CN109302406A - A kind of method and system of distribution webpage evidence obtaining - Google Patents

A kind of method and system of distribution webpage evidence obtaining Download PDF

Info

Publication number
CN109302406A
CN109302406A CN201811285296.0A CN201811285296A CN109302406A CN 109302406 A CN109302406 A CN 109302406A CN 201811285296 A CN201811285296 A CN 201811285296A CN 109302406 A CN109302406 A CN 109302406A
Authority
CN
China
Prior art keywords
node
evidence
evidence obtaining
address
service request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811285296.0A
Other languages
Chinese (zh)
Other versions
CN109302406B (en
Inventor
林海斌
陈艳
郭文静
陈雅贤
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Legal Notary Cloud (xiamen) Technology Co Ltd
Original Assignee
Legal Notary Cloud (xiamen) Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Legal Notary Cloud (xiamen) Technology Co Ltd filed Critical Legal Notary Cloud (xiamen) Technology Co Ltd
Priority to CN201811285296.0A priority Critical patent/CN109302406B/en
Publication of CN109302406A publication Critical patent/CN109302406A/en
Application granted granted Critical
Publication of CN109302406B publication Critical patent/CN109302406B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q50/00Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
    • G06Q50/10Services
    • G06Q50/18Legal services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1097Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/52Network services specially adapted for the location of the user terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/60Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2101/00Indexing scheme associated with group H04L61/00
    • H04L2101/60Types of network addresses
    • H04L2101/69Types of network addresses using geographic information, e.g. room number

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Business, Economics & Management (AREA)
  • Tourism & Hospitality (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • Economics (AREA)
  • General Health & Medical Sciences (AREA)
  • Human Resources & Organizations (AREA)
  • Marketing (AREA)
  • Primary Health Care (AREA)
  • Technology Law (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Power Engineering (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention proposes a kind of distributed webpage evidence collecting methods, and include the following steps: S1: data center receives evidence obtaining service request from the user;S2: evidence obtaining service request is assigned to the suitable evidence obtaining host node currently registered in registration center by data center;S3: after host node of collecting evidence receives distributed evidence obtaining service request, analyzing evidence obtaining service request, and service request of collecting evidence is assigned to the suitable of evidence obtaining host node based on analysis result and is collected evidence from node, to execute forensics process from node by collecting evidence.The double-deck distributed node scheduling is carried out from node by being forwarded to evidence obtaining host node and evidence obtaining to evidence obtaining service request, and use nodejs concurrent processing mechanism that can still provide efficiently and accurately webpage for user in the case where data high concurrent and collect evidence and services.And evidence obtaining process is also ensured in the case where saving cost and is collected evidence according to higher practicability, safety, validity and legitimacy by notarial office's mechanism controls.

