CN102769632A - Method and system for grading detection and prompt of fishing website - Google Patents

Method and system for grading detection and prompt of fishing website Download PDF

Info

Publication number
CN102769632A
CN102769632A CN2012102703248A CN201210270324A CN102769632A CN 102769632 A CN102769632 A CN 102769632A CN 2012102703248 A CN2012102703248 A CN 2012102703248A CN 201210270324 A CN201210270324 A CN 201210270324A CN 102769632 A CN102769632 A CN 102769632A
Authority
CN
China
Prior art keywords
website
information
url
database
white list
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2012102703248A
Other languages
Chinese (zh)
Inventor
彭仁诚
潘建波
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Kingsoft Internet Security Software Co Ltd
Shell Internet Beijing Security Technology Co Ltd
Zhuhai Juntian Electronic Technology Co Ltd
Beijing Kingsoft Internet Science and Technology Co Ltd
Original Assignee
Zhuhai Juntian Electronic Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhuhai Juntian Electronic Technology Co Ltd filed Critical Zhuhai Juntian Electronic Technology Co Ltd
Priority to CN2012102703248A priority Critical patent/CN102769632A/en
Publication of CN102769632A publication Critical patent/CN102769632A/en
Pending legal-status Critical Current

Links

Images

Abstract

The invention belongs to the technical field of computer defense and particularly discloses a method and a system for grading detection and prompt of a fishing website. The method includes transmitting uniform resource locator (URL) of a user current visit website to a server end, searching whether the URL is in the preset blacklist database or a white list database, allowing users to visit the current website if the URL in the white list database, preventing the users from visiting the current website and transmitting corresponding risk prompt information if the URL is in the blacklist database, obtaining page content information according to the URL if the URL is not in the blacklist database or the white list database, matching phishing website reference characteristics in a preset phishing website characteristic database with webpage content information and transmitting different risk prompt information according to different matching results. Risk prompt with different grades can be given according to characteristics of different websites, so that using safety of users can be further guaranteed.

