WO2017054716A1 - 识别被劫持浏览器的方法及浏览器 - Google Patents

识别被劫持浏览器的方法及浏览器 Download PDF

Info

Publication number
WO2017054716A1
WO2017054716A1 PCT/CN2016/100426 CN2016100426W WO2017054716A1 WO 2017054716 A1 WO2017054716 A1 WO 2017054716A1 CN 2016100426 W CN2016100426 W CN 2016100426W WO 2017054716 A1 WO2017054716 A1 WO 2017054716A1
Authority
WO
WIPO (PCT)
Prior art keywords
browser
hijacked
access request
blacklist
domain name
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/100426
Other languages
English (en)
French (fr)
Inventor
高庆光
贾正强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN201510639835.6A external-priority patent/CN105357265A/zh
Priority claimed from CN201510639832.2A external-priority patent/CN105160246A/zh
Priority claimed from CN201510640171.5A external-priority patent/CN105160247B/zh
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Publication of WO2017054716A1 publication Critical patent/WO2017054716A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures

Definitions

  • the present invention relates to the field of computer network technologies, and in particular, to a method and a browser for identifying a hijacked browser.
  • the following methods are generally adopted: first, the user checks whether the browser's home page or other settings have been changed; second, the user determines whether a cascading pop-up window appears, that is, on the screen. There is a seemingly endless series of pop-up pop-ups; third, the user determines whether a new toolbar or favorites is installed, and provides icons and links to web pages that you don't need; the above judgment methods are user-determined browsers. Whether it is hijacked, and the user usually judges whether the browser is hijacked through his own experience, and the user's experience directly affects the accuracy of the judgment. Users with less experience will inevitably have a judgment error. The method leading to the judgment of whether the browser is hijacked in the prior art has a problem of low accuracy.
  • the embodiment of the present application solves the technical problem that the method for determining whether a browser is hijacked in the prior art has low accuracy by providing a method for identifying a hijacked browser and a browser, and improves whether the browser is judged to be The technical effect of the accuracy of hijacking.
  • the present application provides the following technical solutions by using an embodiment of the present application:
  • the present application discloses a method for identifying a hijacked browser, including:
  • the browser obtains a webpage access request and corresponding operation information
  • the browser detects whether the operation information meets a preset rule, and the preset rule includes an operation request allowed by the browser;
  • the browser When the browser detects that the operation information does not meet the preset rule, the browser identifies that the browser has been hijacked;
  • the browser obtains the webpage access request and the corresponding operation information
  • the method includes: obtaining, by the browser, a webpage access request of the navigation page, and acquiring a target domain name corresponding to the webpage access request;
  • the browser detects whether the operation information meets a preset rule, and specifically includes: the browser determining whether the target domain name is consistent with an original domain name of the navigation page;
  • the browser detects that the operation information meets the preset rule, the browser is not hijacked, and the method includes: when the browser determines that the target domain name is consistent with the original domain name, Identifying that the browser is not hijacked;
  • the browser detects that the operation information does not meet the preset rule, the browser identifies that the browser has been hijacked, and the method includes: the browser determines that the target domain name is inconsistent with the original domain name. At the time, it is recognized that the browser has been hijacked.
  • the browser obtains the webpage access request and the corresponding operation information, and specifically includes: setting parameter information of the command line of the shortcut of the browser;
  • the detecting, by the browser, whether the operation information meets the preset rule includes: determining whether the setting mode corresponding to the parameter setting information is consistent with the preset mode;
  • the browser When the browser detects that the operation information does not meet the preset rule, the browser identifies that the browser has been hijacked, and specifically includes: identifying, when the setting mode is inconsistent with the preset mode, identifying The browser has been hijacked;
  • the method includes: when determining that the setting mode is consistent with the preset mode, identifying the device The browser is not hijacked.
  • the present application discloses a method for identifying a hijacked browser, including:
  • the browser obtains a webpage access request and corresponding operation information
  • the browser detects whether the operation information meets a preset rule, and the preset rule includes an operation request allowed by the browser;
  • the browser When detecting that the operation information does not meet the preset rule, the browser acquires a page address of a search page corresponding to the webpage access request;
  • the browser determines whether the page address is located in the blacklist, and obtains a determination result, wherein the blacklist stores the website information of the browser that is hijacked;
  • the browser When the browser detects that the judgment result indicates that the page address is located in the blacklist, the browser identifies that the browser has been hijacked;
  • the browser When the browser detects that the judgment result indicates that the page address is not located in the blacklist, the browser identifies that the browser is not hijacked.
  • the present application provides the following technical solutions by using an embodiment of the present application:
  • the application discloses a browser, and the browser includes:
  • An access request obtaining unit configured to obtain a webpage access request
  • An operation information acquiring unit configured to acquire operation information corresponding to the webpage access request
  • a detecting unit configured to detect whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser;
  • the identifying unit is configured to: when detecting that the operation information does not meet the preset rule, identify that the browser has been hijacked; and identify that the operation information meets the preset rule The browser is not hijacked.
  • the browser further includes:
  • the access request obtaining unit is specifically configured to acquire a webpage access request of a navigation page of the browser
  • a target domain name obtaining unit configured to acquire a target domain name corresponding to the webpage access request
  • a determining unit configured to determine whether the target domain name is consistent with an original domain name of the navigation page
  • the identifying unit is specifically configured to: when it is determined that the target domain name is consistent with the original domain name, identify that the browser is not hijacked; and when determining that the target domain name is inconsistent with the original domain name, It is then recognized that the browser has been hijacked.
  • the browser further includes:
  • a command line parameter obtaining unit configured to obtain parameter setting information of a command line of a shortcut of the browser
  • a determining unit configured to determine whether a setting manner corresponding to the parameter setting information is consistent with a preset manner
  • the identifying unit is configured to: when it is determined that the setting manner is inconsistent with the preset manner, identify that the browser has been hijacked; and when determining that the setting manner is consistent with the preset manner Recognizing that the browser is not hijacked.
  • the present application provides the following technical solutions by using an embodiment of the present application:
  • the application discloses a browser, and the browser includes:
  • An access request obtaining unit configured to obtain a webpage access request
  • An operation information acquiring unit configured to acquire operation information corresponding to the webpage access request
  • a detecting unit configured to detect whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser;
  • a page address obtaining unit configured to acquire a page address of a search page corresponding to the webpage access request when detecting that the operation information does not meet the preset rule
  • a judging unit configured to determine whether the page address is located in a blacklist, and obtain a judgment result, wherein the blacklist stores information about the web address of the browser that is hijacked;
  • An identifying unit configured to: when detecting that the determining result indicates that the page address is located in the blacklist, identifying that the browser has been hijacked; and detecting that the page address is not represented by the determining result When located in the blacklist, it is recognized that the browser is not hijacked.
  • a computer program comprising computer readable code, when said computer readable code is run on a computing device, causing said computing device to perform recognition according to said The method of hijacking the browser.
  • a computer readable medium storing the above computer program is provided.
  • a method for identifying a hijacked browser and a browser the browser obtains a webpage access request and its corresponding operation information, and then detects whether the operation information conforms to a preset rule,
  • the rule is preset, it is recognized that the browser has been hijacked, otherwise, the browser is recognized as not being hijacked, because the preset rule includes an operation request allowed by the browser, by detecting whether the operation request is Compliance with the preset rule can more accurately identify whether the browser is hijacked, so that the browser can improve the accuracy of whether the browser is hijacked according to the judgment result, and The browser judges whether it is hijacked or not, and the working efficiency of the judgment can be greatly improved compared with the manual judgment in the prior art.
  • a method for hijacking a browser by domain name identification by the browser, the browser obtains a webpage access request and its corresponding target domain name, and then determines whether the target domain name is original with the navigation page. The domain name is consistent. When it is determined that the target domain name is consistent with the original domain name, the browser is recognized as not being hijacked; and when it is determined that the target domain name is inconsistent with the original domain name, the device is identified.
  • the browser has been hijacked; thus, by determining whether the target domain name is consistent with the original domain name, thereby identifying whether the browser is hijacked, the accuracy of the recognition is also improved, and The browser judges whether it is hijacked or not, and the working efficiency of the judgment can be greatly improved compared with the manual judgment in the prior art.
  • the present invention obtains parameter setting information of a command line of a shortcut of the browser; determines whether the setting mode corresponding to the parameter setting information is consistent with the preset mode; and determines the setting mode and the pre-determination
  • the mode is inconsistent, it is recognized that the browser has been hijacked; when it is determined that the setting mode is consistent with the preset mode, it is recognized that the browser is not hijacked; thus, by determining the setting Whether the manner is consistent with the preset manner to determine whether the setting manner has been modified, and when the browser is not hijacked, the setting manner is consistent with the preset manner, and the browser is In the case of hijacking, the setting manner may be inconsistent with the preset manner, so that it is possible to accurately identify whether the browser is hijacked or not by determining whether the setting manner is consistent with the preset manner.
  • the accuracy of the recognition, and the machine judgment method to determine whether the browser is hijacked, compared with the manual judgment in the prior art, the judgment Work efficiency can be greatly improved.
  • FIG. 1 is a first flowchart of a method for identifying a hijacked browser according to an embodiment of the present invention
  • FIG. 2 is a second flowchart of a method for identifying a hijacked browser according to an embodiment of the present invention
  • FIG. 3 is a first block diagram of a browser according to an embodiment of the present invention.
  • FIG. 4 is a second block diagram of a browser according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of a method for hijacking a browser by domain name identification according to an embodiment of the present invention
  • FIG. 6 is a block diagram of a browser according to an embodiment of the present invention.
  • FIG. 7 is a third flowchart of a method for identifying a hijacked browser according to an embodiment of the present invention.
  • FIG. 8 is a fourth flowchart of a method for identifying a hijacked browser according to an embodiment of the present invention.
  • FIG. 9 is a block diagram of a device for identifying a hijacked browser according to an embodiment of the present invention.
  • Figure 10 is a schematic block diagram of a computing device for performing a method of identifying a hijacked browser in accordance with the present invention
  • Figure 11 schematically illustrates a storage unit for holding or carrying program code that implements a method of identifying a hijacked browser in accordance with the present invention.
  • a method for identifying a hijacked browser includes the following steps:
  • Step S101 The browser obtains a webpage access request and corresponding operation information
  • Step S102 The browser detects whether the operation information conforms to a preset rule, where the preset rule includes an operation request allowed by the browser;
  • Step S103 The browser recognizes that the browser has been hijacked when detecting that the operation information does not meet the preset rule.
  • Step S104 When the browser detects that the operation information conforms to the preset rule, it is recognized that the browser is not hijacked.
  • step S101 after the browser is started, the operation information of the user is received, and based on the operation information, the browser automatically generates and obtains a webpage access request corresponding to the operation information, so that the browser is enabled.
  • the webpage access request and the corresponding operation information thereof can be obtained, wherein the operation information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can input the search in the search bar of the browser.
  • Informational information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can input the search in the search bar of the browser.
  • the user receives the operation information of www.axxx.com in the search bar of the browser, and the browser generates a visit www based on the operation information.
  • Operation information which is information for inputting www.axxx.com in the search field of a browser.
  • step S102 is performed, in which the browser detects whether the operation information conforms to a preset rule, and the preset rule includes an operation request allowed by the browser.
  • step S101 after the browser obtains the operation information in step S101, it is detected whether the operation information meets the preset rule, and the preset rule includes an operation request allowed by the browser, and thus, Whether the operation information conforms to the preset rule, that is, whether the operation information is legal or not can be determined.
  • the operation request allowed by the browser includes a first operation request for inputting search information in a search bar of the browser and a second operation request generated by clicking a hyperlink on the navigation page of the browser, and then Detecting whether the operation information matches one of the first operation request and the second operation request, the operation information and the first operation request and the second operation When the requests are not matched, it is determined that the operation information does not meet the preset rule; when the operation information matches any one of the first operation request and the second operation request Determining that the operation information conforms to the preset rule.
  • the preset rule further includes a third operation request for inputting information in the search engine when the search engine is loaded in the browser, and the following specific The preset rule is an example of the first and second operation requests.
  • the operation information is a request for inputting search information of www.axxx.com in a search bar of a browser, and the first operation of inputting search information in a search bar of a browser is a preset rule of a browser.
  • a second operation request generated by requesting and clicking on a hyperlink on a navigation page of the browser, and determining that the operation information conforms to the preset because the operation information matches the first operation request rule.
  • the preset rule may further be: determining that the operation information matches the webpage access request, for example, the operation information is search information of www.axxx.com input in a search bar of a browser, where The webpage access request is an access request to www.bxxx.com, so that it can be determined that the operation information does not match the webpage access request, and then the browser is determined to be hijacked; and when the browser is not hijacked, The operational information is matched to the webpage access request.
  • step S103 is performed to identify that the browser has been hijacked; and when the browser detects that the operation information meets the preset rule, the browser performs step S104. Identified that the browser was not hijacked.
  • the browser when the browser detects that the operation information does not meet the preset rule, the browser confirms that the browser has been hijacked; and if it detects that the operation information meets the preset rule, Make sure the browser is not hijacked.
  • the user receives the search information of www.axxx.com in the search bar of the browser, and the browser generates a visit www.axxx based on the operation information.
  • the operation information is information for inputting www.axxx.com in the search bar of the browser, because the preset rule of the browser is the first operation request and the pair of inputting the search information in the search bar of the browser.
  • the second operation request generated by clicking on the hyperlink on the navigation page of the browser, due to the operation The information matches the first operation request, and then determines that the operation information conforms to the preset rule, that is, the browser can determine that the browser is not hijacked, so that the browser is in the
  • the judgment result indicates that the accuracy of whether the browser is hijacked is improved, and the browser judges whether it is hijacked by itself, and the working efficiency of the judgment can be compared with the manual judgment in the prior art. Great improvement.
  • the present application also provides a method for identifying a hijacked browser. Referring to FIG. 2, the method includes the following steps:
  • Step S201 The browser obtains a webpage access request and corresponding operation information
  • Step S202 The browser detects whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser;
  • Step S203 The browser acquires a page address of the search page corresponding to the webpage access request when detecting that the operation information does not meet the preset rule;
  • Step S204 The browser determines whether the page address is located in the blacklist, and obtains a determination result, wherein the blacklist stores the website information of the hijacking browser;
  • Step S205 When the browser detects that the judgment result indicates that the page address is located in the blacklist, the browser identifies that the browser has been hijacked;
  • Step S206 The browser recognizes that the browser is not hijacked when detecting that the judgment result indicates that the page address is not located in the blacklist.
  • step S201 after the browser is started, the operation information of the user is received, and based on the operation information, the browser automatically generates and obtains a webpage access request corresponding to the operation information, so that the browser is enabled.
  • the webpage access request and the corresponding operation information thereof can be obtained, wherein the operation information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can input the search in the search bar of the browser.
  • Informational information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can input the search in the search bar of the browser.
  • step S202 is performed, in which the browser detects whether the operation information conforms to a preset rule, and the preset rule includes an operation request allowed by the browser.
  • step S101 after the browser obtains the operation information in step S101, it is detected whether the operation information meets the preset rule, and the preset rule includes an operation request allowed by the browser, and thus, Whether the operation information conforms to the preset rule, that is, whether the operation information is legal or not can be determined.
  • step S203 is executed to obtain a page address of the search page corresponding to the webpage access request.
  • the browser when the browser detects that the operation information does not meet the preset rule, the browser obtains a page address of the search page corresponding to the webpage access request, and the search page may be a browser.
  • the home page which can also be the browser's navigation page, can also be a search engine page loaded in the browser, or a navigation page of other browsers loaded in the browser, of course, usually the browser's home page and browser
  • the navigation page may be the same page.
  • the user receives the search information of www.axxx.com in the search bar of the browser, and the webpage generated by the browser based on the operation information.
  • the request of com since www.bxxx.com is different from www.axxx.com, determines that the operation information does not comply with the preset rule, because the webpage search request is input in the search bar of a browser.
  • the search information generated by www.axxx.com is generated, thereby determining that the search page is the homepage of the browser of a browser, and then obtaining the page address of the homepage of the browser of the browser is, for example, http://hao.axxx.com/ .
  • a browser page is loaded with a navigation page, wherein a navigation page is a preset navigation page in a browser, and a browser receives the user.
  • the a browser can receive the webpage access request to access www.axxx.com and its corresponding operation information, the operation information is the information of inputting www.axxx.com in the a navigation page, if
  • the preset rule of the browser is a first operation request for inputting search information in the search bar of the browser of the browser and a second operation request generated by clicking on the hyperlink on the navigation page of the browser of the browser.
  • the operation information does not match the first operation request and the second operation request, determining that the operation information does not meet the preset rule, and then acquiring a search page corresponding to the webpage access request is a navigation page, then get the page of a navigation page
  • the address of the page for example, http://hao.axxx.com/.
  • step S204 is performed, in which the browser determines whether the page address is in the blacklist and obtains A result of the judgment, wherein the blacklist stores the URL information of the hijacking browser.
  • the browser before the browser determines whether the page address is in the blacklist, the browser obtains and stores the blacklist according to the historical data of the browser being hijacked, wherein the browser acquires the history.
  • the historical data may be obtained by receiving the feedback information of the user, or the historical data may be acquired by means of data collection and monitoring, and after the blacklist is obtained through the historical data, the browser further
  • the blacklist can be continuously updated by continuously collecting other data that the browser is hijacked, so that the blacklist can store more URL information of the hijacked browser, so that the page is judged by the blacklist. Whether the address is located in the blacklist and the result of the judgment can be more accurate.
  • a browser collects historical data of a browser that is hijacked, and displays A web address, B web address, and C web address to hijack a browser, and then establishes the black list, so that the The A, B, and C URLs are stored in the blacklist.
  • the a browser generates the blacklist according to the currently collected historical data, where the blacklist stores the A web address, the B web address, and the C web address, after the blacklist is generated.
  • the browser continuously collects other data that the browser is hijacked.
  • the other data collected includes the D URL and the data of the a browser is hijacked
  • the D URL is added to the blacklist to make the update.
  • the D-list is stored in the blacklist, and the D-URL is stored in the blacklist after the update, so that more URL information of the hijacked browser can be stored in the blacklist, and the updated
  • the blacklist can determine whether the page address is located in the blacklist, the judgment result can be made more accurate.
  • step S203 After the browser obtains the page address in step S203, it is determined whether the page address is located in the blacklist, and obtains the determination result, wherein when the page address is located in the blacklist, The determining result indicates that the page address is located in the blacklist; when the page address is not located in the blacklist, the determining result indicates that the page address is not located in the blacklist.
  • a browser page loads a b navigation page, wherein the b navigation page is not a preset navigation page in a browser, and a browser receives the user.
  • the a browser can receive the webpage access request to access www.cxxx.com and its corresponding operation information, the operation information is the information of the www.cxxx.com and the b browsing in the b navigation page If the first operation request and the second operation request in the preset rule of the device do not match, it is determined that the operation information does not meet the preset rule, and then extracts from the webpage access request.
  • the page address is http://www.axxx.com/, and then judge whether http://www.axxx.com/ is located in the blacklist stored in a browser, if http://www .axxx.com/ is located in the blacklist, and the judgment result indicates that the page address is located in the In the blacklist; if http://www.axxx.com/ is not located in the blacklist, the judgment result indicates that the page address is not located in the blacklist.
  • step S205 When the browser detects that the judgment result indicates that the page address is located in the blacklist, step S205 is performed to identify that the browser has been hijacked; and the browser detects the result of the determination to represent the page address.
  • step S206 is performed to identify that the browser is not hijacked.
  • the determination result obtained in step S204 can accurately determine whether the page address is located in the blacklist, and the browser determines, according to the determination result, whether the browser is hijacked.
  • a b navigation page is loaded on a browser, wherein b navigation page is not a preset navigation page in a browser, and a browser receives
  • the a browser can receive the webpage access request to access www.axxx.com and its corresponding operation information, the operation information is the information of entering www.axxx.com in the b navigation page and a If the first operation request and the second operation request in the preset rule of the browser do not match, determining that the operation information does not meet the preset rule, and then acquiring the corresponding corresponding to the webpage access request
  • the search page is b navigation page, and then obtain the page address of a navigation page, for example, http://hao.bxxx.com/, and then judge whether http://www.bxxx.com/ is located in a browsing In the blacklist stored in the device, if http://www.bxxx.com/ is located in the blacklist
  • the judgment result indicates that the page address is located in the blacklist, so that it can be recognized that the a browser has been hijacked; if http://www.bxxx.com/ is not located in the blacklist, The judgment result indicates that the page address is not located in
  • the method when the webpage access request is a webpage access request of a navigation page of the browser, the method further includes: the browser determining whether the access address corresponding to the webpage access request of the navigation page is the Navigation address of the navigation page; when the browser determines that the access address is not the navigation address, it recognizes that the browser has been hijacked; when the browser determines that the access address is the navigation address, it recognizes browsing The device was not hijacked.
  • the browser may obtain, by detecting whether the webpage access request is to load the navigation page at startup, if Determining, the webpage access request is a webpage access request of the navigation page, and then acquiring the access address according to the webpage access request, the accessing address is a webpage of the navigation page; of course, the browser is After the startup, the browser may also be configured to detect whether the webpage access request is obtained when the user initiates the activation request of the navigation page, and if yes, determine that the webpage access request is the webpage access of the navigation page. The requesting, the browser loads the navigation page according to the startup request, and further obtains a webpage access request of the navigation page, and then acquires the access address according to the webpage access request.
  • the browser detects that the webpage access request is a webpage access request of the navigation page of the browser, it is determined whether the access address corresponding to the webpage access request of the navigation page is a navigation address of the navigation page, where The navigation address of the navigation page of the browser may be pre-stored in the browser, and the page may be pre-stored in the user terminal where the browser is installed, which is not specifically limited herein.
  • a navigation page is automatically loaded.
  • the a browser when receiving the start request of the user to start a navigation page, the a browser loads a navigation page, generates a webpage access request of the a navigation page, and then extracts the access address from the webpage access request of the a navigation page to http:/ /hao.axxx.cn/, and then determine whether http://hao.axxx.cn/ is the same as the navigation address of the navigation page in a browser.
  • the navigation page loaded may be a navigation page, but other web pages are, for example, commercial web pages, advertisement web pages, and the like.
  • a navigation page is automatically loaded, and when a browser loads a navigation page, a webpage access request of a navigation page is generated, and if a webpage of a navigation page is generated,
  • the browser extracts the access address from the webpage access request of the a navigation page: http://hao.bxxx.cn/, Then, it is judged whether http://hao.bxxx.cn/ is the same as the navigation address of the navigation page in the browser, if the navigation address stored in advance is http://hao.axxx.cn/, because a navigation page
  • the navigation address is http://hao.axxx.cn/ is different from http://hao.bxxx.cn/, then the browser recognizes that it has been hijacked.
  • a method for identifying a hijacked browser and a browser the browser obtains a webpage access request and its corresponding operation information, and then detects whether the operation information conforms to a preset rule,
  • the rule is preset, it is recognized that the browser has been hijacked, otherwise, the browser is recognized as not being hijacked, because the preset rule includes an operation request allowed by the browser, by detecting whether the operation request is Compliance with the preset rule can more accurately identify whether the browser is hijacked, so that the browser can improve the accuracy of whether the browser is hijacked according to the judgment result, and The browser judges whether it is hijacked or not, and the working efficiency of the judgment can be greatly improved compared with the manual judgment in the prior art.
  • the browser when the operation information does not meet the preset rule, the browser further obtains an access address corresponding to the webpage access request, and then determines whether the page address is located in the blacklist, and identifies the location according to the obtained judgment result. Whether the browser is hijacked, because the blacklist stores the web address information of the browser, so that the browser can be more accurately identified according to the judgment result, so that the browsing is performed. The accuracy of identifying whether the browser is hijacked according to the judgment result is improved, and the browser is self-determined whether it is hijacked, and the working efficiency of the judgment is compared with the manual judgment in the prior art. A large improvement can also be obtained.
  • the browser includes:
  • the access request obtaining unit 301 is configured to obtain a webpage access request
  • the operation information obtaining unit 302 is configured to acquire operation information corresponding to the webpage access request
