An abnormal access prediction and dynamic blocking method based on streaming behavior modeling, server, product and medium
Patent Information
- Application Number
- CN202611175966.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-04
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]在实际高并发业务环境中,异常访问行为往往在一个统计周期的中间阶段逐步发生并持续演化,而上述方式需等待当前周期结束后方可生成检测结果,周期内已发生的异常访问在等待期间持续作用于业务系统而未被及时处置,导致异常行为从发生到被响应之间存在不可忽视的时间延迟,业务系统在该延迟期间持续暴露于风险之中
[0025]1、由于采用了实时采集网络访问数据并接入流式计算框架、依据滑动时间窗口对同一访问对象的离散访问请求进行行为聚合、基于多窗口行为特征向量建立正常行为基线模型、将当前行为特征向量与基线模型比对并结合访问上下文信息生成动态风险评分、按风险等级执行分级防护策略、以及根据阻断执行结果动态调整模型参数与风险阈值的技术手段,其中流式计算框架与滑动时间窗口使得行为检测在数据持续流入过程中即可完成,所以异常访问的检测与防护响应能够随滑动时间窗口持续推进执行,有效解决了现有技术中基于固定统计周期批量处理导致异常行为发生至被响应之间存在时间延迟的问题,进而实现了异常访问的实时流式检测与防护策略的闭环动态调整。
Smart Images

Figure CN122845277A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security, and in particular to an abnormal access prediction and dynamic blocking method, server, product and medium based on streaming behavior modeling. Background Technology
[0002] As the scale of network business system access continues to grow, threats such as automated attacks, malicious scanning, and abnormal crawling targeting business interfaces are becoming increasingly frequent. Timely detection and effective protection against abnormal access behavior have become an important requirement in the field of network security.
[0003] In existing technologies, abnormal access detection is typically implemented using a periodic statistical method based on fixed thresholds and static rules. After each fixed statistical period, the system batch summarizes indicators such as the total number of access requests and the distribution of their sources within that period. The summarized results are then compared with preset fixed thresholds. If the thresholds are exceeded, the system is judged as abnormal and a unified blocking operation is performed.
[0004] In real-world high-concurrency business environments, abnormal access behaviors often occur gradually and evolve in the middle of a statistical period. The above method requires waiting until the end of the current period before generating detection results. Abnormal access that has already occurred within the period continues to affect the business system during the waiting period without being dealt with in a timely manner, resulting in a significant time delay between the occurrence of abnormal behavior and the response. During this delay, the business system remains continuously exposed to risks. Summary of the Invention
[0005] This application provides a method, server, product, and medium for anomaly access prediction and dynamic blocking based on streaming behavior modeling, which can improve the real-time performance of anomaly access detection.
[0006] Firstly, this application provides a method for abnormal access prediction and dynamic blocking based on streaming behavior modeling, applied to a server. The method includes: real-time collection of network access data and integration into a streaming computing framework; aggregation of discrete access requests for the same access object according to access identifier information and a sliding time window, organizing them into an access behavior sequence in chronological order; the network access data includes access request information and access context information; extraction of multi-dimensional behavioral features from the access behavior sequence to form a behavioral feature vector corresponding to the current sliding time window; establishment of a normal behavior baseline model for the access object based on the behavioral feature vectors accumulated within multiple consecutive sliding time windows; real-time comparison of the behavioral feature vector within the current sliding time window with the normal behavior baseline model to calculate the behavioral deviation; calculation of a dynamic risk score based on the behavioral deviation and access context information; classification of the access object into corresponding risk levels based on the dynamic risk score; automatic matching and execution of corresponding protection strategies based on the risk level; recording the blocking execution results and subsequent behavioral changes of the access object; and dynamically adjusting the model parameters and risk thresholds of the normal behavior baseline model based on the blocking execution results and subsequent behavioral changes.
[0007] In the above embodiments, a streaming computing framework and a sliding time window mechanism are used to achieve real-time aggregation and continuous monitoring of access behavior. Based on the normal behavior baseline model, the behavior deviation is calculated and dynamic risk scores are generated by combining context information. Tiered protection strategies are executed according to risk levels, and model parameters and risk thresholds are adjusted based on the feedback of blocking execution results, forming a closed-loop processing flow of detection, response and optimization, which improves the real-time performance of abnormal access detection and the adaptability of protection strategies.
[0008] In conjunction with some embodiments of the first aspect, in some embodiments, the step of extracting multi-dimensional behavioral features from the access behavior sequence to form a behavioral feature vector corresponding to the current sliding time window, and establishing a normal behavior baseline model of the access object based on the behavioral feature vectors accumulated within multiple consecutive sliding time windows, specifically includes: statistically analyzing the total number of access requests within the current sliding time window according to the time dimension of the access behavior sequence as an access frequency value; calculating the time interval between adjacent access requests to form a time interval sequence; calculating the mean and variance of the time interval sequence as time interval distribution features; combining the access frequency value and the time interval distribution features as temporal statistical features; extracting the interface identifiers accessed by each access request in chronological order to form an interface call sequence; statistically analyzing the number of non-repeating interface identifiers as interface coverage; calculating the change amplitude between request parameters of adjacent access requests to form a parameter change sequence and taking the mean as parameter change intensity; combining the interface coverage and parameter change intensity as behavioral pattern features; normalizing the temporal statistical features and behavioral pattern features respectively and concatenating them to form a behavioral feature vector corresponding to the current sliding time window; accumulating the behavioral feature vectors within multiple consecutive sliding time windows in chronological order; calculating the mean and variance for each feature dimension respectively; and constructing a normal behavior baseline model of the access object.
[0009] In the above embodiments, by extracting time-series statistical features and behavioral pattern features from the access behavior sequence and normalizing and concatenating them into a behavioral feature vector, the behavioral feature vector is accumulated within multiple consecutive sliding time windows and the mean and variance of each dimension are calculated to construct a normal behavior baseline model of the access object. This baseline model can quantitatively characterize the stable behavioral patterns of the access object in terms of time distribution and interface call patterns.
[0010] In conjunction with some embodiments of the first aspect, in some embodiments, the step of comparing the behavioral feature vector within the current sliding time window with the normal behavioral baseline model in real time to calculate the behavioral deviation, calculating and generating a dynamic risk score based on the behavioral deviation and access context information, and classifying the accessed object into the corresponding risk level based on the dynamic risk score specifically includes: comparing the behavioral feature vector within the current sliding time window with the mean of the corresponding feature dimension in the normal behavioral baseline model dimension by dimension, calculating the standardized distance of the current feature value from the mean in each feature dimension, and combining them to form the behavioral deviation; obtaining the access context information within the current sliding time window, and determining the weight adjustment factor corresponding to each feature dimension based on the degree of change of the access source region, device identifier, and login authentication status compared to the previous sliding time window; multiplying the standardized distance of each feature dimension by the corresponding weight adjustment factor and then weighting and summing them to generate the dynamic risk score within the current sliding time window; comparing the dynamic risk score with a preset risk threshold, and classifying the accessed object into the corresponding risk level based on the risk score range that the dynamic risk score falls into.
[0011] In the above embodiments, the behavior deviation is formed by calculating the standardized distance between the current behavior feature vector and the mean of the normal behavior baseline model in each dimension. The weight adjustment factor is determined according to the degree of change of the access source region, device identifier and login authentication status. The standardized distance of each dimension is weighted and summed to generate a dynamic risk score, so that the risk assessment result can reflect the comprehensive impact of the degree of behavior deviation and context changes, and improve the distinguishability of risk level classification.
[0012] In conjunction with some embodiments of the first aspect, in some embodiments, the step of recording the blocking execution result and the subsequent behavioral changes of the accessed object, and dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the blocking execution result and the subsequent behavioral changes, specifically includes: within a preset observation period after the completion of the protection strategy, collecting the subsequent access behavior of the accessed object and extracting the subsequent behavior feature vector, comparing it with the normal behavior baseline model to calculate the subsequent behavior deviation; performing correlation analysis between the blocking execution result and the subsequent behavior deviation, marking it as effective blocking when the subsequent behavior deviation is continuously lower than the risk threshold within the observation period, and marking it as ineffective blocking when it exceeds the risk threshold again; dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the effectiveness marking result, and applying the adjusted model parameters and risk threshold to the behavioral deviation calculation and dynamic risk score generation in the subsequent sliding time window.
[0013] In the above embodiments, by continuously collecting subsequent behaviors and calculating the deviation of subsequent behaviors during the observation period after the protection strategy is executed, the effectiveness of blocking is marked based on whether the deviation is continuously lower than the risk threshold, and the model parameters and risk threshold of the normal behavior baseline model are adjusted accordingly, so that the detection model can be continuously optimized according to the actual effect of protection execution, reducing the probability of false positives and false negatives.
[0014] In conjunction with some embodiments of the first aspect, in some embodiments, the step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the validity marking results specifically includes: for access objects marked as effectively blocked, incorporating the subsequent behavioral feature vectors within the observation period into the historical feature data of the normal behavior baseline model, recalculating the mean and variance of each feature dimension to update the model parameters; statistically analyzing the proportion of invalid blocking to all blocking execution results within a preset evaluation period as the invalid blocking rate, lowering the risk threshold when the invalid blocking rate exceeds a preset proportion threshold, and raising the risk threshold when it is lower than the preset proportion threshold.
[0015] In the above embodiments, the subsequent behavioral feature vectors corresponding to effective blocking are incorporated into historical feature data to update the mean and variance of the baseline model. The risk threshold is adjusted according to the comparison results of the ineffective blocking rate and the preset proportion threshold, so that the parameter update of the baseline model has a data verification basis, and a quantitative correlation is formed between the adjustment direction of the risk threshold and the detection effect.
[0016] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the blocking execution result and subsequent behavior changes, the method further includes: during the execution of the protection strategy, continuously calculating the behavioral deviation of the access object within each recovery monitoring window with a preset recovery monitoring window as the period; when the behavioral deviation of the access object within a consecutive preset number of recovery monitoring windows is lower than the current risk threshold, gradually lifting the access restriction measures on the access object in descending order of protection strategy strength until the access permission is fully restored; during the gradual lifting of access restriction measures, if the behavioral deviation of the access object exceeds the current risk threshold again, the lifting process is stopped and the risk level of the access object is restored to the level before the lifting, and the count of the recovery monitoring window is reset; extending the window duration of the subsequent recovery monitoring window for access objects that have accumulated a preset number of times the lifting process has been triggered within a preset statistical period, and increasing the basic weight of the access object in the subsequent dynamic risk score calculation.
[0017] In the above embodiments, the behavior deviation of the access object is continuously monitored in cycles of recovery monitoring windows. When the deviation is below the threshold in multiple consecutive windows, the access restriction is lifted step by step. When the deviation exceeds the threshold again, the lifting is stopped and the count is reset. The monitoring window duration is extended and the basic weight is increased for access objects that trigger the suspension multiple times, so that the access permission recovery process is gradual and reversible, reducing the secondary risks caused by premature lifting of restrictions.
[0018] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the blocking execution result and subsequent behavior changes, the method further includes: extracting the behavioral feature vectors of multiple different access objects within the current sliding time window, and calculating the similarity between the behavioral feature vectors of each access object; when the similarity of the behavioral feature vectors between a preset number of different access objects exceeds a preset similarity threshold, and the target interfaces accessed by different access objects within the same time window overlap, marking the different access objects as a collaborative behavior group; and adding a collaborative risk bonus to the dynamic risk score of each access object marked as a collaborative behavior group based on the original score, wherein the collaborative risk bonus is determined jointly based on the number of access objects included in the collaborative behavior group and the similarity of the behavioral feature vectors.
[0019] In the above embodiments, by calculating the similarity between the behavioral feature vectors of multiple different access objects within the same time window, when the similarity exceeds the threshold and the target interfaces overlap, they are marked as a collaborative behavior group, and a collaborative risk additional score is added to each access object in the group, so that distributed abnormal access with multi-source collaboration has the ability to jointly detect and weighted evaluate.
[0020] In a second aspect, embodiments of this application provide a server comprising: one or more processors and a memory; the memory is coupled to the one or more processors and is used to store computer program code, the computer program code including computer instructions, wherein the one or more processors invoke the computer instructions to cause the server to perform the method described in the first aspect and any possible implementation thereof.
[0021] Thirdly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a server, cause the server to perform the method described in the first aspect and any possible implementation thereof.
[0022] Fourthly, embodiments of this application provide a computer program product containing instructions that, when the computer program product is run on a server, cause the server to execute the method described in the first aspect and any possible implementation thereof.
[0023] Understandably, the server provided in the second aspect, the computer storage medium provided in the third aspect, and the computer program product provided in the fourth aspect are all used to execute the methods provided in the embodiments of this application. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0024] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0025] 1. By employing techniques such as real-time acquisition of network access data and integration with a streaming computing framework, aggregation of discrete access requests for the same access object based on a sliding time window, establishment of a normal behavior baseline model based on multi-window behavior feature vectors, comparison of the current behavior feature vector with the baseline model and generation of dynamic risk scores by combining access context information, execution of graded protection strategies according to risk levels, and dynamic adjustment of model parameters and risk thresholds based on blocking execution results, the streaming computing framework and sliding time window enable behavior detection to be completed during the continuous data inflow process. Therefore, the detection and protection response of abnormal access can be continuously executed as the sliding time window progresses, effectively solving the problem of time delay between the occurrence of abnormal behavior and the response caused by batch processing based on fixed statistical periods in existing technologies. This achieves real-time streaming detection of abnormal access and closed-loop dynamic adjustment of protection strategies.
[0026] 2. By employing techniques such as combining access frequency values and time interval distribution features into time-series statistical features, extracting interface coverage and parameter change intensity into behavioral pattern features, normalizing and concatenating the two types of features to form behavioral feature vectors, and accumulating behavioral feature vectors within multiple continuous sliding time windows and calculating the mean and variance of each dimension to construct a normal behavioral baseline model, the baseline model can quantitatively and completely characterize the stable behavioral patterns of the accessed object. This effectively solves the problem that single-dimensional features cannot fully depict the access behavior pattern, resulting in a lack of sufficient comparison benchmarks for deviation calculation, thus achieving accurate quantitative modeling of multi-dimensional behavioral baselines.
[0027] 3. By employing technical means such as calculating the standardized distance between the current behavioral feature vector and the baseline model mean to form the behavioral deviation, determining the weight adjustment factor based on the degree of change in the access source region, device identifier, and login authentication status, multiplying the standardized distance of each dimension by the weight adjustment factor and then weighting and summing to generate a dynamic risk score, and classifying risk levels based on the risk score range, the standardized distance eliminates the difference in the dimensions of each feature dimension, allowing the deviation to be compared across dimensions. The weight adjustment factor allows changes in the context environment to affect the weight allocation of risk assessment. Therefore, the dynamic risk score can comprehensively reflect the degree of behavioral deviation and changes in the access environment, effectively solving the problem that the fixed weight scoring method cannot adapt to the dynamic changes in the access environment, resulting in insufficient risk assessment discrimination. This achieves context-aware differentiated dynamic risk assessment. Attached Figure Description
[0028] Figure 1 This is a schematic diagram of the overall architecture of the abnormal access prediction and dynamic blocking method based on streaming behavior modeling in the embodiments of this application;
[0029] Figure 2 This is a flowchart illustrating an abnormal access prediction and dynamic blocking method based on streaming behavior modeling in an embodiment of this application.
[0030] Figure 3 This is a schematic diagram of the abnormal access prediction process in an embodiment of this application;
[0031] Figure 4 This is a schematic diagram of behavioral feature extraction and baseline model construction in an embodiment of this application;
[0032] Figure 5 This is a schematic diagram of the dynamic blocking and policy execution mechanism in an embodiment of this application;
[0033] Figure 6 This is a schematic diagram of the feedback learning and model optimization mechanism in the embodiments of this application;
[0034] Figure 7 This is another flowchart illustrating the abnormal access prediction and dynamic blocking method based on streaming behavior modeling in this application embodiment;
[0035] Figure 8 This is a schematic diagram of the physical device structure of a server in an embodiment of this application. Detailed Implementation
[0036] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification of this application, the singular expressions “a,” “an,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to any or all possible combinations including one or more of the listed items.
[0037] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0038] To facilitate understanding, the application scenarios of the embodiments of this application are described below.
[0039] As internet service architecture continues to evolve, the number and scale of publicly accessible application programming interfaces (APIs) are constantly increasing, leading to increasingly covert and diverse malicious access behaviors targeting these interfaces. Traditional access control schemes typically rely on fixed rules for protection, such as setting fixed access frequency limits or using static blacklists and whitelists for blocking. These schemes struggle to accurately identify and effectively block low-frequency, slow penetration attacks, automated scripts simulating normal user behavior, and distributed malicious requests initiated by multiple accounts. Furthermore, fixed-threshold protection strategies lack automatic correction mechanisms after misjudgments, failing to dynamically adjust restrictions based on changes in the actual behavior of the access target, resulting in a decline in the user experience for legitimate users or the continued escape of malicious access.
[0040] The dynamic risk assessment and adaptive protection method for interface access behavior provided in this application embodiment is applicable to the following application scenarios: An internet platform provides multiple business interfaces, including user information query interfaces, order data interfaces, and payment transaction interfaces. The platform's security gateway deploys the method described in this application embodiment to perform real-time monitoring of all interface access requests. When the request behavior of an access object exhibits characteristics such as abnormally high interface coverage, parameter change intensity far exceeding the normal baseline, and a sharp increase in access frequency within a sliding time window, the system calculates a high dynamic risk score by comparing the behavior feature vector with the normal behavior baseline model dimension by dimension, and automatically triggers the corresponding level of protection strategy to implement rate limiting or blocking for the access object; when the similarity of the behavior feature vectors of multiple access objects exceeds the threshold and the access target interfaces overlap, they are marked as a collaborative behavior group and a collaborative risk additional score is added to achieve linkage protection; after the protection strategy is executed, the behavior deviation is continuously observed by restoring the monitoring window, and the restriction measures are gradually lifted to restore access permissions for access objects whose behavior returns to normal. Based on the feedback results of the blocking effectiveness, the model parameters and risk thresholds are automatically calibrated to form a complete closed-loop protection system from real-time detection, accurate assessment, hierarchical response to automatic optimization.
[0041] like Figure 1 As shown, the overall system architecture, from top to bottom, includes a network access data source layer, a streaming data acquisition module, a streaming computing and processing module, a behavior analysis and modeling center, and a protection execution layer.
[0042] The network access data source layer is responsible for generating raw access data, which comes from sources such as web access logs, API call logs, and authentication logs. The streaming data acquisition module uses a Kafka message queue or log broker to collect and asynchronously buffer the raw data in real time, ensuring the continuity and stability of data access. The streaming computing processing module uses streaming computing frameworks such as Flink or Spark Streams to continuously process the incoming data, performing preprocessing operations such as data cleaning, format standardization, and time sorting.
[0043] The Behavior Analysis and Modeling Center is the core processing layer of the system, comprising four sub-modules: feature extraction, behavior modeling, risk scoring, and anomaly prediction. The feature extraction module extracts multi-dimensional behavioral features from access behavior sequences to form behavioral feature vectors. The behavior modeling module constructs a baseline model of normal behavior based on behavioral feature vectors within multiple consecutive sliding time windows. The risk scoring module compares the current behavioral feature vector with the baseline model to calculate the behavioral deviation and generates a dynamic risk score by incorporating access context information. The anomaly prediction module classifies risk levels and determines abnormal behavior based on the risk score.
[0044] The dynamic blocking control module automatically matches the corresponding protection strategy based on the risk level and sends the execution command to the protection strategy execution module. The protection strategy execution module is responsible for implementing protection measures such as rate limiting, CAPTCHA verification, access blocking, temporary IP blocking, and session isolation. At the same time, it feeds back the blocking execution results to the behavior analysis and modeling center for dynamic adjustment of model parameters and risk thresholds.
[0045] To facilitate understanding, the method provided in this implementation will be described in detail below, using the above scenario as an example. Please refer to [link / reference]. Figure 2 This is a flowchart illustrating an abnormal access prediction and dynamic blocking method based on streaming behavior modeling in this application.
[0046] S201. Collect network access data in real time and connect it to the streaming computing framework. Based on the access identification information, aggregate the discrete access requests of the same access object according to the sliding time window and organize them into an access behavior sequence in chronological order.
[0047] Network access data refers to the raw data related to access behavior generated during the operation of the business system. This includes access request information and access context information. Access request information represents the content carried by the request itself, such as the target interface address, request method, request parameters, and timestamp. Access context information represents environmental attributes associated with the access, such as the access source region, device identifier, and login authentication status. Access identification information refers to attribute fields used to uniquely identify the access source, including source IP address, user identifier, and session ID. A sliding time window is a time interval division method that slides forward at a fixed time length, used to segment continuously flowing data according to time range. An access behavior sequence refers to an ordered set of requests formed by arranging multiple discrete access requests for the same access object within the current sliding time window according to their timestamps from first to last.
[0048] Specifically, the system continuously acquires network access data at the business network boundary through methods such as log brokering, traffic mirroring, or message queue subscription, and connects to the streaming computing framework in the form of message streams for continuous reception and real-time processing. After standardizing the format of the raw data, completing missing fields, and cleaning up duplicate records, the system extracts access identification information from each access record, and assigns requests with the same access identification information to the same access object. Using a sliding time window as a unit, the system aggregates all discrete access requests for the same access object falling within the current window range into a group, and sorts them by timestamp from earliest to latest to form the access behavior sequence of that access object. The sliding time window continues to advance in a preset step size, and the above aggregation and sorting operations are repeated for the data in the new window with each advance.
[0049] In some embodiments, real-time collection and streaming access of network access data can be achieved in several ways: Optionally, a log collection agent is deployed on the business server to monitor changes in the access log file in real time. When a new record is generated, it is immediately read and encapsulated into a standardized message and sent to the streaming computing framework via a message queue. After receiving the message, the framework groups the data according to the access identifier information and completes behavior aggregation and sorting within a sliding time window. Optionally, traffic mirroring is enabled on the network gateway device to mirror access request data to the collection node in real time. The collection node performs protocol parsing on the mirrored traffic, extracts complete field information, and pushes it to the streaming computing framework. The framework aggregates requests for the same access object according to preset window parameters and organizes them into a sequence of access behaviors in chronological order. It is understood that other methods can also be used to achieve real-time collection and streaming access processing of network access data, which are not limited here.
[0050] To better understand the execution logic between the above steps, please refer to [link / reference]. Figure 3 This is a schematic diagram of the abnormal access prediction process in an embodiment of this application.
[0051] like Figure 3 As shown, the abnormal access prediction process begins with real-time collection of access data. The system first performs data cleaning and standardization on the collected raw access data, including format unification, missing field completion, abnormal character filtering, and duplicate record removal. The cleaned data then enters the behavior sequence construction stage. Based on access identification information, the system aggregates discrete access requests for the same access object according to a sliding time window and organizes them into an access behavior sequence in chronological order.
[0052] The system then proceeds to the behavioral feature extraction stage, where it extracts multi-dimensional behavioral features from the access behavior sequence, including access frequency, time interval distribution, interface coverage, and parameter change intensity, forming a behavioral feature vector corresponding to the current sliding time window. In the behavioral model matching stage, the system compares the current behavioral feature vector with the normal behavioral baseline model dimension by dimension, calculating the behavioral deviation.
[0053] After entering the risk scoring calculation phase, the system generates a dynamic risk score based on the degree of behavioral deviation and access context information. Finally, in the risk threshold determination stage, if the dynamic risk score does not reach the risk threshold, the system determines that the current behavior is normal and continues to monitor subsequent behaviors; if the dynamic risk score reaches or exceeds the risk threshold, the system determines that the current behavior is abnormal and triggers the corresponding protection strategy execution process.
[0054] S202. Extract multi-dimensional behavioral features from the access behavior sequence to form the behavioral feature vector corresponding to the current sliding time window, and establish a normal behavior baseline model of the accessed object based on the behavioral feature vectors accumulated in multiple consecutive sliding time windows.
[0055] Among them, multidimensional behavioral features refer to quantitative features extracted from the access behavior sequence, covering two dimensions: temporal statistics and behavioral patterns. Temporal statistics features include access frequency values and time interval distribution characteristics (mean and variance of time intervals between adjacent requests). Behavioral pattern features include interface coverage (number of unique interface identifiers) and parameter change intensity (mean of parameter change amplitude between adjacent requests). The behavioral feature vector is a one-dimensional numerical vector formed by concatenating the above two types of features after normalization. The normal behavior baseline model is a statistical model constructed based on the behavioral feature vectors accumulated over multiple consecutive sliding time windows, calculating the mean and variance of each feature dimension, used to characterize the stable behavioral patterns of the access object.
[0056] Specifically, the system extracts features from the access behavior sequence within the current sliding time window in two dimensions. In the time dimension, the total number of access requests within the window is used as the access frequency value, and the mean and variance of the time interval sequence between adjacent requests are calculated as the time interval distribution feature; these two are combined to form the time-series statistical feature. In the behavior pattern dimension, the number of unique interface identifiers extracted from each request in chronological order is counted as the interface coverage, and the average of the changes in parameters between adjacent requests is calculated as the parameter change intensity; these two are combined to form the behavior pattern feature. After normalizing both types of features, they are concatenated to form the behavior feature vector corresponding to the current window. The system accumulates the behavior feature vectors of multiple consecutive windows in chronological order. When the number of accumulated windows reaches the preset modeling number, the mean and variance of each dimension are calculated to construct a normal behavior baseline model.
[0057] In some embodiments, the extraction of behavioral feature vectors and the establishment of baseline models can be achieved in several ways: Optionally, the system triggers feature extraction at the end of each sliding time window, traverses the sequence to calculate various statistics, maps each feature value to the range of zero to one through min-max normalization, and then concatenates them into a vector. After accumulating to a preset number of windows, the arithmetic mean and variance of each dimension are calculated to form a baseline model. Optionally, the system uses an exponentially weighted moving average to establish the baseline model. After each new window generates a behavioral feature vector, the historical mean and variance are updated with a preset decay coefficient, so that the contribution weight of newer windows is higher than that of earlier windows, and the weighting calculation is performed independently for each dimension. It is understood that other methods can also be used to achieve behavioral feature extraction and baseline model construction, which are not limited here.
[0058] In some embodiments, this step specifically includes:
[0059] The total number of access requests within the current sliding time window is statistically analyzed along the time dimension of the access behavior sequence as the access frequency value. The time interval between adjacent access requests is calculated to form a time interval sequence. The mean and variance of the time interval sequence are calculated as the time interval distribution feature. The access frequency value and the time interval distribution feature are combined as a time series statistical feature. The interface identifiers accessed by each access request are extracted in chronological order to form an interface call sequence. The number of unique interface identifiers is counted as the interface coverage. The change amplitude between the request parameters of adjacent access requests is calculated to form a parameter change sequence, and the mean is taken as the parameter change intensity. The interface coverage and parameter change intensity are combined as a behavior pattern feature. The time series statistical feature and the behavior pattern feature are normalized and concatenated to form the behavior feature vector corresponding to the current sliding time window. The behavior feature vectors in multiple consecutive sliding time windows are accumulated in chronological order, and the mean and variance are calculated for each feature dimension to construct a normal behavior baseline model of the access object.
[0060] The access frequency value refers to the total number of access requests within the current sliding time window. The time interval sequence is a numerical sequence formed by arranging the time differences obtained by subtracting the timestamps of two adjacent access requests in chronological order. The time interval distribution characteristic refers to two statistical measures obtained by calculating the arithmetic mean and variance of the time interval sequence. The interface call sequence is an ordered list composed of the interface identifiers accessed by each request in chronological order. Interface coverage refers to the number of different interface identifiers remaining after removing duplicates from the interface call sequence. The parameter change intensity is the arithmetic mean of the changes in parameters between adjacent requests; the change intensity is obtained by comparing each field of adjacent request parameters and counting the proportion of fields that have changed out of the total number of fields. Normalization is the process of mapping each feature value to a uniform numerical range; when using min-max normalization, the current value is subtracted from the historical minimum value of that dimension and then divided by the difference between the maximum and minimum values.
[0061] Specifically, the system iterates through the access behavior sequence within the current sliding time window, recording the total number of requests in the sequence as the access frequency value. It then takes the timestamps of adjacent requests and calculates the difference to generate a time interval sequence. The sum of all values in this sequence is divided by the number of values to obtain the mean. The squares of the differences between each value and the mean are squared, summed, and divided by the number of values to obtain the variance. The mean and variance are combined to form the time interval distribution feature, which, along with the access frequency value, constitutes the time-series statistical feature. The system reads the interface identifiers accessed by each request in chronological order and writes them into the interface call sequence. The sequence is deduplicated, and the number of remaining identifiers is counted to obtain the interface coverage. The parameter fields of adjacent requests are compared item by item. The number of fields that changed is divided by the total number of fields to obtain the single change amplitude. The sum of all change amplitudes is divided by the number of changes to obtain the parameter change intensity. These two elements constitute the behavioral pattern feature. Finally, min-max normalization is applied to each dimension of the time-series statistical feature and each dimension of the behavioral pattern feature, and the vector is concatenated to form the behavioral feature vector. The system stores the behavioral feature vectors generated by multiple consecutive windows into a queue in chronological order. When the queue length reaches the preset number of modeling windows, the system calculates the arithmetic mean and variance of each dimension in the vector. The combination of the mean and variance of each dimension constitutes the normal behavioral baseline model of the accessed object.
[0062] For a further explanation of the specific process of behavioral feature extraction and baseline model construction, please refer to [link / reference]. Figure 4 This is a schematic diagram of behavioral feature extraction and baseline model construction in an embodiment of this application.
[0063] like Figure 4 As shown, the raw access behavior data first enters the session aggregation and reorganization module. This module performs session-level aggregation and reorganization of discrete access requests based on access identification information such as source IP address, user identifier, and session ID, and organizes requests belonging to the same access object into a continuous access behavior sequence in chronological order.
[0064] The aggregated data enters the behavior feature extraction module, which extracts features from the access behavior sequence from four dimensions: access frequency feature, which describes the total number of access requests and their changing trends within the current sliding time window; time interval feature, which calculates the time interval between adjacent access requests to form a time interval sequence and calculates its mean and variance to characterize the rhythm and suddenness of access behavior; interface path feature, which extracts the interface call sequence and counts the number of unique interface identifiers as interface coverage to identify abnormal interface traversal behavior; and parameter change feature, which calculates the magnitude of parameter changes between adjacent requests and takes the mean as the intensity of parameter changes to detect batch scanning or enumeration behavior. These four types of features are then normalized and concatenated to form a behavior feature vector.
[0065] The behavioral feature vectors are then fed into the behavioral model building module. This module accumulates the behavioral feature vectors accumulated over multiple consecutive sliding time windows in chronological order, calculates the mean and variance for each feature dimension, and constructs a normal behavioral baseline model for the accessed object. The normal behavioral baseline model quantitatively represents the stable behavioral patterns of the accessed object in terms of time distribution and interface call patterns, serving as a benchmark for subsequent behavioral deviation calculations.
[0066] S203. Compare the behavioral feature vector within the current sliding time window with the normal behavioral baseline model in real time to calculate the behavioral deviation. Calculate and generate a dynamic risk score based on the behavioral deviation and access context information. Classify the accessed object into the corresponding risk level based on the dynamic risk score.
[0067] Among them, behavioral deviation refers to the quantitative representation of the difference between the current behavioral feature vector and the mean of the corresponding dimension of the normal behavioral baseline model, formed by the combination of standardized distances of each dimension. Standardized distance is the value obtained by dividing the difference between the current feature value and the mean of that dimension by the standard deviation of that dimension. Weight adjustment factor is a coefficient determined based on the degree of change of access context information (source region, device identifier, login authentication status) compared to the previous window, used to adjust the weight of each dimension in the risk score. Dynamic risk score is the weighted sum of the standardized distances of each dimension multiplied by the corresponding weight adjustment factor. Risk level refers to the classification of the accessed object based on the score range that the dynamic risk score falls into.
[0068] Specifically, the system compares the current behavior feature vector with the baseline model dimension by dimension. For each dimension, it calculates the standardized distance by subtracting the mean of that dimension from the current value and dividing by the standard deviation. The combination of standardized distances across dimensions forms the behavior deviation. Then, it acquires the access context information of the current window, comparing the source region, device identifier, and login authentication status with records from previous windows. Based on the degree of change, it determines the weight adjustment factor for each dimension; when the context changes significantly, the corresponding factor takes a larger value; otherwise, the base value is used. The standardized distances of each dimension are multiplied by the corresponding weight adjustment factor, and then weighted and summed to generate a dynamic risk score. Finally, the score is compared with a preset risk threshold, and the risk level is determined based on the score range it falls into.
[0069] In some embodiments, behavioral deviation calculation and dynamic risk score generation can be implemented in multiple ways: Optionally, the system calculates the absolute value of the standardized distance for each dimension, sets corresponding factor values based on whether the source region, device identifier, and login status have changed, multiplies the standardized distance of each dimension by the factor, and sums them to obtain a score. The score is then compared with low-risk and high-risk thresholds to determine the level. Optionally, the system uses Mahalanobis distance to calculate the overall deviation, calculates the overall deviation value by weighting the difference between the eigenvector and the mean vector using the inverse of the covariance matrix, applies a multiplicative adjustment coefficient based on the degree of contextual change to generate a dynamic risk score, and maps it to a risk level according to a multi-level threshold system. It is understood that other methods can also be used to implement deviation calculation and risk level classification, which are not limited here.
[0070] In some embodiments, this step specifically includes:
[0071] The behavior feature vector within the current sliding time window is compared dimension by dimension with the mean of the corresponding feature dimension in the normal behavior baseline model. The standardized distance of the current feature value deviating from the mean in each feature dimension is calculated and combined to form the behavior deviation degree. The access context information within the current sliding time window is obtained. Based on the degree of change of the access source region, device identifier, and login authentication status compared with the previous sliding time window, the weight adjustment factor corresponding to each feature dimension is determined. The standardized distance of each feature dimension is multiplied by the corresponding weight adjustment factor and then weighted and summed to generate the dynamic risk score within the current sliding time window. The dynamic risk score is compared with the preset risk threshold. Based on the risk score range that the dynamic risk score falls into, the access object is divided into the corresponding risk level.
[0072] The standardized distance is the difference between the current feature value and the mean of the corresponding dimension in the baseline model, divided by the standard deviation of that dimension. The standard deviation is the square root of the variance. Behavioral deviation is a vector or set of values formed by combining the standardized distances of each dimension, used to characterize the overall difference between the current behavior and historical normal behavior. The weighting adjustment factor is a multiplicative coefficient for each dimension determined based on the degree of change in the access context information; for example, the factor is set to 1.5 when the source region changes and 1.0 when it does not change. The dynamic risk score is the sum of the standardized distances of each dimension multiplied by their corresponding weighting adjustment factors. The risk score range refers to multiple predefined continuous numerical ranges, each corresponding to a different risk level; for example, a score of 0 to 30 corresponds to low risk, 30 to 60 to medium risk, and above 60 to high risk.
[0073] Specifically, the system reads the behavioral feature vector of the current sliding time window and the mean and variance of each dimension stored in the normal behavior baseline model. For each dimension, it performs standardized distance calculation: subtracting the mean of that dimension from the current dimension's feature value, and then dividing by the square root of the variance of that dimension, yields the standardized distance for that dimension. The standardized distances of all dimensions are summed to form the behavioral deviation. Subsequently, the system extracts the access context information of the current window, comparing the source region with the region value recorded in the previous window. If they are inconsistent, the weight adjustment factor for that dimension is set to a preset high value; otherwise, it is set to the base value of 1.0. Device identification and login authentication status are determined using the same comparison logic. The absolute value of the standardized distance for each dimension is multiplied by the corresponding weight adjustment factor and then accumulated dimension by dimension to obtain a dynamic risk score. The system compares this score with a preset risk threshold system to determine the risk score range it falls into, and assigns the risk level corresponding to that range to the current access object.
[0074] S204. Automatically match and execute the corresponding protection strategy based on the risk level.
[0075] Among them, the protection strategy refers to a set of pre-configured access control measures for different risk levels. Low risk corresponds to lightweight interventions such as request rate limiting and CAPTCHA verification; medium risk corresponds to restricting access permissions to some interfaces or shortening the session validity period; and high risk corresponds to high-intensity measures such as access blocking, temporary IP blocking, session isolation, or account freezing. Automatic matching refers to the process by which the system searches for and selects the corresponding protection strategy from the preset policy mapping relationship based on the current risk level of the access object.
[0076] Specifically, after determining the risk level, the system searches for the corresponding protection measure type and execution parameters in the pre-configured policy mapping table based on that level, and then sends the matching result to the corresponding execution component for implementation. For low-risk situations, a rate-limiting command is sent to the traffic control component or a verification requirement is triggered to the CAPTCHA service; for medium-risk situations, a permission restriction command is sent to the access control component to reduce the range of accessible interfaces or shorten session duration; for high-risk situations, a blocking command is sent to the blocking execution component to add the source IP to the temporary blocking list, terminate active sessions, or freeze associated accounts. Each protection policy has a set validity period parameter, remaining effective for the access target within the specified period.
[0077] In some embodiments, automatic matching and execution of protection policies can be achieved in several ways: Optionally, the system maintains a policy configuration table indexed by risk level. After determining the risk level, the system directly looks up the list of protection measures in the table and sends control commands to each execution component in order of priority to complete the implementation. Optionally, the system uses a rule engine to perform rule matching with risk level, access object type, and business scenario identifier as input conditions. After outputting applicable policy combinations, the system converts them into execution commands and sends them to the gateway or access control component for execution. It is understood that other methods can also be used to achieve policy matching and execution, which are not limited here.
[0078] To further illustrate the correspondence between different risk levels and protection strategies, please refer to [link / reference]. Figure 5 This is a schematic diagram of the dynamic blocking and policy execution mechanism in the embodiments of this application.
[0079] like Figure 5 As shown, the abnormal risk score results first enter the risk level determination module. This module compares the dynamic risk score with the preset risk threshold and divides the accessed object into two levels, low risk and high risk, based on the risk score range in which the score falls.
[0080] For access objects determined to be of low risk level, the system selects and executes one of three lightweight protection measures: the rate limiting module limits the rate of subsequent requests to the access object, reducing its access frequency per unit time; the CAPTCHA verification module initiates a human verification request to the access object, distinguishing between automated scripts and normal user access through CAPTCHA verification; and the delayed response module increases the response delay time for the access object's requests, reducing the execution efficiency of its batch access.
[0081] For access targets deemed high-risk, the system selects and executes one of three high-strength protection measures: the access blocking module directly rejects subsequent access requests from the target and returns a blocking response; the IP temporary blocking module adds the target's source IP address to a temporary blocking list, blocking all access requests from that IP address for a set blocking period; and the session isolation module terminates the target's current active session and clears associated session state information, preventing it from using established sessions to perform abnormal operations. Each protection measure has a set validity period parameter, remaining in effect for the target within that period.
[0082] S205. Record the blocking execution results and subsequent behavioral changes of the accessed object, and dynamically adjust the model parameters and risk thresholds of the normal behavior baseline model based on the blocking execution results and subsequent behavioral changes.
[0083] The blocking execution result refers to the status record after the protection strategy is implemented, including the type of measures implemented, the time, the object identification, and the execution status. Subsequent behavioral changes refer to the continued access behavior of the accessing object within the observation period after the protection strategy is implemented. Effective blocking refers to the situation where the subsequent behavioral deviation remains below the risk threshold within the observation period; ineffective blocking refers to the situation where the subsequent behavioral deviation exceeds the risk threshold again. Model parameters refer to the mean and variance of each dimension in the baseline model. The risk threshold refers to the boundary value used to distinguish different risk levels.
[0084] Specifically, after the protection strategy is implemented, the system enters the observation phase. Within a preset observation period, it continuously collects subsequent behavioral data of the access target and extracts feature vectors, comparing them with the baseline model to calculate the deviation of subsequent behavior. When the deviation remains below the risk threshold throughout the observation period, it is marked as effective blocking; otherwise, it is marked as ineffective blocking. For effectively blocked access targets, the subsequent behavioral feature vectors from the observation period are incorporated into the historical data of the baseline model, and the mean and variance of each dimension are recalculated to update the model parameters. The system calculates the ineffective blocking rate within a preset evaluation period; if it exceeds a preset proportion threshold, the risk threshold is lowered; if it falls below the proportion threshold, the risk threshold is raised. The adjusted parameters are applied to the deviation calculation and score generation in subsequent windows.
[0085] In some embodiments, blocking result analysis and dynamic model adjustment can be achieved in multiple ways: Optionally, the system creates blocking records when the protection strategy is executed, collects behavioral data in each sub-window of the observation period, calculates the deviation, and writes it into the records. After the period ends, the system determines the effectiveness label based on whether the deviation of each sub-window is lower than the threshold. The mean and variance of the feature vector of effective blocking are updated incrementally. At the end of each evaluation period, the ineffective blocking rate is calculated and the risk threshold is adjusted according to a preset step size. Optionally, the system adopts a sliding evaluation window method, calculates the ratio of effective to ineffective blocking within the window, determines the threshold adjustment magnitude and direction based on the deviation of this ratio from the target value, and updates the baseline model parameters of the feature vector of effective blocking in an exponentially weighted manner. It is understood that other methods can also be used to achieve blocking effectiveness determination and dynamic model adjustment, which are not limited here.
[0086] In some embodiments, this step specifically includes:
[0087] Within a preset observation period after the protection strategy is implemented, subsequent access behaviors of the accessed objects are collected and subsequent behavior feature vectors are extracted. The deviation of subsequent behaviors is calculated by comparing them with the normal behavior baseline model. The correlation analysis between the blocking execution results and the subsequent behavior deviation is performed. When the subsequent behavior deviation is consistently lower than the risk threshold within the observation period, it is marked as effective blocking. When it exceeds the risk threshold again, it is marked as ineffective blocking. For accessed objects marked as effectively blocked, the subsequent behavior feature vectors within the observation period are incorporated into the historical feature data of the normal behavior baseline model. The mean and variance of each feature dimension are recalculated to update the model parameters. Within a preset evaluation period, the proportion of ineffective blocking to all blocking execution results is statistically analyzed as the ineffective blocking rate. When the ineffective blocking rate exceeds the preset proportion threshold, the risk threshold is lowered. When it is lower than the preset proportion threshold, the risk threshold is raised. The adjusted model parameters and risk threshold are applied to the behavior deviation calculation and dynamic risk score generation in the subsequent sliding time window.
[0088] The preset observation period refers to a fixed time interval used to observe the subsequent behavior of the accessed object after the protection strategy is executed, for example, set to 30 minutes. The subsequent behavior feature vector refers to the behavioral feature vector extracted from subsequent access behavior within the observation period using the same method as normal feature extraction. Effective blocking refers to the situation where the deviation of subsequent behavior remains below the risk threshold throughout the entire observation period. Ineffective blocking refers to the situation where the deviation of subsequent behavior reaches or exceeds the risk threshold again within the observation period. The ineffective blocking rate is the ratio of the number of ineffective blocks within the preset evaluation period to the total number of blocking executions.
[0089] Specifically, after the protection strategy is executed, the system starts an observation timer. During the observation period, it continuously collects subsequent access request data of the accessed object in units of recovery monitoring windows. Feature extraction is performed on the data in each sub-window to generate a subsequent behavior feature vector. This vector is then compared with the normal behavior baseline model dimension by dimension, and the standardized distance is calculated and weighted to obtain the subsequent behavior deviation. At the end of the observation period, the following criteria are determined: if the deviation of each sub-window is below the risk threshold, the block is marked as effective; if the deviation of any sub-window reaches or exceeds the risk threshold, it is marked as ineffective. For effectively blocked accessed objects, the system appends the subsequent behavior feature vectors generated by each sub-window during the observation period to the historical feature data set of the baseline model, and recalculates the arithmetic mean and variance of each dimension to cover the original parameters and complete the model update. At the end of each evaluation period, the system calculates the number of ineffective blocks in all block records within that period, divides it by the total number of blocks to obtain the ineffective block rate, and compares this rate with a preset threshold: if it exceeds the threshold, the risk threshold is subtracted by a preset adjustment step size to reduce the rate; if it is below the threshold, the risk threshold is added to the preset adjustment step size to increase the rate. The adjusted model parameters and risk thresholds are written to the configuration storage, and the deviation calculation and score generation of the subsequent sliding time window are executed by reading the updated values.
[0090] For a further explanation of the specific process of feedback learning and model optimization, please refer to [link / reference]. Figure 6 This is a schematic diagram of the feedback learning and model optimization mechanism in the embodiments of this application.
[0091] like Figure 6 As shown, the feedback learning and model optimization process takes the anomaly detection and blocking results as input and goes through four stages in sequence: effect evaluation, parameter analysis, threshold adjustment and model update.
[0092] The effectiveness evaluation module assesses the effectiveness of the blocking results within a preset observation period after the protection strategy is implemented. It quantifies the detection performance of the current model and strategy using metrics such as accuracy and false alarm rate. Accuracy reflects the proportion of correctly identified abnormal access behavior, while the false alarm rate reflects the proportion of normal access behavior misclassified as abnormal.
[0093] Based on the effect evaluation results, the model parameter analysis module analyzes whether the mean and variance parameters of each feature dimension in the normal behavior baseline model need to be adjusted, and identifies the feature dimensions that cause misjudgment or omission and their offset direction.
[0094] The threshold dynamic adjustment module dynamically adjusts the risk threshold based on parameter analysis results. When the invalid blocking rate exceeds the preset proportional threshold, it indicates that the current risk threshold is too high, causing some abnormal behaviors to be not effectively blocked. The system lowers the risk threshold to improve detection sensitivity. When the invalid blocking rate is lower than the preset proportional threshold, it indicates that the current detection sensitivity is sufficient. The system raises the risk threshold to reduce false alarms.
[0095] The behavior model update module writes the adjusted model parameters and risk thresholds into the normal behavior baseline model. For access subjects marked as effectively blocked, it incorporates subsequent behavioral feature vectors within the observation period into historical feature data to recalculate the mean and variance of each dimension, thus completing the model parameter update. The updated model serves as the output of the optimized model and is applied to the calculation of behavioral deviation and the generation of dynamic risk scores in subsequent sliding time windows, forming a closed-loop feedback mechanism for continuous optimization.
[0096] The following provides a more detailed description of the process of the method provided in this implementation. Please refer to [link / reference]. Figure 7 This is another flowchart illustrating the abnormal access prediction and dynamic blocking method based on streaming behavior modeling in this application.
[0097] S701. During the execution of the protection strategy, the behavior deviation of the access object in each recovery monitoring window is continuously calculated in a preset period. When the behavior deviation of the access object in each preset number of consecutive recovery monitoring windows is lower than the current risk threshold, the access restriction measures on the access object are lifted in order of protection strategy strength from high to low until the access permission is fully restored.
[0098] The recovery monitoring window refers to the time interval during which the subsequent behavior of the accessed object is continuously observed at fixed intervals during the execution of the protection policy. For example, each recovery monitoring window is set to 5 minutes, and the system calculates the deviation of the behavior data within the window every 5 minutes. The consecutive preset number refers to the number of consecutive windows that meet the threshold as a condition for lifting the restriction. For example, if it is set to 3, the deviation must be below the threshold for 3 consecutive recovery monitoring windows before the lifting operation can be triggered. Step-by-step lifting refers to the process of revoking the restrictions in descending order of the strength level of the protection policy. For example, if the currently implemented protection policy includes IP blocking, interface permission restriction, and request rate limiting, the lifting order is to first revoke the IP blocking, then restore the interface permission, and finally cancel the rate limiting.
[0099] Specifically, after the protection strategy takes effect, the system initiates a recovery monitoring process. It periodically collects behavioral data of the accessed object according to the duration of the recovery monitoring window and extracts behavioral feature vectors. This vector is then compared dimension-by-dimensionally with the normal behavior baseline model to calculate the standardized distance and generate a behavioral deviation. The system maintains a continuous compliance counter. At the end of each recovery monitoring window, it checks whether the deviation is below the current risk threshold. If it is, the counter is incremented; otherwise, it is reset to zero. When the counter value reaches a preset number, a strategy cancellation operation is triggered. The system selects the strongest protection measure from the currently effective list and cancels it. After cancellation, the counter is reset to zero, and the next monitoring cycle begins. Subsequently, each time the counter reaches the threshold again, the next level of protection is canceled, and this cycle continues until all restrictions are lifted, and the accessed object regains full access rights.
[0100] S702. During the process of gradually lifting access restrictions, if the behavior deviation of the accessed object exceeds the current risk threshold again, the lifting process will be stopped and the risk level of the accessed object will be restored to the level before the lifting. At the same time, the count of the monitoring window will be reset.
[0101] The process of suspending the lifting of restrictions refers to immediately stopping the revocation of subsequent measures when the deviation from the expected risk threshold is exceeded again during the process of gradually lifting restrictions. Restoring to the pre-lifting risk level means resetting the risk level of the accessed individual to the level before the current lifting process was triggered, and re-executing all protective measures corresponding to that level. Resetting the counter means clearing the value of the continuous compliance counter to zero, requiring the accessed individual to meet the continuous compliance conditions again before the lifting process can be triggered again.
[0102] Specifically, the system continuously calculates behavioral deviation within the subsequent recovery monitoring window after each restriction is revoked. When the deviation value within a window is greater than or equal to the current risk threshold, the system immediately executes a stop operation. The stop operation consists of three steps: First, the current removal process is stopped, and no further low-intensity restrictions in the queue are revoked; second, the risk level recorded before the start of this removal process is read, the risk level of the accessed object is restored to that recorded value, and all protective measures corresponding to that level are reissued to the execution component for effect, including reactivating measures that have been revoked; third, the continuous compliance counter is reset to zero, and the accessed object needs to accumulate consecutive compliance counts again in the subsequent recovery monitoring window. This mechanism ensures that accessed objects whose behavior has not truly returned to normal cannot regain permissions through a brief disguise.
[0103] S703. Extend the window duration of the subsequent recovery monitoring window for access objects that have triggered the suspension and release process a preset number of times within the preset statistical period, and increase the basic weight of the access objects in the subsequent dynamic risk score calculation.
[0104] The preset statistical period refers to a fixed time interval used to count the number of times the suspension / relief process is triggered, such as 1 hour. The cumulative number of suspension / relief process triggers reaching the preset number refers to the total number of times the same access object's process is suspended / relieved again due to exceeding the deviation limit within this statistical period, reaching a set threshold, such as 3 times. Extending the window duration means increasing the time span of the subsequent recovery monitoring window for this access object, for example, extending the original 5-minute window to 10 minutes. Increasing the base weight means increasing the initial values of the weight adjustment factors for each dimension in the subsequent dynamic risk scoring calculation for this access object.
[0105] Specifically, the system maintains a counter for the number of times the termination and cancellation process is triggered for each access object within the current statistical period, incrementing the counter by one each time a termination operation is executed. When the counter value reaches a preset number, the system performs two parameter adjustments for the access object: First, it multiplies the subsequent recovery monitoring window length of the access object by a preset extension coefficient to obtain a new window length. For example, if the extension coefficient is 2, the window lengthens from 5 minutes to 10 minutes, making the behavior observation interval longer and requiring the access object to remain stable for a longer period before triggering termination. Second, it increases the base weight value of the access object in the subsequent dynamic risk score calculation by a preset increment, so that the standardized distance of each dimension of the access object generates a higher weighted contribution when multiplied by the weight adjustment factor, thereby obtaining a higher dynamic risk score under the same degree of deviation and improving the sensitivity to repeatedly abnormal access objects.
[0106] S704. Within the current sliding time window, extract the behavioral feature vectors of multiple different access objects and calculate the similarity between the behavioral feature vectors of each access object.
[0107] Here, multiple different access objects refer to independent access sources with different access identification information that have access behavior records within the current sliding time window. Behavioral feature vector similarity is a numerical value obtained by measuring the similarity between the behavioral feature vectors of two access objects; the higher the value, the more similar their behavioral patterns are.
[0108] Specifically, at the end of the current sliding time window, the system extracts the behavioral feature vectors of all active access objects within that window. Access objects within the window are paired, and cosine similarity is calculated for each pair of behavioral feature vectors: the inner product is obtained by multiplying the corresponding dimensions of the two vectors dimension by dimension and summing the results; the square root of the sum of the squares of each dimension of the two vectors is then calculated to obtain their respective magnitudes; the inner product is divided by the product of the two magnitudes to obtain the cosine similarity value, which ranges from -1 to 1. The closer the value is to 1, the more consistent the directions of the two vectors, indicating more similar behavioral patterns. When the number of active access objects within the window is large, the system first groups and filters them according to the target interface visited, performing similarity calculations only on access object pairs whose target interfaces overlap, reducing unnecessary computation.
[0109] S705. When the similarity of the behavioral feature vectors between a preset number of different access objects exceeds a preset similarity threshold, and the target interfaces accessed by different access objects within the same time window overlap, the different access objects are marked as a collaborative behavior group.
[0110] The preset number of different access objects refers to the minimum number of access objects required to participate in the collaborative behavior determination. For example, if it is set to 3, then the flag will only be triggered when at least 3 different access objects meet the conditions. Overlapping target interfaces means that different access objects send requests with the same target interface address within the same time window. A collaborative behavior group refers to a set of multiple access objects determined to have collaborative access characteristics, and members within the group share the same group identifier.
[0111] Specifically, after calculating the similarity between each pair of accessed objects, the system filters out all pairs of accessed objects whose similarity exceeds a preset similarity threshold. These pairs are then constructed into an undirected graph, where each node represents an accessed object, and there is an edge between two nodes whose similarity exceeds the threshold. The system performs connected component detection on this graph, extracting connected components containing a preset number of nodes as candidate groups. For each candidate group, the system extracts the set of target interface addresses accessed by each accessed object within the current window, calculates the intersection between the sets, and confirms that the target interface overlap condition is met when the intersection contains at least one identical target interface address. All accessed objects within this candidate group are then marked as belonging to the same collaborative behavior group and assigned a unified group identifier. Candidate groups that do not meet the interface overlap condition are not marked.
[0112] S706. The dynamic risk score of each access object marked as a collaborative behavior group is supplemented with a collaborative risk additional score on the basis of the original score. The collaborative risk additional score is determined by the number of access objects included in the collaborative behavior group and the similarity of the behavioral feature vectors.
[0113] The collaborative risk bonus score refers to the additional score added to the original dynamic risk score of an accessed object because it is marked as a member of a collaborative behavior group. This bonus score is determined by two factors: the number of accessed objects included in the collaborative behavior group and the similarity of the behavioral feature vectors within the group. The more accessed objects there are and the higher the similarity, the greater the bonus score.
[0114] Specifically, after the collaborative behavior group is marked, the system calculates a collaborative risk bonus score for each access object within the group and adds it to its dynamic risk score. The calculation method is as follows: the total number of access objects in the collaborative behavior group is taken as a quantity factor; the arithmetic mean of the similarity of behavioral feature vectors between all pairs of access objects within the group is taken as a similarity factor; the quantity factor and the similarity factor are multiplied together, and then multiplied by a preset collaborative risk coefficient to obtain the collaborative risk bonus score. For example, if the group contains 5 access objects, the average similarity within the group is 0.92, and the collaborative risk coefficient is set to 10, then the bonus score is 5 multiplied by 0.92 multiplied by 10, which equals 46. The system adds this bonus score to each member's original dynamic risk score to obtain an updated score, and then re-compares the risk level against the risk threshold based on the updated score. If the level changes, the corresponding protection strategy is switched and executed.
[0115] The server in the embodiments of this invention is described below from the perspective of hardware processing. Please refer to [link / reference]. Figure 8 This is a schematic diagram of the physical device structure of a server in an embodiment of this application.
[0116] It should be noted that, Figure 8 The server structure shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0117] like Figure 8 As shown, the server includes a CPU 801, which can perform various appropriate actions and processes according to a program stored in ROM 802 or a program loaded from storage portion 808 into RAM 803, such as performing the methods described in the above embodiments. RAM 803 also stores various programs and data required for system operation. CPU 801, ROM 802, and RAM 803 are interconnected via bus 804. I / O interface 805 is also connected to bus 804.
[0118] The following components are connected to I / O interface 805: input section 806 including audio input devices, push-button switches, etc.; output section 807 including liquid crystal display (LCD) and audio output devices, indicator lights, etc.; storage section 808 including hard disks, etc.; and communication section 809 including network interface cards such as LAN (Local Area Network) cards, modems, etc. Communication section 809 performs communication processing via a network such as the Internet. Drive 810 is also connected to I / O interface 805 as needed. Removable media 811, such as disks, optical disks, magneto-optical disks, semiconductor memories, etc., are installed on drive 810 as needed so that computer programs read from them can be installed into storage section 808 as needed.
[0119] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by CPU 801, it performs the various functions defined in the present invention.
[0120] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those shown in the drawings.
[0121] Specifically, the server in this embodiment includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, it implements the abnormal access prediction and dynamic blocking method based on streaming behavior modeling provided in the above embodiment.
[0122] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the server described in the above embodiments; or it may exist independently and not assembled into the server. The storage medium carries one or more computer programs that, when executed by a processor of the server, cause the server to implement the abnormal access prediction and dynamic blocking method based on streaming behavior modeling provided in the above embodiments.
[0123] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0124] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".
Claims
1. A method for anomaly access prediction and dynamic blocking based on streaming behavior modeling, characterized in that, Applied to a server, the method includes: Real-time network access data is collected and connected to a streaming computing framework. Based on access identification information, discrete access requests for the same access object are aggregated according to a sliding time window and organized into an access behavior sequence in chronological order. The network access data includes access request information and access context information. Multidimensional behavioral features are extracted from the access behavior sequence to form a behavioral feature vector corresponding to the current sliding time window. A normal behavior baseline model of the accessed object is established based on the behavioral feature vectors accumulated in multiple consecutive sliding time windows. The behavior feature vector within the current sliding time window is compared with the normal behavior baseline model in real time to calculate the behavior deviation. A dynamic risk score is generated based on the behavior deviation and access context information. The accessed object is classified into the corresponding risk level according to the dynamic risk score. Automatically match and execute the corresponding protection strategy based on the risk level; Record the blocking execution results and subsequent behavioral changes of the accessed object, and dynamically adjust the model parameters and risk thresholds of the normal behavior baseline model based on the blocking execution results and the subsequent behavioral changes.
2. The method according to claim 1, characterized in that, The step of extracting multi-dimensional behavioral features from the access behavior sequence to form a behavioral feature vector corresponding to the current sliding time window, and establishing a normal behavior baseline model of the accessed object based on the behavioral feature vectors accumulated within multiple consecutive sliding time windows, specifically includes: The total number of access requests within the current sliding time window is statistically analyzed according to the time dimension of the access behavior sequence as the access frequency value. The time interval between adjacent access requests is calculated to form a time interval sequence. The mean and variance of the time interval sequence are calculated as the time interval distribution feature. The access frequency value and the time interval distribution feature are combined into a time series statistical feature. Extract the interface identifiers accessed by each access request in chronological order to form an interface call sequence. Count the number of unique interface identifiers as the interface coverage. Calculate the change magnitude between the request parameters of adjacent access requests to form a parameter change sequence and take the average as the parameter change intensity. Combine the interface coverage and parameter change intensity to form a behavioral pattern feature. The time-series statistical features and behavioral pattern features are normalized and then concatenated to form the behavioral feature vector corresponding to the current sliding time window. The behavioral feature vectors within multiple consecutive sliding time windows are accumulated in chronological order, and the mean and variance of each feature dimension are calculated to construct a baseline model of the normal behavior of the accessed object.
3. The method according to claim 1, characterized in that, The steps of comparing the behavioral feature vector within the current sliding time window with the normal behavioral baseline model in real time to calculate the behavioral deviation, generating a dynamic risk score based on the behavioral deviation and access context information, and classifying the accessed object into corresponding risk levels based on the dynamic risk score specifically include: The behavior feature vector within the current sliding time window is compared dimension by dimension with the mean of the corresponding feature dimension in the normal behavior baseline model. The standardized distance of the current feature value from the mean in each feature dimension is calculated and combined to form the behavior deviation. Obtain the access context information within the current sliding time window, and determine the weight adjustment factor corresponding to each feature dimension based on the degree of change of the access source region, device identifier, and login authentication status compared to the previous sliding time window; The standardized distances of each feature dimension are multiplied by their respective weight adjustment factors and then summed to generate a dynamic risk score within the current sliding time window. The dynamic risk score is compared with a preset risk threshold, and the accessed object is classified into a corresponding risk level based on the risk score range in which the dynamic risk score falls.
4. The method according to claim 1, characterized in that, The steps of recording the blocking execution results and subsequent behavioral changes of the accessed object, and dynamically adjusting the model parameters and risk thresholds of the normal behavior baseline model based on the blocking execution results and the subsequent behavioral changes, specifically include: Within a preset observation period after the protection strategy is executed, the subsequent access behavior of the accessed object is collected and the subsequent behavior feature vector is extracted. The subsequent behavior deviation is calculated by comparing it with the normal behavior baseline model. The correlation analysis between the blocking execution result and the deviation of subsequent behavior is performed. When the deviation of subsequent behavior is continuously lower than the risk threshold during the observation period, it is marked as effective blocking. When it exceeds the risk threshold again, it is marked as ineffective blocking. Based on the validity labeling results, the model parameters and risk thresholds of the normal behavior baseline model are dynamically adjusted, and the adjusted model parameters and risk thresholds are applied to the behavioral deviation calculation and dynamic risk score generation in subsequent sliding time windows.
5. The method according to claim 4, characterized in that, The step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the validity labeling results specifically includes: For access targets marked as effectively blocked, the subsequent behavioral feature vectors within the observation period are incorporated into the historical feature data of the normal behavior baseline model, and the mean and variance of each feature dimension are recalculated to update the model parameters. The proportion of invalid blocking to all blocking results within a preset evaluation period is used as the invalid blocking rate. When the invalid blocking rate exceeds a preset percentage threshold, the risk threshold is lowered; when it is lower than the preset percentage threshold, the risk threshold is raised.
6. The method according to claim 1, characterized in that, After the step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the blocking execution result and the subsequent behavioral changes, the method further includes: During the execution of the protection strategy, the behavior deviation of the access object in each recovery monitoring window is continuously calculated with a preset recovery monitoring window as the cycle. When the behavior deviation of the access object in each consecutive preset number of recovery monitoring windows is lower than the current risk threshold, the access restriction measures on the access object are lifted in order of protection strategy strength from high to low until the access permission is fully restored. If the behavior deviation of the access object exceeds the current risk threshold again during the process of gradually lifting access restrictions, the lifting process will be stopped and the risk level of the access object will be restored to the level before the lifting. At the same time, the count of the recovery monitoring window will be reset. Extend the window duration of the subsequent recovery monitoring window for access objects that have triggered the suspension and release process a preset number of times within a preset statistical period, and increase the basic weight of the access objects in the subsequent dynamic risk score calculation.
7. The method according to claim 1, characterized in that, After the step of dynamically adjusting the model parameters and risk threshold of the normal behavior baseline model based on the blocking execution result and the subsequent behavioral changes, the method further includes: Within the current sliding time window, extract the behavioral feature vectors of multiple different access objects and calculate the similarity between the behavioral feature vectors of each access object. When the similarity of the behavioral feature vectors between a preset number of different access objects exceeds a preset similarity threshold, and the target interfaces accessed by the different access objects within the same time window overlap, the different access objects are marked as a collaborative behavior group. The dynamic risk score of each access object marked as a collaborative behavior group is supplemented with a collaborative risk additional score on the basis of the original score. The collaborative risk additional score is determined by the number of access objects included in the collaborative behavior group and the similarity of the behavioral feature vectors.
8. A server, characterized in that, The server includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code including computer instructions, and the one or more processors call the computer instructions to cause the server to perform the method as described in any one of claims 1-7.
9. A computer-readable storage medium comprising instructions, characterized in that, When the instructions are executed on the server, the server causes the server to perform the method as described in any one of claims 1-7.
10. A computer program product, characterized in that, When the computer program product is run on the server, the server performs the method as described in any one of claims 1-7.