Request header processing method and device, computer equipment and storage medium
By detecting the number of fields, evaluating their value, and prioritizing them in the request header, combined with a circuit breaker mechanism, the problem of insufficient control over the number of fields in request header processing is solved, ensuring the validity and security of the request.
Patent Information
- Application Number
- CN202511052053.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-09-30
AI Technical Summary
In the existing technology, the request header processing method lacks effective control over the number of fields, resulting in resource waste and performance degradation. Especially in the fields of healthcare and financial technology, improper handling of sensitive information may lead to data leakage or system performance degradation.
By obtaining access requests, parsing request headers, detecting the number of fields, and using a pre-trained field value assessment model to determine field priority, and then trimming request headers based on priority, the circuit breaker mechanism is triggered to protect key fields, thus achieving effective control over the number of request header fields.
It effectively reduces the number of fields in the request header, optimizes system performance, and ensures the validity and security of requests, especially in the fields of healthcare and financial technology, ensuring the protection of sensitive information.
Smart Images

Figure CN120729909A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a request header processing method, device, computer equipment, and computer-readable storage medium. Background Art
[0002] With the rapid development of internet technology, the complexity and diversity of network applications are constantly increasing. In modern network communications, HTTP (Hypertext Transfer Protocol) and its extensions (such as HTTPS) are the core mechanisms for communication between clients and servers. As an important component of a request, the HTTP request header carries a wealth of information, such as the user agent, authentication information, and content type. This information is crucial for servers to correctly process requests.
[0003] However, in practical network applications, request header processing faces numerous challenges. On the one hand, malicious users may attack servers by constructing abnormal request headers, such as sending a large number of meaningless fields, resulting in wasted server resources or even crashes. On the other hand, some legitimate requests may contain a large number of unnecessary fields, increasing the burden on network transmission and reducing overall system performance. Currently, traditional request header processing methods mainly focus on simple parsing and validation of request headers, lacking effective control over the number of fields and assessment of field importance. For example, some systems will directly reject requests containing too many fields, but this may misjudge some legitimate requests; while other systems will process all fields indiscriminately, resulting in wasted resources and poor performance.
[0004] In the healthcare sector, with the widespread adoption of electronic medical record systems, telemedicine, and medical IoT devices, large amounts of medical data are transmitted over the network. The transmission of this data requires strict security and efficiency assurance. Request headers may contain sensitive patient information (such as identity authentication information and medical record numbers). Improper handling can lead to data leakage or system performance degradation. Furthermore, network requests from medical devices may contain a variety of auxiliary information, some of which may not be required for every request. Therefore, optimizing network request processing efficiency while ensuring the security of medical information is a critical issue facing the healthcare sector.
[0005] In the FinTech sector, network request processing is crucial. Financial transaction systems must handle a large number of user requests, and these request headers may contain sensitive data such as user account information and transaction authentication information. Malicious attackers may attempt to bypass security checks or cause system overload by constructing complex request headers. Furthermore, FinTech systems must maintain high performance in highly concurrent environments. Excessive field processing increases system burden and slows down transactions. Therefore, optimizing network request processing efficiency while ensuring financial transaction security is a pressing issue in the FinTech sector.
[0006] Based on this, how to provide a request header processing method, device, computer equipment and computer-readable storage medium that can effectively control the number of fields in the request header to ensure the validity of the request is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0007] In view of the above-mentioned deficiencies in the prior art, the purpose of the present invention is to provide a request header processing method, apparatus, computer equipment and computer-readable storage medium, aiming to solve the problem of how to effectively control the number of fields in the request header to ensure the validity of the request.
[0008] In order to achieve the above object, the present invention adopts the following technical solutions:
[0009] In a first aspect, the present invention provides a request header processing method, which includes:
[0010] Get the access request for the target page;
[0011] Parsing the access request and extracting the request header of the access request;
[0012] Detecting the number of fields in the request header; when it is detected that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model; and determining the priority of each field in the request header based on an output result of the field value evaluation model;
[0013] The request header is clipped according to the priority of each field in the request header, and a fuse mechanism is triggered when a target field in the request header needs to be clipped.
[0014] In a second aspect, the present invention provides a request header processing device, comprising:
[0015] The acquisition module is used to obtain the access request for accessing the target page;
[0016] A parsing module, configured to parse the access request and extract a request header of the access request;
[0017] a detection module, configured to detect the number of fields in the request header, and when detecting that the number of fields in the request header exceeds a preset field threshold, input the request header into a pre-trained field value evaluation model, and determine the priority of each field in the request header based on an output result of the field value evaluation model;
[0018] The clipping module is used to clip the request header according to the priority of each field in the request header, and trigger a fuse mechanism when a target field in the request header needs to be clipped.
