WO2017004952A1 - 用于检测和阻止恶意点击广告链接的方法和装置 - Google Patents

用于检测和阻止恶意点击广告链接的方法和装置 Download PDF

Info

Publication number
WO2017004952A1
WO2017004952A1 PCT/CN2015/098733 CN2015098733W WO2017004952A1 WO 2017004952 A1 WO2017004952 A1 WO 2017004952A1 CN 2015098733 W CN2015098733 W CN 2015098733W WO 2017004952 A1 WO2017004952 A1 WO 2017004952A1
Authority
WO
WIPO (PCT)
Prior art keywords
network access
access request
advertisement link
advertisement
network
Prior art date
Application number
PCT/CN2015/098733
Other languages
English (en)
French (fr)
Inventor
叶爱平
蒋嘉琦
陈鑫
韩龙
Original Assignee
安一恒通(北京)科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 安一恒通(北京)科技有限公司 filed Critical 安一恒通(北京)科技有限公司
Publication of WO2017004952A1 publication Critical patent/WO2017004952A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]

Definitions

  • the present invention relates to network technologies, and more particularly to a method and apparatus for detecting and blocking malicious click advertisement links.
  • Information media such as radio, television, and newspapers and magazines are traditional media for advertising.
  • network technologies especially wireless network technologies, the network has become a new advertising medium that can quickly and effectively implement information promotion.
  • the advertisement platform located on the network side usually cooperates with the traffic channel to push the advertisement information to the network user by using the traffic channel. Because there is often a relationship between the traffic channel and the advertising platform, there may be a malicious click on the advertisement link in the traffic channel, and the malicious click behavior will bring loss of interest to the advertising platform.
  • the network access request transmitted by the user side is usually detected on the network side, and when the network access request generated by the malicious click behavior is detected, the network access request is blocked.
  • the network accesses the request to avoid malicious click activity that harms the interests of the advertising platform.
  • the inventor has found that although the existing implementation method for detecting and blocking malicious click advertisement links can avoid malicious click activity causing damage to the advertisement platform, the network access request corresponding to the malicious click behavior
  • the network transmission resource has been occupied, and the network side detects all network access requests transmitted from the user side. A large amount of computing resources on the network side are consumed, which affects the performance of devices on the network side.
  • a method for detecting and blocking a malicious click advertisement link includes the steps of: monitoring, in a kernel mode, a network access request, uploading the monitored network access request to User mode, and in the case that it is determined that the intercepted network access request meets the corresponding advertisement link interception information in the interception information set, intercepting the intercepted network access request; in the user state, determining In the case that the network access request from the kernel mode belongs to the network access request for the advertisement, the click status of the advertisement link corresponding to the network access request is counted, and in the case that the click condition is determined to meet the malicious click condition, the kernel state is An advertisement link intercepting information for the advertisement link is sent to update the interception information set.
  • an apparatus for detecting and blocking a malicious click advertisement link mainly comprising: a listening module, configured in a kernel mode, adapted to listen for a network access request, and to monitor The network access request is uploaded to the user state; the intercepting module is set in the kernel mode, and is adapted to determine, when the intercepted network access request meets the corresponding advertisement link interception information in the interception information set, The network access request to the interception process; the statistics module is set in the user mode, and is adapted to count the advertisement corresponding to the network access request if it is determined that the network access request from the kernel state belongs to the network access request for the advertisement a click condition of the link; the control module is configured to be in a user mode, and is adapted to send the advertisement link interception information for the advertisement link to the kernel state to update the interception information, if the click condition is determined to meet the malicious click condition set.
  • the present invention monitors and reports a network access request by using a kernel state on the user side, so that the user state can calculate the current status of the advertisement link according to the received network access request in real time. Click on the situation, in this way, in the case of malicious click on the ad link phenomenon, the user mode can be found in time, and in time to the kernel state Send the corresponding advertisement link to intercept the information, so that the kernel mode can intercept the corresponding network access request generated subsequently, so that the network access request generated by the malicious click advertisement link is not sent by the user side to the network side, and the malicious click is
  • the phenomenon of the advertisement link is limited to the user side; since the user side in the present invention only listens and intercepts the network access request generated internally, the technical solution provided by the present invention has very limited resource consumption to the user side itself.
  • the technical solution provided by the present invention can eliminate the adverse effect of the malicious click on the advertisement link phenomenon on the network in the earliest time period, thereby saving the network. Transfer resources and improve device performance on the network side.
  • FIG. 1 is a flowchart of a method for detecting and blocking a malicious click advertisement link according to Embodiment 1 of the present invention
  • FIG. 2 is a flowchart of a method for detecting and blocking a malicious click advertisement link according to Embodiment 2 of the present invention
  • FIG. 3 is a flowchart of a method for detecting and blocking a malicious click advertisement link according to Embodiment 3 of the present invention
  • FIG. 4 is a schematic diagram of an apparatus for detecting and blocking a malicious click advertisement link according to Embodiment 4 of the present invention.
  • user equipment as used in the context, which may also be referred to as “user network terminal equipment”, refers to intelligence located on the user side and capable of performing predetermined processing such as numerical calculations and/or logical calculations by running predetermined programs or instructions.
  • An electronic device which may include a processor and a memory, the processor executing a pre-stored instruction stored in the memory to perform a predetermined process, or performing a predetermined process by hardware such as an ASIC, an FPGA, a DSP, or the like, or a combination thereof to realise.
  • server as used in the context may include: a logical server or a server on an entity, and the server on the entity may also be referred to as a "network device", which is located on the network side (eg, in the cloud), and may be scheduled to run by running.
  • An intelligent electronic device that executes a predetermined process, such as numerical calculations and/or logic calculations, that can include a processor and a memory that is executed by the processor to execute a predetermined process pre-stored in the memory to perform a predetermined process, or by an ASIC.
  • the hardware such as FPGA or DSP performs a predetermined processing process or is implemented by a combination of the two.
  • the above intelligent electronic device includes, but is not limited to, a desktop PC, a notebook computer, a smart mobile phone, a tablet computer, etc., which can be connected to the network through a wired or wireless manner; the server on the entity may be a small desktop device or a large desktop device;
  • the servers in the network include, but are not limited to, a single network server, a server group composed of multiple network servers, or a cloud computing system consisting of a large number of computers or network servers, wherein cloud computing is a type of distributed computing.
  • a super virtual computer consisting of a group of loosely coupled computers.
  • Embodiment 1 A method for detecting and blocking a malicious click on an advertisement link.
  • FIG. 1 is a flowchart of a method for detecting and blocking a malicious click advertisement link according to the embodiment, and the method shown in FIG. 1 mainly includes steps S110 and S111 performed in a kernel mode and steps performed in a user state. S120 and step S121. The respective steps in Fig. 1 will be described below.
  • S110 Listen to the network access request, and upload the monitored network access request to the user state.
  • a corresponding network access request is generated in the user equipment, and the embodiment is a kernel state pair on the user side.
  • a network access request is being listened to.
  • the network access request in the kernel mode can be monitored by using a network filter driver (NetFilter) provided by the operating system of the user equipment; for example, for the WINDOWS XP operating system, the TDI (Trandport Driver Interface) can be used in this embodiment.
  • the driver interface monitors the network access request in the kernel mode.
  • the embodiment can use the WFP (Windows Filtering Platform) framework to monitor network access requests. This embodiment does not limit the specific implementation manner of monitoring the network access request in the kernel mode.
  • the embodiment can monitor the HTTP message in the kernel mode. That is to say, when an HTTP message is detected in the kernel state, the HTTP message is reported from the kernel state to the user state.
  • HTTP HyperText Transfer Protocol
  • the type of the message monitored in this embodiment should also change accordingly. This embodiment does not limit the specific manifestation of network access requests.
  • the embodiment needs to perform a processing operation of reporting the network access request to the user state, and A judgment processing operation to perform whether or not the network access request needs to be intercepted.
  • the embodiment does not limit the sequence of execution of the report processing operation and the intercept judgment processing operation. That is, the report processing operation and the intercept judgment processing operation may be performed simultaneously, or the report processing operation may be performed before the intercept judgment processing operation is performed. It is also possible to perform an interception judgment processing operation and then perform a report processing operation.
  • the interception information set is used to determine whether the intercepted network access request needs to be intercepted, that is, the interception information set is preset in the kernel state, and the interception information set may be empty or may include at least one advertisement.
  • Link interception information if the interception information set is empty in the initial state; if the user side does not have a malicious click advertisement link phenomenon in the current period of time, the interception information set is empty; and on the user side at the current time
  • the interception information set includes one or more advertisement link interception information because the user state sends the advertisement link interception information to the kernel state. It can be seen that the interception information set in the kernel state of this embodiment is dynamically maintained and updated by the user state.
  • the advertisement link interception information in this embodiment mainly includes the feature information of the network access request, and the feature information is mainly used to identify the network access request that needs to be intercepted.
  • the feature information may be identification information of the network access request, and the feature information may be link address information or the like.
  • the advertisement link interception information in this embodiment may further include other information, such as the validity period of the advertisement link interception information of this article, and the like. This embodiment does not limit the specific content included in the advertisement link interception information.
  • the kernel mode may automatically execute the corresponding advertisement link interception information in the deletion interception information set or perform the corresponding in the interception information set when the validity period corresponding to the advertisement link interception information ends.
  • the advertisement link interception information sets an expiration flag and the like; and if the advertisement link interception information does not include an expiration date, the kernel mode may delete the corresponding advertisement link interception in the interception information set according to the delete advertisement link interception information notification sent by the user state. information.
  • the interception information set in this embodiment may use a file or a database or a table or an array to collect the advertisement link interception information. This embodiment does not limit the interception information set. Specific form of expression.
  • a specific example of the interception judgment in this embodiment is: if the HTTP message is intercepted in the kernel mode, it is determined whether the current interception information set is empty. If the interception information set is empty, the interception judgment result is incorrect.
  • the HTTP message performs subsequent intercept processing operations, and the kernel state performs subsequent processing according to the existing manner. For example, the kernel state sends the HTTP message to the network side through hardware; if the intercept information set is not empty, the link in the HTTP message is The address information is matched with the link address information in each advertisement link interception information in the interception information set respectively.
  • the result of the interception judgment is that the HTTP message needs to be intercepted; if there is no advertisement link interception information in the interception information set that matches the link address information in the HTTP message, the interception judgment result is There is no need to intercept the HTTP message, and the kernel state is now Manner for subsequent processing, such as kernel mode transmits the HTTP message to the network hardware.
  • the interception process for the network access request in this embodiment may specifically be to discard the network access request (ie, delete the HTTP message), etc., to prevent the network access request from being transmitted by the user side to the network side.
  • the embodiment can implement the interception judgment processing operation and the intercept processing operation on the network access request in the kernel state by using the corresponding function provided by the operating system in the user equipment; for the WINDOWS XP operating system, the embodiment can utilize the operating system.
  • the NDIS Network Driver Interface Specification
  • the network access request performs an intercept judgment processing operation and an intercept processing operation. This embodiment does not limit the specific implementation manner of the interception judgment processing operation and the interception processing operation for the network access request in the kernel state.
  • the network access request when the user mode receives the network access request from the kernel mode, The network access request should be first judged in the user state to determine whether the network access request from the kernel mode belongs to a network access request for an advertisement (ie, a network access request generated by clicking an advertisement link); and then, If the network access request belongs to the network access request for the advertisement, the statistical operation of the click condition of the advertisement link is performed based on the network access request; and if it is determined that the network access request does not belong to the network access request for the advertisement, The network access request will not be counted as a click operation, but the network access request in the user mode can be directly discarded.
  • a network access request for an advertisement ie, a network access request generated by clicking an advertisement link
  • the pre-set advertisement link feature information set may be used to determine whether the network access request from the kernel mode belongs to a network access request for an advertisement, that is, a set of advertisement link feature information is preset in the user state.
  • the advertisement link feature information set in this embodiment is not normally empty, that is, usually includes at least one advertisement link feature information, and the advertisement link feature information is mainly used to represent a network access request generated by clicking the advertisement link.
  • the advertisement link feature information may be specifically the identification information of the advertisement link, for example, the advertisement link feature information may be specifically the advertisement link address information and the like.
  • the advertisement link feature information set of this embodiment may be in an empty state in an initial state.
  • the advertisement link feature information set of the embodiment is generally dynamically updated by the network side. For example, when the user side receives the notification of adding the advertisement link feature information sent by the network side (such as the cloud server), the advertisement in the notification is used. The link feature information is added to the advertisement link feature information set; if the user side receives the notification of deleting the advertisement link feature information sent by the network side (such as the cloud server), the advertisement link feature is selected according to the information carried in the notification. The corresponding ad link feature information is deleted from the information collection.
  • the advertisement link feature information in the advertisement link feature information set corresponds to the validity period
  • the user state may automatically execute the advertisement link feature information corresponding to the advertisement link feature information set or execute when the validity period corresponding to the advertisement link feature information ends.
  • the feature information notification deletes the corresponding advertisement link feature information in the combination of the advertisement link feature information.
  • the advertisement link feature information set of this embodiment may adopt a file or a database or a table. Or an array or the like, the embodiment does not limit the specific expression form of the advertisement link feature information set.
  • a specific example of determining whether the network access request belongs to the network access request for the advertisement in the embodiment is: extracting the link address information from the network access request from the kernel mode, and extracting the extracted link address information and the advertisement link feature information set The advertisement link feature information is matched one by one. If there is advertisement link feature information matching the link address information in the advertisement link feature information set, the current judgment result is that the network access request belongs to a network access request for the advertisement, otherwise The result of this judgment is that the network access request does not belong to a network access request for an advertisement.
  • various existing statistical methods may be used to count the click status of the advertisement link corresponding to the network access request of the advertisement, and a simple example is based on the historical network access request and the current network access request statistics in a period of time. The frequency of visits or the number of visits, etc. of the advertisement link within a predetermined time period. This embodiment does not limit the specific implementation manner of the click condition of the advertisement link corresponding to the statistical network access request.
  • the advertisement link interception information for the corresponding advertisement link is sent to the kernel state to update the interception information set.
  • a malicious click condition for performing a malicious click determination is pre-set, and the malicious click condition may be sent by the network side (such as a cloud server) and stored locally by the user side (for example, stored in the user).
  • the malicious click condition may be that the frequency of access within a predetermined time period exceeds a predetermined access frequency, or the number of accesses within a predetermined time period exceeds a predetermined number of accesses, and the like.
  • the malicious click condition may be a malicious click determination policy dynamically set by the network side based on the data mining result; this embodiment does not limit the specific content of the malicious click condition.
  • the present embodiment should determine whether the currently counted click condition meets the malicious click condition, and if it is determined that the currently counted click condition meets the malicious click condition, then the determination is made.
  • the network access request is a network access request generated by maliciously clicking the advertisement link, and the user mode should send the advertisement link interception information for the advertisement link to the kernel state for the network access request, so that the kernel mode can be
  • the network access request is intercepted for subsequent malicious clicks on the advertisement link; if it is determined that the currently counted click condition does not meet the malicious click condition, the user state determines that the network access request is not due to malicious click on the advertisement link.
  • the generated network access request, the user mode can directly discard the network access request from the kernel state.
  • the corresponding advertisement link interception information may be executed according to the current situation of the advertisement link interception information in the kernel mode. The operation is performed; if the user state first determines whether there is currently valid advertisement link interception information in the kernel state (for example, determining whether the advertisement link interception information exists in the kernel state; and determining whether the advertisement link interception information exists in the kernel state and Whether the advertisement link intercepts the information is in a valid state), if there is currently valid advertisement link interception information in the kernel state, the user state may not send the advertisement link interception information to the kernel state (of course, in this case, the user state It is also feasible to send the advertisement link interception information to the kernel state; if there is no valid advertisement link interception information in the kernel state (such as the presence of the advertisement link interception information in the kernel state is in a stale state), the user The state should send the advertisement link interception information to the kernel state.
  • the advertisement link interception information sent by the user state to the kernel state may be the advertisement link interception information that is sent by the network side and stored locally on the user side. For example, in the process of sending the advertisement link feature information to the user side, the network side The advertisement link feature information is respectively set to the corresponding advertisement link interception information, and then the network side sends the advertisement link feature information together with the corresponding advertisement link interception information to the user side.
  • the advertisement link interception information sent by the user state to the kernel state may also be the advertisement link interception information generated by the user state or the advertisement link interception information set by default, and the embodiment does not restrict the user state from advertising to the kernel state.
  • the specific implementation of the link interception information and the specific source of the advertisement link interception information issued by the user state may be the advertisement link interception information that is sent by the network side and stored locally on the user side.
  • the advertisement link feature information is respectively set to the corresponding advertisement link interception information, and then the network side sends the advertisement link feature information together with the corresponding advertisement link interception information
  • This embodiment can effectively limit the phenomenon of malicious clicks on the advertisement link to the user side, and avoid the phenomenon of establishing an advertisement link between the user side and the network side due to malicious clicks, thereby effectively protecting the interests of the advertisement platform. It also saves network transmission resources and improves device performance on the network side.
  • Embodiment 2 A method for detecting and blocking a malicious click on an advertisement link.
  • the user equipment on the user side adopts the WINDOWS XP operating system as an example, and the method for detecting and blocking the malicious click advertisement link in this embodiment is described with reference to FIG. 2 .
  • the left side is the existing processing flow of the network access request after the user initiates the network access request; the right side is the processing flow of the network access request initiated by the user for the user; the upper side is executed in the user state. Operation; the lower side is the operation performed in the kernel mode.
  • the user initiates a network access request due to a network access operation (such as clicking an advertisement link in the current page), and the network access request is transmitted from the user state to the kernel state, and proceeds to step S22 and step S23, respectively.
  • a network access operation such as clicking an advertisement link in the current page
  • the network access request is processed in the kernel mode to be sent to the network side, such as performing TCP/IP-based processing for the network access request, and the like, to step S24.
  • the network access request transmitted to the kernel mode is reported from the kernel state to the user state based on the monitoring of the TDI framework, to step S25.
  • the interception judgment of the network access request processed by the step S22 is performed based on the NDIS, and the corresponding interception process is performed according to the interception judgment result. Specifically, whether the network access request processed in step S22 includes the advertisement link is determined. Blocking the advertisement link interception information in the information set, if it is included, determining that the network access request needs to be intercepted. In this case, the operation of sending the hardware to the network side for the network access request should be prohibited, for example, the network access can be directly discarded. The request; if the advertisement link interception information is not included, it is determined that the network access request does not need to be intercepted, to step S26.
  • the user state determines, according to the advertisement link feature information set formed by the advertisement link feature information acquired from the cloud server, whether the current network access request from the kernel mode belongs to a network access request for the advertisement, and if the determination result is a network access for the advertisement. If the request is made, the user state performs click statistics on the advertisement link corresponding to the network access request, and continues to determine whether the currently counted click condition meets the malicious click condition obtained by the user side from the cloud server, and if the judgment result is currently calculated. If the click condition meets the malicious click condition, the user state sends the corresponding advertisement link interception information to the kernel state; if the judgment result is that the currently counted click condition does not meet the malicious click condition, the user state may directly discard the network access request.
  • step S26 The network access request processed in step S22 is sent to the network side through hardware.
  • Embodiment 3 A method for detecting and blocking a malicious click on an advertisement link.
  • the user equipment on the user side adopts the WINDOWS vista operating system as an example, and the method for detecting and blocking the malicious click advertisement link in this embodiment is described with reference to FIG. 3 .
  • the left side is the existing processing flow of the network access request after the user initiates the network access request; the right side is the processing flow of the network access request initiated by the user for the user; the upper side is executed in the user mode. Operation; the lower side is the operation performed in the kernel mode.
  • step S31 The user initiates a network access request due to a network access operation (such as clicking an advertisement link in the current page), and the network access request is transmitted from the user state to the kernel state, and proceeds to step S32 and step S33, respectively.
  • a network access operation such as clicking an advertisement link in the current page
  • the network access request is processed in the kernel mode to send to the network side, for example, performing TCP/IP-based processing for the network access request, and the like, to step S33.
  • the network access request transmitted to the kernel mode is reported from the kernel state to the user state based on the monitoring of the WFP framework, to step S34.
  • the interception judgment of the network access request processed by the above step S32 is implemented based on the WFP framework, and the corresponding interception processing is performed according to the interception judgment result; specifically, it is determined whether the network access request processed in step S32 includes an advertisement.
  • the link interception information in the link interception information collection if included, determines that the network access request needs to be intercepted. In this case, the operation of sending the hardware to the network side by the network access request should be prohibited, for example, the network can be directly discarded.
  • the user state determines, according to the advertisement link feature information set formed by the advertisement link feature information acquired from the cloud server, whether the current network access request from the kernel mode belongs to a network access request for the advertisement, and if the determination result is a network access for the advertisement.
  • the request the user state performs click statistics on the advertisement link corresponding to the network access request, and continues to determine whether the currently counted click status conforms to the user side from the cloud server.
  • the malicious click condition obtained by the user if the judgment result is that the currently counted click condition meets the malicious click condition, the user state sends the corresponding advertisement link interception information to the kernel state; if the judgment result is that the currently counted click condition does not meet the malicious situation By clicking the condition, the user mode can directly discard the network access request.
  • step S35 The network access request processed in step S32 is sent to the network side through hardware.
  • Embodiment 4 A device for detecting and blocking a malicious click on an advertisement link.
  • the device of this embodiment is disposed in a user equipment, and the main structure of the device is as shown in FIG. 4 .
  • the apparatus for detecting and blocking a malicious click advertisement link includes: a listening module 400, an intercepting module 410, a statistics module 420, and a control module 430.
  • the apparatus can also include a collection update module 440.
  • the monitoring module 400 is set in the kernel mode, and the monitoring module 400 is mainly used for monitoring the network access request, and uploading the monitored network access request to the user state.
  • a corresponding network access request is generated in the user equipment, and the monitoring module 400 is a kernel state pair on the user side.
  • a network access request is being listened to.
  • the monitoring module 400 can monitor the network access request in the kernel mode by using a network filtering driver (NetFilter) provided by the operating system of the user equipment; for example, for the WINDOWS XP operating system, the monitoring module 400 can utilize the TDI framework in the kernel state.
  • the network access request is monitored; for example, for the WINDOWS vista operating system, the listening module 400 can utilize the WFP framework to listen for network access requests.
  • This embodiment does not limit the specific implementation manner in which the listening module 400 listens to the network access request in the kernel mode.
  • the listening module 400 can listen to the HTTP message in the kernel state, that is, in the kernel mode of the listening module 400. When the HTTP message is detected, the listening module 400 reports the HTTP message from the kernel state to the user state.
  • the type of the message monitored by the listening module 400 should also be The corresponding changes have taken place. This embodiment does not limit the specific manifestation of the network access request monitored by the listening module 400.
  • the intercepting module 410 is disposed in the kernel mode, and the intercepting module 410 is mainly adapted to the network monitored by the monitoring module 400 in the case that it is determined that the network access request monitored by the listening module 400 meets the corresponding advertisement link interception information in the interception information set. Access requests are intercepted.
  • the monitoring module 400 listens to the network access request in the kernel mode, on the one hand, the monitoring module 400 needs to perform a processing operation for reporting the network access request to the user state, and on the other hand, the intercepting module 410 needs to perform the processing. Whether the network access request needs to intercept the judgment processing operation.
  • the embodiment does not limit the sequence in which the monitoring module 400 performs the reporting processing operation and the intercepting module 410 performs the intercepting determination processing operation. That is, the reporting processing operation performed by the monitoring module 400 and the intercepting determination processing operation performed by the intercepting module 410 can be performed.
  • the monitoring module 400 may perform the reporting processing operation first, the intercepting module 410 performs the intercepting and determining processing operation, and the intercepting module 410 first performs the intercepting and determining processing operation, and the monitoring module 400 performs the reporting processing operation.
  • the intercepting module 410 uses the intercepting information set to determine whether the network access request monitored by the monitoring module 400 needs to be intercepted.
  • the intercepting module 410 is preset with an intercepting information set, and the intercepting information set usually includes at least one piece.
  • the advertisement link intercepts the information, of course, the interception information set also exists in an empty state; if the interception information set is in an empty state in the initial state; and if the user side does not have the malicious click advertisement link phenomenon in the current period of time, The interception information set is in an empty state; and in the case that the user side has a malicious click advertisement link phenomenon in the current period of time, the user state sends the advertisement link interception information to the kernel state to make the interception information set. Contains one or more ad link blocking information. It can be seen that the interception information set in the kernel state of this embodiment is dynamically maintained and updated by the user state.
  • the advertisement link interception information in this embodiment mainly includes the feature information of the network access request, and the feature information is mainly used to identify the network access request that needs to be intercepted.
  • the feature information may be identification information of the network access request, and the feature information may be link address information or the like.
  • the advertisement link interception information in this embodiment may further include other information, such as the validity period of the advertisement link interception information of this article, and the like. This embodiment does not limit the specific content included in the advertisement link interception information.
  • the intercepting module 410 may automatically perform the corresponding advertisement link interception information in the deletion interception information set or perform correspondingly in the interception information set when the validity period corresponding to the advertisement link interception information ends.
  • the advertisement link intercepting information sets an expiration flag and the like; if the advertisement link interception information does not include an expiration date, the intercepting module 410 may delete the corresponding advertisement link in the interception information set according to the deleted advertisement link interception information notification sent by the user state. Intercept information.
  • the interception information set in this embodiment may use a file or a database or a table or an array to collect the advertisement link interception information. This embodiment does not limit the specific expression form of the interception information set.
  • a specific example of the interception determination of the interception module 410 is: in the case that the interception module 400 listens to the HTTP message, the interception module 410 determines whether the current interception information set is empty, and if the interception information set is empty, the interception judgment of this time The result is that the HTTP message is not subjected to subsequent intercept processing operations, and the kernel mode performs subsequent processing according to the existing manner.
  • the kernel mode sends the HTTP message to the network side through hardware; if the intercept information set is not empty, the intercepting module 410 The link address information in the HTTP message is matched with the link address information in each advertisement link interception information in the interception information set respectively, if there is an advertisement in the interception information set that matches the link address information in the HTTP message.
  • the interception judgment result of this time is that the HTTP message needs to be intercepted; if the interception information set does not have the advertisement link interception information that matches the link address information in the HTTP message, The interception judgment result is that the HTTP message does not need to be entered.
  • kernel mode proceeds as a conventional manner, such as kernel mode transmits the HTTP message to the network hardware.
  • the intercepting process of the network access request by the intercepting module 410 may specifically be that the intercepting module 410 discards the network access request (ie, deletes the HTTP message) and the like to prevent the network access request from being transmitted by the user side to the network side.
  • the intercepting module 410 can be implemented by using corresponding functions provided by an operating system in the user equipment.
  • the interception determination processing operation and the intercept processing operation are performed on the network access request in the kernel state; for the WINDOWS XP operating system, the intercepting module 410 can intercept the network access request in the kernel state by using the NDIS provided by the operating system. And intercepting the processing operation; and for the WINDOWS vista operating system, the intercepting module 410 can utilize the WFP framework to intercept the network access request and perform the interception processing operation and the intercept processing operation.
  • This embodiment does not limit the specific implementation manner in which the interception module 410 performs an interception determination processing operation and an interception processing operation on the network access request in the kernel state.
  • the statistics module 420 is set in the user mode, and the statistics module 420 is mainly adapted to count the clicks of the advertisement links corresponding to the network access request in the case that it is determined that the network access request from the kernel state belongs to the network access request for the advertisement.
  • the statistics module 420 should first determine, in the user state, the network access request to determine whether the network access request from the kernel mode belongs to the network for advertising. Access request (ie, a network access request generated by clicking on the advertisement link); then, if the statistics module 420 determines that the network access request belongs to a network access request for the advertisement, the statistics module 420 further advertises based on the network access request. The statistical operation of the link click condition; and if the statistics module 420 determines that the network access request does not belong to the network access request for the advertisement, the statistics module 420 does not perform the statistical operation of the click condition on the network access request, but is statistically Module 420 directly discards the network access request in the user mode.
  • Access request ie, a network access request generated by clicking on the advertisement link
  • the statistics module 420 further advertises based on the network access request. The statistical operation of the link click condition; and if the statistics module 420 determines that the network access request does not belong to the network access request for the advertisement, the statistics module 420 does
  • the statistics module 420 can determine whether the network access request from the kernel mode belongs to the network access request for the advertisement by using the preset advertisement link feature information set, that is, the advertisement link feature information set is preset in the user state.
  • the advertisement link feature information set in this embodiment is not normally empty, that is, usually includes at least one advertisement link feature information, and the advertisement link feature information is mainly used to represent a network access request generated by clicking the advertisement link.
  • the advertisement link feature information may be specifically the identification information of the advertisement link, for example, the advertisement link feature information may be specifically the advertisement link address information and the like.
  • the advertisement link feature information set of this embodiment may be in an empty state in an initial state.
  • a specific example of the statistics module 420 determining whether the network access request belongs to a network access request for an advertisement is that the statistics module 420 extracts from the network access request from the kernel mode. Linking the address information, and matching the extracted link address information with the advertisement link feature information in the advertisement link feature information set one by one, if the advertisement link feature information set has the advertisement link feature information matching the link address information, the statistic module 420 determines that the current judgment result is that the network access request belongs to the network access request for the advertisement. Otherwise, the statistics module 420 determines that the current judgment result is that the network access request does not belong to the network access request for the advertisement.
  • the statistics module 420 can use various existing statistical methods to count the clicks of the advertisement links corresponding to the network access request of the advertisement. For a simple example, the statistics module 420 performs historical network access requests and current network access according to a period of time. Request to count the frequency of visits or the number of visits, etc. of the corresponding ad link within a predetermined time period. This embodiment does not limit the specific implementation manner of the click condition of the advertisement link corresponding to the statistical network access request.
  • the control module 430 is configured to be in the user mode, and the control module 430 is mainly configured to send the advertisement link interception information for the advertisement link to the kernel state to update the interception information set, if the click condition is determined to meet the malicious click condition.
  • the control module 430 is preset with a malicious click condition for performing malicious click determination.
  • the malicious click condition may be that the frequency of access within a predetermined time period exceeds a predetermined access frequency, or the number of accesses within a predetermined time period exceeds a predetermined number of accesses, and the like.
  • the malicious click condition may be a malicious click determination policy dynamically set by the network side based on the data mining result; this embodiment does not limit the specific content of the malicious click condition.
  • the control module 430 should determine whether the currently counted click condition meets the malicious click condition, and if it is determined that the currently counted click condition meets the malicious click condition.
  • the control module 430 determines that the network access request is a network access request generated by maliciously clicking the advertisement link.
  • the control module 430 should send the advertisement link interception information for the advertisement link to the kernel state for the network access request, so that The intercepting module 410 can intercept the network access request for subsequent malicious clicks on the advertisement link in time; if the control module 430 determines that the currently counted click condition does not meet the malicious click condition, the control module 430 determines the network.
  • the network access request is not a network access request generated by maliciously clicking the advertisement link, and the control module 430 can directly discard the network access request from the kernel mode.
  • the control module 430 when the control module 430 sends the advertisement link interception information for the advertisement link to the kernel state for the network access request, the corresponding advertisement link interception information may be executed according to the current situation of the advertisement link interception information in the kernel mode. If the control module 430 determines whether there is currently valid advertisement link interception information in the kernel state (for example, the control module 430 determines whether the advertisement link interception information exists in the kernel state; and if the control module 430 determines whether the kernel state is in the kernel state If the advertisement link interception information exists and whether the advertisement link interception information is in a valid state, if the advertisement link interception information is currently valid in the kernel state, the control module 430 may not send the advertisement link interception information to the kernel state (of course In this case, it is completely feasible for the control module 430 to send the advertisement link interception information to the kernel state; if there is currently no valid advertisement link interception information in the kernel state (such as the advertisement link interception information exists in the kernel state) If it is in a failed state, then
  • the advertisement link interception information sent by the control module 430 to the kernel state may be the advertisement link interception information that is sent by the network side and stored locally on the user side, for example, in the process of the network side sending the advertisement link feature information to the user side, Each of the advertisement link feature information sets a corresponding advertisement link interception information, and then the network side sends the advertisement link feature information together with the corresponding advertisement link interception information to the user side, and the collection update module 440 sends the advertisement according to the network side.
  • the link interception information updates the interception information collection.
  • the advertisement link interception information sent by the control module 430 to the kernel state may also be the advertisement link interception information generated by the control module 430 or the advertisement link interception information set by default.
  • the embodiment does not limit the control module 430 to the kernel state.
  • the specific implementation of the advertisement link interception information and the specific source of the advertisement link interception information sent by the control module 430 are provided.
  • the set update module 440 is set in the user mode, and the set update module 440 is mainly adapted to update the advertisement link feature information set according to the advertisement link feature delivered by the network side. That is to say, the advertisement link feature information set of the embodiment is generally dynamically updated by the network side. For example, when the user side receives the notification of adding the advertisement link feature information sent by the network side (such as the cloud server), the set update is performed. Module 440 adds the advertisement link feature information in the notification Adding to the advertisement link feature information set; if the user side receives the notification of deleting the advertisement link feature information sent by the network side (such as the cloud server), the collection update module 440 will use the information carried in the notification from the advertisement link. The corresponding advertisement link feature information is deleted from the feature information set.
  • the collection update module 440 may automatically execute the advertisement link feature information corresponding to the advertisement link feature information set when the validity period corresponding to the advertisement link feature information ends. Or performing an operation of setting an expiration flag for the corresponding advertisement link feature information in the advertisement link feature information set; and if the advertisement link feature information of the advertisement link feature information set does not have a corresponding validity period, the set update module 440 may send the message according to the network side.
  • the delete advertisement link feature information notification deletes the corresponding advertisement link feature information in the advertisement link feature information combination.
  • the advertisement link feature information set of this embodiment may be in the form of a file or a database or a table or an array. The embodiment does not limit the specific expression form of the advertisement link feature information set.
  • the set update module 440 is further adapted to update the interception information set according to the advertisement link interception information delivered by the network side.
  • the set update module 440 may also be adapted to store malicious click conditions on the network side (such as the cloud server) on the user side.
  • the present invention can be implemented in software and/or a combination of software and hardware.
  • the various devices of the present invention can be implemented using an application specific integrated circuit (ASIC) or any other similar hardware device.
  • the software program of the present invention may be executed by a processor to implement the steps or functions described above.
  • the software programs (including related data structures) of the present invention can be stored in a computer readable recording medium such as a RAM memory, a magnetic or optical drive or a floppy disk and the like.
  • some of the steps or functions of the present invention may be implemented in hardware, for example, as a circuit that cooperates with a processor to perform various steps or functions.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Information Transfer Between Computers (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本发明提供了一种用于检测和阻止恶意点击广告链接的方法和装置,其中的方法包括:在内核态,对网络访问请求进行监听,将监听到的网络访问请求上传至用户态,并在确定出监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对网络访问请求进行拦截处理;在用户态,在确定出来自内核态的网络访问请求属于针对广告的网络访问请求时,统计网络访问请求对应的广告链接的点击情况,在确定点击情况符合恶意点击条件的情况下,向内核态下发针对广告链接的广告链接拦截信息,以更新该拦截信息集合。本发明提供的技术方案能够尽可能早的消除恶意点击广告链接现象给网络带来的不良影响,从而节约了网络传输资源,并提高了网络侧的设备性能。

Description

用于检测和阻止恶意点击广告链接的方法和装置
相关申请的交叉引用
本申请请求于2015年7月9日提交的申请号为201510401739.8的中国专利申请的优先权,该中国专利申请的内容以引用方式被完整包含于此。
技术领域
本发明涉及网络技术,尤其是涉及一种用于检测和阻止恶意点击广告链接的方法和装置。
背景技术
广播、电视以及报刊杂志等信息媒介是广告的传统媒介。随着网络技术尤其是无线网络技术的快速发展,网络已经成为能够快速有效的实现信息推广的新型广告媒介。
目前,在利用网络实现信息推广的过程中,位于网络侧的广告平台通常会与流量渠道进行合作,以借助流量渠道向网络用户推送其广告信息。由于流量渠道与广告平台之间往往存在利益关系,因此,流量渠道中可能会存在恶意点击广告链接的行为,该恶意点击行为会给广告平台带来利益损失。
为了避免恶意点击行为对广告平台的损害,目前通常会在网络侧对用户侧传输来的网络访问请求进行检测,在检测出该网络访问请求是由于恶意点击行为而产生的网络访问请求时,阻止该网络访问请求,从而避免恶意点击行为对广告平台利益的损害。
发明人在实现本发明过程中发现,虽然现有的用于检测和阻止恶意点击广告链接的实现方式能够避免恶意点击行为给广告平台带来利益损害,但是,恶意点击行为所对应的网络访问请求已经占用了网络传输资源,而且,网络侧对用户侧传输来的所有网络访问请求进行检测势必 会大量消耗网络侧的计算资源,从而会对网络侧的设备性能产生影响。
发明内容
本发明的目的是提供一种用于检测和阻止恶意点击广告链接的方法和装置。
根据本发明的其中一个方面,提供一种用于检测和阻止恶意点击广告链接的方法,且该方法包括以下步骤:在内核态,对网络访问请求进行监听,将监听到的网络访问请求上传至用户态,并在确定出所述监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对所述监听到的网络访问请求进行拦截处理;在用户态,在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计所述网络访问请求对应的广告链接的点击情况,在确定所述点击情况符合恶意点击条件的情况下,向内核态下发针对所述广告链接的广告链接拦截信息,以更新该拦截信息集合。
根据本发明的另一个方面,还提供一种用于检测和阻止恶意点击广告链接的装置,所述装置主要包括:监听模块,设置于内核态,适于对网络访问请求进行监听,并将监听到的网络访问请求上传至用户态;拦截模块,设置于内核态,适于在确定出所述监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对所述监听到的网络访问请求进行拦截处理;统计模块,设置于在用户态,适于在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计所述网络访问请求对应的广告链接的点击情况;控制模块,设置于用户态,适于在确定所述点击情况符合恶意点击条件的情况下,向内核态下发针对所述广告链接的广告链接拦截信息,以更新该拦截信息集合。
与现有技术相比,本发明具有以下优点:本发明通过在用户侧的内核态对网络访问请求进行监听并上报,使用户态可以根据接收到的网络访问请求实时的统计出广告链接的当前点击情况,这样,在出现恶意点击广告链接的现象时,用户态可以及时发现,并及时向内核态下 发相应的广告链接拦截信息,使内核态可以对后续产生的相应网络访问请求进行拦截,从而尽可能的使恶意点击广告链接产生的网络访问请求不会由用户侧向网络侧发送,将恶意点击广告链接的现象限制在用户侧;由于本发明中的用户侧仅针对其内部产生的网络访问请求进行监听以及拦截处理,因此,本发明提供的技术方案对用户侧自身的资源消耗非常有限,基本上不会对用户侧的设备性能产生影响;由此可知,本发明提供的技术方案能够在尽可能早的时间段内消除了恶意点击广告链接现象给网络带来的不良影响,从而节约了网络传输资源,并提高了网络侧的设备性能。
附图说明
通过阅读参照以下附图所作的对非限制性实施例所作的详细描述,本发明的其它特征、目的和优点将会变得更明显:
图1为本发明实施例一的用于检测和阻止恶意点击广告链接的方法流程图;
图2为本发明实施例二的用于检测和阻止恶意点击广告链接的方法流程图;
图3为本发明实施例三的用于检测和阻止恶意点击广告链接的方法流程图;
图4为本发明实施例四的用于检测和阻止恶意点击广告链接的装置示意图。
附图中相同或相似的附图标记代表相同或相似的部件。
具体实施方式
在更加详细地讨论示例性实施例之前应当提到的是,一些示例性实施例被描述成作为流程图描绘的处理或方法。虽然流程图将各项操作描述成顺序的处理,但是其中的许多操作可以被并行地、被并发地或者同时被实施。此外,各项操作的顺序可以被重新安排。当其操作完成时,所述处理可以被终止,但是还可以具有未包括在附图中的附加 步骤。另外,所述处理可以对应于方法、函数、规程、子例程、子程序等等。
在上下文中所称“用户设备”,也可以称为“用户网络终端设备”,是指位于用户侧,且可以通过运行预定程序或指令来执行数值计算和/或逻辑计算等预定处理过程的智能电子设备,其可以包括处理器与存储器,由处理器执行在存储器中预存的存续指令来执行预定处理过程,或是由ASIC、FPGA、DSP等硬件执行预定处理过程,或是由上述二者组合来实现。
在上下文中所称“服务器”可以包括:逻辑上的服务器或者实体上的服务器,实体上的服务器也可以称为“网络设备”,是指位于网络侧(如位于云端),且可以通过运行预定程序或指令来执行数值计算和/或逻辑计算等预定处理过程的智能电子设备,其可以包括处理器以及存储器,由处理器执行在存储器中预存的存续指令来执行预定处理过程,或是由ASIC、FPGA、DSP等硬件执行预定处理过程,或是由上述二者组合来实现。
上述智能电子设备包括但不限于可以通过有线或者无线方式接入网络的台式PC机、笔记本电脑、智能移动电话以及平板电脑等;上述实体上的服务器可以为小型台式设备或者大型台式设备等;上下文中的服务器包括但不限于单个网络服务器、多个网络服务器组成的服务器组或基于云计算(Cloud Computing)的由大量计算机或网络服务器构成的云,其中,云计算是分布式计算的一种,由一群松散耦合的计算机集组成的一个超级虚拟计算机。需要说明的是,上述用户设备以及服务器仅为举例,其他现有的或者今后可能出现的用户设备以及网络设备如可适用于本发明,也应包含在本发明保护范围内,并以引用方式包含于此。
后面所讨论的方法(其中的一些是通过流程图示出的)通常可以通过硬件、软件、固件、中间件、微代码、硬件描述语言或其任意组合来实施。当用软件、固件、中间件或微代码来实施时,用以实施必要任务的程序代码或代码段可以被存储在机器或者计算机可读介质(比如 存储介质)中。(一个或多个)处理器可以实施必要的任务。
这里所公开的具体结构以及功能细节仅仅是代表性的,并且是用于描述本发明的示例性实施例的目的。但是本发明可以通过许多替换形式来具体实现,并且不应当被解释成仅仅受限于这里所阐述的实施例。
应当理解的是,虽然在这里可能使用了术语“第一”、“第二”等等来描述各个单元,但是这些单元不应当受这些术语限制。使用这些术语仅仅是为了将一个单元与另一个单元进行区分。举例来说,在不背离示例性实施例的范围的情况下,第一单元可以被称为第二单元,并且类似地第二单元可以被称为第一单元。这里所使用的术语“和/或”包括其中一个或更多所列出的相关联项目的任意和所有组合。
应当理解的是,当一个单元被称为“连接”或者“耦合”到另一个单元时,其可以直接连接或者耦合到所述另一单元,或者可存在一中间单元。与此相对,当一个单元被称为“直接连接”或“直接耦合”到另一单元时,则不存在一中间单元。应当按照类似的方式来解释被用于描述单元之间的关系的其他类似词语(例如“处于...之间”相比于“直接处于...之间”,“与...邻近”相比于“与...直接邻近”等等)。
这里所使用的术语仅仅是为了描述具体实施例而不意图限制示例性实施例。除非上下文明确地另有所指,否则,这里所使用的单数形式“一个”或者“一项”等还意图包括复数。还应当理解的是,这里所使用的术语“包括”和/或“包含”规定所陈述的特征、整数、步骤、操作、单元和/或组件的存在,而不排除存在或者添加一个或者更多其他特征、整数、步骤、操作、单元、组件和/或其组合。
还应当提到的是,在一些替换实现方式中,所提到的功能/动作可按照不同于附图中标示的顺序发生。举例来说,取决于所涉及的功能/动作,相继示出的两幅图实际上可基本上同时执行或者有时可以按照相反的顺序来执行。
下面结合附图对本发明作进一步详细描述。
实施例一、用于检测和阻止恶意点击广告链接的方法。
图1为本实施例的用于检测和阻止恶意点击广告链接的方法的流程图,且图1所示的方法主要包括在内核态中执行的步骤S110和步骤S111以及在用户态中执行的步骤S120以及步骤S121。下面对图1中的各步骤分别进行说明。
S110、对网络访问请求进行监听,并将监听到的网络访问请求上传至用户态。
具体的,基于用户在其用户设备上的操作(如打开网页操作、文件上传操作或者文件下载操作等),用户设备中会产生相应的网络访问请求,本实施例是在用户侧的内核态对网络访问请求进行监听的。本实施例可以利用用户设备的操作系统提供的网络过滤驱动(NetFilter)对内核态中的网络访问请求进行监听;例如针对WINDOWS XP操作系统而言,本实施例可以利用TDI(Trandport Driver Interface,传输驱动程序接口)框架对内核态中的网络访问请求进行监听;再例如针对WINDOWS vista操作系统而言,本实施例可以利用WFP(Windows Filtering Platform,Windows过滤平台)框架对网络访问请求进行监听。本实施例不限制对内核态中的网络访问请求进行监听的具体实现方式。
在网络访问请求(尤其是广告所对应的网络访问请求)通常为基于HTTP(HyperText Transfer Protocol,超文本传输协议)的消息的情况下,本实施例可以对内核态中的HTTP消息进行监听,也就是说,在内核态中监听到HTTP消息时,将该HTTP消息由内核态上报至用户态。当然,在网络访问请求为基于其他协议的消息时,本实施例所监听的消息类型也应相应的发生变化。本实施例不限制网络访问请求的具体表现形式。
S111、在确定出上述监听到的网络访问请求符合拦截信息集合中相应的广告链接拦截信息的情况下,对上述监听到的网络访问请求进行拦截处理。
具体的,本实施例在内核态中监听到网络访问请求的情况下,一方面需要执行将该网络访问请求上报至用户态的处理操作,另一方面需 要执行对该网络访问请求是否需要拦截的判断处理操作。本实施例并不限制上报处理操作与拦截判断处理操作的先后执行顺序,也就是说,上报处理操作和拦截判断处理操作既可以同时进行,也可以先执行上报处理操作再执行拦截判断处理操作,还可以先执行拦截判断处理操作再执行上报处理操作。
本实施例是利用拦截信息集合来判断是否需要对监听到的网络访问请求进行拦截处理的,即内核态中预先设置有拦截信息集合,该拦截信息集合可以为空,也可以包含有至少一条广告链接拦截信息;如在初始状态下拦截信息集合为空;再如在用户侧在当前一段时间内没有出现恶意点击广告链接现象的情况下,拦截信息集合为空;而在用户侧在当前一段时间内出现了恶意点击广告链接现象的情况下,由于用户态向内核态下发了广告链接拦截信息而使拦截信息集合中包含有一条或者多条广告链接拦截信息。由此可知,本实施例内核态中的拦截信息集合是由用户态动态维护更新的。
本实施例中的广告链接拦截信息主要包括网络访问请求的特征信息,该特征信息主要用于表征需要拦截的网络访问请求。该特征信息可以为网络访问请求的标识信息,如特征信息可以为链接地址信息等。
本实施例中的广告链接拦截信息还可以包括其他信息,如本条广告链接拦截信息的有效期等等。本实施例不限制广告链接拦截信息所包含的具体内容。另外,在广告链接拦截信息中包含有效期的情况下,内核态可以在广告链接拦截信息对应的有效期结束时,自动执行删除拦截信息集合中相应的广告链接拦截信息或者执行为拦截信息集合中相应的广告链接拦截信息设置过期标志等操作;而在广告链接拦截信息中没有包含有效期的情况下,内核态可以根据用户态下发的删除广告链接拦截信息通知而删除拦截信息集合中相应的广告链接拦截信息。
本实施例中的拦截信息集合可以采用文件或者数据库或者表或者数组等方式来汇集广告链接拦截信息,本实施例不限制拦截信息集合的 具体表现形式。
本实施例的拦截判断的一个具体例子为:在内核态中监听到HTTP消息的情况下,判断当前的拦截信息集合是否为空,如果拦截信息集合为空,则本次的拦截判断结果为不对该HTTP消息进行后续的拦截处理操作,内核态按照现有的方式进行后续处理,如内核态通过硬件向网络侧发送该HTTP消息;如果拦截信息集合不为空,则将该HTTP消息中的链接地址信息与拦截信息集合中的每一条广告链接拦截信息中的链接地址信息分别进行匹配,如果拦截信息集合中存在链接地址信息与HTTP消息中的链接地址信息相匹配的广告链接拦截信息,则本次的拦截判断结果为需要对该HTTP消息进行拦截处理;如果拦截信息集合中并不存在链接地址信息与HTTP消息中的链接地址信息相匹配的广告链接拦截信息,则本次的拦截判断结果为不需要对该HTTP消息进行拦截处理,内核态按照现有的方式进行后续处理,如内核态通过硬件向网络侧发送该HTTP消息。
本实施例中的对网络访问请求的拦截处理可以具体为丢弃该网络访问请求(即删除HTTP消息)等,以避免该网络访问请求由用户侧向网络侧传输。
本实施例可以利用用户设备中的操作系统提供的相应功能实现对内核态中的网络访问请求执行拦截判断处理操作以及拦截处理操作;如针对WINDOWS XP操作系统而言,本实施例可以利用操作系统提供的NDIS(Network Driver Interface Specification,网络驱动接口规范)对内核态中的网络访问请求进行拦截判断处理操作以及拦截处理操作;再如针对WINDOWS vista操作系统而言,本实施例可以利用WFP框架对网络访问请求进行拦截判断处理操作以及拦截处理操作。本实施例不限制在内核态中对网络访问请求进行拦截判断处理操作以及拦截处理操作的具体实现方式。
S120、在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计该网络访问请求对应的广告链接的点击情况。
具体的,本实施例在用户态接收到来自内核态的网络访问请求时, 应先在用户态中针对该网络访问请求进行判断,以确定来自内核态的该网络访问请求是否属于针对广告的网络访问请求(即由于点击广告链接而产生的网络访问请求);然后,在判断出该网络访问请求属于针对广告的网络访问请求的情况下,再基于该网络访问请求进行广告链接的点击情况的统计操作;而如果判断出该网络访问请求并不属于针对广告的网络访问请求,则不会对该网络访问请求进行点击情况的统计操作,而是可以直接丢弃用户态中的该网络访问请求。
本实施例可以利用预先设置的广告链接特征信息集合来判断来自内核态的网络访问请求是否属于针对广告的网络访问请求,即用户态中预先设置有广告链接特征信息集合。本实施例中的广告链接特征信息集合在通常情况下不为空,即通常会包含有至少一条广告链接特征信息,该广告链接特征信息主要用于表征由点击广告链接而产生的网络访问请求。广告链接特征信息可以具体为广告链接的标识信息,如广告链接特征信息可以具体为广告链接地址信息等。本实施例的广告链接特征信息集合在初始状态下可能会处于为空的状态。
本实施例的广告链接特征信息集合通常是由网络侧动态维护更新的,如用户侧在接收到网络侧(如云端服务器)下发的增加广告链接特征信息的通知时,将该通知中的广告链接特征信息添加至广告链接特征信息集合中;再如用户侧在接收到网络侧(如云端服务器)下发的删除广告链接特征信息的通知时,将根据该通知中承载的信息从广告链接特征信息集合中删除相应的广告链接特征信息。另外,在广告链接特征信息集合中的广告链接特征信息对应有有效期的情况下,用户态可以在广告链接特征信息对应的有效期结束时,自动执行广告链接特征信息集合相应的广告链接特征信息或者执行为广告链接特征信息集合中相应的广告链接特征信息设置过期标志等操作;而在广告链接特征信息集合的广告链接特征信息没有对应有效期的情况下,用户态可以根据网络侧下发的删除广告链接特征信息通知而删除广告链接特征信息结合中相应的广告链接特征信息。
本实施例的广告链接特征信息集合可以采用文件或者数据库或者表 或者数组等形式,本实施例不限制广告链接特征信息集合的具体表现形式。
本实施例中的判断网络访问请求是否属于针对广告的网络访问请求的一个具体例子为:从来自内核态的网络访问请求中提取链接地址信息,并将提取的链接地址信息与广告链接特征信息集合中的广告链接特征信息逐个进行匹配,如果广告链接特征信息集合中存在与该链接地址信息匹配的广告链接特征信息,则本次的判断结果为该网络访问请求属于针对广告的网络访问请求,否则,本次的判断结果为该网络访问请求不属于针对广告的网络访问请求。
本实施例可以采用现有的多种统计方式来统计针对广告的网络访问请求对应的广告链接的点击情况,一个简单的例子,根据一段时间内的历史网络访问请求以及当前的网络访问请求统计相应的广告链接在预定时间段内的访问频率或者访问次数等。本实施例不限制统计网络访问请求对应的广告链接的点击情况的具体实现方式。
S121、在确定上述点击情况符合恶意点击条件的情况下,向内核态下发针对相应广告链接的广告链接拦截信息,以更新拦截信息集合。
具体的,本实施例的用户态中预先设置有用于进行恶意点击判断的恶意点击条件,该恶意点击条件可以由网络侧(如云端服务器)下发,并由用户侧本地存储(如存储于用户态中)。一个简单的例子,该恶意点击条件可以为在预定时间段内的访问频率超过预定访问频率,也可以为在预定时间段内的访问次数超过预定访问次数等。在恶意点击条件由网络侧下发的应用场景中,恶意点击条件可以是网络侧基于数据挖掘结果而动态设置的恶意点击判断策略;本实施例不限制恶意点击条件的具体内容。
在用户态中,本实施例在统计出某一广告链接的点击情况后,应判断当前统计出的点击情况是否符合恶意点击条件,如果判断出当前统计出的点击情况符合恶意点击条件,则确定该网络访问请求为恶意点击广告链接而产生的网络访问请求,此时用户态应针对该网络访问请求向内核态下发针对该广告链接的广告链接拦截信息,以使内核态可 以及时的对后续针对该广告链接的恶意点击而产生网络访问请求进行拦截;如果判断出当前统计出的点击情况不符合恶意点击条件,则用户态确定出该网络访问请求不是由于恶意点击广告链接而产生的网络访问请求,用户态可以直接将该来自内核态的网络访问请求丢弃。
需要说明的是,用户态在针对该网络访问请求向内核态下发针对广告链接的广告链接拦截信息时,可以根据内核态中的广告链接拦截信息的当前情况而执行相应的广告链接拦截信息的下发操作;如用户态先判断内核态中当前是否存在有效的该广告链接拦截信息(如判断内核态中是否存在该广告链接拦截信息;再如判断内核态中是否存在该广告链接拦截信息以及该广告链接拦截信息是否处于有效状态),如果内核态中当前存在有效的该广告链接拦截信息,则用户态可以不向内核态下发该广告链接拦截信息(当然,在此情况下,用户态向内核态下发该广告链接拦截信息也是完全可行的);如果内核态中当前并没有存在有效的该广告链接拦截信息(如内核态中存在该广告链接拦截信息已处于失效状态),则用户态应向内核态下发该广告链接拦截信息。
用户态向内核态下发的广告链接拦截信息可以是由网络侧下发并本地存储于用户侧的广告链接拦截信息,如网络侧在向用户侧下发广告链接特征信息的过程中,针对每一条广告链接特征信息分别设置相应的广告链接拦截信息,然后,网络侧将广告链接特征信息与对应的广告链接拦截信息一并向用户侧下发。当然,用户态向内核态下发的广告链接拦截信息也可以是用户态自行产生的广告链接拦截信息或者缺省设置的广告链接拦截信息等,本实施例不限制用户态向内核态下发广告链接拦截信息的具体实现方式以及用户态所下发的广告链接拦截信息的具体来源等。
本实施例能够有效的将恶意点击广告链接的现象限制在用户侧,尽可能的避免了由于恶意点击而在用户侧与网络侧之间建立广告链接的现象,不仅有效的保护了广告平台的利益,还节约了网络传输资源,并提高了网络侧的设备性能。
实施例二、用于检测和阻止恶意点击广告链接的方法。
本实施例以用户侧的用户设备采用WINDOWS XP操作系统为例,并结合图2对本实施例的用于检测和阻止恶意点击广告链接的方法进行说明。
图2中,左侧为用户在发起了网络访问请求后,对网络访问请求的现有处理流程;右侧为本实施例针对用户发起的网络访问请求处理流程;上侧为用户态中执行的操作;下侧为内核态中执行的操作。
S21、用户由于其网络访问操作(如点击当前页面中的广告链接)而发起网络访问请求,该网络访问请求由用户态传输至内核态,并分别到步骤S22以及步骤S23。
S22、该网络访问请求在内核态中进行相应的处理,以向网络侧发送,如针对该网络访问请求进行基于TCP/IP的处理等,到步骤S24。
S23、被传输至内核态中的网络访问请求基于TDI框架的监听而由内核态上报至用户态,到步骤S25。
S24、基于NDIS实现对经过上述步骤S22处理后的网络访问请求的拦截判断,并根据拦截判断结果进行相应的拦截处理;具体的,判断经过步骤S22处理后的网络访问请求中是否包含有广告链接拦截信息集合中的广告链接拦截信息,如果包含,则确定需要对网络访问请求进行拦截处理,此时应禁止针对该网络访问请求执行通过硬件向网络侧发送的操作,如可以直接丢弃该网络访问请求;如果不包含广告链接拦截信息,则确定不需要对网络访问请求进行拦截处理,到步骤S26。
S25、用户态基于从云端服务器处获取的广告链接特征信息形成的广告链接特征信息集合判断当前来自内核态的网络访问请求是否属于针对广告的网络访问请求,如果判断结果为属于针对广告的网络访问请求,则用户态针对该网络访问请求对应的广告链接进行点击情况统计,并继续判断当前统计出的点击情况是否符合用户侧从云端服务器处获取的恶意点击条件,如果判断结果为当前统计出的点击情况符合恶意点击条件,则用户态向内核态下发相应的广告链接拦截信息;如果判断结果为当前统计出的点击情况不符合恶意点击条件,则用户态可以直接丢弃该网络访问请求。
S26、经过步骤S22处理后的网络访问请求通过硬件向网络侧发送。
实施例三、用于检测和阻止恶意点击广告链接的方法。
本实施例以用户侧的用户设备采用WINDOWS vista操作系统为例,并结合图3对本实施例的用于检测和阻止恶意点击广告链接的方法进行说明。
图3中,左侧为用户在发起了网络访问请求后,对网络访问请求的现有处理流程;右侧为本实施例针对用户发起的网络访问请求处理流程;上侧为用户态中执行的操作;下侧为内核态中执行的操作。
S31、用户由于其网络访问操作(如点击当前页面中的广告链接)而发起网络访问请求,该网络访问请求由用户态传输至内核态,并分别到步骤S32以及步骤S33。
S32、该网络访问请求在内核态中进行相应的处理,以向网络侧发送,如针对该网络访问请求进行基于TCP/IP的处理等,到步骤S33。
S33、被传输至内核态中的网络访问请求基于WFP框架的监听而由内核态上报至用户态,到步骤S34。
同时,基于WFP框架实现对经过上述步骤S32处理后的网络访问请求的拦截判断,并根据拦截判断结果进行相应的拦截处理;具体的,判断经过步骤S32处理后的网络访问请求中是否包含有广告链接拦截信息集合中的广告链接拦截信息,如果包含,则确定需要对网络访问请求进行拦截处理,此时应禁止针对该网络访问请求执行通过硬件向网络侧发送的操作,如可以直接丢弃该网络访问请求;如果不包含广告链接拦截信息,则确定不需要对网络访问请求进行拦截处理,到步骤S35。
S34、用户态基于从云端服务器处获取的广告链接特征信息形成的广告链接特征信息集合判断当前来自内核态的网络访问请求是否属于针对广告的网络访问请求,如果判断结果为属于针对广告的网络访问请求,则用户态针对该网络访问请求对应的广告链接进行点击情况统计,并继续判断当前统计出的点击情况是否符合用户侧从云端服务器 处获取的恶意点击条件,如果判断结果为当前统计出的点击情况符合恶意点击条件,则用户态向内核态下发相应的广告链接拦截信息;如果判断结果为当前统计出的点击情况不符合恶意点击条件,则用户态可以直接丢弃该网络访问请求。
S35、经过步骤S32处理后的网络访问请求通过硬件向网络侧发送。
实施例四、用于检测和阻止恶意点击广告链接的装置。
本实施例的装置设置于用户设备中,且该装置的主要结构如图4所示。
图4中,用于检测和阻止恶意点击广告链接的装置包括:监听模块400、拦截模块410、统计模块420以及控制模块430。该装置还可以包括:集合更新模块440。
监听模块400设置于内核态,且监听模块400主要用于对网络访问请求进行监听,并将监听到的网络访问请求上传至用户态。
具体的,基于用户在其用户设备上的操作(如打开网页操作、文件上传操作或者文件下载操作等),用户设备中会产生相应的网络访问请求,监听模块400是在用户侧的内核态对网络访问请求进行监听的。监听模块400可以利用用户设备的操作系统提供的网络过滤驱动(NetFilter)对内核态中的网络访问请求进行监听;例如针对WINDOWS XP操作系统而言,监听模块400可以利用TDI框架对内核态中的网络访问请求进行监听;再例如针对WINDOWS vista操作系统而言,监听模块400可以利用WFP框架对网络访问请求进行监听。本实施例不限制监听模块400对内核态中的网络访问请求进行监听的具体实现方式。
在网络访问请求(尤其是广告所对应的网络访问请求)通常为基于HTTP的消息的情况下,监听模块400可以对内核态中的HTTP消息进行监听,也就是说,在监听模块400在内核态中监听到HTTP消息时,监听模块400将该HTTP消息由内核态上报至用户态。当然,在网络访问请求为基于其他协议的消息时,监听模块400所监听的消息类型也应 相应的发生变化。本实施例不限制监听模块400所监听的网络访问请求的具体表现形式。
拦截模块410设置于内核态,且拦截模块410主要适于在确定出监听模块400监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对监听模块400监听到的网络访问请求进行拦截处理。
具体的,在监听模块400在内核态中监听到网络访问请求的情况下,一方面监听模块400需要执行将该网络访问请求上报至用户态的处理操作,另一方面拦截模块410需要执行对该网络访问请求是否需要拦截的判断处理操作。本实施例并不限制监听模块400执行上报处理操作与拦截模块410执行拦截判断处理操作的先后顺序,也就是说,监听模块400执行的上报处理操作和拦截模块410执行的拦截判断处理操作既可以同时进行,也可以监听模块400先执行上报处理操作,拦截模块410再执行拦截判断处理操作,还可以拦截模块410先执行拦截判断处理操作,监听模块400再执行上报处理操作。
拦截模块410是利用拦截信息集合来判断是否需要对监听模块400监听到的网络访问请求进行拦截处理的,如拦截模块410中预先设置有拦截信息集合,该拦截信息集合通常情况下包含有至少一条广告链接拦截信息,当然该拦截信息集合也存在为空的状态;如在初始状态下拦截信息集合处于为空的状态;再如在用户侧在当前一段时间内没有出现恶意点击广告链接现象的情况下,拦截信息集合处于为空的状态;而在用户侧在当前一段时间内出现了恶意点击广告链接现象的情况下,由于用户态向内核态下发了广告链接拦截信息而使拦截信息集合中包含有一条或者多条广告链接拦截信息。由此可知,本实施例内核态中的拦截信息集合是由用户态动态维护更新的。
本实施例中的广告链接拦截信息主要包括网络访问请求的特征信息,该特征信息主要用于表征需要拦截的网络访问请求。该特征信息可以为网络访问请求的标识信息,如特征信息可以为链接地址信息等。
本实施例中的广告链接拦截信息还可以包括其他信息,如本条广告链接拦截信息的有效期等等。本实施例不限制广告链接拦截信息所包含的具体内容。另外,在广告链接拦截信息中包含有效期的情况下,拦截模块410可以在广告链接拦截信息对应的有效期结束时,自动执行删除拦截信息集合中相应的广告链接拦截信息或者执行为拦截信息集合中相应的广告链接拦截信息设置过期标志等操作;在广告链接拦截信息中没有包含有效期的情况下,拦截模块410可以根据用户态下发的删除广告链接拦截信息通知而删除拦截信息集合中相应的广告链接拦截信息。
本实施例中的拦截信息集合可以采用文件或者数据库或者表或者数组等方式来汇集广告链接拦截信息,本实施例不限制拦截信息集合的具体表现形式。
拦截模块410的拦截判断的一个具体例子为:在监听模块400监听到HTTP消息的情况下,拦截模块410判断当前的拦截信息集合是否为空,如果拦截信息集合为空,则本次的拦截判断结果为不对该HTTP消息进行后续的拦截处理操作,内核态按照现有的方式进行后续处理,如内核态通过硬件向网络侧发送该HTTP消息;如果拦截信息集合不为空,则拦截模块410将该HTTP消息中的链接地址信息与拦截信息集合中的每一条广告链接拦截信息中的链接地址信息分别进行匹配,如果拦截信息集合中存在链接地址信息与HTTP消息中的链接地址信息相匹配的广告链接拦截信息,则本次的拦截判断结果为需要对该HTTP消息进行拦截处理;如果拦截信息集合中并不存在链接地址信息与HTTP消息中的链接地址信息相匹配的广告链接拦截信息,则本次的拦截判断结果为不需要对该HTTP消息进行拦截处理,内核态按照现有的方式进行后续处理,如内核态通过硬件向网络侧发送该HTTP消息。
拦截模块410对网络访问请求的拦截处理可以具体为拦截模块410丢弃该网络访问请求(即删除HTTP消息)等,以避免该网络访问请求由用户侧向网络侧传输。
拦截模块410可以利用用户设备中的操作系统提供的相应功能实现 对内核态中的网络访问请求执行拦截判断处理操作以及拦截处理操作;如针对WINDOWS XP操作系统而言,拦截模块410可以利用操作系统提供的NDIS对内核态中的网络访问请求进行拦截判断处理操作以及拦截处理操作;再如针对WINDOWS vista操作系统而言,拦截模块410可以利用WFP框架对网络访问请求进行拦截判断处理操作以及拦截处理操作。本实施例不限制拦截模块410对内核态中的网络访问请求执行拦截判断处理操作以及拦截处理操作的具体实现方式。
统计模块420设置于在用户态,且统计模块420主要适于在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计网络访问请求对应的广告链接的点击情况。
具体的,在用户态接收到来自内核态的网络访问请求时,统计模块420应先在用户态中针对该网络访问请求进行判断,以确定来自内核态的该网络访问请求是否属于针对广告的网络访问请求(即由于点击广告链接而产生的网络访问请求);然后,统计模块420在判断出该网络访问请求属于针对广告的网络访问请求的情况下,统计模块420再基于该网络访问请求进行广告链接的点击情况的统计操作;而如果统计模块420判断出该网络访问请求并不属于针对广告的网络访问请求,则统计模块420不会对该网络访问请求进行点击情况的统计操作,而是统计模块420直接丢弃用户态中的该网络访问请求。
统计模块420可以利用预先设置的广告链接特征信息集合来判断来自内核态的网络访问请求是否属于针对广告的网络访问请求,即用户态中预先设置有广告链接特征信息集合。本实施例中的广告链接特征信息集合在通常情况下不为空,即通常会包含有至少一条广告链接特征信息,该广告链接特征信息主要用于表征由点击广告链接而产生的网络访问请求。广告链接特征信息可以具体为广告链接的标识信息,如广告链接特征信息可以具体为广告链接地址信息等。本实施例的广告链接特征信息集合在初始状态下可能会处于为空的状态。
统计模块420判断网络访问请求是否属于针对广告的网络访问请求的一个具体例子为:统计模块420从来自内核态的网络访问请求中提取 链接地址信息,并将提取的链接地址信息与广告链接特征信息集合中的广告链接特征信息逐个进行匹配,如果广告链接特征信息集合中存在与该链接地址信息匹配的广告链接特征信息,则统计模块420确定本次的判断结果为该网络访问请求属于针对广告的网络访问请求,否则,统计模块420确定本次的判断结果为该网络访问请求不属于针对广告的网络访问请求。
统计模块420可以采用现有的多种统计方式来统计针对广告的网络访问请求对应的广告链接的点击情况,一个简单的例子,统计模块420根据一段时间内的历史网络访问请求以及当前的网络访问请求统计相应的广告链接在预定时间段内的访问频率或者访问次数等。本实施例不限制统计网络访问请求对应的广告链接的点击情况的具体实现方式。
控制模块430设置于用户态,且控制模块430主要适于在确定点击情况符合恶意点击条件的情况下,向内核态下发针对该广告链接的广告链接拦截信息,以更新该拦截信息集合。
具体的,控制模块430中预先设置有用于进行恶意点击判断的恶意点击条件。一个简单的例子,该恶意点击条件可以为在预定时间段内的访问频率超过预定访问频率,也可以为在预定时间段内的访问次数超过预定访问次数等。在恶意点击条件由网络侧下发的应用场景中,恶意点击条件可以是网络侧基于数据挖掘结果而动态设置的恶意点击判断策略;本实施例不限制恶意点击条件的具体内容。
在用户态中,在统计模块420统计出某一广告链接的点击情况后,控制模块430应判断当前统计出的点击情况是否符合恶意点击条件,如果判断出当前统计出的点击情况符合恶意点击条件,则控制模块430确定该网络访问请求为恶意点击广告链接而产生的网络访问请求,此时控制模块430应针对该网络访问请求向内核态下发针对该广告链接的广告链接拦截信息,以使拦截模块410可以及时的对后续针对该广告链接的恶意点击而产生网络访问请求进行拦截;如果控制模块430判断出当前统计出的点击情况不符合恶意点击条件,则控制模块430确定出该网 络访问请求不是由于恶意点击广告链接而产生的网络访问请求,控制模块430可以直接将该来自内核态的网络访问请求丢弃。
需要说明的是,控制模块430在针对该网络访问请求向内核态下发针对广告链接的广告链接拦截信息时,可以根据内核态中的广告链接拦截信息的当前情况而执行相应的广告链接拦截信息的下发操作;如控制模块430判断内核态中当前是否存在有效的该广告链接拦截信息(如控制模块430判断内核态中是否存在该广告链接拦截信息;再如控制模块430判断内核态中是否存在该广告链接拦截信息以及该广告链接拦截信息是否处于有效状态),如果内核态中当前存在有效的该广告链接拦截信息,则控制模块430可以不向内核态下发该广告链接拦截信息(当然,在该情况下控制模块430向内核态下发该广告链接拦截信息也是完全可行的);如果内核态中当前并没有存在有效的该广告链接拦截信息(如内核态中存在该广告链接拦截信息已处于失效状态),则控制模块430应向内核态下发该广告链接拦截信息。
控制模块430向内核态下发的广告链接拦截信息可以是由网络侧下发并本地存储于用户侧的广告链接拦截信息,如网络侧在向用户侧下发广告链接特征信息的过程中,针对每一条广告链接特征信息分别设置相应的广告链接拦截信息,然后,网络侧将广告链接特征信息与对应的广告链接拦截信息一并向用户侧下发,集合更新模块440根据网络侧下发的广告链接拦截信息更新拦截信息集合。当然,控制模块430向内核态下发的广告链接拦截信息也可以是控制模块430自行产生的广告链接拦截信息或者缺省设置的广告链接拦截信息等,本实施例不限制控制模块430向内核态下发广告链接拦截信息的具体实现方式以及控制模块430所下发的广告链接拦截信息的具体来源。
集合更新模块440设置于用户态,且集合更新模块440主要适于根据网络侧下发的广告链接特征更新广告链接特征信息集合。也就是说,本实施例的广告链接特征信息集合通常是由网络侧动态维护更新的,如用户侧在接收到网络侧(如云端服务器)下发的增加广告链接特征信息的通知时,集合更新模块440将该通知中的广告链接特征信息添 加至广告链接特征信息集合中;再如用户侧在接收到网络侧(如云端服务器)下发的删除广告链接特征信息的通知时,集合更新模块440将根据该通知中承载的信息从广告链接特征信息集合中删除相应的广告链接特征信息。另外,在广告链接特征信息集合中的广告链接特征信息对应有有效期的情况下,集合更新模块440可以在广告链接特征信息对应的有效期结束时,自动执行广告链接特征信息集合相应的广告链接特征信息或者执行为广告链接特征信息集合中相应的广告链接特征信息设置过期标志等操作;而在广告链接特征信息集合的广告链接特征信息没有对应有效期的情况下,集合更新模块440可以根据网络侧下发的删除广告链接特征信息通知而删除广告链接特征信息结合中相应的广告链接特征信息。本实施例的广告链接特征信息集合可以采用文件或者数据库或者表或者数组等形式,本实施例不限制广告链接特征信息集合的具体表现形式。
另外,集合更新模块440还适于根据网络侧下发的广告链接拦截信息更新拦截信息集合。还有,集合更新模块440也可以适于将网络侧(如云端服务器)下发恶意点击条件存储于用户侧。
需要注意的是,本发明可以在软件和/或者软件与硬件的组合体中被实施,例如,本发明的各个装置可采用专用集成电路(ASIC)或者任何其他类似硬件设备来实现。在一个实施例中,本发明的软件程序可以通过处理器执行以实现上文所述步骤或功能。同样地,本发明的软件程序(包括相关的数据结构)可以被存储到计算机可读记录介质中,例如,RAM存储器、磁或者光驱动器或软磁盘及类似设备。另外,本发明的一些步骤或功能可采用硬件来实现,例如,作为与处理器配合从而执行各个步骤或功能的电路。
对于本领域技术人员而言,显然,本发明不限于上述示范性实施例的细节,而且在不背离本发明的精神或基本特征的情况下,能够以其他的具体形式实现本发明。因此,无论从哪一方面来看,均应该将实施例看作是示范性的,而且是非限制性的,本发明的范围由所附权利要求而不是上述说明来限定,因此,旨在将落在权利要求的等同要件 的含义和范围内的所有变化涵括在本发明内。不应该将权利要求中的任何附图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或步骤,单数不排除复数。系统权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第一以及第二等词语用来表示名称,而并不表示任何特定顺序。
虽然前面特别示出并且描述了示例性实施例,但是本领域技术人员将会理解的是,在不背离权利要求书的精神和范围的情况下,在其形式和细节方面可以有所变化。这里所寻求的保护在所附权利要求书中做了阐述。

Claims (15)

  1. 一种用于检测和阻止恶意点击广告链接的方法,在用户侧执行,其中,该方法包括以下步骤:
    在内核态,对网络访问请求进行监听,将监听到的网络访问请求上传至用户态,并在确定出所述监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对所述监听到的网络访问请求进行拦截处理;
    在用户态,在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计所述网络访问请求对应的广告链接的点击情况,在确定所述点击情况符合恶意点击条件的情况下,向内核态下发针对所述广告链接的广告链接拦截信息,以更新该拦截信息集合。
  2. 根据权利要求1所述的方法,其中,所述对网络访问请求进行监听包括:基于网络过滤驱动对网络访问请求进行监听,其中,所述网络访问请求包括超文本传输协议HTTP消息。
  3. 根据权利要求2所述的方法,其中,所述基于网络过滤驱动对网络访问请求进行监听包括:
    利用传输驱动程序接口TDI框架对网络访问请求进行监听;或者
    利用Windows文件保护WFP框架对网络访问请求进行监听。
  4. 根据权利要求1所述的方法,其中,所述方法还包括:
    根据网络侧下发的广告链接拦截信息更新所述拦截信息集合;和/或
    根据网络侧下发的恶意点击条件更新用户侧的恶意点击条件。
  5. 根据权利要求1至4中任一权利要求所述的方法,其中,所述确定出来自内核态的网络访问请求属于针对广告的网络访问请求包括:
    判断来自内核态的网络访问请求中是否包含有广告链接特征信息集合中的广告链接特征,如果包含,则确定出所述网络访问请求属于针对广告的网络访问请求,否则确定出所述网络访问请求不属于针对广告的网络访问请求。
  6. 根据权利要求5所述的方法,其中,所述方法还包括:
    根据网络侧下发的广告链接特征更新所述广告链接特征信息集合。
  7. 一种用于检测和阻止恶意点击广告链接的装置,设置于用户侧,其中,该装置包括:
    监听模块,设置于内核态,适于对网络访问请求进行监听,并将监听到的网络访问请求上传至用户态;
    拦截模块,设置于内核态,适于在确定出所述监听到的网络访问请求符合拦截信息集合中的相应广告链接拦截信息的情况下,对所述监听到的网络访问请求进行拦截处理;
    统计模块,设置于在用户态,适于在确定出来自内核态的网络访问请求属于针对广告的网络访问请求的情况下,统计所述网络访问请求对应的广告链接的点击情况;
    控制模块,设置于用户态,适于在确定所述点击情况符合恶意点击条件的情况下,向内核态下发针对所述广告链接的广告链接拦截信息,以更新该拦截信息集合。
  8. 根据权利要求7所述的装置,其中,所述监听模块具体适于:
    基于网络过滤驱动对网络访问请求进行监听,其中,所述网络访问请求包括超文本传输协议HTTP消息。
  9. 根据权利要求8所述的装置,其中,所述监听模块具体适于:
    利用传输驱动程序接口TDI框架对网络访问请求进行监听;或者
    利用Windows文件保护WFP框架对网络访问请求进行监听。
  10. 根据权利要求7所述的装置,其中,所述装置还包括:
    根据网络侧下发的广告链接拦截信息更新所述拦截信息集合;和/或
    根据网络侧下发的恶意点击条件更新用户侧的恶意点击条件。
  11. 根据权利要求7至11中任一权利要求所述的装置,其中,所述统计模块具体适于:
    判断来自内核态的网络访问请求中是否包含有广告链接特征信息集合中的广告链接特征,如果包含,则确定出所述网络访问请求属于针 对广告的网络访问请求,否则确定出所述网络访问请求不属于针对广告的网络访问请求。
  12. 根据权利要求11所述的装置,其中,所述装置还包括:
    集合更新模块,设置于用户态,适于根据网络侧下发的广告链接特征更新所述广告链接特征信息集合。
  13. 一种计算机可读存储介质,所述计算机可读存储介质包括计算机指令,当所述计算机指令被执行时,如权利要求1至6中任一项所述的方法被执行。
  14. 一种计算机程序产品,当所述计算机程序产品被执行时,如权利要求1至6中任一项所述的方法被执行。
  15. 一种计算机设备,所述计算机设备包括存储器和处理器,所述存储器中存储有计算机指令,所述处理器被配置来通过执行所述计算机指令以执行如权利要求1至6中任一项所述的方法。
PCT/CN2015/098733 2015-07-09 2015-12-24 用于检测和阻止恶意点击广告链接的方法和装置 WO2017004952A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510401739.8 2015-07-09
CN201510401739.8A CN106341373B (zh) 2015-07-09 2015-07-09 用于检测和阻止恶意点击广告链接的方法和装置

Publications (1)

Publication Number Publication Date
WO2017004952A1 true WO2017004952A1 (zh) 2017-01-12

Family

ID=57684706

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/098733 WO2017004952A1 (zh) 2015-07-09 2015-12-24 用于检测和阻止恶意点击广告链接的方法和装置

Country Status (2)

Country Link
CN (1) CN106341373B (zh)
WO (1) WO2017004952A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020151030A1 (zh) * 2019-01-22 2020-07-30 网宿科技股份有限公司 一种处理数据报文的方法和装置
CN115052004A (zh) * 2022-06-13 2022-09-13 北京天融信网络安全技术有限公司 网络访问旁路监控方法及电子设备
CN116048544A (zh) * 2022-08-24 2023-05-02 荣耀终端有限公司 一种弹窗广告的处理方法、电子设备及可读存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107578263B (zh) * 2017-07-21 2021-01-05 北京奇艺世纪科技有限公司 一种广告异常访问的检测方法、装置和电子设备
CN108920944B (zh) * 2018-06-12 2023-05-23 腾讯科技(深圳)有限公司 辅助点击事件的检测方法、装置、计算机设备及存储介质
CN109587269A (zh) * 2018-12-27 2019-04-05 迅雷计算机(深圳)有限公司 一种下载行为的拦截方法、设备、装置、系统及存储介质
CN110266732B (zh) * 2019-07-24 2020-05-08 北京众谊越泰科技有限公司 一种WFP+NDISFilter组合驱动实现网络底层过滤的方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102202062A (zh) * 2011-06-03 2011-09-28 苏州九州安华信息安全技术有限公司 一种实现访问控制的方法和装置
CN102340428A (zh) * 2011-09-29 2012-02-01 哈尔滨安天科技股份有限公司 基于网络丢包的url检测与拦截方法和系统
CN103581363A (zh) * 2013-11-29 2014-02-12 杜跃进 对恶意域名和非法访问的控制方法及装置
CN104378762A (zh) * 2014-11-19 2015-02-25 北京极科极客科技有限公司 一种用户上网流量的监控方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080147456A1 (en) * 2006-12-19 2008-06-19 Andrei Zary Broder Methods of detecting and avoiding fraudulent internet-based advertisement viewings
CN102594771B (zh) * 2011-01-07 2015-02-25 北京开心人信息技术有限公司 一种过滤非正常点击广告的方法及系统
CN104463635A (zh) * 2014-12-22 2015-03-25 北京奇虎科技有限公司 广告恶意点击检测方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102202062A (zh) * 2011-06-03 2011-09-28 苏州九州安华信息安全技术有限公司 一种实现访问控制的方法和装置
CN102340428A (zh) * 2011-09-29 2012-02-01 哈尔滨安天科技股份有限公司 基于网络丢包的url检测与拦截方法和系统
CN103581363A (zh) * 2013-11-29 2014-02-12 杜跃进 对恶意域名和非法访问的控制方法及装置
CN104378762A (zh) * 2014-11-19 2015-02-25 北京极科极客科技有限公司 一种用户上网流量的监控方法

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2020151030A1 (zh) * 2019-01-22 2020-07-30 网宿科技股份有限公司 一种处理数据报文的方法和装置
CN115052004A (zh) * 2022-06-13 2022-09-13 北京天融信网络安全技术有限公司 网络访问旁路监控方法及电子设备
CN116048544A (zh) * 2022-08-24 2023-05-02 荣耀终端有限公司 一种弹窗广告的处理方法、电子设备及可读存储介质
CN116048544B (zh) * 2022-08-24 2023-11-07 荣耀终端有限公司 一种弹窗广告的处理方法、电子设备及可读存储介质

Also Published As

Publication number Publication date
CN106341373A (zh) 2017-01-18
CN106341373B (zh) 2019-07-23

Similar Documents

Publication Publication Date Title
WO2017004952A1 (zh) 用于检测和阻止恶意点击广告链接的方法和装置
US9634915B2 (en) Methods and computer program products for generating a model of network application health
US10404556B2 (en) Methods and computer program products for correlation analysis of network traffic in a network device
US10601951B2 (en) Optimization of resource polling intervals to satisfy mobile device requests
US8868727B2 (en) Methods and computer program products for storing generated network application performance data
US9621441B2 (en) Methods and computer program products for analysis of network traffic by port level and/or protocol level filtering in a network device
US9021048B2 (en) Caching adapted for mobile application behavior and network conditions
KR101227769B1 (ko) 폴링 간격을 이용한 모바일 네트워크 배경 트래픽 데이터 관리
US8645532B2 (en) Methods and computer program products for monitoring the contents of network traffic in a network device
US8903954B2 (en) Optimization of resource polling intervals to satisfy mobile device requests
CN111124819B (zh) 全链路监控的方法和装置
US8589537B2 (en) Methods and computer program products for aggregating network application performance metrics by process pool
US9961157B2 (en) Adaptive compression management for web services
US8909761B2 (en) Methods and computer program products for monitoring and reporting performance of network applications executing in operating-system-level virtualization containers
US10776245B2 (en) Analyzing physical machine impact on business transaction performance
EP2789138A1 (en) A mobile device and method to utilize the failover mechanisms for fault tolerance provided for mobile traffic management and network/device resource conservation
WO2022063032A1 (zh) 一种面向分布式系统的故障信息关联上报方法及相关设备
US8312138B2 (en) Methods and computer program products for identifying and monitoring related business application processes
WO2015000428A1 (zh) 数据处理的方法、服务器及系统
JP2016158070A (ja) 基地局輻輳管理システム、及び基地局輻輳管理方法
US20170214732A1 (en) Techniques to detect and react to proxy interference
JP6076813B2 (ja) 端末の稼動状況監視方法
US9674282B2 (en) Synchronizing SLM statuses of a plurality of appliances in a cluster
CN116781746A (zh) 物联网消息缓存指令数量控制方法、装置、设备及介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15897600

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 30/04/2018)

122 Ep: pct application non-entry in european phase

Ref document number: 15897600

Country of ref document: EP

Kind code of ref document: A1