Description

The method and system of fishing website hierarchical detection and prompting
Technical field
The invention belongs to computer defense technique field, be specifically related to the method and system of a kind of fishing website hierarchical detection and prompting.
Background technology
Fishing website is a kind of network fraud behavior; Refer to that the lawless person utilizes various means; The URL address and the content of pages of counterfeit true website; Perhaps utilize the leak on the true Website server program in some webpage of website, to insert dangerous HTML code, gain user bank or private data such as credit card account, password by cheating or let the consumer directly money imported in cheat's the bank account, seriously influenced on-line finance service, Development of E-business with the mode of payment with this; Endanger public interest, influence the confidence of public's applying Internet.
In order to prevent the harm of fishing website, present thinking has two kinds:
One, check fishing website with a kind of method or device, such as the recognition methods of the detection method of No. 200910106659 a kind of fishing websites of patent of China and device, No. 201110172952.8 patent fishing websites of China and device, No. 200710072997.1 patent of China based on the method for gateway, bridge guarding phishing website etc.These schemes all attempt to find a kind of rule according to the characteristic of fishing website, and then formulate certain detection rule and remove to detect fishing website, and this method or Device Testing result are security websites or are fishing website.Because the characteristic of dissimilar fishing websites is different; And always in continuous variation; Thereby the accuracy that causes this kind method is not very high, promptly is that the possibility of wrong report is higher relatively, in case the fishing website wrong report is security website; Possibly not have the effect of strick precaution for the client brings no small loss.
Two, set up the fishing website database; Find that a fishing website just adds this fishing website in this database to; Check that through this database the website is a fishing website, this kind mode accuracy rate is high, but a difficult point of this mode is; The timely collection of fishing website is in the face of a large amount of this type of prevention methods of new website is helpless.
Summary of the invention
In order to address the above problem, the object of the present invention is to provide the method and system of a kind of fishing website hierarchical detection and prompting, provide the prompting of different risk class according to the different web sites characteristic.
In order to realize the foregoing invention purpose, the technical scheme that the present invention adopts is following:
The method of a kind of fishing website hierarchical detection and prompting may further comprise the steps:
The URL of user's current accessed website is sent to server end; Inquire about said URL whether in preset blacklist database or white list database; Store the url data information of the fishing website of having confirmed in the said blacklist database, store the url data information of the security website that has confirmed in the said white list database;
If in said white list database, then allow the user capture current site;
If in said blacklist database, then stop the user capture current site and send corresponding indicating risk information;
If not in said blacklist database and white list database, then obtain the content of pages information of website according to said URL;
Fishing website reference feature and said web page content information in the preset fishing website property data base are mated, send the different risk information according to different matching results.
Further, the different risk information comprises described in this method:
Doubtful information is used to point out the user to have high risk;
Reminding information is used to point out the user to have certain risk;
The education information is used for prompting explanation normal condition with for reference.
The system of a kind of fishing website hierarchical detection and prompting comprises:
The fishing website detection module is used for the URL of user's current accessed website is sent to server end, inquires about said URL whether in preset blacklist database or white list database, if in said white list database, then allows the user capture current site;
The white list database is used to store the url data information of the security website that has confirmed;
The blacklist database, the url data information that is used to store the fishing website of having confirmed;
The interception reminding module if in said blacklist database, is used to stop the user capture current site and sends corresponding indicating risk information;
If the web page contents acquisition module not in said blacklist database and white list database, is used for obtaining according to said URL the content of pages information of website;
The unknown detection and reminding module is used for the fishing website reference feature and the said web page content information of preset fishing website property data base are mated, and sends the different risk information according to different matching results;
The fishing website property data base is used to store fishing website reference feature data message.
Further, the different risk information comprises described in this system:
Doubtful information is used to point out the user to have high risk;
Reminding information is used to point out the user to have certain risk;
The education information is used for prompting explanation normal condition with for reference.
URL, the abbreviation of English Uniform/Universal Resource Locator is translated as URL, also is called as web page address, is the resource addresses (Address) of standard on the internet.
When using, the present invention takes the measure of treating with a certain discrimination according to different situations; Security website directly lets pass, fishing website is directly tackled, the different risk prompting is sent according to its situation of hitting the fishing website characteristic in unknown website; Rather than adopt existing mode of imposing uniformity without examining individual cases, further defend degree of safety.
By on can know that with respect to the detection technique of existing fishing website, the present invention can accomplish that the characteristic according to different web sites provides the indicating risk of different brackets, ensured that further the user's is safe in utilization.
Description of drawings
The picture that this description of drawings provided is used for auxiliary to further understanding of the present invention, constitutes the application's a part, does not constitute to improper qualification of the present invention, in the accompanying drawings:
Fig. 1 is the corresponding flow chart of the inventive method;
Fig. 2 is the corresponding block diagram of system of the present invention.
Embodiment
As shown in Figure 1, present embodiment discloses the method for a kind of fishing website hierarchical detection and prompting, may further comprise the steps:
Step1: the URL of user's current accessed website is sent to server end; Inquire about said URL whether in preset blacklist database or white list database; Store the url data information of the fishing website of having confirmed in the said blacklist database, store the url data information of the security website that has confirmed in the said white list database; The purpose of this step is exactly, and the mode through the data with existing storehouse detects fishing website accurately, takes the measure and ensure user security of tackling for the fishing website of confirming;
If in said white list database, then carry out Step2A: allow the user capture current site;
If in said blacklist database, then carry out Step2B: stop the user capture current site and send corresponding indicating risk information;
If not in said blacklist database and white list database, then carry out Step2C: the content of pages information of obtaining the website according to said URL; Wherein, URL is exactly a web page address, has had web page address to obtain content of pages and specifically can adopt a lot of art methods, enters into this website such as input URL in browser and downloads getter content of pages information or the like then;
Step3: fishing website reference feature and said web page content information in the preset fishing website property data base are mated, send the different risk information according to different matching results;
For example: preset " certificates handling ", " praticing fraud " these two excessive risk characteristics that are characterized as fishing website in the fishing website property data base; If the content of pages characteristic of certain unknown website is hit these characteristics; Then send doubtful information; Be used to point out the user to have high risk, concrete information can be " this website is likely fishing website, please notes risk prevention ";
For example: this is characterized as the average risk characteristic in the fishing website property data base, to preset " platform version millet mobile phone "; If the content of pages characteristic of certain unknown website is hit this characteristic; Then send reminding information; Be used to point out the user to have certain risk, concrete information can be " platform version millet mobile phone possibly be a mountain vallage goods, asks the user carefully to buy ";
For example: preset " i Phone " and " price is higher than 4000 " these two is characterized as the low-risk characteristic in the fishing website property data base; If the content of pages characteristic of certain unknown website is hit this two characteristics; The i Phone of selling such as this website has only 2000, then educates information, is used for prompting explanation normal condition with for reference; Concrete information can be " the i Phone average price is 4500, for your guidance " etc.
As shown in Figure 2, present embodiment also discloses a kind of system corresponding with said method, and this system comprises:
Fishing website detection module 1 is used for the URL of user's current accessed website is sent to server end, inquires about said URL whether in preset blacklist database or white list database, if in said white list database, then allows the user capture current site;
White list database 2 is used to store the url data information of the security website that has confirmed;
Blacklist database 3, the url data information that is used to store the fishing website of having confirmed;
Interception reminding module 4 if in said blacklist database, is used to stop the user capture current site and sends corresponding indicating risk information;
If web page contents acquisition module 5 not in said blacklist database and white list database, is used for obtaining according to said URL the content of pages information of website;
The unknown detection and reminding module 6 is used for the fishing website reference feature and the said web page content information of preset fishing website property data base are mated, and sends the different risk information according to different matching results; Said different risk information comprises: doubtful information is used to point out the user to have high risk; Reminding information is used to point out the user to have certain risk; The education information is used for prompting explanation normal condition with for reference;
Fishing website property data base 7 is used to store fishing website reference feature data message.
Through said method or system, can provide the indicating risk of different brackets according to the characteristic of different web sites, ensured that further the user's is safe in utilization.
More than describe preferred embodiment of the present invention in detail, the ordinary skill that should be appreciated that this area need not creative work and just can design according to the present invention make many modifications and variation.Therefore, all technical staff in the art according to the present invention design on the prior art basis through logic analysis, reasoning perhaps according to the available technical scheme of limited experiment, all should be among determined protection range by these claims.

