Multi-model fusion service security protection method and system

By employing a multi-model fusion approach to business security protection, and utilizing deep learning through parameter, access, and identity micro-models, the problem of high false alarm rates in traditional defense technologies is solved, achieving efficient and adaptive attack identification and protection.

CN120979736APending Publication Date: 2025-11-18BEIJING JUXIN DEREN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511162437.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In traditional business security defense technologies, rule bases lead to high false alarm rates, affecting defense effectiveness and failing to effectively identify attack threats in complex environments.

Method used

A multi-model fusion approach to business security protection is adopted. By constructing parameter micro-models, access micro-models, and identity micro-models, and combining deep learning technology, user interaction behavior and traffic information are analyzed to accurately identify abnormal behavior and carry out multi-level processing.

Benefits of technology

It improves the accuracy of attack identification, reduces the false alarm rate, adapts to various application scenarios, enhances the protection capabilities of web applications, and can automatically iterate and update without manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979736A_ABST
    Figure CN120979736A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-model fusion service security protection method and system. The method comprises the following steps: extracting an interactive behavior of a user side and a feature vector of traffic information of the interactive behavior; the feature vectors of the interaction behaviors and the traffic information of the user side comprise parameter features, access behavior features, identity features and operation behavior features; inputting the parameter characteristics into a parameter micro-model to detect whether the access parameters are abnormal or not; inputting the access behavior characteristics into the access micro-model to detect whether the user access behavior is abnormal or not; inputting the identity features into an identity micro-model to detect whether the access identity is abnormal or not; inputting the operation behavior characteristics into a behavior micro-model to detect whether the user operation behavior is abnormal or not; and if any one of the access parameter, the user access behavior, the access identity and the user operation behavior is detected to be abnormal, processing the user access behavior. Through the application, the defense effect can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security protection technology, and in particular to a business security protection method and system. Background Technology

[0002] In today's digital age, with the rapid development of the internet and information technology, business security faces unprecedented challenges. Enterprises and organizations' business systems not only carry a large amount of sensitive information but also face various security attack threats from both internal and external sources. These threats can lead to financial losses and damage a company's reputation and user trust. Therefore, the importance of business security is increasingly prominent, becoming one of the key factors for sustainable enterprise development. A robust business security technology solution can effectively identify and prevent various security threats, protect the integrity and privacy of user data, and ensure business continuity and stability.

[0003] Traditional techniques use static rule bases for detection and defense. These predefined rule bases match network traffic, user behavior, or system logs to identify known attack patterns. However, in complex environments, rule bases may generate many false positives, impacting the effectiveness of the defense. Summary of the Invention

[0004] Based on this, and in response to the aforementioned technical problems, a multi-model fusion business security protection method and system are provided to address the issue of ineffective defense by existing technologies.

[0005] Firstly, a multi-model fusion business security protection method, the method comprising:

[0006] Receive user terminal interaction behavior and its traffic information, and extract feature vectors of the user terminal interaction behavior and its traffic information; the feature vectors of the user terminal interaction behavior and its traffic information include parameter features, access behavior features, identity features and operation behavior features;

[0007] The parameter features in the feature vector of the user's interactive behavior and traffic information are input into a pre-built parameter micro-model to detect whether the access parameters are abnormal.

[0008] The access behavior features in the feature vector of the user's interaction behavior and traffic information are input into a pre-built access micro-model to detect whether there are any abnormalities in the user's access behavior.

[0009] The identity features in the feature vectors of the user's interactive behavior and traffic information are input into a pre-built identity micro-model to detect whether there are any abnormalities in the access identity.

[0010] The operation behavior features in the feature vector of the user's interaction behavior and traffic information are input into a pre-built behavior micro-model to detect whether there are any abnormalities in the user's operation behavior.

[0011] If any abnormality is detected in the access parameters, user access behavior, access identity, or user operation behavior, the user access behavior will be dealt with accordingly.

[0012] Optionally, in the above scheme, the parameter micro-model includes: a URL address access path anomaly detection module, a Header header anomaly detection module, a QUERY parameter anomaly detection module, and a Payload anomaly detection module.

[0013] Optionally, in the above scheme, the access micro-model includes: an IP address anomaly detection module, a geographical location anomaly detection module, a client anomaly detection module, an access traffic anomaly detection module, and an access time anomaly detection module.

[0014] Optionally, in the above scheme, the access micro-model includes: an IP address anomaly detection module, a geographical location anomaly detection module, a client anomaly detection module, an access traffic anomaly detection module, and an access time anomaly detection module.

[0015] Optionally, in the above scheme, the identity model includes: a user login information anomaly detection module, a user token information anomaly detection module, a user session information anomaly detection module, and an OAuth information anomaly detection module.

[0016] Optionally, the handling of user access behavior in the above scheme may include:

[0017] The user's access behavior can be intercepted, redirected, or a human verification command can be sent to the user's terminal.

[0018] Optionally, in the above scheme, the feature vector of the user access request includes temporal features, semantic features, and graph features.

[0019] Optionally, in the above scheme, if any abnormality is detected in the access parameters, access behavior, access identity, or user behavior, the method further includes:

[0020] The attack patterns of the user access behavior are identified, and the user access behavior is dealt with according to the identification results.

[0021] Secondly, a multi-model fusion business security protection system, the system comprising:

[0022] Feature extraction module: used to receive user terminal interaction behavior and its traffic information, and extract feature vectors of the user terminal interaction behavior and its traffic information; the feature vectors include parameter features, access behavior features, identity features and operation behavior features;

[0023] Access parameter anomaly detection module: used to input the parameter features in the feature vector of the user terminal's interactive behavior and traffic information into a pre-built parameter micro-model to detect whether the access parameters are abnormal;

[0024] Access behavior anomaly detection module: used to input the access behavior features in the feature vector of the user's interaction behavior and traffic information into a pre-built access micro-model in order to detect whether there are any anomalies in the user's access behavior;

[0025] Access Identity Anomaly Detection Module: This module is used to input the identity features from the feature vectors of the user's interaction behavior and traffic information into a pre-built identity micro-model to detect whether there are any anomalies in the access identity.

[0026] User behavior anomaly detection module: used to input the operation behavior features in the feature vector of the user's interaction behavior and traffic information into a pre-built behavior micro-model in order to detect whether there are any anomalies in the user's operation behavior;

[0027] The handling module is used to handle user access behavior if any abnormality is detected in access parameters, user access behavior, access identity, or user operation behavior.

[0028] Thirdly, a computer device includes a memory and a processor, the memory storing a computer program, the processor executing the computer program to perform the steps of the multi-model fusion business security protection method described in the first aspect above.

[0029] Fourthly, a computer program product includes a computer program / instructions, characterized in that, when the computer program / instructions are executed by a processor, they implement the steps of the multi-model fusion business security protection method described in the first aspect.

[0030] This application has at least the following beneficial effects:

[0031] This application constructs corresponding parameter models, access models, identity models, and behavioral micro-models for protection. Upon receiving an access request, it utilizes these models to perform comprehensive multi-model content analysis to identify risks, thereby accurately identifying attack behaviors. Furthermore, due to the multiple models, it can be adapted to various application scenarios such as web business systems, APIs, apps, mini-programs, and official accounts, comprehensively improving the protection capabilities of web applications. Attached Figure Description

[0032] Figure 1 A flowchart illustrating a multi-model fusion business security protection method provided in one embodiment of this application;

[0033] Figure 2 A detailed flowchart of a multi-model fusion business security protection method provided in one embodiment of this application;

[0034] Figure 3 This is a structural diagram of a parametric micromodel provided in one embodiment of this application;

[0035] Figure 4 This is a structural diagram of an access micromodel provided in one embodiment of this application;

[0036] Figure 5 This is a structural diagram of an identity micromodel provided in one embodiment of this application;

[0037] Figure 6 This is a flowchart illustrating a multi-model fusion business security protection method provided in one embodiment of this application. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0039] In one embodiment, such as Figure 1 and Figure 2 As shown, a multi-model fusion business security protection method is provided, the method comprising:

[0040] Step S1: Receive user terminal interaction behavior and its traffic information, and extract the feature vector of the user terminal interaction behavior and its traffic information; the feature vector of the user terminal interaction behavior and its traffic information includes parameter features, access behavior features, identity features and operation behavior features.

[0041] Step S2: Input the parameter features in the feature vector of the user terminal's interactive behavior and traffic information into the pre-built parameter micro-model to detect whether the access parameters are abnormal;

[0042] Step S3: Input the access behavior features in the feature vector of the user's interaction behavior and traffic information into the pre-built access micro-model to detect whether there are any abnormalities in the user's access behavior;

[0043] Step S4: Input the identity features in the feature vector of the user's interaction behavior and traffic information into the pre-built identity micro-model to detect whether there are any abnormalities in the access identity;

[0044] Step S5: Input the operation behavior features in the feature vector of the user's interaction behavior and traffic information into the pre-built behavior micro-model to detect whether there are any abnormalities in the user's operation behavior;

[0045] Step S6: If any abnormality is detected in the access parameters, user access behavior, access identity, or user operation behavior, then the user access behavior shall be dealt with.

[0046] In this embodiment, through deep learning of server traffic and behavior, protection models such as parameter models, access models, identity models, and defense models are automatically established. Risk is analyzed by integrating the content of multiple models, and different defense systems are constructed for different businesses. Based on self-feedback technology, it can self-iterate, update, and evolve without manual intervention. Artificial intelligence algorithms are used to accurately analyze the characteristics and behaviors exhibited by scanning and probing, thereby achieving automatic interception and effectively preventing attackers from discovering exploitable system weaknesses, blocking bot attacks and malicious crawler behavior. The CPU instruction set and C programming language architecture ensure complete code autonomy and control, forming a trusted whitelist mechanism with high performance. The parameter model, access model, identity model, and behavior micro-model are collectively referred to as the defense micro-model.

[0047] The aforementioned multi-model fusion business security protection method constructs corresponding parameter models, access models, identity models, and behavioral micro-models. Upon receiving an access request, it comprehensively analyzes the risks using these three models, enabling accurate identification of attack behaviors. Furthermore, the use of multiple models allows for adaptation to various application scenarios, including web business systems, APIs, apps, mini-programs, and official accounts, comprehensively enhancing web application protection capabilities.

[0048] In one embodiment, such as Figure 3 As shown, the parameter micro-model includes: a URL address access path anomaly detection module, a Header header anomaly detection module, a QUERY parameter anomaly detection module, and a Payload anomaly detection module.

[0049] In this embodiment, the address access path anomaly detection module learns access paths of a large number of normal URI addresses and models URL data using an algorithm; the header anomaly detection module learns the content of normal access request header messages, records corresponding access habits and characteristics, and models data using an algorithm; the QUERY parameter anomaly detection module models the QUERRY data following each normal access URL; and the payload anomaly detection module learns and records the roaming data content transmitted in HTTP requests and models data using an algorithm.

[0050] In one embodiment, such as Figure 4 As shown, the access micro-model includes: an IP address anomaly detection module, a geographical location anomaly detection module, a client anomaly detection module, an access traffic anomaly detection module, and an access time anomaly detection module.

[0051] In this embodiment, the system includes: an IP address anomaly detection module (recording the IP addresses of interface addresses and URLs to model the source IPs); a geographic location anomaly detection module (identifying access requests from different geographic locations and using this information for data modeling); a client anomaly detection module (modeling client data based on OS type, browser version, screen resolution, etc.); an access traffic anomaly detection module (modeling access traffic data based on different IP addresses); and an access time anomaly detection module (learning from examples of access times to form access time-based data modeling).

[0052] In one embodiment, such as Figure 5 As shown, the identity model includes: a user login information anomaly detection module, a user token information anomaly detection module, a user session information anomaly detection module, and an OAuth information anomaly detection module.

[0053] In one embodiment, handling user access behavior includes: intercepting the user access behavior, redirecting it, or sending a human-machine verification command to the user terminal.

[0054] In this embodiment, the application adopts a multi-level processing strategy: immediate interception (hard blocking), request redirection (honeypot inducement), and human-machine verification (seamless challenge mechanism).

[0055] In one embodiment, the feature vector of the user access request includes temporal features, semantic features, and graph features.

[0056] In one embodiment, the step of detecting any abnormality in access parameters, access behavior, access identity, or user behavior further includes:

[0057] The attack patterns of the user access requests are identified, and the user access requests are processed according to the identification results.

[0058] In this embodiment, if any abnormality is detected in the access parameters, access behavior, access identity, or user behavior, the attack mode of the access request is identified, and based on the identification, it is determined which decision in the multi-level handling decision is adopted.

[0059] This application combines big data analysis, constructs a security knowledge graph, and then performs attack pattern matching, knowledge graph query, threat scoring, and response decision-making.

[0060] The performance indicators of this application compared to traditional methods are shown in Table 1:

[0061] Table 1

[0062] Indicator Item Traditional WAF Smart WAF Zero-day attack detection rate 18-32% 76-89% False alarm rate 0.15-0.3% 0.02-0.08% Rule update delay hourly Minutes Computational resource consumption 4 cores 8GB 2 core 4GB

[0063] This application's micro-model technology focuses on creating detailed micro-models of the system to better capture and analyze the overall system's behavior and dynamics. Based on this, this application constructs various micro-models, including parameter micro-models, access micro-models, identity micro-models, and behavioral micro-models. Through these multiple micro-models, different defense systems are built for different business processes and different APIs, making it impossible for attackers to guess the overall defense strategy from the attack interception behavior of a single API. This also prevents the construction of effective attack payloads. Furthermore, the models can self-iterate, update, and self-clean up based on self-feedback technology, requiring no manual intervention.

[0064] In one embodiment, a multi-model fusion business security protection system is provided, the system comprising:

[0065] Feature extraction module: used to receive user terminal interaction behavior and its traffic information, and extract feature vectors of the user terminal interaction behavior and its traffic information; the feature vectors include parameter features, access behavior features, identity features and operation behavior features;

[0066] Access parameter anomaly detection module: used to input the parameter features in the feature vector of the user terminal's interactive behavior and traffic information into a pre-built parameter micro-model to detect whether the access parameters are abnormal;

[0067] Access behavior anomaly detection module: used to input the access behavior features in the feature vector of the user's interaction behavior and traffic information into a pre-built access micro-model in order to detect whether there are any anomalies in the user's access behavior;

[0068] Access Identity Anomaly Detection Module: This module is used to input the identity features from the feature vectors of the user's interaction behavior and traffic information into a pre-built identity micro-model to detect whether there are any anomalies in the access identity.

[0069] User behavior anomaly detection module: used to input the operation behavior features in the feature vector of the user's interaction behavior and traffic information into a pre-built behavior micro-model in order to detect whether there are any anomalies in the user's operation behavior;

[0070] The handling module is used to handle user access behavior if any abnormality is detected in access parameters, user access behavior, access identity, or user operation behavior.

[0071] like Figure 6 As shown, the traffic preprocessing layer includes a feature extraction module, and the AI ​​micro-model array includes parameter micro-models, access micro-models, identity micro-models, and behavior micro-models for anomaly monitoring. If any anomaly exists, it is handled through the dynamic response layer (i.e., the handling module). Figure 6 The numerical feature library contains a constructed knowledge graph to facilitate subsequent classification of abnormal behaviors. The federated learning model trains and constructs parameter micro-models, access micro-models, identity micro-models, and behavior micro-models.

[0072] The priority of this application is as follows:

[0073] 1. Ruleless protection: No signature database required, effectively resisting zero-day attacks.

[0074] 2. Strong compatibility: Based on middle-layer defense, it is seamless for both users and servers, requiring no modification to server or client software.

[0075] 3. Multi-dimensional defense: Based on micro-models, multi-dimensional defense is used to build a comprehensive defense system.

[0076] For specific limitations regarding a multi-model fusion business security protection system, please refer to the limitations of a multi-model fusion business security protection method described above, which will not be repeated here. Each module in the aforementioned multi-model fusion business security protection system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0077] In one embodiment, a computer device, which may be a server, is provided. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements the aforementioned multi-model fusion business security protection method.

[0078] In one embodiment, a computer-readable storage medium is also provided, on which a computer program is stored relating to all or part of the processes in the methods of the above embodiments.

[0079] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0080] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0081] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A multi-model fusion business security protection method, characterized in that, The method comprises: receiving the interaction behavior and traffic information of the user terminal, and extracting a feature vector of the interaction behavior and traffic information of the user terminal; the feature vector of the interaction behavior and traffic information of the user terminal comprises parameter features, access behavior features, identity features and operation behavior features; inputting the parameter features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed parameter micro model to detect whether the access parameters are abnormal; inputting the access behavior features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed access micro model to detect whether the user access behavior is abnormal; inputting the identity features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed identity micro model to detect whether the access identity is abnormal; inputting the operation behavior features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed behavior micro model to detect whether the user operation behavior is abnormal; if any of the access parameters, user access behavior, access identity and user operation behavior is detected to be abnormal, the user access behavior is disposed.

2. The multi-model fusion business security protection method of claim 1, wherein, The parameter micro model comprises: an access path abnormality detection module of a URL address, a Header header abnormality detection module, a QUERY parameter abnormality detection module and a Payload abnormality detection module.

3. The method of claim 1, wherein, The access micro model comprises: an IP address abnormality detection module, a geographic location abnormality detection module, a client abnormality detection module, an access traffic abnormality detection module and an access time abnormality detection module.

4. The multi-model fusion business security protection method of claim 1, wherein, The identity micro model comprises: a user login information abnormality detection module, a user Token information abnormality detection module, a user Session information abnormality detection module and an OAuth information abnormality detection module.

5. The multi-model fusion business security protection method of claim 1, wherein, The disposal of the user access behavior comprises: intercepting, redirecting or sending a human-computer verification command to the user terminal.

6. The multi-model fusion business security protection method of claim 1, wherein, The feature vector of the user access request comprises timing features, semantic features and graph features.

7. The multi-model fusion business security protection method of claim 1, wherein, The disposal of the user access behavior further comprises: identifying an attack mode of the user access behavior, and disposing the user access behavior according to the identification result.

8. A multi-model fusion business security protection system, characterized in that, The system comprises: a feature extraction module for receiving the interaction behavior and traffic information of the user terminal, and extracting a feature vector of the interaction behavior and traffic information of the user terminal; the feature vector comprises parameter features, access behavior features, identity features and operation behavior features; an access parameter abnormality detection module for inputting the parameter features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed parameter micro model to detect whether the access parameters are abnormal; an access behavior abnormality detection module for inputting the access behavior features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed access micro model to detect whether the user access behavior is abnormal; an identity abnormality detection module for inputting the identity features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed identity micro model to detect whether the access identity is abnormal; and an operation behavior abnormality detection module for inputting the operation behavior features in the feature vector of the interaction behavior and traffic information of the user terminal into a pre-constructed behavior micro model to detect whether the user operation behavior is abnormal. An access identity anomaly detection module is configured to input an identity feature in a feature vector of an interaction behavior of the user terminal and traffic information thereof into a pre-constructed identity micro model to detect whether an access identity is abnormal. A user behavior anomaly judgment module is configured to input an operation behavior feature in a feature vector of the interaction behavior of the user terminal and traffic information thereof into a pre-constructed behavior micro model to detect whether a user operation behavior is abnormal. A disposal module is configured to dispose the user access behavior if any of the access parameters, the user access behavior, the access identity, and the user operation behavior is abnormal. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to implement the steps of the method in any one of claims 1 to 7.

10. A computer program product comprising computer programs / instructions, characterized in that, The computer program / instruction is executed by the processor to implement the steps of the method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network attack behavior analysis method and device based on full flow

    CN115134099A

  • UEBA-based multi-dimensional feature fusion abnormal traffic detection method

    CN117540323A