CN112231566A - Information pushing method, device and system and readable storage medium - Google Patents

Information pushing method, device and system and readable storage medium Download PDF

Info

Publication number
CN112231566A
CN112231566A CN202011113047.0A CN202011113047A CN112231566A CN 112231566 A CN112231566 A CN 112231566A CN 202011113047 A CN202011113047 A CN 202011113047A CN 112231566 A CN112231566 A CN 112231566A
Authority
CN
China
Prior art keywords
information
user side
website
pushed
accessed
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN202011113047.0A
Other languages
Chinese (zh)
Other versions
CN112231566B (en
Inventor
张博洋
邓金城
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Chengdu Knownsec Information Technology Co ltd
Original Assignee
Chengdu Knownsec Information Technology Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Chengdu Knownsec Information Technology Co ltd filed Critical Chengdu Knownsec Information Technology Co ltd
Priority to CN202011113047.0A priority Critical patent/CN112231566B/en
Publication of CN112231566A publication Critical patent/CN112231566A/en
Application granted granted Critical
Publication of CN112231566B publication Critical patent/CN112231566B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/953Querying, e.g. by the use of web search engines
    • G06F16/9535Search customisation based on user profiles and personalisation
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/958Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking

Abstract

The embodiment of the invention provides an information pushing method, an information pushing device, an information pushing system and a readable storage medium, and relates to the technical field of Internet. According to the information pushing method, the information pushing device, the information pushing system and the readable storage medium, after an access request of a user side is received, whether the user side is in a dynamic intercepting state or not is judged according to the access request, if the user side is in the dynamic intercepting state, the access request of the user side is intercepted, information to be pushed is obtained according to parameter information of the user side and parameter information of a website to be accessed, an intercepting page including the information to be pushed is generated according to the information to be pushed, and the intercepting page is pushed to the user side.

Description

Information pushing method, device and system and readable storage medium
Technical Field
The invention relates to the technical field of internet, in particular to an information pushing method, device and system and a readable storage medium.
Background
At present, defense of various network attacks by using a cloud-side Web Application defense (WAF) architecture has been developed into a very mature technology, but the existing cloud WAF architecture generally only performs a simple prompt after intercepting an attack behavior. And a large cloud WAF framework is usually accessed to tens of thousands of client websites, the request intercepted every day can reach hundreds of millions of orders of magnitude, and if only simple suggestive words are returned without utilizing the pages, the method is a waste of mass flow resources.
Disclosure of Invention
Based on the above research, the present invention provides an information pushing method, apparatus, system and readable storage medium to improve the above problems.
Embodiments of the invention may be implemented as follows:
in a first aspect, an embodiment of the present invention provides an information pushing method, which is applied to a WAF node, and the method includes:
receiving an access request of a user side, and judging whether the user side is in a dynamic interception state or not according to the access request;
if the mobile terminal is in the dynamic interception state, intercepting an access request of the user side, and acquiring information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
and generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
In an optional embodiment, if the state of dynamic interception is not present, the method further includes:
forwarding the access request of the user side to the website to be accessed, and receiving response information of the website to be accessed;
identifying the response information, and judging whether the response information is an inaccessible state code;
if the status code is the status code, acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
and generating a prompt page comprising the information to be pushed and prompt contents corresponding to the state codes according to the information to be pushed and the state codes, and pushing the prompt page to the user side.
In an optional embodiment, the step of identifying the response information and determining whether the response information is an inaccessible state code includes:
judging whether the website to be accessed starts prompt page information push configuration or not;
if the prompt page information pushing configuration is not started, pushing response information of the website to be accessed to the user side;
and if the prompt page information pushing configuration is started, identifying the response information, and judging whether the response information is an inaccessible state code.
In an optional embodiment, before forwarding the access request of the user side to the website to be accessed, the method further includes:
judging whether the access of the user side is attack access;
if the access request is non-attack access, forwarding the access request of the user side to the website to be accessed;
if the access is attack access, intercepting an access request of the user side, acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed, generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
In an optional embodiment, after determining that the access of the user side is an attack access, the method further includes:
judging whether the attack times of the user side in a preset time period reach a set interception threshold value or not;
if the interception threshold is reached, setting a dynamic interception mark for the user side;
and if the interception threshold value is not reached, updating the attack times of the user side.
In an optional embodiment, the step of obtaining the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed includes:
sending the parameter information of the user side and the parameter information of the website to be accessed to an information distribution platform, so that the information distribution platform obtains the information to be pushed according to the parameter information of the user side, the parameter information of the website to be accessed and a pre-stored pushing configuration parameter;
and receiving the information to be pushed sent by the information distribution platform.
In an alternative embodiment, the method further comprises:
generating an access log according to each access request of each user side;
sending the access log to the data processing platform so that the data processing platform can perform user portrait on an access user according to the access log to obtain a user portrait result;
the step of acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed comprises the following steps:
sending the parameter information of the user side and the parameter information of the website to be accessed to an information distribution platform, so that the information distribution platform sends the parameter information of the user side, the parameter information of the website to be accessed and a pre-stored push configuration parameter to the data processing platform, and the data processing platform performs information matching based on the user portrait result, the parameter information of the user side, the parameter information of the website to be accessed and the push configuration parameter to obtain an information matching result;
and receiving the information to be pushed, which is obtained by the information distribution platform according to the information matching result.
In a second aspect, an embodiment of the present invention provides an information pushing apparatus, which is applied to a WAF node, where the apparatus includes a request processing module, an information obtaining module, and an information pushing module;
the request processing module is used for receiving an access request of a user side and judging whether the user side is in a dynamic interception state or not according to the access request;
if the mobile terminal is in the dynamic interception state, the information acquisition module is used for intercepting the access request of the user side and acquiring information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
the information pushing module is used for generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
In a third aspect, an embodiment of the present invention provides an information push system, including an information distribution platform and a cloud WAF platform, where the cloud WAF platform includes at least one WAF node;
the WAF node is used for receiving an access request of a user side and judging whether the user side is in a dynamic interception state or not according to the access request; if the mobile terminal is in the dynamic intercepting state, intercepting the access request of the user side, sending the parameter information of the user side and the parameter information of the website to be accessed to the information distribution platform to obtain the information to be pushed, generating an intercepting page comprising the information to be pushed according to the information to be pushed, and pushing the intercepting page to the user side.
In a fourth aspect, an embodiment of the present invention provides a readable storage medium, where a computer program is stored, and when the computer program is executed, the information push method according to any one of the foregoing embodiments is implemented.
According to the information pushing method, the information pushing device, the information pushing system and the readable storage medium, after an access request of a user side is received, whether the user side is in a dynamic intercepting state or not is judged according to the access request, if the user side is in the dynamic intercepting state, the access request of the user side is intercepted, information to be pushed is obtained according to parameter information of the user side and parameter information of a website to be accessed, an intercepting page including the information to be pushed is generated according to the information to be pushed, and the intercepting page is pushed to the user side.
Drawings
In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings needed to be used in the embodiments will be briefly described below, it should be understood that the following drawings only illustrate some embodiments of the present invention and therefore should not be considered as limiting the scope, and for those skilled in the art, other related drawings can be obtained according to the drawings without inventive efforts.
Fig. 1 is a schematic diagram of a working principle of a cloud WAF platform according to an embodiment of the present invention.
FIG. 2 is a diagram illustrating an interception page in the prior art.
Fig. 3 is a schematic diagram of a hint page in the prior art.
Fig. 4 is a schematic structural diagram of an information pushing system according to an embodiment of the present invention.
Fig. 5 is a block diagram of a WAF node according to an embodiment of the present invention.
Fig. 6 is a flowchart illustrating an information pushing method according to an embodiment of the present invention.
Fig. 7 is another flow chart illustrating an information pushing method according to an embodiment of the present invention.
Fig. 8 is a schematic flowchart of an information pushing method according to an embodiment of the present invention.
Fig. 9 is a schematic diagram of another architecture of an information push system according to an embodiment of the present invention.
Fig. 10 is a block diagram of an information pushing apparatus according to an embodiment of the present invention.
Icon: 1-an information push system; 100-cloud WAF platform; 10-WAF node; 11-an information push device; 111-request processing module; 112-an information acquisition module; 113-an information push module; 12-a memory; 13-a processor; 14-a communication unit; 200-an information distribution platform; 300-data processing platform.
Detailed Description
In order to make the objects, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are some, but not all, embodiments of the present invention. The components of embodiments of the present invention generally described and illustrated in the figures herein may be arranged and designed in a wide variety of different configurations.
Thus, the following detailed description of the embodiments of the present invention, presented in the figures, is not intended to limit the scope of the invention, as claimed, but is merely representative of selected embodiments of the invention. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention.
It should be noted that: like reference numbers and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it need not be further defined and explained in subsequent figures.
In the description of the present invention, it should be noted that if the terms "upper", "lower", "inside", "outside", etc. indicate an orientation or a positional relationship based on that shown in the drawings or that the product of the present invention is used as it is, this is only for convenience of description and simplification of the description, and it does not indicate or imply that the device or the element referred to must have a specific orientation, be constructed in a specific orientation, and be operated, and thus should not be construed as limiting the present invention.
Furthermore, the appearances of the terms "first," "second," and the like, if any, are used solely to distinguish one from another and are not to be construed as indicating or implying relative importance.
It should be noted that the features of the embodiments of the present invention may be combined with each other without conflict.
The cloud WAF is a cloud-end Web application defense System established on the basis of a Content Delivery Network (CDN), and a user can easily realize protection of a website by only changing Domain Name System (DNS) configuration of a website Domain Name without deploying additional software programs or hardware devices.
As shown in fig. 1, a large cloud WAF architecture is composed of a plurality of WAF nodes. For normal access requests of users, the WAF node forwards the request to a website requested by the users, then returns response data of a server of the website to the users in an original way, and for various identified attack requests, the WAF node directly intercepts the requests and returns an interception page to the users.
At present, defense of various network attacks by using a cloud-side Web Application defense (WAF) architecture has been developed into an extremely mature technology, but after intercepting an attack behavior, the existing cloud WAF architecture generally only performs a simple prompt, as shown in fig. 2. On the other hand, for the suggestive page such as 404 page or 503 page returned by the client website, the WAF node will also generally return directly to the requester, as shown in fig. 3.
A large cloud WAF architecture often has access to tens of thousands of customer sites, with 404, 503 pages intercepted and returned per day on the order of hundreds of millions. If only a simple suggestive utterance is returned without utilizing such pages, it is a waste of massive traffic resources.
Based on the above research, the present embodiment provides an information pushing method, apparatus, system and readable storage medium, which push information on a page returned to a user in a cloud WAF workflow, thereby implementing effective utilization of traffic resources.
Referring to fig. 4, fig. 4 is a schematic structural diagram of an information push system 1 provided in the present embodiment. The information push system 1 provided in the present embodiment includes an information distribution platform 200 and a cloud WAF platform 100. The cloud WAF platform 100 is in communication connection with the information distribution platform 200 through a network, so as to realize data communication.
In this embodiment, the cloud WAF platform 100 includes at least one WAF node 10, and each WAF node 10 is connected to at least one website, and is configured to receive an access request of a user to the connected website, and identify the access request, so as to implement protection on the connected website.
Optionally, in this embodiment, the WAF node 10 may be an electronic device with data processing capability, and its internal structure diagram may be as shown in fig. 5, and include an information pushing apparatus 11, a memory 12, a processor 13, and a communication unit 14.
The memory 12, the processor 13 and the communication unit 14 are electrically connected to each other directly or indirectly to realize data transmission or interaction. For example, the components may be electrically connected to each other via one or more communication buses or signal lines. The memory 12 stores the information pushing apparatus 11, the information pushing apparatus 11 includes at least one software functional module which can be stored in the memory 12 in the form of software or firmware (firmware), and the processor 13 executes various functional applications and data processing by running software programs and modules stored in the memory 12, such as the information pushing apparatus 11 in the embodiment of the present invention, so as to implement the information pushing method in the embodiment of the present invention.
The Memory 12 may be, but is not limited to, a Random Access Memory (RAM), a Read Only Memory (ROM), a Programmable Read-Only Memory (PROM), an Erasable Read-Only Memory (EPROM), an electrically Erasable Read-Only Memory (EEPROM), and the like. The memory 12 is configured to store a program, and the processor 13 executes the program after receiving the execution instruction.
The processor 13 may be an integrated circuit chip having data processing capabilities. The Processor 13 may be a general-purpose Processor including a Central Processing Unit (CPU), a Network Processor (NP), and the like. The various methods, steps and logic blocks disclosed in embodiments of the present invention may be implemented or performed. A general purpose processor may be a microprocessor or the processor may be any conventional processor or the like.
Communication unit 14 is configured to establish a communication connection between WAF node 10 and other devices (such as a website server, a user terminal, and information distribution platform 200) via a network, so as to implement data transceiving operation. The network may include a wireless network or a wired network.
It is to be understood that the configuration shown in fig. 5 is merely illustrative and that WAF node 10 may include more or fewer components than shown in fig. 5 or may have a different configuration than shown in fig. 5. The components shown in fig. 5 may be implemented in hardware, software, or a combination thereof.
In this embodiment, the information distribution platform 200 may be a single physical server, or may be a server group including a plurality of physical servers for performing different data processing functions. The server group may be centralized or distributed. In some possible embodiments, if information distribution platform 200 employs a single physical server, the physical server may be assigned different logical server components based on different service functions.
Optionally, in this embodiment, the information distribution platform 200 stores information that can be pushed, and the WAF node 10 may obtain information to be pushed from the information distribution platform 200.
Referring to fig. 6 in conjunction with the implementation architectures of fig. 4 and fig. 5, fig. 6 is a schematic flow chart of the information pushing method provided in this embodiment. The method is performed by WAF node 10 shown in fig. 4 and described in detail below with respect to the flowchart shown in fig. 6.
Step S10: and receiving an access request of a user side.
Step S20: and judging whether the user side is in a dynamic interception state or not according to the access request.
If the state is the dynamic interception state, step S30 is executed.
Step S30: intercepting an access request of a user side, and acquiring information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed.
Step S40: and generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
If a certain user side is in a dynamic interception state, it indicates that the access request of the user side has a risk and needs to be intercepted, and therefore, after the user side is determined to be in the dynamic interception state, the access request of the user side is intercepted, and an interception page is returned to the user side.
In order to improve the utilization rate of the interception page, that is, the utilization rate of the traffic resource, in this embodiment, after an access request of a user side is intercepted, information to be pushed is obtained from the information distribution platform according to parameter information of the user side and parameter information of a website to be accessed. After the information to be pushed is obtained, an interception page including the information to be pushed is generated according to the information to be pushed, namely, the information to be pushed is configured on the interception page, and then the interception page is pushed to the user side.
The information pushing method provided by the embodiment can realize effective utilization of traffic resources and avoid waste of the traffic resources by pushing information on the interception page.
Optionally, in this embodiment, the access request of the user end includes an IP address of the user end and an IP address of the website to be accessed, and after receiving the access request of the user end, the WAF node may determine whether the IP address of the user end is provided with a dynamic interception flag according to the access request, and if the IP address of the user end is provided with the dynamic interception flag, determine that the user end is in a dynamic interception state. If the dynamic interception mark is not set, the access request of the user side can be forwarded to the website to be accessed.
Optionally, in order to improve the protection of the WAF node against the website access, please refer to fig. 7, in this embodiment, before forwarding the access request of the user end to the website to be accessed, the access of the user end needs to be identified, and the step may include step S21.
Step S21: and judging whether the access of the user side is attack access or not.
If the access is a non-attack access, step S50 is executed. If the access is an attack access, the steps S30 to S40 are performed.
Step S50: and forwarding the access request of the user side to the website to be accessed.
If the access request of the user side is judged to be not in the dynamic interception state, analyzing the access request of the user side, judging whether the access request has the characteristic information of attack access, if so, judging that the access of the user is the attack access, intercepting the access request of the user side, and acquiring the information to be pushed from the information distribution platform according to the parameter information of the user side and the parameter information of the website to be accessed. After the information to be pushed is obtained, an interception page including the information to be pushed is generated according to the information to be pushed, and then the interception page is pushed to the user side, so that the effective utilization of flow resources is realized, and the waste of the flow resources is avoided.
Optionally, in order to improve the processing efficiency of the WAF node, in this embodiment, after determining that the access of the user side is an attack access, the method further includes:
and judging whether the attack times of the user terminal in a preset time period reach a set interception threshold value or not.
And if the interception threshold is reached, setting a dynamic interception mark for the user side. And if the interception threshold value is not reached, updating the attack times of the user side.
After the access of the user side is judged to be attack access, whether the attack times of the user side in a preset time period reach a set interception threshold value or not is judged, if the attack times reach the set interception threshold value, a dynamic interception mark is set for the user side, namely the dynamic interception mark is set for an IP address of the user side, and if the attack times do not reach the interception threshold value, the attack times of the user side are updated, namely the original attack access times of the user side are added by 1.
It should be noted that after the dynamic interception flag is set for the IP address of the user side, that is, after the dynamic interception is started for the IP address of the user side, the access request of the user side is intercepted within a set time period, and each access of the user side is pushed in the set time period, for example, if the attack frequency of the user side within a preset time period (e.g., 5 minutes) reaches a set interception threshold, all the access requests of the user side within the next set time period (e.g., 10 minutes) are intercepted. And after the set time period is exceeded, the access times (attack times) of the user side are cleared, and then the access request of the user side is identified again, so that the processing efficiency of the WAF node can be effectively improved.
It can be understood that, if the access request does not have the characteristic information of the attack access, it is determined that the access of the user side is the non-attack access, and then the access request of the user side is forwarded to the website to be accessed.
In practical application, after the access request is forwarded to the website to be accessed, the website server may not return the corresponding access content and only return the page that cannot be accessed for some reasons. Therefore, in order to further improve the utilization rate of the traffic resource, please refer to fig. 8, in this embodiment, after forwarding the access request of the user terminal to the website to be accessed if the user terminal is not in the dynamic interception state, the information pushing method provided in this embodiment further includes steps S60 to S90.
Step S60: and receiving response information of the website to be accessed.
Step S70: and identifying the response information and judging whether the response information is an inaccessible state code.
If the status code is not the inaccessible status code, the step S80 is executed, and if the response information is not the inaccessible status code, the step S90 is executed.
Step S80: the method comprises the steps of obtaining information to be pushed according to parameter information of a user side and parameter information of a website to be accessed, generating a prompt page comprising the information to be pushed and prompt contents corresponding to state codes according to the information to be pushed and the state codes, and pushing the prompt page to the user side.
Step S90: and pushing the response information to the user terminal.
If the response information is the inaccessible state code, the response information indicates that the access content corresponding to the access request cannot be acquired from the website server. If the response message is not the inaccessible status code, the response message indicates that the content requested by the user side is returned by the website server, and therefore the response message can be directly pushed to the user side.
Optionally, in this embodiment, the inaccessible state code includes a 404 state code and a 503 state code, and when the inaccessible state code is the 404 state code, it indicates that the resource requested by the user does not exist, and the corresponding resource cannot be found. When the inaccessible status code is 503 status code, it means that the request from the user end causes service error to the web server, and the service cannot be provided normally.
In this embodiment, if it is determined that the obtained response information is the inaccessible status code, the information to be pushed is obtained from the information distribution platform according to the parameter information of the user side and the parameter information of the website to be accessed. After the information to be pushed is obtained, a prompt page including the information to be pushed and prompt contents corresponding to the status codes is generated according to the information to be pushed and the status codes, that is, the information to be pushed and the prompt contents corresponding to the status codes are configured on the prompt page, and then the prompt page is pushed to the user side.
For example, when the response information is the 404 state code, the returned prompt page includes the information to be pushed and the prompt content corresponding to the 404 state code, that is, the corresponding resource cannot be found. For another example, when the response information is the 503 status code, the returned prompt page includes the information to be pushed and the prompt content corresponding to the 503 status code, that is, the service cannot be normally provided.
In practical use, some websites may not open the page information pushing configuration, so in this embodiment, the step of identifying the response information and determining whether the response information is an inaccessible state code may further include:
and judging whether the website to be accessed starts prompt page information push configuration or not.
And if the prompt page information pushing configuration is not started, pushing response information of the website to be accessed to the user side.
And if the prompt page information pushing configuration is started, identifying the response information and judging whether the response information is the inaccessible state code.
If the prompt page information pushing configuration is not started in the website to be accessed, the response information of the website to be accessed is directly pushed to the user side, and even if the response information is the inaccessible state code, the information does not need to be pushed on the inaccessible page returned to the user side. If the website to be accessed is started with prompt page information pushing configuration, identifying response information, judging whether the response information is an inaccessible state code, acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed when the response information is the inaccessible state code, generating a prompt page comprising the information to be pushed and prompt contents corresponding to the state code according to the information to be pushed and the state code, and pushing the prompt page to the user side.
Optionally, in this embodiment, the step of determining whether the website to be accessed starts the prompt page information push configuration may include:
and judging whether the website to be accessed is started 404 page information pushing configuration and/or 503 page information pushing configuration.
If the website to be accessed only starts 404 page information pushing configuration, the information to be pushed is acquired according to the parameter information of the user side and the parameter information of the website to be accessed only when the response information is 404 state codes, a prompt page comprising the information to be pushed and prompt contents corresponding to the 404 state codes is generated according to the information to be pushed and the 404 state codes, and then the prompt page is pushed to the user side.
If the website to be accessed only starts 503 page information pushing configuration, the information to be pushed is obtained according to the parameter information of the user side and the parameter information of the website to be accessed only when the response information is 503 state codes, a prompt page comprising the information to be pushed and prompt contents corresponding to the 503 state codes is generated according to the information to be pushed and the 503 state codes, and then the prompt page is pushed to the user side.
If the website to be accessed simultaneously starts 404 page information pushing configuration and 503 page information pushing configuration, when the response information is 404 state code or 503 state code, acquiring the information to be pushed according to the parameter information of the user terminal and the parameter information of the website to be accessed, generating a prompt page comprising the information to be pushed and prompt content corresponding to the state code according to the information to be pushed and the state code, and then pushing the prompt page to the user terminal.
Optionally, in this embodiment, after determining that the user side is in a dynamic interception state and intercepting an access request of the user side, the WAF node may also determine whether the website to be accessed starts interception page information push configuration, if the website to be accessed does not start interception page information push configuration, directly return an interception page including only interception information to the user side, and if the interception page information push configuration is started, obtain information to be pushed according to parameter information of the user side and parameter information of the website to be accessed, then generate an interception page including the information to be pushed according to the information to be pushed, and push the interception page to the user side.
It should be noted that, in this embodiment, when each website accesses the cloud WAF platform, whether to start the intercepting page information pushing configuration and the prompting page information pushing configuration may be autonomously selected. The access process can be as follows:
after a website is accessed to a cloud WAF platform, whether to start an information pushing function or not can be selected, if the information pushing function is not selected to be started, the cloud WAF platform only starts a WAF defense function on the website, and if the information pushing function is selected to be started, the website can independently select whether to start an interception page information pushing configuration and a prompt page information pushing configuration or not. The prompt page information pushing configuration comprises 404 page information pushing configuration and 503 page information pushing configuration, and the website can independently select to start 404 page information pushing configuration and/or 503 page information pushing configuration.
After the website starts the information pushing configuration of the interception page, the access request of the user side can be intercepted, the information to be pushed is obtained according to the parameter information of the user side and the parameter information of the website to be accessed, the interception page comprising the information to be pushed is generated according to the information to be pushed, and the interception page is pushed to the user side.
After the website starts the prompt page information pushing configuration, when the response information is the inaccessible state code, the information to be pushed is acquired according to the parameter information of the user side and the parameter information of the website to be accessed, then a prompt page comprising the information to be pushed and prompt content corresponding to the state code is generated according to the information to be pushed and the state code, and the prompt page is pushed to the user side.
The information pushing method provided by this embodiment performs pushing of information by configuring information to be pushed on the interception page and/or the prompt page, thereby implementing effective utilization of traffic resources.
Optionally, in this embodiment, the step of obtaining the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed includes:
and sending the parameter information of the user side and the parameter information of the website to be accessed to the information distribution platform, so that the information distribution platform obtains the information to be pushed according to the parameter information of the user side, the parameter information of the website to be accessed and the pre-stored push configuration parameters.
And receiving the information to be pushed sent by the information distribution platform.
The information distribution platform receives the parameter information of the user side and the parameter information of the website to be accessed, and then the information distribution platform can obtain the information to be pushed according to the parameter information of the user side, the parameter information of the website to be accessed and the prestored pushing configuration parameters.
Optionally, in this embodiment, the parameter information of the ue may include an IP address of the ue and a type of the ue. The type of the user terminal may include device types such as a mobile terminal, a Personal Computer (PC), a wearable device, an in-vehicle device, an Augmented Reality (AR)/Virtual Reality (VR) device, and the like. The parameter information of the website to be visited may include a type and an IP address of the website to be visited, and the type of the website to be visited may include a video website, a social website, and the like.
Optionally, in this embodiment, the push configuration parameter may be, but is not limited to, the level of the user group and the pushable information corresponding to each level, the information that each website and each website can push, and the priority of the website accessing the cloud WAF platform and the pushable information corresponding to each level.
When the push configuration parameters are the levels of the user groups and the pushable information corresponding to each level, after the information distribution platform receives the parameter information of the user side and the parameter information of the website to be accessed, the level of the access user corresponding to the user side can be obtained according to the parameter information of the user side, and then the information to be pushed is obtained based on the levels of the access user and the pushable information corresponding to the levels.
For example, after receiving the parameter information of the user side, the information distribution platform may obtain the access preference of the access user corresponding to the user side according to the IP address of the user side, then obtain the rank of the access user according to the access preference of the access user, and after obtaining the rank of the access user, may screen out information adapted to the type of the user side, that is, information to be pushed, from the rank. For example, if the access preference of the access user is music video, the level of the access user is music level, information adapted to the type of the user side can be screened from the pushable information corresponding to the music level, and the screened information is information to be pushed.
When the push configuration parameters are information which can be pushed by each website and each website, after the information distribution platform receives the parameter information of the user side and the parameter information of the website to be accessed, the information which can be pushed by the website to be accessed can be determined and obtained according to the parameter information of the website to be accessed, and then the information to be pushed is obtained. For example, after receiving the parameter information of the user side and the parameter information of the website to be accessed, the information distribution platform may determine to obtain the information that can be pushed by the website to be accessed according to the IP address of the website to be accessed, and then select one or more pieces of information from the information as the information to be pushed.
When the push configuration parameter is the priority of the website accessed to the cloud WAF platform and the pushable information corresponding to each level, after the information distribution platform receives the parameter information of the client and the parameter information of the website to be accessed, the level of the website to be accessed can be determined according to the parameter information of the website to be accessed, and then the information to be pushed is obtained according to the pushable information corresponding to the level.
For example, after receiving the parameter information of the user side and the parameter information of the website to be accessed, the information distribution platform may determine to obtain the level of the website to be accessed according to the IP address and the type of the website to be accessed, then obtain the pushable information corresponding to the level, and select one or more pieces of information from the pushable information as the information to be pushed.
After the information to be pushed is obtained, the information distribution platform can send the information to be pushed to the WAF node, and after the WAF node receives the information to be pushed, the WAF node can generate an interception page or a prompt page including the information to be pushed according to the information to be pushed, and then pushes the generated interception page or the prompt page including the information to be pushed to a user side, so that the information is put in, and the utilization rate of flow resources is improved.
It should be noted that, in this embodiment, the information stored in the information distribution platform may be input by an information input owner, and the information input owner may set the push configuration parameters after inputting the information to the information distribution platform. In addition, after the information delivery owner delivers the information to the information distribution platform, the information delivery website, the industry of the information delivery website, the user group for delivery and the like can be preferentially designated.
Optionally, in this embodiment, the information may be, but is not limited to, advertisement information, news information, and the like, and may be in the form of, but is not limited to, video, photos, text, and the like.
In order to ensure the cooperation of the website, the cloud WAF platform and the information distribution platform, the win-win situation of multi-party cooperation is realized. Optionally, in this embodiment, after the information delivery owner puts in the information, a certain amount of money can be paid for the information, and then the cloud WAF platform can allocate the amount of money with each accessed website according to a set proportion, so that the cloud WAF platform can obtain additional income with each accessed website, and the experience and the enthusiasm of the website, the cloud WAF platform, and the information distribution platform are improved.
As an alternative implementation, each website may also calculate the benefit of information push according to the number of times of information push, and after calculating the benefit of each website, pay the amount to each website according to the benefit of each website.
According to the information pushing method provided by the embodiment, the information is pushed on the interception page and the prompt page, so that the reasonable utilization of the traffic resource is realized, and the defense of the cloud WAF platform to the website and the normal operation content of the website are not influenced.
Because the current flow resources mastered by internet enterprises mainly come from users using internet products in the enterprises, the objects for information delivery have certain closure regardless of the size of the user group, such as users only watching kuku videos, users only browsing news of new seas, and the like. Therefore, the information delivery owner must carefully choose the information delivery platform to find a delivery channel suitable for the product.
In order to achieve the accuracy of information pushing, as shown in fig. 9, the information pushing system 1 provided in this embodiment may further include a data processing platform 300, and the information pushing method provided in this embodiment further includes:
and generating an access log according to each access request of each user side.
And sending the access log to a data processing platform so that the data processing platform can perform user portrait on the access user according to the access log to obtain a user portrait result.
The step of obtaining the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed comprises the following steps:
the parameter information of the user side and the parameter information of the website to be accessed are sent to the information distribution platform, so that the information distribution platform sends the parameter information of the user side, the parameter information of the website to be accessed and the pre-stored push configuration parameters to the data processing platform, and the data processing platform performs information matching based on the user portrait result, the parameter information of the user side, the parameter information of the website to be accessed and the push configuration parameters to obtain an information matching result.
And receiving the information to be pushed, which is obtained by the information distribution platform according to the information matching result.
Optionally, in this embodiment, the data processing platform 300 may be a single physical server, or may be a server group composed of a plurality of physical servers for performing different data processing functions. The server group may be centralized or distributed. In some possible embodiments, if data processing platform 300 employs a single physical server, different logical server components may be assigned to the physical server based on different data processing functions.
In this embodiment, after receiving each access request of each user, each WAF node generates an access log according to each access request of each user, and then sends the access log to the data processing platform for data processing. The access log includes the IP address of the user end, the access requirement, and the attribute information (such as gender and age) of the user.
Optionally, in this embodiment, the data processing platform 300 builds a recommendation system for user portrait, so that after receiving the access log sent by each WAF node 10, the data processing platform 300 performs user portrait on the access user according to the received access log, and obtains a result of the user portrait. The information overview of the access user can be described in all directions according to the user portrait result, and the requirement of the access user is dug out deeply, so that the information is pushed based on the user portrait result, and the accuracy of information pushing can be effectively improved.
After receiving the parameter information of the user end and the parameter information of the website to be accessed, which are sent by the WAF node, the information distribution platform sends the parameter information of the user end, the parameter information of the website to be accessed and the pre-stored push configuration parameters to the data processing platform, and the data processing platform performs information matching according to the parameter information of the user end, the parameter information of the website to be accessed, the push configuration parameters and the pre-obtained user image result to obtain an information matching result. And after the information matching result is obtained, the information matching result is sent to the information distribution platform, and the information distribution platform sends the information to be pushed to the WAF node according to the information matching result.
The information matching result represents the type of the information which can be pushed or the specific information which can be pushed and corresponds to the user side. After the information distribution platform receives the information matching result, the information to be pushed can be obtained by screening from the pre-stored information according to the information matching result, after the information to be pushed is obtained, the information to be pushed can be pushed to the WAF node, the WAF node generates an interception page or a prompt page comprising the information to be pushed, and then the interception page or the prompt page is pushed to the user side, so that the information is pushed and the effective utilization of flow resources is realized.
The information pushing method provided by the embodiment provides data support for the user portrait function of the data processing platform based on the diversity of the user groups corresponding to the cloud WAF, and can effectively improve the accuracy of information pushing based on the user portrait result, the parameter information of the user side, the parameter information of the website to be accessed and the pre-stored pushing configuration parameter pushing information.
Based on the same inventive concept, please refer to fig. 10 in combination, the present embodiment further provides an information pushing apparatus 11, which is applied to the WAF node 10, and the information pushing apparatus 11 includes a request processing module 111, an information obtaining module 112, and an information pushing module 113.
The request processing module 111 is configured to receive an access request from a user side, and determine whether the user side is in a dynamic interception state according to the access request.
If the website is in the dynamic intercepting state, the information obtaining module 112 is configured to intercept the access request of the user side, and obtain information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed.
The information pushing module 113 is configured to generate an interception page including information to be pushed according to the information to be pushed, and push the interception page to the user side.
It can be clearly understood by those skilled in the art that, in the present embodiment, the request processing module 111, the information obtaining module 112, and the information pushing module 113 may execute corresponding steps of the information pushing method, and for convenience and simplicity of description, the specific working process of the above-described device may refer to the corresponding process in the foregoing method, and will not be described in detail herein.
On the basis, as shown in fig. 9, the present embodiment further provides an information pushing system 1, which includes an information distribution platform 200 and a cloud WAF platform 100, where the cloud WAF platform 100 includes at least one WAF node 10.
The WAF node 10 is configured to receive an access request of a user, and determine whether the user is in a dynamic interception state according to the access request; if the website is in the dynamic intercepting state, intercepting an access request of a user side, sending parameter information of the user side and parameter information of a website to be accessed to the information distribution platform 200 to obtain information to be pushed, generating an intercepting page comprising the information to be pushed according to the information to be pushed, and pushing the intercepting page to the user side.
Optionally, the information pushing system 1 provided in this embodiment may further include a data processing platform 300, and the role of the data processing platform 300 may refer to the corresponding description in the information pushing method.
It can be clearly understood by those skilled in the art that, for convenience and brevity of description, the specific working process of the information pushing system 1 may refer to the corresponding process in the foregoing method, and will not be described in detail herein.
On the basis of the above, the present embodiment also provides a readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the steps in the above-described method embodiments.
It is clear to those skilled in the art that, for convenience and brevity of description, the specific working process of the readable storage medium described above may refer to the corresponding process in the foregoing method, and will not be described in detail herein.
In summary, the information pushing method, apparatus, system, and readable storage medium provided in the embodiments of the present invention push information on the interception page and the prompt page returned to the user in the cloud WAF workflow, so that not only is effective utilization of traffic resources achieved, but also the defense of the cloud WAF platform against each website is not affected, and the normal operation of each website is not affected.
Meanwhile, based on the diversity of the cloud WAF corresponding user groups, data support is provided for the user portrait function of the data processing platform, each access user can be effectively and accurately positioned, the information pushing precision is improved, and selectivity and convenience are provided for the information delivery main delivery.
The above description is only for the specific embodiment of the present invention, but the scope of the present invention is not limited thereto, and any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope of the present invention are included in the scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the appended claims.

Claims (10)

1. An information pushing method applied to a WAF node, the method comprising:
receiving an access request of a user side, and judging whether the user side is in a dynamic interception state or not according to the access request;
if the mobile terminal is in the dynamic interception state, intercepting an access request of the user side, and acquiring information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
and generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
2. The information pushing method according to claim 1, wherein if the state of dynamic interception is not maintained, the method further comprises:
forwarding the access request of the user side to the website to be accessed, and receiving response information of the website to be accessed;
identifying the response information, and judging whether the response information is an inaccessible state code;
if the status code is the status code, acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
and generating a prompt page comprising the information to be pushed and prompt contents corresponding to the state codes according to the information to be pushed and the state codes, and pushing the prompt page to the user side.
3. The information pushing method according to claim 2, wherein the step of identifying the response information and determining whether the response information is an inaccessible status code comprises:
judging whether the website to be accessed starts prompt page information push configuration or not;
if the prompt page information pushing configuration is not started, pushing response information of the website to be accessed to the user side;
and if the prompt page information pushing configuration is started, identifying the response information, and judging whether the response information is an inaccessible state code.
4. The information pushing method according to claim 2, wherein before forwarding the access request from the user side to the website to be accessed, the method further comprises:
judging whether the access of the user side is attack access;
if the access request is non-attack access, forwarding the access request of the user side to the website to be accessed;
if the access is attack access, intercepting an access request of the user side, acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed, generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
5. The information pushing method according to claim 4, wherein after determining that the access of the user side is an attack access, the method further comprises:
judging whether the attack times of the user side in a preset time period reach a set interception threshold value or not;
if the interception threshold is reached, setting a dynamic interception mark for the user side;
and if the interception threshold value is not reached, updating the attack times of the user side.
6. The information push method according to any one of claims 1 to 5, wherein the step of obtaining the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed includes:
sending the parameter information of the user side and the parameter information of the website to be accessed to an information distribution platform, so that the information distribution platform obtains the information to be pushed according to the parameter information of the user side, the parameter information of the website to be accessed and a pre-stored pushing configuration parameter;
and receiving the information to be pushed sent by the information distribution platform.
7. The information pushing method according to any one of claims 1 to 5, wherein the method further comprises:
generating an access log according to each access request of each user side;
sending the access log to a data processing platform so that the data processing platform can perform user portrait on an access user according to the access log to obtain a user portrait result;
the step of acquiring the information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed comprises the following steps:
sending the parameter information of the user side and the parameter information of the website to be accessed to an information distribution platform, so that the information distribution platform sends the parameter information of the user side, the parameter information of the website to be accessed and a pre-stored push configuration parameter to the data processing platform, and the data processing platform performs information matching based on the user portrait result, the parameter information of the user side, the parameter information of the website to be accessed and the push configuration parameter to obtain an information matching result;
and receiving the information to be pushed, which is obtained by the information distribution platform according to the information matching result.
8. An information pushing device is applied to a WAF node and comprises a request processing module, an information acquisition module and an information pushing module;
the request processing module is used for receiving an access request of a user side and judging whether the user side is in a dynamic interception state or not according to the access request;
if the mobile terminal is in the dynamic interception state, the information acquisition module is used for intercepting the access request of the user side and acquiring information to be pushed according to the parameter information of the user side and the parameter information of the website to be accessed;
the information pushing module is used for generating an interception page comprising the information to be pushed according to the information to be pushed, and pushing the interception page to the user side.
9. An information pushing system is characterized by comprising an information distribution platform and a cloud WAF platform, wherein the cloud WAF platform comprises at least one WAF node;
the WAF node is used for receiving an access request of a user side and judging whether the user side is in a dynamic interception state or not according to the access request; if the mobile terminal is in the dynamic intercepting state, intercepting the access request of the user side, sending the parameter information of the user side and the parameter information of the website to be accessed to the information distribution platform to obtain the information to be pushed, generating an intercepting page comprising the information to be pushed according to the information to be pushed, and pushing the intercepting page to the user side.
10. A readable storage medium, characterized in that a computer program is stored in the readable storage medium, and when executed, the computer program implements the information pushing method according to any one of claims 1 to 7.
CN202011113047.0A 2020-10-16 2020-10-16 Information pushing method, device, system and readable storage medium Active CN112231566B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202011113047.0A CN112231566B (en) 2020-10-16 2020-10-16 Information pushing method, device, system and readable storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202011113047.0A CN112231566B (en) 2020-10-16 2020-10-16 Information pushing method, device, system and readable storage medium

Publications (2)

Publication Number Publication Date
CN112231566A true CN112231566A (en) 2021-01-15
CN112231566B CN112231566B (en) 2023-11-28

Family

ID=74118564

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202011113047.0A Active CN112231566B (en) 2020-10-16 2020-10-16 Information pushing method, device, system and readable storage medium

Country Status (1)

Country Link
CN (1) CN112231566B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114816826A (en) * 2022-06-28 2022-07-29 杭银消费金融股份有限公司 Push defect identification method and device of application system

Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050055400A1 (en) * 2003-09-09 2005-03-10 Eric Goutard Method of inserting thematic filtering information pertaining to HTML pages and corresponding system
JP2005267014A (en) * 2004-03-17 2005-09-29 Vodafone Kk Server device
US20090265471A1 (en) * 2007-07-24 2009-10-22 Huawei Technologies Co., Ltd. Method, system, server and terminal for processing message
CN102761554A (en) * 2012-07-24 2012-10-31 北京亿赞普网络技术有限公司 Method, device and system for pushing information to client
CN103620576A (en) * 2010-11-01 2014-03-05 七网络公司 Caching adapted for mobile application behavior and network conditions
CN105939313A (en) * 2015-09-01 2016-09-14 杭州迪普科技有限公司 State code redirecting method and device
CN106302100A (en) * 2015-06-12 2017-01-04 中兴通讯股份有限公司 Information push method and device
CN106911757A (en) * 2015-12-23 2017-06-30 阿里巴巴集团控股有限公司 The method for pushing and device of a kind of business information
CN107977857A (en) * 2017-11-14 2018-05-01 上海斐讯数据通信技术有限公司 A kind of advertisement sending method and system
US20190372959A1 (en) * 2018-05-30 2019-12-05 Oracle International Corporation Techniques for authentication using push notifications

Patent Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050055400A1 (en) * 2003-09-09 2005-03-10 Eric Goutard Method of inserting thematic filtering information pertaining to HTML pages and corresponding system
JP2005267014A (en) * 2004-03-17 2005-09-29 Vodafone Kk Server device
US20090265471A1 (en) * 2007-07-24 2009-10-22 Huawei Technologies Co., Ltd. Method, system, server and terminal for processing message
CN103620576A (en) * 2010-11-01 2014-03-05 七网络公司 Caching adapted for mobile application behavior and network conditions
CN102761554A (en) * 2012-07-24 2012-10-31 北京亿赞普网络技术有限公司 Method, device and system for pushing information to client
CN106302100A (en) * 2015-06-12 2017-01-04 中兴通讯股份有限公司 Information push method and device
CN105939313A (en) * 2015-09-01 2016-09-14 杭州迪普科技有限公司 State code redirecting method and device
CN106911757A (en) * 2015-12-23 2017-06-30 阿里巴巴集团控股有限公司 The method for pushing and device of a kind of business information
CN107977857A (en) * 2017-11-14 2018-05-01 上海斐讯数据通信技术有限公司 A kind of advertisement sending method and system
US20190372959A1 (en) * 2018-05-30 2019-12-05 Oracle International Corporation Techniques for authentication using push notifications

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
CARSTEN BORMANN等: "CoAP: An Application Protocol for Billions of Tiny Internet Nodes", 《IEEE INTERNET COMPUTING》, vol. 16, no. 2, pages 62 - 67, XP011428692, DOI: 10.1109/MIC.2012.29 *
张森炜: "基于openwrt的远程控制wifi路由器系统设计与实现", 《中国优秀硕士学位论文全文数据库信息科技辑》, no. 11, pages 136 - 339 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114816826A (en) * 2022-06-28 2022-07-29 杭银消费金融股份有限公司 Push defect identification method and device of application system
CN114816826B (en) * 2022-06-28 2022-09-23 杭银消费金融股份有限公司 Push defect identification method and device of application system

Also Published As

Publication number Publication date
CN112231566B (en) 2023-11-28

Similar Documents

Publication Publication Date Title
US11546418B2 (en) Method, client, server, and system for sharing content
CN106933871B (en) Short link processing method and device and short link server
CN107786621B (en) User information management method, access processing method, device and system
US20180309802A1 (en) Infinite micro-services architecture
Wishart et al. SuperstringRep: reputation-enhanced service discovery
CN102904765B (en) The method and apparatus that data report
CN110572390A (en) Method, device, computer equipment and storage medium for detecting domain name hijacking
CN107239701B (en) Method and device for identifying malicious website
CN108683668A (en) Resource checksum method, apparatus, storage medium and equipment in content distributing network
CN107347015B (en) Method, device and system for identifying content distribution network
JP2021516381A (en) Enhanced online privacy
CN109086158B (en) Abnormal cause analysis method and device and server
CN114153581A (en) Data processing method, data processing device, computer equipment and storage medium
CN111459658A (en) Resource data acquisition method and related equipment
CN112866062B (en) Distributed pressure test system, method, device, equipment and storage medium
CN112231566B (en) Information pushing method, device, system and readable storage medium
CN114039961A (en) Message pushing method, device, server and storage medium based on WebSocket
US7533414B1 (en) Detecting system abuse
CN110933070A (en) User identification method, system, equipment and computer readable storage medium
CN116776030A (en) Gray release method, device, computer equipment and storage medium
CN111262779A (en) Method, device, server and system for acquiring data in instant messaging
CN111209325A (en) Service system interface identification method, device and storage medium
CN108737350B (en) Information processing method and client
CN113596105B (en) Content acquisition method, edge node and computer readable storage medium
CN112035760B (en) Task allocation method and computer equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant