WO2012142938A1 - 一种保证用户网络安全性的方法及客户端 - Google Patents

一种保证用户网络安全性的方法及客户端 Download PDF

Info

Publication number
WO2012142938A1
WO2012142938A1 PCT/CN2012/074191 CN2012074191W WO2012142938A1 WO 2012142938 A1 WO2012142938 A1 WO 2012142938A1 CN 2012074191 W CN2012074191 W CN 2012074191W WO 2012142938 A1 WO2012142938 A1 WO 2012142938A1
Authority
WO
WIPO (PCT)
Prior art keywords
payment
executable file
login
monitoring
preset
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2012/074191
Other languages
English (en)
French (fr)
Inventor
陈宁一
郑文彬
肖鹏
朱翼鹏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Qihoo Technology Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Priority to US14/112,059 priority Critical patent/US20140317733A1/en
Publication of WO2012142938A1 publication Critical patent/WO2012142938A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction

Definitions

  • the present application relates to the field of computer network technologies, and in particular, to a method and a client for ensuring user network security. Background technique
  • the embodiment of the present application provides a method and a client for ensuring user network security, so as to solve the problem that user information is easily stolen in the existing network payment process, resulting in low network security.
  • a method for ensuring user network security including:
  • the user's login process or payment process is security monitored according to a preset security policy, so that when the unsafe event is monitored, the user is prompted or blocked. The execution of security incidents.
  • the monitoring whether the user opens the login operation mode or the payment operation mode through the client includes: It is tested whether the user opens the login operation mode or the payment operation mode through the client browser.
  • the security monitoring of the login process or the payment process of the user according to the preset security policy includes at least one of the following methods:
  • the monitoring of the dangerous process in the login process or the payment process by using the preset process list includes:
  • the current process Acquiring the current process that is started in the login process or the payment process, and when the current process is found in the preset blacklist, the current process is determined to be a dangerous process, where the The blacklist list is used to save the identified dangerous processes that are threatening the system.
  • the monitoring the executable file transmitted during the login process or the payment process includes: when detecting that the client is ready to receive the executable file, or during receiving the executable file, or receiving the executable file, Determine if the executable is a suspicious file by looking up a list of preset executables.
  • the determining, by searching for a preset executable file list, whether the executable file is a suspicious file includes:
  • the executable file is determined as a suspicious file, wherein the preset white list is used to save all the secure executable files;
  • the executable file When the executable file is found in the preset blacklist, the executable file is determined as a suspicious file, wherein the preset blacklist is used to save all dangerous executable files.
  • the monitoring of the executable file transmitted during the login process or the payment process includes: When it is detected that the client receives the executable file, extracting behavior characteristics in the executable file, determining whether the behavior feature extracted from the executable file is a pre-recorded security behavior feature, and if not, the The execution file is determined to be a file.
  • the monitoring of the browser calling behavior in the login process or the payment process includes: monitoring, by the underlying driver, a correlation function between the processes;
  • a client that includes:
  • a monitoring unit configured to monitor whether the user opens the login operation mode or the payment operation mode through the client
  • the monitoring unit is configured to: after monitoring the user to enable the login operation mode or the payment operation mode, perform security monitoring on the login process or the payment process of the user according to the preset security policy, so as to prompt the user when the unsafe event is monitored Or block the execution of the unsafe event.
  • the monitoring unit is specifically configured to monitor whether the user opens the login operation mode or the payment operation mode through the client browser.
  • the monitoring unit includes at least one of the following units:
  • An executable file monitoring unit for monitoring executable files transmitted during the login process or payment process
  • the browser invokes a monitoring unit for monitoring the browser calling behavior during the login process or payment process;
  • the input content calls a monitoring unit for monitoring the call of the keyboard input during the login process or the payment process;
  • the dangerous process monitoring unit includes at least one of the following units:
  • a whitelist intercepting unit configured to acquire a current process that is started during the login process or the payment process, and when the current process is not found in the preset whitelist list, determine the current process as a dangerous process. Pulling, wherein the preset whitelist is used to save a confirmed security process that is not threatening to the system;
  • a blacklist intercepting unit configured to acquire a current process that is started during the login process or the payment process, and when the current process is found in the preset blacklist list, determine the current process as a dangerous process
  • the preset blacklist is used to save a dangerous process that has been confirmed to be threatening to the system.
  • the executable file monitoring unit includes:
  • a first executable file monitoring unit configured to search for a preset executable file list when monitoring that the client is ready to receive the executable file, or during receiving the executable file, or when receiving the executable file, Determine if the executable is a suspicious file.
  • the first executable file monitoring unit includes:
  • a whitelist monitoring unit configured to determine the executable file as a suspicious file when the executable file is not found in the preset whitelist, where the preset whitelist is used for saving All secure executables; or,
  • a blacklist monitoring unit configured to determine the executable file as a suspicious file when the executable file is found in a preset blacklist, where the preset blacklist is used to save all Dangerous executable file.
  • the executable file monitoring unit includes:
  • a second executable file monitoring unit configured to: when detecting that the client receives the executable file, extract behavior characteristics in the executable file, and determine whether the behavior feature extracted from the executable file is a pre-recorded security behavior The feature, if not, determines the executable as a file.
  • the browser invoking monitoring unit includes:
  • a function monitoring unit configured to monitor a correlation function between processes by using an underlying driver
  • an event intercepting unit configured to intercept the corresponding function call triggered by the operation of the browser process through the remote procedure call interface Call event
  • Calling an event parsing unit configured to parse the calling event, and filtering out the event that initiates the calling event Process
  • the illegal process determining unit is configured to determine whether the process of initiating the calling event is an illegal process by searching a preset process list.
  • the user after detecting that the user starts the login operation mode or the payment operation mode, the user performs security monitoring on the login process or the payment process of the user according to a preset security policy.
  • the login process or the payment process may be securely protected through various security policies specifically for securing the login process or the payment process, and the dangerous process is adopted. Intercept, executable file prompts, and browser call monitoring to ensure network security during the login process or payment process.
  • FIG. 1 is a flowchart of a first embodiment of a method for ensuring user network security according to the present application
  • FIG. 2 is a flowchart of a second embodiment of a method for ensuring user network security according to the present application
  • FIG. 4 is a flow chart of a fourth embodiment of a method for ensuring user network security according to the present application
  • FIG. 5 is a block diagram of an embodiment of a client of the present application. detailed description
  • Step 101 Monitor whether a user opens a login operation mode or a payment operation mode through a client.
  • the embodiment of the present application can be specifically applied in the process of the user performing network payment through the client, that is, detecting whether the user opens the payment page through the client. To ensure that user information will not be vented during the payment process. Exposure, improve the security of online payments. Specifically, the user is monitored whether the login operation mode or the payment operation mode is enabled through the client browser.
  • Step 102 After monitoring the user to open the login operation mode or the payment operation mode, perform security monitoring on the login process or the payment process of the user according to the preset security policy.
  • the security policy is a security policy set in advance for the login operation mode or the payment operation mode.
  • the client can monitor the dangerous process in the login process or the payment process through a preset process list; or monitor the executable file transmitted during the login process or the payment process through a preset list of secure executable files; or Monitor the browser calling behavior during the login process or payment process; or monitor the call of the keyboard input during the login process or payment process; or monitor the data objects transmitted by the client during the login process or payment process, for example,
  • the transmitted data object should be intercepted; or the web page opened during the login process or payment process can be monitored, for example
  • the payment page that the user may open is a webpage that is forged by a malicious third party and is similar to the real payment webpage, so the opened webpage needs to be monitored.
  • FIG. 2 a flow chart of a second embodiment of a method for ensuring user network security according to the present application, which takes an online payment as an example, shows a process of monitoring a dangerous process:
  • Step 201 Monitor the operation of the user on the client.
  • Step 202 Determine, according to the monitoring result, whether the user starts online payment, and if yes, execute step 203; otherwise, return to step 201.
  • a list of payment websites can be pre-stored on the user's client.
  • the URL of the browser access page (Uniform / Univer sa Resource Locator, web address) is obtained, and the obtained URL and payment website list are obtained.
  • the payment website URL is compared. If a consistent URL is found, the user can be confirmed to have entered the payment page and start online payment.
  • Step 203 Find a preset whitelist according to the current process that is started.
  • the whitelist keeps the confirmed security processes that are not threatening to the system, so These processes can be pulled without being pulled.
  • the whitelist is usually kept locally, so the operation of finding the whitelist is also performed locally. Further, in the process of running the current process, the cloud server is connected to the cloud, and the current process is searched for by the plurality of whitelists already existing on the network.
  • Step 204 Determine whether the current process is found in the whitelist list. If not found, go to step 205; if no, go to step 206.
  • Step 205 Intercept the current process as a dangerous process.
  • the whitelist search is taken as an example to show the process of intercepting the dangerous process.
  • the blacklist list may also be preset. When the current process is found in the blacklist list, The current process is intercepted as a dangerous process; for processes that are neither whitelisted nor blacklisted, the user can be prompted to choose whether to prevent the running of these processes and prevent dangerous processes that may exist in the unknown process.
  • Step 206 Determine whether the user has finished online payment, and if yes, end the process; otherwise, return to step 203.
  • FIG. 3 is a flowchart of a third embodiment of a method for ensuring user network security according to the present application, the process of monitoring the received executable file in the process:
  • Step 301 Monitor the operation of the user on the client.
  • Step 302 Determine, according to the monitoring result, whether the user starts online payment, and if yes, perform step 303; otherwise, return to step 301.
  • the user's client can pre-save a list of payment websites.
  • the URL of the browser access page is obtained, and the obtained URL and the payment network in the payment website list are obtained.
  • the station URL is compared. If a consistent URL is found, the user can be confirmed to have entered the payment page and start online payment.
  • Step 303 Determine whether the client receives the executable file, and if yes, execute step 304; otherwise, return to step 303.
  • users may receive executable files (such as files with the suffix exe) transmitted by the third party to the user.
  • Some of these executable files are files that need to be used during the payment process, and some are malicious third parties.
  • the above-mentioned files may be transmitted to the terminal device where the user is located through the instant communication tool, the user may be downloaded to the terminal device by downloading or sharing, or transmitted to the terminal device of the user by illegal means such as hanging Trojan or virus, or The file is transferred to the terminal device where the user is located when copying the file in the mobile storage device.
  • the executable file When the executable file is detected, it can be monitored by the user's instant communication tool, browser, etc., or it can be detected in real time when the file is downloaded to the local; in addition, when the executable file is started, and after the startup, Can be detected by the system.
  • Step 304 Find a list of pre-set secure executables.
  • the size of the file, the time of the file, the MD5 information of the file, the signature of the file, etc. can be recorded in the list of secure executables.
  • the behavioral characteristics determine whether the behavioral feature extracted from the executable file satisfies the recorded security behavior characteristics, and the file that satisfies the security behavior characteristic can be confirmed as a secure executable file.
  • Step 305 Determine whether the received executable file is found in the executable file list, and if yes, execute step 306; otherwise, execute step 307.
  • Step 306 Output selection prompt information requesting the user to select whether to run the executable file.
  • Step 307 Determine whether the user has finished online payment, and if yes, end the process; otherwise, return to step 303.
  • the executable file that the client is prepared to receive, or the executable file being received may also be monitored. Specifically, when the client is detected to be ready to receive the executable file, the preset security is searched. a full list of executable files, if the executable file is not found in the executable file list, determining that the executable file is a suspicious file, and outputting a selection prompt message requesting the user to select whether to receive the executable file; When the client is in the process of receiving the executable file, it searches for a pre-set list of secure executable files.
  • FIG. 4 a flowchart of a fourth embodiment of a method for ensuring user network security according to the present application, which takes an online payment as an example, shows a process of monitoring a browser call behavior in a secure payment process:
  • Step 401 Monitor the operation of the user on the client.
  • Step 402 Determine, according to the monitoring result, whether the user starts online payment, and if yes, execute step 403; otherwise, return to step 401.
  • the user's client may pre-save a list of payment websites.
  • the URL of the browser access page is obtained, and the obtained URL is compared with the payment website URL in the payment website list, if a consistent one is found.
  • the URL confirms that the user has entered the payment page and starts paying online.
  • Step 403 Monitor the related functions of communication between processes through the underlying driver.
  • the communication function between the processes monitored by the underlying driver may include an API (Appl icating Programming Interface) function as follows: NtAlpcSendWa i tReceivePor t
  • Step 404 Determine whether the related function call triggered by the operation of the browser process by the remote procedure call interface is monitored, and if yes, execute step 405; otherwise, return to step 403.
  • a program attempts to call a related function for communication between processes
  • the interface of the browser process is operated through a remote procedure call interface (for example, a COM interface)
  • a remote procedure call interface for example, a COM interface
  • Step 405 intercept the corresponding call event, and parse the call event, and filter out the call to initiate the event. The process of the piece.
  • the intercepted call event is the event called to the function.
  • the function call is a function called during RPC (Remote Procedure Call).
  • the calling function is parsed.
  • the parsed call function is NtRequestWaitReplyPort
  • the parsed correlation function can include RequestMessage, PortHandle, and so on.
  • the A process When filtering the function call triggered by the operation of the browser process through the remote procedure call interface, for example, the A process tries to operate the browser process B to jump to the malicious website C, and reaches the online shopping process of hijacking online payment, then the A process Will connect to the remote procedure call interface of browser process B, and generate a port handle (PortHandle), and then encapsulate the call sequence number and jump URL information to be called into the parameter Reques tMessage of the function NtRequestWaitRe lyPort, RequestMessage is a cache address, Finally, the NtRequestWaitReplyPort API function is called, and the jump request is sent to the remote process call port of the browser process B to implement the jump control process.
  • PortHandle port handle
  • the call sequence number and the jump URL of the called function are parsed and restored from the cache of the parameter RequestMessage, and the information is recognized as an operation browser call event, and the trigger is obtained.
  • the browser invokes the A process of the event.
  • Step 406 Find a list of processes set in advance.
  • the process ID, execution path, file information of the corresponding file, and the like of the process can be obtained.
  • the corresponding file is obtained according to the execution path, and the summary of the file is calculated, and the hash information representing the uniqueness of the file is obtained.
  • the process list can be whitelisted or blacklisted. If the whitelisted hash information is compared with the hash information in the whitelist, if there is consistent hash information, the obtained process is a secure process, and no truncation is performed; if there is still a blacklist, The process matching the hash information in the blacklist is intercepted and an alarm is issued; for the process corresponding to the hash information that is neither in the whitelist nor the blacklist, the interception may be performed and the user may be prompted.
  • Step 407 Determine whether the process is an illegal process according to the search result. If yes, go to step 408; otherwise, go to step 409.
  • Step 408 Reject the invocation event.
  • Step 409 Determine whether the user has ended the online payment, and if yes, end the process; otherwise, Go back to step 403.
  • the payment process can be securely protected by various security policies, by intercepting the dangerous process, prompting the executable file, and The browser calls for monitoring, etc., to ensure the network security of the user during the login process.
  • the present application also provides an embodiment of the client.
  • FIG. 5 it is a block diagram of an embodiment of a client of the present application.
  • the client includes: a monitoring unit 510 and a monitoring unit 520.
  • the monitoring unit 510 is configured to monitor whether the user opens the login operation mode or the payment operation mode through the client.
  • the monitoring unit 520 is configured to: after monitoring the user to enable the login operation mode or the payment operation mode, perform security monitoring on the login process or the payment process of the user according to a preset security policy, so as to perform an unsafe event on the user, Prompting or blocking the execution of the unsafe event.
  • the security policy is a security policy that is preset to protect the login process or the payment process.
  • the monitoring unit 510 is specifically configured to monitor whether the user opens the login operation mode or the payment operation mode through the client browser.
  • the monitoring unit 520 may include at least one of the following units (not shown in FIG. 5): a dangerous process monitoring unit, configured to monitor a dangerous process in the login process or the payment process by using a preset process list;
  • An executable file monitoring unit for monitoring executable files transmitted during the login process or payment process
  • the browser invokes a monitoring unit for monitoring the browser calling behavior during the login process or payment process;
  • the input content calls a monitoring unit for monitoring the call of the keyboard input during the login process or the payment process;
  • a data object monitoring unit configured to monitor a data object transmitted by the client during the login process or the payment process
  • the webpage monitoring unit is configured to monitor webpages opened during the login process or the payment process.
  • the dangerous process monitoring unit may include at least one of the following units:
  • a whitelist intercepting unit configured to preset a whitelist, to obtain a current process in the login process or the payment process, and when the current process is not found in the whitelist, the current process is used as Dangerous process interception;
  • a blacklist intercepting unit configured to preset a blacklist, to obtain a current process in the login process or the payment process, and when the current process is found in the blacklist, the current process is regarded as a danger The process is pulled.
  • the executable file monitoring unit may include at least one of the following units:
  • a first executable file monitoring unit configured to: when detecting that the client is ready to receive the executable file, searching for a preset executable file list, if the executable file is not found in the executable file list, Determining that the executable file is a suspicious file, and outputting selection prompt information requesting the user to select whether to receive the executable file; or, when monitoring that the client is in the process of receiving the executable file, searching for a preset executable a file list, if the executable file is not found in the executable file list, determining that the executable file is a suspicious file, and outputting a selection prompt message requesting the user to select whether to continue receiving the executable file; or When it is detected that the client receives the executable file, searching for a preset executable file list, if the executable file is not found in the executable file list, determining that the executable file is a suspicious file , outputting a selection prompt requesting the user to select whether to run the executable file information.
  • the first executable file monitoring unit may include:
  • a whitelist monitoring unit configured to determine the executable file as a suspicious file when the executable file is not found in the preset whitelist, where the preset whitelist is used for saving All secure executables; or,
  • a blacklist monitoring unit configured to determine the executable file as a suspicious file when the executable file is found in a preset blacklist, where the preset blacklist is used to save all Dangerous executable file.
  • the executable file monitoring unit may include:
  • a second executable file monitoring unit configured to: when detecting that the client receives the executable file, extract behavior characteristics in the executable file, and determine whether the behavior feature extracted from the executable file is a pre-recorded security behavior The feature, if not, determines the executable as a file.
  • the browser invoking the monitoring unit may include: a function monitoring unit, configured to monitor a correlation function between processes by using an underlying driver; and an event intercepting unit configured to intercept the corresponding function call triggered by the operation of the browser process through the remote procedure call interface Call event
  • Calling an event parsing unit configured to parse the calling event, and filtering out a process that initiates the calling event
  • the illegal process determining unit is configured to determine whether the process of initiating the calling event is an illegal process by searching a preset process list, where the process list includes a whitelist or a blacklist;
  • it may further include calling an event reject unit for rejecting the call event when it is determined that the process is an illegal process.
  • the user after detecting that the user starts the login operation mode or the payment operation mode, the user performs security monitoring on the login process or the payment process of the user according to the preset security policy.
  • the login process or the payment process may be securely protected through various security policies specifically for securing the login process or the payment process, through the dangerous process. Intercept, executable file prompts, and browser call monitoring to ensure network security during the login process or payment process. It will be apparent to those skilled in the art that the techniques in the embodiments of the present invention can be implemented by means of software plus a necessary general hardware platform.
  • the technical solution in the embodiments of the present invention may be embodied in the form of a software product in essence or in the form of a software product, and the computer software product may be stored in a storage medium, such as a ROM/RAM. , a diskette, an optical disk, and the like, including instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform the methods described in various embodiments of the present invention or portions of the embodiments.
  • a computer device which may be a personal computer, server, or network device, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Business, Economics & Management (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Accounting & Taxation (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Finance (AREA)
  • Information Transfer Between Computers (AREA)
  • Computer And Data Communications (AREA)

Abstract

一种保证用户网络安全性的方法及客户端,该方法包括:监测用户是否通过客户端开启登录操作模式或支付操作模式;当监测到用户开启登录操作模式或支付操作模式后,按照预先设置的安全策略对用户的登录过程或支付过程进行安全监控。应用本申请实施例,当客户端用户处于登录过程中或在线支付过程中时,可以通过多种专门用于保障登录过程或支付过程的安全策略对登录过程或支付过程进行安全保护,通过危险进程拦截、可执行文件提示及浏览器调用监控等,保证用户在登录过程或支付过程中的网络安全性。

Description

一种保证用户网络安全性的方法 户端
技术领域
本申请涉及计算机网络技术领域, 特别是涉及一种保证用户网络安全性的 方法及客户端。 背景技术
随着网络应用的扩展, 网络用户可以在线支付各种费用, 最常见的应用就 是用户登录网上商城购买物品时, 通过预先开通的网络银行进行网上转账支 付。在通过网络银行支付的过程中, 用户需要输入银行卡账号和预先设置的密 码, 因此保护网络支付的安全性至关重要。 现有技术中, 恶意第三方往往会通 过木马盗取用户的网络银行账号和密码, 例如, 当用户在网页上点击支付按钮 时, 可能进入的支付页面是恶意第三方预先设置好的、与正常支付网页相似的 恶意网页, 一旦用户在恶意网页上输入了用户名和密码, 则导致用户信息会被 盗取。 由此可知, 在现有网络支付过程中, 用户网银容易被盗用, 导致网络安 全性不高, 容易给用户造成损失。 发明内容
为了解决上述技术问题,本申请实施例提供了一种保证用户网络安全性的 方法及客户端, 以解决现有网络支付过程中用户信息容易被盗取,导致网络安 全性不高的问题。
本申请实施例公开了如下技术方案:
一种保证用户网络安全性的方法, 包括:
监测用户是否通过客户端开启登录操作模式或支付操作模式;
当监测到用户开启登录操作模式或支付操作模式后,按照预先设置的安全 策略对用户的登录过程或支付过程进行安全监控, 以便当监控到不安全事件 时, 向用户进行提示或者阻止所述不安全事件的执行。
其中,
所述监测用户是否通过客户端开启登录操作模式或支付操作模式包括:监 测用户是否通过客户端浏览器开启登录操作模式或支付操作模式。
其中,所述按照预先设置的安全策略对用户的登录过程或支付过程进行安 全监控包括至少一种下述方式:
通过预设的进程列表对登录过程或支付过程中的危险进程进行监控; 对登录过程或支付过程中传输的可执行文件进行监控;
对登录过程或支付过程中的浏览器调用行为进行监控;
对登录过程或支付过程中的键盘输入内容的调用进行监控;
对登录过程或支付过程中客户端传输的数据对象进行监控;
对登录过程或支付过程中所开启的网页进行监控。
其中,所述通过预设的进程列表对登录过程或支付过程中的危险进程进行 监控包括:
获取所述登录过程或支付过程中开启的当前进程,当在预置的白名单列表 中未查找到所述当前进程时, 则将所述当前进程确定为危险进程进行拦截, 其 中, 所述预置的白名单列表中用于保存已经确认的对系统没有威胁的安全进 程; 或者,
获取所述登录过程或支付过程中开启的当前进程,当在预置的黑名单列表 中查找到所述当前进程时,则将所述当前进程确定为危险进程进行拉截,其中, 所述预置的黑名单列表中用于保存已经确认的对系统存在威胁的危险进程。
其中, 所述对登录过程或支付过程中传输的可执行文件进行监控包括: 当监测到客户端准备接收可执行文件时,或者处于接收可执行文件过程中 时, 或者接收了可执行文件时, 通过查找预置的可执行文件列表, 确定所述可 执行文件是否为可疑文件。
其中, 所述通过查找预置的可执行文件列表,确定所述可执行文件是否为 可疑文件包括:
当在预置的白名单中未查找到所述可执行文件时,则将所述可执行文件确 定为可疑文件, 其中, 所述预置的白名单中用于保存所有安全的可执行文件; 或者,
当在预置的黑名单中查找到所述可执行文件时,则将所述可执行文件确定 为可疑文件, 其中, 所述预置的黑名单中用于保存所有危险的可执行文件。
其中, 所述对登录过程或支付过程中传输的可执行文件进行监控包括: 当监测到客户端接收了可执行文件时, 提取所述可执行文件中的行为特 征, 判断从可执行文件中提取的行为特征是否为预先记录的安全行为特征, 如 果不是, 则将所述可执行文件确定为可以文件。
其中, 所述对登录过程或支付过程中的浏览器调用行为进行监控包括: 通过底层驱动监控进程之间通讯的相关函数;
当监控到通过远程过程调用接口对浏览器进程进行操作所触发的相关函 数调用时, 拦截相应的调用事件;
解析所述调用事件, 过滤出发起所述调用事件的进程;
通过查找预先设置的进程名单确定所述发起调用事件的进程是否为非法 进程。
一种客户端, 包括:
监测单元,用于监测用户是否通过客户端开启登录操作模式或支付操作模 式;
监控单元, 用于当监测到用户开启登录操作模式或支付操作模式后,按照 预先设置的安全策略对用户的登录过程或支付过程进行安全监控,以便当监控 到不安全事件时, 向用户进行提示或者阻止所述不安全事件的执行。
其中,
所述监测单元,具体用于监测用户是否通过客户端浏览器开启登录操作模 式或支付操作模式。
其中, 所述监控单元包括至少一个下述单元:
危险进程监控单元,用于通过预设的进程列表对登录过程或支付过程中的 危险进程进行监控;
可执行文件监控单元,用于对登录过程或支付过程中传输的可执行文件进 行监控;
浏览器调用监控单元,用于对登录过程或支付过程中的浏览器调用行为进 行监控;
输入内容调用监控单元,用于对登录过程或支付过程中的键盘输入内容的 调用进行监控;
数据对象监控单元,用于对登录过程或支付过程中客户端传输的数据对象 进行监控; 网页监控单元, 用于对登录过程或支付过程中所开启的网页进行监控。 其中, 所述危险进程监控单元包括至少一个下述单元:
白名单拦截单元, 用于获取所述登录过程或支付过程中开启的当前进程, 当在预置的白名单列表中未查找到所述当前进程时,则将所述当前进程确定为 危险进程进行拉截, 其中, 所述预置的白名单列表中用于保存已经确认的对系 统没有威胁的安全进程;
黑名单拦截单元, 用于获取所述登录过程或支付过程中开启的当前进程, 当在预置的黑名单列表中查找到所述当前进程时,则将所述当前进程确定为危 险进程进行拉截, 其中, 所述预置的黑名单列表中用于保存已经确认的对系统 存在威胁的危险进程。
其中, 所述可执行文件监控单元包括:
第一可执行文件监控单元, 用于当监测到客户端准备接收可执行文件时, 或者处于接收可执行文件过程中时, 或者接收了可执行文件时,通过查找预置 的可执行文件列表, 确定所述可执行文件是否为可疑文件。
其中, 所述第一可执行文件监控单元包括:
白名单监控单元, 用于当在预置的白名单中未查找到所述可执行文件时, 则将所述可执行文件确定为可疑文件, 其中, 所述预置的白名单中用于保存所 有安全的可执行文件; 或者,
黑名单监控单元, 用于当在预置的黑名单中查找到所述可执行文件时, 则 将所述可执行文件确定为可疑文件, 其中, 所述预置的黑名单中用于保存所有 危险的可执行文件。
其中, 所述可执行文件监控单元包括:
第二可执行文件监控单元, 用于当监测到客户端接收了可执行文件时,提 取所述可执行文件中的行为特征,判断从可执行文件中提取的行为特征是否为 预先记录的安全行为特征, 如果不是, 则将所述可执行文件确定为可以文件。
其中, 所述浏览器调用监控单元包括:
函数监控单元, 用于通过底层驱动监控进程之间通讯的相关函数; 调用事件拦截单元,用于当监控到通过远程过程调用接口对浏览器进程进 行操作所触发的相关函数调用时, 拦截相应的调用事件;
调用事件解析单元, 用于解析所述调用事件, 过滤出发起所述调用事件的 进程;
非法进程确定单元,用于通过查找预先设置的进程名单确定所述发起调用 事件的进程是否为非法进程。
由上述实施例可以看出,本申请实施例中在监测到用户开启登录操作模式 或支付操作模式后,按照预先设置的安全策略对用户的登录过程或支付过程进 行安全监控。应用本申请实施例, 当客户端用户处于登录过程中或在线支付过 程中时,可以通过多种专门用于保障登录过程或支付过程的安全策略对登录过 程或支付过程进行安全保护,通过危险进程拦截、可执行文件提示及浏览器调 用监控等, 保证用户在登录过程或支付过程中的网络安全性。 附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施 例或现有技术描述中所需要使用的附图作筒单地介绍,显而易见地,对于本领 域普通技术人员而言,在不付出创造性劳动性的前提下,还可以根据这些附图 获得其他的附图。
