Intranet Web application identification method, device and equipment based on behavior pattern
By building a multi-level conversation map and using self-attention network and multi-layer perceptron model, the problems of high false alarm rate and high operation and maintenance costs in existing web application recognition technology are solved, and more efficient web application recognition is achieved.
Patent Information
- Application Number
- CN202510501692.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-08-05
AI Technical Summary
Existing web application recognition technology relies on static fingerprint libraries, resulting in high false alarm rates and high operation and maintenance costs, and active detection affects the normal operation of components.
Collect conversation information of web applications, build a multi-level conversation map, use self-attention network and multi-layer perceptron model to identify web applications through adaptive weighted features.
It improves the accuracy of web application identification, reduces the false alarm rate and operation and maintenance costs, and reduces the impact on the normal operation of components.
Smart Images

Figure CN120433968A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, apparatus, device and medium for identifying intranet Web applications based on behavior patterns. Background Art
[0002] With the development of the internet, the complexity of network environments and web applications has gradually increased, leading to a growing demand for web application identification. Most web application identification technologies currently available rely on pre-set static identification rules and active detection based on specific fingerprint libraries. These methods have limitations in practice. First, active detection requires sending specific requests to the target component, which may affect its normal operation. Second, due to the frequent updates of web applications, static fingerprint libraries are prone to becoming outdated or invalid, resulting in high false positive rates, high operational costs, and the need for significant manpower to maintain and update identification rules.
[0003] Therefore, there is an urgent need for an intranet Web application identification method based on behavior patterns to improve the accuracy of Web application identification. Summary of the Invention
[0004] The present application provides a method, apparatus, device, and medium for identifying intranet web applications based on behavior patterns, which are used to improve the accuracy of web application identification.
[0005] In a first aspect, the present application provides a method for identifying intranet web applications based on behavior patterns, the method comprising:
[0006] Collect any session information of a Web application; the session information includes at least one round of interaction between requests and responses;
[0007] Constructing a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first characteristic of a corresponding round of interaction; each middle-level node represents a second characteristic between bottom-level nodes that have a dependency relationship; and the top-level node represents a third characteristic of the entire conversation information; the weight of any edge in the conversation graph is determined based on the characteristics of the connected nodes;
[0008] Determining a graph feature matrix of the conversation graph;
[0009] Inputting the graph feature matrix into a self-attention network to obtain adaptive weighted features of the session information;
[0010] The adaptive weighted features are input into a multilayer perceptron model, and a recognition result of the Web application is output; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
[0011] In a possible implementation manner, the first feature includes a response delay feature and a structural feature of a response data packet corresponding to a round of interaction;
[0012] For any first edge between a bottom-layer node and an intermediate-layer node, the time weight of the first edge is determined based on the response delay characteristics of the bottom-layer node to which the first edge is connected; the size weight of the first edge is determined based on the data size of the response data packet of the bottom-layer node to which the first edge is connected; and the weight of the first edge is determined based on the size weight and the time weight.
[0013] In a possible implementation manner, the second feature includes a response success rate of the intermediate node and / or a request frequency of the intermediate node;
[0014] For any second edge between the middle-layer node and the top-level node, the frequency weight of the second edge is determined based on the request frequency of the middle-layer node connected to the second edge; the success rate weight of the second edge is determined based on the response success rate of the middle-layer node connected to the second edge; and the weight of the second edge is determined based on the success rate weight and / or the frequency weight.
[0015] In a possible implementation, the third feature includes the first response time of the session information and / or the request frequency of the session information.
[0016] In a possible implementation, before determining the graph feature matrix of the conversation graph, the method further includes:
[0017] The weight of any first edge in the conversation graph is exponentially decayed; the exponential decay is determined by the difference between the current time and the interaction time of the underlying node connected to the first edge.
[0018] In a possible implementation, determining the graph feature matrix of the conversation graph includes:
[0019] For any first node in the conversation graph, based on the weight of the edge between the first node and the second node and the features of the second node, obtain the aggregate features between the first node and the second node, thereby forming an aggregate feature matrix between the nodes; the second node is any node in the conversation graph other than the first node;
[0020] A multi-scale convolution kernel is used to perform at least two convolution operations on the aggregated feature matrix to obtain a graph feature matrix of the conversation graph.
[0021] In one possible implementation, the graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, including:
[0022] Mapping the graph feature matrix to generate a query vector Q, a key vector K, and a value vector V for any feature;
[0023] For any feature, the similarity between different features is obtained based on the inner product of the query vector Q of the feature and the key vector K of the feature, and the similarity is normalized by the softmax function to obtain the weight ratio of the feature; the value vector V of the feature is weighted according to the weight ratio to obtain an adaptive weighted feature.
