Flow control method and apparatus, storage medium, and computer program product
Patent Information
- Application Number
- CN202510371229.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]本申请实施例提供了一种流量控制方法和装置、存储介质及计算机程序产品,以至少解决相关技术中通过人为规定的异常流量检测规则实现流量控制,导致对流量控制的准确性比较低的技术问题
[0024]根据本发明实施例的另一方面,还提供了一种计算机可读存储介质,存储介质存储程序,其中,在程序运行时控制存储介质所在设备执行上述任意一项的流量控制方法。
Smart Images

Figure CN122845141A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and more specifically, to a flow control method and apparatus, a storage medium, and a computer program product. Background Technology
[0002] In cloud computing environments, with the exponential growth of task scale and user numbers, the volume of network requests, user behavior, and potential threat data expands rapidly. Furthermore, automated attack methods are highly variable and have short cycles, making it difficult for traditional detection mechanisms to respond promptly to emerging threats, resulting in lagging protection. Current technologies often rely on manually defined abnormal traffic detection rules for traffic control, which is insufficient to effectively prevent threats such as identity spoofing and malicious traffic.
[0003] There is currently no effective solution to the problem that the accuracy of flow control is relatively low due to the use of manually defined abnormal flow detection rules in the aforementioned related technologies. Summary of the Invention
[0004] This application provides a flow control method and apparatus, storage medium, and computer program product to at least solve the technical problem in the related art where flow control is achieved through manually defined abnormal flow detection rules, resulting in relatively low accuracy of flow control.
[0005] According to one aspect of the embodiments of this application, a traffic control method is provided, comprising: receiving first traffic data and acquiring target traffic feature information corresponding to the first traffic data; performing anomaly detection on the target traffic feature information according to a target traffic detection rule to obtain a first detection result, wherein the target traffic detection rule is obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model, and the first detection result is used to indicate whether the first traffic data has a risk; and determining a processing strategy for the first traffic data based on the first detection result, wherein the processing strategy is used to control the first traffic data.
[0006] Furthermore, before performing anomaly detection on the target traffic feature information according to the target traffic detection rules to obtain the first detection result, the method further includes: obtaining real traffic feature information corresponding to the real traffic data based on the log file corresponding to the application firewall engine; constructing target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether the real traffic data is abnormal based on the real traffic feature information, and to generate traffic detection rules if the real traffic data is abnormal; and processing the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0007] Furthermore, constructing target prompt information based on the real traffic feature information includes: determining the meaning information corresponding to the feature information in the real traffic feature information; obtaining the constraints on the output results of the target natural language model; and combining the meaning information, the real traffic feature information, and the constraints to obtain the target prompt information.
[0008] Further, processing the target prompt information using the target natural language model to obtain the target traffic detection rule includes: parsing the target prompt information using the target natural language model to obtain an initial traffic detection rule; performing anomaly detection on the second traffic data according to the initial traffic detection rule to obtain a second detection result, wherein the second detection result is used to characterize whether the second traffic data is abnormal; determining a first hit rate and a first hit distribution information corresponding to the initial traffic detection rule based on the second detection result and the actual detection result corresponding to the second traffic data; and adjusting the initial traffic detection rule based on the first hit rate and the first hit distribution information to obtain the target traffic detection rule.
[0009] Furthermore, based on the log file corresponding to the application firewall engine, obtaining the real traffic feature information corresponding to the real traffic data includes: performing feature collection on the log file through a streaming computing engine to obtain initial traffic feature information; filtering the initial traffic feature information according to a preset time sliding window to obtain first traffic feature information; and filtering the first traffic feature information according to historical traffic detection rules to obtain the real traffic feature information.
[0010] Furthermore, before obtaining initial traffic feature information by collecting features from the log file through the streaming computing engine, the method further includes: upon receiving real traffic data from external access, processing the real traffic data through an application firewall engine to obtain real traffic feature information corresponding to the real traffic data; encoding and compressing the traffic feature information to obtain string information; and generating the log file based on the string information.
[0011] Furthermore, filtering the initial traffic feature information according to a preset time sliding window to obtain the first traffic feature information includes: determining the device type of the device that triggered the real traffic data; determining the time range corresponding to the preset time sliding window based on the device type; and filtering the initial traffic feature information according to the time range to obtain the first traffic feature information.
[0012] Furthermore, after determining the processing strategy for the first traffic data based on the first detection result, the method further includes: if an update instruction for the target traffic detection rule is received, determining the second hit rate and second hit distribution information corresponding to the target traffic detection rule based on the first detection result and the actual detection result corresponding to the first traffic data; adjusting the target traffic detection rule according to the second hit rate and the second hit distribution information to obtain the adjusted target traffic detection rule; when receiving third traffic data, filtering the traffic feature information corresponding to the third traffic data according to the adjusted target traffic detection rule to obtain second traffic feature information; processing the second traffic feature information through the target natural language model to obtain an updated traffic detection rule, and updating the adjusted target traffic detection rule according to the updated traffic detection rule to obtain the updated target traffic detection rule.
[0013] Furthermore, before processing the target prompt information through the target natural language model to obtain the target traffic detection rule, the method further includes: acquiring domain knowledge information for traffic protection; and training the initial natural language model using the domain knowledge information to obtain the target natural language model.
[0014] According to another aspect of the embodiments of this application, a traffic control device is also provided, comprising: a receiving unit, configured to receive first traffic data and acquire target traffic feature information corresponding to the first traffic data; a detection unit, configured to perform anomaly detection on the target traffic feature information according to a target traffic detection rule to obtain a first detection result, wherein the target traffic detection rule is obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model, and the first detection result is used to indicate whether the first traffic data has a risk; and a first determining unit, configured to determine a processing strategy for the first traffic data based on the first detection result, wherein the processing strategy is used to control the first traffic data.
[0015] Furthermore, the device further includes: a first acquisition unit, configured to acquire real traffic feature information corresponding to the real traffic data based on the log file corresponding to the application firewall engine before performing anomaly detection on the target traffic feature information according to the target traffic detection rules and obtaining a first detection result; a construction unit, configured to construct target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether the real traffic data is abnormal based on the real traffic feature information, and to generate traffic detection rules if the real traffic data is abnormal; and a first processing unit, configured to process the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0016] Furthermore, the construction unit includes: a first determining module, used to determine the meaning information corresponding to the feature information in the real traffic feature information; an acquisition module, used to acquire the constraints on the output result of the target natural language model; and a construction module, used to combine the meaning information, the real traffic feature information and the constraints to obtain the target prompt information.
[0017] Further, the processing unit includes: a processing module, used to parse the target prompt information through the target natural language model to obtain an initial traffic detection rule; a detection module, used to perform anomaly detection on the second traffic data according to the initial traffic detection rule to obtain a second detection result, wherein the second detection result is used to characterize whether the second traffic data is abnormal; a second determination module, used to determine a first hit rate and a first hit distribution information corresponding to the initial traffic detection rule based on the second detection result and the actual detection result corresponding to the second traffic data; and an adjustment module, used to adjust the initial traffic detection rule according to the first hit rate and the first hit distribution information to obtain the target traffic detection rule.
