Method, device and equipment for identifying automatic access attack of firewall

By integrating and completing the behavioral sequences in network access logs and combining multi-dimensional correlation and machine learning models, the problem of the inability to identify automated access attacks in existing technologies is solved, achieving higher recognition accuracy and system robustness.

CN120785627AActive Publication Date: 2025-10-14BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511065175.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-10-14
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

Existing technologies make it difficult to accurately identify network resource access attacks carried out by robots or automated programs, especially when the access entity frequently changes its IP address or crosses labels or domains, which causes the behavior sequence to be split and makes it impossible to effectively identify abnormal access entities.

Method used

By integrating and completing the behavioral sequences in network access log information, using multi-dimensional correlation to divide access requests, combining IP addresses, time intervals and cookie IDs, the behavioral sequences of access entities are reconstructed, and machine learning models are used to identify automated access attackers.

Benefits of technology

It improves the accuracy of identifying automated access attacks, significantly enhances the completeness of behavior sequences and the robustness of the recognition system, and enables more accurate identification of abnormal access entities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785627A_ABST
    Figure CN120785627A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method, a device and equipment for identifying an automatic access attack for a firewall, and a storage medium. The method comprises: based on log information of network resources, determining a plurality of access requests for the network resources, the plurality of access requests respectively comprising information in multiple dimensions; dividing the plurality of access requests into a plurality of groups of access requests based on the association degree of the plurality of access requests on at least one of the plurality of dimensions; determining a plurality of integrated behavior sequences respectively corresponding to the plurality of groups of access requests based on the access time of each group of access requests in the plurality of groups of access requests; determining at least one complemented behavior sequence corresponding to the at least one access entity, respectively, by performing behavior complementation on at least one integrated behavior sequence of the plurality of integrated behavior sequences; and identifying an automated access aggressor in the at least one access entity based on the at least one complemented behavior sequence.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Example embodiments of the present disclosure generally relate to the field of computers, and in particular, to a method, apparatus, device, computer-readable storage medium and computer program product for identifying automated access attacks for a firewall. BACKGROUND

[0002] With the popularity of the Internet, there are more and more network access behavior data generated by accessing various network resources. Among a large amount of network access behavior data, there may be abnormal access. For example, multiple or continuous access to resources by robots or automated programs will increase the processing load of the resource server. How to correctly identify automated access attacks from a large amount of behavior data is a problem to be solved. SUMMARY

[0003] In a first aspect of the present disclosure, a method for identifying automated access attacks for a firewall is provided, comprising: determining, based on log information of a network resource, a plurality of access requests to the network resource, the plurality of access requests respectively including information in a plurality of dimensions; dividing, based on a correlation degree of the plurality of access requests in at least one of the plurality of dimensions, the plurality of access requests into a plurality of groups of access requests; determining, based on access times of each group of access requests in the plurality of groups of access requests, a plurality of integrated behavior sequences respectively corresponding to the plurality of groups of access requests, an integrated behavior sequence in the plurality of integrated behavior sequences including access behaviors to the network resource at a plurality of time points; determining at least one completed behavior sequence respectively corresponding to at least one access entity by performing behavior completion on at least one integrated behavior sequence in the plurality of integrated behavior sequences; and identifying an automated access attacker in the at least one access entity based on the at least one completed behavior sequence.

[0004] In a second aspect of the present disclosure, there is provided an apparatus for identifying automated access attacks for a firewall, comprising: an access request determination module configured to determine, based on log information of the network resource, multiple access requests for a network resource, each of the multiple access requests including information on multiple dimensions; a multiple-group access request division module configured to divide the multiple access requests into multiple groups of access requests based on the correlation of the multiple access requests on at least one of the multiple dimensions; an integrated behavior sequence determination module configured to determine, based on the access time of each group of access requests in the multiple groups of access requests, multiple integrated behavior sequences corresponding to the multiple groups of access requests, each integrated behavior sequence in the multiple integrated behavior sequences including access behaviors to the network resource at multiple time points; a completed behavior sequence determination module configured to determine, by performing behavior completion on at least one integrated behavior sequence in the multiple integrated behavior sequences, at least one completed behavior sequence corresponding to at least one access entity; and an automated access attacker identification module configured to identify an automated access attacker in at least one access entity based on the at least one completed behavior sequence.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. When executed by the at least one processor, the instructions cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present disclosure, a computer-readable storage medium is provided, wherein computer-executable instructions are stored on the computer-readable storage medium, and the computer-executable instructions can be executed by a processor to implement the method of the first aspect.

[0007] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising computer-executable instructions, wherein the computer-executable instructions implement the method of the first aspect when executed by a processor.

[0008] It should be understood that the content described in this summary section is not intended to limit the key features or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. In the accompanying drawings, the same or similar reference numerals represent the same or similar elements, wherein:

[0010] Figure 1 A schematic diagram illustrating an example environment in which embodiments of the present disclosure can be implemented;

[0011] Figure 2 A flowchart illustrating a process for identifying automated access attacks according to some embodiments of the present disclosure is shown;

[0012] Figure 3 A schematic diagram illustrating an example architecture for identifying automated access attacks according to some embodiments of the present disclosure is shown;

[0013] Figure 4 A block diagram illustrating an apparatus for identifying automated access attacks according to some embodiments of the present disclosure; and

[0014] Figure 5 A block diagram of a device capable of implementing one or more embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0015] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0016] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may be included below.

[0017] Herein, unless explicitly stated otherwise, executing a step “in response to A” does not mean executing the step immediately after “A” but may include one or more intermediate steps.

[0018] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) must comply with the requirements of relevant laws, regulations and relevant provisions.

[0019] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0020] For example, in response to receiving a user's active request, a prompt message is sent to the user to clearly remind the user that the operation requested to be performed will require obtaining and using the user's personal information, so that the user can independently choose whether to provide personal information to the electronic device, application, server or storage medium and other software or hardware that performs the operation of the technical solution of the present disclosure based on the prompt message.

[0021] As an optional but non-limiting implementation, in response to receiving a user's active request, a prompt message may be sent to the user, for example, in the form of a pop-up window, in which the prompt message may be presented in text form. Furthermore, the pop-up window may also include a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0022] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0023] As used herein, the term "model" can learn the association between corresponding inputs and outputs from training data, so that after training is completed, corresponding outputs can be generated for given inputs. The generation of the model can be based on machine learning technology. Deep learning is a machine learning algorithm that processes inputs and provides corresponding outputs by using multiple layers of processing units. A neural network model is an example of a model based on deep learning. In this article, "model" may also be referred to as "machine learning model", "learning model", "machine learning network" or "learning network", and these terms are used interchangeably in this article.

[0024] Figure 1 1 shows a schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented. Figure 1 As shown, example environment 100 may include electronic device 110 and server 130 .

[0025] In the environment 100, a user 132 can access some network resources through an associated electronic device 110 (e.g., a terminal device). For example, the user 132 can send an access request for accessing a network resource to a server of the resource. The server 130 obtains (e.g., collects) the access request from the electronic device 110. It should be understood that although a single user 132 and a single electronic device 110 are shown, the environment 100 can include multiple users and corresponding electronic devices. A user can be one example of an access entity. In embodiments of the present disclosure, an access entity can be a source object that initiates an access request actively, which can include, but is not limited to, a device that initiates an access, a program (e.g., an automated program), a user, an account, or other types of entities, and the like. In this document, an automated program (which can also be referred to as an automated access attacker, an abnormal access entity, or a robot. The user 132 can access some resources in a network resource pool 120 through the associated electronic device 110. The network resource pool 120 can include one or more resources 122-1, 122-2, …, 122-M. For ease of discussion, the one or more resources 122-1, 122-2, …, 122-M can be referred to collectively or individually as resources 122.

[0026] The server 130 can obtain multiple access requests from different electronic devices. Among these access requests obtained by the server 130, there can be abnormal access requests issued by an automated access attacker. For example, batch registration by an automated program, brute force cracking of a verification code, crawling of sensitive data. In the environment 100, the server 130 can determine an automated access attacker (e.g., an abnormal user, a robot) based on integration of behavior sequences corresponding to these access requests.

[0027] The electronic device 110 can be any type of mobile terminal, fixed terminal, or portable terminal including a mobile handset, a tablet computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination thereof, including accessories and peripherals of these devices, or any combination thereof. In some embodiments, the electronic device 110 can also support any type of interface to a user (such as "wearable" circuitry, etc.).

[0028] The server 130 can be a standalone physical server, a server cluster composed of multiple physical servers, or a distributed system, and can also be a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks, and basic cloud computing services such as big data and artificial intelligence platforms. The server 130 can include, for example, a computing system / server such as a mainframe, an edge computing node, a computing device in a cloud environment, and the like. The server 130 can provide background services for applications in the electronic device 110 that support resource request services.

[0029] A communication connection can be established between the server 130 and the electronic device 110. The communication connection can be established by wired or wireless means. The communication connection can include, but is not limited to, a Bluetooth connection, a mobile network connection, a Universal Serial Bus (USB) connection, a Wireless Fidelity (WiFi) connection, and the like, and embodiments of the present disclosure are not limited in this regard. In embodiments of the present disclosure, the server 130 and the electronic device 110 can achieve signaling interaction through the communication connection therebetween.

[0030] It should be understood that the structure and function of the various elements in the environment 100 are described for illustrative purposes only, without implying any limitation on the scope of the present disclosure.

[0031] With the rapid development of application programs (for example, Web) that interact through large networks such as the Internet or local area networks, some automated programs have emerged. Automated programs affect the server through batch registration, brute force cracking of verification codes, crawling of data, and the like. Conventionally, abnormal access can be identified based on detection of network access logs. For example, a single identifier (for example, an Internet Protocol address) can be used to divide requests into sessions. Then, an abnormal access can be identified by a classification model.

[0032] However, for access entities that frequently change Internet Protocol (IP) addresses, the behavior sequence of the same access entity is split into multiple short fragment sequences. In this case, the above-mentioned method cannot accurately identify abnormal access entities. In addition, for the above-mentioned scenario, even if cookies or other information are used, the cross-label, cross-domain, or cross-period behavior of the same access entity will still be split. Therefore, the above-mentioned method cannot accurately identify abnormal access entities.

[0033] In view of this, according to some embodiments of the present disclosure, an improved scheme for identifying automated access attacks is proposed. According to the scheme of the embodiment of the present disclosure, based on the log information of the network resource, multiple access requests for the network resource are determined, and the multiple access requests respectively include information on multiple dimensions. Based on the correlation of the multiple access requests in at least one dimension among the multiple dimensions, the multiple access requests are divided into multiple groups of access requests; based on the access time of each group of access requests in the multiple groups of access requests, multiple integrated behavior sequences corresponding to the multiple groups of access requests are determined, and the integrated behavior sequences in the multiple integrated behavior sequences include access behaviors to the network resource at multiple time points. By performing behavior completion on at least one integrated behavior sequence in the multiple integrated behavior sequences, at least one completed behavior sequence corresponding to at least one access entity is determined. Based on the at least one completed behavior sequence, the automated access attacker in the at least one access entity is identified.

[0034] In this way, by integrating and completing behavioral sequences, the completeness of the restored user's behavioral sequence can be significantly improved. This allows for analysis of more realistic and continuous behavioral sequences based on the integrated and completed behavioral sequences. Consequently, these integrated and completed behavioral sequences can be used to analyze features across multiple dimensions, thereby improving the accuracy of identifying automated access attackers.

[0035] Various example implementations of the present disclosure will be described in detail below with reference to the accompanying drawings. Figure 2 A schematic diagram of an example process 200 for identifying automated access attacks according to some embodiments of the present disclosure is shown. Figure 1 The example process 200 is described with respect to the environment 100 of FIG.

[0036] In the discussion of process 200, for better understanding, Figure 3 Some embodiments of the present disclosure for identifying abnormal access are explained. Figure 3 A schematic diagram of an example architecture 300 for identifying automated access attacks according to some embodiments of the present disclosure is shown.

[0037] In this article, an access entity (e.g., user 132) can access network resources through an electronic device. In the process of a user accessing network resources, a large amount of log information can be generated. In some scenarios, a user may use an automated program (also referred to as an automated access attacker, an abnormal access entity, or a robot in this article) to access certain network resources multiple times, such as accessing limited network resources through a large number of registrations, cracking verification codes, crawling data, etc. Therefore, for security reasons, it is necessary to identify the automated access attacker from a large number of access requests. In view of this, in this article, the automated access attacker can be identified by integrating and completing the behavior sequence of the access entity. The behavior sequence can indicate the access behavior of the access entity to the resource recorded in chronological order within a certain time period. For example, on a website, each step of the access entity's behavior from entering the website to leaving the website can be recorded as an access entity behavior, thereby forming an access entity behavior sequence. The behavior sequence can be used to analyze the behavior patterns and interests of the access entity.

[0038] like Figure 2 As shown, in block 210, the server 130 determines multiple access requests for the network resource based on the log information of the network resource. In some embodiments, the multiple access requests respectively include information on multiple dimensions. In some examples, the information on multiple dimensions may indicate multiple fields included in the access request. That is, each access request in the multiple access requests may include multiple fields. Figure 3 As shown, the server 130 can determine access requests 315 , 316 , and so on for network resources from the log information obtained.

[0039] refer to Figure 3 Describe some examples of multiple dimensions. Figure 3 As shown, the multiple dimensions may include an access time dimension, such as a timestamp 311. Alternatively or additionally, the multiple dimensions may include an access address dimension, such as an Internet Protocol (IP address) 312. Alternatively or additionally, the multiple dimensions may include a cookie dimension 314. Cookies may indicate data stored on a user's local device by certain websites in order to identify the user and conduct session tracking. In some examples, cookies may be stored in the form of text files. Alternatively or additionally, the multiple dimensions may also include a request path (Request Path) 315, which may be used to record the root directory accessed by the user, for example. Alternatively or additionally, the multiple dimensional information may include a user agent (User-Agent) for identifying information such as the client device, operating system, and browser. In this way, information based on multiple dimensions may facilitate subsequent integration and completion of the behavioral sequence of the same access entity.

[0040] At block 220, the server 130 divides the plurality of access requests into a plurality of groups of access requests based on a correlation of the plurality of access requests in at least one of a plurality of dimensions. As an example, the server 130 can determine the plurality of groups of access requests according to a correlation of the plurality of access requests in an access time dimension and an access address dimension. As an example, the server 130 can determine the plurality of groups of access requests according to a correlation of the plurality of access requests in a cookie dimension. How the plurality of groups of access requests are determined will be described below with reference to the accompanying drawings. In this way, the accuracy of the integrated behavior sequences can be improved according to the correlation in the plurality of dimensions.

[0041] In some embodiments, for the access address (e.g., IP address) dimension, the server 130 can determine at least two first access requests of the plurality of access requests that have a same access address. If an access time interval between the two first access requests is less than a predetermined time interval, the at least two first access requests are divided into a group of access requests of the plurality of groups of access requests. As an example, referring to Figure 3 , the server 130 can determine at least two access requests of the plurality of access requests that have a same IP address, e.g., the access request 315 and the access request 316. Further, if an access time difference between the access request 315 and the access request 316 is less than a predetermined time interval, the server 130 can divide the access request 315 and the access request 316 into a same group of access requests of the plurality of groups of access requests. In this way, it can be facilitated to merge the behaviors corresponding to each access request of the group of access requests into a same behavior sequence. In some examples, the predetermined time interval can be configured via a user, e.g., 1 minute or any other suitable time interval. In this way, by dividing the access requests according to the address dimension, the completeness of the restored behavior sequences of the access entity can be improved.

[0042] In some embodiments, for the cookie dimension, the server 130 can determine whether the identities in the cookies of at least two second access requests of the plurality of access requests are the same. If the identities in the cookies of the at least two second access requests are the same, the at least two second access requests are merged into one integrated behavior sequence of the plurality of integrated behavior sequences. In some examples, the identity in the cookie can include a cookie ID.

[0043] As an example, referring to Figure 3, the server 130 extracts cookie ID 321, such as _gid, GA1.2XXX, etc., from the log information corresponding to the multiple access requests. Assuming that the cookie ID 321 of access request 315 and access request 316 is the same, access request 315 and access request 316 can be divided into the same group of access requests. Furthermore, the behaviors corresponding to each group of access requests in the group of access requests can be merged into the same behavior sequence. In some examples, if different IP addresses have the same cookie ID, access requests with the same identifier can be merged into the same sequence. Therefore, by grouping access requests based on Cookie ID, the completeness of the behavior sequence of the restored access entity can be improved.

[0044] At block 230, server 130 determines a plurality of consolidated behavior sequences corresponding to the plurality of access requests, based on the access time of each access request in the plurality of access requests. The consolidated behavior sequences in the plurality of consolidated behavior sequences include access behaviors to network resources at a plurality of time points. In some embodiments, server 130 may determine the consolidated behavior sequence corresponding to each access request in each group of access requests based on the access time of each access request in the group. In some examples, server 130 may standardize the time format of the access requests it determines and sort the access requests in each group of access requests in a chronological order (e.g., ascending chronological order or any other suitable order).

[0045] In some examples, server 130 can sort the access requests in each group of access requests in chronological order. Server 130 can then organize the access requests in the group of access requests into an integrated behavior sequence corresponding to the group of access requests based on the sorting results. For example, each access request corresponds to an access behavior in the integrated behavior sequence. Thus, by integrating the behavior sequences, the completeness of the restored user behavior sequence can be improved, thereby increasing the accuracy of identifying automated access attackers.

[0046] References Figure 2 and Figure 3 This article describes how to determine consolidated behavior sequences. In some scenarios, multiple consolidated behavior sequences may still contain behavior sequences belonging to the same access entity. To address this situation, this article describes how to perform behavior completion on some consolidated behavior sequences. This complete behavior sequence facilitates more accurate identification of automated access attackers.

[0047] The following will continue to refer to Figure 2 and Figure 3 To describe how to perform behavior completion on an integrated behavior sequence.

[0048] At block 240, the server 130 determines at least one completed behavior sequence respectively corresponding to the at least one access entity by performing behavior completion on at least one of the plurality of integrated behavior sequences. In some embodiments, the server 130 can combine at least two of the plurality of integrated behavior sequences into one of the at least one completed behavior sequence based on at least respective sequence lengths of the plurality of integrated behavior sequences.

[0049] In some embodiments, the server 130 can determine a long behavior sequence and a short behavior sequence from the integrated behavior sequences. Accordingly, the server 130 can determine a sequence template corresponding to the long behavior sequence. Then, the server 130 can supplement the short behavior sequence into the long behavior sequence corresponding to the sequence template based on a matching degree between the short behavior sequence and the sequence template. In this way, the method of behavior sequence completion according to the long behavior sequence template can realize complete behavior sequence reconstruction. The long behavior sequence can refer to an integrated behavior sequence satisfying a first preset condition. In some examples, the first preset condition can include that the integrated behavior sequence length is greater than a predetermined length, or any other appropriate preset condition. The short behavior sequence can refer to an integrated behavior sequence satisfying a second preset condition. In some examples, the second preset condition can include that the integrated behavior sequence length is less than a predetermined length, or any other appropriate preset condition.

[0050] Referring to Figure 3 Suppose the server 130 determines that the integrated behavior sequences include an integrated behavior sequence 331 corresponding to the access entity 1, an integrated behavior sequence 332 corresponding to the access entity 2, and a behavior sequence 333 corresponding to the access entity 3. The server 130 can determine a long behavior sequence 331 (also referred to as the integrated behavior sequence 331 herein) and a long behavior sequence 333 (also referred to as the integrated behavior sequence 333 herein) from these integrated behavior sequences, which satisfy the first preset condition. The server 130 can determine a short behavior sequence 332 (also referred to as the integrated behavior sequence 332 herein) from these integrated behavior sequences, which satisfies the second preset condition.

[0051] In some embodiments, the server 130 can determine a behavior sequence template respectively corresponding to the long behavior sequence 331, the long behavior sequence 333, and so on, based on at least one behavior feature of the long behavior sequences. The behavior sequence template is used to describe the behavior pattern of the long behavior sequence, for example, to describe the behaviors of the user A in the process from entering the website to leaving the website.

[0052] As an example, the server 130 can determine the behavior sequence template corresponding to the long behavior sequence 333 based on time intervals between respective access behaviors in the long behavior sequence (e.g., the long behavior sequence 333 or other long behavior sequence). In some examples, the server 130 can determine the behavior sequence template corresponding to the long behavior sequence 333 based on access time intervals corresponding to each sub-behavior sequence included in the long behavior sequence 333. The time intervals are, for example, time intervals between respective steps in a login process, such as time intervals between inputting an account name, inputting a password, inputting a verification code, and verifying the verification code.

[0053] As an example, the server 130 can determine the behavior sequence template corresponding to the long behavior sequence 333 based on access paths corresponding to respective access behaviors in the long behavior sequence (e.g., the long behavior sequence 333 or other long behavior sequence). In some examples, the server 130 can determine the behavior sequence template corresponding to the long behavior sequence 333 based on access paths corresponding to each sub-behavior sequence included in the long behavior sequence 333. For example, for a scenario of registering an account, the access paths can include inputting an account name, a password, a verification code, and clicking a login control.

[0054] As an example, the server 130 can determine the behavior sequence template corresponding to the long behavior sequence 333 based on an interaction period corresponding to the long behavior sequence (e.g., the long behavior sequence 333 or other long behavior sequence). For example, for A user to register an account, it can take 2 minutes, and thus the interaction period is 2 minutes. For A user to login an account, it can take 3 minutes, and thus the interaction period is 3 minutes.

[0055] In some embodiments, for a short behavior sequence (e.g., the short behavior sequence 332 or any other appropriate short behavior sequence), the server 130 can match the short behavior sequence 332 with a plurality of behavior sequence templates. The server 130 can add the short behavior sequence 332 to the long behavior sequence 333 to determine a completed behavior sequence 334 if the server 130 determines that the short behavior sequence 332 matches the behavior sequence template corresponding to the long behavior sequence 333. In some examples, the server 130 can insert the short behavior sequence 332 into the long behavior sequence 333 in a time order at both ends or a gap of the long behavior sequence 333 to obtain the completed behavior sequence 334 if the server 130 determines that the short behavior sequence 332 matches the behavior sequence template corresponding to the long behavior sequence 333. That is, if the short behavior sequence 332 matches the behavior sequence template corresponding to the long behavior sequence 333, the access entity 2 and the access entity 3 belong to the same access entity.

[0056] In some embodiments, the server 130 can determine the matching degree between a short behavior sequence (e.g., the short behavior sequence 332 or any other appropriate short behavior sequence) and a behavior sequence template in the following manner. The server 130 can determine the similarity between the short behavior sequence 332 and the long behavior sequence 333 by utilizing a dynamic time warping algorithm. Further, the server 130 can determine the edit distance spent to change the behaviors in the short behavior sequence 332 to the behaviors in the behavior sequence template corresponding to the long behavior sequence 333. The server 130 can determine the matching degree between the short behavior sequence 332 and the behavior sequence template corresponding to the long behavior sequence 333 according to the similarity and the edit distance. That is, the server 130 can determine the matching degree between the short behavior sequence 332 and the behavior sequence template corresponding to the long behavior sequence 333 according to a hybrid metric of dynamic time warping (DTW) and edit distance. In this way, the complete behavior sequence reconstruction is achieved by automatically concatenating the behavior sequences that are adjacent in time and similar in pattern to the long behavior sequence.

[0057] In summary, by combining the IP address and the time interval with the CookieId, the continuous access sequence of the same access entity can be accurately restored. In this way, the problem of frequent IP address change and cross-site behavior fragmentation of the automated access attacker can be solved.

[0058] Alternatively or additionally, the server 130 can invoke a machine learning model to combine the short behavior sequences and the long behavior sequences into a plurality of completed behavior sequences. In some examples, the server 130 can input the short behavior sequences and the long behavior sequences into the machine learning model, and the machine learning model can output the completed behavior sequences.

[0059] The above describes how to determine the completed behavior sequences. Based on the completed behavior sequences, an abnormal access entity can be identified from the plurality of access entities. Figure 2 Figure 3 The above describes how to determine the completed behavior sequences. Based on the completed behavior sequences, an abnormal access entity can be identified from the plurality of access entities.

[0060] The above describes how to determine the completed behavior sequences. Based on the completed behavior sequences, an abnormal access entity can be identified from the plurality of access entities. Figure 2 Figure 3 The above describes how to determine the completed behavior sequences. Based on the completed behavior sequences, an abnormal access entity can be identified from the plurality of access entities.

[0061] In block 250, the server 130 identifies an automated access attacker from the at least one access entity based on the at least one completed behavior sequence. In some embodiments, the server 130 can utilize a machine learning model to identify the automated access attacker from the plurality of completed behavior sequences. Refer to Figure 3 ​​The server 130 can input the completed behavior sequence 334 (which can be referred to herein as a first completed behavior sequence) to a machine learning model to generate a label 342 for the access entity (e.g., access entity 2) to which the completed behavior sequence 334 corresponds. The label 342 can indicate that the access entity 2 is an automated access attacker. Accordingly, based on the integrated and completed behavior sequences, features of multiple dimensions can be analyzed, thereby improving the accuracy of identifying automated access attackers.

[0062] As an example, the server 130 can input the integrated behavior sequence 331 to a machine learning model to generate a label 341 for the access entity (e.g., access entity 1) to which the integrated behavior sequence 331 corresponds. The label 341 can indicate that the access entity 1 is a normal access entity.

[0063] In some embodiments, the machine learning model can include at least a large language model (LLM). The large language model can receive model inputs in a text modality (e.g., natural language and / or machine language) and can generate corresponding model outputs according to the model inputs and a prompt word. The prompt word herein can indicate a generation requirement, thereby guiding the machine learning model to generate a desired identification result. In some embodiments, the machine learning model can include a multi-modal model that can receive model inputs in a text modality (e.g., natural language and / or machine language) and model inputs in a non-text modality (e.g., images, speech, videos, etc.), thereby generating model outputs.

[0064] In some embodiments, the server 130 can determine at least one feature of the completed behavior sequence (e.g., the completed behavior sequence 334 or any other appropriate behavior sequence). Further, the server 130 can determine a label for the access entity (e.g., access entity 2) to which the completed behavior sequence corresponds based on the at least one feature using a machine learning model. In some examples, the server 130 can construct multi-granularity features for the completed behavior sequence. Then, the server 130 can output a label for the access entity to which the completed behavior sequence corresponds based on the constructed multi-granularity features using the machine learning model. In some embodiments, the machine learning model can be a long short-term memory network-attention mechanism (LSTM-Attention) model. In some embodiments, the server 130 can classify the completed behavior sequence based on a gradient boosting decision tree algorithm (GBDT) to determine the label for the access entity to which the completed behavior sequence corresponds.

[0065] As an example, the server 130 can determine the timing features of the completed behavior sequence 334 based on the mean, variance, covariance, entropy, burst rate, etc. of the completed behavior sequence 334. Further, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the timing features of the completed behavior sequence 334 using the machine learning model. As an example, the server 130 can determine the semantic features of the completed behavior sequence 334 based on the access path, request method distribution, etc. of the completed behavior sequence 334. Further, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the semantic features of the completed behavior sequence 334 using the machine learning model.

[0066] As an example, the server 130 can determine the length of the completed behavior sequence 334. Further, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the length of the completed behavior sequence 334 using the machine learning model. Conventionally, for the scenario of registering an account, a normal access entity can only need to input the account number, password, verification code to complete the registration. However, for an automated program, it can need to input the account number, crack the password, input the password, crack the verification code, input the verification code to complete the registration. For the above example, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the length of the completed behavior sequence 334 using the machine learning model.

[0067] As an example, the server 130 can also determine the number of network resources corresponding to the completed behavior sequence 334. Further, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the number of network resources corresponding to the completed behavior sequence 334 using the machine learning model. Conventionally, for the scenario of registering an account, a normal access entity can only need to access the network resources that it needs. However, for an automated program, it can need to access a large number of network resources. For the above example, the server 130 can determine the label of the access entity corresponding to the completed behavior sequence 334 based on the number of network resources corresponding to the completed behavior sequence 334 using the machine learning model.

[0068] Two or more of the above different features can be used in combination. The combined features can be provided to the machine learning model to identify the abnormal access user. In this way, based on the timing features, semantic features, length of the behavior sequence, number of network resources, the accuracy of identifying the automated access attacker can be improved.

[0069] In summary, integrating and completing behavior sequences significantly improves the completeness of restored user behavior sequences. This allows for analysis of more realistic and continuous behavior sequences. Furthermore, these integrated and completed behavior sequences can be used to analyze features across multiple dimensions, thereby increasing the accuracy of identifying automated access attackers and enhancing the robustness and sustainable protection capabilities of the detection system.

[0070] The embodiments of the present disclosure also provide corresponding devices for implementing the above methods or processes.

[0071] Figure 4 : A schematic structural block diagram of an apparatus 400 for identifying automated access attacks according to certain embodiments of the present disclosure is shown. The apparatus 400 may be implemented as or included in the server 130. Each module / component in the apparatus 400 may be implemented by hardware, software, firmware, or any combination thereof.

[0072] like Figure 4 As shown, apparatus 400 includes an access request determination module 410 configured to determine multiple access requests for a network resource based on log information of the network resource, each of which includes information across multiple dimensions. Apparatus 400 also includes a multiple access group division determination module 420 configured to divide the multiple access requests into multiple groups of access requests based on the correlation between the multiple access requests across at least one of the multiple dimensions. Apparatus 400 also includes an integrated behavior sequence determination module 430 configured to determine multiple integrated behavior sequences corresponding to the multiple groups of access requests based on the access time of each of the multiple groups of access requests, each of which includes access behaviors to the network resource at multiple time points. Apparatus 400 also includes a completed behavior sequence determination module 440 configured to determine at least one completed behavior sequence corresponding to at least one access entity by performing behavior completion on at least one of the multiple integrated behavior sequences. Apparatus 400 also includes an automated access attacker identification module 450 configured to identify an automated access attacker within the at least one access entity based on the at least one completed behavior sequence. In this way, by integrating and completing the behavior sequence, the completeness of the restored user's behavior sequence can be significantly improved. In this way, based on the integrated and completed behavior sequence, it is easier to analyze a more realistic and continuous behavior sequence.

[0073] In some embodiments, the at least one dimension includes at least one of the following: access time dimension, access address dimension, or cookie dimension. In this way, information based on multiple dimensions can facilitate subsequent integration and completion of the same user's behavior sequence.

[0074] In some embodiments, the multiple access request grouping module 420 is further configured to, based on the access address dimension, identify at least two first access requests from the multiple access requests that have the same access address; and, in response to an access time interval between the at least two first access requests being less than a predetermined time interval, group the at least two first access requests into one of the multiple access request groups. Thus, by grouping access requests based on the access address dimension, the completeness of the restored user behavior sequence can be improved.

[0075] In some embodiments, the multiple access request grouping module 420 is further configured to determine, based on the cookie dimension, whether the identifiers in the cookies of at least two second access requests among the multiple access requests are the same; and in response to the identifiers in the cookies of at least two second access requests being the same, group the at least two second access requests into one of the multiple access request groups. Thus, by grouping access requests based on CookieId, the completeness of the restored user behavior sequence can be improved.

[0076] In some embodiments, the completed behavior sequence determination module 440 is further configured to combine at least two of the plurality of integrated behavior sequences into one of the at least one completed behavior sequences based at least on the respective sequence lengths of the plurality of integrated behavior sequences. In this way, by completing the behavior sequences based on the lengths of the integrated behavior sequences, a complete behavior sequence can be reconstructed.

[0077] In some embodiments, the completed behavior sequence determination module 440 is further configured to determine a long behavior sequence among the multiple integrated behavior sequences, wherein the sequence length of the long behavior sequence satisfies a first preset condition; determine a behavior sequence template corresponding to the long behavior sequence based on at least one behavior feature of the long behavior sequence, wherein the behavior sequence template describes the behavior pattern of the long behavior sequence; determine whether the multiple integrated behavior sequences include at least one short behavior sequence that matches the behavior sequence template, wherein the sequence length of the at least one short behavior sequence satisfies a second preset condition; and in response to determining at least one short behavior sequence that matches the behavior sequence template, add the at least one short behavior sequence to the long behavior sequence to determine a completed behavior sequence in the at least one completed behavior sequence. In this way, the method of completing a behavior sequence according to the long behavior sequence template can achieve complete behavior sequence reconstruction.

[0078] In some embodiments, the apparatus 400 further includes a matching degree determination module, further configured to determine, for a first short behavior sequence in at least one short behavior sequence, the similarity between the first short behavior sequence and the long behavior sequence using a dynamic time warping algorithm; determine the edit distance required to change the behavior in the first short behavior sequence to the behavior in the behavior sequence template; and determine the matching degree between the first short behavior sequence and the behavior sequence template based on the similarity and the edit distance. In this way, the method for completing the behavior sequence according to the long behavior sequence template can achieve complete behavior sequence reconstruction.

[0079] In some embodiments, the at least one behavior feature includes at least one of the following: the time interval between access behaviors in a long behavior sequence, the access path corresponding to each access behavior in the long behavior sequence, or the interaction period corresponding to the long behavior sequence. Thus, by automatically linking temporally adjacent and similar behavior sequences to the long behavior sequence, a complete behavior sequence can be reconstructed.

[0080] In some embodiments, the automated access attacker identification module 450 is further configured to use a machine learning model to generate a label for a first access entity corresponding to a first completed behavior sequence in the at least one completed behavior sequence, the label indicating whether the first access entity is an automated access attacker. This allows for analysis of features across multiple dimensions, thereby improving the accuracy of identifying automated access attackers.

[0081] In some embodiments, the automated access attacker identification module 450 is further configured to determine at least one feature of the first completed behavior sequence; and based on the at least one feature, use a machine learning model to determine a label for the first access entity corresponding to the first completed behavior sequence. This can significantly improve the completeness of the restored user behavior sequence.

[0082] In some embodiments, the at least one feature includes at least one of the following: a temporal feature of the first completed behavior sequence, a semantic feature of the first completed behavior sequence, a length of the first completed behavior sequence, or the number of network resources corresponding to the first completed behavior sequence. In this way, based on the temporal feature, semantic feature, length of the behavior sequence, and number of network resources, the accuracy of identifying automated access attackers can be improved.

[0083] The units and / or modules included in the device 400 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units and / or modules can be implemented using software and / or firmware, such as machine executable instructions stored on a storage medium. In addition to or as an alternative to machine executable instructions, some or all of the units and / or modules in the device 400 can be implemented at least in part by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0084] It should be understood that one or more steps in the above method can be performed by a suitable electronic device or combination of electronic devices. Such an electronic device or combination of electronic devices may include, for example, Figure 1 Server 130 in.

[0085] Figure 5 1 shows a block diagram of an electronic device 500 in which one or more embodiments of the present disclosure may be implemented. Figure 5 The illustrated electronic device 500 is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 5 The electronic device 500 shown can be used to implement Figure 1 Server 130.

[0086] like Figure 5 As shown, electronic device 500 is in the form of a general electronic device. Components of electronic device 500 may include, but are not limited to, one or more processors 510 or processing units, memory 520, storage device 530, one or more communication units 540, one or more input devices 550, and one or more output devices 560. Processor 510 may be a real or virtual processor and is capable of performing various processes according to programs stored in memory 520. In a multi-processor system, multiple processors execute computer-executable instructions in parallel to increase the parallel processing capabilities of electronic device 500.

[0087] The electronic device 500 typically includes a plurality of computer storage media. Such media can be any available media accessible to the electronic device 500, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 520 can be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 530 can be a removable or non-removable medium and can include a machine-readable medium, such as a flash drive, a disk, or any other medium that can be used to store information and / or data and can be accessed within the electronic device 500.

[0088] The electronic device 500 may further include additional removable / non-removable, volatile / non-volatile storage media. Figure 5 As shown in FIG, a magnetic disk drive for reading from or writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk") and an optical disk drive for reading from or writing to a removable, non-volatile optical disk may be provided. In these cases, each drive may be connected to a bus (not shown) by one or more data media interfaces. Memory 520 may include a computer program product 525 having one or more program modules configured to perform various methods or actions of various embodiments of the present disclosure.

[0089] The communication unit 540 enables communication with other electronic devices via a communication medium. Additionally, the functions of the components of the electronic device 500 can be implemented in a single computing cluster or multiple computing machines that can communicate via a communication connection. Thus, the electronic device 500 can operate in a networked environment using a logical connection with one or more other servers, a network personal computer (PC), or another network node.

[0090] Input device 550 may be one or more input devices, such as a mouse, keyboard, or trackball. Output device 560 may be one or more output devices, such as a display, a speaker, or a printer. Electronic device 500 may also communicate with one or more external devices (not shown) via communication unit 540 as needed, such as a storage device, a display device, or the like, with one or more devices that allow a user to interact with electronic device 500, or with any device that allows electronic device 500 to communicate with one or more other electronic devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface (not shown).

[0091] According to an example implementation of the present disclosure, a computer readable storage medium is provided having computer executable instructions stored thereon, where the computer executable instructions are executed by a processor to implement the method described above. According to an example implementation of the present disclosure, a computer program product is also provided that is tangibly stored on a non-transitory computer readable medium and includes computer executable instructions, where the computer executable instructions are executed by a processor to implement the method described above.

[0092] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0093] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can include a non-transitory computer readable storage medium. The instructions stored on the computer readable storage medium can be used to program a computer, a programmable data processing apparatus, and / or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0094] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0095] The computer program product of the present disclosure can have a signal including said computer program. This signal can be electronic, electromagnetic, optical, or any other suitable type of signal. Such a signal can be provided through a communication connection, such as electrical wiring, optical fiber, wireless interface, etc. Examples of computer program products include computer program implemented on a personal computer, server, or other networked device. A non-transitory computer readable medium, such as a floppy disk, CD-ROM, DVD-ROM, Blu-ray Disc, hard disk drive, or any other suitable non-transitory computer readable medium can store the computer program product.

[0096] Various implementations of the disclosure have been described in detail above. The foregoing description is exemplary and explanatory only, and is not intended to be exhaustive or to limit various implementations of the disclosure to the precise forms disclosed. Many modifications and variations are possible in light of the above teachings without departing from the scope and spirit of the disclosure. It is intended that the scope of the disclosure be limited only by the claims and the equivalents thereof. The use of the terms "including," "containing," "comprising," "having," "in involving," "portions," "elements," "components," "steps," "phases," "processes," "operations," "steps," "stages," "procedures," "methods," "mechanisms," "devices," "systems," "apparatuses," "units," "means," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "apparatuses," "units," "devices," "systems," "

Claims

1. A method for identifying automated access attacks for a firewall, comprising: Determining, based on log information of the network resource, multiple access requests for the network resource, wherein the multiple access requests respectively include information on multiple dimensions; dividing the plurality of access requests into a plurality of groups of access requests based on a degree of correlation of the plurality of access requests in at least one dimension of the plurality of dimensions; determining, based on an access time of each of the plurality of access requests, a plurality of integrated behavior sequences corresponding to the plurality of access requests, wherein an integrated behavior sequence in the plurality of integrated behavior sequences includes access behaviors to the network resource at a plurality of time points; determining at least one completed behavior sequence corresponding to at least one access entity, respectively, by performing behavior completion on at least one integrated behavior sequence among the plurality of integrated behavior sequences; as well as An automated access attacker is identified in the at least one access entity based on the at least one completed behavior sequence.

2. The method according to claim 1, wherein the at least one dimension comprises at least one of the following: Access time dimension, Access the address dimension, or cookie dimensions.

3. The method according to claim 2, wherein dividing the plurality of access requests into a plurality of groups of access requests comprises: For the access address dimension, determining at least two first access requests having the same access address among the multiple access requests; as well as In response to an access time interval between the at least two first access requests being less than a predetermined time interval, the at least two first access requests are divided into one group of access requests among the multiple groups of access requests.

4. The method according to claim 2, wherein dividing the plurality of access requests into a plurality of groups of access requests comprises: determining, with respect to the cookie dimension, whether identifiers in cookies of at least two second access requests among the multiple access requests are the same; as well as In response to the identifiers in the cookies of the at least two second access requests being the same, the at least two second access requests are divided into one group of access requests in the multiple groups of access requests.

5. The method according to claim 1 , wherein determining the at least one completed behavior sequence respectively corresponding to the at least one access entity comprises: At least two integrated behavior sequences of the plurality of integrated behavior sequences are combined into one of the at least one completed behavior sequence based at least on the respective sequence lengths of the plurality of integrated behavior sequences.

6. The method of claim 5, wherein combining at least two integrated behavior sequences of the plurality of integrated behavior sequences into one of the at least one completed behavior sequence comprises: Determining a long behavior sequence among the plurality of integrated behavior sequences, wherein a sequence length of the long behavior sequence satisfies a first preset condition; Determining a behavior sequence template corresponding to the long behavior sequence based on at least one behavior feature of the long behavior sequence, wherein the behavior sequence template describes a behavior pattern of the long behavior sequence; determining whether the plurality of integrated behavior sequences include at least one short behavior sequence matching the behavior sequence template, wherein a sequence length of the at least one short behavior sequence satisfies a second preset condition; as well as In response to determining the at least one short behavior sequence matching the behavior sequence template, the at least one short behavior sequence is added to the long behavior sequence to determine one completed behavior sequence among the at least one completed behavior sequence.

7. The method of claim 6, wherein determining whether the plurality of integrated behavior sequences include at least one short behavior sequence matching the behavior sequence template comprises: For a first short behavior sequence in the at least one short behavior sequence, Determining the similarity between the first short behavior sequence and the long behavior sequence using a dynamic time warping algorithm; determining an edit distance required to change a behavior in the first short behavior sequence to a behavior in the behavior sequence template; as well as Based on the similarity and the edit distance, a matching degree between the first short behavior sequence and the behavior sequence template is determined.

8. The method of claim 6, wherein the at least one behavioral characteristic comprises at least one of the following: The time interval between each access behavior in the long behavior sequence, The access path corresponding to each access behavior in the long behavior sequence, or The interaction period corresponding to the long behavior sequence.

9. The method of claim 1 , wherein identifying an automated access attacker in the at least one access entity comprises: For a first completed behavior sequence in the at least one completed behavior sequence, a machine learning model is used to generate a label for a first access entity corresponding to the first completed behavior sequence, wherein the label indicates whether the first access entity is an automated access attacker.

10. The method according to claim 9, wherein outputting a label of the access entity corresponding to the completed behavior sequence using a machine learning model comprises: determining at least one characteristic of the first completed sequence of behaviors; as well as Based on the at least one feature, a machine learning model is used to determine a label of the first access entity corresponding to the first completed behavior sequence.

11. The method of claim 10, wherein the at least one characteristic comprises at least one of: the temporal features of the first completed behavior sequence, the semantic features of the first completed action sequence, the length of the first completed sequence of behaviors, or The number of network resources corresponding to the first completed behavior sequence.

12. A device for identifying abnormal access in a firewall, comprising: an access request determination module, configured to determine, based on log information of a network resource, a plurality of access requests for the network resource, wherein the plurality of access requests respectively include information in a plurality of dimensions; a multi-group access request division module configured to divide the plurality of access requests into a plurality of groups of access requests based on a correlation degree of the plurality of access requests in at least one dimension of the plurality of dimensions; an integrated behavior sequence determination module configured to determine, based on an access time of each of the multiple groups of access requests, a plurality of integrated behavior sequences respectively corresponding to the multiple groups of access requests, wherein an integrated behavior sequence in the multiple integrated behavior sequences includes access behaviors to the network resource at multiple time points; a completed behavior sequence determining module configured to determine at least one completed behavior sequence respectively corresponding to at least one access entity by performing behavior completion on at least one integrated behavior sequence among the plurality of integrated behavior sequences; as well as The automated access attacker identification module is configured to identify an abnormal access entity among the at least one access entity based on the at least one completed behavior sequence.

13. An electronic device comprising: at least one processor; as well as At least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 11 when executed by the at least one processor.

14. A computer-readable storage medium having computer-executable instructions stored thereon, wherein the computer-executable instructions can be executed by a processor to implement the method according to any one of claims 1 to 11.

15. A computer program product comprising computer executable instructions, wherein the computer executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Systems, methods, devices, and platforms for industrial internet of things

    CA3252125A1

  • Attacker IP defense method and defense system based on honey array cooperation

    CN115208679A

  • Network attack processing method and device, electronic equipment and storage medium

    CN118250069A

  • Behavior gene identification method for network attack organization

    CN118611983A

  • Interface traffic security detection method, device, equipment, medium and program product

    CN119071070A