CN110069910A - A kind of machine behavior determines method, web browser and web page server - Google Patents
A kind of machine behavior determines method, web browser and web page server Download PDFInfo
- Publication number
- CN110069910A CN110069910A CN201810063286.6A CN201810063286A CN110069910A CN 110069910 A CN110069910 A CN 110069910A CN 201810063286 A CN201810063286 A CN 201810063286A CN 110069910 A CN110069910 A CN 110069910A
- Authority
- CN
- China
- Prior art keywords
- webpage
- behavior
- information
- user
- web page
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/958—Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/316—User authentication by observing the pattern of computer usage, e.g. typical user behaviour
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
Abstract
The present invention relates to a kind of machine behaviors to determine method, web browser and web page server, web browser carries out authentication before user accesses webpage, the identity information of input and public security system and the student system of major universities and colleges are subjected to networking certification identity, browsing Web Page Processing is entered after approved qualified;Webpage is inputted, input information is obtained from web page server, and web standards code name is judged whether it is according to input information, after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user includes mouse action information and keyboard operation information for the operation behavior information of the webpage;The operation behavior information of acquisition is sent to web page server;Web page server determines whether the user is effective for the machine behavior of the webpage according to the operation behavior information received;And when judging that the machine behavior is effective, the operation behavior for determining that the user is directed to the webpage is machine behavior.
Description
Technical field
The present invention relates to a kind of technical fields of internet information processing, more particularly to a kind of machine behavior determination side
Method, web browser and web page server.
Background technique
With the continuous development of Internet technology, more and more information resources select network as the carrier propagated, and use
Family can access the information in each webpage by web browser.But in the prior art, certain user is in order to obtain website
Integral, or for the releasing advertisements in website or fallacious message, the operation of software program models people, Lai Jinhang may be used
The operations such as malicious registration, malice are logged in, maliciously posted, malice is replied, for example, after user starts malicious registration software program, it should
Software program can simulate the operation of people, and the registration information generated at random is inputted in the webpage of user's registration, then click registration,
Wherein, the operation behavior as caused by the operation of software program models people is referred to as machine behavior.If web page server is not
Whether the operation behavior that can identify user for webpage is machine behavior, then web page server will generate machine behavior each
Kind operation requests (registration request, logging request, request of posting, reply request etc.) carry out respective handling, this just consumes webpage
The more process resource of server, reduces the treatment effeciency of web page server, in addition, can also generate in web page server a large amount of
Malicious act data, occupy the more storage resource of web page server.
In view of the above-mentioned problems, the prior art proposes that (registration request, login are asked in the certain operation requests for receiving user
Ask, request of posting, reply request etc.) after, whether the operation behavior for judging user is machine behavior, if judging for machine row
Not handle these operation requests then.The prior art generally determines machine behavior by following two methods:
First method, IP address analysis method, IP address if they are the same have continuously transmitted multiple in a short period of time
Specified operation requests (such as registration request), then it is assumed that user is likely to machine behavior for the operation behavior of webpage;It is above-mentioned
First method mainly determines machine behavior according to the IP address of user, since quick-replaceable may be implemented in IP address, just
The machine behavior of frequently replacement IP address cannot be accurately determined out, so that determining that the accuracy of machine behavior is lower.
Second method, operation information analysis method analyze the operation information in the specified operation requests of user,
If specified operation requests are registration request, then the registration information in registration request is just operation information, if analysis obtains user
Multiple specified operation requests in operation information between there are certain characteristic rules, then it is assumed that user be directed to webpage operation
Behavior is likely to machine behavior.But since many Malwares can be realized the random generation of operation information, for example, user
It generates the registration user name that Software Create is registered every time at random using user name, is not deposited between each registration user name of generation
In apparent rule, then web page server can not just determine that whether the user's registers behavior as machine behavior, it is thus determined that
The accuracy of machine behavior is also relatively low.
Therefore accuracy of the prior art when determining machine behavior is lower.
Summary of the invention
The purpose of the present invention is to provide a kind of machine behaviors to determine method, web browser and web page server, its energy
The problem of effective solution background technique.
To achieve the above object, the invention provides the following technical scheme: specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input body
Part information, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, certification
Enter browsing Web Page Processing after qualification;
S2, input webpage obtain input information from web page server, and judge whether it is webpage mark according to input information
Quasi- code name after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user
Operation behavior information for the webpage includes mouse action information and keyboard operation information;By the operation behavior information of acquisition
It is sent to web page server;Web page server determines the user for the webpage according to the operation behavior information received
Machine behavior it is whether effective;And when judging that the machine behavior is effective, determine that the user is directed to the behaviour of the webpage
Making behavior is machine behavior.
Further, judging the specific method of identity information in step sl is: user can be in the rule of identity identification webpage
Determine input identity information in number and judge, when identity information judgement is more than the direct screen locking of stipulated number, prompt is waited 12 hours
After continue.
Further, determine that the user is directed to the whether effective concrete mode of machine behavior of the webpage in step s 2
It is:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and carries out to the claim
Accumulative superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, by one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and to the claim into
The accumulative superposition of row is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
Further, the operation behavior information that user is directed to the webpage in step s 2 also includes fingerprint identification information,
Specific step is as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and taps one to every
The fingerprint that a keyboard identification goes out is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than
When claim specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as
Mouse taps behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
Further, web browser is when reaching stipulated time point, when upper stipulated time point to current regulations time point
Between before the deadline, the operation behavior is sent to web page server by user.
The invention also discloses a kind of web browser characterized by comprising
First acquisition unit assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage
Interior progress identity information input;
Receiving unit, for receive web page server transmission, determine the user be directed to the webpage operation behavior
For the definitive result of machine behavior.
The invention also discloses a kind of web page server, it is characterised in that: specifically includes with lower module:
First acquisition unit assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage
Interior progress identity information input;
Receiving unit, for receive web page server transmission, determine the user be directed to the webpage operation behavior
For the definitive result of machine behavior;
Controller, the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will
Final claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, for obtaining mouse
The mouse signal pressed generates a claim 2 often to press next mouse, and final claim 2 is overlapped, finally with regulation
Claim comparison, and comparing result is sent to receiving unit.
Further, the controller can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is human body and refer to
Judging result is transmitted and received unit by line.
Compared with prior art, the beneficial effects of the present invention are: first carrying out authentication when webpage is opened, then pass through
Real-time tracking is carried out to the operational circumstances of keyboard and mouse to judge whether webpage input is machine manual operation behavior, is finally mentioned
The safety and accuracy of high webpage input.
Detailed description of the invention
Fig. 1 is the flow diagram that the machine behavior of one of the present embodiment 1 determines method;
Fig. 2 is that step S2 is determining whether the user is effective for the machine behavior of the webpage in the present embodiment 1
Flow diagram;
Fig. 3 is flow diagram of the step S2 in user for the operation behavior information of the webpage in the present embodiment 1;
Fig. 4 is the structural schematic diagram of one of the present embodiment 1 web browser;
Fig. 5 is the structural schematic diagram of one of the present embodiment 1 web page server.
In appended drawing reference: 1. first acquisition units;2. receiving unit;3. controller.
Specific embodiment
Present invention will be further explained below with reference to the attached drawings and examples.
Embodiment 1:
As shown in Figure 1, a kind of machine behavior provided in this embodiment determines method, specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input body
Part information, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, certification
Enter browsing Web Page Processing after qualification;
S2, input webpage obtain input information from web page server, and judge whether it is webpage mark according to input information
Quasi- code name after being confirmed as web standards code name, obtains the operation behavior information that the user is directed to the webpage;Wherein, user
Operation behavior information for the webpage includes mouse action information and keyboard operation information;By the operation behavior information of acquisition
It is sent to web page server;Web page server determines the user for the webpage according to the operation behavior information received
Machine behavior it is whether effective;And when judging that the machine behavior is effective, determine that the user is directed to the behaviour of the webpage
Making behavior is machine behavior.