[0018] Furthermore, the first acquisition unit includes: a collection module, used to collect features from the log file through a streaming computing engine to obtain initial traffic feature information; a first filtering module, used to filter the initial traffic feature information according to a preset time sliding window to obtain first traffic feature information; and a second filtering module, used to filter the first traffic feature information according to historical traffic detection rules to obtain the real traffic feature information.
[0019] Furthermore, the device further includes: a second processing unit, configured to, before obtaining initial traffic feature information by feature collection of the log file through a streaming computing engine, process the real traffic data received from external access through an application firewall engine to obtain real traffic feature information corresponding to the real traffic data; a third processing unit, configured to encode and compress the traffic feature information to obtain string information; and a generation unit, configured to generate the log file based on the string information.
[0020] Furthermore, the first filtering module includes: a first determining submodule, used to determine the device type of the device that triggers the real traffic data; a second determining submodule, used to determine the time range corresponding to the preset time sliding window based on the device type; and a filtering submodule, used to filter the initial traffic feature information based on the time range to obtain the first traffic feature information.
[0021] Furthermore, the device further includes: a second determining unit, configured to, after determining a processing strategy for the first traffic data based on the first detection result, if an update instruction for the target traffic detection rule is received, determine a second hit rate and a second hit distribution information corresponding to the target traffic detection rule based on the first detection result and the actual detection result corresponding to the first traffic data; an adjusting unit, configured to adjust the target traffic detection rule based on the second hit rate and the second hit distribution information to obtain an adjusted target traffic detection rule; a filtering unit, configured to, upon receiving third traffic data, filter the traffic feature information corresponding to the third traffic data based on the adjusted target traffic detection rule to obtain second traffic feature information; and a processing unit, configured to process the second traffic feature information through the target natural language model to obtain an updated traffic detection rule, and update the adjusted target traffic detection rule based on the updated traffic detection rule to obtain an updated target traffic detection rule.
[0022] Furthermore, the device further includes: a second acquisition unit, configured to acquire domain knowledge information for traffic protection before processing the target prompt information through the target natural language model to obtain the target traffic detection rule; and a training unit, configured to train the initial natural language model using the domain knowledge information to obtain the target natural language model.
[0023] According to another aspect of the present invention, an electronic device is also provided, comprising: a memory storing an executable program; and a processor for running the program, wherein the program executes the flow control method of any one of the above embodiments during runtime.
[0024] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein the storage medium stores a program, and the program controls the device where the storage medium is located to execute any of the above-described flow control methods when it is running.
[0025] According to another aspect of the present invention, a computer program product is also provided, including a computer program or instructions that, when executed by a processor, implement the flow control method described above.
[0026] In this embodiment, the following steps are employed: receiving first traffic data and obtaining target traffic feature information corresponding to the first traffic data; performing anomaly detection on the target traffic feature information according to target traffic detection rules to obtain a first detection result, wherein the target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model, and the first detection result is used to indicate whether the first traffic data is risky; determining a processing strategy for the first traffic data based on the first detection result, wherein the processing strategy is used to control the first traffic data, solving the technical problem in related technologies where traffic control is achieved through manually defined anomaly traffic detection rules, resulting in low accuracy of traffic control. In this solution, the target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model. Compared with the fixed rules in the prior art, the target natural language model can understand and learn the complexity of traffic, and can generate more flexible and adaptable target traffic detection rules, enabling the target traffic detection rules to more accurately identify risky traffic, thereby achieving the technical effect of reducing the false positive rate and the false negative rate. Attached Figure Description
[0027] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0028] Figure 1 This is a hardware structure block diagram of a computer terminal provided according to Embodiment 1 of this application;
[0029] Figure 2 This is the flow chart of the flow control method provided in Embodiment 1 of this application. Figure 1 ;
[0030] Figure 3 This is a schematic diagram of the flow control method provided according to Embodiment 1 of this application;
[0031] Figure 4 This is the flow chart of the flow control method provided in Embodiment 1 of this application. Figure 2 ;
[0032] Figure 5 This is a schematic diagram of a flow control device according to Embodiment 2 of this application;
[0033] Figure 6 This is a structural block diagram of an electronic device provided according to Embodiment 3 of this application. Detailed Implementation
[0034] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0035] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0036] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:
[0037] Ant i-bot: Anti-automation attack technology, mainly used to detect and defend against attacks launched by malicious programs (such as automated scripts), ensuring the normal operation of the system and the legitimate use of resources.
[0038] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0039] Example 1
[0040] According to an embodiment of this application, a flow control method is also provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0041] The method embodiment provided in Embodiment 1 of this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware block diagram of a computer terminal (or mobile device) for implementing a flow control method is shown. Figure 1 As shown, the computer terminal (or mobile device) 10 may include a processor set 102 (the processor set 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc., and the processor set 102 may include a processor set, Figure 1 (Illustrated as 102a, 102b, ..., 102n), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0042] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0043] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the flow control method in the embodiments of this application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the above-mentioned flow control method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0044] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0045] The display may be a touchscreen LCD display that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0046] Under the aforementioned operating environment, this application provides the following: Figure 2 The flow control method shown. Figure 2 This is the flow chart of the flow control method according to Embodiment 1 of this application. Figure 1 The method includes:
[0047] Step S201: Receive the first traffic data and obtain the target traffic feature information corresponding to the first traffic data.
[0048] Optionally, the first traffic data can be received, for example, through a proxy deployed at the network ingress. The first traffic data can be request data from the web client and the app client. In practical applications, when a user initiates external access through the web client or the app client, the access request (i.e., the aforementioned first traffic data) is transmitted to the application firewall engine; therefore, the first traffic data can be received through the application firewall engine.
[0049] After receiving the first traffic data, the application firewall engine can calculate the target traffic characteristic information corresponding to the first traffic data in real time. For example, the target traffic characteristic information includes, but is not limited to, IP address, device ID, APP environment information, or browser environment information.
[0050] Step S202: Anomaly detection is performed on the target traffic feature information according to the target traffic detection rules to obtain a first detection result. The target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through the target natural language model. The first detection result is used to indicate whether there is a risk in the first traffic data.
[0051] Optionally, after obtaining the target traffic feature information corresponding to the first traffic data, the application firewall engine performs anomaly detection on the target traffic feature information according to the target traffic detection rules. For example, it matches the traffic feature information according to the risk features in the target traffic detection rules to determine whether there are risk features in the target traffic feature information.
[0052] It should be noted that the target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model. For example, based on a large-scale pre-trained language model, the target natural language model is fine-tuned by introducing expert knowledge in the field of cybersecurity and historical attack data. Then, the real traffic data is input into the target natural language model, and finally, a set of target traffic detection rules is generated through the target natural language model.
[0053] In an alternative embodiment, these targeted traffic detection rules can be specific traffic patterns, threat detection logic, or anomalous behavior. For example, a targeted traffic detection rule could be to consider traffic containing the identifier of an automated tool as risky traffic. Another example is determining the risk of initial traffic data by detecting specific "Headless" flags or "web driver" attributes in a web browser.
[0054] Step S203: Based on the first detection result, determine the processing strategy for the first traffic data, wherein the processing strategy is used to control the first traffic data.
[0055] Optionally, based on the first detection result, a corresponding processing strategy is determined, such as allowing traffic, issuing warnings, or blocking traffic. Actions are taken on the traffic according to the established strategy, such as conducting in-depth inspections of suspicious traffic and blocking identified malicious traffic.
[0056] In summary, after receiving the first traffic data, the corresponding target traffic feature information is obtained. Then, anomaly detection is performed on the target traffic feature information using target traffic detection rules. Based on the first detection result, the processing strategy for the first traffic data is determined. The target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data using a target natural language model. Compared with the fixed rules in the prior art, the target natural language model can understand and learn the complexity of traffic, and can generate more flexible and adaptable target traffic detection rules. This allows the target traffic detection rules to more accurately identify risky traffic, thereby achieving the technical effect of reducing the false positive and false negative rates.
[0057] Obtaining the target traffic detection rules is crucial. Therefore, in the traffic control method provided in Embodiment 1 of this application, before performing anomaly detection on the target traffic feature information according to the target traffic detection rules and obtaining the first detection result, the method further includes: obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine; constructing target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether there is anomaly in the real traffic data based on the real traffic feature information, and generating traffic detection rules when there is anomaly in the real traffic data; and processing the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0058] Optionally, the above target traffic detection rules can be obtained using the following steps: In practical applications, when users initiate external access via the web or app, the access request (i.e., the first traffic data mentioned above) is transmitted to the application firewall engine. Therefore, the real traffic characteristic information corresponding to the real traffic data can be collected through the log files of the application firewall engine. For example, a data extraction module can be deployed to collect log files. These log files contain all request data passing through the firewall, including but not limited to HTTP / HTTPS request headers, request parameters, user IP, session ID, user agent, and other information.
[0059] It should be noted that, due to the massive volume of network requests, user behavior, and potential threat data, a streaming computing engine can be used to read log files in order to improve the efficiency of obtaining real traffic characteristic information and subsequent processing.
[0060] After obtaining the actual traffic characteristics, corresponding target prompts are constructed. For example, the target prompt could be "actual traffic characteristics; based on the above information, output rules for detecting anomalies." Then, the target prompts are input into a target natural language model (NLP). Finally, the target NLP processes the target prompts to obtain target traffic detection rules. The target NLP can leverage its knowledge in the cybersecurity field, based on the traffic characteristics in the prompts, to generate traffic detection rules that describe the anomaly detection logic.
[0061] By leveraging the powerful analytical capabilities of the target natural language model and combining it with real-time traffic data from the application firewall engine, traffic detection rules can be generated, effectively improving the efficiency and accuracy of network protection.
[0062] To improve the accuracy of the natural language model output, the flow control method provided in Embodiment 1 of this application constructs target prompt information based on real flow characteristic information, including: determining the meaning information corresponding to the feature information in the real flow characteristic information; obtaining the constraints on the output result of the target natural language model; and combining the meaning information, real flow characteristic information and constraints to obtain the target prompt information.
[0063] Optionally, to improve the accuracy of the natural language model's output, some relevant knowledge can be explained, namely, determining the meaning of the features in the real traffic characteristic information, i.e., what the meaning of the field corresponding to each feature is. For example, the User-Agent field not only reflects the type of browser or client software, but also the identifier of the automated tool, whose abnormal patterns may include missing header information. Understanding the meaning of the features helps the model accurately identify which feature combinations indicate potential automated attack behavior. Without a clear understanding of the meaning of the features, the rules generated by the natural language model may lack specificity and effectiveness.
[0064] To further improve the accuracy of the natural language model's output, the output of the target natural language model can be restricted. This involves imposing constraints on the target model's output, such as limiting it to JSON-formatted fields and prohibiting the output of additional analysis content and suggestions. Finally, the semantic information, real traffic characteristics, and constraints are assembled to obtain the aforementioned target prompt information.
[0065] In an optional embodiment, the target prompt information is as follows:
[0066] #Roles
[0067] You are an Ant i-Bot security expert, proficient in various attack countermeasures against app-side attacks. Please try to analyze whether there are any anomalies in the data collected by the appsdk environment. The following is relevant knowledge you can refer to: meaning of appsdk fields ${Retr ieva l_GjzU.resu lt.chunkLi st.[content]};
[0068] When data arrives, first, based on the meaning of each data collection point in the app SDK in the knowledge base, then combine your expert knowledge to determine whether it is an anomaly, and provide attack and defense detection rules.
[0069] #Ski ll
[0070] Proficient in various data scraping methods and detection techniques in the Ant i-Bot field, and able to accurately identify suspicious features. Experienced expert, adept at analyzing abnormal data from different devices and generating detection rules.
[0071] #Limits
[0072] - Minimize Anti-Crawling Rules: When writing rules, minimize the identified attack characteristics to reduce the risk of false positives.
[0073] - Output format is as follows:
[0074] 1. Use "benign" or "malicious" to describe whether something is abnormal, and denote it as the "result" field.
[0075] 2. The final result is scored from 0 to 100 based on the severity of the attack. A non-malicious attack receives 0 points, and a confirmed malicious attack receives 100 points. This score is recorded in the "score" field.
[0076] 3. Output rules that can detect outliers; denoted as the rules field.
[0077] 4. Output your reasoning for your judgment. A brief description is sufficient, not exceeding 20 characters. Record this as the `desc` field.
[0078] 5. Package the above fields into a JSON format.
[0079] 6. Output content restrictions: Only fields in JSON format are allowed for output. Additional analysis content and recommendations are prohibited.
[0080] 7. Output rule restriction: Only output the rule with the most obvious attack characteristics.
[0081] By clearly defining the meaning of features and defining output constraints, the intelligent analysis capabilities of LLM can be fully utilized to generate traffic detection rules that meet actual needs and are easy to execute, effectively improving the efficiency and accuracy of network security protection.
[0082] To improve the accuracy of target traffic detection rules, the traffic control method provided in Embodiment 1 of this application processes target prompt information using a target natural language model to obtain target traffic detection rules. This includes: parsing the target prompt information using the target natural language model to obtain initial traffic detection rules; performing anomaly detection on second traffic data based on the initial traffic detection rules to obtain a second detection result, wherein the second detection result is used to characterize whether the second traffic data is abnormal; determining a first hit rate and a first hit distribution information corresponding to the initial traffic detection rules based on the second detection result and the actual detection result corresponding to the second traffic data; and adjusting the initial traffic detection rules based on the first hit rate and the first hit distribution information to obtain target traffic detection rules.
[0083] Optionally, the target prompt information is input into the target natural language model, which then outputs initial traffic detection rules. These rules may include conditional statements, trigger thresholds, and security decision logic. After obtaining the initial traffic detection rules, they can be applied to the application firewall engine to perform anomaly detection on the second traffic data to obtain the second detection result. Alternatively, traffic data from a real network environment can be collected, and then this initial traffic data can be used to perform anomaly detection on the traffic data in the real network environment to obtain the second detection result.
[0084] Then, based on the second detection result and the actual detection result corresponding to the second traffic data, the first hit rate and first hit distribution information corresponding to the initial traffic detection rule are determined. It should be noted that the first hit rate can be the ratio of the number of correctly identified anomalies to the total number of actual abnormal traffic. The first hit distribution information can be the distribution ratio of abnormal and normal outbound access initiated by a certain object; for example, out of 100 outbound accesses initiated by a certain object, 80% are normal accesses and 20% are abnormal accesses. It should also be noted that the actual detection result can be a detection result based on expert experience.
[0085] The initial traffic detection rules are adjusted based on the first hit rate and the first hit distribution information to obtain the target traffic detection rules. For example, if the hit rate is lower than expected, the logic of the rules may need to be analyzed, and more conditions may need to be added or thresholds adjusted to improve the accuracy of anomaly detection. Alternatively, the rule can be deleted. As another example, if the hit distribution information is abnormal—for example, out of 100 outbound accesses initiated by a certain object, 80% are abnormal accesses and 20% are normal accesses—this indicates that the traffic detection rule is abnormal and needs to be deleted.
[0086] In an optional embodiment, security experts can also manually review the initially optimized rules based on their domain knowledge and experience to further ensure the rationality and security of the rules.
[0087] By automatically understanding and generating initial traffic detection rules based on target prompts using a target natural language model, the need for traditional manual rule writing is greatly reduced, and the efficiency of rule generation is improved. The first hit rate and first hit distribution information fed back by the second detection results can significantly improve the accuracy and generalization ability of the rules, reduce false positives and false negatives, and enable the rules to better adapt to the ever-changing network environment and attack patterns.
[0088] In the traffic control method provided in Embodiment 1 of this application, before obtaining initial traffic feature information by collecting features from the log file through the streaming computing engine, the method further includes: when receiving real traffic data of external access, processing the real traffic data through the application firewall engine to obtain real traffic feature information corresponding to the real traffic data; encoding and compressing the traffic feature information to obtain string information; and generating a log file based on the string information.
[0089] Optionally, when receiving real traffic data from the network interface, the application firewall engine processes the real traffic data. For example, it extracts key traffic characteristic information such as user-agent, source IP address, access frequency, access time, HTTP header information, URL path, cookies, device ID, and app environment information. To reduce storage space and transmission bandwidth, the application firewall engine encodes and compresses the extracted traffic characteristic information. For example, it converts the traffic characteristic information into string encoding, and then uses data compression technology to compress the string to obtain the aforementioned string information. Finally, it generates a log file based on the string information, for example, recording the string information in the log file.
[0090] Through the above process, the application firewall engine can efficiently and accurately process and record traffic data, laying a solid data foundation for building an intelligent network security protection system. These log files can also be used to train and fine-tune large-scale language models, enabling them to better understand and generate intelligent detection rules applicable to real-world traffic environments, thereby improving the efficiency and accuracy of network security protection.
[0091] To improve the efficiency of obtaining real traffic feature information, in the traffic control method provided in Embodiment 1 of this application, obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine includes: collecting features from the log file through a streaming computing engine to obtain initial traffic feature information; filtering the initial traffic feature information according to a preset time sliding window to obtain first traffic feature information; and filtering the first traffic feature information according to historical traffic detection rules to obtain real traffic feature information.
[0092] Optionally, given the massive volume of network requests, user behavior, and potential threat data, a streaming computing engine can be used to collect log files in a bypass manner to improve the efficiency of acquiring real traffic characteristic information and subsequent processing. The streaming computing engine can efficiently process continuously generated data streams, ensuring the real-time and continuous nature of data processing. The streaming computing engine reads log files generated by the firewall engine and extracts data related to traffic characteristics, such as access frequency, IP address, User-Agent, request URL, and device information.
[0093] Having obtained the initial traffic characteristic information, since a single access request can correspond to multiple traffic data points within a short period, to improve the efficiency of subsequent model usage, the initial traffic characteristic information can be filtered through a preset time sliding window to obtain the first traffic characteristic information. For example, within the preset time sliding window, if some traffic entries have the same IP address, access domain name, and User Agent, only one of them is retained. In an optional embodiment, the preset time sliding window can also be used to eliminate noise and short-term random fluctuations.
[0094] After obtaining the initial traffic characteristic information, it can be filtered using historical traffic detection rules to obtain the true traffic characteristic information. It should be noted that the historical traffic detection rules can be existing rule sets used to identify abnormal traffic. Filtering traffic data based on existing rules reduces redundant data and optimizes subsequent processing performance.
[0095] The screening process improves the efficiency of data analysis, reduces the computational burden on the target natural language model, and helps to more accurately identify and respond to new threats, thereby enhancing the overall level of cybersecurity protection.
[0096] To improve the accuracy of the preset time sliding window, in the flow control method provided in Embodiment 1 of this application, the initial flow feature information is filtered according to the preset time sliding window to obtain the first flow feature information, including: determining the device type of the device that triggers the real flow data; determining the time range corresponding to the preset time sliding window according to the device type; and filtering the initial flow feature information according to the time range to obtain the first flow feature information.
[0097] Optionally, first determine the device type of the device that triggers the real traffic data, for example, whether the device type is web or app. Then, based on the device type, determine the time range corresponding to the preset time sliding window. For example, if the stability of the app is higher than that of the web, the time sliding window corresponding to the app can be set to be longer, for example, one hour, while the time sliding window corresponding to the web can be set to be shorter, for example, half an hour.
[0098] After determining the time range of the time sliding window, the streaming computing engine will filter the initial traffic feature information extracted from the log file. For example, within the preset time range, if some traffic has the same IP, access domain name, and User Agent, only one will be retained.
[0099] Based on the characteristics and behavior patterns of different devices, a time-sliding window can be customized to more effectively filter and analyze traffic data, thereby improving the targeting and real-time nature of security protection.
[0100] To improve the accuracy of subsequent abnormal traffic detection, in the traffic control method provided in Embodiment 1 of this application, after determining the processing strategy for the first traffic data based on the first detection result, the method further includes: if an update instruction for the target traffic detection rule is received, determining the second hit rate and second hit distribution information corresponding to the target traffic detection rule based on the first detection result and the actual detection result corresponding to the first traffic data; adjusting the target traffic detection rule according to the second hit rate and second hit distribution information to obtain the adjusted target traffic detection rule; when receiving third traffic data, filtering the traffic feature information corresponding to the third traffic data according to the adjusted target traffic detection rule to obtain the second traffic feature information; processing the second traffic feature information through a target natural language model to obtain an updated traffic detection rule, and updating the adjusted target traffic detection rule according to the updated traffic detection rule to obtain the updated target traffic detection rule.
