Internet data service security monitoring method and system based on deep learning
The method leverages a graph neural network model with a dynamic threshold mechanism to address the limitations of traditional methods in capturing API call relationships and detecting authentication bypass attacks, enhancing the security of internet data services by improving anomaly detection accuracy and adaptability.
Patent Information
- Application Number
- CN202510451618.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing Internet data service API security monitoring technology is difficult to effectively handle complex API call relationships, adapt to dynamic access mode changes, and identify and authenticate bypass attacks, resulting in poor protection effects.
The graph neural network model is used to model the API call relationship, and combined with the dynamic threshold mechanism, the context features of the API call chain are extracted through graph convolution operation, and the Gaussian mixed model and local outlier factors are used for deviation evaluation, so as to detect abnormal access behavior in real time.
It improves the recognition accuracy of authentication bypass attacks, reduces the false positive rate, realizes deep semantic modeling and real-time protection of complex access behaviors, and improves the security of Internet data services.
Smart Images

Figure CN120320992A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet data service security monitoring, and in particular to a method and system for Internet data service security monitoring based on deep learning. Background Art
[0002] With the rapid development of Internet technology and the widespread application of cloud computing services, data services based on Internet data service API interfaces have become the core components of modern Internet application systems. Traditional Internet data service API security protection technologies mainly rely on static protection methods such as identity authentication, access control and encrypted transmission. Although these methods can guarantee the security of API interfaces to a certain extent, in the face of increasingly complex forms of network attacks, especially targeted authentication bypass attacks, their protection effects are often difficult to meet actual needs. Existing Internet data service API security monitoring methods mainly include technical routes such as rule matching-based anomaly detection, statistical feature-based behavior analysis, and machine learning-based pattern recognition. Among them, the rule matching-based method requires security experts to continuously maintain the rule base and is prone to false positives; the statistical feature-based method is difficult to effectively extract the correlation between API calls and cannot accurately characterize complex access behavior patterns; the traditional machine learning-based method has obvious deficiencies in feature expression when processing high-dimensional and nonlinear API access data.
[0003] With the rapid development of deep learning technology, deep neural networks have provided new technical ideas for API security monitoring with their powerful feature extraction and pattern recognition capabilities. However, the current mainstream deep learning models such as convolutional neural networks (CNN) and recurrent neural networks (RNN) mainly model Euclidean spatial data such as images and sequences, and it is difficult to effectively capture the complex topological relationship between API calls. At the same time, most of the existing anomaly detection algorithms use fixed thresholds or static probability models, which cannot adapt to the dynamic changes in API access patterns and easily lead to a high false alarm rate. In addition, traditional feature engineering methods often regard API calls as independent events and ignore the call dependencies between different APIs, which makes it difficult for the system to identify complex attack behaviors based on a combination of multiple APIs.
[0004] In response to the above problems, the present invention provides a method and system for Internet data service security monitoring based on deep learning. The method models the API call relationship through a graph neural network model, and combines the dynamic threshold mechanism to realize real-time detection of authentication bypass attacks, so as to improve the security protection capability of Internet data services. Summary of the invention
[0005] In view of the deficiencies of existing Internet data service API security monitoring technologies in dealing with complex API call relationships, adapting to changes in dynamic access patterns, and identifying authentication bypass attacks, the present invention is proposed.
[0006] Therefore, the problem to be solved by the present invention is how to deeply model the API call relationship by constructing a graph neural network model, and combine a dynamic density evaluation mechanism to accurately identify abnormal access behaviors, so as to effectively protect Internet data services from the threat of authentication bypass attacks.
[0007] To solve the above technical problems, the present invention provides the following technical solutions:
[0008] In a first aspect, an embodiment of the present invention provides an Internet data service security monitoring method based on deep learning, which includes:
[0009] Collect the request logs of the API interface, extract the access features of the request logs, and construct an API access feature sequence;
[0010] Aggregate the API access feature sequences according to the user dimension and divide them into access segments of a fixed duration;
[0011] Construct a graph neural network model, map the API call relationship in the access segment into a graph structure, extract the context features of the API call chain through graph convolution operations, and generate an API access pattern vector;
[0012] Perform density evaluation on the API access pattern vector, and calculate the deviation degree of the current access behavior from the historical normal access pattern;
[0013] When the deviation degree exceeds the dynamic threshold, it is determined that there is an abnormal access behavior, and an authentication bypass attack warning is output to implement the security monitoring of Internet data services.
[0014] As a preferred solution of the Internet data service security monitoring method based on deep learning according to the present invention, wherein: the calculation method of the deviation degree is as follows:
[0015] Collect the API access pattern vectors in the historical normal access data, and use a Gaussian mixture model to fit the distribution of the API access pattern vectors to obtain K Gaussian components;
[0016] Calculate the Mahalanobis distance D k (x) between the current API access pattern vector x and each Gaussian component, and select the minimum Mahalanobis distance value D mi n(x) = min(D1(x), D2(x), …, D K (x)) as the evaluation index of the deviation degree;
[0017] Set the dynamic threshold μ D +3σ D , where μ D is the mean of the minimum Mahalanobis distance, and σ D is the standard deviation of the minimum Mahalanobis distance value;
[0018] When the minimum Mahalanobis distance value is less than the dynamic threshold μ D +3σ D , mark the current API access mode vector x as a candidate anomaly, and calculate the local outlier factor for the candidate anomaly;
[0019] If the local outlier factor is less than the preset threshold, it is determined that the access behavior corresponding to the current API access mode vector x is an abnormal access behavior;
[0020] Adopt a sliding window mechanism to maintain N normal API access mode vectors, and update the mean μ D of the minimum Mahalanobis distance and the standard deviation σ D of the minimum Mahalanobis distance value in real time to ensure that the dynamic threshold adapts to the change of the access mode;
[0021] If it is determined that there is an abnormal access behavior, an alarm message is output, and at the same time, the false alarm sample is added to the historical normal data set to trigger the incremental update of the Gaussian mixture model, where the alarm message includes the user ID, the API call sequence, and the deviation score.
[0022] As a preferred solution of the method for monitoring the security of Internet data services based on deep learning according to the present invention, where: calculating the local outlier factor for the candidate anomaly includes:
[0023] Determine the k-nearest neighbor set N k (x) of the current API access mode vector x;
[0024] Calculate the reachable distance LRD k (o) and the local reachability density LRD k (x) of the k-nearest neighbor set N k (x), and obtain the local outlier factor LOF k (x).
[0025] As a preferred solution of the method for monitoring the security of Internet data services based on deep learning according to the present invention, where: the method for generating the API access mode vector is
[0026] For the API call sequence of the access segment, each API interface node is used as the vertex of the graph, and the order relationship of the API calls is used as the directed edge to construct a directed weighted graph structure;
[0027] Assign an initial feature vector to each vertex of the directed weighted graph structure, where the initial feature vector includes the request method type of the API interface, the total number of request parameters, and the response status code;
[0028] Assign a weight value to each edge of the directed weighted graph structure, where the weight value is calculated from the call time interval and call frequency of the vertices at both ends of the edge;
[0029] Based on the directed weighted graph structure, establish a graph convolutional network model;
[0030] Perform forward propagation calculation on each access segment through the graph convolutional network model to obtain the global representation of the graph structure;
[0031] Reduce the dimension of the global representation of the graph structure through a fully connected layer to generate an API access pattern vector with a fixed dimension.
[0032] As a preferred solution of the method for monitoring the security of Internet data services based on deep learning according to the present invention, wherein: the graph convolutional network model includes a spatial domain convolutional operation layer, a temporal domain convolutional operation layer, and an attention pooling operation layer; the spatial domain convolutional operation layer is used to fuse the feature information of adjacent API nodes; the temporal domain convolutional operation layer is used to extract the temporal pattern of the API call sequence; the attention pooling operation layer assigns higher weights to the API call relationships by introducing a self-attention mechanism.
[0033] As a preferred solution of the method for monitoring the security of Internet data services based on deep learning according to the present invention, wherein: the method for dividing the access segment is as follows:
[0034] Extract the user identifier according to the authentication token information, and group the API access feature sequences according to the user identifier;
[0035] Sort the access feature sequences within each user group according to the timestamp to form an access behavior sequence in the user dimension;
[0036] Process the access behavior sequence using a temporal slicing method, and divide the access behavior sequence into multiple consecutive and fixed-duration access segments by setting the time window length parameter, and the duration of the access segment is the preset time window length.
[0037] As a preferred solution of the method for monitoring the security of Internet data services based on deep learning according to the present invention, wherein: the method for constructing the API access feature sequence is as follows:
[0038] Deploy a log collection agent program in the application server to obtain the request logs of the API gateway layer in real time;
[0039] Preprocess the request log and extract access features according to preset feature extraction rules, where the access features include request method, authentication token, request parameters, and request time;
[0040] Arrange the access features in ascending order of timestamp and perform vector quantization encoding on each feature;
[0041] Organize the encoded access features in time series to construct an API access feature sequence.
[0042] In a second aspect, an embodiment of the present invention provides an Internet data service security monitoring system based on deep learning, which includes:
[0043] A feature extraction module, configured to collect request logs of API interfaces, extract access features of the request logs, and construct an API access feature sequence;
[0044] A time series slicing module, configured to aggregate the API access feature sequence according to the user dimension and divide it into access segments of a fixed duration;
[0045] A generation module, configured to construct a graph neural network model, map the API call relationship in the access segment to a graph structure, extract context features of the API call chain through graph convolution operations, and generate an API access pattern vector;
[0046] A density evaluation module, configured to perform density evaluation on the API access pattern vector and calculate the deviation degree of the current access behavior from the historical normal access pattern;
[0047] A security warning module, configured to determine that there is an abnormal access behavior when the deviation degree exceeds a dynamic threshold, output an authentication bypass attack warning, and implement the security monitoring of Internet data services.
[0048] In a third aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the processor executes the computer program, any step of the above-mentioned Internet data service security monitoring method based on deep learning is implemented.
[0049] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by a processor, any step of the above-mentioned Internet data service security monitoring method based on deep learning is implemented.
[0050] Compared with the prior art, the beneficial effects of the present invention are as follows: By constructing a graph structure and introducing a graph neural network, the temporal characteristics and context dependencies of API call relationships are comprehensively extracted, breaking through the limitations of traditional rule matching and shallow feature methods, and realizing deep semantic modeling of complex access behaviors; Using a Gaussian mixture model combined with Mahalanobis distance for deviation evaluation, and supplemented by local outlier factors for multi-scale judgment, effectively suppressing false positives and false negatives, and improving the accuracy and credibility of abnormal access recognition; Introducing a sliding window mechanism and an incremental update strategy to continuously maintain the model parameters of access behaviors, enabling the monitoring system to respond in a timely manner to the natural evolution of access behavior patterns, and improving the long-term stability and self-learning ability of the model; Extracting user identities through authentication tokens, dividing access segments and focusing on user behavior sequences, effectively avoiding user confusion problems, and realizing refined analysis and abnormal detection of specific user behaviors; Constructing a closed-loop mechanism from access behavior collection, semantic extraction, abnormal recognition to alarm feedback, which can identify and respond to authentication bypass attacks in real time and accurately, greatly improving the security protection ability of the Internet data service platform. Description of the Drawings
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:
[0052] Figure 1 It is a flowchart of an Internet data service security monitoring method based on deep learning. Detailed Embodiments
[0053] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention with reference to the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0054] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0055] Second, the "one embodiment" or "embodiment" mentioned herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that exclude each other with other embodiments.
[0056] The present invention is described in detail in conjunction with schematic diagrams. When detailing the embodiments of the present invention, for the convenience of explanation, the cross-sectional views showing the device structure will be enlarged locally in a non-general proportion, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention herein. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.
[0057] At the same time, in the description of the present invention, it should be noted that the orientation or positional relationship indicated by terms such as "upper, lower, inner, and outer" is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention. In addition, the terms "first, second, or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0058] Unless otherwise clearly specified and limited in the present invention, the terms "mounted, connected, and connected" should be understood in a broad sense. For example: it can be a fixed connection, a detachable connection, or an integral connection; it can also be a mechanical connection, an electrical connection, or a direct connection, and can also be indirectly connected through an intermediate medium, or it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood in specific situations.
[0059] Embodiment 1
[0060] Referring to Figure 1 , which is the first embodiment of the present invention. This embodiment provides a security monitoring method for Internet data services based on deep learning, including:
[0061] S1: Collect the request logs of the API interface, extract the access features of the request logs, and construct an API access feature sequence.
[0062] Specifically, by deploying a log collection proxy program in the application server, the request logs of the API gateway layer are obtained in real time.
[0063] In an alternative embodiment, the request logs are preprocessed, and the access features are extracted according to a preset feature extraction rule.
[0064] Exemplarily, the preprocessing includes removing null records in the log data to avoid interference of invalid data on subsequent feature extraction and modeling processes; performing unified format conversion on the time fields in the log, standardizing different time formats into a unified timestamp format to ensure the comparability and temporal correctness of the feature sequence in the time dimension; for the request parameter content stored in JSON format in the log, performing structured parsing to extract nested fields into recognizable key-value pairs, thereby facilitating the accurate extraction and vectorized encoding of subsequent access features.
[0065] Exemplarily, the access features include request method, authentication token, request parameters, and request time; specifically including: extracting the method type used in the HTTP request, such as GET, POST, PUT, DELETE, etc., to identify the operation intention of the request; extracting the authentication token information from the request header, including Bearer Token or API Key, for identifying the caller's identity; parsing the request parameter values in the URL, the parameter values carried in the Cookie, and the JSON format parameters in the request body to fully restore the business data carried by the request; recording the timestamp when the request is initiated to support the temporal analysis of access behaviors; obtaining the IP address of the client for identifying the request source and access pattern.
[0066] In an optional implementation manner, the access features are sorted in ascending order of the timestamp, and each feature is vectorized and encoded.
