A network access behavior risk analysis method and system

CN122824477APending Publication Date: 2026-09-25SHANGHAI TECHN INST OF ELECTRONICS & INFORMATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611131079.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-29
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

而基于个人基线的用户画像方案,不仅部署成本高昂、需要长达数周的学习周期,更致命的是,一旦攻击者通过社工或凭证窃取接管了合法账户,其初始操作会被基线默认为用户本人行为,从而产生灾难性的漏报

Benefits of technology

[0052]与现有技术相比,本发明的有益效果是:本发明通过捕获会话请求的时间戳序列并提取请求间隔的节律复杂度特征与突发度特征进行联合判定,将风险检测依据从可伪造的请求内容与可规避的频次阈值,转变为操作者无法伪装的底层人机交互节律差异;无需用户历史行为学习周期即可在会话建立初期即时生效,从物理时间维度区分人类操作与自动化脚本,有效解决合法账户被接管后的慢速数据窃取难以发现的问题,同时避免对正常用户密集操作的误拦,实现安全防护与业务体验的平衡。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824477A_ABST
    Figure CN122824477A_ABST
Patent Text Reader

Abstract

The application discloses a network access behavior risk analysis method and belongs to the network security field, and has the beneficial effects that the application jointly determines rhythm complexity features and burstiness features of request intervals by capturing a timestamp sequence of a session request, and changes risk detection basis from a request content that can be forged and a frequency threshold that can be evaded to a bottom human-computer interaction rhythm difference that cannot be disguised by an operator, so that the application can take effect immediately at the initial stage of session establishment without a user historical behavior learning period, distinguishes human operation from an automated script from a physical time dimension, and effectively solves the problem that slow data stealing after a legal account is taken over is difficult to find.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security, and in particular relates to a method and system for analyzing network access behavior risks. Background Technology

[0002] Currently, the mainstream technical approaches for automated risk behavior detection after login to business systems mainly rely on three types of methods. First, traffic analysis based on statistical thresholds: by setting an upper limit on the frequency of requests per unit time, IPs or sessions exceeding the threshold are blocked or subjected to verification challenges. Second, malicious behavior matching based on rule signatures and feature libraries: for example, identifying the User-Agent characteristics of known web crawling tools, the TLS fingerprint of specific script engines, or abnormal request header order. Third, user behavior profiling based on machine learning: by collecting individual user operation habits over a long period, a personal baseline model is built, including dimensions such as click interval, browsing duration, and access path; behaviors deviating from the baseline by more than a preset deviation are marked as abnormal. These methods constitute the core detection capabilities of existing web security protection and anti-fraud systems.

[0003] However, the aforementioned technologies have revealed significant limitations in real-world combat scenarios. Fixed-threshold frequency strategies are easily bypassed by attackers: automated scripts can simply adjust the request frequency below the threshold to remain dormant and steal data for extended periods without triggering alerts. Rule signature methods face long-term escalation of attacks; attackers can easily disable the rule base by highly customizing request characteristics and simulating mainstream browser behavior. Furthermore, user profiling solutions based on personal baselines are not only costly to deploy and require weeks of learning, but more critically, once attackers gain control of legitimate accounts through social engineering or credential theft, their initial actions will be defaulted to the user's own behavior by the baseline, resulting in catastrophic false negatives.

[0004] The combination of these problems directly leads to two severe derivative dilemmas. First, security and business cannot be balanced: to compensate for missed detections in threshold-based strategies, companies are forced to lower the interception threshold, resulting in numerous legitimate users' continuous actions being misjudged as bots, frequently triggering CAPTCHAs and severely damaging user experience and business conversion rates. Second, internal threats are almost undetectable: malicious behavior with correct credentials is completely identical to normal operations at the content level. Traditional technologies cannot distinguish between "human operation" and "script operation" from the request itself, meaning that data is slowly stolen and often only accidentally discovered months later, by which time the loss is irreversible.

[0005] In summary, existing technologies cannot achieve a balance between security and business operations, and cannot effectively distinguish the essential differences between human operations and automated scripts. This results in a dual dilemma: normal users are frequently and mistakenly blocked, while slow data theft under the cover of legitimate accounts is difficult to detect. Improvements are needed. Summary of the Invention

[0006] Therefore, it is necessary to provide a method and system for analyzing network access behavior risks to address the above-mentioned problems.

[0007] This invention is implemented as follows: a method for analyzing network access behavior risks includes the following steps:

[0008] Capture all HTTP request packets of the current session from network traffic, extract the arrival time of each packet, and construct the request timestamp sequence of the session in chronological order;

[0009] The difference between every two adjacent timestamps in the request timestamp sequence is calculated to obtain the request interval value, and the request interval value is appended to the request interval sequence of the session in the order of generation.

[0010] Maintain a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence. Whenever a new request interval value is added to the request interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence.

[0011] Discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session;

[0012] The number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence is counted, and the proportion of this number to the total number of intervals N in the observation window is calculated as the burstiness feature of the current session.

[0013] Compare the rhythm complexity feature with a preset entropy threshold, and compare the burstiness feature with a preset burst ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burst ratio threshold, mark the session as an automated risky behavior.

