on behavior analysis are implemented.

[0013] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the above-mentioned dynamic front-end security protection method based on behavior analysis are implemented.

[0014] In the solutions implemented by the above-mentioned dynamic front-end security protection method, device, computer device, and storage medium based on behavior analysis, real-time interaction data collected by a user device can be received through a browser in the user terminal, and abnormal data can be detected based on the real-time interaction data; the reasons for the detected abnormal data can be analyzed and an abnormal data adjustment plan can be formulated; the abnormal data adjustment plan can be executed and a warning message can be issued. Through real-time behavior analysis and dynamic adjustment strategies, the detection ability for complex and emerging attacks can be improved, and the overall security can be enhanced. Security policies can be dynamically generated and adjusted, reducing the complexity and error risk of static configuration. The system can adapt to new attack patterns and threat changes in real time, providing more flexible and intelligent protection. By reducing false positives and false negatives, it is ensured that normal user operations are not affected, and the user experience is improved. The protection policy can be automatically updated and adjusted, reducing the manual maintenance burden and improving the automation level of the system. Description of the Drawings

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 is a schematic diagram of an application environment of the dynamic front-end security protection method based on behavior analysis in an embodiment of the present invention;

[0017] Figure 2 is a schematic flowchart of the dynamic front-end security protection method based on behavior analysis in an embodiment of the present invention;

[0018] Figure 3 is a schematic structural diagram of the dynamic front-end security protection device based on behavior analysis in an embodiment of the present invention;

[0019] Figure 4It is a schematic structural diagram of a computer device in an embodiment of the present invention;

[0020] Figure 5 It is another schematic structural diagram of a computer device in an embodiment of the present invention. Detailed implementation manners

[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0022] The dynamic front-end security protection method based on behavior analysis provided by the embodiments of the present invention can be applied in an application environment such as Figure 1 . Among them, the browser in the user terminal receives the real-time interaction data collected by the real-time monitoring of the user device, and detects abnormal data based on the real-time interaction data; analyzes the reasons for the detected abnormal data and formulates an abnormal data adjustment plan; executes the abnormal data adjustment plan and issues a warning message. By real-time behavior analysis and dynamic adjustment strategies, the detection ability for complex and emerging attacks is improved, and the overall security is enhanced. Dynamically generate and adjust security policies, reducing the complexity and error risk of static configurations. The system can adapt to new attack patterns and threat changes in real time, providing more flexible and intelligent protection. By reducing false positives and false negatives, it ensures that normal user operations are not affected and improves the user experience. Automatically update and adjust protection policies, reducing the manual maintenance burden and improving the automation level of the system. Among them, the user terminal can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices. The server side can be implemented by an independent server or a server cluster composed of multiple servers. The present invention will be described in detail below through specific embodiments.

[0023] Please refer to Figure 2 as shown in Figure 2 which is a flowchart of the dynamic front-end security protection method based on behavior analysis provided by the embodiments of the present invention, including the following steps:

[0024] S10: Receive the real-time interaction data collected by the real-time monitoring of the user device, and detect abnormal data based on the real-time interaction data;

[0025] The dynamic front-end security protection method based on behavior analysis provided by the present invention can be applied to dynamic front-end modules such as intelligent devices or page components in various application scenarios. Dynamic front-end security protection is usually implemented through a server, which can receive real-time interaction data collected by user devices in real time. For example, in the financial field, the interaction data collected by the user device contains abnormal data. Among them, the abnormal data may represent potential fraud behaviors or market fluctuations. Timely output of adjustment plans and warning information helps to reduce risks. In the field of network security of medical systems, the interaction data collected by the user device contains abnormal data. Among them, the abnormal data may represent potential network attacks or system vulnerabilities. Timely warning and handling can prevent data leakage or system paralysis. The dynamic front-end security protection method based on behavior analysis is applicable to both financial and medical scenarios.

[0026] Specifically, collect interaction data on the usage of user devices and browsers. The interaction data includes at least page browsing records, click behaviors, scrolling behaviors, input behaviors, interaction events, etc. Page browsing records: the web page addresses (URLs) visited by the user, access times, stay times, etc.; click behaviors: click positions, click frequencies, clicked elements (such as buttons, links, etc.) on the page; scrolling behaviors: scrolling distances, scrolling speeds, areas where the user stays on the page, etc.; input behaviors: input contents (such as search keywords, login information, etc.) in forms, as well as input frequencies and times; interaction events: interactions between the user and page elements, such as mouse hovering, dragging, zooming in / out, etc.

[0027] Of course, in addition to the above data types related to user behaviors, the interaction data also includes performance data, user preference data, device and environment data.

[0028] Performance data includes page loading time, resource loading time, JavaScript execution time, memory occupancy, and CPU usage rate. The page loading time is the time from requesting the page to the page being fully loaded. The resource loading time includes the loading times of resources such as images, scripts, and style sheets. The JavaScript execution time is specifically the execution time of JavaScript code in the page. The memory occupancy is the size of the memory occupied by the browser during operation. The CPU usage rate is the CPU resources occupied by the browser.

[0029] User preference data includes browser settings, extension usage, bookmarks and favorites, and privacy settings. Browser settings specifically include the language, font size, theme color, etc. selected by the user. Extension usage is the extensions installed by the user and their usage frequencies. Bookmarks and favorites are the commonly visited websites and pages saved by the user. Privacy settings are the user's preferences for privacy protection, such as whether to allow tracking and whether to enable incognito browsing, etc.

[0030] Device and environment data include browser type and version, operating system information, screen resolution, and network environment. The browser type and version are the name of the browser used by the user (such as Chrome, Firefox, Safari, etc.) and its version number. The operating system information is the type of operating system used by the user (such as Windows, MacOS, Linux, etc.) and its version. The screen resolution is the screen resolution of the user's device. The network environment is the type of network connection used by the user (such as Wi-Fi, 4G, 5G, etc.) and the network speed.

[0031] Methods for collecting browser interaction data include: front-end code, performance monitoring APIs, browser extensions, server-side logs, and third-party analysis tools.

[0032] The front-end code specifically refers to JavaScript event listening data and performance monitoring API data. JavaScript event listening mainly involves embedding JavaScript code in web pages to listen for events such as user clicks, scrolls, inputs, etc., and sending this data to the server. The performance monitoring API is to use the performance monitoring APIs provided by the browser (such as the Performance API) to collect data such as page load time and resource load time.

[0033] Browser extensions mainly collect users' browsing behaviors and preference settings through extension plugins. For example, information such as users' bookmarks, favorites, and visited websites are recorded through extension plugins. Server-side logs include access logs and performance logs. Access logs are records of user access requests on the server side, including information such as the accessed URL, time, IP address, browser type, etc. Performance logs include performance data such as page load time and resource load time recorded on the server side. Third-party analysis tools at least include Google Analytics, heatmap tools, etc. Google Analytics collects data such as users' browsing behaviors and source channels by embedding Google Analytics tracking code in websites. Heatmap tools mainly use heatmap tools (such as Hotjar, Crazy Egg, etc.) to visualize users' click behaviors and scroll behaviors.

[0034] Among them, the collected real-time interaction data is analyzed. The specific analysis includes descriptive analysis, performance analysis, predictive analysis, and visualization analysis. Descriptive analysis includes user profile analysis and behavior analysis. User profile analysis is to construct a user profile based on data such as the user's device information and preference settings to understand the user's basic characteristics. Behavior analysis mainly analyzes data such as the user's click behavior and browsing path to understand the user's interest points and behavior patterns. Performance analysis includes loading time analysis and resource analysis. Loading time analysis analyzes the page loading time and resource loading time to find performance bottlenecks and optimize website performance. Resource analysis analyzes the loading time of different resources (such as images, scripts, and style sheets) and optimizes the resource loading strategy. Predictive analysis includes user behavior prediction and performance prediction. User behavior prediction uses machine learning algorithms to predict the user's future behavior based on the user's historical behavior data to support personalized recommendations. Performance prediction analyzes historical performance data to predict the performance of the website under different traffic conditions and optimizes resource allocation in advance. Visualization analysis includes heat map analysis and funnel chart analysis, etc. Heat map analysis visualizes the user's click behavior and scrolling behavior through a heat map to intuitively display the user's attention area. Funnel chart analysis analyzes the conversion rate of users in different pages or processes through a funnel chart to find the key links where users are lost.

