Business Logic Protection via Tracking Code Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing business logic protection methods are inefficient and resource-intensive due to complex authentication processes, failing to effectively prevent vulnerabilities in complex business systems.
Innovation Solution
A big-data-based business logic learning method and apparatus that identifies and updates procedure direction tables by parsing network requests, distributing tracking codes with request identifiers and timestamps, and restarting business logic processes when deviations are detected, thereby improving protection efficiency and adaptability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple verifying or manual verifying measures are used to protect business logic, then security protection is provided, but resource consumption increases and protection efficiency decreases
Solution Approach 1:
The system performs preliminary learning of normal business logic procedures in advance through tracking codes and procedure direction tables. By pre-establishing what constitutes normal behavior patterns, the system can quickly validate requests without complex real-time verification, thus improving protection efficiency while maintaining security.
Solution Approach 2:
The system creates a virtual model of normal business logic procedures by copying and analyzing tracking data from multiple requests. This virtual model (procedure direction table) serves as a reference for validation, replacing the need for complex manual verification processes while maintaining protection reliability.
2Reliability
If multiple verifying or manual verifying measures are used to protect business logic, then security protection is provided, but resource consumption increases
Solution Approach 1:
The system creates a virtual model of normal business logic procedures by copying and analyzing tracking data from multiple requests. This virtual model (procedure direction table) serves as a reference for validation, replacing the need for complex manual verification processes while maintaining protection reliability.
Solution Approach 2:
The system automatically learns and updates normal business logic patterns through tracking codes embedded in requests. This self-learning mechanism eliminates the need for continuous manual verification configuration, reducing resource consumption while maintaining protection effectiveness.
3Reliability
If complex authentication processes are used for business logic protection, then security is improved, but user experience is degraded
Solution Approach 1:
The system extracts only the essential validation logic from complex authentication processes. By separating the core procedure validation from unnecessary authentication steps, the system maintains security while significantly improving user experience through simpler, faster request processing.
4Adaptability or versatility
If big data-based learning is performed to obtain normal requesting procedures, then adaptability to changing business logic is improved, but system complexity increases
Solution Approach 1:
The system performs preliminary learning of normal business logic procedures in advance through tracking codes and procedure direction tables. By pre-establishing what constitutes normal behavior patterns, the system can quickly validate requests without complex real-time verification, thus improving protection efficiency while maintaining security.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The present disclosure discloses methods and apparatuses for learning and protecting business logic based on big data. The learning method includes: receiving a network request sent by a requester, recognizing a current request identifier of the network request, and parsing procedure information of the network request; extracting a reference request identifier from the procedure information, determining whether a direction from the reference request identifier to the current request identifier exists in a procedure direction table, and updating the procedure direction table based on a determination result; and distributing tracking code for the network request, where the tracking code includes the current request identifier and a timestamp for distributing the tracking code. The technical solutions provided in the present disclosure can improve efficiency of protecting business logic based on big data, can be applied to various business logic scenarios, and can flexibly adapt to various changes in business logic requirements.