Abnormal path detection method and device, equipment and storage medium
Through the long and short-term memory neural network model and the abnormal path detection model trained by sliding window strategy, the problem of legal user access traffic being misjudged as malicious behavior is solved, and accurate analysis of access paths and effective identification of complex attacks is achieved.
Patent Information
- Application Number
- CN202510635413.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-11
AI Technical Summary
The prior art can easily misjudgment the access traffic of legitimate users as DDoS attacks or automation tools under large-scale promotional activities or hot events, resulting in the risk control system misidentifying normal user requests as malicious behavior.
An exception path detection model trained based on long and short-term memory neural network model and sliding window strategy is adopted. By obtaining access path data, a comprehensive analysis is carried out, the sequence pattern of access path interfaces in the transaction process is captured, subtle changes in the order of interface calls are identified, and the comparison is combined with internal and external threat intelligence databases is carried out, threat types are marked and alarms are triggered.
It significantly improves the recognition accuracy of abnormal behaviors, can effectively identify and prevent complex attacks such as bypassing and repeated transactions in the verification process, and reduces the rate of misjudgment.
Smart Images

Figure CN120301690A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and particularly to an abnormal path detection method, device, equipment and storage medium. Background Art
[0002] Internet products for clients have always been the targets coveted by black and gray industries, especially the trading scenarios are the focus of attacks.
[0003] Moreover, in scenarios such as large-scale promotional activities and hot events, the access traffic of legitimate users may experience sudden growth, and their behavioral characteristics are likely to overlap with the behavioral patterns of DDoS attacks or automated tools, resulting in misjudgment by the risk control system and misidentifying normal user requests as malicious behaviors.
[0004] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of the present application is to provide an abnormal path detection method, device, equipment and storage medium, aiming to solve the technical problem that normal user requests are easily misidentified as malicious behaviors at present.
[0006] To achieve the above purpose, the present application proposes an abnormal path detection method, and the method includes:
[0007] Obtain access path data;
[0008] Input the access path data into a pre-constructed abnormal path detection model to obtain a detection result, and the abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
[0009] In one embodiment, before the step of inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result, it includes:
[0010] Use the sliding window strategy to train the long short-term memory neural network model to obtain the abnormal path detection model.
[0011] In one embodiment, the step of using the sliding window strategy to train the long short-term memory neural network model to obtain the abnormal path detection model includes:
[0012] Obtain a path data statistical table;
[0013] Based on a preset screening rule, screen out normal paths from the path data statistical table;
[0014] Construct a training data set based on the normal paths;
[0015] Based on the training data set, the long short-term memory neural network is trained using the sliding window strategy;
[0016] Judge whether the current training round reaches a preset maximum value;
[0017] If so, output the abnormal path detection model;
[0018] If not, calculate the multi-class cross-entropy, and perform gradient descent update on the parameters of the long short-term memory neural network model based on the multi-class cross-entropy;
[0019] Perform gradient backpropagation on the long short-term memory neural network model, and return to execute the step: based on a preset screening rule, screen out normal paths from the path data statistical table.
[0020] In one embodiment, the obtaining access path data includes:
[0021] Obtain the log data of user consumption from the business system;
[0022] Clean the log data of user consumption to obtain the cleaned log data;
[0023] Based on the cleaned log data, construct path data according to the access order of each session interface;
[0024] Judge whether the path data belongs to common data;
[0025] If not, filter the path data to obtain the filtered path data, and use the filtered path data as the access path data.
[0026] In one embodiment, after the step of judging whether the path data belongs to common data, it further includes:
[0027] If so, write the path data into the path data statistical table, so as to screen out normal paths from the path data statistical table based on a preset screening rule, and construct a training data set based on the normal paths.
[0028] In one embodiment, the judging whether the path data belongs to common data includes:
[0029] Query the transaction paths of a preset period from the path data;
[0030] Judge whether the transaction path appears within a preset time period;
[0031] If so, judge whether the number of devices corresponding to the transaction path reaches a certain threshold;
[0032] If so, determine whether the number of IPs corresponding to the transaction path reaches a certain threshold;
[0033] If so, mark the transaction path as a normal path and perform manual confirmation on the transaction path.
