WO2017054731A1 - 处理被劫持浏览器的方法及设备 - Google Patents
处理被劫持浏览器的方法及设备 Download PDFInfo
- Publication number
- WO2017054731A1 WO2017054731A1 PCT/CN2016/100574 CN2016100574W WO2017054731A1 WO 2017054731 A1 WO2017054731 A1 WO 2017054731A1 CN 2016100574 W CN2016100574 W CN 2016100574W WO 2017054731 A1 WO2017054731 A1 WO 2017054731A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- browser
- hijacked
- webpage
- information
- page
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
Definitions
- the present invention relates to the field of computer network technologies, and in particular, to a method and device for processing a hijacked browser.
- the following methods are generally used for processing: first, uninstalling and reinstalling the browser; second, using antivirus software to kill the virus; the above processing method has a longer processing time and is heavy When the browser is installed, the browser cannot be used. As a result, the method of handling the browser being hijacked in the prior art has a problem that the processing time is long and the browser usage is reduced during the process of handling the hijacked browser.
- the embodiment of the present application solves the technical problem that the processing method in the prior art when the browser is hijacked has a long processing time by providing a method and a device for processing the hijacked browser, thereby realizing the shortening of the processing time and the processing being The technical effect of increasing browser usage during hijacking of the browser.
- the present application provides the following technical solutions by using an embodiment of the present application:
- the present application discloses a method for processing a browser to be hijacked, including:
- the page content is loaded in the browser to display the page content.
- the identifier information is parameter information.
- the obtaining the identification information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser specifically: acquiring the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser Parameter information;
- the obtaining, according to the identifier information of the original webpage, the address information of the original webpage from the local storage device specifically: acquiring, according to the parameter information of the original webpage, the page of the original webpage from the local storage device content.
- the application also discloses a device for processing a browser to be hijacked, the device comprising:
- An identification unit configured to identify whether the browser is hijacked
- the original webpage obtaining unit is configured to: when identifying that the browser is hijacked, acquire identification information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser;
- An address information obtaining unit configured to acquire address information of the original webpage from a local storage device according to the identifier information of the original webpage;
- a page content obtaining unit configured to acquire page content of the original page based on the address information
- a loading unit configured to load the page content in the browser to display the page content loading unit.
- the identifier information is parameter information.
- the identifying unit is specifically configured to identify whether the browser is hijacked
- the original webpage obtaining unit is configured to acquire, when the browser is hijacked, the parameter information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser;
- the page content obtaining unit is configured to obtain, according to the parameter information of the original webpage, the page content of the original webpage from the local storage device;
- the loading unit is specifically configured to load the page content in the browser to display the page content in the browser.
- the present application provides the following technical solutions by using an embodiment of the present application:
- the present application also discloses a computer program comprising computer readable code, when the computer readable code is run on a computing device, causing the computing device to perform the method of any of the processing browsers described above being hijacked .
- the present application provides the following technical solutions by using an embodiment of the present application:
- the present application also discloses a computer readable medium in which the above computer program is stored.
- a method and apparatus for processing a hijacked browser by the present invention, first identifying whether a browser is hijacked, and acquiring a hijacked loading on the browser when it is recognized that the browser is hijacked
- the information of the original webpage that is not hijacked corresponding to the webpage; the address information of the original webpage is obtained from the local storage device according to the identifier information; and the page content of the original page is obtained and loaded based on the address information,
- To display the content of the page and thus, in recognizing that the browser is hijacked, Acquiring the page content of the original webpage from the local storage device to be loaded, so that the browser can immediately display the page content of the original webpage, shortening the processing time, and still using the browser during the process, thereby improving Browser usage during the process of being hijacked by the browser.
- the present invention firstly identifies whether the browser is hijacked, and when it is recognized that the browser is hijacked, acquires parameter information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser; Obtaining, according to the parameter information, a page content of the original webpage from a local storage device, and loading the page content to display the page content in the browser, so that, when the browser is hijacked, The page content of the original webpage can be directly loaded from the local storage device for loading, so that the browser can immediately display the page content of the original webpage, shortening the processing time, and the browser can still be used during the processing. Increased browser usage during the process of handling a hijacked browser.
- FIG. 1 is a flowchart of a method for processing a hijacked browser according to an embodiment of the present invention
- FIG. 2 is a block diagram of a device for processing a hijacked browser according to an embodiment of the present invention
- FIG. 3 is another flowchart of a method for processing a hijacked browser according to an embodiment of the present invention
- FIG. 4 is another block diagram of a device for processing a hijacked browser according to an embodiment of the present invention.
- Figure 5 is a schematic block diagram of a computing device for performing a method of processing a hijacked browser in accordance with the present invention
- Fig. 6 schematically shows a storage unit for holding or carrying program code implementing a method of processing a hijacked browser in accordance with the present invention.
- the embodiment of the present application solves the technical problem that the processing method in the prior art when the browser is hijacked has a long processing time by providing a method and a device for processing the hijacked browser, thereby realizing the shortening of the processing time and the processing being The technical effect of increasing browser usage during hijacking of the browser.
- a method for processing a hijacked browser includes the following steps:
- S103 Obtain address information of the original webpage from a local storage device according to the identifier information of the original webpage.
- S104 Acquire, according to the address information, a page content of the original page.
- S105 Load the page content in the browser to display the page content.
- the executor of the present application may be the device in which the browser is installed, or may be the browser.
- the present application does not specifically limit the method, wherein when the browser is recognized as being hijacked, The method for identifying the browser is hijacked by using three methods.
- the first method for identifying may be: acquiring a webpage access request and corresponding operation information; and detecting whether the operation information conforms to a preset rule,
- the setting rule includes an operation request allowed by the browser; the browser identifies that the browser has been hijacked when detecting that the operation information does not meet the preset rule; the browser detects the When the operation information conforms to the preset rule, it is recognized that the browser is not hijacked.
- the operation information of the user is received, and based on the operation information, the browser automatically generates and obtains a webpage access request corresponding to the operation information, so that the browsing is performed.
- the device can obtain the webpage access request and its corresponding operation information, wherein the operation information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can be input in the search bar of the browser.
- the information of the search information of course, the execution body of the first identification method may also be a device.
- the user receives the search information of www.axxx.com in the search bar of the browser, and the browser generates a visit www.axxx based on the operation information.
- the operation information is information for inputting www.axxx.com in the search bar of the browser, because the preset rule of the browser is the first operation request and the pair of inputting the search information in the search bar of the browser.
- a second operation request generated by clicking a hyperlink on a navigation page of the browser, and if the operation information matches the first operation request, determining that the operation information conforms to the preset rule, even if The browser can determine that the browser is not hijacked, so that the browser can improve the accuracy of whether the browser is hijacked according to the judgment result, and the browser is self-determined. Whether it was Hold, as compared with the prior art manual judgment, that determines the efficiency can be greatly improved.
- the second identification method may specifically identify whether the browser is hijacked by using a domain name, and the specific implementation steps are as follows: the browser obtains a webpage access request of the navigation page, and acquires a webpage access request corresponding to the webpage access request. Destination domain name; the browser determines whether the target domain name is original with the navigation page The browser domain is consistent; when the browser determines that the target domain name is consistent with the original domain name, it identifies that the browser is not hijacked; the browser determines the target domain name and the original When the domain names are inconsistent, it is recognized that the browser has been hijacked.
- the browser automatically loads the navigation page when the browser is started, so that the browser can obtain the webpage access request of the navigation page, and then obtain the target domain name according to the webpage access request;
- the browser receives the start request of the navigation page by the browser after the browser is started, the browser loads the navigation page according to the startup request, thereby acquiring a webpage access request of the navigation page.
- the target domain name is obtained, and then the target domain name is consistent with the original domain name.
- the execution entity of the first identification method may also be a device.
- a navigation page is automatically loaded.
- the third identification mode may be that the browser is hijacked by the parameter setting information of the command line of the shortcut
- the specific implementation steps are as follows: acquiring a command line of the shortcut of the browser Parameter setting information; determining whether the setting mode corresponding to the parameter setting information is consistent with the preset mode; and determining that the setting mode is inconsistent with the preset mode, identifying that the browser has been hijacked; When the setting manner is consistent with the preset manner, it is recognized that the browser is not hijacked.
- the execution entity of the third identification mode is a device, and the device may be, for example, a device such as a tablet computer, a notebook computer, a smart phone, a desktop computer, etc., and the browser is installed in the device, and a shortcut for obtaining the browser is obtained.
- the command line program installed in the device can be started.
- the command line program is usually cmd.exe, and then the device receives the user input and browses.
- the parameter setting information is displayed in the command line program when the command information is corresponding to the quick mode, so that the parameter setting information can be obtained according to the display content, wherein the parameter setting information is Contains the setting mode information of the shortcut.
- the parameter setting information may be obtained by viewing the attribute information of the shortcut of the browser.
- the preset mode is a default setting manner of the shortcut of the browser, and may be manually Setting method or automatic Setting method.
- a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
- the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtaining the parameter setting information, if the setting mode information of the shortcut mode included in the parameter setting information is displayed, the setting mode corresponding to the shortcut of the browser is the manual setting mode, due to the manual setting mode and the If the preset mode is the same, it is determined that the setting mode is consistent with the preset mode, so that it can be determined that the b browser is not hijacked; if the shortcut mode corresponding to the b browser is set to the automatic setting mode, The setting manner is different from the preset manner, and determining that the setting manner is inconsistent with the
- the setting mode corresponding to the shortcut of the b browser is necessarily the preset mode
- the setting mode corresponding to the shortcut of the b browser is Different from the preset mode, by determining whether the setting mode corresponding to the shortcut of the b browser is consistent with the preset mode, it is possible to accurately determine whether the b browser is hijacked, so that the accuracy of the judgment is made. Can be improved.
- step S102 is performed.
- the identification information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser is acquired.
- the hijacked webpage refers to the hijacked webpage
- the unhijacked original webpage refers to the webpage before being hijacked, for example, taking a browser as an example, a browser receives a user click.
- a browser automatically presses a navigation page button
- a navigation page is automatically loaded on a browser, but then a browser is hijacked, and the loaded navigation page is hijacked to b navigation page, so that browsing in a
- the page content of the b navigation page displayed on the device wherein a navigation page is the unhijacked original web page, and b navigation page is the hijacked web page.
- the jump information corresponding to the hijacked webpage may be acquired; and the un-hijacked original webpage is obtained based on the jump information.
- Identification information wherein the jump information includes information for jumping from the original webpage to the hijacked webpage, so that the jump information includes the name of the original webpage and the hijacked webpage The name and the like information, so that the identification information of the original webpage can be obtained from the jump information, the identifier information includes the name of the original webpage, and of course, when the browser is hijacked, Obtaining an execution code corresponding to the hijacked webpage, and acquiring identification information of the original webpage according to the execution code.
- a browser recognizes that a browser has been hijacked, and gets loaded in a.
- the hijacked page on the browser is a c navigation page
- the c navigation page is the hijacked webpage
- the jump information corresponding to the c navigation page is obtained, and if the jump information includes a jump from the a navigation page to the c
- the information of the navigation page is obtained according to the jump information, and the identification information of the navigation page is a.
- step S103 is performed, in which the address information of the original webpage is obtained from the local storage device according to the identification information of the original webpage.
- the address information of the preset webpage may be stored in the local storage device in advance, where the preset webpage includes a webpage commonly used by the user and a large number of well-known webpages, so that the preset webpage includes The original webpage is stored, and the address information of the preset webpage is stored in the local storage device, so that part or all of the identifier information of the original webpage is used as a keyword in the local storage device. Searching, searching for the address information that matches the identification information is the address information of the original webpage, wherein the address information may be, for example, a URL of the original webpage.
- the address information of the preset page may be indexed, so that when the corresponding address information is found according to the identifier information of the original webpage, the address of the original webpage can be quickly found through the index.
- Information improving the efficiency of the search; of course, it is also possible to traverse all the address information stored in the local storage device, and then find the address information of the original web page, wherein each page in the preset page may be The name is used as the file name.
- searching through the identification information of the original webpage the address information of the original webpage can be quickly obtained.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the identification information of the navigation page is obtained according to the jump information, and then The address information of the preset page stored in the tablet A installed with the browser is searched by a as the keyword, and the corresponding address information is found, that is, the address information of the navigation page is, for example, http://hao. Axxx.cn/.
- step S104 is performed, in which the page content of the original page is obtained based on the address information.
- step S104 after obtaining the address information in step S104, generating an access request for accessing the original webpage according to the address information, so that the server storing the original webpage receives the access request
- the browser returns the page content of the original webpage, so that the page content of the original webpage can be obtained.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the identification information of the navigation page is obtained according to the jump information, and then Tablet A with a browser installed Searching for the address information of the preset page stored in the address with a as the keyword, and finding the corresponding address information, that is, the address information of the navigation page is, for example, http://hao.axxx.cn/, and then generating access a
- the access request of the navigation page causes the server storing the navigation page to return the page content of the a navigation page to the a browser according to the access request, so that the browser can obtain the page content of the navigation page.
- step S105 is performed, in which the page content is loaded in the browser to display the page content.
- the page content may be loaded in the browser, and the page content is overwritten by the display content of the hijacked webpage; or the page content may be loaded in the browser.
- the display content of the hijacked webpage is replaced with the page content, and the page content of the original webpage can be loaded on the browser by the two methods, so that the browser can immediately display the page content of the original webpage.
- the processing time is shortened, and the browser can still be used during processing, which improves the browser usage during the process of handling the hijacked browser.
- step S104 After the page content of the original page is acquired through step S104, the page content is directly loaded on the browser and displayed, so that the displayed content matches the user's needs.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the identification information of the navigation page is obtained according to the jump information, and then The address information of the preset page stored in the tablet A installed with the browser is searched by a as the keyword, and the corresponding address information is found, that is, the address information of the navigation page is, for example, http://hao.
- Axxx.cn/ then generate an access request to access a navigation page, so that the server storing the navigation page returns the page content of the a navigation page to the a browser according to the access request, so that the browser can acquire a navigation The page content of the page, and then directly load the page content of the obtained a navigation page on the a browser, so that the page content of the a navigation page covers the page content of the c navigation page, so that the display on the a browser is still Is a page within a navigation page
- a method for processing a hijacked browser first identifies whether a browser is hijacked, and when it is recognized that the browser is hijacked, acquiring a hijacked webpage loaded on the browser
- the information of the original webpage that is not hijacked; the address information of the original webpage is obtained from the local storage device according to the identifier information; and the page content of the original page is obtained and loaded based on the address information to display
- the page content such that, in recognition of the browser being hijacked, may be directly from the
- the page content of the original webpage is obtained by the local storage device for loading, so that the browser can immediately display the page content of the original webpage, shortening the processing time, and the browser can still be used during the processing, and the processing is improved. Browser usage during hijacking of the browser.
- the device includes:
- the identifying unit 201 is configured to identify whether the browser is hijacked
- the original webpage obtaining unit 202 is configured to acquire, when the browser is hijacked, the identifier information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser;
- the address information obtaining unit 203 is configured to obtain the address information of the original webpage from the local storage device according to the identifier information of the original webpage.
- the page content obtaining unit 204 is configured to acquire page content of the original page based on the address information
- the loading unit 205 is configured to load the page content in the browser to display the page content in the browser.
- the device may identify whether the browser is hijacked by using three methods when the browser is hijacked.
- the first identification method may be: obtaining a webpage access request and corresponding operation information. And detecting whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser; and when detecting that the operation information does not meet the preset rule, identifying the browser Has been hijacked; when it is detected that the operation information conforms to the preset rule, it is recognized that the browser is not hijacked.
- the second identification method may specifically identify whether the browser is hijacked by using a domain name
- the specific implementation steps are as follows: the device acquires a webpage access request of the navigation page, and obtains the webpage access request with the webpage. Corresponding target domain name; determining whether the target domain name is consistent with the original domain name of the navigation page; and determining that the target domain name is consistent with the original domain name, identifying that the browser is not hijacked; When the target domain name is inconsistent with the original domain name, it is recognized that the browser has been hijacked.
- the third identification manner may be that the browser is hijacked by the parameter setting information of the command line of the shortcut
- the specific implementation steps are as follows: the device acquires the shortcut command of the browser. Parameter setting information of the line; determining whether the setting mode corresponding to the parameter setting information is consistent with the preset mode; and determining that the setting mode is inconsistent with the preset mode, identifying that the browser has been hijacked; When it is determined that the setting manner is consistent with the preset manner, it is recognized that the browser is not hijacked.
- the device further includes:
- the pre-storage unit 206 is configured to store the address information of the preset webpage in the local storage device before the address information of the original webpage is obtained from the local storage device, where the preset webpage includes The original web page.
- the device further includes:
- the jump information obtaining unit 207 is configured to acquire jump information corresponding to the hijacked webpage
- the original webpage obtaining unit 202 is specifically configured to acquire, according to the jump information, identifier information of the unhijacked original webpage, where the logo information includes a name of the original webpage.
- the local storage device includes a user terminal that installs the browser and a local server that is connected to the user terminal.
- the loading unit 205 is specifically configured to load the page content in the browser, and overlay the page content on the display content of the hijacked webpage.
- the loading unit 205 is specifically configured to load the page content in the browser, and replace the display content of the hijacked webpage with the page content.
- a device for processing a hijacked browser by the present invention, first identifies whether a browser is hijacked, and when it is recognized that the browser is hijacked, acquires a hijacked webpage loaded on the browser.
- the information of the original webpage that is not hijacked; the address information of the original webpage is obtained from the local storage device according to the identifier information; and the page content of the original page is obtained and loaded based on the address information to display
- the content of the page is such that, after recognizing that the browser is hijacked, the page content of the original webpage can be directly loaded from the local storage device to be loaded, so that the browser can immediately display the page content of the original webpage. , shortens the processing time, and can still use the browser during processing, which improves the browser usage during the process of handling the hijacked browser.
- a method for processing a hijacked browser includes the following steps:
- S302 Acquire, when the browser is hijacked, acquiring parameter information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser;
- S304 loading the page content in the browser to display the page content in the browser.
- the executor of the present application may be the device in which the browser is installed, or may be the browser.
- the application is not specifically limited. There are three ways to identify whether the browser is hijacked.
- the first method of identification may specifically be Obtaining a webpage access request and corresponding operation information; and detecting whether the operation information conforms to a preset rule, where the preset rule includes an operation request allowed by the browser; and the browser detects that the operation information is not When the preset rule is met, it is recognized that the browser has been hijacked; when the browser detects that the operation information conforms to the preset rule, it is recognized that the browser is not hijacked.
- the operation information of the user is received, and based on the operation information, the browser automatically generates and obtains a webpage access request corresponding to the operation information, so that the browsing is performed.
- the device can obtain the webpage access request and its corresponding operation information, wherein the operation information can be, for example, information that the user clicks on the hyperlink on the navigation page of the browser, or can be input in the search bar of the browser.
- the information of the search information of course, the execution body of the first identification method may also be a device.
- the user receives the search information of www.axxx.com in the search bar of the browser, and the browser generates a visit www.axxx based on the operation information.
- the operation information is information for inputting www.axxx.com in the search bar of the browser, because the preset rule of the browser is the first operation request and the pair of inputting the search information in the search bar of the browser.
- a second operation request generated by clicking a hyperlink on a navigation page of the browser, and if the operation information matches the first operation request, determining that the operation information conforms to the preset rule, even if The browser can determine that the browser is not hijacked, so that the browser can improve the accuracy of whether the browser is hijacked according to the judgment result, and the browser is self-determined. Whether it was Hold, as compared with the prior art manual judgment, that determines the efficiency can be greatly improved.
- the second identification method may specifically identify whether the browser is hijacked by using a domain name
- the specific implementation steps are as follows: the browser obtains a webpage access request of the navigation page, and acquires a webpage access request corresponding to the webpage access request.
- the target domain name the browser determines whether the target domain name is consistent with the original domain name of the navigation page; and the browser identifies the browsing when determining that the target domain name is consistent with the original domain name
- the browser is not hijacked; when the browser determines that the target domain name is inconsistent with the original domain name, the browser recognizes that the browser has been hijacked.
- the browser automatically loads the navigation page when the browser is started, so that the browser can obtain the webpage access request of the navigation page, and then obtain the target domain name according to the webpage access request;
- the browser receives the start request of the navigation page by the browser after the browser is started, the browser loads the navigation page according to the startup request, thereby acquiring a webpage access request of the navigation page.
- the target domain name is obtained, and then the target domain name is consistent with the original domain name.
- the execution entity of the first identification method may also be a device.
- a browser will automatically load a navigation page when it starts, a browser is loading
- the domain name is hao.bxxx.cn. If the original domain name of a navigation page is pre-stored in a browser is hao.axxx.cn, since hao.bxxx.cn is different from hao.axxx.cn, that is, a browser judges the above.
- the target domain name is inconsistent with the original domain name, so that the browser detects that the judgment result indicates that the target domain name is inconsistent with the original domain name, thereby recognizing that the browser has been hijacked; if a browser is pre-stored
- the original domain name of the navigation page is hao.bxxx.cn, because the original domain name is the same as the target domain name, that is, the browser determines that the target domain name is consistent with the original domain name, so that the browser detects the judgment.
- the result is that the target domain name is consistent with the original domain name, thereby recognizing that the a browser is not hijacked.
- the third identification mode may be that the browser is hijacked by the parameter setting information of the command line of the shortcut
- the specific implementation steps are as follows: acquiring a command line of the shortcut of the browser Parameter setting information; determining whether the setting mode corresponding to the parameter setting information is consistent with the preset mode; and determining that the setting mode is inconsistent with the preset mode, identifying that the browser has been hijacked; When the setting manner is consistent with the preset manner, it is recognized that the browser is not hijacked.
- the execution entity of the third identification mode is a device, and the device may be, for example, a device such as a tablet computer, a notebook computer, a smart phone, a desktop computer, etc., and the browser is installed in the device, and a shortcut for obtaining the browser is obtained.
- the command line program installed in the device can be started.
- the command line program is usually cmd.exe, and then the device receives the user input and browses.
- the parameter setting information is displayed in the command line program when the command information is corresponding to the quick mode, so that the parameter setting information can be obtained according to the display content, wherein the parameter setting information is Contains the setting mode information of the shortcut.
- the parameter setting information may be obtained by viewing the attribute information of the shortcut of the browser.
- the preset mode is a default setting manner of the shortcut of the browser, and may be manually Setting method or automatic setting method.
- a b browser is installed in the notebook computer A and a shortcut of the b browser is created, and the cmd information is input in the search field of the start menu of the notebook computer A according to the received user.
- the cmd.exe is started, and then the parameter setting information corresponding to the shortcut of the b browser is displayed in the cmd.exe according to the command information corresponding to the received shortcut of the search b browser, so that the notebook is made A obtaining the parameter setting information, if the setting mode information of the shortcut mode included in the parameter setting information is displayed, the setting mode corresponding to the shortcut of the browser is the manual setting mode, due to the manual setting mode and the If the preset mode is the same, it is determined that the setting mode is consistent with the preset mode, so that it can be determined that the b browser is not hijacked; if the shortcut mode corresponding to the b browser is set to the automatic setting mode, Setting mode is different from the preset mode, and determining the setting mode and The preset manners
- the setting mode corresponding to the shortcut of the b browser is necessarily the preset mode
- the setting mode corresponding to the shortcut of the b browser is Different from the preset mode, by determining whether the setting mode corresponding to the shortcut of the b browser is consistent with the preset mode, it is possible to accurately determine whether the b browser is hijacked, so that the accuracy of the judgment is made. Can be improved.
- step S302 is executed.
- the parameter information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser is acquired.
- the hijacked webpage refers to the hijacked webpage
- the unhijacked original webpage refers to the webpage before being hijacked, for example, taking a browser as an example, a browser receives a user click.
- a browser automatically presses a navigation page button
- a navigation page is automatically loaded on a browser, but then a browser is hijacked, and the loaded navigation page is hijacked to b navigation page, so that browsing in a
- the page content of the b navigation page displayed on the device wherein a navigation page is the unhijacked original web page, and b navigation page is the hijacked web page.
- the jump information corresponding to the hijacked webpage may be acquired; and the un-hijacked original webpage is obtained based on the jump information.
- Parameter information wherein the jump information includes information for jumping from the original webpage to the hijacked webpage, so that parameter information of the original webpage may be obtained from the jump information.
- the parameter information includes information such as a domain name and/or a web address of the original webpage.
- an execution code corresponding to the hijacked webpage may also be acquired, and obtained according to the execution code. Parameter information of the original webpage.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c Jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the parameter information of the navigation page is obtained according to the jump information as a navigation page
- step S303 is performed, in which the page content of the original webpage is obtained from the local storage device according to the parameter information of the original webpage.
- the local storage device includes a user terminal that installs the browser and a local server that is connected to the user terminal, where the local storage device stores a page content of a plurality of web pages, and the original webpage Part or all of the parameter information is a keyword searched in the local storage device, and the stored data that matches the parameter information is the page content of the original web page, wherein the local storage The page content of the original webpage is pre-stored in the device.
- the storage may be performed.
- the page content of the large number of webpages is indexed, so that when the corresponding page content is found according to the parameter information of the original webpage, the page content of the original webpage can be quickly found through the index, thereby improving the efficiency of the search; Or traversing all the data stored in the local storage device, and then finding the page content of the original webpage, where each page content is corresponding to the page content of the plurality of webpages stored in the local storage device
- the domain name and/or the web address of the webpage is used as the file name.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c Jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the parameter information of the navigation page is obtained according to the jump information as a navigation page The domain name hao.axxx.cn, and then search for the keyword of hao.axxx.cn from the page content of a large number of web pages stored in the tablet A installed with a browser, and find the corresponding page content, that is, a navigation The page content of the page.
- step S304 is performed, in which the page content is loaded in the browser to display the page content in the browser.
- the page content may be loaded in the browser, and the page content is overwritten by the display content of the hijacked webpage; or the page content may be loaded in the browser.
- the display content of the hijacked webpage is replaced with the page content, and the page content of the original webpage can be loaded on the browser by the two methods, so that the browser can immediately display the page content of the original webpage.
- the processing time is shortened, and the browser can still be used during processing, which improves the browser usage during the process of handling the hijacked browser.
- step S303 After the page content of the original page is acquired through step S303, the page content is directly loaded on the browser and displayed, so that the displayed content matches the user's needs.
- the hijacked page loaded on the browser is obtained as a c navigation page, and the c navigation page is the hijacked webpage.
- c Jump information corresponding to the navigation page if the information included in the jump information jumps from the a navigation page to the c navigation page, the parameter information of the navigation page is obtained according to the jump information as a navigation page
- the domain name hao.axxx.cn and then search for the keyword of hao.axxx.cn from the page content of a large number of web pages stored in the tablet A installed with a browser, and find the folder named hao.axxx.cn
- the data read from the folder is the page content of the a navigation page, and then directly loads the page content of the read a navigation page on the a browser, so that the page content of the a navigation page covers the c navigation The page content of the page, so that the page content of the a navigation page is still displayed
- a method for processing a hijacked browser by the present invention, first identifies whether a browser is hijacked, and when it is recognized that the browser is hijacked, acquiring a hijacked webpage loaded on the browser Parameter information of the unhijacked original webpage; obtaining, according to the parameter information, the page content of the original webpage from the local storage device and loading, to display the page content in the browser, After recognizing that the browser is hijacked, the page content of the original webpage can be directly loaded from the local storage device to be loaded, so that the browser can immediately display the page content of the original webpage, thereby shortening the processing time. And the browser can still be used during processing, which improves the browser usage during the process of handling the hijacked browser.
- the device includes:
- the identifying unit 401 is configured to identify whether the browser is hijacked
- the original webpage obtaining unit 402 is configured to acquire parameter information of the unhijacked original webpage corresponding to the hijacked webpage loaded on the browser when the browser is hijacked;
- the page content obtaining unit 403 is configured to obtain, according to the parameter information of the original webpage, the page content of the original webpage from the local storage device;
- the loading unit 404 is configured to load the page content in the browser to display the page content in the browser.
- the device may identify whether the browser is hijacked by using three methods when the browser is hijacked.
- the first identification method may be: obtaining a webpage access request and corresponding operation information. And detecting whether the operation information meets a preset rule, where the preset rule includes an operation request allowed by the browser; and when detecting that the operation information does not meet the preset rule, identifying the browser Has been hijacked; when it is detected that the operation information conforms to the preset rule, it is recognized that the browser is not hijacked.
- the second identification method may specifically identify whether the browser is hijacked by using a domain name
- the specific implementation steps are as follows: the device acquires a webpage access request of the navigation page, and obtains the webpage access request with the webpage. Corresponding target domain name; determining whether the target domain name is consistent with the original domain name of the navigation page; and determining that the target domain name is consistent with the original domain name, identifying that the browser is not hijacked; When the target domain name is inconsistent with the original domain name, it is recognized that the browser has been hijacked.
- the third identification manner may be that the browser is hijacked by the parameter setting information of the command line of the shortcut
- the specific implementation steps are as follows: the device acquires the shortcut of the browser. The parameter setting information of the command line of the mode; determining whether the setting mode corresponding to the parameter setting information is consistent with the preset mode; and when determining that the setting mode is inconsistent with the preset mode, identifying that the browser has been Being hijacked; when it is determined that the setting manner is consistent with the preset manner, it is recognized that the browser is not hijacked.
- the device further includes:
- a jump information obtaining unit 405, configured to acquire jump information corresponding to the hijacked webpage
- the original webpage obtaining unit 402 is specifically configured to acquire parameter information of the unhijacked original webpage based on the jump information.
- the local storage device includes a user terminal that installs the browser and a local server that is connected to the user terminal.
- the loading unit 404 is specifically configured to load the page content in the browser, and overlay the page content on the displayed content of the hijacked webpage.
- the loading unit 404 is specifically configured to load the page content in the browser, and replace the display content of the hijacked web page with the page content.
- a device for processing a hijacked browser by the present invention, first identifies whether a browser is hijacked, and when it is recognized that the browser is hijacked, acquires a hijacked webpage loaded on the browser.
- Parameter information of the unhijacked original webpage obtaining, according to the parameter information, the page content of the original webpage from the local storage device and loading, to display the page content in the browser,
- the page content of the original webpage can be directly loaded from the local storage device to be loaded, so that the browser can immediately display the page content of the original webpage, thereby shortening the processing time.
- the browser can still be used during processing, which improves the browser usage during the process of handling the hijacked browser.
- modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
- the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
- any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
- Each feature disclosed in this specification (including the accompanying claims, the abstract and the drawings) may be replaced by alternative features that provide the same, equivalent or similar purpose.
- the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
- a microprocessor or digital signal processor may be used in practice to implement some or all of the functionality of some or all of the components of a device that is being hijacked by a browser in accordance with an embodiment of the present invention.
- the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
- Such a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
- Figure 5 illustrates a computing device, such as an application server, that can implement a method of processing a browser that is hijacked in accordance with the present invention.
- the computing device conventionally includes a processor 510 and a computer program product or computer readable medium in the form of a memory 520.
- the memory 520 may be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), an EPROM, a hard disk, or a ROM.
- Memory 520 has a memory space 530 for program code 531 for performing any of the method steps described above.
- storage space 530 for program code may include various program code 531 for implementing various steps in the above methods, respectively.
- the program code can be read from or written to one or more computer program products.
- These computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks.
- Such computer program products are typically portable or fixed storage units as described with reference to FIG.
- the storage unit may have storage segments, storage spaces, and the like that are similarly arranged to memory 520 in the computing device of FIG.
- the program code can be compressed, for example, in an appropriate form.
- the storage unit includes computer readable code 531 ', ie, code readable by a processor, such as 510, that when executed by a computing device causes the computing device to perform each of the methods described above Steps.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
Abstract
一种处理被劫持浏览器的方法及设备,识别浏览器是否被劫持(S101);在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息(S102);根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息(S103);基于所述地址信息,获取所述原始页面的页面内容(S104);在所述浏览器中加载所述页面内容,以显示所述页面内容(S105)。上述的处理被劫持浏览器的方法及设备,解决了现有技术中在浏览器被劫持时的处理方法存在处理时间长的技术问题,实现了缩短处理时间和在处理被劫持浏览器过程中提高浏览器的使用率的技术效果。
Description
本发明涉及计算机网技术领域,尤其涉及一种处理被劫持浏览器的方法及设备。
随着互联网的迅速发展,浏览器提供了丰富多样的功能,供用户在网上能够快速查找资料及个人所需要的各种信息。但是,现实中浏览器会通过浏览器插件、浏览器辅助对象(Browser Helper Object,简称BHO)、WinsockLSP等形式对浏览器进行篡改,从而使得浏览器被劫持,而在浏览器被劫持时,浏览器的主页及互联网搜索页会变为不知名的网站、访问正常网站时被转向到恶意网页、当输入错误的网址时被转到劫持软件指定的网站和输入字符时浏览器速度严重减慢等。由于这些被劫持的浏览器给用户的日常浏览造成了不良影响,因此网络安全工具一个很重要的工作就是,需要将网络中存在的被劫持的浏览器识别出来。
现有技术中,在浏览器被劫持时,通常采用以下方式进行处理:其一、卸载并重装浏览器;其二、通过杀毒软件来杀毒;上述处理方法其处理时间较长,而且在重装浏览器时会导致浏览器不能使用,如此,使得现有技术中在处理浏览器被劫持的方法存在处理时间长且在处理被劫持浏览器过程中浏览器的使用率降低的问题。
发明内容
本申请实施例通过提供一种处理被劫持浏览器的方法及设备,解决了现有技术中在浏览器被劫持时的处理方法存在处理时间长的技术问题,实现了缩短处理时间和在处理被劫持浏览器过程中提高浏览器的使用率的技术效果。
一方面,本申请通过本申请的一实施例提供如下技术方案:
本申请公开了一种处理浏览器被劫持的方法,包括:
识别浏览器是否被劫持;
在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;
根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;
基于所述地址信息,获取所述原始页面的页面内容;
在所述浏览器中加载所述页面内容,以显示所述页面内容。
可选的,所述标识信息为参数信息;
所述获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息,具体包括:获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;
所述根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息,具体包括:根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容。
另一方面,本申请通过本申请的一实施例,提供如下技术方案:
本申请还公开了一种处理浏览器被劫持的设备,所述设备包括:
识别单元,用于识别浏览器是否被劫持;
原始网页获取单元,用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;
地址信息获取单元,用于根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;
页面内容获取单元,用于基于所述地址信息,获取所述原始页面的页面内容;
加载单元,用于在所述浏览器中加载所述页面内容,以显示所述页面内容加载单元。
可选的,所述标识信息为参数信息;
所述识别单元,具体用于识别浏览器是否被劫持;
所述原始网页获取单元,具体用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;
所述页面内容获取单元,具体用于根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容;
所述加载单元,具体用于在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
第三方面,本申请通过本申请的一实施例,提供如下技术方案:
本申请还公开了一种计算机程序,其包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行上述任一个所述的处理浏览器被劫持的方法。
第四方面,本申请通过本申请的一实施例,提供如下技术方案:
本申请还公开了一种计算机可读介质,其中存储了上述计算机程序。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种处理被劫持浏览器的方法及设备,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;根据所述标识信息,从本地存储设备中获取所述原始网页的地址信息;基于所述地址信息,获取并加载所述原始页面的页面内容,以显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接
从所述本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
进一步地,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;在根据所述参数信息,从本地存储设备中获取与所述原始网页的页面内容并进行加载,以在所述浏览器中显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接从所述本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
上述说明仅是本发明技术方案的概述,为了能够更清楚了解本发明的技术手段,而可依照说明书的内容予以实施,并且为了让本发明的上述和其它目的、特征和优点能够更明显易懂,以下特举本发明的具体实施方式。
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本发明的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1为本发明实施例提供的处理被劫持浏览器的方法的流程图;
图2为本发明实施例提供的处理被劫持浏览器的设备的模块图;
图3为本发明实施例提供的处理被劫持浏览器的方法的另一种流程图;
图4为本发明实施例提供的处理被劫持浏览器的设备的另一种模块图;
图5示意性地示出了用于执行根据本发明的处理被劫持浏览器的方法的计算设备的框图;以及
图6示意性地示出了用于保持或者携带实现根据本发明的处理被劫持浏览器的方法的程序代码的存储单元。
本申请实施例通过提供一种处理被劫持浏览器的方法及设备,解决了现有技术中在浏览器被劫持时的处理方法存在处理时间长的技术问题,实现了缩短处理时间和在处理被劫持浏览器过程中提高浏览器的使用率的技术效果。
为了更好的理解上述技术方案,下面将结合说明书附图以及具体的实施方式对上述技术方案进行详细的说明。
参见图1,本发明实施例提供的处理被劫持浏览器的方法包括以下步骤:
S101:识别浏览器是否被劫持;
S102:在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;
S103:根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;
S104:基于所述地址信息,获取所述原始页面的页面内容;
S105:在所述浏览器中加载所述页面内容,以显示所述页面内容。
其中,在步骤S101中,本申请的执行主体可以是安装有所述浏览器的设备,也可以是所述浏览器,本申请不作具体限制,其中,在识别所述浏览器被劫持时,可以通过三种方法来识别出所述浏览器是否被劫持,第一种识别方法,具体可以是获取网页访问请求及其对应的操作信息;再检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
其中,所述浏览器启动之后,会接收到用户的操作信息,基于所述操作信息,所述浏览器会自动生成并获取到与所述操作信息对应的网页访问请求,如此,使得所述浏览器能够获取到所述网页访问请求及其对应的操作信息,其中,所述操作信息例如可以是用户点击浏览器的导航页上的超链接的信息,还可以是在浏览器的搜索栏中输入搜索信息的信息,当然,所述第一种识别方法的执行主体还可以是设备。
例如,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a浏览器的搜索栏中输入www.axxx.com的信息,由于a浏览器的预设规则为在浏览器的搜索栏中输入搜索信息的第一种操作请求和对浏览器的导航页上的超链接进行点击而生成的第二种操作请求,由于所述操作信息与所述第一种操作请求相匹配,则确定所述操作信息符合所述预设规则,即使得a浏览器可以判断出a浏览器未被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
具体来讲,第二种识别方法,具体可以是通过域名来识别所述浏览器是否被劫持,其具体实施步骤如下:浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;所述浏览器判断所述目标域名是否与所述导航页的原
始域名相一致;所述浏览器在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;所述浏览器在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
其中,所述浏览器在启动时会自动加载导航页,使得所述浏览器能够获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名;当然,所述浏览器在启动之后,所述浏览器接收到用户启动所述导航页的启动请求时,所述浏览器根据所述启动请求来加载所述导航页,进而获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名,再判断所述目标域名与所述原始域名是否一致,当然,所述第一种识别方法的执行主体还可以是设备。
例如,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.bxxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取目标域名为hao.bxxx.cn,若a浏览器中预先存储有a导航页的原始域名为hao.axxx.cn,由于hao.bxxx.cn与hao.axxx.cn不同,即a浏览器判断所述目标域名与所述原始域名不一致,则使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名不一致,从而识别出a浏览器已被劫持;若a浏览器中预先存储有a导航页的原始域名为hao.bxxx.cn,由于所述原始域名与所述目标域名相同,即a浏览器判断所述目标域名与所述原始域名一致,使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名一致,从而识别出a浏览器未被劫持。
具体来讲,第三种识别方式,具体可以是通过快捷方式的命令行的参数设置信息来所述浏览器是否被劫持,其具体实施步骤如下:获取所述浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
其中,所述第三识别方式的执行主体是设备,所述设备例如可以是平板电脑、笔记本电脑、智能手机、台式电脑等设备,所述设备中安装有浏览器,在获取浏览器的快捷方式的命令行的参数设置信息时,可以通过启动安装在所述设备中的命令行程序,例如在windows环境下,命令行程序通常为cmd.exe,然后所述设备在接收到用户输入的与浏览器的快速方式对应的命令信息时,将所述参数设置信息显示在所述命令行程序中,如此,根据所述显示内容,即可获取所述参数设置信息,其中,所述参数设置信息中包含有所述快捷方式的设置方式信息。当然,还可以通过查看所述浏览器的快捷方式的属性信息来获取所述参数设置信息,进一步的,所述预设方式为所述浏览器的快捷方式的默认的设置方式,具体可以是手动设置方式或自动
设置方式。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若所述参数设置信息中包含的所述快捷方式的设置方式信息显示b浏览器的快捷方式对应的设置方式为手动设置方式时,由于手动设置方式与所述预设方式相同,则确定所述设置方式与所述预设方式相一致,如此,可以确定b浏览器未被劫持;若b浏览器的快捷方式对应的设置方式为自动设置方式时,由于自动设置方式与所述预设方式不同,则确定所述设置方式与所述预设方式不一致,如此,可以确定b浏览器已被劫持。
其中,在b浏览器未被劫持时,b浏览器的快捷方式对应的设置方式必然为所述预设方式,而在b浏览器被劫持时,b浏览器的快捷方式对应的设置方式才会与所述预设方式不同,如此,通过判断b浏览器的快捷方式对应的设置方式是否与所述预设方式相一致,即可以准确的判断出b浏览器是否被劫持,使得判断的准确性得以提高。
接下来执行步骤S102,在该步骤中,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息。
其中,所述被劫持网页指的已被劫持后的网页,所述未被劫持的原始网页指的是未被劫持之前的网页,例如,以a浏览器为例,a浏览器接收到用户点击了a浏览器自动的a导航页的按键时,在a浏览器上自动加载a导航页,但是这时a浏览器被劫持,且将加载的a导航页劫持到b导航页,使得在a浏览器上显示的b导航页的页面内容,其中,a导航页为所述未被劫持的原始网页,而b导航页为所述被劫持网页。
在具体实施过程中,在通过步骤S101识别出所述浏览器被劫持时,可以获取所述被劫持网页对应的跳转信息;基于所述跳转信息,获取所述未被劫持的原始网页的标识信息,其中,所述跳转信息中包含有从所述原始网页跳转至所述被劫持网页的信息,使得所述跳转信息中包含有所述原始网页的名称和所述被劫持网页的名称等信息,如此,可以从所述跳转信息获取到所述原始网页的标识信息,所述标识信息包括所述原始网页的名称,当然,在识别出所述浏览器被劫持时,还可以获取与所述被劫持网页对应的执行代码,根据所述执行代码,获取所述原始网页的标识信息。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a
浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的标识信息为a。
接下来执行步骤S103,在该步骤中,根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息。
在具体实施过程中,可以预先在所述本地存储设备中存储有预设网页的地址信息,所述预设网页包括用户常用的网页和大量的知名网页,使得所述预设网页中包含有所述原始网页,并将所述预设网页的地址信息存储在所述本地存储设备中,如此,以所述原始网页的标识信息中的部分或全部内容为关键词在所述本地存储设备中进行搜索,搜索到与所述标识信息相匹配的地址信息即为所述原始网页的地址信息,其中,所述地址信息例如可以是所述原始网页的URL。
具体来讲,可以对所述预设页面的地址信息建立索引,以使得在根据所述原始网页的标识信息查找到对应的地址信息时,通过索引能够更快的查找到所述原始网页的地址信息,提高查找的效率;当然,也可以是遍历所述本地存储设备中存储的所有地址信息,然后找到所述原始网页的地址信息,其中,可以将所述预设页面中的每一个页面的名称作为文件名,如此,通过所述原始网页的标识信息进行搜索,可以快速的获取所述原始网页的地址信息。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的标识信息为a,然后从安装有a浏览器的平板电脑A中存储的预设页面的地址信息中以a为关键词进行搜索,查找到对应的地址信息,即为a导航页的地址信息例如为http://hao.axxx.cn/。
接下来执行步骤S104,在该步骤中,基于所述地址信息,获取所述原始页面的页面内容。
在具体实施过程中,在通过步骤S104获取到所述地址信息之后,根据所述地址信息生成访问所述原始网页的访问请求,使得存储所述原始网页的服务器接收到所述访问请求时向所述浏览器返回所述原始网页的页面内容,从而可以获取到所述原始网页的页面内容。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的标识信息为a,然后从安装有a浏览器的平板电脑A
中存储的预设页面的地址信息中以a为关键词进行搜索,查找到对应的地址信息,即为a导航页的地址信息例如为http://hao.axxx.cn/,然后生成访问a导航页的访问请求,使得存储a导航页的服务器根据所述访问请求,将a导航页的页面内容返回给a浏览器,使得a浏览器能够获取到a导航页的页面内容。
接下来执行步骤S105,在该步骤中,在所述浏览器中加载所述页面内容,以显示所述页面内容。
在具体实施过程中,可以在所述浏览器中加载所述页面内容,将所述页面内容覆盖所述被劫持网页的显示内容;也可以在所述浏览器中加载所述页面内容,将所述被劫持网页的显示内容替换为所述页面内容,通过这两种方式均可以在所述浏览器上加载所述原始网页的页面内容,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
具体来讲,在通过步骤S104获取到所述原始页面的页面内容之后,直接在所述浏览器上加载所述页面内容并进行显示,使得显示的内容与用户的需求相匹配。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的标识信息为a,然后从安装有a浏览器的平板电脑A中存储的预设页面的地址信息中以a为关键词进行搜索,查找到对应的地址信息,即为a导航页的地址信息例如为http://hao.axxx.cn/,然后生成访问a导航页的访问请求,使得存储a导航页的服务器根据所述访问请求,将a导航页的页面内容返回给a浏览器,使得a浏览器能够获取到a导航页的页面内容,然后直接将获取的a导航页的页面内容加载在a浏览器上,使得a导航页的页面内容覆盖住c导航页的页面内容,如此,使得在a浏览器上显示的仍是a导航页的页面内容,从而解决了a浏览器上显示所述被劫持网页即c导航页的问题,缩短了处理时间,而且在处理过程中仍然可以使用a浏览器,提高了在处理被劫持a浏览器过程中a浏览器的使用率。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种处理被劫持浏览器的方法,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;根据所述标识信息,从本地存储设备中获取所述原始网页的地址信息;基于所述地址信息,获取并加载所述原始页面的页面内容,以显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接从所述
本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
根据同一发明构思,本申请另一实施例提供一种处理浏览器被劫持的设备,参见图2,所述设备包括:
识别单元201,用于识别浏览器是否被劫持;
原始网页获取单元202,用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;
地址信息获取单元203,用于根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;
页面内容获取单元204,用于基于所述地址信息,获取所述原始页面的页面内容;
加载单元205,用于在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
其中,所述设备在识别所述浏览器被劫持时,可以通过三种方法来识别出所述浏览器是否被劫持,第一种识别方法,具体可以是获取网页访问请求及其对应的操作信息;再检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;在检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
具体来讲,第二种识别方法,具体可以是通过域名来识别所述浏览器是否被劫持,其具体实施步骤如下:所述设备获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;判断所述目标域名是否与所述导航页的原始域名相一致;在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
具体的,第三种识别方式,具体可以是通过快捷方式的命令行的参数设置信息来所述浏览器是否被劫持,其具体实施步骤如下:所述设备获取所述浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
具体的,所述设备还包括:
预存单元206,用于在所述从本地存储设备中获取所述原始网页的地址信息之前,预先在所述本地存储设备中存储有预设网页的地址信息,所述预设网页中包含有所述原始网页。
具体的,所述设备还包括:
跳转信息获取单元207,用于获取所述被劫持网页对应的跳转信息;
原始网页获取单元202,具体用于基于所述跳转信息,获取所述未被劫持的原始网页的标识信息,所述标志信息包括所述原始网页的名称。
具体的,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器。
具体的,加载单元205,具体用于在所述浏览器中加载所述页面内容,并将所述页面内容覆盖所述被劫持网页的显示内容。
具体的,加载单元205,具体用于在所述浏览器中加载所述页面内容,并将所述被劫持网页的显示内容替换为所述页面内容。
上述本申请实施例中的技术方案,至少具有如下的技术效果或优点:
根据本发明的一种处理被劫持浏览器的设备,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;根据所述标识信息,从本地存储设备中获取所述原始网页的地址信息;基于所述地址信息,获取并加载所述原始页面的页面内容,以显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接从所述本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
参见图3,本发明实施例提供的处理被劫持浏览器的方法包括以下步骤:
S301:识别浏览器是否被劫持;
S302:在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;
S303:根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容;
S304:在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
其中,在步骤S301中,本申请的执行主体可以是安装有所述浏览器的设备,也可以是所述浏览器,本申请不作具体限制,其中,在识别所述浏览器被劫持时,可以通过三种方法来识别出所述浏览器是否被劫持,第一种识别方法,具体可以是获
取网页访问请求及其对应的操作信息;再检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;所述浏览器在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;所述浏览器检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
其中,所述浏览器启动之后,会接收到用户的操作信息,基于所述操作信息,所述浏览器会自动生成并获取到与所述操作信息对应的网页访问请求,如此,使得所述浏览器能够获取到所述网页访问请求及其对应的操作信息,其中,所述操作信息例如可以是用户点击浏览器的导航页上的超链接的信息,还可以是在浏览器的搜索栏中输入搜索信息的信息,当然,所述第一种识别方法的执行主体还可以是设备。
例如,以a浏览器为例,在a浏览器启动之后,接收到用户在a浏览器的搜索栏中输入了www.axxx.com的搜索信息,a浏览器基于该操作信息生成访问www.axxx.com的网页访问请求例如包含有String url="http://www.axxx.com/";如此,使得a浏览器能够接收到访问www.axxx.com的网页访问请求及其对应的操作信息,所述操作信息为在a浏览器的搜索栏中输入www.axxx.com的信息,由于a浏览器的预设规则为在浏览器的搜索栏中输入搜索信息的第一种操作请求和对浏览器的导航页上的超链接进行点击而生成的第二种操作请求,由于所述操作信息与所述第一种操作请求相匹配,则确定所述操作信息符合所述预设规则,即使得a浏览器可以判断出a浏览器未被劫持,如此,使得所述浏览器在根据所述判断结果识别出所述浏览器是否被劫持的准确性得以提高,而且所述浏览器是自行判断是否被劫持,与现有技术中的人工判断相比,其判断的工作效率也能够得到较大的提高。
具体来讲,第二种识别方法,具体可以是通过域名来识别所述浏览器是否被劫持,其具体实施步骤如下:浏览器获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;所述浏览器判断所述目标域名是否与所述导航页的原始域名相一致;所述浏览器在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;所述浏览器在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
其中,所述浏览器在启动时会自动加载导航页,使得所述浏览器能够获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名;当然,所述浏览器在启动之后,所述浏览器接收到用户启动所述导航页的启动请求时,所述浏览器根据所述启动请求来加载所述导航页,进而获取到所述导航页的网页访问请求,再根据所述网页访问请求,获取所述目标域名,再判断所述目标域名与所述原始域名是否一致,当然,所述第一种识别方法的执行主体还可以是设备。
例如,以a浏览器为例,a浏览器启动时会自动加载a导航页,a浏览器在加载
a导航页时,会生成a导航页的网页访问请求例如包含有String url="http://hao.bxxx.cn/";如此,使得浏览器能够从a导航页的网页访问请求中提取目标域名为hao.bxxx.cn,若a浏览器中预先存储有a导航页的原始域名为hao.axxx.cn,由于hao.bxxx.cn与hao.axxx.cn不同,即a浏览器判断所述目标域名与所述原始域名不一致,则使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名不一致,从而识别出a浏览器已被劫持;若a浏览器中预先存储有a导航页的原始域名为hao.bxxx.cn,由于所述原始域名与所述目标域名相同,即a浏览器判断所述目标域名与所述原始域名一致,使得a浏览器检测到所述判断结果表征所述目标域名与所述原始域名一致,从而识别出a浏览器未被劫持。
具体来讲,第三种识别方式,具体可以是通过快捷方式的命令行的参数设置信息来所述浏览器是否被劫持,其具体实施步骤如下:获取所述浏览器的快捷方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
其中,所述第三识别方式的执行主体是设备,所述设备例如可以是平板电脑、笔记本电脑、智能手机、台式电脑等设备,所述设备中安装有浏览器,在获取浏览器的快捷方式的命令行的参数设置信息时,可以通过启动安装在所述设备中的命令行程序,例如在windows环境下,命令行程序通常为cmd.exe,然后所述设备在接收到用户输入的与浏览器的快速方式对应的命令信息时,将所述参数设置信息显示在所述命令行程序中,如此,根据所述显示内容,即可获取所述参数设置信息,其中,所述参数设置信息中包含有所述快捷方式的设置方式信息。当然,还可以通过查看所述浏览器的快捷方式的属性信息来获取所述参数设置信息,进一步的,所述预设方式为所述浏览器的快捷方式的默认的设置方式,具体可以是手动设置方式或自动设置方式。