图 1为本申请保证用户网络安全性的方法的第一实施例流程图; 图 2为本申请保证用户网络安全性的方法的第二实施例流程图; 图 3为本申请保证用户网络安全性的方法的第三实施例流程图; 图 4为本申请保证用户网络安全性的方法的第四实施例流程图; 图 5为本申请客户端的实施例框图。 具体实施方式
本发明如下实施例提供了一种保证用户网络安全性的方法及客户端。 为了使本技术领域的人员更好地理解本发明实施例中的技术方案,并使本 发明实施例的上述目的、特征和优点能够更加明显易懂, 下面结合附图对本发 明实施例中技术方案作进一步详细的说明。
参见图 1 , 为申请保证用户网络安全性的方法的第一实施例流程图: 步骤 101 : 监测用户是否通过客户端开启登录操作模式或支付操作模式。 本申请实施例可以特别应用在用户通过客户端进行网络支付的过程中,即 检测用户是否通过客户端开启了支付页面。以保证支付过程中用户信息不会泄 露, 提高网络支付的安全性。 具体的, 监测用户是否通过客户端浏览器开启登 录操作模式或支付操作模式。
步骤 102: 当监测到用户开启登录操作模式或支付操作模式后, 按照预先 设置的安全策略对用户的登录过程或支付过程进行安全监控。
其中,安全策略为预先针对登录操作模式或支付操作模式所设置的安全策 略。
客户端可以通过预设的进程列表对登录过程或支付过程中的危险进程进 行监控;或者通过预设的安全的可执行文件列表对登录过程或支付过程中传输 的可执行文件进行监控;或者对登录过程或支付过程中的浏览器调用行为进行 监控; 或者对登录过程或支付过程中的键盘输入内容的调用进行监控; 或者对 登录过程或支付过程中客户端传输的数据对象进行监控, 例如, 当监控到客户 端向与登录过程或支付过程无关的对象传输与登录或支付相关的数据时,则应 当拦截所传输的数据对象;或者对登录过程或支付过程中所开启的网页进行监 控, 例如, 在登录过程或支付过程中, 用户可能开启的支付网页为恶意第三方 伪造的与真实支付网页类似的网页, 因此需要对所开启的网页进行监控。
需要说明的是,上述所列六种安全策略执行方式可以在整个监控过程中并 行执行, 或者根据需要选择其中至少一个进行执行,对此本申请实施例不进行 限制。 参见图 2 , 为本申请保证用户网络安全性的方法的第二实施例流程图, 该 实施例以在线支付为例, 示出了对危险进程进行监控的过程:
步骤 201 : 监测用户在客户端上的操作。
步骤 202: 根据监测结果判断用户是否开始在线支付, 若是, 则执行步骤 203; 否则, 返回步骤 201。
在用户的客户端可以预先保存一个支付网站列表,当监测到用户打开浏览 器后, 获取浏览器访问页面的 URL ( Uniform / Univer sa l Resource Locator , 网页地址), 将获取的 URL与支付网站列表中的支付网站 URL进行对比, 如果 找到一致的 URL, 则可确认用户进入了支付页面, 并开始在线支付。
步骤 203: 根据已开启的当前进程查找预设的白名单列表。
白名单列表中保存的是已经确认的对系统没有威胁的安全进程,因此对于 这些进程可以不进行拉截。
白名单列表通常保存在本地,因此查找白名单列表的操作也相应在本地执 行。 进一步, 也可以结合云查杀的方式, 在当前进程运行的过程中, 连接云服 务器,通过网络中已经存在的多个白名单列表对当前进程是否为安全进程进行 查找。
在整个在线支付过程中, 可能会开启多个进程, 当每个进程开启后, 该进 程都作为当前进程对其执行查找白名单列表的操作。
步骤 204: 判断是否在白名单列表中查找到当前进程, 若未查找到, 则执 行步骤 205 ; 否查找到, 则执行步骤 206。
步骤 205 : 将当前进程作为危险进程进行拦截。
对于未在白名单列表中的进程, 可以将其直接作为危险进程进行拉截,也 可以对用户进行提示, 由用户选择是否允许该进程的执行, 或者阻止该进程的 执行。对于未在白名单列表中的进程, 可以向用户提供限制这些进程执行的功 能, 包括但不限于冻结进程、 隔离进程、 终止进程。
本实施例以白名单查找为例, 示出了对危险进程的拦截过程, 实际应用过 程中, 也可以预设黑名单列表, 当在所述黑名单列表中查找到当前进程时, 则 将所述当前进程作为危险进程进行拦截;对于既不在白名单也不在黑名单中的 进程, 可以对用户进行提示, 由用户选择是否阻止这些进程的运行, 防止未知 进程中可能存在的危险进程。
步骤 206: 判断用户是否已经结束在线支付, 若是, 则结束流程; 否则, 返回步骤 203。 参见图 3 , 为本申请保证用户网络安全性的方法的第三实施例流程图, 该 过程中接收到的可执行文件进行监控的过程:
步骤 301 : 监测用户在客户端上的操作。
步骤 302: 根据监测结果判断用户是否开始在线支付, 若是, 则执行步骤 303; 否则, 返回步骤 301。
在用户的客户端可以预先保存一个支付网站列表,当监测到用户打开浏览 器后, 获取浏览器访问页面的 URL, 将获取的 URL与支付网站列表中的支付网 站 URL进行对比, 如果找到一致的 URL, 则可确认用户进入了支付页面, 并开 始在线支付。
步骤 303: 判断客户端是否接收到可执行文件, 若是, 则执行步骤 304; 否则, 返回步骤 303。
用户在线支付的过程中, 可能接收到第三方传输给用户的可执行文件(例 如后缀为. exe的文件;), 这些可执行文件有些是支付过程中需要使用的文件, 有些则是恶意第三方发送给用户的危险文件。上述这些文件可能通过即时通信 工具传输给用户所在的终端设备、通过下载或分享的方式诱导用户下载到其所 在的终端设备、 通过挂木马或病毒传播等非法方式传播到用户所在的终端设 备、 或者在拷贝移动存储设备中的文件时传输到用户所在的终端设备。
在检测可执行文件时,可以通过用户的即时通信工具、浏览器等进行监控, 也可以在文件被下载到本地时实时检测到; 另外, 可执行文件在启动运行时, 以及启动运行后, 也都能够被系统检测到。
步骤 304: 查找预先设置的安全的可执行文件列表。
安全的可执行文件列表中可以记录文件的大小、 文件的时间、 文件的 MD5 信息、 文件的签名等。 的可执行文件; 或者采用黑名单的方式,通过黑名单保存所有危险的可执行文 件; 或者, 采用行为特征的方式, 记录所有安全行为特征, 在接收到可执行文 件后,提取可执行文件中的行为特征, 判断从可执行文件中提取的行为特征是 否满足所记录的安全行为特征,对于满足安全行为特征的文件则可确认为安全 的可执行文件。
步骤 305 :判断是否在可执行文件列表中查找到接收的可执行文件,若是, 则执行步骤 306; 否则, 执行步骤 307。
步骤 306: 输出请求用户选择是否运行所述可执行文件的选择提示信息。 步骤 307: 判断用户是否已经结束在线支付, 若是, 则结束流程; 否则, 返回步骤 303。
除了上述实施例中示出的对安全支付过程中接收到的可执行文件进行监 控外,也可以对客户端准备接收的可执行文件, 或者正在接收的可执行文件进 行监控。 具体的, 当监测到客户端准备接收可执行文件时, 查找预先设置的安 全的可执行文件列表,如果未在可执行文件列表中查找到该可执行文件, 则确 定该可执行文件为可疑文件,输出请求用户选择是否接收该可执行文件的选择 提示信息; 当监测到客户端处于接收可执行文件过程中时, 查找预先设置的安 全的可执行文件列表,如果未在可执行文件列表中查找到该可执行文件, 则确 定该可执行文件为可疑文件,输出请求用户选择是否接续接收该可执行文件的 选择提示信息。 参见图 4 , 为本申请保证用户网络安全性的方法的第四实施例流程图, 该 实施例以在线支付为例,示出了对安全支付过程中的浏览器调用行为进行监控 的过程:
步骤 401 : 监测用户在客户端上的操作。
步骤 402: 根据监测结果判断用户是否开始在线支付, 若是, 则执行步骤 403; 否则, 返回步骤 401。
在用户的客户端可以预先保存一个支付网站列表,当监测到用户打开浏览 器后, 获取浏览器访问页面的 URL, 将获取的 URL与支付网站列表中的支付网 站 URL进行对比, 如果找到一致的 URL, 则可确认用户进入了支付页面, 并开 始在线支付。
步骤 403: 通过底层驱动监控进程之间通讯的相关函数。
对于在线支付过程,底层驱动监控的进程之间的通讯函数可以包括如下示 例的 API ( Appl icat ion Programming Interface , 应用程序编程接口 ) 函数: NtAlpcSendWa i tReceivePor t
NtReques tWa i tReplyPor t
NtReques tPor t
步骤 404: 判断是否监控到通过远程过程调用接口对浏览器进程进行操作 所触发的相关函数调用, 若是, 则执行步骤 405 ; 否则, 返回步骤 403。
当有程序试图调用进程之间通讯的相关函数时,会通过远程过程调用接口 (例如, COM接口)对浏览器进程的接口进行操作, 当该操作试图控制浏览器 进程的网址或页面内容时,会监控到相应的函数调用事件, 此时就会触发对函 数调用进行拦截。
步骤 405 : 拦截相应的调用事件, 并解析调用事件, 过滤出发起该调用事 件的进程。
拦截到的调用事件即为对函数调用的事件, 通常函数调用是 RPC (Remote Procedure Call, 远程过程调用)过程中调用的函数, 此时对调用函数进行解 析, 例如, 如果解析的调用函数为 NtRequestWaitReplyPort, 则解析出的相 关函数可以包括 RequestMessage, PortHandle等。
在过滤通过远程过程调用接口对浏览器进程进行操作所触发的函数调用 时, 例如, A进程试图操作浏览器进程 B, 以跳转到恶意网址 C, 达到劫持在 线支付的网购过程, 则 A进程会连接浏览器进程 B的远程过程调用接口, 并 产生一个端口句柄 (PortHandle), 然后将要调用的调用序号和跳转网址等信 息封装到函数 NtRequestWaitRe lyPort 的参数 Reques tMessage 中 , RequestMessage为一个緩存地址, 最后调用 NtRequestWaitReplyPort API 函 数,将跳转请求发送给浏览器进程 B的远程过程调用端口,实现跳转操控过程。 本实施例中通过拦截、 监视这个函数 NtRequestWaitReplyPort , 从参数 RequestMessage 的緩存中解析并还原出所调用函数的调用序号和跳转网址等 信息,将这些信息识别为一个操作浏览器调用事件, 并获取触发该浏览器调用 事件的 A进程。
步骤 406: 查找预先设置的进程名单。
在获取到触发浏览器调用事件的 A进程后, 可以获得该进程的进程 ID、 执行路径、 对应文件的文件信息等。 根据执行路径获取对应文件, 并对文件的 摘要进行计算, 获取代表该文件唯一性的哈希信息。
其中, 进程名单可以采用白名单方式或者黑名单方式。在采用白名单方式 哈希信息与该白名单中的哈希信息进行比较,如果存在一致的哈希信息, 则表 示获取到的进程为安全进程, 不用进行拉截; 如果还存在黑名单, 则对与黑名 单中哈希信息匹配一致的进程进行拉截并发出警报;对于既不在白名单也不在 黑名单中的哈希信息对应的进程, 则可以进行拉截并向用户发出提示。
步骤 407: 根据查找结果判断该进程是否为非法进程, 若是, 则执行步骤 408; 否则, 执行步骤 409。
步骤 408: 拒绝该调用事件。
步骤 409: 判断用户是否已经结束在线支付, 若是, 则结束流程; 否则, 返回步骤 403。
由上述实施例可见,当客户端用户进行登录操作,特别是在线支付过程中, 可以通过多种安全策略对支付过程进行安全保护, 通过对危险进程进行拉截、 对可执行文件进行提示及对浏览器调用进行监控等,保证用户在登录过程中的 网络安全性。 与本申请保证用户网络安全性的方法的实施例相对应,本申请还提供了客 户端的实施例。
参见图 5 , 为本申请客户端的实施例框图。
该客户端包括: 监测单元 510和监控单元 520。
其中, 监测单元 510 , 用于监测用户是否通过客户端开启登录操作模式或 支付操作模式;
监控单元 520 , 用于当监测到用户开启登录操作模式或支付操作模式后, 按照预先设置的安全策略对用户的登录过程或支付过程进行安全监控,以便当 监控到不安全事件时, 向用户进行提示或者阻止所述不安全事件的执行。
其中,所述安全策略为预先设置的专用于保障所述登录过程或支付过程的 安全策略; 所述监测单元 510 , 具体用于监测用户是否通过客户端浏览器开启 登录操作模式或支付操作模式。
其中, 监控单元 520可以包括至少一个下述单元(图 5中未示出): 危险进程监控单元,用于通过预设的进程列表对登录过程或支付过程中的 危险进程进行监控;
可执行文件监控单元,用于对登录过程或支付过程中传输的可执行文件进 行监控;
浏览器调用监控单元,用于对登录过程或支付过程中的浏览器调用行为进 行监控;
输入内容调用监控单元,用于对登录过程或支付过程中的键盘输入内容的 调用进行监控;
数据对象监控单元,用于对登录过程或支付过程中客户端传输的数据对象 进行监控;
网页监控单元, 用于对登录过程或支付过程中所开启的网页进行监控。 具体的, 危险进程监控单元可以包括至少一个下述单元:
白名单拦截单元, 用于预设白名单列表, 获取所述登录过程或支付过程中 的当前进程, 当在所述白名单列表中未查找到所述当前进程时, 则将所述当前 进程作为危险进程进行拦截;
黑名单拦截单元, 用于预设黑名单列表, 获取所述登录过程或支付过程中 的当前进程, 当在所述黑名单列表中查找到所述当前进程时, 则将所述当前进 程作为危险进程进行拉截。
具体的, 可执行文件监控单元可以包括至少一个下述单元:
第一可执行文件监控单元, 用于当监测到客户端准备接收可执行文件时, 查找预先设置的可执行文件列表,如果未在所述可执行文件列表中查找到所述 可执行文件, 则确定所述可执行文件为可疑文件,还可以输出请求用户选择是 否接收所述可执行文件的选择提示信息; 或者, 当监测到客户端处于接收可执 行文件过程中时, 查找预先设置的可执行文件列表,如果未在所述可执行文件 列表中查找到所述可执行文件, 则确定所述可执行文件为可疑文件,输出请求 用户选择是否接续接收所述可执行文件的选择提示信息; 或者, 当监测到客户 端接收了可执行文件时, 查找预先设置的可执行文件列表,如果未在所述可执 行文件列表中查找到所述可执行文件, 则确定所述可执行文件为可疑文件,输 出请求用户选择是否运行所述可执行文件的选择提示信息。
其中, 第一可执行文件监控单元可以包括:
白名单监控单元, 用于当在预置的白名单中未查找到所述可执行文件时, 则将所述可执行文件确定为可疑文件, 其中, 所述预置的白名单中用于保存所 有安全的可执行文件; 或者,
黑名单监控单元, 用于当在预置的黑名单中查找到所述可执行文件时, 则 将所述可执行文件确定为可疑文件, 其中, 所述预置的黑名单中用于保存所有 危险的可执行文件。
在另一种实现方式下, 可执行文件监控单元可以包括:
第二可执行文件监控单元, 用于当监测到客户端接收了可执行文件时,提 取所述可执行文件中的行为特征,判断从可执行文件中提取的行为特征是否为 预先记录的安全行为特征, 如果不是, 则将所述可执行文件确定为可以文件。
具体的, 浏览器调用监控单元可以包括: 函数监控单元, 用于通过底层驱动监控进程之间通讯的相关函数; 调用事件拦截单元,用于当监控到通过远程过程调用接口对浏览器进程进 行操作所触发的相关函数调用时, 拦截相应的调用事件;
调用事件解析单元, 用于解析所述调用事件, 过滤出发起所述调用事件的 进程;
非法进程确定单元,用于通过查找预先设置的进程名单确定所述发起调用 事件的进程是否为非法进程, 所述进程名单包括白名单或者黑名单;
在需要阻止这种不安全事件的执行时,还可以包括调用事件拒绝单元, 用 于当确定所述进程为非法进程时, 拒绝所述调用事件。
通过对以上实施方式的描述可知,本申请实施例中在监测到用户开启登录 操作模式或支付操作模式后,按照预先设置的安全策略对用户的登录过程或支 付过程进行安全监控。应用本申请实施例, 当客户端用户处于登录过程中或在 线支付过程中时,可以通过多种专门用于保障登录过程或支付过程的安全策略 对登录过程或支付过程进行安全保护, 通过危险进程拦截、可执行文件提示及 浏览器调用监控等, 保证用户在登录过程或支付过程中的网络安全性。 本领域的技术人员可以清楚地了解到本发明实施例中的技术可借助软件 加必需的通用硬件平台的方式来实现。基于这样的理解, 本发明实施例中的技 术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现 出来, 该计算机软件产品可以存储在存储介质中, 如 R0M/RAM、磁碟、 光盘等, 包括若干指令用以使得一台计算机设备(可以是个人计算机, 服务器, 或者网 络设备等)执行本发明各个实施例或者实施例的某些部分所述的方法。
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相 似的部分互相参见即可, 每个实施例重点说明的都是与其他实施例的不同之 处。 尤其, 对于系统实施例而言, 由于其基本相似于方法实施例, 所以描述的 比较筒单, 相关之处参见方法实施例的部分说明即可。
以上所述的本发明实施方式, 并不构成对本发明保护范围的限定。任何在 本发明的精神和原则之内所作的修改、等同替换和改进等, 均应包含在本发明 的保护范围之内。

Claims

权 利 要 求 书
1、 一种保证用户网络安全性的方法, 其特征在于, 包括:
监测用户是否通过客户端开启登录操作模式或支付操作模式;
当监测到用户开启登录操作模式或支付操作模式后,按照预先设置的安全 策略对用户的登录过程或支付过程进行安全监控, 以便当监控到不安全事件 时, 向用户进行提示或者阻止所述不安全事件的执行。
2、 根据权利要求 1所述的方法, 其特征在于,
所述监测用户是否通过客户端开启登录操作模式或支付操作模式包括:监 测用户是否通过客户端浏览器开启登录操作模式或支付操作模式。
3、 根据权利要求 1所述的方法, 其特征在于, 所述按照预先设置的安全 策略对用户的登录过程或支付过程进行安全监控包括至少一种下述方式:
通过预设的进程列表对登录过程或支付过程中的危险进程进行监控; 对登录过程或支付过程中传输的可执行文件进行监控;
对登录过程或支付过程中的浏览器调用行为进行监控;
对登录过程或支付过程中的键盘输入内容的调用进行监控;
对登录过程或支付过程中客户端传输的数据对象进行监控;
对登录过程或支付过程中所开启的网页进行监控。
4、 根据权利要求 3所述的方法, 其特征在于, 所述通过预设的进程列表 对登录过程或支付过程中的危险进程进行监控包括:
获取所述登录过程或支付过程中开启的当前进程,当在预置的白名单列表 中未查找到所述当前进程时, 则将所述当前进程确定为危险进程进行拦截, 其 中, 所述预置的白名单列表中用于保存已经确认的对系统没有威胁的安全进 程; 或者,
获取所述登录过程或支付过程中开启的当前进程,当在预置的黑名单列表 中查找到所述当前进程时,则将所述当前进程确定为危险进程进行拉截,其中, 所述预置的黑名单列表中用于保存已经确认的对系统存在威胁的危险进程。
5、 根据权利要求 3所述的方法, 其特征在于, 所述对登录过程或支付过 程中传输的可执行文件进行监控包括:
当监测到客户端准备接收可执行文件时,或者处于接收可执行文件过程中 时, 或者接收了可执行文件时, 通过查找预置的可执行文件列表, 确定所述可 执行文件是否为可疑文件。
6、 根据权利要求 5所述的方法, 其特征在于, 所述通过查找预置的可执 行文件列表, 确定所述可执行文件是否为可疑文件包括:
当在预置的白名单中未查找到所述可执行文件时,则将所述可执行文件确 定为可疑文件, 其中, 所述预置的白名单中用于保存所有安全的可执行文件; 或者,
当在预置的黑名单中查找到所述可执行文件时,则将所述可执行文件确定 为可疑文件, 其中, 所述预置的黑名单中用于保存所有危险的可执行文件。
7、 根据权利要求 3所述的方法, 其特征在于, 所述对登录过程或支付过 程中传输的可执行文件进行监控包括:
当监测到客户端接收了可执行文件时, 提取所述可执行文件中的行为特 征, 判断从可执行文件中提取的行为特征是否为预先记录的安全行为特征, 如 果不是, 则将所述可执行文件确定为可以文件。
8、 根据权利要求 3所述的方法, 其特征在于, 所述对登录过程或支付过 程中的浏览器调用行为进行监控包括:
通过底层驱动监控进程之间通讯的相关函数;
当监控到通过远程过程调用接口对浏览器进程进行操作所触发的相关函 数调用时, 拦截相应的调用事件;
解析所述调用事件, 过滤出发起所述调用事件的进程;
通过查找预先设置的进程名单确定所述发起调用事件的进程是否为非法 进程。
9、 一种客户端, 其特征在于, 包括:
监测单元,用于监测用户是否通过客户端开启登录操作模式或支付操作模 式;
监控单元, 用于当监测到用户开启登录操作模式或支付操作模式后,按照 预先设置的安全策略对用户的登录过程或支付过程进行安全监控,以便当监控 到不安全事件时, 向用户进行提示或者阻止所述不安全事件的执行。
10、 根据权利要求 9所述的客户端, 其特征在于,
所述监测单元,具体用于监测用户是否通过客户端浏览器开启登录操作模 式或支付操作模式。
11、 根据权利要求 9所述的客户端, 其特征在于, 所述监控单元包括至少 一个下述单元:
危险进程监控单元,用于通过预设的进程列表对登录过程或支付过程中的 危险进程进行监控;
可执行文件监控单元,用于对登录过程或支付过程中传输的可执行文件进 行监控;
浏览器调用监控单元,用于对登录过程或支付过程中的浏览器调用行为进 行监控;
输入内容调用监控单元,用于对登录过程或支付过程中的键盘输入内容的 调用进行监控;
数据对象监控单元,用于对登录过程或支付过程中客户端传输的数据对象 进行监控;
网页监控单元, 用于对登录过程或支付过程中所开启的网页进行监控。
12、 根据权利要求 11所述的客户端, 其特征在于, 所述危险进程监控单 元包括至少一个下述单元:
白名单拦截单元, 用于获取所述登录过程或支付过程中开启的当前进程, 当在预置的白名单列表中未查找到所述当前进程时,则将所述当前进程确定为 危险进程进行拉截, 其中, 所述预置的白名单列表中用于保存已经确认的对系 统没有威胁的安全进程;
黑名单拦截单元, 用于获取所述登录过程或支付过程中开启的当前进程, 当在预置的黑名单列表中查找到所述当前进程时,则将所述当前进程确定为危 险进程进行拉截, 其中, 所述预置的黑名单列表中用于保存已经确认的对系统 存在威胁的危险进程。
13、 根据权利要求 11所述的客户端, 其特征在于, 所述可执行文件监控 单元包括:
第一可执行文件监控单元, 用于当监测到客户端准备接收可执行文件时, 或者处于接收可执行文件过程中时, 或者接收了可执行文件时,通过查找预置 的可执行文件列表, 确定所述可执行文件是否为可疑文件。
14、 根据权利要求 13所述的客户端, 其特征在于, 所述第一可执行文件 监控单元包括:
白名单监控单元, 用于当在预置的白名单中未查找到所述可执行文件时, 则将所述可执行文件确定为可疑文件, 其中, 所述预置的白名单中用于保存所 有安全的可执行文件; 或者,
黑名单监控单元, 用于当在预置的黑名单中查找到所述可执行文件时, 则 将所述可执行文件确定为可疑文件, 其中, 所述预置的黑名单中用于保存所有 危险的可执行文件。
15、 根据权利要求 11所述的客户端, 其特征在于, 所述可执行文件监控 单元包括:
第二可执行文件监控单元, 用于当监测到客户端接收了可执行文件时,提 取所述可执行文件中的行为特征,判断从可执行文件中提取的行为特征是否为 预先记录的安全行为特征, 如果不是, 则将所述可执行文件确定为可以文件。
16、 根据权利要求 11所述的客户端, 其特征在于, 所述浏览器调用监控 单元包括:
函数监控单元, 用于通过底层驱动监控进程之间通讯的相关函数; 调用事件拦截单元,用于当监控到通过远程过程调用接口对浏览器进程进 行操作所触发的相关函数调用时, 拦截相应的调用事件;
调用事件解析单元, 用于解析所述调用事件, 过滤出发起所述调用事件的 进程;
非法进程确定单元,用于通过查找预先设置的进程名单确定所述发起调用 事件的进程是否为非法进程。
PCT/CN2012/074191 2011-04-18 2012-04-17 一种保证用户网络安全性的方法及客户端 Ceased WO2012142938A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US14/112,059 US20140317733A1 (en) 2011-04-18 2012-04-17 Method and client for ensuring user network security

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110097169XA CN102164138A (zh) 2011-04-18 2011-04-18 一种保证用户网络安全性的方法及客户端
CN201110097169X 2011-04-18

Publications (1)

Publication Number Publication Date
WO2012142938A1 true WO2012142938A1 (zh) 2012-10-26

Family

ID=44465112

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2012/074191 Ceased WO2012142938A1 (zh) 2011-04-18 2012-04-17 一种保证用户网络安全性的方法及客户端

Country Status (3)

Country Link
US (1) US20140317733A1 (zh)
CN (1) CN102164138A (zh)
WO (1) WO2012142938A1 (zh)

Families Citing this family (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102164138A (zh) * 2011-04-18 2011-08-24 奇智软件(北京)有限公司 一种保证用户网络安全性的方法及客户端
CN102663289B (zh) * 2012-03-22 2015-07-15 北京奇虎科技有限公司 一种对修改网页元素的恶意程序进行拦截的方法及装置
CN102811146B (zh) * 2012-08-31 2015-03-04 飞天诚信科技股份有限公司 一种检测报文处理环境的方法和装置
CN102857519B (zh) * 2012-09-29 2015-01-07 北京奇虎科技有限公司 主动防御系统
CN102902908B (zh) * 2012-10-08 2015-10-21 北京奇虎科技有限公司 免安装ActiveX插件安全检测装置及方法
CN105117642B (zh) * 2012-10-08 2018-05-08 北京奇虎科技有限公司 免安装ActiveX插件安全检测装置及方法
CN102930209B (zh) * 2012-10-16 2016-04-27 北京奇虎科技有限公司 移动存储设备的文件处理方法和文件处理装置
CN103824018B (zh) * 2012-11-19 2017-11-14 腾讯科技(深圳)有限公司 一种可执行文件处理方法以及可执行文件监控方法
CN103218561B (zh) * 2013-03-18 2016-04-06 珠海市君天电子科技有限公司 一种保护浏览器的防篡改方法和装置
CN103150511B (zh) * 2013-03-18 2016-12-28 珠海市君天电子科技有限公司 一种安全防护系统
CN103309937A (zh) * 2013-04-19 2013-09-18 无锡成电科大科技发展有限公司 一种云平台内容监管的方法
CN103607422B (zh) * 2013-10-18 2017-04-05 北京奇虎科技有限公司 云服务信息的处理方法、浏览器及系统
CN104700031B (zh) * 2013-12-06 2019-12-13 腾讯科技(深圳)有限公司 防止应用操作中远程代码被执行的方法、装置及系统
CN103853980A (zh) * 2014-02-28 2014-06-11 珠海市君天电子科技有限公司 安全提示方法及装置
CN103984899B (zh) * 2014-06-09 2017-02-01 武汉大学 一种虚拟机在线高效批量杀毒系统及杀毒方法
CN104021467A (zh) * 2014-06-12 2014-09-03 北京奇虎科技有限公司 保护移动终端支付安全的方法和装置以及移动终端
CN104038504A (zh) * 2014-06-25 2014-09-10 深圳市鸿宇顺科技有限公司 一种防范网络支付信息被盗的系统和方法
CN104486301B (zh) * 2014-12-02 2018-01-09 百度在线网络技术(北京)有限公司 登录验证方法及装置
CN105260660A (zh) * 2015-09-14 2016-01-20 百度在线网络技术(北京)有限公司 智能终端支付环境的监控方法、装置及系统
CN105825149A (zh) * 2015-09-30 2016-08-03 维沃移动通信有限公司 一种多操作系统间的切换方法及终端设备
CN105187449B (zh) * 2015-09-30 2018-10-02 北京恒华伟业科技股份有限公司 一种接口调用方法及装置
CN105635126B (zh) * 2015-12-24 2018-10-09 北京奇虎科技有限公司 恶意网址访问防护方法、客户端、安全服务器及系统
CN105450666A (zh) * 2015-12-30 2016-03-30 百度在线网络技术(北京)有限公司 一种登录验证方法和装置
CN107292412A (zh) * 2016-03-31 2017-10-24 阿里巴巴集团控股有限公司 一种问题预测方法及预测系统
CN107545424B (zh) * 2016-06-23 2020-11-27 腾讯科技(深圳)有限公司 一种数据监控处理方法、装置以及系统
CN106504000A (zh) * 2016-10-25 2017-03-15 广州爱九游信息技术有限公司 用户终端及支付方式检测装置与方法
US10757087B2 (en) * 2018-01-02 2020-08-25 Winbond Electronics Corporation Secure client authentication based on conditional provisioning of code signature
JP6700337B2 (ja) * 2018-05-30 2020-05-27 日本電信電話株式会社 保護装置及び保護方法
CN110147967B (zh) * 2019-05-28 2023-05-30 创新先进技术有限公司 风险防控方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7483972B2 (en) * 2003-01-08 2009-01-27 Cisco Technology, Inc. Network security monitoring system
CN101409719A (zh) * 2007-10-08 2009-04-15 联想(北京)有限公司 实现网络安全支付的方法及客户端
CN101478407A (zh) * 2008-01-03 2009-07-08 联想(北京)有限公司 在线安全登录的方法及装置
CN102164138A (zh) * 2011-04-18 2011-08-24 奇智软件(北京)有限公司 一种保证用户网络安全性的方法及客户端

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6728886B1 (en) * 1999-12-01 2004-04-27 Trend Micro Incorporated Distributed virus scanning arrangements and methods therefor
US10043008B2 (en) * 2004-10-29 2018-08-07 Microsoft Technology Licensing, Llc Efficient white listing of user-modifiable files
CN101098226B (zh) * 2006-06-27 2011-02-09 飞塔公司 一种病毒在线实时处理系统及其方法
US8510837B2 (en) * 2007-12-31 2013-08-13 Cisco Technology, Inc. Detecting rootkits over a storage area network
US8839431B2 (en) * 2008-05-12 2014-09-16 Enpulz, L.L.C. Network browser based virus detection
US8499150B1 (en) * 2010-11-11 2013-07-30 Symantec Corporation Selectively trusting signed files

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7483972B2 (en) * 2003-01-08 2009-01-27 Cisco Technology, Inc. Network security monitoring system
CN101409719A (zh) * 2007-10-08 2009-04-15 联想(北京)有限公司 实现网络安全支付的方法及客户端
CN101478407A (zh) * 2008-01-03 2009-07-08 联想(北京)有限公司 在线安全登录的方法及装置
CN102164138A (zh) * 2011-04-18 2011-08-24 奇智软件(北京)有限公司 一种保证用户网络安全性的方法及客户端

Also Published As

Publication number Publication date
CN102164138A (zh) 2011-08-24
US20140317733A1 (en) 2014-10-23

Similar Documents

Publication Publication Date Title
US20140317733A1 (en) Method and client for ensuring user network security
CN103795703A (zh) 一种保证用户网络安全性的方法及客户端
CN107211016B (zh) 会话安全划分和应用程序剖析器
RU2595511C2 (ru) Система и способ ограничения работы доверенных приложений при наличии подозрительных приложений
EP2839406B1 (en) Detection and prevention of installation of malicious mobile applications
US9032085B1 (en) Identifying use of software applications
JP6624771B2 (ja) クライアントベースローカルマルウェア検出方法
CN107135073B (zh) 接口调用方法和装置
CN104239577A (zh) 检测网页数据真伪的方法和装置
EP3526723B1 (en) Detecting device masquerading in application programming interface (api) transactions
CN102073953A (zh) 一种网上支付方法及系统
CN104463569A (zh) 安全连接支付方法及其装置
CN102932329A (zh) 一种对程序的行为进行拦截的方法、装置和客户端设备
WO2015007231A1 (zh) 一种恶意url的鉴定方法及装置
CN103888480B (zh) 基于云监测的网络信息安全性鉴定方法及云端设备
WO2015188788A1 (zh) 保护移动终端支付安全的方法、装置以及移动终端
CN106453266A (zh) 一种异常网络请求检测方法与装置
CN104008331A (zh) 一种恶意网站的访问方法、装置和系统
WO2016045541A1 (zh) 一种对中间人的存在进行辨识的方法及装置
US8555384B1 (en) System and method for gathering data for detecting fraudulent transactions
WO2017190436A1 (zh) 一种数据处理方法及装置
CN112351006B (zh) 一种网站访问攻击拦截方法及相关组件
US11082437B2 (en) Network resources attack detection
US10757118B2 (en) Method of aiding the detection of infection of a terminal by malware
CN102790799B (zh) 一种基于云安全服务的资源下载方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 12773693

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 12773693

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14112059

Country of ref document: US