Application programming interface asset management method and apparatus, and electronic device
By extracting and aggregating asset information of application program interface assets in network traffic data, the problem of poor management timeliness is solved, real-time management of API assets and data security guarantees are achieved.
Patent Information
- Application Number
- PCT/CN2024/135609
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-16
- Filing Date
- 2024-11-29
- Publication Date
- 2025-07-24
Smart Images

Figure CN2024135609_24072025_PF_FP_ABST
Abstract
Description
Application program interface asset management method, device, and electronic device
[0001] Related applications
[0002] This application claims priority to Chinese patent application number 2024100644708, filed on January 16, 2024, entitled “Method, device and electronic device for managing application program interface assets,” the entire text of which is hereby incorporated by reference. Technical Field
[0003] The present application relates to the field of data processing, and more specifically, to a method, device, and electronic device for managing application program interface assets. Background Art
[0004] As companies and organizations establish more and more digital systems, these systems will provide internal and external application programming interfaces (APIs). All API-related information and resources are called API assets, including the API's name, description, version, endpoints, authorization mechanisms, availability, and performance metrics. To better manage an organization's API assets and meet security audit requirements, it's necessary to centrally manage API information from each system.
[0005] Existing technologies for managing API assets from network traffic data can collect API assets in real time through each business system and then report them to the API asset management system. However, due to differences between business systems and network issues, this approach inevitably results in omissions and gaps in the collected API assets, leading to poor real-time management of API assets. Furthermore, this approach fails to collect sensitive information associated with API assets, making it impossible to take appropriate measures for APIs involving sensitive information, resulting in low data security.
[0006] Regarding the problem of poor timeliness in managing application program interface assets in network traffic data in related technologies due to the large amount of network traffic data, no effective solution has been proposed so far. Summary of the Invention
[0007] According to the first aspect of the present application, a method for managing application program interface assets is provided, the method comprising: upon receiving network traffic data, extracting asset information of the application program interface assets contained in each network request in the network traffic data to obtain an asset information set, wherein the asset information comprises at least the following information: asset path, request type, and sensitive information type, wherein the sensitive information type refers to the type of sensitive information when the application program interface asset contains sensitive information; aggregating the asset information in the asset information set according to the asset path and the request type to obtain N types of asset information, wherein N is a positive integer; counting the sensitive information type involved in each type of asset information in the N types of asset information according to the asset information set to obtain target asset information; and updating the asset information in a preset database according to the target asset information to manage the application program interface assets in the network traffic data, wherein the preset database stores the asset information of the application program interface assets.
[0008] In some embodiments, extracting the asset information of the application interface assets contained in each network request in the network traffic data to obtain an asset information set includes: extracting the request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and the request type; determining the application interface assets contained in the request parameter set through a preset regular expression to obtain an asset information set; determining the first asset information containing sensitive information in the asset information set through the regular expression, marking the first asset information, and updating the asset information in the asset information set.
[0009] In some embodiments, determining the application program interface assets included in the request parameter set using a preset regular expression to obtain the asset information set includes: using a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter at least includes the following field information: the request domain name and the request path; when the first matching result indicates a successful match, determining the first network request corresponding to the first matching result, and generating the asset path of the first network request; when the first matching result indicates a failed match, using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, wherein the second network request refers to the network request in the request parameter set other than the first network request; and combining the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
[0010] In some embodiments, using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result includes: splitting the request path of each second network request based on preset characters to obtain a first path list for each second network request; using the multiple second regular expressions to perform regular matching on each element in the first path list in sequence to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed based on different aggregation rules; when the third matching result indicates a successful match, using a second preset string to replace the successfully matched element to obtain a second path list for each second network request; splicing the elements in the second path list to obtain a target path for each second network request, and generating the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0011] In some embodiments, determining the first asset information containing sensitive information in the asset information set through the regular expression, marking the first asset information, and updating the asset information in the asset information set includes: using a third regular expression set to match each network request in the request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; when the third matching result indicates a successful match, determining the asset information corresponding to the successfully matched network request in the asset information set to obtain the first asset information; determining the sensitive information type of the first asset information based on the third matching result, and updating the asset information set using the sensitive information type of the first asset information.
[0012] In some embodiments, before determining the application interface assets included in the request parameter set through a preset regular expression and obtaining the asset information set, the method also includes: determining the aggregation rules of the application interface assets based on business needs; configuring the regular expression based on the aggregation rules to obtain the preset regular expression, and loading the preset regular expression.
[0013] In some embodiments, updating the asset information in the preset database based on the target asset information includes: when the target asset information is inconsistent with the asset information in the preset database, updating the corresponding asset information in the preset database based on the target asset information; when the target asset information is consistent with the asset information in the preset database, updating the time information of the corresponding asset information in the target asset information in the preset database.
[0014] According to the second aspect of the present application, a device for managing application program interface assets is provided, which includes: an extraction unit for extracting, when network traffic data is received, asset information of the application program interface assets contained in each network request in the network traffic data, to obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, and sensitive information type, wherein the sensitive information type refers to the type of sensitive information when the application program interface asset contains sensitive information; an aggregation unit for aggregating the asset information in the asset information set according to the asset path and the request type, to obtain N types of asset information, wherein N is a positive integer; a statistics unit for counting the sensitive information type involved in each type of asset information in the N types of asset information according to the asset information set, to obtain target asset information; an update unit for updating the asset information in a preset database according to the target asset information, so as to manage the application program interface assets in the network traffic data, wherein the preset database stores the asset information of the application program interface assets.
[0015] In some embodiments, the extraction unit includes: an extraction subunit, used to extract request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and the request type; a first determination subunit, used to determine the application interface assets included in the request parameter set through a preset regular expression to obtain an asset information set; a marking subunit, used to determine the first asset information containing sensitive information in the asset information set through the regular expression, mark the first asset information, and update the asset information in the asset information set.
[0016] In some embodiments, the determination subunit includes: a first matching module, configured to use a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter includes at least the following field information: the request domain name and the request path; a first determination module, configured to determine the first network request corresponding to the first matching result when the first matching result indicates a successful match, and generate the asset path of the first network request; a second matching module, configured to use multiple second regular expressions to match the request path of the second network request when the first matching result indicates a failed match, to obtain a second matching result, and generate the asset path of the second network request based on the second matching result, wherein the second network request refers to a network request other than the first network request in the request parameter set; and a combination module, configured to combine the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
[0017] In some embodiments, the second matching module includes: a splitting submodule for splitting the request path of each second network request according to preset characters to obtain a first path list for each second network request; a matching submodule for performing regular matching on each element in the first path list in sequence using the multiple second regular expressions to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed according to different aggregation rules; a replacement submodule for replacing the successfully matched element with a second preset string when the third matching result indicates a successful match to obtain a second path list for each second network request; and a splicing submodule for splicing the elements in the second path list to obtain a target path for each second network request, and generating the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0018] In some embodiments, the labeling sub-unit includes: a third matching module, used to use a third regular expression set to match each network request in the request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; a second determination module, used to determine the asset information corresponding to the successfully matched network request in the asset information set when the third matching result indicates a successful match, to obtain the first asset information; an update module, used to determine the sensitive information type of the first asset information based on the third matching result, and update the asset information set using the sensitive information type of the first asset information.
[0019] In some embodiments, the extraction unit also includes: a second determination sub-unit, used to determine the application interface assets included in the request parameter set through a preset regular expression, and before obtaining the asset information set, determine the aggregation rules of the application interface assets based on business needs; a loading sub-unit, used to configure the regular expression based on the aggregation rule, obtain the preset regular expression, and load the preset regular expression.
[0020] In some embodiments, the update unit includes: a first update sub-unit, used to update the corresponding asset information in the preset database based on the target asset information when the target asset information is inconsistent with the asset information in the preset database; a second update sub-unit, used to update the time information of the corresponding asset information in the target asset information in the preset database when the target asset information is consistent with the asset information in the preset database.
[0021] According to a third aspect of the present application, a computer-readable storage medium is provided, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned application interface asset management methods.
[0022] According to the fourth aspect of the present application, an electronic device is provided, comprising one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any one of the above-mentioned methods for managing application program interface assets.
[0023] The details of one or more embodiments of the present application are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the present application will become apparent from the description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings, which constitute part of this application, are intended to provide a further understanding of this application. The exemplary embodiments and descriptions of this application are intended to explain this application and do not constitute an improper limitation on this application. In the accompanying drawings:
[0025] FIG1 is a flowchart of a method for managing application program interface assets according to a first embodiment of the present application;
[0026] FIG2 is a schematic diagram of an optional method for managing application program interface assets according to the first embodiment of the present application;
[0027] FIG3 is a schematic diagram of an application program interface asset management device according to a second embodiment of the present application;
[0028] FIG4 is a schematic diagram of an electronic device for managing application program interface assets according to a fifth embodiment of the present application. DETAILED DESCRIPTION
[0029] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0030] It should be noted that the user information (including but not limited to user device information, user personal information, user information contained in network traffic data, user information contained in application program interfaces, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, collected network traffic data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant areas, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0033] For ease of description, some nouns or terms involved in the embodiments of the present application are explained below:
[0034] Flink: Apache Flink is a framework and distributed processing engine for stateful computations on unbounded and bounded data streams. Flink runs on all common cluster environments and can perform computations at memory speed and at any scale.
[0035] Example 1
[0036] The present application is described below in conjunction with implementation steps. FIG1 is a flow chart of a method for managing application program interface assets according to a first embodiment of the present application. As shown in FIG1 , the method includes the following steps:
[0037] Step S101, when network traffic data is received, extract the asset information of the application interface asset contained in each network request in the network traffic data to obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, sensitive information type, and the sensitive information type refers to the type of sensitive information when the application interface asset contains sensitive information.
[0038] In this first embodiment, a network request refers to the act of a user's client sending a request to a server to obtain a specific resource, such as a request to obtain content such as a web page, image, video, or data. This request can be made using the HTTP protocol or other requests, such as FTP (File Transfer Protocol) requests, SSH (Secure Shell) requests, and DNS (Domain Name System) requests. Requests generated using the HTTP protocol are referred to as HTTP requests.
[0039] To manage API asset information (i.e., the aforementioned application program interface asset information) in network traffic data in real time, it is necessary to extract the API asset information involved in each network request from the request parameters in the network traffic data. The aforementioned asset information set is derived from the API asset information for each network request. The asset path in the API asset information identifies the API asset involved in the network request. The request type refers to the type of network request, such as GET, POST, PUT, DELETE, etc., and the sensitive information type refers to the type of sensitive information contained in the network request, such as ID number, mobile phone number, etc.
