CN103905424A - Method for assessing security of short domain names - Google Patents

Method for assessing security of short domain names Download PDF

Info

Publication number
CN103905424A
CN103905424A CN201310729327.8A CN201310729327A CN103905424A CN 103905424 A CN103905424 A CN 103905424A CN 201310729327 A CN201310729327 A CN 201310729327A CN 103905424 A CN103905424 A CN 103905424A
Authority
CN
China
Prior art keywords
domain name
short
domain names
original
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201310729327.8A
Other languages
Chinese (zh)
Inventor
严寒冰
李轶夫
王永刚
赵忠华
姚珊
徐剑
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
National Computer Network and Information Security Management Center
Original Assignee
National Computer Network and Information Security Management Center
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by National Computer Network and Information Security Management Center filed Critical National Computer Network and Information Security Management Center
Priority to CN201310729327.8A priority Critical patent/CN103905424A/en
Publication of CN103905424A publication Critical patent/CN103905424A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Information Transfer Between Computers (AREA)

Abstract

The invention discloses a method for assessing security of short domain names. The method comprises the steps of restoring the received short domain names to the original domain names; performing security check on the original domain names, and giving out a prompt to users according to check results. According to the method, the short domain names convert to the original domain names, judgment is performed on security of the domain names, malicious domain names are intercepted, prompt is given when uncertain domain names exist, and security of the short domain names can be improved greatly.

Description

A kind of short domain name safety assessment method
Technical field
The present invention relates to Internet technical field, particularly relate to a kind of short domain name safety assessment method.
Background technology
Short domain name is also short network address (Short URL), as the term suggests be exactly shorter in form network address.Conventionally that use is SAP(Active Server Page, Active Server Pages) or PHP(PHP:Hypertext Preprocessor, hypertext preprocessor) turn to, in today of Web2.0, to have to, this is a trend.There are at present many similar services, can have substituted original tediously long network address by brief network address by short network address, allowed user can easierly share link.
Short network address service is very general in microblogging application, such as, when we are in the time that Tengxun, Sina's microblogging are sent out microblogging, in content, sometimes comprise that very long network address connects, but because microblogging only limits 140 words, so the fourdrinier wire location that microblogging is just sent out you has automatically been converted to short network address.Short network address is used " network address of fewer character "+"/"+" code " conventionally, open short network address webpage and conventionally can directly jump to the network address (common) that you will shorten, or after advertisement in several seconds in redirect.Such as can self-defined suffix to the short network address of Baidu, some short network address can also be carried out Extensive domain name analysis, and very convenient everybody uses.
But, because short domain name has height hiding, be not easy to user and identify in domain name whether contain despiteful behavior, therefore, there is network security problem.
Summary of the invention
The technical problem to be solved in the present invention is to provide a kind of short domain name safety assessment method, in order to solve the problem of likely hiding malicious act in the short domain name of prior art.
For solving the problems of the technologies described above, the invention provides a kind of short domain name safety assessment method, comprising:
The short domain name receiving is reduced into original domain name;
Original domain name is carried out to safety inspection, point out to user according to check result.
Further, the uniform resource position mark URL of original domain name is carried out to safety inspection; If determine that original domain name is safe domain name, short domain name offered to user.
Further, if determine that original domain name is unsafe domain name, user's short domain name is redirected to the self-defining obstruction page.
Further, if the safe condition of original domain name can not determine, can not determine as secure domain name, can not be judged to be malice domain name, point out user, by user determine whether connect.
Beneficial effect of the present invention is as follows:
The present invention, by short domain name is converted to former domain name, judges the fail safe of this domain name, and despiteful domain name is stopped, and uncertain domain name is pointed out, and has greatly improved the fail safe of short domain name.
Brief description of the drawings
Fig. 1 is the flow chart of a kind of short domain name safety assessment method in the embodiment of the present invention.
Embodiment
Below in conjunction with accompanying drawing and embodiment, the present invention is further elaborated.Should be appreciated that specific embodiment described herein, only in order to explain the present invention, does not limit the present invention.
As shown in Figure 1, the embodiment of the present invention relates to a kind of short domain name safety assessment method, comprising:
Step S101, is reduced into original domain name by the short domain name receiving;
User is to the short domain name of the Internet request, and request user can directly get targeted website by short domain name, and by the parsing to short domain name, assisting users completes this object.
Because short domain name is to be all transformed by certain algorithm by original domain name, therefore, adopt with the inverse operation of converting algorithm and just short domain name can be reduced into original domain name.
Step S102, carries out safety inspection to original domain name, points out to user according to check result.
In the parsing time, to the URL(Uniform Resource Locator of original domain name, URL(uniform resource locator)) carry out total inspection; If determine that original domain name is safe domain name, short domain name offered to user; If determine that original domain name is unsafe domain name, be malice domain name, user's short domain name is redirected to the self-defining obstruction page.
If the safe condition of original domain name be can not determine, can not determine as secure domain name, can not affirm be judged to be malice domain name, point out user, allow to select voluntarily manually manner of execution, user can manually activate the warning page of short domain name link, also can abandon connecting.
As can be seen from the above-described embodiment, the present invention, by short domain name is converted to former domain name, judges the fail safe of this domain name, and despiteful domain name is stopped, and uncertain domain name is pointed out, and has greatly improved the fail safe of short domain name.
Although be example object, the preferred embodiments of the present invention are disclosed, it is also possible those skilled in the art will recognize various improvement, increase and replacement, therefore, scope of the present invention should be not limited to above-described embodiment.

Claims (4)

1. a short domain name safety assessment method, is characterized in that, comprising:
The short domain name receiving is reduced into original domain name;
Original domain name is carried out to safety inspection, point out to user according to check result.
2. short domain name safety assessment method as claimed in claim 1, is characterized in that, the uniform resource position mark URL of original domain name is carried out to safety inspection; If determine that original domain name is safe domain name, short domain name offered to user.
3. short domain name safety assessment method as claimed in claim 2, is characterized in that, if determine that original domain name is unsafe domain name, user's short domain name is redirected to the self-defining obstruction page.
4. short domain name safety assessment method as claimed in claim 2 or claim 3, is characterized in that, if the safe condition of original domain name can not determine, can not determine as secure domain name, can not be judged to be malice domain name, point out user, determined whether to connect by user.
CN201310729327.8A 2013-12-25 2013-12-25 Method for assessing security of short domain names Pending CN103905424A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310729327.8A CN103905424A (en) 2013-12-25 2013-12-25 Method for assessing security of short domain names

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310729327.8A CN103905424A (en) 2013-12-25 2013-12-25 Method for assessing security of short domain names

Publications (1)

Publication Number Publication Date
CN103905424A true CN103905424A (en) 2014-07-02

Family

ID=50996578

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310729327.8A Pending CN103905424A (en) 2013-12-25 2013-12-25 Method for assessing security of short domain names

Country Status (1)

Country Link
CN (1) CN103905424A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104735074A (en) * 2015-03-31 2015-06-24 江苏通付盾信息科技有限公司 Malicious URL detection method and implement system thereof
CN106548068A (en) * 2016-10-31 2017-03-29 珠海市魅族科技有限公司 Short website information display system and method
WO2017114206A1 (en) * 2015-12-30 2017-07-06 阿里巴巴集团控股有限公司 Method and device for processing short link, and short link server

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104735074A (en) * 2015-03-31 2015-06-24 江苏通付盾信息科技有限公司 Malicious URL detection method and implement system thereof
WO2017114206A1 (en) * 2015-12-30 2017-07-06 阿里巴巴集团控股有限公司 Method and device for processing short link, and short link server
US10798056B2 (en) 2015-12-30 2020-10-06 Alibaba Group Holding Limited Method and device for processing short link, and short link server
CN106548068A (en) * 2016-10-31 2017-03-29 珠海市魅族科技有限公司 Short website information display system and method

Similar Documents

Publication Publication Date Title
TWI526825B (en) Web page link detection method, device and system
KR101723937B1 (en) Cloud-assisted method and service for application security verification
CN102663000B (en) The maliciously recognition methods of the method for building up of network address database, maliciously network address and device
CN102663319B (en) Prompting method and device for download link security
CN102957664B (en) A kind of method and device identifying fishing website
US20110145435A1 (en) Reputation Based Redirection Service
CN102769632A (en) Method and system for grading detection and prompt of fishing website
KR101530941B1 (en) Method, system and client terminal for detection of phishing websites
CN102724187A (en) Method and device for safety detection of universal resource locators
CN103338236B (en) A kind of concurrent data acquisition methods and system
CN104021154B (en) A kind of method and apparatus scanned in a browser
CN104767747A (en) Click jacking safety detection method and device
WO2015109928A1 (en) Method, device and system for loading recommendation information and detecting url
CN103810268A (en) Search result recommendation information loading method, device and system and URL detection method, device and system
CN102255915A (en) Internet virus detection method, apparatus thereof and system thereof
US9825907B2 (en) Transfer of a domain name through mobile devices
CN103905424A (en) Method for assessing security of short domain names
CN105989149A (en) Method and system for extracting and recognizing fingerprint of user equipment
US20130124687A1 (en) Apparatus and method for detecting modified uniform resource locator
CN109670100B (en) Page data capturing method and device
JP2011043924A (en) Web action history acquisition system, web action history acquisition method, gateway device and program
CN103825772A (en) Method for identifying user click behavior and gateway equipment
CN111143722A (en) Method, device, equipment and medium for detecting webpage hidden link
CN103390129B (en) Detect the method and apparatus of security of uniform resource locator
WO2012119496A1 (en) Pre-reading method and equipment

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
WD01 Invention patent application deemed withdrawn after publication
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20140702