CN102857369B - Website log saving system, method and apparatus - Google Patents

Website log saving system, method and apparatus Download PDF

Info

Publication number
CN102857369B
CN102857369B CN201210279783.2A CN201210279783A CN102857369B CN 102857369 B CN102857369 B CN 102857369B CN 201210279783 A CN201210279783 A CN 201210279783A CN 102857369 B CN102857369 B CN 102857369B
Authority
CN
China
Prior art keywords
necessary information
request message
response message
log file
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201210279783.2A
Other languages
Chinese (zh)
Other versions
CN102857369A (en
Inventor
李晓亮
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing Ding Zhen Information Technology Co., Ltd.
Original Assignee
BEIJING DINGZHEN TECHNOLOGY Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by BEIJING DINGZHEN TECHNOLOGY Co Ltd filed Critical BEIJING DINGZHEN TECHNOLOGY Co Ltd
Priority to CN201210279783.2A priority Critical patent/CN102857369B/en
Publication of CN102857369A publication Critical patent/CN102857369A/en
Application granted granted Critical
Publication of CN102857369B publication Critical patent/CN102857369B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

The invention provides a website log saving system, a website log saving method and a website log saving apparatus based on a bypass mirror, and is used for solving problems existing in the prior art. According to the website log saving system, the website log saving method and the website log saving apparatus based on the bypass mirror, access data is acquired in a bypass mirror manner, the data of an accessed website is subjected to bypass mirroring to obtain original data package information of the website accessed by a user, and the original data package information can be recorded into website logs in different formats after being subjected to behavior classification by a behavior analysis module. The technical scheme provided by the invention can not cause any load to a web server, and a log format is completely unconcerned with the selection of the web server. A traditional networking model is used for accessing relevant WEB servers onto a network switch, and relevant functions such as website log saving and the like are finished by a WEB server entity.