Description

A kind of method and system of distribution webpage evidence obtaining
Technical field
The present invention relates to electronic evidence-collecting fields, more particularly to a kind of method and system of distributed webpage evidence obtaining.
Background technique
With popularizing for network, the network behavior of people is increased.It is each that internet is also more and more applied to each row Among industry.Human society has one after another moved to various activities on internet, forms with E-Government, e-commerce, electronics Finance, electronic instruction etc. are the various applications of representative, so that the use of internet becomes the daily living habit of people.At this In process, network security problem is gradually concerned by people, and continuing to bring out with network safety event, network information peace Become hot issue entirely.
Skill is obtained for safety of the extractive technique major design of network information evidence to computer system and file at present Art avoids carrying out any destruction to original medium and the real time data of interference and computer in a certain special time period is searched Collection technology further includes the recovery technique etc. to the information for including in swap file, cache file, temporary file.
With the high speed development of internet, online infringement case is commonplace, in the feelings that webpage quantity exponentially increases Under condition, user wants to safeguard that the equity of oneself is very difficult in time, and has a large number of users to have this demand, causes evidence obtaining platform Pressure be also very huge.In notarization enforcing law, webpage is to use using its content as evidence, therefore can be attributed to book Card, but webpage do not allow generally it is easy to maintain, it is possible to carry out the authenticity of the certification by a notary webpage and the legitimacy of evidence obtaining.Cause Webpage is more and more deposited card as one of evidence acquiring way in notarization enforcing law by this.Therefore seek a kind of more efficient Evidence obtaining, and evidence of collecting evidence has the evidence collecting method of effective legal effect and system is very important.
Currently, webpage evidence collecting method mostly uses one layer of distributed network architecture, webpage is collected evidence low efficiency, the section in network Point is all that cannot achieve the region overlay of national large area by each enterprise's independent control, and acquired web data not necessarily has There is effective legal effect.It can be seen that proposing that one kind can efficiently collect evidence, and evidence of collecting evidence has effective legal effect Evidence collecting method and system are very meaningful.
Summary of the invention
One layer of distributed network architecture low efficiency is used for existing webpage evidence obtaining set forth above, node of collecting evidence is by looking forward to Industry independent control, can not large area region overlay, therefore the invention proposes a kind of distributed webpage evidence collecting methods, including such as Lower step:
S1: data center receives evidence obtaining service request from the user;
S2: evidence obtaining service request is assigned to the main section of suitably evidence obtaining currently registered in registration center by data center Point;
S3: after evidence obtaining host node receives distributed evidence obtaining service request, analyzing evidence obtaining service request, and Service request of collecting evidence the suitable of evidence obtaining host node is assigned to based on analysis result to collect evidence from node, to be held by collecting evidence from node Row forensics process.
Further, evidence obtaining result is sent to evidence obtaining host node after node completion forensics process by evidence obtaining.It collects evidence main section Point and evidence obtaining can be by notarial office's nodes and subordinate's notarization node control in all parts of the country from node, and effectively realization evidence have Effect property and legitimacy.
Further, S1 is specifically included: being carried out registration login in registration center by user, and is received from the user IP address and real-time geographical locations, and receive corresponding webpage evidence obtaining service request.Registration center is arranged on the number in cloud According in center, and uniformly collect by the data center in cloud the evidence obtaining service request of user.
Further, evidence obtaining host node is registered in registration center by following steps: evidence obtaining host node is in registration The heart registers first node information, first node information include collect evidence the actual geographic address of host node, IP address, node capacity, Node connects quantity, response time, vertex ticks;Evidence obtaining is registered in registration center from node by following steps: evidence obtaining The evidence obtaining of host node registers second node information in registration center from node, and second node information includes the reality collected evidence from node Geographical address, IP address, node capacity, node processing task quantity, response time, vertex ticks, nodal community.
Further, S2 specifically comprises the following steps:
S21: the real-time geographical locations of user are sent to the IP address of registration center's request evidence obtaining host node by data center;
S22: registration center matches according to the real-time geographical locations of user with the actual geographic address of evidence obtaining host node And the IP address for host node of collecting evidence or present node are connected to the IP address of the least evidence obtaining host node of quantity according to matching result It is sent to data center, the real-time geographical locations of user match if it exists with the actual geographic address of evidence obtaining host node and the master that collects evidence The vertex ticks of node is that the IP address for host node of collecting evidence then normally is sent to data center, if it does not exist matching or presence Match but the vertex ticks for host node of collecting evidence is the abnormal IP address that present node is then connected to the least evidence obtaining host node of quantity It is sent to data center;
S23: data center connects the least evidence obtaining host node of quantity according to the IP address or present node of evidence obtaining host node IP address forwarding evidence obtaining service request to collect evidence host node;Realize first layer distributed node scheduling i.e. evidence obtaining host node tune Degree.
S24: monitoring center obtains response time and the node connection quantity of evidence obtaining host node in real time;
S25: the information update first node information that registration center obtains according to monitoring center.
Further, S3 specifically comprises the following steps:
S31: the evidence obtaining service request of user and analysis result are sent to registration center's request evidence obtaining from section by data center The IP address of point;
S32: registration center is matched and according to matching result based on the analysis results with evidence obtaining from the nodal community of node Evidence obtaining is sent to data center from the least evidence obtaining of the IP address or present node of node connection quantity from the IP address of node, The analysis result of evidence obtaining service request includes detailed network address, keyword, picture, and nodal community includes network address, keyword, picture, The vertex ticks that the analysis result for service request of collecting evidence is matched if it exists and collected evidence from node from the nodal community of node with evidence obtaining For evidence obtaining is then normally sent to data center from the IP address of node, matching is matched or existed if it does not exist but is collected evidence from node Vertex ticks be it is abnormal, the least evidence obtaining of present node connection quantity from the IP address of node is sent to data center;
S33: data center collects evidence from the IP address or present node of node connection quantity are least from node according to evidence obtaining IP address forwarding evidence obtaining service request to collecting evidence from node;Realize second layer distributed node scheduling i.e. evidence obtaining from node tune Degree.
S34: monitoring center obtains response time and the node processing task quantity collected evidence from node in real time;
S35: the information update second node information that registration center obtains according to monitoring center.
Further, the evidence obtaining host node that the response time is more than threshold value is connected into quantity taking more than node capacity with node Host node is demonstrate,proved labeled as abnormal, evidence obtaining host node is labeled as normal in the case of remaining;It is more than the evidence obtaining of threshold value by the response time From vertex ticks be from the evidence obtaining that node and node processing task quantity are more than node capacity it is abnormal, in the case of remaining evidence obtaining from Vertex ticks is normal.
Further, user is made as using nodejs concurrent processor in evidence obtaining host node and data center and login note is provided Volume receives evidence obtaining service request operation, is handled when user volume reaches certain amount using concurrent processing mechanism.It can be in number Efficient and accurately webpage evidence obtaining service can be still provided in the case where according to high concurrent for user.
The invention also provides a kind of distributed webpage evidence-obtaining systems, comprising:
Login module is registered, is logged in make user carry out real name registration, and create proper account, distribution storage for user Space;
Positioning obtains module, to obtain IP address, the real-time geographical locations of user's current accessed;
Service request module, to the webpage evidence obtaining service request for receiving user's proposition and its analysis as a result, obtaining evidence obtaining The IP address forwarding evidence obtaining service request of the least evidence obtaining host node of IP address or present node connection quantity of host node is to taking Host node is demonstrate,proved, evidence obtaining is obtained and is forwarded from the least evidence obtaining of the IP address or present node of node connection quantity from the IP address of node Service request of collecting evidence is to collecting evidence from node;
Collect evidence host node scheduler module, be assigned to the service request that will collect evidence currently registered in registration center it is suitable Evidence obtaining host node, according to the real-time geographical locations of user with evidence obtaining host node actual geographic address match, and according to Matching result is by the IP address for host node of collecting evidence or the IP address of the least evidence obtaining host node of present node connection quantity, according to taking The analysis result for demonstrate,proving service request is matched from the nodal community of node with evidence obtaining and will be collected evidence according to matching result from node IP address or the least evidence obtaining of present node connection quantity from the IP address of node;
Service request analysis module, to analyze to receiving distributed evidence obtaining service request, and based on point Analysis result is sent to service request module, is assigned to service request of collecting evidence by service request module and is connected to evidence obtaining host node Suitable evidence obtaining is from node, to execute forensics process from node by collecting evidence;
Evidence memory module generates the MD5 value of evidence using MD5 algorithm to store the summary info of evidence, and storage is used The IP address of family information, evidence MD5 value and host node of collecting evidence;
Evidence enquiry module, to the IP address according to user information, evidence MD5 value and host node of collecting evidence, from evidence obtaining Host node obtains former data information and consults for user.
The invention also provides a kind of computer readable storage mediums, are stored thereon with computer program, which is located Reason device realizes method described in above-mentioned any one when executing.
A kind of distributed webpage evidence collecting method proposed by the present invention and system, uniformly collect user by the data center in cloud Evidence obtaining service request, then evidence obtaining service request is forwarded to evidence obtaining host node and evidence obtaining and carries out the double-deck distributed node from node Scheduling.Wherein evidence obtaining host node and evidence obtaining can be by notarial office's node in all parts of the country and subordinate's notarization node controls from node System, and using the double-deck distributed node scheduling and region zones node is used, it is more efficient under the premise of being convenient for the user to use Carry out collect evidence, and collect evidence according to having effective legal effect.And using nodejs concurrent processing mechanism in data high concurrent In the case where can still be provided for user efficiently and accurately webpage evidence obtaining service, and process of collecting evidence is by notarial office's mechanism controls, It also ensures and is collected evidence according to higher practicability, safety, validity and legitimacy in the case where saving cost.
Detailed description of the invention
Including attached drawing to provide a further understanding of embodiments and attached drawing is incorporated into this specification and is constituted this Part of specification.Drawing illustration embodiment and together with the description principle for explaining the present invention.It will readily recognize that To many expected advantages of other embodiments and embodiment, because described in detail below by quoting, they become by preferably Understand.The element of attached drawing is not necessarily mutually proportionally.Same appended drawing reference refers to corresponding like.
Fig. 1 is the general flow chart of the distributed webpage evidence collecting method of the embodiment of the present invention;
Fig. 2 is the flow chart of the step S2 of the distributed webpage evidence collecting method of the embodiment of the present invention;
Fig. 3 is the flow chart of the step S3 of the distributed webpage evidence collecting method of the embodiment of the present invention;
Fig. 4 is the structure chart of the distributed webpage evidence-obtaining system of the embodiment of the present invention.
Specific embodiment
To make the objectives, technical solutions, and advantages of the present invention clearer, below in conjunction with attached drawing to the present invention make into It is described in detail to one step, it is clear that described embodiments are only a part of the embodiments of the present invention, rather than whole implementation Example.Based on the embodiments of the present invention, obtained by those of ordinary skill in the art without making creative efforts All other embodiment, shall fall within the protection scope of the present invention.
The invention proposes the invention proposes the invention proposes a kind of distributed webpage evidence collecting methods, as shown in Figure 1, Include the following steps:
S1: data center receives evidence obtaining service request from the user;
Step S1 is specifically included: registration login is carried out in registration center by user, and with receiving IP from the user Location and real-time geographical locations, and receive corresponding webpage evidence obtaining service request.Registration center is arranged in the data in cloud In the heart, user carries out real name registration login by modes such as recognition of face, fingerprint recognition, identity card identification, cell-phone number verifyings, is System is that user creates proper account, and distributes memory space.And the evidence obtaining service of user is uniformly collected by the data center in cloud Request.
Host node collect evidence in registration center's registration first node information, first node information includes the reality of evidence obtaining host node Geographical address, IP address, node capacity, node connect quantity, response time, vertex ticks;Collect evidence host node evidence obtaining from section Point registration center register second node information, second node information include collect evidence the actual geographic address from node, IP address, Node capacity, node processing task quantity, response time, vertex ticks, nodal community.Node capacity indicates that synchronization can be located How many task are managed, vertex ticks includes normal, abnormal.When host node of collecting evidence refuses offer service, registration center will be deleted Its corresponding first node information is then added when host node of collecting evidence provides service again in its corresponding first node information.When Evidence obtaining from node refuse offer service when, registration center will delete its corresponding second node information, when evidence obtaining from node again Its corresponding second node information is then added when service is provided.The result for service request of collecting evidence can be detailed network address, keyword, figure Piece;Nodal community may be network address, keyword, picture.
S2: evidence obtaining service request is assigned to the main section of suitably evidence obtaining currently registered in registration center by data center Point;
As shown in Fig. 2, S2 specifically comprises the following steps:
S21: the real-time geographical locations of user are sent to the IP address of registration center's request evidence obtaining host node by data center;
S22: registration center matches according to the real-time geographical locations of user with the actual geographic address of evidence obtaining host node And the IP address for host node of collecting evidence or present node are connected to the IP address of the least evidence obtaining host node of quantity according to matching result It is sent to data center, the real-time geographical locations of user match if it exists with the actual geographic address of evidence obtaining host node and the master that collects evidence The vertex ticks of node is that the IP address for host node of collecting evidence then normally is sent to data center, if it does not exist matching or presence Match but the vertex ticks for host node of collecting evidence is the abnormal IP address that present node is then connected to the least evidence obtaining host node of quantity It is sent to data center;The evidence obtaining host node that response time is more than threshold value is connected into the evidence obtaining that quantity is more than node capacity with node Host node is labeled as abnormal, and evidence obtaining host node is labeled as normal in the case of remaining.
S23: data center connects the least evidence obtaining host node of quantity according to the IP address or present node of evidence obtaining host node IP address forwarding evidence obtaining service request to collect evidence host node;Realize first layer distributed node scheduling i.e. evidence obtaining host node tune Degree.
S24: monitoring center obtains response time and the node connection quantity of evidence obtaining host node in real time;
S25: the information update first node information that registration center obtains according to monitoring center.
S3: after evidence obtaining host node receives distributed evidence obtaining service request, analyzing evidence obtaining service request, and Service request of collecting evidence the suitable of evidence obtaining host node is assigned to based on analysis result to collect evidence from node, to be held by collecting evidence from node Row forensics process.
As shown in figure 3, S3 specifically comprises the following steps:
S31: the evidence obtaining service request of user and analysis result are sent to registration center's request evidence obtaining from section by data center The IP address of point;
S32: registration center is matched and according to matching result based on the analysis results with evidence obtaining from the nodal community of node Evidence obtaining is sent to data center from the least evidence obtaining of the IP address or present node of node connection quantity from the IP address of node, The analysis result of evidence obtaining service request includes detailed network address, keyword, picture, and nodal community includes network address, keyword, picture, The vertex ticks that the analysis result for service request of collecting evidence is matched if it exists and collected evidence from node from the nodal community of node with evidence obtaining For evidence obtaining is then normally sent to data center from the IP address of node, matching is matched or existed if it does not exist but is collected evidence from node Vertex ticks be it is abnormal, the least evidence obtaining of present node connection quantity from the IP address of node is sent to data center; By the response time be more than threshold value evidence obtaining from node and node processing task quantity be more than the evidence obtaining of node capacity from vertex ticks To be abnormal, evidence obtaining is normal from vertex ticks in the case of remaining.
S33: data center collects evidence from the IP address or present node of node connection quantity are least from node according to evidence obtaining IP address forwarding evidence obtaining service request to collecting evidence from node;Realize second layer distributed node scheduling i.e. evidence obtaining from node tune Degree.
S34: monitoring center obtains response time and the node processing task quantity collected evidence from node in real time;
S35: the information update second node information that registration center obtains according to monitoring center.
It collects evidence from the nodal community of node if detailed network address, is then directly entered detailed network address and carries out webpage evidence obtaining operation; Nodal community is then retrieved keyword using search engine if keyword, the website information retrieved is chosen corresponding Quantity enters corresponding web site and carries out webpage evidence obtaining operation;If picture, network is carried out again after first analyzing using picture analyzing algorithm Retrieval, then the website information retrieved selection respective numbers are entered into corresponding web site and carry out webpage evidence obtaining operation.It collects evidence from node Evidence obtaining result is sent to evidence obtaining host node after completion forensics process.Collecting evidence host node and evidence obtaining can be by all parts of the country from node Notarial office's node and subordinate's notarization node control, effectively realize evidence validity and legitimacy.And result of collecting evidence into Row storage, stores the summary info of evidence, i.e., generates the MD5 value of evidence using MD5 algorithm, and by user information, evidence MD5 Value, the contents such as former address data memory i.e. evidence obtaining host node address store, according to user information, evidence MD5 value and original Address data memory i.e. evidence obtaining host node address obtains former data information from evidence obtaining host node and consults for user.
Using nodejs concurrent processor to be made as in evidence obtaining host node and data center, user provides Login Register, reception takes Service request operation is demonstrate,proved, is handled when user volume reaches certain amount using concurrent processing mechanism.It can be in data high concurrent In the case where can still be provided for user efficiently and accurately webpage evidence obtaining service.
The invention also provides a kind of distributed webpage evidence-obtaining systems, as shown in Figure 4, comprising:
Login module 1 is registered, is logged in make user carry out real name registration, and create proper account for user, distribution is deposited Store up space;In a preferred embodiment, user in registration login module 1 using recognition of face, fingerprint recognition, identity card by being known Not, the modes such as cell-phone number verifying carry out real name registration login.
Positioning obtains module 2, to obtain IP address, the real-time geographical locations of user's current accessed;
Service request module 3, to the webpage evidence obtaining service request for receiving user's proposition and its analysis as a result, obtaining evidence obtaining The IP address forwarding evidence obtaining service request of the least evidence obtaining host node of IP address or present node connection quantity of host node is to taking Host node is demonstrate,proved, evidence obtaining is obtained and is forwarded from the least evidence obtaining of the IP address or present node of node connection quantity from the IP address of node Service request of collecting evidence is to collecting evidence from node;
Evidence obtaining host node scheduler module 4, will collect evidence, service request is assigned to the conjunction currently registered in registration center Suitable evidence obtaining host node is matched according to the real-time geographical locations of user with the actual geographic address of evidence obtaining host node, and root The IP address that the IP address for host node of collecting evidence or present node are connected to the least evidence obtaining host node of quantity according to matching result, according to The analysis result for service request of collecting evidence is matched from the nodal community of node with evidence obtaining and will be collected evidence according to matching result from section IP address of the least evidence obtaining of IP address or present node connection quantity of point from node;
Service request analysis module 5, to analyze to receiving distributed evidence obtaining service request, and based on point Analysis result is sent to service request module 3, is assigned to evidence obtaining service request by service request module and is connected to evidence obtaining host node Suitable evidence obtaining from node, to execute forensics process from node by collecting evidence;
Evidence memory module generates the MD5 value of evidence using MD5 algorithm to store the summary info of evidence, and storage is used The IP address of family information, evidence MD5 value and host node of collecting evidence;
Evidence enquiry module, to the IP address according to user information, evidence MD5 value and host node of collecting evidence, from evidence obtaining Host node obtains former data information and consults for user.
Embodiment one
Webpage forensics process: user provides corresponding real name information in registration login module 1 and registers and user name is arranged And login password, to use corresponding user name and password login system.And real-time obtain of module 2 is obtained by positioning and is used Family current location, and webpage evidence obtaining service request is proposed by service request module.
After data center gets evidence obtaining service request, by the evidence obtaining evidence obtaining host node of host node module schedules 4, it will collect evidence Service request is forwarded to the good evidence obtaining host node of Systematic selection.Evidence obtaining host node is asked after getting evidence obtaining service request by service It asks analysis module 5 to be analyzed, completes evidence obtaining using different schemes based on the analysis results, the evidence obtaining service request after analysis is made With dynamic dispatching algorithm scheduling evidence obtaining from the evidence obtaining service request after node, forwarding analysis to evidence obtaining from node.It collects evidence from node Evidence obtaining task is completed after obtaining evidence obtaining service request, and result is back to corresponding evidence obtaining host node.Evidence memory module 6 exists Evidence obtaining host node storage evidence obtaining as a result, and generate evidence obtaining result MD5 value storage, MD5 value is forwarded to data center.In data The heart stores evidence MD5 value and the i.e. evidence obtaining host node address of former address data memory into the account of relative users.
Node scheduling process: evidence obtaining host node scheduler module 4 preferentially selects the main section of evidence obtaining according to user's positioning address first Point inquires server queue's situation of current evidence obtaining host node, and minimum connection method selection evidence obtaining host node is used if beyond limiting. Host node of collecting evidence dispatches multiple evidence obtainings using minimum connection method and provides service from node.
Service request analysis process: the evidence obtaining service request information that user proposes is analyzed using service request analysis module 5 It is specific network address or keyword or picture.Evidence obtaining host node arranges accordingly to collect evidence to collect evidence from node processing based on the analysis results to take Business request.
Evidence Stored Procedure: evidence obtaining result is back to evidence obtaining host node from node by evidence obtaining, and evidence memory module 6 is being collected evidence The MD5 value of host node generation evidence;Evidence obtaining host node stores former data and MD5 value to the account of relative users.By MD5 value It is forwarded to data center.Data center stores MD5 value to relative users account.
Evidence querying flow: user's logon data center, in the information that the selection of evidence enquiry module 7 needs to inquire.Data The MD5 value of user information and selected evidence is forwarded to corresponding evidence obtaining host node by center.Evidence obtaining host node is believed according to user Breath and MD5 value check former data forwarding to data center for user.
The invention also provides a kind of computer readable storage mediums, are stored thereon with computer program, which is located Reason device realizes method described in above-mentioned any one when executing.
A kind of distributed webpage evidence collecting method proposed by the present invention and system, the evidence obtaining of user is uniformly collected by data center Service request, then evidence obtaining service request is forwarded to evidence obtaining host node and evidence obtaining and carries out the double-deck distributed node scheduling from node. Wherein evidence obtaining host node and evidence obtaining can be by notarial office's nodes and subordinate's notarization node control in all parts of the country from node, and adopt Region zones node, under the premise of being convenient for the user to use, more efficient progress are dispatched and used with the double-deck distributed node Evidence obtaining, and evidence of collecting evidence has effective legal effect.And using nodejs concurrent processing mechanism the data high concurrent the case where Under can still be provided for user efficiently and accurately webpage evidence obtaining service, and collect evidence process by notarial office's mechanism controls, saving It also ensures and is collected evidence according to higher practicability, safety, validity and legitimacy in the case where cost.
The foregoing describe the protection scopes of the specific embodiment of the application, but the application to be not limited thereto, any ripe It knows those skilled in the art within the technical scope of the present application, can easily think of the change or the replacement, should all cover Within the scope of protection of this application.Therefore, the protection scope of the application should be based on the protection scope of the described claims.
In the description of the present application, although centainly sequentially to list each step in claim to a method, this A little steps might not be executed with listed step, on the contrary can be with without departing substantially from spirit of the invention and purport It is executed with opposite or parallel form.The presence in the unlisted element or step of claim is not precluded in word ' including '. Word ' one ' before element or ' one ' presence of multiple such elements is not precluded.In mutually different dependent claims The middle simple fact for recording certain measures does not show that the combination of these measures is consequently not used for improving.In the claims any Reference symbol should not be construed as limited to range.

Claims (10)

1. a kind of distribution webpage evidence collecting method, which comprises the steps of:
S1: data center receives evidence obtaining service request from the user;
S2: evidence obtaining service request is assigned to the suitable evidence obtaining host node currently registered in registration center by data center;
S3: after evidence obtaining host node receives distributed evidence obtaining service request, evidence obtaining service request is analyzed, and is based on Service request of collecting evidence is assigned to the suitable of evidence obtaining host node and collected evidence from node by analysis result, to be taken by collecting evidence from node execution Demonstrate,prove process.
2. distribution webpage evidence collecting method according to claim 1, which is characterized in that the evidence obtaining is completed to collect evidence from node Evidence obtaining result is sent to the evidence obtaining host node after process.
3. distribution webpage evidence collecting method according to claim 1, which is characterized in that the S1 is specifically included: by user Registration login is carried out in the registration center, and receives IP address from the user and real-time geographical locations, and receive Corresponding webpage evidence obtaining service request.
4. distribution webpage evidence collecting method according to claim 1, which is characterized in that the evidence obtaining host node passes through following Step is registered in the registration center: the evidence obtaining host node registers first node information in the registration center, described First node information includes the actual geographic address of the evidence obtaining host node, IP address, node capacity, node connection quantity, sound Between seasonable, vertex ticks;The evidence obtaining is registered in the registration center from node by following steps: the main section of evidence obtaining The evidence obtaining of point registers second node information in the registration center from node, and the second node information includes described collect evidence from section The actual geographic address of point, IP address, node capacity, node processing task quantity, response time, vertex ticks, nodal community.
5. distribution webpage evidence collecting method according to claim 1, which is characterized in that the S2 specifically includes following step It is rapid:
S21: the real-time geographical locations of the user are sent to the registration center by the data center requests the evidence obtaining to be led The IP address of node;
S22: the registration center is according to the real-time geographical locations of the user and the actual geographic address of the evidence obtaining host node It carries out matching and is led the IP address of the evidence obtaining host node or the least evidence obtaining of present node connection quantity according to matching result The IP address of node is sent to the data center, and the real-time geographical locations of the user and the evidence obtaining host node are practically Reason address matches if it exists and the vertex ticks for host node of collecting evidence is normally then to be sent to the IP address of the evidence obtaining host node The data center, it is abnormal then by present node for matching or exist the vertex ticks of matching but host node of collecting evidence if it does not exist The IP address of the least evidence obtaining host node of connection quantity is sent to the data center;
S23: the data center leads according to the IP address or the least evidence obtaining of present node connection quantity of the evidence obtaining host node The IP address of node forwards evidence obtaining service request to the evidence obtaining host node;
S24: monitoring center obtains response time and the node connection quantity of the evidence obtaining host node in real time;
S25: registration center first node information according to the information update that the monitoring center obtains.
6. distribution webpage evidence collecting method according to claim 1, which is characterized in that the S3 specifically includes following step It is rapid:
S31: the evidence obtaining service request of user and analysis result are sent to the registration center and requested by the data center IP address of the evidence obtaining from node;
S32: the registration center match from the nodal community of node with the evidence obtaining according to the analysis result and basis Matching result sends out the evidence obtaining from the least evidence obtaining of the IP address or present node of node connection quantity from the IP address of node It send to the data center, the analysis result of the evidence obtaining service request includes detailed network address, keyword, picture, the node Attribute includes network address, keyword, picture, analysis result and the nodal community collected evidence from node of the evidence obtaining service request It matches and collects evidence if it exists and evidence obtaining is then sent to data center from the IP address of node from the vertex ticks of node to be normal, if It is abnormal then that present node connection quantity is least there is no matching or existing matching but collect evidence from the vertex ticks of node Evidence obtaining is sent to data center from the IP address of node;
S33: the data center according to it is described evidence obtaining from the IP address or present node of node connection quantity it is least evidence obtaining from The IP address of node forwards the evidence obtaining service request to collect evidence to described from node;
S34: monitoring center obtains response time and node processing task quantity of the evidence obtaining from node in real time;
S35: registration center second node information according to the information update that the monitoring center obtains.
7. any distributed webpage evidence collecting method in -6 according to claim 1, which is characterized in that by the response time Evidence obtaining host node more than threshold value connects with the node evidence obtaining host node of the quantity more than the node capacity labeled as not just Often, host node is collected evidence in the case of remaining labeled as normal;It is more than the evidence obtaining of threshold value from node and node by the response time Reason task quantity is more than that the evidence obtaining of node capacity is abnormal from vertex ticks, from vertex ticks is normal in the case of remaining.
8. any distributed webpage evidence collecting method in -6 according to claim 1, which is characterized in that in the main section of evidence obtaining Point and data center are made as user using nodejs concurrent processor and provide Login Register, reception evidence obtaining service request operation, It is handled when user volume reaches certain amount using concurrent processing mechanism.
9. a kind of distribution webpage evidence-obtaining system characterized by comprising
Login module is registered, is logged in make user carry out real name registration, and create proper account for user, distribution storage is empty Between;
Positioning obtains module, to obtain IP address, the real-time geographical locations of user's current accessed;
Service request module, to the webpage evidence obtaining service request for receiving user's proposition and its analysis as a result, obtaining the evidence obtaining The IP address of the least evidence obtaining host node of IP address or present node connection quantity of host node forwards evidence obtaining service request to institute Evidence obtaining host node is stated, IP of the evidence obtaining from the least evidence obtaining of the IP address or present node of node connection quantity from node is obtained Address forwards the evidence obtaining service request to collect evidence to described from node;
Collect evidence host node scheduler module, to the evidence obtaining service request is assigned to currently registered in registration center it is suitable Evidence obtaining host node, according to the real-time geographical locations of the user and it is described evidence obtaining host node actual geographic address carry out Match, and the IP address of the evidence obtaining host node or present node are connected by the least evidence obtaining host node of quantity according to matching result IP address, according to the service of the evidence obtaining service request
With the IP address collected evidence and matched from the nodal community of node and according to matching result by the evidence obtaining from node Or the least IP address collected evidence from node of present node connection quantity;
Service request analysis module, to analyze to receiving distributed evidence obtaining service request, and based on analysis knot Fruit is sent to the service request module, and evidence obtaining service request is assigned to the evidence obtaining host node by the service request module The suitable evidence obtaining from node, to execute forensics process from node by the evidence obtaining;
Evidence memory module generates the MD5 value of evidence, storage user's letter using MD5 algorithm to store the summary info of evidence The IP address of breath, evidence MD5 value and host node of collecting evidence;
Evidence enquiry module, to according to the user information, evidence MD5 value and it is described evidence obtaining host node IP address, from The evidence obtaining host node obtains former data information and consults for user.
10. a kind of computer readable storage medium, is stored thereon with computer program, which is characterized in that the program is by processor Method described in any one of claim 1-8 is realized when execution.
CN201811285296.0A 2018-10-31 2018-10-31 Distributed webpage evidence obtaining method and system Active CN109302406B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811285296.0A CN109302406B (en) 2018-10-31 2018-10-31 Distributed webpage evidence obtaining method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811285296.0A CN109302406B (en) 2018-10-31 2018-10-31 Distributed webpage evidence obtaining method and system

Publications (2)

Publication Number Publication Date
CN109302406A true CN109302406A (en) 2019-02-01
CN109302406B CN109302406B (en) 2021-06-25

Family

ID=65145043

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811285296.0A Active CN109302406B (en) 2018-10-31 2018-10-31 Distributed webpage evidence obtaining method and system

Country Status (1)

Country Link
CN (1) CN109302406B (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110191146A (en) * 2019-03-21 2019-08-30 北京北信源软件股份有限公司 A kind of long-range retrieval method of file based on browser and system
CN115186854A (en) * 2022-09-07 2022-10-14 艾斯特国际安全技术(深圳)有限公司 Certificate acquisition control method, device and system and storage medium

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101021928A (en) * 2007-03-12 2007-08-22 北京中网安达信息安全科技有限公司 Apparatus and method for antipiracy monitoring and evidence-taking
CN101465875A (en) * 2008-11-12 2009-06-24 湖南大学 Load equilibrium algorithm based on network orientation
CN102340543A (en) * 2011-10-18 2012-02-01 华为技术有限公司 Method and equipment for selecting master node of system
CN102439913A (en) * 2009-02-27 2012-05-02 雅塔公司 System and method for network traffic management and load balancing
CN103401953A (en) * 2013-07-18 2013-11-20 东南大学 End-to-end voice communication node addressing method based on dual-layer structure
CN104579851A (en) * 2015-01-28 2015-04-29 中国人民解放军国防科学技术大学 Evidence obtaining system for large-scale mobile internet core network
CN107291847A (en) * 2017-06-02 2017-10-24 东北大学 A kind of large-scale data Distributed Cluster processing method based on MapReduce
US20170315886A1 (en) * 2010-12-13 2017-11-02 Amazon Technologies, Inc. Locality based quorum eligibility

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101021928A (en) * 2007-03-12 2007-08-22 北京中网安达信息安全科技有限公司 Apparatus and method for antipiracy monitoring and evidence-taking
CN101465875A (en) * 2008-11-12 2009-06-24 湖南大学 Load equilibrium algorithm based on network orientation
CN102439913A (en) * 2009-02-27 2012-05-02 雅塔公司 System and method for network traffic management and load balancing
US20170315886A1 (en) * 2010-12-13 2017-11-02 Amazon Technologies, Inc. Locality based quorum eligibility
CN102340543A (en) * 2011-10-18 2012-02-01 华为技术有限公司 Method and equipment for selecting master node of system
CN103401953A (en) * 2013-07-18 2013-11-20 东南大学 End-to-end voice communication node addressing method based on dual-layer structure
CN104579851A (en) * 2015-01-28 2015-04-29 中国人民解放军国防科学技术大学 Evidence obtaining system for large-scale mobile internet core network
CN107291847A (en) * 2017-06-02 2017-10-24 东北大学 A kind of large-scale data Distributed Cluster processing method based on MapReduce

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
BALWINDER SODHI: "A Cloud Architecture Using Smart Nodes", 《2011 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE》 *
高蓟超: "Hadoop平台存储策略的研究与优化", 《中国优秀硕士学位论文全文数据库 信息科技辑》 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110191146A (en) * 2019-03-21 2019-08-30 北京北信源软件股份有限公司 A kind of long-range retrieval method of file based on browser and system
CN115186854A (en) * 2022-09-07 2022-10-14 艾斯特国际安全技术(深圳)有限公司 Certificate acquisition control method, device and system and storage medium

Also Published As

Publication number Publication date
CN109302406B (en) 2021-06-25

Similar Documents

Publication Publication Date Title
JP5735969B2 (en) System and method for analyzing social graph data for determining connections within a community
Shao et al. Personalized qos prediction forweb services via collaborative filtering
US7739314B2 (en) Scalable user clustering based on set similarity
US7809752B1 (en) Representing user behavior information
US8984226B2 (en) Load balancing based upon data usage
BRPI0715701A2 (en) Data collection method in a distributed network
WO2011047474A1 (en) Systems and methods for social graph data analytics to determine connectivity within a community
US9910858B2 (en) System and method for providing contextual analytics data
KR20110009198A (en) Search results with most clicked next objects
JP7084691B2 (en) How to process and present real-time social data on a map
CN108399226A (en) A kind of big data cleaning method for digital library
KR20140025416A (en) Method and system for an improved reservation system optimizing repeated search requests
Kleppe et al. Analysing and understanding news consumption patterns by tracking online user behaviour with a multimodal research design
Blake et al. Workflow composition of service level agreements for web services
US8352442B2 (en) Determination of an updated data source from disparate data sources
US11797617B2 (en) Method and apparatus for collecting information regarding dark web
CN109302406A (en) A kind of method and system of distribution webpage evidence obtaining
Sams et al. E-research applications for tracking online socio-political capital in the Asia-Pacific region
JP2012103759A (en) Library holdings retrieval system, recommendation information providing method, and program
Rai et al. Using open source intelligence as a tool for reliable web searching
CN114584486A (en) Distributed network asset scanning detection platform and scanning detection method
Huang et al. A process mining based service composition approach for mobile information systems
CN109324955A (en) A kind of IT operational system interface creating method with intelligent recommendation function
Alam et al. A discrete event simulation tool for performance management of web-based application systems
Ahmad et al. QaaS (quality as a service) model for web services using big data technologies

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant