CN110247825B - Information shielding method and device - Google Patents

Information shielding method and device Download PDF

Info

Publication number
CN110247825B
CN110247825B CN201910599926.XA CN201910599926A CN110247825B CN 110247825 B CN110247825 B CN 110247825B CN 201910599926 A CN201910599926 A CN 201910599926A CN 110247825 B CN110247825 B CN 110247825B
Authority
CN
China
Prior art keywords
information
user
module
shielded
historical behavior
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201910599926.XA
Other languages
Chinese (zh)
Other versions
CN110247825A (en
Inventor
袁晓静
翟京卿
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China United Network Communications Group Co Ltd
Original Assignee
China United Network Communications Group Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China United Network Communications Group Co Ltd filed Critical China United Network Communications Group Co Ltd
Priority to CN201910599926.XA priority Critical patent/CN110247825B/en
Publication of CN110247825A publication Critical patent/CN110247825A/en
Application granted granted Critical
Publication of CN110247825B publication Critical patent/CN110247825B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/02Capturing of monitoring data
    • H04L43/028Capturing of monitoring data by filtering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/18Protocol analysers

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

The invention provides an information shielding method and device, wherein a first message and a second message carried in a data message sent by a service server are acquired by monitoring the data message, a third message is acquired according to the first message, whether the second message comprises information to be shielded is judged according to the third message, if yes, the information to be shielded is filtered from the data message, and the filtered data message is sent to a user terminal corresponding to the first message; by using the scheme of the invention, the information to be shielded aiming at the user in the internet service can be automatically selected and filtered according to the third information, thereby avoiding the influence of bad information or uninteresting information on the normal use of the internet service by the user and improving the user experience.

Description

Information shielding method and device
Technical Field
The invention relates to the technical field of communication, in particular to an information shielding method and device.
Background
The intelligent home gateway is the core of intelligent home service, has two functions of an intelligent home control hub and a wireless router, and is connected to a service network or the Internet through a broadband access and bearer network. Various home network terminals realize device interconnection through an intelligent home gateway, access a broadband IP (Internet Protocol Address) network through the home gateway, and cooperate with a service platform on the broadband IP network or other various terminals to further provide wider home network service capability for users.
DPI (Deep Packet Inspection ) refers to an application layer traffic Inspection and control technology based on data packets, which performs Deep Inspection and analysis on different layers of information of the data packets to obtain application layer information of the entire data stream or data packets, and then performs statistical analysis and control on traffic according to a policy defined by a system.
With the rapid development of network technology and internet applications, people passively receive various advertisement pages or video propaganda and promotion information while browsing or using the network or the application, and in most cases, the advertisements received by people are uninteresting and cannot be closed immediately.
Disclosure of Invention
Aiming at the defects in the prior art, the invention provides an information shielding method and an information shielding device, which are used for solving the problem that advertisement information and bad information influence the normal use of internet services.
In order to solve the technical problems, the invention adopts the following technical scheme:
the invention provides an information shielding method, which comprises the following steps:
when a data message sent by a service server is received, acquiring first information and second information from the data message, wherein the first information is user identity information;
acquiring third information according to the first information;
judging whether the second information comprises information to be shielded or not according to the third information, and if so, filtering the information to be shielded from the data message;
and sending the filtered data message to a user terminal corresponding to the first information.
Preferably, the third information comprises user characteristics and historical behavior characteristics;
the determining, according to the third information, whether the second information includes information to be shielded specifically includes:
and judging whether the second information comprises information which is not in accordance with the user characteristics and/or information which is not in accordance with the historical behavior characteristics, if so, the second information comprises information to be shielded, and the information to be shielded is the information which is not in accordance with the user characteristics and/or the information which is not in accordance with the historical behavior characteristics.
Preferably, the user characteristics include one or any combination of the following: gender, age, occupation, hobby.
Further, the information shielding method further includes:
acquiring user internet behavior data;
determining the historical behavior characteristics of the user according to the user internet behavior data;
and sending the user characteristics and the historical behavior characteristics of the user to the intelligent gateway management server according to a preset configuration strategy, so that the intelligent gateway management server stores the corresponding user characteristics and the historical behavior characteristics in a preset database according to the user identity information.
Preferably, the configuration policy is issued by the deep packet inspection operation server.
The present invention also provides an intelligent gateway device, comprising:
the device comprises a first receiving module, a first obtaining module, a second obtaining module, a judging module, a filtering module and a first sending module;
the first obtaining module is used for obtaining first information and second information from a data message sent by a service server when the first receiving module receives the data message, wherein the first information is user identity information;
the second obtaining module is used for obtaining third information according to the first information;
the judging module is used for judging whether the second information comprises information to be shielded or not according to the third information;
the filtering module is used for filtering the information to be shielded from the data message when the second information comprises the information to be shielded;
and the first sending module is used for sending the filtered data message to the user terminal corresponding to the first information.
Preferably, the third information comprises user characteristics and historical behavior characteristics;
the judging module is specifically configured to judge whether the second information includes information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics, and if so, the second information includes information to be shielded, where the information to be shielded is information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics.
Preferably, the user characteristics include one or any combination of the following: gender, age, occupation, hobby.
Furthermore, the intelligent gateway device further comprises a third obtaining module, a processing module and a second sending module;
the third acquisition module is used for acquiring the internet surfing behavior data of the user;
the processing module is used for determining the historical behavior characteristics of the user according to the user internet behavior data;
the sending module is used for sending the user characteristics and the historical behavior characteristics of the user to the intelligent gateway management server according to a preset configuration strategy, so that the intelligent gateway management server stores the corresponding user characteristics and the historical behavior characteristics in a preset database according to the user identity information.
Furthermore, the intelligent gateway device further includes a second receiving module, where the second receiving module is configured to receive the configuration policy issued by the deep packet inspection operation server.
The method comprises the steps of monitoring a data message sent by a service server, acquiring first information and second information carried in the data message, acquiring third information according to the first information, judging whether the second information comprises information to be shielded or not according to the third information, filtering the information to be shielded from the data message if the information to be shielded is included, and sending the filtered data message to a user terminal corresponding to the first information; by using the scheme of the invention, the information to be shielded aiming at the user in the internet service can be automatically selected and filtered according to the third information, thereby avoiding the influence of bad information or uninteresting information on the normal use of the internet service by the user and improving the user experience.
Drawings
FIG. 1 is a system architecture diagram of an embodiment of the present invention;
FIG. 2 is a flow chart of information masking provided by an embodiment of the present invention;
fig. 3 is a flowchart of reporting third information according to an embodiment of the present invention;
fig. 4 is a schematic structural diagram of an intelligent gateway device according to an embodiment of the present invention;
fig. 5 is a second schematic structural diagram of an intelligent gateway device according to an embodiment of the present invention.
Detailed Description
The technical solution of the present invention will be described clearly and completely with reference to the accompanying drawings, and it should be understood that the described embodiments are a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments, which can be obtained by a person skilled in the art without any inventive step based on the embodiments of the present invention, are within the scope of the present invention.
The embodiment of the invention provides a communication number preprocessing method, which is applied to a system shown in figure 1, and the system comprises the following steps: the system comprises intelligent gateway equipment, a DPI operation server, a service server, an intelligent gateway management server and a user terminal.
The intelligent gateway is provided with a DPI plug-in, the DPI plug-in can collect user data flowing through the intelligent gateway according to a service strategy and upload the user data to the intelligent gateway management server for analysis, and data exchange is carried out between the DPI plug-in and the intelligent gateway management server through a consistent approved data mode. The DPI plug-in divides the data message into a plurality of application flows according to the quintuple and detects the specific data message in the application flows through the identification technology, thereby determining the application or user action corresponding to the application flows.
The intelligent gateway can be a home gateway and can be connected to a service network or the Internet through a broadband access and bearer network. Meanwhile, the intelligent home gateway is connected to a home network remote management server and a network element management server through a bearing network and managed by the remote management server and the network element management server, so that the remote management function of the intelligent home gateway user is realized.
The DPI operation server is responsible for managing and controlling the service policy, for example, making a policy, and issuing policy configuration information to a DPI plug-in of the intelligent gateway.
The intelligent gateway management server stores service characteristic parameters, the service characteristic parameters of various services are stored in a characteristic database to provide identification of specific services for the intelligent gateway, and the characteristic database needs to be updated and maintained regularly.
The user terminal is bound with the intelligent gateway, can locally or remotely control the intelligent gateway, and can receive information sent by the intelligent gateway.
The information masking flow provided by the embodiment of the present invention is described in detail below with reference to fig. 2. It should be noted that, before executing the information shielding process, the user terminal accesses the network through the intelligent gateway to implement data interaction with the service server. As shown in fig. 2, the process includes the following steps:
