WO2014090080A1 - Method and apparatus for restricting network applications - Google Patents

Method and apparatus for restricting network applications Download PDF

Info

Publication number
WO2014090080A1
WO2014090080A1 PCT/CN2013/087748 CN2013087748W WO2014090080A1 WO 2014090080 A1 WO2014090080 A1 WO 2014090080A1 CN 2013087748 W CN2013087748 W CN 2013087748W WO 2014090080 A1 WO2014090080 A1 WO 2014090080A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
scene
restricting
module
running
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/087748
Other languages
French (fr)
Inventor
Jie Lin
Xi Zhang
Jing Yang
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tencent Technology Shenzhen Co Ltd
Original Assignee
Tencent Technology Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tencent Technology Shenzhen Co Ltd filed Critical Tencent Technology Shenzhen Co Ltd
Publication of WO2014090080A1 publication Critical patent/WO2014090080A1/en
Priority to US14/729,694 priority Critical patent/US10116586B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/70Admission control; Resource allocation
    • H04L47/74Admission control; Resource allocation measures in reaction to resource unavailability
    • H04L47/748Negotiation of resources, e.g. modification of a request
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0894Policy-based network configuration management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/2866Architectures; Arrangements
    • H04L67/30Profiles
    • H04L67/306User profiles

Definitions

  • the present disclosure relates to Web applications, and particularly to a method and an apparatus for restricting network applications.
  • a conventional solution is to store a black list of processes whose network speed is restricted in a local device.
  • a process consumes a large amount of network resources, the process is added into the black list and then ended.
  • network resources previously occupied by the process become available, and network speed is increased.
  • Various examples of the present disclosure provide a method and an apparatus for restricting network applications to increase network speed of a local application.
  • a method for restricting network applications may include: a current network using scene is identified; a network application is restricted using a network speed protecting policy corresponding to the network using scene.
  • An apparatus for restricting network applications may include: a scene identifying module and an application restricting module.
  • the scene identifying module identifies a current network using scene in real time
  • the application restricting module restricts a network application using a network speed protecting policy corresponding to the network using scene identified by the scene identifying module.
  • the mechanism of examples of the present disclosure monitors the network using scene when a user device accesses the network and adopts a network speed protecting policy corresponding to the scene identified to restrict network applications. Therefore, targeted protection and restriction of network applications are implemented, which do not restrict a regular network application but restrict an application which is automatically started and consumes a large amount of network resources. The network speed of a local application can be increased.
  • Fig. 1 is a schematic diagram illustrating an example of a computing device
  • Fig. 2 is a flowchart illustrating a method for restricting network applications according to an example of the present disclosure
  • Figs. 3a, 3b, 3c, 3d, 3e, 3f, 3g, 3h, 3i and 4 are schematic diagrams respectively illustrating several examples of an apparatus for restricting network applications. Detailed Descriptions
  • a computing device may execute methods and software systems of the present application.
  • Fig. 1 is a schematic diagram illustrating an example of a computing device.
  • computing device 100 may be capable of executing a method and apparatus of the present disclosure.
  • the computing device 100 may, for example, be a device such as a personal desktop computer or a portable device, such as a laptop computer, a tablet computer, a cellular telephone, or a smart phone.
  • the computing device 100 may also be a server that connects to the above devices locally or via a network.
  • the computing device 100 may vary in terms of capabilities or features. Claimed subject matter is intended to cover a wide range of potential variations.
  • the computing device 100 may include a keypad/keyboard 156. It may also include a display 154, such as a liquid crystal display (LCD), or a display with a high degree of functionality, such as a touch- sensitive color 2D or 3D display.
  • a web-enabled computing device 100 may include one or more physical or virtual keyboards, and mass storage medium 130.
  • the computing device 100 may also include or may execute a variety of operating systems 141, including an operating system, such as a WindowsTM or LinuxTM, or a mobile operating system, such as iOSTM, AndroidTM, or Windows MobileTM.
  • the computing device 100 may include or may execute a variety of possible applications 142, such as a network speed protecting application 145.
  • the computing device 100 may include one or more non-transitory processor-readable storage media 130 and one or more processors 122 in communication with the non-transitory processor-readable storage media 130.
  • the non-transitory processor-readable storage media 130 may be a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of non-transitory storage medium known in the art.
  • the one or more non-transitory processor-readable storage media 130 may store sets of instructions, or units and/or modules that include the sets of instructions, for conducting operations described in the present application.
  • the one or more processors may be configured to execute the sets of instructions and perform the operations in examples of the present application.
  • Fig. 2 is a flowchart illustrating a method for restricting network applications according to an example of the present disclosure.
  • the entity that executes the method may be the network speed protecting application 145 in the computing device 100, e.g., a user device and the like.
  • the method may include the following procedures.
  • a current scene of network usage (which is also referred to as network using scene) is identified in real time.
  • Different network using scenes may have different requirements for network resources, e.g., an online video scene and an online game scene generally require more bandwidth or I/O resources and are more sensitive to network delay than a webpage browsing scene. Therefore, the current network using scene is identified before restrictions are applied to network applications.
  • the real-time identifying refers to an act of identifying a network using scene when a user starts using a network.
  • a uniform resource locator is monitored in real time to identify the network using scene.
  • the URL is an identity describing the address of a webpage or other resources in the Internet.
  • the system may identify the current network using scene by monitoring the URL currently being visited in real time. For example, when it is determined the user is visiting *. youku.com via a browser, it can be determined the network using scene is an online video scene.
  • the network using scene may be identified in real time by monitoring the software the user switches on/off in real time. That is, the switching on/off of software may be used for determining the network using scene. For example, when a user starts a QQ car racing process, it can be determined that the current network using scene is an online game scene.
  • New network using scenes may be recorded and network using scenes may be subdivided from time to time.
  • a user may be in two different network using scenes at the same time. For example, a user may be playing an online game while listening to online music. This situation is related to user habits. Therefore, an interface may be provided by the user device for the user to select applications that are allowed to run in a network using scene.
  • a network using scene may be identified by monitoring a URL and switching on/off of applications at the same time.
  • capabilities of the user device may also affect the network speed of an application running in the user device. Restricting the network speed of a user device with low capabilities may result in lower performances of the machine.
  • capabilities including hardware capabilities and software capabilities of the user device are also identified and classified.
  • Hardware capabilities may include capabilities of a CPU, a memory, a video card, a hard drive and the like of the user device.
  • Software capabilities may include an operating system of the user device.
  • Information on the hardware capabilities and software capabilities is reported to a background module in the user device. The background module may classify the capabilities of the user device into ranks such as high, medium, low, and so on. If a user device is classified to have low capabilities, information may be displayed to prompt the user to switch off a process and/or a service that is occupying network resources when the user device accesses the network.
  • a network speed protecting policy corresponding to the scene is adopted to restrict network applications running in the network using scene.
  • an auxiliary policy may be adopted to restrict network applications running in the scene; and/or, a black/white list policy may be used for restricting processes running in the scene.
  • Restricting processes using the black/white list policy may involve classifying processes running in the network using scene.
  • a network speed protecting application in the user device may monitor usage of network by other processes running in the network using scene, and report monitoring results to a background module.
  • the background module classifies the processes. For example, the processes may be classified by using the name of the company producing the software, e.g., Microsoft, Xunlei and the like. Then the processes are further classified by using the name of the product to obtain application categories.
  • the process may be put into a black list or a white list. If a process does not belong to any known category, manual work is required to determine whether the process is related to the current network using scene and possibly provide a score. As such, the background module may generate a score for each of all the processes representing the correlation between the process and the network using scene. A process may be added into the white list or the black list according to the score of the process using one or multiple pre-defined thresholds.
  • the network speed protecting application in the user device may automatically provide a prompt message to suggest the user to adopt a network speed protecting policy associated with the scene.
  • Processes may be restricted according to the classification result after the processes in a network using scene are classified, i.e., if a process running in a scene belongs to the white list of the scene, the process is not restricted; if the process belongs to the black list of the scene, the process is ended; if the process belongs to a gray list, network resources consumed by the process are restricted.
  • processes running in the online game scene which are necessary to the running of the online game e.g., a system process, a gaming process, a gaming subprocess, an application accompanying the game (e.g., a game accelerator and the like) and etc., belong to a white list and thus are not restricted by the network speed protecting application in the user device.
  • Processes running in the online gaming scene which are not necessary to the running of the online game and occupy a lot of system resources belong to a black list.
  • the network speed protecting application in the user device may apply a restricting policy to the processes in the black list, e.g., directly ending the process or ending the process and the like.
  • Processes belonging to a gray list e.g., an unknown process or a third party process that the user does not wish to be ended, may be restricted according to a network speed restricting policy.
  • Restricting network applications running in an identifiable network using scene by using an auxiliary policy may involve not restricting the speed of a suspended process, not restricting an application which is manually started by the user, restricting or ending a process running in a user device with low capabilities, and so on.
  • the network speed protecting application does not restrict the network speed of the online game process in the online game scene.
  • the network speed protecting application in the user device does not restrict the network speed of the application manually started by the user in the online game scene.
  • processes running in the user device are restricted or ended to ensure there are enough resources for running the online game in the device.
  • the auxiliary policy and/or the black/white list policy may be network speed protecting policies stored in a local policy center or obtained from a cloud server in real time.
  • network speed protecting policies in a server in the cloud may be obtained by using a cloud hub.