Description

A kind of web log file saved system and method and apparatus
Technical field
The present invention relates to communication technical field, particularly relate to a kind of web log file saved system and method and apparatus.
Background technology
Web log file is the file ended up with .log that record web server receives the various raw informations such as process request and run time error.When whom can understand by web log file uses any instrument to have accessed which content of website, and it is the most based sources of web analytics and website data storage.Because the necessary basis ensureing that web server is normally run can be become by complete errorless preservation web log file.
In the prior art, web log file is by WEB server self record, and when accessing generation, WEB server is recorded in some information of this access on this locality or certain webserver in a text form according to the journal format pre-set.
But different WEB server generally only supports oneself specific journal format, the W3C journal format that the NCSA journal format supported as apache and IIS support, most log analysis tool all provides the support to NCSA and W3C at least one form.Separately there is the journal format that some WEB server have oneself to give tacit consent to as nginx, generally need manual configuration to become NCSA form with log analysis software easy to use.There is following problem in prior art generally:
1. access log is responsible for record by web server, and web server not only needs the request responding visitor also to need record access daily record, adds the burden of web server.Obtaining the information of accessing each time is all synchronously carried out when processing request by web server, affects the performance of web server.
2. the form of daily record is relevant with the web server of use, the range of choice of the web log file analysis tool that this strongly limits.The web server that traditional web log file form is used restricts, and have selected certain server and also just have selected certain journal format, selects certain server in other words in order to certain journal format can be used to have to.
3. daily record layoutprocedure very complicated, some web server even only just can complete daily record configuration through configuration file, and this needs higher computer literacy and could complete smoothly.Web server does not generally provide the screening function to the daily record generated in addition, cannot carry out Screening Treatment to the daily record generated.
4. log recording does not possess intelligent, existing web log file is the simple intrinsic information entrained by record web message, do not possess any behavioural analysis ability, no matter be attack or normally access there is no what difference for website daily record, generally professional and technical personnel is all needed to carry out analyzing the behavior of presumed access, if website is attacked, find in a large amount of access logs and attack clue just as looking for a needle in a haystack.
Summary of the invention
For the above-mentioned shortcoming of conventional web sites logging mode, the object of the present invention is to provide a kind of web log file saved system based on bypass mirror image and method and apparatus, thus solve the foregoing problems existed in prior art.The present invention adopts the mode of bypass mirror image to obtain visit data, the data of access websites are carried out " bypass mirror image ", obtain the initial data package informatin of user's access websites, the web log file of multiple format after behaviour classification being carried out to access via behavioural analysis module, can be recorded as.Technical scheme of the present invention can not cause any burden to web server, and the selection of journal format and web server is completely irrelevant.Traditional group pessimistic concurrency control is exactly on the network switch, access relevant WEB server, is completed the functions such as relevant web log file preservation by WEB server entity; And technology networking plan of the present invention to be bypass on switches deploy an equipment entity, preserved the function of web log file and query web daily record by this equipment entity, WEB server entity has only needed the information answer function of website.
Technical scheme disclosed by the invention is specific as follows:
A kind of web log file saved system, comprise fire compartment wall, the network switch and web server, the described network switch is the network switch possessing mirror port, described mirror port is connected with daily record and preserves server; Described mirror port is used for being obtained by traffic mirroring mode being connected with the communication data that the PORT COM of server is preserved in described daily record.
Preferably, described daily record preservation server comprises flow collection module, http protocol-analysis model, Request message analysis module, Response message analysis module, behavioural analysis module, Log conditions checking module and web log file preservation module; Described flow collection module, described http protocol-analysis model, described Request message analysis module, described Response message analysis module, described behavioural analysis module, described Log conditions checking module and described web log file are preserved sequence of modules and are connected.
Preferably, described web log file saved system also comprises web log file screening module, and the condition that described web log file screening module is used for specifying according to request end is screened web log file and the selection result is fed back to described request end.
