CN110069910A - A kind of machine behavior determines method, web browser and web page server - Google Patents

A kind of machine behavior determines method, web browser and web page server Download PDF

Info

Publication number
CN110069910A
CN110069910A CN201810063286.6A CN201810063286A CN110069910A CN 110069910 A CN110069910 A CN 110069910A CN 201810063286 A CN201810063286 A CN 201810063286A CN 110069910 A CN110069910 A CN 110069910A
Authority
CN
China
Prior art keywords
webpage
behavior
information
user
web page
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201810063286.6A
Other languages
Chinese (zh)
Inventor
袁明凯
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Individual
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Priority to CN201810063286.6A priority Critical patent/CN110069910A/en
Publication of CN110069910A publication Critical patent/CN110069910A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/958Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/316User authentication by observing the pattern of computer usage, e.g. typical user behaviour
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Abstract

The present invention relates to a kind of machine behaviors to determine method, web browser and web page server, web browser carries out authentication before user accesses webpage, the identity information of input and public security system and the student system of major universities and colleges are subjected to networking certification identity, browsing Web Page Processing is entered after approved qualified;Webpage is inputted, input information is obtained from web page server, and web standards code name is judged whether it is according to input information, after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user includes mouse action information and keyboard operation information for the operation behavior information of the webpage;The operation behavior information of acquisition is sent to web page server;Web page server determines whether the user is effective for the machine behavior of the webpage according to the operation behavior information received;And when judging that the machine behavior is effective, the operation behavior for determining that the user is directed to the webpage is machine behavior.

Description

A kind of machine behavior determines method, web browser and web page server
Technical field
The present invention relates to a kind of technical fields of internet information processing, more particularly to a kind of machine behavior determination side Method, web browser and web page server.
Background technique
With the continuous development of Internet technology, more and more information resources select network as the carrier propagated, and use Family can access the information in each webpage by web browser.But in the prior art, certain user is in order to obtain website Integral, or for the releasing advertisements in website or fallacious message, the operation of software program models people, Lai Jinhang may be used The operations such as malicious registration, malice are logged in, maliciously posted, malice is replied, for example, after user starts malicious registration software program, it should Software program can simulate the operation of people, and the registration information generated at random is inputted in the webpage of user's registration, then click registration, Wherein, the operation behavior as caused by the operation of software program models people is referred to as machine behavior.If web page server is not Whether the operation behavior that can identify user for webpage is machine behavior, then web page server will generate machine behavior each Kind operation requests (registration request, logging request, request of posting, reply request etc.) carry out respective handling, this just consumes webpage The more process resource of server, reduces the treatment effeciency of web page server, in addition, can also generate in web page server a large amount of Malicious act data, occupy the more storage resource of web page server.
In view of the above-mentioned problems, the prior art proposes that (registration request, login are asked in the certain operation requests for receiving user Ask, request of posting, reply request etc.) after, whether the operation behavior for judging user is machine behavior, if judging for machine row Not handle these operation requests then.The prior art generally determines machine behavior by following two methods:
First method, IP address analysis method, IP address if they are the same have continuously transmitted multiple in a short period of time Specified operation requests (such as registration request), then it is assumed that user is likely to machine behavior for the operation behavior of webpage;It is above-mentioned First method mainly determines machine behavior according to the IP address of user, since quick-replaceable may be implemented in IP address, just The machine behavior of frequently replacement IP address cannot be accurately determined out, so that determining that the accuracy of machine behavior is lower.
Second method, operation information analysis method analyze the operation information in the specified operation requests of user, If specified operation requests are registration request, then the registration information in registration request is just operation information, if analysis obtains user Multiple specified operation requests in operation information between there are certain characteristic rules, then it is assumed that user be directed to webpage operation Behavior is likely to machine behavior.But since many Malwares can be realized the random generation of operation information, for example, user It generates the registration user name that Software Create is registered every time at random using user name, is not deposited between each registration user name of generation In apparent rule, then web page server can not just determine that whether the user's registers behavior as machine behavior, it is thus determined that The accuracy of machine behavior is also relatively low.
Therefore accuracy of the prior art when determining machine behavior is lower.
Summary of the invention
The purpose of the present invention is to provide a kind of machine behaviors to determine method, web browser and web page server, its energy The problem of effective solution background technique.
To achieve the above object, the invention provides the following technical scheme: specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input body Part information, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, certification Enter browsing Web Page Processing after qualification;
S2, input webpage obtain input information from web page server, and judge whether it is webpage mark according to input information Quasi- code name after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user Operation behavior information for the webpage includes mouse action information and keyboard operation information;By the operation behavior information of acquisition It is sent to web page server;Web page server determines the user for the webpage according to the operation behavior information received Machine behavior it is whether effective;And when judging that the machine behavior is effective, determine that the user is directed to the behaviour of the webpage Making behavior is machine behavior.
Further, judging the specific method of identity information in step sl is: user can be in the rule of identity identification webpage Determine input identity information in number and judge, when identity information judgement is more than the direct screen locking of stipulated number, prompt is waited 12 hours After continue.
Further, determine that the user is directed to the whether effective concrete mode of machine behavior of the webpage in step s 2 It is:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and carries out to the claim Accumulative superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, by one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and to the claim into The accumulative superposition of row is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
Further, the operation behavior information that user is directed to the webpage in step s 2 also includes fingerprint identification information, Specific step is as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and taps one to every The fingerprint that a keyboard identification goes out is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than When claim specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as Mouse taps behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
Further, web browser is when reaching stipulated time point, when upper stipulated time point to current regulations time point Between before the deadline, the operation behavior is sent to web page server by user.
The invention also discloses a kind of web browser characterized by comprising
First acquisition unit assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage Interior progress identity information input;
Receiving unit, for receive web page server transmission, determine the user be directed to the webpage operation behavior For the definitive result of machine behavior.
The invention also discloses a kind of web page server, it is characterised in that: specifically includes with lower module:
First acquisition unit assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage Interior progress identity information input;
Receiving unit, for receive web page server transmission, determine the user be directed to the webpage operation behavior For the definitive result of machine behavior;
Controller, the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will Final claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, for obtaining mouse The mouse signal pressed generates a claim 2 often to press next mouse, and final claim 2 is overlapped, finally with regulation Claim comparison, and comparing result is sent to receiving unit.
Further, the controller can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is human body and refer to Judging result is transmitted and received unit by line.
Compared with prior art, the beneficial effects of the present invention are: first carrying out authentication when webpage is opened, then pass through Real-time tracking is carried out to the operational circumstances of keyboard and mouse to judge whether webpage input is machine manual operation behavior, is finally mentioned The safety and accuracy of high webpage input.
Detailed description of the invention
Fig. 1 is the flow diagram that the machine behavior of one of the present embodiment 1 determines method;
Fig. 2 is that step S2 is determining whether the user is effective for the machine behavior of the webpage in the present embodiment 1 Flow diagram;
Fig. 3 is flow diagram of the step S2 in user for the operation behavior information of the webpage in the present embodiment 1;
Fig. 4 is the structural schematic diagram of one of the present embodiment 1 web browser;
Fig. 5 is the structural schematic diagram of one of the present embodiment 1 web page server.
In appended drawing reference: 1. first acquisition units;2. receiving unit;3. controller.
Specific embodiment
Present invention will be further explained below with reference to the attached drawings and examples.
Embodiment 1:
As shown in Figure 1, a kind of machine behavior provided in this embodiment determines method, specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input body Part information, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, certification Enter browsing Web Page Processing after qualification;
S2, input webpage obtain input information from web page server, and judge whether it is webpage mark according to input information Quasi- code name after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user Operation behavior information for the webpage includes mouse action information and keyboard operation information;By the operation behavior information of acquisition It is sent to web page server;Web page server determines the user for the webpage according to the operation behavior information received Machine behavior it is whether effective;And when judging that the machine behavior is effective, determine that the user is directed to the behaviour of the webpage Making behavior is machine behavior.
Further, judging the specific method of identity information in step sl is: user can be in the rule of identity identification webpage Determine input identity information in number and judge, when identity information judgement is more than the direct screen locking of stipulated number, prompt is waited 12 hours After continue.
As shown in Fig. 2, further, determining whether the user is effective for the machine behavior of the webpage in step s 2 Concrete mode be:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and carries out to the claim Accumulative superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, by one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and to the claim into The accumulative superposition of row is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
As shown in figure 3, the operation behavior information that user is directed to the webpage in step s 2 also includes fingerprint identification information, The specific steps of which are as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and taps one to every The fingerprint that a keyboard identification goes out is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than When claim specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as Mouse taps behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
Further, web browser is when reaching stipulated time point, when upper stipulated time point to current regulations time point Between before the deadline, the operation behavior is sent to web page server by user.
As shown in figure 4, the present embodiment also discloses a kind of web browser comprising:
First acquisition unit 1 assert webpage for before user accesses webpage, obtaining identity, and then the identity assert net Identity information input is carried out in page;
Receiving unit 2, for receive web page server transmission, determine the user be directed to the webpage operation behavior For the definitive result of machine behavior.
As shown in figure 5, the present embodiment also discloses a kind of web page server, specifically include with lower module:
First acquisition unit 1 assert webpage for before user accesses webpage, obtaining identity, and then the identity assert net Identity information input is carried out in page;
Receiving unit 2, for receive web page server transmission, determine the user be directed to the webpage operation behavior For the definitive result of machine behavior;
Controller 3, the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will Final claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, for obtaining mouse The mouse signal pressed generates a claim 2 often to press next mouse, and final claim 2 is overlapped, finally with regulation Claim comparison, and comparing result is sent to receiving unit.
Further, the controller 3 can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is human body and refer to Judging result is transmitted and received unit 2 by line.
Authentication is first carried out when webpage is opened in the present embodiment, then passes through the operational circumstances to keyboard and mouse Real-time tracking is carried out to judge whether webpage input is machine manual operation behavior, finally improves the safety and standard of webpage input True property.

Claims (8)

1. a kind of machine behavior determines method, which is characterized in that specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input identity letter Breath, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, approved qualified Enter browsing Web Page Processing afterwards;
S2, input webpage obtain input information from web page server, and judge whether it is web standards generation according to input information Number, after being confirmed as web standards code name, obtain the operation behavior information that the user is directed to the webpage;Wherein, user is directed to The operation behavior information of the webpage includes mouse action information and keyboard operation information;The operation behavior information of acquisition is sent To web page server;Web page server determines that the user is directed to the machine of the webpage according to the operation behavior information received Whether device behavior is effective;And when judging that the machine behavior is effective, determine that the user is directed to the operation row of the webpage For for machine behavior.
2. a kind of machine behavior according to claim 1 determines method, which is characterized in that judge that identity is believed in step sl The specific method of breath is: user can input identity information and be judged in the stipulated number that identity assert webpage, when identity is believed Breath judgement is more than the direct screen locking of stipulated number, prompts to continue after waiting 12 hours.
3. a kind of machine behavior according to claim 1 determines method, which is characterized in that determine the use in step s 2 Family is for the whether effective concrete mode of machine behavior of the webpage:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and adds up to the claim Superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, pass through one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and carries out to the claim tired Meter superposition is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
4. a kind of machine behavior according to claim 1 determines method, it is characterised in that: user is directed to institute in step s 2 The operation behavior information for stating webpage also includes fingerprint identification information, the specific steps of which are as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and to one key of every percussion The fingerprint that disk identifies is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than claim When specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as mouse Percussion behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
5. a kind of machine behavior according to claim 1 or 2 or 3 or 4 determines method, it is characterised in that: web browser When reaching stipulated time point, when upper stipulated time point is to before the deadline, user will between current regulations time point The operation behavior is sent to web page server.
6. a kind of web browser characterized by comprising
First acquisition unit (1) assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage Interior progress identity information input;
Receiving unit (2), for receive web page server transmission, determine the user and be for the operation behavior of the webpage The definitive result of machine behavior.
7. a kind of web page server, it is characterised in that: specifically include with lower module:
First acquisition unit (1) assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage Interior progress identity information input;
Receiving unit (2), for receive web page server transmission, determine the user and be for the operation behavior of the webpage The definitive result of machine behavior;
Controller (3), the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will most Whole claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, pressed for obtaining mouse Under mouse signal, generate a claim 2 often to press next mouse, and final claim 2 be overlapped, finally provide to weigh Item comparison, and comparing result is sent to receiving unit (2).
8. a kind of web page server according to claim 7, it is characterised in that: specifically include with lower module: the control Device (3) can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is somatic fingerprint, and judging result is transmitted and received Unit (2).
CN201810063286.6A 2018-01-23 2018-01-23 A kind of machine behavior determines method, web browser and web page server Pending CN110069910A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201810063286.6A CN110069910A (en) 2018-01-23 2018-01-23 A kind of machine behavior determines method, web browser and web page server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201810063286.6A CN110069910A (en) 2018-01-23 2018-01-23 A kind of machine behavior determines method, web browser and web page server

Publications (1)

Publication Number Publication Date
CN110069910A true CN110069910A (en) 2019-07-30

Family

ID=67365088

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201810063286.6A Pending CN110069910A (en) 2018-01-23 2018-01-23 A kind of machine behavior determines method, web browser and web page server

Country Status (1)

Country Link
CN (1) CN110069910A (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111641588A (en) * 2020-04-28 2020-09-08 深圳壹账通智能科技有限公司 Webpage analog input detection method and device, computer equipment and storage medium
CN112540904A (en) * 2020-12-15 2021-03-23 北京百度网讯科技有限公司 Machine operation behavior recognition method and device, electronic equipment and computer medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1305157A (en) * 2000-12-12 2001-07-25 林学优 Fingerprint computer
CN102737019A (en) * 2011-03-31 2012-10-17 阿里巴巴集团控股有限公司 Machine behavior determining method, webpage browser and webpage server
CN106155298A (en) * 2015-04-21 2016-11-23 阿里巴巴集团控股有限公司 Man-machine recognition methods and device, the acquisition method of behavior characteristics data and device
CN106650350A (en) * 2016-10-21 2017-05-10 中国银联股份有限公司 Identity authentication method and system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1305157A (en) * 2000-12-12 2001-07-25 林学优 Fingerprint computer
CN102737019A (en) * 2011-03-31 2012-10-17 阿里巴巴集团控股有限公司 Machine behavior determining method, webpage browser and webpage server
CN106155298A (en) * 2015-04-21 2016-11-23 阿里巴巴集团控股有限公司 Man-machine recognition methods and device, the acquisition method of behavior characteristics data and device
CN106650350A (en) * 2016-10-21 2017-05-10 中国银联股份有限公司 Identity authentication method and system

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111641588A (en) * 2020-04-28 2020-09-08 深圳壹账通智能科技有限公司 Webpage analog input detection method and device, computer equipment and storage medium
CN112540904A (en) * 2020-12-15 2021-03-23 北京百度网讯科技有限公司 Machine operation behavior recognition method and device, electronic equipment and computer medium
CN112540904B (en) * 2020-12-15 2023-06-23 北京百度网讯科技有限公司 Machine operation behavior recognition method, device, electronic equipment and computer medium

Similar Documents

Publication Publication Date Title
CN110399925B (en) Account risk identification method, device and storage medium
US10740411B2 (en) Determining repeat website users via browser uniqueness tracking
EP3353700B1 (en) Computer system for discovery of vulnerabilities in applications including guided tester paths based on application coverage measures
CN105930727A (en) Web-based crawler identification algorithm
CN111435507A (en) Advertisement anti-cheating method and device, electronic equipment and readable storage medium
US11087334B1 (en) Method and system for identifying potential fraud activity in a tax return preparation system, at least partially based on data entry characteristics of tax return content
CN108696490A (en) The recognition methods of account permission and device
Chu et al. Bot or human? A behavior-based online bot detection system
US20190066248A1 (en) Method and system for identifying potential fraud activity in a tax return preparation system to trigger an identity verification challenge through the tax return preparation system
US10333964B1 (en) Fake account identification
US10374934B2 (en) Method and program product for a private performance network with geographical load simulation
CN104852916A (en) Social engineering-based webpage verification code recognition method and system
CN109145544A (en) A kind of human-computer behavior detection system and method
Bakar et al. Adaptive authentication based on analysis of user behavior
CN110581841B (en) Back-end anti-crawler method
CN110069910A (en) A kind of machine behavior determines method, web browser and web page server
CN101170408A (en) Method and system for realizing agent certification based on identity authentication mode including random information
Wen et al. Detecting malicious websites in depth through analyzing topics and web-pages
RU2745362C1 (en) System and method of generating individual content for service user
Alotaibi et al. FingerID: A new security model based on fingerprint recognition for personal learning environments (PLEs)
CN109787940B (en) User data processing method and device based on robot customer service
Liu et al. Smooth Intervention Model of Individual Interactive Behavior.
Roden et al. Cry wolf: Toward an experimentation platform and dataset for human factors in cyber security analysis
Li et al. Phishing knowledge based user modelling in software design.
Demir et al. System for detection of network threats based on classifiers

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
WD01 Invention patent application deemed withdrawn after publication
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20190730