[0035] Among them, the real-time interaction data collected by monitoring the user device in real-time calculation is received; based on machine learning, the real-time interaction data is behaviorally analyzed with the preset interaction data, and the part of the real-time interaction data that exceeds the preset interaction data is detected as abnormal data.

[0036] Based on machine learning, the real-time interaction data is behaviorally analyzed, and the predicted interaction behavior of the user in the future is obtained. The predicted interaction behavior is compared with the preset interaction data. When the two are inconsistent, the current real-time interaction data is abnormal data. When the two are consistent, the current real-time interaction data is normal data. The preset interaction data is the interaction data extracted from the historical interaction data and classified and summarized before being preset.

[0037] Among them, machine learning identifies and predicts the normal behavior patterns of users or systems by constructing models. The models can learn from historical data and be used for real-time behavior analysis of new interaction data. Machine learning can be divided into three categories: Supervised learning: In supervised learning, the model learns the relationship between inputs and outputs through a labeled training dataset. The input data and the corresponding outputs (labels) are given, and the task of the model is to learn how to predict the correct outputs from the input data. Unsupervised learning: The training data for unsupervised learning has no labels, and the goal of the model is to find hidden structures or patterns in the data. Reinforcement learning: Reinforcement learning is a way of learning by interacting with the environment and based on feedback. The agent takes actions in the environment and adjusts its strategy according to the reward or punishment signals returned by the environment.

[0038] Among them, the user device receives and monitors the real-time interaction data collected by the user in real time; identifies the potential malicious behavior data in the real-time interaction data, and detects the potential malicious behavior data to obtain abnormal data.

[0039] The behavior data with malicious labels in the historical behavior database. When potential interaction data matching the malicious behavior data is identified in the interaction data, then this data is identified as malicious behavior data, that is, abnormal data. Specifically, behavior analysis identifies abnormal behaviors that do not conform to the normal behavior pattern by monitoring the real-time interaction data of users or systems. Machine learning techniques can automatically learn the characteristics of normal behaviors from historical data and be used to detect potential malicious behaviors in real time. For example, by analyzing the behavior characteristics of network traffic, such as packet size, source / destination IP addresses, ports, etc., abnormal traffic is identified. A DDoS attack will cause a sharp change in the entropy value of the destination IP address, which can be used as a detection sign. For example, the normal behavior of the user is modeled as a baseline, and any behavior deviating from the baseline is regarded as a potential malicious behavior. The user behavior is modeled through one-class classification algorithms (such as Gaussian density estimation, PCA) to detect abnormal behaviors. For example, deep learning models (such as the Transformer architecture) or traditional machine learning algorithms (such as random forests, support vector machines) are used to analyze real-time data to identify abnormal behaviors. Specifically, fraud behaviors in financial transactions are detected in the financial field.

[0040] S20: Analyze the reasons for the detected abnormal data and formulate an adjustment plan for the abnormal data;

[0041] Specifically, by comparing the abnormal data with the preset interaction data, analyze the reasons for the detected abnormal data; formulate an adjustment plan for the abnormal data based on the reasons for the data abnormality. Among them, analyze the data type, reasons, and impacts of the detected abnormal data; formulate an adjustment plan and generate a warning message according to the analysis results.

[0042] By real-time monitoring of interaction data and comparing it with preset interaction data, data that deviates from the normal pattern is detected. Among them, the detection methods include: Detection based on thresholds: When the data exceeds the preset threshold range, it is marked as abnormal; Detection based on statistics: Calculate the statistical characteristics of the data (such as mean, variance), and consider it abnormal when it deviates from the normal range; Detection based on machine learning: Use a trained model to identify abnormal data.

[0043] Conduct in-depth analysis on the detected abnormal data to find out the reasons for its deviation from the normal pattern. The analysis content includes: Data type, is the abnormal data numerical, text or other types? Cause analysis, Technical reasons: such as network latency, system failure, data entry errors, etc. Behavioral reasons: such as user operation errors, malicious attacks, abnormal transactions, etc. Environmental reasons: such as external interference, equipment failure, etc. Impact assessment: Analyze the impact of abnormal data on the system or business, for example, whether it causes performance degradation, business interruption or security risks.

[0044] Among them, formulate an adjustment plan for abnormal data according to the reasons and impacts of the abnormal data. The goal of the adjustment plan is to restore the abnormal data to the normal range or reduce its impact on the system. The adjustment plan may include:

[0045] For incorrect or missing data, make corrections or fill them; If the abnormality is caused by unreasonable preset rules, adjust the rules to adapt to the new situation; For system performance problems, optimize resource allocation or repair faults; For abnormalities caused by user behavior, remind the user or restrict their operations.

[0046] Generate warning information according to the type, cause and impact of the abnormal data. The warning information should include: Clearly point out the specific situation of the abnormal data, such as data value, occurrence time, involved users or devices, etc.; Briefly explain the reason for the abnormal data; Describe the possible risks or impacts brought by the abnormal data; Provide a suggested solution to deal with the abnormality, such as repair methods, optimization suggestions, etc.

[0047] S30: Execute the abnormal data adjustment plan and release warning information.

[0048] Specifically, execute the abnormal data adjustment plan and release warning information; Continuously monitor the data status, and provide real-time feedback on the execution process of the abnormal data adjustment plan and the release process of the warning information.

[0049] According to the preset abnormal data adjustment plan, take specific measures to restore the abnormal data to the normal range or reduce its impact. The execution process includes: using scripts or automated tools to execute adjustment measures, for example, fixing error data, adjusting system parameters, optimizing resource allocation, etc.; for common abnormal problems, automated scripts can be pre-written for quick response; for complex or high-risk abnormalities, manual review and handling are required. For example, the security team intervenes in the investigation of malicious behaviors, or the operation and maintenance personnel manually repair system failures; when manual intervention is required, record the operation steps and results for subsequent traceability.

[0050] The release of early warning information is to timely notify relevant personnel of abnormal situations so that further measures can be taken. The released content includes: clarifying the specific situation of the abnormal data (such as data value, occurrence time, involved modules, etc.); briefly explaining the cause of the abnormality; describing the possible risks or impacts of the abnormality; providing a recommended solution to deal with the abnormality.

[0051] After the adjustment plan is executed, it is necessary to continuously monitor the data status to verify whether the adjustment measures are effective and promptly discover new abnormalities. The monitoring content includes: monitoring key data indicators (such as system performance indicators, business indicators, etc.) to ensure that they are restored to the normal range;

[0052] Using monitoring tools (such as Prometheus, Grafana) to display data changes in real time; monitoring system logs and application logs to capture abnormal log information and promptly discover potential problems; using log analysis tools (such as ELK Stack) to perform real-time analysis and alarm on the logs; monitoring user feedback channels (such as customer service systems, user complaint channels) to promptly discover abnormal problems perceived by users.

[0053] During the execution of the adjustment plan and the release of early warning information, it is necessary to provide real-time feedback on the execution process and results to ensure that relevant personnel understand the latest situation. The feedback content includes: providing real-time feedback on the execution progress of the adjustment plan (such as completed, in progress, execution failed, etc.); feedback on whether the adjustment measures are effective and whether the data has been restored to the normal range; if new abnormalities occur during the execution process, record and notify relevant personnel in a timely manner; feedback on whether the early warning information has been successfully released (such as successful SMS sending, email delivery, etc.); confirm whether relevant personnel have received the early warning information and record the confirmation time; collect the handling feedback of the receiving personnel on the early warning information for subsequent optimization of the early warning mechanism.

[0054] In an actual application scenario example, the network traffic is monitored in real time, and it is found that the traffic of a certain IP address suddenly surges and exceeds the preset threshold. It is initially judged that it may be a DDoS attack or malicious crawler behavior. Adjustment plan: Automated execution: Restrict the traffic of this IP address through firewall rules; Manual intervention: The security team intervenes to investigate the source of the attack and takes further defensive measures. Send text messages and emails to notify the security team and operation and maintenance personnel, and visually display the abnormal traffic and handling progress in the monitoring system.

[0055] After that, continuously monitor the network traffic, verify whether the traffic has returned to normal, and provide real-time feedback on the execution results of the firewall rules and the handling progress of the security team. If new attack characteristics are found, adjust the defensive strategy in a timely manner and issue new warning information.

[0056] Update the adjustment plan for abnormal data, and store the adjusted abnormal data as new preset interaction data. This process not only solves the current abnormal problem, but also improves the system's adaptability to similar situations in the future by updating the baseline data. After implementing the adjustment plan, it is necessary to evaluate the effectiveness of the plan to determine whether the expected goals have been achieved: Check whether the adjusted data has returned to the normal range; Evaluate whether the system performance and stability have returned to normal; Collect feedback from users on the adjustment effect to confirm whether the problem has been solved.

[0057] If the adjustment plan fails to completely solve the problem or there is room for improvement, it needs to be adjusted according to the evaluation results: Optimize the adjustment plan according to the actual effect, such as adjusting parameters, improving algorithms, or adding new processing steps; If new abnormal patterns or potential risks are found, update the warning rules to better handle similar situations; Record in detail the updated content and reasons of the adjustment plan for subsequent traceability and analysis.

[0058] Before actually applying the updated adjustment plan, it is necessary to verify to ensure its effectiveness and security: Simulate abnormal situations in the test environment to verify whether the updated adjustment plan can work properly; Select a small amount of data in the production environment for trial operation and observe the effect of the adjustment plan; Evaluate the impact of the updated adjustment plan on the system performance to ensure that no new problems are introduced.

[0059] The adjusted abnormal data can be incorporated into the preset interaction data as a new normal behavior pattern. Clean and organize the adjusted data to ensure that it meets the format and quality requirements of the preset data, and integrate the updated data into the existing preset interaction dataset as the new baseline data. If the preset interaction data is generated by a machine learning model, it may be necessary to retrain the model to adapt to the new data pattern.

[0060] Store the updated preset interaction data in the system for subsequent anomaly detection and analysis: Select a suitable storage location, such as a database, file system, or cloud storage service, ensure that the data is stored in a suitable format for subsequent reading and processing, and finally perform version management on the preset interaction data, recording the content and time of each update for easy traceability and rollback.

[0061] Data storage is mainly stored in databases, file systems, and cloud storage. Database: Use relational databases (such as MySQL, PostgreSQL) or non-relational databases (such as MongoDB) to store preset interaction data. File system: Store the data in the form of files for subsequent reading and processing. Cloud storage: Utilize cloud storage services (such as AWS S3, Azure BlobStorage) to store large-scale data.

[0062] Of course, based on machine learning, an incremental learning method can be adopted to update the model in real time to adapt to new data patterns. Regularly retrain the model to ensure it adapts to the latest data changes.

[0063] It can be seen that in the above solution, for the dynamic front-end security protection based on behavior analysis, first, the browser in the user terminal receives the real-time interaction data collected by real-time monitoring of the user device, and detects abnormal data based on the real-time interaction data; analyzes the reasons for the detected abnormal data and formulates an adjustment plan for the abnormal data; executes the adjustment plan for the abnormal data and issues a warning message. By real-time behavior analysis and dynamic adjustment strategies, improve the detection ability for complex and emerging attacks, enhance the overall security. Dynamically generate and adjust security policies, reduce the complexity and error risk of static configuration. The system can adapt to new attack patterns and threat changes in real time, providing more flexible and intelligent protection. By reducing false positives and false negatives, ensure that normal user operations are not affected and improve the user experience. Automatically update and adjust protection policies, reduce the manual maintenance burden, and improve the automation level of the system.

[0064] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0065] In one embodiment, a dynamic front-end security protection device based on behavior analysis is provided. The dynamic front-end security protection device based on behavior analysis corresponds one-to-one with the dynamic front-end security protection method based on behavior analysis in the above embodiment. As Figure 3 shown, the dynamic front-end security protection device based on behavior analysis includes a receiving module 101, an analysis module 102, and an execution module 103. The detailed description of each functional module is as follows:

[0066] The receiving module 101 is configured to receive real-time interaction data collected by a user device for real-time monitoring of the user, and detect abnormal data based on the real-time interaction data;

[0067] The analysis module 102 is configured to analyze the cause of the detected abnormal data and formulate an adjustment plan for the abnormal data;

[0068] The execution module 103 is configured to execute the adjustment plan for the abnormal data and issue a warning message.

[0069] In one embodiment, the receiving module 101 is specifically configured to:

[0070] Receive real-time interaction data collected by a user device for real-time computing and monitoring of the user;

[0071] Based on machine learning, analyze the real-time interaction data and preset interaction data, and detect the part of the real-time interaction data that exceeds the preset interaction data as abnormal data.

[0072] In one embodiment, the receiving module 101 is further specifically configured to:

[0073] Receive real-time interaction data collected by a user device for real-time computing and monitoring of the user;

[0074] Identify potential malicious behavior data in the real-time interaction data, and detect the potential malicious behavior data to obtain abnormal data.

[0075] In one embodiment, the analysis module 102 is specifically configured to:

[0076] Compare the abnormal data with the preset interaction data, and analyze the cause of the detected abnormal data;

[0077] Formulate an adjustment plan for the abnormal data based on the cause of the data abnormality.

[0078] In one embodiment, the analysis module 102 is further specifically configured to:

[0079] Analyze the data type, cause, and impact of the detected abnormal data;

[0080] Formulate an adjustment plan and generate a warning message according to the analysis results.

[0081] In one embodiment, the execution module 103 is specifically configured to:

[0082] Execute the adjustment plan for the abnormal data and issue a warning message;

[0083] Continuously monitor the data status, and provide real-time feedback on the execution progress of the adjustment plan for the abnormal data and the release progress of the warning message.

[0084] In one embodiment, the apparatus further includes:

[0085] Update the abnormal data adjustment plan, convert the abnormal data into new preset interaction data, and store it.

[0086] The present invention provides a dynamic front-end security protection device based on behavior analysis. The browser in the user terminal receives real-time interaction data collected by real-time monitoring of the user device, and detects abnormal data based on the real-time interaction data; analyzes the causes of the detected abnormal data and formulates an abnormal data adjustment plan; executes the abnormal data adjustment plan and issues a warning message. Through real-time behavior analysis and dynamic adjustment strategies, the detection ability for complex and emerging attacks is improved, and the overall security is enhanced. Dynamically generate and adjust security policies to reduce the complexity and error risk of static configuration. The system can adapt to new attack patterns and threat changes in real time, providing more flexible and intelligent protection. By reducing false positives and false negatives, it ensures that normal user operations are not affected and improves the user experience. Automatically update and adjust protection policies, reducing the manual maintenance burden and improving the automation level of the system.

[0087] For the specific limitations of the dynamic front-end security protection device based on behavior analysis, reference can be made to the limitations of the dynamic front-end security protection method based on behavior analysis in the above text, which will not be elaborated here. Each module in the above dynamic front-end security protection device based on behavior analysis can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0088] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 4 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage media. The network interface of the computer device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps of the server side of a dynamic front-end security protection method based on behavior analysis.

[0089] In one embodiment, a computer device is provided. The computer device can be a client, and its internal structure diagram can be as Figure 5As shown in the figure. The computer device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a dynamic front-end security protection method based on behavior analysis

[0090] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are realized:

[0091] Receive real-time interaction data collected by the user device for real-time monitoring of the user, and detect abnormal data based on the real-time interaction data;

[0092] Analyze the reasons for the detected abnormal data and formulate an adjustment plan for the abnormal data;

[0093] Execute the adjustment plan for the abnormal data and issue a warning message.

[0094] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are realized:

[0095] Receive real-time interaction data collected by the user device for real-time monitoring of the user, and detect abnormal data based on the real-time interaction data;

[0096] Analyze the reasons for the detected abnormal data and formulate an adjustment plan for the abnormal data;

[0097] Execute the adjustment plan for the abnormal data and issue a warning message.

[0098] It should be noted that for the functions or steps that can be realized by the above-mentioned computer-readable storage medium or computer device, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0099] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0100] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0101] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A dynamic front-end security protection method based on behavior analysis, characterized in that Including: Receiving real-time interaction data collected by a user device through real-time monitoring of the user, and detecting abnormal data based on the real-time interaction data; Analyzing the reasons for the detected abnormal data and formulating an adjustment plan for the abnormal data; Executing the adjustment plan for the abnormal data and issuing a warning message.

2. The dynamic front-end security protection method based on behavior analysis according to claim 1, wherein The step of receiving real-time interaction data collected by a user device through real-time monitoring of the user and detecting abnormal data based on the real-time interaction data includes: Receiving real-time interaction data collected by a user device through real-time calculation and monitoring; Based on machine learning, analyzing the real-time interaction data and preset interaction data, and detecting the part of the real-time interaction data that exceeds the preset interaction data as abnormal data.

3. The dynamic front-end security protection method based on behavior analysis according to claim 2, characterized in that, The step of analyzing the reasons for the detected abnormal data and formulating an adjustment plan for the abnormal data includes: Comparing the abnormal data with the preset interaction data and analyzing the reasons for the detected abnormal data; Formulating an adjustment plan for the abnormal data based on the reasons for the data abnormality.

4. The dynamic front-end security protection method based on behavior analysis according to claim 3, characterized in that, The step of analyzing the reasons for the detected abnormal data includes: Analyzing the data type, reasons, and impacts of the detected abnormal data; Formulating an adjustment plan and generating a warning message according to the analysis results.

5. The dynamic front-end security protection method based on behavior analysis according to claim 1, wherein The step of receiving real-time interaction data collected by a user device through real-time monitoring of the user and detecting abnormal data based on the real-time interaction data further includes: Receiving real-time interaction data collected by a user device through real-time calculation and monitoring; Identifying potential malicious behavior data in the real-time interaction data and detecting the potential malicious behavior data to obtain abnormal data.

6. The dynamic front-end security protection method based on behavior analysis according to claim 3, characterized in that The step of executing the adjustment plan for the abnormal data and issuing a warning message includes: Executing the adjustment plan for the abnormal data and issuing a warning message; Continuously monitoring the data status and providing real-time feedback on the execution progress of the adjustment plan for the abnormal data and the issuance progress of the warning message.

7. The dynamic front-end security protection method based on behavior analysis according to claim 1, characterized in that, After the step of executing the adjustment plan for the abnormal data and issuing a warning message, the method further includes: Updating the adjustment plan for the abnormal data and the abnormal data to new preset interaction data and storing them.

8. A dynamic front-end security protection device based on behavior analysis, characterized in that, Including: A receiving module for receiving real-time interaction data collected by a user device through real-time monitoring of the user and detecting abnormal data based on the real-time interaction data; An analyzing module for analyzing the reasons for the detected abnormal data and formulating an adjustment plan for the abnormal data; An executing module for executing the adjustment plan for the abnormal data and issuing a warning message.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the dynamic front-end security protection method based on behavior analysis according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the dynamic front-end security protection method based on behavior analysis according to any one of claims 1 to 7.

Citation Information

Cited By

  • Desktop browser plug-in compatible adaptation method and system based on credential terminal Web application

    CN121501376A