AI 中文总结
针对Web应用程序授权违规难实时检测处理的问题,提出非侵入式流量分析框架,通过关联事务提取信息并映射到风险组件,经加权融合等产生分级决策,在测试中取得高准确率等结果,证明了框架可行性。
AI 中文摘要
在有效的Web会话中,授权违规很难通过流量实时识别和处理,因为它们强烈依赖业务语义且协议级特征不明显。本文提出一个用于授权风险检测与协同响应的非侵入式流量分析框架。通过关联请求-响应事务来提取访问主体、业务端点等信息。将多种因素映射到可解释的风险组件,经加权融合和高风险优先级约束产生分级决策。在含2000个平衡标记样本的受控本地测试平台及原型可行性测试中取得了较好结果,证明了该框架的可行性,但未证明在生产环境中的普遍适用性。
英文摘要
Authorization violations under valid Web sessions are difficult to identify and handle in real time from traffic because they depend strongly on business semantics and exhibit few distinctive protocol-level features. This paper proposes a non-intrusive traffic analysis framework for authorization risk detection and coordinated response. Request-response transactions are correlated to extract the access subject, business endpoint, object identifier, authentication state, and behavioral sequence. Object-access evidence, identity consistency, behavioral anomalies, authentication context, network environment, and endpoint-operation risk are mapped to interpretable risk components. Weighted fusion and high-risk priority constraints produce graded decisions that drive allow, alert, block, and external policy actions. The risk components are instantiated using deterministic and interpretable rules to evaluate multi-source evidence organization, risk fusion, and the coordinated-response loop at the framework level. In a controlled local testbed containing 2,000 balanced labeled samples, the framework classified 998 of 1,000 authorization-risk events as risky and produced no false positives among 1,000 normal accesses, achieving 99.90% accuracy, 100.00% precision, 99.80% recall, and a 99.90% F1 score. Removing runtime object evidence reduced the F1 score to 81.31%, while removing the high-risk priority constraint reduced it to 73.90%. In a prototype feasibility test with 100 concurrent requests and 1,000 total requests, mean risk-decision computation latency was 0.077 ms and P99 latency was 0.137 ms. The results demonstrate the feasibility of organizing heterogeneous runtime evidence and establishing an executable authorization-risk decision and coordinated-response loop without modifying application code, but do not establish general applicability in production environments.
Comments25 pages; bilingual English-Chinese version. The complete English version is followed by the complete Chinese version; each version contains 3 figures and 5 tables