[0019] In a third aspect, the present invention provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the request header processing method as described above when executing the computer program.
[0020] In a fourth aspect, the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program implements the request header processing method as described above when executed by a processor.
[0021] Compared with the prior art, the present invention provides a request header processing method, apparatus, computer equipment and computer-readable storage medium, wherein an access request for accessing a target page is obtained; the access request is parsed to extract the request header of the access request; the number of fields in the request header is detected, and when it is detected that the number of fields in the request header exceeds a preset field threshold, the request header is input into a pre-trained field value evaluation model, and the priority of each field in the request header is determined according to the output result of the field value evaluation model; the request header is trimmed according to the priority of each field in the request header, and when the target field in the request header needs to be trimmed, a fuse mechanism is triggered; thereby, the present invention can effectively control the number of fields in the request header, thereby ensuring the validity of the request. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] Figure 1 A schematic diagram of an application environment of a request header processing method provided by an embodiment of the present invention.
[0024] Figure 2A flowchart of a request header processing method provided by one embodiment of the present invention.
[0025] Figure 3 A schematic diagram of program modules of a request header processing device provided by one embodiment of the present invention.
[0026] Figure 4 A schematic diagram of the structure of a computer device provided in one embodiment of the present invention.
[0027] Figure 5 Another structural diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0028] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0029] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0030] It will also be understood that the term "and / or" used in the present description and appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0031] As used in the present specification and the appended claims, the term "if" may be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" may be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0032] In addition, in the description of the present specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0033] References to "one embodiment" or "some embodiments" in the present specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present invention. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0034] It should be understood that the order of execution of the steps in the following embodiments does not necessarily mean the order in which they are executed. The order in which each process is executed should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0035] In order to illustrate the technical solution of the present invention, specific embodiments are provided below.
[0036] An embodiment of the present invention provides a request header processing method that can be applied to Figure 1 In the application environment shown, the client and server communicate via a network. The client includes, but is not limited to, PDAs, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud computing devices, personal digital assistants (PDAs), and other computer devices. The server can be a standalone server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0037] See also Figure 2 An embodiment of the present invention provides a request header processing method, wherein the method comprises the following steps:
[0038] S100: Obtain an access request for accessing a target page;
[0039] S200: Parse the access request and extract the request header of the access request;
[0040] S300, detecting the number of fields in the request header. When it is detected that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model, and determining the priority of each field in the request header based on an output result of the field value evaluation model;
[0041] S400: Clip the request header according to the priority of each field in the request header, and trigger a fuse mechanism when a target field in the request header needs to be clipped.
[0042] In specific implementation, the request header processing method of this embodiment realizes effective control of the number of request header fields and ensures the validity of the request through a series of orderly steps. The specific analysis is as follows:
[0043] 1. Field quantity control
[0044] Field Quantity Detection and Threshold Comparison: This method first detects the number of fields in the request header and compares it against a preset field threshold (i.e., the field quantity threshold). This operation can quickly filter out requests with abnormal field quantities and identify potentially malicious or unnecessary fields, providing a basis for subsequent processing and initially achieving field quantity control.
[0045] Field value assessment and priority determination: When the number of fields in the request header exceeds the field threshold (of course, in some embodiments, a comprehensive judgment can also be made in combination with whether the total length of the request header exceeds the length threshold, that is, when it is detected that the number of fields in the request header exceeds the field threshold and / or the total length of the request header exceeds the length threshold), the method further uses the pre-trained field value assessment model to evaluate the value of the fields in the request header and determine the priority of each field based on the assessment results. This step introduces an intelligent assessment mechanism that can distinguish the importance and necessity of fields, providing precise guidance for subsequent cropping operations and avoiding misjudgments that may result from blind cropping.
[0046] Priority-based pruning: Request headers are pruned based on field priority, prioritizing high-priority fields and pruning low-priority fields. This selective pruning approach reduces the number of fields while preserving information critical to request processing. This effectively manages the number of fields in the request header to meet system processing requirements and avoids resource waste and performance degradation caused by excessive fields.
[0047] 2. Ensuring the validity of requests
[0048] Application of an intelligent evaluation model: Fields are evaluated using a pre-trained field value assessment model. This model accurately identifies fields that are truly valuable and necessary for request processing based on extensive data and complex feature learning. This makes clipping more scientific and rational, avoiding situations where request processing may fail due to clipping key fields, thereby ensuring request validity.
[0049] The protective role of the circuit breaker mechanism: During the clipping process, if a target field in the request header (i.e., a field critical to business logic or system security) is detected to be clipped, the circuit breaker mechanism is immediately triggered. The introduction of the circuit breaker mechanism provides a final line of defense for system security and stability. It can promptly interrupt operations that may negatively impact the system, preventing business logic anomalies or security issues caused by clipping critical fields, and ensuring that requests are processed within a safe and controllable range.
[0050] Orderly processing throughout the entire process: From obtaining access requests to parsing and extracting request headers, to field count detection, value assessment, priority determination, pruning, and circuit breaker implementation, the entire approach forms a complete process. Each step is closely linked and coordinated to ensure comprehensive and systematic request header processing. This orderly, full-process approach effectively ensures that requests are properly handled at every stage, ultimately guaranteeing the validity of the request.
[0051] Therefore, this request header processing method achieves effective control over the number of request header fields through field quantity detection, intelligent evaluation, priority-based clipping, and a circuit breaker mechanism, and optimizes the system's performance and security while ensuring the validity of the request.
[0052] It is understandable that the request header processing method provided in the embodiment of the present invention can be applied to request header processing scenarios related to the medical and health field. The following is a specific example:
[0053] Scenario Description
[0054] In the healthcare sector, patients schedule online consultations through telemedicine platforms. The patient's request header may contain multiple fields, such as a token for authentication, a field identifying the patient's device type, a field specifying the request body format, a unique patient identifier, a field specifying the reason for the visit, a field specifying the referring physician, and additional medical information.
[0055] Problem Analysis
[0056] Too many fields: The request header may contain a large number of unnecessary fields, increasing the network transmission burden.
[0057] Key field protection: Certain fields (such as the authentication token field and the patient unique identifier field) are sensitive information and cannot be trimmed.
[0058] Performance optimization: It is necessary to optimize request processing efficiency while ensuring security.
[0059] Application of the method of the present invention
[0060] 1. Obtain access request: The telemedicine platform receives the patient's online consultation request.
[0061] 2. Parse the request header: extract the fields in the request header.
[0062] 3. Field quantity detection: The number of request header fields detected is 10, which exceeds the preset field threshold (assuming it is 8).
[0063] 4. Field Value Evaluation: Input the request header into the pre-trained field value evaluation model. The model output shows:
[0064] Authentication token field: High priority (9 points)
[0065] Device Type Field: Medium Priority (6 points)
[0066] Request body format field: High priority (8 points)
[0067] Patient unique identifier field: High priority (9 points)
[0068] Reason for Visit: Medium Priority (7 points)
[0069] Referral doctor information field: Low priority (3 points)
[0070] Additional Medical Information Field: Low Priority (2 points)
[0071] 5. Field trimming: Trim fields based on priority, trimming low-priority referral physician information fields and additional medical information fields.
[0072] 6. Circuit breaker mechanism: Detects that high-priority sensitive fields (such as the authentication token field and the patient unique identification field) are not trimmed and continues to process the request.
[0073] Effect
[0074] Reduction in the number of fields: After pruning, the number of fields is reduced from 10 to 8, reducing the burden on network transmission.
[0075] Key field protection: High-priority sensitive fields are retained to ensure data security.
[0076] Performance improvement: After trimming unnecessary fields, request processing efficiency is improved and system response time is shortened.
[0077] It is understandable that the request header processing method provided in the embodiment of the present invention can also be applied to request header processing scenarios related to the financial technology field. The following is a specific example:
[0078] Scenario Description
[0079] In the fintech sector, a user initiates a financial transaction through an online trading platform. The request header may contain multiple fields, such as a token for authentication, a field identifying the user's device type, a field specifying the request body format, a unique transaction identifier, a transaction amount, a transaction currency type, information about the source page, and additional transaction information.
[0080] Problem Analysis
[0081] Too many fields: The request header may contain a large number of unnecessary fields, increasing the network transmission burden.
[0082] Key field protection: Certain fields (such as the authentication token field and the transaction unique identifier field) are sensitive information and cannot be trimmed.
[0083] Performance optimization: It is necessary to optimize request processing efficiency while ensuring security.
[0084] Application of the method of the present invention
[0085] 1. Obtain access request: The online trading platform receives the user's transaction request.
[0086] 2. Parse the request header: extract the fields in the request header.
[0087] 3. Field quantity detection: The number of request header fields detected is 12, which exceeds the preset field threshold (assuming it is 10).
[0088] 4. Field Value Evaluation: Input the request header into the pre-trained field value evaluation model. The model output shows:
[0089] Authentication token field: High priority (9 points)
[0090] Device Type Field: Medium Priority (6 points)
[0091] Request body format field: High priority (8 points)
[0092] Transaction unique identification field: High priority (9 points)
[0093] Transaction amount field: High priority (8 points)
[0094] Transaction Currency Type Field: High Priority (8 points)
[0095] Source page information field: Low priority (3 points)
[0096] Additional transaction information field: Low priority (2 points)
[0097] 5. Field trimming: Trim fields based on priority, trimming low-priority source page information fields and additional transaction information fields.
[0098] 6. Circuit breaker mechanism: Detects that high-priority sensitive fields (such as the authentication token field and the transaction unique identifier field) are not trimmed and continues to process the request.
[0099] Effect
[0100] Reduction in the number of fields: After pruning, the number of fields is reduced from 12 to 10, reducing the burden on network transmission.
[0101] Key field protection: High-priority sensitive fields are retained to ensure transaction security.
[0102] Performance improvement: After trimming unnecessary fields, request processing efficiency is improved and system response time is shortened.
[0103] Through the specific application examples in the above two fields, it can be seen that the request header processing method provided by the embodiment of the present invention can effectively control the number of fields in the request header, while ensuring the validity and security of the request and optimizing system performance.
[0104] Furthermore, in one embodiment, the request header processing method, wherein the parsing of the access request and extracting the request header of the access request, specifically comprises the steps of:
[0105] Verifying whether the format of the access request complies with predetermined standards;
[0106] When the format verification of the access request passes, parsing the access request and extracting the request header therein;
[0107] The extracted request header is standardized by removing redundant spaces, unifying the case of field names, and formatting field values.
[0108] In specific implementation, the specific implementation process of this embodiment is roughly as follows:
[0109] Step 1: Verify the format of the access request
[0110] 1. Receive access request:
[0111] Receives a request from the network to access the target page. The request is usually sent in the form of HTTP / HTTPS protocol and contains a request line, request headers, and request body.
[0112] 2. Format Verification:
[0113] Check whether the format of the access request meets the predetermined standards. The verification content includes:
[0114] Whether the request line complies with the HTTP protocol specification (for example, whether it contains the correct request method, URL path, and protocol version).
[0115] Check whether the request header is in the correct format (for example, whether the field name and field value are separated by a colon and whether the field ends with a newline character).
[0116] The request body, if present, conforms to the expected format (for example, for a POST request, check that the Content-Type field is correct).
[0117] If the request format does not meet the predetermined standards, an error response (such as 400 Bad Request) is returned and detailed error information is recorded.
[0118] Step 2: Parse the access request and extract the request header
[0119] 1. Format verification passed:
[0120] When the format of the access request passes the verification, the access request begins to be parsed.
[0121] 2. Extract the request header:
[0122] Extract the request header from the access request. The request header is usually located after the request line until the first blank line (two consecutive newline characters).
[0123] Use line breaks (\r\n) to split the request header into multiple fields. The format of each field is "field name:field value".
[0124] The extracted fields are stored as key-value pairs for easy subsequent processing.
[0125] Step 3: Standardize the request header
[0126] 1. Remove extra spaces:
[0127] Process each extracted field value to remove extra spaces at both ends of the field value. For example, process "value" as "value".
[0128] 2. Unify the case of field names:
[0129] Convert all field names to a consistent case format, usually lowercase. For example, convert "Content-Type" and "content-type" to "content-type" to ensure consistency in field names.
[0130] 3. Format field values:
[0131] Format the field value, for example:
[0132] Decodes URL-encoded field values.
[0133] For field values that contain special characters, escape or normalize them.
[0134] For some fields (such as Content-Length), ensure that their values are in a valid numeric format.
[0135] 4. Store the standardized request header:
[0136] Store the standardized request header fields as key-value pairs for subsequent field quantity detection and value evaluation.
[0137] Through the above process, this embodiment implements format verification of access requests, request header extraction, and standardized processing of request headers. These steps ensure that the request header format is correct, field names are consistent, and field values are formatted. This provides a reliable foundation for subsequent field quantity detection and value assessment, thereby improving the accuracy and efficiency of request processing.
[0138] Furthermore, in one embodiment, the request header processing method, wherein the number of fields in the request header is detected, and when it is detected that the number of fields in the request header exceeds a preset field threshold, the request header is input into a pre-trained field value evaluation model, and the priority of each field in the request header is determined based on the output result of the field value evaluation model, specifically comprises the steps of:
[0139] Load the pre-trained field value assessment model;
[0140] Calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold;
[0141] When the number of fields in the request header exceeds the field threshold, the request header is input into the field value evaluation model;
[0142] Obtain a priority score for each field in the request header output by the field value assessment model, and determine a priority order of the fields in the request header according to the priority score.
[0143] Furthermore, the request header processing method, wherein the step of calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold, specifically comprises the steps of:
[0144] Split the request header into several separate fields using line breaks, and count the number of all fields in the request header;
[0145] The number of fields in the request header is compared with a preset field threshold, and when the number of fields in the request header does not exceed the field threshold, the number of fields in the request header continues to be monitored.
[0146] In specific implementation, the specific implementation process of this embodiment is roughly as follows:
[0147] Step 1: Load the pre-trained field value assessment model
[0148] 1. Model loading:
[0149] When the system starts or before processing a request, load a pre-trained field value estimation model. This model is usually a machine learning model that is used to estimate the value of each field in the request header.
[0150] Ensure that the model is correctly loaded into memory and is ready to receive input data.
[0151] Step 2: Count the number of fields in the request header and compare with the threshold
[0152] 1. Extract the request header:
[0153] Extracts the request headers from the received HTTP request, up to the first blank line (that is, two consecutive newline characters).
[0154] 2. Split the request header and count the number of fields:
[0155] Use newline characters (\r\n) to split the request header into several separate fields.
[0156] The number of fields after segmentation is the total number of fields in the request header.
[0157] 3. Compare the number of fields with the preset threshold:
[0158] Compare the counted field quantity with the preset field threshold.
[0159] If the number of fields does not exceed the preset threshold, the number of fields in the request header continues to be monitored, waiting for the next request or further processing.
[0160] If the number of fields exceeds the preset threshold, proceed to the next step.
[0161] Step 3: Feed the request header into the field value evaluation model
[0162] 1. Prepare input data:
[0163] Arrange the fields and their values in the request header into the input format required by the model. Usually, the model requires field names and field values as input.
[0164] 2. Input the model and get the output:
[0165] Input the sorted request header fields into the pre-trained field value evaluation model.
[0166] Get the priority score for each field output by the model.
[0167] Step 4: Determine the order of priority for the fields
[0168] 1. Analytical model output:
[0169] Parse the output of the field value assessment model to obtain the priority score for each field.
[0170] 2. Sort fields:
[0171] Sorts the fields based on their priority scores. Fields with higher priority scores are sorted first, and fields with lower priority scores are sorted last.
[0172] 3. Storage priority order:
[0173] The sorted fields and their priority order are stored for use in subsequent field pruning operations.
[0174] Through the above process, this embodiment detects the number of request header fields, evaluates the value of the fields, and determines the field priority. These steps provide a foundation for subsequent field clipping and circuit breaking mechanisms, ensuring the efficiency and security of request header processing.
[0175] Furthermore, in one embodiment, the request header processing method, wherein the request header is trimmed according to the priority of each field in the request header, and when the target field in the request header needs to be trimmed, a fuse mechanism is triggered, specifically comprises the steps of:
[0176] Comparing the priority score of each field in the request header with a preset score threshold;
[0177] Marking fields in the request header whose priority scores are lower than the score threshold as clippable fields;
[0178] Each of the clippable fields in the request header is clipped in sequence according to its corresponding priority order, and when it is detected that the target field in the clippable fields needs to be clipped, the fuse mechanism is triggered.
[0179] Furthermore, the request header processing method, wherein the clipping of each of the clippable fields in the request header is performed in sequence according to their corresponding priority order, specifically comprises the steps of:
[0180] sorting the clippable fields according to the priority scores of the clippable fields in the request header, and generating a clipping plan;
[0181] According to the clipping plan, clipping each of the clippable fields in the request header in sequence;
[0182] During the clipping process, the request header after clipping is monitored in real time to see whether it complies with the corresponding protocol specification and does not cause business logic abnormalities.
[0183] Furthermore, the request header processing method, wherein, when it is detected that the target field in the clippable field needs to be clipped, triggering the fuse mechanism, specifically comprises the steps of:
[0184] Detect in real time whether the current croppable field is the target field;
[0185] When it is detected that the current trimmable field is the target field, the fuse mechanism is immediately triggered;
[0186] Among them, the specific actions of the fuse mechanism include: suspending the execution of the access request, returning an error response, and notifying the administrator.
[0187] In specific implementation, the specific implementation process of this embodiment is roughly as follows:
[0188] Step 1: Priority score comparison and marking of trimmable fields
[0189] 1. Loading priority score:
[0190] Get the priority score of each field output by the field value assessment model.
[0191] 2. Comparison score and threshold:
[0192] Compare the priority score of each field with the preset score threshold.
[0193] 3. Mark the trimmable fields:
[0194] If a field's priority score is below a preset score threshold, the field is marked as a clippable field.
[0195] Store all clippable fields in a list for subsequent clipping operations.
[0196] Step 2: Generate a trimming plan and trim fields sequentially
[0197] 1. Generate cutting plan:
[0198] The pruning plan is generated by sorting the pruning fields according to their priority scores. The pruning plan specifies the pruning order for each field, with the fields with the lowest priority being pruned first.
[0199] 2. Crop fields in order:
[0200] According to the trimming plan, the trimmable fields in the request header are trimmed in sequence. The trimming operation can be to completely remove the field or partially trim the length of the field value.
[0201] 3. Real-time monitoring of the trimmed request header:
[0202] During the clipping process, monitor in real time whether the clipped request header complies with the corresponding protocol specifications and does not cause business logic anomalies. For example, check whether the field format and field value are legal, and whether the clipped request header can still be correctly parsed and processed.
[0203] If it is detected that the trimmed request header does not comply with the protocol specification or may cause business logic abnormalities, the trimming operation is suspended and detailed logs are recorded.
[0204] Step 3: Detect the target field and trigger the circuit breaker mechanism
[0205] 1. Real-time detection of target fields:
[0206] During the clipping process, the system checks in real time whether the current clippable field is the target field. Target fields are those that are critical to business logic or system security, such as identity authentication fields and user unique identification fields.
[0207] 2. Triggering the circuit breaker mechanism:
[0208] If it is detected that the current trimmable field is the target field, the circuit breaker mechanism is triggered immediately.
[0209] 3. Specific behavior of the circuit breaker mechanism:
[0210] Pauses the execution of the current access request to prevent potential problems caused by trimming the target field.
[0211] Returns an error response to explain to the client why the request was interrupted.
[0212] Notify the administrator and record detailed log information, including the detailed content of the request, trimmed fields, and the cause of the exception, to alert the administrator for subsequent analysis and processing.
[0213] Through the above process, this embodiment implements priority evaluation, clipping, and triggering of the circuit breaker mechanism for the request header field. These steps ensure that the validity and security of the request are not affected when the field is clipped, while optimizing the processing efficiency of the request header.
[0214] It can be seen from the above method embodiments that the request header processing method provided by the present invention includes: obtaining an access request for accessing a target page; parsing the access request and extracting the request header of the access request; detecting the number of fields in the request header, and when it is detected that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model, and determining the priority of each field in the request header according to the output result of the field value evaluation model; trimming the request header according to the priority of each field in the request header, and triggering a fuse mechanism when the target field in the request header needs to be trimmed. In this way, the method of the present invention can effectively control the number of fields in the request header, thereby ensuring the validity of the request.
[0215] It should be understood that although the present application provides method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-creative work, and these operation steps are not necessarily performed in the order of the embodiments or flowcharts. The order of steps listed in the embodiments or flowcharts is only one way of executing the steps among many steps and does not represent the only execution order. It should be noted that there is not necessarily a certain order between the above steps. Those of ordinary skill in the art can understand from the description of the embodiments of the present invention that in different embodiments, the above steps may have different execution orders, that is, they may be executed in parallel, or they may be executed in an interchangeable manner, etc. Moreover, at least a portion of the steps in the embodiments or flowcharts may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but may be executed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be executed in turn, alternately or synchronously with other steps or at least a portion of the sub-steps or stages of other steps.
[0216] Based on the above method embodiment, please refer to Figure 3 Another embodiment of the present invention further provides a request header processing device, wherein the device includes:
[0217] An acquisition module 11 is used to acquire an access request for accessing a target page;
[0218] The parsing module 12 is used to parse the access request and extract the request header of the access request;
[0219] a detection module 13 for detecting the number of fields in the request header. When it is detected that the number of fields in the request header exceeds a preset field threshold, the detection module 13 inputs the request header into a pre-trained field value evaluation model, and determines the priority of each field in the request header based on the output result of the field value evaluation model;
[0220] The clipping module 14 is configured to clip the request header according to the priority of each field in the request header, and trigger a fuse mechanism when a target field in the request header needs to be clipped.
[0221] Furthermore, in one embodiment, the request header processing device, wherein the parsing of the access request and extracting the request header of the access request specifically includes:
[0222] Verifying whether the format of the access request complies with predetermined standards;
[0223] When the format verification of the access request passes, parsing the access request and extracting the request header therein;
[0224] The extracted request header is standardized by removing redundant spaces, unifying the case of field names, and formatting field values.
[0225] Furthermore, in one embodiment, the request header processing device, wherein the detecting the number of fields in the request header, when detecting that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model, and determining the priority of each field in the request header based on the output result of the field value evaluation model, specifically includes:
[0226] Load the pre-trained field value assessment model;
[0227] Calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold;
[0228] When the number of fields in the request header exceeds the field threshold, the request header is input into the field value evaluation model;
[0229] Obtain a priority score for each field in the request header output by the field value assessment model, and determine a priority order of the fields in the request header according to the priority score.
[0230] Furthermore, in the request header processing device, the step of calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold specifically includes:
[0231] Split the request header into several separate fields using line breaks, and count the number of all fields in the request header;
[0232] The number of fields in the request header is compared with a preset field threshold, and when the number of fields in the request header does not exceed the field threshold, the number of fields in the request header continues to be monitored.
[0233] Furthermore, in one embodiment, the request header processing device, wherein the request header is trimmed according to the priority of each field in the request header, and when the target field in the request header needs to be trimmed, a fuse mechanism is triggered, specifically comprising:
[0234] Comparing the priority score of each field in the request header with a preset score threshold;
[0235] Marking fields in the request header whose priority scores are lower than the score threshold as clippable fields;
[0236] Each of the clippable fields in the request header is clipped in sequence according to its corresponding priority order, and when it is detected that the target field in the clippable fields needs to be clipped, the fuse mechanism is triggered.
[0237] Furthermore, the request header processing device, wherein the clipping of each of the clippable fields in the request header is performed in sequence according to their corresponding priority order, specifically includes:
[0238] sorting the clippable fields according to the priority scores of the clippable fields in the request header, and generating a clipping plan;
[0239] According to the clipping plan, clipping each of the clippable fields in the request header in sequence;
[0240] During the clipping process, the request header after clipping is monitored in real time to see whether it complies with the corresponding protocol specification and does not cause business logic abnormalities.
[0241] Furthermore, the request header processing device, wherein, when detecting that the target field in the clippable field needs to be clipped, triggering the fuse mechanism, specifically includes:
[0242] Detect in real time whether the current croppable field is the target field;
[0243] When it is detected that the current trimmable field is the target field, the fuse mechanism is immediately triggered;
[0244] Among them, the specific actions of the fuse mechanism include: suspending the execution of the access request, returning an error response, and notifying the administrator.
[0245] It should be noted that, in the embodiment of the device of the present invention, the information interaction, execution process and other contents between the above modules are based on the same concept as the embodiment of the method of the present invention. Their specific functions and technical effects can be found in the aforementioned method embodiment part and will not be repeated here.
[0246] Based on the above method embodiment, another embodiment of the present invention further provides a computer device, which can be a server, and its internal structure diagram can be as follows: Figure 4 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the functions or steps on the server side of the request header processing method in any of the above method embodiments are implemented.
[0247] Based on the above method embodiment, another embodiment of the present invention further provides a computer device, which can be a client, and its internal structure diagram can be as follows: Figure 5 As shown. The computer device includes a processor, memory, network interface, display screen and input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the functions or steps of the client side of the request header processing method in any of the above method embodiments are implemented.
[0248] Those skilled in the art will understand that Figure 4 and Figure 5The structural diagram shown in the figure is only a schematic diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more components than shown in the figure, or combine certain components, or have a different component arrangement.
[0249] The processor referred to herein may be a CPU, other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or any conventional processor, etc.
[0250] The memory includes a readable storage medium, an internal memory, etc., wherein the internal memory can be the memory of a computer device, and the internal memory provides an environment for the operation of the operating system and computer-readable instructions in the readable storage medium. The readable storage medium can be a hard disk of the computer device, and in other embodiments, it can also be an external storage device of the computer device, for example, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the computer device. Furthermore, the memory can also include both an internal storage unit of the computer device and an external storage device. The memory is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as the program code of a computer program. The memory can also be used to temporarily store data that has been output or is about to be output.
[0251] Based on the above method embodiments, another embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the request header processing method described in any of the above method embodiments. The computer-readable storage medium may be non-volatile or volatile.
[0252] It should be noted that the above-mentioned functions or steps that can be implemented by computer-readable storage media or computer devices, and the technical effects brought about by the functions / steps, can be found in the relevant descriptions in the aforementioned method embodiments. To avoid repetition, they will not be described one by one here.
[0253] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM). The disclosed memory components or memories of the operating environments described herein are intended to comprise one or more of these and / or any other suitable types of memory.
[0254] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, in the embodiment of the device of the present invention, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual application, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the above-mentioned method embodiment, which will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0255] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0256] In the embodiments provided by the present invention, it should be understood that the disclosed apparatus / computer equipment and methods can be implemented in other ways. For example, the apparatus / computer equipment embodiments described above are merely illustrative. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0257] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0258] It should be noted that if software tools or components other than those of the Company appear in the embodiments of this application, they are merely for illustration and do not represent actual use. The above embodiments are intended only to illustrate the technical solutions of the present invention, not to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some of the technical features therein with equivalents. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.
Claims
1. A request header processing method, characterized in that: include: Get the access request for the target page; Parsing the access request and extracting the request header of the access request; Detecting the number of fields in the request header; when it is detected that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model; and determining the priority of each field in the request header based on an output result of the field value evaluation model; The request header is clipped according to the priority of each field in the request header, and a fuse mechanism is triggered when a target field in the request header needs to be clipped.
2. The request header processing method according to claim 1, characterized in that: The parsing of the access request and extracting the request header of the access request includes: Verifying whether the format of the access request complies with predetermined standards; When the format verification of the access request passes, parsing the access request and extracting the request header therein; The extracted request header is standardized by removing redundant spaces, unifying the case of field names, and formatting field values.
3. The request header processing method according to claim 1, characterized in that: The detecting the number of fields in the request header, and when it is detected that the number of fields in the request header exceeds a preset field threshold, inputting the request header into a pre-trained field value evaluation model, and determining the priority of each field in the request header according to an output result of the field value evaluation model, includes: Load the pre-trained field value assessment model; Calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold; When the number of fields in the request header exceeds the field threshold, the request header is input into the field value evaluation model; Obtain a priority score for each field in the request header output by the field value assessment model, and determine a priority order of the fields in the request header according to the priority score.
4. The request header processing method according to claim 3, characterized in that: Calculating the number of fields in the request header and comparing the number of fields in the request header with a preset field threshold includes: Split the request header into several separate fields using line breaks, and count the number of all fields in the request header; The number of fields in the request header is compared with a preset field threshold, and when the number of fields in the request header does not exceed the field threshold, the number of fields in the request header continues to be monitored.
5. The request header processing method according to claim 3, characterized in that: The step of clipping the request header according to the priority of each field in the request header and triggering a fuse mechanism when a target field in the request header needs to be clipped includes: Comparing the priority score of each field in the request header with a preset score threshold; Marking fields in the request header whose priority scores are lower than the score threshold as clippable fields; Each of the clippable fields in the request header is clipped in sequence according to its corresponding priority order, and when it is detected that the target field in the clippable fields needs to be clipped, the fuse mechanism is triggered.
6. The request header processing method according to claim 5, characterized in that: The step of clipping the clippable fields in the request header in order of their corresponding priorities includes: sorting the clippable fields according to the priority scores of the clippable fields in the request header, and generating a clipping plan; According to the clipping plan, clipping each of the clippable fields in the request header in sequence; During the clipping process, the request header after clipping is monitored in real time to see whether it complies with the corresponding protocol specification and does not cause business logic abnormalities.
7. The request header processing method according to claim 5, characterized in that: When it is detected that the target field in the trimmable field needs to be trimmed, triggering the fuse mechanism includes: Detect in real time whether the current croppable field is the target field; When it is detected that the current trimmable field is the target field, the fuse mechanism is immediately triggered; Among them, the specific actions of the fuse mechanism include: suspending the execution of the access request, returning an error response, and notifying the administrator.
8. A request header processing device, characterized in that: include: The acquisition module is used to obtain the access request for accessing the target page; A parsing module, configured to parse the access request and extract a request header of the access request; a detection module, configured to detect the number of fields in the request header, and when detecting that the number of fields in the request header exceeds a preset field threshold, input the request header into a pre-trained field value evaluation model, and determine the priority of each field in the request header based on an output result of the field value evaluation model; The clipping module is used to clip the request header according to the priority of each field in the request header, and trigger a fuse mechanism when a target field in the request header needs to be clipped.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the request header processing method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the request header processing method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Financial product field updating method and device, equipment and storage medium
CN113868270A
Abnormal behavior detection method and device based on transaction data, equipment and medium
CN115965468A
Data cutting method and system based on restful interface
CN117407093A
Data processing method and device and electronic equipment
CN118796823A
Methods and Apparatus for Improving Header Compression
US20110231577A1