[0040] Step S102 : Aggregate the asset information in the asset information set according to the asset path and the request type to obtain N types of asset information, where N is a positive integer.
[0041] In the first embodiment of the present invention, in order to manage the API assets in the network requests collected in real time, it is necessary to aggregate the API assets in the network requests according to business needs or the aggregation needs of business personnel, so as to count the API asset information in the network traffic data according to the category of API assets, meet the needs of business personnel in managing API assets, and at the same time remove redundant asset information in the network requests, so as to facilitate management by business personnel, thereby achieving the effect of improving the efficiency of business personnel in managing API assets.
[0042] In an optional embodiment, aggregation rules can be determined based on business needs. Different asset paths and request types can be defined in the aggregation rules. Then, each API asset in the asset information set is classified according to the asset path and request type to obtain the above-mentioned N types of asset information.
[0043] Step S103: Count the sensitive information types involved in each type of asset information in the N types of asset information based on the asset information set to obtain target asset information.
[0044] In the first embodiment of this invention, after the asset information is aggregated and classified, the sensitive information involved in the plain text transmission in each type of API asset can be counted, that is, the unencrypted sensitive information transmitted in each type of API asset can be counted. This can help enterprises to promptly discover and deal with potential security risks, take corresponding protection measures, and ensure the data security and privacy of users. At the same time, it avoids the problem of too many API assets and redundant asset information making it difficult for business personnel to manage API assets.
[0045] In step S104 , the asset information in the preset database is updated according to the target asset information to manage the application program interface assets in the network traffic data, wherein the preset database stores the asset information of the application program interface assets.
[0046] In the first embodiment of the present invention, in order to avoid storing each API asset immediately in the preset database after it is parsed, resulting in a large amount of read and write resources being occupied and resulting in low cluster processing efficiency, the API asset information can be aggregated, and the sensitive information types involving sensitive information can be counted to obtain the target asset information. Then, the asset information in the preset database can be updated in batches according to the target asset information, so as to achieve the effect of saving cluster resources while improving the real-time and accuracy of asset information.
[0047] In summary, the method for managing application interface assets provided in the first embodiment of the present application obtains an asset information set by extracting the asset information of the application interface assets contained in each network request in the network traffic data when receiving network traffic data, wherein the asset information includes at least the following information: asset path, request type, and sensitive information type, where the sensitive information type refers to the type of sensitive information of the application interface asset when it contains sensitive information; the asset information in the asset information set is aggregated according to the asset path and request type to obtain N types of asset information, wherein N is a positive integer; the sensitive information type involved in each type of asset information in the N types of asset information is counted according to the asset information set to obtain target asset information; the asset information in the preset database is updated according to the target asset information to manage the application interface assets in the network traffic data, wherein the preset database stores the asset information of the application interface assets, which solves the problem of poor timeliness of managing application interface assets in the related technology due to the large amount of network traffic data when managing application interface assets in network traffic data. By extracting and aggregating a large number of API assets requested by network traffic data, and batch updating the API asset information in the preset database based on the aggregated asset information, it is possible to extract key information and remove redundant information to assist business personnel in managing API assets, thereby ensuring the real-time nature of API asset information and achieving the effect of real-time management of API assets by business personnel. At the same time, by counting sensitive information types, it is helpful for business personnel to configure corresponding security measures for API assets based on the sensitive information types, thereby achieving the effect of ensuring data security.
[0048] Optionally, in the application interface asset management method provided in Example 1 of the present application, asset information of the application interface assets contained in each network request in the network traffic data is extracted to obtain an asset information set, including: extracting request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and request type; determining the application interface assets contained in the request parameter set through a preset regular expression to obtain an asset information set; determining the first asset information containing sensitive information in the asset information set through a regular expression, marking the first asset information, and updating the asset information in the asset information set.
[0049] In the first embodiment of the present invention, in order to manage API assets in real time, network traffic data can be captured in real time, and the relevant parameters of each network request (i.e., the above-mentioned request parameter set) can be extracted from it. The API assets contained in the network request can be parsed according to the relevant parameters of each network request in the request parameter set, and the sensitive information type of each API asset involving sensitive information can be marked.
[0050] Specifically, a traffic probe is used to collect network traffic data (e.g., HTTP data stream) and store it in a Kafka cluster or other data storage system. The network traffic data is obtained from the Kafka cluster, and then the relevant parameters of each network request in the network traffic data are parsed into a preset data structure, namely the request parameters mentioned above. The field information contained in the request parameters is shown in Table 1, where the request domain name refers to the domain address accessed by the HTTP request, for example, "www.example.com", the request path refers to the path of the specific resource requested by the HTTP request, for example, " / index.html", the request parameters refer to the parameters of the HTTP request, for example, "id=123" in "http: / / example.com / api / user?id=123", the response parameters refer to the parameters of the response result returned to the client after the server responds to the HTTP request, for example, a status code of 200 indicates a successful response, a Content-Type (the type of data returned) of a string, etc., and the request type refers to the type of HTTP request, indicating the operation to be performed by the server, for example, GET, POST, PUT, DELETE, etc. After parsing the network parameters of each network request, the request parameter set mentioned above is obtained from the network parameters of all network requests.
