Web application-based ai protection engine construction method and system

By building an AI protection engine based on Web applications, utilizing semantic parsing and multi-agent collaborative decision-making, combined with neural networks and symbolic reasoning, we have solved the problem of unsatisfactory detection of complex attacks in existing technologies and achieved effective defense against logical vulnerabilities and unknown variant attacks.

CN120415912BActive Publication Date: 2025-10-14SHAOGUAN COLLEGE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510906326.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-10-14
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

Existing Web security protection technologies have poor detection effects when facing complex and changing attacks, especially logical vulnerabilities, advanced persistent threats, and zero-day vulnerabilities. They are also unable to handle both known pattern attacks and unknown variant attacks at the same time.

Method used

Build an AI protection engine based on web applications, which achieves deep understanding and dynamic protection of HTTP requests through semantic parsing, multi-dimensional threat feature extraction, temporal behavior analysis, and multi-agent collaborative decision-making, combined with neural networks and symbolic reasoning.

Benefits of technology

It effectively identifies and defends against logical vulnerability attacks that are difficult for traditional systems to detect, improves the ability to detect complex attacks, and minimizes the impact on normal business while ensuring security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415912B_ABST
    Figure CN120415912B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of AI protection, and discloses an AI protection engine construction method and system based on a Web application. The method comprises the following steps: obtaining a Web application HTTP request and performing semantic analysis to obtain request feature data; performing multidimensional threat feature extraction to obtain a Web request threat feature set; performing pattern matching on the Web request threat feature set and a preset attack mode library to obtain threat type determination results and attack intention information; performing time sequence behavior analysis to obtain Web behavior abnormality indexes; performing comprehensive decision-making through a multi-agent collaborative decision-making system to obtain a defense decision-making scheme; and selecting corresponding defense components through a defense execution engine according to the defense decision-making scheme to perform security protection and obtain a Web request processing result. The application can take corresponding protection measures for requests with different risk levels, and can effectively identify and defend against logical vulnerability attacks that are difficult to detect by traditional systems.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of AI protection, in particular to an AI protection engine construction method and system based on a Web application. BACKGROUND

[0002] Traditional Web security protection technology mainly relies on static rule matching and feature recognition. These methods have obvious limitations when facing complex and variable attacks, especially when facing business logic vulnerabilities, advanced persistent threats (APTs) and zero-day vulnerabilities and other new attack methods. The detection effect is not ideal. Existing security products often completely separate protection rules and business logic, and cannot understand the association between HTTP requests and the context semantics, resulting in a large number of logic vulnerability attacks that cannot be effectively identified.

[0003] There are two main problems in current Web application protection technology: on the one hand, although the security protection system based on traditional rules has high efficiency and interpretability, it lacks self-adaptive ability and recognition ability for complex patterns; on the other hand, the protection technology based on deep learning that has emerged in recent years has strong feature extraction and pattern recognition ability, but its black box characteristics make the protection decision difficult to explain, which cannot meet the strict requirements of the security field for interpretability, and also cannot effectively utilize the domain knowledge of security experts. In addition, most existing protection engines adopt a single technical route, which is difficult to handle known pattern attacks and unknown variant attacks existing in Web applications at the same time. SUMMARY

[0004] The application provides an AI protection engine construction method and system based on a Web application, which can take corresponding protection measures for requests of different risk levels, thereby effectively identifying and defending logic vulnerability attacks that are difficult to detect by traditional systems.

[0005] In a first aspect, the application provides an AI protection engine construction method based on a Web application, which comprises:

[0006] Obtaining a Web application HTTP request and performing semantic analysis to obtain request feature data;

[0007] Performing multi-dimensional threat feature extraction on the request feature data to obtain a Web request threat feature set;

[0008] Performing pattern matching on the Web request threat feature set and a preset attack pattern library to obtain a threat type determination result and attack intention information of the Web application HTTP request;

[0009] Performing time sequence behavior analysis on the request feature data to obtain a Web behavior anomaly index;

[0010] input the threat type determination result, the attack intention information and the Web behavior abnormality index into a multi-agent collaborative decision system for comprehensive decision to obtain a defense decision scheme;

[0011] According to the defense decision scheme, a corresponding defense component is selected through a defense execution engine for security protection to obtain a Web request processing result.

[0012] In a second aspect, the present application provides a Web application-based AI protection engine construction system, which comprises:

[0013] A semantic analysis module is configured to obtain a Web application HTTP request and perform semantic analysis to obtain request feature data;

[0014] A feature extraction module is configured to perform multi-dimensional threat feature extraction on the request feature data to obtain a Web request threat feature set;

[0015] A pattern matching module is configured to perform pattern matching on the Web request threat feature set and a preset attack pattern library to obtain a threat type determination result and attack intention information of the Web application HTTP request;

[0016] A time sequence behavior analysis module is configured to perform time sequence behavior analysis on the request feature data to obtain a Web behavior abnormality index;

[0017] A comprehensive decision module is configured to input the threat type determination result, the attack intention information and the Web behavior abnormality index into a multi-agent collaborative decision system for comprehensive decision to obtain a defense decision scheme;

[0018] A security protection module is configured to select a corresponding defense component through a defense execution engine according to the defense decision scheme for security protection to obtain a Web request processing result.

[0019] In the technical solution provided by the application, the dual-path parallel processing of the neural network path and the symbolic reasoning path is realized by the neural symbol hybrid analysis module, on the one hand, the deep nonlinear characteristics are captured by the neural network, and on the other hand, the logical judgment is retained by the symbolic reasoning, thereby effectively solving the limitations of a single technical route, enabling the protection system to cope with known mode attacks and unknown variant attacks at the same time. The adaptive weight fusion mechanism is adopted to realize the effective integration of the neural network feature vector and the symbolic reasoning result, and through the context-sensitive weight distribution strategy, the system can dynamically adjust the weight proportion of the two paths according to the request characteristics, thereby improving the richness and accuracy of the feature representation. By constructing the abstract syntax tree structure of the HTTP request and applying the graph attention network to analyze the semantic association relationship between parameters, the system can understand the implicit dependency between parameters, effectively identify and defend against logical vulnerability attacks that are difficult to detect by traditional systems. The content analysis layer and the timing behavior layer are designed as two interactive enhanced recurrent neural networks, the content features and behavior features are closely associated through the cross-modal attention mechanism, and the detection ability of the system for complex attacks based on abnormal behavior sequences is significantly improved. Different protection functions are modularized into professional agents, and a sparse communication protocol is introduced to realize efficient information sharing between agents, and the system can automatically construct the optimal protection chain according to the application business logic and threat characteristics, thereby breaking through the limitations of traditional static rule combination. The layered protection mechanism of the network layer, the protocol layer, the application layer and the context layer is adopted, and combined with the differentiated processing strategy, the system can take corresponding protection measures for requests with different risk levels, thereby minimizing the impact on normal business while ensuring security. BRIEF DESCRIPTION OF DRAWINGS

[0020] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are some embodiments of the application, and for those skilled in the art, other drawings can also be obtained based on these drawings without creative labor.

[0021] Figure 1 An embodiment schematic diagram of the method for constructing the AI protection engine based on the Web application in the embodiment of the application;

[0022] Figure 2 An embodiment schematic diagram of the system for constructing the AI protection engine based on the Web application in the embodiment of the application. DETAILED DESCRIPTION

[0023] The embodiments of the present application provide a Web application-based AI protection engine construction method and system. The terms "first", "second", "third", "fourth" and the like (if any) in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" or "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0024] For ease of understanding, the specific flow of the embodiments of the present application is described below. Please refer to Figure 1 One embodiment of the Web application-based AI protection engine construction method in the embodiments of the present application includes:

[0025] Step S101, obtaining a Web application HTTP request and performing semantic analysis to obtain request feature data;

[0026] It can be understood that the execution subject of the present application can be a Web application-based AI protection engine construction system, and can also be a terminal or a server, and the specific execution subject is not limited here. The embodiments of the present application take the server as the execution subject for example.

[0027] Specifically, a non-blocking I / O interception unit is deployed between the web server and the application, which is built based on an event-driven model and uses an asynchronous reading mechanism to intercept all passing HTTP requests in real time, ensuring complete capture of data streams without affecting the business request throughput capacity; the interception unit is based on high-concurrent connection processing capability, and through asynchronous buffering and multi-thread cooperative strategy, the original request stream is divided into independent data channels, and according to the request identifier, the ordered forwarding is performed to form the request data segments that can be processed independently. The captured HTTP request data is preprocessed. The HTTP request header is standardized, and various variant formats are unified into standard structures conforming to the protocol specification; secondly, the URL part is decoded to restore the escaped characters or obfuscated encoding that may exist, thereby restoring the real access path and parameter combination; the HTTP request body and URL parameters are parsed and extracted to construct a preliminary structured request information representation including parameter name, parameter value, parameter position, data type identifier, etc. In this process, a multi-layer parsing strategy is called to ensure that even in multi-layer nested requests or composite coding structures, the request parameter information can be completely restored. After the structured information is constructed, a syntax rule matching mechanism is introduced. This mechanism performs parameter analysis operations based on a previously established web request syntax rule library, which combines various HTTP syntax configurations and web application specific logic templates, and can perform syntax recognition and type classification on each parameter item in the request through context-free grammar (CFG) matching. In the matching process, the basic data types of the parameters (such as string, integer, boolean, array, etc.) are identified, and their possible value ranges are abstractly labeled, and the dependency relationship between parameters is identified, such as whether the value of one parameter is determined by another parameter or whether there is a semantic condition of mutual constraint on the value domain. After completing type identification and dependency relationship modeling, the above information is input as nodes and edges into the abstract syntax tree generation module, which uses a bottom-up recursive construction algorithm to construct AST nodes layer by layer according to the hierarchical structure and dependency relationship between parameters, and assigns each node with parameter name, type, value range, position index and parent-child dependency information, generating an abstract syntax tree. At the same time, the attention weight mechanism in graph structure is introduced in the construction process, and the semantic similarity and correlation between nodes are calculated through graph attention network, further embedding semantic dependency weights in the AST graph structure, and improving the accuracy of subsequent semantic reasoning and behavior modeling. Finally, the request feature data is obtained.