[0014] In one embodiment, the present invention provides a method for analyzing network access behavior risks. The method involves capturing all HTTP request packets of the current session from network traffic, extracting the arrival time of each packet, and constructing a request timestamp sequence for the session in chronological order. Specifically, this includes:

[0015] By deploying traffic acquisition probes on the gateway node, all HTTP request packets passing through the gateway can be captured in real time.

[0016] Parse the transport layer header of each HTTP request packet and extract the capture time of the SYN packet or the first packet as the arrival time of the request;

[0017] Arrange the arrival times in ascending order of timestamp values ​​to obtain the request timestamp sequence for this session.

[0018] In one embodiment, the present invention provides a method for analyzing network access behavior risks, wherein the method involves calculating the difference between every two adjacent timestamps in a request timestamp sequence to obtain a request interval value, and appending the request interval value to the request interval sequence of the session in the order of its generation. Specifically, this includes:

[0019] Starting from the first timestamp of the requested timestamp sequence, take two adjacent timestamps in sequence to form a timestamp pair;

[0020] For each timestamp pair, subtract the previous timestamp from the next timestamp to obtain the request interval value;

[0021] The calculated request interval values ​​are appended to the end of the request interval sequence for this session in the order in which the timestamp pairs appear in the sequence.

[0022] In one embodiment, the present invention provides a method for analyzing network access behavior risks. The method involves maintaining a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence. Whenever a new request interval value is added to the request interval sequence, the sliding observation window is updated to obtain the current observation interval sequence. Specifically, this includes:

[0023] Set the capacity parameter N of the sliding observation window, where N is a fixed positive integer;

[0024] When the length of the requested interval sequence is less than or equal to N, the sliding observation window contains all elements of the requested interval sequence;

[0025] When the length of the request interval sequence is greater than N, the sliding observation window discards the earliest generated request interval value in the sequence and includes the latest added request interval value, keeping the number of request intervals in the window constant at N.

[0026] Take the N requested interval values ​​currently contained in the sliding observation window to form the current observation interval sequence.

[0027] In one embodiment, the present invention provides a method for network access behavior risk analysis, wherein the method involves discretizing and binning the current observation interval sequence, counting the frequency of request interval values ​​within each bin, and calculating information entropy based on the frequency distribution as a rhythmic complexity feature of the current session, specifically including:

[0028] Define a set of boundary thresholds for binning, dividing the range of request interval values ​​into several non-overlapping intervals, with each interval being a bin;

[0029] Iterate through each requested interval value in the current observation interval sequence, determine its corresponding bin, and increment the cumulative frequency of that bin by one.

[0030] Calculate the proportion of the cumulative frequency of each bin to the total number of elements N in the current observation interval sequence to obtain the frequency value of each bin;

[0031] Shannon entropy is calculated for the frequency values ​​of each sub-box. The calculation formula is to multiply the negative frequency value of each sub-box by the sum of the logarithms of the frequency values ​​with base 2. The calculation result is used as the rhythm complexity feature.

[0032] In one embodiment, the present invention provides a method for network access behavior risk analysis, wherein the method further includes discretizing and binning the current observation interval sequence, counting the frequency of occurrence of request interval values ​​within each bin, and calculating information entropy based on the frequency distribution as a rhythmic complexity feature of the current session:

[0033] The original non-overlapping bin boundaries are expanded into intervals with a preset overlap ratio. When the requested interval value falls into the overlapping area, it is simultaneously included in the two adjacent bins. Finally, the entropy value of each bin after frequency weighting is taken as the rhythm complexity feature to offset the artificial increase effect of boundary jitter.

[0034] In one embodiment, the present invention provides a method for analyzing network access behavior risks. The method involves counting the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculating the proportion of this number to the total number of intervals N in the observation window, as a burstiness feature of the current session. Specifically, this includes:

[0035] Set a preset interval threshold, which is a physiological limit response time value based on human nerve conduction and muscle response time measurements;

[0036] Iterate through each requested interval value in the current observation interval sequence, compare each one with the preset interval threshold, and accumulate the number of requested interval values ​​that are less than the preset interval threshold;

[0037] Divide the cumulative number by N, and use the quotient as the burstiness feature.

[0038] In one embodiment, the present invention provides a method for analyzing network access behavior risks. The method further includes: counting the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculating the proportion of this number to the total number of intervals N in the observation window, as a burstiness feature of the current session.

[0039] For all request interval values ​​in the current observation interval sequence that are determined to be less than the preset interval threshold, trace back to the corresponding consecutive requests in the original request timestamp sequence to form a cluster. Calculate the time span between the first and last requests within the cluster. When the time span is greater than the preset aggregation time window, the cluster is not included in the cumulative number of bursts, in order to eliminate pseudo-dense requests caused by network latency.

[0040] In one embodiment, the present invention provides a method for analyzing network access behavior risks. The method compares rhythm complexity features with a preset entropy threshold and burstiness features with a preset burstiness ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burstiness ratio threshold, the session is marked as an automated risk behavior. Specifically, this includes:

[0041] Set a preset entropy threshold and a preset burst ratio threshold. The preset entropy threshold is used to distinguish between irregular time series distributions and regular time series distributions, and the preset burst ratio threshold is used to distinguish between human operation interval distributions and automated program operation interval distributions.

[0042] Determine whether the rhythm complexity feature is less than a preset entropy threshold; if it is less, the rhythm abnormality condition is met.

[0043] Determine whether the suddenness characteristic is greater than the preset suddenness ratio threshold. If it is greater, the suddenness anomaly condition is met.

[0044] When both rhythm abnormality conditions and sudden abnormality conditions are met simultaneously, an automated risk behavior flag is generated, associated with the current session identifier, and an alarm is output.

[0045] In one embodiment, the present invention provides a network access behavior risk analysis system, comprising:

[0046] The request timestamp sequence building module is used to capture all HTTP request packets of the current session from network traffic, extract the arrival time of each packet, and build the request timestamp sequence of the session in chronological order.

[0047] The request interval sequence construction module is used to calculate the difference between every two adjacent timestamps in the request timestamp sequence to obtain the request interval value, and append the request interval value to the request interval sequence of the session in the order of generation.

[0048] The observation interval sequence acquisition module is used to maintain a sliding observation window containing a fixed number of N most recent requested intervals on the requested interval sequence. Whenever a new requested interval value is added to the requested interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence.

[0049] The rhythm complexity feature calculation module is used to discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session.

[0050] The burstiness feature calculation module is used to count the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculate the proportion of this number to the total number of intervals N in the observation window, as the burstiness feature of the current session.

[0051] The risk behavior judgment module is used to compare the rhythm complexity feature with the preset entropy threshold and the suddenness feature with the preset suddenness ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the suddenness exceeds the preset suddenness ratio threshold, the session is marked as an automated risk behavior.

[0052] Compared with existing technologies, the beneficial effects of this invention are as follows: This invention captures the timestamp sequence of session requests and extracts the rhythmic complexity and burstiness features of the request interval for joint judgment, changing the basis for risk detection from forgeable request content and evasive frequency thresholds to the underlying human-computer interaction rhythm differences that cannot be faked by the operator; it can take effect immediately at the beginning of session establishment without requiring a user history behavior learning cycle, distinguishing human operations from automated scripts from the physical time dimension, effectively solving the problem of slow data theft that is difficult to detect after legitimate accounts are taken over, while avoiding false blocking of normal users' intensive operations, thus achieving a balance between security protection and business experience. Attached Figure Description

[0053] Figure 1 This is a flowchart illustrating a network access behavior risk analysis method provided in an embodiment of the present invention.

[0054] Figure 2 This is a schematic diagram of the process for constructing a request timestamp sequence provided in an embodiment of the present invention.

[0055] Figure 3 This is a schematic diagram of the process for obtaining the request interval sequence provided in an embodiment of the present invention.

[0056] Figure 4 This is a schematic diagram of the process for obtaining the observation interval sequence provided in an embodiment of the present invention.

[0057] Figure 5 This is a schematic diagram illustrating the process of calculating rhythm complexity features provided in an embodiment of the present invention.

[0058] Figure 6 This is a schematic diagram of the process for offsetting the artificial increase effect provided in an embodiment of the present invention.

[0059] Figure 7 This is a schematic diagram of the burstiness feature calculation process provided in an embodiment of the present invention.

[0060] Figure 8 This is a schematic diagram of the process for eliminating pseudo-dense requests provided in an embodiment of the present invention.

[0061] Figure 9 This is a schematic diagram of the risk behavior identification process provided in an embodiment of the present invention.

[0062] Figure 10 This is a schematic diagram of a network access behavior risk analysis system provided in an embodiment of the present invention. Detailed Implementation

[0063] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0064] In one embodiment, such as Figure 1 As shown, a method for analyzing network access behavior risks includes the following steps:

[0065] Step S1: Capture all HTTP request packets of the current session from the network traffic, extract the arrival time of each packet, and construct the request timestamp sequence of the session in chronological order;

[0066] Step S2: Calculate the difference between every two adjacent timestamps in the request timestamp sequence to obtain the request interval value, and append the request interval value to the request interval sequence of the session in the order of generation.

[0067] Step S3: Maintain a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence. Whenever a new request interval value is added to the request interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence.

[0068] Step S4: Discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session.

[0069] Step S5: Count the number of requests with interval values ​​less than the preset interval threshold in the current observation interval sequence, and calculate the proportion of this number to the total number of intervals N in the observation window, as the burstiness feature of the current session;

[0070] Step S6: Compare the rhythm complexity feature with the preset entropy threshold, and compare the burstiness feature with the preset burst ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burst ratio threshold, mark the session as an automated risky behavior.

[0071] The basis of this method is the rhythmic characteristics exhibited by the operator over time, rather than the request content or credential information. Step S1 captures the precise arrival time of the current session's HTTP requests and constructs a timestamp sequence. The purpose is to completely preserve the chronological relationship and interval distribution of the operation behavior on the timeline, providing a unique data source for all subsequent rhythmic analyses. Step S2 converts the absolute timestamps into request interval values ​​between adjacent requests, eliminating the difference in the specific time when the user started the operation, allowing different sessions to be compared on a unified interval dimension. Step S3 maintains a sliding observation window on the request interval sequence to obtain the current observation interval sequence. This is because rhythmic characteristic judgment requires a sufficient sample size to be statistically significant, but including all historical data would overwhelm recent behavioral changes. The sliding window ensures statistical sufficiency while focusing the analysis on the most recent N operations, enabling a rapid response to behavioral changes. Step S4 discretizes and bins the current observation interval sequence and calculates the information entropy to obtain the rhythmic complexity feature. This feature is used to quantify the degree of disorder in the interval distribution. Human operations exhibit high entropy values ​​due to random interference, while automated scripts exhibit low entropy values ​​due to timing logic. Step S5 calculates the percentage of requests in the current observation interval sequence that are less than a preset interval threshold to obtain the burstiness feature. This feature quantifies the proportion of dense requests that exceed human physiological response time limits, directly reflecting whether the operator is a program. Step S6 jointly determines the rhythm complexity feature and the burstiness feature, requiring both features to simultaneously exhibit machine attributes before being marked as automated risky behavior. This eliminates misjudgments caused by deliberate, regular human operations or accidental, dense network arrivals when relying solely on a single feature, thus improving the accuracy of the determination.

[0072] In one embodiment, such as Figure 2 As shown, a network access behavior risk analysis method includes step S1, which involves capturing all HTTP request packets of the current session from network traffic, extracting the arrival time of each packet, and constructing a request timestamp sequence for the session in chronological order. Specifically, this includes:

[0073] Step S11: Capture all HTTP request packets passing through the gateway in real time by deploying traffic acquisition probes on the gateway node;

[0074] Step S12: Parse the transport layer header of each HTTP request data packet and extract the capture time of the SYN packet or the first data packet as the arrival time of the request.

[0075] Step S13: Arrange the arrival times in ascending order of timestamp values ​​to obtain the request timestamp sequence for the session.

[0076] Step S11 deploys a traffic collection probe on the gateway node because the gateway is the necessary convergence point for all HTTP requests between the user terminal and the business server. Collecting data here ensures complete and timely request packets for the current session, avoiding potential clock asynchrony or packet loss issues on the terminal side. Step S12 parses the transport layer header and uses the capture time of the SYN packet or the first data packet as the request arrival time because the SYN packet is the first packet in a TCP connection, and its capture time is closest to the actual time the user initiated the request, minimizing the interference of network latency jitter on the request time stamp. Step S13 arranges the arrival times in ascending order of timestamp values ​​because data packets may arrive out of order during network transmission. The rearranged sequence accurately reflects the order in which the operator sent requests, ensuring the correct time direction for subsequent request interval calculations.

[0077] In one embodiment, such as Figure 3 As shown, a network access behavior risk analysis method, step S2, calculates the difference between every two adjacent timestamps in the request timestamp sequence to obtain a request interval value, and appends the request interval value to the request interval sequence of the session in the order of generation, specifically including:

[0078] Step S21: Starting from the first timestamp of the requested timestamp sequence, take two adjacent timestamps in sequence to form a timestamp pair;

[0079] Step S22: For each timestamp pair, perform the calculation of subtracting the previous timestamp from the next timestamp to obtain the requested interval value;

[0080] Step S23: The calculated request interval values ​​are appended to the end of the request interval sequence of the session in the order in which the timestamp pairs appear in the sequence.

[0081] Step S21 involves sequentially taking adjacent timestamps to form timestamp pairs to obtain all consecutive operation intervals in the sequence, ensuring no potential human-machine rhythm feature sample is missed. Step S22 subtracts the previous timestamp from the subsequent timestamp to obtain the request interval value, ensuring the time direction is consistent with the operation sequence and the interval value accurately reflects the time consumption between two consecutive requests from the operator. Step S23 appends the request interval values ​​to the end of the request interval sequence according to the order in which the timestamp pairs appear. This maintains a strict correspondence between the interval value and the order in which the operations occur, allowing subsequent sliding observation window analysis to reflect the temporal characteristics of the most recent operation.

[0082] In one embodiment, such as Figure 4As shown, a network access behavior risk analysis method includes step S3, which maintains a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence. Whenever a new request interval value is added to the request interval sequence, the sliding observation window is updated to obtain the current observation interval sequence. Specifically, this includes:

[0083] Step S31: Set the capacity parameter N of the sliding observation window, where N is a fixed positive integer;

[0084] Step S32: When the length of the requested interval sequence is less than or equal to N, the sliding observation window contains all elements of the requested interval sequence;

[0085] Step S33: When the length of the request interval sequence is greater than N, the sliding observation window discards the earliest generated request interval value in the sequence and incorporates the latest added request interval value, keeping the number of request intervals in the window constant at N.

[0086] Step S34: Take the N requested interval values ​​currently contained in the sliding observation window to form the current observation interval sequence.