  • the mechanism of examples of the present disclosure monitors the network using scene in real time when a user device accesses the network, and adopts a network speed protecting policy corresponding to the scene identified to restrict network applications if the scene is identifiable. Therefore, targeted protection and restriction of network applications are implemented, which do not restrict a regular network application but restrict an application which is automatically started and consumes a large amount of network resources. The network speed of an application can be increased.
  • Fig. 3a is a schematic diagram illustrating a structure of an apparatus for restricting network applications according to an example of the present disclosure. Only those features related with the implementation of the mechanism are illustrated for simplicity.
  • the apparatus as shown in Fig. 3a may be a network speed protecting software installed in a user device.
  • the apparatus may include a scene identifying module 301 and an application restricting module 302.
  • a scene identifying module 301 is configured to identify a current network using scene in real time
  • an application restricting module 302 configured to restrict a network application using a network speed protecting policy corresponding to the network using scene identified by the scene identifying module 301.
  • the scene identifying module 301 may include a first identifying module 3011 as shown in Fig. 3b.
  • the first identifying module 3011 is configured to monitor a URL in real time to identify the network using scene.
  • the scene identifying module 301 may include a second identifying module 3012 as shown in Fig. 3c.
  • the second identifying module 3012 is configured to monitor switching on/off of an application in real time to identify the network using scene.
  • the scene identifying module 301 in the apparatus may include the first identifying module 3011 and the second identifying module 3012.
  • the application restricting module 302 may include a first restricting module 3021 as shown in Fig. 3e.
  • the first restricting module 3021 is configured to restrict a network application running in the network using scene by using an auxiliary policy.
  • the auxiliary policy may include any or any combination of: not restrict the speed of a suspended process, not restricting an application which is manually started by the user, restricting or ending a process running in a user device with low capabilities.
  • the application restricting module 302 may include a second restricting module 3022 as shown in Fig. 3f.
  • the second restricting module 3022 is configured to restrict a process running in the network using scene using a black/white list policy.
  • the apparatus may include the first restricting module 3021 and the second restricting module 3022, as shown in Fig. 3g.
  • the second restricting module 3022 may include a classifying module 3221, a first process handling module 3222, a process ending module 3223 and a second process handling module 3224, as shown in Fig. 3h and Fig. 3i.
  • the classifying module 3221 is configured to classify processes running in the network using scene.
  • the first process handling module 3222 is configured to apply no restriction on a process running in the network using scene if the process belongs to a white list.
  • the process ending module 3223 is configured to end a process running in the network using scene if the process belongs to a black list.
  • the second process handling module 3224 is configured to restrict a network speed obtained by a process running in the network using scene if the process belongs to a gray list.
  • Fig. 4 is a schematic diagram illustrating a structure of an apparatus for restricting network applications according to an example of the present disclosure.
  • the apparatus may include a scene identifying module 401, an application restricting module 402, a capability identifying module 403 and a prompting module 404.
  • Functions of the scene identifying module 401 and the application restricting module 402 may be similar to those of the scene identifying module 301 and the application restricting module 302.
  • the capability identifying module 403 is configured to identify and classify capabilities of a user device.
  • the categories of user device capabilities may include high, medium and low.
  • the prompting module 404 is configured to prompt the user to end a process and/or a service that consumes network resources if the capability identifying module 403 determines the user device has low capabilities when the user device is accessing the network.
  • a hardware module may be implemented mechanically or electronically.
  • a hardware module may include dedicated circuitry or logic that is permanently configured (e.g., as a special-purpose processor, such as a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC)) to perform certain operations.
  • a hardware module may also include programmable logic or circuitry (e.g., as encompassed within a general-purpose processor or other programmable processor) that is temporarily configured by software to perform certain operations. It will be appreciated that the decision to implement a hardware module mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations.
  • a machine-readable storage medium is also provided, which is to store instructions to cause a machine to execute a method as described herein.
  • a system or apparatus having a storage medium which stores machine -readable program codes for implementing functions of any of the above examples and which may make the system or the apparatus (or CPU or MPU) read and execute the program codes stored in the storage medium.
  • instructions of the program codes may cause an operating system running in a computer to implement part or all of the operations.
  • the program codes implemented from a storage medium are written in a storage device in an extension board inserted in the computer or in a storage in an extension unit connected to the computer.
  • a CPU in the extension board or the extension unit executes at least part of the operations according to the instructions based on the program codes to realize the technical scheme of any of the above examples.
  • the storage medium for providing the program codes may include floppy disk, hard drive, magneto-optical disk, compact disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tape drive, Flash card, ROM and so on.
  • the program code may be downloaded from a server computer via a communication network.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Information Transfer Between Computers (AREA)
  • User Interface Of Digital Computer (AREA)

Abstract

Various examples of the present disclosure provide a method and an apparatus for restricting network applications to increase network speed of the local device. According to the method, a network using scene is identified; a network application running in the network using scene is restricted using a network speed protecting policy corresponding to the network using scene identified.

Description

METHOD AND APPARATUS FOR RESTRICTING
NETWORK APPLICATIONS
Related documents
[0001] The present invention claims priority of Chinese patent application No. 201210527650.2 titled "method and apparatus for restricting network applications" and filed on October 10, 2012 with the Patent Office of the People's Republic of China, the disclosure of which is incorporated by reference in its entirety for all purposes.
Technical Field
[0002] The present disclosure relates to Web applications, and particularly to a method and an apparatus for restricting network applications.
Background
[0003] Software technology has undergone drastic changes with the rapid growth in the Internet. For example, once-prevailing stand-alone software and local network software are evolving into Internet software. The currently popular Internet "cloud" technology is also driving the development of software towards the direction of "Internet connected". Some general-purpose operating systems such as Windows, etc., do not adopt a completely free competition mechanism for software to access network resources, but allow the software which first seized the resources to use the resources. Therefore, the software that started later may not function properly because it is unable to obtain adequate resources. For example, online game software are generally sensitive to changes in network bandwidth and network delay, and a sudden increase in network resource occupancy by other applications may greatly affect the fluency of online gaming and may even make the user fall off-line in severe cases.
[0004] A conventional solution is to store a black list of processes whose network speed is restricted in a local device. When a process consumes a large amount of network resources, the process is added into the black list and then ended. As such, network resources previously occupied by the process become available, and network speed is increased. Summary
[0005] Various examples of the present disclosure provide a method and an apparatus for restricting network applications to increase network speed of a local application.
[0006] A method for restricting network applications may include: a current network using scene is identified; a network application is restricted using a network speed protecting policy corresponding to the network using scene.
[0007] An apparatus for restricting network applications may include: a scene identifying module and an application restricting module.
The scene identifying module identifies a current network using scene in real time;
The application restricting module restricts a network application using a network speed protecting policy corresponding to the network using scene identified by the scene identifying module.
[0008] The mechanism of examples of the present disclosure monitors the network using scene when a user device accesses the network and adopts a network speed protecting policy corresponding to the scene identified to restrict network applications. Therefore, targeted protection and restriction of network applications are implemented, which do not restrict a regular network application but restrict an application which is automatically started and consumes a large amount of network resources. The network speed of a local application can be increased.
Brief Description of the Drawings
[0009] Features of the present disclosure are illustrated by way of example and not limited in the following figures, in which like numerals indicate like elements, in which:
Fig. 1 is a schematic diagram illustrating an example of a computing device;
Fig. 2 is a flowchart illustrating a method for restricting network applications according to an example of the present disclosure;
Figs. 3a, 3b, 3c, 3d, 3e, 3f, 3g, 3h, 3i and 4 are schematic diagrams respectively illustrating several examples of an apparatus for restricting network applications. Detailed Descriptions
[0010] For simplicity and illustrative purposes, the present disclosure is described by referring mainly to an example thereof. In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure. As used herein, the term "includes" means includes but not limited to, the term "including" means including but not limited to. The term "based on" means based at least in part on. Due to characteristics of the Chinese language, quantities of an element, unless specifically mentioned, may be one or a plurality of, or at least one.
[0011] In an example, a computing device may execute methods and software systems of the present application. Fig. 1 is a schematic diagram illustrating an example of a computing device. As shown in Fig.l, computing device 100 may be capable of executing a method and apparatus of the present disclosure. The computing device 100 may, for example, be a device such as a personal desktop computer or a portable device, such as a laptop computer, a tablet computer, a cellular telephone, or a smart phone. The computing device 100 may also be a server that connects to the above devices locally or via a network.
[0012] The computing device 100 may vary in terms of capabilities or features. Claimed subject matter is intended to cover a wide range of potential variations. For example, the computing device 100 may include a keypad/keyboard 156. It may also include a display 154, such as a liquid crystal display (LCD), or a display with a high degree of functionality, such as a touch- sensitive color 2D or 3D display. In contrast, however, as another example, a web-enabled computing device 100 may include one or more physical or virtual keyboards, and mass storage medium 130.
[0013] The computing device 100 may also include or may execute a variety of operating systems 141, including an operating system, such as a WindowsTM or LinuxTM, or a mobile operating system, such as iOSTM, AndroidTM, or Windows MobileTM. The computing device 100 may include or may execute a variety of possible applications 142, such as a network speed protecting application 145. [0014] Further, the computing device 100 may include one or more non-transitory processor-readable storage media 130 and one or more processors 122 in communication with the non-transitory processor-readable storage media 130. For example, the non-transitory processor-readable storage media 130 may be a RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of non-transitory storage medium known in the art. The one or more non-transitory processor-readable storage media 130 may store sets of instructions, or units and/or modules that include the sets of instructions, for conducting operations described in the present application. The one or more processors may be configured to execute the sets of instructions and perform the operations in examples of the present application.
[0015] Fig. 2 is a flowchart illustrating a method for restricting network applications according to an example of the present disclosure. The entity that executes the method may be the network speed protecting application 145 in the computing device 100, e.g., a user device and the like. As shown in Fig. 2, the method may include the following procedures.
[0016] In block S201, a current scene of network usage (which is also referred to as network using scene) is identified in real time.