Apply the method that web log file saved system carries out daily record preservation, comprise the following steps:
S1, obtains by described mirror port the entire packet that described web server receives and send;
S2, analyzes described packet, obtains http protocol data bag from described packet;
S3, analyzes the Request message data in described http protocol data bag, obtains Request message necessary information;
S4, analyzes the Response message data in described http protocol data bag, obtains Response message necessary information;
S5, analyzes described Request message necessary information and/or Response message necessary information, obtains access behavior type information;
S6, with described Request message necessary information and/or Response message necessary information and/or access behavior type and pre-conditioned contrast, if meet described pre-conditioned, Request message described in buffer memory, and etc. the Response message corresponding with this Request message to be obtained, after getting the Response message corresponding with described Request message, then mutually corresponding Request message and Response message are formed complete access process, and described complete access process is saved in database and/or journal file according to preset format forms web log file.
Preferably, further comprising the steps of:
S7, the screening conditions arranged according to request end filter out qualified log recording, and this qualified log recording is saved as new file feed back to request end again from described database and/or journal file.
Preferably, described pre-conditioned, described preset format, described screening conditions are all arranged by web page.
Preferably, the described Request message necessary information Cookies that comprises the IP address of visitor, the concrete domain name of access, concrete URL, Refrence information of access, UserAgent and carry; Described Response message necessary information comprises response status code, the content type carried and message length.
Preferably,
S1 is specially, and is obtained by described mirror port, obtains all messages being sent to described web server and sending from described web server, and described message is separated into uplink and downlink flow; And/or
S2 is specially, and by distinguishing the content analysis of TCP load in described uplink and downlink flow, acquires http protocol massages; And/or
S3 is specially, and carries out decoding process, isolate Request necessary information to the Request message in described http protocol massages, and by described Request necessary information buffering; And/or
S4 is specially, and carries out decoding process, isolate Response necessary information to the Response message in described http protocol massages, and by described Response necessary information buffering; And/or
S5 is specially, and the access behavior of information to visitor entrained by described Request message and described Response message is analyzed, and determines the behavior type of described access behavior; And/or
S6 is specially, with described Request necessary information and/or described Response necessary information and/or described access behavior type and default Log conditions comparison, if meet described default Log conditions, then the Request packet buffer including described Request necessary information, and wait for the Response message corresponding with this Request message, after getting the Response message corresponding with this Request message, then the Request necessary information in mutually corresponding Request message and the Response necessary information in Response message are merged the complete access process of composition one, be combined into a final web log file according to the journal format preset and journal entries again and set up the search index of this web log file in write into Databasce and/or journal file.
Apply the device that web log file saved system carries out daily record preservation, comprising:
Flow collection module, for obtaining the entire packet that described web server receives and sends by described mirror port;
Http protocol-analysis model, for analyzing described packet, obtains http protocol data bag from described packet;
Request message analysis module, for analyzing the Request message data in described http protocol data bag, obtains Request message necessary information;
Response message analysis module, for analyzing the Response message data in described http protocol data bag, obtains Response message necessary information;
Behavioural analysis module, for analyzing described Request message necessary information and/or Response message necessary information, obtains access behavior type information;
Log conditions checking module, for described Request message necessary information and/or Response message necessary information and/or access behavior type and pre-conditioned contrast, if meet described pre-conditioned, sends into next treatment step;
Web log file preserves module, forms web log file for being saved in database and/or journal file according to preset format by complete access process.
Preferably, described device also comprises web log file screening module, and described web log file screening module is used for screening web log file according to specified requirements.
The invention has the beneficial effects as follows:
1. to record and while preserving web log file, on website without any impact, without the need to revising any configuration in website, without the need to rewriting the webpage of website, can plug and play be accomplished;