[0067] Exemplarily, the vectorized encoding includes performing One-Hot encoding on categorical features, normalizing numerical features, and converting text features into word vectors; the specific methods of vectorized encoding vary according to different feature types, specifically including:
[0068] For categorical features, such as the HTTP request method (e.g., GET, POST, PUT, DELETE) and the type of authentication token (e.g., Bearer Token, API Key), the One-Hot encoding method is used for processing; this method constructs an independent dimension for each possible category, converting the original category information into a sparse binary vector, effectively retaining the independence between categories and avoiding introducing meaningless order biases;
[0069] For numerical features, such as the timestamp when the request is initiated and the client IP address (which can be converted into a numerical form or the network segment number), a normalization processing strategy is adopted; the original numerical values are mapped to a unified range between 0 and 1 to reduce the impact of dimensionality differences on model training, and improve the model convergence efficiency and prediction stability; the timestamp can usually be encoded with periodic features (such as the sine and cosine transforms of hours / minutes) to express the time regularity of access behaviors;
[0070] For text-based features, which mainly include free text fields in request parameters or descriptive texts that may exist in JSON parameter values in the request body, word vector conversion is required. Optionally, a pre-trained word vector model (such as Word2Vec, GloVe, or BERT) can be used to convert the text content into semantic expression vectors, thereby preserving the semantic relationships between words and enhancing the model's understanding ability of the text content.
[0071] Furthermore, organize the encoded access features in chronological order to construct an API access feature sequence.
[0072] Exemplarily, the API access feature sequence contains the complete behavior features of each request, and each record contains the time when the request occurs and the corresponding feature vector.
[0073] S2: Aggregate the API access feature sequence by user dimension and divide it into access segments of a fixed duration.
[0074] Specifically, extract the user identifier according to the authentication token information, and group the API access feature sequence by user identifier; for the access feature sequence within each user group, sort it according to the timestamp to form an access behavior sequence in the user dimension.
[0075] Furthermore, use the chronological slicing method to process the access behavior sequence, and by setting the time window length parameter, divide the access behavior sequence into multiple consecutive and fixed-duration access segments, and the duration of the access segment is the preset time window length.
[0076] It should be noted that during the process of generating access segments, a sliding window mechanism is adopted, and the window sliding step size is a preset value to ensure that there is chronological overlap between adjacent access segments, which is used to capture the access behavior features within a continuous time period; perform a complementation process on the feature sequence within each access segment. When the number of requests within the segment is less than the preset number of requests, zero padding is used to maintain the consistency of the feature dimension; generate the chronological index of the access segment, and record the start time and end time of each access segment.
[0077] S3: Construct a graph neural network model, map the API call relationships in the access segment to a graph structure, extract the context features of the API call chain through graph convolution operations, and generate an API access pattern vector.
[0078] Specifically, for the API call sequence of the access segment, each API interface node is used as the vertex of the graph, and the sequential relationship of API calls is used as the directed edge to construct a directed weighted graph structure. An initial feature vector is assigned to each vertex of the directed weighted graph structure, where the initial feature vector includes the request method type, the total number of request parameters, and the response status code of the API interface. A weight value is assigned to each edge of the directed weighted graph structure, where the weight value is calculated from the call time interval and call frequency of the vertices at both ends of the edge.
[0079] Furthermore, based on the directed weighted graph structure, a graph convolutional network model is established. The graph convolutional network model includes a spatial domain convolutional operation layer, a temporal domain convolutional operation layer, and an attention pooling operation layer. The spatial domain convolutional operation layer is used to fuse the feature information of adjacent API nodes. The temporal domain convolutional operation layer is used to extract the temporal pattern of the API call sequence. The attention pooling operation layer assigns higher weights to the API call relationships by introducing a self-attention mechanism.
[0080] Exemplarily, the spatial domain convolutional operation layer adopts a graph convolution method based on the adjacency matrix to fuse the feature information of each node and its adjacent nodes, and realizes the extraction and diffusion of local structure information. This layer focuses on the local connection pattern of nodes in the call graph, which helps to capture the context-dependent characteristics of API call behavior.
[0081] Exemplarily, the temporal domain convolutional operation layer combines the time feature information contained in the edge weights between nodes to perform one-dimensional convolution operations or time gating mechanism operations, so as to extract the potential temporal evolution patterns and dependency paths in the call sequence.
[0082] Exemplarily, the attention pooling operation layer assigns dynamic weights to the importance of different call paths in the graph structure by introducing a self-attention mechanism, so that the aggregation process of the global representation can pay more attention to key call nodes and high-influence call relationships.
[0083] Even further, forward propagation calculation is performed on each access segment through the graph convolutional network model to obtain the global representation of the graph structure. The global representation of the graph structure is subjected to dimensionality reduction transformation through a fully connected layer to generate an API access pattern vector with a fixed dimension.
[0084] S4: Evaluate the density of the API access pattern vector and calculate the deviation degree of the current access behavior from the historical normal access pattern.