[0017] Different network using scenes may have different requirements for network resources, e.g., an online video scene and an online game scene generally require more bandwidth or I/O resources and are more sensitive to network delay than a webpage browsing scene. Therefore, the current network using scene is identified before restrictions are applied to network applications. The real-time identifying refers to an act of identifying a network using scene when a user starts using a network.
[0018] In an example, a uniform resource locator (URL) is monitored in real time to identify the network using scene. The URL is an identity describing the address of a webpage or other resources in the Internet. When a user accesses network resources using a browser in the user device, the system may identify the current network using scene by monitoring the URL currently being visited in real time. For example, when it is determined the user is visiting *. youku.com via a browser, it can be determined the network using scene is an online video scene. [0019] In another example, the network using scene may be identified in real time by monitoring the software the user switches on/off in real time. That is, the switching on/off of software may be used for determining the network using scene. For example, when a user starts a QQ car racing process, it can be determined that the current network using scene is an online game scene.
[0020] New network using scenes may be recorded and network using scenes may be subdivided from time to time. Sometimes, a user may be in two different network using scenes at the same time. For example, a user may be playing an online game while listening to online music. This situation is related to user habits. Therefore, an interface may be provided by the user device for the user to select applications that are allowed to run in a network using scene. A network using scene may be identified by monitoring a URL and switching on/off of applications at the same time.
[0021] When a user accesses the network by using a client application, capabilities of the user device may also affect the network speed of an application running in the user device. Restricting the network speed of a user device with low capabilities may result in lower performances of the machine. In an example, besides monitoring the network using scene in real time, capabilities including hardware capabilities and software capabilities of the user device are also identified and classified. Hardware capabilities may include capabilities of a CPU, a memory, a video card, a hard drive and the like of the user device. Software capabilities may include an operating system of the user device. Information on the hardware capabilities and software capabilities is reported to a background module in the user device. The background module may classify the capabilities of the user device into ranks such as high, medium, low, and so on. If a user device is classified to have low capabilities, information may be displayed to prompt the user to switch off a process and/or a service that is occupying network resources when the user device accesses the network.
[0022] In block S202, if the scene is identifiable, a network speed protecting policy corresponding to the scene is adopted to restrict network applications running in the network using scene.
[0023] In an example, an auxiliary policy may be adopted to restrict network applications running in the scene; and/or, a black/white list policy may be used for restricting processes running in the scene. Restricting processes using the black/white list policy may involve classifying processes running in the network using scene. In an example, when a user accesses the network under a certain network using scene, a network speed protecting application in the user device may monitor usage of network by other processes running in the network using scene, and report monitoring results to a background module. The background module classifies the processes. For example, the processes may be classified by using the name of the company producing the software, e.g., Microsoft, Xunlei and the like. Then the processes are further classified by using the name of the product to obtain application categories. If a process belongs to a known category, the process may be put into a black list or a white list. If a process does not belong to any known category, manual work is required to determine whether the process is related to the current network using scene and possibly provide a score. As such, the background module may generate a score for each of all the processes representing the correlation between the process and the network using scene. A process may be added into the white list or the black list according to the score of the process using one or multiple pre-defined thresholds. When a user enters a certain network using scene, the network speed protecting application in the user device may automatically provide a prompt message to suggest the user to adopt a network speed protecting policy associated with the scene.
[0024] Processes may be restricted according to the classification result after the processes in a network using scene are classified, i.e., if a process running in a scene belongs to the white list of the scene, the process is not restricted; if the process belongs to the black list of the scene, the process is ended; if the process belongs to a gray list, network resources consumed by the process are restricted. Taking the network using scene being a user playing an online game (e.g., a QQ car racing game) as an example, processes running in the online game scene which are necessary to the running of the online game, e.g., a system process, a gaming process, a gaming subprocess, an application accompanying the game (e.g., a game accelerator and the like) and etc., belong to a white list and thus are not restricted by the network speed protecting application in the user device. Processes running in the online gaming scene which are not necessary to the running of the online game and occupy a lot of system resources belong to a black list. The network speed protecting application in the user device may apply a restricting policy to the processes in the black list, e.g., directly ending the process or ending the process and the like. Processes belonging to a gray list, e.g., an unknown process or a third party process that the user does not wish to be ended, may be restricted according to a network speed restricting policy.
[0025] Restricting network applications running in an identifiable network using scene by using an auxiliary policy may involve not restricting the speed of a suspended process, not restricting an application which is manually started by the user, restricting or ending a process running in a user device with low capabilities, and so on. Still taking the user playing an online game as an example, when the user has started an online game process but is not playing the game, i.e., the online game process is suspended, the network speed protecting application does not restrict the network speed of the online game process in the online game scene. When the user has started the online game process and then manually starts another application that also consumes network resources, the network speed protecting application in the user device does not restrict the network speed of the application manually started by the user in the online game scene. When the user has started an online game process but the user device has low capabilities, processes running in the user device are restricted or ended to ensure there are enough resources for running the online game in the device.
[0026] The auxiliary policy and/or the black/white list policy may be network speed protecting policies stored in a local policy center or obtained from a cloud server in real time. In an example, network speed protecting policies in a server in the cloud may be obtained by using a cloud hub.
[0027] The mechanism of examples of the present disclosure monitors the network using scene in real time when a user device accesses the network, and adopts a network speed protecting policy corresponding to the scene identified to restrict network applications if the scene is identifiable. Therefore, targeted protection and restriction of network applications are implemented, which do not restrict a regular network application but restrict an application which is automatically started and consumes a large amount of network resources. The network speed of an application can be increased.
[0028] Fig. 3a is a schematic diagram illustrating a structure of an apparatus for restricting network applications according to an example of the present disclosure. Only those features related with the implementation of the mechanism are illustrated for simplicity. The apparatus as shown in Fig. 3a may be a network speed protecting software installed in a user device. The apparatus may include a scene identifying module 301 and an application restricting module 302.
[0029] A scene identifying module 301 is configured to identify a current network using scene in real time;
[0030] an application restricting module 302, configured to restrict a network application using a network speed protecting policy corresponding to the network using scene identified by the scene identifying module 301.
[0031] In an example, the scene identifying module 301 may include a first identifying module 3011 as shown in Fig. 3b.
[0032] The first identifying module 3011 is configured to monitor a URL in real time to identify the network using scene.
[0033] In an example, the scene identifying module 301 may include a second identifying module 3012 as shown in Fig. 3c.
[0034] The second identifying module 3012 is configured to monitor switching on/off of an application in real time to identify the network using scene.
[0035] As shown in Fig. 3d, the scene identifying module 301 in the apparatus may include the first identifying module 3011 and the second identifying module 3012.
[0036] In an example, the application restricting module 302 may include a first restricting module 3021 as shown in Fig. 3e.
[0037] The first restricting module 3021 is configured to restrict a network application running in the network using scene by using an auxiliary policy. For example, the auxiliary policy may include any or any combination of: not restrict the speed of a suspended process, not restricting an application which is manually started by the user, restricting or ending a process running in a user device with low capabilities.
[0038] In an example, the application restricting module 302 may include a second restricting module 3022 as shown in Fig. 3f.
[0039] The second restricting module 3022 is configured to restrict a process running in the network using scene using a black/white list policy. [0040] In an example, the apparatus may include the first restricting module 3021 and the second restricting module 3022, as shown in Fig. 3g.
[0041] In an example, the second restricting module 3022 may include a classifying module 3221, a first process handling module 3222, a process ending module 3223 and a second process handling module 3224, as shown in Fig. 3h and Fig. 3i.
[0042] The classifying module 3221 is configured to classify processes running in the network using scene.
[0043] The first process handling module 3222 is configured to apply no restriction on a process running in the network using scene if the process belongs to a white list.
[0044] The process ending module 3223 is configured to end a process running in the network using scene if the process belongs to a black list.
[0045] The second process handling module 3224 is configured to restrict a network speed obtained by a process running in the network using scene if the process belongs to a gray list.
[0046] Fig. 4 is a schematic diagram illustrating a structure of an apparatus for restricting network applications according to an example of the present disclosure. The apparatus may include a scene identifying module 401, an application restricting module 402, a capability identifying module 403 and a prompting module 404.
[0047] Functions of the scene identifying module 401 and the application restricting module 402 may be similar to those of the scene identifying module 301 and the application restricting module 302.
[0048] The capability identifying module 403 is configured to identify and classify capabilities of a user device. The categories of user device capabilities may include high, medium and low.
[0049] The prompting module 404 is configured to prompt the user to end a process and/or a service that consumes network resources if the capability identifying module 403 determines the user device has low capabilities when the user device is accessing the network.
[0050] It should be understood that in the above processes and structures, not all of the procedures and modules are necessary. Certain procedures or modules may be omitted according to the needs. The order of the procedures is not fixed, and can be adjusted according to the needs. The modules are defined based on function simply for facilitating description. In implementation, a module may be implemented by multiple modules, and functions of multiple modules may be implemented by the same module. The modules may reside in the same device or distribute in different devices. The "first", "second" in the above descriptions are merely for distinguishing two similar objects, and have no substantial meanings.
[0051] In various embodiments, a hardware module may be implemented mechanically or electronically. For example, a hardware module may include dedicated circuitry or logic that is permanently configured (e.g., as a special-purpose processor, such as a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC)) to perform certain operations. A hardware module may also include programmable logic or circuitry (e.g., as encompassed within a general-purpose processor or other programmable processor) that is temporarily configured by software to perform certain operations. It will be appreciated that the decision to implement a hardware module mechanically, in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations.
[0052] A machine-readable storage medium is also provided, which is to store instructions to cause a machine to execute a method as described herein. Specifically, a system or apparatus having a storage medium which stores machine -readable program codes for implementing functions of any of the above examples and which may make the system or the apparatus (or CPU or MPU) read and execute the program codes stored in the storage medium. In addition, instructions of the program codes may cause an operating system running in a computer to implement part or all of the operations. In addition, the program codes implemented from a storage medium are written in a storage device in an extension board inserted in the computer or in a storage in an extension unit connected to the computer. In this example, a CPU in the extension board or the extension unit executes at least part of the operations according to the instructions based on the program codes to realize the technical scheme of any of the above examples.
[0053] The storage medium for providing the program codes may include floppy disk, hard drive, magneto-optical disk, compact disk (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tape drive, Flash card, ROM and so on. Optionally, the program code may be downloaded from a server computer via a communication network.
[0054] The scope of the claims should not be limited by the embodiments set forth in the examples, but should be given the broadest interpretation consistent with the description as a whole.

Claims

Claims
1. A method for restricting network applications, comprising: identifying a current network using scene; restricting a network application using a network speed protecting policy corresponding to the network using scene.
2. The method of claim 1, wherein the identifying a current network using scene in real time comprises: monitoring a uniform resource locator (URL) to identify the network using scene; and/or monitoring switching on/off of an application to identify the network using scene.
3. The method of claim 1, further comprising: identifying capabilities of a user device, and classifying the capabilities into one of categories including high capabilities, medium capabilities and low capabilities; prompting a user to end a process and/or a service that is occupying network resources when the user device accesses the network if the user device is classified into the category of low capabilities.
4. The method of claim 1, wherein restricting a network application using a network speed protecting policy comprises: adopting an auxiliary policy to restrict a network application running in the network using scene; and/or adopting a black/white list policy to restricting a process running in the network using scene.
5. The method of claim 4, wherein the adopting an auxiliary policy to restrict a network application running in the network using scene comprises: restricting network speeds obtained by processes except for a suspended process, restricting applications except for an application which is manually started by the user, restricting or ending a process running in a user device having low capabilities; wherein adopting a black/white list policy to restricting a process running in the network using scene comprises: classifying processes running in the network using scene; applying no restricting policy to a process belonging to a white list running in the network using scene; ending a process belonging to a black list running in the network using scene; and restricting a network speed obtained by a process belonging to a gray list running in the network using scene.
6. An apparatus for restricting network applications, comprising: a scene identifying module, configured to identify a current network using scene ; an application restricting module, configured to restrict a network application using a network speed protecting policy corresponding to the network using scene identified by the scene identifying module.
7. The apparatus of claim 6, wherein the scene identifying module comprises: a first identifying module, configured to monitor a uniform resource locator (URL) to identify the network using scene; and/or a second identifying module, configured to monitor switching on/off of an application to identify the network using scene.
8. The apparatus of claim 6, further comprising: a capability identifying module, configured to identify and classify capabilities of a user device into categories including high capabilities, medium capabilities and low capabilities; and a prompting module, configured to prompt the user to end a process and/or a service that consumes network resources if the capability identifying module identifies the user device has low capabilities when the user device accesses the network.
9. The apparatus of claim 6, wherein the application restricting module comprises: a first restricting module, configured to adopt an auxiliary policy to restrict the network application running in the network using scene; and/or a second restricting module, configured to restrict a process running in the network using scene using a black/white list policy.
10. The apparatus of claim 9, wherein the first restricting module is configured to restrict network speeds obtained by processes except for a suspended process, restrict applications except for an application which is manually started by the user, restricting or end a process running in a user device having low capabilities; and wherein the second restricting module comprises: a classifying module, configured to classify processes running in the network using scene; a first process handling module, configured to apply no restriction on a process running in the network using scene if the process belongs to a white list; a process ending module, configured to end a process running in the network using scene if the process belongs to a black list; a second process handling module, configured to restrict a network speed obtained by a process running in the network using scene if the process belongs to a gray list.
PCT/CN2013/087748 2012-12-10 2013-11-25 Method and apparatus for restricting network applications Ceased WO2014090080A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US14/729,694 US10116586B2 (en) 2012-12-10 2015-06-03 Managing network bandwidth for network applications

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210527650.2 2012-12-10
CN201210527650.2A CN103873273B (en) 2012-12-10 2012-12-10 A kind of method and apparatus that network application is limited

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/729,694 Continuation US10116586B2 (en) 2012-12-10 2015-06-03 Managing network bandwidth for network applications

Publications (1)

Publication Number Publication Date
WO2014090080A1 true WO2014090080A1 (en) 2014-06-19

Family

ID=50911423

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/087748 Ceased WO2014090080A1 (en) 2012-12-10 2013-11-25 Method and apparatus for restricting network applications

Country Status (3)

Country Link
US (1) US10116586B2 (en)
CN (1) CN103873273B (en)
WO (1) WO2014090080A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113271360A (en) * 2021-05-26 2021-08-17 维沃移动通信(杭州)有限公司 Recommendation method and device of application program, electronic device and medium

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105915360A (en) * 2015-10-23 2016-08-31 乐视致新电子科技(天津)有限公司 Method for adjusting equipment network speed on router and device and system thereof
CN107634962B (en) * 2017-10-11 2019-06-18 Oppo广东移动通信有限公司 Network bandwidth management method and related products
US10776979B2 (en) * 2018-05-31 2020-09-15 Microsoft Technology Licensing, Llc Virtual skeleton based on computing device capability profile
CN110086932B (en) * 2019-04-24 2021-05-25 努比亚技术有限公司 Process starting control method, wearable device and storage medium
CN110090446B (en) * 2019-05-14 2022-11-08 腾讯科技(成都)有限公司 Method and device for processing report information in game
US12047373B2 (en) * 2019-11-05 2024-07-23 Salesforce.Com, Inc. Monitoring resource utilization of an online system based on browser attributes collected for a session
CN111917764A (en) * 2020-07-28 2020-11-10 成都卫士通信息产业股份有限公司 Service operation method, device, equipment and storage medium
CN115396957B (en) * 2022-09-01 2026-01-06 亿咖通(湖北)技术有限公司 Vehicle network control methods, devices, equipment and storage media

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008039033A1 (en) * 2006-09-28 2008-04-03 Hoide Co., Ltd. Policy based network management method and system
CN101431473A (en) * 2008-12-31 2009-05-13 深圳市迅雷网络技术有限公司 Method and apparatus for implementing network speed limit
CN102111333A (en) * 2011-02-17 2011-06-29 上海聚欣网络科技有限公司 Method, device and equipment for determining network speed limiting information in network node
CN102209107A (en) * 2011-05-11 2011-10-05 奇智软件(北京)有限公司 An intelligent speed limiting method and device, a download system

Family Cites Families (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6910210B1 (en) * 1998-11-24 2005-06-21 Microsoft Corp. System and method for terminating applications
US6757661B1 (en) * 2000-04-07 2004-06-29 Netzero High volume targeting of advertisements to user of online service
US20040158630A1 (en) * 2003-02-12 2004-08-12 Chang Tsung-Yen Dean Monitoring and controlling network activity in real-time
US20090043692A1 (en) * 2007-08-07 2009-02-12 Nokia Corporation Downloading of Content
US8510743B2 (en) * 2007-10-31 2013-08-13 Google Inc. Terminating computer applications
CN101562560A (en) * 2008-04-18 2009-10-21 北京启明星辰信息技术股份有限公司 Universal traffic control method and system
US8713535B2 (en) * 2008-06-30 2014-04-29 Microsoft Corporation Reliable and accurate usage detection of a software application
US9081478B2 (en) * 2010-02-25 2015-07-14 Patrick Pecorilli Unified process management software and method
US9098333B1 (en) * 2010-05-07 2015-08-04 Ziften Technologies, Inc. Monitoring computer process resource usage
CN102377588B (en) * 2010-08-13 2014-04-16 腾讯科技(深圳)有限公司 Network transmission control method and system
US8781985B2 (en) * 2010-12-14 2014-07-15 Microsoft Corporation Addressing system degradation by application disabling
US8997171B2 (en) * 2011-08-19 2015-03-31 Microsoft Technology Licensing, Llc Policy based application suspension and termination
US8863297B2 (en) * 2012-01-06 2014-10-14 Mobile Iron, Inc. Secure virtual file management system
US20140007106A1 (en) * 2012-07-02 2014-01-02 Arnold S. Weksler Display and Terminate Running Applications
GB201215279D0 (en) * 2012-08-28 2012-10-10 Microsoft Corp Downloading content

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008039033A1 (en) * 2006-09-28 2008-04-03 Hoide Co., Ltd. Policy based network management method and system
CN101431473A (en) * 2008-12-31 2009-05-13 深圳市迅雷网络技术有限公司 Method and apparatus for implementing network speed limit
CN102111333A (en) * 2011-02-17 2011-06-29 上海聚欣网络科技有限公司 Method, device and equipment for determining network speed limiting information in network node
CN102209107A (en) * 2011-05-11 2011-10-05 奇智软件(北京)有限公司 An intelligent speed limiting method and device, a download system

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113271360A (en) * 2021-05-26 2021-08-17 维沃移动通信(杭州)有限公司 Recommendation method and device of application program, electronic device and medium
CN113271360B (en) * 2021-05-26 2023-09-29 维沃移动通信(杭州)有限公司 Application program recommendation method and device, electronic equipment and medium

Also Published As

Publication number Publication date
CN103873273B (en) 2017-03-08
US10116586B2 (en) 2018-10-30
CN103873273A (en) 2014-06-18
US20150271094A1 (en) 2015-09-24

Similar Documents

Publication Publication Date Title
US10116586B2 (en) Managing network bandwidth for network applications
CN111526529B (en) Network prompting method and device and electronic equipment
US11606620B2 (en) Method and device for acquiring virtual resource and storage medium
US10884605B2 (en) Methods and systems for displaying hidden information on a web page
US10516640B2 (en) Group message updating and displaying method, apparatus, and terminal
CN105718875B (en) A kind of visual fatigue detection method and user terminal
US20160241589A1 (en) Method and apparatus for identifying malicious website
US20150350396A1 (en) Method for controlling background through voice and mobile terminal
CN106708496B (en) Processing method and device for label page in graphical interface
CN107835984B (en) Thermal mitigation user experience
CN103617393A (en) A detection method of mobile Internet malicious application software based on support vector machine
CN105094728A (en) Intelligent screen-splitting method and device for terminal
CN103500307A (en) Mobile internet malignant application software detection method based on behavior model
CN107797841A (en) Window control method, apparatus, terminal device and storage medium
CN107544842A (en) Application program processing method and device, computer equipment, storage medium
CN110784727B (en) Reporting method and device for live broadcast
CN110659618A (en) Video distribution method and device
US10338663B2 (en) Energy saving method and apparatus of mobile terminal
CN107633172B (en) Malicious webpage monitoring method and electronic equipment
CN107197489A (en) Network switching method, mobile terminal and computer-readable storage medium
CN106528148A (en) Interface skipping method, interface skipping system and terminal equipment
CN113467659B (en) Icon display method, device and storage medium
US10878078B2 (en) System notification service control method, apparatus, terminal device, and storage medium
Albasir et al. Smart mobile web browsing
CN107491349A (en) Application program processing method and device, computer equipment, storage medium

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13862525

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205N DATED 18/08/2015)

122 Ep: pct application non-entry in european phase

Ref document number: 13862525

Country of ref document: EP

Kind code of ref document: A1