Method, apparatus, and device for identifying automated access attacks for a firewall

By integrating and completing network access behavior sequences, and utilizing multi-dimensional correlation and machine learning models, the problem of inaccurate identification of automated access attacks in existing technologies has been solved, achieving more efficient identification and protection against abnormal access.

CN120785627BActive Publication Date: 2026-07-24BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING VOLCANO ENGINE TECH CO LTD
Filing Date
2025-07-30
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately identify network access attacks using robots or automated programs, especially when the accessing entity frequently changes its IP address or crosses labels or domains, leading to inaccurate identification of abnormal access.

Method used

By integrating and completing network access behavior sequences, access requests are segmented using multi-dimensional correlations. By combining IP addresses, time intervals, and cookie IDs, the behavior sequences of access entities are reconstructed, and machine learning models are used to identify automated access attackers.

Benefits of technology

It improves the accuracy of identifying automated access attacks, enhances the integrity and continuity of behavioral sequences, and improves the robustness and protection capabilities of the identification system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785627B_ABST
    Figure CN120785627B_ABST
Patent Text Reader

Abstract

According to embodiments of the present disclosure, a method, device, equipment and storage medium for identifying an automated access attack for a firewall are provided. The method comprises: determining a plurality of access requests for a network resource based on log information of the network resource, the plurality of access requests respectively comprising information in a plurality of dimensions; dividing the plurality of access requests into a plurality of groups of access requests based on correlation degrees of the plurality of access requests in at least one of the plurality of dimensions; determining a plurality of integrated behavior sequences respectively corresponding to the plurality of groups of access requests based on access times of each group of access requests in the plurality of groups of access requests; determining at least one completed behavior sequence respectively corresponding to at least one access entity by performing behavior completion on at least one integrated behavior sequence in the plurality of integrated behavior sequences; and identifying an automated access attacker in the at least one access entity based on the at least one completed behavior sequence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The exemplary embodiments disclosed herein generally relate to the field of computers, and particularly to methods, apparatus, devices, computer-readable storage media, and computer program products for identifying automated access attacks for firewalls. Background Technology

[0002] With the widespread use of the internet, the amount of network access behavior data generated from accessing various online resources is increasing. Among this vast amount of data, abnormal access may exist. For example, using bots or automated programs to repeatedly or continuously access resources can increase the processing load on resource servers. How to correctly identify automated access attacks from this large amount of behavioral data is a pressing problem that needs to be solved. Summary of the Invention

[0003] In a first aspect of this disclosure, a method for identifying automated access attacks for a firewall is provided, comprising: determining multiple access requests for network resources based on log information of network resources, wherein each access request includes information in multiple dimensions; dividing the multiple access requests into multiple groups of access requests based on the correlation of the multiple access requests in at least one of the multiple dimensions; determining multiple integrated behavior sequences corresponding to the multiple groups of access requests based on the access time of each group of access requests, wherein the integrated behavior sequences include access behaviors to network resources at multiple time points; determining at least one completed behavior sequence corresponding to at least one access entity by performing behavior completion on at least one integrated behavior sequence; and identifying an automated access attacker in at least one access entity based on the at least one completed behavior sequence.

[0004] In a second aspect of this disclosure, an apparatus for identifying automated access attacks for a firewall is provided, comprising: an access request determination module configured to determine multiple access requests for network resources based on log information of network resources, wherein the multiple access requests each include information in multiple dimensions; a multiple access request segmentation module configured to segment the multiple access requests into multiple access requests based on the correlation of the multiple access requests in at least one of the multiple dimensions; an integrated behavior sequence determination module configured to determine multiple integrated behavior sequences corresponding to the multiple access requests based on the access time of each of the multiple access requests, wherein the integrated behavior sequences include access behaviors to network resources at multiple time points; an integrated behavior sequence determination module configured to determine at least one completed behavior sequence corresponding to at least one access entity by performing behavior completion on at least one of the multiple integrated behavior sequences; and an automated access attacker identification module configured to identify an automated access attacker in at least one access entity based on at least one completed behavior sequence.

[0005] In a third aspect of this disclosure, an electronic device is provided. The device includes at least one processor; and at least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor. When executed by the at least one processor, the instructions cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of this disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores computer-executable instructions that can be executed by a processor to implement the method of the first aspect.

[0007] According to a fifth aspect of this disclosure, a computer program product is provided, including computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method of the first aspect.

[0008] It should be understood that the content described in this content section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0009] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0010] Figure 1 A schematic diagram of an example environment in which embodiments of the present disclosure can be implemented is shown;

[0011] Figure 2 A flowchart is shown illustrating a process for identifying automated access attacks according to some embodiments of the present disclosure;

[0012] Figure 3 A schematic diagram of an example architecture for identifying automated access attacks according to some embodiments of the present disclosure is shown;

[0013] Figure 4 A block diagram of an apparatus for identifying automated access attacks according to some embodiments of the present disclosure is shown; and

[0014] Figure 5 A block diagram of an apparatus capable of implementing one or more embodiments of the present disclosure is shown. Detailed Implementation

[0015] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0016] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below.

[0017] In this document, unless explicitly stated otherwise, performing a step in response to A does not mean that the step is performed immediately after A, but may include one or more intermediate steps.

[0018] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0019] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and user authorization should be obtained.

[0020] For example, in response to receiving a user's active request, a prompt message is sent to the user to clearly inform the user that the requested operation will require the acquisition and use of the user's personal information, thereby enabling the user to choose whether to provide personal information to the software or hardware such as electronic devices, applications, servers or storage media that perform the operation of the technical solution disclosed herein, based on the prompt message.

[0021] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0022] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0023] As used in this paper, the term "model" refers to a model that learns the relationship between inputs and outputs from training data, enabling it to generate corresponding outputs for a given input after training. Model generation can be based on machine learning techniques. Deep learning is a machine learning algorithm that processes inputs and provides corresponding outputs using multiple layers of processing units. A neural network model is an example of a deep learning-based model. In this paper, "model" may also be referred to as a "machine learning model," "learning model," "machine learning network," or "learning network," and these terms are used interchangeably.

[0024] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. For example... Figure 1 As shown, example environment 100 may include electronic device 110 and server 130.

[0025] In environment 100, user 132 can access network resources through an associated electronic device 110 (e.g., a terminal device). For example, user 132 can send an access request to a server of the resource to access the network resource. Server 130 receives (e.g., collects) the access request from electronic device 110. It should be understood that although a single user 132 and a single electronic device 110 are shown, environment 100 may include multiple users and corresponding electronic devices. A user can be an example of an accessing entity. In embodiments of this disclosure, an accessing entity can be a source object that actively initiates an access request, such as including but not limited to the device initiating the access, a program (e.g., an automation program), a user, an account, or other types of entities. In this document, an automated program (also referred to as an automated access attacker, an anomalous access entity, or a bot) is used. User 132 can access some resources in network resource pool 120 through associated electronic device 110. Network resource pool 120 may include one or more resources 122-1, 122-2, ..., 122-M. For ease of discussion, one or more resources 122-1, 122-2, ..., 122-M may be collectively referred to as or individually referred to as resource 122.

[0026] Server 130 may obtain multiple access requests from different electronic devices. Among these access requests obtained by server 130, there may be abnormal access requests issued by automated access attackers. For example, automated programs may perform batch registration, brute-force CAPTCHA cracking, or crawling sensitive data. In environment 100, server 130 can identify automated access attackers (e.g., abnormal users, bots) based on the integration of behavioral sequences corresponding to these access requests.

[0027] Electronic device 110 can be any type of mobile terminal, fixed terminal, or portable terminal, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio / video players, digital cameras / camcorders, television receivers, radio receivers, e-book devices, gaming devices, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, electronic device 110 may also support any type of user-facing interface (such as "wearable" circuitry).

[0028] Server 130 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms. Server 130 may include, for example, computing systems / servers such as mainframes, edge computing nodes, computing devices in a cloud environment, etc. Server 130 can provide background services for applications in electronic device 110 that support resource request services.

[0029] A communication connection can be established between server 130 and electronic device 110. This communication connection can be established via wired or wireless means. The communication connection may include, but is not limited to, Bluetooth, mobile network, Universal Serial Bus (USB), and Wireless Fidelity (WiFi) connections; the embodiments of this disclosure are not limited in this respect. In the embodiments of this disclosure, server 130 and electronic device 110 can achieve signaling interaction through the communication connection between them.

[0030] It should be understood that the structure and function of the various elements in environment 100 are described for illustrative purposes only and do not imply any limitation on the scope of this disclosure.

[0031] With the rapid development of applications (e.g., the Web) that interact over large networks such as the Internet or local area networks, automated programs have emerged. These programs can impact servers through methods such as bulk registration, brute-force CAPTCHA cracking, and data scraping. Conventionally, abnormal access can be identified based on the inspection of network access logs. For example, requests can be segmented into sessions using a single identifier (e.g., Internet Protocol address). Then, a classification model can be used to identify abnormal access.

[0032] However, for entities that frequently change their Internet Protocol (IP) addresses, causing the same entity's behavioral sequence to be broken into multiple short fragment sequences, the above methods cannot accurately identify abnormal entities. Furthermore, even with the use of cookies or other information, cross-tag, cross-domain, or cross-time-period behaviors of the same entity can still be fragmented in these scenarios. Therefore, the above methods also cannot accurately identify entities with abnormal access.

[0033] In view of this, an improved scheme for identifying automated access attacks is proposed based on some embodiments of this disclosure. According to the scheme of this disclosure, multiple access requests targeting network resources are identified based on log information of network resources, each access request including information across multiple dimensions. Based on the correlation between the multiple access requests and at least one of the multiple dimensions, the multiple access requests are divided into multiple groups of access requests. Based on the access time of each group of access requests, multiple integrated behavior sequences corresponding to the multiple groups of access requests are determined, each integrated behavior sequence including access behaviors to network resources at multiple time points. By performing behavior completion on at least one integrated behavior sequence, at least one completed behavior sequence corresponding to at least one accessing entity is determined. Based on the at least one completed behavior sequence, an automated access attacker in at least one accessing entity is identified.

[0034] In this way, by integrating and completing the behavioral sequences, the completeness of reconstructing the user's behavioral sequence can be significantly improved. This integrated and completed behavioral sequence facilitates the analysis of more realistic and continuous behavioral sequences. Consequently, based on the integrated and completed behavioral sequence, multi-dimensional features can be analyzed, thereby improving the accuracy of identifying automated access attackers.

[0035] Various example implementations of this disclosure will be described in detail below with reference to the accompanying drawings. Figure 2 A schematic diagram of an example process 200 for identifying automated access attacks according to some embodiments of the present disclosure is shown. For ease of discussion, reference will be made to... Figure 1 The example process 200 will be described using environment 100 as an example. Furthermore, the example embodiment will be described below primarily with respect to server 130.

[0036] In the discussion of process 200, for better understanding, we will combine... Figure 3 This disclosure will explain some embodiments used to identify anomalous access. Figure 3 A schematic diagram of an example architecture 300 for identifying automated access attacks according to some embodiments of the present disclosure is shown.

[0037] In this paper, an accessing entity (e.g., user 132) can access network resources via electronic devices. During this access process, a large amount of log information is generated. In some scenarios, users may use automated programs (also referred to as automated access attackers, anomalous access entities, or bots in this paper) to access certain network resources multiple times, such as through mass registration, cracking CAPTCHAs, or data scraping. Therefore, for security reasons, it is necessary to identify automated access attackers from a large number of access requests. In this regard, this paper proposes identifying automated access attackers by integrating and completing the behavioral sequences of accessing entities. A behavioral sequence indicates the access behavior of an accessing entity to resources, recorded chronologically within a certain time period. For example, on a website, each step an accessing entity takes from entering the website to leaving can be recorded as an accessing entity behavior, thus forming an accessing entity behavior sequence. Behavioral sequences can be used to analyze the behavioral patterns and interests of accessing entities.

[0038] like Figure 2 As shown in box 210, server 130 determines multiple access requests for network resources based on log information of the network resources. In some embodiments, the multiple access requests each include information across multiple dimensions. In some examples, the information across multiple dimensions may indicate multiple fields included in the access request. That is, each of the multiple access requests may include multiple fields. For example... Figure 3 As shown, server 130 can determine access requests such as access request 315 and access request 316 for network resources from the log information it obtains.

[0039] refer to Figure 3 Examples describing multiple dimensions. For example... Figure 3 As shown, multiple dimensions can include an access time dimension, such as a timestamp 311. Optionally or additionally, multiple dimensions can include an access address dimension, such as an Internet Protocol (IP) address 312. Optionally or additionally, multiple dimensions can include a cookie dimension 314. Cookies can indicate data stored on a user's local device by certain websites to identify the user and track sessions. In some examples, cookies can be stored as text files. Optionally or additionally, multiple dimensions can also include a request path 315, such as the root directory that can be used to record user visits. Optionally or additionally, multiple dimension information can include a user-agent to identify the client device, operating system, browser, etc. Thus, information based on multiple dimensions facilitates subsequent integration and completion of the behavioral sequence of the same access entity.

[0040] In box 220, server 130 divides multiple access requests into multiple groups of access requests based on the correlation between multiple access requests and at least one of multiple dimensions. For example, server 130 can determine multiple groups of access requests based on the correlation between multiple access requests and the access address dimension. For example, server 130 can determine multiple groups of access requests based on the correlation between multiple access requests and the cookie dimension. The following description, with reference to the accompanying figures, illustrates how multiple groups of access requests are determined. In this way, based on the correlation across multiple dimensions, the accuracy of integrating behavioral sequences can be improved.

[0041] In some embodiments, based on the access address (e.g., IP address) dimension, server 130 can identify at least two first access requests with the same access address among multiple access requests. If the access time interval between these two first access requests is less than a predetermined time interval, the at least two first access requests are grouped into one group of access requests within the multiple groups of access requests. As an example, see... Figure 3 Server 130 can identify at least two access requests with the same IP address among multiple access requests, such as access request 315 and access request 316. Further, if the access time difference between access request 315 and access request 316 is less than a predetermined time interval, server 130 can group access request 315 and access request 316 into the same group of access requests within the multiple groups. This facilitates merging the actions corresponding to each access request in the group into a single action sequence. In some examples, the predetermined time interval can be configured by the user, such as 1 minute or any other suitable time interval. Therefore, by dividing access requests according to the address dimension, the completeness of reconstructing the action sequence of the accessed entity can be improved.

[0042] In some embodiments, regarding the cookie dimension, server 130 may determine whether the identifiers in the cookies of at least two of the multiple access requests are the same. If the identifiers in the cookies of at least two of the second access requests are the same, the at least two second access requests are merged into one of the multiple integrated action sequences. In some examples, the identifier in the cookie may include a cookieID.

[0043] As an example, refer to Figure 3Server 130 extracts cookieID321 from the log information corresponding to multiple access requests, such as _gid, GA1.2XXX, etc. Assuming that access requests 315 and 316 have the same cookie ID321, they can be grouped into the same group of access requests. Furthermore, the actions corresponding to each group of access requests can be merged into a single action sequence. In some examples, if different IP addresses have the same cookie ID, access requests with the same identifier can be merged into the same sequence. Therefore, by grouping access requests based on cookie ID, the completeness of reconstructing the action sequence of the access entity can be improved.

[0044] In box 230, server 130 determines multiple integrated behavior sequences corresponding to the multiple sets of access requests, based on the access time of each set of access requests. The integrated behavior sequences include access behaviors to network resources at multiple points in time. In some embodiments, server 130 may determine the integrated behavior sequence corresponding to a set of access requests according to the access time of each access request within that set. In some examples, server 130 may standardize the time format of the determined access requests and sort the individual access requests within each set of access requests in chronological order (e.g., ascending time or any other suitable order).

[0045] In some examples, for each group of access requests, server 130 can sort the access requests in that group in chronological order. Then, server 130 can organize the access requests in that group into an integrated sequence of behaviors corresponding to that group of access requests, based on the sorting result. For example, each access request corresponds to one access behavior in the integrated sequence of behaviors. Therefore, by integrating the behavior sequences, the completeness of reconstructing the user behavior sequence can be improved, thereby increasing the accuracy of identifying automated access attackers.

[0046] The above reference Figure 2 and Figure 3 This paper describes how to determine the integrated behavior sequence. In some scenarios, among multiple integrated behavior sequences, there may still be behavior sequences belonging to the same accessing entity. In this paper, we address this situation by performing behavior completion on some integrated behavior sequences. This, based on the completed behavior sequence, facilitates more accurate identification of automated access attackers.

[0047] The following will continue to refer to Figure 2 and Figure 3 This describes how to perform behavior completion on the integrated behavior sequence.

[0048] In box 240, server 130 determines at least one completed behavior sequence corresponding to at least one accessing entity by performing behavior completion on at least one of the plurality of integrated behavior sequences. In some embodiments, server 130 may combine at least two of the plurality of integrated behavior sequences into one of at least one completed behavior sequence, based at least on the respective sequence lengths of the plurality of integrated behavior sequences.

[0049] In some embodiments, server 130 can determine long and short behavior sequences from the integrated behavior sequences. Accordingly, server 130 can determine the sequence template corresponding to the long behavior sequence. Then, server 130 can supplement the short behavior sequence into the long behavior sequence corresponding to the sequence template based on the matching degree between the short behavior sequence and the sequence template. Thus, the behavior sequence completion method based on the long behavior sequence template enables the reconstruction of a complete behavior sequence. A long behavior sequence may refer to an integrated behavior sequence that satisfies a first preset condition. In some examples, the first preset condition may include an integrated behavior sequence length greater than a predetermined length, or any other suitable preset condition. A short behavior sequence may refer to an integrated behavior sequence that satisfies a second preset condition. In some examples, the second preset condition may include an integrated behavior sequence length less than a predetermined length, or any other suitable preset condition.

[0050] Reference Figure 3 Assume that the integrated behavior sequence determined by server 130 includes integrated behavior sequence 331 corresponding to access entity 1, integrated behavior sequence 332 corresponding to access entity 2, and behavior sequence 333 corresponding to access entity 3. Server 130 can determine from these integrated behavior sequences a long behavior sequence 331 (also referred to herein as integrated behavior sequence 331) and a long behavior sequence 333 (also referred to herein as integrated behavior sequence 333) that satisfy a first preset condition. Server 130 can also determine from these integrated behavior sequences a short behavior sequence 332 (also referred to herein as integrated behavior sequence 332) that satisfies a second preset condition.

[0051] In some embodiments, server 130 may determine behavior sequence templates corresponding to long behavior sequences 331, 333, etc., based on at least one behavioral feature of these long behavior sequences. The behavior sequence templates are used to describe the behavioral patterns of the long behavior sequences, for example, to describe the various behaviors of user A from entering the website to leaving the website.

[0052] As an example, server 130 can determine the behavior sequence template corresponding to long behavior sequence 333 based on the time intervals between various access behaviors in a long behavior sequence (e.g., long behavior sequence 333 or other long behavior sequences). In some examples, server 130 can determine the behavior sequence template corresponding to long behavior sequence 333 based on the access time intervals corresponding to each sub-behavior sequence included in long behavior sequence 333. Time intervals are, for example, the time intervals between various steps in the login process, such as the time intervals between entering an account, entering a password, entering a verification code, and verifying the verification code.

[0053] As an example, server 130 can determine the behavior sequence template corresponding to long behavior sequence 333 based on the access paths corresponding to each access behavior in the long behavior sequence (e.g., long behavior sequence 333 or other long behavior sequences). In some examples, server 130 can determine the behavior sequence template corresponding to long behavior sequence 333 based on the access paths corresponding to each sub-behavior sequence included in long behavior sequence 333. For example, in a scenario of registering an account, the access path may include entering the account name, password, verification code, and clicking the login control.

[0054] As an example, server 130 can determine the behavior sequence template corresponding to long behavior sequence 333 based on the interaction period corresponding to long behavior sequence (e.g., long behavior sequence 333 or other long behavior sequences). For example, if user A registers an account, it may take 2 minutes, so the interaction period is 2 minutes. If user A logs in to an account, it may take 3 minutes, so the interaction period is 3 minutes.

[0055] In some embodiments, for a short behavior sequence (e.g., short behavior sequence 332 or any other suitable short behavior sequence), server 130 may match it with multiple behavior sequence templates. If server 130 determines that short behavior sequence 332 matches the behavior sequence template corresponding to long behavior sequence 333, it may add short behavior sequence 332 to long behavior sequence 333 to determine completed behavior sequence 334. In some examples, if server 130 determines that short behavior sequence 332 matches the behavior sequence template corresponding to long behavior sequence 333, it may insert short behavior sequence 332 into both ends or gaps of long behavior sequence 333 in chronological order to obtain completed behavior sequence 334. That is, if short behavior sequence 332 matches the behavior sequence template corresponding to long behavior sequence 333, then access entity 2 and access entity 3 belong to the same access entity.

[0056] In some embodiments, server 130 can determine the matching degree between a short behavior sequence (e.g., short behavior sequence 332 or any other suitable short behavior sequence) and a behavior sequence template by means of a dynamic time warping algorithm. Server 130 can utilize a dynamic time warping algorithm to determine the similarity between short behavior sequence 332 and long behavior sequence 333. Further, server 130 can determine the edit distance required to change the behavior in short behavior sequence 332 to the behavior in the behavior sequence template corresponding to long behavior sequence 333. Server 130 can determine the matching degree between short behavior sequence 332 and the behavior sequence template corresponding to long behavior sequence 333 based on similarity and edit distance. That is, server 130 can determine the matching degree between short behavior sequence 332 and the behavior sequence template corresponding to long behavior sequence 333 based on a hybrid metric of dynamic time warping (DTW) and edit distance. Thus, by automatically attaching temporally adjacent and pattern-similar behavior sequences to long behavior sequences, complete behavior sequence reconstruction is achieved.

[0057] In summary, by combining IP address, time interval, and CookieId in a dual-strategy approach, it is possible to accurately reconstruct the continuous access sequence of the same accessing entity. This addresses the issues of automated access attackers frequently changing IP addresses and fragmented cross-site behavior.

[0058] Alternatively or additionally, server 130 may invoke a machine learning model to combine short and long action sequences into multiple completed action sequences. In some examples, server 130 may input short and long action sequences into a machine learning model, which may output completed action sequences.

[0059] The above reference Figure 2 and Figure 3 This paper describes how to determine the completed behavior sequence. Based on the completed behavior sequence, anomalous access entities can be identified from multiple access entities.

[0060] The following will continue to refer to Figure 2 and Figure 3 This describes how to identify automated access attackers.

[0061] In box 250, server 130 identifies an automated access attacker in at least one accessing entity based on at least one completed sequence of behaviors. In some embodiments, server 130 may utilize a machine learning model to identify automated access attackers from multiple completed sequences of behaviors. (Refer to...) Figure 3Server 130 can input the completed behavior sequence 334 (referred to herein as the first completed behavior sequence) into a machine learning model to generate a label 342 for the accessing entity (e.g., accessing entity 2) corresponding to the completed behavior sequence 334. Label 342 can indicate that accessing entity 2 belongs to an automated access attacker. Accordingly, based on the integrated and completed behavior sequence, features of multiple dimensions can be analyzed, thereby improving the accuracy of identifying automated access attackers.

[0062] As an example, server 130 can input the integrated behavior sequence 331 into a machine learning model to generate a label 341 for the access entity (e.g., access entity 1) corresponding to the integrated behavior sequence 331. Label 341 can indicate that access entity 1 is a normal access entity.

[0063] In some embodiments, the machine learning model may include at least a Large Language Model (LLM). The LLM can receive text-modal model input (e.g., natural language and / or machine language) and can produce corresponding model outputs based on the model input and prompt words. These prompt words can indicate generation requirements, thereby guiding the machine learning model to generate the desired recognition result. In some embodiments, the machine learning model may include a multimodal model that can receive text-modal model input (e.g., natural language and / or machine language) and non-text-modal model input (e.g., images, speech, video, etc.) to produce model outputs.

[0064] In some embodiments, server 130 may determine at least one feature of the completed action sequence (e.g., completed action sequence 334 or any other suitable action sequence). Further, server 130 may use a machine learning model based on at least one feature to determine the label of the accessing entity (e.g., accessing entity 2) corresponding to the completed action sequence. In some examples, server 130 may construct multi-granularity features for the completed action sequence. Then, based on the constructed multi-granularity features, server 130 may use a machine learning model to output the label for the accessing entity corresponding to the completed action sequence. In some embodiments, the machine learning model may be a Long Short-Term Memory Network-Attention (LSTM-Attention) model. In some embodiments, server 130 may classify the completed action sequence based on a Gradient Boosting Decision Tree (GBDT) algorithm to determine the label of the accessing entity corresponding to the completed action sequence.

[0065] As an example, server 130 can determine the temporal characteristics of the completed behavior sequence 334 based on its mean, variance, covariance, entropy, burst rate, etc. Furthermore, server 130 can use a machine learning model to determine the label of the accessed entity corresponding to the completed behavior sequence 334 based on its temporal characteristics. As an example, server 130 can determine the semantic characteristics of the completed behavior sequence 334 based on its access path, request method distribution, etc. Furthermore, server 130 can use a machine learning model to determine the label of the accessed entity corresponding to the completed behavior sequence 334 based on its semantic characteristics.

[0066] As an example, server 130 can determine the length of the completed behavior sequence 334. Further, server 130 can use a machine learning model to determine the label of the accessing entity corresponding to the completed behavior sequence 334 based on its length. Typically, for account registration scenarios, a normal accessing entity might only need to enter its username, password, and verification code to complete registration. However, for automated programs, it might require entering the username, cracking the password, entering the password again, cracking the verification code, and entering the verification code again to complete registration. In the above example, server 130 can use a machine learning model to determine the label of the accessing entity corresponding to the completed behavior sequence 334 based on its length.

[0067] As an example, server 130 can also determine the number of network resources corresponding to the completed behavior sequence 334. Further, server 130 can use a machine learning model to determine the label of the accessing entity corresponding to the completed behavior sequence 334 based on the number of network resources corresponding to the completed behavior sequence 334. Typically, in a scenario involving account registration, a normal accessing entity may only need to access the network resources it requires. However, automated programs may need to access a large number of network resources. In the above example, server 130 can use a machine learning model to determine the label of the accessing entity corresponding to the completed behavior sequence 334 based on the number of network resources corresponding to the completed behavior sequence 334.

[0068] Two or more of the aforementioned features can be combined. These combined features can be fed into machine learning models to identify anomalous users. In this way, based on temporal features, semantic features, the length of the behavioral sequence, and the number of network resources, the accuracy of identifying automated access attackers can be improved.

[0069] In summary, integrating and completing behavioral sequences can significantly improve the completeness of reconstructing user behavior sequences. This allows for the analysis of more realistic and continuous behavioral sequences. Consequently, based on the integrated and completed behavioral sequences, multi-dimensional features can be analyzed, thereby improving the accuracy of identifying automated access attackers and enhancing the robustness and sustainable protection capabilities of the detection system.

[0070] Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes.

[0071] Figure 4 A schematic structural block diagram of an apparatus 400 for identifying automated access attacks according to certain embodiments of the present disclosure is shown. The apparatus 400 may be implemented as or included in server 130. The various modules / components in the apparatus 400 may be implemented by hardware, software, firmware, or any combination thereof.

[0072] like Figure 4 As shown, the device 400 includes an access request determination module 410, configured to determine multiple access requests for network resources based on log information of network resources, wherein each access request includes information in multiple dimensions. The device 400 also includes a multi-group access segmentation determination module 420, configured to segment the multiple access requests into multiple groups of access requests based on the correlation of the multiple access requests in at least one of the multiple dimensions. The device 400 further includes an integrated behavior sequence determination module 430, configured to determine multiple integrated behavior sequences corresponding to the multiple groups of access requests based on the access time of each group of access requests, wherein the integrated behavior sequences include access behaviors to network resources at multiple time points. The device 400 also includes an integrated behavior sequence determination module 440, configured to determine at least one integrated behavior sequence corresponding to at least one accessing entity by performing behavior completion on at least one integrated behavior sequence among the multiple integrated behavior sequences. The device 400 also includes an automated access attacker identification module 450, configured to identify automated access attackers in at least one accessing entity based on at least one integrated behavior sequence. In this way, by integrating and completing the behavioral sequences, the completeness of reconstructing the user's behavioral sequences can be significantly improved. Thus, based on the integrated and completed behavioral sequences, it becomes easier to analyze more realistic and continuous behavioral sequences.

[0073] In some embodiments, at least one dimension includes at least one of the following: access time dimension, access address dimension, or cookie dimension. This allows for the subsequent integration and completion of the same user's behavioral sequence based on information from multiple dimensions.

[0074] In some embodiments, the multiple access request segmentation module 420 is further configured to, based on the access address dimension, identify at least two first access requests with the same access address among multiple access requests; and, in response to an access time interval between the at least two first access requests being less than a predetermined time interval, segment the at least two first access requests into one group of access requests within the multiple groups of access requests. Thus, by grouping access requests according to the access address dimension, the completeness of reconstructing the user's behavior sequence can be improved.

[0075] In some embodiments, the multiple access request segmentation module 420 is further configured to determine, based on the cookie dimension, whether the identifiers in the cookies of at least two second access requests are the same; and in response to the fact that the identifiers in the cookies of at least two second access requests are the same, to segment the at least two second access requests into one group of access requests in the multiple access requests. Thus, by grouping access requests based on CookieId, the completeness of reconstructing the user's behavior sequence can be improved.

[0076] In some embodiments, the completed behavior sequence determination module 440 is further configured to combine at least two of the multiple integrated behavior sequences into at least one completed behavior sequence based on the corresponding sequence lengths of the multiple integrated behavior sequences. Thus, by completing the behavior sequence according to the length of the integrated behavior sequence, complete behavior sequence reconstruction can be achieved.

[0077] In some embodiments, the completed behavior sequence determination module 440 is further configured to: determine a long behavior sequence among a plurality of integrated behavior sequences, wherein the sequence length of the long behavior sequence satisfies a first preset condition; determine a behavior sequence template corresponding to the long behavior sequence based on at least one behavioral feature of the long behavior sequence, wherein the behavior sequence template describes the behavioral pattern of the long behavior sequence; determine whether the plurality of integrated behavior sequences include at least one short behavior sequence matching the behavior sequence template, wherein the sequence length of the at least one short behavior sequence satisfies a second preset condition; and, in response to determining at least one short behavior sequence matching the behavior sequence template, add the at least one short behavior sequence to the long behavior sequence to determine one of the at least one completed behavior sequence. Thus, the behavior sequence completion method based on the long behavior sequence template enables the reconstruction of a complete behavior sequence.

[0078] In some embodiments, the apparatus 400 further includes a matching degree determination module, which is further configured to, for a first short behavior sequence in at least one short behavior sequence, use a dynamic time warping algorithm to determine the similarity between the first short behavior sequence and a long behavior sequence; determine the edit distance required to change the behavior in the first short behavior sequence to the behavior in the behavior sequence template; and determine the matching degree between the first short behavior sequence and the behavior sequence template based on the similarity and the edit distance. Thus, the behavior sequence completion method based on the long behavior sequence template enables the reconstruction of a complete behavior sequence.

[0079] In some embodiments, at least one behavioral feature includes at least one of the following: the time interval between each access behavior in the long behavioral sequence, the access path corresponding to each access behavior in the long behavioral sequence, or the interaction period corresponding to the long behavioral sequence. Thus, by automatically attaching temporally adjacent and pattern-similar behavioral sequences to the long behavioral sequence, complete behavioral sequence reconstruction can be achieved.

[0080] In some embodiments, the automated access attacker identification module 450 is further configured to generate a label for a first access entity corresponding to a first completed behavior sequence in at least one completed behavior sequence, using a machine learning model. The label indicates whether the first access entity is an automated access attacker. This allows for the analysis of features across multiple dimensions, thereby improving the accuracy of identifying automated access attackers.

[0081] In some embodiments, the automated access attacker identification module 450 is further configured to determine at least one feature of the first completed behavior sequence; and based on the at least one feature, to use a machine learning model to determine the label of the first access entity corresponding to the first completed behavior sequence. This significantly improves the completeness of reconstructing the user's behavior sequence.

[0082] In some embodiments, at least one feature includes at least one of the following: a temporal feature of the first completed behavior sequence, a semantic feature of the first completed behavior sequence, the length of the first completed behavior sequence, or the number of network resources corresponding to the first completed behavior sequence. Thus, based on the temporal feature, semantic feature, length of the behavior sequence, and number of network resources, the accuracy of identifying automated access attackers can be improved.

[0083] The units and / or modules included in device 400 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units and / or modules can be implemented using software and / or firmware, such as machine-executable instructions stored on a storage medium. In addition to or as an alternative to machine-executable instructions, some or all of the units and / or modules in device 400 can be implemented at least partially by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that can be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), and so on.

[0084] It should be understood that one or more steps in the above methods can be performed by suitable electronic devices or combinations of electronic devices. Such electronic devices or combinations of electronic devices may include, for example, […]. Figure 1 Server 130 in the middle.

[0085] Figure 5 A block diagram of an electronic device 500 in which one or more embodiments of the present disclosure may be implemented is shown. It should be understood that... Figure 5 The electronic device 500 shown is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 5 The electronic device 500 shown can be used to achieve Figure 1 Server 130.

[0086] like Figure 5 As shown, electronic device 500 is in the form of a general-purpose electronic device. Components of electronic device 500 may include, but are not limited to, one or more processors 510 or processing units, memory 520, storage device 530, one or more communication units 540, one or more input devices 550, and one or more output devices 560. Processor 510 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 520. In a multiprocessor system, multiple processors execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 500.

[0087] Electronic device 500 typically includes multiple computer storage media. Such media can be any available media accessible to electronic device 500, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 520 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 530 can be removable or non-removable media and can include machine-readable media, such as flash drives, disks, or any other media capable of storing information and / or data and accessible within electronic device 500.

[0088] Electronic device 500 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated... Figure 5 As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 520 may include computer program product 525 having one or more program modules configured to perform various methods or actions of various embodiments of this disclosure.

[0089] Communication unit 540 enables communication with other electronic devices via a communication medium. Additionally, the functionality of components of electronic device 500 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, electronic device 500 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.

[0090] Input device 550 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 560 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 500 can also communicate with one or more external devices (not shown) via communication unit 540 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 500, or with any device that enables electronic device 500 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interface (not shown).

[0091] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above. According to an exemplary implementation of this disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.

[0092] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0093] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0094] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0095] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0096] Various implementations of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. A method for identifying automated access attacks using a firewall, comprising: Based on the log information of the network resources, multiple access requests for the network resources are identified, and the multiple access requests include information from multiple dimensions. Based on the correlation of the multiple access requests in at least one of the multiple dimensions, the multiple access requests are divided into multiple groups of access requests; Based on the access time of each of the multiple access requests, a plurality of integrated behavior sequences corresponding to the multiple access requests are determined. The integrated behavior sequences include access behaviors to the network resources at multiple time points. By performing behavior completion on at least one of the plurality of integrated behavior sequences, at least one completed behavior sequence corresponding to at least one accessing entity is determined; as well as Based on the at least one completed behavior sequence, identify the automated access attacker in the at least one accessing entity.

2. The method according to claim 1, wherein the at least one dimension comprises at least one of the following: Access time dimension Access address dimension, or Cookie dimension.

3. The method according to claim 2, wherein dividing the plurality of access requests into multiple groups of access requests includes: Based on the access address dimension, at least two first access requests with the same access address are identified among the plurality of access requests; as well as In response to the fact that the access time interval between the at least two first access requests is less than a predetermined time interval, the at least two first access requests are divided into one group of access requests in the plurality of groups of access requests.

4. The method according to claim 2, wherein dividing the plurality of access requests into multiple groups of access requests includes: Regarding the cookie dimension, determine whether the identifiers in the cookies of at least two of the multiple access requests are the same; as well as If the identifier in the cookie of the at least two second access requests is the same, the at least two second access requests are divided into one group of access requests in the plurality of access requests.

5. The method of claim 1, wherein determining the at least one completed action sequence corresponding to the at least one accessing entity comprises: Based at least on the corresponding sequence lengths of the plurality of integrated behavior sequences, at least two of the plurality of integrated behavior sequences are combined into one of the at least one completed behavior sequence.

6. The method of claim 5, wherein combining at least two of the plurality of integrated behavior sequences into one of the at least one completed behavior sequence comprises: Determine the long behavior sequence among the plurality of integrated behavior sequences, wherein the sequence length of the long behavior sequence satisfies a first preset condition; Based on at least one behavioral feature of the long behavioral sequence, a behavioral sequence template corresponding to the long behavioral sequence is determined, wherein the behavioral sequence template describes the behavioral pattern of the long behavioral sequence. Determine whether the plurality of integrated behavior sequences include at least one short behavior sequence that matches the behavior sequence template, wherein the sequence length of the at least one short behavior sequence satisfies a second preset condition; as well as In response to determining the at least one short behavior sequence that matches the behavior sequence template, the at least one short behavior sequence is added to the long behavior sequence to determine one of the at least one completed behavior sequences.

7. The method of claim 6, wherein determining whether the plurality of integrated behavior sequences includes at least one short behavior sequence matching the behavior sequence template comprises: For the first short action sequence in the at least one short action sequence, The similarity between the first short action sequence and the long action sequence is determined using a dynamic time warping algorithm. Determine the edit distance required to change the behavior in the first short behavior sequence to the behavior in the behavior sequence template; as well as Based on the similarity and the edit distance, the matching degree between the first short behavior sequence and the behavior sequence template is determined.

8. The method of claim 6, wherein the at least one behavioral feature comprises at least one of the following: The time interval between each access action in the long action sequence. The access path corresponding to each access behavior in the long behavior sequence, or The interaction period corresponding to the long behavior sequence.

9. The method of claim 1, wherein identifying an automated access attacker in the at least one accessing entity comprises: For the first completed behavior sequence in the at least one completed behavior sequence, a machine learning model is used to generate a label for the first accessing entity corresponding to the first completed behavior sequence, the label indicating whether the first accessing entity is an automated access attacker.

10. The method of claim 9, wherein outputting a label for the accessed entity corresponding to the completed behavior sequence using a machine learning model comprises: Determine at least one feature of the first completed action sequence; as well as Based on the at least one feature, a machine learning model is used to determine the label of the first accessed entity corresponding to the first completed behavior sequence.

11. The method of claim 10, wherein the at least one feature comprises at least one of the following: The temporal characteristics of the first completed action sequence, The semantic features of the first completed action sequence The length of the first completed line sequence, or The number of network resources corresponding to the first completed action sequence.

12. An apparatus for identifying abnormal access in a firewall, comprising: The access request determination module is configured to determine multiple access requests for the network resource based on log information of the network resource, wherein the multiple access requests include information from multiple dimensions. The multiple access request segmentation module is configured to divide the multiple access requests into multiple access requests based on the correlation degree of the multiple access requests in at least one of the multiple dimensions. The integrated behavior sequence determination module is configured to determine multiple integrated behavior sequences corresponding to the multiple access requests based on the access time of each access request in the multiple access requests. The integrated behavior sequences in the multiple integrated behavior sequences include access behaviors to the network resources at multiple time points. The completed behavior sequence determination module is configured to determine at least one completed behavior sequence corresponding to at least one access entity by performing behavior completion on at least one integrated behavior sequence among the plurality of integrated behavior sequences; as well as An automated access attacker identification module is configured to identify anomalous access entities among the at least one access entity based on the at least one completed behavior sequence.

13. An electronic device, comprising: At least one processor; as well as At least one memory coupled to the at least one processor and storing instructions for execution by the at least one processor, the instructions causing the electronic device to perform the method according to any one of claims 1 to 11 when executed by the at least one processor.

14. A computer-readable storage medium having stored thereon computer-executable instructions that can be executed by a processor to implement the method according to any one of claims 1 to 11.

15. A computer program product comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 11.