[0028] Step S102, multi-dimensional threat feature extraction is performed on the request feature data to obtain a set of web request threat features;

[0029] Specifically, the request feature data is distributed in a double-path manner by a neural-symbol hybrid analysis module. According to the structural information and logical relationship embodied in the request feature, the request feature is mapped into first input data suitable for neural network path processing and second input data suitable for a symbolic reasoning system, wherein the first input data retains the parameter graph structure representation form, which is suitable for graph neural network modeling; and the second input data is converted into a set of facts and constraints conforming to the first-order predicate logic structure, which facilitates the rule system to perform logical matching and reasoning. The first input data is transmitted to a three-layer graph convolutional neural network (GCN), and the GCN model updates the high-order feature fusion and context representation of each parameter node in the input graph structure through continuous adjacency matrix normalization and feature propagation operations. In each convolutional layer, the node feature representation is weighted aggregated between its direct neighbors and self-loop nodes, and then transmitted to the next layer through an activation function. The output node representation can encode the complex structural dependency relationship, semantic similarity and multi-hop context information between parameters, and generate a discriminative Web request deep feature vector. The vector captures the hierarchical structure features and potential attack pattern features of the parameters, and can reflect whether the request has abnormal organization in structure and whether the parameter combination violates the regular pattern. Meanwhile, the second input data is input into a rule reasoning engine based on the first-order predicate logic. The engine contains a rule base defined by domain experts and constructed by system learning. Each rule is represented in the premise implication structure, that is, a conclusion predicate is jointly derived from multiple predicates. The reasoning engine executes the reasoning process on the input facts through an improved forward chaining mechanism, matches the rule conditions one by one, and triggers the rule conclusions to generate security judgment information, such as "there is a type inconsistency between parameters A and B and the value of B is abnormal, which is judged as a suspected SQL injection". The judgment points out the potential threat of the request and retains the logical chain, enhancing the explainability of subsequent decision-making. The Web request deep feature vector and the symbolic reasoning result containing security judgment information are input into a semantic bridging layer for adaptive weight fusion. The semantic bridging layer maps the deep feature vector output by the neural network and the structured judgment information generated by the symbolic reasoning into a unified vector space through a context-aware adaptive weight fusion mechanism, and dynamically adjusts the fusion weight according to the request feature on this basis. The fusion function includes a weighted combination calculated by an attention mechanism, and embeds a gated update structure and a residual connection technology to enhance the ability of feature interference and the stability of information transmission. The output representation after fusion constitutes the Web request threat feature set.

[0030] In step S103, the Web request threat feature set is matched with the preset attack pattern library to obtain the threat type judgment result and attack intention information of the Web application HTTP request.

[0031] Specifically, an attack pattern library covering multiple attack scenarios is constructed, which takes attack feature templates as the basic unit, each template consisting of multiple dimensional feature vectors, covering structural features, behavior trajectories, semantic patterns, and contextual relevance, and forming high-confidence attack feature baselines through expert annotation and historical attack data mining. In the defense process, the system receives web requests, which are analyzed and processed through dual-path analysis and semantic fusion, forming a web request threat feature set containing multi-source information. This feature set is represented in the form of a unified high-dimensional vector and has deep structural semantics, logical rule determination, and contextual behavior information. Subsequently, the threat feature set is compared with all attack feature templates in the attack pattern library, and a vector-level matching is performed through an improved similarity calculation mechanism. This mechanism uses basic measurement methods such as cosine similarity and introduces a multi-channel attention enhancement model. Different weights are introduced in the comparison to reflect the discriminability of features in different attack types, outputting a set of attack type similarity scores for each template. According to multiple sets of attack type similarity scores, a threat classifier is used for multi-class discriminant analysis. The classifier is constructed using a combination of stacked deep neural network models and ensemble discriminant learning algorithms, and can handle complex boundary determination problems between high-dimensional input vectors and multiple overlapping categories. The classifier integrates multiple attack samples in the training stage, including SQL injection, cross-site scripting, command injection, logical deception, parameter tampering, etc. Through guided model learning, the distribution of each type of attack in the feature space is learned, and then in the reasoning stage, multiple sets of similarity scores are used for multi-class comprehensive judgment, outputting the threat type determination result, clearly indicating whether the current request belongs to a certain attack type, and if so, outputting the category and its confidence score. While obtaining the threat type, semantic level analysis and attack target extraction are performed on the web request threat feature set to understand the attack intent. The semantic level analysis process is based on a multi-layer Transformer structure. The system maps the feature set to the semantic space, uses a pre-trained attack scenario semantic model to analyze the resource range, key parameter direction, and behavior target involved in the request, and locates the potential attack target in the vector space, such as database fields, authentication tokens, control variables, or business paths. The attack target extraction result is represented in a structured label and includes dimensions such as location, type, and permission level. After obtaining the attack target recognition result, combined with the threat type determination result, an attack intent graph is constructed through an intent association analysis module. This module establishes a multi-hop semantic relationship between attack types and target resources, uses a graph convolution embedding model and a path attention mechanism to mine potential attack motives and attack chains. For example, when a request is determined to be a "logical deception" attack and its target object is a permission control variable, the system infers that its attack intent is "bypassing authentication"; if the type is "command injection" and the target is a server terminal interface, the intent is "remote control execution".The system outputs a complete threat description including the attack type name, target object and attack intention.

[0032] In step S104, time sequence behavior analysis is performed on the requested feature data to obtain a Web behavior anomaly index.

[0033] Specifically, a historical request record library covering the access behaviors of all users in the station is established, which organizes data in units of user sessions, records the request path, request timestamp, parameter transformation, identity status, behavior type and other information of each user in a single session, and maintains time continuity and semantic integrity. When a new Web request arrives, the system matches the historical request record library according to the user identification, session ID, cookie information, source IP, device fingerprint and other key features contained in the request, restores the complete time sequence access sequence where the request is located through matching association, and forms a Web request time sequence sequence containing the current request context. Time decay processing and behavior feature extraction operations are performed on the Web request time sequence sequence. Time decay processing dynamically adjusts the weight of historical behavior in the sequence by defining a time decay function, so that behaviors closer to the current request time have a stronger impact on feature expression, while behaviors farther away have a gradually decreasing impact, thereby highlighting behavior mutations or abnormally frequent access behaviors in a short period of time. At the same time, high-order behavior features including page jump path, request frequency, parameter variation range, identity switching trajectory, action category order are extracted from the request sequence, and these features are encoded into time sequence feature vectors in the form of time sequence, and input into the subsequent analysis model in the form of multi-dimensional tensor. The constructed time sequence feature vector is input into a double-layer recurrent neural network structure, which is composed of a content analysis layer and a time sequence behavior layer in parallel. The content analysis layer is built based on bidirectional gated recurrent unit, responsible for modeling the semantic content change trend in the request sequence, retaining the original feature information of each request step through residual connection mechanism, and introducing context window to capture the semantic linkage relationship between parameters; while the time sequence behavior layer is composed of multi-layer long short-term memory network structure, which integrates time decay factor, making it more sensitive to changes in behaviors close in time, suitable for capturing behavior features such as high-frequency access, access path mutation, abnormal request interval in a short period of time. The two network layers output content feature representation and behavior feature representation respectively, which reveal the structure and behavior deviation of the request from the semantic and time perspectives. In order to fuse the information from the two different sources, a cross-modal attention mechanism is introduced to establish mutual attention relationship between the content feature representation and the behavior feature representation. The attention mechanism establishes a mapping matrix through query-key-value calculation method, measures the response degree of each content semantic dimension to the behavior mode, and gives higher attention weight to the potential abnormal points in the behavior dimension, realizing dynamic focusing and feature alignment of information from content to behavior. Finally, the two features are integrated through an attention weighted fusion function to form a high-dimensional Web behavior anomaly index, which can represent whether the current request has appeared mutation in the time dimension, whether it has broken the boundary of historical access mode, whether it has shown a non-typical behavior sequence, etc., and can output abnormal score or behavior label quantitatively.

[0034] In step S105, the threat type determination result, the attack intention information, and the Web behavior anomaly index are input into a multi-agent collaborative decision system for comprehensive decision to obtain a defense decision scheme.

[0035] Specifically, the input features are semantically deconstructed and domain mapped by an efficient data feature distribution gateway. Based on the feature tag mechanism, the gateway performs reordering and vectorization encapsulation operations on the input features, so that the threat type judgment result can be converted into a structured attack label set, the attack intent information can be converted into a target behavior vector, and the Web behavior anomaly index can be expressed in the form of a time-weighted tensor, thereby providing a unified and deconstructible data format for the subsequent multi-agent processing module. According to the preset mapping rules, the gateway allocates these features to five types of core agents in the collaborative decision system according to the responsibility domain, including attack recognition agents, behavior analysis agents, business logic agents, security policy agents, and resource scheduling agents. Each agent is composed of an independent policy network and an evaluation network, and has the ability to reason and analyze security events and risk assessment in its professional domain. After receiving the allocated feature data, the attack recognition agent measures the attack similarity and corrects the class confidence based on the attack label set and the historical attack type graph; the behavior analysis agent uses the abnormal tensor and session behavior graph to perform multi-layer variation detection on the user behavior trajectory; the business logic agent maps and verifies the request path and business model to detect whether there are business layer abnormalities such as bypassing control and process fraud; the security policy agent performs policy adaptation and matching according to the current threat context, and evaluates whether the system should trigger secondary verification, dynamic verification code, isolation mechanism or direct interception; the resource scheduling agent dynamically evaluates the current system resource occupation and response load to judge the system bearing feasibility of defense measures. The above five types of agents complete one evaluation iteration in their own policy network and output professional evaluation results in their respective fields. In order to avoid isolated and local optimal decision of agents, an information exchange mechanism based on sparse communication protocol is introduced to establish a limited state sharing channel between agents. This mechanism sets a communication threshold θ for each agent, initiates a partial state broadcast request to other agents according to the evaluation result change amplitude and abnormal level, and forms a collaborative state matrix. The collaborative state matrix integrates the local analysis results of each agent on the current request, and through a dynamic attention fusion mechanism, the different evaluation weights are weighted and regulated, so that the system forms a unified collaborative cognitive state for the current request. Based on the collaborative state matrix, the system enters the joint strategy generation phase. This phase is driven by a central strategy generator, which uses the collaborative matrix as input features to search for a matching response path in the pre-trained policy space, forming multiple candidate defense schemes, including request interception, parameter verification enhancement, session isolation, response delay or speed limit, and forced identity verification, etc. Each scheme will be accompanied by an execution feasibility score, which considers threat level, security policy fit, and current resource availability. The strategy generator uses a multi-objective decision model based on policy gradient optimization to output a candidate scheme set through joint optimization of the policy reward function and the resource constraint function.An optimal solution selection is performed on multiple candidate defense schemes and their corresponding execution feasibility scores, the selection mechanism based on priority ranking and Bayesian belief update model, the historical success rate of the scheme, the matching degree of the current system state and the risk offset ability are weighted and summed, and the defense scheme with the highest global score is selected as the final defense decision output of this Web request.

[0036] A feature distribution gateway with semantic label recognition and dynamic feature mapping capability is constructed. The gateway uses a meta-information-driven scheduling mechanism to identify the domain of the input security features, reconstruct the feature vector, and encode the feature weight. Through feature channel modeling, various information is transmitted to five independent agent modules, allowing each agent to efficiently receive and analyze data related to its specific feature space, thereby achieving dynamic binding and accurate mapping of input features and agent capability structure. Under this mechanism, the threat type determination result is input into the first feature space of the attack recognition agent. This space encodes the attack label, attack confidence, and impact factor into a hierarchical risk map. Then, a three-layer perception neural network model is constructed to perform attack type re-verification and impact range assessment. The perception network takes attack pattern embedding vectors as input, performs robust evaluation of the input attack determination result through multiple nonlinear transformations, and restores the attack source propagation path, thereby generating attack recognition evaluation results, including attack type confirmation, variation mode assessment, and propagation path node weight matrix. Meanwhile, the Web behavior anomaly indicators are input into the second feature space of the behavior analysis agent. A time series perception network is constructed in this feature space. The core of the network is a long short-term memory network with attention mechanism, which takes behavior tensor sequences as input and can capture behavior deviation trends, request dependency, and temporal local anomaly fluctuations. In the output stage, an anomaly degree quantification module is used to standardize the recognition results into anomaly level scores, deviation trajectory curves, and abnormal behavior categories, forming the behavior analysis evaluation results. The attack intent information is input into the third feature space of the business logic agent. In this space, a rule verification network is used to check the compliance of the request intent and the current business process model. By constructing a logic verification network composed of rule constraint graphs and process state machines, the triggering action, target resource, and call relationship of the request are analyzed to identify whether the request triggers operations outside the process boundary or sensitive interface calls. A sensitive behavior confidence calculation module is used to score the potential business risks caused by the request, generating business logic evaluation results including illegal operation identification, process breakpoint position, and operation sensitivity level. The combination of threat type determination results, attack intent information, and Web behavior anomaly indicators is input into the fourth feature space of the security policy agent. A knowledge graph-based policy matching engine is integrated in this space to build a matching mapping relationship between policy graph nodes and input security scenarios. By combining nearest neighbor search in the policy embedding space with policy execution cost prediction, the engine filters multiple feasible defense strategies under the current scenario and outputs security policy evaluation results based on policy coverage, adaptation level, and response level, ensuring that the defense selection is contextually consistent and dynamically adaptable.The resource scheduling agent runs a resource optimization algorithm in the fifth feature space after receiving the same set of comprehensive features. The algorithm considers multiple dimensions such as the current system resource state, service load, user priority, and policy implementation cost. Through a multi-objective resource scheduling optimization model, the resource consumption, response delay, and system occupancy rate of each candidate strategy under actual deployment are solved. The resource scheduling evaluation results are generated, and a set of indicators including policy execution cost distribution, performance impact prediction, and system stability evaluation are output. The attack recognition evaluation results, behavior analysis evaluation results, business logic evaluation results, security policy evaluation results, and resource scheduling evaluation results are unified and encapsulated as the multi-agent professional domain evaluation results.

[0037] According to the attack recognition agent, the behavior analysis agent, the business logic agent, the security policy agent and the resource scheduling agent, the collaborative state matrix is divided into professional domain to obtain the professional domain state sub-matrix of each agent. Each agent inputs its corresponding professional domain state sub-matrix into the deep policy network for action value evaluation. The attack recognition agent extracts the response tension of the attack context to the interception strategy through the convolution perception structure and the residual feedback mechanism, and generates an attack interception action set, which includes defense actions such as direct blocking, protocol rollback, and man-in-the-middle forwarding for attack traffic. The behavior analysis agent maps the behavior evolution trend and user deviation degree based on time series feature convolution and gating mechanism, and outputs a behavior restriction action set, such as access frequency flow control, behavior verification code triggering, and dynamic parameter randomization. The business logic agent calls the rule control network to match the business process risk path with the current behavior target, and outputs a business rule action set, including parameter dependency verification, transaction consistency check or jump path rewriting. The security policy agent matches the corresponding policy response path in the policy graph space according to the current security scenario, and outputs a security policy action set including response level, execution depth and verification mechanism combination. The resource scheduling agent outputs a resource allocation action set based on the system load data and the policy demand mapping function, including concurrent quota adjustment, load balancing node switching, memory isolation strategy and other system-level response methods. After all the action sets are generated, the system enters the action coordinator stage, which is a multi-channel action fusion network based on the reinforcement learning control graph structure. It can model joint actions according to the context dependency relationship between actions, execution conflict probability and cooperative benefit function, and optimize each action set through a policy coupling decoder. It generates candidate defense schemes while avoiding action redundancy, logic conflict and resource overload, forming several candidate defense schemes containing different policy configuration combinations. Each scheme covers attack response methods, behavior control mechanisms, business constraint updates, security policy settings and resource configuration boundaries, and has an end-to-end policy executable structure. Joint evaluation is performed on multiple candidate defense schemes. The security effect prediction module and the system load evaluation module are introduced to calculate the policy defense success rate, expected threat suppression degree, business impact degree, resource consumption rate, system response delay and scalability indicators of each candidate scheme under the current system state. The security effect prediction module uses an integrated Bayesian regression model to fit and predict the performance of each action combination in a similar historical scenario. The system load evaluation module constructs a joint load propagation graph based on the resource mapping graph and the strategy invocation graph, and quantifies the implementation cost and system bearing feasibility of each scheme in different dimensions by solving the strategy influence radius and the system response function.An execution feasibility score is assigned to each candidate defense scheme, which comprehensively considers security benefits, business stability, resource cost and strategy generality, and is normalized to form a comparable score interval, which is an important basis for the final decision module to select the optimal defense scheme.

[0038] Step S106, according to the defense decision scheme, the corresponding defense component is selected by the defense execution engine for security protection, and a Web request processing result is obtained.

[0039] Specifically, the defense decision scheme is input into the defense execution engine for defense component matching and sequence generation. The engine receives the defense decision scheme output from the upstream joint strategy generation module and processes the scheme as input in its internal strategy scheduling model. During this process, the defense execution engine identifies the functional modules that need to be activated, such as SQL injection protection, identity verification enhancement, parameter integrity check, business path verification, or session integrity maintenance, by analyzing the action structure and policy label in the decision scheme. Based on the component registry and policy atlas indexing mechanism, the engine selects available and suitable defense components and organizes them into a defense execution chain containing component sequences, call relationships, and dependency orders according to the execution logic of the policy. The components in the defense execution chain are processed in multiple levels based on a standard hierarchical protection mechanism, which divides the entire protection process into four logical processing stages: network layer, protocol layer, application layer, and context layer. In the network layer, IP blocking, port access control, black and white list filtering, and TLS connection analysis are used to filter transmission-level threats. In the protocol layer, HTTP protocol parser and status code verification mechanisms are enabled to regulate protocol field abnormalities, method misuse, and illegal jumps. In the application layer, defense components further analyze URL paths, parameter structures, form data, and Cookie contents, and perform logical verification, syntax detection, and token consistency checks to capture parameter poisoning, code injection, or logic deception attacks. In the context layer, behavior consistency verification and context reconstruction are performed based on historical session traces, user identity, permission models, and time behavior graphs to identify fake identities, bypass authorization, or permission drifts. The processing results of each layer are recorded by the intermediate processor before entering the next layer and generate intermediate security evaluation labels for subsequent decision reference, ensuring that the information flow between layers has complete context association. After all defense layers have completed processing, the multi-level security protection results are aggregated based on the detection results and policy adaptation of each component in the entire defense execution chain. The results are represented in the form of a structured security state vector, containing the risk level detected by each layer, component output label, interception suggestion, and operation log. After that, the system enters the differentiated processing stage, and the defense execution engine matches the differential response strategy based on these results: if there is a high-confidence threat identification in a certain layer, it executes direct blocking, redirection, or connection closing instructions; if there is a medium-level risk that needs to be confirmed, the system triggers challenge mechanisms such as CAPTCHA verification, behavior recognition, and secondary verification; if there is only a low-confidence suspicious behavior, it applies response delay, speed limit, or fuzzy response for gentle protection operations; for requests determined to be safe, it is directly released with behavior labels for continuous monitoring.Based on the matched differentiated response mode, corresponding web request processing instructions are generated, which are sent to the system resource scheduling module for execution control, and the execution state, response action, processing result, performance index and judgment logic of each defense component in the entire defense process are recorded as defense process data by the defense execution engine, which is written into the defense log system for subsequent tracing, auditing, model optimization and strategy iteration. The web request processing result is returned to the upper layer process as the final output, which includes information such as whether the request is released, modified or blocked, and also includes defense effect explanation and component call track.

[0040] In the embodiment of the application, the dual-path parallel processing of the neural network path and the symbolic reasoning path is realized by the neural-symbol hybrid analysis module. On the one hand, the neural network is used to capture deep nonlinear features, and on the other hand, the symbolic reasoning is used to retain the interpretability of logical judgment, effectively solving the limitations of single technology route, so that the defense system can cope with known mode attacks and unknown variant attacks at the same time. An adaptive weight fusion mechanism is used to realize the effective integration of the neural network feature vector and the symbolic reasoning result. Through a context-sensitive weight distribution strategy, the system can dynamically adjust the weight proportion of the two paths according to the request characteristics, improving the richness and accuracy of feature representation. By constructing an abstract syntax tree structure of HTTP requests and applying a graph attention network to analyze the semantic association between parameters, the system can understand the implicit dependencies between parameters, effectively identifying and defending against logical vulnerability attacks that traditional systems cannot detect. Two interactive enhanced recurrent neural networks, content analysis layer and timing behavior layer, are designed. Through a cross-modal attention mechanism, the content features and behavior features are closely related, significantly improving the system's detection ability for complex attacks based on abnormal behavior sequences. Different defense function modules are modularized into professional agents, and a sparse communication protocol is introduced to realize efficient information sharing between agents. The system can automatically build the optimal defense chain according to the application business logic and threat characteristics, breaking through the limitations of traditional static rule combination. A hierarchical defense mechanism is adopted at the network layer, protocol layer, application layer and context layer, combined with a differentiated processing strategy. The system can take corresponding defense measures for requests of different risk levels, minimizing the impact on normal business while ensuring security.

[0041] In a specific embodiment, the process of performing step S101 can specifically include the following steps:

[0042] The non-blocking I / O interception unit is set between the Web server and the application program to capture the Web application HTTP request;

[0043] The Web application HTTP request is processed by request header standardization, URL decoding and parameter extraction to obtain structured HTTP request information;

[0044] The structured HTTP request information is matched with syntax rules to obtain parameter types, value ranges and mutual dependency relationships of the HTTP request of the Web application;

[0045] An abstract syntax tree is generated based on the parameter types, value ranges and mutual dependency relationships to obtain request feature data.

[0046] Specifically, a set of non-blocking request monitoring and analysis channels with high throughput, low delay and strong compatibility is constructed, in which a non-blocking I / O interception unit is deployed as a key component in the transmission link between the Web server and the application logic processing layer, and an asynchronous network framework (such as epoll, kqueue or IOCP) based on event polling mechanism is used to realize real-time monitoring and interception of data packets transmitted through the layer. In this process, to ensure system stability and performance, the interception unit manages multiple client connections through connection multiplexing mechanism, copies the request raw data stream to the internal buffer without occupying the main thread, and judges the HTTP request status through protocol analysis to ensure the request format legality and integrity, and then transmits the payload part into the preprocessing process. The request header standardization operation is performed to format the original request, which may have encoding ambiguity, field redundancy, header out-of-order, etc. The standardization processing realizes the unified field label, case normalization, redundancy removal and merging, etc. through the establishment of a standardized mapping table for the request method, path, protocol version, Content-Type, User-Agent, Cookie, Authorization and other key fields, and converts the highly variable request header into a unified semantic template for subsequent rule matching. After completing the request header standardization, the URL is processed through multi-level decoding, which includes URL encoding (percent encoding) restoration, as well as recursive decoding of Base64 encoding, Unicode obfuscation encoding and escape characters contained in the request path and parameters to avoid the situation where attackers bypass filters through multiple encoding. The decoded URL information is divided into path segments, query strings and parameter domains, and is sent to the parameter extraction module while maintaining the hierarchical structure. In the parameter extraction module, the segmented parser is used to extract the query parameters, request body (POST / PUT form), path variables (RESTful style) and implicit parameters that may exist in the header, and the data format is judged according to the request method and Content-Type type, such as form key-value pairs, JSON structure, XML document or multi-part upload body, etc. to establish a complete parameter dictionary table. The dictionary table records the name, position (URL, Header, Body), initial value, data structure (basic type or composite structure) and frequency of each parameter, and constructs a parameter dependency chain for subsequent syntax matching and semantic modeling. After completing the structured HTTP request information construction system, it enters the syntax rule matching stage, which relies on a pre-defined Web request syntax rule library composed of manually defined rules and automatically generated semantic patterns. The internal combination of context-free grammar and finite state automaton is used to perform semantic recognition and logical mapping on the request structure.According to the parameter position and type, the corresponding rule branch is called, the type of the value of each parameter is parsed, it is judged whether it conforms to the basic semantic categories such as string, number, boolean, array, object or date, and then the value range is judged through regular constraints, value distribution model and context relationship. At the same time, the semantic dependency modeling of the combination relationship between parameters is carried out, for example, whether the valid value of a parameter depends on the state of another parameter, or whether a combination action is formed between multiple parameters, such as “page” and “size” in the paging parameter or “role” and “resource” in the permission control. In this process, a parameter dependency graph is constructed, which takes parameters as nodes and dependency, containment or constraint relationships as edges, forming an intermediate semantic expression structure for the semantic analysis engine to process. Based on the parameter type, value range and mutual dependency relationship, an abstract syntax tree is generated, and a bottom-up syntax tree construction algorithm is used in this stage to organize all parameters and their semantic attributes in the form of nodes, and to recursively establish parent-child node relationships according to the request path, parameter position and structural nesting level. For request structures with high complexity of dependency relationship, a graph attention network enhancement module is introduced during AST generation, which calculates the semantic similarity weight between nodes to supplement the cross semantic dependency that the tree structure cannot capture, so that the finally generated AST not only represents the hierarchical nesting between parameters, but also encodes attack features such as semantic deviation, value range anomaly and logical coupling, thereby providing structured and information complete request feature data representation for subsequent deep neural network models or symbolic reasoning systems. The finally output AST structure is stored as part of the request context object in the middleware data pool for real-time calling and dynamic updating by the subsequent feature extraction, risk analysis and decision modeling modules of the protection engine.

[0047] In a specific embodiment, the process of performing step S102 can specifically include the following steps:

[0048] The request feature data is distributed through the neural-symbol hybrid analysis module to obtain first input data for neural network analysis and second input data for symbolic reasoning;

[0049] The first input data is analyzed for parameter structure relationship through a three-layer graph convolutional neural network to obtain a Web request deep feature vector;

[0050] The second input data is matched for rules through a rule reasoning engine based on first-order predicate logic to obtain a symbolic reasoning result containing security judgment information;

[0051] The Web request deep feature vector and the symbolic reasoning result containing security judgment information are input into the semantic bridging layer for adaptive weight fusion to obtain a Web request threat feature set.

[0052] Specifically, the abstract syntax tree (AST) and parameter semantic graph constructed by the pre-module are transmitted into the neural-symbol hybrid analysis module after being uniformly encoded with the structure, semantic attributes and parameter dependency of HTTP requests. This module is a feature distribution core module with information reconstruction, structure redistribution and semantic shunt capabilities. Its main responsibility is to identify the information content in the request feature data that is suitable for high-dimensional modeling through neural networks and the constraint information that is suitable for explicit judgment through logical rules, and to convert them into structured first input data and second input data, respectively. This module adopts a learnable channel separator structure, which reorganizes the nodes in the AST through a similarity measurement mechanism and a domain template guided model, encodes and labels the nodes according to parameter semantic complexity, nesting depth and context dependency level, and outputs the nodes and structural information with high-dimensional, nonlinear relationships as graph structure input for the first input data of neural network analysis. The parts with definable rules, clear logical structure, explicit Boolean constraints or covered by security rules are output as symbolic input data to the rule reasoning path, forming the second input data for symbolic system processing. The first input data is passed into a three-layer graph convolutional neural network (GCN) structure for parameter structure relationship analysis. The GCN model takes the request parameter graph as input, where each node represents a parameter, and the node feature vector is composed of parameter name, type, value statistical features, position index and semantic label encoding. The edges represent the semantic dependency, data transmission, action order or flow nesting between parameters. In the first layer of GCN, the system completes the basic adjacency propagation operation, and the information between nodes is preliminarily fused according to the normalized adjacency matrix. The second layer maps the aggregated node features in the feature space to enhance the expression ability of the nonlinear interaction between parameters. The third layer enhances the stability and context consistency of feature representation by introducing residual connection and normalization mechanism. In the entire GCN calculation process, the ReLU activation function and dropout mechanism are used to avoid overfitting problems, and the node features are output to the intermediate feature fusion channel after each layer. Through pooling operation and full connection mapping, the entire graph structure is converted into a fixed-dimensional Web request deep feature vector, which contains the hierarchical relationship of parameter structure and also integrates the parameter semantic propagation path and overall structure features, with the ability of abstract representation for downstream model modeling and decision analysis. At the same time, the second input data enters the symbolic reasoning path, where a rule reasoning engine based on first-order predicate logic is used to match and reason the input data with security rules. The rule engine contains a rule base and a reasoning mechanism, where each rule in the rule base is represented in a formal structure, including premise conditions and entailment relationships.The reasoning mechanism adopts a forward chaining method, which parses each parameter and its attribute in the second input data as a fact expression after receiving the second input data, and matches it with the rule base one by one. If the matching is successful, a new judgment conclusion is derived. These conclusions are structured as symbolic reasoning results, and are attached with rich semantic tags such as confidence level, trigger rule number, affected field, attack type, etc., forming a reasoning output result set with causal logic traceability. In order to integrate the deep vector representation extracted by the neural network path and the structured logical conclusion output by the symbolic reasoning path, a semantic bridging layer is introduced for adaptive fusion. The layer is composed of three parts: feature compressor, semantic aligner and weighted fusioner. First, the sparse auto-encoding compression is performed on the deep feature vector of the Web request output by the GCN, and the feature dimension is mapped from the original space to the intermediate semantic representation space using the encoding-decoding structure, and the redundant dimensions are eliminated. Then, the symbolic reasoning results are converted into vector form through knowledge distillation technology, so that the symbolic reasoning logic structure and the neural network output are aligned in the same vector space. The relevance weight between the two is calculated through the multi-head attention mechanism, and the fusion ratio of neural features and symbolic information is automatically adjusted according to the request structure complexity and semantic ambiguity. Finally, the feature fusion is performed through the gating mechanism and the residual connection. The fused output features are uniformly encoded into the Web request threat feature set.

[0053] In a specific embodiment, the process of performing step S103 can specifically include the following steps:

[0054] The Web request threat feature set is compared with the attack feature templates in the preset attack pattern library to obtain multiple sets of attack type similarity scores.

[0055] According to the multiple sets of attack type similarity scores, multi-class discriminant analysis is performed by a threat classifier to obtain a threat type determination result of the Web application HTTP request.

[0056] The Web request threat feature set is subjected to semantic hierarchical analysis and target extraction to obtain an attack target recognition result.

[0057] The threat type determination result and the attack target recognition result are combined for intent association analysis to obtain attack intent information.

[0058] Specifically, the Web request threat feature set is compared with the attack feature templates in the preset attack pattern library. The attack pattern library is constructed by combining manual annotation and automatic learning, and contains feature templates of various attack types (such as SQL injection, XSS, CSRF, command execution, privilege bypass, logic deception, directory traversal, etc.). Each template is represented in the form of a structured attack vector, which combines attack behavior patterns, parameter feature layouts, behavior sequence paths, commonly used attack instruction structures, semantic offset points, and risk context labels, and is stored in a vector database in a standard dimension embedding manner. In the similarity calculation stage, the Web request threat feature set and the attack templates are dimensionally aligned and vector normalized to ensure that all features fall within a unified dimensional space. Then, cosine similarity, Euclidean distance, and KL divergence are used to calculate the similarity scores between the input vector and each attack template. An attention weighting mechanism is introduced to adjust the matching degree of different dimensions, so that the model can adaptively increase the weight of certain feature dimensions (such as path structure, parameter semantics, and context behavior) according to the structural features of the current request, avoiding false matches or ignoring important features caused by fixed weights. The similarity calculation results are output in matrix form, with each row representing the matching results of a request and an attack type template, and each column representing the similarity scores of specific feature dimensions under the attack type. After aggregation, multiple sets of attack type similarity scores are formed. The multiple sets of attack type similarity scores are input into the threat classifier for multiclass discrimination analysis. The classifier uses a multiclass cross-entropy loss optimization model based on Softmax output, and combines residual connection and multi-scale perception mechanism in the model architecture, so that the response to similarity input not only considers the matching degree of a single attack type, but also introduces cross interference correction between adjacent attack types, thereby improving the discrimination accuracy of the model for multi-label attacks, mixed attacks, and variant attacks. In the classifier training stage, positive and negative samples in the attack template library are used for supervised training, and in the inference stage, the similarity scores of each input are scored comprehensively, and the threat type judgment result of the Web request is output, including the attack type name (such as SQL injection), the matching confidence score, the closest attack template number, and the identification path information, which provides clear attack category judgment for downstream inference modules. After completing the type determination, semantic hierarchical analysis and attack target extraction are performed on the Web request threat feature set to construct the attack target model of the request. In the semantic hierarchical analysis stage, the Transformer structure is used as the basis, and the mapping relationship of the request in the structure, semantics, and context dimensions is analyzed through multiple layers of attention mapping mechanism, to capture the resource objects, logic interfaces, data table structures, authentication channels, or sensitive variables pointed to by the request, and to structure the targets through semantic projection mechanism.An attack target object table is established based on the analysis results, which contains information such as target type (data field, control instruction, resource interface), target scope (local / cross-domain), target sensitivity level, and behavior action (reading, writing, modifying, deleting). The threat type determination result and the attack target identification result are analyzed for intention association. The analysis module uses a graph neural network enhanced intention graph reasoning mechanism to embed the ternary relationship graph of "attack type-parameter target-execution action" into the attack intention space for path inference. The core intention of the attacker is identified through the upper and lower reasoning rules and relationship path learning mechanism in the knowledge graph. For example, when the attack type is command injection and the target is a system execution interface, the reasoning result derived from the intention path is "remote code execution". If the attack type is logical deception and the target is an authentication path, the system can identify the attack intention as "identity spoofing or session hijacking". The intention association analysis outputs the final attack intention information, including attack target object, attack type label, intention category (control system / data acquisition / bypass permission / process disruption), trust score, and path explanation vector.

[0059] In a specific embodiment, the process of performing step S104 can specifically include the following steps:

[0060] Correlate the request feature data with the user session data in the historical request record library to obtain a Web request time sequence;

[0061] Perform time decay processing and behavior feature extraction on the Web request time sequence to obtain a time sequence feature vector reflecting the user behavior pattern;

[0062] Input the time sequence feature vector into the content analysis layer and the time sequence behavior layer in the double-layer recurrent neural network for parallel processing to obtain content feature representation and behavior feature representation;

[0063] Perform cross-modal attention feature fusion based on the content feature representation and the behavior feature representation to obtain a Web behavior anomaly index.

[0064] Specifically, a request record library containing a large number of historical user access trajectories is constructed, which is indexed by user session dimensions, each session containing complete HTTP request sequence, behavior timestamp, identity token, request content digest, parameter change trajectory, page jump path, source information and environmental attributes (such as IP address, browser fingerprint, device model, etc.), and a data structure supporting high-concurrency associated access is constructed through multi-dimensional hash index. Once the current request enters the system, it will go through a unified identity recognition mechanism, combined with session ID, cookie information, user token or feature similarity matching method, to retrieve the associated session trajectory in the historical record library, and to concatenate the historical requests and the current request in the session in chronological order to generate a Web request timing sequence, which retains the behavior trajectory and context environmental features of the current user within a specific time window. The Web request timing sequence is subjected to time decay processing and behavior feature extraction. The purpose of time decay processing is to adjust the influence weight of each request according to its distance from the current time point, so that the request behavior closer to the current time occupies a larger proportion in the overall behavior modeling. This processing assigns a time weight value to each historical request using an exponential decay function or a Gaussian weight function with threshold truncation, and uses this time weight as an additional vector dimension to concatenate with the behavior data. The behavior feature extraction module performs semantic encoding operations on the structured fields in each request sequence, including request method, path structure, parameter pattern, operation type, action intent, etc., and generates a multi-dimensional behavior vector combining access order, page jump pattern and parameter change frequency. In the processing, the mutation features existing in the session are captured, such as high-frequency operation, path re-entry, short-period repeated request, cross-domain jump behavior, identity switching or parameter structure mutation, etc., which are embedded into the feature tensor to enhance the sensitivity of the model to attack-type behavior. The entire Web request timing sequence is uniformly encoded into a timing feature vector under the joint action of time decay weight and behavior label encoding, which takes time as the step, maintains the time sequence in structure, and presents the behavior evolution trend in semantics, and serves as the input of the deep analysis model. The timing feature vector is input into a double-layer recurrent neural network architecture in parallel, which is composed of a content analysis layer and a timing behavior layer, both of which are independent in structure and complementary in semantics. The content analysis layer uses a bidirectional gated recurrent unit for modeling, which scans the input from both ends simultaneously, can capture the context semantic relationship between requests, and enhances the long-term dependence modeling capability through residual connection and layer normalization mechanism, outputs the context content vector representation at each time node, and expresses the relevance between the current request and the historical request in structure, semantics and operation logic.The time sequence behavior layer adopts a three-layer stacked long short-term memory network, and a time decay factor is introduced in the core structure to adjust the response strength to historical behavior. Through joint modeling of the hidden state before and after and the time offset, this layer has stronger response capability to behavior frequency, behavior mutation, and short-term anomaly, and is suitable for identifying typical behavior attack patterns such as interface brushing, session hijacking, directional probing, and parameter drift. The double-layer structure outputs a set of content feature representations and a set of behavior feature representations after parallel operation, respectively encoding the semantic evolution trajectory of the Web request and the user behavior change curve. In order to effectively fuse the two types of information and improve the accuracy of abnormal behavior identification, a cross-modal attention fusion mechanism is introduced to establish a correlation channel between the content feature representation and the behavior feature representation. This mechanism constructs a query-key-value attention mapping model, takes the content representation as the query vector, and maps the behavior representation as the key and value vectors. In each behavior segment corresponding to the time window, the content attention degree is dynamically adjusted to identify semantic change segments that are strongly related to behavior mutation. At the same time, the reverse channel aligns the behavior attention to the content change interval, so that the behavior model can identify behavior mutations related to semantic breaks. The fusion process uses a bidirectional attention matrix as an intermediary, outputs a unified fusion vector sequence through weighted splicing and gate update strategy, and finally generates a comprehensive index vector representing the degree of Web behavior anomaly through pooling and full connection mapping. The Web behavior anomaly index is used as the real-time behavior state output of the system, which is used to drive the downstream threat identification model, abnormal response module or defense strategy scheduler, and forms a complete context-aware protection foundation with other attack judgment results and intent recognition information.

[0065] In a specific embodiment, the process of performing step S105 can specifically include the following steps:

[0066] The threat type judgment result, attack intent information and Web behavior anomaly index are distributed to the attack identification agent, behavior analysis agent, business logic agent, security policy agent and resource scheduling agent in the multi-agent collaborative decision system through the feature distribution gateway for parallel processing to obtain professional domain evaluation results of each agent;

[0067] Based on the information exchange mechanism between agents based on the sparse communication protocol, the professional domain evaluation results of each agent are shared to obtain a collaborative state matrix;

[0068] Based on the collaborative state matrix, a joint strategy is generated to obtain multiple candidate defense schemes and their execution feasibility scores;

[0069] An optimal decision is selected for the multiple candidate defense schemes and their execution feasibility scores to obtain a defense decision scheme.

[0070] Specifically, a feature distribution gateway with high-dimensional security context decomposition capability is constructed. After receiving the threat type judgment results, attack intention information, and Web behavior anomaly indicators generated by the front-end identification module, the gateway performs semantic separation and vector reconstruction on the three types of security features through a set of distribution strategies based on semantic templates and agent function mapping. The distribution gateway will accurately route the reconstructed feature combinations to five types of agents according to the label weight of the input features, attack scene attributes, context coupling degree, and behavior frequency: the attack recognition agent receives the structural labels and matching template paths mainly related to attack types, the behavior analysis agent processes the time series feature vectors centered on behavior deviation, mutation frequency, and session trajectory, the business logic agent focuses on the business resources, operation paths, and control states involved in attack intentions, the security policy agent receives the integrated judgment results for response strategy matching, and the resource scheduling agent combines all input comprehensive risk parameters with the current system load state for resource execution pressure evaluation. This feature distribution process realizes efficient shunting of input features by responsibility domain and ensures that each agent can obtain the most compact structure, most relevant semantics, and most controllable cost domain input in the parallel processing stage. After receiving the input features in their professional domains, each agent executes security judgment and strategy estimation analysis in the strategy reasoning model deployed in its internal. The attack recognition agent discriminates and enhances the attack type labels and their similarity confidence based on deep perception network, constructs a risk propagation graph based on historical attack topology and pattern variation rules, and generates an attack recognition evaluation vector; the behavior analysis agent runs a behavior change prediction module with a memory mechanism in its constructed time series deviation network, compares the behavior rhythm with historical patterns, and outputs a behavior analysis evaluation vector composed of behavior anomaly level, change rate, and behavior risk score; the business logic agent calls the flow dependency model of the graph constraint rule verification engine to determine whether there is inconsistency or illegal invocation path between the semantic label of the attack target and the current business state graph, and outputs a business logic evaluation vector composed of logic deviation level, flow deviation trajectory, and interface sensitivity label; the security policy agent uses a knowledge retrieval mechanism based on a strategy graph to retrieve multiple matching schemes from the strategy library, selects the strategy priority score, applicable range score, and combinability index through strategy coverage analysis and conflict detection to form a security policy evaluation vector; the resource scheduling agent uses a resource dynamic mapping network based on a reinforcement learning optimizer to output a resource scheduling evaluation vector composed of resource cost score, resource load impact prediction, and resource time delay tolerance threshold by combining the current defense pressure, system throughput, and resource saturation.When the five agents each output the domain evaluation results, the system enters the inter-agent state sharing phase based on the sparse communication protocol. The protocol mechanism builds an efficient interaction mechanism that activates cross-agent state broadcasting only when key risk information reaches a certain propagation threshold, avoiding the communication load and response delay caused by redundant broadcasting of full information. The system identifies which evaluation vectors contain high-risk trigger factors (such as attack propagation risk level exceeding 90%, continuous increase in behavior mutation rate, business control path boundary crossing, policy strong intervention level exceeding standard, or uncontrollable resource cost) through a threshold determinator, then builds sub-channels to broadcast only the core summary values of the corresponding vectors to other agents, forming collaborative state sub-segments. Each sub-segment is integrated into a collaborative state matrix in the aggregator, which records the security context evaluation results of each agent for the current request and the cross-influence factors of risk linkage between them, forming a global collaborative perception space that can be called by the unified strategy generation engine. Joint strategy generation is based on the collaborative state matrix. This phase is completed by the strategy generator, which includes a graph embedding driven strategy combination network and a strategy feasibility optimization module based on gradient evaluation. The strategy generator maps the collaborative state matrix into a graph structure, taking each type of agent evaluation dimension as a node and the strategy coupling relationship between each type of index as an edge to build a strategy combination graph. Then, through a graph neural network, the node state is encoded with strategy weights to generate multiple possible defense strategy path combinations, such as attack interception + behavior throttling, interface rewriting + dynamic verification, business segmentation + resource isolation, etc. These combinations are labeled as candidate defense schemes. The strategy feasibility scorer is called to predict the security effect and model the resource cost of the candidate schemes. The security effect scorer analyzes the strategy coverage range and maps historical scenarios based on the strategy path and attack influence domain, predicting the defense success rate, false interception probability, and execution response time. The resource cost evaluation module simulates the deployment feasibility of each scheme in the actual running environment by combining the current resource usage and the unit cost of each strategy execution, resulting in a feasibility scoring matrix composed of multiple indicators such as system load, component response delay, and user experience impact. The candidate defense schemes are finally one-to-one corresponding to their execution feasibility scores, forming an evaluation output set for the final decision engine. The optimal decision module uses a multi-objective weighted function selection algorithm to weigh and score all candidate defense schemes based on the security benefit function, system resource loss function, and execution cost function, and selects the optimal defense decision scheme in the current scenario based on the principle of global minimum cost and maximum benefit. This scheme includes the specific execution components of the stress strategy, trigger conditions, response mechanisms, and strategy combination chain, and encapsulates the strategy execution path, expected effect prediction, resource scheduling suggestion, and dynamic adjustment flag.

[0071] In a specific embodiment, the execution step distributes the threat type determination result, the attack intention information and the Web behavior abnormality index to the attack recognition agent, the behavior analysis agent, the business logic agent, the security policy agent and the resource scheduling agent in the multi-agent collaborative decision system through the feature distribution gateway for parallel processing, and the process of obtaining the professional domain evaluation results of each agent can specifically include the following steps:

[0072] Distributing the threat type determination result, the attack intention information and the Web behavior abnormality index to the multi-agent collaborative decision system through the feature distribution gateway;

[0073] Inputting the threat type determination result into the first feature space of the attack recognition agent, verifying the vulnerability type and analyzing the attack influence range through the three-layer perception network in the attack recognition agent, and obtaining the attack recognition evaluation result;

[0074] Inputting the Web behavior abnormality index into the second feature space of the behavior analysis agent, identifying the deviation mode and quantifying the abnormality degree through the long short-term memory network of the attack recognition agent, and obtaining the behavior analysis evaluation result;

[0075] Inputting the attack intention information into the third feature space of the business logic agent, performing business process compliance checking and sensitive operation identification through the rule verification network in the business logic agent, and obtaining the business logic evaluation result;

[0076] Inputting the threat type determination result, the attack intention information and the Web behavior abnormality index into the fourth feature space of the security policy agent, performing defense strategy screening through the strategy matching engine, and obtaining the security policy evaluation result;

[0077] Inputting the threat type determination result, the attack intention information and the Web behavior abnormality index into the fifth feature space of the resource scheduling agent, performing execution cost calculation through the resource optimization algorithm, and obtaining the resource scheduling evaluation result;

[0078] Taking the attack recognition evaluation result, the behavior analysis evaluation result, the business logic evaluation result, the security policy evaluation result and the resource scheduling evaluation result as the professional domain evaluation results of each agent.

[0079] Specifically, a feature distribution gateway with security semantic understanding and responsibility domain mapping capabilities is established. The gateway serves as a bridge between the identification layer and the decision layer, receiving three types of high-dimensional, structured threat feature information: threat type judgment results, attack intent information, and Web behavior anomaly indicators. The semantic separation model is used to disassemble and map these information to multiple independent feature subspaces as needed. The distribution process combines the mapping rules between feature attributes, priority identifiers, and agent function models to ensure that each type of information is routed to the input channels of each agent in the most matching way, thereby achieving the basic conditions for parallel computing and distributed discrimination. After successful feature distribution, the threat type judgment results are input into the first feature space of the attack recognition agent. A three-layer perception network structure is deployed within the agent to perform attack type re-verification, pattern variation reconstruction, and impact area expansion analysis. The first layer of the perception network performs semantic matching and confidence correction on the input threat type label vector to prevent mislabeling or label conflicts in the early stage of judgment. The second layer introduces an attack style embedding mapping mechanism to compare and learn the input threat type with various variation structures in the historical attack graph, identifying potential disguised attacks or multiple combination attack patterns. The third layer uses an attack target impact range modeling algorithm to evaluate the business modules, parameter structures, and system components that may be affected by the current attack type, outputting attack recognition evaluation results including attack confirmation labels, impact levels, propagation paths, and abnormal confidence. Meanwhile, the Web behavior anomaly indicators are input into the second feature space of the behavior analysis agent. The agent relies on a long short-term memory (LSTM) network to build a behavior evolution modeling framework, which establishes a time window through the input behavior tensor sequence to identify rhythm changes, repeated paths, request mutations, and time distribution features in user operation trajectories. The LSTM uses a time step perception mechanism to capture abnormal patterns such as short-cycle high-frequency requests, cross-functional jumps, and pseudo-continuous access. It also uses an attention mechanism to identify key behavior nodes, quantify deviation and risk levels, and output behavior analysis evaluation results such as behavior fluctuation curves, risk level scores, behavior trigger factors, and abnormal trend paths. These results are used to determine the behavior intent behind the request and whether it has automated or probing characteristics. For attack intent information, it is input into the third feature space of the business logic agent, which uses a rule verification network to perform process compliance checks and sensitive interface identification. The network combines pre-set business operation graphs, interface call graphs, and parameter dependency graphs to build a process state machine. It judges whether the current attack intent breaks the boundaries of the pre-set business by matching paths and comparing permission levels. It also performs sensitivity determination on target fields and key operations (such as modifying permissions, transfer requests, logout calls, etc.) contained in the intent to identify whether controlled resource access is triggered. Finally, it outputs business logic evaluation results including process legality labels, unauthorized risk labels, operation criticality scores, and path deviation amounts, indicating whether the current attack seriously threatens the integrity or execution order of the business.The three types of features are simultaneously input into the fourth feature space of the security policy intelligent agent, in which the intelligent agent performs policy candidate screening and response path planning through a policy matching engine. The policy matching engine is internally composed of a policy atlas, a response rule library, and a policy cost model, and can generate multiple policy response path combinations according to the threat type, attack intention, and behavior intensity, such as policy A (interception + isolation), policy B (speed limit + human-computer identification), policy C (parameter rewriting + verification insertion), etc. Each policy combination calculates its fitness to the current scene through a scoring function, and outputs a security policy evaluation result including the response policy number, policy matching score, implementation priority, and policy chain topology graph. At the same time, the same set of three types of features is input into the fifth feature space of the resource scheduling intelligent agent, which performs defense scheme resource cost analysis based on a resource optimization algorithm. The algorithm models the current system resource state, schedulable components, processing delay boundary, etc., to construct a resource constraint space, and then combines the resource consumption curve of each policy execution path in this space to calculate the execution time, concurrent tolerance, and system carrying capacity score of each defense policy in the current environment, and outputs a resource scheduling evaluation result including resource consumption value, response load prediction, system stability score, and resource allocation suggestion. The attack recognition evaluation result, behavior analysis evaluation result, business logic evaluation result, security policy evaluation result, and resource scheduling evaluation result are combined to form a multi-agent professional domain evaluation result set, which is stored in a structured form to construct a multi-agent state matrix.

[0080] In a specific embodiment, the execution step is based on the cooperative state matrix to generate joint strategies, and the process of obtaining a plurality of candidate defense schemes and their execution feasibility scores can specifically include the following steps:

[0081] According to the attack recognition intelligent agent, the behavior analysis intelligent agent, the business logic intelligent agent, the security policy intelligent agent, and the resource scheduling intelligent agent, the cooperative state matrix is divided into professional domain state sub-matrices of each intelligent agent;

[0082] The professional domain state sub-matrix of each intelligent agent is input into the corresponding intelligent agent's deep policy network for action value evaluation to obtain an attack interception action set, a behavior restriction action set, a business rule action set, a security policy action set, and a resource allocation action set;

[0083] The attack interception action set, the behavior restriction action set, the business rule action set, the security policy action set, and the resource allocation action set are combined and optimized by an action coordinator to obtain a plurality of candidate defense schemes;

[0084] Based on the plurality of candidate defense schemes, safety effect prediction and system load evaluation are performed to obtain an execution feasibility score corresponding to each candidate defense scheme.

[0085] Specifically, the collaborative state matrix is divided into professional domains according to the attack recognition agent, the behavior analysis agent, the business logic agent, the security policy agent and the resource scheduling agent, to obtain the professional domain state sub-matrix of each agent. The internal dimensions of these sub-matrices are strongly related to the corresponding agent tasks, such as attack propagation radius, vulnerability exploitation path score, historical attack matching degree, etc. in the attack recognition sub-matrix; behavior deviation coefficient, rhythm fluctuation index, session trajectory tension, etc. in the behavior analysis sub-matrix; operation process deviation, call path compliance score, interface risk identification, etc. in the business logic sub-matrix; policy adaptability score, policy priority distribution, historical policy effect feedback, etc. in the security policy sub-matrix; resource occupancy rate, response time delay estimation, component concurrency tolerance, etc. in the resource scheduling sub-matrix. Each sub-matrix maintains the same time step and spatial layout structure as the global state matrix, ensuring consistency and context coherence in subsequent model processing. The professional domain state sub-matrix of each agent is input into the corresponding agent's deep policy network for action value evaluation. Each agent's policy network uses a neural architecture customized for the task characteristics. The policy network of the attack recognition agent is a multi-channel perception fusion network, which consists of a convolutional feature extractor and a risk value regression module. It can extract high-order correlation features from different attack feature channels and output a set of attack interception actions, including blocking connections, jumping through, data injection marking, and their value function scores. The policy network of the behavior analysis agent uses a behavior pattern predictor based on a time-aware gating mechanism. It aggregates and simulates the response of the behavior sequence state, and outputs a set of behavior restriction actions, such as speed limit policy, verification code insertion, dynamic behavior verification, etc. Each behavior suppression method is scored to represent the effect prediction and user experience impact weight. The policy network of the business logic agent is a rule graph state encoder. This model embeds the current business process state and attack intent graph into a unified graph space. Through path matching and control point conflict identification, it outputs a set of business rule actions, such as forced parameter verification, interface jump reconstruction, call order correction, etc. The model also evaluates the business integrity protection score and system acceptability. The policy network of the security policy agent is a policy graph atlas attention model. It globally models the historical policy response effect, current attack state and policy priority path to form a set of policy combination actions, including interception-isolation-verification combination chain, link breakpoint replacement sequence, etc. Each chain is assigned a value score and a trigger condition confidence. The policy network of the resource scheduling agent is a reinforcement learning driven resource optimization function predictor. This model simulates the deployment impact and resource cost of various policy combinations on different components, and outputs a set of resource allocation actions, such as load balancing policy, resource quota adjustment, cache release priority, etc. Each execution is assigned a cost function score and a delay impact score.The five types of action sets are input into a unified action coordinator, which is composed of a policy graph modeling layer, a conflict detection module, and a combination optimization unit. The policy graph modeling layer constructs a policy combination graph by taking each action as a graph node and establishing edges based on the logical sequence in the defense path, data dependency, conflict constraints, and combinable markers. The conflict detection module identifies policy conflicts, behavior conflicts, resource mutual exclusion, and business logic overlap, and deletes or replaces unreasonable combination paths. Conditional edges are injected into the graph to represent execution constraints. The combination optimization unit uses a heuristic search or a policy path sampling method based on reinforcement learning to generate multiple candidate defense schemes in the graph, each of which is a complete policy chain containing attack interception strategies, behavior restriction mechanisms, business rule corrections, security policy responses, and resource scheduling paths. Each scheme has strong linkage, closed structure, and traceable execution path. After generating the candidate defense schemes, the system enters the security effect prediction and system load evaluation stage. The security effect evaluation module simulates the defense capability of each candidate scheme, and the prediction indicators include the predicted attack suppression rate, threat diffusion suppression index, vulnerability trigger probability reduction value, and false interception tolerance. At the same time, the system load evaluation module simulates the resource scheduling trajectory, response delay variation, concurrent processing pressure, and component load impact of each policy path in the current operating environment. The system cost value of each defense path is calculated by the resource consumption model and deployment bottleneck estimation function, and finally an execution feasibility score matrix is formed, including policy chain label, expected revenue score, execution cost score, response delay estimation, and compatibility level.

[0086] In a specific embodiment, the process of performing step S106 can specifically include the following steps:

[0087] The defense decision scheme is input into the defense execution engine for defense component matching and call sequence generation to obtain a defense execution chain containing defense components.

[0088] The defense components in the defense execution chain are sequentially called and processed at the network layer, protocol layer, application layer, and context layer through the hierarchical protection mechanism to obtain a multi-level security protection result.

[0089] According to the multi-level security protection result, the potential threat request is processed differently to obtain a Web request processing instruction.

[0090] Based on the Web request processing instruction, corresponding security protection measures are executed and protection process data is recorded to obtain a Web request processing result.

[0091] Specifically, a defense execution engine with dynamic decision mapping capability is constructed, which serves as the key hub in the AI defense engine system from policy planning to actual landing execution. Its core function is to receive the defense decision scheme generated by the agent system, and to perform structural analysis and component mapping on the scheme, converting it into a defense execution chain that can actually drive the system components to respond cooperatively. The defense execution engine includes a policy analysis module, a component matching module, and a sequence constructor. In the policy analysis module, the policy action items, execution order, priority, and response conditions in the decision scheme are abstractly deconstructed, and the defense capability tags required by each policy action are extracted, such as intrusion blocking, parameter filtering, behavior rate limiting, token verification, logic jumping, and behavior log recording. Then, the component matching module checks the registered defense component capabilities in the system, finds the corresponding component instances from the component capability map, and performs capability verification and combination filtering according to the function tags, calling interfaces, execution environments, and upstream and downstream dependencies of the components. Through the sequence constructor, an invocation sequence containing multiple specific defense component instances is constructed according to the execution logic, dependency path, and control flow specified in the policy, generating a structured defense execution chain. This chain describes the input and output formats, parameter passing logic, and trigger sequence of each component through standardized middleware interfaces, providing a clear operation path for subsequent system linkage. When the defense execution chain is generated, a hierarchical defense mechanism based on hierarchical response structure is started. This mechanism follows the security response principle of "first external, then internal, and layer-by-layer deepening", and divides each component in the execution chain into four levels according to its function dimension, namely network layer, protocol layer, application layer, and context layer, and processes them in turn according to this order.At the network layer, components with access control capabilities are activated, including IP blacklist filters, port controllers, connection rate limiters, traffic pattern recognizers, etc. These components directly act on the network transmission path, preliminarily suppressing and limiting the flow of connections with suspicious sources, abnormal rates, or behavior characteristics matching attack models; At the protocol layer, components with protocol compliance and semantic consistency judgment capabilities are called, such as HTTP request validators, content encoding parsers, Header consistency analyzers, etc. The request format, protocol fields, request methods, and coding specifications are compared one by one, and input traffic with obfuscation, tampering, and fake protocol behavior is removed; Then enter the application layer, the system starts defense components closely coupled with Web business models, such as path access controllers, parameter semantic validators, session validators, Token expiration analyzers, interface permission checkers, etc. These components perform in-depth deconstruction of requests based on business rules and control logic, and perform semantic-level discrimination and directional filtering of malicious parameter insertion, unauthorized calling, logic jumping, and abnormal user agent behavior; Finally, enter the context layer, the system activates components with historical behavior memory and multi-dimensional state monitoring capabilities, such as session state managers, cross-request behavior graph modelers, user historical trajectory comparators, etc. These components combine historical access logs and behavior models to dynamically match and measure the behavior path, frequency characteristics, and state transition logic of the current request, identify complex latent threats such as fake behavior chains, slow attacks, low-frequency probes, and hidden jumps, and implement full-dimensional review of the complete semantics, state, and behavior of the request before execution. After all the components at all levels complete the processing and evaluation of the request, each defense component returns its processing results, including interception status, risk level, processing suggestions, and behavior scores, in a structured intermediate state format to the defense execution engine, which forms a unified multi-level security protection result after aggregation. The system then starts the differentiated request handling module, which makes decisions based on risk level labels, interception confidence scores, behavior intent predictions, policy trigger paths, and resource impact assessments in the protection results. Through the built-in request handling rule tree or dynamic policy table, the module determines the processing method for the current request. If the request is jointly determined by multiple high-risk components to be malicious, the system generates a forced interception instruction to immediately interrupt the request; If the request has some suspicious behavior but has not reached the blocking threshold, a challenge mechanism call instruction is generated, such as returning a verification code, initiating a secondary authentication, jumping to a security verification page, etc.; If the request only triggers low-confidence abnormal behavior components, a speed limit, response fuzzing, behavior tagging, or observation recording instruction is generated; For requests that do not trigger any defense conditions, a direct forwarding instruction is generated. The Web request processing instruction is sent as an execution command to the protection execution module, which calls corresponding system services and defense component instances according to the instruction type to complete the specific handling operation of the request.Meanwhile, the entire request processing procedure, including input and output of each defense component, intermediate processing path, final disposal action, resource consumption index, security decision logic and behavior analysis model response, are all written into the protection log recorder for standardized storage in the form of event structure.

[0092] The above describes the AI protection engine construction method based on a Web application in the embodiments of the application, and the following describes an AI protection engine construction system based on a Web application in the embodiments of the application, please refer to Figure 2 An embodiment of the AI protection engine construction system based on a Web application in the embodiments of the application includes:

[0093] The semantic analysis module 201 is configured to acquire a Web application HTTP request and perform semantic analysis to obtain request feature data;

[0094] The feature extraction module 202 is configured to perform multi-dimensional threat feature extraction on the request feature data to obtain a Web request threat feature set;

[0095] The pattern matching module 203 is configured to perform pattern matching on the Web request threat feature set and a preset attack pattern library to obtain a threat type determination result and attack intention information of the Web application HTTP request;

[0096] The time sequence behavior analysis module 204 is configured to perform time sequence behavior analysis on the request feature data to obtain a Web behavior anomaly index;

[0097] The comprehensive decision module 205 is configured to input the threat type determination result, the attack intention information and the Web behavior anomaly index into a multi-agent collaborative decision system for comprehensive decision to obtain a defense decision scheme;

[0098] The security protection module 206 is configured to select a corresponding defense component for security protection through a defense execution engine according to the defense decision scheme to obtain a Web request processing result.

[0099] Through the cooperation of the above-mentioned components, the dual-path parallel processing of the neural network path and the symbolic reasoning path is realized through the neural symbol hybrid analysis module. On the one hand, the deep nonlinear characteristics are captured by using the neural network, and on the other hand, the logical judgment is retained by using the symbolic reasoning, which effectively solves the limitations of a single technical route, so that the protection system can cope with known mode attacks and unknown variant attacks. The adaptive weight fusion mechanism is adopted to realize the effective integration of the neural network feature vector and the symbolic reasoning result. Through the context-sensitive weight distribution strategy, the system can dynamically adjust the weight proportion of the two paths according to the request characteristics, and improve the richness and accuracy of the feature representation. By constructing the abstract syntax tree structure of the HTTP request and applying the graph attention network to analyze the semantic association relationship between parameters, the system can understand the implicit dependency between parameters, effectively identify and defend against logical vulnerability attacks that are difficult to detect by traditional systems. The content analysis layer and the time sequence behavior layer are designed as two interactive enhanced recurrent neural networks. Through the cross-modal attention mechanism, the content features and behavior features are closely related, which significantly improves the detection ability of the system to complex attacks based on abnormal behavior sequences. The different protection functions are modularized into professional agents, and a sparse communication protocol is introduced to realize efficient information sharing between agents. The system can automatically build the optimal protection chain according to the application business logic and threat characteristics, breaking through the limitations of traditional static rule combination. A layered protection mechanism is adopted at the network layer, protocol layer, application layer and context layer, and combined with a differentiated processing strategy, the system can take corresponding protection measures for requests with different risk levels, minimizing the impact on normal business while ensuring security.

[0100] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, system and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0101] The integrated unit, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application or the whole or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a Web application-based AI protection engine construction device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0102] The above-described embodiments are only used to illustrate the technical solutions of the present application, but not to limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalent replacements; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for building an AI protection engine based on Web applications, characterized in that: include: Obtain web application HTTP requests and perform semantic analysis to obtain request feature data; Performing multi-dimensional threat feature extraction on the request feature data to obtain a Web request threat feature set; Specifically, the method includes: performing dual-path distribution on the request feature data through a neural-symbolic hybrid analysis module to obtain first input data for neural network analysis and second input data for symbolic reasoning; performing parameter structure relationship analysis on the first input data through a three-layer graph convolutional neural network to obtain a deep feature vector of the web request; performing rule matching on the second input data through a rule reasoning engine based on first-order predicate logic to obtain a symbolic reasoning result containing security judgment information; and inputting the deep feature vector of the web request and the symbolic reasoning result containing security judgment information into a semantic bridging layer for adaptive weight fusion to obtain a web request threat feature set. Performing pattern matching on the Web request threat feature set and a preset attack pattern library to obtain a threat type determination result and attack intent information of the Web application HTTP request; Performing time series behavior analysis on the request feature data to obtain Web behavior anomaly indicators; Inputting the threat type determination result, the attack intention information, and the Web behavior anomaly indicator into a multi-agent collaborative decision-making system for comprehensive decision-making to obtain a defense decision-making plan; According to the defense decision plan, the defense execution engine selects the corresponding defense component for security protection to obtain the Web request processing result.

2. The method for constructing an AI protection engine based on Web applications according to claim 1, characterized in that: The method of obtaining the web application HTTP request and performing semantic analysis to obtain request feature data includes: Capture web application HTTP requests through a non-blocking I / O interception unit set between the web server and the application; Performing request header standardization, URL decoding, and parameter extraction processing on the Web application HTTP request to obtain structured HTTP request information; Matching the structured HTTP request information with grammatical rules to obtain parameter types, value ranges, and interdependencies of the Web application HTTP request; An abstract syntax tree is generated based on the parameter types, value ranges, and interdependencies to obtain request feature data.

3. The method for constructing an AI protection engine based on Web applications according to claim 1, characterized in that: The pattern matching of the Web request threat feature set with a preset attack pattern library to obtain the threat type determination result and attack intent information of the Web application HTTP request includes: Calculate similarity between the Web request threat feature set and the attack feature templates in the preset attack pattern library to obtain multiple groups of attack type similarity scores; Performing multi-category discriminant analysis using a threat classifier based on the multiple groups of attack type similarity scores to obtain a threat type determination result of the Web application HTTP request; Performing semantic hierarchical analysis and target extraction on the Web request threat feature set to obtain an attack target identification result; Intention association analysis is performed in combination with the threat type determination result and the attack target identification result to obtain attack intention information.

4. The method for constructing an AI protection engine based on Web applications according to claim 1, characterized in that: The time series behavior analysis of the request feature data to obtain Web behavior anomaly indicators includes: Associating the request feature data with the user session data in the historical request record library to obtain a Web request time series; Performing time decay processing and behavioral feature extraction on the Web request time series to obtain a time series feature vector reflecting the user behavior pattern; Inputting the time series feature vector into the content analysis layer and the time series behavior layer in the two-layer recurrent neural network for parallel processing to obtain content feature representation and behavior feature representation; Cross-modal attention feature fusion is performed based on the content feature representation and the behavior feature representation to obtain a Web behavior anomaly indicator.

5. The method for constructing an AI protection engine based on Web applications according to claim 1, characterized in that: The threat type determination result, the attack intention information, and the Web behavior anomaly indicator are input into a multi-agent collaborative decision-making system for comprehensive decision-making to obtain a defense decision-making plan, including: The threat type determination result, the attack intent information, and the Web behavior anomaly index are distributed to the attack identification agent, behavior analysis agent, business logic agent, security policy agent, and resource scheduling agent in the multi-agent collaborative decision-making system through a feature distribution gateway for parallel processing to obtain the professional domain evaluation results of each agent; Based on the information exchange mechanism between intelligent agents of the sparse communication protocol, the professional domain evaluation results of each intelligent agent are shared to obtain a collaborative state matrix; Based on the collaborative state matrix, a joint strategy is generated to obtain multiple candidate defense solutions and their execution feasibility scores; An optimal decision is selected for the multiple candidate defense solutions and their execution feasibility scores to obtain a defense decision solution.

6. The method for constructing an AI protection engine based on Web applications according to claim 5, characterized in that: The threat type determination result, the attack intent information, and the Web behavior anomaly indicator are distributed to the attack identification agent, the behavior analysis agent, the business logic agent, the security policy agent, and the resource scheduling agent in the multi-agent collaborative decision-making system through a feature distribution gateway for parallel processing to obtain the professional domain evaluation results of each agent, including: Distributing the threat type determination result, the attack intention information, and the Web behavior anomaly indicator to a multi-agent collaborative decision-making system through a feature distribution gateway; The threat type determination result is input into the first feature space of the attack identification agent, and the vulnerability type verification and attack impact surface analysis are performed through the three-layer perception network in the attack identification agent to obtain the attack identification assessment result; Inputting the Web behavior anomaly indicator into the second feature space of the behavior analysis agent, performing deviation pattern recognition and anomaly degree quantification through the long short-term memory network of the attack recognition agent, and obtaining a behavior analysis evaluation result; Inputting the attack intention information into the third feature space of the business logic agent, performing business process compliance check and sensitive operation identification through the rule verification network in the business logic agent, and obtaining a business logic evaluation result; Inputting the threat type determination result, the attack intent information, and the Web behavior anomaly indicator into the fourth feature space of the security policy agent, performing defense policy screening through a policy matching engine, and obtaining a security policy evaluation result; Inputting the threat type determination result, the attack intent information, and the Web behavior anomaly indicator into the fifth feature space of the resource scheduling agent, performing execution cost calculation using a resource optimization algorithm, and obtaining a resource scheduling evaluation result; The attack identification evaluation result, the behavior analysis evaluation result, the business logic evaluation result, the security policy evaluation result and the resource scheduling evaluation result are used as the professional domain evaluation results of each intelligent agent.

7. The method for constructing an AI protection engine based on Web applications according to claim 5, characterized in that: The joint strategy generation based on the collaborative state matrix to obtain multiple candidate defense solutions and their execution feasibility scores includes: Divide the collaborative state matrix into specialized domains according to attack identification agents, behavior analysis agents, business logic agents, security policy agents, and resource scheduling agents, and obtain specialized domain state submatrices for each agent; The professional domain state submatrix of each agent is input into the deep policy network of the corresponding agent to evaluate the action value, and the attack interception action set, behavior restriction action set, business rule action set, security policy action set and resource allocation action set are obtained; Combining and optimizing the attack interception action set, the behavior restriction action set, the business rule action set, the security policy action set, and the resource allocation action set through an action coordinator to obtain multiple candidate defense solutions; Security effect prediction and system load evaluation are performed based on the multiple candidate defense solutions to obtain an execution feasibility score corresponding to each candidate defense solution.

8. The method for constructing an AI protection engine based on Web applications according to claim 1, characterized in that: The method of selecting corresponding defense components for security protection through the defense execution engine according to the defense decision scheme to obtain a Web request processing result includes: Inputting the defense decision plan into the defense execution engine to perform defense component matching and call sequence generation to obtain a defense execution chain including defense components; Through the layered protection mechanism, the defense components in the defense execution chain are called and processed in sequence at the network layer, protocol layer, application layer and context layer to obtain a multi-level security protection result; Performing differentiated processing on potential threat requests based on the multi-level security protection results to obtain Web request processing instructions; Based on the Web request processing instruction, corresponding security protection measures are executed and protection process data is recorded to obtain the Web request processing result.

9. A system for building an AI protection engine based on Web applications, characterized in that: The method for constructing an AI protection engine based on a Web application according to any one of claims 1 to 8 is configured to implement the method, wherein the system for constructing an AI protection engine based on a Web application comprises: Semantic parsing module, used to obtain Web application HTTP requests and perform semantic parsing to obtain request feature data; A feature extraction module is used to extract multi-dimensional threat features from the request feature data to obtain a Web request threat feature set; A pattern matching module is used to perform pattern matching on the Web request threat feature set and a preset attack pattern library to obtain a threat type determination result and attack intent information of the Web application HTTP request; A time series behavior analysis module is used to perform time series behavior analysis on the request feature data to obtain Web behavior anomaly indicators; A comprehensive decision-making module is used to input the threat type determination result, the attack intention information and the Web behavior abnormality indicator into the multi-agent collaborative decision-making system for comprehensive decision-making to obtain a defense decision-making plan; The security protection module is used to select the corresponding defense component for security protection through the defense execution engine according to the defense decision plan to obtain the Web request processing result.

Citation Information

Patent Citations

  • Intelligent Web application protection method based on AI semantics

    CN119030732A

  • Network security management system based on big data

    CN119172150A

  • Artificial intelligence hosted web firewall service system for managing web server security in a multi-cloud environment and method thereof

    KR102726463B1