[0087] Step S31 sets the sliding observation window capacity parameter N to a fixed positive integer to unify the analysis scale across all sessions, making rhythm complexity and burst characteristics comparable across different sessions. Step S32, when the request interval sequence length is less than or equal to N, directly includes all elements in the sliding observation window. This ensures analysis can begin even when the initial number of requests in a session does not yet meet N, avoiding blind spots in new sessions. Step S33, when the sequence length is greater than N, discards the earliest generated request interval value and includes the latest added request interval value, maintaining a constant number of elements N within the window. This sliding mechanism ensures the window always reflects the rhythm state of the operator's most recent N operations; old actions are excluded from the analysis, while new actions immediately affect the judgment results. Step S34 takes the N request interval values ​​currently included in the sliding observation window to form the current observation interval sequence, outputting the window state in a standardized data structure for independent reading in subsequent steps S4 and S5.

[0088] In one embodiment, such as Figure 5 As shown, a network access behavior risk analysis method includes step S4, which involves discretizing and binning the current observation interval sequence, counting the frequency of request interval values ​​within each bin, and calculating the information entropy based on the frequency distribution as a feature of the rhythmic complexity of the current session. Specifically, this includes:

[0089] Step S41: Define the set of boundary thresholds for binning, and divide the range of requested interval values ​​into several non-overlapping intervals, with each interval being a bin.

[0090] Step S42: Traverse each requested interval value in the current observation interval sequence, determine its corresponding bin, and increment the cumulative frequency of that bin by one.

[0091] Step S43: Calculate the proportion of the cumulative frequency of each bin to the total number of elements N in the current observation interval sequence, and obtain the frequency value of each bin;

[0092] Step S44: Perform Shannon entropy calculation on the frequency values ​​of each sub-box. The calculation formula is to multiply the negative frequency value of each sub-box by the sum of the logarithms of the frequency values ​​with base 2. The calculation result is used as the rhythm complexity feature.

[0093] Step S41 defines the binning boundary threshold set and divides the range of requested interval values ​​into non-overlapping intervals because information entropy calculation requires discretization of continuous variables. Binning groups similar interval values ​​into the same category, making frequency statistics possible. Step S42 traverses the current observation interval sequence to determine the bin to which each requested interval value belongs and accumulates the frequency, constructing the frequency distribution basis of the interval values. Step S43 calculates the proportion of the accumulated frequency of each bin to the total number of elements N in the current observation interval sequence to obtain the frequency value, converting absolute frequency to relative frequency, eliminating the influence of the observation window size on subsequent entropy value calculation, and ensuring that results under different N values ​​are still comparable. Step S44 performs Shannon entropy calculation on the frequency values ​​of each bin, and the result is used as a rhythm complexity feature. Shannon entropy measures the uniformity of the distribution of requested interval values ​​across bins. The more uniform the distribution, the more the interval values ​​appear in multiple intervals, and the more the behavior is closer to the random characteristics of human operation. A lower entropy value indicates that the interval values ​​are concentrated in a few bins, and the behavior is closer to the timed triggering characteristics of automated scripts.

[0094] For example: Set the sliding observation window size N=10, and the current observation interval sequence is [120,135,118,980,125,130,122,119,2000,128], in milliseconds. This sequence simulates a human operator browsing a business page, where most request intervals are concentrated within a normal operating rhythm of 120 to 135 milliseconds, interspersed with a 980-millisecond page reading pause and a long pause of 2000 milliseconds.

[0095] Step S41 defines a set of bin boundary thresholds, dividing the range of the requested interval value into four non-overlapping bins: [0,200), [200,500), [500,1000), and [1000,∞), with the unit being milliseconds.

[0096] Step S42 iterates through the 10 elements of the current observation interval sequence and determines their respective bins: 8 values ​​(120, 135, 118, 125, 130, 122, 119, 128) fall into the bin [0, 200); 980 falls into the bin [500, 1000); and 2000 falls into the bin [1000, ∞). No value falls into the bin [200, 500). The cumulative frequencies of each bin are 8, 0, 1, and 1, respectively.

[0097] Step S43 calculates the proportion of each sub-box frequency to the total number of elements N=10, and obtains frequency values ​​of 0.8, 0, 0.1, and 0.1 respectively.

[0098] Step S44 performs the Shannon entropy calculation: -(0.8×log₂ 0.8+0×log₂ 0+0.1×log₂ 0.1+0.1×log₂ 0.1), where 0×log₂ 0 is taken as 0 on the limit. log₂ 0.8≈-0.3219, log₂ 0.1≈-3.3219. The calculated result is 0.9219. The rhythmic complexity characteristic of this session is 0.9219, which is relatively uniformly distributed and consistent with the random characteristics of human operation.

[0099] In one embodiment, such as Figure 6 As shown, a network access behavior risk analysis method, in step S4, discretizes the current observation interval sequence into bins, counts the frequency of request interval values ​​within each bin, and calculates information entropy based on the frequency distribution as a rhythmic complexity feature of the current session, further includes:

[0100] Step S45: Expand the original non-overlapping bin boundaries into intervals with a preset overlap ratio. When the requested interval value falls into the overlapping area, it is simultaneously included in the two adjacent bins. Finally, take the entropy value of each bin after frequency weighting as the rhythm complexity feature to offset the artificial increase effect of boundary jitter.

[0101] When network fluctuations cause random jitter in request arrival times, the regular request intervals that were originally concentrated in the same bin can spread to adjacent bins. This results in an artificially inflated uniformity of frequency distribution, leading to a higher calculated value for the rhythm complexity feature than the actual value, causing automated scripts to miss certain cases. Therefore, a bin overlap strategy is designed.

[0102] In one embodiment, such as Figure 7 As shown, a network access behavior risk analysis method includes step S5, which involves counting the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculating the proportion of this number to the total number of intervals N in the observation window. This proportion is used as a burstiness feature of the current session. Specifically, this includes:

[0103] Step S51: Set a preset interval threshold, which is a physiological limit response time value based on the measurement of human nerve conduction and muscle response time.

[0104] Step S52: Iterate through each requested interval value in the current observation interval sequence, compare each one with the preset interval threshold, and accumulate the number of requested interval values ​​that are less than the preset interval threshold.

[0105] Step S53: Divide the cumulative number by N, and use the quotient as the burstiness feature.

[0106] Step S51 sets a preset interval threshold. This threshold, based on measurements of human nerve conduction and muscle response time, constitutes an objective physical boundary distinguishing human-machine interaction and is universally effective without relying on historical user data. Step S52 iterates through the current observation interval sequence, comparing each request interval value with the preset interval threshold one by one, accumulating the number of requests less than the threshold. The purpose is to accurately count the number of requests that exceeded physiological limits in the most recent N operations, reflecting the density of programmed operations. Step S53 divides the accumulated number by the total number of elements N in the current observation interval sequence, and the quotient is used as the burstiness feature. The absolute number is converted into a proportion, making this indicator comparable under different observation window sizes, and is directly used as the input value for comparison with the preset burst proportion threshold in step S6.

[0107] Continuing from steps S41 to S44, the following example illustrates the process: Step S51 sets a preset interval threshold of 50 milliseconds, which is based on the determination of the shortest physiological response time for two consecutive conscious clicks by a human.

[0108] Step S52 iterates through the 10 elements of the current observation interval sequence and compares them one by one with 50 milliseconds: 120, 135, 118, 980, 125, 130, 122, 119, 2000, and 128 are all greater than 50 milliseconds, and no requested interval value is less than the threshold, so the cumulative count is 0.

[0109] Step S53 divides the cumulative count of 0 by N=10, resulting in a burstiness characteristic of 0. The burstiness characteristic of this session is 0, indicating that no intensive requests exceeding physiological limits occurred in the last 10 operations, consistent with human operational characteristics.

[0110] In one embodiment, such as Figure 8 As shown, a network access behavior risk analysis method, in step S5, counts the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, calculates the proportion of this number to the total number of intervals N in the observation window, and uses this proportion as the burstiness feature of the current session, further includes:

[0111] Step S54: For all request interval values ​​in the current observation interval sequence that are determined to be less than the preset interval threshold, trace back the corresponding consecutive requests in the original request timestamp sequence to form a cluster. Calculate the time span between the first and last requests within the cluster. When the time span is greater than the preset aggregation time window, the cluster is not included in the cumulative number of bursts, so as to eliminate pseudo-dense requests caused by network latency.

[0112] When the total number of session requests is sparse and network latency fluctuates significantly, a single network congestion can compress multiple normal requests into a short period of time, making it indistinguishable from the high-speed concurrency of automated scripts in terms of interval values. This leads to the calculated burstiness characteristic value being higher than the actual value, causing human operators to be misjudged. Therefore, a short-term aggregation check is designed.

[0113] In one embodiment, such as Figure 9 As shown, a network access behavior risk analysis method includes step S6, which compares the rhythm complexity feature with a preset entropy threshold and the burstiness feature with a preset burst ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burst ratio threshold, the session is marked as an automated risk behavior. Specifically, this includes:

[0114] Step S61: Set a preset entropy threshold and a preset burst ratio threshold. The preset entropy threshold is used to distinguish between irregular time series distribution and regular time series distribution, and the preset burst ratio threshold is used to distinguish between human operation interval distribution and automated program operation interval distribution.

[0115] Step S62: Determine whether the rhythm complexity feature is less than the preset entropy threshold. If it is less, the rhythm abnormality condition is met.

[0116] Step S63: Determine whether the burst intensity feature is greater than the preset burst ratio threshold. If it is greater, the burst anomaly condition is met.

[0117] Step S64: When both the rhythm abnormality condition and the sudden abnormality condition are met, an automated risk behavior flag is generated, associated with the current session identifier, and an alarm is output.

[0118] Step S61 sets a preset entropy threshold and a preset burst ratio threshold, corresponding to rhythmic anomaly conditions and burst anomaly conditions, respectively. This is because rhythmic complexity and burst characteristics reflect two independent dimensions of automated behavior—the regularity of the intervals and the speed of the intervals—and require independent judgment using their respective thresholds. Step S62 determines whether the rhythmic complexity characteristic is less than the preset entropy threshold. If it is less, it indicates that the request interval distribution is too regular, consistent with the timed triggering characteristics of automated scripts. Step S63 determines whether the burst characteristic is greater than the preset burst ratio threshold. If it is greater, it indicates an abnormal proportion of dense requests exceeding physiological limits, consistent with the high-speed concurrency characteristics of automated scripts. Step S64 generates an automated risk behavior flag and associates it with the current session identifier only when both the rhythmic anomaly condition and the burst anomaly condition are simultaneously met. This execution and logical judgment aims to ensure that automated risk behavior is only ultimately confirmed when the operation deviates from the range of human operation in both the regularity and speed dimensions, avoiding misjudgments that may be caused by a single dimension.

[0119] In one embodiment, such as Figure 10 As shown, a network access behavior risk analysis system includes:

[0120] The request timestamp sequence building module is used to capture all HTTP request packets of the current session from network traffic, extract the arrival time of each packet, and build the request timestamp sequence of the session in chronological order.

[0121] The request interval sequence construction module is used to calculate the difference between every two adjacent timestamps in the request timestamp sequence to obtain the request interval value, and append the request interval value to the request interval sequence of the session in the order of generation.

[0122] The observation interval sequence acquisition module is used to maintain a sliding observation window containing a fixed number of N most recent requested intervals on the requested interval sequence. Whenever a new requested interval value is added to the requested interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence.

[0123] The rhythm complexity feature calculation module is used to discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session.

[0124] The burstiness feature calculation module is used to count the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, calculate the proportion of this number to the total number of intervals N in the observation window, and use it as the burstiness feature of the current session.

[0125] The risk behavior judgment module is used to compare the rhythm complexity feature with the preset entropy threshold and the suddenness feature with the preset suddenness ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the suddenness exceeds the preset suddenness ratio threshold, the session is marked as an automated risk behavior.

[0126] When performing legitimate long-running business operations such as batch data export or report generation, users enter a waiting period after triggering the operation. During this period, the server continuously returns processing status, and the frontend automatically initiates polling requests to obtain task progress. The fixed interval pattern of these polling requests is completely consistent with the timed heartbeat behavior of automated scripts, causing the rhythm complexity feature to drop to within the scope of automated judgment, resulting in normal business operations being misjudged. Therefore, a legitimate rule recognition module is designed to identify whether there is a pattern in the current session request URL sequence that meets the preset polling recognition rules. These rules include: the same URL reappears at fixed time intervals and the response content contains a task status identifier field. When a request subsequence that matches the polling pattern is identified, the request interval value corresponding to that subsequence is removed from the current observation interval sequence, and the remaining interval values ​​are re-involved in the rhythm complexity feature calculation, thus solving the problem of legitimate business polling being misjudged as automated heartbeats.

[0127] It should be understood that although the steps in the flowcharts of the various embodiments of the present invention are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the various embodiments may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least a portion of the sub-steps or stages of other steps.

[0128] Those skilled in the art will understand that all or part of the processes in the systems described in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0129] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0130] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of this patent should be determined by the appended claims.

[0131] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0132] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.

Claims

1. A method for analyzing network access behavior risks, characterized in that, The network access behavior risk analysis method includes the following steps: Capture all HTTP request packets of the current session from network traffic, extract the arrival time of each packet, and construct the request timestamp sequence of the session in chronological order; The difference between every two adjacent timestamps in the request timestamp sequence is calculated to obtain the request interval value, and the request interval value is appended to the request interval sequence of the session in the order of generation. Maintain a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence. Whenever a new request interval value is added to the request interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence. Discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session; The number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence is counted, and the proportion of this number to the total number of intervals N in the observation window is calculated as the burstiness feature of the current session. Compare the rhythm complexity feature with a preset entropy threshold, and compare the burstiness feature with a preset burst ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burst ratio threshold, mark the session as an automated risky behavior.

2. The network access behavior risk analysis method according to claim 1, characterized in that, The process of capturing all HTTP request packets of the current session from network traffic, extracting the arrival time of each packet, and constructing a request timestamp sequence for the session in chronological order specifically includes: By deploying traffic acquisition probes on the gateway node, all HTTP request packets passing through the gateway can be captured in real time. Parse the transport layer header of each HTTP request packet and extract the capture time of the SYN packet or the first packet as the arrival time of the request; Arrange the arrival times in ascending order of timestamp values ​​to obtain the request timestamp sequence for this session.

3. The network access behavior risk analysis method according to claim 1, characterized in that, The step of calculating the difference between every two adjacent timestamps in the request timestamp sequence to obtain the request interval value, and appending the request interval value to the request interval sequence of the session in the order of generation, specifically includes: Starting from the first timestamp of the requested timestamp sequence, take two adjacent timestamps in sequence to form a timestamp pair; For each timestamp pair, subtract the previous timestamp from the next timestamp to obtain the request interval value; The calculated request interval values ​​are appended to the end of the request interval sequence for this session in the order in which the timestamp pairs appear in the sequence.

4. The network access behavior risk analysis method according to claim 1, characterized in that, The process of maintaining a sliding observation window containing a fixed number of N most recent request intervals on the request interval sequence, updating the sliding observation window whenever a new request interval value is added to the request interval sequence, and obtaining the current observation interval sequence specifically includes: Set the capacity parameter N of the sliding observation window, where N is a fixed positive integer; When the length of the requested interval sequence is less than or equal to N, the sliding observation window contains all elements of the requested interval sequence; When the length of the request interval sequence is greater than N, the sliding observation window discards the earliest generated request interval value in the sequence and includes the latest added request interval value, keeping the number of request intervals in the window constant at N. Take the N requested interval values ​​currently contained in the sliding observation window to form the current observation interval sequence.

5. The network access behavior risk analysis method according to claim 1, characterized in that, The process of discretizing and binning the current observation interval sequence, counting the frequency of requested interval values ​​within each bin, and calculating information entropy based on the frequency distribution as a feature of the rhythmic complexity of the current session specifically includes: Define a set of boundary thresholds for binning, dividing the range of request interval values ​​into several non-overlapping intervals, with each interval being a bin; Iterate through each requested interval value in the current observation interval sequence, determine its corresponding bin, and increment the cumulative frequency of that bin by one. Calculate the proportion of the cumulative frequency of each bin to the total number of elements N in the current observation interval sequence to obtain the frequency value of each bin; Shannon entropy is calculated for the frequency values ​​of each sub-box. The calculation formula is to multiply the negative frequency value of each sub-box by the sum of the logarithms of the frequency values ​​with base 2. The calculation result is used as the rhythm complexity feature.

6. The network access behavior risk analysis method according to claim 5, characterized in that, The process of discretizing and binning the current observation interval sequence, counting the frequency of requested interval values ​​within each bin, and calculating information entropy based on the frequency distribution as a feature of the rhythmic complexity of the current session also includes: The original non-overlapping bin boundaries are expanded into intervals with a preset overlap ratio. When the requested interval value falls into the overlapping area, it is simultaneously included in the two adjacent bins. Finally, the entropy value of each bin after frequency weighting is taken as the rhythm complexity feature to offset the artificial increase effect of boundary jitter.

7. The network access behavior risk analysis method according to claim 1, characterized in that, The method of counting the number of requested interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculating the proportion of this number to the total number of intervals N in the observation window, is used as a burstiness feature of the current session, specifically including: Set a preset interval threshold, which is a physiological limit response time value based on human nerve conduction and muscle response time measurements; Iterate through each requested interval value in the current observation interval sequence, compare each one with the preset interval threshold, and accumulate the number of requested interval values ​​that are less than the preset interval threshold; Divide the cumulative number by N, and use the quotient as the burstiness feature.

8. The network access behavior risk analysis method according to claim 7, characterized in that, The method of counting the number of requested interval values ​​less than a preset interval threshold in the current observation interval sequence and calculating the proportion of this number to the total number of intervals N in the observation window, as a burstiness feature of the current session, also includes: For all request interval values ​​in the current observation interval sequence that are determined to be less than the preset interval threshold, trace back to the corresponding consecutive requests in the original request timestamp sequence to form a cluster. Calculate the time span between the first and last requests within the cluster. When the time span is greater than the preset aggregation time window, the cluster is not included in the cumulative number of bursts, in order to eliminate pseudo-dense requests caused by network latency.

9. The network access behavior risk analysis method according to claim 1, characterized in that, The process compares the rhythm complexity feature with a preset entropy threshold and the burstiness feature with a preset burst ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the burstiness exceeds the preset burst ratio threshold, the session is marked as an automated risky behavior. Specifically, this includes: Set a preset entropy threshold and a preset burst ratio threshold. The preset entropy threshold is used to distinguish between irregular time series distributions and regular time series distributions, and the preset burst ratio threshold is used to distinguish between human operation interval distributions and automated program operation interval distributions. Determine whether the rhythm complexity feature is less than a preset entropy threshold; if it is less, the rhythm abnormality condition is met. Determine whether the suddenness characteristic is greater than the preset suddenness ratio threshold. If it is greater, the suddenness anomaly condition is met. When both rhythm abnormality conditions and sudden abnormality conditions are met simultaneously, an automated risk behavior flag is generated, associated with the current session identifier, and an alarm is output.

10. A network access behavior risk analysis system, characterized in that, include: The request timestamp sequence building module is used to capture all HTTP request packets of the current session from network traffic, extract the arrival time of each packet, and build the request timestamp sequence of the session in chronological order. The request interval sequence construction module is used to calculate the difference between every two adjacent timestamps in the request timestamp sequence to obtain the request interval value, and append the request interval value to the request interval sequence of the session in the order of generation. The observation interval sequence acquisition module is used to maintain a sliding observation window containing a fixed number of N most recent requested intervals on the requested interval sequence. Whenever a new requested interval value is added to the requested interval sequence, the sliding observation window is updated once to obtain the current observation interval sequence. The rhythm complexity feature calculation module is used to discretize and bin the current observation interval sequence, count the frequency of the requested interval value in each bin, and calculate the information entropy based on the frequency distribution as the rhythm complexity feature of the current session. The burstiness feature calculation module is used to count the number of requests with interval values ​​less than a preset interval threshold in the current observation interval sequence, and calculate the proportion of this number to the total number of intervals N in the observation window, as the burstiness feature of the current session. The risk behavior judgment module is used to compare the rhythm complexity feature with the preset entropy threshold and the suddenness feature with the preset suddenness ratio threshold. When the rhythm complexity is lower than the preset entropy threshold and the suddenness exceeds the preset suddenness ratio threshold, the session is marked as an automated risk behavior.