Network pornography image and flame detect multifunctional management system
One, technical field: the present invention relates to the Internet flame filtration system, particularly relate to the multifunctional management system that a kind of network pornography image and flame detect.
Two, background technology: the Internet is worldwide popularized rapidly as a kind of modernized communication technology, and the Internet communication approach spreads all over each corner in the world.Because network world is a Virtual Space, all data in real life, sound, information such as image can change computer bit kenel into, shuttle back and forth in the whole world with computerized information stream, at present increasing people is engaged in amusement on network, research and commercial activity, thereby form a virtual society on the network, network user need not disclose the true identity of oneself and can enjoy a trip to therebetween, the interpersonal also rare morals of daily society, the ethics constraint, therefore network world is more complicated more than real society, fearful, panoramic personage is mingled with therebetween, nourish different purposes separately, justice, evil difficulty is distinguished.Because ordering about of violence, porn site and pornographic webpage are mad in recent years increases, particularly the strong harmful informations such as pornographic image of stimulus to the sense organ are overflowed, bring out juvenile deliquency, have a strong impact on pupillary growing up healthy and sound, cause the head of a family's very big indignation and worry, also cause the concern of society and government, even send the cry of " helping child ", causing spends huge sums set up in, primary school's campus gateway has closed the passage of leading to network education, also disabled for the household PC that child buys, wasted investment greatly, have to give up online superior educational resource.
For online harmful informations such as filtering eroticisms, a large amount of filter softwares and system have also appearred on the market in recent years, can be referred to as " blacklist software ", its technological means is to utilize artificial means that known pornographic network address or domain name are included in " blacklist " address database, by address comparison and keyword comparison, listed network address and related web page information in " blacklist " database that the blockade viewer lands.The shortcoming of this method is: for a large amount of undiscovered and increase newly and the conversion looks after the pornographic network address that reappears powerless, the discovery of intelligence that can not be real-time also is included into blacklist with it, and the literal comparison time also is subjected to the restriction of country variant literal, makes this type of filter software can only be in passive filtration state all the time.
A kind of Sexy file judging system and the method for Chinese invention patent 210112132.7, elder generation's input marking file in system, word segment in the isolated tested webpage and picture part are sent to literal relatively engine and porny identification engine respectively, also compare by the pornographic index that calculates literal and picture, judge Sexy file with pornographic index of discrimination; A kind of Sexy picture checking system of ZL0112127.0 filters the examine picture by dual engine, has introduced relatively engine of porny database and database, has improved the accuracy of porny identification; A kind of Web content filtration system of patent application 200410053683.3, act on behalf of by information filtering, querying server and content analysis and management server, the information filtering proxies store has blacklist and white list, querying server has one and has the URL storehouse of rating information suddenly of classifying, content analysis and management server are classified and classified estimation to the resource among the intemet, system has self-learning capability, can improve the genealogical classification precision, can initiatively filter all kinds of media datas that exist in the Internet: its main filtration approach remains based on automatic renewal and interception to URL, the shortage profound level, completely, based on the filtration of flesh and blood, a large amount of strong pornographic image of stimulus to the sense organ can not directly be tackled arranged still.The method or the system of present this class network filtering, general mode with software application occurs and is used, and processing speed is slow; unloaded easily; do not have survivability, be difficult to reach the purpose of protecting young people and not encroached on, and can't realize and the irrelevant characteristics of browser by the bad network information.
Three, summary of the invention:
Technical problem to be solved by this invention:, propose the multifunctional management system of a kind of content-based, multi-level the Internet pornographic image and bad image detecting system at the defective that the present the Internet of background technology pornographic image detects, filtration system exists.
The technical solution adopted in the present invention:
The multifunctional management system that a kind of network pornography image and flame detect, the pornographic image that management is browsed client computer under Client and the testing process of flame, described multifunctional management system contains server subsystem and client computer subsystem
Described server subsystem contains: detection procedure administration module, image detection API, PCI driver module and video processing board-card, mutual and communication between detection procedure administration module management server subsystem and client computer subsystem process, and management is to the detection procedure of the pornographic image of client browses;
Server subsystem at first starts a monitor process, in order to finish the mutual communication with the client computer subsystem, realize monitoring the connection request of client computer subsystem image detection, server subsystem is behind the connection request of receiving the client computer subsystem, start an image detection thread, carry out mutual communication by imperative structures and client computer subsystem, call image detection API application program simultaneously, make the video processing board-card that the image detection core algorithm is housed carry out computing, the network image that the client computer subsystem is sent here detects, and passes testing result back the client computer subsystem;
Described client computer subsystem contains:
The data filter interface provides obtaining and loopback interface of network data;
Separate protocol module, extract the HTTP data, the network information is handled, realize the decomposition and the reorganization of application layer and IP bag data from the data filter interface;
Data detection module contains following functional module, and credible URL detects, bad URL detects, keyword detects and the image detection process, and described data detection module calling graph is as detection procedure, and the request server subsystem detects network image;
Automatically update module is upgraded application program and data automatically from the internet;
The server subsystem communication module is finished the mutual communication between client computer subsystem and server subsystem.
The multifunctional management system that described network pornography image and flame detect, the Windows socket application programming interface for client applications access network services of the data filter interface of client computer subsystem for providing by Winsock2 or XP, comprise the Winsock ISP interface SPI and the ws2_32.dll that realize by transmission ISP and name resolution ISP, described multifunctional management system has been integrated operating system, browser, relation between the video processing board-card of http protocol and embedded nuclear center algorithm has realized that the Internet flame filters and the irrelevant characteristics of browser.
The multifunctional management system that described network pornography image and flame detect, after the data filter interface of client computer subsystem intercepts and sends data, at first check the data legitimacy, judge whether the HTTP head is the image request head, whether if image request is then judged this packet is that browser sends, if then duplicate socket and send data to the purpose http server, simultaneously the data that send are sent to server subsystem and carry out image detection, data according to the transmission of image detection result treatment browser, if then directly clearance of normal data, if pornographic image then replaces to data predefined view data.
The multifunctional management system that described network pornography image and flame detect, server subsystem contains other worker thread, and other worker thread comprises the data analysis service, in order to the analytical system daily record, carry out the record and the analysis of bad network address, handle bad url list; Automatically whether update service is made regular check on version and is upgraded, and upgrades from the internet automatically; User application interface, for the user increases believable URL and bad URL, and this user application interface can the display system daily record.
The multifunctional management system that described network pornography image and flame detect, the website is filtered and is adopted absolute filtering policy, promptly carry out multi-level domain name and filter the user being landed solicited message, behind the IP address filtering, on the basis that normal image is filtered, increased the image statistics function, comprise rate by the pornographic image of adding up a webpage of being browsed and judge whether the website of this webpage correspondence is the porn site, if judging, a webpage contains n pornographic image, the website of then judging this webpage correspondence is the porn site, and is intercepted, and wherein n gets 5, according to the classification of browsing difference is set, n or be taken as 4, or be 3, or be 6 natural number.
The multifunctional management system that described network pornography image and flame detect, the detection of pornographic image is the application layer at server, when being unpacked back pie graph picture frame, a plurality of IP packets carry out, for TCP connects not chain rupture, adopt " storage is transmitted " method: filtration system is left complete data message earlier, issues the client computer subsystem again, Web is made a start, the filtration system debit that disguises oneself as, to real recipient's client computer subsystem, the filtration system originating party that disguises oneself as again.
Positive beneficial effect of the present invention:
1, under the Client of multifunctional management system of the present invention in the Internet local, the division of labor of image filtering and IP address filtering between management server and client computer, and communicating by letter between the overall plan network that solves filtration duty and server and client computer with mutual, realize the decomposition of IP layer data and the reorganization of application layer data, under the condition of analysis operation system, integrate with operating system, realized having the filtration of own characteristic, the speed of service is fast, the filter efficiency height.
2, multifunctional management system of the present invention has been integrated the relation between the video processing board-card of operating system, browser, http protocol and embedded nuclear center algorithm, information filtering product and operating system are combined closely, realized that the Internet flame filters and the irrelevant characteristics of browser, at server end the network pornography image is filtered and handles, improved filtration treatment efficient.
3, multifunctional management system of the present invention utilizes online store-and-forward mode, has solved parallel connection of a plurality of client computer TCP in the image recognition testing process and the problem of not chain rupture.
Four, description of drawings:
Fig. 1: multifunctional management system is formed block diagram
Fig. 2: multifunctional management system server subsystem workflow block diagram
Fig. 3: multifunctional management platform client computer subsystem structure is formed block diagram
Fig. 4: multifunctional management system client-side data filter interface is formed schematic diagram
Fig. 5: multifunctional management system image client computer subsystem detection procedure workflow block diagram
Fig. 6: the storage repeating process schematic diagram of guaranteeing not chain rupture of TCP
Five, embodiment:
Embodiment one: referring to Fig. 1, Fig. 3, network pornography image and flame detect multifunctional management system, contain server subsystem and client computer subsystem, both realize communication and data interaction by communication module, server subsystem contains the detection procedure administration module, image detection is surveyed API, PCI driver module and video processing board-card, video processing board-card is installed on the server computer, the detection procedure administration module is in order to finish and the communicating by letter of client computer, server subsystem starts an image detection thread and client communication, finish communicating by letter of server and client computer, call video processing board-card simultaneously, image is detected and return testing result; Described server subsystem also contains other worker thread, comprises the data analysis service, in order to the analytical system daily record, carries out the record and the analysis of bad network address, handles bad url list; Automatically whether update service is made regular check on version and is upgraded, and upgrades from the internet automatically; User application interface, for the user provides the URL that enhances trust, bad URL and display system daily record.The client computer subsystem contains the data filter interface, separates protocol module, data detection module, update module, server communication module automatically, and data filter interface wherein is responsible for obtaining website data and loopback interface; Separate protocol module, extract http protocol and handle; Data detection module contains credible URL detection, bad URL detection, keyword detection and image detection; Automatically update module is upgraded application program and data automatically from the internet; The server communication module is realized communication and data interaction between client computer and server.
Referring to Fig. 2: multifunctional management system server subsystem workflow block diagram, server at first starts the connection request that a monitor process is monitored client computer, and after receiving the connection request of client computer, start the image detection thread, detect thread by imperative structures and clients exchange information, call video processing board-card simultaneously network image is detected, and pass result back client computer.The processing procedure more complicated of image detection process reality, if for example judge that request URL is bad URL, then server no longer detects the order of just directly returning " filtration ".In the image detection process, the image detection of image detection card is serial, but the image detection request walks abreast, in other words a plurality of image detection requests can take place in a period of time, therefore need by a scheduling thread image detection request to be delivered in the test card according to the order of " detecting earlier first ".The image detection process also can write journal file to the result who detects, and the data of analysis are provided for later system manager.
Fig. 4 is that network pornography image and flame detect multifunctional management system data filter interface composition schematic diagram, the Windows socket application programming interface for client applications access network services of data filter interface for providing by Winsock2, comprise the Winsock ISP interface SPI and the ws2_32.dll that are realized by transmission ISP and name resolution ISP, its filtration pattern is: the HOOK interface (core DLL) of installing or unload the SPI open standard; Data processing core (HOOKDLL); Image detection interface (network communication interface), the mutually mutual communication of this three.
The interface function that SPI is opened to standard inserts one deck in the middle of the ISP, thereby realizes SPIHOOK.SPI has an allocation list, the order of in store loading and other attribute information, and this table just is kept in the registration table, and operating system can load the SPI module according to this table.By revising this table, allow our SPI module of system loads, our SPI module reloads system then, and connection request is forwarded to system, finishes the HOOK of SPI.
Utilize the sSpiPathName in the self-defining SPIDLL Program path replacement registration table, and the sSpiPathName of saved system, after finishing such operation, system will use self-defined SPIDLL when loading SPI, utilizes the SPIDLL of the system path loading system of preserving to finish forwarding then.Before using SOCKET, must call the WSPStarup of SPI, 30 SOCKET service function pointers that obtain SPI from this function provide SOCKET communication service then.
Last parameter L pProcTable is used for returning the pointer of 30 SPI service functions.Derive the WSPStartup function so need write a DLL, and be installed to system as the ISP, when the self-defined DLL of system loads, the corresponding SPIDLL of loading system uses LoadLibrary loading system DLL then.Self-defined DLL uses GetProcAddress to obtain the WSPStartup function pointer of the DLL of system, can obtain 30 ISP's function pointers, and it is modified as own function address.
Referring to Fig. 6.Because the detection pornographic image is the application layer at server, when being unpacked back pie graph picture frame, a plurality of IP packets carry out, for TCP connects not chain rupture, adopt " storage is transmitted " method: filtration system is left complete data message earlier, issue client again, Web is made a start, and the filtration system debit that disguises oneself as is to real recipient's client computer originating party that disguises oneself as again.Because the filtration system connection processing is a plurality of complete message of a plurality of client computer, any one equipment does not all have this concatenation ability, and we will lose the message that some affect the general situation in the accurate Calculation time-out time for this reason, guarantee to connect not chain rupture.
Fig. 5 is a client computer subsystem image detection process workflow of the present invention.URL detects and the keyword detection is to detect the data in the IP bag, and therefore fairly simple: the image detection process is to detect complete image, generally is the combination that several IP wrap, so more complicated.SurGuard.d11 judges whether the HTTP head is the image request head after intercepting and sending data.If image then judges that according to User-Agent this packet is that browser sends or SurGuard.d11 sends, if the data that browser sends, then duplicate socket (sockaddr-in structure) and Send (Get data) data, start a new thread these data are sent to the purpose http server.
The purpose http server generally can return 2000K or 304Not Modified, and the former represents normal data, and the latter has represented to use the cache of IE.New thread receives the data of http server and is sent to the image detection server and detects, and handles browser Send data according to testing result, if then directly clearance of normal data, if bad view data is then with " GET " makes into "! ET " send.
The purpose of not blocking the Send data is to receive a normal http server response, and response data is replaced to predefined view data, and browser just can replace to bad image the image of setting like this.Http server receive "! ET " to be bound to reply 501 misrepresentation HTTP request imperfect in request, and at this moment that the response data of server is replaced to predefined view data is just passable for SurGuard.d11.
Embodiment two: referring to Fig. 1, present embodiment is substantially with embodiment one, and its difference is: present embodiment network pornography image and flame detect multifunctional management system, and the website is filtered and adopted absolute filtering policy.The function of information filtering product is to prevent flame on the Internet to teen-age harm, and is wherein particularly important to the filtration of pornographic image information.No matter be that domain name is filtered, the IP address filtering, or image filtering, what finally estimate filter effect is the integral filter ability of system.
Absolute filtering policy is to have increased the image statistics function on the basis that normal image is filtered, and promptly comprises rate by the pornographic image of adding up a webpage and judges that this website is the porn site, closes down this website then.What adopt at present is simple pornographic image counting, as long as a webpage is judged n (getting 5 at present) pornographic image, then directly closes down whole website.
After adopting absolute filtering policy, pornographic image interception rate reaches 99.38%, and website interception rate reaches 99.75%, and reaching high filter effect like this is cost to close down normal website, and this is very important for the teenager.In order to remedy this defective, system has adopted the method for classification setting, and the head of a family or adult can not be subjected to the restriction of this filtration like this.
Embodiment three: referring to Fig. 1, Fig. 2, present embodiment network pornography image and flame detect multifunctional management system, server subsystem contains other worker thread, other worker thread comprises the data analysis service, in order to the analytical system daily record, carry out the record and the analysis of bad network address, handle bad url list; Automatically whether update service is made regular check on version and is upgraded, and upgrades from the internet automatically; User application interface, for the user provides the URL that enhances trust, bad URL and display system daily record.