[0034] In one embodiment, the step of inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result includes:
[0035] Adopt the sliding window strategy to select consecutive interfaces from the access path data;
[0036] Use a first number of consecutive interfaces as input samples and a second number of consecutive interfaces as labels;
[0037] Input the input samples into the long short-term memory neural network to predict the probability distribution of the second number of consecutive interfaces;
[0038] If the distribution probability of the second number of consecutive interfaces is lower than a preset threshold, it is determined as an abnormal path;
[0039] Compare the abnormal path and the corresponding context information with the internal and external threat intelligence database. If a known malicious IP or attack pattern is matched, mark the threat type for the abnormal path;
[0040] Dynamically display the complete call chain of the abnormal path through the monitoring interface;
[0041] Trigger an alarm mechanism based on the threat type to enable the security team to confirm the status of the abnormal path.
[0042] In addition, to achieve the above object, the present application also proposes an abnormal path detection device, which includes:
[0043] A data acquisition module for acquiring access path data;
[0044] A path prediction module for inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result, and the abnormal path detection model is trained based on a long short-term memory network neural model and a sliding window strategy.
[0045] In addition, to achieve the above object, the present application also proposes an abnormal path detection device, the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the abnormal path detection method as described above.
[0046] In addition, to achieve the above object, the present application also provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the abnormal path detection method described above are implemented.
[0047] One or more technical solutions provided by the present application have at least the following technical effects:
[0048] The present application uses a long short-term memory neural network model to accurately capture the sequence pattern of access path interfaces in the transaction process, conduct a comprehensive analysis, discover subtle changes in the interface call order in the access path, significantly improve the recognition accuracy of abnormal behaviors, and can effectively identify and prevent complex attacks such as verification process bypass and repeated transactions. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0050] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0051] Figure 1 It is a schematic flowchart provided for the first embodiment of the abnormal path detection method of the present application;
[0052] Figure 2 It is a schematic structural diagram of a long short-term memory neural network model;
[0053] Figure 3 It is a schematic flowchart for the present application to determine whether path data belongs to common data;
[0054] Figure 4 It is a schematic overall flowchart of the abnormal path detection method of the present application;
[0055] Figure 5 It is a schematic module structure diagram of the abnormal path detection device in the embodiment of the present application;
[0056] Figure 6 It is a schematic device structure diagram of the hardware operating environment involved in the abnormal path detection method in the embodiment of the present application.
[0057] The implementation of the object, functional features, and advantages of the present application will be further described in conjunction with the embodiments with reference to the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0058] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not used to limit the present application.
[0059] For a better understanding of the technical solutions of the present application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific implementation manners.
[0060] The main solution of the embodiment of the present application is: obtaining access path data;
[0061] Inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result, where the abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
[0062] In this embodiment, for the convenience of description, the following will be described with an abnormal path detection system as the execution subject.
[0063] Due to the prior art, in scenarios such as large-scale promotional activities and hot events, the access traffic of legitimate users may suddenly increase, and their behavioral characteristics are likely to overlap with the behavioral patterns of DDoS attacks or automated tools, resulting in misjudgments by the risk control system and misidentifying normal user requests as malicious behaviors.
[0064] The present application provides a solution. The present application uses a long short-term memory neural network model to accurately capture the sequence patterns of access path interfaces in the transaction process, conduct a comprehensive analysis, discover subtle changes in the interface call order in the access path, significantly improve the recognition accuracy of abnormal behaviors, and can effectively identify and prevent complex attacks such as bypassing the verification process and repeated transactions.
[0065] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, an abnormal path detection device, etc. that can implement the above functions, or an electronic system, an abnormal path detection system, etc. that can implement the above functions. The following will take the abnormal path detection system as an example to illustrate this embodiment and the following embodiments.
[0066] Based on this, the embodiment of the present application provides an abnormal path detection method, referring to Figure 1 , Figure 1 which is a schematic flow chart provided for the first embodiment of the abnormal path detection method of the present application.
[0067] In this embodiment, the abnormal path detection method includes steps S10 and S30:
[0068] Step S10, obtaining access path data;
[0069] Among them, the access path data can be a sequence of API interface endpoints continuously called by a user or a system within a specific time period, usually including metadata such as timestamps, endpoint URLs, request parameters, etc., and can be sourced from Web server logs (such as Nginx), API gateways (such as Kong), application monitoring (such as ELK), etc.
[0070] Step S30: Input the access path data into a pre-constructed abnormal path detection model to obtain a detection result. The abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
[0071] Among them, the long short-term memory neural model is a special type of recurrent neural network (RNN). By introducing "memory cells" and "gating mechanisms" (input gate, forget gate, output gate), it effectively solves the gradient vanishing / exploding problems of traditional RNNs and is good at processing and predicting long sequence data (such as time series, natural language, etc.).
[0072] Furthermore, the long short-term memory neural model used in this application is as Figure 2 shown Figure 2 as the structural schematic diagram of the long short-term memory neural network model.
[0073] Among them, the long short-term memory neural network model includes a cell state C t , C t running through the "memory channel" of the entire LSTM, long-term preserving key information, and can be selectively updated through three gating mechanisms (forget / input / output).
[0074] The three control gates are shown in Table 1 below:
[0075] Table 1
[0076]
[0077] Among them, W is the weight matrix, W f is the weight of the forget gate, W i is the weight of the input gate, and W o is the weight of the output gate.
[0078] Among them, b f , b i , b o are the independent biases of each gating and candidate value respectively.
[0079] Among them, h t-1 is the hidden state of the previous time step, and xt is the input of the current time step.
[0080] In addition, is a candidate value used to temporarily store newly input information, and its calculation formula is: tanh(W c ·[h t-1 ,x t +b c ). Among them, W c is the weight, b c is the independent bias corresponding to the gate and candidate value, h t-1 is the hidden state of the previous time step, and x t is the input of the current time step.
[0081] Among them, the detection result can be a probability distribution, that is, the prediction probabilities of all possible subsequent APIs (output through Softmax), and the detection result can also be a binary classification result, such as normal (0) / abnormal (1) (determined through a threshold).
[0082] Among them, considering the dynamic changes in the business transaction process, the model needs to be adaptable. Therefore, scenario-specific strategies are adopted to configure independent detection models for each business scenario.
[0083] Among them, each business scenario (such as payment transactions, user logins, data exports, etc.) has an independent anomaly detection model. These models are specifically trained according to the data characteristics and business rules of the corresponding scenarios to ensure that the detection logic highly matches the scenario requirements. For example, the model for the payment scenario will focus on features such as transaction amount, frequency, and payee, while the model for the login scenario will pay more attention to dimensions such as IP address, device, and login time.
[0084] As an implementation method, the system can be deployed based on containerization, and only instances need to be added for new scenarios.
[0085] Furthermore, when a new business scenario is added, the system can automatically complete model deployment through the scenario registration mechanism. Business developers only need to submit a scenario definition file to describe the data source, key fields, and initial threshold, and the system can generate the corresponding model container instance. This process does not require manual intervention in the model code, realizing the decoupling of business and technology.
[0086] Among them, the system monitors the request load of each scenario in real time and automatically adjusts the number of model instances based on preset policies. For example, during peak e-commerce promotion periods, the model instances for the payment scenario will scale out horizontally to handle traffic peaks, while the instances for low-frequency scenarios will automatically scale in to save resources. The scaling process is implemented through a container orchestration platform to ensure service continuity.
[0087] When business developers determine the abnormal path, they can actively trigger model training or wait for the system to automatically update. After the model is updated, the system will automatically re-predict all historical results that have not been manually confirmed and update the transaction path status.
[0088] Among them, when the model is updated, new version snapshots will be generated, including training data, parameters, and evaluation metrics. If an exception occurs during the actual operation of the new version, the system supports a one-key rollback to the historical stable version. Moreover, the version information of the model is persistently stored through the meta-database, facilitating auditing and traceability.
[0089] This application uses a long short-term memory neural network model to accurately capture the sequential patterns of access path interfaces in the transaction process, conduct a comprehensive analysis, discover subtle changes in the interface call order in the access path, significantly improve the recognition accuracy of abnormal behaviors, and can effectively identify and prevent complex attacks such as bypassing the verification process and repeated transactions.
[0090] Based on Embodiment 1 of this application, in Embodiment 2 of this application, the same or similar content as the above Embodiment 1 can be referred to the above introduction and will not be elaborated hereinafter. On this basis, before step S30, the abnormal path detection method further includes step S20:
[0091] Step S20, training the long short-term memory neural network model using the sliding window strategy to obtain the abnormal path detection model.
[0092] On this basis, step S20, training the long short-term memory neural network model using the sliding window strategy to obtain the abnormal path detection model further includes steps S21 to S28:
[0093] Step S21, obtaining a path data statistical table;
[0094] Among them, the path data statistical table can be obtained by counting from the historical API interface access logs, and the path data statistical table can include path frequency, time series distribution, and user behavior characteristics.
[0095] Step S22, screening out normal paths from the path data statistical table based on preset screening rules;
[0096] Among them, the preset screening rules can be frequency thresholds, time regularity, etc. For example, if the call volume in the past 30 days > 1,000 times and the success rate > 99%, it is a normal path; if it is a path that appears at a fixed time period every day, it is a normal path.
[0097] Step S23, constructing a training data set based on the normal paths;
[0098] Among them, the filtered normal paths are converted into a numerical data set that can be processed by the model.
[0099] Furthermore, the filtered normal paths can be converted into a numerical data set that can be processed by the model by using One-hot encoding or embedding vectors.
[0100] Step S24: Based on the training data set, use the sliding window strategy to train the long short-term memory neural network;
[0101] Among them, the long short-term memory neural network can be used to capture and learn the sequential patterns of normal transaction paths, and each path consists of dozens of APIs arranged in chronological order.
[0102] Among them, adopting the sliding window strategy, each time three consecutive APIs are selected: the first two are used as input samples, and the third is used as a label.
[0103] For example, for the transaction path API1 / API2 / API3 / API4 / API5, three training set data can be constructed as shown in Table 2 below.
[0104] Table 2
[0105] Input sample Label value API1, API2 API3 API2, API3 API4 API3, API4 API5
[0106] Convert the API identifiers into binary form through One-hot encoding to construct the training data set.
[0107] Among them, adopting the sliding window strategy, each time two consecutive API calls are selected, and the probability distribution of the next API is predicted by inputting into the model.
[0108] Furthermore, a scheduled task can be set to extract the path data of the previous day from the database statistical table every day and filter out the data that has not been predicted.
[0109] Step S25: Determine whether the current training round has reached the preset maximum value;
[0110] Step S26: If so, output the abnormal path detection model;
[0111] Step S27: If not, calculate the multi-class cross-entropy, and perform gradient descent update on the parameters of the long short-term memory neural network model based on the multi-class cross-entropy;
[0112] Among them, the multi-class cross-entropy can measure the difference between the predicted path and the true path.
[0113] Among them, when performing gradient descent, the Adam optimizer can be used to dynamically adjust the learning rate to avoid local optima.
[0114] Step S28: Perform gradient backpropagation on the long short-term memory neural network model, and return to execute the step: Based on the preset screening rules, screen out the normal paths from the path data statistical table.
[0115] Among them, steps S25 to S28 are the process of continuously optimizing model parameters through multiple rounds of training until convergence or reaching the maximum round. Thus, the model undergoes multiple iterations, gradually reduces the training error, and finally trains an optimized and best performing neural network model.
[0116] The embodiment of the present application can improve the accuracy of the model by screening the normal path. Through multiple rounds of training, the model parameters are continuously optimized until convergence or the maximum round is reached, which can balance the training efficiency and model performance and prevent overfitting.
[0117] It should be noted that the current attack detection methods are relatively simple, such as analyzing potential attack behaviors through access frequency statistics of factors such as IP and devices. The pain points of current attack detection methods include: complex attack processes are difficult to identify, access frequency-based detection often only focuses on a single API interface, and simple detection is difficult to identify problems such as bypassing the verification process and repeated transactions.
[0118] In order to solve the above problems, this embodiment is proposed. This embodiment is based on the above embodiment. For the same or similar contents as the above embodiment, please refer to the above introduction, and will not be repeated later. On this basis, step S10, obtaining access path data also includes steps S11 to S15:
[0119] Step S11, obtaining user consumption log data from the business system;
[0120] Step S12, cleaning the log data consumed by the user to obtain cleaned log data;
[0121] Among them, invalid / interference data can be eliminated and field formats can be standardized.
[0122] Furthermore, different cleaning logics can be defined for different business lines.
[0123] Step S13, based on the cleaned log data, construct path data according to the access sequence of each session interface;
[0124] Among them, the cleaned logs are aggregated according to user sessions to generate a time-series access path.
[0125] The embodiment of the present application is based on the cleaned log data and constructs path data according to the access order of each session interface. It can focus on multiple API interfaces to prevent problems such as bypassing the verification process and duplicate transactions. It can accurately identify attacks by analyzing the execution order of the entire transaction process.
[0126] Step S14, determining whether the path data is common data;
[0127] Step S15, if not, filter the path data to obtain the filtered path data, and use the filtered path data as the access path data.
[0128] As an implementation, a whitelist mechanism can be set up to forcibly retain the core business process paths.
[0129] As another implementation, the paths with low frequency but high importance can be weighted, and then the path data can be filtered based on the weights.
[0130] As another implementation, clustering analysis can be performed on the filtered paths to discover potential new attack patterns, and then the clustering results can be used as new attack samples and added to the "abnormal category" label of the training set to expand the model's recognition range of unknown threats.
[0131] In addition, the present application can adopt a bypass deployment method, which only needs to consume user log data, can be quickly integrated into various business systems, is non-invasive to existing products, and has wide applicability.
[0132] As an implementation, the existing log files of the business system (such as Nginx access logs, application log files) can be directly read without modifying the business code. New log entries can be captured in real time through the Tail-based technology, so as to be non-invasive to existing products.
[0133] As another implementation, the logs can also be sent to an enterprise-level message queue (such as Kafka / RabbitMQ) through the business system, and the bypass system subscribes to the required data through an independent consumer group, so as to decouple from the business logic.
[0134] As another implementation, port mirroring (Port Mirroring) can also be configured on the switch or load balancer to copy the HTTP / API request traffic of the business system to the bypass analysis system, and restore the user operation path through deep packet inspection (DPI).
[0135] As another implementation, a transparent proxy (such as the Sidecar mode) can also be deployed at the network entrance of the business system to automatically copy the request and response data, making the business system unaware.
[0136] By cleaning the log data in the embodiments of the present application, the data quality can be improved, and the error rate of subsequent analysis can be reduced. By filtering the path data, the model can focus on the mainstream business scenarios and improve the accuracy of anomaly detection.
[0137] Based on the above embodiments, for the same or similar content as the above embodiments, reference can be made to the above introduction and will not be elaborated hereinafter. On this basis, after step S14 of determining whether the path data belongs to common data, steps S16 to S17 are further included:
[0138] Step S16, if so, write the path data into a path data statistical table, so as to screen out normal paths from the path data statistical table based on a preset screening rule, and construct a training data set based on the normal paths.
[0139] Among them, write the path data belonging to common data into the path data statistical table, so as to obtain the path data statistical table when training the long short-term memory neural network model subsequently; screen out normal paths from the path data statistical table based on a preset screening rule; construct a training data set based on the normal paths; and train the long short-term memory neural network by using the sliding window strategy based on the training data set.
[0140] This application uses a long short-term memory neural network model to accurately capture the sequence pattern of access path interfaces in the transaction process, conduct a comprehensive analysis, discover subtle changes in the interface call order in the access path, significantly improve the recognition accuracy of abnormal behaviors, and can effectively identify and prevent complex attacks such as bypassing the verification process and repeated transactions.
[0141] The pain points existing in the current attack detection methods also include: it is difficult to detect high-end attack means. The black and gray production gangs adjust the access frequency through scripts, or use emulators or even a large number of real machines to access, resulting in the difficulty of conventional detection methods to detect abnormalities in attack characteristics in dimensions such as frequency and devices, thus letting attacks go.
[0142] To solve the above problems, this embodiment is proposed. Based on the above embodiments, for the same or similar content as the above embodiments, reference can be made to the above introduction and will not be elaborated hereinafter. On this basis, step S14 of determining whether the path data belongs to common data further includes steps S141 to S145:
[0143] Step S141, query the transaction paths within a preset period from the path data;
[0144] As an implementation manner, all transaction paths within the past month can be queried from the path data.
[0145] Step S142, determine whether the transaction path appears within a preset time period;
[0146] As an implementation manner, it can be determined whether the transaction path appears every day.
[0147] Step S143, if so, determine whether the number of devices corresponding to the transaction path reaches a certain threshold;
[0148] Step S144, if so, determine whether the number of IPs corresponding to the transaction path reaches a certain threshold;
[0149] Step S145, if so, mark the transaction path as a normal path and perform manual confirmation on the transaction path.
[0150] In the embodiment of the present application, by querying the transaction path in the preset period from the path data and determining whether the transaction path appears in the preset time period, the abnormality of the attack characteristics in the frequency dimension that is difficult to discover by conventional detection methods can be detected; in the embodiment of the present application, by determining whether the number of devices corresponding to the transaction path reaches a certain threshold and determining whether the number of IPs corresponding to the transaction path reaches a certain threshold, the abnormality of the attack characteristics in the device dimension that is difficult to discover by conventional detection methods can be detected.
[0151] It can be referred to Figure 3 , Figure 3 is a schematic flowchart of the process for the present application to determine whether the path data belongs to common data.
[0152] As Figure 3 shown, for each transaction scenario, the system needs to screen out common paths from a large number of paths and perform screening according to specific conditions, such as whether the path appears every day, and whether the number of device information and IPs involved every day reaches a certain frequency, etc.
[0153] Through the "appearing daily + multi-device / IP coverage" condition screening in the present application, it is ensured that only stable and widely used paths are marked as normal, avoiding misjudging temporary activity paths (such as promotion interfaces) or test traffic as abnormal, thereby reducing the false alarm probability.
[0154] Based on the above embodiments, the same or similar content as the above embodiments can be referred to the above introduction and will not be elaborated later. On this basis, step S30, inputting the access path data into a pre-constructed abnormal path detection model, and the obtained detection result further includes steps S31 to S37:
[0155] Step S31, using the sliding window strategy, select consecutive interfaces from the access path data;
[0156] It should be noted that the present application not only uses the sliding window strategy in training the long short-term memory neural network, but also can use the sliding window strategy when using the long short-term memory application network.
[0157] Among them, the principle of the sliding window strategy is to slide and segment the continuous API path sequence according to a fixed window length (e.g., window size = 3), and the step size is usually 1.
[0158] For example, if the original path is A→B→C→D→E, the cutting result when the window = 3 is [A, B, C] → predict D; [B, C, D] → predict E.
[0159] As an implementation, the size of the window can be adjusted dynamically. Short windows (2-3 interfaces) are suitable for detecting immediate anomalies, and long windows (more than 5 interfaces) are suitable for identifying complex attack chains.
[0160] Step S32: Use the first quantity of continuous interfaces as input samples and the second quantity of continuous interfaces as labels;
[0161] For example, three consecutive APIs can be selected each time, with the first two as input samples and the third as the label.
[0162] Step S33: Input the input samples into the long short-term memory neural network to predict the probability distribution of the second quantity of continuous interfaces;
[0163] Step S34: If the distribution probability of the second quantity of continuous interfaces is lower than the preset threshold, it is determined as an abnormal path;
[0164] If the second quantity is 1 and the interface of the second quantity is API12, then the probability distribution of API12 is predicted. If the probability distribution of API12 is lower than the threshold (e.g., 0.01), it is determined as abnormal; otherwise, it is regarded as normal and the next group of APIs is continued to be detected.
[0165] Step S35: Compare the abnormal path and the corresponding context information with the internal and external threat intelligence databases. If a known malicious IP or attack pattern is matched, mark the threat type for the abnormal path;
[0166] Among them, the internal threat intelligence database can include historical attack records, enterprise self-built malicious IP databases, etc.
[0167] The external threat intelligence database can include commercial threat platforms (such as Recorded Future), open source intelligence (such as AlienVault OTX), etc.
[0168] Step S36: Dynamically display the complete call chain of the abnormal path through the monitoring interface;
[0169] Among them, dynamically displaying the complete call chain of the abnormal path through the monitoring interface includes: topology graph and context association. Through the topology graph, the highlighted abnormal nodes can be displayed (such as / api / deleteUser), and through the context association, the recent activity timeline of the same IP / user can be displayed.
[0170] Step S37, trigger the alarm mechanism based on the threat type so that the security team can confirm the status of the abnormal path.
[0171] For example, the alarm mechanism can be as shown in Table 3 below:
[0172] Table 3
[0173] Threat type Notification channel Response time limit High risk (such as data leakage) Phone + Enterprise WeChat + Work order 5 minutes Medium risk (such as scanning and detection) Email 1 hour
[0174] Furthermore, closed-loop processing can also be performed, that is, when the security team confirms the status (false alarm / real attack), it is fed back to the model training.
[0175] Through the combination of manual review and analysis in the embodiments of the present application, the risk points and black and gray production attack behaviors in the transaction process can be accurately identified.
[0176] Exemplarily, in order to help understand the implementation process of the abnormal path detection method obtained by combining the above-mentioned Embodiment 1 in this embodiment, please refer to Figure 4 , Figure 4 A brief flow schematic diagram of an abnormal path detection method is provided. Specifically, the process includes the following steps:
[0177] Training the model:
[0178] Step S110, obtain the log data of user consumption from the business system. For example, obtain the log data of user consumption from the distributed stream processing platform kafka;
[0179] Step S111, clean the log data of user consumption to obtain the cleaned log data;
[0180] Step S112, based on the cleaned log data, construct path data according to the access order of each session interface;
[0181] Step S113, determine whether the path data belongs to common data;
[0182] Step S114, if so, write the path data into the path data statistical table, so as to screen out the normal paths from the path data statistical table based on the preset screening rules, and construct a training dataset based on the normal paths;
[0183] Step S115, screen out the normal paths from the path data statistical table based on the preset screening rules;
[0184] Step S116, construct a training data set based on the normal path;
[0185] Step S117, based on the training data set, adopt the sliding window strategy to train the long short-term memory neural network; it should be noted that the model of this application supports dynamic real-time training, can flexibly adapt to changes in different scenarios, instantaneously adjust the prediction results, and ensure continuous accuracy. In addition, each business scenario can flexibly configure the model training parameters according to its own characteristics to maximize the detection effect.
[0186] Step S118, determine whether the current training round reaches a preset maximum value;
[0187] Step S119, if so, output the abnormal path detection model;
[0188] Step S1110, if not, calculate the multi-class cross-entropy, and perform gradient descent update on the parameters of the long short-term memory neural network model based on the multi-class cross-entropy;
[0189] Step S1111, perform gradient backpropagation on the long short-term memory neural network model, and return to execute the step: select the normal path from the path data statistical table based on a preset screening rule.
[0190] Use the model:
[0191] Execute steps S110 to S113, and continue to execute step S121. If not, filter the path data to obtain the filtered path data, and use the filtered path data as the access path data.
[0192] Step S122, adopt the sliding window strategy to select consecutive interfaces from the access path data;
[0193] Step S123, use the first number of consecutive interfaces as input samples and the second number of consecutive interfaces as labels;
[0194] Step S124, input the input samples into the long short-term memory neural network to predict the probability distribution of the second number of consecutive interfaces;
[0195] Step S125, if the distribution probability of the second number of consecutive interfaces is lower than a preset threshold, it is determined as an abnormal path;
[0196] Step S126, compare the abnormal path and the corresponding context information with the internal and external threat intelligence database. If a known malicious IP or attack pattern is matched, mark the threat type for the abnormal path;
[0197] Step S127, dynamically display the complete call chain of the abnormal path through the monitoring interface;
[0198] Step S128, trigger an alarm mechanism based on the threat type to enable the security team to confirm the status of the abnormal path. After the security team confirms the status (false alarm / real attack), feedback it to model training.
[0199] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the abnormal path detection method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0200] This application also provides an abnormal path detection device. Please refer to Figure 5 The abnormal path detection device includes:
[0201] A data acquisition module 10 for acquiring access path data;
[0202] A path prediction module 20 for inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result. The abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
[0203] The abnormal path detection device provided by this application adopts the abnormal path detection method in the above embodiment and can solve the technical problem that normal user requests are easily misidentified as malicious behaviors at present. Compared with the prior art, the beneficial effects of the abnormal path detection device provided by this application are the same as those of the abnormal path detection method provided by the above embodiment, and other technical features in the abnormal path detection device are the same as those disclosed in the method of the above embodiment, which will not be elaborated here.
[0204] This application provides an abnormal path detection device. The abnormal path detection device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the abnormal path detection method in Embodiment 1 above.
[0205] Next, refer to Figure 6, which shows a schematic structural diagram of an abnormal path detection device suitable for implementing the embodiments of the present application. The abnormal path detection device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The shown abnormal path detection device is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0206] As Figure 6 shown, the abnormal path detection device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory 1002 or the program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the abnormal path detection device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems may be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the abnormal path detection device to communicate with other devices wirelessly or wireline to exchange data. Although the figure shows an abnormal path detection device having various systems, it should be understood that it is not required to implement or have all the shown systems. Instead, more or fewer systems may be implemented or had.
[0207] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by a processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0208] The abnormal path detection device provided by the present application adopts the abnormal path detection method in the above embodiments, and can solve the technical problem that normal user requests are easily misidentified as malicious behaviors at present. Compared with the prior art, the beneficial effects of the abnormal path detection device provided by the present application are the same as those of the abnormal path detection method provided by the above embodiments, and other technical features in the abnormal path detection device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.
[0209] It should be understood that the various parts disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0210] As described above, only the specific embodiments of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0211] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the abnormal path detection method in the above embodiments.
[0212] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0213] The above computer-readable storage medium can be included in the abnormal path detection device; it can also exist separately without being assembled into the abnormal path detection device.
[0214] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by the abnormal path detection device, the abnormal path detection device is caused to: obtain access path data;
[0215] Input the access path data into a pre-constructed abnormal path detection model to obtain a detection result. The abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
[0216] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by connecting through the Internet using an Internet service provider).
[0217] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0218] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0219] The readable storage medium provided in this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned abnormal path detection method, and can solve the technical problem that normal user requests are easily misidentified as malicious behaviors at present. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the abnormal path detection method provided in the above embodiments, and will not be elaborated here.
[0220] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.
Claims
1. An abnormal path detection method, characterized in that, The method includes: Obtain access path data; Input the access path data into a pre-constructed abnormal path detection model to obtain a detection result, where the abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
2. The method according to claim 1, wherein Before the step of inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result, it includes: Use the sliding window strategy to train the long short-term memory neural network model to obtain the abnormal path detection model.
3. The method according to claim 2, wherein The step of using the sliding window strategy to train the long short-term memory neural network model to obtain the abnormal path detection model includes: Obtain a path data statistical table; Based on a preset screening rule, screen out normal paths from the path data statistical table; Construct a training data set based on the normal paths; Based on the training data set, use the sliding window strategy to train the long short-term memory neural network; Judge whether the current training round reaches a preset maximum value; If so, output the abnormal path detection model; If not, calculate the multi-class cross-entropy, and perform gradient descent update on the parameters of the long short-term memory neural network model based on the multi-class cross-entropy; Perform gradient backpropagation on the long short-term memory neural network model, and return to execute the step: Based on a preset screening rule, screen out normal paths from the path data statistical table.
4. The method according to claim 3, characterized in that, The obtaining of the access path data includes: Obtain log data of user consumption from the business system; Clean the log data of user consumption to obtain the cleaned log data; Based on the cleaned log data, construct path data according to the access order of each session interface; Judge whether the path data belongs to common data; If not, filter the path data to obtain the filtered path data, and use the filtered path data as the access path data.
5. The method according to claim 4, wherein After the step of judging whether the path data belongs to common data, it further includes: If so, write the path data into the path data statistical table, so as to screen out normal paths from the path data statistical table based on a preset screening rule, and construct a training data set based on the normal paths.
6. The method according to claim 5, characterized in that, The judging whether the path data belongs to common data includes: Query the transaction path of a preset period from the path data; Judge whether the transaction path appears within a preset time period; If so, judge whether the number of devices corresponding to the transaction path reaches a certain threshold; If so, judge whether the number of IPs corresponding to the transaction path reaches a certain threshold; If so, mark the transaction path as a normal path and perform manual confirmation on the transaction path.
7. The method according to claim 1, wherein The step of inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result includes: Use the sliding window strategy to select consecutive interfaces from the access path data; Use the first number of consecutive interfaces as input samples and the second number of consecutive interfaces as labels; Input the input sample into the long short-term memory neural network to predict the probability distribution of the second number of consecutive interfaces; If the distribution probability of the second number of consecutive interfaces is lower than a preset threshold, it is determined as an abnormal path; Compare the abnormal path and the corresponding context information with the internal and external threat intelligence database. If a known malicious IP or attack pattern is matched, mark the threat type for the abnormal path; Dynamically display the complete call chain of the abnormal path through the monitoring interface; Trigger an alarm mechanism based on the threat type to enable the security team to confirm the status of the abnormal path.
8. An abnormal path detection device, characterized in that, The device includes: A data acquisition module for acquiring access path data; A path prediction module for inputting the access path data into a pre-constructed abnormal path detection model to obtain a detection result. The abnormal path detection model is trained based on a long short-term memory neural model and a sliding window strategy.
9. An abnormal path detection device, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. The computer program is configured to implement the steps of the abnormal path detection method according to any one of claims 1 to 7.
10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the abnormal path detection method according to any one of claims 1 to 7.