Application protection system based on behavior analysis

By constructing an application protection system based on behavior analysis, the problem of difficulty in conducting multi-dimensional risk assessment in existing technologies has been solved, enabling accurate identification and dynamic response to complex network threats, thereby improving security and the legitimate user experience.

CN121864347APending Publication Date: 2026-04-14HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing application protection systems struggle to conduct unified, dynamic, and intelligent risk assessment and decision-making when facing complex and dynamically changing network threats, especially automated script attacks, reverse proxy attacks, and low-frequency, slow attacks. This results in blind spots or misjudgments in protection.

Method used

An application protection system based on behavior analysis is constructed, including a client environment awareness module, a script secure execution module, a dynamic token management module, a proxy attack identification module, and a dynamic interception decision engine. Risk assessment is performed through a multi-dimensional fusion model, generating a comprehensive risk score and outputting interception decision signals.

Benefits of technology

It achieves comprehensive, in-depth, and proactive security assessment and protection of client environment trustworthiness, user operation legitimacy, and network request authenticity, improves the ability to accurately identify and dynamically respond to complex automated attacks and identity spoofing attacks, and optimizes the interactive experience of legitimate users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864347A_ABST
    Figure CN121864347A_ABST
Patent Text Reader

Abstract

According to the behavior analysis-based application protection system provided by the invention, a collaborative protection system integrating environment perception, script security execution, token management, agent identification and behavior analysis is constructed, and fusion analysis of multi-dimensional risk information is carried out by a dynamic interception decision engine; omnibearing, deep and active security assessment and protection of client environment credibility, user operation legality and network request authenticity are realized, and the accurate recognition and dynamic response capability of the system in the face of complex automatic attacks and identity forgery attacks is effectively improved. And meanwhile, the interaction experience of legal users is optimized on the premise of ensuring the safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer information security technology, and in particular to an application protection system based on behavior analysis. Background Technology

[0002] With the deepening development of internet technology, various web applications have penetrated into all key areas of social production and life, such as finance, e-commerce, and government affairs, becoming important platforms for core business and data interaction. Against this backdrop, advanced persistent attacks and automated malicious behaviors targeting the web application layer are becoming increasingly rampant, posing a severe challenge to traditional security protection measures. In existing technologies, the development of application protection systems has mainly evolved from static rule-based feature matching (such as early firewalls and intrusion detection systems) to the introduction of device fingerprinting and behavioral verification. However, these protective measures still have significant shortcomings when facing increasingly complex and dynamically changing network threats, especially against carefully disguised automated script attacks, reverse proxy attacks that use proxy tools to conceal the real source address, and low-frequency, slow attacks that simulate normal user operations. The biggest drawback of current technology is that its various protection components are often arranged in an isolated or simply connected "chimney" layout. It lacks a central hub that can deeply integrate security context information from multiple dimensions such as client environment trustworthiness, user real-time behavioral intent, and network link risks, and conduct unified, dynamic, and intelligent risk assessment and decision-making. As a result, when facing multi-stage and cross-layer composite attacks, the system is unable to form effective collaborative defense and accurate interception judgment, thus creating protection blind spots or misjudgments, ultimately affecting the normal experience of legitimate users and business security. Summary of the Invention

[0003] In view of this, the present invention provides an application protection system based on behavior analysis to address the technical deficiencies existing in the prior art.

[0004] Specifically, the present invention provides an application protection system based on behavior analysis, comprising: The client-side environment awareness module is used to collect and process the client's environmental information to generate environmental fingerprint data; The script secure execution module connects to the client environment awareness module to receive environment fingerprint data and dynamically decrypt and execute the front-end script, and output the script execution status. The dynamic token management module connects to the script security execution module and generates and verifies a one-time dynamic token based on the script execution status when the user performs a critical operation. The proxy attack identification module is used to analyze the source characteristics of network requests to identify proxy tools and malicious reverse proxy behavior, and generate proxy risk data. Historical behavior baseline database, used to store and provide historical behavior pattern data of users and entities; The dynamic interception decision engine is connected to the dynamic token management module, the proxy attack identification module, and the historical behavior baseline database. It integrates the verification results of dynamic tokens, proxy risk data, and historical behavior pattern data, calculates a comprehensive risk score through a risk assessment model, and outputs an interception decision signal based on the comprehensive risk score to execute corresponding actions.

[0005] In some implementations, the client environment awareness module includes a browser type acquisition unit, a device fingerprint generation unit, and a runtime behavior monitoring unit. The browser type acquisition unit is used to acquire the client's browser and its plugin information. The device fingerprint generation unit is used to generate a unique device identifier based on the client's hardware and software configuration. The runtime behavior monitoring unit is used to capture the mouse trajectory and click sequence during user interaction.

[0006] In some implementations, the script secure execution module uses code obfuscation and encryption techniques to protect the core logic, and dynamically decrypts and executes the front-end script after the client environment awareness module confirms that the environment is trustworthy.

[0007] In some implementations, the proxy attack identification module includes a tool fingerprint database and a link analysis unit. The tool fingerprint database stores the request characteristics of known proxy tools, and the link analysis unit identifies abnormal proxy links by injecting probe elements into the response and analyzing its return.

[0008] In some implementations, the risk assessment model built into the dynamic interception decision engine is a multi-dimensional fusion model. The multi-dimensional fusion model combines environmental anomaly scores, behavioral deviation scores, and standardized agent risk scores into a comprehensive risk score through a weighted fusion method.

[0009] In some implementations, the formula for calculating the comprehensive risk score includes:

[0010] in, This represents the overall risk score, used for final decision-making. This represents the total number of environmental verification indicators, and its value comes from the number of indicator types collected by the client's environmental perception module. The weight coefficient of the i-th environmental verification indicator is obtained by training an offline machine learning model. This represents the original observed value of the i-th environmental verification indicator. Its dimensions are determined by the specific indicator and are collected in real time by the client's environmental perception module. represents the historical average of the i-th environmental verification indicator in the normal user group. Its dimension is the same as EiEi, and it is obtained from the historical behavior baseline database. represents the historical standard deviation of the i-th environmental verification indicator in the normal user group. Its dimension is the same as EiEi, and it is obtained from the historical behavior baseline database. This represents the total number of user behavior features, and its value is determined by the feature dimensions maintained in the historical behavior baseline database. The weight coefficients representing the j-th user behavior feature are obtained by training an offline machine learning model. The original observation value representing the j-th user behavior feature is extracted from real-time session data; This represents the historical mean of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the historical standard deviation of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the total number of risk dimensions associated with the proxy attack; its value is determined by the number of risk dimensions output by the proxy attack identification module. This represents the weight coefficient for the k-th agent risk dimension, which is preset by the system according to the security policy; This represents the standardized agency risk score for the k-th agency risk dimension; The smoothing factor representing the agent risk score is a real number greater than zero, and is preset by the system to adjust the contribution scale of this item.

[0011] In some implementations, the standardized agent risk score Pk′ is a calculation result for a specific dimension. The calculation method may be the same or different for different dimensions. When the specific dimension is the tool fingerprint matching dimension, the formula for calculating the standardized agent risk score Ptool′ for tool fingerprint matching includes:

[0012] in, This represents the standardized proxy risk score for tool fingerprint matching, used as an instance of Pk′ for calculating the comprehensive risk score; This represents the total number of known proxy tool feature matches detected, and its value is obtained by the proxy attack identification module after comparing it with the tool fingerprint database. This represents the confidence score of the m-th matched known proxy tool feature, obtained from the tool fingerprint database; The system's preset maximum value for the confidence score of the proxy tool's features is used for normalization; The non-linear amplification exponent, representing the confidence score, is a real number greater than 1 and is preset by the system according to the security policy. This represents the total number of abnormal request frequency characteristics, and its value is determined by the number of predefined abnormal frequency detection rules within the proxy attack identification module. The current observation value representing the anomaly feature of the nth request frequency is obtained by the proxy attack identification module within the time window. The normal baseline value representing the abnormal frequency characteristic of the nth request is obtained from the historical behavior baseline database; The nonlinear adjustment index, which represents the impact of frequency anomalies, is a real number greater than 1 and is preset by the system according to the safety policy. This represents the total number of abnormal signals detected by the link probe, and its value is determined by the number of probe nodes deployed by the link analysis unit in the proxy attack identification module. This represents the abnormal state value of the p-th link probe node, which is obtained by the link analysis unit based on the return information of the probe elements; This represents the total number of request timestamp anomaly types, and its value is determined by the number of predefined time series anomaly detection rules within the proxy attack identification module. This represents the severity of the q-th type of timestamp anomaly, calculated by the proxy attack identification module based on the degree of deviation. This represents a very small positive integer to prevent the denominator from being zero; it is preset by the system.

[0013] In some implementations, the system also includes a security data association library, which is connected to the dynamic interception decision engine to store and associate asset information, vulnerability information and threat intelligence, providing additional contextual data support for the dynamic interception decision engine.

[0014] In some implementations, after executing the action, the dynamic interception decision engine will send back the fingerprint information of this attack and store it in the security data association library to update the behavioral pattern data and threat intelligence in the historical behavior baseline database.

[0015] In some implementations, the dynamic interception decision engine triggers different actions based on different threshold ranges of the comprehensive risk score. These actions include allowing passage, requiring secondary verification, and forced interception.

[0016] At least one embodiment of the present invention constructs a collaborative protection system integrating environmental awareness, secure script execution, token management, proxy identification, and behavior analysis. A dynamic interception decision engine performs multi-dimensional risk information fusion analysis, achieving comprehensive, in-depth, and proactive security assessment and protection of client environment trustworthiness, user operation legitimacy, and network request authenticity. This effectively improves the system's accurate identification and dynamic response capabilities when facing complex automated attacks and identity forgery attacks, while optimizing the interactive experience of legitimate users while ensuring security. Attached Figure Description

[0017] Figure 1 This is a structural block diagram of an application protection system based on behavior analysis provided by the present invention. Detailed Implementation

[0018] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0019] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of the one or more embodiments of this specification. The singular forms “a” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items. The modifications “a” and “a plurality” as used in this disclosure are illustrative and not restrictive, and those skilled in the art will understand that they should be understood as “one or more” unless the context clearly indicates otherwise.

[0020] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0021] See Figure 1 , Figure 1This document illustrates a structural block diagram of an application protection system based on behavior analysis, according to some embodiments thereof. The system includes: a client environment awareness module for collecting and processing client environment information to generate environment fingerprint data; a script secure execution module connected to the client environment awareness module for receiving environment fingerprint data and dynamically decrypting and executing front-end scripts, outputting script execution status; a dynamic token management module connected to the script secure execution module for generating and verifying one-time dynamic tokens based on the script execution status when a user performs critical operations; a proxy attack identification module for analyzing the source characteristics of network requests to identify proxy tools and malicious reverse proxy behavior, generating proxy risk data; a historical behavior baseline database for storing and providing historical behavior pattern data of users and entities; and a dynamic interception decision engine connected to the dynamic token management module, the proxy attack identification module, and the historical behavior baseline database, for fusing the dynamic token verification results, proxy risk data, and historical behavior pattern data, calculating a comprehensive risk score through a risk assessment model, and outputting an interception decision signal based on the comprehensive risk score to execute corresponding actions.

[0022] The client-side environment awareness module refers to the component responsible for collecting and processing information about the client's hardware and software environment during runtime. For example, this module might call browser APIs to obtain user agent strings, screen resolution, and a list of installed plugins, and generate device identifiers based on Canvas fingerprints or WebRTC information to establish a unique identifier and trust baseline for the client. Environment information refers to a set of data that characterizes the client's device type, software configuration, and interaction state during runtime. This information includes, but is not limited to, operating system type, browser version, time zone settings, language preferences, screen parameters, and mouse movement trajectories and keyboard event sequences generated by user interaction with the page, providing raw contextual data for subsequent risk assessment. Environment fingerprint data refers to a string or data structure generated after feature extraction and hash calculation of environment information, used to uniquely or highly identify the client's environment. For example, this data might be generated by feeding collected environment information such as font lists and hardware acceleration support status into the SHA-256 algorithm to generate a fixed-length digest, serving as the core basis for judging the trustworthiness of the session environment.

[0023] A secure script execution module can refer to a component responsible for securely decrypting and running protected JavaScript code in the front-end environment. For example, this module receives environmental fingerprint data from the environment awareness module as part of the decryption key, uses the AES decryption algorithm to dynamically decrypt the pre-obfuscated and encrypted script, and executes it directly in memory without writing it to disk. This ensures that core business logic runs only in a trusted environment, preventing static analysis or tampering of the code. A front-end script can refer to JavaScript code executed in the user's browser environment to implement application interaction logic. For example, this script may have been processed by code obfuscation tools such as UglifyJS before being released on the server side, and key functions may have been encrypted. It can only be dynamically decrypted and executed after verification in the client environment, preventing malicious users from decompiling and understanding the code. Script execution status can refer to the success, failure, timeout, or exception information displayed by the front-end script during execution. For example, this status is obtained by the secure script execution module by listening to `onload` and `onerror` events and using `try-catch` statements to catch runtime errors. This can serve as a key indicator of whether the client environment is stable and whether the script has been maliciously interfered with.

[0024] A dynamic token management module can refer to a component responsible for generating and verifying one-time credentials when a user performs a critical operation. For example, this module generates a 6-digit dynamic token using the TOTP algorithm based on script execution status and timestamps, and compares this token with the expected value on the server side. This ensures that critical operations such as transaction payments or information modifications are initiated by a legitimate user within the expected session. Critical operations can refer to sensitive actions that, once executed, may have a significant impact on user account security, business data integrity, or system stability. Examples include, but are not limited to, password changes, large-sum fund transfers, updates to important personal information, or the export of sensitive data, which can trigger a higher level of security verification process. A one-time dynamic token can refer to an authentication credential that is valid for only a very short time and expires after use. For example, this token is generated by the dynamic token management module using the HMAC-SHA1 algorithm based on a shared key and the current time window, and delivered to the user via SMS or a built-in authenticator application. It provides strong authentication for critical operations and prevents credential replay attacks.

[0025] A proxy attack detection module refers to a component used to detect whether a network request originates from a proxy tool or passes through a malicious proxy chain. For example, this module analyzes fields such as `X-Forwarded-For` and `Via` in the HTTP request header and matches them against a built-in proxy tool fingerprint database. It also injects hidden image tags into the response HTML to probe the link, enabling it to identify attackers attempting to hide their real source IP address. A network request refers to an HTTP or HTTPS protocol data packet sent by a client to a server to obtain resources or submit data. This request includes elements such as the method, URL, request headers, and request body, which can be parsed by the proxy attack detection module to extract source characteristics for analyzing the legitimacy and potential threats of the request. Source characteristics refer to the set of information extracted from the network request that characterizes the origin attributes of the request. These characteristics include the geographical location and reputation of the IP address, TCP connection characteristics, TLS handshake parameters, request header order, and the presence or absence of specific fields, serving as important criteria for distinguishing between legitimate browsers and automated proxy tools. Proxy tools can refer to software or services used to forward or spoof the source address of network requests. Examples include forward proxies, reverse proxies, VPN clients, and automated testing frameworks such as Selenium and Puppeteer. Proxy attack identification modules identify these tools by detecting unique request headers or differences in the JavaScript runtime environment, preventing attackers from using them for automated attacks or identity spoofing. Malicious reverse proxy behavior refers to attackers deploying reverse proxy servers to steal communication data between users and legitimate websites or to launch man-in-the-middle attacks. For example, this behavior might involve injecting JavaScript probe code into the client response through a link analysis unit and checking if the code is correctly returned to the server, thus detecting the presence of intermediate nodes set up by attackers to eavesdrop or tamper with data. Proxy risk data refers to structured assessment results output by the proxy attack identification module after analyzing network requests, quantifying the probability of proxy attacks. This data might include dimensions such as tool matching confidence, abnormal request frequency scores, and abnormal link probe flags, serving as one of the inputs for a dynamic interception decision engine to conduct a comprehensive risk assessment.

[0026] A historical behavior baseline database refers to a persistent storage system that stores historical behavior patterns of users and entities. For example, this database records and maintains the statistical mean and standard deviation of each user ID or device fingerprint's login time, operation frequency, access path, transaction amount, and other behaviors over a long period, providing a benchmark for real-time behavior analysis. Historical behavior pattern data of users and entities refers to a set of features representing normal operating habits, statistically learned from the historical sessions of users or devices. This data includes historical login geographic locations, typical active time periods, access sequences of commonly used functional modules, average request intervals, etc., and can be used to build user behavior profiles as a basis for detecting abnormal behavior.

[0027] The dynamic interception decision engine refers to the core processing unit responsible for integrating multi-source security information, conducting risk assessments, and ultimately generating interception commands. For example, this engine receives token verification results from the dynamic token management module, proxy risk data from the proxy attack identification module, and behavioral pattern data queried from the historical behavior baseline database. It then performs fusion calculations using a preset risk assessment model to output the final interception decision signal. The dynamic token verification result refers to the success or failure boolean state obtained after verifying a user-submitted one-time dynamic token. For instance, this result is generated by the dynamic token management module comparing the user-input token with the expected value calculated by the server based on the same key and time window, directly reflecting whether the current operator possesses a valid two-factor authentication credential. Behavioral pattern data refers to feature information extracted in real-time from the user's current session that reflects their operating habits and intentions. This data includes mouse movement speed, click accuracy, page dwell time, and function navigation paths in the current session, and can be used for real-time comparison with patterns in the historical behavior baseline database to detect behavioral anomalies. A risk assessment model can refer to a mathematical framework that integrates multiple security indicators into a comprehensive risk score. For example, this model might use weighted summation, normalization, and nonlinear function combinations to map scores from multiple dimensions such as environmental anomalies, behavioral deviations, and proxy risks into a scalar value, quantifying the overall security risk level of the current session. The comprehensive risk score can be a numerical indicator calculated by the risk assessment model, representing the overall threat level of the current session. For instance, this score is the fusion result of environmental anomaly scores, behavioral deviation scores, and proxy risk scores after weighted summation function transformation. Its value is typically set between 0 and 100, serving as a quantitative basis for triggering different levels of intervention. An interception decision signal can refer to a control command generated by the dynamic interception decision engine based on the comprehensive risk score, instructing the execution of specific intervention actions. For example, this signal might be an enumerated value such as "ALLOW," "CHALLENGE," or "BLOCK," which can be sent to the gateway or application frontend to perform actions such as allowing access, requiring secondary verification, or forced interception. Handling actions can refer to the specific response measures taken by the system to deal with different levels of security risks. These actions include allowing the request to pass, requiring the user to complete slider verification or SMS verification, logging and issuing alarms, and directly terminating the session and returning an error page, which can realize a tiered response to potential threats.

[0028] As a concrete example: In an energy cost management scenario, a user logs in and requests a large transfer. The client-side environment awareness module first collects information about the user's device OS (Windows 10), browser (Chrome 95), screen resolution (1920x1080), and time zone (UTC+8) through the browser's Navigator and Screen interfaces. It then generates a device fingerprint hash value, "a1b2c3," based on Canvas rendering. The script security execution module uses this fingerprint as part of a key to decrypt and execute the AES-encrypted script responsible for constructing the transfer page. The dynamic token management module detects the user clicking the "Confirm Transfer" button, immediately generates a 6-digit time-to-transfer (TOTP) dynamic token, "654321," and sends it via SMS. Simultaneously, the proxy attack identification module detects an abnormal `X-Forwarded-For` hop count in the HTTP header of the request, and the User-Agent string matches a known Selenium automated driver fingerprint library, thus generating high-proxy-risk data. The dynamic interception decision engine queries the historical behavior baseline database and finds that the user typically initiates small transfers from a fixed city during the day, but this particular transaction occurred at night and the device fingerprint was new. The engine inputs the successful token verification result, the high proxy risk score, and behavioral data deviating from the historical baseline (such as excessively fast operation speed) into the risk assessment model. The model calculates and outputs a comprehensive risk score as high as 85, triggering the "CHALLENGE" interception decision signal. The system then interrupts the transfer process, forcing the user to undergo secondary facial recognition verification, thus allowing legitimate users to operate while effectively preventing automated fraudulent transactions suspected of being initiated through proxy tools.

[0029] The beneficial effects of one of the embodiments in this specification include at least the following: by constructing a collaborative protection system that integrates environmental awareness, secure script execution, token management, proxy identification, and behavior analysis, and by using a dynamic interception decision engine to perform multi-dimensional risk information fusion analysis, a comprehensive, in-depth, and proactive security assessment and protection of the client environment's trustworthiness, the legitimacy of user operations, and the authenticity of network requests is achieved. This effectively improves the system's accurate identification and dynamic response capabilities when facing complex automated attacks and identity forgery attacks, while optimizing the interactive experience of legitimate users while ensuring security.

[0030] In some implementations, the client environment awareness module includes a browser type acquisition unit, a device fingerprint generation unit, and a runtime behavior monitoring unit. The browser type acquisition unit is used to acquire the client's browser and its plugin information. The device fingerprint generation unit is used to generate a unique device identifier based on the client's hardware and software configuration. The runtime behavior monitoring unit is used to capture the mouse trajectory and click sequence during user interaction.

[0031] The browser type acquisition unit can refer to a submodule specifically designed to identify and collect information about the client's browser and its extensions. For example, this unit can obtain the browser name, version number, and list of installed plugins by parsing the userAgent, appVersion, and plugins properties of the Navigator object, which can be used to build a browser environment profile. The device fingerprint generation unit can refer to a functional component that generates a unique device identifier based on the client's hardware and software configuration. For example, this unit can collect multi-dimensional hardware and software features such as screen color depth, CPU core count, installed font list, and graphics card rendering characteristics, and synthesize a high-entropy device fingerprint string after hashing to achieve cross-session device tracking and identification. A unique device identifier can refer to a string or code that can stably and uniquely represent a specific client device over a period of time. For example, this identifier can be generated by normalizing the collected hardware and software configuration features and then inputting them into an MD5 or SHA-1 hash algorithm to generate a fixed-length digest value, which can be used to accurately distinguish different physical devices or virtual machine instances. Runtime behavior monitoring units refer to submodules that capture user actions in real time during interactions with web applications. For example, this unit might listen to DOM events such as `mousemove`, `click`, and `keydown`, recording mouse movement coordinate sequences, the target position of clicked elements, and the timestamps of the events. This can detect automated script operations or abnormal human behavior patterns. Mouse trajectories refer to the sequence of position points formed by the continuous movement of the cursor in the screen coordinate system when a user operates the mouse. For example, this trajectory might consist of a series of timestamped (x, y) coordinate points. By calculating features such as movement speed, acceleration, and angle, it can be used to distinguish the randomness of human operations from the linear movement of automated tools. Click timing refers to the time-related information associated with a user's mouse click event. This timing includes the time interval between two consecutive clicks, the duration of the click, and the specific time of day the click occurred. Combining mouse trajectories with this information allows analysis to determine whether the rhythm of user operations conforms to human behavior characteristics.

[0032] As a concrete example: In the user login process of an energy user management platform, the browser type acquisition unit identifies the client as using Chrome version 98.0.4758.102 by parsing navigator.userAgent, and detects the two browser plugins AdBlock and Grammarly. The device fingerprint generation unit simultaneously collects the device's screen resolution (2560x1440), color depth (24-bit), the list of fonts supported by the system, and the graphics card fingerprint obtained through WebGL rendering. This data is then hashed using SHA-256 to generate the device identifier "f7e3a8d1". When the user begins to enter information in the login form, the runtime behavior monitoring unit starts, listening to and recording the mouse movement trajectory from the username input box to the password input box. This trajectory includes a set of coordinate points with millisecond-level timestamps [(120, 250), (125,253), ... (280, 310)], and precisely records the timestamp of the user clicking the left mouse button in the password input box as 14:35:26.123. The system packages the collected browser type, plugin list, device identifier, and interactive behavior data including mouse trajectory and click timing to form a complete client environment profile. This provides crucial input for the subsequent script security execution module to determine the trustworthiness of the current environment. If an outdated browser version or unnatural linear mouse movement is detected, a security mechanism may be triggered requiring additional verification.

[0033] By subdividing the environmental awareness dimension and deeply integrating browser features, device fingerprints, and real-time interactive behavior, this invention constructs a multi-layered client trust status assessment system, which significantly improves the accuracy of distinguishing normal users from automated scripts, emulators, and malicious tools, providing a more reliable and richer contextual basis for the subsequent execution of dynamic security policies.

[0034] In some implementations, the script secure execution module uses code obfuscation and encryption techniques to protect the core logic, and dynamically decrypts and executes the front-end script after the client environment awareness module confirms that the environment is trustworthy.

[0035] Code obfuscation and encryption techniques refer to methods that alter the structure and form of source code to make it difficult to understand and analyze, while simultaneously using cryptographic algorithms to encrypt and protect the code content. For example, this technique uses tools like JavaScript Obfuscator to rename variables, insert useless code, and encrypt critical functions using AES-256-CBC mode, significantly increasing the difficulty of reverse engineering and code analysis. Core logic refers to the code portion essential for implementing critical business functions of an application, which would pose a serious security risk if leaked or tampered with. For instance, in online payment scenarios, this logic includes functions for calculating amounts, assembling payment interface call parameters, and updating transaction status. This part of the code can be heavily protected by applying the strongest obfuscation and encryption. Dynamic decryption refers to the process of converting encrypted code into executable code in real time during the code execution phase, rather than the loading phase. For example, this process uses a key derived from an environmental fingerprint, decrypts the encrypted script using the AES-GCM algorithm of the Web Crypto API, and immediately executes the decrypted code using `eval()` or the Function constructor, preventing the encrypted code from being stolen during disk or network transmission. Front-end scripts can refer to JavaScript code that executes in the user's browser environment to implement application interaction logic. For example, the script may have been processed by code obfuscation tools such as UglifyJS before being released on the server side, and key functions may have been encrypted. It can only be dynamically decrypted and executed after being verified in the client environment, which can prevent malicious users from decompiling and understanding the code.

[0036] As a concrete example: In an online document editing application, its core logic includes a document content encryption algorithm, an access control function, and a real-time collaborative data synchronization mechanism. Before code deployment, Webpack and Terser are used for variable name compression and control flow flattening obfuscation. Simultaneously, the core logic modules are encrypted using the AES-256 algorithm, and the ciphertext is released along with the obfuscated bootstrap code. When a user accesses the editing page, the client-side environment awareness module collects the Canvas fingerprint, WebGL renderer information, and font list to generate an environment fingerprint "env_fingerprint_xyz". The script security execution module verifies that the fingerprint's match with the user's historical session records exceeds a threshold. Then, it uses this fingerprint combined with the user's session ID to derive a decryption key and dynamically decrypts the encrypted core logic code using the `decrypt` method of the SubtleCrypto API. The decrypted code is immediately injected into the V8 engine's isolated execution environment, without writing any intermediate decryption state to disk. During this process, if the environment awareness module detects that the browser's developer tools are enabled, it determines the environment is untrusted and terminates the decryption process, effectively protecting the document encryption algorithm and access control logic from reverse engineering.

[0037] By deeply coupling code protection with runtime environment verification, this invention ensures that core business logic can only be restored and executed in a secure and trusted environment, effectively resisting static analysis, dynamic debugging, and code theft attacks against front-end code, and providing strong technical protection for the intellectual property rights of key algorithms and business rules.

[0038] In some implementations, the proxy attack identification module includes a tool fingerprint database and a link analysis unit. The tool fingerprint database stores the request characteristics of known proxy tools, and the link analysis unit identifies abnormal proxy links by injecting probe elements into the response and analyzing its return.

[0039] A tool fingerprint database can refer to a database that stores the network behavior characteristics of known proxy tools and automation frameworks. For example, this database records typical HTTP header characteristics, TLS handshake parameters, and specific attributes exposed during JavaScript runtime for tools such as Selenium and Puppeteer, which can be used to quickly match and identify common proxy tools. Request characteristics of known proxy tools can refer to network communication patterns that can uniquely or with a high probability identify specific proxy software or automation frameworks. These characteristics include specific User-Agent string formats, missing or abnormally arranged HTTP Accept headers, and TCP window size settings specific to connection sockets, which can serve as key criteria for distinguishing normal browsers from automation tools. A link analysis unit can refer to a functional component that actively probes to diagnose whether there are abnormal intermediate nodes in the network request transmission path. For example, this unit can insert an invisible IMG element pointing to its own domain name into the HTTP response body and analyze whether the probe request carries abnormal header fields or comes from an unusual IP range, thus discovering disguised reverse proxy links. Probe elements can refer to specific code or resource references injected into a normal response to detect network path anomalies. For example, this element could be a piece of JavaScript code, a hidden iframe, or a pixel-sized transparent image. Its URL contains a unique session identifier used to send back link diagnostic information when the client loads the response. The response details can refer to the behavioral characteristics and network parameters exhibited by the client browser when it requests the probe element. These include whether the request occurred, whether the returned HTTP Referer header is abnormal, whether the request source IP matches the original session IP, and whether the response time exceeds the normal range. This can be used to determine if a man-in-the-middle proxy exists. An abnormal proxy link can refer to an unauthorized or maliciously configured request forwarding link in the network communication path. For example, such a link might manifest as the client request being redirected through multiple unconventional proxy IPs, the probe request failing to return as expected, or the returned data containing markers specific to the proxy software. This can indicate that communication may be being monitored or tampered with.

[0040] As a concrete example: During a user login process, the proxy attack detection module is triggered. Its tool fingerprint database pre-stores hundreds of proxy tool characteristics, including the User-Agent format "PhantomJS / 2.1.1" for a specific version of PhantomJS and the corresponding missing Accept-Language header. When a login request is received, the module immediately compares the request header with the fingerprint database, finding that the request's User-Agent is indeed "PhantomJS / 2.1.1" and that the Accept-Language header is missing, with a match confidence of 92%. Simultaneously, the link analysis unit injects a 1x1 transparent GIF image with the src attribute "https: / / api.example.com / probe.jpg?sid=abc123" into the login page's response HTML. Normally, the browser should load this image directly from api.example.com. However, analysis reveals that the request for this probe image originates from an IP range of a known proxy service provider, and the request header contains X-Forwarded-For multi-level redirect information. By combining the tool fingerprint matching results and link detection anomalies, the module determines that there are abnormal proxy links and generates high-risk proxy risk data to output to the dynamic interception decision engine.

[0041] By combining static tool feature matching with dynamic link active detection as a dual verification mechanism, this invention can effectively identify automated attacks and man-in-the-middle eavesdropping behaviors that use proxy tools to hide their true source, enhancing the detection capability of carefully disguised network layer attacks and providing a deeper level of protection for application security.

[0042] In some implementations, the risk assessment model built into the dynamic interception decision engine is a multi-dimensional fusion model. The multi-dimensional fusion model combines environmental anomaly scores, behavioral deviation scores, and standardized agent risk scores into a comprehensive risk score through a weighted fusion method.

[0043] A multi-dimensional fusion model refers to a mathematical model that integrates risk indicators from multiple different natures and security domains and performs unified calculations. For example, this model assigns weight coefficients to environmental verification indicators, user behavior characteristics, and proxy risk dimensions, and uses standardization and function transformation to eliminate the influence of dimensions, thus comprehensively reflecting the overall status of session security. A weighted fusion method refers to a calculation method that assigns different importance coefficients to different input variables during data fusion. For example, this method obtains the weights of environmental verification indicators through offline machine learning model training, presets the weights of proxy risk dimensions according to security policies, and then weights and combines the standardized scores of each dimension, highlighting the influence of key risk factors. An environmental anomaly score refers to a numerical indicator that quantifies the degree of deviation of client environmental characteristics from the normal historical baseline. For example, this score is obtained by calculating the standardized residuals of the original observed values ​​of environmental verification indicators and the historical mean, multiplying them by weights, squaring them, and summing the results, reflecting the possibility that the client environment has been tampered with or simulated. A behavioral deviation score refers to a numerical measure that characterizes the difference between a user's real-time operational behavior and historical behavioral patterns. For example, this score is obtained by taking the logarithmic transformation of the weighted sum of absolute deviations, which can capture subtle behavioral anomalies. A standardized proxy risk score can refer to a numerical representation that unifies the raw risk metric output by the proxy attack identification module to a standard scale. For example, this score is obtained by normalizing and weighting the raw scores of multiple risk dimensions such as tool fingerprint matching, abnormal request frequency, and abnormal link detection, thus eliminating the dimensional differences between different risk dimensions. A comprehensive risk score can refer to a numerical indicator that characterizes the overall threat level of the current session, calculated by a risk assessment model. For example, this score is a fusion result of an abnormal environment score, behavioral deviation score, and standardized proxy risk score after weighting and function transformation, and is used as a quantitative basis for triggering different levels of handling actions.

[0044] As a concrete example: In a sensitive step of a transfer transaction, the dynamic interception decision engine initiates a risk assessment. It obtains abnormal data from the client's environment awareness module regarding a sudden change in screen resolution, calculating an environment anomaly score of 15.6; it queries the historical behavior baseline database to find that the user typically transacts during weekdays, but this time the operation occurred in the early morning, combining this with the mechanical characteristics of the mouse movement trajectory, calculating a behavior deviation score of 8.2; the proxy attack identification module detects that the request originates from a data center IP and matches a Selenium fingerprint, resulting in a standardized proxy risk score of 22.1. The engine's built-in multi-dimensional fusion model presets weights of 0.4, 0.3, and 0.3 for these three dimensions respectively, using a weighted sum of squares calculation: Overall Risk Score = 0.4 × 15.6^2 + 0.3 × 8.2 + 0.3 × 22.1^2 = 97.3 + 20.1 + 146.5 = 263.9. This score far exceeds the preset interception threshold of 200, and the engine immediately generates a forced interception signal, terminating the transaction process and triggering a security alarm. Throughout the process, the weighted fusion approach ensured that the agent risk dimension was appropriately emphasized due to its higher threat level, while the contributions of environmental anomalies and behavioral deviations were also reasonably incorporated into the final decision.

[0045] By adopting a multi-dimensional weighted and integrated risk assessment mechanism, this invention can comprehensively consider multiple key security factors such as environmental credibility, behavioral compliance, and network link security, and achieve accurate quantification and intelligent judgment of complex attack scenarios. This effectively improves the systematicness and scientific nature of security decisions and avoids missed or false alarms caused by misjudgment due to a single dimension.

[0046] In some implementations, the formula for calculating the comprehensive risk score includes:

[0047] in, This represents the overall risk score, used for final decision-making. This represents the total number of environmental verification indicators, and its value comes from the number of indicator types collected by the client's environmental perception module. The weight coefficient of the i-th environmental verification indicator is obtained by training an offline machine learning model. This represents the original observed value of the i-th environmental verification indicator. Its dimensions are determined by the specific indicator and are collected in real time by the client's environmental perception module. represents the historical average of the i-th environmental verification indicator in the normal user group. Its dimension is the same as EiEi, and it is obtained from the historical behavior baseline database. represents the historical standard deviation of the i-th environmental verification indicator in the normal user group. Its dimension is the same as EiEi, and it is obtained from the historical behavior baseline database. This represents the total number of user behavior features, and its value is determined by the feature dimensions maintained in the historical behavior baseline database. The weight coefficients representing the j-th user behavior feature are obtained by training an offline machine learning model. The original observation value representing the j-th user behavior feature is extracted from real-time session data; This represents the historical mean of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the historical standard deviation of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the total number of risk dimensions associated with the proxy attack; its value is determined by the number of risk dimensions output by the proxy attack identification module. This represents the weight coefficient for the k-th agent risk dimension, which is preset by the system according to the security policy; This represents the standardized agency risk score for the k-th agency risk dimension; The smoothing factor representing the agent risk score is a real number greater than zero, and is preset by the system to adjust the contribution scale of this item.

[0048] The final decision can refer to the specific security action selected and executed based on the comprehensive risk score. For example, this decision might compare the score R with a preset threshold range to trigger different levels of response, such as allowing passage, requiring secondary verification, or mandatory interception, thus completing a closed loop from risk quantification to security response. The total number of environmental verification indicators can refer to the number of quantifiable feature parameters used in the environmental anomaly assessment process. An offline machine learning model can refer to a risk assessment model trained using historical session data before system deployment or during off-peak periods. For example, this model might use labeled normal and malicious session datasets and optimize the weights of various environmental indicators through gradient descent algorithms to achieve optimal risk identification accuracy in real-time decision-making. The raw observations of environmental verification indicators can refer to unstandardized initial data directly measured or read from the client environment. For example, this value might be a pixel value obtained through JavaScript's `screen.width` property or a language code string obtained through `navigator.language`, preserving the original information of environmental characteristics. The historical mean of a normal user group refers to the arithmetic mean of a large number of sessions marked as legitimate users within a specific time window on a certain environmental indicator. It can be used to detect abnormal environments deviating from mainstream configurations. The historical behavior baseline database refers to a persistent storage system that stores historical behavior pattern data of users and entities, providing a benchmark for real-time behavior analysis. The historical standard deviation of a normal user group refers to a measure of the dispersion of normal user sessions on a specific environmental indicator, used to calculate the standardized distance between the current observation and the normal baseline. The total number of user behavior features refers to the number of quantifiable user operation characteristics used in behavior analysis. For example, this total includes the number of valid behavior pattern categories extracted from interaction data such as mouse events, keyboard events, and touch events, affecting the granularity of behavior risk assessment. The feature dimensions maintained in the historical behavior baseline database are determined by the actual number of behavior feature types stored and calculated in the database. The numerical values, for example, if the database maintains historical statistics for 20 behavioral characteristics, then... The value is set to 20 to ensure consistency between real-time behavioral analysis and historical baselines. Real-time session data refers to the continuous stream of operation events generated during the current user interaction. This data includes timestamped browser events such as mousemove, click, and keydown, captured by event listeners and temporarily stored in memory for extracting behavioral features (Bj). The total number of proxy risk dimensions refers to the number of independent risk factor categories considered during proxy attack assessment. The number of risk dimensions can also refer to the count of different assessment perspectives or factor categories used in a specific risk assessment domain. For example, in proxy risk assessment, this number may include the number of risk factors from different aspects such as tool fingerprint dimensions, request frequency dimensions, and link anomaly dimensions, reflecting the multi-faceted nature of risk assessment. System-based security policy presets refer to the process by which security administrators or security policy engines pre-configure parameters based on organizational security requirements and threat intelligence. For example, this process assigns a higher weight (wkp) to the tool fingerprint matching dimension based on the main proxy attack types currently faced, reflecting the targeted and flexible nature of risk response. The smoothing factor of the proxy risk score can refer to the adjustment parameter used in risk fusion calculation to balance the influence intensity of proxy risk items. For example, this factor can maintain the balance of risk assessment by appropriately reducing the growth rate of high proxy risk scores and avoiding excessive influence of a single high-risk dimension on the final decision.

[0049] By constructing a multi-dimensional weighted fusion model that includes environmental anomalies, behavioral deviations, and proxy risks, and by employing standardization to eliminate dimensional differences, nonlinear transformation to enhance robustness, and smoothing factors to balance contribution scales, this invention achieves refined quantification and unified assessment of complex security threats. This provides a scientific and reliable quantitative basis for accurate security decision-making, significantly improving the accuracy of risk identification and the rationality of decision-making.

[0050] In some implementations, the standardized agent risk score Pk′ is a calculation result for a specific dimension. The calculation method may be the same or different for different dimensions. When the specific dimension is the tool fingerprint matching dimension, the formula for calculating the standardized agent risk score Ptool′ for tool fingerprint matching includes:

[0051] in, This represents the standardized proxy risk score for tool fingerprint matching, used as an instance of Pk′ for calculating the comprehensive risk score; This represents the total number of known proxy tool feature matches detected, and its value is obtained by the proxy attack identification module after comparing it with the tool fingerprint database. This represents the confidence score of the m-th matched known proxy tool feature, obtained from the tool fingerprint database; The system's preset maximum value for the confidence score of the proxy tool's features is used for normalization; The non-linear amplification exponent, representing the confidence score, is a real number greater than 1 and is preset by the system according to the security policy. This represents the total number of abnormal request frequency characteristics, and its value is determined by the number of predefined abnormal frequency detection rules within the proxy attack identification module. The current observation value representing the anomaly feature of the nth request frequency is obtained by the proxy attack identification module within the time window. The normal baseline value representing the abnormal frequency characteristic of the nth request is obtained from the historical behavior baseline database; The nonlinear adjustment index, which represents the impact of frequency anomalies, is a real number greater than 1 and is preset by the system according to the safety policy. This represents the total number of abnormal signals detected by the link probe, and its value is determined by the number of probe nodes deployed by the link analysis unit in the proxy attack identification module. This represents the abnormal state value of the p-th link probe node, which is obtained by the link analysis unit based on the return information of the probe elements; This represents the total number of request timestamp anomaly types, and its value is determined by the number of predefined time series anomaly detection rules within the proxy attack identification module. This represents the severity of the q-th type of timestamp anomaly, calculated by the proxy attack identification module based on the degree of deviation. This represents a very small positive integer to prevent the denominator from being zero; it is preset by the system.

[0052] The calculation results for a specific dimension can refer to a quantitative risk value calculated separately for a specific assessment aspect of proxy risk. For example, the result might be calculated specifically for a single dimension such as tool fingerprint matching, abnormal request frequency, or abnormal link probing, providing fine-grained risk analysis. The tool fingerprint matching dimension can refer to an assessment aspect in proxy risk evaluation that specifically focuses on the degree to which request characteristics match a known proxy tool fingerprint database. For example, this dimension can quantify the risk of automated proxy tools by comparing HTTP header features, TLS parameters, and JavaScript runtime attributes with known patterns of tools like Selenium and PhantomJS in the fingerprint database. A standardized proxy risk score based on tool fingerprint matching can refer to a comprehensive evaluation value that integrates multiple risk indicators from the tool fingerprint dimension into a unified standard scale. For example, this score is obtained by weighted combination of sub-scores such as tool feature matching confidence, abnormal request frequency, and abnormal link probing, and can be used for fair comparison with other risk dimensions. The total number of detected known proxy tool feature matches refers to the number of items identified in the current network request that match the features of known proxy tools in the fingerprint database. This total number may include the count of multiple feature matches such as User-Agent string matching, HTTP header missing anomalies, and special configurations of TLS cipher suites, comprehensively reflecting the likelihood of proxy tool usage. The system-preset maximum value of the proxy tool feature confidence score refers to the upper limit of the feature confidence score determined during system design. For example, this value is usually set to 100, representing a completely certain feature match, where the confidence score Am of all actual feature matches is less than or equal to this value, providing a stable benchmark for normalization calculations. The non-linear amplification index of the confidence score refers to the power parameter used in score calculation to adjust the influence strength of high-confidence features. For example, when this index is greater than 1, the relative weight of high-confidence features will be significantly amplified after the γ-power operation of Am / Amax, highlighting the role of strong discriminative features. The system's pre-configured security policy parameters can refer to the process by which security administrators or the security policy engine pre-configure parameters based on organizational security requirements and threat intelligence. For example, this process might set an appropriate γ value to adjust the amplification of high-confidence features based on the current level of proxy attack threats, reflecting the targeted nature of risk response. The total number of abnormal request frequency features can refer to the number of different anomaly detection indicators used in the frequency anomaly analysis process. This total might include multiple independent detection dimensions such as exceeding the limit for requests per minute, excessively large standard deviation of request intervals, and burstiness of continuous requests, enabling multi-faceted identification of frequency anomaly patterns. The number of predefined frequency anomaly detection rules within the proxy attack identification module can be determined by the number of built-in request frequency anomaly judgment rules in the module design. The specific values, for example, if the module predefines 5 frequency anomaly detection rules, then The value is set to 5 to ensure the consistency of the assessment system. The frequency anomaly impact nonlinear adjustment index refers to the power parameter used to adjust the relationship between the degree of anomaly and the score value in the frequency anomaly scoring. For example, when this index is greater than 1, the frequency anomaly ratio Fn / Fn(base) raised to the power of δ will amplify the contribution of high anomaly values, highlighting the risk impact of severe frequency anomalies. The total number of link probe anomaly signals refers to the number of anomaly indicators generated by different types of probe mechanisms deployed during link anomaly detection. For example, this total includes the number of anomaly signals from multiple independent probe dimensions such as DNS resolution timeouts, TCP handshake RTT anomalies, and HTTP redirection path anomalies, providing a comprehensive assessment of link health. The number of deployed probe nodes determines the specific value of Nd based on the actual number of network probe points implemented. For example, if the link analysis unit deploys probe nodes on servers in three different geographical locations, the value of Nd is set to 3, reflecting the scale of the link probe infrastructure. The total number of request timestamp anomaly types can refer to the number of different anomaly pattern categories used in the time series anomaly detection process. For example, this total includes the count of multiple independent anomaly types such as timestamp reversal, request intervals not conforming to a Poisson distribution, and disordered key operation sequences, enabling comprehensive identification of time-dimensional anomalies. The number of predefined time series anomaly detection rules within the proxy attack identification module can be determined by the number of built-in timestamp anomaly judgment rules in the module design. The specific values, for example, if the module predefines four timestamp anomaly detection rules, then... The value was set to 4, which ensures the systematization of time anomaly assessment.

[0053] By constructing a multi-dimensional evaluation system that includes tool feature matching, request frequency analysis, link detection, and time series anomaly assessment, and by employing nonlinear amplification to enhance strong evidence weights, normalization to eliminate dimensional differences, and minimal constants to ensure computational stability, this invention achieves refined quantification and comprehensive evaluation of proxy attack risks, significantly improving the accuracy and reliability of identifying automated tools and malicious proxies in complex network environments.

[0054] In some implementations, the system also includes a security data association library, which is connected to the dynamic interception decision engine to store and associate asset information, vulnerability information and threat intelligence, providing additional contextual data support for the dynamic interception decision engine.

[0055] A security data association library refers to a dedicated database system that stores and associates various security-related information. For example, this library uses unified resource identifiers to associate asset information, vulnerability information, threat intelligence, and historical attack event data, providing rich contextual data support for dynamic interception decision engines. Vulnerability information refers to technical descriptions and risk assessment data of security flaws in software or hardware. This information includes key attributes such as CVE numbers, CVSS baseline scores, affected product version ranges, vulnerability types, and exploitability assessments, providing detailed information on known security weaknesses. Threat intelligence refers to analyzed and verified information about cybersecurity threats. This intelligence includes malicious IP addresses and domains, attacker-used TTPs, malware hashes, attack activity attribution, and related confidence and severity ratings, providing awareness of the external threat environment. Additional contextual data support refers to supplementary information beyond the scope of real-time session data that enhances the accuracy of risk assessment. For example, this support obtains threat intelligence for the current IP, known vulnerabilities in related assets, and historical attack patterns by querying the security data association library, providing a more comprehensive basis for risk assessment.

[0056] As a concrete example: When a web application is subjected to a credential stuffing attack, the dynamic interception decision engine, in assessing the risk of login requests, not only analyzes real-time environmental fingerprints and behavioral data, but also queries a security data association library to obtain additional context. This library associates an asset identifier with the login server IP (asset information) which contains an unpatched CVE-2023-12345 vulnerability in Apache Struts (vulnerability information, CVSS 8.5), while threat intelligence shows that the source IP segment has been marked as malicious in the past 24 hours (threat intelligence, confidence level 85%). This associated data is returned to the decision engine in real time through database join queries. The engine integrates this contextual data with environmental anomaly scores and behavioral deviation scores to calculate a significantly increased comprehensive risk score. Based on this, even if real-time behavioral characteristics only show minor anomalies, the engine can still make accurate interception decisions, effectively preventing combined attacks exploiting known vulnerabilities and malicious IPs.

[0057] By introducing a security data association library and providing the decision engine with multi-dimensional contextual data such as assets, vulnerabilities, and threat intelligence, this invention significantly expands the information foundation for risk assessment, enabling security decisions to be based not only on real-time behavioral characteristics but also on the external threat environment and internal asset vulnerabilities, thereby achieving a more comprehensive and accurate identification and response to complex attack scenarios.

[0058] In some implementations, after executing the action, the dynamic interception decision engine will send back the fingerprint information of this attack and store it in the security data association library to update the behavioral pattern data and threat intelligence in the historical behavior baseline database.

[0059] The execution of actions can refer to the process of implementing specific security responses based on interception decision signals. Such actions include terminating the current session, resetting the connection, returning to the challenge page, logging security events, or notifying the administrator, which can effectively block or mitigate identified security threats.

[0060] As a concrete example: After an automated script attack targeting an online payment system is intercepted, the dynamic interception decision engine sends the attack's fingerprint information (including the attack source IP 192.168.1.100, the Selenium WebDriver characteristics used, the attack time window of 14:30-14:45, and the targeted API endpoint / api / transfer) back to the security data association database via a TLS encrypted channel. This database first stores these raw attack fingerprints, then uses data association analysis to identify that this IP has attempted similar attack patterns in the past 72 hours. Next, the system automatically updates the behavioral pattern data associated with this IP in the historical behavior baseline database, marking it as a malicious IP and adjusting the corresponding risk weight. Simultaneously, newly discovered Selenium attack characteristics are extracted and added to the threat intelligence database to enhance the ability to detect similar attacks in the future. When the same attacker launches another attack from a different IP, 192.168.1.200, the system can accurately identify and intercept the attack even if the new IP has no historical records, by comparing the attack characteristics in the threat intelligence database.

[0061] By establishing a closed-loop feedback mechanism from attack detection to knowledge update, this invention realizes the self-learning and adaptive capabilities of the security protection system, enabling the system to continuously learn new threat characteristics from actual attacks and dynamically optimize protection strategies, thereby continuously improving the identification and defense effects against new and variant attacks.

[0062] In some implementations, the dynamic interception decision engine triggers different actions based on different threshold ranges of the comprehensive risk score. These actions include allowing passage, requiring secondary verification, and forced interception.

[0063] As a concrete example: In a transaction monitoring scenario of an energy trading system, the comprehensive risk score calculated by the dynamic interception decision engine is mapped to three preset threshold ranges: 0-25 is the low-risk allowance range, 25-75 is the medium-risk verification range, and 75-100 is the high-risk interception range. When a user initiates a small transfer, the engine calculates a risk score of 18, falling into the low-risk range, and the system allows the transaction to proceed normally. When another user initiates a large transfer on an uncommon device, the risk score is calculated to be 52, falling into the medium-risk range. The system triggers a secondary verification action, sending a 6-digit SMS verification code to the user's registered mobile phone. Only after successful verification can the transaction continue. When a login attempt from a known malicious IP is detected, the risk score reaches 88, falling into the high-risk range. The system immediately executes a forced interception action, terminating the session and recording the security event. This tiered handling mechanism based on risk score ranges ensures a smooth experience for normal users while providing appropriate security responses for different threat levels.

[0064] By establishing a tiered response mechanism based on a comprehensive risk score threshold range, this invention achieves precise and differentiated security responses. It avoids unnecessary interference with low-risk users while ensuring timely blocking of high-risk threats. It optimizes user experience while ensuring security, achieving an effective balance between security protection and business convenience.

[0065] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this invention. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. An application protection system based on behavior analysis, characterized in that, include: The client-side environment awareness module is used to collect and process the client's environmental information to generate environmental fingerprint data; The script secure execution module is connected to the client environment awareness module and is used to receive the environment fingerprint data, dynamically decrypt and execute the front-end script, and output the script execution status. The dynamic token management module is connected to the script security execution module and generates and verifies a one-time dynamic token when the user performs a critical operation based on the script execution status. The proxy attack identification module is used to analyze the source characteristics of network requests to identify proxy tools and malicious reverse proxy behavior, and generate proxy risk data. Historical behavior baseline database, used to store and provide historical behavior pattern data of users and entities; The dynamic interception decision engine is connected to the dynamic token management module, the proxy attack identification module, and the historical behavior baseline database, respectively. It is used to integrate the verification results of the dynamic token, the proxy risk data, and the historical behavior pattern data, calculate a comprehensive risk score through a risk assessment model, and output an interception decision signal based on the comprehensive risk score to execute corresponding handling actions.

2. The system according to claim 1, characterized in that, The client environment awareness module includes a browser type acquisition unit, a device fingerprint generation unit, and a runtime behavior monitoring unit. The browser type acquisition unit is used to acquire the client's browser and its plugin information. The device fingerprint generation unit is used to generate a unique device identifier based on the client's hardware and software configuration. The runtime behavior monitoring unit is used to capture the mouse trajectory and click sequence during user interaction.

3. The system according to claim 1, characterized in that, The script secure execution module uses code obfuscation and encryption technology to protect the core logic, and dynamically decrypts and executes the front-end script after the client environment awareness module confirms that the environment is trustworthy.

4. The system according to claim 1, characterized in that, The proxy attack identification module includes a tool fingerprint database and a link analysis unit. The tool fingerprint database stores the request characteristics of known proxy tools, and the link analysis unit identifies abnormal proxy links by injecting probe elements into the response and analyzing its return.

5. The system according to claim 4, characterized in that, The risk assessment model built into the dynamic interception decision engine is a multi-dimensional fusion model. The multi-dimensional fusion model combines the environmental anomaly score, behavioral deviation score, and standardized agent risk score into the comprehensive risk score through a weighted fusion method.

6. The system according to claim 5, characterized in that, The formula for calculating the comprehensive risk score includes: in, The comprehensive risk score is used for the final decision. This represents the total number of environmental verification indicators, the value of which comes from the number of indicator types collected by the client's environmental perception module. The weight coefficient of the i-th environmental verification indicator is obtained by training an offline machine learning model. This represents the original observed value of the i-th environmental verification indicator, the dimension of which is determined by the specific indicator and is collected in real time by the client's environmental perception module; represents the historical average of the i-th environmental verification indicator in the normal user group, and its dimension is the same as EiEi, which is obtained from the historical behavior baseline database; represents the historical standard deviation of the i-th environmental verification indicator in the normal user group, and its dimension is the same as EiEi, which is obtained from the historical behavior baseline database; This represents the total number of user behavior features, the value of which is determined by the feature dimensions maintained in the historical behavior baseline database. The weight coefficients representing the j-th user behavior feature are obtained by training an offline machine learning model. The original observation value representing the j-th user behavior feature is extracted from real-time session data; This represents the historical mean of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the historical standard deviation of the j-th user behavior feature in the historical behavior baseline database, and its dimensions are... same; This represents the total number of risk dimensions associated with the proxy attack, and its value is determined by the number of risk dimensions output by the proxy attack identification module. This represents the weight coefficient for the k-th agent risk dimension, which is preset by the system according to the security policy; This represents the standardized agency risk score for the k-th agency risk dimension; The smoothing factor representing the agent risk score is a real number greater than zero, and is preset by the system to adjust the contribution scale of this item.

7. The system according to claim 6, characterized in that, The standardized proxy risk score Pk′ is a calculation result for a specific dimension. The calculation method may be the same or different for different dimensions. When the specific dimension is the tool fingerprint matching dimension, the formula for calculating the standardized proxy risk score Ptool′ for tool fingerprint matching includes: in, This represents the standardized proxy risk score for tool fingerprint matching, used as an instance of Pk′ in the calculation of the comprehensive risk score; This represents the total number of known proxy tool feature matches detected, and its value is obtained by the proxy attack identification module comparing it with the tool fingerprint database. The confidence score represents the feature of the m-th matched known proxy tool, which is obtained by querying the tool fingerprint database; The system's preset maximum value for the confidence score of the proxy tool's features is used for normalization; The non-linear amplification exponent, representing the confidence score, is a real number greater than 1 and is preset by the system according to the security policy. This represents the total number of abnormal request frequency characteristics, and its value is determined by the number of predefined abnormal frequency detection rules within the proxy attack identification module. The current observation value representing the abnormal frequency feature of the nth request is obtained by the proxy attack identification module within the time window. The normal baseline value representing the abnormal feature of the nth request frequency is obtained by querying the historical behavior baseline database; The nonlinear adjustment index, which represents the impact of frequency anomalies, is a real number greater than 1 and is preset by the system according to the safety policy. This represents the total number of abnormal signals detected by the link probe, and its value is determined by the number of probe nodes deployed by the link analysis unit in the proxy attack identification module. This represents the abnormal state value of the p-th link probe node, which is obtained by the link analysis unit based on the return information of the probe element; This represents the total number of request timestamp anomaly types, and its value is determined by the number of predefined time series anomaly detection rules within the proxy attack identification module. The severity of the q-th type of timestamp anomaly is calculated by the proxy attack identification module based on the degree of deviation. This represents a very small positive integer to prevent the denominator from being zero; it is preset by the system.

8. The system according to claim 1, characterized in that, The system also includes a security data association library, which is connected to the dynamic interception decision engine and is used to store and associate asset information, vulnerability information and threat intelligence, providing additional contextual data support for the dynamic interception decision engine.

9. The system according to claim 8, characterized in that, After executing the action, the dynamic interception decision engine will send back the fingerprint information of this attack and store it in the security data association library to update the behavioral pattern data and threat intelligence in the historical behavior baseline database.

10. The system according to claim 1, characterized in that, The dynamic interception decision engine triggers different actions based on the different threshold ranges of the comprehensive risk score. These actions include allowing passage, requiring secondary verification, and forced interception.