CN110347501A - A kind of service testing method, device, storage medium and electronic equipment - Google Patents

A kind of service testing method, device, storage medium and electronic equipment Download PDF

Info

Publication number
CN110347501A
CN110347501A CN201910538146.4A CN201910538146A CN110347501A CN 110347501 A CN110347501 A CN 110347501A CN 201910538146 A CN201910538146 A CN 201910538146A CN 110347501 A CN110347501 A CN 110347501A
Authority
CN
China
Prior art keywords
service
service request
server
business
business datum
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201910538146.4A
Other languages
Chinese (zh)
Inventor
高峰
顾雨
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Dami Technology Co Ltd
Original Assignee
Beijing Dami Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Dami Technology Co Ltd filed Critical Beijing Dami Technology Co Ltd
Priority to CN201910538146.4A priority Critical patent/CN110347501A/en
Publication of CN110347501A publication Critical patent/CN110347501A/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/46Multiprogramming arrangements
    • G06F9/50Allocation of resources, e.g. of the central processing unit [CPU]
    • G06F9/5083Techniques for rebalancing the load in a distributed system

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The embodiment of the present application discloses a kind of service testing method, device, storage medium and electronic equipment, wherein, method includes: to obtain the service request that load-balanced server is sent on service link, the service request is generated by the business in the client of the triggering service link, obtain the business datum that the service request carries, safety detection is carried out to the service request according to the business datum, the target service server service request after safety detection being sent on the service link, so that the target service server is based on the business datum and handles the service request.Using the embodiment of the present application, the processing pressure of service server can be reduced, improve the response speed of service request.

Description

A kind of service testing method, device, storage medium and electronic equipment
Technical field
This application involves field of computer technology more particularly to a kind of service testing method, device, storage medium and electronics Equipment.
Background technique
Universal with intelligent terminal with the development of internet technology, user is accessed by the application software of intelligent terminal Service server, to obtain the resource of service server.
Currently, this industry accessed can be sent to service server when user accesses service server by intelligent terminal Business request, service server can be detected (authentication detection, flow inspection after receiving service request to the service request Survey etc.), after detection passes through, service server is again handled service request.However, when some service server receives When the service request arrived is more, each service request is detected in service server in this way, excessive will be accounted for With the resource of service server, so as to cause service server processing pressure and load be excessive, service request response speed compared with Slow problem.
Summary of the invention
The embodiment of the present application provides a kind of service testing method, device, storage medium and electronic equipment, can reduce industry The processing pressure of business server.The technical solution is as follows:
In a first aspect, the embodiment of the present application provides a kind of service testing method, which comprises
The service request that load-balanced server is sent on service link is obtained, the service request is to trigger the business Business in the client of link is generated;
The business datum that the service request carries is obtained, safety is carried out to the service request according to the business datum Detection;
The service request after safety detection is sent to the target service server on the service link, so that institute Target service server is stated to handle the service request based on the business datum.
Second aspect, the embodiment of the present application provide a kind of business detection device, and described device includes:
Request module, for obtaining the service request that load-balanced server is sent on service link, the business The business in the client by the triggering service link is requested to be generated;
Safety detection module, the business datum carried for obtaining the service request, according to the business datum to institute It states service request and carries out safety detection;
Request sending module, the target for being sent to the service request after safety detection on the service link Service server, so that the target service server is based on the business datum and handles the service request.
The third aspect, the embodiment of the present application provide a kind of computer storage medium, and the computer storage medium is stored with A plurality of instruction, described instruction are suitable for being loaded by processor and executing above-mentioned method and step.
Fourth aspect, the embodiment of the present application provide a kind of electronic equipment, it may include: processor and memory;Wherein, described Memory is stored with computer program, and the computer program is suitable for being loaded by the processor and being executed above-mentioned method step Suddenly.
The technical solution bring beneficial effect that some embodiments of the application provide includes at least:
In the embodiment of the present application, the business that gateway server obtains that load-balanced server is sent on service link is asked It asks, the service request is generated by the business in the client of the triggering service link, and is obtained the service request and taken The business datum of band carries out safety detection to the service request according to the business datum, by the industry after safety detection The target service server that business request is sent on the service link, so that the target service server is based on the business Data handle the service request.By carrying out safety detection to the service request in gateway server, then will The service request after safety detection is sent to target service server process, it is possible to reduce occupies the money of service server The response speed of service request is improved to reduce the processing pressure and load of service server in source.
Detailed description of the invention
In order to illustrate the technical solutions in the embodiments of the present application or in the prior art more clearly, to embodiment or will show below There is attached drawing needed in technical description to be briefly described, it should be apparent that, the accompanying drawings in the following description is only this Some embodiments of application for those of ordinary skill in the art without creative efforts, can be with It obtains other drawings based on these drawings.
Fig. 1 is a kind of scene framework schematic diagram of business detection provided by the embodiments of the present application;
Fig. 2 is a kind of flow diagram of service testing method provided by the embodiments of the present application;
Fig. 3 is the flow diagram of another service testing method provided by the embodiments of the present application;
Fig. 4 is a kind of structural schematic diagram of business detection device provided by the embodiments of the present application;
Fig. 5 is the structural schematic diagram of another business detection device provided by the embodiments of the present application;
Fig. 6 is a kind of structural schematic diagram of safety detection module provided by the embodiments of the present application;
Fig. 7 is the structural schematic diagram of a kind of electronic equipment provided by the embodiments of the present application.
Specific embodiment
Below in conjunction with the attached drawing in the embodiment of the present application, technical solutions in the embodiments of the present application carries out clear, complete Site preparation description, it is clear that described embodiments are only a part of embodiments of the present application, instead of all the embodiments.It is based on Embodiment in the application, it is obtained by those of ordinary skill in the art without making creative efforts every other Embodiment shall fall in the protection scope of this application.
In the description of the present application, it is to be understood that term " first ", " second " etc. are used for description purposes only, without It can be interpreted as indication or suggestion relative importance.In the description of the present application, it should be noted that unless otherwise specific regulation And restriction, " comprising " and " having " and their any deformations, it is intended that cover and non-exclusive include.Such as contain a system The process, method, system, product or equipment of column step or unit are not limited to listed step or unit, but optional Ground further includes the steps that not listing or unit, or optionally further comprising intrinsic for these process, methods, product or equipment Other step or units.For the ordinary skill in the art, above-mentioned term can be understood in the application with concrete condition In concrete meaning.In addition, unless otherwise indicated, " multiple " refer to two or more in the description of the present application." and/ Or ", the incidence relation of affiliated partner is described, indicates may exist three kinds of relationships, for example, A and/or B, can indicate: individually depositing In A, A and B, these three situations of individualism B are existed simultaneously.It is a kind of "or" that character "/", which typicallys represent forward-backward correlation object, Relationship.
The application is described in detail below with reference to specific embodiment.
It referring to Figure 1, is a kind of configuration diagram of service detection system provided by the embodiments of the present application.As shown in Figure 1, The service detection system may include client 100, load-balanced server 110, gateway server 120 and service server 130。
The client 100 can be the electronic equipment with network access functions, which includes but is not limited to: PC, handheld device, mobile unit, wearable device, calculates equipment or is connected to radio modem tablet computer Other processing equipments etc..Client 100 can be called different titles in different networks, such as: user equipment, access Terminal, subscriber unit, subscriber station, movement station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, nothing Line communication equipment, user agent or user apparatus, cellular phone, wireless phone, personal digital assistant (personal digital Assistant, PDA), the terminal device in 5G network or future evolution network etc..
The load-balanced server 110, gateway server 120 and service server 130 can be individual server Equipment, such as: rack, blade, tower or cabinet-type server apparatus can also use work station, mass computing Machine, etc. have stronger computing capability hardware device, can also using multiple servers composition server cluster, the services set Each server in group can be to be formed in a symmetrical, wherein every server function equivalence, status in service link Equivalence, each server individually can externally provide service, described service is provided separately to can be understood as without other server Auxiliary.
When the business in client 100 is triggered, client 100 generates the corresponding service request of the business and through industry Link transmission of being engaged in service server 130 is handled.
The service link refers to data link or physical link, and wherein data link includes service link, virtual chain Road and logical links etc..In general, service link includes service server, interchanger, gateway etc..In the present embodiment, institute Stating service link can be understood as the service request in the path that each service node transmits, i.e., by client 100, load balancing The link that server 110, gateway server 120 and service server 130 form.When the business in client 100 is triggered, The client 100 especially by reading and execute the corresponding machine-executable instruction of control logic that the business is triggered, Client 100 recognizes business by execution described instruction and is triggered, and then generates the service request of the business, then by institute Each service node (load-balanced server, gateway server etc.) transmission of the service request through service link is stated, finally to business The service server 130 of link is handled.
In the scene of a specific reservation course, the client 100 can be the smart machines such as computer, mobile phone, It for convenience of description, is computer citing with client 100, the computer can be used equipped with the application program of reservation course " Saturday-the English class " option is chosen by connecting the external equipment mouse of computer in family, and clicks confirmation.Above-mentioned reservation " Saturday-English Language class " business is triggered, and computer monitoring executes the reservation " Saturday-English to choosing the operation of " Saturday-the English class " option The corresponding machine-executable instruction of control logic that language class " business is triggered, computer generate reservation by executing described instruction Then the service request is transmitted to service server 130 through service link and handled by the service request of " Saturday-the English class ".
Load-balanced server 110 distributes the service request on service link to gateway server 120.
Specifically, service request is assigned to one under service link by load-balanced server 110 by load-balancing algorithm Service node gateway server 120.
Specifically, the load-balancing algorithm can be random algorithm, polling algorithm, Weighted Round Robin, Smallest connection, It hashes to source and hash algorithm.It should be noted that complete in the present embodiment the algorithm that is related to of load balancing can be it is above-mentioned One of algorithm is a variety of, is not especially limited herein.
Optionally, when user triggers the business function of client 100, load of the client 100 on service link is equal The server 110 that weighs sends a service request, and the service request is for inquiring the available gateway server of next service node 120 addresses or gateway service information.After load-balanced server 110 receives the service request, the industry is analyzed first The business datum that business request carries, later in available next service node, inside load-balanced server 110 The load information and load balancing of each gateway server 120 of maintenance, using load-balancing algorithm, calculating one be can be used Gateway server 120, be then based on the IP address of the gateway server 120 or with special format comprising address information Service content, the service request is distributed to gateway server 120.
