Network application protection system and method, storage medium and computer program product
The network application protection system, with its distributed architecture and intelligent traffic scheduling, solves the performance bottlenecks and security risks of centralized web application firewalls, achieving efficient and stable network protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
- Filing Date
- 2026-04-07
- Publication Date
- 2026-05-05
AI Technical Summary
Centralized web application firewall nodes can become performance bottlenecks when traffic is too high, leading to network latency and security risks. They are also prone to becoming single points of failure, affecting system stability and security.
The network application protection system adopts a distributed architecture. It uses a traffic scheduler to predict and distribute traffic using a predictive model, and combines this with the protection management node to dynamically adjust protection strategies, thereby achieving fine-grained traffic scheduling and adaptive protection, reducing network latency and improving security.
This effectively avoids single-point overload, reduces network latency, improves system efficiency and security, and ensures the stability and reliability of the protection system.
Smart Images

Figure CN121984791A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network security technology, and in particular to a network application protection system, method, storage medium, and computer program product. Background Technology
[0002] Currently, protection nodes in related technologies, such as Web Application Firewall (WAF) nodes, typically adopt a centralized deployment scheme. Their main feature is that WAF nodes are deployed on one or more data centers or cloud service providers' nodes to detect and filter all web application traffic.
[0003] However, centralized WAF nodes are responsible for traffic detection and filtering for the entire system. When the traffic is too high, the performance of the WAF nodes will become the bottleneck of the entire system. Furthermore, since centralized WAF nodes are usually deployed on nodes of data centers or cloud service providers, when users remotely access web applications, there will be a large network latency, which will lead to insufficient performance of the WAF nodes. Summary of the Invention
[0004] To address the technical problems existing in related technologies, embodiments of this application provide a network application protection system, method, storage medium, and computer program product.
[0005] To achieve the above objectives, the technical solution of this application embodiment is implemented as follows: In a first aspect, embodiments of this application provide a network application protection system, the system comprising: a traffic scheduler and a protection management node, wherein the protection management node includes one or more protection nodes; The traffic scheduler is used to receive access requests for network applications sent by clients, perform traffic analysis on the access requests using a prediction model to obtain traffic prediction values at the target time, and distribute the traffic prediction values to different protection nodes. The protection management node is used to detect potential attack behaviors in the access request, and adjust the source protection strategy based on the attack type, attack frequency and attack severity of the potential attack behaviors to obtain the target protection strategy.
[0006] Secondly, embodiments of this application also provide a network application protection method, the method comprising: Receive access requests for network applications sent by clients; The access requests are analyzed using a predictive model to obtain the predicted traffic value at the target time; the predicted traffic value is then distributed to different protection nodes. The system detects potential attack behaviors in the access requests and adjusts the source protection strategy based on the attack type, frequency, and severity of the potential attack behaviors to obtain the target protection strategy.
[0007] Thirdly, embodiments of this application also provide a storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the network application protection method described in embodiments of this application.
[0008] Fourthly, embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the network application protection method described in embodiments of this application.
[0009] The network application protection system, method, storage medium, and computer program product provided in this application embodiment include: a traffic scheduler and a protection management node, wherein the protection management node comprises one or more protection nodes; the traffic scheduler is used to receive access requests for network applications sent by clients, perform traffic analysis on the access requests using a prediction model to obtain traffic prediction values at a target time, and allocate the traffic prediction values to different protection nodes; the protection management node is used to detect potential attack behaviors in the access requests, and adjust the source protection strategy based on the attack type, attack frequency, and attack severity of the potential attack behaviors to obtain a target protection strategy. By adopting the technical solution of this application embodiment, the traffic scheduler performs traffic analysis on the access requests using a prediction model to obtain traffic prediction values at a target time, and dynamically allocates the traffic prediction values to different protection nodes, achieving fine-grained traffic scheduling and avoiding performance bottlenecks caused by overload of a single node; the protection management node comprehensively considers the attack type, attack frequency, and attack severity of potential attack behaviors, dynamically adjusts the protection strategy, reduces network latency, improves protection efficiency, and ensures the high efficiency and security of the entire system. Attached Figure Description
[0010] Figure 1 This is a schematic diagram of the composition structure of the network application protection system according to an embodiment of this application; Figure 2 This is a flowchart illustrating the network application protection method according to an embodiment of this application; Figure 3 This is a schematic diagram of the architecture of the network application protection system according to an embodiment of this application; Figure 4 This is a schematic diagram of the composition structure of the network application protection device according to an embodiment of this application; Figure 5 This is a schematic diagram of the hardware composition of the network application protection device according to an embodiment of this application. Detailed Implementation
[0011] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.
[0012] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.
[0013] Existing WAF nodes typically employ a centralized deployment scheme, characterized by deploying the WAF nodes on one or several central nodes to detect and filter all web application traffic. A specific scheme is as follows: 1. Deploy WAF nodes on data center or cloud service provider nodes to detect and filter all web application traffic; 2. Use a load balancer to distribute user-requested web application traffic to different WAF nodes, thereby achieving load balancing and high availability.
[0014] However, the main drawbacks of the aforementioned existing technical solutions include the following: Single point of failure: The centralized WAF node becomes the single point of failure for the entire system. Once the WAF node fails, the entire system will be unable to function.
[0015] Performance bottleneck: The centralized WAF node is responsible for the traffic detection and filtering tasks of the entire system. When the traffic is too large, the performance of the WAF node will become the bottleneck of the entire system.
[0016] Local performance deficiencies: Centralized WAF nodes are typically deployed on nodes in data centers or cloud service providers. When users remotely access web applications, significant network latency occurs, leading to insufficient performance of the WAF nodes.
[0017] Security issues: Centralized WAF nodes have become the primary target of attackers. Once a WAF node is successfully attacked, the entire system will face serious security risks.
[0018] Based on this, embodiments of this application propose a network application protection system, method, storage medium, and computer program product. In various embodiments of this application, the traffic scheduler analyzes access requests using a prediction model to obtain traffic prediction values at the target time, and dynamically allocates the traffic prediction values to different protection nodes to achieve fine-grained traffic scheduling and avoid performance bottlenecks caused by overload of a single node. The protection management node comprehensively considers the attack type, attack frequency, and attack severity of potential attack behaviors, dynamically adjusts the protection strategy, reduces network latency, and improves protection efficiency to ensure the high efficiency and security of the entire system.
[0019] This application provides a network application protection system. Figure 1 This is a schematic diagram of the composition structure of the network application protection system according to an embodiment of this application, as shown below. Figure 1 As shown, the system includes: a traffic scheduler 11 and a protection management node 12, wherein the protection management node 12 contains one or more protection nodes; The traffic scheduler 11 is used to receive access requests for network applications sent by clients, perform traffic analysis on the access requests using a prediction model to obtain traffic prediction values at the target time, and distribute the traffic prediction values to different protection nodes. The protection management node 12 is used to detect potential attack behaviors in the access request, and adjust the source protection strategy based on the attack type, attack frequency and attack severity of the potential attack behaviors to obtain the target protection strategy.
[0020] In this embodiment, the network application can be a web application. When a user corresponding to a client accesses a web application, the client sends an access request for that web application to the traffic scheduler 11. The protection node, for example, can be a WAF node, which is a node specifically designed to protect web applications and has protective functions.
[0021] Here, a WAF node is a network security device used to protect web applications from various web attacks, such as Structured Query Language (SQL) injection attacks, Cross-Site Scripting (XSS) attacks, command execution vulnerabilities, and file inclusion attacks.
[0022] Here, there are multiple protection management nodes 12, which are deployed in a regionalized manner through a distributed architecture. Specifically, the multiple protection management nodes 12 are distributed in different geographical areas, so that access requests can be routed to the nearest protection management node, thereby effectively reducing network latency when users access the network and improving protection response efficiency.
[0023] It should be noted that in practical applications, multiple protection nodes (such as WAF nodes) can be deployed in each geographical area to achieve redundancy and disaster recovery. When a WAF node fails or suffers a major attack, traffic will automatically switch to other WAF nodes to ensure service continuity and stability.
[0024] In one embodiment, the WAF node can deploy localized protection strategies (corresponding to source protection strategies) based on specific attack intelligence of its geographical location. For example, if a specific type of attack is frequently detected in a certain geographical area, the protection management node 12 will enhance the corresponding protection measures for that geographical area (i.e., enhance the source protection strategy) to prevent the attack from spreading.
[0025] Here, the traffic scheduler can also be called an intelligent traffic scheduler, or a traffic controller, or an intelligent traffic controller. The name of the traffic scheduler is not limited in the embodiments of this application.
[0026] In practical applications, in order to achieve accurate prediction of traffic peaks and attack behaviors, the traffic scheduler 11 relies on a complex prediction model, which is a machine learning analysis model, or simply a machine learning model.
[0027] Accordingly, in one embodiment, the prediction model includes a time series prediction model and an attack behavior prediction model; The traffic scheduler 11 is specifically used for: The traffic data related to the access request is input into the time series prediction model to obtain the time series data of the traffic; The attack behavior indicators related to the access request are input into the attack behavior prediction model to obtain the attack behavior prediction value; Based on the time series data of the traffic and the predicted value of the attack behavior, the predicted value of the traffic at the target time is determined.
[0028] Here, traffic data related to access requests may include the current time when the access request was sent. Traffic data, and the current moment Traffic data from one or several moments prior. A time series prediction model, also known as a time series prediction function, analyzes traffic data related to access requests using this function to obtain time series data of the traffic. In other words, the time series prediction function captures the time trend and pattern of the traffic (corresponding to the time series data of the traffic). Attack behavior indicators related to access requests can be seen as the current moment the access request was sent. Attack behavior indicators can include, for example, request frequency and abnormal request types. Attack behavior prediction models can be deep learning models.
[0029] In one embodiment, after obtaining the time-series traffic data and attack behavior predictions, the traffic scheduler 11 can also consider the noise of the prediction model. Thus, by combining the time-series traffic data, attack behavior predictions, and prediction model noise, the traffic prediction value for the target time is determined. The noise of the prediction model can also be referred to as the error term of the prediction model, used to handle unpredictable random fluctuations.
[0030] As can be seen, the prediction model in this application combines time series analysis and deep learning techniques, enabling it to process multi-dimensional data inputs and thus obtain high-precision prediction results, namely, the traffic prediction value at the target time. Specifically, the traffic prediction value at the target time can be calculated using the following formula (1): (1); in, Indicating a view on the future The predicted flow rate at a given time, i.e., the predicted flow rate at the target time. Indicates the current time Traffic data; Indicates the current time Traffic data from the previous moment; Indicates the current time Indicators of attack behavior, such as request frequency and abnormal request types; Indicates the current time The attack behavior indicators of the previous moment; This represents the time series forecasting function, i.e., the time series forecasting model; Indicates the first A deep learning model, namely an attack behavior prediction model; Indicates the first The weights of a deep learning model can represent the contribution of that deep learning model to the overall prediction. This represents the noise or error term in the prediction model; and These represent the time window lengths for traffic and attack behavior, respectively. This represents the total number of deep learning models involved in the prediction.
[0031] Here, the prediction model in this application embodiment is a composite model. This composite model not only combines classical time series analysis, but also captures complex nonlinear patterns through deep learning models. It can identify traffic peaks and potential threats in advance, providing a reliable prediction basis for traffic scheduling.
[0032] In practical applications, the traffic scheduler 11 adopts an improved multi-objective optimization algorithm during the traffic allocation process. This algorithm not only considers the availability of line resources, node load and security priority, but also introduces factors such as historical performance weight and real-time performance periodic fluctuations to more accurately adapt to the dynamic changes of the system.
[0033] Based on this, in one embodiment, the traffic scheduler 11 is specifically used for: Based on the first attribute information of each protection node, the traffic allocation ratio of each protection node is determined; the first attribute information includes one or more of the following: line resource availability; node load; security priority; historical performance weight; real-time performance periodic fluctuations; Based on the traffic allocation ratio of each protection node, the traffic prediction value is allocated to different protection nodes.
[0034] Here, line resource availability can be, for example, bandwidth availability. Node load can be, for example, a central processing unit (CPU) or memory. Historical performance can be understood as the performance and reliability of the protection node in the past. Real-time performance periodic fluctuations can be, for example, short-term fluctuations in CPU temperature or response time.
[0035] Specifically, the flow allocation ratio of each protection node can be calculated using the following formula (2): (2); in, Indicates time Time allocated to the The traffic proportion of the WAF node, i.e., the number of nodes. Traffic allocation ratio for each WAF node; Indicates the first WAF nodes in time The availability of line resources at any given time; Indicates the first WAF nodes in time The node load at any given time, such as the inverse ratio of CPU or memory utilization, can be used as an inverse ratio. express; Indicates the first WAF nodes in time Security priorities at all times; and These represent the adjustment parameters related to system load fluctuations, used to simulate the impact of periodic fluctuations; This indicates phase offset, reflecting whether the load is synchronous or asynchronous between WAF nodes; Indicates the first Historical performance weighting coefficients of each WAF node; This represents the adjustment coefficient, used to balance the impact of real-time performance fluctuations; Indicates the first WAF nodes in time Real-time performance fluctuates periodically at any given moment; This indicates the total number of WAF nodes.
[0036] Through the above formula (2), the traffic scheduler 11 can not only dynamically respond to the current node load and line resource status, but also make more forward-looking traffic allocation based on historical data (i.e., historical performance) and periodic changes (i.e., real-time performance periodic fluctuations), avoiding single-point overload or performance bottlenecks.
[0037] In one embodiment, the traffic scheduler 11 is further configured to: Based on the second attribute information of each protection node, the routing priority of each protection node is determined; the second attribute information includes one or more of the following: security assessment score; the intensity of attacks it has withstood; historical routing performance; and health status. Based on the routing priority of each protection node, the traffic prediction value is routed to the corresponding protection node.
[0038] Here, the routing priority of the protection node is used to determine whether the protection node receives more traffic. During the traffic allocation process, the traffic scheduler 11 dynamically applies security policies to ensure the overall security and reliability of the system. The security policy application can calculate the routing priority based on a multi-weighted formula, and based on the routing priority of each protection node, ensure that traffic is preferentially routed to safe, reliable and healthy protection nodes, thereby reducing potential security risks and the possibility of system crashes. Specifically, the routing priority of each protection node can be calculated using the following formula (3): (3); in, Indicates time Time of the first Routing priority of each WAF node; Indicates weights based on security policies; Indicates the weight based on real-time attack intelligence; Indicates time Time of the first The security assessment score of each WAF node can be generated based on the current security situation and real-time attack intelligence. Indicates time Time of the first The intensity of the attack behavior currently detected by each WAF node can be used to reflect the attack pressure suffered by that WAF node in real time; Weighting coefficients representing historical routing performance; and This represents the adjustment parameter in logistic regression; Indicates the first Cumulative routing performance of each WAF node over a period of time; This represents the control factor, used to adjust newly introduced parameters. Impact on routing priority; Indicates the first Real-time health metrics for each WAF node, such as node response time, CPU temperature, or other health monitoring data.
[0039] As can be seen, through the above weighted formula (3), the traffic scheduler 11 can comprehensively consider the real-time security situation, historical routing performance and node health, and ensure that traffic is preferentially routed to safe, reliable and healthy WAF nodes, thereby reducing potential security risks and the possibility of system crashes.
[0040] Here, the protection management node 12 is a key component of the network application protection system. It is responsible for real-time detection and filtering of potential attack behaviors in access requests, and dynamically adjusting the source protection strategy of the protection node according to different attack types, attack frequencies and attack severity to ensure the security and effectiveness of the system.
[0041] Here, the protection management node 12 identifies potential attack behaviors by analyzing the content and behavior of access requests (such as web requests) in real time, and filters the identified potential attack behaviors according to predefined protection policies (i.e., source protection policies). Specifically, it first performs deep analysis on the access requests to extract key features, then uses a pattern matching algorithm to match key features and detect potential attack behaviors in the access requests; finally, it combines historical behavior data of access requests and uses a rule-based engine or machine learning model to analyze abnormal behavior of access requests, such as detecting duplicate requests, sudden increases in access volume, or abnormal parameter value changes.
[0042] It should be noted that before performing key feature matching through the pattern matching algorithm, the protection management node 12 can also perform normalization processing on the extracted key features to remove irrelevant information and standardize the data format, and then perform key feature matching after normalization through the pattern matching algorithm.
[0043] In one embodiment, the protection management node 12 is further configured to: A risk assessment is performed on the detected potential attack behaviors to obtain an attack risk value; Based on the attack risk value, determine the processing method for the access request.
[0044] Here, in one embodiment, the step of assessing the risk of the detected potential attack behavior to obtain an attack risk value includes: assessing the risk of the detected potential attack behavior based on the attack type, attack severity, and historical behavior records to obtain an attack risk value.
[0045] Specifically, the attack risk value can be calculated using the following formula (4): (4); in, Indicates the attack risk value; Indicates the first Risk score for each attack characteristic; This represents the weight of the corresponding attack characteristics, which can be dynamically adjusted according to the attack type and strategy. Indicates the first Risk score of each behavioral analysis result; This indicates the weight of the corresponding behavior analysis result; This represents the total number of attack signatures; This represents the total number of behavioral analysis results.
[0046] Here, after the protection management node 12 calculates the attack risk value using the above formula (4), it can determine the processing method for the access request based on the attack risk value. The processing method includes one of the following: allow access; log; block the request; enhance protection. Specifically, if the calculated attack risk value is low, the request is allowed to pass and forwarded to the target web server; if the calculated attack risk value is medium, only logs are recorded for subsequent analysis; if the calculated attack risk value is high, the request is immediately blocked and an error page is returned or redirected to a secure page; if the calculated attack risk value remains high, the protection measures are dynamically enhanced.
[0047] Here, the protection management node 12 supports multi-level protection policies, which can automatically adjust the protection level according to the severity of the attack. The protection level includes one or more of the following levels: low protection; medium protection; high protection; and emergency protection. Among them, low protection: only logs and warnings are recorded, and no further action is required; medium protection: logs are recorded and minor interventions are made, such as reducing the request rate or prompting the user; high protection: take mandatory measures, such as blocking requests, disabling users, or enabling fully automated public Turing test (CAPTCHA) to distinguish between computers and humans; emergency protection: in extreme cases (such as major attacks), emergency policies are automatically activated, which may include site-wide access restrictions or traffic scrubbing.
[0048] In one embodiment, the system further includes: a distributed collaborative defense module; wherein, The distributed collaborative defense module is used to establish a secure communication channel between each protection node and to transmit attack intelligence information and the target protection strategy through the secure communication channel.
[0049] Here, the distributed collaborative defense module can also be called a distributed collaborative defense system, and the secure communication channel can also be called a secure communication channel. The distributed collaborative defense module is used to establish a secure communication channel between each protection node through the Transport Layer Security (TLS) protocol. This secure communication channel is an encrypted communication channel, which ensures that all data transmitted between protection nodes, including attack intelligence information and protection strategies, is secure and will not be eavesdropped on or tampered with.
[0050] Here, strong authentication mechanisms (e.g., certificate-based two-way authentication) are used between the protection nodes to verify identities, ensuring that only authorized protection nodes can participate in communication and intelligence sharing.
[0051] Here, a certain protection node will collect the attack intelligence information detected locally in real time, and distribute this attack intelligence information to other nodes through the distributed collaborative defense module. The attack intelligence information includes one or more of the following: the Internet Protocol (IP) address of the attack source; the attack type; the attack frequency; and the attack characteristics.
[0052] It should be noted that the shared attack intelligence information can be marked according to priority, and critical attack intelligence information (such as attack intelligence information on new types of attacks or widely spread attacks) will be distributed first.
[0053] Here, when a new type of attack is detected and a new protection strategy (i.e., the target protection strategy) is formulated, the new protection strategy will be synchronized to all other nodes through the distributed collaborative defense module. In this way, the entire system can respond to the new type of attack in a unified manner in a short period of time.
[0054] Here, within a specific geographical area, if some WAF nodes suffer a large-scale attack, the distributed collaborative defense module will coordinate with other nodes within that area to share the defense burden. For example, it can alleviate the overload risk of individual nodes through load balancing and traffic diversion.
[0055] In practical applications, the distributed collaborative defense module can also be used for cross-node abnormal behavior analysis, enabling a rapid response to new types of attacks.
[0056] Based on this, in one embodiment, the distributed collaborative defense module is further configured to: Attack intelligence information from multiple protection nodes is integrated to obtain integrated attack intelligence information; Anomaly analysis is performed on the integrated attack intelligence information to obtain cross-node anomaly analysis results; Based on the cross-node abnormal behavior analysis results, the defense order of each protection node is adjusted.
[0057] Here, the distributed collaborative defense module integrates attack intelligence information from multiple protection nodes, performs cross-node abnormal behavior analysis on the integrated attack intelligence information, identifies widely distributed complex attack behaviors (such as distributed denial of service (DDoS) attacks), and then, based on the cross-node abnormal behavior analysis results, the distributed collaborative defense module can adjust the defense order of each protection node so that it prioritizes defense against the most threatening attack behaviors at present.
[0058] In one embodiment, the system further includes a centralized management platform; wherein, The centralized management platform is used to monitor the operating status, attack detection, and traffic distribution of each protection node; based on the operating status, attack detection, and traffic distribution of each protection node, it generates a security report; the security report is used by the enterprise entity to meet various regulatory requirements.
[0059] In one embodiment, the centralized management platform is further used for: Obtain security event log data from all protected nodes; generate a compliance report based on the security event log data.
[0060] Here, all protection nodes can transmit their security event log data to the centralized management platform via the syslog protocol (a standard protocol for transmitting log information over a network, essentially the system's logging protocol), where it is stored in the ClickHouse database (a high-performance columnar database). This security event log data includes attack detection records, the implementation status of protective measures, and abnormal traffic analysis. Based on the collected security event log data, compliance reports that meet regulatory requirements are generated, allowing administrators to view this log data at any time, understand the overall network security status of the system, and adjust protection strategies as needed.
[0061] This application provides a network application protection method, which is applied to a network application protection device. Figure 2 This is a flowchart illustrating the network application protection method according to an embodiment of this application, as shown below. Figure 2 As shown, the method includes: Step 201: Receive the access request for the network application sent by the client.
[0062] Here, the network application can be a web application. When the user corresponding to the client accesses a web application, the client sends an access request for that web application to the network application protection device.
[0063] Step 202: Perform traffic analysis on the access request using a prediction model to obtain the traffic prediction value at the target time; distribute the traffic prediction value to different protection nodes.
[0064] In practical applications, in order to accurately predict traffic peaks and attack behaviors, network application protection devices rely on complex prediction models, which are machine learning analysis models, or simply machine learning models.
[0065] Based on this, in one embodiment, the prediction model includes a time series prediction model and an attack behavior prediction model; the step of performing traffic analysis on the access request using the prediction model to obtain the traffic prediction value at the target time includes: The traffic data related to the access request is input into the time series prediction model to obtain the time series data of the traffic; The attack behavior indicators related to the access request are input into the attack behavior prediction model to obtain the attack behavior prediction value; Based on the time series data of the traffic and the predicted value of the attack behavior, the predicted value of the traffic at the target time is determined.
[0066] Here, traffic data related to access requests may include the current time when the access request was sent. Traffic data, and the current moment Traffic data from one or several moments prior. A time series prediction model, also known as a time series prediction function, analyzes traffic data related to access requests using this function to obtain time series data of the traffic. In other words, the time series prediction function captures the time trend and pattern of the traffic (corresponding to the time series data of the traffic). Attack behavior indicators related to access requests can be seen as the current moment the access request was sent. Attack behavior indicators can include, for example, request frequency and abnormal request types. Attack behavior prediction models can be deep learning models.
[0067] In one embodiment, after obtaining the time-series traffic data and attack behavior predictions, the network application protection device can also consider the noise of the prediction model. Thus, by combining the time-series traffic data, attack behavior predictions, and prediction model noise, the traffic prediction value for the target time is determined. The noise of the prediction model can also be referred to as the error term of the prediction model, used to handle unpredictable random fluctuations.
[0068] As can be seen, the prediction model in this application combines time series analysis and deep learning techniques, enabling it to process multi-dimensional data inputs and thus obtain high-precision prediction results, namely, the traffic prediction value at the target time. Specifically, the traffic prediction value at the target time can be calculated using the following formula (1): (1); in, Indicating a view on the future The predicted flow rate at a given time, i.e., the predicted flow rate at the target time. Indicates the current time Traffic data; Indicates the current time Traffic data from the previous moment; Indicates the current time Indicators of attack behavior, such as request frequency and abnormal request types; Indicates the current time The attack behavior indicators of the previous moment; This represents the time series forecasting function, i.e., the time series forecasting model; Indicates the first A deep learning model, namely an attack behavior prediction model; Indicates the first The weights of a deep learning model can represent the contribution of that deep learning model to the overall prediction. This represents the noise or error term in the prediction model; and These represent the time window lengths for traffic and attack behavior, respectively. This represents the total number of deep learning models involved in the prediction.
[0069] Here, the prediction model in this application embodiment is a composite model. This composite model not only combines classical time series analysis, but also captures complex nonlinear patterns through deep learning models. It can identify traffic peaks and potential threats in advance, providing a reliable prediction basis for traffic scheduling.
[0070] In practical applications, network application protection devices employ an improved multi-objective optimization algorithm during traffic allocation. This algorithm not only considers line resource availability, node load, and security priority, but also incorporates factors such as historical performance weights and real-time performance periodic fluctuations to more accurately adapt to the dynamic changes of the system.
[0071] Based on this, in one embodiment, the step of allocating the traffic prediction value to different protection nodes includes: Based on the first attribute information of each protection node, the traffic allocation ratio of each protection node is determined; the first attribute information includes one or more of the following: line resource availability; node load; security priority; historical performance weight; real-time performance periodic fluctuations; Based on the traffic allocation ratio of each protection node, the traffic prediction value is allocated to different protection nodes.
[0072] Here, line resource availability can be, for example, bandwidth availability. Node load can be, for example, CPU or memory. Historical performance can be understood as the performance and reliability of the protection node in the past. Real-time performance periodic fluctuations can be, for example, short-term fluctuations in CPU temperature or response time.
[0073] Specifically, the flow allocation ratio of each protection node can be calculated using the following formula (2): (2); in, Indicates time Time allocated to the The traffic proportion of the WAF node, i.e., the number of nodes. Traffic allocation ratio for each WAF node; Indicates the first WAF nodes in time The availability of line resources at any given time; Indicates the first WAF nodes in time The node load at any given time, such as the inverse ratio of CPU or memory utilization, can be used as an inverse ratio. express; Indicates the first WAF nodes in time Security priorities at all times; and These represent the adjustment parameters related to system load fluctuations, used to simulate the impact of periodic fluctuations; This indicates phase offset, reflecting whether the load is synchronous or asynchronous between WAF nodes; Indicates the first Historical performance weighting coefficients of each WAF node; This represents the adjustment coefficient, used to balance the impact of real-time performance fluctuations; Indicates the first WAF nodes in time Real-time performance fluctuates periodically at any given moment; This indicates the total number of WAF nodes.
[0074] Through the above formula (2), the network application protection device can not only dynamically respond to the current node load and line resource status, but also make more forward-looking traffic allocation based on historical data (i.e., historical performance) and periodic changes (i.e., real-time performance periodic fluctuations), avoiding single-point overload or performance bottlenecks.
[0075] In one embodiment, the method further includes: Based on the second attribute information of each protection node, the routing priority of each protection node is determined; the second attribute information includes one or more of the following: security assessment score; the intensity of attacks it has withstood; historical routing performance; and health status. Based on the routing priority of each protection node, the traffic prediction value is routed to the corresponding protection node.
[0076] Here, the routing priority of a protection node determines whether that node receives more traffic. During traffic allocation, the network application protection device dynamically applies security policies to ensure the overall security and reliability of the system. Security policy application can calculate routing priorities based on a multi-weighted formula, and based on the routing priorities of each protection node, ensure that traffic is preferentially routed to safe, reliable, and healthy protection nodes, thereby reducing potential security risks and the possibility of system crashes.
[0077] Specifically, the routing priority of each protection node can be calculated using the following formula (3): (3); in, Indicates time Time of the first Routing priority of each WAF node; Indicates weights based on security policies; Indicates the weight based on real-time attack intelligence; Indicates time Time of the first The security assessment score of each WAF node can be generated based on the current security situation and real-time attack intelligence. Indicates time Time of the first The intensity of the attack behavior currently detected by each WAF node can be used to reflect the attack pressure suffered by that WAF node in real time; Weighting coefficients representing historical routing performance; and This represents the adjustment parameter in logistic regression; Indicates the first Cumulative routing performance of each WAF node over a period of time; This represents the control factor, used to adjust newly introduced parameters. Impact on routing priority; Indicates the first Real-time health metrics for each WAF node, such as node response time, CPU temperature, or other health monitoring data.
[0078] As can be seen, through the above weighted formula (3), the network application protection device can comprehensively consider the real-time security situation, historical routing performance and node health, and ensure that traffic is preferentially routed to safe, reliable and healthy WAF nodes, thereby reducing potential security risks and the possibility of system crashes.
[0079] Step 203: Detect potential attack behaviors in the access request, and adjust the source protection strategy based on the attack type, attack frequency and attack severity of the potential attack behaviors to obtain the target protection strategy.
[0080] Here, network application protection devices analyze the content and behavior of access requests (such as web requests) in real time to identify potential attack behaviors and filter them according to predefined protection policies (i.e., source protection policies). Specifically, the access requests are first deeply analyzed to extract key features. Then, a pattern matching algorithm is used to match these key features and detect potential attack behaviors within the access requests. Finally, combined with historical behavior data of the access requests, a rule-based engine or machine learning model is used to analyze abnormal behavior, such as detecting duplicate requests, sudden increases in access volume, or abnormal parameter value changes.
[0081] It should be noted that before performing key feature matching through pattern matching algorithms, network application protection devices can also perform normalization processing on the extracted key features to remove irrelevant information and standardize the data format, and then perform key feature matching after normalization through pattern matching algorithms.
[0082] In one embodiment, the method further includes: A risk assessment is performed on the detected potential attack behaviors to obtain an attack risk value; Based on the attack risk value, determine the processing method for the access request.
[0083] Here, in one embodiment, the step of assessing the risk of the detected potential attack behavior to obtain an attack risk value includes: assessing the risk of the detected potential attack behavior based on the attack type, attack severity, and historical behavior records to obtain an attack risk value.
[0084] Specifically, the attack risk value can be calculated using the following formula (4): (4); in, Indicates the attack risk value; Indicates the first Risk score for each attack characteristic; This represents the weight of the corresponding attack characteristics, which can be dynamically adjusted according to the attack type and strategy. Indicates the first Risk score of each behavioral analysis result; This indicates the weight of the corresponding behavior analysis result; This represents the total number of attack signatures; This represents the total number of behavioral analysis results.
[0085] Here, after calculating the attack risk value using the above formula (4), the network application protection device can determine the processing method for the access request based on the attack risk value. The processing method includes one of the following: allow access; log; block the request; enhance protection. Specifically, if the calculated attack risk value is low, the request is allowed to pass and forwarded to the target web server; if the calculated attack risk value is medium, only logs are recorded for subsequent analysis; if the calculated attack risk value is high, the request is immediately blocked and an error page is returned or redirected to a secure page; if the calculated attack risk value remains high, the protection measures are dynamically enhanced.
[0086] In one embodiment, the method further includes: A secure communication channel is established between each protection node, and attack intelligence information and the target protection strategy are transmitted through the secure communication channel.
[0087] Here, a secure communication channel can also be called a secure communication channel. Network application protection devices can establish secure communication channels between various protection nodes through the TLS protocol. This secure communication channel is an encrypted communication channel, which ensures that all data transmitted between protection nodes, including attack intelligence information and protection strategies, is secure and will not be eavesdropped on or tampered with.
[0088] In this embodiment of the application, the attack intelligence information includes one or more of the following: attack source IP address; attack type; attack frequency; attack characteristics.
[0089] In practical applications, network application protection devices can also perform cross-node abnormal behavior analysis, enabling rapid response to new types of attacks.
[0090] Based on this, in one embodiment, the method further includes: Attack intelligence information from multiple protection nodes is integrated to obtain integrated attack intelligence information; Anomaly analysis is performed on the integrated attack intelligence information to obtain cross-node anomaly analysis results; Based on the cross-node abnormal behavior analysis results, the defense order of each protection node is adjusted.
[0091] Here, the network application protection device integrates attack intelligence information from multiple protection nodes, performs cross-node abnormal behavior analysis on the integrated attack intelligence information, identifies widely distributed complex attack behaviors (such as DDoS attacks), and then, based on the cross-node abnormal behavior analysis results, the distributed collaborative defense module can adjust the defense order of each protection node so that it prioritizes defense against the most threatening attack behaviors at present.
[0092] In one embodiment, the method further includes: Monitor the operational status, attack detection, and traffic distribution of each protection node; Based on the operational status, attack detection, and traffic distribution of each protection node, a security report is generated; the security report is used by the enterprise entity to meet various regulatory requirements.
[0093] In one embodiment, the method further includes: Obtain security event log data from all protected nodes; A compliance report is generated based on the security event log data.
[0094] Here, all protection nodes can transmit their security event log data to the centralized management platform via the syslog protocol, where it is stored in the ClickHouse database. This security event log data includes attack detection records, protection measure implementation status, and abnormal traffic analysis. Based on the collected security event log data, compliance reports that meet regulatory requirements are generated, allowing administrators to view this log data at any time, understand the overall network security status of the system, and adjust protection strategies as needed.
[0095] The present application will be described below with reference to application examples.
[0096] To address the single point of failure, performance bottlenecks, local performance deficiencies, and security issues existing in related technologies, this application proposes a distributed cloud WAF system based on intelligent scheduling and adaptive protection. This system can resolve the single point of failure, performance bottlenecks, local performance deficiencies, and security issues of centralized WAF nodes. Through a distributed architecture, intelligent traffic scheduling, adaptive protection, and collaborative defense mechanisms, it achieves higher availability, performance, and security. Specifically, the technical problems it solves include: Eliminating single points of failure: Through a distributed architecture, multiple adaptive WAF nodes (corresponding to the aforementioned protection management nodes) are distributed in different geographical areas. Even if one node fails, other nodes can continue to provide protection services, ensuring the high availability of the system.
[0097] Improve system performance: The intelligent traffic scheduler (corresponding to the aforementioned traffic scheduler) dynamically allocates traffic based on real-time load and network conditions, avoiding overload of individual nodes, improving the overall processing capacity of the system, reducing latency and enhancing user experience.
[0098] Adapting to complex network environments: Adaptive WAF nodes can autonomously adjust their protection strategies and workloads based on different geographical regions and network conditions, reducing network latency and improving protection efficiency.
[0099] Enhance system security: Through the distributed collaborative defense system (corresponding to the aforementioned distributed collaborative defense module), each WAF node shares attack intelligence in real time and responds collaboratively to new types of attacks, effectively reducing the systemic risk caused by the breach of a single point.
[0100] Figure 3 This is a schematic diagram of the architecture of the network application protection system according to an embodiment of this application, such as... Figure 3 As shown, the system architecture mainly comprises four core components: an intelligent traffic scheduler, adaptive WAF nodes, a distributed collaborative defense system, and a centralized management platform. The system adopts a distributed and cloud-native architecture, possessing elastic scalability. Clients access the intelligent traffic scheduler through the Domain Name System (DNS). The intelligent traffic scheduler connects to the nearest load balancer. Multiple adaptive WAF nodes are distributed across different regions and connected to the web server. Each adaptive WAF node includes an intelligent load balancer (SLB), a web application firewall (i.e., the WAF node), and an adaptive protection module (…). Figure 3 (Components not shown in the image). All WAF nodes in the system are connected via the Internet and coordinated and managed by an intelligent traffic scheduler. The intelligent traffic scheduler can dynamically adjust the traffic allocation of WAF nodes based on information such as traffic load, security policies, and network topology to ensure the system's efficiency and security.
[0101] like Figure 3 As shown, the system comprises four core components, and the functions of each component are as follows: 1. Intelligent Traffic Scheduler The main function of the intelligent traffic scheduler is to handle global traffic scheduling. Its design, based on machine learning models and real-time traffic analysis, dynamically distributes traffic to different WAF nodes. The core design of the intelligent traffic scheduler lies in achieving fine-grained traffic scheduling through complex multi-objective optimization algorithms, machine learning models, and dynamic security policies, ensuring the system's efficiency and security under various load and attack conditions. The specific functions and implementation of the intelligent traffic scheduler are as follows: 1.1 Traffic Allocation The intelligent traffic scheduler employs an improved multi-objective optimization algorithm during traffic allocation. This algorithm not only considers line resources, node load, and security priorities, but also incorporates historical performance weights and real-time performance periodic fluctuations to more accurately adapt to dynamic system changes. The traffic allocation formula is as follows: (2); in, Indicates time Time allocated to the Traffic ratio of each WAF node. Indicates the first WAF nodes in time The availability of line resources (e.g., bandwidth availability) at any given time. Indicates the first WAF nodes in time The current load at any given moment (e.g., an inverse ratio of CPU or memory utilization), using an inverse ratio This is to avoid allocating more traffic to nodes that are already overloaded. Indicates the first WAF nodes in time Security priorities at all times (security priorities are assessed based on real-time security policies and attack intelligence). and These are adjustment parameters related to system load fluctuations, used to simulate the impact of periodic fluctuations (such as day-night flow variations). This indicates phase offset, reflecting whether the load is synchronous or asynchronous between WAF nodes, which helps to balance the load during traffic peaks or attacks. Indicates the first The historical performance weighting coefficients of each WAF node are adjusted based on the node's past performance and reliability to ensure that more stable nodes receive more traffic. This represents the adjustment coefficient, used to balance the impact of real-time performance fluctuations. Indicates the first WAF nodes in time Periodic fluctuations in real-time performance (e.g., short-term fluctuations in CPU temperature or response time). This indicates the total number of WAF nodes.
[0102] This formula enables the intelligent traffic scheduler to not only dynamically respond to the current node load and line resource status, but also to perform more forward-looking traffic allocation based on historical data and periodic changes, avoiding single-point overload or performance bottlenecks.
[0103] 1.2 Machine Learning Analysis To achieve accurate predictions of traffic spikes and attack behavior, the intelligent traffic scheduler relies on a sophisticated machine learning model. This model combines time series analysis and deep learning techniques, enabling it to process multi-dimensional data inputs and produce high-precision predictions. The prediction model is implemented as follows: (1); in, It is about the future Traffic flow forecast for a given moment. Indicates the current time Traffic data. Indicates the current time Indicators of attack behavior, such as request frequency and abnormal request types. It is a classic time series forecasting function that combines autoregression (AR), moving average (MA), and long short-term memory (LSTM) models to capture the time trends and patterns of traffic. It is the first Each deep learning model is specifically designed for feature extraction and prediction of specific attack behaviors. They all perform best under different attack modes, such as DDoS attacks and SQL injection. It is the first The weights of each deep learning model represent its contribution to the overall prediction. The weights are automatically adjusted using a multidimensional gradient descent algorithm to adapt to constantly changing attack patterns. It is the noise or error term in the prediction model, used to handle unpredictable random fluctuations. and These refer to the time window lengths for traffic and attack behavior, respectively. It represents the total number of deep learning models involved in the prediction.
[0104] This composite model not only combines classic time series analysis, but also captures complex nonlinear patterns through deep learning models, enabling it to identify traffic peaks and potential threats in advance, providing a reliable predictive basis for traffic scheduling.
[0105] 1.3 Application of Security Policies During traffic allocation, the intelligent traffic scheduler dynamically applies security policies to ensure the overall security and reliability of the system. The application of security policies is based on the following multi-weighted formula: (3); in, Indicates time Time of the first The routing priority of each WAF node determines whether that node receives more traffic. It is a weight based on security policy, set by the administrator, and can be dynamically adjusted according to actual conditions to adapt to different security needs. It is based on the weight of real-time attack intelligence, which is determined by the severity and frequency of the attack, to ensure that critical nodes are protected first during an attack. It is the first The security assessment score of each WAF node is generated based on the current security situation and real-time attack intelligence. It is time Time of the first The intensity of the attack behavior currently detected by each WAF node reflects the attack pressure suffered by that WAF node in real time. It is a weighting coefficient for historical routing performance, representing the reliability and security of a node over a past period. and It is an adjustment parameter in logistic regression that controls the impact of historical routing data on the current routing priority, preventing the current decision from being excessively influenced by the performance of historical routes. It is the first The cumulative routing performance of each WAF node over a period of time is used to measure the long-term stability of the node. It is a control factor that adjusts newly introduced parameters. Impact on routing priority. It is the first Real-time health metrics for each WAF node, such as node response time, CPU temperature, or other health monitoring data.
[0106] Through this weighted formula, the intelligent traffic scheduler can comprehensively consider real-time security status, historical routing performance, and node health to ensure that traffic is preferentially routed to safe, reliable, and healthy nodes, thereby reducing potential security risks and the possibility of system crashes.
[0107] Through the algorithms described above, the intelligent traffic scheduler can more effectively allocate traffic, accurately predict potential threats, and dynamically adjust security policies under high load and attack conditions, ensuring the efficiency, reliability, and security of the distributed cloud WAF system. These technological innovations not only enhance the system's flexibility and responsiveness but also provide a solid foundation for addressing increasingly complex cyber threats in the future.
[0108] 2. Adaptive WAF Nodes Adaptive WAF nodes are a key component of distributed cloud WAF systems, responsible for real-time detection and filtering of web application attacks, and dynamically adjusting protection strategies based on different attack types and severity to ensure system security and effectiveness. The following are the specific functions and implementation details of adaptive WAF nodes: 2.1 Attack Detection and Filtering Adaptive WAF nodes analyze the content and behavior of web requests in real time to identify potential attack behaviors and filter them according to predefined protection policies. The specific implementation of attack detection and filtering includes the following steps: 1) Request parsing and feature extraction: The adaptive WAF node performs deep parsing on each incoming Hypertext Transfer Protocol (HTTP) request to extract key features such as request method, Uniform Resource Locator (URL), header information, request body, parameters, etc. Then, these key features are normalized to remove irrelevant information and standardize the data format.
[0109] 2) Feature matching and behavior analysis: Feature matching: Using a set of predefined attack signature libraries (such as SQL injection, cross-site scripting attacks, etc.), potential attack behaviors in requests are detected by pattern matching algorithms (such as the Aho-Corasick algorithm).
[0110] Behavioral analysis: Combining historical request behavior data, rule-based engines or machine learning models (such as Support Vector Machine (SVM), Random Forest, etc.) are used to analyze abnormal request behavior. For example, detecting duplicate requests, sudden increases in access volume, or abnormal parameter value changes.
[0111] 3) Risk Assessment and Decision-Making: Conduct risk assessments on detected potential attacks and calculate attack risk values. Risk assessment can be based on multiple dimensions, including attack type, attack severity, reputation of the requesting IP, and historical behavior records. The formula for calculating the attack risk value is as follows: (4); in, It is the first Risk score for each attack characteristic; These are the weights corresponding to the attack characteristics, which are dynamically adjusted based on the attack type and strategy. It is the first Risk scores for behavioral analysis results, such as risk scores for abnormal request frequency, duplicate requests, etc. These are the weights of the corresponding behavioral analysis results.
[0112] 4) Filtering and Response: Based on the calculated attack risk value This determines how to handle the request. The handling methods include: Allow: If the attack risk value is low, allow the request to pass and forward it to the target web server.
[0113] Log the attack: If the attack risk is moderate, only log the attack for later analysis.
[0114] Block requests: If the attack risk is high, immediately block the request and return an error page or redirect to a secure page.
[0115] Enhanced protection: For persistent or high-risk attacks (i.e., attacks with a consistently high risk value), protection measures can be dynamically enhanced, such as enabling stricter rules or temporarily restricting access from certain IP ranges.
[0116] 2.2 Adaptive Protection Adaptive WAF nodes can dynamically adjust their protection strategies based on the detected attack type, frequency, and severity to cope with different attack scenarios. The specific implementation of adaptive protection includes the following aspects: 1) Dynamic Policy Adjustment: The adaptive WAF node has a built-in policy engine that can automatically adjust protection policies based on real-time detection results and historical data. Policy adjustments include: Rule Activation / Disabling: Activate or disable certain protection rules based on the current attack situation. For example, enable rate limiting and IP blocking rules during peak DDoS attack periods.
[0117] Threshold Adjustment: Adjust thresholds such as request rate limits and parameter length limits based on attack frequency and severity. For example, when an SQL injection attack is detected, lower the parameter length limit threshold.
[0118] 2) Attack intelligence sharing and feedback: Adaptive WAF nodes share attack intelligence through a secure channel. When a node detects a new type of attack, it immediately distributes the relevant intelligence to other nodes, enabling the entire system to update its protection strategies synchronously and improve overall protection capabilities.
[0119] 3) Machine Learning and Self-Optimization: Adaptive WAF nodes perform self-optimization through machine learning algorithms (such as deep neural networks and reinforcement learning). By continuously learning attack patterns and protection effectiveness, adaptive WAF nodes can continuously improve their detection and protection capabilities. For example, by analyzing cases of failed attacks, they can automatically optimize protection rules, reducing false positives and false negatives.
[0120] 4) Hierarchical Protection Strategy: The adaptive WAF node supports multi-level protection strategies, automatically adjusting the protection level based on the severity of the attack. Specifically, this includes: Low-level protection: Only logs and warnings are recorded; no further action is required.
[0121] Intermediate protection: Log messages and take minor interventions, such as reducing the request rate or alerting the user.
[0122] Advanced protection: Take enforcement measures such as blocking requests, disabling users, or enabling CAPTCHA authentication.
[0123] Emergency protection: In extreme situations (such as major attacks), emergency policies are automatically activated, which may include restricting access to the entire site or performing traffic scrubbing.
[0124] 2.3 Geographical Distribution and Deployment Adaptive WAF nodes, through geographically distributed deployment, can effectively reduce latency for users and improve protection response efficiency. Specific implementations include: 1) Regional Deployment: Adaptive WAF nodes are deployed in different geographical regions, allowing user requests to be routed to the nearest adaptive WAF node, thereby reducing network latency and improving response speed. Each adaptive WAF node autonomously adjusts its protection strategy according to its geographical region to adapt to local network conditions and user behavior.
[0125] 2) Load balancing and traffic distribution: The intelligent traffic scheduler can dynamically adjust traffic distribution based on real-time network conditions and node load, ensuring that each node can handle an appropriate amount of traffic while operating efficiently.
[0126] 3) Regional Redundancy and Disaster Recovery: Multiple adaptive WAF nodes are deployed in each region to achieve redundancy and disaster recovery. When a node fails or suffers a major attack, traffic will automatically switch to other nodes to ensure service continuity and stability.
[0127] 4) Localized Protection Strategy: Adaptive WAF nodes can deploy localized protection strategies based on specific threat intelligence in their region. For example, if a particular type of attack is frequently detected in a certain area, the adaptive WAF node will enhance corresponding protection measures for that area to prevent the attack from spreading.
[0128] Adaptive WAF nodes, through advanced attack detection and filtering technologies, dynamically adjusted protection strategies, and geographically distributed deployment, can effectively respond to various web application attacks and optimize protection measures according to actual conditions. By applying these technologies, adaptive WAF nodes not only improve system security and reliability but also maintain high responsiveness in changing network environments.
[0129] 3. Distributed collaborative defense system The distributed collaborative defense system is a key component of a distributed cloud WAF system. It is responsible for establishing secure communication channels between various WAF nodes, enabling real-time sharing of attack intelligence and protection strategies, thereby enhancing overall protection capabilities. The following are the specific functions and implementation methods of the distributed collaborative defense system: 3.1 Establishment of secure communication channels Encrypted communication: Establish encrypted communication channels between WAF nodes (e.g., using the TLS protocol to establish encrypted communication channels) to ensure that all data transmitted between nodes, including attack intelligence and protection strategies, is secure and will not be eavesdropped on or tampered with.
[0130] Authentication mechanism: Strong authentication mechanisms (e.g., certificate-based two-way authentication) are used between WAF nodes to verify identities, ensuring that only authorized nodes can participate in communication and intelligence sharing.
[0131] 3.2 Real-time attack intelligence sharing Intelligence gathering and distribution: Each WAF node collects attack intelligence information detected locally in real time and distributes this attack intelligence information to other nodes through a distributed collaborative defense system. Attack intelligence information includes attack source IP, attack type, frequency, and characteristics.
[0132] Intelligence Priority: Shared attack intelligence is marked according to priority. Critical intelligence (such as new types of attacks or widely spread attacks) will be distributed first and immediately trigger the update of protection strategies on each node.
[0133] 3.3 Cooperative Defense Mechanism Synchronized protection strategy: When a node detects a new type of attack and formulates a new protection strategy, this strategy is synchronized to all other nodes through the distributed collaborative defense system. In this way, the entire system can respond to new attacks in a unified manner in a short period of time.
[0134] Regional coordinated defense: Within a specific geographical area, if some nodes suffer a large-scale attack, the distributed collaborative defense system will coordinate with other nodes in the area to share the defense burden. For example, it can alleviate the overload risk of individual nodes through load balancing and traffic diversion.
[0135] 3.4 Collaborative Detection of Abnormal Behaviors Cross-node behavior analysis: By integrating attack intelligence from multiple nodes, the distributed collaborative defense system can perform cross-node abnormal behavior analysis to identify complex attack behaviors that are widely distributed (such as DDoS attacks).
[0136] Adaptive defense adjustment: Based on cross-node analysis results, the distributed collaborative defense system can automatically adjust the protection strategies of each node to prioritize defense against the most threatening attacks.
[0137] 4. Centralized Management Platform The centralized management platform is the core management component of the entire distributed cloud WAF system, responsible for the unified management and configuration of all adaptive WAF nodes, intelligent traffic schedulers, and distributed collaborative defense systems. Its main functions include: 4.1 Unified Management and Configuration Policy distribution: The centralized management platform can distribute global protection policies to each adaptive WAF node and perform personalized configurations according to the needs of different regions, including protection rules, response measures, and log recording settings.
[0138] Monitoring and Reporting: The centralized management platform monitors the operational status, attack detection, and traffic distribution of each adaptive WAF node in real time. Administrators can generate detailed security reports through the centralized management platform to help enterprises meet various regulatory requirements, such as the General Data Protection Regulation (GDPR).
[0139] 4.2 Traffic Audit and Compliance Report Log Collection and Storage: Security event logs from all WAF nodes are transmitted to a centralized management platform via the syslog protocol and stored in the ClickHouse database. These logs include attack detection records, implementation status of protective measures, and abnormal traffic analysis.
[0140] Compliance report generation: Based on the collected log data, the centralized management platform can generate compliance reports that meet regulatory requirements, helping users demonstrate the status of their cybersecurity and the effectiveness of their protective measures.
[0141] Specific implementation method: 1) Protection Configuration Distribution: The centralized management platform distributes protection configurations to each adaptive WAF node and generates a canonical name (CNAME) pointing to the intelligent traffic scheduler for traffic routing. When a user accesses the website, traffic is first routed and distributed by the intelligent traffic scheduler to ensure load balancing and the effective implementation of protection policies.
[0142] 2) Traffic detection and protection: The adaptive WAF node performs real-time detection and analysis of the requests passing through it. If a suspicious or malicious request is detected, the node will immediately implement corresponding defense measures (such as blocking, redirection, etc.); legitimate requests will be forwarded to the web server normally.
[0143] 3) Security Incident Logging and Auditing: All security incidents are sent to the centralized management platform via syslog and stored in the ClickHouse database. Administrators can view these logs at any time to understand the overall security status of the system and adjust protection strategies as needed.
[0144] 4) Intelligence Sharing and Collaborative Defense: The distributed collaborative defense system shares security intelligence among nodes to ensure the entire system can respond quickly to new attacks and prevent their spread. Simultaneously, the system enhances its overall protection capabilities through a cross-node collaborative defense mechanism.
[0145] The main contents of this application include the following aspects: Intelligent Traffic Scheduling Algorithm: The intelligent traffic scheduler in this application employs an improved multi-objective optimization algorithm, a prediction model combining time series analysis and deep learning, and a traffic scheduling method based on dynamic security policies. This intelligent traffic scheduler can not only accurately allocate traffic based on real-time network conditions, but also predict traffic peaks and attack behaviors through machine learning, thereby improving the system's response speed and protection capabilities.
[0146] Adaptive Protection Mechanism: Adaptive WAF nodes possess the ability to dynamically adjust protection strategies. Its core lies in automatically optimizing protection rules and policies based on real-time analysis of attack type, frequency, and severity. This mechanism not only includes the detection and filtering of attack behaviors but also continuously improves protection efficiency through machine learning and self-optimization mechanisms.
[0147] Distributed Collaborative Defense System: This system establishes secure communication channels between various WAF nodes, enabling real-time attack intelligence sharing and collaborative defense mechanisms. Through cross-node anomaly behavior analysis and synchronized protection strategies, the system can respond quickly to new types of attacks and reduce the risk of overload on individual nodes through regional defense linkages.
[0148] Unified Management and Configuration of the Centralized Management Platform: The centralized management platform is responsible for the unified management and configuration of the entire distributed cloud WAF system, particularly the distribution of protection policies, traffic auditing, and the generation of compliance reports. Through centralized log management and real-time monitoring, the centralized management platform ensures efficient collaborative operation of all system components and helps users meet various regulatory requirements.
[0149] Compared with the solutions of related technologies, the solution of this application has the following advantages: 1) Enhanced security: Because distributed cloud WAFs can run on multiple nodes, they are better able to withstand large-scale attacks such as DDoS attacks. Furthermore, global traffic scheduling can distribute traffic across different nodes, thereby reducing the risk of a single node being attacked.
[0150] 2) Greater flexibility and adaptability: Through intelligent traffic scheduling algorithms and adaptive protection mechanisms, this application can dynamically adjust the system's traffic allocation and protection strategies based on real-time network conditions and attack behaviors. Compared to traditional centralized WAF systems, this application can more flexibly cope with changing network environments and complex attack scenarios.
[0151] 3) High availability thanks to the distributed architecture: This application adopts a distributed cloud architecture, with multiple WAF nodes distributed in different geographical locations, avoiding the single point of failure problem of centralized systems. The distributed collaborative defense system ensures that each node can share attack intelligence in real time, quickly respond to new attacks, and improve the overall protection capability of the system.
[0152] 4) Lower cost and higher efficiency: Since a distributed cloud WAF can run on multiple nodes, it can better utilize resources, thereby reducing costs. At the same time, global traffic scheduling can be performed according to actual conditions, thereby improving the efficiency of the entire system.
[0153] 5) Accurate prediction and optimization based on machine learning: The intelligent traffic scheduler and adaptive WAF node in this application can accurately predict traffic peaks and attack behaviors by combining time series analysis and deep learning technology, and continuously improve the protection effect through self-optimization mechanism. This enables the system to protect itself more proactively and effectively when facing complex and ever-changing attacks.
[0154] 6) Enhanced Management and Compliance Support: The centralized management platform makes system management more efficient through unified management and configuration. Centralized log management, traffic auditing, and compliance reporting functions help enterprises meet various regulatory requirements and provide comprehensive monitoring of the security of the entire system.
[0155] To implement the network application protection method of this application embodiment, this application embodiment also provides a network application protection device. Figure 4 This is a schematic diagram of the composition structure of the network application protection device according to an embodiment of this application, as shown below. Figure 4 As shown, the device includes: The receiving unit 41 is used to receive access requests for network applications sent by the client; The first analysis unit 42 is used to perform traffic analysis on the access request through a prediction model to obtain the traffic prediction value at the target time. Allocation unit 43 is used to allocate the traffic prediction value to different protection nodes; Detection unit 44 is used to detect potential attack behaviors in the access request; The first adjustment unit 45 is used to adjust the source protection strategy based on the attack type, attack frequency and attack severity of the potential attack behavior to obtain the target protection strategy.
[0156] In one embodiment, the prediction model includes a time series prediction model and an attack behavior prediction model; the first analysis unit 42 is specifically used for: The traffic data related to the access request is input into the time series prediction model to obtain the time series data of the traffic; The attack behavior indicators related to the access request are input into the attack behavior prediction model to obtain the attack behavior prediction value; Based on the time series data of the traffic and the predicted value of the attack behavior, the predicted value of the traffic at the target time is determined.
[0157] In one embodiment, the allocation unit 43 is specifically used for: Based on the first attribute information of each protection node, the traffic allocation ratio of each protection node is determined; the first attribute information includes one or more of the following: line resource availability; node load; security priority; historical performance weight; real-time performance periodic fluctuations; Based on the traffic allocation ratio of each protection node, the traffic prediction value is allocated to different protection nodes.
[0158] In one embodiment, the device further includes: a first determining unit and a control unit; wherein, The first determining unit is used to determine the routing priority of each protection node based on the second attribute information of each protection node; the second attribute information includes one or more of the following: security assessment score; the intensity of the attack behavior it has withstood; historical routing performance; and health status. The control unit is used to control the routing of the traffic prediction value to the corresponding protection node based on the routing priority of each protection node.
[0159] In one embodiment, the apparatus further includes: an evaluation unit and a second determination unit; wherein, The evaluation unit is used to perform a risk assessment on the detected potential attack behavior and obtain an attack risk value; The second determining unit is used to determine the processing method for the access request based on the attack risk value.
[0160] In one embodiment, the apparatus further includes: a channel establishment unit and a transmission unit; wherein, The channel establishment unit is used to establish a secure communication channel between each protection node; The transmission unit is used to transmit attack intelligence information and target protection strategies through the secure communication channel.
[0161] In one embodiment, the device further includes: an integration unit, a second analysis unit, and a second adjustment unit; wherein, The integration unit is used to integrate attack intelligence information from multiple protection nodes to obtain integrated attack intelligence information. The second analysis unit is used to perform abnormal behavior analysis on the integrated attack intelligence information to obtain cross-node abnormal behavior analysis results; The second adjustment unit is used to adjust the defense order of each protection node based on the cross-node abnormal behavior analysis results.
[0162] In practical applications, the receiving unit 41 can be implemented by the communication interface in the network application protection device; the first analysis unit 42, the allocation unit 43, the detection unit 44 and the first adjustment unit 45 can be implemented by the processor in the network application protection device.
[0163] It should be noted that the network application protection device provided in the above embodiments is only illustrated by the division of the above program modules when performing network application protection. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the network application protection device and the network application protection method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the network application protection method embodiments, which will not be repeated here.
[0164] Based on the hardware implementation of the above program modules, and in order to implement the network application protection method of this application embodiment, this application embodiment also provides a network application protection device. Figure 5 This is a schematic diagram of the hardware composition structure of the network application protection device according to an embodiment of this application, such as... Figure 5 As shown, the network application protection device 50 includes: The communication interface 51 enables information exchange with other devices; The processor 52 is connected to the communication interface 51 to enable information interaction with other devices. When running a computer program, it executes the network application protection method provided above, and the computer program is stored in the memory 53.
[0165] It should be noted that the specific processing procedures of communication interface 51 and processor 52 can be understood by referring to the above-mentioned network application protection methods.
[0166] Of course, in practical applications, the various components in the network application protection device 50 are coupled together through the bus system 54. It can be understood that the bus system 54 is used to implement communication between these components. In addition to the data bus, the bus system 54 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 5 The general labeled all buses as Bus System 54.
[0167] The memory 53 in this embodiment is used to store various types of data to support the operation of the network application protection device 50. Examples of such data include any computer programs used to operate on the network application protection device 50.
[0168] The network application protection method disclosed in the above embodiments of this application can be applied to the processor 52, or implemented by the processor 52. The processor 52 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above network application protection method can be completed by the integrated logic circuit of the hardware in the processor 52 or by instructions in the form of software. The processor 52 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 52 can implement or execute the network application protection methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the network application protection method disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in the memory 53. The processor 52 reads the information in the memory 53 and combines its hardware to complete the steps of the aforementioned network application protection method.
[0169] In an exemplary embodiment, the network application protection device 50 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned network application protection method.
[0170] It is understood that the memory 53 in this embodiment can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 53 described in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0171] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 53 storing a computer program. This computer program can be executed by the processor 52 in the network application protection device 50 to complete the steps of the network application protection method described in the aforementioned embodiment. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
[0172] In an exemplary embodiment, this application also provides a computer program product, including a computer program that can be executed by a processor 52 in a network application protection device 50 to complete the steps of the network application protection method described in the foregoing embodiments of this application.
[0173] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0174] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0175] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network application protection system, characterized in that, The system includes: a traffic scheduler and a protection management node, wherein the protection management node contains one or more protection nodes; The traffic scheduler is used to receive access requests for network applications sent by clients, perform traffic analysis on the access requests using a prediction model to obtain traffic prediction values at the target time, and distribute the traffic prediction values to different protection nodes. The protection management node is used to detect potential attack behaviors in the access request, and adjust the source protection strategy based on the attack type, attack frequency and attack severity of the potential attack behaviors to obtain the target protection strategy.
2. The system according to claim 1, characterized in that, The prediction model includes a time series prediction model and an attack behavior prediction model; The traffic scheduler is specifically used for: The traffic data related to the access request is input into the time series prediction model to obtain the time series data of the traffic; The attack behavior indicators related to the access request are input into the attack behavior prediction model to obtain the attack behavior prediction value; Based on the time series data of the traffic and the predicted value of the attack behavior, the predicted value of the traffic at the target time is determined.
3. The system according to claim 1, characterized in that, The traffic scheduler is specifically used for: Based on the first attribute information of each protection node, the traffic allocation ratio of each protection node is determined; the first attribute information includes one or more of the following: line resource availability; node load; security priority; historical performance weight. Real-time performance fluctuates periodically; Based on the traffic allocation ratio of each protection node, the traffic prediction value is allocated to different protection nodes.
4. The system according to claim 1, characterized in that, The traffic scheduler is also used for: Based on the second attribute information of each protection node, the routing priority of each protection node is determined; the second attribute information includes one or more of the following: security assessment score; the intensity of attacks it has withstood; historical routing performance; and health status. Based on the routing priority of each protection node, the traffic prediction value is routed to the corresponding protection node.
5. The system according to claim 1, characterized in that, The protection management node is also used for: A risk assessment is performed on the detected potential attack behaviors to obtain an attack risk value; Based on the attack risk value, determine the processing method for the access request.
6. The system according to claim 1, characterized in that, The system also includes: a distributed collaborative defense module; wherein... The distributed collaborative defense module is used to establish a secure communication channel between each protection node and to transmit attack intelligence information and the target protection strategy through the secure communication channel.
7. The system according to claim 6, characterized in that, The distributed collaborative defense module is also used for: Attack intelligence information from multiple protection nodes is integrated to obtain integrated attack intelligence information; Anomaly analysis is performed on the integrated attack intelligence information to obtain cross-node anomaly analysis results; Based on the cross-node abnormal behavior analysis results, the defense order of each protection node is adjusted.
8. A method for protecting network applications, characterized in that, The method includes: Receive access requests for network applications sent by clients; The access requests are analyzed using a predictive model to obtain the predicted traffic value at the target time; the predicted traffic value is then distributed to different protection nodes. The system detects potential attack behaviors in the access requests and adjusts the source protection strategy based on the attack type, frequency, and severity of the potential attack behaviors to obtain the target protection strategy.
9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 8.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method of claim 8.
Citation Information
Patent Citations
Distributed Web application firewall system based on cloud platform
CN117336096A
Network traffic optimization scheduling method based on deep reinforcement learning and suitable for periodic traffic characteristics
CN120090989A
Network security protection method, apparatus, and system
WO2022088405A1