[0051] Next, the request parameters of each network request in the request parameter set are matched using a preset regular expression, parsing the API assets therein to obtain the asset information set. The preset regular expression is pre-configured and loaded based on the API asset aggregation rules. Finally, each API asset in the asset information set is determined to contain sensitive information based on the regular expression matching sensitive information, as well as the type of sensitive information. The sensitive information is then labeled accordingly, and the asset information in the asset information set is updated.
[0052] Table 1
[0053] Optionally, in the application interface asset management method provided in the first embodiment of the present application, the application interface assets included in the request parameter set are determined by a preset regular expression to obtain an asset information set, including: using a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter includes at least the following field information: request domain name, request path; when the first matching result indicates a successful match, determining the first network request corresponding to the first matching result, and generating the asset path of the first network request; when the first matching result indicates a failed match, using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, wherein the second network request refers to a network request other than the first network request in the request parameter set; combining the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
[0054] In this first embodiment, the first regular expression is configured based on a higher-priority aggregation rule. The higher-priority aggregation rule may be an aggregation rule developed based on business requirements. An example of the first regular expression is shown in Table 2, where the rule tag value refers to the tag value used to tag the asset information of the network request after a successful match. It should be noted that the number of first regular expressions can be adaptively adjusted based on business requirements and is not specifically limited in this first embodiment.
[0055] Multiple second regular expressions are multiple regular expressions constructed based on different URL path analysis rules, and are used to classify API assets into multiple categories according to different URL paths. An example of the second regular expression can be shown in Table 3, which includes aggregation rules for three types of URL paths, corresponding to different rule tag values (such as ":id", ":uuid", and ":.jpg" in Table 3).
[0056] Table 2
[0057] Table 3
[0058] In an optional embodiment, when parsing API assets in a network request, at least one first regular expression can be used to match the request domain name and request path (i.e., the target parameters) of each network request in the request parameter set. If the request domain name and request path of the network request successfully match the first regular expression, the asset path of the API asset of the current network request is directly marked according to the request type of the network request and the rule tag value corresponding to the first regular expression. If the request domain name and request path of the network request do not successfully match the first regular expression, multiple second regular expressions are used to match the network request. Once a regular expression is successfully matched with any of the multiple second regular expressions, the asset path of the network request is generated according to the request parameters of the network request and the rule tag value corresponding to the second regular expression that successfully matched. If the network request fails to match all the second regular expressions, the next network request is parsed. Finally, the asset information of each network request is determined according to the request type and asset path of each network request to obtain the above-mentioned asset information set.
[0059] Optionally, in the application program interface asset management method provided in the first embodiment of the present application, multiple second regular expressions are used to match the request path of the second network request to obtain a second matching result, and the asset path of the second network request is generated based on the second matching result, including: splitting the request path of each second network request according to preset characters to obtain a first path list for each second network request; using multiple second regular expressions to perform regular matching on each element in the first path list in turn to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed based on different aggregation rules; when the third matching result indicates a successful match, using a second preset string to replace the successfully matched element to obtain a second path list for each second network request; splicing the elements in the second path list to obtain a target path for each second network request, and generating the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0060] In an optional embodiment, the delimiter " / " (i.e., the preset character mentioned above) can be used to split the request path of each second network request, and the split character string is used as each element of the list to obtain the first path list of each second network request mentioned above. Then, the multiple second regular expressions contained in Table 3 are used to perform regular matching with each element in the first path list in turn. When a column element successfully matches any second regular expression, the rule tag value corresponding to the successfully matched second regular expression is used to replace the successfully matched element in the first path list. If each element in the first path list fails to match all the second regular expressions, the element in the first path list is not replaced. Finally, after the first path list corresponding to each network request is matched, the replaced first path lists are spliced as the target path corresponding to each network request, and the request type, request domain name and target path of the network request are used as the asset path of the network request.
[0061] Optionally, in the application interface asset management method provided in Example 1 of the present application, first asset information containing sensitive information in an asset information set is determined by using a regular expression, the first asset information is marked, and the asset information in the asset information set is updated, including: using a third regular expression set to match each network request in the request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; when the third matching result indicates a successful match, the asset information corresponding to the successfully matched network request is determined in the asset information set to obtain the first asset information; the sensitive information type of the first asset information is determined based on the third matching result, and the asset information set is updated using the sensitive information type of the first asset information.
[0062] In this first embodiment, a corresponding regular expression can be configured based on at least one sensitive information type involved in the API asset, namely the third regular expression set described above. Each third regular expression in the third regular expression set is matched against the request parameters in each network request. If a match is successful, the network request is added with the sensitive information identifier corresponding to the third regular expression (such as the rule tag value in Table 4), namely the first asset information described above, thereby determining the sensitive information type involved in the sensitive information of each API asset in the asset information set, and updating the asset information set. The third regular expression in the third regular expression set can be as shown in Table 4.
[0063] Table 4
[0064] Optionally, in the application interface asset management method provided in Example 1 of the present application, before determining the application interface assets included in the request parameter set through a preset regular expression and obtaining the asset information set, the above method also includes: determining the aggregation rules of the application interface assets based on business needs; configuring the regular expression based on the aggregation rules, obtaining the preset regular expression, and loading the preset regular expression.
[0065] In the first embodiment of the present invention, in order to flexibly adjust the aggregation results of API assets according to business needs, the aggregation rules of the API can be flexibly configured and / or adjusted according to business needs, and the corresponding regular expressions, i.e., the above-mentioned preset regular expressions (for example, the above-mentioned first regular expression, the above-mentioned second regular expression, the above-mentioned third regular expression) are configured according to the determined aggregation rules, and it is necessary to pre-load the configured aggregation rules before parsing the network traffic data so as to parse the collected network traffic data in real time. In addition, in an optional embodiment, the preset regular expression can also be loaded into the keyby operator, and multiple network requests can be parsed in parallel through the keyby operator, thereby achieving the effect of improving the processing efficiency of network requests and further achieving the effect of ensuring the real-time management of API assets.
[0066] In an optional embodiment, when business personnel need to change the aggregation rules (for example, business personnel find that there is unclustered API asset information in the preset database, or API asset information with incorrect clustering results), the parsing rules can be adjusted according to the API asset information in the preset database, that is, the above-mentioned higher-priority aggregation rules, and the first regular expression corresponding to the higher-priority aggregation rules can be adjusted accordingly, and then the adjusted first regular expression can be reconfigured and loaded to continue processing the http data stream.
[0067] Optionally, in the application interface asset management method provided in Example 1 of the present application, updating the asset information in the preset database based on the target asset information includes: when the target asset information is inconsistent with the asset information in the preset database, updating the corresponding asset information in the preset database based on the target asset information; when the target asset information is consistent with the asset information in the preset database, updating the time information of the corresponding asset information in the target asset information in the preset database.
[0068] In the first embodiment of the present invention, in order to ensure the real-time nature of the API asset information in the preset database, it is necessary to compare the target asset information with the API asset information stored in the preset database after the target asset information is counted to see whether the network request information, API asset type, quantity, and sensitive information type of the API assets in the two are consistent. If there is any inconsistency, the API asset information in the preset database is updated based on the target asset information. For example, if there is one more API asset of the jpg type in the target asset information than in the preset database, the API asset is added to the preset database and the update time is recorded. If there is any inconsistency, the update time of the API asset contained in the target asset information in the preset database is updated according to the current moment to ensure the real-time nature of the API asset information. Business personnel can also adjust the aggregation rules based on the updated asset information in the preset database and load the aggregation rules so that the adjusted aggregation rules can be used to parse the http data stream later.
[0069] Optionally, in the first embodiment of the present invention, the process of updating API asset information in real time can be shown in FIG2. First, the http data stream is collected through the traffic probe, the http data stream is formatted, and the request parameters of each http request in the http data stream are extracted to obtain the above-mentioned request parameter set. Then, a first regular expression with a higher priority is used to match the request parameters of each network request in the request parameter set. If the match is successful, the next network request is matched. If the match is unsuccessful, multiple second regular expressions are used for matching, and the asset information of each network request is parsed to obtain the asset information, and the sensitive information type of each network request involving sensitive information is marked to obtain the above-mentioned asset information set. Finally, the API assets in the http data stream are aggregated according to the asset information of each network request, and the sensitive information type involved in each type of asset information is counted to obtain the above-mentioned target asset information. The API asset information in the preset database (such as the API asset library in FIG2) is updated based on the target asset information to ensure the real-time nature of the data.
[0070] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0071] Example 2
[0072] The second embodiment of the present application also provides an application program interface asset management device. It should be noted that the application program interface asset management device of the second embodiment of the present application can be used to execute the application program interface asset management method provided in the first embodiment of the present application. The following describes the application program interface asset management device provided in the second embodiment of the present application.
[0073] FIG3 is a schematic diagram of an apparatus for managing application program interface assets according to a second embodiment of the present application. As shown in FIG3 , the apparatus includes: an extraction unit 301 , an aggregation unit 302 , a statistics unit 303 , and an update unit 304 .
[0074] Specifically, the extraction unit 301 is used to extract the asset information of the application interface assets contained in each network request in the network traffic data when receiving the network traffic data, and obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, and sensitive information type. The sensitive information type refers to the type of sensitive information when the application interface asset contains sensitive information.
[0075] The aggregation unit 302 is configured to aggregate the asset information in the asset information set according to the asset path and the request type to obtain N types of asset information, where N is a positive integer.
[0076] The statistical unit 303 is used to count the sensitive information types involved in each type of asset information in the N types of asset information based on the asset information set to obtain target asset information.
[0077] The updating unit 304 is configured to update the asset information in the preset database according to the target asset information so as to manage the application program interface assets in the network traffic data, wherein the preset database stores the asset information of the application program interface assets.
[0078] The second embodiment of the present application provides an application program interface asset management device. When receiving network traffic data, an extraction unit 301 extracts the asset information of the application program interface asset contained in each network request in the network traffic data to obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, and sensitive information type. The sensitive information type refers to the type of sensitive information when the application program interface asset contains sensitive information; an aggregation unit 302 aggregates the asset information in the asset information set according to the asset path and request type to obtain N types of asset information, wherein N is a positive integer; a statistics unit 303 counts the sensitive information type involved in each type of asset information in the N types of asset information according to the asset information set to obtain target asset information; an update unit 304 updates the asset information in the preset database according to the target asset information to manage the application program interface assets in the network traffic data, wherein the preset database stores the asset information of the application program interface assets, thereby solving the problem of poor timeliness of managing application program interface assets in the related art due to the large amount of network traffic data when managing application program interface assets in network traffic data. By extracting and aggregating a large number of API assets requested by network traffic data, and batch updating the API asset information in the preset database based on the aggregated asset information, it is possible to extract key information and remove redundant information to assist business personnel in managing API assets, thereby ensuring the real-time nature of API asset information and achieving the effect of real-time management of API assets by business personnel. At the same time, by counting sensitive information types, it is helpful for business personnel to configure corresponding security measures for API assets based on the sensitive information types, thereby achieving the effect of ensuring data security.
