CN102664913B - Method and device for webpage access control - Google Patents

Method and device for webpage access control Download PDF

Info

Publication number
CN102664913B
CN102664913B CN201210077074.6A CN201210077074A CN102664913B CN 102664913 B CN102664913 B CN 102664913B CN 201210077074 A CN201210077074 A CN 201210077074A CN 102664913 B CN102664913 B CN 102664913B
Authority
CN
China
Prior art keywords
event
chained address
web page
judging
access control
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201210077074.6A
Other languages
Chinese (zh)
Other versions
CN102664913A (en
Inventor
肖锐
肖鹏
向明
宁敢
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qizhi Business Consulting Co ltd
Beijing Qihoo Technology Co Ltd
360 Digital Security Technology Group Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Priority to CN201210077074.6A priority Critical patent/CN102664913B/en
Publication of CN102664913A publication Critical patent/CN102664913A/en
Application granted granted Critical
Publication of CN102664913B publication Critical patent/CN102664913B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Computer And Data Communications (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

The invention discloses a method and a device for webpage access control. The method comprises obtaining the event generated by the operations of input device when webpage is being accessed, judging the obtained event and ascertaining link address corresponding to the object that the event is operating if the event is generated by webpage access, and prohibiting webpage access corresponding to the event if the link address complies with the filtering condition. The embodiment of the invention judges the link address corresponding to the obtained event and prohibits webpage access corresponding to the event when the link address complies with the filtering condition in order to enable analysis and determination of operation event from the bottom, thereby intercepting the access to malicious link prior to the event message being transferred to application layer of the terminal, improving interception reliability and security of network access for users.

Description

Webpage access control method and device
Technical field
The present invention relates to computer realm, and especially, relate to a kind of Webpage access control method and device.
Background technology
At present, user, when accesses network, can be conducted interviews by certain hyperlink in mouse even selected (such as, clicking with the mouse) webpage of keyboard.
But there is a lot of malicious websites (hanging horse fishing website) at present, these websites can provide a lot of malicious link, once user clicks and enter, will be subject to the attack of malicious websites, cause terminal by poisoning intrusion.
In order to improve the fail safe of customer access network, propose the multiple technology carrying out checking also disable access to hyperlink.These prior arts can user select certain hyperlink conduct interviews time, legitimate verification is carried out to hyperlink, connects if this hyperlink is malice, then carry out prompting also disable access.
Although prior art can avoid the attack of malicious websites to a certain extent; but; when user carries out the selected operation of hyperlink by the input equipment such as mouse, keyboard; the event of these operations is obtained by terminal; and each application of terminal system is distributed in the mode of event message; now; hyperlink checking and access are forbidden but not starting to carry out; but; a lot of virus has in fact invaded the system of terminal; therefore, prior art can not realize safeguard protection truly.
For the problem that effectively cannot ensure the fail safe that customer access network links in correlation technique, at present effective solution is not yet proposed.
Summary of the invention
For the problem that effectively cannot ensure the fail safe that customer access network links in correlation technique, the present invention proposes a kind of Webpage access control method and device, more effectively can tackle the access to malicious link, improves the fail safe of customer access network.
Technical scheme of the present invention is achieved in that
According to an aspect of the present invention, a kind of Webpage access control method is provided.
The method comprises:
Obtain input equipment to carry out operating produced event in web page access situation;
The event obtained being judged, when judging that the event obtained is web page access operation, determining the chained address that object that event carries out operating is corresponding;
When judging that chained address meets filter condition, forbid the web page access that execution event is corresponding.
Wherein, determine that the chained address that object that event carries out operating is corresponding comprises:
According to the position of the parameter information determination operation of event;
Whether the object according to the position judgment operation determined is hyperlink;
When the object of judgement operation is hyperlink, determine the chained address that object is corresponding.
In addition, judge that chained address meets filter condition and comprises: search in predetermined malicious link address table, if lookup result is chained address when being arranged in predetermined malicious link address table, judge that chained address meets filter condition, wherein, the malicious link address table terminal local that is kept at input equipment place or in being kept at terminal communication server.
The method comprises further: when judging that chained address meets filter condition, carries out alarm prompt for event.
The method also comprises further: when judging that chained address does not meet filter condition, the event message of event is distributed to the application of registration, and the web page access that the event that performs is corresponding.
Wherein, input equipment comprise following one of at least: mouse, keyboard.
Further, the operation that input equipment performs comprise following one of at least: mouse is clicked, keyboard is selected confirms.
According to a further aspect in the invention, a kind of web page access control device is provided.
This device comprises:
Acquisition module, carries out operating produced event for obtaining input equipment in web page access situation;
Judge module, for judging the event obtained, judges whether the event obtained is web page access operation;
Determination module, for when the judged result of judge module is for being, determines the chained address that object that event carries out operating is corresponding;
Access control module, for judging whether chained address meets filter condition, and when judging that chained address meets filter condition, forbids the web page access that execution event is corresponding.
Whether wherein, determination module is used for the position according to the parameter information determination operation of event, and be hyperlink according to the object of the position judgment operation determined, and when the object of judgement operation is hyperlink, determines the chained address that object is corresponding.
And, access control module is used for searching in predetermined malicious link address table, if lookup result is chained address when being arranged in predetermined malicious link address table, judge that chained address meets filter condition, wherein, the malicious link address table terminal local that is kept at input equipment place or in being kept at terminal communication server.
The present invention is by judging the chained address corresponding to the event obtained, when meeting filter condition, forbid the web page access that implementation event is corresponding, can analyze the Action Events from bottom and judge, thus just tackled to the access of malicious link be forwarded to the application layer of terminal at event message before, improve the reliability of interception, improve the fail safe of customer access network.
Accompanying drawing explanation
In order to be illustrated more clearly in the embodiment of the present invention or technical scheme of the prior art, be briefly described to the accompanying drawing used required in embodiment below, apparently, accompanying drawing in the following describes is only some embodiments of the present invention, for those of ordinary skill in the art, under the prerequisite not paying creative work, other accompanying drawing can also be obtained according to these accompanying drawings.
Fig. 1 is the flow chart of the Webpage access control method according to the embodiment of the present invention;
Fig. 2 is the block diagram of the web page access control device according to the embodiment of the present invention.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the present invention, be clearly and completely described the technical scheme in the embodiment of the present invention, obviously, described embodiment is only the present invention's part embodiment, instead of whole embodiments.Based on the embodiment in the present invention, the every other embodiment that those of ordinary skill in the art obtain, all belongs to the scope of protection of the invention.
According to embodiments of the invention, provide a kind of Webpage access control method.
As shown in Figure 1, comprise according to the Webpage access control method of the embodiment of the present invention:
Step S101, obtain input equipment to carry out operating produced event (now in web page access situation, terminal only obtains the bottom event of this operation, when getting this event, the event information of this event can be stopped to distribute in the application layer of terminal, that is, this operation can not come into force);
Step S103, judges the event obtained, and when judging that the event obtained is web page access operation, determines the chained address that object that this event carries out operating is corresponding;
Step S105, when judging that this chained address meets filter condition, forbids performing web page access corresponding to this event.
Wherein, input equipment can be anyly in terminal can receive user instruction thus carry out the equipment of web page access, such as, can be conventional mouse, keyboard etc.Further, the operation that input equipment performs can comprise any selected operation to hyperlink, and such as, can be that mouse is clicked, keyboard is selected confirms (pressing space or carriage return to hyperlink).
Particularly, when determining chained address corresponding to object that this event carries out operating, can according to the position of the parameter information determination operation of event; Afterwards, whether the object operated according to the position judgment determined is hyperlink (such as, according to the position of the operation determined before, can determine whether this position exists hyperlink, if existed, then can judge that the object of this operation is hyperlink); When the object of judgement operation is hyperlink, determine the chained address that this object is corresponding.
In actual applications, the information obtained for a certain Action Events can comprise a lot of content, except operation position (such as, mouse clicks the position of screen) outside, window corresponding to the position of operation can also be comprised (such as, click under browser window background, or the click carried out under desktop background).
In addition, when judging whether chained address meets filter condition, can carry out searching (the current chained address determining to obtain is mated with the address in predetermined malicious link address table) in predetermined malicious link address table, if lookup result is chained address when being arranged in predetermined malicious link address table, then illustrate that this current chained address determining to obtain is malicious link address, can judge that this chained address meets filter condition.Wherein, malicious link address table comprises many address informations prejudged as malicious link, malicious link address table can be kept at the terminal local at input equipment place, also can be kept in the server with terminal communication, its content can generate according to information such as report records, like this, when know that input equipment performs be operating as a selected hyperlink, will go to inquire about in malicious link address table, determine whether the address of this selected hyperlink is present in malicious link address table, if malicious link address table is preserved in the terminal, then local search can be carried out, if malicious link address table is kept at server end, this server will be arrived and carry out remote inquiry (such as, can cloud inquiry be carried out).
When judgement chained address meets filter condition (this chained address is malicious link address), the event message that not only can stop this accessing operation is distributed in the application layer of terminal, also can carry out alarm prompt for this event, and user can be shown to by being judged as the chained address meeting filter condition.In addition, when carrying out alarm, the option allowing user be confirmed whether to continue this chained address of access can be shown, if user still confirms to need to continue access, then the event message of above-mentioned event being distributed to the application of registration, that is, continuing to perform this web page access.
On the other hand, when judging that chained address does not meet filter condition, the event message of this event is distributed to the application of registration, and performs web page access corresponding to this event.
No matter be that user confirms when alarm to proceed web page access, or this operation is not the operation (without the need to interception) of web page access, or the chained address that this operation is web page access operation and accesses not is malicious link address, all needs the event message of this operation to distribute.
Such as, Action Events (such as, the mouse click event) transmitting procedure in systems in which for webpage relates generally to inner nuclear layer (bottom) R0 and application layer R3.
In R0 and R3, the operation of execution mainly comprises following components:
(1) in R0, in driving, receive the various events of mouse hardware, notice R3 distribute, the present invention then and non-immediate notice R3 distribute, but stop distribution process, the event from bottom produced by web page access is analyzed.
Operation in R3 is as follows:
KiUserCallbackDispatcher: this function finds the KernelCallbackTable system message distributing list of preserving in current process PEB structure to navigate to distribution function corresponding in table according to parameter@Index, Msg is forwarded, such as, the corresponding KernelCallbackTable! of WH_MOUSE message _ fnHkINLPMOUSEHOOKSTRUCTEX;
_ fnHkINLPMOUSEHOOKSTRUCTEX: the mouse event being responsible for the webpages such as process MH_MOUSE, enumerates chained list, unified dispatch messages;
(4) mouse information hook registration function: mouse information hook refers to Action Events and application contacts, like this, just event message can be sent to corresponding application, multiple application (such as, applying 1-N) in terminal system, may be there is;
(5) between message hook and COM, BHO aspect interception OnBeforeNavigate, and URL event can be intercepted and captured, such as, can be tackled by HOOK;
(6) 2 functions ensure the BHO order first of oneself below
IEFRAME!CConnectionPointEnum::Next
IEFRAME!CConnectionPoint::EnumConnections
(7) network filtering layer: intercept and capture download event by Inline Hook with minor function: recv/send/WASRecv/closesocket.
In actual applications, carry out on the basis of tackling in (1) part, can also carry out tackling (such as in (4) part, as mentioned above, tackled by HOOK), and can in (2), (3), (5) or (6) part carries out other interception.
KiUserCallbackDispatcher, because this function is the process function that R3 aspect receives message the earliest, and wherein can process the message such as WH_MOUSE, the WH_DEBUG produced due to operation, so, if carry out the interception of malicious link for this function and stop the forwarding of event message, the access to malicious link address can be avoided as early as possible, improve fail safe; And when tackling, can resolve by web technologies the URL obtaining current click object, inquire about this URL with blocking way.If the download chain of malice, then eject alert box at once, inform that this link of user exists the risk of access, avoid the access to malicious link address.
When warning, can by means of various ways, such as, alarm event message (representing that current needs carries out alarm prompt) can be distributed to can the application of alarm, such as, fire compartment wall, antivirus software etc., alarm is carried out by the application receiving this event message, the mode of alarm is also not only confined to eject alert box, in addition, sound can also be adopted to combine ejection alert box or Pop-up message or sound point out in conjunction with the mode of Pop-up message, the application will not enumerate this.
According to embodiments of the invention, additionally provide a kind of web page access control device.
As shown in Figure 2, web page access control device according to the present invention comprises:
Acquisition module 21, carries out operating produced event for obtaining input equipment in web page access situation;
Judge module 22, for judging the event obtained, judges whether the event obtained is web page access operation;
Determination module 23, for when the judged result of judge module 22 is for being, determines the chained address that object that event carries out operating is corresponding;
Access control module 24, for judging whether chained address meets filter condition, and when judging that chained address meets filter condition, forbids the web page access that execution event is corresponding.
Wherein, whether determination module 23 for the position of the parameter information determination operation according to event, and is hyperlink according to the object of the position judgment operation determined, and when the object of judgement operation is hyperlink, determines the chained address that object is corresponding.
Further, access control module 24 for searching in predetermined malicious link address table, if lookup result is chained address when being arranged in predetermined malicious link address table, judges that chained address meets filter condition.
In addition, access control module can also perform the normal browsing process of above-mentioned R3 part, no longer repeats here.
In sum, by means of technique scheme of the present invention, by judging the chained address corresponding to the event obtained, when meeting filter condition, forbid the web page access that implementation event is corresponding, can analyze the Action Events from bottom and judge, thus just tackle to the access of malicious link be forwarded to the application layer of terminal at event message before, improve the reliability of interception, improve the fail safe of customer access network.
The foregoing is only preferred embodiment of the present invention, not in order to limit the present invention, within the spirit and principles in the present invention all, any amendment done, equivalent replacement, improvement etc., all should be included within protection scope of the present invention.

Claims (8)

1. a Webpage access control method, is characterized in that, comprising:
Obtain input equipment to carry out operating produced event in web page access situation, this event is inner nuclear layer event, and when getting this event, the process function receiving message by means of application the earliest stops the event message of this event to distribute in the application layer of terminal;
The described event obtained being judged, when judging that the described event obtained is web page access operation, determining the chained address that object that described event carries out operating is corresponding;
When judging that described chained address meets filter condition, the event message being stopped this accessing operation by browser auxiliary object BHO aspect blocking way is distributed in the application layer of terminal, forbids performing web page access corresponding to described event;
Wherein, judge that described chained address meets filter condition and comprises:
Search in predetermined malicious link address table, if lookup result is described chained address when being arranged in described predetermined malicious link address table, judge that described chained address meets filter condition, wherein, described malicious link address table is kept at the terminal local at described input equipment place or is kept at the server of described terminal communication.
2. Webpage access control method according to claim 1, is characterized in that, determines that the chained address that object that described event carries out operating is corresponding comprises:
The position of described operation is determined according to the parameter information of described event;
Whether the object operated according to the position judgment determined is hyperlink;
When the object judging described operation is hyperlink, determine the chained address that described object is corresponding.
3. Webpage access control method according to claim 1, is characterized in that, comprises further:
When judging that described chained address meets filter condition, carry out alarm prompt for described event.
4. Webpage access control method according to claim 1, is characterized in that, comprises further:
When judging that described chained address does not meet described filter condition, the event message of described event is distributed to the application of registration, and performs web page access corresponding to described event.
5. Webpage access control method according to any one of claim 1 to 4, is characterized in that, described input equipment comprise following one of at least: mouse, keyboard.
6. Webpage access control method according to claim 5, is characterized in that, the described operation that described input equipment performs comprise following one of at least: mouse is clicked, keyboard is selected confirms.
7. a web page access control device, is characterized in that, comprising:
Acquisition module, carry out operating produced event in web page access situation for obtaining input equipment, this event is inner nuclear layer event, and when getting this event, the process function receiving message by means of application the earliest stops the event message of this event to distribute in the application layer of terminal;
Judge module, for judging the described event obtained, judges whether the described event obtained is web page access operation;
Determination module, for when the judged result of judge module is for being, determines the chained address that object that described event carries out operating is corresponding;
Access control module, for judging whether described chained address meets filter condition, and when judging that described chained address meets described filter condition, the event message being stopped this accessing operation by browser auxiliary object BHO aspect blocking way is distributed in the application layer of terminal, forbid performing web page access corresponding to described event, wherein, judge that described chained address meets filter condition and comprises:
Search in predetermined malicious link address table, if lookup result is described chained address when being arranged in described predetermined malicious link address table, judge that described chained address meets filter condition, wherein, described malicious link address table is kept at the terminal local at described input equipment place or is kept at the server of described terminal communication.
8. web page access control device according to claim 7, it is characterized in that, described determination module is used for the position determining described operation according to the parameter information of described event, and whether the object operated according to the position judgment determined is hyperlink, and when the object judging described operation is hyperlink, determine the chained address that described object is corresponding.
CN201210077074.6A 2012-03-21 2012-03-21 Method and device for webpage access control Active CN102664913B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210077074.6A CN102664913B (en) 2012-03-21 2012-03-21 Method and device for webpage access control

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210077074.6A CN102664913B (en) 2012-03-21 2012-03-21 Method and device for webpage access control

Publications (2)

Publication Number Publication Date
CN102664913A CN102664913A (en) 2012-09-12
CN102664913B true CN102664913B (en) 2015-04-15

Family

ID=46774322

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210077074.6A Active CN102664913B (en) 2012-03-21 2012-03-21 Method and device for webpage access control

Country Status (1)

Country Link
CN (1) CN102664913B (en)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103761482B (en) * 2014-01-23 2018-08-07 珠海市君天电子科技有限公司 A kind of method and Virus detection device of Virus detection
CN104102743B (en) * 2014-07-31 2017-11-03 可牛网络技术(北京)有限公司 A kind of method and device of filtering web page advertisement
CN106022150A (en) * 2016-05-30 2016-10-12 宇龙计算机通信科技(深圳)有限公司 Freezing application method and device
CN108509184B (en) * 2018-03-28 2021-11-09 武汉斗鱼网络科技有限公司 Message distribution method, computer-readable storage medium and electronic device
CN110262749B (en) * 2019-06-27 2021-05-28 北京思维造物信息科技股份有限公司 Webpage operation method, device, container, equipment and medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1859398A (en) * 2006-01-05 2006-11-08 珠海金山软件股份有限公司 System and method for reverse network fishing
CN1949715A (en) * 2005-10-12 2007-04-18 腾讯科技(深圳)有限公司 Method for limiting browser access network address

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8584232B2 (en) * 2007-04-23 2013-11-12 Sap Ag Enhanced cross-site attack prevention

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1949715A (en) * 2005-10-12 2007-04-18 腾讯科技(深圳)有限公司 Method for limiting browser access network address
CN1859398A (en) * 2006-01-05 2006-11-08 珠海金山软件股份有限公司 System and method for reverse network fishing

Also Published As

Publication number Publication date
CN102664913A (en) 2012-09-12

Similar Documents

Publication Publication Date Title
US11223637B2 (en) Detecting attacks on web applications using server logs
US10893068B1 (en) Ransomware file modification prevention technique
US20190207966A1 (en) Platform and Method for Enhanced Cyber-Attack Detection and Response Employing a Global Data Store
CN109688097B (en) Website protection method, website protection device, website protection equipment and storage medium
US9838419B1 (en) Detection and remediation of watering hole attacks directed against an enterprise
US7941854B2 (en) Method and system for responding to a computer intrusion
KR101689298B1 (en) Automated verification method of security event and automated verification apparatus of security event
EP2529321B1 (en) Url filtering based on user browser history
US9817969B2 (en) Device for detecting cyber attack based on event analysis and method thereof
WO2019133453A1 (en) Platform and method for retroactive reclassification employing a cybersecurity-based global data store
US8707441B1 (en) Techniques for identifying optimized malicious search engine results
US20160164893A1 (en) Event management systems
US11240275B1 (en) Platform and method for performing cybersecurity analyses employing an intelligence hub with a modular architecture
CN111274583A (en) Big data computer network safety protection device and control method thereof
US20160337378A1 (en) Method and apparatus for detecting security of online shopping environment
CN102664913B (en) Method and device for webpage access control
CN107465702B (en) Early warning method and device based on wireless network intrusion
US11128649B1 (en) Systems and methods for detecting and responding to anomalous messaging and compromised accounts
US20200125729A1 (en) Online assets continuous monitoring and protection
WO2016138400A1 (en) System and methods for computer network security involving user confirmation of network connections
US11856011B1 (en) Multi-vector malware detection data sharing system for improved detection
CN107566401B (en) Protection method and device for virtualized environment
CN109587122A (en) Realize that self ensures the system and method for Web subsystem safety based on WAF system function
CN115086064A (en) Large-scale network security defense system based on cooperative intrusion detection
US20240111809A1 (en) System event detection system and method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
ASS Succession or assignment of patent right

Owner name: QIZHI SOFTWARE (BEIJING) CO., LTD.

Effective date: 20120913

Owner name: BEIJING QIHU TECHNOLOGY CO., LTD.

Free format text: FORMER OWNER: QIZHI SOFTWARE (BEIJING) CO., LTD.

Effective date: 20120913

C41 Transfer of patent application or patent right or utility model
COR Change of bibliographic data

Free format text: CORRECT: ADDRESS; FROM: 100025 CHAOYANG, BEIJING TO: 100088 XICHENG, BEIJING

TA01 Transfer of patent application right

Effective date of registration: 20120913

Address after: 100088 Beijing city Xicheng District xinjiekouwai Street 28, block D room 112 (Desheng Park)

Applicant after: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Applicant after: Qizhi software (Beijing) Co.,Ltd.

Address before: The 4 layer 100025 unit of Beijing city Chaoyang District Jiuxianqiao Road No. 14 Building C

Applicant before: Qizhi software (Beijing) Co.,Ltd.

C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP01 Change in the name or title of a patent holder
CP01 Change in the name or title of a patent holder

Address after: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park)

Patentee after: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Patentee after: Beijing Qizhi Business Consulting Co.,Ltd.

Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park)

Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Patentee before: Qizhi software (Beijing) Co.,Ltd.

TR01 Transfer of patent right

Effective date of registration: 20220322

Address after: 100016 1773, 15 / F, 17 / F, building 3, No.10, Jiuxianqiao Road, Chaoyang District, Beijing

Patentee after: Sanliu0 Digital Security Technology Group Co.,Ltd.

Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park)

Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd.

Patentee before: Beijing Qizhi Business Consulting Co.,Ltd.

TR01 Transfer of patent right