Further, judging the specific method of identity information in step sl is: user can be in the rule of identity identification webpage
Determine input identity information in number and judge, when identity information judgement is more than the direct screen locking of stipulated number, prompt is waited 12 hours
After continue.
As shown in Fig. 2, further, determining whether the user is effective for the machine behavior of the webpage in step s 2
Concrete mode be:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and carries out to the claim
Accumulative superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, by one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and to the claim into
The accumulative superposition of row is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
As shown in figure 3, the operation behavior information that user is directed to the webpage in step s 2 also includes fingerprint identification information,
The specific steps of which are as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and taps one to every
The fingerprint that a keyboard identification goes out is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than
When claim specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as
Mouse taps behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
Further, web browser is when reaching stipulated time point, when upper stipulated time point to current regulations time point
Between before the deadline, the operation behavior is sent to web page server by user.
As shown in figure 4, the present embodiment also discloses a kind of web browser comprising:
First acquisition unit 1 assert webpage for before user accesses webpage, obtaining identity, and then the identity assert net
Identity information input is carried out in page;
Receiving unit 2, for receive web page server transmission, determine the user be directed to the webpage operation behavior
For the definitive result of machine behavior.
As shown in figure 5, the present embodiment also discloses a kind of web page server, specifically include with lower module:
First acquisition unit 1 assert webpage for before user accesses webpage, obtaining identity, and then the identity assert net
Identity information input is carried out in page;
Receiving unit 2, for receive web page server transmission, determine the user be directed to the webpage operation behavior
For the definitive result of machine behavior;
Controller 3, the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will
Final claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, for obtaining mouse
The mouse signal pressed generates a claim 2 often to press next mouse, and final claim 2 is overlapped, finally with regulation
Claim comparison, and comparing result is sent to receiving unit.
Further, the controller 3 can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is human body and refer to
Judging result is transmitted and received unit 2 by line.
Authentication is first carried out when webpage is opened in the present embodiment, then passes through the operational circumstances to keyboard and mouse
Real-time tracking is carried out to judge whether webpage input is machine manual operation behavior, finally improves the safety and standard of webpage input
True property.
Claims (8)
1. a kind of machine behavior determines method, which is characterized in that specifically includes the following steps:
S1, web browser first carry out authentication before user accesses webpage, jump out identity and assert webpage, input identity letter
Breath, the identity information and the student system of public security system and major universities and colleges are networked, and carry out authentication, approved qualified
Enter browsing Web Page Processing afterwards;
S2, input webpage obtain input information from web page server, and judge whether it is web standards generation according to input information
Number, after being confirmed as web standards code name, obtain the operation behavior information that the user is directed to the webpage;Wherein, user is directed to
The operation behavior information of the webpage includes mouse action information and keyboard operation information;The operation behavior information of acquisition is sent
To web page server;Web page server determines that the user is directed to the machine of the webpage according to the operation behavior information received
Whether device behavior is effective;And when judging that the machine behavior is effective, determine that the user is directed to the operation row of the webpage
For for machine behavior.
2. a kind of machine behavior according to claim 1 determines method, which is characterized in that judge that identity is believed in step sl
The specific method of breath is: user can input identity information and be judged in the stipulated number that identity assert webpage, when identity is believed
Breath judgement is more than the direct screen locking of stipulated number, prompts to continue after waiting 12 hours.
3. a kind of machine behavior according to claim 1 determines method, which is characterized in that determine the use in step s 2
Family is for the whether effective concrete mode of machine behavior of the webpage:
S21, pass through one keyboard of every percussion, keyboard internal controller obtains a claim 1 automatically, and adds up to the claim
Superposition is judged as that keyboard taps behavior when the superimposed number of claim is greater than claim specified value;
S22, pass through one mouse button of every click, mouse internal controller obtains a claim 2 automatically, and carries out to the claim tired
Meter superposition is judged as that mouse taps behavior when the superimposed number of claim is greater than claim specified value;
S23, after all meeting the requirements the step of step S21 and S22, be determined as the operation behavior to the webpage.
4. a kind of machine behavior according to claim 1 determines method, it is characterised in that: user is directed to institute in step s 2
The operation behavior information for stating webpage also includes fingerprint identification information, the specific steps of which are as follows:
S211, pass through one keyboard of every percussion, the Fingerprint Identification Unit identification on keyboard is somatic fingerprint, and to one key of every percussion
The fingerprint that disk identifies is determined claim 1, and carries out accumulative superposition to the claim, when the superimposed number of claim is greater than claim
When specified value, it is judged as that keyboard taps behavior;
S212, by one mouse button of every clicks, the Fingerprint Identification Unit on mouse button identifies after being somatic fingerprint, is judged as mouse
Percussion behavior;
S213, after all meeting the requirements the step of step S211 and S212, be determined as the operation behavior to the webpage.
5. a kind of machine behavior according to claim 1 or 2 or 3 or 4 determines method, it is characterised in that: web browser
When reaching stipulated time point, when upper stipulated time point is to before the deadline, user will between current regulations time point
The operation behavior is sent to web page server.
6. a kind of web browser characterized by comprising
First acquisition unit (1) assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage
Interior progress identity information input;
Receiving unit (2), for receive web page server transmission, determine the user and be for the operation behavior of the webpage
The definitive result of machine behavior.
7. a kind of web page server, it is characterised in that: specifically include with lower module:
First acquisition unit (1) assert webpage for before user accesses webpage, obtaining identity, and then the identity assert webpage
Interior progress identity information input;
Receiving unit (2), for receive web page server transmission, determine the user and be for the operation behavior of the webpage
The definitive result of machine behavior;
Controller (3), the keyboard signal pressed for obtaining keyboard generate a claim 1 often to press a key disk, and will most
Whole claim 1 is overlapped, and finally to provide that claim compares, and comparing result is sent to receiving unit, pressed for obtaining mouse
Under mouse signal, generate a claim 2 often to press next mouse, and final claim 2 be overlapped, finally provide to weigh
Item comparison, and comparing result is sent to receiving unit (2).
8. a kind of web page server according to claim 7, it is characterised in that: specifically include with lower module: the control
Device (3) can obtain the fingerprint signal on finger keyboard and mouse, and judge whether it is somatic fingerprint, and judging result is transmitted and received
Unit (2).
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810063286.6A CN110069910A (en) | 2018-01-23 | 2018-01-23 | A kind of machine behavior determines method, web browser and web page server |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810063286.6A CN110069910A (en) | 2018-01-23 | 2018-01-23 | A kind of machine behavior determines method, web browser and web page server |
Publications (1)
Publication Number | Publication Date |
---|---|
CN110069910A true CN110069910A (en) | 2019-07-30 |
Family
ID=67365088
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810063286.6A Pending CN110069910A (en) | 2018-01-23 | 2018-01-23 | A kind of machine behavior determines method, web browser and web page server |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN110069910A (en) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111641588A (en) * | 2020-04-28 | 2020-09-08 | 深圳壹账通智能科技有限公司 | Webpage analog input detection method and device, computer equipment and storage medium |
CN112540904A (en) * | 2020-12-15 | 2021-03-23 | 北京百度网讯科技有限公司 | Machine operation behavior recognition method and device, electronic equipment and computer medium |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1305157A (en) * | 2000-12-12 | 2001-07-25 | 林学优 | Fingerprint computer |
CN102737019A (en) * | 2011-03-31 | 2012-10-17 | 阿里巴巴集团控股有限公司 | Machine behavior determining method, webpage browser and webpage server |
CN106155298A (en) * | 2015-04-21 | 2016-11-23 | 阿里巴巴集团控股有限公司 | Man-machine recognition methods and device, the acquisition method of behavior characteristics data and device |
CN106650350A (en) * | 2016-10-21 | 2017-05-10 | 中国银联股份有限公司 | Identity authentication method and system |
-
2018
- 2018-01-23 CN CN201810063286.6A patent/CN110069910A/en active Pending
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1305157A (en) * | 2000-12-12 | 2001-07-25 | 林学优 | Fingerprint computer |
CN102737019A (en) * | 2011-03-31 | 2012-10-17 | 阿里巴巴集团控股有限公司 | Machine behavior determining method, webpage browser and webpage server |
CN106155298A (en) * | 2015-04-21 | 2016-11-23 | 阿里巴巴集团控股有限公司 | Man-machine recognition methods and device, the acquisition method of behavior characteristics data and device |
CN106650350A (en) * | 2016-10-21 | 2017-05-10 | 中国银联股份有限公司 | Identity authentication method and system |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111641588A (en) * | 2020-04-28 | 2020-09-08 | 深圳壹账通智能科技有限公司 | Webpage analog input detection method and device, computer equipment and storage medium |
CN112540904A (en) * | 2020-12-15 | 2021-03-23 | 北京百度网讯科技有限公司 | Machine operation behavior recognition method and device, electronic equipment and computer medium |
CN112540904B (en) * | 2020-12-15 | 2023-06-23 | 北京百度网讯科技有限公司 | Machine operation behavior recognition method, device, electronic equipment and computer medium |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN110399925B (en) | Account risk identification method, device and storage medium | |
US10740411B2 (en) | Determining repeat website users via browser uniqueness tracking | |
EP3353700B1 (en) | Computer system for discovery of vulnerabilities in applications including guided tester paths based on application coverage measures | |
CN105930727A (en) | Web-based crawler identification algorithm | |
CN111435507A (en) | Advertisement anti-cheating method and device, electronic equipment and readable storage medium | |
US11087334B1 (en) | Method and system for identifying potential fraud activity in a tax return preparation system, at least partially based on data entry characteristics of tax return content | |
CN108696490A (en) | The recognition methods of account permission and device | |
Chu et al. | Bot or human? A behavior-based online bot detection system | |
US20190066248A1 (en) | Method and system for identifying potential fraud activity in a tax return preparation system to trigger an identity verification challenge through the tax return preparation system | |
US10333964B1 (en) | Fake account identification | |
US10374934B2 (en) | Method and program product for a private performance network with geographical load simulation | |
CN104852916A (en) | Social engineering-based webpage verification code recognition method and system | |
CN109145544A (en) | A kind of human-computer behavior detection system and method | |
Bakar et al. | Adaptive authentication based on analysis of user behavior | |
CN110581841B (en) | Back-end anti-crawler method | |
CN110069910A (en) | A kind of machine behavior determines method, web browser and web page server | |
CN101170408A (en) | Method and system for realizing agent certification based on identity authentication mode including random information | |
Wen et al. | Detecting malicious websites in depth through analyzing topics and web-pages | |
RU2745362C1 (en) | System and method of generating individual content for service user | |
Alotaibi et al. | FingerID: A new security model based on fingerprint recognition for personal learning environments (PLEs) | |
CN109787940B (en) | User data processing method and device based on robot customer service | |
Liu et al. | Smooth Intervention Model of Individual Interactive Behavior. | |
Roden et al. | Cry wolf: Toward an experimentation platform and dataset for human factors in cyber security analysis | |
Li et al. | Phishing knowledge based user modelling in software design. | |
Demir et al. | System for detection of network threats based on classifiers |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
WD01 | Invention patent application deemed withdrawn after publication | ||
WD01 | Invention patent application deemed withdrawn after publication |
Application publication date: 20190730 |