2. this programme is by the flow collection module data acquisition be placed on bypass equipment, can not damage the performance of web, makes web server can save resource and improves concurrent request amount and computational speed.
3. this programme has carried out intelligent classification by behavioural analysis module to access behavior, and attack, reptile, normal access etc. are very clear.
4. the log record of this programme is with what web server of use without any relation, uses apache server also can obtain the daily record of W3C form.
5. Log Filter module of the present invention can export directly to user the log content meeting user's request.
Accompanying drawing explanation
Fig. 1 is web log file saved system structural representation disclosed by the invention;
Fig. 2 is the flow chart of steps that application web log file saved system disclosed by the invention carries out the method for daily record preservation;
Fig. 3 is the schematic block diagram that application web log file saved system disclosed by the invention carries out the device of daily record preservation.
Embodiment
In order to make technical problem solved by the invention, technical scheme and beneficial effect clearly understand, below in conjunction with accompanying drawing, the present invention is further elaborated.Should be appreciated that embodiment described herein only in order to explain the present invention, be not intended to limit the present invention.
As shown in Figure 1, the invention discloses a kind of web log file saved system, comprise fire compartment wall, the network switch and web server, the described network switch is the network switch possessing mirror port, described mirror port is connected with daily record and preserves server; Described mirror port is used for being obtained by traffic mirroring mode being connected with the communication data that the PORT COM of server is preserved in described daily record.Described daily record is preserved server and is comprised flow collection module, http protocol-analysis model, Request message analysis module, Response message analysis module, behavioural analysis module, Log conditions checking module and web log file preservation module; Described flow collection module, described http protocol-analysis model, described Request message analysis module, described Response message analysis module, described behavioural analysis module, described Log conditions checking module and described web log file are preserved sequence of modules and are connected.Described web log file saved system also comprises web log file screening module, and the condition that described web log file screening module is used for specifying according to request end is screened web log file and the selection result is fed back to described request end.
As shown in Figure 2, the invention discloses and a kind ofly apply the method that web log file saved system carries out daily record preservation, comprise the following steps:
S1, obtains by described mirror port the entire packet that described web server receives and send; Be specially, obtained by described mirror port, obtain all messages being sent to described web server and sending from described web server, and described message is separated into uplink and downlink flow;
S2, analyzes described packet, obtains http protocol data bag from described packet; Being specially, by accurately distinguishing to the content analysis of TCP load in described uplink and downlink flow the message belonging to http agreement, acquiring http protocol massages; Because http agreement is initiated by Request message, therefore first http protocol analysis system isolates Request message, and then find response for this Request message, respectively Request message and Response message are delivered to Request analytical system and Response analytical system, and form the corresponding relation of Request message and Response message.
S3, analyzes the Request message data in described http protocol data bag, obtains Request message necessary information; Be specially, decoding process carried out to the Request message in described http protocol massages, isolates Request necessary information, and by described Request necessary information buffering; Described Request message necessary information comprises the information such as the IP address of visitor, the concrete domain name of access, concrete URL, Refrence information of access, UserAgent and the Cookies that carries;
S4, analyzes the Response message data in described http protocol data bag, obtains Response message necessary information; Be specially, decoding process carried out to the Response message in described http protocol massages, isolates Response necessary information, and by described Response necessary information buffering; Described Response message necessary information comprises the information such as response status code, the content type carried and message length.
S5, analyzes described Request message necessary information and/or Response message necessary information, obtains access behavior type information; Be specially, the access behavior of information to visitor entrained by described Request message and described Response message is analyzed, and determines the behavior type of described access behavior; Described access behavior type comprises: the multiple behavior types such as normal access, reptile and attack.
S6, with described Request message necessary information and/or Response message necessary information and/or access behavior type and pre-conditioned contrast, if meet described pre-conditioned, Request message described in buffer memory, and etc. the Response message corresponding with this Request message to be obtained, after getting the Response message corresponding with described Request message, then mutually corresponding Request message and Response message are formed complete access process, and described complete access process is saved in database and/or file according to preset format forms web log file, be specially, with described Request necessary information and/or described Response necessary information and/or described access behavior type and default Log conditions comparison, if meet described default Log conditions, then the Request packet buffer including described Request necessary information, and wait for the Response message corresponding with this Request message, after getting the Response message corresponding with this Request message, then the Request necessary information in mutually corresponding Request message and the Response necessary information in Response message are merged the complete access process of composition one, be combined into a final web log file according to the journal format preset and journal entries again and set up the search index of this web log file in write into Databasce and/or journal file.
In order to allow the web log file obtaining preservation have larger availability, after preserving web log file by above-mentioned steps, can also be screened daily record by following steps.
S7, the screening conditions arranged according to request end filter out qualified log recording, and this qualified log recording is saved as new file feed back to request end again from described database and/or file.
Described journal format: the appearance order and the form thereof that need the entry of record, entry in a daily record.Web log file form common at present mainly contains NCSA journal format and W3C journal format, is adopted respectively by apache and IIS, has again thinner classification not introduce under these two kinds of forms.
Preserve server preserve equipment as daily record, so just can be arranged described pre-conditioned, described preset format, described screening conditions etc. by the web-based management page on this server owing to employing a special daily record in this programme in addition.Described preset format can be NCSA common, NCSA combined, W3C masterplate, self-defined and the W3C user-defined format of Apache etc., described screening conditions can be responsive state (as 200,304), requesting method (as Get), source IP, object IP, eliminating IP, URL rule, content type (as picture) and behaviour classification (as normally access, reptile, attack etc.) etc.; These conditions also can combinationally use.By arranging screening conditions easily, and then can log content required for quick obtaining, thus daily record need not be searched as looking for a needle in a haystack, improve operating efficiency.
As shown in Figure 3, the invention discloses and a kind ofly apply the device that web log file saved system carries out daily record preservation, comprising:
Flow collection module, for obtaining the entire packet that described web server receives and sends by described mirror port;
Http protocol-analysis model, for analyzing described packet, obtains http protocol data bag from described packet;
Request message analysis module, for analyzing the Request message data in described http protocol data bag, obtains Request message necessary information;
Response message analysis module, for analyzing the Response message data in described http protocol data bag, obtains Response message necessary information;
Behavioural analysis module, for analyzing described Request message necessary information and/or Response message necessary information, obtains access behavior type information;
Log conditions checking module, for described Request message necessary information and/or Response message necessary information and/or access behavior type and pre-conditioned contrast, if meet described pre-conditioned, sends into next treatment step;
Web log file preserves module, forms web log file for being saved in database and/or journal file according to preset format by complete access process.
Also comprise web log file screening module, described web log file screening module is used for screening web log file according to specified requirements.
By adopting technique scheme disclosed by the invention, obtain effect useful as follows:
1. to record and while preserving web log file, on website without any impact, without the need to revising any configuration in website, without the need to rewriting the webpage of website, can plug and play be accomplished;
2. this programme is by the flow collection module data acquisition be placed on bypass equipment, can not damage the performance of web, makes web server can save resource and improves concurrent request amount and computational speed.
3. this programme has carried out intelligent classification by behavioural analysis module to access behavior, and attack, reptile, normal access etc. are very clear.
4. the log record of this programme is with what web server of use without any relation, uses apache server also can obtain the daily record of W3C form.
Log Filter module of the present invention can export directly to user the log content meeting user's request.
The above is only the preferred embodiment of the present invention; it should be pointed out that for those skilled in the art, under the premise without departing from the principles of the invention; can also make some improvements and modifications, these improvements and modifications also should look protection scope of the present invention.

Claims (9)

1. apply the method that web log file saved system carries out daily record preservation for one kind, described web log file saved system, comprise fire compartment wall, the network switch and web server, it is characterized in that, the described network switch is the network switch possessing mirror port, described mirror port is connected with daily record and preserves server; Described mirror port is used for being obtained by traffic mirroring mode being connected with the communication data that the PORT COM of server is preserved in described daily record;
Said method comprising the steps of:
S1, obtains by described mirror port the entire packet that described web server receives and send;
S2, analyzes described packet, obtains http protocol data bag from described packet;
S3, analyzes the Request message data in described http protocol data bag, obtains Request message necessary information;
S4, analyzes the Response message data in described http protocol data bag, obtains Response message necessary information;
S5, analyzes described Request message necessary information and/or Response message necessary information, obtains access behavior type information;
S6, with described Request message necessary information and pre-conditioned contrast and/or by described Request message necessary information with access behavior type and pre-conditioned contrast, if meet described pre-conditioned, Request message described in buffer memory, and etc. the Response message corresponding with this Request message to be obtained, after getting the Response message corresponding with described Request message, then mutually corresponding Request message and Response message are formed complete access process, and described complete access process is saved in database and/or journal file according to preset format forms web log file.
2. method according to claim 1, is characterized in that, further comprising the steps of:
S7, the screening conditions arranged according to request end filter out qualified log recording, and this qualified log recording is saved as new file feed back to request end again from described database and/or journal file.
3. method according to claim 1 and 2, is characterized in that, described pre-conditioned, described preset format, described screening conditions are all arranged by web page.
4. method according to claim 1 and 2, is characterized in that, the Cookies that described Request message necessary information comprises the IP address of visitor, the concrete domain name of access, concrete URL, Refrence information of access, UserAgent and carries; Described Response message necessary information comprises response status code, the content type carried and message length.
5. method according to claim 1 and 2, is characterized in that,
S1 is specially, and is obtained by described mirror port, obtains all messages being sent to described web server and sending from described web server, and described message is separated into uplink and downlink flow; And/or
S2 is specially, and by distinguishing the content analysis of TCP load in described uplink and downlink flow, acquires http protocol massages; And/or
S3 is specially, and carries out decoding process, isolate Request necessary information to the Request message in described http protocol massages, and by described Request necessary information buffering; And/or
S4 is specially, and carries out decoding process, isolate Response necessary information to the Response message in described http protocol massages, and by described Response necessary information buffering; And/or
S5 is specially, and the access behavior of information to visitor entrained by described Request message and described Response message is analyzed, and determines the behavior type of described access behavior; And/or
S6 is specially, with described Request necessary information and default Log conditions comparison and/or with described Request necessary information and described Response necessary information and default Log conditions comparison and/or with described Request necessary information and described access behavior type and default Log conditions comparison, if meet described default Log conditions, then the Request packet buffer including described Request necessary information, and wait for the Response message corresponding with this Request message, after getting the Response message corresponding with this Request message, then the Request necessary information in mutually corresponding Request message and the Response necessary information in Response message are merged the complete access process of composition one, be combined into a final web log file according to the journal format preset and journal entries again and set up the search index of this web log file in write into Databasce and/or journal file.
6. method according to claim 1 and 2, it is characterized in that, described daily record is preserved server and is comprised flow collection module, http protocol-analysis model, Request message analysis module, Response message analysis module, behavioural analysis module, Log conditions checking module and web log file preservation module; Described flow collection module, described http protocol-analysis model, described Request message analysis module, described Response message analysis module, described behavioural analysis module, described Log conditions checking module and described web log file are preserved sequence of modules and are connected.
7. method according to claim 1 and 2, it is characterized in that, described web log file saved system also comprises web log file screening module, and the condition that described web log file screening module is used for specifying according to request end is screened web log file and the selection result is fed back to described request end.
8. apply the device that web log file saved system carries out daily record preservation for one kind, described web log file saved system, comprise fire compartment wall, the network switch and web server, it is characterized in that, the described network switch is the network switch possessing mirror port, described mirror port is connected with daily record and preserves server; Described mirror port is used for being obtained by traffic mirroring mode being connected with the communication data that the PORT COM of server is preserved in described daily record;
Described device comprises:
Flow collection module, for obtaining the entire packet that described web server receives and sends by described mirror port;
Http protocol-analysis model, for analyzing described packet, obtains http protocol data bag from described packet;
Request message analysis module, for analyzing the Request message data in described http protocol data bag, obtains Request message necessary information;
Response message analysis module, for analyzing the Response message data in described http protocol data bag, obtains Response message necessary information;
Behavioural analysis module, for analyzing described Request message necessary information and/or Response message necessary information, obtains access behavior type information;
Log conditions checking module, for described Request message necessary information and/or Response message necessary information and/or access behavior type and pre-conditioned contrast; If meet described pre-conditioned, Request message described in buffer memory, and etc. the Response message corresponding with this Request message to be obtained, after getting the Response message corresponding with described Request message, then mutually corresponding Request message and Response message are formed complete access process;
Web log file preserves module, forms web log file for being saved in database and/or journal file according to preset format by complete access process.
9. device according to claim 8, is characterized in that described device also comprises web log file screening module, and described web log file screening module is used for screening web log file according to specified requirements.
CN201210279783.2A 2012-08-07 2012-08-07 Website log saving system, method and apparatus Expired - Fee Related CN102857369B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210279783.2A CN102857369B (en) 2012-08-07 2012-08-07 Website log saving system, method and apparatus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210279783.2A CN102857369B (en) 2012-08-07 2012-08-07 Website log saving system, method and apparatus

Publications (2)

Publication Number Publication Date
CN102857369A CN102857369A (en) 2013-01-02
CN102857369B true CN102857369B (en) 2015-02-11

Family

ID=47403577

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210279783.2A Expired - Fee Related CN102857369B (en) 2012-08-07 2012-08-07 Website log saving system, method and apparatus

Country Status (1)

Country Link
CN (1) CN102857369B (en)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103118035B (en) * 2013-03-07 2016-05-04 星云融创(北京)科技有限公司 Method and the device of analyzing web site access request parameters legal range
CN104281672B (en) * 2014-09-28 2021-02-12 网神信息技术(北京)股份有限公司 Method and device for processing log data
CN104537120A (en) * 2015-01-26 2015-04-22 浪潮通信信息系统有限公司 DNS data mining system and method based on user behavior analysis
CN105138606A (en) * 2015-08-03 2015-12-09 上海斐讯数据通信技术有限公司 Server log management method and system
CN105933268B (en) * 2015-11-27 2019-05-10 中国银联股份有限公司 A kind of website back door detection method and device based on the analysis of full dose access log
CN107563878A (en) * 2017-09-27 2018-01-09 携程计算机技术(上海)有限公司 The playback system and method for the product booking process of OTA websites
CN107592233A (en) * 2017-10-30 2018-01-16 郑州云海信息技术有限公司 A kind of method and system for screening network log
CN109327430A (en) * 2018-08-01 2019-02-12 中国科学院、水利部成都山地灾害与环境研究所 A kind of user request analysis method and apparatus
CN111913913B (en) * 2020-08-07 2024-02-13 北京星辰天合科技股份有限公司 Access request processing method and device
CN112527843B (en) * 2020-12-18 2023-04-14 国家工业信息安全发展研究中心 Data query method, device, terminal equipment and storage medium
CN114553460A (en) * 2021-12-20 2022-05-27 东方博盾(北京)科技有限公司 Internet shadow defense method and system

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101267349A (en) * 2008-04-29 2008-09-17 杭州华三通信技术有限公司 Network traffic analysis method and device
CN101719847A (en) * 2009-10-15 2010-06-02 上海寰雷信息技术有限公司 High-performance monitoring method for DNS traffic
CN102347872A (en) * 2010-08-02 2012-02-08 横河电机株式会社 Improper communication detection system

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101267349A (en) * 2008-04-29 2008-09-17 杭州华三通信技术有限公司 Network traffic analysis method and device
CN101719847A (en) * 2009-10-15 2010-06-02 上海寰雷信息技术有限公司 High-performance monitoring method for DNS traffic
CN102347872A (en) * 2010-08-02 2012-02-08 横河电机株式会社 Improper communication detection system

Also Published As

Publication number Publication date
CN102857369A (en) 2013-01-02

Similar Documents

Publication Publication Date Title
CN102857369B (en) Website log saving system, method and apparatus
US20210349964A1 (en) Predictive resource identification and phased delivery of structured documents
US10331758B2 (en) Digital communications platform for webpage overlay
JP6488508B2 (en) Web page access method, apparatus, device, and program
US10447742B2 (en) Information sharing method and device
CN101079768B (en) A method for computing click data of webpage link
US20160301732A1 (en) Systems and Methods for Recording and Replaying of Web Transactions
CN104268082B (en) The method for testing pressure and device of browser
CN103546498B (en) It is a kind of that the method and apparatus accessing webpage is provided for mobile terminal
CN109684575A (en) Processing method and processing device, storage medium, the computer equipment of web data
CN104125209A (en) Malicious website prompt method and router
CN103412890A (en) Webpage loading method and device
CN105095280A (en) Caching method and apparatus for browser
US10250521B2 (en) Data stream identifying method and device
US9356949B2 (en) Network service interface analysis
CN108256092A (en) Combined moving history in equipment
CN109634753B (en) Data processing method, device, terminal and storage medium for switching browser kernels
CN105159992A (en) Method and device for detecting page contents and network behaviors of application program
CN103513986B (en) A kind of method utilizing CGI technology to realize dynamic web server in without operating system equipment
CN111708962A (en) Rendering method, device and equipment of skeleton screen and storage medium
CN106202368A (en) Prestrain method and apparatus
CN108108381B (en) Page monitoring method and device
CN203039704U (en) Web log storage system
KR20180047467A (en) System and method for providing user profile
CN113918865A (en) Data processing method, data processing apparatus, storage medium, and electronic apparatus

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
TR01 Transfer of patent right

Effective date of registration: 20170914

Address after: 3-1202 purple mansion, Tianyuan Middle Road, Jiangning District, Jiangsu, Nanjing 210000

Patentee after: Nanjing Ding Zhen Information Technology Co., Ltd.

Address before: 102208, room 1, unit 102, building 18, two Longxi District, Changping District, Beijing, Huilongguan

Patentee before: Beijing Dingzhen Technology Co., Ltd.

TR01 Transfer of patent right
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20150211

Termination date: 20200807

CF01 Termination of patent right due to non-payment of annual fee