Method, device and equipment for identifying abnormal access entity for firewall

By generating text with smaller data volumes in network access logs and using machine learning models to identify abnormal access entities, the problems of semantic fragmentation and information loss in existing technologies are solved, achieving higher recognition accuracy and efficiency.

CN120785626APending Publication Date: 2025-10-14BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511064730.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Existing technologies have difficulty in effectively identifying abnormal access entities in network access behaviors, especially in large amounts of log records. Language models are prone to semantic fragmentation and information loss, resulting in low recognition accuracy.

Method used

By splicing the first text from the log records, a second text with a smaller data volume is generated according to a predetermined strategy, and a machine learning model is used for recognition, including compressing the text data based on a strategy based on resource type, number of accesses and differences, and adapting the window of the machine learning model.

Benefits of technology

The accuracy of machine learning models in identifying abnormal access entities has been improved, noise interference has been reduced, and the accuracy and efficiency of identification have been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785626A_ABST
    Figure CN120785626A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method, a device and equipment for identifying an abnormal access entity for a firewall and a storage medium. The method comprises the following steps: determining a log record of at least one access request from a first access entity from a log set of access requests for network resources; determining a first text describing the at least one access request based on the log record of the at least one access request; according to at least one predetermined strategy, a second text describing the at least one access request is generated based on the first text, and the data size of the second text is smaller than that of the first text; and based on the second text, utilizing a machine learning model to determine an identification result about whether the first access entity is an abnormal access entity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Example embodiments of the present disclosure generally relate to the field of computers, and more particularly, to a method, apparatus, device, computer-readable storage medium, and computer program product for identifying abnormal access entities for a firewall. Background Art

[0002] With the widespread use of the internet, access to various network resources generates an increasing amount of network access behavior data. Within this vast amount of network access behavior data, there may be abnormal access. For example, repeated or continuous access to resources using robots or automated programs increases the processing load on resource servers. Accurately identifying abnormal access from this massive amount of behavior data is an urgent problem. Summary of the Invention

[0003] In a first aspect of the present disclosure, a method for identifying abnormal access for a firewall is provided, comprising: determining, from a log collection of access requests for network resources, a log record of at least one access request from a first access entity; determining, based on the log record of the at least one access request, a first text describing the at least one access request; generating, based on the first text, a second text describing the at least one access request in accordance with at least one predetermined policy, the second text having a smaller data volume than the first text; and determining, based on the second text, using a machine learning model, an identification result as to whether the first access entity is an abnormal access entity.

[0004] In a second aspect of the present disclosure, a device for identifying abnormal access of a firewall is provided, comprising: a log record determination module, configured to determine a log record of at least one access request from a first access entity from a log set of access requests for network resources; a first text determination module, configured to determine a first text describing at least one access request based on the log record of at least one access request; a second text generation module, configured to generate a second text describing at least one access request based on the first text in accordance with at least one predetermined policy, the data volume of the second text being smaller than the data volume of the first text; and an identification result determination module, configured to determine an identification result of whether the first access entity is an abnormal access entity based on the second text using a machine learning model.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. When executed by the at least one processor, the instructions cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has stored thereon computer-executable instructions that are executable by a processor to implement the method of the first aspect.

[0007] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method of the first aspect.

[0008] It should be understood that nothing in the Summary is to be construed as a limitation on the scope of the embodiments of the present disclosure. Other features of the present disclosure will be apparent from the following description, along with the associated drawings. BRIEF DESCRIPTION OF DRAWINGS

[0009] The above and other features, aspects, and advantages of embodiments of the present disclosure will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings. In the drawings, like reference numerals refer to like elements, wherein:

[0010] Figure 1 a schematic diagram illustrating an example environment in which embodiments of the present disclosure can be implemented;

[0011] Figure 2 a flowchart illustrating a process for identifying an abnormal access entity according to some embodiments of the present disclosure;

[0012] Figure 3 a schematic diagram illustrating an example architecture for identifying an abnormal access entity according to some embodiments of the present disclosure;

[0013] Figure 4 a block diagram of an apparatus for identifying an abnormal access entity according to some embodiments of the present disclosure; and

[0014] Figure 5 a block diagram of an apparatus capable of implementing one or more embodiments of the present disclosure. DETAILED DESCRIPTION

[0015] Embodiments of the present disclosure will be described below in greater detail with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be construed as being limited to the embodiments set forth herein; rather, these embodiments are provided so as to more completely and thoroughly understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.

[0016] In the description of embodiments of the disclosure, the term "comprising" and similar terms are to be interpreted as open-ended, i.e., "including but not limited to". The term "based on" is to be interpreted as "based, at least in part, on". The term "one embodiment" or "the embodiment" is to be interpreted as "at least one embodiment". The term "some embodiments" is to be interpreted as "at least some embodiments". Other explicit and implicit definitions can also be included below.

[0017] In this document, unless explicitly stated, performing a step "in response to A" does not mean performing the step immediately after A, but can include one or more intermediate steps.

[0018] It can be understood that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, the obtaining or use of the data) should comply with the requirements of the corresponding laws and regulations and relevant provisions.

[0019] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type of personal information involved in the present disclosure, the use range, the use scenario, etc. should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.

[0020] For example, in response to receiving the active request of the user, prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will need to obtain and use the personal information of the user, so that the user can voluntarily choose whether to provide the personal information to the software or hardware such as electronic device, application program, server or storage medium, etc. performing the operation of the technical solutions of the present disclosure according to the prompt information.

[0021] As an optional but non-limiting implementation manner, in response to receiving the active request of the user, the manner of sending prompt information to the user can be, for example, the manner of pop-up window, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0022] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0023] As used herein, the term "model" can learn the association between corresponding inputs and outputs from training data, so that after training is completed, corresponding outputs can be generated for given inputs. The generation of the model can be based on machine learning technology. Deep learning is a machine learning algorithm that processes inputs and provides corresponding outputs by using multiple layers of processing units. A neural network model is an example of a model based on deep learning. In this article, "model" may also be referred to as "machine learning model", "learning model", "machine learning network" or "learning network", and these terms are used interchangeably in this article.

[0024] Figure 1 1 shows a schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented. Figure 1 As shown, example environment 100 may include electronic device 110 and server 130 .

[0025] In the environment 100, a user 132 can access some network resources through an associated electronic device 110 (e.g., a terminal device). For example, the user 132 can send an access request to the resource server for accessing the network resource. The server 130 can obtain (e.g., collect) a log collection of access requests from the electronic device 110. It should be understood that although a single user 132 and a single electronic device 110 are shown, the environment 100 may include multiple users and corresponding electronic devices. In some embodiments, these users may be referred to as access entities. Access entities may include, for example, users and automated programs (also referred to herein as abnormal access entities or robots). The user 132 can access some resources in the network resource pool 120 through the associated electronic device 110. The network resource pool 120 may include one or more resources 122-1, 122-2, ..., 122-M. For ease of discussion, one or more resources 122-1, 122-2, ..., 122-M may be collectively or individually referred to as resources 122.

[0026] Server 130 can receive multiple access requests from different electronic devices. Among these access requests received by server 130, some may be issued by unusual access entities. For example, automated programs may perform batch registrations, brute force verification code cracking, or crawl sensitive data. In environment 100, server 130 can identify unusual access entities (e.g., unusual users, robots) by converting log records of these access requests into text.

[0027] The electronic device 110 can be any type of mobile terminal, fixed terminal, or portable terminal including a mobile handset, a tablet computer, a laptop computer, a notebook computer, a netbook computer, a smart device, a media player, a navigation device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combinations of the aforementioned and the like, including wearables, accessories, peripherals and the like of such devices, or any combinations thereof. In some embodiments, the electronic device 110 can also be capable of supporting any type of interface to the user (such as "wearable" circuitry, etc.).

[0028] The server 130 can be a standalone physical server, a server cluster composed of multiple physical servers, or a distributed system, and can also be a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks, and basic cloud computing services such as big data and artificial intelligence platforms. The server 130 may, for example, include a computing system / server, such as a mainframe, an edge computing node, a computing device in a cloud environment, and the like. The server 130 can provide background services for applications in the electronic device 110 that support resource request services.

[0029] A communication connection can be established between the server 130 and the electronic device 110. The communication connection can be established by wired or wireless means. The communication connection can include, but is not limited to, a Bluetooth connection, a mobile network connection, a Universal Serial Bus (USB) connection, a Wireless Fidelity (WiFi) connection, and the like, and embodiments of the present disclosure are not limited in this regard. In embodiments of the present disclosure, the server 130 and the electronic device 110 can achieve signaling interaction through the communication connection therebetween.

[0030] It should be understood that the structure and function of the various elements in the environment 100 are described for illustrative purposes only, and do not imply any limitation on the scope of the present disclosure.

[0031] With the rapid development of application programs (e.g., Web) that interact through large networks such as the Internet or a local area network, some automated programs have emerged. Automated programs affect the server through batch registration, brute force cracking of verification codes, and data crawling. Therefore, for access requests from the same access entity, it is expected to be able to identify whether the access entity belongs to an abnormal access entity (e.g., an automated program). In some solutions, a language model (LM) can be used to perform end-to-end discrimination on the access request to determine whether the access entity of the access request is an abnormal access entity.

[0032] However, since the log records of access requests are usually stored in the form of a table, it is easy for a language model to cause semantic fragmentation when identifying whether an access entity is an abnormal access entity based on the log records. For example, due to the lack of contextual connection between table fields, semantic fragmentation is easy to occur during the analysis process of the language model. Accordingly, due to the large number of contents in the log records, in the process of using the language model to identify abnormal access entities based on log records stored in the form of a table, it is easy to exceed the token length acceptable to the language model. Traditionally, the log records can also be simply truncated or randomly sampled. In this way, important temporal relationships are easily lost, resulting in the language model being unable to fully learn the differences between abnormal access entities and normal access entities.

[0033] In view of this, according to some embodiments of the present disclosure, an improved scheme for identifying abnormal access is proposed. According to the scheme of the embodiment of the present disclosure, a log record of at least one access request from a first access entity is determined from a log set of access requests to network resources. Based on the log record of at least one access request, a first text describing the at least one access request is determined. Further, according to at least one predetermined strategy, a second text describing the at least one access request is generated based on the first text. The amount of data in the second text is less than the amount of data in the first text. Subsequently, based on the second text, a machine learning model is used to determine an identification result as to whether the first access entity is an abnormal access entity.

[0034] In this way, the log records corresponding to access requests from the same access entity are first concatenated into a first text. Then, based on the larger first text, a smaller second text is generated according to a predetermined strategy. This significantly compresses the number of tokens while retaining key behavioral transition information, enabling adaptation to the window of a machine learning model (e.g., a language model). Furthermore, based on the smaller second text, the input length can be significantly reduced and key semantics can be highlighted, thereby improving the recognition accuracy of the machine learning model.

[0035] Various example implementations of the present disclosure will be described in detail below with reference to the accompanying drawings. Figure 2 A schematic diagram of an example process 200 for identifying abnormal access entities according to some embodiments of the present disclosure is shown. Figure 1 The example process 200 is described with respect to the environment 100 of FIG.

[0036] In the discussion of process 200, for better understanding, Figure 3 Some embodiments of the present disclosure for identifying abnormal access are explained. Figure 3A schematic diagram of an example architecture 300 for identifying abnormal access entities according to some embodiments of the present disclosure is shown.

[0037] In this article, an access entity (e.g., a user or automated program) can access network resources through an electronic device. During the process of an access entity accessing network resources, a large amount of log information can be generated. In some scenarios, a user may utilize an automated program (also referred to as a robot in this article) to access certain network resources multiple times, for example, by registering in large quantities, cracking verification codes, crawling data, and so on, to access limited network resources. Therefore, for security reasons, it is necessary to identify abnormal access entities from a large number of access requests.

[0038] In view of this, in this article, the log records corresponding to the access requests from the same access entity can be spliced ​​into a first text with natural language semantics. Then, the first text can be compressed into a second text according to a predetermined strategy. The server 130 can use a machine learning model to identify whether the access entity is an abnormal access entity based on the compressed second text. In some examples, each access request of the access entity can correspond to a behavior. The sequence can indicate the access behavior of the access entity to the resource recorded in chronological order within a certain time period. For example, on a website, each step of the access entity's behavior from entering the website to leaving the website can be recorded as an access entity behavior, thereby forming a behavior sequence of the access entity. The behavior sequence can be used to analyze the behavior patterns and interests of the access entity.

[0039] In some embodiments, the machine learning model used may include a generative model, which can generate the desired output content based on the input information and the generation requirements. For example, the second text and the generation requirements indicating the generation of the recognition result can be provided to the machine learning model to output the recognition result as to whether the access source is an abnormal access source. In some embodiments, the machine learning model may include at least a large language model (LLM). The large language model can receive a model input in a textual modality (e.g., natural language and / or machine language), and can obtain a corresponding model output based on the model input and the prompt word. The prompt word here can indicate the generation requirements, thereby guiding the machine learning model to generate the desired recognition result. In some embodiments, the machine learning model may include a multimodal model, which can receive a model input in a textual modality (e.g., natural language and / or machine language) and a model input in a non-textual modality (e.g., image, voice, video, etc.), thereby obtaining a model output.

[0040] like Figure 2As shown, in box 210, the server 130 can determine the log record of at least one access request from the first access entity from the log collection of access requests for network resources. In some embodiments, the access entity can be the source object that actively initiates the access request, for example, it can include but is not limited to the device that initiates the access, program (for example, an automated program), user, account or other type of entity, etc. In some embodiments, multiple access requests respectively include values ​​on multiple dimensions. In some examples, the values ​​on multiple dimensions may include field values ​​of multiple fields included in the access request. That is, each access request in the multiple access requests may include multiple fields, and each field has its corresponding field value. As Figure 3 As shown, the server 130 can determine the log records of access requests 315, 316, and so on from the log records of multiple access requests for network resources from the access entity 132 (also referred to as the first access entity in this article).

[0041] refer to Figure 3 Describe some examples of multiple dimensions. Figure 3 As shown, the multiple dimensions may include an access time dimension 311, such as a timestamp field. Accordingly, the value of the access time dimension 311 included in the access request 315 may be, for example, 1001. Alternatively or additionally, the multiple dimensions may include an access address dimension 312, such as an Internet Protocol address (IP address). Accordingly, the value of the access address dimension 312 included in the access request 315 may be, for example, 180.XX.XX. Alternatively or additionally, the multiple dimensions may include a cookie 314. Accordingly, the value of the cookie 314 included in the access request 315 may be, for example, XXXXX. A cookie may indicate data stored on a user's local device by certain websites for user identification and session tracking. In some examples, the cookie may be stored in the form of a text file. Alternatively or additionally, the multiple dimensions may also include a request path 315, such as a root directory accessed by the user. Accordingly, the value of the request path 315 included in the access request 315 may be, for example, / A / BX. Alternatively or additionally, the multiple dimension information may include a user agent (User-Agent) for identifying information such as a client device, an operating system, a browser, etc. Accordingly, the value of the access time dimension 311 included in the access request 315 may be, for example, XXXX.

[0042] At block 220, the server 130 may determine a first text describing the at least one access request based on the log record of the at least one access request. Figure 3As shown, server 130 may concatenate access requests 315, 316, and so on into text 321 (also referred to herein as first text). In some examples, server 130 may concatenate the access requests from access entity 132 into text 321 in chronological order (e.g., ascending chronological order or any other appropriate order). In some embodiments, text 321 may be text with natural language semantics.

[0043] In some embodiments, reference Figure 3 For access request 315 in at least one access request, server 130 may concatenate the values ​​of access request 315 in multiple dimensions into a text segment 322 describing access request 315. For example, the format of text segment 322 may be "IP: 180.XX.XX, RequestPath: / Catcha / ..." or any other appropriate format. Similarly, for access request 316 in at least one access request, server 130 may concatenate the values ​​of access request 316 in multiple dimensions into a text segment 323 describing access request 316. For example, the format of text segment 323 may be "IP: 180.XX.XX, RequestPath: / Login.aspx" or any other appropriate format.

[0044] Furthermore, server 130 sorts access requests 315, 316, and so on according to their values ​​in the time dimension. Server 130 then concatenates text segments 322, 323, and so on, describing access requests 315, 316, and so on, into text 321 in this order. In this way, by concatenating these access requests into text 321 in chronological order based on their values ​​in the time dimension, the log records corresponding to these access requests are effectively converted into text 321. This ensures temporal and semantic integrity.

[0045] References Figure 2 and Figure 3 Describes how to determine the first text (eg, text 321). Figure 2 and Figure 3 To describe how to compress the text 321 into the second text.

[0046] At block 230, server 130 generates a second text describing at least one access request based on the first text according to at least one predetermined policy. The second text has a smaller data volume than the first text. In some embodiments, server 130 may compress text 321 into a smaller second text according to the predetermined policy. This smaller second text significantly reduces input length and highlights key semantics, thereby improving the recognition accuracy of the machine learning model.

[0047] like Figure 3 As shown, in some embodiments, server 130 may generate a second text describing the access request from access entity 132 based on text 321 according to resource type-based removal policy 341. Resource type-based removal policy 341 may instruct removal of access requests for access to resources of a predetermined type, for example, by deleting a text segment in the first text indicating a static resource.

[0048] Alternatively or additionally, in some embodiments, server 130 may generate, based on text 321, a second text describing an access request from accessing entity 132 in accordance with access count-based filtering policy 342. Access count-based filtering policy 342 may indicate filtering access requests based on the access count of the accessing entity. If server 130 determines that the number of accesses (e.g., 1 or any other appropriate number) by accessing entity 132 to a network resource is less than an access count threshold, the text indicating the access request by accessing entity 132 may be deleted.

[0049] Alternatively or additionally, in some embodiments, the server 130 may generate a second text describing the access request from the access entity 132 based on the text 321 according to a difference-based recording strategy 343. The difference-based recording strategy 343 may indicate that information about the access request is recorded based on the differences between different access requests. For example, in the case where different access requests have the same values ​​on certain dimensions, the server 130 may delete from the text 321 the text fragment indicating one of the access requests on these dimensions. In the case where different access requests have different values ​​on certain dimensions, the server 130 may retain from the text 321 the text fragment indicating these dimensions. Thus, by performing a reduction operation on the first text according to different predetermined strategies, a second text with a smaller amount of data can be obtained. In this way, key semantics can be highlighted and the recognition accuracy of the machine learning model can be improved.

[0050] The following describes in detail how to generate the second text based on the text 321 according to the above predetermined strategy. In some embodiments, the server 130 can generate the second text according to a combination of a removal strategy 341 based on resource type, a filtering strategy 342 based on access count, and a recording strategy 343 based on differences.

[0051] The following first describes how to generate a second text based on text 321 according to a resource type-based removal policy 341. In some embodiments, resource types may include static resources, such as, but not limited to, images, .js, and .css. Resource types may also include dynamic resources, such as, but not limited to, server-side portals (e.g., .aspx, .php, .do, etc.).

[0052] In some embodiments, the server 130 can determine a first set of access requests for accessing static resources and a second set of access requests for accessing dynamic resources from the access requests from the access entity 132. Furthermore, the server 130 can delete the text fragments used to describe the first set of access requests from the text 321. Then, the server 130 can determine the second text based on the text fragments used to describe the second set of access requests in the text 321. In some examples, the server 130 can identify and discard the text fragments indicating static resources from the text 321, and only retain the text fragments indicating dynamic resources. In this way, without losing key information, the input data to be provided to the machine learning model can be reduced, thereby improving the accuracy of the machine learning model's recognition.

[0053] The following further describes how to generate a second text based on text 321 according to filtering policy 342 based on the number of accesses. In some embodiments, server 130 may determine whether the number of access requests from accessing entity 132 is greater than a threshold number. If server 130 determines that the number of access requests is greater than the threshold number, text 321 may be reduced to the second text. For example, if server 130 determines that the number of access requests from accessing entity 132 to a network resource (i.e., the number of accesses, such as 1 or any other appropriate number) is less than the threshold number, text indicating access requests from accessing entity 132 may be deleted.

[0054] In some examples, server 130 may combine the behaviors indicated by some access requests of access entity 132 into the same behavior sequence. Therefore, if server 130 determines that the length of the behavior sequence of access entity 132 is less than a length threshold, it may delete the text indicating the behavior sequence. In the case of fine-tuning a machine learning model (as will be described below), if the number of accesses to a certain sample is too small, the annotation credibility of such a sample is also insufficient. In this way, by deleting such samples, the interference of noise on the fine-tuning of the machine learning model can be reduced, which can effectively avoid reducing the quality of the samples used to train the machine learning model.

[0055] The following further describes how to generate a second text based on text 321 according to difference-based recording strategy 343. For ease of discussion, the following description will take a first access request (eg, access request 315) and a second access request (eg, access request 316) that are adjacent in time as an example.

[0056] In some embodiments, the server 130 may determine whether the access request 315 and the access request 316 from the access entity 132 have dimensions with the same values ​​in multiple dimensions. If the server 130 determines that the access request 315 and the access request 316 have the same values ​​in certain dimensions, the server 130 may delete the values ​​of the access request 316 (or the access request 315) in these dimensions from the text 321. For example, assuming that the value "180.XX.XX" of the access request 315 in the access address dimension 312 is the same as the value "180.XX.XX" of the access request 316 in the access address dimension 312, the value "180.XX.XX" of one of the access requests in the access address dimension 312 may be deleted from the text 321 to determine the second text. For another example, assuming that the request path of the access request 315 is the same as the request path of the access request 316, the text segment indicating the access path of one of the access requests may be deleted from the text 321 to determine the second text.

[0057] In some embodiments, if server 130 determines that access request 315 and access request 316 have different values ​​in other dimensions, server 130 may retain text fragments in text 321 indicating the values ​​in these dimensions. In some examples, if server 130 determines that access request 315 and access request 316 have different values ​​in dimension A (e.g., the "Referer" field) (e.g., access request 315 originates from page A, and access request 315 originates from page B), server 130 may retain the values ​​of access request 315 and access request 316 in this dimension included in text 321, thereby determining the second text. The "Referer" field can be used to record the source page of the access request.

[0058] In some examples, if server 130 determines that access request 315 and access request 316 have different values ​​for dimension B (e.g., the "status" field) (e.g., the "status" field of access request 315 is BB, and the "status" field of access request 316 is AA), server 130 may retain the value of access request 315 and the value of access request 316 for this dimension included in text 321, thereby determining a second text. The "status" field can be used to record status information of the access request.

[0059] That is, in this embodiment, server 130 can compare adjacent access requests line by line for text 321, and omit key-value pairs whose field contents remain unchanged, recording only the changes. This differentiated recording allows the machine learning model to pay more attention to state changes and abnormal jumps, thereby improving the accuracy of the machine learning model's recognition.

[0060] The above describes compressing a first text into a second text according to at least one predetermined strategy. It should be understood that the above different strategies can be used in combination. For example, one or more access requests can be removed according to the resource type-based removal strategy 341. Then, the information of access entities with a small number of accesses can be filtered according to the access count-based filtering strategy 342. Finally, text reduction can be performed according to the difference-based recording strategy 343.

[0061] In the disclosed embodiment, only compressed text data is used, so there is no need to modify the underlying log structure or database design. This allows the machine learning model to more accurately identify whether the access entity is abnormal.

[0062] The following will continue to refer to Figure 2 and Figure 3 To describe how to determine the recognition result of whether the access entity is an abnormal access entity.

[0063] In box 240, the server 130 uses a machine learning model based on the second text to determine the recognition result of whether the first access entity is an abnormal access entity. The machine learning model can be a large model, such as a large language model (LLM). In some embodiments, the server 130 can input the compressed second text into the fine-tuned machine learning model to obtain the recognition result for the access entity 132. The machine learning model can output the confidence probability that the access entity 132 belongs to a normal access entity and the confidence probability that it belongs to an abnormal access entity through the key tags or prompt words in the attention mechanism. Based on the second text with a smaller amount of data, the input length can be greatly reduced and the key semantics can be highlighted, thereby improving the accuracy of identifying abnormal access entities.

[0064] like Figure 3 As shown, for access requests corresponding to access entity 1 and access entity 2, server 130 may input the compressed text corresponding to access entity 1 and access entity 2 into a machine learning model to generate a label 341 for access entity 1 and a label 342 for access entity 2. Label 341 may indicate that access entity 1 is a normal access entity, and label 342 may indicate that access entity 2 is an abnormal access entity.

[0065] In some embodiments, the server 130 may fine-tune the machine learning model based on the text sample compressed according to a predetermined strategy. The specific details of compressing the first text sample into the second text sample according to the predetermined strategy can be referred to the above description of compressing the first text into the second text, and the present disclosure will not go into details here. In some embodiments, the server 130 may obtain a reference result as to whether the first access entity is an abnormal access entity. The reference result may, for example, indicate the label corresponding to the first access entity, such as whether it belongs to an abnormal access entity or a normal access entity. In some examples, the reference result may be the actual result corresponding to the first access entity. Further, the server 130 may update the machine learning model based on the difference between the recognition result determined by the second text sample and the reference result. Thus, by fine-tuning the machine learning model using the compressed text, the recognition accuracy of the machine learning model can be improved.

[0066] In summary, by following a predetermined strategy, a smaller second text can be generated based on a larger first text. This significantly compresses the number of tokens while preserving key behavioral transition information, enabling adaptation to the window of a machine learning model (e.g., LLM). Furthermore, based on the smaller second text, the input length can be significantly reduced while highlighting key semantics, thereby improving the recognition accuracy of the machine learning model.

[0067] The embodiments of the present disclosure also provide corresponding devices for implementing the above methods or processes.

[0068] Figure 4 1 shows a schematic structural block diagram of an apparatus 400 for identifying abnormal access entities according to certain embodiments of the present disclosure. The apparatus 400 may be implemented as or included in the server 130. Each module / component in the apparatus 400 may be implemented by hardware, software, firmware, or any combination thereof.

[0069] like Figure 4As shown, the device 400 includes a log record determination module 410, which is configured to determine a log record of at least one access request from a first access entity from a log set of access requests for network resources. The device 400 also includes a first text determination module 420, which is configured to determine a first text describing at least one access request based on the log record of at least one access request. The device 400 also includes a second text generation module 430, which is configured to generate a second text describing at least one access request based on the first text in accordance with at least one predetermined strategy, and the data volume of the second text is smaller than the data volume of the first text. The device 400 also includes an identification result determination module 440, which is configured to determine the identification result of whether the first access entity is an abnormal access entity based on the second text using a machine learning model. By following a predetermined strategy, a second text with a smaller data volume can be generated based on a first text with a larger data volume. In this way, the number of tokens is significantly compressed while retaining key behavior transfer information, and the window of the machine learning model (e.g., language model LM) can be adapted.

[0070] In some embodiments, the at least one predetermined policy includes at least one of the following: a resource type-based removal policy, which instructs the removal of access requests for accessing resources of a predetermined type; a filtering policy based on access counts, which instructs the filtering of access requests based on the access count of the accessing entity; or a difference-based recording policy, which instructs the recording of access request information based on the differences between different access requests. In this way, based on the smaller second text, the input length can be significantly reduced and key semantics can be highlighted, thereby improving the recognition accuracy of the machine learning model.

[0071] In some embodiments, at least one predetermined policy includes a removal policy based on resource type, where the resource type includes static resources or dynamic resources. Furthermore, the second text generation module 430 is further configured to determine, from the at least one access request, a first set of access requests for accessing static resources and a second set of access requests for accessing dynamic resources; remove text segments describing the first set of access requests from the first text; and determine the second text based on the text segments describing the second set of access requests in the first text. This reduces the input data required for the machine learning model without losing critical information, thereby improving the accuracy of the machine learning model's recognition.

[0072] In some embodiments, at least one predetermined policy includes a filtering policy based on the number of access requests, and the second text generation module 430 is further configured to determine whether the number of at least one access request is greater than a threshold; and in response to the number of at least one access request being greater than the threshold, reduce the first text to the second text. In this way, the interference of noise on the fine-tuning of the machine learning model can be reduced, effectively avoiding degradation of the quality of samples used to train the machine learning model.

[0073] In some embodiments, each of the at least one access request includes values ​​across multiple dimensions, at least one predetermined policy includes a difference-based recording policy, and the second text generation module 430 is further configured to, for a first access request and a second access request that are temporally adjacent in the at least one access request, determine whether the first access request and the second access request have the same value across the multiple dimensions; in response to determining that the first access request and the second access request have the same value across at least one first dimension among the multiple dimensions, remove the value of the second access request across the at least one first dimension from the first text; and determine the second text based on the removed first text. In this way, by differentially recording, the machine learning model can pay more attention to state transitions and abnormal jumps, thereby improving the accuracy of the machine learning model's recognition.

[0074] In some embodiments, the multiple dimensions include at least one second dimension, the first access request and the second access request have different values ​​for the at least one second dimension, and the second text includes a text segment indicating the at least one second dimension. In this way, by differentiating the records, the machine learning model can focus more on state transitions and abnormal jumps.

[0075] In some embodiments, first text determination module 420 is further configured to, for at least one access request, combine the values ​​of the access request in multiple dimensions into a text segment describing the access request; sort the at least one access request based on the value of the at least one access request in the time dimension; and, based on the sort, combine the corresponding text segments describing the at least one access request into the first text. In this way, by combining the access requests in chronological order into text 321 based on the values ​​of the access request in the time dimension, the log records corresponding to the access requests can be effectively converted into text 321. Furthermore, temporal and semantic integrity can be ensured.

[0076] In some embodiments, the method is performed during the training phase of the machine learning model, and the apparatus 400 further includes a model updating module configured to obtain a reference result regarding whether the first access entity is an abnormal access entity; and update the machine learning model based on the difference between the recognition result and the reference result. Thus, by fine-tuning the machine learning model using compressed text, the recognition accuracy of the machine learning model can be improved.

[0077] The units and / or modules included in the device 400 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units and / or modules can be implemented using software and / or firmware, such as machine executable instructions stored on a storage medium. In addition to or as an alternative to machine executable instructions, some or all of the units and / or modules in the device 400 can be implemented at least in part by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0078] It should be understood that one or more steps in the above method can be performed by a suitable electronic device or combination of electronic devices. Such an electronic device or combination of electronic devices may include, for example, Figure 1 Server 130 in.

[0079] Figure 5 1 shows a block diagram of an electronic device 500 in which one or more embodiments of the present disclosure may be implemented. Figure 5 The illustrated electronic device 500 is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 5 The electronic device 500 shown can be used to implement Figure 1 Server 130.

[0080] like Figure 5 As shown, electronic device 500 is in the form of a general electronic device. Components of electronic device 500 may include, but are not limited to, one or more processors 510 or processing units, memory 520, storage device 530, one or more communication units 540, one or more input devices 550, and one or more output devices 560. Processor 510 may be a real or virtual processor and is capable of performing various processes according to programs stored in memory 520. In a multi-processor system, multiple processors execute computer-executable instructions in parallel to increase the parallel processing capabilities of electronic device 500.

[0081] The electronic device 500 typically includes a plurality of computer storage media. Such media can be any available media accessible to the electronic device 500, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 520 can be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 530 can be a removable or non-removable medium and can include a machine-readable medium, such as a flash drive, a disk, or any other medium that can be used to store information and / or data and can be accessed within the electronic device 500.

[0082] The electronic device 500 may further include additional removable / non-removable, volatile / non-volatile storage media. Figure 5 As shown in FIG, a magnetic disk drive for reading from or writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk") and an optical disk drive for reading from or writing to a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data media interfaces. Memory 520 may include a computer program product 525 having one or more program modules configured to perform various methods or actions of various embodiments of the present disclosure.

[0083] The communication unit 540 enables communication with other electronic devices via a communication medium. Additionally, the functions of the components of the electronic device 500 can be implemented in a single computing cluster or multiple computing machines that can communicate via a communication connection. Thus, the electronic device 500 can operate in a networked environment using a logical connection with one or more other servers, a network personal computer (PC), or another network node.

[0084] Input device 550 may be one or more input devices, such as a mouse, keyboard, or trackball. Output device 560 may be one or more output devices, such as a display, a speaker, or a printer. Electronic device 500 may also communicate with one or more external devices (not shown) via communication unit 540 as needed, such as a storage device, a display device, or the like, with one or more devices that allow a user to interact with electronic device 500, or with any device that allows electronic device 500 to communicate with one or more other electronic devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).

[0085] According to an exemplary implementation of the present disclosure, a computer-readable storage medium is provided, on which computer-executable instructions are stored, wherein the computer-executable instructions are executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the method described above.

[0086] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0087] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine such that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0088] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.

[0089] The flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to multiple implementations of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a part for a module, program segment or instruction, and a part for a module, program segment or instruction comprises one or more executable instructions for realizing the logical function of the specification. In some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be realized by a special hardware-based system that performs the function or action of the specification, or can be realized by a combination of special hardware and computer instructions.

[0090] While various implementations of the present disclosure have been described above, the foregoing description is intended to be illustrative, not exhaustive, and not limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is selected to best explain the principles of the implementations, their practical applications, or improvements to existing technologies, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. A method for identifying abnormal access entities for a firewall, comprising: Determining, from a log set of access requests to network resources, a log record of at least one access request from a first access entity; determining, based on the log record of the at least one access request, first text describing the at least one access request; generating, based on the first text and in accordance with at least one predetermined policy, a second text describing the at least one access request, wherein the amount of data in the second text is smaller than the amount of data in the first text; as well as Based on the second text, a machine learning model is used to determine an identification result as to whether the first access entity is an abnormal access entity.

2. The method according to claim 1, wherein the at least one predetermined policy comprises at least one of the following: A resource type-based removal policy, wherein the resource type-based removal policy indicates removal of access requests to resources of a predetermined type. A filtering policy based on access counts, wherein the filtering policy based on access counts indicates filtering access requests according to the access counts of the access entity, or A difference-based recording policy indicates recording information of access requests based on differences between different access requests.

3. The method of claim 1 , wherein the at least one predetermined policy comprises a removal policy based on a resource type, the resource type comprises a static resource or a dynamic resource, and determining the second text based on the first text comprises: determining, from the at least one access request, a first group of access requests for accessing the static resource and a second group of access requests for accessing the dynamic resource; removing, from the first text, text segments describing the first set of access requests; and The second text is determined based on a text segment in the first text that describes the second group of access requests.

4. The method according to claim 1, wherein the at least one predetermined policy comprises a filtering policy based on the number of accesses, and determining the second text based on the first text comprises: determining whether the number of the at least one access request is greater than a threshold number; as well as In response to the number of the at least one access request being greater than the threshold number, the first text is reduced to the second text.

5. The method of claim 1 , wherein each of the at least one access request comprises values ​​on multiple dimensions, the at least one predetermined policy comprises a difference-based recording policy, and determining the second text based on the first text comprises: For a first access request and a second access request that are adjacent in time among the at least one access request, determining whether the first access request and the second access request have dimensions with the same value among the plurality of dimensions; In response to determining that the first access request and the second access request have the same value in at least one first dimension of the plurality of dimensions, removing the value of the second access request in the at least one first dimension from the first text; as well as The second text is determined based on the removed first text. 6 . The method of claim 5 , wherein the plurality of dimensions include at least one second dimension, the first access request and the second access request have different values ​​on the at least one second dimension, and the second text includes a text segment indicating the at least one second dimension.

7. The method of claim 1 , wherein determining first text describing the at least one access request comprises: For an access request in the at least one access request, concatenating values ​​of the access request in multiple dimensions into a text segment describing the access request; sorting the at least one access request based on a value of the at least one access request in a time dimension; as well as According to the order, corresponding text segments describing the at least one access request are spliced ​​into the first text.

8. The method according to claim 1, wherein the method is performed during a training phase of the machine learning model, and the method further comprises: Obtaining a reference result regarding whether the first access entity is an abnormal access entity; as well as Based on the difference between the recognition result and the reference result, the machine learning model is updated.

9. A device for identifying abnormal access in a firewall, comprising: a log record determination module configured to determine, from a log set of access requests to network resources, a log record of at least one access request from a first access entity; a first text determination module configured to determine a first text describing the at least one access request based on the log record of the at least one access request; a second text generating module configured to generate, based on the first text and in accordance with at least one predetermined policy, a second text describing the at least one access request, wherein the amount of data in the second text is smaller than that in the first text; as well as The recognition result determination module is configured to determine the recognition result of whether the first access entity is an abnormal access entity based on the second text using a machine learning model.

10. An electronic device comprising: at least one processor; as well as At least one memory is coupled to the at least one processor and stores instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 8 when executed by the at least one processor.

11. A computer-readable storage medium having computer-executable instructions stored thereon, wherein the computer-executable instructions can be executed by a processor to implement the method according to any one of claims 1 to 8.

12. A computer program product comprising computer executable instructions, wherein the computer executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • HTTP request exception detection method and system

    CN111585955A

  • Abnormal access detection method and device, electronic equipment and storage medium

    CN114650187A

  • Interface access processing method and device, computer equipment and storage medium

    CN117909729A