[0079] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned extraction unit 301 includes: an extraction sub-unit, used to extract the request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and request type; a first determination sub-unit, used to determine the application interface assets included in the request parameter set through a preset regular expression to obtain an asset information set; a marking sub-unit, used to determine the first asset information containing sensitive information in the asset information set through a regular expression, mark the first asset information, and update the asset information in the asset information set.
[0080] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned determination subunit includes: a first matching module, which is used to use a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter includes at least the following field information: request domain name, request path; a first determination module, which is used to determine the first network request corresponding to the first matching result when the first matching result indicates a successful match, and generate the asset path of the first network request; a second matching module, which is used to use multiple second regular expressions to match the request path of the second network request when the first matching result indicates a failed match, to obtain a second matching result, and generate the asset path of the second network request based on the second matching result, wherein the second network request refers to the network request other than the first network request in the request parameter set; a combination module, which is used to combine the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain an asset information set.
[0081] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned second matching module includes: a splitting submodule, which is used to split the request path of each second network request according to preset characters to obtain a first path list for each second network request; a matching submodule, which is used to use multiple second regular expressions to perform regular matching on each element in the first path list in sequence to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed according to different aggregation rules; a replacement submodule, which is used to replace the successfully matched elements with a second preset string when the third matching result indicates a successful match to obtain a second path list for each second network request; a splicing submodule, which is used to splice the elements in the second path list to obtain the target path of each second network request, and generate the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0082] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned annotation sub-unit includes: a third matching module, used to use a third regular expression set to match each network request in the request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; a second determination module, used to determine the asset information corresponding to the successfully matched network request in the asset information set when the third matching result indicates a successful match, to obtain the first asset information; an update module, used to determine the sensitive information type of the first asset information based on the third matching result, and update the asset information set using the sensitive information type of the first asset information.
[0083] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned extraction unit 301 also includes: a second determination sub-unit, used to determine the application interface assets included in the request parameter set through a preset regular expression, and before obtaining the asset information set, determine the aggregation rules of the application interface assets according to business needs; a loading sub-unit, used to configure the regular expression according to the aggregation rule, obtain the preset regular expression, and load the preset regular expression.
[0084] Optionally, in the application interface asset management device provided in Example 2 of the present application, the above-mentioned update unit 304 includes: a first update sub-unit, used to update the corresponding asset information in the preset database based on the target asset information when the target asset information is inconsistent with the asset information in the preset database; a second update sub-unit, used to update the time information of the corresponding asset information in the target asset information in the preset database when the target asset information is consistent with the asset information in the preset database.
[0085] The management device for the application interface assets includes a processor and a memory. The above-mentioned extraction unit 301, aggregation unit 302, statistics unit 303 and update unit 304 are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize corresponding functions.
[0086] The processor contains a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be configured, and the real-time performance of managing API assets can be improved by adjusting kernel parameters.
[0087] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0088] A third embodiment of the present application provides a computer-readable storage medium having a program stored thereon, which implements a method for managing application program interface assets when executed by a processor.
[0089] A fourth embodiment of the present application provides a processor, which is used to run a program, wherein the method for managing application program interface assets is executed when the program is running.
[0090] As shown in Figure 4, embodiment five of the present application provides an electronic device, which includes a processor, a memory, and a program stored in the memory and runnable on the processor. When the processor executes the program, the following steps are implemented: when network traffic data is received, the asset information of the application interface assets contained in each network request in the network traffic data is extracted to obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, sensitive information type, and the sensitive information type refers to the type of sensitive information of the application interface asset when it contains sensitive information; the asset information in the asset information set is aggregated according to the asset path and request type to obtain N types of asset information, wherein N is a positive integer; the sensitive information type involved in each type of asset information in the N types of asset information is counted according to the asset information set to obtain target asset information; the asset information in the preset database is updated according to the target asset information to manage the application interface assets in the network traffic data, wherein the preset database stores the asset information of the application interface assets.
[0091] When the processor executes the program, the following steps are also implemented: extracting the asset information of the application interface assets contained in each network request in the network traffic data to obtain an asset information set, including: extracting the request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and request type; determining the application interface assets contained in the request parameter set through a preset regular expression to obtain an asset information set; determining the first asset information containing sensitive information in the asset information set through a regular expression, marking the first asset information, and updating the asset information in the asset information set.
[0092] When the processor executes the program, the following steps are also implemented: determining the application program interface assets included in the request parameter set through a preset regular expression, and obtaining the asset information set includes: using a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter at least includes the following field information: request domain name, request path; when the first matching result indicates a successful match, determining the first network request corresponding to the first matching result, and generating the asset path of the first network request; when the first matching result indicates a failed match, using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, wherein the second network request refers to a network request other than the first network request in the request parameter set; combining the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
[0093] When the processor executes the program, the following steps are also implemented: using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, including: splitting the request path of each second network request according to preset characters to obtain a first path list for each second network request; using multiple second regular expressions to perform regular matching on each element in the first path list in sequence to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed according to different aggregation rules; when the third matching result indicates a successful match, using a second preset string to replace the successfully matched element to obtain a second path list for each second network request; splicing the elements in the second path list to obtain a target path for each second network request, and generating the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0094] When the processor executes the program, the following steps are also implemented: determining first asset information containing sensitive information in an asset information set through a regular expression, marking the first asset information, and updating the asset information in the asset information set, including: using a third regular expression set to match each network request in the request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; when the third matching result indicates a successful match, determining the asset information corresponding to the successfully matched network request in the asset information set to obtain the first asset information; determining the sensitive information type of the first asset information based on the third matching result, and updating the asset information set using the sensitive information type of the first asset information.
[0095] When the processor executes the program, the following steps are also implemented: before determining the application interface assets included in the request parameter set through a preset regular expression and obtaining the asset information set, the above method also includes: determining the aggregation rules of the application interface assets based on business needs; configuring the regular expression based on the aggregation rules, obtaining the preset regular expression, and loading the preset regular expression.
[0096] When the processor executes the program, it also implements the following steps: updating the asset information in the preset database based on the target asset information includes: when the target asset information is inconsistent with the asset information in the preset database, updating the corresponding asset information in the preset database based on the target asset information; when the target asset information is consistent with the asset information in the preset database, updating the time information of the corresponding asset information in the target asset information in the preset database.
[0097] The devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0098] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialized program having the following method steps: when network traffic data is received, extracting the asset information of the application interface assets contained in each network request in the network traffic data to obtain an asset information set, wherein the asset information includes at least the following information: asset path, request type, sensitive information type, and the sensitive information type refers to the type of sensitive information of the application interface asset when it contains sensitive information; aggregating the asset information in the asset information set according to the asset path and request type to obtain N types of asset information, wherein N is a positive integer; counting the sensitive information types involved in each type of asset information in the N types of asset information according to the asset information set to obtain target asset information; and updating the asset information in the preset database according to the target asset information to manage the application interface assets in the network traffic data, wherein the preset database stores the asset information of the application interface assets.
[0099] When executed on a data processing device, it is also suitable for executing an initialization program having the following method steps: extracting the asset information of the application interface assets contained in each network request in the network traffic data to obtain an asset information set including: extracting the request parameters of each network request in the network traffic data to obtain a request parameter set, wherein the request parameters include at least the following field information: request domain name, request path, request parameters, response parameters, and request type; determining the application interface assets contained in the request parameter set through a preset regular expression to obtain an asset information set; determining the first asset information containing sensitive information in the asset information set through a regular expression, marking the first asset information, and updating the asset information in the asset information set.
[0100] When executed on a data processing device, it is also suitable for executing an initialization program having the following method steps: determining the application interface assets included in the request parameter set through a preset regular expression to obtain an asset information set, including: using a first regular expression to match the target parameter of each network request in the request parameter set to obtain a first matching result, wherein the target parameter at least includes the following field information: request domain name, request path; when the first matching result indicates a successful match, determining the first network request corresponding to the first matching result, and generating the asset path of the first network request; when the first matching result indicates a failed match, using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, wherein the second network request refers to a network request other than the first network request in the request parameter set; combining the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
[0101] When executed on a data processing device, the program is also suitable for executing an initialization program having the following method steps: using multiple second regular expressions to match the request path of the second network request to obtain a second matching result, and generating the asset path of the second network request based on the second matching result, including: splitting the request path of each second network request based on preset characters to obtain a first path list for each second network request; using multiple second regular expressions to perform regular matching on each element in the first path list in sequence to obtain a third matching result, wherein the multiple second regular expressions are regular expressions constructed based on different aggregation rules; when the third matching result indicates a successful match, replacing the successfully matched element with a second preset string to obtain a second path list for each second network request; splicing the elements in the second path list to obtain a target path for each second network request, and generating the asset path of the second network request based on the request parameters of each second network request and the target path of each second network request.
[0102] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: determining first asset information containing sensitive information in an asset information set through a regular expression, marking the first asset information, and updating the asset information in the asset information set, including: using a third regular expression set to match each network request in a request parameter set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed based on different sensitive information types; when the third matching result indicates a successful match, determining the asset information corresponding to the successfully matched network request in the asset information set to obtain the first asset information; determining the sensitive information type of the first asset information based on the third matching result, and updating the asset information set using the sensitive information type of the first asset information.
[0103] When executed on a data processing device, it is also suitable for executing an initialization program having the following method steps: before determining the application interface assets included in the request parameter set through a preset regular expression and obtaining the asset information set, the above method also includes: determining the aggregation rules of the application interface assets based on business needs; configuring the regular expression based on the aggregation rules, obtaining the preset regular expression, and loading the preset regular expression.
[0104] When executed on a data processing device, it is also suitable for executing an initialized program having the following method steps: updating the asset information in the preset database based on the target asset information includes: when the target asset information is inconsistent with the asset information in the preset database, updating the corresponding asset information in the preset database based on the target asset information; when the target asset information is consistent with the asset information in the preset database, updating the time information of the corresponding asset information in the target asset information in the preset database.
[0105] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0106] The present application is described with reference to the flow chart and / or block diagram of the method, device (system), and computer program product according to the embodiment of the present application. It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processing machine or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for realizing the function specified in one flow chart flow or multiple flows and / or one box or multiple boxes of the block diagram.
