Network request classification method and device, storage medium and electronic equipment

By dynamically adjusting the weights of the K-layer cascade decision tree model, the problem of low accuracy in abnormal request detection in the existing technology is solved, efficient real-time abnormal request detection is achieved, and the accuracy and efficiency of network attack detection are improved.

CN120658471APending Publication Date: 2025-09-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510845548.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

The existing methods for detecting abnormal requests have low accuracy and are difficult to deal with unknown or mutated network attacks. In addition, there are delays in rule updates, resulting in low detection efficiency and accuracy.

Method used

A decision tree model with a K-layer cascade structure receives network requests within a preset time window, extracts target feature vectors, and dynamically adjusts decision tree weights to achieve high-accuracy real-time abnormal request detection.

Benefits of technology

It achieves high-accuracy real-time abnormal request detection, improves the efficiency and accuracy of network attack detection, and enhances the security and stability of network systems in financial transaction scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658471A_ABST
    Figure CN120658471A_ABST
Patent Text Reader

Abstract

The invention discloses a network request classification method and device, a storage medium and electronic equipment, and relates to the field of artificial intelligence. The method comprises the steps that N network requests in a preset time window are received, and N is an integer larger than 1; taking the N network requests as a request combination, and extracting a target feature vector of the request combination; the target feature vector is input into a target model, a target score value of the request combination is determined through the target model according to the target feature vector, the target model adopts a K-layer cascading structure, each layer of structure is composed of a plurality of decision trees, and the target model is obtained by utilizing multiple pieces of historical request information. The weight of each decision tree in the initial model is dynamically adjusted to obtain a classification model, and K is an integer greater than 1; and determining the types of the N network requests in the request combination according to the target score value. The technical problem of low accuracy of an abnormal request detection method in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of artificial intelligence, and more specifically, to a method, device, storage medium, and electronic device for classifying network requests. Background Art

[0002] In today's information society, the Internet has become the key to the daily operations of banks and other financial institutions. At the same time, the means of network attacks are changing with each passing day. Attackers cleverly exploit network protocol loopholes, encryption technology weaknesses, and software defects to attack network systems in financial transaction scenarios.

[0003] Traditional abnormal request detection methods, such as rule-based intrusion detection systems and firewalls, mainly rely on predefined rules and feature libraries. Although they are effective for detecting known attacks, they are difficult to deal with unknown or mutated attacks, and there are delays in rule updates, resulting in low detection efficiency and accuracy. Although detection methods based on statistical analysis can identify anomalies in traffic patterns, they are limited to single feature analysis and lack the ability to identify complex attacks. Traditional machine learning algorithms, such as support vector machines and random forests, can automatically learn features, but when faced with time-series network traffic data, they are obviously insufficient in capturing sequential patterns. In addition, the high training data requirements lead to low detection accuracy and real-time performance in real environments.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The present application provides a method, device, storage medium and electronic device for classifying network requests, so as to at least solve the technical problem of low accuracy of the detection method of abnormal requests in the prior art.

[0006] According to one aspect of the present application, a method for classifying network requests is provided, comprising: receiving N network requests within a preset time window, wherein N is an integer greater than 1; treating the N network requests as a request combination, and extracting a target feature vector of the request combination; inputting the target feature vector into a target model, and determining a target score value of the request combination based on the target feature vector through the target model, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1; and determining the types of the N network requests in the request combination based on the target score value.

[0007] Optionally, N network requests are taken as a request combination, and a target feature vector of the request combination is extracted, including: detecting target information of each network request in the request combination, wherein the target information of each network request includes characteristic attribute information and behavior pattern information of the network request; and determining the target feature vector of the request combination based on the target information of each network request in the request combination.

[0008] Optionally, based on the target information of each network request in the request combination, a target feature vector of the request combination is determined, including: performing feature selection on the target information of each network request according to a target feature sequence, and forming at least one feature corresponding to each network request into a feature set to obtain N feature sets corresponding to N network requests, wherein the influence value of the features in the target feature sequence when identifying abnormal requests is greater than a first preset threshold; integrating the feature values ​​corresponding to the same features in each feature set to obtain a target feature set; converting the feature values ​​corresponding to all features in the target feature set to a target range, and converting the converted target feature set into a matrix form to obtain a target matrix; inputting the target matrix into the first model, and determining the target feature vector of the request combination based on the prior knowledge learned by the first model in the model training phase.

[0009] Optionally, the first model is obtained by the following steps: obtaining target information corresponding to multiple historical requests in each of T historical time windows, where T is an integer greater than 1; taking the target information corresponding to multiple historical requests in each historical time window as a set to obtain T first sets; performing feature extraction on the T first sets according to the target feature sequence to obtain T first feature sets; dividing the T first feature sets into a model training set and a model verification set; inputting the model training set and the model verification set into the first initial model for iterative training and verification operations until the number of iterations of the first initial model is greater than a preset number or the training error of the first initial model is lower than a set threshold, and determining that the first initial model enters a convergence state, wherein the verification operation is used to verify the performance of the model; and taking the first initial model in the convergence state as the first model.

[0010] Optionally, each iterative training includes the following steps: when there are M training sets in the model training set, using the target layer of the first initial model to extract features from the M training sets to obtain a feature vector corresponding to each training set, wherein M is an integer greater than or equal to 1, and the target layer includes a first preset number of convolution layers and a second preset number of pooling layers; inputting the feature vector corresponding to each training set into the output layer of the first initial model to obtain a classification result for each training set, wherein the classification result is used to characterize whether the historical request corresponding to each training set is an abnormal request; determining the error between the classification result corresponding to each training set and the actual category corresponding to each training set to obtain M error values; adjusting the model parameters of the first initial model according to the M error values.

[0011] Optionally, the target model is obtained by the following steps: inputting T first sets into the first model for feature extraction to obtain T first feature vectors; dividing each first feature vector in the T first feature vectors into multiple sub-feature vectors, and using the multiple sub-feature vectors obtained by dividing each first feature vector as the second feature set; training the initial model multiple times according to the second feature set until the number of iterations of the initial model is greater than a preset number, thereby obtaining the target model.

[0012] Optionally, each training includes the following steps: selecting R sub-feature vectors from the second feature set, inputting the R sub-feature vectors into the initial model for target processing, and obtaining R target classification results, wherein R is an integer greater than 1; wherein the target processing includes: sequentially inputting the R sub-feature vectors into the decision tree in each layer structure of the initial model for classification, until each decision tree in the K-th layer structure of the initial model outputs a classification result, and taking the average value of the classification result corresponding to each sub-feature vector as the target classification result of the sub-feature vector, wherein the input of the classification tree in other layer structures except the first layer structure of the initial model also includes the output of the classification tree in the previous layer structure; determining the error between the target classification result corresponding to each sub-feature vector in the R sub-feature vectors and the actual category label corresponding to the sub-feature vector, and obtaining R error values; determining the performance index of each decision tree in the initial model based on the R error values, and adjusting the weight of each decision tree in the initial model according to the performance index; and updating the initial model according to the adjusted weight of each decision tree in the initial model.

[0013] Optionally, after iteratively training the initial model according to the second feature set until the number of iterations of the initial model is greater than a preset number and the target model is obtained, it includes: obtaining R target classification results obtained from each training; determining the distribution information of the classification results based on the R target classification results obtained from each training; determining the target threshold according to the distribution information of the classification results, wherein the target threshold is used to distinguish whether the network request is an abnormal request.

[0014] Optionally, the types of the N network requests in the request combination are determined based on the target score value, including: when it is detected that the target score value is greater than or equal to the target threshold, determining that the N network requests in the request combination are abnormal requests; when it is detected that the target score value is less than the target threshold, determining that the N network requests in the request combination are normal requests.

[0015] According to another aspect of the present application, a network request classification device is also provided, including: a receiving unit, for receiving N network requests within a preset time window, wherein N is an integer greater than 1; an extraction unit, for treating the N network requests as a request combination and extracting a target feature vector of the request combination; a first determination unit, for inputting the target feature vector into a target model, and determining a target score value of the request combination based on the target feature vector through the target model, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1; a second determination unit, for determining the types of the N network requests in the request combination based on the target score value.

[0016] According to another aspect of the present application, a computer-readable storage medium is provided, which includes a stored executable program, wherein when the executable program runs, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned network request classification method.

[0017] According to another aspect of the present application, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned method for classifying network requests.

[0018] According to another aspect of an embodiment of the present application, a computer program product is further provided, including computer instructions, which implement the steps of the above-mentioned network request classification method when executed by a processor.

[0019] In the present application, N network requests within a preset time window are first received, where N is an integer greater than 1. Then, the N network requests are taken as a request combination, and the target feature vector of the request combination is extracted. The target feature vector is then input into the target model, and the target score value of the request combination is determined by the target model based on the target feature vector. The target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, where K is an integer greater than 1. Finally, the type of the N network requests in the request combination is determined based on the target score value. That is, by means of a cascade decision model with deep feature analysis and dynamic weight adjustment, the purpose of quantitative scoring and type identification of the request combination is achieved, thereby achieving the technical effect of a high-accuracy real-time abnormal request detection mechanism, thereby solving the technical problem of low accuracy of the abnormal request detection method in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0021] Figure 1 is a flowchart of an optional method for classifying network requests according to an embodiment of the present application;

[0022] Figure 2 is a schematic diagram of an optional method for classifying network requests according to an embodiment of the present application;

[0023] Figure 3 This is a schematic diagram of an optional network request classification device according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] It should be noted that the collected information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation portals for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide users with corresponding operation portals for users to choose to agree or refuse the automated decision-making results; if the user chooses to refuse, the expert decision-making process will be entered.

[0027] According to an embodiment of the present application, a method embodiment of a method for classifying network requests is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0028] It should be noted that an intelligent processing system can be used as the execution subject of the network request classification method of the embodiment of the present application. It is understandable that the network request classification method provided in the embodiment of the present application can also be executed by other systems or devices as the execution subject, and the embodiment of the present application does not specifically limit this.

[0029] Figure 1 is a flow chart of an optional method for classifying network requests according to an embodiment of the present application, such as Figure 1 As shown, the method includes the following steps:

[0030] Step S101: Receive N network requests within a preset time window.

[0031] In step S101 , N is an integer greater than 1.

[0032] Optionally, the intelligent processing system monitors and receives N network requests within a preset time window (for example, every 5 seconds), where N is an integer greater than 1, ensuring that the system can collect a sufficient amount of continuous request data, thereby providing a solid foundation for subsequent feature extraction and analysis.

[0033] Optionally, the selection of the preset time window is based on the need to effectively monitor real-time network traffic, while balancing computing efficiency and data integrity to ensure that the system can respond in a timely manner while processing a moderate amount of data to avoid excessive consumption of resources.

[0034] Optionally, the N network requests are network requests with the same source IP.

[0035] Step S102: taking N network requests as a request combination and extracting a target feature vector of the request combination.

[0036] Optionally, once N network requests are collected, the intelligent processing system will aggregate these requests into a request combination. This step aims to convert a single network request information into a set of related data to facilitate subsequent deeper analysis.

[0037] Optionally, the intelligent processing system then extracts a target feature vector from the request combination through a series of feature engineering techniques. This vector contains information crucial for network attack detection, such as the number of requests per unit time, total traffic volume, the concentration of target IP accesses, and protocol distribution. These features can help the system identify potential abnormal behavior patterns, such as the high request frequency characteristic of a DDoS (Distributed Denial of Service) attack or the abnormally high traffic volume characteristic of a traffic amplification attack.

[0038] Step S103: input the target feature vector into the target model, and determine the target score value of the request combination according to the target feature vector through the target model.

[0039] In step S103, the target model adopts a K-layer cascade structure, each layer of the structure consists of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information.

[0040] In step S103 , K is an integer greater than 1.

[0041] Optionally, the target feature vector is then fed into a target model using a K-layer cascade structure. This model consists of multiple decision trees, with each layer responsible for feature analysis and classification at a specific granularity. The target model dynamically adjusts the weights of each decision tree in the initial model by leveraging historical request information, optimizing the model's classification capabilities.

[0042] Optionally, in this step, the target model calculates a target score reflecting the degree of abnormality of the request combination based on the input target feature vector and the weights of the decision trees in the cascade structure. This score comprehensively considers the evaluation results of all decision trees, and through a weighted average or voting mechanism, it ultimately generates a quantitative anomaly score to determine whether the request combination contains abnormal requests.

[0043] Step S104: determining the types of the N network requests in the request combination according to the target score value.

[0044] Optionally, the intelligent processing system sets a reasonable threshold based on the target score to distinguish between normal and abnormal requests. If the target score of a request combination exceeds the set threshold, the request combination is deemed to contain at least one abnormal network request; otherwise, it is considered a normal request. Through this process, the system can accurately and in real time identify whether there is abnormal behavior among N network requests within a preset time window, effectively improving the efficiency and accuracy of network attack detection.

[0045] Optionally, the entire process begins with receiving a network request, progresses through feature extraction, model scoring, and final request type determination, forming a closed-loop intelligent detection mechanism. This mechanism not only monitors network traffic in real time but also achieves high-precision identification of anomalous network requests through the integration of deep feature analysis and multi-level decision-making models, ensuring the security and stable operation of network systems in financial transaction scenarios. By dynamically adjusting decision tree weights, the model continuously learns and adapts to new attack patterns, enhancing the system's generalization capabilities and addressing the low accuracy of existing anomalous request detection methods.

[0046] From the contents of steps S101 to S104, it can be seen that in this application, N network requests within a preset time window are first received, where N is an integer greater than 1, then the N network requests are taken as a request combination, and the target feature vector of the request combination is extracted, and then the target feature vector is input into the target model, and the target score value of the request combination is determined by the target model based on the target feature vector, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1, and finally the type of the N network requests in the request combination is determined based on the target score value. That is, by means of a cascade decision model with deep feature analysis and dynamic weight adjustment, the purpose of quantitative scoring and type identification of the request combination is achieved, thereby achieving the technical effect of a high-accuracy real-time abnormal request detection mechanism, thereby solving the technical problem of low accuracy of the abnormal request detection method in the prior art.

[0047] In an optional embodiment, the intelligent processing system first detects the target information of each network request in the request combination, wherein the target information of each network request includes characteristic attribute information and behavior pattern information of the network request, and then determines the target feature vector of the request combination based on the target information of each network request in the request combination.

[0048] Optionally, the intelligent processing system first conducts a detailed analysis of the N network requests collected within a preset time window, focusing on detecting the target information of each network request. The target information here is divided into two categories: characteristic attribute information and behavioral pattern information. Characteristic attribute information covers the basic attributes of network requests, including but not limited to protocol type (such as TCP (Transmission Control Protocol, Transmission Control Protocol), UDP (User Datagram Protocol)), source IP address, target IP address, port number, request time, etc.; behavioral pattern information deeply explores the behavioral characteristics of network requests, such as the frequency of requests per unit time, whether there are abnormal traffic peaks, and the concentration of access to the target IP, etc. These are all key indicators for identifying potential attack behaviors. The system extracts the above target information by parsing the packet header information and payload data of each network request, laying the foundation for the subsequent construction of feature vectors.

[0049] Optionally, after obtaining detailed target information for each network request, the intelligent processing system integrates this information to form a target feature vector for the request combination. This process involves the fusion and abstraction of multi-dimensional data. Specifically, the intelligent processing system collects statistics and summarizes the characteristic attributes of network requests, such as calculating the total number of requests per unit time, analyzing the distribution of traffic volume, and evaluating the proportion of access to specific IP addresses. At the same time, the system also deeply analyzes behavioral pattern information to detect signs of abnormal behavior patterns. By combining these statistical results with the results of behavioral pattern analysis, a multi-dimensional target feature vector is formed that comprehensively reflects the comprehensive characteristics and potential abnormal behavior of the request combination.

[0050] From the above, it can be seen that the intelligent processing system detects the target information of network requests and constructs the target feature vector, which is essentially a deep feature engineering task. It aims to extract features with diagnostic value from the complex network request data and lay a data foundation for accurately detecting abnormal requests. Through this series of operations, the system can capture subtle and critical behavioral patterns in network requests and effectively identify potential network attacks even in high-concurrency and complex network environments. The construction of the target feature vector ensures that the intelligent processing system not only focuses on the static properties of a single request, but can also determine the time series characteristics and behavioral patterns of the request, greatly improving the accuracy and real-time performance of anomaly detection, effectively solving the problem of low accuracy of abnormal request detection methods in existing technologies, and enhancing the effectiveness and reliability of network attack defense in financial transaction scenarios.

[0051] In an optional embodiment, the intelligent processing system first performs feature selection on the target information of each network request according to the target feature sequence, and organizes at least one feature corresponding to each network request into a feature set to obtain N feature sets corresponding to N network requests, wherein the influence value of the features in the target feature sequence when identifying abnormal requests is greater than a first preset threshold value, and then integrates the feature values ​​corresponding to the same features in each feature set to obtain a target feature set, and then converts the feature values ​​corresponding to all features in the target feature set into a target range, and converts the converted target feature set into a matrix form to obtain a target matrix, and then inputs the target matrix into the first model, and determines the target feature vector of the request combination based on the prior knowledge learned by the first model in the model training phase.

[0052] Optionally, the intelligent processing system first refines the target information of each network request through a target feature sequence. The "target feature sequence" here refers to a list of features that have a significant impact on identifying abnormal requests, selected through preprocessing and feature engineering steps. The impact value of these features in identifying abnormal requests must be greater than a preset first threshold to ensure that the selected features make a substantial contribution to anomaly detection. The system combines at least one feature related to each network request into a feature set based on the target feature sequence, and ultimately generates N feature sets corresponding to N network requests. This process is essentially an efficient feature extraction of the original network request data, ensuring that subsequent processing steps can be performed based on the features with the most identification value.

[0053] Optionally, the intelligent processing system then consolidates the feature values ​​corresponding to the same features in each feature set. Through statistical analysis and aggregation operations, the system combines the feature values ​​of the same feature across different requests to form a single composite value. This operation helps reduce data redundancy and extract core feature values. This consolidated feature set, called the "target feature set," condenses the key information about the target feature across N network requests, simplifying subsequent processing while improving feature interpretability and detection efficiency.

[0054] Optionally, after obtaining the target feature set, the system converts the eigenvalues ​​corresponding to all features in the set to a target range. This target range might be [0, 1]. Normalization ensures that all eigenvalues ​​are compared on the same scale, eliminating dimensional differences between different eigenvalues, which is crucial for model training and prediction. The converted target feature set is then further converted to a matrix form, resulting in a "target matrix." This process adapts the data format to the input requirements of subsequent deep learning models, facilitating efficient feature learning and anomaly assessment.

[0055] Optionally, the intelligent processing system finally inputs the target matrix into the first model, a deep learning model trained on a large amount of historical data and a variety of abnormal attack samples. Based on the prior knowledge learned during the model training phase, it deeply analyzes the input feature values ​​and generates a "target feature vector" that comprehensively characterizes the likelihood of an abnormal request combination. This vector not only contains important attribute information of the original network request but also incorporates deep insights into behavioral patterns, providing a rich and accurate feature description for subsequent anomaly scoring and attack identification.

[0056] As can be seen from the above, through the aforementioned implementation steps, the intelligent processing system is able to achieve efficient feature selection, feature integration, and deep feature vector construction for network requests. This series of operations significantly improves the accuracy and real-time performance of abnormal request identification. The use of target feature sequences ensures that the model focuses only on the features most influential for anomaly detection, avoiding the interference of redundant features on the model's predictive capabilities. Furthermore, the integration and normalization of feature values ​​further optimizes the data structure and enhances the model's adaptability to diverse and complex network environments. The resulting target feature vector is the result of deep feature learning performed by the intelligent processing system on request combinations. It not only effectively captures the static properties of network requests, but also identifies dynamic correlations and behavioral patterns between requests, providing a strong decision-making basis for anomaly detection and prevention, significantly enhancing the security protection capabilities of the entire system. Through deep feature analysis, the system can more accurately capture the complex patterns of abnormal requests, improve detection efficiency, and ensure network security in financial transaction scenarios.

[0057] In an optional embodiment, the first model is obtained by the following steps: first, the intelligent processing system obtains the target information corresponding to multiple historical requests in each of T historical time windows, where T is an integer greater than 1, and then takes the target information corresponding to the multiple historical requests in each historical time window as a set to obtain T first sets, and then performs feature extraction on the T first sets according to the target feature sequence to obtain T first feature sets, and then divides the T first feature sets into a model training set and a model verification set, and then inputs the model training set and the model verification set into the first initial model for iterative training and verification operations until the number of iterations of the first initial model is greater than a preset number or the training error of the first initial model is lower than a set threshold, and it is determined that the first initial model enters a convergence state, wherein the verification operation is used to verify the performance of the model, and finally the first initial model in the convergence state is used as the first model.

[0058] Optionally, the first model is a CNN (Convolutional Neural Network) model. CNN is a deep learning method with a complex convolutional computing layer and a deep learning structure. It is also a feedforward neural network that trains the weights in the network through a backpropagation algorithm to implement a deep learning algorithm. For the convolution layer, the convolution layer in the CNN consists of convolution operations performed by various small convolution units. The convolution operation can gradually optimize the parameters of each convolution layer, thereby realizing the function of extracting features. During the training process, the convolution layer is generally responsible for the task of extracting features.

[0059] The convolution layer is generally given a square convolution kernel (filter) and sets the convolution step size. In this method, the convolution kernel can slide on the feature image and traverse every pixel on the feature image. Every time the convolution kernel completes the calculation of a local feature, it needs to move a step size to the next part to calculate the local feature. Every time the convolution kernel moves, it will generate an area that overlaps with the feature image. Then the convolution kernel is multiplied by the position corresponding to the overlapping area, and a bias term is added to finally obtain a pixel of the output feature image. By continuously moving the convolution kernel on the feature image, the features of the layer can be extracted. Among them, the method of calculating the feature plane by the convolution kernel is shown in formula (1):

[0060]

[0061] Among them, i and j represent indices, corresponding to the rows and columns of the output feature map (i-th row, j-th column), y i,j is the output of the convolution kernel, which is also the element of feature planning, f(.) is the activation function, θ ij is the convolution kernel parameter, x ij is the convolution block parameter (the pixel value of the area currently overlapping with the convolution kernel in the input feature map), and b is the bias term.

[0062] The purpose of the pooling layer is to reduce the number of features. There are two main methods: Max Pooling and Average Pooling. Table 1 is an example of the calculation method of an optional pooling method according to an embodiment of the present application, as shown in Table 1.

[0063] Table 1

[0064]

[0065] Among them, N represents the total number of elements in the pooling window, that is, the number of input feature values ​​covered by the window.

[0066] Pooling is a downsampling process. Typically, the pooling layer follows the convolutional layer, with the convolutional layer's output serving as the pooling input. Pooling's primary purpose isn't to extract features, but rather to simplify them. This involves reducing the number of features through the pooling process to achieve a desired effect. Max Pooling selects the maximum value in the overlapping region as the output feature pixel, which facilitates extracting prominent features from the image. Average Pooling uses the average value of all pixels in the overlapping region as the output feature pixel. This approach allows for summarizing all features within the overlapping region without discarding key features. The fully connected layer in a CNN serves the same purpose as the hidden layer in a traditional neural network. It also doesn't extract or simplify features, but rather transmits signals to other connected layers via a feedforward network.

[0067] Optionally, the CNN model designed in this embodiment includes 6 convolutional layers, each of which is followed by a normalizer to perform batch normalization on the eigenvalues. All activation functions use ReLU1, and except for the last convolutional layer which uses average pooling, the rest use max pooling. Because the low-level convolutional layers require max pooling to extract significant features, the high-level convolutional layers require average pooling to avoid missing key features. The final eigenvalues ​​are used as input for the isolation forest. Table 2 is an example of an optional CNN configuration according to an embodiment of the present application, as shown in Table 2.

[0068] Table 2

[0069]

[0070]

[0071] Among them, Input layer represents the input layer; Convolution layer1 represents the first convolution layer, and the parameters are "Number of filters 16, Filter size 1×8, Stride 1,1", which means that the layer contains 16 filters (or convolution kernels), each filter size is 1×8, and the stride (that is, the distance the filter moves on the input data) is 1,1. ReLU1 means that the first convolution layer and subsequent layers use the ReLU activation function, and the number of parameters is 144; MaxPoolinglayer1 represents the first pooling layer, and the parameters "Pooling size 1,2, Stride1,2" indicate that a pooling window of size 1×2 is used, the stride is also 1,2, there is no activation function, and the number of parameters is 0 (the pooling layer usually does not contain parameters that need to be learned); Convolution layer2 represents the second convolution layer, which contains 24 filters, the filter size is 1×8, and the stride is 1,1. Using the ReLU activation function, the number of parameters is 3096; and so on, until the last layer, the fully connected layer, the output size is 5, and the SoftMax activation function is used, which means that the final output layer classifies the data into 5 different categories.

[0072] Optionally, the intelligent processing system first collects historical data. This step is the starting point for building the first model (i.e., the CNN model). The system obtains target information for network requests within each of T historical time windows. Here, T is an integer greater than 1, representing the number of historical time periods collected by the system, ensuring sufficient data samples to cover various network request scenarios.

[0073] Optionally, the system then organizes the target information corresponding to multiple historical requests acquired within each historical time window into a single set, generating T first sets. This step transforms raw data into structured feature sets, providing a uniformly formatted dataset for subsequent feature extraction and model training. The first set contains comprehensive information about the characteristic attributes and behavioral patterns of historical requests, serving as a crucial data source for model training.

[0074] Optionally, based on the first set, the system extracts features from the T first sets through the target feature sequence to generate T first feature sets. Through this process, the intelligent processing system can capture the deep information and patterns contained in the historical requests, and provide high-quality feature data for building efficient models. Subsequently, the intelligent processing system further divides the T first feature sets into a model training set and a model verification set. After the model training set and the model verification set are prepared, they are input into the first initial model (i.e., the CNN model that has not yet been optimized) for iterative training and verification operations. In each iteration, the first initial model continuously adjusts its internal parameters through the backpropagation algorithm to optimize the accuracy of feature extraction and classification. The system will continue to observe the training error of the model, and when the number of model iterations is greater than the preset number or the training error of the model is lower than the set threshold, it determines that the first initial model has entered a convergence state, which means that the model training has reached the expected performance level.

[0075] Optionally, after confirming convergence of the first initial model, the intelligent processing system uses this model as the first model for feature vector analysis of real-time request combinations. This model has been fully trained and validated, and possesses the ability to efficiently and accurately identify abnormal requests. This provides high-quality input features for the subsequent Deep Forest model, significantly improving the accuracy and real-time performance of overall anomaly detection.

[0076] From the above, we can see that the intelligent processing system, through in-depth feature engineering and model training, ensures that the first model (CNN) can fully learn the complex features in historical requests, including but not limited to time series characteristics, protocol distribution patterns, and traffic anomaly trends. This not only strengthens the model's ability to identify abnormal requests, but also makes the model more generalizable and able to cope with new types of attacks that may appear in the future. Through a rigorous training and verification process, the intelligent processing system is able to build an efficient and accurate first model, laying a solid foundation for anomaly detection of real-time network requests. In practice, this process significantly improves the training effect of the model, enabling the model to classify request combinations more quickly and accurately, which is crucial to improving the effectiveness of the overall network attack detection and defense system.

[0077] In an optional embodiment, each iterative training includes the following steps: when there are M training sets in the model training set, the intelligent processing system uses the first initial model to extract features from the M training sets to obtain a feature vector corresponding to each training set, wherein M is an integer greater than or equal to 1, and the target layer includes a first preset number of convolution layers and a second preset number of pooling layers, and the feature vector corresponding to each training set is input into the output of the first initial model to obtain a classification result for each training set, wherein the classification result is used to characterize whether the historical request corresponding to each training set is an abnormal request, and then determine the error between the classification result corresponding to each training set and the actual category corresponding to each training set to obtain M error values, and then adjust the model parameters of the first initial model according to the M error values.

[0078] Optionally, the intelligent processing system first focuses on a model training set, which contains M different data subsets, where M is an integer greater than or equal to 1. The system uses the first initial model to perform feature extraction on these M training sets. The core of this process is to automatically identify and learn the deep features of the historical requests contained in each training set through the model's multi-layer neural network structure, thereby converting them into a series of feature vectors. These feature vectors cover the multi-dimensional attributes of historical requests, including but not limited to request frequency, traffic volume, IP access patterns, etc., and serve as the basis for subsequent classification and anomaly identification.

[0079] Optionally, the feature vectors corresponding to each training set are then input into the classification layer of the first initial model. The classification layer is responsible for mapping the feature vectors into specific classification results, which characterize whether the historical requests corresponding to each training set are normal or abnormal. Through the operations of the classification layer, the system can obtain classification results for the M training sets. After obtaining the classification results for the M training sets, the intelligent processing system further compares these results with the true classification (i.e., actual classification) of each training set and calculates the deviation between the classification results and the actual classification, also known as the error. This error calculation process provides feedback to the model, helping it understand in which areas or for which types of data its predictions differ from the actual situation. Finally, based on the M error values, the intelligent processing system uses an optimization algorithm (such as gradient descent or stochastic gradient descent) to adjust the model parameters of the first initial model. Model parameters include weights and biases in the neural network, and their adjustment directly affects the model's feature extraction capabilities. The system typically uses a backpropagation algorithm to infer the parameter updates for each neural network layer based on the error values. Using optimization strategies such as gradient descent, the model parameters are adjusted to reduce classification error and improve the model's anomaly detection capabilities.

[0080] As can be seen from the above, the core purpose of each training step is to significantly improve the feature extraction accuracy of the first model. During training, a classification layer is introduced to evaluate the model's ability to classify anomalous requests. This provides feedback on the quality of the feature vectors and the error between the classification results and the actual categories, revealing how accurately the feature vectors represent anomalous patterns in network requests. Through error-driven parameter adjustment, the first model optimizes its feature extraction process, ensuring that the extracted feature vectors more accurately reflect the essential properties of network requests, thereby improving the accuracy and efficiency of anomaly detection. Each training step based on M training sets aims to enhance the first model's generalization ability to unknown network requests. The system adjusts model parameters by comparing the model's classification results with the actual categories. This process enables the model to not only better understand the features in the training set but also learn broader data distribution patterns. As training progresses, the first model is able to extract common feature patterns from the M training sets, accurately identifying potential anomalous behavior even in newly generated network requests. This provides powerful technical support for real-time network attack detection in financial transaction scenarios.

[0081] In an optional embodiment, the target model is obtained by the following steps: the intelligent processing system inputs T first sets into the first model for feature extraction to obtain T first feature vectors, and then divides each of the T first feature vectors into multiple sub-feature vectors, and uses the multiple sub-feature vectors obtained by dividing each first feature vector as the second feature set, and finally trains the initial model multiple times according to the second feature set until the number of iterations of the initial model is greater than the preset number, thereby obtaining the target model.

[0082] Optionally, the intelligent processing system first inputs T first sets (each set represents a set of network request features within a historical time window) into a first model (i.e., a pre-trained deep learning model, such as a CNN). The first model uses its powerful feature extraction capabilities to perform in-depth analysis on each input set, converting each set into a first feature vector. These feature vectors integrate the basic attributes of network requests (such as source IP, destination IP, port number, etc.) and behavioral patterns (such as access frequency and changes in traffic volume).

[0083] Optionally, the intelligent processing system then employs a multi-granularity scanning strategy for each first eigenvector, subdividing it into multiple sub-eigenvectors. This division is performed using different time window lengths and feature dimensions to capture more layers of network behavior patterns, enhancing the model's sensitivity to detail and generalization capabilities. The collection of sub-eigenvectors is defined as the second feature set, providing a diverse and refined feature sample for the next step of model training.

[0084] Optionally, the intelligent processing system can also perform feature extraction in different frequency bands and use feature selection techniques based on machine learning, such as feature importance scoring in random forests, to optimize the feature set.

[0085] Optionally, finally, the system iteratively trains the initial model (i.e., the unoptimized cascade forest model) based on the second feature set. In each iteration, the model adjusts its internal decision tree weights according to the input sub-feature vectors and optimizes the decision boundary so that the model can more accurately distinguish between normal requests and abnormal requests. The training process continues until the number of iterations of the initial model exceeds the preset threshold, which means that the model has undergone enough learning cycles and its ability to score abnormalities of network requests has been significantly improved. At this point, the initial model has completed the transformation from a primary to a mature model and has become the final target model, the optimized cascade forest model.

[0086] As can be seen from the above, through the above steps, the intelligent processing system achieves a comprehensive transformation from raw data to an efficient anomaly detection model. First, feature vectors are extracted through a deep learning model, ensuring that the model input features are both profound and comprehensive, covering both the static properties and dynamic behavior of network requests. Second, the division of sub-feature vectors enhances the model's adaptability to complex network environments and its ability to perceive details, enabling the model to more flexibly handle diverse attack patterns. Finally, through iterative training and model optimization, the model ensures that its anomaly detection accuracy continues to improve during the learning process. Even in the face of unknown attack types, it can effectively defend against them based on existing feature patterns. This entire process not only improves the efficiency and accuracy of anomaly detection but also enhances the system's real-time response capabilities. This provides strong protection for network security in financial transaction scenarios, effectively responding to various network attacks and maximizing the protection of user assets and system stability.

[0087] In an optional embodiment, each training includes the following steps: the intelligent processing system selects R sub-feature vectors from the second feature set, inputs the R sub-feature vectors into the initial model for target processing, and obtains R target classification results, wherein R is an integer greater than 1; wherein the target processing includes: sequentially inputting the R sub-feature vectors into the decision tree in each layer structure of the initial model for classification, until each decision tree in the K-th layer structure of the initial model outputs a classification result, and taking the average value of the classification result corresponding to each sub-feature vector as the target classification result of the sub-feature vector, wherein the input of the classification tree in other layer structures except the first layer structure of the initial model also includes the output of the classification tree in the previous layer structure; then determining the error between the target classification result corresponding to each sub-feature vector in the R sub-feature vectors and the actual category label corresponding to the sub-feature vector, obtaining R error values, and then determining the performance index of each decision tree in the initial model based on the R error values, and adjusting the weight of each decision tree in the initial model according to the performance index, and finally updating the initial model according to the adjusted weight of each decision tree in the initial model.

[0088] Optionally, the intelligent processing system randomly selects R sub-feature vectors from the second feature set. Here, R is an integer greater than 1, representing the number of sub-feature vectors used for training during each iterative training process. These R sub-feature vectors are then input one by one into the initial model (i.e., the cascade forest model that has not yet been fully trained and optimized) for target processing. The essence of target processing is to classify the feature vectors using the decision tree in the model to evaluate the model's ability to recognize different request types.

[0089] Optionally, in target processing, the intelligent processing system inputs each sub-feature vector into the decision tree in each layer of the model in sequence according to the structural design of the cascade forest for classification. This process starts from the first layer until each decision tree in the K-th layer has output its own classification result. It is worth noting that in the layers other than the first layer, the classification tree not only accepts input from the current sub-feature vector, but also integrates the output of the classification tree in the previous layer as additional input information. Doing so ensures that the model has multi-level decision-making capabilities, thereby more accurately identifying abnormal patterns of complex request combinations. Finally, the system calculates the average of all classification results for each sub-feature vector after passing through the entire cascade structure, and uses this average as the target classification result for the sub-feature vector.

[0090] Optionally, after obtaining the target classification results, the system compares these results with the actual class labels corresponding to each sub-feature vector, calculating R error values. This error value reflects the gap between the model's prediction and the actual label and is an important indicator of model accuracy. Based on these R error values, the intelligent processing system can further determine the performance indicators of each decision tree in the initial model. Performance indicators typically include classification accuracy and recall. The calculation of these indicators provides the necessary basis for subsequent weight adjustments.

[0091] Optionally, the intelligent processing system dynamically adjusts the weight of each decision tree in the initial model based on the calculated performance metrics. Specifically, decision trees that perform well in classification are assigned higher weights, while those with larger errors are assigned lower weights. This is done to make the model more inclined to make decisions based on the results of decision trees with better performance, thereby improving the model's overall prediction accuracy. After the weight adjustment is completed, the system updates the initial model, making it an optimized model after one round of iterative training, ready for the next round of training or for actual request combination anomaly scoring.

[0092] Optionally, the intelligent processing system uses an integrated pruning technique of feature vectorization and quantum walk to improve the performance of the cascade random forest. By characterizing the decision tree, evaluating its node number, depth, diversity contribution and margin score, and calculating the margin score using formulas (2) and (3), v is the number of classifiers that correctly classify samples, v' is the number of classifiers that misclassify samples, M is the total number of classifiers, Margin(h) represents the overall margin score of classifier h on the entire data set D, and y i Represents sample x i The true label, that is, x i The correct category to which it actually belongs, I(*) is the indicator function, when h correctly classifies sample x i When (that is, the classification result of classifier h is equal to y i When (I(*) is 1, otherwise I(*) is 0. Formula (2) and formula (3) are as follows:

[0093]

[0094] Optionally, to improve the accuracy of network traffic classification, the intelligent processing system introduces an innovative ensemble learning framework that combines the advantages of deep learning and traditional random forests. In ensemble learning, the weight of each tree is dynamically adjusted to give high-performance models a greater impact on the results and optimize the classification effect. In feature selection, a reinforcement learning algorithm is used to automatically explore the optimal feature combination, overcoming the limitations of traditional methods and improving the quality of the feature set. At the same time, multimodal data fusion technology is introduced to integrate data from different modalities and enhance classification accuracy. To accelerate model training, the application of quantum computing is explored, leveraging its parallel computing advantages to significantly shorten the training time of large-scale data sets. In addition, an emotional context perception module is introduced to understand the context and improve classification accuracy in complex scenarios.

[0095] Optionally, the target model is a cascade forest of classifiers based on an ensemble structure, consisting of a completely random forest and a random forest. During training, each tree generates a probability distribution for each class, dynamically adjusting its weights based on performance to calculate the weighted proportions of the entire forest. The input network traffic data from the previous layer is combined with the output calculation results as input to the next layer. Finally, the three-dimensional vectors output by all forests are averaged, and the maximum value is selected as the final output to achieve network traffic classification.

[0096] As can be seen from the above, the intelligent processing system significantly improves the training efficiency and classification accuracy of the deep forest model by introducing steps such as sub-feature vector selection, cascade classification of multi-layer decision trees, error calculation, and dynamic weight adjustment during model training. The cascade structure design allows the model to integrate multiple layers of information during the classification process, enhancing its ability to understand complex features. Furthermore, the error-based decision tree weight adjustment mechanism ensures that the model can continuously optimize itself, improving the accuracy of identifying abnormal request combinations. This iterative training strategy not only accelerates model convergence but also improves the model's generalization ability across different request types, providing strong support for real-time network traffic monitoring and anomaly detection, and effectively ensuring network security in financial transaction scenarios. Through multiple iterative training, the model is able to self-learn and adjust to the ever-changing network environment and attack patterns, realizing a more intelligent and dynamic network defense mechanism.

[0097] In an optional embodiment, the intelligent processing system obtains R target classification results obtained from each training, and then determines the distribution information of the classification results based on the R target classification results obtained from each training, and then determines the target threshold based on the distribution information of the classification results, wherein the target threshold is used to distinguish whether the network request is an abnormal request.

[0098] Optionally, during each training process, the intelligent processing system will generate R target classification results based on a series of historical request data, where R is an integer greater than or equal to 1. These target classification results are the model's prediction of whether each training request is an abnormal request, representing the model's classification judgment on different training samples. The system needs to record all target classification results generated in each training for subsequent analysis. Next, the intelligent processing system needs to analyze the distribution information of these R target classification results. This process usually involves statistical analysis. The system will calculate statistical indicators such as the frequency distribution, mean, standard deviation, and other statistical indicators of the abnormal request classification results. Through these indicators, a probability distribution graph of the classification results can be drawn, which clearly shows the model's tendency and stability in identifying abnormal requests.

[0099] Optionally, based on the distribution of the classification results, the intelligent processing system sets a target threshold to distinguish whether a network request is an abnormal request. The target threshold is typically determined based on the distribution pattern of the abnormal request classification results and business requirements. For example, the system may select a certain percentile of the abnormal classification results as the threshold. This threshold covers the majority of abnormal requests while minimizing misjudgments of normal requests. Furthermore, given the unique nature of financial transaction scenarios, threshold setting also requires a balance between detection accuracy and system performance, ensuring that as many abnormal behaviors as possible are captured without impacting the normal operation of the system.

[0100] As can be seen from the above steps, a highly efficient anomaly detection mechanism based on a deep learning model is provided for the intelligent processing system. First, by collecting and analyzing the target classification results from each training session, the system accurately grasps the distribution characteristics of abnormal requests, providing a data foundation for subsequent threshold setting. Second, the target threshold determined based on this distribution information effectively distinguishes between normal network requests and abnormal requests, improving the accuracy and real-time performance of anomaly detection. This mechanism not only enhances the model's decision-making capabilities but also ensures that the system can respond promptly to complex and changing network environments, protecting the security of financial transactions. By dynamically adjusting the target threshold, the intelligent processing system can adapt to network traffic changes over time and at different scales, achieving continuous monitoring and prevention of abnormal requests, significantly improving the effectiveness and reliability of the entire network attack detection and prevention system. In practice, this process helps the system more accurately identify potential network attacks, reduces false positives and false negatives, and makes a significant contribution to maintaining the network information security of the financial system.

[0101] In an optional embodiment, when the intelligent processing system detects that the target score value is greater than or equal to the target threshold, it determines that the N network requests in the request combination are abnormal requests; when the intelligent processing system detects that the target score value is less than the target threshold, it determines that the N network requests in the request combination are normal requests.

[0102] Optionally, the intelligent processing system compares the generated target score value with a pre-set target threshold. If the target score value is greater than or equal to the target threshold, the intelligent processing system will immediately determine that the N network requests in the request combination are abnormal and may have been subjected to a network attack. This judgment is based on the abnormal score distribution of the deep forest model and the specific needs of the financial transaction scenario to ensure that the system can respond to potential security threats in a timely manner. Conversely, if the target score value is less than the target threshold, the intelligent processing system considers that the network requests in the request combination are normal. This means that the current network request combination does not show abnormal behavior or signs of attack and can be regarded as safe, and normal network operations and data processing can continue. This step also reflects the accuracy and reliability of the target model in judging the normality of the request combination.

[0103] As can be seen from the above, by setting target thresholds and comparing target scores, the intelligent processing system can quickly and accurately determine abnormal network request states and respond immediately. This scoring threshold-based judgment mechanism, combined with the powerful anomaly detection capabilities of the deep forest model, can effectively identify potential network attacks when processing highly concurrent financial transaction data, reducing response time to security incidents and improving the efficiency and accuracy of overall network defense. In practical applications, this mechanism not only responds to known attack types but also has the potential to identify new attack patterns, further strengthening the network security of the financial industry. By dynamically adjusting the target threshold, the system can also optimize the sensitivity and accuracy of anomaly detection based on changes in the network environment.

[0104] In an optional embodiment, Figure 2 This is a schematic diagram of an optional network request classification method according to an embodiment of the present application, which includes four modules: data acquisition and preprocessing module, feature extraction module (based on CNN), classification module (based on deep forest), and attack detection and defense module. Specifically:

[0105] Data collection and preprocessing module: Data source: An integrated API interface can be used to obtain access requests and transaction request data from financial transactions as raw data. Traffic tools can also be used to capture data tables from the network in real time as raw data. The collected raw data can be defined as real-time traffic data; Real-time traffic data: This part of the data records the detailed information of each network request, including packet header information (protocol type, source IP, destination IP, port number, request time, number of requests, etc.) and load information. Due to the large number of actual network access requests, only a few brief examples can be given below to illustrate the process. Example:

[0106] Network request data A: (TCP, 192.168.1.10, 10.0.0.1, 443, 8080, 2025-01-01 12:00:01, 1, 512 bytes) corresponds to (protocol type, source IP, destination IP, source port number, destination port number, request time, number of requests, payload size);

[0107] Network request data B: (TCP, 192.168.1.10, 10.0.0.1, 443, 8080, 2025-01-01 12:00:02, 1,512 bytes) corresponds to (protocol type, source IP, destination IP, source port number, destination port number, request time, number of requests, payload size);

[0108] Network request data C: (TCP, 192.168.1.10, 10.0.0.1, 443, 8080, 2025-01-01 12:00:03, 1,512 bytes) corresponds to (protocol type, source IP, destination IP, source port number, destination port number, request time, number of requests, payload size);

[0109] After data collection is preprocessed, feature processing is used to extract influential features from the raw data. The data is then divided into two parts: a training dataset and a test dataset. This embodiment constructs time-based feature sequence data. To ensure detection accuracy, the raw data is selected over a 12-day period, for example. The first 10 days of data are used as training data, and the last 2 days of data are used as test data.

[0110] (1) Feature Engineering. This step aims to define important features in the data to classify normal traffic and malicious traffic. The present invention mainly focuses on the number of requests per unit time (abnormally high number of requests may indicate a DDoS attack), the total traffic size per unit time (abnormally high traffic size may indicate a traffic attack), the target IP access concentration (requests are concentrated on a single target IP), and the protocol distribution (abnormal protocol distribution, such as a large number of UDP packets may indicate an amplification attack).

[0111] (2) Input data preparation: convert the preprocessed data into a format suitable for CNN input. In this embodiment, it is converted into a time series matrix. The following steps can be followed to count the above features using a 5-second time window: (192.168.1.10, 3, 1536, 100%, 100%, 0%) corresponding to (source IP, total number of visits, total load size, target IP ratio, TCP protocol ratio, UDP protocol ratio).

[0112] In order to input the above feature data into the CNN model, the above feature data is transformed to adapt to the CNN model, for example, converted to a fixed-size two-dimensional input (such as T×F), where T is the number of time windows (time series) and F is the feature dimension of each time window. Assuming there are multiple time windows, set the maximum and minimum values, and normalize the feature values ​​according to the following formula (total number of visits [0, 1000], total load size [0, 1000000], target IP ratio [0%, 100%], TCP ratio / UDP ratio [0%, 100%]): X normalized =(XX min ) / (X max -X min ), where X normalized represents the normalized data, X min Indicates the minimum value of the setting, X max Indicates the maximum value of the setting. The output matrix example is: [[0.003,0.001536,1.0,1.0,0.0][0.01,0.005,0.9,0.8,0.2][0.002,0.0008,1.0,1.0,0.0]].

[0113] Feature extraction module: Build a specific CNN model for feature extraction.

[0114] Classification Module: After extracting the aforementioned feature vectors, this embodiment uses a modified deep forest algorithm to classify network traffic to detect malicious traffic. Based on the distribution of anomaly scores in the classification results during training, a detection threshold is set to distinguish between normal and malicious traffic.

[0115] Real-time attack detection and defense module: Based on the detection threshold set based on the anomaly score distribution of the classification results, real-time network traffic is classified to detect whether there is malicious traffic. Based on the classification results, the specific attack type of malicious traffic (such as DDoS attacks, malicious scanning, etc.) is identified. When an attack (malicious traffic) is detected, the system automatically generates a corresponding defense strategy, including: blocking the attack source IP, preventing access to the IP address of the malicious traffic source through firewall rules or router policies; traffic restriction, limiting the flow of traffic to the target server to prevent server paralysis due to DDoS or traffic amplification attacks; alarm notification, sending alarm information to the administrator, including attack type, attack source IP, target port, etc.; dynamic adjustment of strategies, updating defense rules in real time according to changes in attack behavior. This achieves the ultimate goal of defending against network traffic attacks.

[0116] In summary, this embodiment combines the above four modules and applies specific CNN and deep forest models to the network attack detection and defense system. The overall summary is as follows:

[0117] 1. Use the data acquisition and preprocessing module to obtain the raw data of the network attack detection system, and parse it to generate structured samples as input for a specific CNN model.

[0118] 2. Receive the two-dimensional traffic matrix from the data preprocessing module and build a specific CNN model in the feature extraction module to automatically extract deep features from the traffic data and capture the complex spatiotemporal patterns of network traffic. The output shape is (1×N), where N is the dimension of the feature vector.

[0119] 3. Receive the feature vector (1×N) extracted by CNN and use the deep forest in the classification module to classify the feature vector extracted by CNN to determine whether the traffic is malicious and further identify the specific attack type.

[0120] 4. The real-time attack detection and defense module responds to attack behaviors in real time based on the classification results and generates corresponding defense strategies, such as blocking the attack source IP, traffic restriction, etc., to protect network security and achieve the ultimate goal of real-time defense against network attacks.

[0121] In this embodiment, the intelligent processing system leverages the powerful feature extraction capabilities of CNNs to extract features from preprocessed data, which are then fed into a deep forest to produce the final detection results. Compared to existing cross-network attack detection solutions, this method offers high detection accuracy, strong generalization capabilities, and no reliance on rules or feature libraries. Deep forests excel in small sample sizes, making them suitable for environments where actual attack samples are scarce. Furthermore, by combining the lightweight features of CNNs and deep forests, they reduce resource consumption, providing more efficient, accurate, and real-time transaction detection capabilities in complex real-world detection environments. This improves the efficiency of the overall detection system and further safeguards network security.

[0122] The present application also provides a network request classification device. It should be noted that the network request classification device of the present application embodiment can be used to execute the network request classification method provided in the present application embodiment. The network request classification device provided in the present application embodiment is introduced below.

[0123] According to an embodiment of the present application, a device for implementing the above-mentioned network request classification method is also provided. Figure 3 is a schematic diagram of an optional network request classification device according to an embodiment of the present application, such as Figure 3 As shown, the apparatus includes: a receiving unit 302 , an extracting unit 303 , a first determining unit 303 and a second determining unit 304 .

[0124] Optionally, the receiving unit 301 is used to receive N network requests within a preset time window, where N is an integer greater than 1; the extraction unit 302 is used to take the N network requests as a request combination and extract the target feature vector of the request combination; the first determination unit 303 is used to input the target feature vector into the target model, and determine the target score value of the request combination based on the target feature vector through the target model, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1; the second determination unit 304 is used to determine the types of the N network requests in the request combination based on the target score value.

[0125] Optionally, the extraction unit 302 includes: a first detection subunit and a first determination subunit. The first detection subunit is configured to detect target information of each network request in the request combination, wherein the target information of each network request includes characteristic attribute information and behavior pattern information of the network request; and the first determination subunit is configured to determine a target feature vector of the request combination based on the target information of each network request in the request combination.

[0126] Optionally, the first determination subunit includes: a first selection module, a first processing module, a first conversion module, and a first determination module. The first selection module is used to perform feature selection on the target information of each network request according to the target feature sequence, and to form a feature set with at least one feature corresponding to each network request to obtain N feature sets corresponding to N network requests, wherein the influence value of the features in the target feature sequence when identifying abnormal requests is greater than a first preset threshold; the first processing module is used to integrate the feature values ​​corresponding to the same features in each feature set to obtain a target feature set; the first conversion module is used to convert the feature values ​​corresponding to all features in the target feature set into a target range, and convert the converted target feature set into a matrix form to obtain a target matrix; the first determination module is used to input the target matrix into the first model and determine the target feature vector of the request combination based on the prior knowledge learned by the first model during the model training phase.

[0127] Optionally, the first determination module includes: a first acquisition submodule, a first determination submodule, a first extraction submodule, a first division submodule, a first training submodule, and a second determination submodule. The first acquisition submodule is used to obtain target information corresponding to multiple historical requests in each of T historical time windows, where T is an integer greater than 1; the first determination submodule is used to treat the target information corresponding to multiple historical requests in each historical time window as a set to obtain T first sets; the first extraction submodule is used to perform feature extraction on the T first sets according to the target feature sequence to obtain T first feature sets; the first division submodule is used to divide the T first feature sets into a model training set and a model verification set; the first training submodule is used to input the model training set and the model verification set into the first initial model for iterative training and verification operations until the number of iterations of the first initial model is greater than a preset number or the training error of the first initial model is lower than a set threshold, and it is determined that the first initial model enters a convergence state, wherein the verification operation is used to verify the performance of the model; the second determination submodule is used to use the first initial model in the convergence state as the first model.

[0128] Optionally, the first training submodule includes: a first extraction component, a first processing component, a first determination component, and a first adjustment component. The first extraction component is used to extract features from the M training sets using the first initial model when there are M training sets in the model training set, to obtain a feature vector corresponding to each training set, wherein M is an integer greater than or equal to 1, and the target layer includes a first preset number of convolution layers and a second preset number of pooling layers; the first processing component is used to input the feature vector corresponding to each training set into the output layer of the first initial model to obtain a classification result for each training set, wherein the classification result is used to characterize whether the historical request corresponding to each training set is an abnormal request; the first determination component is used to determine the error between the classification result corresponding to each training set and the actual category corresponding to each training set, to obtain M error values; the first adjustment component is used to adjust the model parameters of the first initial model according to the M error values.

[0129] Optionally, the first determination unit 303 includes: a first extraction subunit, a first division subunit, and a first training subunit. The first extraction subunit is configured to input the T first sets into the first model for feature extraction to obtain T first feature vectors; the first division subunit is configured to divide each of the T first feature vectors into multiple sub-feature vectors, and use the multiple sub-feature vectors obtained by dividing each first feature vector as a second feature set; and the first training subunit is configured to train the initial model multiple times based on the second feature set until the number of iterations of the initial model exceeds a preset number, thereby obtaining a target model.

[0130] Optionally, the first training subunit includes: a second processing module, a second determination module, a third determination module and a first updating module. Among them, the second processing module is used to select R sub-feature vectors from the second feature set, input the R sub-feature vectors into the initial model for target processing, and obtain R target classification results, where R is an integer greater than 1; wherein the target processing includes: sequentially inputting the R sub-feature vectors into the decision tree in each layer structure of the initial model for classification, until each decision tree in the K-th layer structure of the initial model outputs a classification result, and taking the average value of the classification result corresponding to each sub-feature vector as the target classification result of the sub-feature vector, wherein the input of the classification tree in other layer structures except the first layer structure of the initial model also includes the output of the classification tree in the previous layer structure; the second determination module is used to determine the error between the target classification result corresponding to each sub-feature vector in the R sub-feature vectors and the actual category label corresponding to the sub-feature vector, to obtain R error values; the third determination module is used to determine the performance index of each decision tree in the initial model based on the R error values, and adjust the weight of each decision tree in the initial model according to the performance index; the first update module is used to update the initial model according to the adjusted weight of each decision tree in the initial model.

[0131] Optionally, the network request classification apparatus further includes: a first acquisition unit, a third determination unit, and a fourth determination unit. The first acquisition unit is configured to acquire R target classification results obtained during each training session; the third determination unit is configured to determine distribution information of the classification results based on the R target classification results obtained during each training session; and the fourth determination unit is configured to determine a target threshold based on the distribution information of the classification results, wherein the target threshold is used to distinguish whether a network request is an abnormal request.

[0132] Optionally, the second determining unit 304 includes: a second determining subunit and a third determining subunit. The second determining subunit is configured to determine that the N network requests in the request combination are abnormal requests when detecting that the target score value is greater than or equal to the target threshold; and the third determining subunit is configured to determine that the N network requests in the request combination are normal requests when detecting that the target score value is less than the target threshold.

[0133] According to another aspect of the present application, a computer-readable storage medium is provided, which includes a stored executable program, wherein when the executable program runs, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned network request classification method.

[0134] According to another aspect of the present application, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned method for classifying network requests.

[0135] According to another aspect of an embodiment of the present application, a computer program product is further provided, including computer instructions, which implement the steps of the above-mentioned network request classification method when executed by a processor.

[0136] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0137] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0138] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0139] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0140] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0141] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0142] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for classifying network requests, characterized in that: include: Receive N network requests within a preset time window, where N is an integer greater than 1; Taking the N network requests as a request combination, and extracting a target feature vector of the request combination; Inputting the target feature vector into a target model, and determining a target score value for the request combination based on the target feature vector through the target model, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1; The types of the N network requests in the request combination are determined according to the target score value.

2. The method for classifying network requests according to claim 1, wherein: The N network requests are used as a request combination, and a target feature vector of the request combination is extracted, including: Detecting target information of each network request in the request combination, wherein the target information of each network request includes characteristic attribute information and behavior pattern information of the network request; A target feature vector of the request combination is determined based on target information of each network request in the request combination.

3. The method for classifying network requests according to claim 2, wherein: Determining a target feature vector of the request combination based on target information of each network request in the request combination includes: Performing feature selection on the target information of each network request according to the target feature sequence, and forming at least one feature corresponding to each network request into a feature set, to obtain N feature sets corresponding to the N network requests, wherein the influence value of the features in the target feature sequence when identifying abnormal requests is greater than a first preset threshold; Integrate the feature values ​​corresponding to the same features in each feature set to obtain the target feature set; Converting the eigenvalues ​​corresponding to all features in the target feature set to a target range, and converting the converted target feature set into a matrix form to obtain a target matrix; The target matrix is ​​input into the first model, and the target feature vector of the request combination is determined based on the prior knowledge learned by the first model during the model training phase.

4. The method for classifying network requests according to claim 3, wherein: The first model is obtained by the following steps: Obtain target information corresponding to multiple historical requests in each of T historical time windows, where T is an integer greater than 1; Taking the target information corresponding to the multiple historical requests in each historical time window as a set, obtaining T first sets; Performing feature extraction on the T first sets according to the target feature sequence to obtain T first feature sets; Dividing the T first feature sets into a model training set and a model validation set; Inputting the model training set and the model validation set into a first initial model for iterative training and validation operations until the number of iterations of the first initial model is greater than a preset number or the training error of the first initial model is lower than a set threshold, and determining that the first initial model enters a convergence state, wherein the validation operation is used to validate the performance of the model; The first initial model in the converged state is used as the first model.

5. The method for classifying network requests according to claim 4, wherein: Each training iteration consists of the following steps: When there are M training sets in the model training set, use the target layer of the first initial model to perform feature extraction on the M training sets to obtain a feature vector corresponding to each training set, where M is an integer greater than or equal to 1, and the target layer includes a first preset number of convolutional layers and a second preset number of pooling layers; Inputting the feature vector corresponding to each training set into the output layer of the first initial model to obtain a classification result for each training set, wherein the classification result is used to indicate whether the historical request corresponding to each training set is an abnormal request; Determine the error between the classification result corresponding to each training set and the actual category corresponding to each training set, and obtain M error values; Adjust the model parameters of the first initial model according to the M error values.

6. The method for classifying network requests according to claim 4, wherein: The target model is obtained by the following steps: Inputting the T first sets into the first model for feature extraction to obtain T first feature vectors; Dividing each of the T first eigenvectors into a plurality of sub-eigenvectors, and using the plurality of sub-eigenvectors obtained by dividing each first eigenvector as a second feature set; The initial model is trained multiple times according to the second feature set until the number of iterations of the initial model is greater than a preset number, thereby obtaining the target model.

7. The method for classifying network requests according to claim 6, wherein: Each training session consists of the following steps: Selecting R sub-feature vectors from the second feature set, inputting the R sub-feature vectors into the initial model for target processing, and obtaining R target classification results, where R is an integer greater than 1; The target processing includes: sequentially inputting the R sub-feature vectors into the decision tree in each layer structure of the initial model for classification, until each decision tree in the K-th layer structure of the initial model outputs a classification result, and taking the average value of the classification results corresponding to each sub-feature vector as the target classification result of the sub-feature vector, wherein the input of the classification tree in the layer structure other than the first layer structure of the initial model also includes the output of the classification tree in the previous layer structure; Determine the error between the target classification result corresponding to each sub-feature vector in the R sub-feature vectors and the actual category label corresponding to the sub-feature vector, to obtain R error values; Determining a performance indicator of each decision tree in the initial model based on the R error values, and adjusting a weight of each decision tree in the initial model according to the performance indicator; The initial model is updated according to the adjusted weight of each decision tree in the initial model.

8. The method for classifying network requests according to claim 7, wherein: After iteratively training the initial model according to the second feature set until the number of iterations of the initial model exceeds a preset number and the target model is obtained, the method includes: Obtain the R target classification results obtained from each training; Determining distribution information of classification results based on the R target classification results obtained in each training; A target threshold is determined according to the distribution information of the classification result, wherein the target threshold is used to distinguish whether the network request is the abnormal request.

9. The method for classifying network requests according to claim 8, wherein: Determining the types of the N network requests in the request combination according to the target score value includes: When detecting that the target score value is greater than or equal to the target threshold, determining that the N network requests in the request combination are abnormal requests; When it is detected that the target score value is less than the target threshold, it is determined that the N network requests in the request combination are normal requests.

10. A network request classification device, characterized in that: include: A receiving unit, configured to receive N network requests within a preset time window, where N is an integer greater than 1; an extraction unit, configured to take the N network requests as a request combination and extract a target feature vector of the request combination; a first determining unit, configured to input the target feature vector into a target model, and determine a target score value for the request combination based on the target feature vector through the target model, wherein the target model adopts a K-layer cascade structure, each layer of the structure is composed of multiple decision trees, and the target model is a classification model obtained by dynamically adjusting the weight of each decision tree in the initial model using multiple historical request information, wherein K is an integer greater than 1; A second determining unit is configured to determine types of the N network requests in the request combination according to the target score value.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located executes the network request classification method according to any one of claims 1 to 9.

12. An electronic device, characterized in that: The method comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the network request classification method according to any one of claims 1 to 9.

13. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the network request classification method according to any one of claims 1 to 9 are implemented.