  • the detecting unit 303 is configured to detect whether the operation information meets a preset rule, where the preset rule includes the browser Allowed operation request;
  • the identifying unit 304 is configured to: when detecting that the operation information does not meet the preset rule, identify that the browser has been hijacked; and identify that the operation information meets the preset rule, and identify The browser is not hijacked.
  • the browser further includes:
  • the determining unit 305 is further configured to: when the webpage access request is a webpage access request of the navigation page of the browser, determine whether the access address corresponding to the webpage access request of the navigation page is a navigation address of the navigation page;
  • the identifying unit 304 is further configured to: when it is determined that the access address is not the navigation address, identify that the browser has been hijacked; and determine that the access address is the navigation address, identify the The browser has not been hijacked.
  • the access request obtaining unit 301 is further configured to: when the webpage access request is a webpage access request of the navigation page of the browser, when the navigation page is started and loaded, obtaining webpage access of the navigation page request.
  • another embodiment of the present application provides a browser, and referring to FIG. 4, the browser includes:
  • the access request obtaining unit 401 is configured to obtain a webpage access request
  • the operation information acquiring unit 402 is configured to acquire operation information corresponding to the webpage access request
  • the detecting unit 403 is configured to detect whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser;
  • the page address obtaining unit 404 is configured to: when detecting that the operation information does not meet the preset rule, acquire a page address of a search page corresponding to the webpage access request;
  • the determining unit 405 is configured to determine whether the page address is located in the blacklist, and obtain a determination result, wherein the blacklist stores the website information of the browser that is hijacked;
  • the identifying unit 406 is configured to: when detecting that the determining result indicates that the page address is located in the blacklist, identify that the browser has been hijacked; and characterizing the page address after detecting the determining result When not in the blacklist, it is recognized that the browser is not hijacked.
  • the browser further includes:
  • the blacklist obtaining unit 407 is configured to acquire and store the blacklist according to historical data that the browser is hijacked before the browser determines whether the page address is in the blacklist.
  • a method for identifying a hijacked browser and a browser the browser obtains a webpage access request and its corresponding operation information, and then detects whether the operation information conforms to a preset rule,
  • the rule is preset, it is recognized that the browser has been hijacked, otherwise, the browser is recognized as not being hijacked, because the preset rule includes an operation request allowed by the browser, by detecting whether the operation request is Compliance with the preset rule can more accurately identify whether the browser is hijacked, so that the browser can improve the accuracy of whether the browser is hijacked according to the judgment result, and The browser judges whether it is hijacked or not, and the working efficiency of the judgment can be greatly improved compared with the manual judgment in the prior art.
  • the browser when the operation information does not meet the preset rule, the browser further obtains an access address corresponding to the webpage access request, and then determines whether the page address is located in the blacklist, and identifies the location according to the obtained judgment result. Whether the browser is hijacked, because the blacklist stores the web address information of the browser, so that the browser can be more accurately identified according to the judgment result, so that the browsing is performed. The accuracy of identifying whether the browser is hijacked according to the judgment result is improved, and the browser is self-determined whether it is hijacked, and the working efficiency of the judgment is compared with the manual judgment in the prior art. A large improvement can also be obtained.
  • a method for hijacking a browser by domain name identification includes the following steps:
  • S501 The browser obtains a webpage access request of the navigation page, and acquires a target domain name corresponding to the webpage access request;
  • S502 The browser determines whether the target domain name is consistent with the original domain name of the navigation page.
  • the browser automatically loads the navigation page when the browser starts, so that the browser can obtain the webpage access request of the navigation page, and then obtain the target domain name according to the webpage access request;
  • the browser receives a startup request by the user to start the navigation page, and the browser loads the guide according to the startup request.
  • the navigation page further obtains a webpage access request to the navigation page, and then acquires the target domain name according to the webpage access request.
  • the browser when the browser obtains the target domain name, the browser may directly extract the target domain name from the webpage access request, and the webpage access request may specifically be an http format access request.
  • a navigation page is automatically loaded.
  • the browser can extract the target domain name from the webpage access request of a navigation page to hao.axxx.cn; if the browser is started, the user starts a navigation page
  • the browser loads a navigation page, generates a webpage access request for the navigation page, and then extracts the target domain name from the webpage access request of the a navigation page to hao.axxx.cn.
  • the navigation page loaded may be a navigation page, but a navigation page of another browser, such as a b navigation page, such as a commercial webpage, an advertisement webpage, etc., so that the obtained
  • the target domain name is different from the original domain name of the a navigation page; and when the a browser is not hijacked, the acquired target domain name is the same as the original domain name of the a navigation page.
  • step S502 is performed, in which the browser determines whether the target domain name is consistent with the original domain name of the navigation page.
  • the browser before the browser determines whether the target domain name is consistent with the original domain name of the navigation page, the browser stores the original domain name of the navigation page, and thus, after acquiring the target domain name, the browser The target domain name can be compared with the original domain name to determine whether the target domain name is consistent with the original domain name.
  • the original domain name can also be stored in a user terminal where the browser is installed.
  • the browser determines whether the target domain name is the same as the original domain name, and if the same, determines that the target domain name is consistent with the original domain name; if not, It is determined that the target domain name is inconsistent with the original domain name.
  • the webpage of the navigation page may be obtained directly when the browser first starts and loads the navigation page, and then the navigation is extracted from the webpage of the navigation page.
  • the original domain name of the page is then stored in the browser; or the webpage access request of the navigation page is automatically generated when the navigation page is loaded before the browser is not hijacked, the browser from the browser.
  • the original domain name of the navigation page is extracted from the webpage access request, and then the original domain name is stored in a browser.
  • a navigation page is automatically loaded.
  • step S503 is performed to identify that the browser is not hijacked; and when the browser determines that the target domain name is inconsistent with the original domain name, the browser performs steps. S504, identifying that the browser has been hijacked.
  • the browser identifies, according to the step S502, that the target domain name is consistent with the original domain name, the browser is not hijacked; and determining the target domain name and location When the original domain name is inconsistent, it is recognized that the browser has been hijacked.
  • a navigation page is automatically loaded.
  • the method when the recognizing that the browser has been hijacked, the method further includes: the browser generates the prompt information, and generates a prompt window on the page loaded by the browser; the browser displays the prompt information The loading is displayed in the prompt window.
  • the browser when the browser recognizes that the browser is hijacked, the browser may generate the prompt information, where the prompt information may be text information such as “the browser has been hijacked” and “the browser has a security risk”.
  • the prompt window is then generated on the page loaded by the browser, and the prompt information is loaded into the prompt window for display to remind the user.
  • the prompt information may further include voice information, and when the prompt information is loaded in the prompt window for display, the prompt information may also be voice output.
  • a method for hijacking a browser by domain name identification by which the browser obtains a webpage access request and its corresponding target domain name, and then determines whether the target domain name is consistent with the original domain name of the navigation page. Identifying, when the target domain name is consistent with the original domain name, identifying that the browser is not hijacked; and identifying that the target domain name is inconsistent with the original domain name, identifying the browser Has been hijacked; in this way, by determining whether the target domain name is consistent with the original domain name, thereby identifying whether the browser is hijacked, the accuracy of the recognition is also improved, and the browser itself Judging whether or not you are hijacked, the working efficiency of the judgment can be greatly improved compared with the manual judgment in the prior art.
  • FIG. 6 the browser includes:
  • the access request obtaining unit 601 is configured to acquire a webpage access request of the navigation page of the browser;
  • the target domain name obtaining unit 602 is configured to acquire a target domain name corresponding to the webpage access request
  • the determining unit 603 is configured to determine whether the target domain name is consistent with the original domain name of the navigation page.
  • the identifying unit 604 is configured to: when it is determined that the target domain name is consistent with the original domain name, identify that the browser is not hijacked; and when it is determined that the target domain name is inconsistent with the original domain name, identify The browser has been hijacked.
  • the access request obtaining unit 601 is configured to acquire a webpage access request of the navigation page when the navigation page is started and loaded
  • the target domain name obtaining unit 602 is specifically configured to acquire the location according to the webpage access request.
  • the target domain name may be specifically extracted from the webpage access request.
  • the browser automatically loads the navigation page when the browser starts, and the access request obtaining unit 601 can obtain the webpage access request of the navigation page, and then obtain the target domain name according to the webpage access request; of course, the browser is started.
  • the access request obtaining unit 601 receives the activation request of the navigation page by the user, the webpage access request of the navigation page can also be acquired according to the activation.
  • the browser further includes:
  • the domain name storage unit 605 is configured to store the original domain name of the navigation page before determining whether the target domain name matches the original domain name of the navigation page.
  • the domain name storage unit 605 Before the determining unit 603 determines whether the target domain name is consistent with the original domain name of the navigation page, the domain name storage unit 605 stores the original domain name of the navigation page in the browser, so that the target domain name is obtained. Afterwards, the determining unit 603 can compare the target domain name with the original domain name, so as to determine whether the target domain name is consistent with the original domain name. Of course, the domain name storage unit 605 can also store the original domain name. In the user terminal where the browser is installed.
  • the determining unit 603 determines whether the target domain name is the same as the original domain name, and if the same, determines that the target domain name is consistent with the original domain name; If not, it is determined that the target domain name is inconsistent with the original domain name.
  • the browser further includes a prompt information and a window generating unit 606, configured to generate prompt information when the browser is recognized to be hijacked, and generate a prompt window on the page loaded by the browser.
  • the loading unit 607 is configured to load the prompt information in the prompt window for display.
  • a method for hijacking a browser by domain name identification by which the browser obtains a webpage access request and its corresponding target domain name, and then determines whether the target domain name is consistent with the original domain name of the navigation page.
  • the target domain name is consistent with the original domain name
  • identifying that the browser is not hijacked identifying that the browser is not hijacked; and determining the destination
  • the target domain name is inconsistent with the original domain name, it is recognized that the browser has been hijacked; thus, whether the browser is recognized by determining whether the target domain name is consistent with the original domain name Hijacking, the accuracy of its recognition is also improved, and the browser itself judges whether or not it is hijacked.
  • the working efficiency of the judgment can be greatly improved.
  • an embodiment of the present invention further provides a method for identifying a hijacked browser, including the following steps:
  • S701 Obtain parameter setting information of a command line of a shortcut of the browser
  • S702 Determine whether a setting manner corresponding to the parameter setting information is consistent with a preset manner
  • the execution subject of the present invention is a device
  • the device may be, for example, a tablet computer, a notebook computer, a smart phone, a desktop computer, etc.
  • the browser is installed in the device, and the browser is quickly obtained.
  • the command line parameter information of the mode is set, the command line program installed in the device can be started.
  • the command line program is usually cmd.exe, and then the device receives the user input and
  • the parameter setting information is displayed in the command line program, so that the parameter setting information may be acquired according to the display content, wherein the parameter setting information
  • the setting mode information of the shortcut is included.
  • the parameter setting information may also be obtained by viewing attribute information of a shortcut of the browser.
  • a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
  • the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtains the parameter setting information.
  • step S702 is performed, in which it is determined whether the setting mode corresponding to the parameter setting information is consistent with the preset mode.
  • the preset mode is a default setting mode of the shortcut of the browser, and may be a manual setting mode or an automatic setting mode, and the following is specifically taking the preset mode as a manual setting mode.
  • step S701 After obtaining the parameter setting information in step S701, acquiring setting mode information of the shortcut mode from the parameter setting information, determining the setting mode based on the setting mode information of the shortcut mode, and then determining the Whether the setting mode is the manual setting mode, when the setting mode is the manual setting mode, determining that the setting mode is consistent with the preset mode; if the setting mode is not the manual setting mode, determining the The setting manner is inconsistent with the preset manner, wherein the determining method is the same as the foregoing determining method when the preset mode is the automatic setting mode.
  • a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
  • the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtaining the parameter setting information, if the setting mode information of the shortcut mode included in the parameter setting information is displayed, the setting mode corresponding to the shortcut of the browser is the manual setting mode, due to the manual setting mode and the If the preset mode is the same, it is determined that the setting mode is consistent with the preset mode; if the shortcut mode corresponding to the b browser is the automatic setting mode, since the automatic setting mode is different from the preset mode, It is determined that the setting manner is inconsistent with the preset manner.
  • step S703 is performed to identify that the browser has been hijacked; and when it is determined that the setting mode is consistent with the preset mode, step S704 is performed. It is recognized that the browser is not hijacked.
  • the device determines, by step S702, that the setting mode is inconsistent with the preset mode, the device identifies that the browser has been hijacked, and determines the setting mode and the pre-predetermined When the modes are the same, it is recognized that the browser is not hijacked.
  • a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
  • the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtaining the parameter setting information, if the setting mode information of the shortcut mode included in the parameter setting information is displayed, the setting mode corresponding to the shortcut of the browser is the manual setting mode, due to the manual setting mode and the The preset mode is the same, then the setting mode is determined.
  • the setting mode corresponding to the shortcut of the b browser is necessarily the preset mode
  • the setting mode corresponding to the shortcut of the b browser is Different from the preset mode, by determining whether the setting mode corresponding to the shortcut of the b browser is consistent with the preset mode, it is possible to accurately determine whether the b browser is hijacked, so that the accuracy of the judgment is made. Can be improved.
  • an embodiment of the present invention further provides a method for identifying a hijacked browser. Referring to FIG. 8, the method includes the following steps:
  • S802 Determine whether a setting manner corresponding to the parameter setting information is consistent with a preset manner
  • the execution subject of the present invention is a device
  • the device may be, for example, a tablet computer, a notebook computer, a smart phone, a desktop computer, etc.
  • the browser is installed in the device, and the browser is fast.
  • the command line parameter information of the mode is set
  • the command line program installed in the device can be started.
  • the command line program is usually cmd.exe, and then the device receives the user input and
  • the parameter setting information is displayed in the command line program, so that the parameter setting information may be acquired according to the display content, wherein the parameter setting information
  • the setting mode information of the shortcut is included.
  • the parameter setting information may also be obtained by viewing attribute information of a shortcut of the browser.
  • step S802 is performed, in which it is determined whether the setting mode corresponding to the parameter setting information is consistent with the preset mode.
  • the preset mode is a default setting mode of the shortcut of the browser, and may be a manual setting mode or an automatic setting mode, and the following is specifically taking the preset mode as a manual setting mode.
  • the setting mode information of the shortcut mode is obtained from the parameter setting information, the setting mode is determined based on the setting mode information of the shortcut mode, and then the determining manner is determined.
  • the setting mode is the manual setting mode
  • determining that the setting mode is consistent with the preset mode if the setting mode is not the manual setting mode, determining the The setting manner is inconsistent with the preset manner, wherein the determining method is the same as the foregoing determining method when the preset mode is the automatic setting mode.
  • step S803 is performed to determine whether the parameter setting information corresponding to the destination link is located in a pre-stored blacklist, wherein the blacklist stores hijacking the browsing. URL information for the device.
  • the setting mode is the manual setting mode
  • the setting mode is also the manual setting mode
  • the destination link is located in the blacklist, that is, the destination link is compared with each web address information in the blacklist, and if there is web address information matching the destination link in the blacklist, Determining that the destination link is located in the blacklist; if there is no URL information matching the destination link in the blacklist, determining that the destination link is not located in the blacklist, wherein the destination The link may be extracted from the parameter setting information, for example, the parameter setting information of the b browser includes the setting manner information of the shortcut of the b browser, the URL of the loaded destination link, and the like, and thus, according to the parameter setting of the b browser The information can be obtained from the target link.
  • the method further includes: acquiring and storing the blacklist according to historical data that the browser is hijacked, where
  • the device may obtain the historical data by receiving feedback information of the user, or obtain the historical data by means of data collection and monitoring, and obtain the local data through the historical data.
  • the device may continuously collect other data that the browser is hijacked, so as to continuously update the blacklist, so that the blacklist can store more URL information of the hijacked browser to improve The accuracy of the judgment.
  • the b browser is installed in the notebook computer A, and the historical data of the hijacked by the laptop computer A is displayed, and the A website, the B website, and the C website are all hijacked by the browser. And then establish a house
  • the blacklist is such that the A, B, and C URLs are stored in the blacklist.
  • a b browser is installed in the notebook computer A, and the notebook computer A generates the blacklist according to the currently collected historical data, and the blacklist stores the A website address and the B website address.
  • C URL after generating the blacklist, the laptop A continuously collects other data that the b browser is hijacked, and when the other data collected includes the D address and also hijacks the data of the b browser, then D
  • the URL is added to the blacklist, so that the updated blacklist stores the D webpage, and since the updated blacklist stores the D webpage, the blacklist can store more hijacking browsing.
  • the URL information of the device can be judged whether the access address is located in the blacklist through the updated blacklist, so that the accuracy of the judgment is improved.
  • the device may further add, when the browser is hijacked, the destination link corresponding to the parameter setting information to the pre-stored black when determining that the setting mode is inconsistent with the preset mode.
  • the blacklist stores information about the web address of the browser.
  • a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
  • the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtains the parameter setting information, and if the setting mode corresponding to the shortcut of the acquired b browser is the automatic setting mode according to the parameter setting information, since the automatic setting mode is different from the preset mode, determining The setting manner is inconsistent with the preset manner.
  • the destination link may be extracted from the parameter setting information, for example, an E web address, and the E web address is added.
  • the blacklist in this way, more blacklisted web address information can be stored in the blacklist.
  • step S804 is performed to identify that the browser has been hijacked; and when it is determined that the destination link is not located in the blacklist, step S805 is performed to identify The browser is not hijacked.
  • step S803 when the device determines in step S803 that the destination link is located in the blacklist, it is confirmed that the browser has been hijacked; and determines that the destination link is not located in the blacklist. In the middle, it is confirmed that the browser is not hijacked.
  • a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
  • the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtaining the parameter setting information, if the setting mode corresponding to the shortcut of the b browser is the manual setting mode according to the parameter setting information, since the manual setting mode is different from the preset mode, determining The setting mode is consistent with the preset mode.
  • the destination link may be extracted from the parameter setting information, for example, an A web address, if the blacklist is in the blacklist. Storing an A web address, a B web address, and a C web address, and knowing that the destination link is located in the black list, confirming that the b browser has been hijacked; If the D URL is not stored in the blacklist, the browser may be determined not to be hijacked; if the setting mode is consistent with the preset mode, whether the destination link is Located in the blacklist to further determine whether the b browser is hijacked to further improve the accuracy of determining whether the browser is hijacked.
  • the method when the recognizing that the browser has been hijacked, the method further includes: generating prompt information, and generating a prompt window on the page loaded by the browser; loading the prompt information in the Displayed in the prompt window.
  • the prompt information is automatically generated, and the prompt information may be text information such as “the browser has been hijacked” and “the browser has a security risk”. And generating the prompt window on the page loaded by the browser, and loading the prompt information into the prompt window for display to remind the user.
  • the prompt information may further include voice information, and when the prompt information is loaded in the prompt window for display, the prompt information may also be voice output.
  • a method and a device for identifying a hijacked browser are provided.
  • parameter setting information of a command line of a shortcut of a browser is obtained; and whether a setting mode corresponding to the parameter setting information is compared with a preset mode is determined. Consistent; when it is determined that the setting manner is inconsistent with the preset manner, it is recognized that the browser has been hijacked; When the setting manner is consistent with the preset mode, it is recognized that the browser is not hijacked; thus, it is determined whether the setting mode has been determined by determining whether the setting mode is consistent with the preset mode.
  • By determining whether the setting manner is consistent with the preset manner it is possible to accurately identify whether the browser is hijacked, thereby improving the accuracy of the identification, and determining whether the browser is hijacked by a machine judgment manner. Compared with the manual judgment in the prior art, the working efficiency of the judgment can be greatly improved.
  • the setting mode when it is determined that the setting mode is consistent with the preset mode, it may further determine whether the destination link corresponding to the parameter setting information is located in a pre-stored blacklist, thereby determining the browsing. Whether the browser is hijacked or not, because the web address information of the browser is hijacked in the blacklist, so that the browser can be more accurately identified according to the judgment result, so that the browser is in the browser. The accuracy of identifying whether the browser is hijacked according to the judgment result is further improved.
  • the device includes:
  • the command line parameter obtaining unit 901 is configured to obtain parameter setting information of a command line of a shortcut of the browser;
  • the determining unit 902 is configured to determine whether the setting mode corresponding to the parameter setting information is consistent with the preset mode
  • the identifying unit 903 is configured to: when it is determined that the setting manner is inconsistent with the preset manner, identify that the browser has been hijacked; and identify that the setting manner is consistent with the preset manner, and identify The browser is not hijacked.
  • the preset mode is a default setting manner of the shortcut of the browser, and may be a manual setting manner or an automatic setting manner.
  • the determining unit 902 is specifically configured to determine whether the setting mode is a manual setting mode when the preset mode is the manual setting mode.
  • the device further includes an adding unit 904, configured to add a destination link corresponding to the parameter setting information to a pre-stored blacklist after the browser is hijacked, wherein the black The list contains the URL information of the browser that hijacked the browser.
  • the determining unit 902 is further configured to: when it is determined that the setting mode is the manual setting mode, determine whether the parameter setting information corresponding to the destination link is located in a pre-stored blacklist, where the blacklist is stored Hijacking the URL information of the browser;
  • the identifying unit 903 is further configured to: when it is determined that the destination link is located in the blacklist, identify that the browser has been hijacked; and when it is determined that the destination link is not located in the blacklist, identify The browser is not hijacked.
  • the device further includes a blacklist storage unit 905, configured to acquire and store the destination link corresponding to the browser according to the historical data that the browser is hijacked before adding the destination link corresponding to the parameter setting information to the pre-stored blacklist. Blacklist.
  • the device further includes:
  • the prompt information and window generating unit 906 is configured to generate prompt information when the browser is recognized to have been hijacked, and generate a prompt window on the page loaded by the browser;
  • the loading unit 907 is configured to load the prompt information in the prompt window for display.
  • a method and a device for identifying a hijacked browser are provided.
  • parameter setting information of a command line of a shortcut of a browser is obtained; and whether a setting mode corresponding to the parameter setting information is compared with a preset mode is determined.
  • the setting mode when it is determined that the setting mode is consistent with the preset mode, it may further determine whether the destination link corresponding to the parameter setting information is located in a pre-stored blacklist, thereby determining the browsing. Whether the browser is hijacked or not, because the web address information of the browser is hijacked in the blacklist, so that the browser can be more accurately identified according to the judgment result, so that the browser is in the browser. The accuracy of identifying whether the browser is hijacked according to the judgment result is further improved.
  • modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
  • the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
  • any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
  • Each feature disclosed in this specification (including the accompanying claims, the abstract and the drawings) may be replaced by alternative features that provide the same, equivalent or similar purpose.
  • the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor may be used in practice to implement some or all of the functionality of some or all of the components of the browser, device, in accordance with embodiments of the present invention.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
  • Figure 10 illustrates a computing device that can implement a method of identifying a hijacked browser.
  • the computing device conventionally includes a processor 1010 and a computer program product or computer readable medium in the form of a memory 1020.
  • the memory 1020 may be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), an EPROM, a hard disk, or a ROM.
  • the memory 1020 has a memory space 1030 for executing program code 1031 of any of the above method steps.
  • storage space 1030 for program code may include various program code 1031 for implementing various steps in the above methods, respectively.
  • the program code can be read from or written to one or more computer program products.
  • Such computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks.
  • Such a computer program product is typically a portable or fixed storage unit as described with reference to FIG.
  • the storage unit may have storage segments, storage spaces, and the like that are similarly arranged to memory 1020 in the computing device of FIG.
  • the program code can be compressed, for example, in an appropriate form.
  • the storage unit includes computer readable code 1031', ie, code that can be read by, for example, a processor such as 1010, which when executed by a computing device causes the computing device to perform each of the methods described above step.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