[0024] In a second aspect, the present application provides a Web application identification device, the device comprising:
[0025] A collection module, configured to collect any session information of a Web application; the session information includes at least one round of interaction between requests and responses;
[0026] A construction module is configured to construct a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first feature of a corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes having a dependency relationship; and the top-level node represents a third feature of the entire conversation information; the weight of any edge in the conversation graph is determined based on the features of the connected nodes; and a graph feature matrix of the conversation graph is determined;
[0027] The recognition module is configured to input the graph feature matrix into a self-attention network to obtain adaptive weighted features of the session information; input the adaptive weighted features into a multilayer perceptron model to output recognition results of the Web application; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
[0028] In a possible implementation manner, the first feature includes a response delay feature and a structural feature of a response data packet corresponding to a round of interaction;
[0029] The construction module is specifically used to determine the time weight of any first edge between the bottom-layer node and the middle-layer node according to the response delay characteristics of the bottom-layer node connected to the first edge; determine the size weight of the first edge according to the data size of the response data packet of the bottom-layer node connected to the first edge; and determine the weight of the first edge according to the size weight and the time weight.
[0030] In a possible implementation manner, the second feature includes a response success rate of the intermediate node and / or a request frequency of the intermediate node;
[0031] The construction module is specifically used to determine the frequency weight of any second edge between the middle-layer node and the top-level node according to the request frequency of the middle-layer node connected to the second edge; determine the success rate weight of the second edge according to the response success rate of the middle-layer node connected to the second edge; and determine the weight of the second edge according to the success rate weight and / or the frequency weight.
[0032] In a possible implementation, the third feature includes the first response time of the session information and / or the request frequency of the session information.
[0033] In a possible implementation, the construction module is further configured to perform exponential decay on the weight of any first edge in the conversation graph; the exponential decay is determined by the difference between the current time and the interaction time of the underlying node connected to the first edge.
[0034] In one possible implementation, the construction module is specifically configured to obtain, for any first node in the conversation graph, aggregate features between the first node and the second node based on the weight of the edge between the first node and the second node and the features of the second node, thereby forming an aggregate feature matrix between the nodes; the second node is any node in the conversation graph other than the first node; and convolution operations are performed on the aggregate feature matrix at least twice using a multi-scale convolution kernel to obtain a graph feature matrix of the conversation graph.
[0035] In one possible embodiment, the recognition module is specifically used to map the graph feature matrix to generate a query vector Q, a key vector K, and a value vector V for any feature; for any feature, the similarity between different features is obtained based on the inner product of the query vector Q of the feature and the key vector K of the feature, and the similarity is normalized by a softmax function to obtain the weight ratio of the feature; the value vector V of the feature is weighted according to the weight ratio to obtain an adaptive weighted feature.
[0036] In a third aspect, the present application provides an electronic device, which includes at least a processor and a memory, and the processor is used to implement the steps of any method described in the first aspect when executing a computer program stored in the memory.
[0037] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of any method described in the first aspect.
[0038] In a fifth aspect, the present application provides a computer program product, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the steps of any method described in the first aspect.
[0039] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the implementation methods in the embodiments of the present application or related technologies, the following is a brief introduction to the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0041] Figure 1 A schematic diagram of a Web application identification process provided for some embodiments of the present application;
[0042] Figure 2 A schematic diagram of a conversation graph provided for some embodiments of the present application;
[0043] Figure 3 Another schematic diagram of a Web application identification process provided for some embodiments of the present application;
[0044] Figure 4 A schematic diagram of the structure of a Web application identification device provided in some embodiments of the present application;
[0045] Figure 5A schematic structural diagram of an electronic device provided for some embodiments of the present application. DETAILED DESCRIPTION
[0046] To make the purpose, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described in this application are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0047] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.
[0048] In the specification and claims of this application and the accompanying drawings, the terms "first," "second," "third," etc. are used to distinguish similar or similar objects or entities, and are not necessarily intended to limit a particular order or sequence, unless otherwise noted. It should be understood that the terms used in this manner are interchangeable under appropriate circumstances.
[0049] The terms "comprise," "include," and "have," and any variations thereof, are intended to cover but not exclude inclusion; for example, a product or device comprising a list of components is not necessarily limited to all the components expressly listed but may include other components not expressly listed or inherent to such product or device.
[0050] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functionality associated with that element.
[0051] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
[0052] The following description of exemplary embodiments of the present application is made in conjunction with the accompanying drawings, which include various details of the embodiments of the present application to facilitate understanding, and they should be considered as merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope disclosed in this application. Similarly, for the sake of clarity and conciseness, the description of well-known functions and structures is omitted in the following description. It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned, which should be considered as exemplary, and their purpose is only to illustrate the feasibility of the implementation of the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0053] Before introducing the behavior pattern-based intranet Web application identification method provided by the embodiment of the present application, in order to facilitate understanding, the technical background of the embodiment of the present application is first introduced.
[0054] With the development of the internet, the complexity of network environments and web applications has gradually increased, leading to a growing demand for web application identification. Most web application identification technologies currently available rely on pre-set static identification rules and active detection based on specific fingerprint libraries. These methods have limitations in practice. First, active detection requires sending specific requests to the target component, which may affect its normal operation. Second, due to the frequent updates of web applications, static fingerprint libraries are prone to becoming outdated or invalid, resulting in high false positive rates, high operational costs, and the need for significant manpower to maintain and update identification rules.
[0055] Based on this, the present application provides a method, apparatus, device, medium, and computer program product for identifying intranet web applications based on behavioral patterns. In this method, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a session graph of the session information is constructed, wherein the session graph includes bottom-layer nodes, middle-layer nodes, and top-layer nodes; each bottom-layer node represents a first feature of the corresponding round of interaction; each middle-layer node represents a second feature between bottom-layer nodes with a dependency relationship; and the top-layer node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; a graph feature matrix of the session graph is determined; the graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information; the adaptive weighted features are input into a multilayer perceptron model to output the recognition result of the web application; the multilayer perceptron model is obtained by training session information with different behavioral patterns and corresponding web application types.
[0056] Example 1:
[0057] Figure 1 A schematic diagram of a process for identifying a Web application is provided in some embodiments of the present application. Figure 1 As shown, the process includes the following steps:
[0058] S101: Collect any session information of a Web application; the session information includes at least one round of interaction between requests and responses.
[0059] The behavior pattern-based intranet Web application identification method in the embodiment of the present application is applied to an electronic device, where the electronic device can be a server, a PC or other device.
[0060] A web application refers to an independent web application or middleware that provides web services. To accurately identify a web application, we collect session information for each web application. This session information includes at least one round of request-response interaction. When a user accesses a web application's server, a session is established and ends when one party disconnects. A single session can include multiple rounds of request-response interactions. Session information can include response latency characteristics and response packet structure, as well as response success rate and request frequency.
[0061] For example, for any collected session information of a web application, the session information can be recorded, including timing features, frequency features, and response structure features. Timing features include, but are not limited to, the response delay between requests and responses in each round, the time interval between requests and responses in different rounds, and the first response time. Response delay can be determined based on a request-response time matching algorithm. A hash map is used to record the send time of each request packet. Upon receiving a response packet, the matching request packet is retrieved from the map to calculate the response delay. For sessions with multiple rounds of interaction, the earliest response time is used as the first response time feature, reflecting the startup response speed of the web application. Frequency features can be generated using a sliding time window algorithm to calculate the frequency distribution of requests and responses within a specific time range. Time series data is segmented into fixed time windows, and the number of requests within each window is counted to generate a time series frequency distribution. This effectively captures changes in traffic density over short periods of time and identifies the interaction density and rhythm of web applications. Response structure features can be used with a response structure parser to obtain the data length, hierarchical structure, and data format of each interaction packet.
[0062] In one possible implementation, network traffic can be captured and classified to gather session information. This data is received from a traffic collection system that extracts and restores data. The data is accessed from the switch's mirrored traffic. Each packet contains header information, such as the source IP address of the request, the destination IP address of the response, and information such as the port and protocol. The system uses a traffic parser module to perform classification and create a unique identifier for each session, which is stored in the session information.
[0063] S102: Construct a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first feature of a corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; the top-level node represents a third feature of the entire conversation information; and the weight of any edge in the conversation graph is determined based on the features of the connected nodes.
[0064] To more accurately and comprehensively capture the interaction characteristics between requests and responses in different rounds of session information, a session graph can be constructed based on the session information. Unlike traditional graph structures that only focus on a single request-response relationship, in this embodiment of the application, the session graph is a multi-layered graph structure. Figure 2 A diagram of a conversation graph is provided for some embodiments of the present application. Figure 2 As shown, the session graph includes bottom-level nodes, middle-level nodes, and top-level nodes. The bottom-level nodes are nodes with request-response relationships, including request-response A, request-response B, and request-response C. The middle-level nodes are nodes with dependency relationships between bottom-level nodes, including dependency AB and dependency AC. The top-level node is the global session node.
[0065] Each bottom-level node represents the first characteristic of the corresponding interaction turn. For example, each middle-level node represents the second characteristic of the dependency relationship between bottom-level nodes. For example, the second characteristic includes the third characteristic of the top-level node representing the entire conversation information. The weight of any edge in the conversation graph is determined based on the characteristics of the connected nodes.
[0066] The multi-level conversation graph construction method can visually reflect complex interaction relationships and accurately capture the hierarchical structure of multiple interactions in web applications, so as to analyze the entire conversation process.
[0067] S103: Determine a graph feature matrix of the conversation graph.
[0068] Through graph embedding, the graph feature matrix of the conversation graph is determined.
[0069] Graph embedding is a method that converts nodes, edges, or subgraphs in a graph structure into vector representations, preserving the structure and feature information of the graph so that it can be processed and analyzed in machine learning algorithms.
[0070] S104: Input the graph feature matrix into the self-attention network to obtain adaptive weighted features of the session information.
[0071] Adaptive feature weighting dynamically adjusts feature weights based on their importance to the task during model training or processing, assigning different influences to different features to improve model accuracy and generalization. This weight distribution is automatically learned and can adapt to different datasets or task requirements.
[0072] Dynamic weight assignment of multimodal features is achieved through the self-attention mechanism. The self-attention mechanism automatically adjusts the weight of each feature based on its relative importance in a specific context, ensuring that the system captures the most critical features in complex interactive environments. This adaptive weight assignment mechanism, implemented based on a self-attention network, dynamically determines weights by calculating the similarity between the fused input features. The self-attention mechanism can adaptively adjust the weight assignment of features such as timing, frequency, and response structure based on dynamic changes in network traffic, effectively addressing the multidimensional features in complex network environments.
[0073] S105: Inputting the adaptive weighted features into a multilayer perceptron model and outputting the recognition result of the Web application; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
[0074] To accurately identify web applications, a multilayer perceptron (MLP) model is trained on session information with different behavioral patterns and corresponding web application types. This model is trained on a large dataset of traffic labeled with different behavioral patterns and web application types. This pre-training process enables the model to learn the unique behavioral patterns and characteristics of various web applications, enabling rapid and efficient identification in real-world applications.
[0075] In one possible implementation, the multi-layer perceptron model structure includes an input layer, a hidden layer, and an output layer. The input layer receives a multimodal feature vector weighted by a self-attention mechanism, and the feature vector includes time series features, frequency features, and response structure features. The hidden layer uses a four-layer design, with hidden layer 1 being a multimodal feature processing layer, whose main function is to normalize and nonlinearly map the input time series, frequency, and corresponding features. Hidden layer 2 is a multimodal feature fusion layer, whose main function is to align and fuse the input features to ensure that the time series, frequency, and corresponding structure features contained in the same batch enter the space of the same dimension. Hidden layer 3 is a deep feature abstraction layer, whose main function is to extract high-order patterns from the fused features, eliminate redundant features, and reduce computational overhead. The fused features are nonlinearly processed using the hyperbolic tangent (tanh) nonlinear activation function. In order to avoid the gradient vanishing problem in this process, a residual connection mechanism is used to directly pass part of the feature information to higher layers to ensure that important features of the early layers are not lost, and then the dimensionality is reduced layer by layer to eliminate redundant features and reduce computational overhead. Hidden layer 4 is the feature optimization layer. Its primary function is to ensure uniform feature distribution and reduce the risk of overfitting through L2 regularization. A dynamic dropout mechanism is introduced in this process. Based on feature correlation, the probability of dropout is dynamically determined. Only highly correlated features or those that may cause overfitting are randomly dropped, while important features with weaker relationships with other features are retained. The weights of these retained important features are then re-adjusted to ensure maximum utilization of key features, suppress noise, and improve model generalization. During the inference phase, the high-dimensional feature vector input from the upper layer of the model is fed into the output layer, where it is classified using the Softmax function. The output of the output layer takes the probability distribution of the current web application to complete recognition.
[0076] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition.
[0077] Example 2:
[0078] In order to further improve the accuracy of Web application identification, based on the above embodiment, in the embodiment of the present application, the first feature includes the response delay feature of the corresponding round interaction and the structural feature of the response data packet;
[0079] For any first edge between a bottom-layer node and an intermediate-layer node, the time weight of the first edge is determined based on the response delay characteristics of the bottom-layer node to which the first edge is connected; the size weight of the first edge is determined based on the data size of the response data packet of the bottom-layer node to which the first edge is connected; and the weight of the first edge is determined based on the size weight and the time weight.
[0080] The first feature includes the response delay feature of the corresponding round of interaction and the structural feature of the response data packet. For example, the response delay feature can be the time interval between the request and the response, and the structural feature of the data packet can be the length, hierarchical structure and data format of the data packet. In one possible implementation, the TF-IDF algorithm can be used to vectorize the text features in the first feature, and then spliced through the fully connected layer to form a high-dimensional joint feature vector to form a multimodal feature. The specific operation steps of feature splicing can be spliced through the fully connected layer to generate a unified high-dimensional feature vector. The Dropout (random deactivation) mechanism is used to avoid overfitting and ensure the effectiveness of feature fusion. As a result, the conversation graph after graph embedding includes static text load features and dynamic graph features.
[0081] In order to accurately determine the weight of each first edge, for any first edge between the bottom-layer node and the middle-layer node, the time weight of the first edge is determined according to the response delay characteristics of the bottom-layer node connected to the first edge; the size weight of the first edge is determined according to the data size of the response data packet of the bottom-layer node connected to the first edge; and the weight of the first edge is determined based on the size weight and the time weight.
[0082] In one possible implementation, the exponentially weighted moving average (EWMA) method may be used to calculate the time weight of the first edge to ensure dynamic capture of changes in time intervals and other features. Specifically:
[0083] w time (i) = α·Δt(i) + (1-α)·w time (i-1)
[0084] Where α is the attenuation coefficient and Δt(i) is the response delay of the i-th interaction.
[0085] In a possible implementation, the size weight of the first edge may be determined using the following formula:
[0086]
[0087] Among them, the maximum response data size can be the maximum response data size collected within a preset time period, or it can be the maximum response data size freely set according to needs, and this application does not limit this.
[0088] After determining the size weight and time weight of the first edge, the weight of the first edge can be determined based on the sum of the two, or corresponding weight values can be set for the size weight and time weight respectively, and the calculated sum of the weights can be used as the weight of the first edge.
[0089] In an embodiment of the present application, for any first edge between a bottom-layer node and an intermediate-layer node, a time weight of the first edge is determined based on a response delay of the bottom-layer node to which the first edge is connected, a size weight of the first edge is determined based on a data size of a response data packet of the bottom-layer node to which the first edge is connected, and a weight of the first edge is determined based on the size weight and the time weight. This allows the weight of the first edge to be determined more flexibly and accurately based on various features of the session interaction, thereby further improving the accuracy of Web application identification.
[0090] Example 3:
[0091] In order to further improve the accuracy of Web application identification, based on the above embodiments, in the embodiment of the present application, the second feature includes the response success rate of the intermediate node and / or the request frequency of the intermediate node;
[0092] For any second edge between the middle-layer node and the top-level node, the frequency weight of the second edge is determined based on the request frequency of the middle-layer node connected to the second edge; the success rate weight of the second edge is determined based on the response success rate of the middle-layer node connected to the second edge; and the weight of the second edge is determined based on the success rate weight and / or the frequency weight.
[0093] To accurately determine the weight of the second edge, for any second edge between an intermediate node and a top-level node, the frequency weight of the second edge can be determined based on the request frequency of the intermediate node connected to the second edge; the success rate weight of the second edge can be determined based on the response success rate of the intermediate node connected to the second edge. The weight of the second edge can then be determined based on the success rate weight and / or the frequency weight.
[0094] Specifically, in a possible implementation, the frequency weight of the second edge may be determined according to a ratio of a request frequency of an intermediate layer node connected to the second edge to a preset maximum request frequency.
[0095] In one possible implementation, the success rate weight of the second edge can be determined according to the following formula:
[0096]
[0097] Among them, the total number of responses can be the total number of responses collected within a preset time period, or it can be the set total number of responses. It can be freely set according to actual needs, and this application does not limit this.
[0098] The weight of the second edge can be determined according to the success rate weight or the frequency weight, or according to the sum of the success rate weight and the frequency weight. The weight values of the success rate weight and the frequency weight can also be set separately, and the weight of the second edge can be determined by weighted summation.
[0099] In an embodiment of the present application, for any second edge between an intermediate-layer node and a top-level node, a frequency weight of the second edge is determined based on the request frequency of the intermediate-layer node connected to the second edge; a success rate weight of the second edge is determined based on the response success rate of the intermediate-layer node connected to the second edge; and a weight of the second edge is determined based on the success rate weight and / or the frequency weight, thereby enabling the weight of the second edge to be determined more flexibly and accurately based on multiple characteristics of the session interaction, thereby further improving the accuracy of Web application identification.
[0100] Example 4:
[0101] In order to further improve the accuracy of Web application identification, based on the above embodiments, in an embodiment of the present application, the third feature includes the first response time of the session information and / or the request frequency of the session information.
[0102] To further improve the accuracy of Web application identification, the third feature of the entire session information represented by the top-level node may include the first response time of the session information and / or the request frequency of requests included in the session information.
[0103] In the embodiment of the present application, the third feature of the entire session information represented by the top-level node includes the first response time of the session information and / or the request frequency of the session information, thereby reflecting the overall characteristics of the session information.
[0104] Example 5:
[0105] In order to further improve the accuracy of Web application identification, based on the above embodiments, in the embodiment of the present application, before determining the graph feature matrix of the session graph, the following steps are further included:
[0106] The weight of any first edge in the conversation graph is exponentially decayed; the exponential decay is determined by the difference between the current time and the interaction time of the underlying node connected to the first edge.
[0107] Since the number of underlying nodes may be too large, if all underlying nodes are used to extract the graph feature matrix, the graph feature matrix may be too large and the information may be redundant. In an embodiment of the present application, before determining the graph feature matrix of the conversation graph, an adaptive weight decay mechanism may be used to exponentially decay the weight of any first edge of the conversation graph, so as to screen out a better first edge and its connected underlying nodes.
[0108] Specifically, the correlation between historical timing features and current request-response interactions can be found through time series analysis, and the weight of the first edge can be dynamically updated and decayed. In one possible implementation, an exponential decay function based on a time window can be used:
[0109]
[0110] Among them, t current is the current time, t(i) is the time of the i-th interaction, and τ is a time constant used to control the decay rate. Using an exponential decay function based on a time window ensures that historical data gradually becomes obsolete, effectively attenuating the weight of the first edge of each historical interaction round, preventing it from interfering with the current recognition result.
[0111] In an embodiment of the present application, the weight of any first edge in the conversation graph is exponentially decayed, and a graph feature matrix is determined based on the decayed conversation graph to further improve the accuracy of Web application recognition.
[0112] Example 6:
[0113] In order to further improve the accuracy of Web application identification, based on the above embodiments, in the embodiment of the present application, the graph feature matrix for determining the session graph includes:
[0114] For any first node in the conversation graph, based on the weight of the edge between the first node and the second node and the features of the second node, obtain the aggregate features between the first node and the second node, thereby forming an aggregate feature matrix between the nodes; the second node is any node in the conversation graph other than the first node;
[0115] A multi-scale convolution kernel is used to perform at least two convolution operations on the aggregated feature matrix to obtain a graph feature matrix of the conversation graph.
[0116] The traditional graph convolutional network (GCN) only focuses on the direct neighbors of the node. In order to more accurately determine the graph feature matrix of the conversation graph, in an embodiment of the present application, a context-aware graph embedding operation can be used to form an aggregated feature matrix between nodes. By introducing a context-aware mechanism, global context embedding is achieved. Among them, the global context pool construction includes building a global context pool for each node and aggregating the features of its non-directly adjacent nodes. The global context pool can form more expressive node features by summarizing the features of other nodes within a specific time window.
[0117] Specifically, for any node in the conversation graph, the aggregated features between the first node and the second node are obtained based on the weight of the edge between the first node and the second node and the features of the second node, thereby forming an aggregated feature matrix between the nodes, where the second node is any node in the conversation graph except the first node.
[0118] In one possible implementation, in order to reduce computational complexity, a context cache mechanism and an attention mechanism can be used to assist the operation. The feature aggregation formula in the context pool is:
[0119]
[0120] Among them, α ij is the weight of the edge between the first node i and the second node j, h j is the feature embedding vector of the second node j.
[0121] Multi-scale convolution is used and the aggregated feature matrix is convolved at least twice to obtain the graph feature matrix of the conversation graph. For example, a 3x3 convolution kernel can be used to extract local interaction features, and a 7x7 convolution kernel can be used to extract global context features, ensuring that the global context information of the conversation graph is fully utilized in complex interactions.
[0122] In an embodiment of the present application, for any first node in a conversation graph, based on the circle of edges between the first node and the second node and the features of the second node, aggregate features between the first node and the second node are obtained, thereby forming an aggregate feature matrix between the nodes; a multi-scale convolution kernel is used to perform at least two convolution operations on the aggregate feature matrix to obtain a graph feature matrix of the conversation graph, fully utilizing the feature information of the conversation graph to further improve the accuracy of web application recognition.
[0123] Example 7:
[0124] In order to further improve the accuracy of web application recognition, based on the above embodiments, the graph feature matrix is input into the self-attention network to obtain the adaptive weighted features of the session information, including:
[0125] Mapping the graph feature matrix to generate a query vector Q, a key vector K, and a value vector V for any feature;
[0126] For any feature, the similarity between different features is obtained based on the inner product of the query vector Q of the feature and the key vector K of the feature, and the similarity is normalized by the softmax function to obtain the weight ratio of the feature; the value vector V of the feature is weighted according to the weight ratio to obtain an adaptive weighted feature.
[0127] In order to more accurately obtain the adaptive weighted features of session information, the embodiment of the present application adopts an adaptive weight distribution method to achieve dynamic weight distribution of multimodal features through the self-attention mechanism. The self-attention mechanism can automatically adjust the weight according to the relative importance of each feature in a specific context, ensuring that the system can capture the most critical features in a complex interactive environment. The adaptive weight distribution mechanism is based on the self-attention network (Self-Attention Network) and dynamically determines the weight by calculating the similarity between the input fusion features. For each input graph feature matrix, the query vector Q, key vector K and value vector V of any feature are mapped and generated. By calculating the inner product between the query vector Q and the key vector K, the system can obtain the similarity between different features, calculate the weighted result based on the similarity, and then normalize these similarities through the softmax function to obtain the weight of the feature. Then, the feature value is weighted according to the weight to obtain the adaptively weighted feature. The attention mechanism can adaptively adjust the weight distribution of features such as timing, frequency, and response structure according to the dynamic changes in network traffic, so that the system can effectively cope with multi-dimensional features in complex network environments.
[0128] The input to this step is the multimodal graph feature matrix output by the upper layer. Each row of the graph feature matrix represents a node, and each column represents a feature. A weight matrix is used to linearly map the input matrix, mapping the input features into a query vector Q, a key vector K, and a value vector V. The inner product between the query vector and the key vector is used to measure the degree of match between the two. A larger inner product value indicates a higher correlation. The inner product score can be positive or negative, so a softmax normalization process is used to generate a weight. The weights are then used to sum the value vectors to obtain the weighted result, namely the adaptive weighted feature.
[0129] In an embodiment of the present application, the graph feature matrix is input into the self-attention network to obtain adaptive weighted features of session information, further improving the accuracy of web application recognition.
[0130] The following is a specific example to further illustrate the entire process of Web application identification in the embodiment of the present application. Figure 3 Another schematic diagram of a Web application identification process is provided for some embodiments of the present application. Figure 3 As shown, the process includes:
[0131] Data is analyzed through the traffic access parsing device, and then passes through the protocol behavior extraction module, the session graph construction and embedding module, the feature fusion module, and the inference recognition model to obtain the final web application recognition output. The specific implementation process of each module can be referred to the methods in the above embodiments and will not be repeated here.
[0132] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition.
[0133] Example 8:
[0134] Based on the same inventive concept and on the basis of the above embodiments, an information disclosure system is provided in an embodiment of the present application. Figure 4 This is a schematic diagram of a structure of a Web application identification device provided in some embodiments of the present application. Figure 4 As shown, the device includes:
[0135] The collection module 401 is used to collect any session information of the Web application; the session information includes at least one round of interaction between requests and responses;
[0136] Construction module 402 is configured to construct a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first feature of a corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes having a dependency relationship; and the top-level node represents a third feature of the entire conversation information; the weight of any edge in the conversation graph is determined based on the features of the connected nodes; and a graph feature matrix of the conversation graph is determined;
[0137] Identification module 403 is configured to input the graph feature matrix into a self-attention network to obtain adaptive weighted features of the session information; input the adaptive weighted features into a multilayer perceptron model to output recognition results of the Web application; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
[0138] In a possible implementation manner, the first feature includes a response delay feature and a structural feature of a response data packet corresponding to a round of interaction;
[0139] The construction module is specifically used to determine the time weight of any first edge between the bottom-layer node and the middle-layer node according to the response delay characteristics of the bottom-layer node connected to the first edge; determine the size weight of the first edge according to the data size of the response data packet of the bottom-layer node connected to the first edge; and determine the weight of the first edge according to the size weight and the time weight.
[0140] In a possible implementation manner, the second feature includes a response success rate of the intermediate node and / or a request frequency of the intermediate node;
[0141] The construction module 402 is specifically used to determine the frequency weight of any second edge between the middle-layer node and the top-level node according to the request frequency of the middle-layer node connected to the second edge; determine the success rate weight of the second edge according to the response success rate of the middle-layer node connected to the second edge; and determine the weight of the second edge according to the success rate weight and / or the frequency weight.
[0142] In a possible implementation, the third feature includes the first response time of the session information and / or the request frequency of the session information.
[0143] In a possible implementation, the construction module 402 is further configured to perform exponential decay on the weight of any first edge in the conversation graph; the exponential decay is determined by the difference between the current time and the interaction time of the underlying node connected to the first edge.
[0144] In one possible implementation, the construction module 402 is specifically configured to obtain, for any first node in the conversation graph, aggregate features between the first node and the second node based on the weight of the edge between the first node and the second node and the features of the second node, thereby forming an aggregate feature matrix between the nodes; the second node is any node in the conversation graph other than the first node; and convolution operations are performed on the aggregate feature matrix at least twice using a multi-scale convolution kernel to obtain a graph feature matrix of the conversation graph.
[0145] In one possible implementation, the identification module 403 is specifically used to map the graph feature matrix to generate a query vector Q, a key vector K, and a value vector V for any feature; for any feature, the similarity between different features is obtained based on the inner product of the query vector Q of the feature and the key vector K of the feature, and the similarity is normalized by a softmax function to obtain a weight ratio of the feature; the value vector V of the feature is weighted according to the weight ratio to obtain an adaptive weighted feature.
[0146] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition.
[0147] Example 9:
[0148] Based on the same inventive concept and on the basis of the above embodiments, an electronic device is provided in an embodiment of the present application. The electronic device can implement the functions of the Web application identification device described above. Figure 5 This is a schematic diagram of the structure of an electronic device provided in some embodiments of the present application. Figure 5 As shown, the electronic device includes: a processor 501, a communication interface 502, a memory 503 and a communication bus 504, wherein the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504;
[0149] The memory 503 stores a computer program. When the processor 501 executes the program, the processor 501 executes the steps of the method for identifying intranet web applications based on behavior patterns as described in any of the above embodiments.
[0150] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0151] The communication interface 502 is used for communication between the electronic device and other devices.
[0152] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Alternatively, the memory may be at least one storage device located away from the processor.
[0153] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.
[0154] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition.
[0155] Example 10:
[0156] Based on the same inventive concept, on the basis of the above embodiments, in an embodiment of the present application, a computer-readable storage medium is provided, which stores a computer program that can be executed by a processor. When the program runs on the processor, the processor implements the steps included in the behavior pattern-based intranet web application identification method as described in any of the above embodiments.
[0157] The above-mentioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in the electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc., optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid-state drives (SSDs), etc.
[0158] Based on the same inventive concept, embodiments of the present application also provide a computer program product comprising: computer program code that, when executed on a computer, causes the computer to perform the steps of any of the aforementioned methods for identifying intranet web applications based on behavioral patterns. Because the principles underlying the problems solved by the aforementioned computer program product are similar to those of the aforementioned methods for identifying intranet web applications based on behavioral patterns, the implementation of the aforementioned computer program product can be referenced to the implementation of the aforementioned methods, and any repetitive details will not be repeated.
[0159] In an embodiment of the present application, any session information of a web application is collected; the session information includes at least one round of interaction between requests and responses; a multi-level session graph of the session information is constructed, wherein each bottom-level node represents a first feature of the corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes with a dependency relationship; and the top-level node represents a third feature of the entire session information; the weight of any edge in the session graph is determined based on the features of the connected nodes; the determined graph feature matrix is input into a self-attention network to obtain adaptive weighted features of the session information, which are input into a multi-layer perceptron model to output a recognition result of the web application, thereby improving the accuracy of web application recognition.
[0160] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0161] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0162] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0163] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0164] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for identifying intranet web applications based on behavioral patterns, characterized in that: The method comprises: Collect any session information of a Web application; the session information includes at least one round of interaction between requests and responses; Constructing a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first characteristic of a corresponding round of interaction; each middle-level node represents a second characteristic between bottom-level nodes that have a dependency relationship; and the top-level node represents a third characteristic of the entire conversation information; the weight of any edge in the conversation graph is determined based on the characteristics of the connected nodes; Determining a graph feature matrix of the conversation graph; Inputting the graph feature matrix into a self-attention network to obtain adaptive weighted features of the session information; The adaptive weighted features are input into a multilayer perceptron model, and a recognition result of the Web application is output; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
2. The method according to claim 1, characterized in that The first characteristics include response delay characteristics and structural characteristics of response data packets corresponding to the round of interaction; For any first edge between a bottom-layer node and an intermediate-layer node, the time weight of the first edge is determined based on the response delay characteristics of the bottom-layer node to which the first edge is connected; the size weight of the first edge is determined based on the data size of the response data packet of the bottom-layer node to which the first edge is connected; and the weight of the first edge is determined based on the size weight and the time weight.
3. The method according to claim 1, characterized in that The second feature includes a response success rate of the middle-layer node and / or a request frequency of the middle-layer node; For any second edge between an intermediate node and a top-level node, determine a frequency weight of the second edge according to a request frequency of the intermediate node connected by the second edge; Determining a success rate weight of the second edge according to a response success rate of an intermediate layer node connected by the second edge; The weight of the second edge is determined according to the success rate weight and / or the frequency weight.
4. The method according to claim 1, wherein The third feature includes the first response time of the session information and / or the request frequency of the session information.
5. The method according to any one of claims 1 to 4, characterized in that Before determining the graph feature matrix of the conversation graph, the method further includes: The weight of any first edge in the conversation graph is exponentially decayed; the exponential decay is determined by the difference between the current time and the interaction time of the underlying node connected to the first edge.
6. The method according to any one of claims 1 to 4, characterized in that Determining the graph feature matrix of the conversation graph includes: For any first node in the conversation graph, based on the weight of the edge between the first node and the second node and the features of the second node, obtain the aggregate features between the first node and the second node, thereby forming an aggregate feature matrix between the nodes; the second node is any node in the conversation graph other than the first node; A multi-scale convolution kernel is used to perform at least two convolution operations on the aggregated feature matrix to obtain a graph feature matrix of the conversation graph.
7. The method according to any one of claims 1 to 4, characterized in that Input the graph feature matrix into the self-attention network to obtain the adaptive weighted features of the session information, including: Mapping the graph feature matrix to generate a query vector Q, a key vector K, and a value vector V for any feature; For any feature, the similarity between different features is obtained based on the inner product of the query vector Q of the feature and the key vector K of the feature, and the similarity is normalized by the softmax function to obtain the weight ratio of the feature; the value vector V of the feature is weighted according to the weight ratio to obtain an adaptive weighted feature.
8. A Web application identification device, characterized in that: The device comprises: A collection module is used to collect any session information of a Web application; the session information includes at least one round of interaction between requests and responses; A construction module is configured to construct a conversation graph of the conversation information, wherein the conversation graph includes bottom-level nodes, middle-level nodes, and top-level nodes; each bottom-level node represents a first feature of a corresponding round of interaction; each middle-level node represents a second feature between bottom-level nodes having a dependency relationship; and the top-level node represents a third feature of the entire conversation information; the weight of any edge in the conversation graph is determined based on the features of the connected nodes; and a graph feature matrix of the conversation graph is determined; The recognition module is configured to input the graph feature matrix into a self-attention network to obtain adaptive weighted features of the session information; input the adaptive weighted features into a multilayer perceptron model to output recognition results of the Web application; the multilayer perceptron model is obtained by training session information with different behavior patterns and corresponding Web application types.
9. An electronic device, characterized in that: include: a memory for storing program instructions; A processor is configured to call program instructions stored in the memory and execute the steps of the method according to any one of claims 1 to 7 according to the obtained program instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a computer, the computer is caused to perform the method according to any one of claims 1 to 7.