Specifically, gateway server 120 obtains the service request that load-balanced server 110 distributes on service link, obtain The business datum for taking the service request to carry carries out safety detection to the service request according to the business datum, will pacify The service request after full inspection is surveyed is sent to target service server 130, and the target service server 130 is based on the industry Business data handle the service request.
In the embodiment of the present application, the business that gateway server obtains that load-balanced server is sent on service link is asked It asks, the service request is generated by the business in the client of the triggering service link, and is obtained the service request and taken The business datum of band carries out safety detection to the service request according to the business datum, by the industry after safety detection The target service server that business request is sent on the service link, so that the target service server is based on the business Data handle the service request.By carrying out safety detection to the service request in gateway server, then will The service request after safety detection is sent to target service server process, it is possible to reduce occupies the money of service server The response speed of service request is improved to reduce the processing pressure and load of service server in source.
In one embodiment, as shown in Fig. 2, spy proposes a kind of service testing method, this method can be dependent on calculating Machine program is realized, can run in the scoring generating means based on von Neumann system.The computer program can be integrated in application In, it also can be used as independent tool-class application operation.The business detection device can be smart phone, tablet computer, personal electricity The mobile devices such as brain, laptop.
Specifically, the service testing method includes:
Step 101: obtaining the service request that load-balanced server is sent on service link, the service request is triggering Business in the client of the service link is generated.
Specifically, in the service link and the business network being made of a plurality of service link, client, load balancing The equipment such as server, gateway server are all each other transparent, sightless.In service link or business network deployment, The IP address of multiple gateway servers, port numbers or the attribute comprising address information with special format can be pre-configured with In the load-balanced server, the load-balanced server, which can be, to be built based on Nginx load-balanced server Load-balanced server cluster.
Specifically, the business in client is triggered, client can generate the service request of the business and through business Link is transmitted.
Optionally, when multiple client concurrently or consecutively generates service request and is transmitted through service link, or work as One client is continuously generated service request and is transmitted through service link, and the load-balanced server on service link can connect By all service requests on service link, the business datum then carried to the service request is parsed, and under The load information (CPU memory, network bandwidth etc.) that each gateway server is obtained in one service node gateway server cluster, according to Load-balancing algorithm calculates the gateway server of the service request, and the service request is then sent to the gateway and is taken Business device.
Optionally, the business datum carried to the service request parses, and the business datum includes service link The IP address and port numbers of next service node of middle client --- load-balanced server, it should be noted that this implementation The IP address and port numbers of load-balanced server can be the IP address and port numbers of multiple load-balanced servers in example, or Person is identical as the IP address of fractional load equalization server and port numbers.
The parsing, which can be, carries out protocol analysis to the business datum, obtains the corresponding communication protocols of the business datum View, then carry out corresponding protocol processes (such as by Http/DNS/RADIU protocol stack by Https protocol conversion be Http assist View etc.), the type of the protocol processes has much to be not especially limited herein.The protocol processes can be understood as can With the gateway server communication of next service node, then the service request after protocol processes is sent to described according to load Equalization algorithm calculates the gateway server of the service request.So that gateway server is available to negative on service link Carry the service request that equalization server is sent.
Step 102: the business datum that the service request carries is obtained, according to the business datum to the service request Carry out safety detection.
The service request can be the request of the Http based on hypertext transfer protocol, the business that the service request carries Containing the identification information of client in data, the identification information can be the id, MAC Address, IP address, client of client Digital certificate, user name and password etc..
Optionally, client is when generating the service request, can be according to Encryption Algorithm by the identification information of client Cryptographic calculation is executed, the cryptographic calculation can be the hash algorithm based on 256 bit encryptions, for example, client is calculated using Hash The information such as the MAC Address of client, IP address, the digital certificate of client and id are spliced and combined the business encrypted for a string by method Data, then client sends the service request for carrying the business datum, when gateway server gets the business When request, the business datum carried to the service request is parsed, so that it may get the business letter of the business datum It ceases (information such as MAC Address, IP address, the digital certificate of client and id of client), then according to the business datum Business information carries out safety detection to the service request.
Wherein, the safety detection includes authentication detection, traffic monitoring, the singly detection etc. of anti-brush.
Optionally, gateway server carries out authentication inspection to the service request according to the business information of the business datum It surveys, especially by the IP address for obtaining client, whether the IP address is then examined according to the authentication list of gateway server In the authentication list, the client of the IP address instruction in the authentication list directly can log in or access business service The resource of device.
In a kind of feasible embodiment, gateway server is when getting the business datum of service request carrying, root The corresponding safety detection item of the service request is determined according to the business datum, such as determines the corresponding safety of the service request Detection is 4, respectively authentication detection, traffic monitoring, anti-brush singly detection, viral diagnosis, then successively to the business datum 4 safety detections are carried out to the service request.And it is weighted according to the testing result of 4 safety detection items and obtains this inspection It measures point, determines that can the service request directly log in or access the resource of service server according to detection score.
Step 103: the target service service service request after safety detection being sent on the service link Device, so that the target service server is based on the business datum and handles the service request.
Specifically, gateway server is according to default allocation rule to institute after carrying out safety detection to the service request It states service request and distributes a target service server, the target service service service request being sent on service link On device.
Specifically, the allocation rule can be the dynamic bandwidth allocation algorithm based on type of service, can be based on rich The queuing network service-allocation algorithm for playing chess opinion, can be the Slot Allocation Algorithm based on traffic forecast, can also be based on business Cross-layer resource allocation algorithm of priority etc..
It should be noted that can be above-mentioned one or more there are many allocation rules, be not especially limited herein.
Optionally, a target industry is distributed to the service request when the gateway server is based on preset allocation rule It is engaged in after server, the gateway server sends a heartbeat packet to target service server, and the heartbeat packet is for judging institute The working condition for stating target service server, it is described after the target service server receives the heartbeat packet and handles Target service server sends response data to gateway server.
Optionally, gateway server is after sending heartbeat packet, according to the time threshold of the preset response data, inspection It surveys and whether receives the response data within the scope of the time threshold:
When not receiving the response data within the scope of the time threshold, then the target service server work Abnormal state, then gateway server redistributes a target service service to the service request according to default allocation rule Device.
When receiving the response data within the scope of the time threshold, then the work of the target service server State is normal, executes gateway server according to the address of the target service server of distribution, the service request is sent to mesh It marks on service server.
Specifically, obtaining the service request after the target service server receives the service request and carrying Business datum, the service request is handled according to the business datum.
In the embodiment of the present application, the business that gateway server obtains that load-balanced server is sent on service link is asked It asks, the service request is generated by the business in the client of the triggering service link, and is obtained the service request and taken The business datum of band carries out safety detection to the service request according to the business datum, by the industry after safety detection The target service server that business request is sent on the service link, so that the target service server is based on the business Data handle the service request.By carrying out safety detection to the service request in gateway server, then will The service request after safety detection is sent to target service server process, it is possible to reduce occupies the money of service server The response speed of service request is improved to reduce the processing pressure and load of service server in source.
Fig. 3 is referred to, Fig. 3 is a kind of process signal of another embodiment for service testing method that the application proposes Figure.It is specific:
Step 201: obtaining the service request that load-balanced server is sent on service link, the service request is triggering Business in the client of the service link is generated.
For details, reference can be made to steps 101, and details are not described herein again.
Step 202: when the quantity of the service request is multiple, obtaining the corresponding timestamp of each service request and institute State the business datum that each service request carries.
The timestamp refers to indicating that a data are already existing, complete before some specific time, can test The data of card, usually a character string, for providing a electronic evidence for user, when generation to prove certain data Between.It can be understood as the business datum that the service request that gateway server is currently got carries in the present embodiment to generate Time.
Specifically, each service node on the service link constantly works, when multiple load balancers simultaneously or Service request continuously is sent to next service node gateway server, or when a load-balanced server continues to ask business It asks when being transmitted to next service node gateway server through service link, gateway server can receive multiple business simultaneously at this time Request.
Optionally, when gateway server receives multiple service requests simultaneously, the corresponding timestamp of each service request is obtained And the business datum that each service request carries, first the timestamp of each service request is parsed to obtain each business and be asked Priority parameters are arranged to all service request according to the sequencing of time in the time asked, the gateway server according to The priority parameters of each service request, preferentially the business datum of the service request highest to current priority carries out safe inspection It surveys.
Step 203: successively judging that the business datum is with default risk data according to the sequencing of the timestamp No matching.
The risk data refers to the sample data in pre-set vulnerability database, and the vulnerability database includes The keyword of the sample data for risk data detection based on the formation of safety detection strategy, key feature information.
Wherein, the keyword that the vulnerability database includes can be the key mark of malicious application, can be evil Meaning brush single characteristic character, the feature stack that can be malicious requests etc., can also be the linear list of label.
Optionally, gateway server can be matched based on the keyword of risk data, and the gateway server is to institute It states business datum to carry out splitting the keyword extracted in business datum, the keyword can be understood as a string in the present embodiment Code, character string, array match the keyword of the business datum with the keyword in safety database.
Wherein, the key feature information that the safety database includes can be the IP address of certain equipment, MAC Address, ID Name, port numbers, domain name etc..
Optionally, gateway server can be matched based on the key feature information of risk data, the gateway service Device carries out the business datum to split the key feature information extracted in business datum, then according to the pass of the business datum Key characteristic information is matched with the key feature information in safety database.
Optionally, user can add the business datum containing characteristic information for needing to intercept in advance according to demand.
For example, it is desired to all service requests to malicious IP addresses 192.1.0.1 intercept, then it only need to be in the safety Characteristic information is added in database --- IP address 192.1.0.1 is simultaneously arranged accordingly.When gateway server receives IP After the service request that address 192.1.0.1 is sent, so that it may which being matched in safety database key feature information is " IP The risk data of location 192.1.0.1 ", and then recognizing the service request is what malicious IP addresses issued.
Specifically, the gateway server loads preset risk data, by current service data and preset risk number According to comparing, comparing result is obtained.The comparing result include the business datum and default risk data keyword and The similarity of key feature information, specific set of metadata of similar data, type of business datum (blacklist, malice are brushed single etc.) etc..
Step 204: when the business datum is matched with the default risk data, intercepting the service request.
Wherein, the business datum is matched with the default risk data, be can be the business datum and is preset with described The similarity of risk data reaches preset risk threshold value.
Specifically, the gateway server loads default risk data, by the business datum and preset secure data It compares, obtains comparing result.When the similarity of the comparing result is greater than or equal to preset risk threshold value, gateway clothes The service request is carried out intercept process by business device.
In a kind of feasible embodiment, the gateway server has suspicious data isolation features, in business datum After matching with the default risk data, the similarity model in suspicious data is judged whether according to the similarity in comparing result In enclosing, the business datum in the similarity dimensions of suspicious data is isolated in sandbox, the sandbox refers to one kind It is then further to the business datum in sandbox according to risk policy limit service calling or the performing environment of program behavior Safety verification.The safety verification includes malicious attack detection, web crawlers detects, detection, flow monitoring etc. are flutterred in business expansion. When the business datum does not pass through safety verification in sandbox, the gateway server is to the corresponding business of the business datum Request carries out intercept process.When the business datum passes through safety verification in sandbox, the gateway server is to the industry The corresponding service request of business data is further processed.
For example, refer to table one, table first is that similarity dimensions, data type, risk class mapping table.
Table one
Similarity dimensions Data type Risk class
0~50 Secure data 1 grade
40~70 Suspicious data 2 grades
≥70 Risk data 1 grade
Gateway server obtains the phase of comparing result after matching to current service data with the default risk data Be 45 like degree, then obtained according to one corresponding relationship of table: current service data is suspicious data, and risk class is 2 grades.The gateway Current suspicious data is isolated in sandbox by server, then in sandbox to the further safety verification of current suspicious data, When the business datum does not pass through safety verification in sandbox, the gateway server asks the corresponding business of the business datum Seek carry out intercept process.
The intercept process, which can be, terminates the server processes that the currently processed service request of gateway server is opened, It can be and the server buffer of the service request is removed, can also be using presently described service request as the safe number of sample According in the secure data for being added to gateway server.
Step 205: when the business datum and the default risk data mismatch, obtaining in service server cluster The business processing status is empty service server as the processing business by the business processing status of each service server The target service server of request.
Wherein, the business processing status can be understood as the service server service request quantity to be processed, CPU usage, waiting time of service request etc., the business processing status are that sky can be understood as the service server Business processing status can receive the service request and handle it.
Optionally, the business processing status for obtaining each service server in service server cluster, can be for actively Acquisition modes: all service servers of the gateway server into service server cluster, which are sent, obtains business processing status Instruction, described instruction is responded after each service server receives described instruction, by current business processing shape State (service request quantity to be processed, CPU usage, waiting time of service request etc.) is fed back to described with data packet form Gateway server.
Optionally, the business processing status for obtaining each service server in service server cluster, can also be quilt Dynamic accepting method: in the service server cluster each service server timing or by preset time interval to gateway server Data packet is sent, the data packet includes the data of the business processing status of current business server.
Specifically, when the business datum and the default secure data mismatch, i.e., the described business datum and default Secure data compare after, the similarity of the comparing result is less than preset secure threshold.Then business clothes are obtained The business processing status of each service server, the data packet specifically sent to the service server solve in business device cluster Analysis obtains value (the service request quantity to be processed, CPU usage, industry of every business processing parameter of the service server It is engaged in waiting time requested etc.), and using the value of every business processing parameter as input, it is input to state judgment models In, outgoing traffic processing status is empty service server.
Optionally, the state judgment models can be using a large amount of test sample train come, as state judge Model can be based on convolutional neural networks (Convolutional Neural Network, CNN) model, deep neural network (Deep Neural Network, DNN) model, Recognition with Recurrent Neural Network (Recurrent Neural Networks, RNN), mould Type, insertion (embedding) model, gradient promote decision tree (Gradient Boosting Decision Tree, GBDT) mould What at least one of type, logistic regression (Logistic Regression, LR) model were realized, based on the sample marked Data are trained state judgment models, available trained state judgment models.
It is asked specifically, the business processing status is empty service server as the business is handled by gateway server The target service server asked.
Step 206: obtaining the address of the target service server, the service request after safety detection is sent to The target service server of the address instruction, so that the target service server is based on the business datum to the business Request is handled.
Specifically, gateway server obtains the address of the target service server, the address can be IP address, domain Name address, MAC Address, port numbers etc., the gateway server are communicated with the target service server foundation that the address indicates Then the service request after safety detection is sent to the target service server of the address instruction, so that institute by connection Target service server is stated to handle the service request based on the business datum.
In the embodiment of the present application, the business that gateway server obtains that load-balanced server is sent on service link is asked It asks, the service request is generated by the business in the client of the triggering service link.When the service request includes more When a, the business datum of the corresponding timestamp of each service request and each service request carrying is obtained, according to the time The sequencing of stamp and according to the business datum successively carries out safety detection to the service request.Judge the business number Whether matched according to default risk data.When the business datum is matched with the risk data, the service request is intercepted. When the business datum and the risk data mismatch, obtain in service server cluster at the business of each service server The business processing status is empty service server as the target service service for handling the service request by reason state Device.The service request after safety detection is sent to the address and indicated by the address for obtaining the target service server Target service server so that the target service server be based on the business datum to the service request at Reason.It only needs to carry out safety detection to the service request in gateway server, then asks the business after safety detection It asks and is sent to target service server process, so that it may the resource for occupying service server is reduced, to reduce service server Processing pressure, improve service request response speed.
Following is the application Installation practice, can be used for executing the application embodiment of the method.It is real for the application device Undisclosed details in example is applied, the application embodiment of the method is please referred to.
Fig. 4 is referred to, it illustrates the structural representations for the business detection device that one exemplary embodiment of the application provides Figure.The business detection device can by software, hardware or both be implemented in combination with as terminal all or part of.It should Device 1 includes request module 11, safety detection module 12 and request sending module 13.
Request module 11, for obtaining the service request that load-balanced server is sent on service link, the industry Business in client of the business request to trigger the service link is generated;
Safety detection module 12, the business datum carried for obtaining the service request, according to the business datum pair The service request carries out safety detection;
Request sending module 13, for the service request after safety detection to be sent to target service server, with Make the target service server be based on the business datum to handle the service request.
Optionally, as shown in figure 5, the safety detection module 12, is specifically used for:
Judge whether the business datum matches with default risk data;
When the business datum is matched with the default risk data, the service request is intercepted;
When the business datum and the default risk data mismatch, triggers the request sending module and examine safety The service request after survey is sent to target service server, so that the target service server is based on the business datum The service request is handled.
Optionally, as shown in figure 5, described device 1 further include:
Server determining module 14, for obtaining the business processing status of each service server in service server cluster, It is empty service server as the target service server for handling the service request using the business processing status.
Optionally, as shown in fig. 6, when the quantity of the service request is multiple, the safety detection module 12, specifically For:
Parameter acquiring unit 1201 is carried for obtaining the corresponding timestamp of each service request and each service request Business datum;
Safety detection unit 1202, for the sequencing according to the timestamp and according to the business datum, successively Safety detection is carried out to the service request.
In the embodiment of the present application, the business that gateway server obtains that load-balanced server is sent on service link is asked It asks, the service request is generated by the business in the client of the triggering service link.When the service request includes more When a, the business datum of the corresponding timestamp of each service request and each service request carrying is obtained, according to the time The sequencing of stamp and according to the business datum successively carries out safety detection to the service request.Judge the business number Whether matched according to default risk data.When the business datum is matched with the business datum of the risk business, institute is intercepted State service request.When the business datum and the risk data mismatch, each business clothes in service server cluster are obtained The business processing status is empty service server as the mesh for handling the service request by the business processing status of business device Mark service server.The service request after safety detection is sent to institute by the address for obtaining the target service server The target service server of address instruction is stated, so that the target service server is based on the business datum and asks to the business It asks and is handled.It only needs to carry out safety detection to the service request in gateway server, then by the institute after safety detection It states service request and is sent to target service server process, so that it may the resource for occupying service server is reduced, to reduce industry The processing pressure of business server, the response speed for improving service request.
It should be noted that business detection device provided by the above embodiment is when executing service testing method, only more than The division progress of each functional module is stated for example, can according to need and in practical application by above-mentioned function distribution by difference Functional module complete, i.e., the internal structure of equipment is divided into different functional modules, with complete it is described above whole or Person's partial function.In addition, business detection device provided by the above embodiment and service testing method embodiment belong to same design, It embodies realization process and is detailed in embodiment of the method, and which is not described herein again.
Above-mentioned the embodiment of the present application serial number is for illustration only, does not represent the advantages or disadvantages of the embodiments.
The embodiment of the present application also provides a kind of computer storage medium, the computer storage medium can store more Item instruction, described instruction are suitable for being loaded by processor and being executed the method and step such as above-mentioned Fig. 1-embodiment illustrated in fig. 3, specifically hold Row process may refer to Fig. 1-embodiment illustrated in fig. 3 and illustrate, herein without repeating.
Present invention also provides a kind of computer program product, which is stored at least one instruction, At least one instruction is loaded as the processor and is executed to realize service testing method described in as above each embodiment.
7 are referred to, provides the structural schematic diagram of a kind of electronic equipment for the embodiment of the present application.As shown in fig. 7, the clothes Business device 1000 may include: at least one processor 1001, at least one network interface 1004, user interface 1003, memory 1005, at least one communication bus 1002.
Wherein, communication bus 1002 is for realizing the connection communication between these components.
Wherein, user interface 1003 may include display screen (Display), camera (Camera), optional user interface 1003 can also include standard wireline interface and wireless interface.
Wherein, network interface 1004 optionally may include standard wireline interface and wireless interface (such as WI-FI interface).
Wherein, processor 1001 may include one or more processing core.Processor 1001 using it is various excuse and Various pieces in the entire server 1000 of connection, by running or executing the instruction being stored in memory 1005, journey Sequence, code set or instruction set, and call the data that are stored in memory 1005, the various functions of execute server 1000 and Handle data.Optionally, processor 1001 can using Digital Signal Processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), programmable logic array At least one of (Programmable Logic Array, PLA) example, in hardware is realized.Processor 1001 can integrating central Processor (Central Processing Unit, CPU), image processor (Graphics Processing Unit, GPU) With the combination of one or more of modem etc..Wherein, the main processing operation system of CPU, user interface and apply journey Sequence etc.;GPU is used to be responsible for the rendering and drafting of content to be shown needed for display screen;Modem is for handling channel radio Letter.It is understood that above-mentioned modem can not also be integrated into processor 1001, carried out separately through chip piece It realizes.
Wherein, memory 1005 may include random access memory (Random Access Memory, RAM), also can wrap Include read-only memory (Read-Only Memory).Optionally, which includes non-transient computer-readable medium (non-transitory computer-readable storage medium).Memory 1005 can be used for store instruction, journey Sequence, code, code set or instruction set.Memory 1005 may include storing program area and storage data area, wherein storing program area Can store the instruction for realizing operating system, the instruction at least one function (such as touch function, sound play function Energy, image player function etc.), for realizing instruction of above-mentioned each embodiment of the method etc.;Storage data area can store each above The data etc. being related in a embodiment of the method.Memory 1005 optionally can also be that at least one is located remotely from aforementioned processing The storage device of device 1001.As shown in fig. 7, as may include operation system in a kind of memory 1005 of computer storage medium System, network communication module, Subscriber Interface Module SIM and business detect application program.
In server 1000 shown in Fig. 7, user interface 1003 is mainly used for providing the interface of input for user, obtains The data of user's input;And processor 1001 can be used for that the business stored in memory 1005 is called to detect application program, and It is specific to execute following operation:
The service request that load-balanced server is sent on service link is obtained, the service request is to trigger the business Business in the client of link is generated;
The business datum that the service request carries is obtained, safety is carried out to the service request according to the business datum Detection;
The service request after safety detection is sent to the target service server on the service link, so that institute Target service server is stated to handle the service request based on the business datum.
In one embodiment, the processor 1001 is executing the business datum for obtaining the service request and carrying, root Safety detection is carried out to business according to the business datum, specific to execute following operation:
Judge whether the business datum matches with default risk data;
When the business datum is matched with the default risk data, the service request is intercepted;
When the business datum and the default risk data mismatch, the industry by after safety detection is executed Business request is sent to target service server, so that the target service server is based on the business datum and asks to the business Ask the step of being handled.
In one embodiment, the service request of the processor 1001 after executing safety detection is sent to target Service server, so that before the target service server is handled the service request based on the business datum, It is specific to execute following operation:
Obtain the business processing status of each service server in service server cluster;
It is empty service server as the target service service for handling the service request using the business processing status Device.
In one embodiment, the processor 1001 is being executed when the quantity of the service request is multiple, described The business datum that the service request carries is obtained, safety detection, tool are carried out to the service request according to the business datum Body executes following operation:
Obtain the business datum of the corresponding timestamp of each service request and each service request carrying;
According to the sequencing of the timestamp and according to the business datum, safety successively is carried out to the service request Detection.
In one embodiment, the service request after safety detection is sent to mesh in execution by the processor 1001 Service server is marked, so that the target service server is based on the business datum and handles the service request, is had Body executes following operation:
The service request after safety detection is sent to the address by the address for obtaining the target service server The target service server of instruction, so that the target service server is based on the business datum and carries out to the service request Processing.
In the present embodiment, gateway server obtains the service request that load-balanced server is sent on service link, institute Service request is stated to be generated by the business in the client of the triggering service link.When the service request includes multiple, The business datum for obtaining the corresponding timestamp of each service request and each service request carrying, according to the elder generation of the timestamp Afterwards sequentially and according to the business datum, safety detection successively is carried out to the service request.Judge the business datum and pre- If whether risk data matches.When the business datum is matched with the risk data, the service request is intercepted.When described When business datum and the risk data mismatch, the business processing shape of each service server in service server cluster is obtained The business processing status is empty service server as the target service server for handling the service request by state.It obtains The service request after safety detection is sent to the target of the address instruction by the address for taking the target service server Service server, so that the target service server is based on the business datum and handles the service request.Only need Safety detection is carried out to the service request in gateway server, then be sent to the service request after safety detection Target service server process, so that it may the resource for occupying service server is reduced, to reduce the processing pressure of service server Power, the response speed for improving service request.
Those of ordinary skill in the art will appreciate that realizing all or part of the process in above-described embodiment method, being can be with Relevant hardware is instructed to complete by computer program, the program can be stored in a computer-readable storage medium In, the program is when being executed, it may include such as the process of the embodiment of above-mentioned each method.Wherein, the storage medium can be magnetic Dish, CD, read-only memory or random access memory etc..
Above disclosed is only the application preferred embodiment, cannot limit the right model of the application with this certainly It encloses, therefore according to equivalent variations made by the claim of this application, still belongs to the range that the application is covered.

Claims (10)

1. a kind of service testing method, which is characterized in that the described method includes:
The service request that load-balanced server is sent on service link is obtained, the service request is to trigger the service link Client on business generated;
The business datum that the service request carries is obtained, safe inspection is carried out to the service request according to the business datum It surveys;
The service request after safety detection is sent to the target service server on the service link, so that the mesh Mark service server is based on the business datum and handles the service request.
2. the method according to claim 1, wherein it is described according to the business datum to the service request into Row safety detection, comprising:
Judge whether the business datum matches with default risk data;
When the business datum is matched with the default risk data, the service request is intercepted;
When the business datum and the default risk data mismatch, executes the business by after safety detection and ask Ask and be sent to target service server so that the target service server be based on the business datum to the service request into The step of row processing.
3. the method according to claim 1, wherein the service request by after safety detection is sent to Target service server, so that the target service server is based on the business datum and carries out handling it to the service request Before, further includes:
Obtain the business processing status of each service server in service server cluster on the service link;
It is empty service server as the target service server for handling the service request using the business processing status.
4. the method according to claim 1, wherein when the quantity of the service request be it is multiple when, it is described to obtain The business datum for taking the service request to carry carries out safety detection to the service request according to the business datum, comprising:
Obtain the business datum of the corresponding timestamp of each service request and each service request carrying;
According to the sequencing of the timestamp and according to the business datum, safe inspection successively is carried out to the service request It surveys.
5. the method according to claim 1, wherein the service request by after safety detection is sent to Target service server on the service link, so that the target service server is based on the business datum to the industry Business request is handled, comprising:
The service request after safety detection is sent to the service link by the address for obtaining the target service server On the address instruction target service server so that the target service server be based on the business datum to described Service request is handled.
6. a kind of business detection device, which is characterized in that described device includes:
Request module, for obtaining the service request that load-balanced server is sent on service link, the service request The business in client to trigger the service link is generated;
Safety detection module, the business datum carried for obtaining the service request, according to the business datum to the industry Business request carries out safety detection;
Request sending module, the target service for being sent to the service request after safety detection on the service link Server, so that the target service server is based on the business datum and handles the service request.
7. device according to claim 6, which is characterized in that the safety detection module is specifically used for:
Judge whether the business datum matches with default risk data, when the business datum and the default risk data Timing intercepts the service request;When the business datum and the default risk data mismatch, the request hair is triggered Send module that the service request after safety detection is sent to target service server, so that the target service server base The service request is handled in the business datum.
8. device according to claim 6, which is characterized in that described device further include:
Server determining module will be described for obtaining the business processing status of each service server in service server cluster Business processing status is empty service server as the target service server for handling the service request.
9. a kind of computer storage medium, which is characterized in that the computer storage medium is stored with a plurality of instruction, described instruction Suitable for being loaded by processor and being executed the method and step such as Claims 1 to 5 any one.
10. a kind of electronic equipment is it is characterised by comprising: processor and memory;Wherein, the memory is stored with computer Program, the computer program are suitable for being loaded by the processor and being executed the method step such as Claims 1 to 5 any one Suddenly.
CN201910538146.4A 2019-06-20 2019-06-20 A kind of service testing method, device, storage medium and electronic equipment Pending CN110347501A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910538146.4A CN110347501A (en) 2019-06-20 2019-06-20 A kind of service testing method, device, storage medium and electronic equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910538146.4A CN110347501A (en) 2019-06-20 2019-06-20 A kind of service testing method, device, storage medium and electronic equipment

Publications (1)

Publication Number Publication Date
CN110347501A true CN110347501A (en) 2019-10-18

Family

ID=68182573

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910538146.4A Pending CN110347501A (en) 2019-06-20 2019-06-20 A kind of service testing method, device, storage medium and electronic equipment

Country Status (1)

Country Link
CN (1) CN110347501A (en)

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111078405A (en) * 2019-12-10 2020-04-28 Oppo(重庆)智能科技有限公司 Memory allocation method and device, storage medium and electronic equipment
CN111163097A (en) * 2019-12-31 2020-05-15 新浪网技术(中国)有限公司 Web application firewall implementation system and method
CN111614624A (en) * 2020-04-24 2020-09-01 支付宝(杭州)信息技术有限公司 Risk detection method, device, system and storage medium
CN112351083A (en) * 2020-10-28 2021-02-09 武汉绿色网络信息服务有限责任公司 Service processing method and network service system
CN112448952A (en) * 2020-11-13 2021-03-05 北京金和网络股份有限公司 Method and device for remotely receiving and storing intelligent equipment parameters
CN112822189A (en) * 2021-01-04 2021-05-18 中国电力科学研究院有限公司 Traffic identification method and device
CN112882895A (en) * 2021-02-22 2021-06-01 中国工商银行股份有限公司 Health examination method, device, computer system and readable storage medium
CN113452691A (en) * 2021-06-24 2021-09-28 未鲲(上海)科技服务有限公司 Service flow detection method and device, server and storage medium
CN114095502A (en) * 2021-10-08 2022-02-25 浙江吉利控股集团有限公司 Service processing method, system, device and medium
CN114157503A (en) * 2021-12-08 2022-03-08 北京天融信网络安全技术有限公司 Access request authentication method and device, API gateway equipment and storage medium
CN114301820A (en) * 2021-12-25 2022-04-08 江苏信而泰智能装备有限公司 Test port reservation method, device, equipment and readable storage medium
CN117252676A (en) * 2023-11-20 2023-12-19 成都新希望金融信息有限公司 Service processing method, device, electronic equipment and index policy system

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8347374B2 (en) * 2007-11-15 2013-01-01 Red Hat, Inc. Adding client authentication to networked communications
CN103647774A (en) * 2013-12-13 2014-03-19 扬州永信计算机有限公司 Web content information filtering method based on cloud computing
US8856869B1 (en) * 2009-06-22 2014-10-07 NexWavSec Software Inc. Enforcement of same origin policy for sensitive data
CN106131078A (en) * 2016-08-29 2016-11-16 联动优势科技有限公司 A kind of method and device processing service request
CN107070983A (en) * 2017-01-23 2017-08-18 天地融科技股份有限公司 A kind of load-balancing method, equipment and system forwarded based on address
CN107277025A (en) * 2017-06-28 2017-10-20 维沃移动通信有限公司 A kind of Secure Network Assecc method, mobile terminal and computer-readable recording medium
CN109510846A (en) * 2017-09-14 2019-03-22 北京金山云网络技术有限公司 API Calls system, method, apparatus, electronic equipment and storage medium

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8347374B2 (en) * 2007-11-15 2013-01-01 Red Hat, Inc. Adding client authentication to networked communications
US8856869B1 (en) * 2009-06-22 2014-10-07 NexWavSec Software Inc. Enforcement of same origin policy for sensitive data
CN103647774A (en) * 2013-12-13 2014-03-19 扬州永信计算机有限公司 Web content information filtering method based on cloud computing
CN106131078A (en) * 2016-08-29 2016-11-16 联动优势科技有限公司 A kind of method and device processing service request
CN107070983A (en) * 2017-01-23 2017-08-18 天地融科技股份有限公司 A kind of load-balancing method, equipment and system forwarded based on address
CN107277025A (en) * 2017-06-28 2017-10-20 维沃移动通信有限公司 A kind of Secure Network Assecc method, mobile terminal and computer-readable recording medium
CN109510846A (en) * 2017-09-14 2019-03-22 北京金山云网络技术有限公司 API Calls system, method, apparatus, electronic equipment and storage medium

Cited By (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111078405B (en) * 2019-12-10 2022-07-15 Oppo(重庆)智能科技有限公司 Memory allocation method and device, storage medium and electronic equipment
CN111078405A (en) * 2019-12-10 2020-04-28 Oppo(重庆)智能科技有限公司 Memory allocation method and device, storage medium and electronic equipment
CN111163097A (en) * 2019-12-31 2020-05-15 新浪网技术(中国)有限公司 Web application firewall implementation system and method
CN111614624A (en) * 2020-04-24 2020-09-01 支付宝(杭州)信息技术有限公司 Risk detection method, device, system and storage medium
CN111614624B (en) * 2020-04-24 2022-09-13 支付宝(杭州)信息技术有限公司 Risk detection method, device, system and storage medium
CN112351083A (en) * 2020-10-28 2021-02-09 武汉绿色网络信息服务有限责任公司 Service processing method and network service system
CN112351083B (en) * 2020-10-28 2023-03-24 武汉绿色网络信息服务有限责任公司 Service processing method and network service system
CN112448952A (en) * 2020-11-13 2021-03-05 北京金和网络股份有限公司 Method and device for remotely receiving and storing intelligent equipment parameters
CN112448952B (en) * 2020-11-13 2023-04-21 北京金和网络股份有限公司 Method and device for remotely receiving and storing intelligent equipment parameters
CN112822189A (en) * 2021-01-04 2021-05-18 中国电力科学研究院有限公司 Traffic identification method and device
CN112882895A (en) * 2021-02-22 2021-06-01 中国工商银行股份有限公司 Health examination method, device, computer system and readable storage medium
CN113452691A (en) * 2021-06-24 2021-09-28 未鲲(上海)科技服务有限公司 Service flow detection method and device, server and storage medium
CN113452691B (en) * 2021-06-24 2022-09-16 未鲲(上海)科技服务有限公司 Service flow detection method and device, server and storage medium
CN114095502A (en) * 2021-10-08 2022-02-25 浙江吉利控股集团有限公司 Service processing method, system, device and medium
CN114095502B (en) * 2021-10-08 2023-11-03 浙江吉利控股集团有限公司 Service processing method, system, device and medium
CN114157503A (en) * 2021-12-08 2022-03-08 北京天融信网络安全技术有限公司 Access request authentication method and device, API gateway equipment and storage medium
CN114301820A (en) * 2021-12-25 2022-04-08 江苏信而泰智能装备有限公司 Test port reservation method, device, equipment and readable storage medium
CN117252676A (en) * 2023-11-20 2023-12-19 成都新希望金融信息有限公司 Service processing method, device, electronic equipment and index policy system
CN117252676B (en) * 2023-11-20 2024-02-02 成都新希望金融信息有限公司 Service processing method, device, electronic equipment and index policy system

Similar Documents

Publication Publication Date Title
CN110347501A (en) A kind of service testing method, device, storage medium and electronic equipment
Yao et al. Hybrid intrusion detection system for edge-based IIoT relying on machine-learning-aided detection
CN105022960B (en) Multiple features mobile terminal from malicious software detecting method and system based on network traffics
CN105187392B (en) Mobile terminal from malicious software detecting method and its system based on Network Access Point
CN105162626B (en) Network flow depth recognition system and recognition methods based on many-core processor
CN110224990A (en) A kind of intruding detection system based on software definition security architecture
CN107645562A (en) Data transmission processing method, device, equipment and system
CN112543176A (en) Abnormal network access detection method, device, storage medium and terminal
CN111786950A (en) Situation awareness-based network security monitoring method, device, equipment and medium
CN109299742A (en) Method, apparatus, equipment and the storage medium of automatic discovery unknown network stream
CN107291928A (en) A kind of daily record storage system and method
CN104618304B (en) Data processing method and data handling system
CN114363064B (en) Dynamic data encryption strategy system for service adaptation of Internet of things
CN106850687A (en) Method and apparatus for detecting network attack
CN107679149A (en) A kind of data processing method and server
CN111273995A (en) Safety scheduling method and system for virtual micro-isolation network
CN110493235A (en) A kind of mobile terminal from malicious software synchronization detection method based on network flow characteristic
CN114301670B (en) Terminal authentication method, device, equipment and medium based on IPV6 address
CN111343153A (en) Data packet detection method, device, server and storage medium
CN110536118A (en) A kind of data capture method, device and computer storage medium
Xiong et al. A distributed security SDN cluster architecture for smart grid based on blockchain technology
CN113129002A (en) Data processing method and equipment
CN111385293B (en) Network risk detection method and device
de la Puerta et al. Detecting malicious Android applications based on the network packets generated
CN114760216A (en) Scanning detection event determination method and device and electronic equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20191018