and step 11, when receiving a data message sent by the service server, acquiring the first information and the second information from the data message.
Specifically, the intelligent gateway monitors data messages flowing through the network in real time, where the data messages include data messages sent by a user terminal and data messages sent by a service server. When the intelligent gateway receives a data message sent by the service server, the first information and the second information are obtained from the data message. The first information is user identity information, and preferably, the first information may be a user identifier.
And step 12, acquiring third information according to the first information.
And the intelligent gateway acquires the third information from the intelligent gateway management server. Specifically, the intelligent gateway sends a third information query request to the intelligent gateway management server, where the third information query request carries the first information. And after receiving the third information query request, the intelligent gateway management server queries corresponding third information according to the first information in a preset database, and sends the third information to the intelligent gateway. It should be noted that the third information in the preset database is stored by using the first information as an index, that is, the database records the corresponding relationship between the first information and the third information, so that the corresponding third information can be queried based on the first information.
And step 13, judging whether the second information comprises information to be shielded or not according to the third information, if so, executing step 14, and otherwise, executing step 16.
Preferably, the third information includes user characteristics and historical behavior characteristics, the user characteristics refer to characteristics for describing attributes of the user, such as gender, age, occupation, hobbies and the like, and the historical behavior characteristics refer to historical internet behavior characteristics of the user, which may include recent internet business and demand and the like.
Specifically, the intelligent gateway determines whether the second information includes information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics, and if the second information includes information to be masked, the information to be masked is filtered from the data packet (i.e., step 14 is executed). The information to be shielded is information which is not in accordance with the characteristics of the user and/or information which is not in accordance with the characteristics of the historical behavior, for example, when the user is a child, advertisements or information which is not suitable for the child can be automatically shielded, the DPI plug-in can identify the advertisement information, and key fields, types, duration and the like of the advertisement information are extracted.
If the second information does not include information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics, which indicates that the data message sent by the service server does not include information to be masked, the data message is directly forwarded (i.e., step 16 is executed).
Step 14, filtering the information to be masked from the data message.
Specifically, the intelligent gateway deletes the information to be shielded in the second information to obtain fourth information, and generates a new data packet (i.e., a filtered data packet) according to the fourth information.
And step 15, sending the filtered data message to the user terminal corresponding to the first information.
And step 16, sending the data message to the user terminal corresponding to the first information.
As can be seen from the foregoing steps 11-16, the present invention obtains the first information and the second information carried in the data message sent by the service server by monitoring the data message, obtains the third information according to the first information, and judges whether the second information includes the information to be shielded according to the third information, if so, filters the information to be shielded from the data message, and sends the filtered data message to the user terminal corresponding to the first information; by using the scheme of the invention, the information to be shielded aiming at the user in the internet service can be automatically selected and filtered according to the third information, thereby avoiding the influence of bad information or uninteresting information on the normal use of the internet service by the user and improving the user experience.
In the embodiment of the invention, the intelligent gateway can also detect and analyze the internet surfing behavior of the user in real time. Therefore, as shown in fig. 3, the information shielding method further includes the steps of:
and step 31, the intelligent gateway acquires the user internet behavior data.
And step 32, the intelligent gateway determines the historical behavior characteristics of the user according to the user internet behavior data.
Specifically, the data packet sent by the user terminal reaches the intelligent gateway, and is subjected to deep packet inspection processing before being forwarded by the intelligent gateway, so as to obtain the user internet behavior analysis information. The deep packet inspection analysis supports identification of access gateway terminal equipment, classification of internet access behaviors and corresponding behavior records (such as use frequency, duration, Quality of Service (QoS) control, terminals, applications, users and the like), and accordingly determines historical behavior characteristics of the users. The deep packet inspection can analyze and count the URL when the intelligent gateway or the off-hook user terminal uses http protocol communication, and the URL includes a terminal IP address, a terminal MAC address, a URL classification ID, URL information, the number of times of URL occurrence in the reporting period and the like, and the information is mainly used for user behavior statistics.
It should be noted that the user characteristics of the user may be set by the user before the intelligent gateway is used.
And step 33, the intelligent gateway sends the user characteristics and the historical behavior characteristics of the user to the intelligent gateway management server according to a preset configuration strategy.
The configuration strategy can be formulated by the DPI operation server and issued to the intelligent gateway, and the DPI operation server can manage a plurality of configuration strategies to implement different deep packet analysis on different intelligent gateways.
And step 34, the intelligent gateway management server stores the corresponding user characteristics and the historical behavior characteristics in a preset database according to the user identity information.
The intelligent gateway management server sends the user identity information and the corresponding user characteristics and historical behavior characteristics to a preset database, so that the database takes the user identity information (namely user identification) as an index, and establishes a mapping relation between the user identity information and third information (namely the user characteristics and the historical behavior characteristics) so as to query the third information.
Based on the same technical concept, an embodiment of the present invention further provides an intelligent gateway device, as shown in fig. 4, where the intelligent gateway device may include: the service server comprises a first receiving module 41, a first obtaining module 42, a second obtaining module 43, a judging module 44, a filtering module 45 and a first sending module 46, wherein the first obtaining module 42 is configured to, when the first receiving module 41 receives a data message sent by a service server, obtain first information and second information from the data message, and the first information is user identity information;
the second obtaining module 43 is configured to obtain third information according to the first information.
The judging module 44 is configured to judge whether the second information includes information to be shielded according to the third information.
The filtering module 45 is configured to, when the second information includes information to be masked, filter the information to be masked from the data packet.
The first sending module 46 is configured to send the filtered data message to the user terminal corresponding to the first information.
Preferably, the third information includes a user characteristic and a historical behavior characteristic.
The determining module 44 is specifically configured to determine whether the second information includes information that does not conform to the user characteristic and/or information that does not conform to the historical behavior characteristic, and if so, include information to be shielded in the second information, where the information to be shielded is information that does not conform to the user characteristic and/or information that does not conform to the historical behavior characteristic.
Preferably, the user characteristics include one or any combination of the following: gender, age, occupation, hobby.
Further, as shown in fig. 5, the intelligent gateway device further includes a third obtaining module 47, a processing module 48, and a second sending module 49.
The third obtaining module 47 is configured to obtain internet behavior data of the user.
The processing module 48 is configured to determine the historical behavior characteristics of the user according to the user internet behavior data.
The sending module 49 is configured to send the user characteristic and the historical behavior characteristic of the user to the intelligent gateway management server according to a preset configuration policy, so that the intelligent gateway management server stores the corresponding user characteristic and the historical behavior characteristic in a preset database according to the user identity information.
Further, the intelligent gateway device further includes a second receiving module 40, where the second receiving module 40 is configured to receive the configuration policy issued by the deep packet inspection operation server.
It will be understood that the above embodiments are merely exemplary embodiments taken to illustrate the principles of the present invention, which is not limited thereto. It will be apparent to those skilled in the art that various modifications and improvements can be made without departing from the spirit and substance of the invention, and these modifications and improvements are also considered to be within the scope of the invention.

Claims (6)

1. An information masking method, characterized in that the method comprises:
when a data message sent by a service server is received, acquiring first information and second information from the data message, wherein the first information is user identity information;
acquiring third information according to the first information;
judging whether the second information comprises information to be shielded or not according to the third information, and if so, filtering the information to be shielded from the data message;
sending the filtered data message to a user terminal corresponding to the first information;
the third information comprises user characteristics and historical behavior characteristics;
the determining, according to the third information, whether the second information includes information to be shielded specifically includes:
judging whether the second information comprises information which is not in accordance with the user characteristics and/or information which is not in accordance with the historical behavior characteristics, if so, the second information comprises information to be shielded, and the information to be shielded is the information which is not in accordance with the user characteristics and/or the information which is not in accordance with the historical behavior characteristics;
acquiring user internet behavior data;
determining the historical behavior characteristics of the user according to the user internet behavior data;
according to a preset configuration strategy, sending the user characteristics and the historical behavior characteristics of the user to an intelligent gateway management server, so that the intelligent gateway management server stores the corresponding user characteristics and the historical behavior characteristics in a preset database according to the user identity information;
the configuration strategy is used for implementing different deep packet analysis on different intelligent gateways.
2. The method of claim 1, wherein the user characteristics comprise one or any combination of: gender, age, occupation, hobby.
3. The method of claim 1, wherein the configuration policy is issued by a deep packet inspection service server.
4. An intelligent gateway device, comprising: the device comprises a first receiving module, a first obtaining module, a second obtaining module, a judging module, a filtering module and a first sending module;
the first obtaining module is used for obtaining first information and second information from a data message sent by a service server when the first receiving module receives the data message, wherein the first information is user identity information;
the second obtaining module is used for obtaining third information according to the first information;
the judging module is used for judging whether the second information comprises information to be shielded or not according to the third information;
the filtering module is used for filtering the information to be shielded from the data message when the second information comprises the information to be shielded;
the first sending module is used for sending the filtered data message to the user terminal corresponding to the first information;
the third information comprises user characteristics and historical behavior characteristics;
the judging module is specifically configured to judge whether the second information includes information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics, and if so, the second information includes information to be shielded, where the information to be shielded is information that does not conform to the user characteristics and/or information that does not conform to the historical behavior characteristics;
the system also comprises a third acquisition module, a processing module and a second sending module;
the third acquisition module is used for acquiring the internet surfing behavior data of the user;
the processing module is used for determining the historical behavior characteristics of the user according to the user internet behavior data;
the sending module is used for sending the user characteristics and the historical behavior characteristics of the user to the intelligent gateway management server according to a preset configuration strategy so that the intelligent gateway management server stores the corresponding user characteristics and the historical behavior characteristics in a preset database according to the user identity information;
the configuration strategy is used for implementing different deep packet analysis on different intelligent gateways.
5. The intelligent gateway device of claim 4, wherein the user characteristics comprise one or any combination of: gender, age, occupation, hobby.
6. The intelligent gateway device of claim 4, further comprising a second receiving module, where the second receiving module is configured to receive the configuration policy sent by the deep packet inspection operation server.
CN201910599926.XA 2019-07-04 2019-07-04 Information shielding method and device Active CN110247825B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910599926.XA CN110247825B (en) 2019-07-04 2019-07-04 Information shielding method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910599926.XA CN110247825B (en) 2019-07-04 2019-07-04 Information shielding method and device

Publications (2)

Publication Number Publication Date
CN110247825A CN110247825A (en) 2019-09-17
CN110247825B true CN110247825B (en) 2021-06-04

Family

ID=67891022

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910599926.XA Active CN110247825B (en) 2019-07-04 2019-07-04 Information shielding method and device

Country Status (1)

Country Link
CN (1) CN110247825B (en)

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105589866A (en) * 2014-10-22 2016-05-18 联想(北京)有限公司 Information display method and apparatus
KR101732587B1 (en) * 2016-05-03 2017-05-24 주식회사 엔비티 Advertising system and method based on predicted user interest
CN108023867B (en) * 2016-10-28 2022-06-14 中国移动通信集团广东有限公司 Method for filtering mobile terminal webpage advertisement, gateway server and filtering server
CN109034874A (en) * 2018-07-03 2018-12-18 天津璧合信息技术有限公司 A kind of advertisement placement method and system

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
产业专利分析报告 第22册 浏览器;杨铁军;《产业专利分析报告 第22册 浏览器》;20141231;全文 *

Also Published As

Publication number Publication date
CN110247825A (en) 2019-09-17

Similar Documents

Publication Publication Date Title
DE112012001557B4 (en) Predictive placement of content through network analysis
US8102879B2 (en) Application layer metrics monitoring
US8965962B2 (en) Diameter session audits
US10015676B2 (en) Detecting fraudulent traffic in a telecommunications system
US20130041994A1 (en) Methods, systems, and computer readable media for policy event record generation
CN110380986A (en) Flow limitation method, device, equipment and storage medium based on Zuul
CN101146047B (en) A method, system and gateway for controlling quantity of network access terminal under routing mode
CN102138301A (en) Fair use management method and system
CN100466560C (en) Method, system, device for detecting service quality, and charging and fault detecting system
US9043928B1 (en) Enabling web page tracking
US20110141924A1 (en) System and Method for Filtering High Priority Signaling and Data for Fixed and Mobile Networks
WO2012051809A1 (en) Method for formulating access control policy for mobile value-added services, and a relevant apparatus and system
CN109547221A (en) Big data analysis service providing method and device, computer readable storage medium
Fiadino et al. HTTPTag: A flexible on-line HTTP classification system for operational 3G networks
US20120324099A1 (en) Content delivery control methods, apparatuses and computer programs
CN102271331A (en) Method and system for detecting reliability of service provider (SP) site
CN110247825B (en) Information shielding method and device
CN114866362B (en) Campus network addiction prevention method and system
CN101686223B (en) Feedback method of content filtering and device
WO2022001480A1 (en) Popular application identification method, network system, network device and storage medium
JP6044020B2 (en) Data packet processing method, system, and device
CN109361546A (en) A kind of program method for early warning and device based on view networking
CN105792265A (en) Malicious traffic detection method and system and monitoring platform
WO2016091294A1 (en) Estimating data traffic composition of a communication network through extrapolation
KR20100062225A (en) A method for collecting audience research in a iptv and a system thereof

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant