Method for determining access frequency of access interface

By acquiring transaction response data and call order of the access interface, the access frequency can be dynamically adjusted, solving the problem that fixed rules in existing technologies are difficult to adapt to dynamic threat environments, thus improving user experience and system security.

CN120915523APending Publication Date: 2025-11-07AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511076978.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing access control policies based on fixed rules are difficult to adapt to dynamically changing threat environments, resulting in a reduced user experience.

Method used

By acquiring transaction response data and call order of the access interface, the access frequency is dynamically adjusted. The trust value is determined using the first, second, and third risk assessment attributes, and the target access frequency is set in combination with the benchmark access frequency.

Benefits of technology

It achieves flexibility and intelligence in access frequency, improves user experience, and enhances system security and resource allocation efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915523A_ABST
    Figure CN120915523A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method for determining the access frequency of an access interface, and the method comprises the steps: obtaining an access interface called when a transaction is generated, and transaction response data for a target object; determining a first risk assessment attribute according to an interface calling actual sequence of the access interface and a preset calling sequence; determining a second risk assessment attribute according to the access frequency of the access interface and a preset access frequency; determining a third risk assessment attribute according to the transaction response data and preset transaction response data; determining a trustworthy value of the target object according to the first, second and third risk assessment attributes; for at least one access interface, the target access frequency of the access interface is determined according to the reference access frequency and the trustworthiness value of the access interface, according to the technical scheme of the embodiment of the invention, the access frequency is dynamically adjusted based on the access interface and the transaction response data called when the transaction is generated, the user experience is improved, and the user experience is improved. And the effects of flexibility and intelligence of access frequency setting are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the technical field of data analysis, and in particular, to a method for determining access frequency of an access interface. BACKGROUND

[0002] With the rapid development of Internet technology, the types and complexity of network security threats in financial transactions are increasing. In order to resist network security threats and protect users' personal information and account security, many online services and platforms have begun to implement access frequency limits for personal accounts.

[0003] However, many current systems still use access control strategies based on fixed rules, which not only make it difficult to adapt to dynamically changing threat environments, but also reduce user experience. SUMMARY

[0004] Embodiments of the present disclosure provide a method for determining access frequency of an access interface to dynamically adjust access frequency, improve user experience, and achieve flexibility and intelligence of access frequency settings.

[0005] In a first aspect, embodiments of the present disclosure provide a method for determining access frequency of an access interface, the method comprising:

[0006] For a target object, at least one access interface called when a transaction is generated within a preset time period is obtained, and transaction response data of the at least one access interface is obtained;

[0007] According to an actual order of interface calls of the at least one access interface when the target object triggers a transaction and at least one interface preset call order corresponding to the transaction, a first risk assessment attribute is determined; according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and an interface preset access frequency corresponding to the access interface, a second risk assessment attribute is determined; according to transaction response data of the at least one access interface and at least one interface preset transaction response data corresponding to the access interface, a third risk assessment attribute is determined; wherein the interface preset call order includes a call order of two access interfaces;

[0008] According to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute, a trust value of the target object is determined;

[0009] For the at least one access interface, according to a reference access frequency of the access interface and the trust value, a target access frequency of the access interface is determined; wherein the reference access frequency is preset according to an interface type of the access interface.

[0010] In a second aspect, an embodiment of the present application further provides a device for determining access frequency of an access interface, the device comprising:

[0011] an access interface obtaining module configured to obtain, for a target object, at least one access interface called when a transaction is generated within a preset time length, and transaction response data of the at least one access interface;

[0012] a risk assessment attribute determining module configured to determine a first risk assessment attribute according to an actual sequence of interface calls of the at least one access interface when the target object triggers a transaction and at least one interface preset call sequence corresponding to the transaction, determine a second risk assessment attribute according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and an interface preset access frequency corresponding to the access interface, and determine a third risk assessment attribute according to the transaction response data of the at least one access interface and at least one interface preset transaction response data corresponding to the access interface, wherein the interface preset call sequence comprises a call sequence of two access interfaces;

[0013] a trustworthiness value determining module configured to determine a trustworthiness value of the target object according to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute;

[0014] a target access frequency determining module configured to determine a target access frequency of the at least one access interface according to a reference access frequency of the access interface and the trustworthiness value, wherein the reference access frequency is preset according to an interface type of the access interface.

[0015] In a third aspect, an embodiment of the present application further provides an electronic device, the electronic device comprising:

[0016] one or more processors;

[0017] a storage device configured to store one or more programs,

[0018] when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the method for determining access frequency of an access interface according to any one of the embodiments of the present application.

[0019] In a fourth aspect, an embodiment of the present application further provides a storage medium containing computer executable instructions, when the computer executable instructions are executed by a computer processor, the computer processor is used to execute the method for determining access frequency of an access interface according to any one of the embodiments of the present application.

[0020] In a fifth aspect, an embodiment of the present application further provides a computer program product comprising a computer program, wherein the computer program, when executed by a processor, implements the method for determining the access frequency of an access interface according to any one of the embodiments of the present application.

[0021] The technical scheme of the embodiment of the present application, for a target object, acquires at least one access interface called when a transaction is generated within a preset time length and transaction response data of the at least one access interface. Then, according to an actual calling sequence of the at least one access interface when the target object triggers the transaction and a preset calling sequence of the at least one interface corresponding to the transaction, a first risk assessment attribute is determined. According to an access frequency of the at least one access interface within a preset sliding window when the target object triggers the transaction and a preset access frequency of the interface corresponding to the access interface, a second risk assessment attribute is determined. According to the transaction response data of the at least one access interface and preset transaction response data of the at least one interface corresponding to the access interface, a third risk assessment attribute is determined. The preset calling sequence of the interface includes a calling sequence of two access interfaces. Further, according to the first risk assessment attribute, the second risk assessment attribute and the third risk assessment attribute, a trust value of the target object is determined. Finally, for the at least one access interface, according to a reference access frequency of the access interface and the trust value, a target access frequency of the access interface is determined. The reference access frequency is preset according to the interface type of the access interface. The problem that the existing technology adopts an access control strategy based on a fixed rule and is difficult to adapt to a dynamically changing threat environment and reduces the user experience is solved. The embodiment of the present application realizes dynamic adjustment of the access frequency based on the access interface called when the transaction is generated and the transaction response data, improves the user experience, and achieves the effects of flexibility and intelligence of the access frequency setting. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical scheme of the exemplary embodiments of the present application, the drawings needed in the description of the embodiments are briefly introduced as follows. Obviously, the drawings introduced are only a part of the drawings of the embodiments to be described by the present application, and the other drawings can be obtained by those skilled in the art without creating any creative labor on the basis of these drawings.

[0023] Figure 1 is a flowchart of a method for determining the access frequency of an access interface provided by the embodiment of the present application;

[0024] Figure 2 is a flowchart of a method for determining the access frequency of an access interface provided by the embodiment of the present application;

[0025] Figure 3 is a schematic diagram of a module provided by the embodiment of the present application;

[0026] Figure 4 is a schematic diagram of determining a trust value provided by an embodiment of the present disclosure;

[0027] Figure 5 is a structural schematic diagram of a device for determining access frequency of an access interface provided by an embodiment of the present disclosure;

[0028] Figure 6 is a structural schematic diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0029] The present application will be further described below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.

[0030] Before introducing the technical solutions provided by the embodiments of the present disclosure, the application scenarios can be exemplarily described. The technical solutions provided by the embodiments of the present disclosure can be applied in the scenario of determining the access frequency of the access interface called by the target object when transacting. For example, it can be applied in the scenario of determining the target access frequency of each access interface based on at least one access interface called by the target object when transacting within a preset time length and transaction response data of the access interface. Based on the technical solutions of the embodiments of the present disclosure, the access frequency is dynamically adjusted based on the access interface called when transacting and the transaction response data, the user experience is improved, and the flexibility and intelligence of the access frequency setting are achieved.

[0031] Embodiment one

[0032] Figure 1 is a flowchart of a method for determining access frequency of an access interface provided by an embodiment of the present disclosure. The embodiments of the present disclosure are applicable to the case of determining the access frequency of the access interface called by the target object when transacting. The method can be executed by a device for determining access frequency of an access interface. The device can be realized in the form of software and / or hardware. The hardware can be an electronic device of a mobile terminal. The electronic device can execute the method for determining access frequency of an access interface provided by the present technical solution.

[0033] As shown in Figure 1 , the method comprises:

[0034] S110, for a target object, acquiring at least one access interface called when transacting within a preset time length and transaction response data of the at least one access interface.

[0035] The target object generally refers to a user who is expected to be analyzed or monitored. For financial transactions, the target object can be a specific customer account, a credit card account, or a loan account. The preset time length is a set time range. In the context of financial transactions, the preset time length can be one hour, one day, one week, or one month in the past, and the specific time length can be defined according to needs. The transaction includes capital deposit, capital withdrawal, capital transfer, and bill payment. The access interface refers to an API or service used in the system for transaction operations. The access interface includes an account query interface, a transaction submission interface, a transaction status query interface, a capital deposit interface, a capital withdrawal interface, an identity verification interface, a report generation interface, and the like. The transaction response data refers to the relevant data returned by the system after the target object calls the access interface. The transaction response data can include transaction status data, transaction timestamp data, transaction capital data, transaction type data, or account remaining capital update data.

[0036] Specifically, first, the target object is determined and the preset time length is set. Then, the system obtains the relevant access interfaces called when the transaction is generated within the preset time length, and obtains the transaction response data within the preset time length. Finally, the system returns at least one access interface called when the transaction is generated and the transaction response data for subsequent analysis and processing.

[0037] S120, according to the interface calling actual sequence of at least one access interface triggered by the target object when the transaction and the interface preset calling sequence corresponding to the transaction, determine the first risk assessment attribute; according to the access frequency of at least one access interface within the preset sliding window triggered by the target object when the transaction and the interface preset access frequency corresponding to the access interface, determine the second risk assessment attribute; according to the transaction response data of at least one access interface and at least one interface preset transaction response data corresponding to the access interface, determine the third risk assessment attribute.

[0038] The interface preset calling sequence includes the calling sequence of two access interfaces.

[0039] It should be noted that the interface calling actual sequence refers to the actual calling sequence of the access interface initiated by the target object within the preset time length. For example, the actual calling sequence of the access interface initiated by the target user within the preset time length can be from the user login interface to the account query interface and then to the transfer submission interface. The preset calling sequence is the interface calling sequence including two access interfaces preset in the system design. For example, the preset calling sequence can be from the user login interface to the identity authentication interface, the preset calling sequence can be from the identity authentication interface to the account query interface, and the preset calling sequence can be from the account query interface to the transfer submission interface. The first risk assessment attribute is an attribute value obtained by evaluating the matching degree of the actual interface calling sequence of the target object and at least one interface preset calling sequence.

[0040] It should be noted that the preset sliding window refers to a time range for monitoring the access frequency of the access interface. For example, the window length of the preset sliding window can be 5 minutes, and the step length of the preset sliding window can be 1 minute. The access frequency refers to the number of times that the target object calls a certain access interface within the preset sliding window. For example, for the identity authentication access interface, the access frequency of 5 means that the target object calls the identity authentication access interface 5 times within the preset sliding window. The interface preset access frequency refers to the preset number of calls within the preset sliding window for each access interface. For example, for the identity authentication access interface, the interface preset access frequency corresponding to the identity authentication access interface can be 1 time. The second risk assessment attribute is an attribute value obtained based on the access frequency of at least one access interface within the preset sliding window and the interface preset access frequency.

[0041] It should also be noted that the interface preset transaction response data refers to the expected return data for each access interface under normal circumstances. For example, for the transfer submission interface, the corresponding interface preset transaction response data can include: status: success; transaction ID: 123456; timestamp: 9:00. The third risk assessment attribute is an attribute value obtained according to the comparison between the actual transaction response data and the preset transaction response data.

[0042] Optionally, according to the state symbol corresponding to at least one access interface and the interface call actual sequence of at least one access interface, at least one access interface at the time of triggering the transaction is changed into a state symbol sequence; according to the state symbol, for at least one interface preset call sequence, the interface preset call sequence is changed into a preset state symbol sequence; according to the state symbol sequence, at least one preset state symbol sequence and the probability value corresponding to the preset state symbol sequence, the first risk assessment attribute is determined.

[0043] It should be noted that the state symbol is used to represent the identifier corresponding to the access interface, and different access interfaces correspond to different state symbols. The state symbol is usually a combination of letters or numbers, which is used to simplify the representation of the access interface. For example, the user login interface can be represented by S1; the identity authentication interface can be represented by S2; and the transfer submission interface can be represented by S3. For the access interface, the sequence generated after the access interface is converted into a state symbol according to the state symbol sequence is the state symbol sequence. For example, when the interface call actual sequence of at least one access interface is from the user login interface to the identity authentication interface and then to the transfer submission interface, the corresponding state symbol sequence can be from S1 to S2 and then to S3.

[0044] It should be noted that the preset state symbol sequence refers to the sequence generated after the access interface is converted into state symbols according to the preset calling sequence of the interface. For example, when the preset calling sequence is from the user login interface to the identity authentication interface, the corresponding preset state symbol sequence can be from S1 to S2; when the preset calling sequence is from the identity authentication interface to the transfer submission interface, the corresponding preset state symbol sequence can be from S2 to S3. The probability value refers to the probability of occurrence of each preset state symbol sequence defined in advance. For example, when the preset state symbol sequence is S1 to S2, the corresponding probability value can be 80%; when the preset state symbol sequence is S1 to S3, the corresponding probability value can be 5%.

[0045] It should also be noted that the first risk assessment attribute can be used to quantify the difference and potential risk between the state symbol sequence and the at least one preset state symbol sequence. In determining the first risk assessment attribute, first, at least one adjacent state symbol pair in the current state symbol sequence is traversed, the at least one adjacent state symbol pair is matched with the at least one preset state symbol sequence, and the probability value corresponding to each adjacent state symbol pair is determined. For example, when the state symbol sequence is from S1 to S2 and then to S3, it is determined that the state symbol sequence matches the preset state symbol sequence S1 to S2 and the preset state symbol sequence S2 to S3. Then, the first risk assessment attribute is calculated according to the probability value of the at least one matched preset state symbol sequence. Specifically, a preset extremely low probability threshold can be determined, and when the probability value of the at least one matched preset state symbol sequence is less than the preset extremely low probability threshold, the adjacent state symbol pair can be marked as an abnormal transition. For the probability value of the at least one matched preset state symbol sequence, the number of probability values less than the preset extremely low probability threshold is counted, i.e., the number of abnormal transitions in the current state symbol sequence is counted. According to the number of abnormal transitions in the current state symbol sequence and the number of all adjacent state symbol pairs, the first risk assessment attribute is determined. If the number of abnormal transitions in the current state symbol sequence is 0, it is considered that the first risk is low risk, and the first risk assessment attribute is randomly taken within 0-30; if the number of abnormal transitions in the current state symbol sequence is within the first preset proportion threshold, it is considered that the first risk is medium risk, and the first risk assessment attribute can be calculated according to the formula ; if the number of abnormal transitions in the current state symbol sequence is greater than the first preset proportion threshold, it is considered that the first risk is high risk, and the first risk assessment attribute is determined according to .

[0046] Optionally, a single second risk evaluation attribute corresponding to a single access interface is determined according to the access frequency of the access interface within the at least one preset sliding window and the interface preset access frequency corresponding to the access interface; and for the at least one access interface, a second risk evaluation attribute is determined according to at least one single second risk evaluation attribute corresponding to all single access interfaces.

[0047] It should be noted that the single second risk evaluation attribute is an attribute value evaluated based on the difference between the access frequency of a single access interface within the preset sliding window and the interface preset access frequency. The single second risk evaluation attribute reflects the degree of deviation of the access behavior of the single access interface from the normal mode, and the value range can be 0-100. The larger the value, the more serious the deviation from the normal mode, and the higher the corresponding single second risk evaluation attribute. For example, the deviation degree of the single access interface can be determined according to the formula . Further, the deviation degree can be mapped to the single second risk evaluation attribute in the range of 0-100 by using a linear mapping relationship. Finally, the second risk evaluation attribute can be determined according to the average value or the maximum value of all single second risk evaluation attributes.

[0048] In this embodiment, for the at least one transaction response data, a data vector corresponding to the transaction response data is determined based on feature conversion; for at least one data vector corresponding to the access interface, a single third risk evaluation attribute corresponding to the access interface is determined according to at least one first element in the data vector and at least one second element corresponding to at least one interface preset transaction response data corresponding to the access interface; and for the at least one access interface, a third risk evaluation attribute is determined according to all single third risk evaluation attributes.

[0049] The transaction response data at least includes an interface path, a transmission protocol method, a response status code, a request parameter quantity, a response time length, an access time, and a transaction value attribute.

[0050] It should be noted that the data vector is a set of numerical values obtained after the transaction response data is converted by feature conversion. The data vector represents the features of the transaction response data in the form of a vector, each dimension corresponds to a specific feature value, which is used for subsequent calculation of the third risk assessment attribute. When converting non-numeric features in the transaction response data into understandable numerical form, for category type features such as interface paths, a hash function can be used to map them to fixed-length numbers; for time type features, the features can be converted to 24-hour sinusoidal values to retain periodicity; for text type parameters, statistical quantities such as parameter value length or special character proportion can be calculated. The numerical features are arranged in a certain order to form a data vector. For example, for transaction response data, a data vector [1000, 1, 200, 3] can be obtained after feature conversion. Among them, 1000 can represent the interface path, 1 can represent the transmission protocol method, 200 can represent the response status code, and 3 can represent the number of request parameters. The first element refers to the feature values in the data vector. The second element refers to the feature values in the vector obtained by converting the interface preset transaction response data corresponding to the access interface.

[0051] It should be noted that the single third risk assessment attribute is an attribute value evaluated based on the difference between the first element in the at least one data vector corresponding to the access interface and the at least one second element corresponding to the interface preset transaction response data. The single third risk assessment attribute reflects the degree to which the transaction response data of a single access interface deviates from the normal mode, and the value range can be 0-100, the larger the value, the more serious the deviation from the normal mode, and the higher the risk. For at least one first element and at least one second element, the single third risk assessment attribute can be calculated according to the cosine similarity formula. The third risk assessment attribute can be determined according to the average value or maximum value of all single third risk assessment attributes.

[0052] Specifically, after obtaining the at least one access interface called when generating transactions within a preset time period and the transaction response data of the at least one access interface, the first risk assessment attribute can be used to quantify the difference between the state symbol sequence and the at least one preset state symbol sequence and the potential risk; the second risk assessment attribute can be used to quantify the difference between the access frequency of the at least one access interface within the preset sliding window and the preset access frequency; and the third risk assessment attribute can be used to quantify the difference between the transaction response data and the interface preset transaction response data.

[0053] S130, determining the trust value of the target object according to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute.

[0054] The trustworthiness value is a quantitative indicator designed to assess the trustworthiness and security of the target object. The trustworthiness value is usually based on the comprehensive results of multiple risk assessment attributes, reflecting the risk level of the target object when performing certain operations. The higher the trustworthiness value, the higher the trustworthiness and the lower the risk.

[0055] Specifically, after calculating the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute, the trustworthiness value of the target object can be calculated based on the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute.

[0056] S140, for at least one access interface, according to the reference access frequency and the trustworthiness value of the access interface, determining the target access frequency of the access interface.

[0057] The reference access frequency is pre-set according to the interface type of the access interface.

[0058] It should be noted that the target access frequency refers to the expected access frequency of a certain access interface within a certain time period, which is calculated based on the reference access frequency of the access interface and the trustworthiness value of the target object. The target access frequency reflects the allowed access times under the premise of considering security and normal use, and can be used to monitor and limit the frequency of certain operations to prevent potential abuse or attacks. The interface type of the access interface refers to the standard for classifying the access interface according to its function and use scenario. The interface type determines the reference access frequency of the interface.

[0059] Optionally, the central processor fingerprint, image processor fingerprint, and hard disk fingerprint of the device used by the target object during the transaction are obtained at a preset frequency; the device fingerprint of the device is determined according to the central processor fingerprint, image processor fingerprint, and hard disk fingerprint; when it is detected that the device fingerprint changes, the trustworthiness value of the target object is triggered to be calculated, and the updated trustworthiness value is determined; the target access frequency of the access interface is determined according to the basic access frequency of the access interface and the updated trustworthiness value.

[0060] The preset frequency refers to a frequency of pre-setly obtaining a central processing unit fingerprint, an image processor fingerprint, and a hard disk fingerprint of a device used by the target object in a transaction. The central processing unit fingerprint is a unique identifier generated based on a hardware feature of a central processing unit. The central processing unit fingerprint usually uses a specific algorithm to process a model and a microcode version of the CPU to generate a short, fixed-length string. The central processing unit fingerprint is used to identify and verify the CPU information of the device. For example, the central processing unit fingerprint can be generated in the following manner: central processing unit fingerprint = SHA3 (model + microcode version) [0:8], and the obtained central processing unit fingerprint can be "8f3a7d1c". The image processor fingerprint is a unique identifier generated based on a hardware feature of an image processor. The image processor fingerprint uses a specific algorithm to process a vendor ID and a device ID of the GPU to generate a short, fixed-length string, which is used to identify and verify the GPU information of the device. For example, the image processor fingerprint can be generated in the following manner: image processor fingerprint = CRC32 (vendor ID + device ID), and the obtained image processor fingerprint can be "45b6e2f9". The hard disk fingerprint is a unique identifier generated based on a hardware feature of a hard disk drive. The hard disk fingerprint is generated by processing a model and a hashed serial number of the hard disk, and is used to identify and verify the hard disk information of the device. For example, the hard disk fingerprint can be generated in the following manner: hard disk fingerprint = SHA256 (model + hashed serial number) [0:8], and the obtained hard disk fingerprint can be "3d82f1e6".

[0061] It should be noted that the device fingerprint is a comprehensive identifier, which is generated based on the central processing unit fingerprint, the image processor fingerprint, and the hard disk fingerprint in the device. The device fingerprint is used to uniquely identify the device of the user, and to prevent device forgery and anonymization to some extent. The central processing unit fingerprint, the image processor fingerprint, and the hard disk fingerprint can be processed to generate the device fingerprint. Updating the trust value refers to that when it is judged that the device fingerprint changes, the trust value is calculated by using at least one access interface called when a transaction is generated within a preset time period and transaction response data of the at least one access interface.

[0062] In this embodiment, the central processing unit fingerprint, the image processor fingerprint, and the hard disk fingerprint are combined to obtain an intermediate combined fingerprint; and the device fingerprint is obtained according to the intermediate combined fingerprint, an encryption hash function, and a salt value.

[0063] It should be noted that the intermediate combined fingerprint refers to the fingerprint obtained by connecting the central processor fingerprint, the image processor fingerprint and the hard disk fingerprint. That is, the intermediate combined fingerprint can be: central processor fingerprint:image processor fingerprint:hard disk fingerprint. For example, when the central processor fingerprint is 8f3a7d1c, the image processor fingerprint is 45b6e2f9, and the hard disk fingerprint is 3d82f1e6, the obtained intermediate combined fingerprint can be: 8f3a7d1c:45b6e2f9:3d82f1e6. The cryptographic hash function can be the HMAC-SHA256 algorithm. The salt value refers to a defined random code. For example, the calculation formula of the device fingerprint can be: device fingerprint =HMAC -SHA256(salt value, intermediate combined fingerprint). Through the above steps, a unique device fingerprint can be generated, which has high consistency and can be used to identify the device of the target object. The generation process of the device fingerprint takes into account the requirements of data protection such as GDPR and CCPA, and ensures the privacy of the target object is protected.

[0064] Specifically, after obtaining the trust value, for each access interface, the target access frequency of each access interface is determined according to the reference access frequency of the access interface and the calculated trust value.

[0065] The technical scheme of the embodiments of the present disclosure, for the target object, obtains at least one access interface called when generating a transaction within a preset time period, and transaction response data of the at least one access interface. Then, according to the actual calling order of the at least one access interface triggered by the target object when triggering the transaction and the preset calling order of the at least one interface corresponding to the transaction, a first risk assessment attribute is determined. According to the access frequency of the at least one access interface within the preset sliding window when the target object triggers the transaction and the interface preset access frequency corresponding to the access interface, a second risk assessment attribute is determined. According to the transaction response data of the at least one access interface and the at least one interface preset transaction response data corresponding to the access interface, a third risk assessment attribute is determined. Wherein, the calling order of two access interfaces is included in the interface preset calling order. Further, according to the first risk assessment attribute, the second risk assessment attribute and the third risk assessment attribute, the trust value of the target object is determined. Finally, for the at least one access interface, the target access frequency of the access interface is determined according to the reference access frequency of the access interface and the trust value. Wherein, the reference access frequency is preset according to the interface type of the access interface. The problem that the existing technology adopts the access control strategy based on fixed rules, and it is difficult to adapt to the dynamically changing threat environment, and the user experience is reduced, is solved. The present disclosure realizes dynamic adjustment of access frequency based on the access interface called when generating a transaction and transaction response data, improves user experience, and achieves the effects of flexibility and intelligence of access frequency setting.

[0066] Embodiment two

[0067] Figure 2 The flowchart of the method for determining the access frequency of the access interface provided in the embodiments of the present application is illustrated in detail based on the foregoing embodiments, and the determination of the trust value of the target object according to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute is illustrated in detail. The specific implementation can be referred to the technical solutions of the embodiments. The same or corresponding technical terms as the foregoing embodiments are not described herein.

[0068] As shown in the method, the method specifically comprises the following steps: Figure 2

[0069] S210, for the target object, acquiring at least one access interface called when a transaction is generated within a preset time length, and transaction response data of the at least one access interface.

[0070] S220, determining the first risk assessment attribute according to the actual calling sequence of the at least one access interface when the target object triggers a transaction and the preset calling sequence of the at least one interface corresponding to the transaction; determining the second risk assessment attribute according to the access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and the preset access frequency of the interface corresponding to the access interface; and determining the third risk assessment attribute according to the transaction response data of the at least one access interface and the preset transaction response data of the at least one interface corresponding to the access interface.

[0071] S230, determining the risk assessment attribute according to the first risk assessment attribute, the first weight, the second risk assessment attribute, the second weight, the third risk assessment attribute, and the third weight.

[0072] The first weight refers to the relative importance of the first risk assessment attribute in the determination of the risk assessment attribute. The value of the first weight is usually between 0 and 1. The selection of the first weight should consider the importance of the first risk assessment attribute to the overall risk assessment attribute. The second weight refers to the relative importance of the second risk assessment attribute in the determination of the risk assessment attribute. The value of the second weight is usually between 0 and 1. The selection of the second weight should consider the importance of the second risk assessment attribute to the overall risk assessment attribute. The third weight refers to the relative importance of the third risk assessment attribute in the determination of the risk assessment attribute. The value of the third weight is usually between 0 and 1. The selection of the third weight should consider the importance of the third risk assessment attribute to the overall risk assessment attribute. The sum of the first weight, the second weight, and the third weight can be 1. For example, the first weight can be 0.5, the second weight can be 0.2, and the third weight can be 0.3.

[0073] ​It should be noted that the formula for determining the risk evaluation attribute according to the first risk evaluation attribute, the first weight, the second risk evaluation attribute, the second weight, the third risk evaluation attribute, and the third weight can be:

[0074]

[0075] Specifically, the product of the first risk evaluation attribute and the first weight, the product of the second risk evaluation attribute and the second weight, and the product of the third risk evaluation attribute and the third weight are added to determine the risk evaluation attribute.

[0076] S240, according to the risk evaluation attribute and the trust value, determining the function of the target object, determining the trust value of the target object.

[0077] Optionally, the trust value determination function is:

[0078]

[0079] Wherein, CTP is the trust value; URE is the risk evaluation attribute; K represents the weight, which can be 10; C is a constant, which can be 0.6.

[0080] Specifically, after inputting the determined risk evaluation attribute, weight and constant into the trust value determination function, the trust value of the target object can be determined.

[0081] S250, for at least one access interface, according to the reference access frequency of the access interface and the trust value, determining the target access frequency of the access interface.

[0082] Optionally, for at least one access interface, the reference access frequency of the access interface is determined according to the interface type of the access interface; for at least one access interface, the trust value is multiplied by the preset reference access frequency corresponding to the access interface to determine the target access frequency of the access interface.

[0083] Wherein, the reference access frequency includes first preset reference access frequency, second preset reference access frequency and third preset reference access frequency.

[0084] It should be noted that the access interface can be divided into three types according to functions and use scenarios. The reference access frequencies of the three types of access interfaces are the first preset reference access frequency, the second preset reference access frequency, or the third preset reference access frequency. When the interface type of the access interface is the first type, the target access frequency of the access interface is the trusted value multiplied by the first preset reference access frequency; when the interface type of the access interface is the second type, the target access frequency of the access interface is the trusted value multiplied by the second preset reference access frequency; and when the interface type of the access interface is the third type, the target access frequency of the access interface is the trusted value multiplied by the third preset reference access frequency.

[0085] In the embodiment, the authentication mode of the target object is configured according to the interface type of the at least one access interface when the target object triggers a transaction.

[0086] It should be noted that three-level progressive security authentication can be used to automatically match the authentication mode according to the interface type of the at least one access interface when a transaction is triggered, and to realize progressive defense from lightweight to strong binding. For example, the first-level enhanced authentication can be short message verification; the second-level enhanced authentication can be password verification plus short message verification code; and the third-level enhanced authentication can be password authentication plus USB Key medium authentication. The hierarchical enhanced security authentication process can be as follows: for the first-level enhanced authentication, a short message verification request can be initiated to the target object after the request of the target object is intercepted. After the client inputs the short message verification code, the server verifies the short message verification code and releases the request after the verification is passed. For the second-level enhanced authentication, the target object can be triggered to perform authentication for the second time within a preset time period, and the target object is required to complete password authentication and synchronously send a short message verification code to the registered client. After the double verification is passed, the request is released. For the third-level enhanced authentication, the target object can be triggered to perform authentication for the third time within a preset time period, and the target object is required to complete password authentication and USB Key security medium authentication, and the request is released after the authentication is passed. If the enhanced authentication is not passed, the access function of the target object to the access interface is blocked.

[0087] The technical scheme of the embodiment of the present disclosure determines the trusted value of the target object according to the risk assessment attribute and the trusted value determination function after determining the risk assessment attribute. Finally, for the at least one access interface, the target access frequency of the access interface is determined according to the reference access frequency of the access interface and the trusted value, and finally the target access frequency of the access interface is configured based on the target access frequency, which can effectively improve the security, user trust, resource configuration efficiency, and user experience of the system, and provides strong security protection and flexibility for modern digital transactions and services.

[0088] Embodiment three

[0089] As an optional embodiment of the present invention, an example is provided to further illustrate the invention.

[0090] It should be noted that, see Figure 3 The system comprises seven modules: data acquisition and generation, risk assessment model, user risk profile generation, dynamic profile update, access frequency setting, interface enhancement authentication, and configuration update. The data acquisition and generation module primarily involves the collection and storage of basic access data, operation sequence data, and environmental data for the target object. Basic access data includes user session ID, IP address, transaction timestamp, accessed page URL, and UserAgent. Operation sequence data includes click events, page dwell time, page redirection paths, and API request parameters. Environmental data includes CPU characteristics, GPU information, and disk information to generate unique identifiers. Basic access data is primarily collected through a server-side log collection plugin. Click events and page dwell events are collected using JavaScript tracking. Environmental data is obtained through JavaScript scripts and desktop tools. User click events, page dwell time, page redirection paths, and API request parameters can be stored in a time-series database. User session ID, IP address, login timestamp, and accessed page URL can be stored as static features in a relational database. For data such as customer risk levels and weights, JSON format data can be stored using NoSQL.

[0091] See the risk assessment model module. Figure 4 For the collected data, feature extraction is performed, and the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute are calculated using Markov chains, request frequency sliding windows, and API call timing.

[0092] In the user risk profile generation module, the user risk profile dimension data includes: target object ID, device fingerprint, risk assessment attribute URE, and trust value CTP. Specifically, the risk assessment attribute URE = first risk assessment attribute * α + second risk assessment attribute * β + third risk assessment attribute * γ. The first, second, and third risk assessment attributes all range from 1 to 100. Furthermore, α, β, and... γ The sum of is 1. Among them, α, β, and γ This is a dynamic value that can be set according to different system types. A higher weight indicates a higher level of control over this type of risk. The function is determined based on the trust value. Determine the trust value (CTP).

[0093] In the portrait dynamic updating module, two user portrait updating strategies are supported. The first is real-time triggering, i.e., updating the portrait immediately when high-risk behavior is detected based on the system set rules, i.e., updating the trust value. The other is batch updating at a fixed time, i.e., the system can calculate the trust value of all target objects every hour, and provide an interface for accessing the target access frequency.

[0094] In the access frequency setting module, the classification and reference threshold configuration of the access interface can be realized. According to the business sensitivity, resource consumption and attack exposure surface of the access interface, it can be automatically classified into three levels: high-risk interfaces can include transfer transaction interfaces and target object information modification interfaces, etc. Medium-risk interfaces can include target object account circulation transaction interfaces, etc. Low-risk interfaces can include information query interfaces, etc. For dynamic frequency threshold calculation, two modes of control mechanism are supported. For static reference threshold, the initial frequency can be preset based on the type of access interface. For dynamic reference threshold, the interface access frequency of the user can be dynamically set as static reference threshold*CTP based on the CTP value calculated by URE. The system supports static or dynamic reference threshold setting according to different transactions.

[0095] In the interface enhanced authentication module, three-level progressive security authentication can be used. According to the type of at least one access interface triggered by the transaction, the authentication mode is automatically matched to realize progressive defense from lightweight to strong binding.

[0096] In the configuration updating module, it can be provided for operation and management personnel to support the rectification of the target access frequency of the access interface and the adjustment of the dynamic weight coefficient generated by the risk assessment attribute, and to create a more humanized and intelligent system. The operation personnel can manually intervene and adjust the trust value to ensure the accuracy of the results. The upper and lower limit setting function of the trust value is provided to dynamically adjust the sensitivity of risk assessment according to business needs. The operation personnel is allowed to configure the related parameters of the target access frequency of the access interface, and to support the adjustment of the calculation logic of the target access frequency of the access interface. The configuration function of the target access frequency control rules of the access interface is provided, the target access frequency of the access interface can be dynamically configured according to the system capacity, the management and control strategies corresponding to different risk levels are supported, such as increasing the verification link, etc.

[0097] The technical solutions of the embodiments of the present disclosure can analyze the access interface and transaction response data of the target object in real time, dynamically update the target access frequency of the access interface, thereby timely identifying potential risks and improving the accuracy and timeliness of risk assessment. According to each target object, the system can customize the target access frequency limit of the access interface, avoid the one-size-fits-all management mode, and improve the flexibility and security of the system. By dynamically adjusting the access limit, unnecessary identity verification and access restriction are reduced, the use experience of the target object is improved, and the user satisfaction is avoided due to excessive restrictions. Based on the target access frequency of the access interface, the system can make more scientific and accurate access control decisions, reduce the interference of human factors, and improve the objectivity and accuracy of the decisions. The target access frequency of the access interface can be dynamically generated according to the configured system parameters, has high flexibility, and can be dynamically adjusted according to the system characteristics.

[0098] Embodiment four

[0099] Figure 5 is a structural schematic diagram of a device for determining the access frequency of an access interface provided by the embodiments of the present disclosure, as Figure 5 shown, the device comprises an access interface acquisition module 310, a risk assessment attribute determination module 320, a trust value determination module 330, and a target access frequency determination module 340.

[0100] The access interface acquisition module is configured to, for a target object, acquire at least one access interface called when a transaction is generated within a preset time length, and transaction response data of the at least one access interface; the risk assessment attribute determination module is configured to determine a first risk assessment attribute according to an actual calling sequence of the at least one access interface when the target object triggers a transaction and at least one interface preset calling sequence corresponding to the transaction; determine a second risk assessment attribute according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and an interface preset access frequency corresponding to the access interface; determine a third risk assessment attribute according to the transaction response data of the at least one access interface and at least one interface preset transaction response data corresponding to the access interface; wherein the interface preset calling sequence includes the calling sequence of two access interfaces; the trust value determination module is configured to determine the trust value of the target object according to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute; the target access frequency determination module is configured to, for the at least one access interface, determine the target access frequency of the access interface according to the reference access frequency of the access interface and the trust value; wherein the reference access frequency is preset according to the interface type of the access interface.

[0101] The technical scheme of the embodiments of the present disclosure, for a target object, acquires at least one access interface called when a transaction is generated within a preset time length, and transaction response data of the at least one access interface. Then, a first risk assessment attribute is determined according to an actual calling sequence of the at least one access interface when the target object triggers the transaction and a preset calling sequence of the at least one access interface corresponding to the transaction. A second risk assessment attribute is determined according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers the transaction and a preset access frequency of the access interface corresponding to the access interface. A third risk assessment attribute is determined according to the transaction response data of the at least one access interface and preset transaction response data of the at least one access interface corresponding to the access interface. The preset calling sequence of the interface includes a calling sequence of two access interfaces. Further, a trust value of the target object is determined according to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute. Finally, for the at least one access interface, a target access frequency of the access interface is determined according to a reference access frequency of the access interface and the trust value. The reference access frequency is preset according to the interface type of the access interface. The present disclosure solves the problem that the prior art access control strategy based on fixed rules cannot adapt to a dynamically changing threat environment, thereby reducing the user experience. The present disclosure dynamically adjusts the access frequency based on the access interface called when the transaction is generated and the transaction response data, improves the user experience, and achieves the effects of flexibility and intelligence of access frequency setting.

[0102] On the basis of the above technical solutions, the risk assessment attribute determination module 320 includes a first risk assessment attribute determination submodule, a second risk assessment attribute determination submodule, and a third risk assessment attribute determination submodule.

[0103] The first risk assessment attribute determination submodule is configured to convert the at least one access interface when the transaction is triggered into a state symbol sequence according to the state symbol corresponding to the at least one access interface and the actual calling sequence of the at least one access interface; convert the preset calling sequence of the at least one interface into a preset state symbol sequence according to the state symbol; and determine the first risk assessment attribute according to the state symbol sequence, the at least one preset state symbol sequence, and the probability value corresponding to the preset state symbol sequence.

[0104] The second risk assessment attribute determination submodule is configured to determine a single second risk assessment attribute corresponding to a single access interface according to the access frequency of the access interface within the at least one preset sliding window and the preset access frequency of the access interface corresponding to the access interface; and determine the second risk assessment attribute of the at least one access interface according to the at least one single second risk assessment attribute corresponding to all single access interfaces.

[0105] The third risk assessment attribute determination submodule is configured to determine, based on feature conversion, a data vector corresponding to at least one transaction response data; wherein the transaction response data at least includes an interface path, a transmission protocol method, a response status code, a request parameter quantity, a response time length, an access time, and a transaction value attribute; and determine, for at least one data vector corresponding to the access interface, a single third risk assessment attribute of the access interface according to at least one first element in the data vector and at least one second element corresponding to at least one interface preset transaction response data of the access interface; and determine, for at least one access interface, a third risk assessment attribute according to all single third risk assessment attributes.

[0106] On the basis of the above technical solutions, the device further comprises a fingerprint acquisition module, a device fingerprint determination module, a trusted value updating module, and a target access frequency updating module.

[0107] The fingerprint acquisition module is configured to acquire, at a preset frequency, a central processing unit fingerprint, an image processor fingerprint, and a hard disk fingerprint of a device used by the target object during the transaction.

[0108] The device fingerprint determination module is configured to determine a device fingerprint of the device according to the central processing unit fingerprint, the image processor fingerprint, and the hard disk fingerprint.

[0109] The trusted value updating module is configured to trigger calculation of a trusted value of the target object and determine an updated trusted value when a change in the device fingerprint is detected.

[0110] The target access frequency updating module is configured to determine a target access frequency of the access interface according to a basic access frequency of the access interface and the updated trusted value.

[0111] On the basis of the above technical solutions, the device fingerprint determination module further comprises an intermediate combined fingerprint determination submodule and a device fingerprint calculation submodule.

[0112] The intermediate combined fingerprint determination submodule is configured to combine the central processing unit fingerprint, the image processor fingerprint, and the hard disk fingerprint to obtain an intermediate combined fingerprint.

[0113] The device fingerprint calculation submodule is configured to obtain the device fingerprint according to the intermediate combined fingerprint, an encryption hash function, and a salt value.

[0114] On the basis of the above technical solutions, the trusted value determination module 330 comprises a risk assessment attribute determination submodule and a trusted value calculation submodule.

[0115] The risk assessment attribute determination submodule is configured to determine a risk assessment attribute according to the first risk assessment attribute, the first weight, the second risk assessment attribute, the second weight, the third risk assessment attribute, and the third weight.

[0116] The trusted value calculation submodule is configured to determine a trusted value of the target object according to the risk assessment attribute and a trusted value determination function.

[0117] On the basis of the above technical solutions, the trusted value determination function is as follows:

[0118] In the formula, CTP represents the trusted value, URE represents the risk assessment attribute, K represents a weight, and C represents a constant.

[0119] On the basis of the above technical solutions, the target access frequency determination module 340 includes a reference access frequency determination submodule and a multiplication calculation submodule.

[0120] The reference access frequency determination submodule is configured to determine, for at least one access interface, a reference access frequency of the access interface according to an interface type of the access interface, wherein the reference access frequency includes a first preset reference access frequency, a second preset reference access frequency, and a third preset reference access frequency.

[0121] The multiplication calculation submodule is configured to multiply, for at least one access interface, the trusted value and a preset reference access frequency corresponding to the access interface to determine a target access frequency of the access interface.

[0122] On the basis of the above technical solutions, the apparatus further includes an authentication mode configuration module configured to configure an authentication mode for the target object according to an interface type of the at least one access interface when the target object triggers a transaction.

[0123] The apparatus for determining an access frequency of an access interface provided in the embodiments of the present disclosure can perform the method for determining an access frequency of an access interface provided in any of the embodiments of the present disclosure, and has the corresponding function modules and beneficial effects of performing the method.

[0124] It should be noted that each unit and module included in the apparatus is only divided according to a function logic, but is not limited to the above division, as long as the corresponding functions can be implemented; in addition, the specific names of each functional unit are only for convenient mutual distinction, and do not serve to limit the protection scope of the embodiments of the present disclosure.

[0125] Embodiment Five

[0126] Figure 6 is a structural schematic diagram of an electronic device provided in the embodiments of the present disclosure. The following will be described with reference toFigure 6 which shows a structural diagram of an electronic device (e.g., a terminal device or a server) 500 suitable for use in implementing embodiments of the present disclosure. The terminal device in embodiments of the present disclosure can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (e.g., a car navigation terminal), and the like. Figure 6 The electronic device shown is merely one example and should not limit the function and scope of use of embodiments of the present disclosure in any way. Figure 6 The electronic device shown is merely one example and should not limit the function and scope of use of embodiments of the present disclosure in any way.

[0127] As shown in FIG. 5, the electronic device 500 can include a processing device (e.g., a central processor, a graphic processor, etc.) 501 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 502 or programs loaded into a random access memory (RAM) 503 from a storage device 508. Various programs and data required for the operation of the electronic device 500 are also stored in the RAM 503. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504. Figure 6 Generally, the following devices can be connected to the I / O interface 505: input devices 506 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; output devices 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; storage devices 508 including, for example, a magnetic tape, a hard disk, and the like; and communication devices 509. The communication devices 509 can allow the electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although

[0128] The electronic device 500 is shown with various devices, but it should be understood that not all of the devices shown are required to be implemented or present. More or fewer devices can alternatively be implemented or present. Figure 6

[0129] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to embodiments of the present disclosure. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication devices 509, or installed from the storage devices 508, or installed from the ROM 502. When the computer program is executed by the processing device 501, the above-described functions defined in the methods of the present disclosure are performed.

[0130] ​Names of messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes, and are not used to limit the scope of the messages or information.

[0131] The electronic device provided by the embodiments of the present disclosure and the method for determining the access frequency of the access interface provided by the above embodiments belong to the same inventive concept, and the technical details not described in detail in the present embodiment can be referred to the above embodiments, and the present embodiment has the same beneficial effects as the above embodiments.

[0132] Embodiment six

[0133] The embodiments of the present disclosure provide a computer storage medium, which stores a computer program, and the program is executed by a processor to implement the method for determining the access frequency of the access interface provided by the above embodiments.

[0134] It should be noted that the computer readable medium of the present disclosure can be a computer readable signal medium or a computer readable storage medium or any combination of the two. The computer readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer readable storage media can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component. In the present disclosure, the computer readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer readable program code. Such a propagated data signal can take many forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component. The program code contained in the computer readable medium can be transmitted by any suitable medium, including but not limited to a wire, a cable, an RF (radio frequency) or the like, or any suitable combination of the above.

[0135] In some embodiments, the server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communications of any form or medium (e.g., a communications network). Examples of communications networks include local area networks ("LAN"), wide area networks ("WAN"), internetworks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future developed networks.

[0136] The computer readable medium described above can be included in the electronic device described above; or can exist separately, without being assembled into the electronic device.

[0137] The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to:

[0138] For the target object, at least one access interface called when a transaction is generated within a preset time length is acquired, and transaction response data of the at least one access interface is acquired;

[0139] According to an actual calling sequence of the at least one access interface when the target object triggers a transaction and at least one interface preset calling sequence corresponding to the transaction, a first risk assessment attribute is determined; according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and an interface preset access frequency corresponding to the access interface, a second risk assessment attribute is determined; according to transaction response data of the at least one access interface and at least one interface preset transaction response data corresponding to the access interface, a third risk assessment attribute is determined; wherein the interface preset calling sequence includes a calling sequence of two access interfaces.

[0140] According to the first risk assessment attribute, the second risk assessment attribute, and the third risk assessment attribute, a trust value of the target object is determined.

[0141] For the at least one access interface, according to a reference access frequency of the access interface and the trust value, a target access frequency of the access interface is determined; wherein the reference access frequency is preset according to an interface type of the access interface.

[0142] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0143] The computer program instructions can also be loaded onto a computer or other programmable information processing apparatus to cause a series of operations to be performed on the computer or other programmable information processing apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable information processing apparatus implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0144] The units described in the embodiments of the present disclosure can be implemented by hardware, software, or a combination of hardware and software. In some cases, the names of the units do not constitute a limitation on the units themselves.

[0145] The functions described in this specification can be implemented in part or in whole through one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Program-specific Integrated Circuits (ASICs), Program-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0146] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include a lined- up electrical connection, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0147] The above description is only preferred embodiments of the present disclosure and the explanation of the applied technical principles. It should be understood by those skilled in the art that the disclosure range involved in the present disclosure is not limited to the technical solutions formed by the specific combinations of the above technical features, and also covers other technical solutions formed by any combination of the above technical features or equivalent features without departing from the above disclosed concept. For example, the technical solutions formed by replacing the above features with the technical features disclosed in the present disclosure (but not limited to) having similar functions.

[0148] In addition, although each operation is described in a particular order, this should not be understood as requiring the operations to be performed in the specific order shown or in a sequential order. In certain circumstances, multitasking and parallel processing can be advantageous. Similarly, although several implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments can also be combined in a single embodiment. Conversely, various features described in the context of a single embodiment can also be separated and implemented in multiple embodiments.

[0149] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A method of determining a frequency of access to an access interface, characterized by, The method comprises the following steps: For a target object, at least one access interface called when a transaction is generated within a preset time length is acquired, and transaction response data of the at least one access interface is acquired; A first risk assessment attribute is determined according to an actual sequence of interface calls of the at least one access interface when the target object triggers a transaction and at least one preset sequence of interface calls corresponding to the transaction; A second risk assessment attribute is determined according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and a preset access frequency of the interface corresponding to the access interface; a third risk assessment attribute is determined according to transaction response data of the at least one access interface and at least one preset transaction response data corresponding to the access interface; wherein the preset sequence of interface calls comprises a sequence of calls of two access interfaces. A trust value of the target object is determined according to the first risk assessment attribute, the second risk assessment attribute and the third risk assessment attribute. For the at least one access interface, a target access frequency of the access interface is determined according to a reference access frequency of the access interface and the trust value; wherein the reference access frequency is preset according to a type of the interface.

2. The method of claim 1, wherein, The first risk assessment attribute is determined according to an actual sequence of interface calls of the at least one access interface when the target object triggers a transaction and at least one preset sequence of interface calls corresponding to the transaction, and comprises the following steps: At least one access interface when triggering a transaction is converted into a state symbol sequence according to a state symbol corresponding to the at least one access interface and the actual sequence of interface calls of the at least one access interface; The preset sequence of interface calls is converted into a preset state symbol sequence according to the state symbol and at least one preset sequence of interface calls; The first risk assessment attribute is determined according to the state symbol sequence, at least one preset state symbol sequence and a probability value corresponding to the preset state symbol sequence.

3. The method of claim 1, wherein, The second risk assessment attribute is determined according to an access frequency of the at least one access interface within a preset sliding window when the target object triggers a transaction and a preset access frequency of the interface corresponding to the access interface, and comprises the following steps: A single second risk assessment attribute corresponding to a single access interface is determined according to an access frequency of the access interface within at least one preset sliding window and a preset access frequency of the interface corresponding to the access interface; For at least one access interface, a second risk assessment attribute is determined according to at least one single second risk assessment attribute corresponding to all single access interfaces.

4. The method of claim 1, wherein, The third risk assessment attribute is determined according to transaction response data of the at least one access interface and at least one preset transaction response data corresponding to the access interface, and comprises the following steps: For at least one transaction response data, a data vector corresponding to the transaction response data is determined based on feature conversion; wherein the transaction response data at least comprises an interface path, a transmission protocol method, a response status code, a number of request parameters, a response time length, an access time and a transaction value attribute. determining a single third risk assessment attribute corresponding to the access interface according to at least one first element in the at least one data vector and at least one second element corresponding to a preset transaction response data of the access interface; determining a third risk assessment attribute according to all single third risk assessment attributes for at least one access interface.

5. The method of claim 1, wherein, The method further comprises: acquiring a central processor fingerprint, an image processor fingerprint and a hard disk fingerprint of a device used by the target object at the transaction time at a preset frequency; determining a device fingerprint of the device according to the central processor fingerprint, the image processor fingerprint and the hard disk fingerprint; triggering calculation of a trust value of the target object and determination of an updated trust value when a change in the device fingerprint is detected; determining a target access frequency of the access interface according to a basic access frequency of the access interface and the updated trust value.

6. The method of claim 5, wherein, The determination of the device fingerprint of the device according to the central processor fingerprint, the image processor fingerprint and the hard disk fingerprint comprises: combining the central processor fingerprint, the image processor fingerprint and the hard disk fingerprint to obtain an intermediate combined fingerprint; obtaining the device fingerprint according to the intermediate combined fingerprint, a cryptographic hash function and a salt value.

7. The method of claim 1, wherein, The determination of the trust value of the target object according to the first risk assessment attribute, the second risk assessment attribute and the third risk assessment attribute comprises: determining a risk assessment attribute according to the first risk assessment attribute, a first weight, the second risk assessment attribute, a second weight, the third risk assessment attribute and a third weight; determining the trust value of the target object according to a trust value determination function.

8. The method of claim 7, wherein, The trust value determination function is: Wherein, CTP is the trusted value; URE is the risk assessment attribute; K represents the weight; and C is a constant.

9. The method of claim 1, wherein, The determination of the target access frequency of the access interface according to the basic access frequency of the access interface and the trust value for the at least one access interface comprises: determining the basic access frequency of the access interface according to the interface type of the access interface for at least one access interface; wherein the basic access frequency comprises a first preset basic access frequency, a second preset basic access frequency and a third preset basic access frequency; multiplying the trust value and the preset basic access frequency corresponding to the access interface to determine the target access frequency of the access interface for at least one access interface.

10. The method of claim 1, wherein, The method further comprises: configuring an authentication mode for the target object according to the interface type of the at least one access interface triggered by the target object at the transaction.