一种识别被劫持浏览器的方法及浏览器,浏览器获取网页访问请求及其对应的操作信息(S101);所述浏览器检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求(S102);所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持(S103);所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持(S104)。所述识别被劫持浏览器的方法及浏览器,解决了现有技术中判断浏览器是否被劫持的方法存在准确性低的技术问题,实现了提高了判断浏览器是否被劫持的准确性的技术效果。

Description

识别被劫持浏览器的方法及浏览器 技术领域
本发明涉及计算机网技术领域,具体涉及一种识别被劫持浏览器的方法及浏览器。
背景技术
随着互联网的迅速发展,浏览器提供了丰富多样的功能,供用户在网上能够快速查找资料及个人所需要的各种信息。但是,现实中浏览器会通过浏览器插件、浏览器辅助对象(Browser Helper Object,简称BHO)、WinsockLSP等形式对浏览器进行篡改,从而使得浏览器被劫持,而在浏览器被劫持时,浏览器的主页及互联网搜索页会变为不知名的网站、访问正常网站时被转向到恶意网页、当输入错误的网址时被转到劫持软件指定的网站和输入字符时浏览器速度严重减慢等。由于这些被劫持的浏览器给用户的日常浏览造成了不良影响,因此网络安全工具一个很重要的工作就是,需要将网络中存在的被劫持的浏览器识别出来。
现有技术中,在判断浏览器被劫持时,通常采用以下方式:其一、用户查看浏览器的主页或其他设置是否已被更改;其二、用户判断是否出现级联弹出窗口,即屏幕上出现看似无穷无尽的连环广告弹出窗口;其三、用户判断是否安装了新的工具栏或收藏夹,并提供指向您不需要的网页的图标和链接;上述判断方式均是用户自行判断浏览器是否被劫持,且用户通常是通过自己的经验来判断浏览器是否被劫持,如此,而用户的经验的多少会直接影响判断的准确性,经验较少的用户必然会出现判断错误的情况,从而导致现有技术中判断浏览器是否被劫持的方法存在准确性较低的问题。
发明内容
本申请实施例通过提供一种识别被劫持浏览器的方法及浏览器,解决了现有技术中判断浏览器是否被劫持的方法存在准确性低的技术问题,实现了提高了判断浏览器是否被劫持的准确性的技术效果。
一方面,本申请通过本申请的一实施例提供如下技术方案:
本申请公开了一种识别被劫持浏览器的方法,包括:
浏览器获取网页访问请求及其对应的操作信息;
所述浏览器检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;
所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
可选的,所述浏览器获取网页访问请求及其对应的操作信息,具体包括:浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;
所述浏览器检测所述操作信息是否符合预设规则,具体包括:所述浏览器判断所述目标域名是否与所述导航页的原始域名相一致;
所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持,具体包括:所述浏览器在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;
所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持,具体包括:所述浏览器在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
可选的,所述浏览器获取网页访问请求及其对应的操作信息,具体包括:获取浏览器的快捷方式的命令行的参数设置信息;
所述浏览器检测所述操作信息是否符合预设规则,具体包括:判断所述参数设置信息对应的设置方式是否与预设方式相一致;
所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持,具体包括:在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;
所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持,具体包括:在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
另一方面,本申请通过本申请的一实施例提供如下技术方案:
本申请公开了一种识别被劫持浏览器的方法,包括:
浏览器获取网页访问请求及其对应的操作信息;
所述浏览器检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
所述浏览器在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
所述浏览器判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
所述浏览器在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出所述浏览器已被劫持;
所述浏览器在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出所述浏览器未被劫持。
第三方面,本申请通过本申请的一实施例提供如下技术方案:
本申请公开了一种浏览器,所述浏览器包括:
访问请求获取单元,用于获取网页访问请求;
操作信息获取单元,用于获取与所述网页访问请求对应的操作信息;
检测单元,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
识别单元,用于在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;以及在检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
可选的,所述浏览器还包括:
所述访问请求获取单元,具体用于获取浏览器的导航页的网页访问请求;
目标域名获取单元,用于获取与所述网页访问请求对应的目标域名;
判断单元,用于判断所述目标域名是否与所述导航页的原始域名相一致;
所述识别单元,具体用于在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
可选的,所述浏览器还包括:
命令行参数获取单元,用于获取浏览器的快捷方式的命令行的参数设置信息;
判断单元,用于判断所述参数设置信息对应的设置方式是否与预设方式相一致;
所述识别单元,具体用于在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;以及在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
第四方面,本申请通过本申请的一实施例提供如下技术方案:
本申请公开了一种浏览器,所述浏览器包括:
访问请求获取单元,用于获取网页访问请求;
操作信息获取单元,用于获取与所述网页访问请求对应的操作信息;
检测单元,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
页面地址获取单元,用于在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
判断单元,用于判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
识别单元,用于在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出所述浏览器已被劫持;以及在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出所述浏览器未被劫持。
依据本发明的又一方面,提供了一种计算机程序,其包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据上文所述的识别被劫持浏览器的方法。
依据本发明的再一方面,提供了一种计算机可读介质,其中存储了上述的计算机程序。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种识别被劫持浏览器的方法及浏览器,通过本发明,浏览器获取网页访问请求及其对应的操作信息,再检测所述操作信息是否符合预设规则,在符合所述预设规则时,识别出所述浏览器已被劫持,否则,则识别所述浏览器未被劫持,由于所述预设规则包括所述浏览器允许的操作请求,通过检测所述操作请求是否符合所述预设规则就能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步地,根据本发明的一种通过域名识别被劫持浏览器的方法,通过本发明,浏览器获取网页访问请求及其对应的目标域名,再判断所述目标域名是否与所述导航页的原始域名相一致,在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持;如此,能通过判断出所述目标域名是否与所述原始域名一致,以此来识别出所述浏览器是否被劫持,其识别的准确性也随之提高,而且是浏览器自行判断自己是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步地,通过本发明,获取浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持;如此,使得可以通过判断所述设置方式是否与所述预设方式相一致来判断出所述设置方式是否已被修改,而在浏览器未被劫持时,所述设置方式与所述预设方式是一致的,而在浏览器被劫持的情况下,所述设置方式可能会与所述预设方式不一致,从而使得通过判断所述设置方式是否与所述预设方式相一致就能够准确识别出所述浏览器是否被劫持,提高了识别的准确性,而且是通过机器判断方式来判断浏览器是否被劫持的,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
上述说明仅是本发明技术方案的概述,为了能够更清楚了解本发明的技术手段,而可依照说明书的内容予以实施,并且为了让本发明的上述和其它目的、特征和优点能够更明显易懂,以下特举本发明的具体实施方式。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本发明的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1为本发明实施例提供的识别被劫持浏览器的方法的第一种流程图;
图2为本发明实施例提供的识别被劫持浏览器的方法的第二种流程图;
图3为本发明实施例提供的浏览器的第一种模块图;
图4为本发明实施例提供的浏览器的第二种模块图;
图5为本发明实施例提供的通过域名识别被劫持浏览器的方法的流程图;
图6为本发明实施例提供的浏览器的模块图;
图7为本发明实施例提供的识别被劫持浏览器的方法的第三种流程图;
图8为本发明实施例提供的识别被劫持浏览器的方法的第四种流程图;
图9为本发明实施例提供的识别被劫持浏览器的设备的模块图;
图10示意性地示出了用于执行根据本发明的识别被劫持浏览器的方法的计算设备的框图;以及
图11示意性地示出了用于保持或者携带实现根据本发明的识别被劫持浏览器的方法的程序代码的存储单元。
具体实施方式
为了更好的理解上述技术方案,下面将结合说明书附图以及具体的实施方式对上述技术方案进行详细的说明。
参见图1,本发明实施例提供的识别被劫持浏览器的方法包括以下步骤:
步骤S101:浏览器获取网页访问请求及其对应的操作信息;
步骤S102:浏览器检测所述操作信息是否符合预设规则,所述预设规则包括浏览器允许的操作请求;
步骤S103:浏览器在检测出所述操作信息不符合所述预设规则时,识别出浏览器已被劫持;
步骤S104:浏览器检测出所述操作信息符合所述预设规则时,识别出浏览器未被劫持。
其中,在步骤S101中,浏览器启动之后,会接收到用户的操作信息,基于所述操作信息,浏览器会自动生成并获取到与所述操作信息对应的网页访问请求,如此,使得浏览器能够获取到所述网页访问请求及其对应的操作信息,其中,所述操作信息例如可以是用户点击浏览器的导航页上的超链接的信息,还可以是在浏览器的搜索栏中输入搜索信息的信息。
具体来讲,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的操作信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a浏览器的搜索栏中输入www.axxx.com的信息。
接下来执行步骤S102,在该步骤中,浏览器检测所述操作信息是否符合预设规则,所述预设规则包括浏览器允许的操作请求。
在具体实施过程中,浏览器通过步骤S101获取到所述操作信息之后,检测所述操作信息是否符合所述预设规则,由于所述预设规则包括浏览器允许的操作请求,如此,通过判断所述操作信息是否符合所述预设规则,即可以判断出所述操作信息是否合法。
具体来讲,浏览器允许的操作请求包括在浏览器的搜索栏中输入搜索信息的第一种操作请求和对浏览器的导航页上的超链接进行点击而生成的第二种操作请求,然后检测所述操作信息是否与所述第一种操作请求和所述第二种操作请求中的一种请求相匹配,在所述操作信息与所述第一种操作请求和所述第二种操作请求均不匹配时,则确定所述操作信息不符合所述预设规则;在所述操作信息与所述第一种操作请求和所述第二种操作请求中的任一种请求相匹配时,则确定所述操作信息符合所述预设规则,当然,所述预设规则还包括在浏览器中加载搜索引擎时,在该搜索引擎中输入信息的第三种操作请求,下面具体以所述预设规则为第一、第二种操作请求为例。
例如,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a浏览器的搜索栏中输入www.axxx.com的搜索信息的请求,由于a浏览器的预设规则为在浏览器的搜索栏中输入搜索信息的第一种操作请求和对浏览器的导航页上的超链接进行点击而生成的第二种操作请求,由于所述操作信息与所述第一种操作请求相匹配,则确定所述操作信息符合所述预设规则。
具体的,所述预设规则还可以是判断所述操作信息与所述网页访问请求相匹配,例如所述操作信息为在浏览器的搜索栏中输入的www.axxx.com的搜索信息,所述网页访问请求为对www.bxxx.com的访问请求,如此,可以判断出所述操作信息与所述网页访问请求不匹配,则确定浏览器被劫持;而在浏览器未被劫持时,所述操作信息与所述网页访问请求是相匹配的。
浏览器在检测出所述操作信息不符合所述预设规则时,执行步骤S103,识别出浏览器已被劫持;浏览器检测出所述操作信息符合所述预设规则时,执行步骤S104,识别出浏览器未被劫持。
在具体实施过程中,浏览器通过步骤S102检测出所述操作信息不符合所述预设规则时,则确认浏览器已被劫持;若检测出所述操作信息符合所述预设规则时,则确认浏览器未被劫持。
例如,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a浏览器的搜索栏中输入www.axxx.com的信息,由于a浏览器的预设规则为在浏览器的搜索栏中输入搜索信息的第一种操作请求和对浏览器的导航页上的超链接进行点击而生成的第二种操作请求,由于所述操作 信息与所述第一种操作请求相匹配,则确定所述操作信息符合所述预设规则,即使得a浏览器可以判断出a浏览器未被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
在另一实施例中,本申请还提供了一种识别被劫持浏览器的方法,参见图2,所述方法包括以下步骤:
步骤S201:浏览器获取网页访问请求及其对应的操作信息;
步骤S202:浏览器检测所述操作信息是否符合预设规则,所述预设规则包括浏览器允许的操作请求;
步骤S203:浏览器在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
步骤S204:浏览器判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持浏览器的网址信息;
步骤S205:浏览器在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出浏览器已被劫持;
步骤S206:浏览器在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出浏览器未被劫持。
其中,在步骤S201中,浏览器启动之后,会接收到用户的操作信息,基于所述操作信息,浏览器会自动生成并获取到与所述操作信息对应的网页访问请求,如此,使得浏览器能够获取到所述网页访问请求及其对应的操作信息,其中,所述操作信息例如可以是用户点击浏览器的导航页上的超链接的信息,还可以是在浏览器的搜索栏中输入搜索信息的信息。
接下来执行步骤S202,在该步骤中,浏览器检测所述操作信息是否符合预设规则,所述预设规则包括浏览器允许的操作请求。
在具体实施过程中,浏览器通过步骤S101获取到所述操作信息之后,检测所述操作信息是否符合所述预设规则,由于所述预设规则包括浏览器允许的操作请求,如此,通过判断所述操作信息是否符合所述预设规则,即可以判断出所述操作信息是否合法。
浏览器在检测出所述操作信息不符合所述预设规则时,执行步骤S203,获取与所述网页访问请求对应的搜索页面的页面地址;
在具体实施过程中,浏览器通过步骤S202检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址,所述搜索页面可以是浏览器的主页,也可以是浏览器的导航页,还可以是浏览器中加载的搜素引擎页,还可以是在浏览器中加载的其它浏览器的导航页,当然通常浏览器的主页和浏览器的导航页可能是同一个页面。
具体来讲,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成的网页访问请求中包含String url="http://www.bxxx.com/",由于所述操作信息表征是输入的www.axxx.com的搜索信息,而所述网页访问请求是访问www.bxxx.com的请求,由于www.bxxx.com与www.axxx.com不同,则确定所述操作信息不符合所述预设规则,由于所述网页搜素请求是在a浏览器的搜索栏中输入了www.axxx.com的搜索信息而生成的,由此,确定所述搜素页面为a浏览器的主页,然后获取a浏览器的主页的页面地址例如为http://hao.axxx.com/。
又例如,以a浏览器为例,在a浏览器启动之后,a浏览器上加载了一个a导航页,其中,a导航页为a浏览器中的预设导航页,a浏览器接收到用户在a导航页中输入了www.cxxx.com的搜索信息,a浏览器基于该操作信息生成访问www.cxxx.com的网页访问请求例如包含有String url="http://www.cxxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a导航页中输入www.axxx.com的信息,若所述a浏览器的预设规则为在a浏览器的搜索栏中输入搜索信息的第一种操作请求和对a浏览器的导航页上的超链接进行点击而生成的第二种操作请求时,由于所述操作信息与所述第一种操作请求和第二种操作请求均不匹配,则确定所述操作信息不符合所述预设规则,然后获取与所述网页访问请求对应的搜索页面为a导航页,然后获取a导航页的页面地址,所述页面地址例如为http://hao.axxx.com/。
接下来执行步骤S204,在该步骤中,浏览器判断所述页面地址是否位于黑名单中,获得 判断结果,其中,所述黑名单中存储有劫持浏览器的网址信息。
在具体实施过程中,在浏览器判断所述页面地址是否位于黑名单中之前,浏览器根据该浏览器被劫持的历史数据,获取并存储所述黑名单,其中,浏览器在获取所述历史数据时,可以通过接收用户的反馈信息来获取所述历史数据,也可以通过数据采集和监控的方式来获取所述历史数据,再通过所述历史数据来获取所述黑名单之后,浏览器还可以不断收集浏览器被劫持的其它数据,以此来不断更新所述黑名单,使得所述黑名单中能够存储更多的劫持浏览器的网址信息,使得通过所述黑名单来判断所述页面地址是否位于所述黑名单而获得所述判断结果能够更准确。
例如,以a浏览器为例,a浏览器收集到a浏览器被劫持的历史数据中显示有A网址、B网址和C网址均劫持过a浏览器,然后建立所述黑名单,使得所述黑名单中存储有A网址、B网址和C网址。
又例如,以a浏览器为例,a浏览器根据当前收集到的历史数据生成了所述黑名单,所述黑名单中存储有A网址、B网址、C网址,在生成所述黑名单之后,a浏览器持续收集a浏览器被劫持的其它数据,在收集到的其它数据中包含有D网址也劫持过a浏览器的数据时,则将D网址添加到所述黑名单中,使得更新后的黑名单中存储有D网址,由于更新后的所述黑名单中存储有D网址,如此,使得所述黑名单中能够存储更多的劫持浏览器的网址信息,通过更新后的所述黑名单就能够判断出所述页面地址是否位于所述黑名单中时,能够使得所述判断结果能够更准确。
具体的,浏览器通过步骤S203获取到所述页面地址之后,判断所述页面地址是否位于所述黑名单中,获取所述判断结果,其中,在所述页面地址位于所述黑名单中时,所述判断结果表征所述页面地址位于所述黑名单中;在所述页面地址未位于所述黑名单中时,所述判断结果表征所述页面地址未位于所述黑名单中。
例如,以a浏览器为例,在a浏览器启动之后,a浏览器上加载了一个b导航页,其中,b导航页并不是a浏览器中的预设导航页,a浏览器接收到用户在b导航页中输入了www.cxxx.com的搜索信息,a浏览器基于该操作信息生成访问www.cxxx.com的网页访问请求例如包含有String url="http://www.cxxx.com/";如此,使得a浏览器能够接收到访问www.cxxx.com的网页访问请求及其对应的操作信息,所述操作信息为在b导航页中输入www.cxxx.com的信息与a浏览器的预设规则中的所述第一种操作请求和所述第二种操作请求均不匹配,则确定所述操作信息不符合所述预设规则,然后从所述网页访问请求中提取所述页面地址,所述页面地址为http://www.axxx.com/,然后判断http://www.axxx.com/是否位于a浏览器中存储的黑名单中,若http://www.axxx.com/位于所述黑名单中,则所述判断结果表征所述页面地址位于所述黑名单中;若http://www.axxx.com/未位于所述黑名单中,则所述判断结果表征所述页面地址未位于所述黑名单中。
浏览器在检测到所述判断结果表征所述页面地址位于所述黑名单中时,执行步骤S205,则识别出浏览器已被劫持;以及浏览器在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,执行步骤S206,则识别出浏览器未被劫持。
在具体实施过程中,通过步骤S204获得的所述判断结果能够准确的确定所述页面地址是否位于所述黑名单,浏览器基于所述判断结果,以识别出浏览器是否被劫持。
具体来讲,以a浏览器为例,在a浏览器启动之后,a浏览器上加载了一个b导航页,其中b导航页并不是a浏览器中的预设导航页,a浏览器接收到用户在b导航页中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在b导航页中输入www.axxx.com的信息与a浏览器的预设规则中的所述第一种操作请求和所述第二种操作请求均不匹配,则确定所述操作信息不符合所述预设规则,然后获取与所述网页访问请求对应的搜索页面为b导航页,然后获取a导航页的页面地址,所述页面地址例如为http://hao.bxxx.com/,然后判断http://www.bxxx.com/是否位于a浏览器中存储的黑名单中,若http://www.bxxx.com/位于所述黑名单中,则所述判断结果表征所述页面地址位于所述黑名单中,如此,可以识别出a浏览器已被劫持;若http://www.bxxx.com/未位于所述黑名单中,则所述判断结果表征所述页面地址未位于所述黑名单中,如此,可以识别出a浏览器未被劫持;如此,在所述操作信息不符 合预设规则时,还需通过所述黑名单进一步判断a浏览器是否被劫持,进一步提高了判断的准确性。
在另一实施例中,在所述网页访问请求为浏览器的导航页的网页访问请求时,所述方法还包括:浏览器判断所述导航页的网页访问请求对应的访问地址是否为所述导航页的导航地址;浏览器判断出所述访问地址不为所述导航地址时,则识别出浏览器已被劫持;浏览器判断出所述访问地址为所述导航地址时,则识别出浏览器未被劫持。
具体来讲,浏览器在检测所述网页访问请求为浏览器的导航页的网页访问请求时,浏览器可以通过检测所述网页访问请求是否是在启动时会加载导航页而获取的,如果是,则确定所述网页访问请求为所述导航页的网页访问请求,然后再根据所述网页访问请求,获取所述访问地址,所述访问地址为所述导航页的网址;当然,浏览器在启动之后,浏览器还可以通过检测所述网页访问请求是否是在收到用户启动所述导航页的启动请求时而获取的,如果是,则确定所述网页访问请求为所述导航页的网页访问请求,浏览器根据所述启动请求来加载所述导航页,进而获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述访问地址。
具体来讲,浏览器检测到所述网页访问请求为浏览器的导航页的网页访问请求时,判断所述导航页的网页访问请求对应的访问地址是否为所述导航页的导航地址,其中,浏览器的导航页的导航地址可以是预先存储在浏览器中,页可以是预先存储在安装该浏览器的用户终端中,本申请不作具体限制。
例如,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.axxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取访问地址为http://hao.axxx.cn/;若a浏览器启动之后并未自动加载a导航页时,接收到用户启动a导航页的启动请求时,a浏览器加载a导航页,生成a导航页的网页访问请求,然后从a导航页的网页访问请求中提取访问地址为http://hao.axxx.cn/,然后判断http://hao.axxx.cn/是否与a浏览器中导航页的导航地址是否相同。
当然,在a浏览器被劫持时,其加载的导航页可能为不是a导航页,而是其他网页例如为商业网页、广告网页等。
又例如,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求,若生成的a导航页的网页访问请求例如包含有String url="http://hao.bxxx.cn/",浏览器则会从a导航页的网页访问请求中提取访问地址为:http://hao.bxxx.cn/,然后判断http://hao.bxxx.cn/是否与a浏览器中导航页的导航地址是否相同,若预先存储的所述导航地址为http://hao.axxx.cn/,由于a导航页的导航地址为http://hao.axxx.cn/与http://hao.bxxx.cn/不同,则a浏览器识别出自身已被劫持。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种识别被劫持浏览器的方法及浏览器,通过本发明,浏览器获取网页访问请求及其对应的操作信息,再检测所述操作信息是否符合预设规则,在符合所述预设规则时,识别出所述浏览器已被劫持,否则,则识别所述浏览器未被劫持,由于所述预设规则包括所述浏览器允许的操作请求,通过检测所述操作请求是否符合所述预设规则就能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步的,在所述操作信息不符合所述预设规则时,浏览器还获取网页访问请求对应的访问地址,再判断所述页面地址是否位于黑名单中,根据获得的判断结果,识别出所述浏览器是否被劫持,由于所述黑名单中存储有劫持所述浏览器的网址信息,使得根据所述判断结果能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
根据同一发明构思,本申请另一实施例提供本申请还公开了一种浏览器,参见图3,所述浏览器包括:
访问请求获取单元301,用于获取网页访问请求;
操作信息获取单元302,用于获取与所述网页访问请求对应的操作信息;
检测单元303,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器 允许的操作请求;
识别单元304,用于在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;以及在检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
具体的,所述浏览器还包括:
判断单元305,还用于在所述网页访问请求为所述浏览器的导航页的网页访问请求时,判断所述导航页的网页访问请求对应的访问地址是否为所述导航页的导航地址;
识别单元304,还用于在判断出所述访问地址不为所述导航地址时,识别出所述浏览器已被劫持;以及判断出所述访问地址为所述导航地址时,识别出所述浏览器未被劫持。
可选的,访问请求获取单元301,还用于在所述网页访问请求为所述浏览器的导航页的网页访问请求时,启动并加载所述导航页时,获取所述导航页的网页访问请求。
在另一实施例中,本申请另一实施例提供本申请还公开了一种浏览器,参见图4,所述浏览器包括:
访问请求获取单元401,用于获取网页访问请求;
操作信息获取单元402,用于获取与所述网页访问请求对应的操作信息;
检测单元403,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
页面地址获取单元404,用于在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
判断单元405,用于判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
识别单元406,用于在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出所述浏览器已被劫持;以及在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出所述浏览器未被劫持。
具体的,所述浏览器还包括:
黑名单获取单元407,用于在所述浏览器判断所述页面地址是否位于黑名单中之前,根据该浏览器被劫持的历史数据,获取并存储所述黑名单。
上述本申请实施例中的技术方案,至少具有如下的技术效果或优点:
根据本发明的一种识别被劫持浏览器的方法及浏览器,通过本发明,浏览器获取网页访问请求及其对应的操作信息,再检测所述操作信息是否符合预设规则,在符合所述预设规则时,识别出所述浏览器已被劫持,否则,则识别所述浏览器未被劫持,由于所述预设规则包括所述浏览器允许的操作请求,通过检测所述操作请求是否符合所述预设规则就能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步的,在所述操作信息不符合所述预设规则时,浏览器还获取网页访问请求对应的访问地址,再判断所述页面地址是否位于黑名单中,根据获得的判断结果,识别出所述浏览器是否被劫持,由于所述黑名单中存储有劫持所述浏览器的网址信息,使得根据所述判断结果能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
参见图5,本发明实施例提供的通过域名识别被劫持浏览器的方法包括以下步骤:
S501:浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;
S502:浏览器判断所述目标域名是否与所述导航页的原始域名相一致;
S503:浏览器在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;
S504:浏览器在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
其中,在步骤S501中,浏览器在启动时会自动加载导航页,使得浏览器能够获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名;当然,浏览器在启动之后,浏览器接收到用户启动所述导航页的启动请求,浏览器根据所述启动请求来加载所述导 航页,进而获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名。
在具体实施过程中,浏览器在获取所述目标域名时,可以直接从所述网页访问请求中提取所述目标域名,所述网页访问请求具体可以为http格式的访问请求。
具体来讲,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.axxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取目标域名为hao.axxx.cn;若a浏览器启动之后,接收到用户启动a导航页的启动请求时,a浏览器加载a导航页,生成a导航页的网页访问请求,然后从a导航页的网页访问请求中提取目标域名为hao.axxx.cn。
当然,在a浏览器被劫持时,其加载的导航页可能为不是a导航页,而是其他浏览器的导航页,比如b导航页网页例如为商业网页、广告网页等,使得获取的所述目标域名与a导航页的原始域名不同;而a浏览器未被劫持时,使得获取的所述目标域名与a导航页的原始域名相同。
接下来执行步骤S502,在该步骤中,浏览器判断所述目标域名是否与所述导航页的原始域名相一致。
在具体实施过程中,浏览器判断所述目标域名是否与所述导航页的原始域名相一致之前,浏览器中存储所述导航页的原始域名,如此,在获取所述目标域名之后,浏览器能够将所述目标域名与所述原始域名进行比对,从而判断出所述目标域名是否与所述原始域名相一致,当然,所述原始域名还可以存储在安装该浏览器的用户终端中。
具体来讲,浏览器获取到所述目标域名之后,判断所述目标域名与所述原始域名是否相同,若相同,则判断出所述目标域名与所述原始域名相一致;若不相同,则判断出所述目标域名与所述原始域名不一致。
具体的,在预先存储所述原始域名时,可以直接在浏览器第一次启动并加载所述导航页时,获取所述导航页的网址,然后从所述导航页的网址中提取所述导航页的原始域名,然后将所述原始域名存储在浏览器中;也可以在浏览器未被劫持之前,加载所述导航页时会自动生成所述导航页的网页访问请求,浏览器从所述网页访问请求中提取所述导航页的原始域名,然后在浏览器中存储所述原始域名。
例如,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.bxxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取目标域名为hao.bxxx.cn,若a浏览器中预先存储有a导航页的原始域名为hao.axxx.cn,由于hao.bxxx.cn与hao.axxx.cn不同,即a浏览器判断所述目标域名与所述原始域名不一致;若a浏览器中预先存储有a导航页的原始域名为hao.bxxx.cn,由于所述原始域名与所述目标域名相同,即a浏览器判断所述目标域名与所述原始域名一致。
浏览器在判断出所述目标域名与所述原始域名一致时,执行步骤S503,识别出所述浏览器未被劫持;浏览器在判断出所述目标域名与所述原始域名不一致时,执行步骤S504,识别出所述浏览器已被劫持。
在具体实施过程中,浏览器根据所述步骤S502,在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
具体来讲,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.bxxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取目标域名为hao.bxxx.cn,若a浏览器中预先存储有a导航页的原始域名为hao.axxx.cn,由于hao.bxxx.cn与hao.axxx.cn不同,即a浏览器判断所述目标域名与所述原始域名不一致,则使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名不一致,从而识别出a浏览器已被劫持;若a浏览器中预先存储有a导航页的原始域名为hao.bxxx.cn,由于所述原始域名与所述目标域名相同,即a浏览器判断所述目标域名与所述原始域名一致,使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名一致,从而识别出a浏览器未被劫持;如此,通过判断所述目标域名与所述原始域名是否一致就能够准确判断出a浏览器是否被劫持,提高判断的准确性,而且是通过a浏览器本身来判断自己是否被劫持,属于机器判断,与人工判断相比,其工作效率得到了较大的提高。
在另一实施例中,在所述识别出浏览器已被劫持时,所述方法还包括:浏览器生成提示信息,并在浏览器加载的页面上生成提示窗口;浏览器将所述提示信息加载在所述提示窗口中进行显示。
在具体实施过程中,浏览器识别出自身被劫持时,浏览器可以生成所述提示信息,所述提示信息具体可以是“浏览器已被劫持”、“浏览器存在安全风险”等文本信息,然后在浏览器加载的页面上生成所述提示窗口,并将所述提示信息加载到所述提示窗口中进行显示,以提醒用户。
具体来讲,所述提示信息还可以包括语音信息,在将所述提示信息加载在所述提示窗口中进行显示时,还可以将所述提示信息进行语音输出。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种通过域名识别被劫持浏览器的方法,通过本发明,浏览器获取网页访问请求及其对应的目标域名,再判断所述目标域名是否与所述导航页的原始域名相一致,在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持;如此,能通过判断出所述目标域名是否与所述原始域名一致,以此来识别出所述浏览器是否被劫持,其识别的准确性也随之提高,而且是浏览器自行判断自己是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
根据同一发明构思,本申请另一实施例提供本申请还公开了一种浏览器,参见图6,所述浏览器包括:
访问请求获取单元601,用于获取浏览器的导航页的网页访问请求;
目标域名获取单元602,用于获取与所述网页访问请求对应的目标域名;
判断单元603,用于判断所述目标域名是否与所述导航页的原始域名相一致;
识别单元604,用于在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
具体的,访问请求获取单元601,具体用于在启动并加载所述导航页时,获取所述导航页的网页访问请求;目标域名获取单元602,具体用于根据所述网页访问请求,获取所述目标域名,具体可以从所述网页访问请求中提取所述目标域名。
其中,浏览器在启动时会自动加载导航页,访问请求获取单元601能够获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名;当然,浏览器在启动之后,访问请求获取单元601接收到用户启动所述导航页的启动请求时,根据所述启动请也能够获取到所述导航页的网页访问请求。
具体的,所述浏览器还包括:
域名存储单元605,用于在判断所述目标域名是否与所述导航页的原始域名相一致之前,存储所述导航页的原始域名。
其中,在判断单元603判断所述目标域名是否与所述导航页的原始域名相一致之前,域名存储单元605将所述导航页的原始域名存储在浏览器中,如此,在获取所述目标域名之后,判断单元603能够将所述目标域名与所述原始域名进行比对,从而判断出所述目标域名是否与所述原始域名相一致,当然,域名存储单元605还可以将所述原始域名存储在安装该浏览器的用户终端中。
进一步的,目标域名获取单元602获取到所述目标域名之后,判断单元603判断所述目标域名与所述原始域名是否相同,若相同,则判断出所述目标域名与所述原始域名相一致;若不相同,则判断出所述目标域名与所述原始域名不一致。
具体的,所述浏览器还包括提示信息和窗口生成单元606,用于在所述识别出所述浏览器已被劫持时,生成提示信息,并在所述浏览器加载的页面上生成提示窗口;加载单元607,用于将所述提示信息加载在所述提示窗口中进行显示。
上述本申请实施例中的技术方案,至少具有如下的技术效果或优点:
根据本发明的一种通过域名识别被劫持浏览器的方法,通过本发明,浏览器获取网页访问请求及其对应的目标域名,再判断所述目标域名是否与所述导航页的原始域名相一致,在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目 标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持;如此,能通过判断出所述目标域名是否与所述原始域名一致,以此来识别出所述浏览器是否被劫持,其识别的准确性也随之提高,而且是浏览器自行判断自己是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
参见图7,本发明实施例还提供了一种识别被劫持浏览器的方法,包括以下步骤:
S701:获取浏览器的快捷方式的命令行的参数设置信息;
S702:判断所述参数设置信息对应的设置方式是否与预设方式相一致;
S703:在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;
S704:在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
其中,在步骤S701中,本发明的执行主体是设备,所述设备例如可以是平板电脑、笔记本电脑、智能手机、台式电脑等设备,所述设备中安装有浏览器,在获取浏览器的快捷方式的命令行的参数设置信息时,可以通过启动安装在所述设备中的命令行程序,例如在windows环境下,命令行程序通常为cmd.exe,然后所述设备在接收到用户输入的与浏览器的快速方式对应的命令信息时,将所述参数设置信息显示在所述命令行程序中,如此,根据所述显示内容,即可获取所述参数设置信息,其中,所述参数设置信息中包含有所述快捷方式的设置方式信息。当然,还可以通过查看所述浏览器的快捷方式的属性信息来获取所述参数设置信息。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息。
接下来执行步骤S702,在该步骤中,判断所述参数设置信息对应的设置方式是否与预设方式相一致。
在具体实施过程中,所述预设方式为所述浏览器的快捷方式的默认的设置方式,具体可以是手动设置方式或自动设置方式,下面具体以所述预设方式为手动设置方式为例,在通过步骤S701获取到所述参数设置信息之后,从所述参数设置信息中获取所述快捷方式的设置方式信息,基于所述快捷方式的设置方式信息确定所述设置方式,然后判断所述设置方式是否为手动设置方式,在所述设置方式为手动设置方式时,则确定所述设置方式与所述预设方式相一致;若所述设置方式不为手动设置方式时,则确定所述设置方式与所述预设方式不一致,其中,所述预设方式为自动设置方式时其判断方法与上述判断方法相同。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若所述参数设置信息中包含的所述快捷方式的设置方式信息显示b浏览器的快捷方式对应的设置方式为手动设置方式时,由于手动设置方式与所述预设方式相同,则确定所述设置方式与所述预设方式相一致;若b浏览器的快捷方式对应的设置方式为自动设置方式时,由于自动设置方式与所述预设方式不同,则确定所述设置方式与所述预设方式不一致。
在判断出所述设置方式与所述预设方式不一致时,执行步骤S703,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,执行步骤S704,识别出所述浏览器未被劫持。
在具体实施过程中,所述设备在通过步骤S702判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持,以及在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若所述参数设置信息中包含的所述快捷方式的设置方式信息显示b浏览器的快捷方式对应的设置方式为手动设置方式时,由于手动设置方式与所述预设方式相同,则确定所述设置方式 与所述预设方式相一致,如此,可以确定b浏览器未被劫持;若b浏览器的快捷方式对应的设置方式为自动设置方式时,由于自动设置方式与所述预设方式不同,则确定所述设置方式与所述预设方式不一致,如此,可以确定b浏览器已被劫持。
其中,在b浏览器未被劫持时,b浏览器的快捷方式对应的设置方式必然为所述预设方式,而在b浏览器被劫持时,b浏览器的快捷方式对应的设置方式才会与所述预设方式不同,如此,通过判断b浏览器的快捷方式对应的设置方式是否与所述预设方式相一致,即可以准确的判断出b浏览器是否被劫持,使得判断的准确性得以提高。
在另一实施例中,本发明实施例还提供了一种识别被劫持浏览器的方法,参见图8,包括以下步骤:
S801:获取浏览器的快捷方式的命令行的参数设置信息;
S802:判断所述参数设置信息对应的设置方式是否与预设方式相一致;
S803:在判断出所述设置方式与所述预设方式一致时,判断所述参数设置信息对应目的链接是否位于预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
S804:在判断出所述目的链接位于所述黑名单中时,则识别出所述浏览器已被劫持;
S805:在判断出所述目的链接未位于所述黑名单中时,则识别出所述浏览器未被劫持。
其中,在步骤S801中,本发明的执行主体是设备,所述设备例如可以是平板电脑、笔记本电脑、智能手机、台式电脑等设备,所述设备中安装有浏览器,在获取浏览器的快捷方式的命令行的参数设置信息时,可以通过启动安装在所述设备中的命令行程序,例如在windows环境下,命令行程序通常为cmd.exe,然后所述设备在接收到用户输入的与浏览器的快速方式对应的命令信息时,将所述参数设置信息显示在所述命令行程序中,如此,根据所述显示内容,即可获取所述参数设置信息,其中,所述参数设置信息中包含有所述快捷方式的设置方式信息。当然,还可以通过查看所述浏览器的快捷方式的属性信息来获取所述参数设置信息。
接下来执行步骤S802,在该步骤中,判断所述参数设置信息对应的设置方式是否与预设方式相一致。
在具体实施过程中,所述预设方式为所述浏览器的快捷方式的默认的设置方式,具体可以是手动设置方式或自动设置方式,下面具体以所述预设方式为手动设置方式为例,在通过步骤S801获取到所述参数设置信息之后,从所述参数设置信息中获取所述快捷方式的设置方式信息,基于所述快捷方式的设置方式信息确定所述设置方式,然后判断所述设置方式是否为手动设置方式,在所述设置方式为手动设置方式时,则确定所述设置方式与所述预设方式相一致;若所述设置方式不为手动设置方式时,则确定所述设置方式与所述预设方式不一致,其中,所述预设方式为自动设置方式时其判断方法与上述判断方法相同。
在判断出所述设置方式与所述预设方式一致时,执行步骤S803,判断所述参数设置信息对应目的链接是否位于预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息。
在具体实施过程中,在所述预设方式为手动设置方式时,若所述设置方式也为手动设置方式,则判断出所述设置方式与所述预设方式一致,此时,再判断所述目的链接是否位于所述黑名单中,即将所述目的链接与所述黑名单中的每一个网址信息进行比对,若所述黑名单中存在与所述目的链接相匹配的网址信息,则确定所述目的链接位于所述黑名单中;若所述黑名单中不存在与所述目的链接相匹配的网址信息,则确定所述目的链接不位于所述黑名单中,其中,所述目的链接可以从所述参数设置信息中提取,例如b浏览器的参数设置信息中包括b浏览器的快捷方式的设置方式信息、加载的目的链接的网址等信息,如此,根据b浏览器的参数设置信息即可以获取所述目标链接。
具体来讲,在将所述参数设置信息对应的目的链接添加到预存的黑名单之前,所述方法还包括:根据所述浏览器被劫持的历史数据,获取并存储所述黑名单,其中,所述设备在获取所述历史数据时,可以通过接收用户的反馈信息来获取所述历史数据,也可以通过数据采集和监控的方式来获取所述历史数据,再通过所述历史数据来获取所述黑名单之后,所述设备还可以不断收集浏览器被劫持的其它数据,以此来不断更新所述黑名单,使得所述黑名单中能够存储更多的劫持浏览器的网址信息,以提高判断的准确性。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器,笔记本电脑A收集到b浏览器被劫持的历史数据中显示有A网址、B网址和C网址均劫持过a浏览器,然后建立所 述黑名单,使得所述黑名单中存储有A网址、B网址和C网址。
又例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器,笔记本电脑A根据当前收集到的历史数据生成了所述黑名单,所述黑名单中存储有A网址、B网址、C网址,在生成所述黑名单之后,笔记本电脑A持续收集b浏览器被劫持的其它数据,在收集到的其它数据中包含有D网址也劫持过b浏览器的数据时,则将D网址添加到所述黑名单中,使得更新后的黑名单中存储有D网址,由于更新后的所述黑名单中存储有D网址,如此,使得所述黑名单中能够存储更多的劫持浏览器的网址信息,通过更新后的所述黑名单就能够判断出所述访问地址是否位于所述黑名单中时,使得判断的准确性得以提高。
具体的,所述设备还可以在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持时,将所述参数设置信息对应的目的链接添加到预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若根据所述参数设置信息,获取到的b浏览器的快捷方式对应的设置方式为自动设置方式时,由于自动设置方式与所述预设方式不同,则确定所述设置方式与所述预设方式不一致,如此,可以确定b浏览器已被劫持,这时,可以从所述参数设置信息中提取所述目的链接例如为E网址,则将E网址则添加到所述黑名单中,如此,使得所述黑名单中能够存储更多的劫持浏览器的网址信息。
在判断出所述目的链接位于所述黑名单中时,执行步骤S804,识别出所述浏览器已被劫持;在判断出所述目的链接未位于所述黑名单中时,执行步骤S805,识别出所述浏览器未被劫持。
在具体实施过程中,所述设备在通过步骤S803判断出所述目的链接位于所述黑名单中时,则确认所述浏览器已被劫持;以及判断出所述目的链接未位于所述黑名单中时,则确认所述浏览器未被劫持。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若根据所述参数设置信息,获取到的b浏览器的快捷方式对应的设置方式为手动设置方式时,由于手动设置方式与所述预设方式不同,则确定所述设置方式与所述预设方式一致,如此,可以确定b浏览器未被劫持,这时,可以从所述参数设置信息中提取所述目的链接例如为A网址,若所述黑名单中存储有A网址、B网址和C网址,可知所述目的链接位于所述黑名单中,则确认b浏览器已被劫持;若所述目的链接例如为D网址,而所述黑名单中未存储有D网址,则可以确定b浏览器未被劫持;如此,再判断出所述设置方式与所述预设方式一致时,通过所述目的链接是否位于所述黑名单来进一步判断b浏览器是否被劫持,以进一步提高判断所述浏览器是否被劫持的准确性。
在另一实施例中,在所述识别出浏览器已被劫持时,所述方法还包括:生成提示信息,并在浏览器加载的页面上生成提示窗口;将所述提示信息加载在所述提示窗口中进行显示。
在具体实施过程中,所述设备识别出浏览器被劫持时,自动生成所述提示信息,所述提示信息具体可以是“浏览器已被劫持”、“浏览器存在安全风险”等文本信息,并在所述浏览器加载的页面上生成所述提示窗口,将所述提示信息加载到所述提示窗口中进行显示,以提醒用户。
具体来讲,所述提示信息还可以包括语音信息,在将所述提示信息加载在所述提示窗口中进行显示时,还可以将所述提示信息进行语音输出。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种识别被劫持浏览器的方法及设备,通过本发明,获取浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设 置方式与所述预设方式一致时,识别出所述浏览器未被劫持;如此,使得可以通过判断所述设置方式是否与所述预设方式相一致来判断出所述设置方式是否已被修改,而在浏览器未被劫持时,所述设置方式与所述预设方式是一致的,而在浏览器被劫持的情况下,所述设置方式可能会与所述预设方式不一致,从而使得通过判断所述设置方式是否与所述预设方式相一致就能够准确识别出所述浏览器是否被劫持,提高了识别的准确性,而且是通过机器判断方式来判断浏览器是否被劫持的,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步的,通过本发明,在判断出所述设置方式与所述预设方式一致时,还可以判断所述参数设置信息对应的目的链接是否位于预存的黑名单中,以此来判断所述浏览器是否被劫持,由于所述黑名单中存储有劫持所述浏览器的网址信息,使得根据所述判断结果能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以进一步提高。
根据同一发明构思,本申请另一实施例提供本申请还公开了一种识别被劫持浏览器的设备,参见图9,所述设备包括:
命令行参数获取单元901,用于获取浏览器的快捷方式的命令行的参数设置信息;
判断单元902,用于判断所述参数设置信息对应的设置方式是否与预设方式相一致;
识别单元903,用于在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;以及在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
其中,所述预设方式为所述浏览器的快捷方式的默认的设置方式,具体可以是手动设置方式或自动设置方式
具体的,判断单元902,具体用于在所述预设方式为手动设置方式时,判断所述设置方式是否为手动设置方式。
具体的,所述设备还包括添加单元904,用于在所述识别出所述浏览器被劫持之后,将所述参数设置信息对应的目的链接添加到预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息。
具体的,判断单元902,还用于在判断出在所述设置方式为手动设置方式时,判断所述参数设置信息对应目的链接是否位于预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
识别单元903,还用于在判断出所述目的链接位于所述黑名单中时,识别出所述浏览器已被劫持;在判断出所述目的链接未位于所述黑名单中时,则识别出所述浏览器未被劫持。
具体的,所述设备还包括黑名单存储单元905,用于在将所述参数设置信息对应的目的链接添加到预存的黑名单之前,根据所述浏览器被劫持的历史数据,获取并存储所述黑名单。
具体的,所述设备还包括:
提示信息和窗口生成单元906,用于在所述识别出所述浏览器已被劫持时,生成提示信息,并在所述浏览器加载的页面上生成提示窗口;
加载单元907,用于将所述提示信息加载在所述提示窗口中进行显示。
上述本申请实施例中的技术方案,至少具有如下的技术效果或优点:
根据本发明的一种识别被劫持浏览器的方法及设备,通过本发明,获取浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持;如此,使得可以通过判断所述设置方式是否与所述预设方式相一致来判断出所述设置方式是否已被修改,而在浏览器未被劫持时,所述设置方式与所述预设方式是一致的,而在浏览器被劫持的情况下,所述设置方式可能会与所述预设方式不一致,从而使得通过判断所述设置方式是否与所述预设方式相一致就能够准确识别出所述浏览器是否被劫持,提高了识别的准确性,而且是通过机器判断方式来判断浏览器是否被劫持的,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
进一步的,通过本发明,在判断出所述设置方式与所述预设方式一致时,还可以判断所述参数设置信息对应的目的链接是否位于预存的黑名单中,以此来判断所述浏览器是否被劫持,由于所述黑名单中存储有劫持所述浏览器的网址信息,使得根据所述判断结果能够更准确的识别出所述浏览器是否被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以进一步提高。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以 在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此所述的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的浏览器、设备中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图10示出了可以实现识别被劫持浏览器的方法的计算设备。该计算设备传统上包括处理器1010和以存储器1020形式的计算机程序产品或者计算机可读介质。存储器1020可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM、硬盘或者ROM之类的电子存储器。存储器1020具有用于执行上述方法中的任何方法步骤的程序代码1031的存储空间1030。例如,用于程序代码的存储空间1030可以包括分别用于实现上面的方法中的各种步骤的各个程序代码1031。这些程序代码可以从一个或者多个计算机程序产品中读出或者写入到这一个或者多个计算机程序产品中。这些计算机程序产品包括诸如硬盘,紧致盘(CD)、存储卡或者软盘之类的程序代码载体。这样的计算机程序产品通常为如参考图11所述的便携式或者固定存储单元。该存储单元可以具有与图10的计算设备中的存储器1020类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元包括计算机可读代码1031’,即可以由例如诸如1010之类的处理器读取的代码,这些代码当由计算设备运行时,导致该计算设备执行上面所描述的方法中的各个步骤。
本文中所称的“一个实施例”、“实施例”或者“一个或者多个实施例”意味着,结合实施例描述的特定特征、结构或者特性包括在本发明的至少一个实施例中。此外,请注意,这里“在一个实施例中”的词语例子不一定全指同一个实施例。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
此外,还应当注意,本说明书中使用的语言主要是为了可读性和教导的目的而选择的,而不是为了解释或者限定本发明的主题而选择的。因此,在不偏离所附权利要求书的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。对于本发明的范围,对本发明所做的公开是说明性的,而非限制性的,本发明的范围由所附权利要求书限定。

Claims (32)

  1. 一种识别被劫持浏览器的方法,包括:
    浏览器获取网页访问请求及其对应的操作信息;
    所述浏览器检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
    所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;
    所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
  2. 如权利要求1所述的方法,其中,在所述网页访问请求为所述浏览器的导航页的网页访问请求时,所述方法还包括:
    所述浏览器判断所述导航页的网页访问请求对应的访问地址是否为所述导航页的导航地址;
    所述浏览器判断出所述访问地址不为所述导航地址时,则识别出所述浏览器已被劫持;
    所述浏览器判断出所述访问地址为所述导航地址时,则识别出所述浏览器未被劫持。
  3. 如权利要求2所述的方法,其中,在所述网页访问请求为所述浏览器的导航页的网页访问请求时,所述浏览器获取导航页的网页访问请求,具体包括:
    所述浏览器启动并加载所述导航页时,获取所述导航页的网页访问请求。
  4. 如权利要求1所述的方法,其中,
    所述浏览器获取网页访问请求及其对应的操作信息,具体包括:浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;
    所述浏览器检测所述操作信息是否符合预设规则,具体包括:所述浏览器判断所述目标域名是否与所述导航页的原始域名相一致;
    所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持,具体包括:所述浏览器在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;
    所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持,具体包括:所述浏览器在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
  5. 如权利要求4所述的方法,其特征在于,所述浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的访问地址,具体包括:
    所述浏览器启动并加载所述导航页时,获取所述导航页的网页访问请求;
    所述浏览器根据所述网页访问请求,获取所述目标域名。
  6. 如权利要求4或5所述的方法,其特征在于,所述浏览器判断所述目标域名是否与所述导航页的原始域名相一致之前,所述方法还包括:
    所述浏览器中预先存储所述导航页的原始域名。
  7. 如权利要求4或5所述的方法,其特征在于,在所述识别出所述浏览器已被劫持时,所述方法还包括:
    所述浏览器生成提示信息,并在所述浏览器加载的页面上生成提示窗口;
    所述浏览器将所述提示信息加载在所述提示窗口中进行显示。
  8. 如权利要求1所述的方法,其中,
    所述浏览器获取网页访问请求及其对应的操作信息,具体包括:获取浏览器的快捷方式的命令行的参数设置信息;
    所述浏览器检测所述操作信息是否符合预设规则,具体包括:判断所述参数设置信息对应的设置方式是否与预设方式相一致;
    所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持,具体包括:在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;
    所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持,具体包括:在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
  9. 如权利要求8所述的方法,其中,在所述预设方式为手动设置方式时,所述判断所述参数设置信息是否与预设方式相一致,具体包括:
    判断所述设置方式是否为手动设置方式。
  10. 如权利要求9所述的方法,其中,所述识别出所述浏览器被劫持之后,所述方法还包括:
    将所述参数设置信息对应的目的链接添加到预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息。
  11. 如权利要求9所述的方法,其中,所述在判断出所述设置方式与所述预设方式一致时,所述方法还包括:
    在所述设置方式为手动设置方式时,判断与所述参数设置信息对应的目的链接是否位于预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
    在判断出所述目的链接位于所述黑名单中时,则识别出所述浏览器已被劫持;
    在判断出所述目的链接未位于所述黑名单中时,则识别出所述浏览器未被劫持。
  12. 如权利要求11所述的方法,其中,在将所述参数设置信息对应的目的链接添加到预存的黑名单之前,所述方法还包括:
    根据所述浏览器被劫持的历史数据,获取并存储所述黑名单。
  13. 如权利要求8或11所述的方法,其中,在所述识别出所述浏览器已被劫持时,所述方法还包括:
    生成提示信息,并在所述浏览器加载的页面上生成提示窗口;
    将所述提示信息加载在所述提示窗口中进行显示。
  14. 一种识别被劫持浏览器的方法,包括:
    浏览器获取网页访问请求及其对应的操作信息;
    所述浏览器检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
    所述浏览器在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
    所述浏览器判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
    所述浏览器在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出所述浏览器已被劫持;
    所述浏览器在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出所述浏览器未被劫持。
  15. 如权利要求14所述的方法,其中,在所述浏览器判断所述页面地址是否位于黑名单中之前,所述方法还包括:
    所述浏览器根据该浏览器被劫持的历史数据,获取并存储所述黑名单。
  16. 一种浏览器,包括:
    访问请求获取单元,用于获取网页访问请求;
    操作信息获取单元,用于获取与所述网页访问请求对应的操作信息;
    检测单元,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
    识别单元,用于在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;以及在检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
  17. 如权利要求16所述的浏览器,其中,所述浏览器还包括:
    判断单元,还用于在所述网页访问请求为所述浏览器的导航页的网页访问请求时,判断所述导航页的网页访问请求对应的访问地址是否为所述导航页的导航地址;
    所述识别单元,还用于在判断出所述访问地址不为所述导航地址时,识别出所述浏览器已被劫持;以及判断出所述访问地址为所述导航地址时,识别出所述浏览器未被劫持。
  18. 如权利要求17所述的浏览器,其中,所述访问请求获取单元,还用于在所述网页访问请求为所述浏览器的导航页的网页访问请求时,启动并加载所述导航页时,获取所述导航页的网页访问请求。
  19. 如权利要求16所述的浏览器,其中,所述浏览器还包括:
    所述访问请求获取单元,具体用于获取浏览器的导航页的网页访问请求;
    目标域名获取单元,用于获取与所述网页访问请求对应的目标域名;
    判断单元,用于判断所述目标域名是否与所述导航页的原始域名相一致;
    所述识别单元,具体用于在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;以及在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
  20. 如权利要求19所述的浏览器,其中,所述访问请求获取单元,具体用于在启动并加载所述导航页时,获取所述导航页的网页访问请求;
    所述目标域名获取单元,具体用于根据所述网页访问请求,获取所述目标域名。
  21. 如权利要求19或20所述的浏览器,其中,所述浏览器还包括:
    域名存储单元,用于在判断所述目标域名是否与所述导航页的原始域名相一致之前,存储所述导航页的原始域名。
  22. 如权利要求19或20所述的浏览器,其中,所述浏览器还包括:
    提示信息和窗口生成单元,用于在所述识别出所述浏览器已被劫持时,生成提示信息,并在所述浏览器加载的页面上生成提示窗口;
    加载单元,用于将所述提示信息加载在所述提示窗口中进行显示。
  23. 如权利要求16所述的浏览器,其中,所述浏览器还包括:
    命令行参数获取单元,用于获取浏览器的快捷方式的命令行的参数设置信息;
    判断单元,用于判断所述参数设置信息对应的设置方式是否与预设方式相一致;
    所述识别单元,具体用于在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;以及在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
  24. 如权利要求23所述的浏览器,其中,所述判断单元,具体用于在所述预设方式为手动设置方式时,判断所述设置方式是否为手动设置方式。
  25. 如权利要求24所述的浏览器,其中,所述浏览器还包括:
    添加单元,用于在所述识别出所述浏览器被劫持之后,将所述参数设置信息对应的目的链接添加到预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息。
  26. 如权利要求24所述的浏览器,其中,所述判断单元,还用于在判断出在所述设置方式为手动设置方式时,判断所述参数设置信息对应目的链接是否位于预存的黑名单中,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
    所述识别单元,还用于在判断出所述目的链接位于所述黑名单中时,识别出所述浏览器已被劫持;在判断出所述目的链接未位于所述黑名单中时,则识别出所述浏览器未被劫持。
  27. 如权利要求26所述的浏览器,其中,所述浏览器还包括:
    黑名单存储单元,用于在将所述参数设置信息对应的目的链接添加到预存的黑名单之前,根据所述浏览器被劫持的历史数据,获取并存储所述黑名单。
  28. 如权利要求23或26所述的浏览器,其中,所述浏览器还包括:
    提示信息和窗口生成单元,用于在所述识别出所述浏览器已被劫持时,生成提示信息,并在所述浏览器加载的页面上生成提示窗口;
    加载单元,用于将所述提示信息加载在所述提示窗口中进行显示。
  29. 一种浏览器,包括:
    访问请求获取单元,用于获取网页访问请求;
    操作信息获取单元,用于获取与所述网页访问请求对应的操作信息;
    检测单元,用于检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;
    页面地址获取单元,用于在检测出所述操作信息不符合所述预设规则时,获取与所述网页访问请求对应的搜索页面的页面地址;
    判断单元,用于判断所述页面地址是否位于黑名单中,获得判断结果,其中,所述黑名单中存储有劫持所述浏览器的网址信息;
    识别单元,用于在检测到所述判断结果表征所述页面地址位于所述黑名单中时,则识别出所述浏览器已被劫持;以及在检测到所述判断结果表征所述页面地址未位于所述黑名单中时,则识别出所述浏览器未被劫持。
  30. 如权利要求29所述的浏览器,其中,所述浏览器还包括:
    黑名单获取单元,用于在所述浏览器判断所述页面地址是否位于黑名单中之前,根据该浏 览器被劫持的历史数据,获取并存储所述黑名单。
  31. 一种计算机程序,包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据权利要求1至15任一项所述的识别被劫持浏览器的方法。
  32. 一种计算机可读介质,其中存储了如权利要求31所述的计算机程序。
PCT/CN2016/100426 2015-09-30 2016-09-27 识别被劫持浏览器的方法及浏览器 Ceased WO2017054716A1 (zh)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
CN201510639835.6A CN105357265A (zh) 2015-09-30 2015-09-30 一种识别浏览器被劫持的方法
CN201510639832.2 2015-09-30
CN201510640171.5 2015-09-30
CN201510639835.6 2015-09-30
CN201510639832.2A CN105160246A (zh) 2015-09-30 2015-09-30 一种识别被劫持浏览器的方法及浏览器
CN201510640171.5A CN105160247B (zh) 2015-09-30 2015-09-30 一种识别浏览器被劫持的方法

Publications (1)

Publication Number Publication Date
WO2017054716A1 true WO2017054716A1 (zh) 2017-04-06

Family

ID=58422675

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/100426 Ceased WO2017054716A1 (zh) 2015-09-30 2016-09-27 识别被劫持浏览器的方法及浏览器

Country Status (1)

Country Link
WO (1) WO2017054716A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109543407A (zh) * 2018-10-19 2019-03-29 北京奇虎科技有限公司 一种Activity劫持的拦截方法及装置
CN110334301A (zh) * 2018-03-21 2019-10-15 深圳市腾讯计算机系统有限公司 一种页面还原方法及装置
CN113542185A (zh) * 2020-04-13 2021-10-22 北京沃东天骏信息技术有限公司 页面防劫持的方法、装置、电子设备和存储介质
CN114697397A (zh) * 2022-02-24 2022-07-01 阿里巴巴(中国)有限公司 一种域名访问方法、装置、电子设备及计算机存储介质

Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7712132B1 (en) * 2005-10-06 2010-05-04 Ogilvie John W Detecting surreptitious spyware
CN102375951A (zh) * 2011-10-18 2012-03-14 北龙中网(北京)科技有限责任公司 网页安全检测方法和系统
CN102780684A (zh) * 2011-05-12 2012-11-14 同济大学 Xss防御系统
CN104486140A (zh) * 2014-11-28 2015-04-01 华北电力大学 一种检测网页被劫持的装置及其检测方法
CN104601543A (zh) * 2014-12-05 2015-05-06 百度在线网络技术(北京)有限公司 鉴别软件篡改浏览器主页的方法和系统
CN105160246A (zh) * 2015-09-30 2015-12-16 北京奇虎科技有限公司 一种识别被劫持浏览器的方法及浏览器
CN105160247A (zh) * 2015-09-30 2015-12-16 北京奇虎科技有限公司 一种识别浏览器被劫持的方法
CN105205393A (zh) * 2015-09-30 2015-12-30 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备
CN105224653A (zh) * 2015-09-30 2016-01-06 北京奇虎科技有限公司 一种浏览器被劫持时的处理方法及处理设备
CN105243134A (zh) * 2015-09-30 2016-01-13 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备
CN105357265A (zh) * 2015-09-30 2016-02-24 北京奇虎科技有限公司 一种识别浏览器被劫持的方法
CN105354490A (zh) * 2015-09-30 2016-02-24 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备

Patent Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7712132B1 (en) * 2005-10-06 2010-05-04 Ogilvie John W Detecting surreptitious spyware
CN102780684A (zh) * 2011-05-12 2012-11-14 同济大学 Xss防御系统
CN102375951A (zh) * 2011-10-18 2012-03-14 北龙中网(北京)科技有限责任公司 网页安全检测方法和系统
CN104486140A (zh) * 2014-11-28 2015-04-01 华北电力大学 一种检测网页被劫持的装置及其检测方法
CN104601543A (zh) * 2014-12-05 2015-05-06 百度在线网络技术(北京)有限公司 鉴别软件篡改浏览器主页的方法和系统
CN105160246A (zh) * 2015-09-30 2015-12-16 北京奇虎科技有限公司 一种识别被劫持浏览器的方法及浏览器
CN105160247A (zh) * 2015-09-30 2015-12-16 北京奇虎科技有限公司 一种识别浏览器被劫持的方法
CN105205393A (zh) * 2015-09-30 2015-12-30 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备
CN105224653A (zh) * 2015-09-30 2016-01-06 北京奇虎科技有限公司 一种浏览器被劫持时的处理方法及处理设备
CN105243134A (zh) * 2015-09-30 2016-01-13 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备
CN105357265A (zh) * 2015-09-30 2016-02-24 北京奇虎科技有限公司 一种识别浏览器被劫持的方法
CN105354490A (zh) * 2015-09-30 2016-02-24 北京奇虎科技有限公司 一种处理被劫持浏览器的方法及设备

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110334301A (zh) * 2018-03-21 2019-10-15 深圳市腾讯计算机系统有限公司 一种页面还原方法及装置
CN110334301B (zh) * 2018-03-21 2024-05-03 深圳市腾讯计算机系统有限公司 一种页面还原方法及装置
CN109543407A (zh) * 2018-10-19 2019-03-29 北京奇虎科技有限公司 一种Activity劫持的拦截方法及装置
CN109543407B (zh) * 2018-10-19 2024-04-05 三六零科技集团有限公司 一种Activity劫持的拦截方法及装置
CN113542185A (zh) * 2020-04-13 2021-10-22 北京沃东天骏信息技术有限公司 页面防劫持的方法、装置、电子设备和存储介质
CN113542185B (zh) * 2020-04-13 2024-05-21 北京沃东天骏信息技术有限公司 页面防劫持的方法、装置、电子设备和存储介质
CN114697397A (zh) * 2022-02-24 2022-07-01 阿里巴巴(中国)有限公司 一种域名访问方法、装置、电子设备及计算机存储介质
CN114697397B (zh) * 2022-02-24 2024-06-07 阿里巴巴(中国)有限公司 一种域名访问方法、装置、电子设备及计算机存储介质

Similar Documents

Publication Publication Date Title
JP7528166B2 (ja) インターネットコンテンツ内の要素の直接的なブラウザ内のマークアップのためのシステムおよび方法
US10484424B2 (en) Method and system for security protection of account information
US9954895B2 (en) System and method for identifying phishing website
CN104933363B (zh) 检测恶意文件的方法和装置
CN108566399B (zh) 钓鱼网站识别方法及系统
CN104980404B (zh) 保护账号信息安全的方法和系统
CN107133165B (zh) 浏览器兼容性检测方法及装置
CN106610988B (zh) 网页推荐方法以及推荐装置
CN105160246A (zh) 一种识别被劫持浏览器的方法及浏览器
CN116366338A (zh) 一种风险网站识别方法、装置、计算机设备及存储介质
WO2019136987A1 (zh) 网络爬虫识别方法、装置、计算机设备和存储介质
CN105354490B (zh) 一种处理被劫持浏览器的方法及设备
JP2018206189A (ja) 情報収集装置、および、情報収集方法
TWI519980B (zh) 網頁顯示方法和裝置及電腦可讀取儲存介質
CN107786529B (zh) 网站的检测方法、装置及系统
CN105243134B (zh) 一种处理被劫持浏览器的方法及设备
CN107085684B (zh) 程序特征的检测方法和装置
CN105095289A (zh) 网页访问方法及装置
WO2017054731A1 (zh) 处理被劫持浏览器的方法及设备
CN114065092B (zh) 网站识别方法、装置、计算机设备和存储介质
CN105205393A (zh) 一种处理被劫持浏览器的方法及设备
CN105224653B (zh) 一种浏览器被劫持时的处理方法及处理设备
CN105160247A (zh) 一种识别浏览器被劫持的方法
CN110825976B (zh) 网站页面的检测方法、装置、电子设备及介质
CN109032924A (zh) 识别页面中资源类型的方法、装置、设备和储存介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16850340

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16850340

Country of ref document: EP

Kind code of ref document: A1