[0085] Specifically, collect the API access pattern vectors in the historical normal access data, and use the Gaussian mixture model to fit the distribution of the API access pattern vectors to obtain K Gaussian components, including:
[0086]
[0087] where \(x\) is the current API access mode vector \(x\); \(K\) is the number of Gaussian components, representing the number of categories of normal behavior patterns; \(\pi\) k is the mixing weight coefficient of the \(k\)-th Gaussian component, with a value range of \([0, 1]\); \(\mu\) k is the mean vector of the \(k\)-th Gaussian component, representing the central feature of this category; is the covariance matrix of the \(k\)-th Gaussian component, representing the distribution of features; \(\lambda\) is the time decay factor, representing the degree of influence on historical data; \(t\) is the current timestamp.
[0088] It should be noted that each Gaussian component includes a mean vector and a covariance matrix.
[0089] Furthermore, calculate the Mahalanobis distance \(D\) k (x) between the current API access mode vector \(x\) and each Gaussian component, and select the minimum Mahalanobis distance value \(D\) min (x) = min(D1(x), D2(x), …, D K (x)) as the evaluation index of the deviation degree.
[0090] Preferably, the specific formula of the Mahalanobis distance \(D\) k (x) is as follows:
[0091]
[0092] where \(\Delta t\) is the time interval, representing the time difference between adjacent accesses; \(\theta\) is the time decay coefficient, used to adjust the rate of time decay, with a value range of \([1, 10]\).
[0093] In an alternative embodiment, set the dynamic threshold \(\mu\) D + 3\(\sigma\) D , where \(\mu\) D is the mean of the minimum Mahalanobis distance within the normal sample window, and \(\sigma\) D is the standard deviation of the minimum Mahalanobis distance values within the window; when the minimum Mahalanobis distance value is less than the dynamic threshold \(\mu\) D + 3\(\sigma\) D , then mark the current API access mode vector \(x\) as a candidate anomaly and calculate the local outlier factor for the candidate anomaly.
[0094] In an alternative embodiment, calculating the local outlier factor for the candidate anomaly includes: determining the \(k\)-nearest neighbor set \(N\) k (x) of the current API access mode vector \(x\); calculating the reachable distance \(LRD\) k (o) and the local reachable density \(LRD\) k (x) of the \(k\)-nearest neighbor set \(N\) k (x), and obtaining the local outlier factor \(LOF\) k (x).
[0095] Preferably, the specific formula for the local outlier factor is as follows:
[0096]
[0097] where α is the distance attenuation coefficient used to adjust the influence of distance; d(x,o) is the Euclidean distance function between samples.
[0098] Exemplarily, assume that 10,000 normal API access pattern vectors (dimension = 256) are collected, and 3 Gaussian components (K = 3) are obtained by fitting with the Gaussian mixture model. The parameters are as follows:
[0099] Component 1:
[0100] π1 = 0.4
[0101] μ1 = [0.2, 0.5, …, -0.1]
[0102] ∑1 is a 256×256 diagonal matrix (variance = 0.3)
[0103] Component 2:
[0104] π2 = 0.3
[0105] μ2 = [-0.1, 0.7, …, 0.4]
[0106] ∑2 is a 256×256 diagonal matrix (variance = 0.2)
[0107] Component 3:
[0108] π3 = 0.3
[0109] μ3 = [0.6, -0.3, …, 0.1]
[0110] ∑3 is a 256×256 diagonal matrix (variance = 0.4);
[0111] Exemplarily, introduce the time decay factor λ = 0.1, θ = 5 to control the influence degree of historical data. In the real-time detection stage, when the current API access pattern vector x = [0.8, -0.2, …, 0.3] is received, the system calculates its time-weighted Mahalanobis distance from each Gaussian component as follows:
[0112]
[0113] Component 1: D1(x) = 2.1×e -2.4 ≈0.19
[0114] Component 2: D2(x) = 3.5×e -2.4 ≈0.32
[0115] Component 3: D3(x) = 1.8 × e -2.4 ≈0.16
[0116] Select the minimum Mahalanobis distance: D min (x) = 0.16.
[0117] Exemplarily, maintain the statistics of the last 1000 normal samples (μ D = 0.12, σ D = 0.05) through a sliding window, and set the dynamic threshold to μ D + 3σ D = 0.27. Since 0.16 < 0.27, this access is determined to be normal.
[0118] Exemplarily, when x' = [5.1, -2.3,..., 4.7] and Δt = 60 seconds, its minimum Mahalanobis distance D min (x′) ≈ 4.8 far exceeds the threshold 0.27, which will trigger the local outlier factor verification. First, determine the 20-nearest neighbor set N_k(x') of x', and calculate its local reachability density LRD k (x′) and the neighbor average density LRD k (o) = 1.2, substitute into the local outlier factor formula (including the distance decay coefficient α = 0.5 and the Euclidean distance d(x′, o) = 8.3) to get the LOF k (x′) value ≈ 2.9. Since this value is greater than the preset threshold 2.5, it is determined to be an abnormal access and an alarm is generated.
[0119] Preferably, this method effectively distinguishes normal access and potential attack behaviors through the dual mechanisms of time-weighted Mahalanobis distance and dynamic threshold, and the introduction of the time decay factor θ and the distance decay coefficient α significantly improves the sensitivity of the model to temporal features and spatial distributions.
[0120] S5: When the deviation degree exceeds the dynamic threshold, it is determined that there is an abnormal access behavior, and an authentication bypass attack alarm is output to achieve the security monitoring of Internet data services.
[0121] Specifically, if the local outlier factor is less than the preset threshold, it is determined that the access behavior corresponding to the current API access mode vector x is an abnormal access behavior; use the sliding window mechanism to maintain N normal API access mode vectors, and update the mean μ of the minimum Mahalanobis distance D and the standard deviation σ of the minimum Mahalanobis distance value D in real time to ensure that the dynamic threshold adapts to the change of the access mode.
[0122] It should be noted that the preset threshold is obtained through clustering analysis and anomaly detection experiments on the access pattern vectors in a large amount of real user access data, and the typical distribution range of the local outlier factor under normal behavior is statistically obtained. Then, an empirical value that takes into account both the recall rate and the false positive rate is selected as the threshold.
[0123] Furthermore, if an abnormal access behavior is determined, an alarm message will be output. At the same time, the false positive samples will be added to the historical normal data set, triggering an incremental update of the Gaussian mixture model. The alarm message includes the user ID, the API call sequence, and the deviation score.
[0124] In an alternative embodiment, after the alarm message is output, a hierarchical response strategy will be executed according to the risk level of the alarm message (such as the deviation score, the local outlier factor value): for high-risk anomalies (such as authentication token theft or high-frequency malicious calls), the dynamic interception module of the API gateway will be immediately triggered to terminate the current session and temporarily block the access permission of the user identifier (such as Token or IP); for medium and low-risk anomalies (such as parameter anomalies but no attack features are detected), throttling or challenge-based verification (such as CAPTCHA) will be adopted for secondary confirmation.
[0125] In an alternative embodiment, the abnormal access behavior will be associated with the detection results of deep learning for attack pattern analysis. For example, if the API access pattern vector extracted by the graph convolutional network model shows an abnormal call chain (such as unauthorized access to sensitive interfaces), an attack behavior portrait will be automatically generated, including the call path, time distribution, and parameter characteristics, and stored in the threat intelligence library; at the same time, the adversarial sample detection module will be started to analyze whether the anomaly belongs to an evasion attack against deep learning (such as bypassing detection by perturbing request parameters), and accordingly optimize the feature extraction rules or adjust the attention weights of the graph convolutional network.
[0126] In an alternative embodiment, an incremental learning mechanism is adopted to realize the dynamic update of the model. For samples confirmed as real attacks, they will be added to the training set, triggering online fine-tuning of the Gaussian mixture model and the graph convolutional network model. The network parameters (such as the weights of the convolutional kernels or the covariance matrix of the Gaussian components) will be adjusted through the backpropagation algorithm to enhance the model's ability to identify new types of attacks. For false positive samples, the classification boundary will be corrected through the negative sample learning strategy, such as adjusting the dynamic threshold of the Mahalanobis distance or the number of neighbors of the local outlier factor, to reduce the subsequent false positive rate.
[0127] Example illustration: When it is detected that user A makes calls through abnormal time sequences (such as densely accessing the "password modification" and "transaction confirmation" interfaces within a short period), in addition to issuing an alarm, the system freezes their session and marks it as a "credential hijacking attack"; after review by the security team, it is confirmed that this behavior conforms to the attack pattern, and then the edge weight calculation logic of the graph convolutional network model is updated (such as shortening the time interval weight for high-frequency calls), and the salience of this type of call chain in the attention pooling layer is enhanced; at the same time, the model encodes such abnormal patterns into a new Gaussian component (K + 1) and incorporates it into subsequent density evaluation.
[0128] In summary, by constructing a graph structure and introducing graph neural networks, the temporal characteristics and context dependencies of API call relationships are comprehensively extracted, breaking through the limitations of traditional rule matching and shallow feature methods, and realizing deep semantic modeling of complex access behaviors; using a Gaussian mixture model combined with Mahalanobis distance for deviation evaluation, and supplemented by local outlier factors for multi-scale judgment, effectively suppressing the false alarm and miss rate, and improving the accuracy and credibility of abnormal access recognition; introducing a sliding window mechanism and an incremental update strategy to continuously maintain the model parameters of access behaviors, enabling the monitoring system to respond in a timely manner to the natural evolution of access behavior patterns, and improving the long-term stability and self-learning ability of the model; extracting user identities through authentication tokens, dividing access segments and focusing on user behavior sequences, effectively avoiding the problem of user confusion, and realizing refined analysis and abnormal detection of specific user behaviors; constructing a closed-loop mechanism from access behavior collection, semantic extraction, abnormal recognition to alarm feedback, which can identify and respond to authentication bypass attacks in real time and accurately, greatly enhancing the security protection ability of the Internet data service platform.
[0129] Example 2
[0130] This is the second embodiment of the present invention. This embodiment also provides an Internet data service security monitoring system based on deep learning, including:
[0131] A feature extraction module, configured to collect request logs of API interfaces, extract access features of the request logs, and construct an API access feature sequence;
[0132] A time sequence slicing module, configured to aggregate the API access feature sequence according to the user dimension and divide it into access segments of a fixed duration;
[0133] A generation module, configured to construct a graph neural network model, map the API call relationships in the access segments into a graph structure, extract context features of API call chains through graph convolutional operations, and generate an API access pattern vector;
[0134] A density evaluation module, configured to perform density evaluation on the API access pattern vector and calculate the deviation degree of the current access behavior from the historical normal access pattern;
[0135] A security warning module, which is used to determine that there is an abnormal access behavior when the deviation degree exceeds the dynamic threshold, output an authentication bypass attack warning, and realize the security monitoring of Internet data services.
[0136] It should be noted that the technical solution of the system for security monitoring of Internet data services based on deep learning belongs to the same concept as the technical solution of the above-mentioned method for security monitoring of Internet data services based on deep learning. For the details not described in detail in the technical solution of the system for security monitoring of Internet data services based on deep learning in this embodiment, reference can be made to the description of the technical solution of the above-mentioned method for security monitoring of Internet data services based on deep learning.
[0137] The above-mentioned unit modules can be embedded in the processor of the computer device in hardware form or be independent of the processor, or can be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above-mentioned modules.
[0138] This embodiment also provides an electronic device, which includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be realized through WIFI, a carrier network, NFC (Near Field Communication) or other technologies. When the computer program is executed by the processor, it realizes a multi-task edge computing resource scheduling method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a button, a trackball or a touchpad provided on the shell of the computer device, or an external keyboard, a touchpad or a mouse, etc.
[0139] This embodiment also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by the processor, it realizes the method proposed in the above-mentioned embodiment.
[0140] The storage medium proposed in this embodiment and the method proposed in the above-mentioned embodiment belong to the same inventive concept. The technical details not described in detail in this embodiment can be referred to the above-mentioned embodiment, and this embodiment has the same beneficial effects as the above-mentioned embodiment.
[0141] From the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software and necessary general-purpose hardware. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disc of a computer, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the method of the embodiments of the present invention.
[0142] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
[0143] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present application can be implemented in various computer languages.
[0144] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0145] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means embodying the functionality specified in the flowchart(s) Figure 1 of one or more flowcharts and / or block diagram(s) Figure 1 of one or more block diagrams.
[0146] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functionality specified in the flowchart(s) Figure 1 of one or more flowcharts and / or block diagram(s) Figure 1 of one or more block diagrams.
[0147] Although the preferred embodiments of the present application have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.
[0148] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. An Internet data service security monitoring method based on deep learning, characterized in that: including, collecting the request logs of the API interface, extracting the access characteristics of the request logs, and constructing an API access feature sequence; aggregating the API access feature sequence by user dimension and dividing it into access segments of a fixed duration; constructing a graph neural network model, mapping the API call relationships in the access segments into a graph structure, extracting the context features of the API call chain through graph convolution operations, and generating an API access pattern vector; performing density evaluation on the API access pattern vector to calculate the deviation degree between the current access behavior and the historical normal access patterns; when the deviation degree exceeds the dynamic threshold, it is determined that there is an abnormal access behavior, and an authentication bypass attack warning is output to achieve the security monitoring of Internet data services.
2. The security monitoring method for Internet data services based on deep learning according to claim 1, characterized in that: The calculation method of the deviation degree is collecting the API access pattern vectors in the historical normal access data and using the Gaussian mixture model to fit the distribution of the API access pattern vectors to obtain K Gaussian components; Calculate the Mahalanobis distance D between the current API access pattern vector x and each Gaussian component k (x), and select the minimum Mahalanobis distance value D min (x)=min(D1(x),D2(x),…,D K (x)) as an evaluation indicator of the degree of deviation; Set the dynamic threshold μ D +3σ D , where μ D is the mean of the minimum Mahalanobis distances, and σ D is the standard deviation of the minimum Mahalanobis distance values; When the minimum Mahalanobis distance value is less than the dynamic threshold μ D +3σ D then the current API access pattern vector x is marked as a candidate anomaly, and the local outlier factor is calculated for the candidate anomaly; if the local outlier factor is less than the preset threshold, it is determined that the access behavior corresponding to the current API access pattern vector x is an abnormal access behavior; Maintain N normal API access pattern vectors using a sliding window mechanism, and update the mean μ of the minimum Mahalanobis distance in real time D and the standard deviation σ of the minimum Mahalanobis distance value D , ensuring that the dynamic threshold adapts to changes in the access pattern; if it is determined that there is an abnormal access behavior, an alarm message is output, and at the same time, the false alarm samples are added to the historical normal data set to trigger the incremental update of the Gaussian mixture model, where the alarm message includes the user ID, the API call sequence, and the deviation score.
3. The method for security monitoring of Internet data services based on deep learning according to claim 2, characterized in that: Calculating the local outlier factor for the candidate anomaly includes: Determine the k-nearest neighbor set N of the current API access mode vector x k (x); Calculate the k-nearest neighbor set N k The reachability distance LRD of (x) k (o) and the local reachability density LRD k (x), obtaining the local outlier factor LOF k (x).
4. The security monitoring method for Internet data services based on deep learning according to claim 2, characterized in that: The generation method of the API access pattern vector is For the API call sequence of the access segment, taking each API interface node as the vertex of the graph and the sequence of API calls as the directed edge, constructing a directed weighted graph structure; assigning an initial feature vector to each vertex of the directed weighted graph structure, where the initial feature vector includes the request method type, the total number of request parameters, and the response status code of the API interface; assigning a weight value to each edge of the directed weighted graph structure, where the weight value is calculated from the call time interval and call frequency of the vertices at both ends of the edge; Based on the directed weighted graph structure, establishing a graph convolutional network model; performing forward propagation calculation on each access segment through the graph convolutional network model to obtain the global representation of the graph structure; reducing the dimension of the global representation of the graph structure through a fully connected layer to generate an API access pattern vector of a fixed dimension.
5. The security monitoring method for Internet data services based on deep learning according to claim 4, characterized in that: The graph convolutional network model includes a spatial domain convolution operation layer, a temporal domain convolution operation layer, and an attention pooling operation layer; the spatial domain convolution operation layer is used to fuse the feature information of adjacent API nodes; the temporal domain convolution operation layer is used to extract the temporal pattern of the API call sequence; the attention pooling operation layer assigns higher weights to the API call relationships by introducing a self-attention mechanism.
6. The security monitoring method for Internet data services based on deep learning according to claim 4, characterized in that: The division method of the access segment is extracting the user identifier according to the authentication token information and grouping the API access feature sequence according to the user identifier; sorting the access feature sequences within each user group according to the time stamp to form an access behavior sequence in the user dimension; The access behavior sequence is processed by using a time-series slicing method, and by setting a time window length parameter, the access behavior sequence is divided into multiple consecutive access segments with a fixed duration, and the duration of the access segment is the preset time window length.
7. The security monitoring method for Internet data services based on deep learning according to claim 6, characterized in that: The construction method of the API access feature sequence is as follows: By deploying a log collection agent program in the application server, the request logs of the API gateway layer are obtained in real time; The request logs are preprocessed, and access features are extracted according to preset feature extraction rules, where the access features include request method, authentication token, request parameters, and request time; The access features are sorted in ascending order of timestamp, and each feature is vectorized and encoded; The encoded access features are organized according to time series to construct an API access feature sequence.
8. An Internet data service security monitoring system based on deep learning, based on the Internet data service security monitoring method based on deep learning according to any one of claims 1 to 7, characterized in that: It includes: A feature extraction module, which is used to collect the request logs of the API interface, extract the access features of the request logs, and construct an API access feature sequence; A time-series slicing module, which is used to aggregate the API access feature sequence according to the user dimension and divide it into access segments with a fixed duration; A generation module, which is used to construct a graph neural network model, map the API call relationship in the access segment into a graph structure, extract the context features of the API call chain through graph convolution operations, and generate an API access pattern vector; A density evaluation module, which is used to evaluate the density of the API access pattern vector and calculate the deviation degree of the current access behavior from the historical normal access pattern; A security warning module, which is used to determine that there is an abnormal access behavior when the deviation degree exceeds the dynamic threshold, output an authentication bypass attack warning, and realize the security monitoring of Internet data services.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, the steps of the security monitoring method for Internet data services based on deep learning according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of the security monitoring method for Internet data services based on deep learning according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Anomaly detection to identify security threats
US10673880B1
Point-of-interest recommendation method based on temporal knowledge graph
US12254420B1
Explainable layered contextual collective outlier identification in a heterogeneous system
US20240028616A1
Generalized behavior analytics framework for detecting and preventing different types of API security vulnerabilities
US20240430282A1
Cloud-native application programming interface (API) recommendation method fusing data augmentation and contrastive learning
US20250013514A1
Cited By
Method, device and equipment for identifying automatic access attack of firewall
CN120785627A