Claims (4)

1. the method for fishing website hierarchical detection and prompting is characterized in that may further comprise the steps:
The URL of user's current accessed website is sent to server end; Inquire about said URL whether in preset blacklist database or white list database; Store the url data information of the fishing website of having confirmed in the said blacklist database, store the url data information of the security website that has confirmed in the said white list database;
If in said white list database, then allow the user capture current site;
If in said blacklist database, then stop the user capture current site and send corresponding indicating risk information;
If not in said blacklist database and white list database, then obtain the content of pages information of website according to said URL;
Fishing website reference feature and said web page content information in the preset fishing website property data base are mated, send the different risk information according to different matching results.
2. method according to claim 1 is characterized in that, said different risk information comprises:
Doubtful information is used to point out the user to have high risk;
Reminding information is used to point out the user to have certain risk;
The education information is used for prompting explanation normal condition with for reference.
3. the system of fishing website hierarchical detection and prompting is characterized in that comprising:
The fishing website detection module is used for the URL of user's current accessed website is sent to server end, inquires about said URL whether in preset blacklist database or white list database, if in said white list database, then allows the user capture current site;
The white list database is used to store the url data information of the security website that has confirmed;
The blacklist database, the url data information that is used to store the fishing website of having confirmed;
The interception reminding module if in said blacklist database, is used to stop the user capture current site and sends corresponding indicating risk information;
If the web page contents acquisition module not in said blacklist database and white list database, is used for obtaining according to said URL the content of pages information of website;
The unknown detection and reminding module is used for the fishing website reference feature and the said web page content information of preset fishing website property data base are mated, and sends the different risk information according to different matching results;
The fishing website property data base is used to store fishing website reference feature data message.
4. system according to claim 1 is characterized in that, said different risk information comprises:
Doubtful information is used to point out the user to have high risk;
Reminding information is used to point out the user to have certain risk;
The education information is used for prompting explanation normal condition with for reference.
CN2012102703248A 2012-07-30 2012-07-30 Method and system for grading detection and prompt of fishing website Pending CN102769632A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2012102703248A CN102769632A (en) 2012-07-30 2012-07-30 Method and system for grading detection and prompt of fishing website

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2012102703248A CN102769632A (en) 2012-07-30 2012-07-30 Method and system for grading detection and prompt of fishing website

Publications (1)

Publication Number Publication Date
CN102769632A true CN102769632A (en) 2012-11-07

Family

ID=47096882

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2012102703248A Pending CN102769632A (en) 2012-07-30 2012-07-30 Method and system for grading detection and prompt of fishing website

Country Status (1)

Country Link
CN (1) CN102769632A (en)

Cited By (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103390128A (en) * 2013-08-01 2013-11-13 贝壳网际(北京)安全技术有限公司 Page labeling method and device and terminal equipment
CN103491101A (en) * 2013-09-30 2014-01-01 北京金山网络科技有限公司 Phishing website detecting method and device and client-side
CN103685254A (en) * 2013-12-05 2014-03-26 奇智软件(北京)有限公司 Common account information safety detecting method and server
CN103745156A (en) * 2014-01-07 2014-04-23 北京奇虎科技有限公司 Method and device for prompting risk information in search engine
CN103853980A (en) * 2014-02-28 2014-06-11 珠海市君天电子科技有限公司 Safety prompting method and device
CN104079528A (en) * 2013-03-26 2014-10-01 北大方正集团有限公司 Method and system of safety protection of Web application
CN104333558A (en) * 2014-11-17 2015-02-04 广州华多网络科技有限公司 Website detection method and device
CN104598458A (en) * 2013-10-30 2015-05-06 腾讯科技(深圳)有限公司 Page detection method and device
CN105429980A (en) * 2015-11-17 2016-03-23 中国联合网络通信集团有限公司 Network security processing method and network security processing device
CN105530218A (en) * 2014-09-28 2016-04-27 北京奇虎科技有限公司 Link security detection method and client
CN105635159A (en) * 2016-01-07 2016-06-01 中国联合网络通信集团有限公司 Plugging method and system based on keywords
CN103685289B (en) * 2013-12-19 2017-02-08 北京奇虎科技有限公司 Method and device for detecting phishing website
CN106656932A (en) * 2015-11-02 2017-05-10 阿里巴巴集团控股有限公司 Business processing method and device
CN106789980A (en) * 2016-12-07 2017-05-31 北京亚鸿世纪科技发展有限公司 A kind of monitoring administration method and device of website legitimacy
CN107018152A (en) * 2017-05-27 2017-08-04 北京奇虎科技有限公司 Message block method, device and electronic equipment
CN107203302A (en) * 2016-03-17 2017-09-26 阿里巴巴集团控股有限公司 A kind of page display method and device
CN107852412A (en) * 2015-08-05 2018-03-27 迈克菲有限责任公司 For phishing and the system and method for brand protection
CN108322441A (en) * 2017-12-29 2018-07-24 广州斯马特信息科技有限公司 Web portal security detection method and system
CN109302383A (en) * 2018-08-31 2019-02-01 平安科技(深圳)有限公司 A kind of URL monitoring method and device
CN110677374A (en) * 2018-07-02 2020-01-10 中国电信股份有限公司 Method and device for preventing phishing attack and computer readable storage medium
CN112015946A (en) * 2019-05-30 2020-12-01 中国移动通信集团重庆有限公司 Video detection method and device, computing equipment and computer storage medium
CN112785130A (en) * 2021-01-13 2021-05-11 上海派拉软件股份有限公司 Website risk level identification method, device, equipment and storage medium
CN114648027A (en) * 2022-05-23 2022-06-21 每日互动股份有限公司 Text information processing method and device, computer equipment and storage medium
CN112785130B (en) * 2021-01-13 2024-04-16 上海派拉软件股份有限公司 Website risk level identification method, device, equipment and storage medium

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101534306A (en) * 2009-04-14 2009-09-16 深圳市腾讯计算机系统有限公司 Detecting method and a device for fishing website
CN102231745A (en) * 2011-07-08 2011-11-02 盛大计算机(上海)有限公司 Safety system and method for network application

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101534306A (en) * 2009-04-14 2009-09-16 深圳市腾讯计算机系统有限公司 Detecting method and a device for fishing website
CN102231745A (en) * 2011-07-08 2011-11-02 盛大计算机(上海)有限公司 Safety system and method for network application

Cited By (34)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104079528A (en) * 2013-03-26 2014-10-01 北大方正集团有限公司 Method and system of safety protection of Web application
CN103390128A (en) * 2013-08-01 2013-11-13 贝壳网际(北京)安全技术有限公司 Page labeling method and device and terminal equipment
CN103491101A (en) * 2013-09-30 2014-01-01 北京金山网络科技有限公司 Phishing website detecting method and device and client-side
CN104598458A (en) * 2013-10-30 2015-05-06 腾讯科技(深圳)有限公司 Page detection method and device
CN103685254A (en) * 2013-12-05 2014-03-26 奇智软件(北京)有限公司 Common account information safety detecting method and server
CN103685289B (en) * 2013-12-19 2017-02-08 北京奇虎科技有限公司 Method and device for detecting phishing website
CN103745156A (en) * 2014-01-07 2014-04-23 北京奇虎科技有限公司 Method and device for prompting risk information in search engine
CN103745156B (en) * 2014-01-07 2017-05-03 北京奇虎科技有限公司 Method and device for prompting risk information in search engine
CN103853980A (en) * 2014-02-28 2014-06-11 珠海市君天电子科技有限公司 Safety prompting method and device
CN105530218A (en) * 2014-09-28 2016-04-27 北京奇虎科技有限公司 Link security detection method and client
CN104333558B (en) * 2014-11-17 2018-02-23 广州华多网络科技有限公司 A kind of network address detection method and network address detection means
CN104333558A (en) * 2014-11-17 2015-02-04 广州华多网络科技有限公司 Website detection method and device
US10778704B2 (en) 2015-08-05 2020-09-15 Mcafee, Llc Systems and methods for phishing and brand protection
CN107852412A (en) * 2015-08-05 2018-03-27 迈克菲有限责任公司 For phishing and the system and method for brand protection
US11095689B2 (en) 2015-11-02 2021-08-17 Advanced New Technologies Co., Ltd. Service processing method and apparatus
US11252197B2 (en) 2015-11-02 2022-02-15 Advanced New Technologies Co., Ltd. Service processing method and apparatus
CN106656932A (en) * 2015-11-02 2017-05-10 阿里巴巴集团控股有限公司 Business processing method and device
CN105429980A (en) * 2015-11-17 2016-03-23 中国联合网络通信集团有限公司 Network security processing method and network security processing device
CN105635159A (en) * 2016-01-07 2016-06-01 中国联合网络通信集团有限公司 Plugging method and system based on keywords
CN105635159B (en) * 2016-01-07 2018-07-03 中国联合网络通信集团有限公司 Method for blocking and system based on keyword
CN107203302A (en) * 2016-03-17 2017-09-26 阿里巴巴集团控股有限公司 A kind of page display method and device
CN107203302B (en) * 2016-03-17 2021-01-01 创新先进技术有限公司 Page display method and device
CN106789980A (en) * 2016-12-07 2017-05-31 北京亚鸿世纪科技发展有限公司 A kind of monitoring administration method and device of website legitimacy
CN107018152A (en) * 2017-05-27 2017-08-04 北京奇虎科技有限公司 Message block method, device and electronic equipment
CN108322441A (en) * 2017-12-29 2018-07-24 广州斯马特信息科技有限公司 Web portal security detection method and system
CN110677374A (en) * 2018-07-02 2020-01-10 中国电信股份有限公司 Method and device for preventing phishing attack and computer readable storage medium
CN109302383A (en) * 2018-08-31 2019-02-01 平安科技(深圳)有限公司 A kind of URL monitoring method and device
CN109302383B (en) * 2018-08-31 2022-04-29 平安科技(深圳)有限公司 URL monitoring method and device
CN112015946A (en) * 2019-05-30 2020-12-01 中国移动通信集团重庆有限公司 Video detection method and device, computing equipment and computer storage medium
CN112015946B (en) * 2019-05-30 2023-11-10 中国移动通信集团重庆有限公司 Video detection method, device, computing equipment and computer storage medium
CN112785130A (en) * 2021-01-13 2021-05-11 上海派拉软件股份有限公司 Website risk level identification method, device, equipment and storage medium
CN112785130B (en) * 2021-01-13 2024-04-16 上海派拉软件股份有限公司 Website risk level identification method, device, equipment and storage medium
CN114648027A (en) * 2022-05-23 2022-06-21 每日互动股份有限公司 Text information processing method and device, computer equipment and storage medium
CN114648027B (en) * 2022-05-23 2022-09-30 每日互动股份有限公司 Text information processing method and device, computer equipment and storage medium

Similar Documents

Publication Publication Date Title
CN102769632A (en) Method and system for grading detection and prompt of fishing website
CN101388768B (en) Method and device for detecting malicious HTTP request
CN103179095B (en) A kind of method and client terminal device detecting fishing website
CN103428189B (en) A kind of methods, devices and systems identifying malicious network device
CN106789939B (en) A kind of detection method for phishing site and device
CN104954372A (en) Method and system for performing evidence acquisition and verification on phishing website
CN103139138B (en) A kind of application layer denial of service means of defence based on client detection and system
CN102638448A (en) Method for judging phishing websites based on non-content analysis
CN103701804A (en) Network shopping environment safety detecting method and device
CN102647408A (en) Method for judging phishing website based on content analysis
CN102467633A (en) Method and system for safely browsing webpage
CN103685289B (en) Method and device for detecting phishing website
CN104580230B (en) Verification method and device are attacked in website
CN102724186A (en) System and method for detecting phishing websites
CN102710646A (en) Method and system for collecting phishing websites
CN101539936A (en) Detecting method for sham websites and device thereof
CN104580092A (en) Method and device for conducting security detection on network page
WO2017080393A1 (en) Method and apparatus for acquiring ip address
CN107896218A (en) A kind of method and system of automatic detection identifying code passback logic leak
CN102891861A (en) Client-based phishing website detecting method and device
CN114422139A (en) API gateway request security verification method and device, electronic equipment and computer readable medium
CN108270754B (en) Detection method and device for phishing website
CN103795679A (en) Rapid detection method and system for phishing website
CN102930214B (en) Method and device for carrying out risk prompt on unknown shopping website
KR101523703B1 (en) Method for user authentication process according to personal identification class

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
ASS Succession or assignment of patent right

Owner name: KINGSOFT CORPORATION LIMITED BEIKE INTERNET (BEIJI

Effective date: 20130503

C41 Transfer of patent application or patent right or utility model
TA01 Transfer of patent application right

Effective date of registration: 20130503

Address after: Jingshan Hill Road, Lane 519015 Lianshan Jida Guangdong province Zhuhai City No. 8

Applicant after: ZHUHAI JUNTIAN ELECTRONIC TECHNOLOGY Co.,Ltd.

Applicant after: BEIJING KINGSOFT INTERNET SECURITY SOFTWARE Co.,Ltd.

Applicant after: SHELL INTERNET (BEIJING) SECURITY TECHNOLOGY Co.,Ltd.

Applicant after: BEIJING KINGSOFT NETWORK TECHNOLOGY Co.,Ltd.

Address before: Jingshan Hill Road, Lane 519015 Lianshan Jida Guangdong province Zhuhai City No. 8

Applicant before: Zhuhai Juntian Electronic Technology Co.,Ltd.

C12 Rejection of a patent application after its publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20121107