[0107] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0109] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0110] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0111] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0112] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0113] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0114] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A method for managing application programming interface (API) assets, comprising: When receiving network traffic data, extracting asset information of API assets included in each network request in the network traffic data to obtain an asset information set, where the asset information at least includes the following information: asset path, request type, sensitive information type, and the sensitive information type refers to the type of sensitive information when the API asset contains sensitive information; Aggregating the asset information in the asset information set according to the asset path and the request type to obtain N types of asset information, where N is a positive integer; Counting the sensitive information types involved in each type of asset information in the N types of asset information according to the asset information set to obtain target asset information; Updating the asset information in a preset database according to the target asset information to manage the API assets in the network traffic data, where the preset database stores the asset information of the API assets.
2. The method according to claim 1, wherein extracting asset information of API assets included in each network request in the network traffic data to obtain an asset information set includes: Extracting request parameters of each network request in the network traffic data to obtain a request parameter set, where the request parameters at least include the following field information: request domain name, request path, request parameters, response parameters, and the request type; Determining API assets included in the request parameter set through a preset regular expression to obtain an asset information set; Determining first asset information with sensitive information in the asset information set through the regular expression, marking the first asset information, and updating the asset information in the asset information set.
3. The method according to claim 2, wherein determining API assets included in the request parameter set through a preset regular expression to obtain an asset information set includes: Matching target parameters of each network request in the request parameter set with a first regular expression to obtain a first matching result, where the target parameters at least include the following field information: the request domain name, the request path; When the first matching result indicates successful matching, determining the first network request corresponding to the first matching result and generating the asset path of the first network request; When the first matching result indicates failed matching, matching the request path of a second network request with a plurality of second regular expressions to obtain a second matching result, and generating the asset path of the second network request according to the second matching result, where the second network request refers to a network request other than the first network request in the request parameter set; Combining the request type of the first network request, the asset path of the first network request, the request type of the second network request, and the asset path of the second network request to obtain the asset information set.
4. The method according to claim 3, wherein matching the request path of the second network request by using a plurality of second regular expressions to obtain a second matching result, and generating the asset path of the second network request according to the second matching result includes: Splitting the request path of each second network request according to a preset character to obtain a first path list of each second network request; Performing regular matching on each element in the first path list by using the plurality of second regular expressions to obtain a third matching result, wherein the plurality of second regular expressions are regular expressions constructed according to different aggregation rules; When the third matching result indicates a successful match, replacing the successfully matched element with a second preset string to obtain a second path list of each second network request; Concatenating the elements in the second path list to obtain a target path of each second network request, and generating the asset path of the second network request according to the request parameters of each second network request and the target path of each second network request.
5. The method according to claim 2, wherein determining, by using the regular expression, a first asset information with sensitive information in the asset information set, marking the first asset information, and updating the asset information in the asset information set includes: Matching each network request in the request parameter set by using a third regular expression set to obtain a third matching result, wherein the third regular expression set includes a set of regular expressions constructed according to different sensitive information types; When the third matching result indicates a successful match, determining, in the asset information set, the asset information corresponding to the successfully matched network request to obtain the first asset information; Determining the sensitive information type of the first asset information according to the third matching result, and updating the asset information set by using the sensitive information type of the first asset information.
6. The method according to claim 2, wherein before obtaining the asset information set by determining, by using a preset regular expression, the application programming interface assets included in the request parameter set, the method further includes: Determining an aggregation rule of the application programming interface assets according to business requirements; Configuring a regular expression according to the aggregation rule to obtain the preset regular expression, and loading the preset regular expression.
7. The method according to claim 1, wherein updating the asset information in the preset database according to the target asset information includes: When the target asset information is inconsistent with the asset information in the preset database, updating the corresponding asset information in the preset database according to the target asset information; When the target asset information is consistent with the asset information in the preset database, updating the time information of the corresponding asset information in the target asset information in the preset database.
8. A management device for application programming interface assets, comprising: An extraction unit, configured to extract asset information of application programming interface assets included in each network request in the network traffic data when receiving the network traffic data, so as to obtain an asset information set, where the asset information at least includes the following information: an asset path, a request type, and a sensitive information type, and the sensitive information type refers to the type of sensitive information when the application programming interface asset includes sensitive information; An aggregation unit, configured to aggregate the asset information in the asset information set according to the asset path and the request type to obtain N types of asset information, where N is a positive integer; A statistics unit, configured to count the sensitive information types involved in each type of asset information in the N types of asset information according to the asset information set to obtain target asset information; An update unit, configured to update the asset information in a preset database according to the target asset information to manage the application programming interface assets in the network traffic data, where the preset database stores the asset information of the application programming interface assets.
9. A computer-readable storage medium, the computer-readable storage medium comprising a stored computer program, wherein, When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the management method of the application programming interface assets according to any one of claims 1 to 7.
10. An electronic device includes one or more processors and a memory, where the memory is used to store one or more programs, wherein, When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the management method of the application programming interface assets according to any one of claims 1 to 7.
Citation Information
Patent Citations
A vulnerability monitoring and detecting system for an intelligent network information system
CN109167799A
API asset management method and device, electronic equipment and storage medium
CN116170331A
Traffic data classification method and device, equipment and storage medium
CN116738369A
Application program interface asset management method and device and electronic equipment
CN117892348A
Automated learning of externally defined network assets by a network security device
US20190297055A1