[0101] Optionally, since the methods of abnormal attacks are varied in practical applications, it is necessary to update and iterate the target traffic detection rules appropriately. Specifically, if an update instruction for the target traffic detection rules is received by user or timed trigger, the second hit rate and second hit distribution information corresponding to the target traffic detection rules are determined based on the first detection result, and then the target traffic detection rules are adjusted to obtain the adjusted target traffic detection rules.
[0102] Upon receiving third-party traffic data, the system first filters the traffic feature information corresponding to the third-party traffic data using the adjusted target traffic detection rules. Specifically, it deletes third-party traffic data that can be identified as problematic. Then, the target natural language model processes the second-party traffic feature information to obtain updated traffic detection rules. These updated rules are then used to update the adjusted target traffic detection rules, resulting in updated target traffic detection rules. Further analysis and learning by the target natural language model generate updated target traffic detection rules. The target natural language model can understand potential attack patterns based on the latest feature information, generating or optimizing detection rules to ensure their continued effectiveness and adaptability.
[0103] In an alternative embodiment, it can be achieved through, as follows: Figure 3 The flowchart shown illustrates the generation of target traffic detection rules, specifically including: (1) Traffic input: collecting request data from calls to the Web SDK and App SDK (i.e., ... Figure 3 (The total network traffic in China).
[0104] (2) Data preprocessing:
[0105] a. Data Feature Extraction / Calculation: The application firewall engine calculates the collected items of real-time traffic data (i.e., traffic feature information, such as IP, device ID, APP environment information / browser environment information, etc.), and then mounts the script to the streaming computing engine platform to automatically parse the Web SDK collected information into specific feature items.
[0106] b. Scrolling window filtering: By using a time-sliding window mechanism, grouping by IP, access domain name, and User Agent, the required number of LLM calls is reduced, and noise and short-term random fluctuations are eliminated.
[0107] c. Rule-based filtering: Based on existing rules, traffic data is filtered to reduce redundant data and optimize subsequent processing performance.
[0108] (3) LLM (the natural language model mentioned above) call:
[0109] a. Knowledge Base Fine-tuning: Provide explanations for LLM-related knowledge, such as the meaning of data collection fields in the Web SDK and App SDK. Through knowledge input, ensure the LLM's output logic is relevant.
[0110] b. Input / Output Constraints: Design a Prompt project to define the constraints on the model's input format and output results, ensuring the accuracy and usability of the model's output.
[0111] (4) LLM analysis:
[0112] a. Intelligent rule generation: Combines LLM analysis results to dynamically generate efficient Ant i-Bot protection rules.
[0113] b. Hit Distribution Verification: Verify the hit rate and distribution of the generated rules to actual traffic to ensure the accuracy of the rules.
[0114] c. Expert Validation: Provides an expert validation process, where the validity and security of the rules are manually reviewed based on domain knowledge.
[0115] (5) Upper limit of atomic ability:
[0116] a. The validated rules are converted into atomic defense capabilities and applied to the production environment in real time.
[0117] b. Feedback mechanism:
[0118] Filtering funnel optimization: Utilize the traffic hit results fed back from the online rules to optimize the filtering strategy and reduce the proportion of low-value data entering the LLM analysis module.
[0119] Reduced LLM call volume: Streamlined input traffic and analysis logic, reduced LLM call costs, and improved overall efficiency.
[0120] By combining the above solutions with the real-time characteristics of a streaming computing engine, the system significantly improves its ability to handle massive traffic volumes, ensuring the efficiency of data preprocessing and LLM calls. The sliding window and rule-based filtering mechanisms effectively reduce the computational load of unnecessary data, improving overall system performance. Based on the adaptive analysis capabilities of LLM, protection rules are dynamically generated, with significantly higher accuracy and applicability than traditional clustering and supervised learning schemes. The system supports rapid response to new types of attacks, resolving the rule lag issue in traditional solutions. A feedback mechanism optimizes the filtering logic, reducing the number of LLM calls and significantly lowering computational resource consumption.
[0121] In the traffic control method provided in Embodiment 1 of this application, before processing the target prompt information through the target natural language model to obtain the target traffic detection rules, the method further includes: acquiring domain knowledge information for traffic protection; and training the initial natural language model through the domain knowledge information to obtain the target natural language model.
[0122] Optionally, the target natural language model can be obtained using the following steps: Acquire domain knowledge information related to traffic protection. It should be noted that domain knowledge information refers to professional knowledge and experience related to network security traffic protection, including but not limited to: Malicious traffic characteristics: such as the behavioral patterns of common automated attack methods; Protection strategies: including known effective protection rules, strategies for dealing with different attack types, and best practices summarized by security experts; Attack cases: record historical attack events, including the source, process, result, and countermeasures taken.
[0123] The initial natural language model is trained using domain knowledge information to obtain the target natural language model. It should be noted that the initial natural language model refers to a model with basic language understanding and generation capabilities. To enable the model to understand and handle specific tasks in the traffic protection domain, it needs to be fine-tuned, i.e., retrained using domain knowledge information related to traffic protection. For example, domain knowledge data can be used as the training set to fine-tune the initial natural language model, allowing it to learn specific knowledge and patterns in the traffic protection domain.
[0124] The above steps enable natural language models to quickly acquire specific knowledge in the field of traffic protection and have the ability to identify traffic anomalies.
[0125] In an alternative embodiment, it can also be achieved through methods such as Figure 4 The flowchart shown illustrates accurate traffic control, specifically including the following steps: An application firewall engine continuously receives network request data for a specific e-commerce website. When network request data arrives, the application firewall engine calculates the data collection items (such as IP address, device ID, app environment information / browser environment information, etc.). Then, target traffic detection rules trained by the target natural language model are used to perform anomaly detection on the data collection items to obtain detection results. Finally, a handling strategy for the network request data is determined based on the detection results.
[0126] In the traffic control method provided in Embodiment 1 of this application, first traffic data is received and target traffic feature information corresponding to the first traffic data is obtained; anomaly detection is performed on the target traffic feature information according to the target traffic detection rule to obtain a first detection result, wherein the target traffic detection rule is obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model, and the first detection result is used to indicate whether the first traffic data has a risk; based on the first detection result, a processing strategy for the first traffic data is determined, wherein the processing strategy is used to control the first traffic data, which solves the technical problem in related technologies that traffic control is achieved by manually defined abnormal traffic detection rules, resulting in relatively low accuracy of traffic control. In this solution, after receiving the first traffic data, the corresponding target traffic feature information is obtained. Then, anomaly detection is performed on the target traffic feature information using target traffic detection rules. Based on the first detection result, the processing strategy for the first traffic data is determined. The target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data using a target natural language model. Compared with the fixed rules in the prior art, the target natural language model can understand and learn the complexity of traffic, and can generate more flexible and adaptable target traffic detection rules. This allows the target traffic detection rules to more accurately identify risky traffic, thereby achieving the technical effect of reducing the false alarm rate and the false alarm rate.
[0127] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0128] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.
[0129] Example 2
[0130] According to embodiments of this application, a flow control device for implementing the above-described flow control method is also provided, such as... Figure 5 As shown, the device includes: a receiving unit 501, a detection unit 502, and a first determining unit 503.
[0131] The receiving unit 501 is used to receive the first traffic data and obtain the target traffic feature information corresponding to the first traffic data;
[0132] The detection unit 502 is used to perform anomaly detection on the target traffic feature information according to the target traffic detection rule and obtain a first detection result. The target traffic detection rule is obtained by processing the real traffic feature information corresponding to the real traffic data through the target natural language model. The first detection result is used to indicate whether the first traffic data has any risk.
[0133] The first determining unit 503 is used to determine a processing strategy for the first traffic data based on the first detection result, wherein the processing strategy is used to control the first traffic data.
[0134] In the flow control device provided in Embodiment 2 of this application, a receiving unit 501 receives first flow data and obtains target flow feature information corresponding to the first flow data; a detection unit 502 performs anomaly detection on the target flow feature information according to the target flow detection rule to obtain a first detection result, wherein the target flow detection rule is obtained by processing the real flow feature information corresponding to the real flow data through a target natural language model, and the first detection result is used to indicate whether the first flow data has a risk; a first determining unit 503 determines a processing strategy for the first flow data based on the first detection result, wherein the processing strategy is used to control the first flow data, which solves the technical problem in the related art that flow control is achieved by manually defined abnormal flow detection rules, resulting in relatively low accuracy of flow control. In this solution, after receiving the first traffic data, the corresponding target traffic feature information is obtained. Then, anomaly detection is performed on the target traffic feature information using target traffic detection rules. Based on the first detection result, the processing strategy for the first traffic data is determined. The target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data using a target natural language model. Compared with the fixed rules in the prior art, the target natural language model can understand and learn the complexity of traffic, and can generate more flexible and adaptable target traffic detection rules. This allows the target traffic detection rules to more accurately identify risky traffic, thereby achieving the technical effect of reducing the false alarm rate and the false alarm rate.
[0135] Optionally, in the traffic control device provided in Embodiment 2 of this application, the device further includes: a first acquisition unit, configured to acquire real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine before performing anomaly detection on the target traffic feature information according to the target traffic detection rules and obtaining the first detection result; a construction unit, configured to construct target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether there is anomaly in the real traffic data based on the real traffic feature information, and to generate traffic detection rules when there is anomaly in the real traffic data; and a first processing unit, configured to process the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0136] Optionally, in the flow control device provided in Embodiment 2 of this application, the construction unit includes: a first determining module, used to determine the meaning information corresponding to the feature information in the real flow feature information; an acquisition module, used to acquire the constraint conditions of the output result of the target natural language model; and a construction module, used to combine the meaning information, the real flow feature information and the constraint conditions to obtain the target prompt information.
[0137] Optionally, in the flow control device provided in Embodiment 2 of this application, the processing unit includes: a processing module, used to parse the target prompt information through a target natural language model to obtain an initial flow detection rule; a detection module, used to perform anomaly detection on the second flow data according to the initial flow detection rule to obtain a second detection result, wherein the second detection result is used to characterize whether the second flow data is abnormal; a second determination module, used to determine the first hit rate and the first hit distribution information corresponding to the initial flow detection rule based on the second detection result and the actual detection result corresponding to the second flow data; and an adjustment module, used to adjust the initial flow detection rule according to the first hit rate and the first hit distribution information to obtain a target flow detection rule.
[0138] Optionally, in the flow control device provided in Embodiment 2 of this application, the first acquisition unit includes: a collection module, used to collect features from log files through a streaming computing engine to obtain initial flow feature information; a first filtering module, used to filter the initial flow feature information according to a preset time sliding window to obtain first flow feature information; and a second filtering module, used to filter the first flow feature information according to historical flow detection rules to obtain real flow feature information.
[0139] Optionally, in the traffic control device provided in Embodiment 2 of this application, the device further includes: a second processing unit, used to process the real traffic data through an application firewall engine to obtain real traffic feature information corresponding to the real traffic data when receiving real traffic data of external access before obtaining initial traffic feature information by collecting features from the log file through the streaming computing engine; a third processing unit, used to encode and compress the traffic feature information to obtain string information; and a generation unit, used to generate a log file based on the string information.
[0140] Optionally, in the flow control device provided in Embodiment 2 of this application, the first filtering module includes: a first determining submodule, used to determine the device type of the device that triggers the real flow data; a second determining submodule, used to determine the time range corresponding to the preset time sliding window based on the device type; and a filtering submodule, used to filter the initial flow characteristic information based on the time range to obtain the first flow characteristic information.
[0141] Optionally, in the flow control device provided in Embodiment 2 of this application, the device further includes: a second determining unit, configured to, after determining the processing strategy for the first flow data based on the first detection result, if an update instruction for the target flow detection rule is received, determine the second hit rate and the second hit distribution information corresponding to the target flow detection rule based on the first detection result and the actual detection result corresponding to the first flow data; an adjusting unit, configured to adjust the target flow detection rule based on the second hit rate and the second hit distribution information to obtain the adjusted target flow detection rule; a filtering unit, configured to, when receiving the third flow data, filter the flow feature information corresponding to the third flow data based on the adjusted target flow detection rule to obtain the second flow feature information; and a processing unit, configured to process the second flow feature information through a target natural language model to obtain an updated flow detection rule, and update the adjusted target flow detection rule based on the updated flow detection rule to obtain the updated target flow detection rule.
[0142] Optionally, in the traffic control device provided in Embodiment 2 of this application, the device further includes: a second acquisition unit, used to acquire domain knowledge information for traffic protection before processing the target prompt information through the target natural language model to obtain the target traffic detection rules; and a training unit, used to train the initial natural language model through the domain knowledge information to obtain the target natural language model.
[0143] It should be noted that the receiving unit 501, the detection unit 502, and the first determining unit 503 mentioned above correspond to steps S201 to S203 in Embodiment 1. The three units and the corresponding steps implement the same examples and application scenarios, but are not limited to the content disclosed in Embodiment 1. It should also be noted that the above modules, as part of the device, can run in the computer terminal 10 provided in Embodiment 1.
[0144] It should be noted that the preferred implementation schemes involved in the above embodiments of this application are the same as the schemes, application scenarios and implementation processes provided in Embodiment 1, but are not limited to the schemes provided in Embodiment 1.
[0145] Example 3
[0146] Embodiments of this application may provide an electronic device, which may be any one of a group of electronic device terminals. Optionally, in this embodiment, the aforementioned electronic device may also be replaced by a terminal device such as a mobile terminal.
[0147] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.
[0148] In this embodiment, the above-mentioned electronic device can execute the program code of the following steps in the flow control method: receiving first flow data and obtaining target flow feature information corresponding to the first flow data; performing anomaly detection on the target flow feature information according to the target flow detection rule to obtain a first detection result, wherein the target flow detection rule is obtained by processing the real flow feature information corresponding to the real flow data through a target natural language model, and the first detection result is used to indicate whether the first flow data has a risk; and determining a processing strategy for the first flow data based on the first detection result, wherein the processing strategy is used to control the first flow data.
[0149] The aforementioned electronic device can execute the program code for the following steps in the traffic control method: before performing anomaly detection on the target traffic feature information according to the target traffic detection rules and obtaining the first detection result, the method further includes: obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine; constructing target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether there is anomaly in the real traffic data based on the real traffic feature information, and generating traffic detection rules when there is anomaly in the real traffic data; and processing the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0150] The aforementioned electronic device can execute the program code for the following steps in the flow control method: constructing target prompt information based on real flow characteristic information, including: determining the meaning information corresponding to the feature information in the real flow characteristic information; obtaining the constraints on the output results of the target natural language model; and combining the meaning information, real flow characteristic information, and constraints to obtain the target prompt information.
[0151] The aforementioned electronic device can execute the following steps in the flow control method: processing the target prompt information through a target natural language model to obtain target flow detection rules, including: parsing the target prompt information through the target natural language model to obtain initial flow detection rules; performing anomaly detection on second flow data according to the initial flow detection rules to obtain a second detection result, wherein the second detection result is used to characterize whether the second flow data is abnormal; determining the first hit rate and first hit distribution information corresponding to the initial flow detection rules based on the second detection result and the actual detection result corresponding to the second flow data; adjusting the initial flow detection rules according to the first hit rate and first hit distribution information to obtain target flow detection rules.
[0152] The aforementioned electronic device can execute the program code for the following steps in the flow control method: obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine, including: collecting features from the log file through the streaming computing engine to obtain initial traffic feature information; filtering the initial traffic feature information according to a preset time sliding window to obtain first traffic feature information; and filtering the first traffic feature information according to historical traffic detection rules to obtain real traffic feature information.
[0153] The aforementioned electronic device can execute the program code for the following steps in the flow control method: before obtaining initial flow characteristic information by collecting features from the log file through the streaming computing engine, the method further includes: when receiving real flow data from external access, processing the real flow data through the application firewall engine to obtain real flow characteristic information corresponding to the real flow data; encoding and compressing the flow characteristic information to obtain string information; and generating a log file based on the string information.
[0154] The aforementioned electronic device can execute the program code for the following steps in the flow control method: filtering initial flow characteristic information according to a preset time sliding window to obtain first flow characteristic information, including: determining the device type of the device that triggers the real flow data; determining the time range corresponding to the preset time sliding window according to the device type; filtering the initial flow characteristic information according to the time range to obtain first flow characteristic information.
[0155] The aforementioned electronic device can execute the following steps of the flow control method: After determining the processing strategy for the first flow data based on the first detection result, the method further includes: if an update instruction for the target flow detection rule is received, determining the second hit rate and second hit distribution information corresponding to the target flow detection rule based on the first detection result and the actual detection result corresponding to the first flow data; adjusting the target flow detection rule based on the second hit rate and second hit distribution information to obtain the adjusted target flow detection rule; when receiving third flow data, filtering the flow feature information corresponding to the third flow data based on the adjusted target flow detection rule to obtain the second flow feature information; processing the second flow feature information through a target natural language model to obtain the updated flow detection rule, and updating the adjusted target flow detection rule based on the updated flow detection rule to obtain the updated target flow detection rule.
[0156] The aforementioned electronic device can execute the program code for the following steps in the flow control method: before processing the target prompt information through the target natural language model to obtain the target flow detection rules, the method further includes: acquiring domain knowledge information for flow protection; training the initial natural language model through the domain knowledge information to obtain the target natural language model.
[0157] Optionally, Figure 6 This is a structural block diagram of an electronic device according to an embodiment of this application. Figure 6 As shown, the electronic device 60 may include: one or more ( Figure 6 (Only one is shown) Processor 602 and memory 604. The electronic device 60 may also include a memory controller to control and manage the memory 604; the electronic device 60 may also include a peripheral interface to connect to a radio frequency module, an audio module, and a display screen, etc.
[0158] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the flow control method and apparatus in this application embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the aforementioned flow control method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the electronic device 60 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0159] The processor can invoke information and application programs stored in the memory through the transmission device to perform the following steps: receiving first traffic data and obtaining target traffic feature information corresponding to the first traffic data; performing anomaly detection on the target traffic feature information according to the target traffic detection rules to obtain a first detection result, wherein the target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model, and the first detection result is used to indicate whether the first traffic data has a risk; and determining a processing strategy for the first traffic data based on the first detection result, wherein the processing strategy is used to control the first traffic data.
[0160] Optionally, the processor may also execute program code for the following steps: before performing anomaly detection on the target traffic feature information according to the target traffic detection rules and obtaining the first detection result, the method further includes: obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine; constructing target prompt information based on the real traffic feature information, wherein the target prompt information is used to instruct the target natural language model to determine whether there is anomaly in the real traffic data based on the real traffic feature information, and generating traffic detection rules when there is anomaly in the real traffic data; and processing the target prompt information through the target natural language model to obtain the target traffic detection rules.
[0161] Optionally, the processor may also execute program code that performs the following steps: constructing target prompt information based on real traffic feature information, including: determining the meaning information corresponding to the feature information in the real traffic feature information; obtaining the constraints on the output of the target natural language model; and combining the meaning information, real traffic feature information and constraints to obtain the target prompt information.
[0162] Optionally, the processor may also execute program code with the following steps: processing the target prompt information through the target natural language model to obtain target traffic detection rules, including: parsing the target prompt information through the target natural language model to obtain initial traffic detection rules; performing anomaly detection on the second traffic data according to the initial traffic detection rules to obtain a second detection result, wherein the second detection result is used to characterize whether the second traffic data is abnormal; determining the first hit rate and first hit distribution information corresponding to the initial traffic detection rules based on the second detection result and the actual detection results corresponding to the second traffic data; adjusting the initial traffic detection rules according to the first hit rate and the first hit distribution information to obtain target traffic detection rules.
[0163] Optionally, the processor may also execute program code that performs the following steps: obtaining real traffic feature information corresponding to real traffic data based on the log file corresponding to the application firewall engine, including: collecting features from the log file through the streaming computing engine to obtain initial traffic feature information; filtering the initial traffic feature information according to a preset time sliding window to obtain first traffic feature information; and filtering the first traffic feature information according to historical traffic detection rules to obtain real traffic feature information.
[0164] Optionally, the processor may also execute program code for the following steps: before obtaining initial traffic feature information by collecting features from the log file through the streaming computing engine, the method further includes: when receiving real traffic data from external access, processing the real traffic data through the application firewall engine to obtain real traffic feature information corresponding to the real traffic data; encoding and compressing the traffic feature information to obtain string information; and generating a log file based on the string information.
[0165] Optionally, the processor may also execute program code that performs the following steps: filtering initial traffic feature information according to a preset time sliding window to obtain first traffic feature information, including: determining the device type of the device that triggers the real traffic data; determining the time range corresponding to the preset time sliding window according to the device type; filtering the initial traffic feature information according to the time range to obtain first traffic feature information.
[0166] Optionally, the processor may also execute program code with the following steps: After determining the processing strategy for the first traffic data based on the first detection result, the method further includes: if an update instruction for the target traffic detection rule is received, determining the second hit rate and second hit distribution information corresponding to the target traffic detection rule based on the first detection result and the actual detection result corresponding to the first traffic data; adjusting the target traffic detection rule according to the second hit rate and second hit distribution information to obtain the adjusted target traffic detection rule; when receiving the third traffic data, filtering the traffic feature information corresponding to the third traffic data according to the adjusted target traffic detection rule to obtain the second traffic feature information; processing the second traffic feature information through the target natural language model to obtain the updated traffic detection rule, and updating the adjusted target traffic detection rule according to the updated traffic detection rule to obtain the updated target traffic detection rule.
[0167] Optionally, the processor may also execute program code for the following steps: before processing the target prompt information through the target natural language model to obtain the target traffic detection rules, the method further includes: acquiring domain knowledge information for traffic protection; training the initial natural language model through the domain knowledge information to obtain the target natural language model.
[0168] Those skilled in the art will understand that Figure 6 The structure shown is for illustrative purposes only. Electronic device 60 can also be a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet Device (MID), a PAD, and other terminal devices. Figure 6 This does not limit the structure of the aforementioned electronic device. For example, electronic device 60 may also include components that are more... Figure 6 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 6 The different configurations shown.
[0169] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0170] Example 4
[0171] Embodiments of this application also provide a computer program product. Optionally, in this embodiment, the computer program product can be used to store the program code executed by the flow control method provided in Embodiment 1.
[0172] Optionally, in this embodiment, the computer program product may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0173] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0174] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0175] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0176] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0177] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0178] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0179] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A flow control method, characterized in that, include: Receive first traffic data and obtain target traffic feature information corresponding to the first traffic data; Anomaly detection is performed on the target traffic feature information according to the target traffic detection rules to obtain a first detection result. The target traffic detection rules are obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model. The first detection result is used to indicate whether the first traffic data has any risk. Based on the first detection result, a processing strategy for the first traffic data is determined, wherein the processing strategy is used to control the first traffic data.
2. The method according to claim 1, characterized in that, Before performing anomaly detection on the target traffic feature information according to the target traffic detection rules to obtain the first detection result, the method further includes: Based on the log files corresponding to the application firewall engine, obtain the real traffic characteristic information corresponding to the real traffic data; Based on the real traffic feature information, target prompt information is constructed, wherein the target prompt information is used to instruct the target natural language model to determine whether there is anomaly in the real traffic data based on the real traffic feature information, and to generate traffic detection rules if there is anomaly in the real traffic data; The target prompt information is processed by the target natural language model to obtain the target traffic detection rule.
3. The method according to claim 2, characterized in that, Based on the actual traffic characteristics, the target prompt information is constructed as follows: Determine the meaning information corresponding to the feature information in the real traffic feature information; Obtain the constraints on the output of the target natural language model; The target prompt information is obtained by combining the meaning information, the actual traffic characteristic information, and the constraint conditions.
4. The method according to claim 2, characterized in that, The target prompt information is processed by the target natural language model to obtain the target traffic detection rules, including: The target prompt information is parsed using the target natural language model to obtain initial traffic detection rules; Anomaly detection is performed on the second traffic data according to the initial traffic detection rules to obtain a second detection result, wherein the second detection result is used to characterize whether there is anomaly in the second traffic data; Based on the second detection result and the actual detection result corresponding to the second traffic data, the first hit rate and the first hit distribution information corresponding to the initial traffic detection rule are determined; The initial traffic detection rule is adjusted based on the first hit rate and the first hit distribution information to obtain the target traffic detection rule.
5. The method according to any one of claims 2 to 4, characterized in that, Based on the log files corresponding to the application firewall engine, the real traffic characteristic information corresponding to the real traffic data is obtained, including: Initial traffic characteristic information is obtained by collecting features from the log files using a streaming computing engine; The initial traffic characteristic information is filtered according to a preset time sliding window to obtain the first traffic characteristic information; The first traffic feature information is filtered according to historical traffic detection rules to obtain the real traffic feature information.
6. The method according to claim 5, characterized in that, Before obtaining initial traffic characteristic information by collecting features from the log files through a streaming computing engine, the method further includes: Upon receiving the real traffic data of outbound access, the application firewall engine processes the real traffic data to obtain the real traffic feature information corresponding to the real traffic data. The traffic characteristic information is encoded and compressed to obtain string information; The log file is generated based on the string information.
7. The method according to claim 5, characterized in that, The initial traffic characteristic information is filtered according to a preset time sliding window to obtain the first traffic characteristic information, which includes: Determine the device type of the device that triggered the actual traffic data; Based on the device type, determine the time range corresponding to the preset time sliding window; The initial traffic characteristic information is filtered according to the time range to obtain the first traffic characteristic information.
8. The method according to claim 1, characterized in that, After determining the processing strategy for the first traffic data based on the first detection result, the method further includes: If an update instruction for the target traffic detection rule is received, then based on the first detection result and the actual detection result corresponding to the first traffic data, the second hit rate and the second hit distribution information corresponding to the target traffic detection rule are determined. Based on the second hit rate and the second hit distribution information, the target traffic detection rule is adjusted to obtain the adjusted target traffic detection rule; When receiving the third traffic data, the traffic feature information corresponding to the third traffic data is filtered according to the adjusted target traffic detection rule to obtain the second traffic feature information; The second traffic feature information is processed by the target natural language model to obtain an updated traffic detection rule, and the adjusted target traffic detection rule is updated according to the updated traffic detection rule to obtain the updated target traffic detection rule.
9. The method according to claim 2, characterized in that, Before processing the target prompt information using the target natural language model to obtain the target traffic detection rule, the method further includes: Obtain domain knowledge information on traffic protection; The target natural language model is obtained by training the initial natural language model with the domain knowledge information.
10. A flow control device, characterized in that, include: The receiving unit is used to receive first traffic data and obtain target traffic feature information corresponding to the first traffic data; The detection unit is used to perform anomaly detection on the target traffic feature information according to the target traffic detection rule and obtain a first detection result. The target traffic detection rule is obtained by processing the real traffic feature information corresponding to the real traffic data through a target natural language model. The first detection result is used to indicate whether the first traffic data has any risk. The first determining unit is used to determine the processing strategy for the first traffic data based on the first detection result.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the storage medium is located to perform the flow control method according to any one of claims 1 to 9.
12. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the flow control method according to any one of claims 1 to 9.
13. A computer program product, characterized in that, It includes a computer program or instructions that, when executed by a processor, implement the flow control method according to any one of claims 1 to 9.