例如,以笔记本电脑A为例,在笔记本电脑A中安装有b浏览器并创建了b浏览器的快捷方式,根据接收到的用户在笔记本电脑A的开始菜单的搜索栏中输入了cmd的信息,则启动cmd.exe,然后在根据接收到的搜索b浏览器的快捷方式对应的命令信息时,将b浏览器的快捷方式对应的参数设置信息显示在cmd.exe中,如此,使得笔记本电脑A获取到所述参数设置信息,若所述参数设置信息中包含的所述快捷方式的设置方式信息显示b浏览器的快捷方式对应的设置方式为手动设置方式时,由于手动设置方式与所述预设方式相同,则确定所述设置方式与所述预设方式相一致,如此,可以确定b浏览器未被劫持;若b浏览器的快捷方式对应的设置方式为自动设置方式时,由于自动设置方式与所述预设方式不同,则确定所述设置方式与
所述预设方式不一致,如此,可以确定b浏览器已被劫持。
其中,在b浏览器未被劫持时,b浏览器的快捷方式对应的设置方式必然为所述预设方式,而在b浏览器被劫持时,b浏览器的快捷方式对应的设置方式才会与所述预设方式不同,如此,通过判断b浏览器的快捷方式对应的设置方式是否与所述预设方式相一致,即可以准确的判断出b浏览器是否被劫持,使得判断的准确性得以提高。
接下来执行步骤S302,在该步骤中,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息。
其中,所述被劫持网页指的已被劫持后的网页,所述未被劫持的原始网页指的是未被劫持之前的网页,例如,以a浏览器为例,a浏览器接收到用户点击了a浏览器自动的a导航页的按键时,在a浏览器上自动加载a导航页,但是这时a浏览器被劫持,且将加载的a导航页劫持到b导航页,使得在a浏览器上显示的b导航页的页面内容,其中,a导航页为所述未被劫持的原始网页,而b导航页为所述被劫持网页。
在具体实施过程中,在通过步骤S301识别出所述浏览器被劫持时,可以获取所述被劫持网页对应的跳转信息;基于所述跳转信息,获取所述未被劫持的原始网页的参数信息,其中,所述跳转信息中包含有从所述原始网页跳转至所述被劫持网页的信息,如此,可以从所述跳转信息获取到所述原始网页的参数信息,所述参数信息包括所述原始网页的域名和/或网址等信息,当然,在识别出所述浏览器被劫持时,还可以获取与所述被劫持网页对应的执行代码,根据所述执行代码,获取所述原始网页的参数信息。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的参数信息为a导航页的域名hao.axxx.cn。
接下来执行步骤S303,在该步骤中,根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容。
在具体实施过程中,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器,所述本地存储设备中存储有大量网页的页面内容,以所述原始网页的参数信息中的部分或全部内容为关键词在所述本地存储设备中进行搜索,搜索到与所述参数信息相匹配的存储数据即为所述原始网页的页面内容,其中,所述本地存储设备中预存有所述原始网页的页面内容。
具体来讲,在所述本地存储设备中存储有大量网页的页面内容时,可以对存储
的大量网页的页面内容建立索引,以使得再根据所述原始网页的参数信息查找到对应的页面内容时,通过索引能够更快的查找到所述原始网页的页面内容,提高查找的效率;当然,也可以是遍历所述本地存储设备中存储的所有数据,然后找到所述原始网页的页面内容,其中,在所述本地存储设备中存储的大量网页的页面内容时,将每一个页面内容对应网页的域名和/或网址作为文件名,如此,通过所述原始网页的参数信息进行搜索,就可以从所述本地存储设备中获取预存的所述原始网页的页面内容。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的参数信息为a导航页的域名hao.axxx.cn,然后从安装有a浏览器的平板电脑A中存储的大量网页的页面内容中以为hao.axxx.cn的关键词进行搜索,查找到对应的页面内容,即为a导航页的页面内容。
接下来执行步骤S304,在该步骤中,在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
在具体实施过程中,可以在所述浏览器中加载所述页面内容,将所述页面内容覆盖所述被劫持网页的显示内容;也可以在所述浏览器中加载所述页面内容,将所述被劫持网页的显示内容替换为所述页面内容,通过这两种方式均可以在所述浏览器上加载所述原始网页的页面内容,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
具体来讲,在通过步骤S303获取到所述原始页面的页面内容之后,直接在所述浏览器上加载所述页面内容并进行显示,使得显示的内容与用户的需求相匹配。
例如,以a浏览器为例,a浏览器识别出a浏览器已被劫持时,获取加载在a浏览器上的被劫持页面为c导航页,c导航页即为所述被劫持网页,获取c导航页对应的跳转信息,若所述跳转信息中包含的从a导航页跳转到c导航页的信息,根据所述跳转信息获取到a导航页的参数信息为a导航页的域名hao.axxx.cn,然后从安装有a浏览器的平板电脑A中存储的大量网页的页面内容中以为hao.axxx.cn的关键词进行搜索,查找名称为hao.axxx.cn的文件夹,然后从该文件夹中读取的数据即为a导航页的页面内容,然后直接将读取的a导航页的页面内容加载在a浏览器上,使得a导航页的页面内容覆盖住c导航页的页面内容,如此,使得在a浏览器上显示的仍是a导航页的页面内容,从而解决了a浏览器上显示所述被劫持网页即c导航页的问题,缩短了处理时间,而且在处理过程中仍然可以使用a浏览器,提高
了在处理被劫持a浏览器过程中a浏览器的使用率。
本申请实施例中提供的一个或多个技术方案,至少具有如下技术效果或优点:
根据本发明的一种处理被劫持浏览器的方法,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;在根据所述参数信息,从本地存储设备中获取与所述原始网页的页面内容并进行加载,以在所述浏览器中显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接从所述本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
根据同一发明构思,本申请另一实施例提供一种处理浏览器被劫持的设备,参见图4,所述设备包括:
识别单元401,用于识别浏览器是否被劫持;
原始网页获取单元402,用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;
页面内容获取单元403,用于根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容;
加载单元404,用于在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
其中,所述设备在识别所述浏览器被劫持时,可以通过三种方法来识别出所述浏览器是否被劫持,第一种识别方法,具体可以是获取网页访问请求及其对应的操作信息;再检测所述操作信息是否符合预设规则,所述预设规则包括所述浏览器允许的操作请求;在检测出所述操作信息不符合所述预设规则时,识别出所述浏览器已被劫持;在检测出所述操作信息符合所述预设规则时,识别出所述浏览器未被劫持。
具体来讲,第二种识别方法,具体可以是通过域名来识别所述浏览器是否被劫持,其具体实施步骤如下:所述设备获取导航页的网页访问请求,以及获取与所述网页访问请求对应的目标域名;判断所述目标域名是否与所述导航页的原始域名相一致;在判断出所述目标域名与所述原始域名一致时,则识别出所述浏览器未被劫持;在判断出所述目标域名与所述原始域名不一致时,则识别出所述浏览器已被劫持。
具体的,第三种识别方式,具体可以是通过快捷方式的命令行的参数设置信息来所述浏览器是否被劫持,其具体实施步骤如下:所述设备获取所述浏览器的快捷
方式的命令行的参数设置信息;判断所述参数设置信息对应的设置方式是否与预设方式相一致;在判断出所述设置方式与所述预设方式不一致时,识别出所述浏览器已被劫持;在判断出所述设置方式与所述预设方式一致时,识别出所述浏览器未被劫持。
具体的,所述设备还包括:
跳转信息获取单元405,用于获取所述被劫持网页对应的跳转信息;
原始网页获取单元402,具体用于基于所述跳转信息,获取所述未被劫持的原始网页的参数信息。
具体的,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器。
具体的,加载单元404,具体用于在所述浏览器中加载所述页面内容,并将所述页面内容覆盖所述被劫持网页的显示内容。
具体的,加载单元404,具体用于在所述浏览器中加载所述页面内容,并将所述被劫持网页的显示内容替换为所述页面内容。
上述本申请实施例中的技术方案,至少具有如下的技术效果或优点:
根据本发明的一种处理被劫持浏览器的设备,通过本发明,首先识别浏览器是否被劫持,在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;在根据所述参数信息,从本地存储设备中获取与所述原始网页的页面内容并进行加载,以在所述浏览器中显示所述页面内容,如此,在识别出所述浏览器被劫持,可以直接从所述本地存储设备中获取所述原始网页的页面内容进行加载,使得浏览器能够立即显示所述原始网页的页面内容,缩短了处理时间,而且在处理过程中仍然可以使用浏览器,提高了在处理被劫持浏览器过程中浏览器的使用率。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此所述的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的处理被劫持浏览器的设备中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图5示出了可以实现根据本发明的处理浏览器被劫持的方法的计算设备,例如应用服务器。该计算设备传统上包括处理器510和以存储器520形式的计算机程序产品或者计算机可读介质。存储器520可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM、硬盘或者ROM之类的电子存储器。存储器520具有用于执行上述方法中的任何方法步骤的程序代码531的存储空间530。例如,用于程序代码的存储空间530可以包括分别用于实现上面的方法中的各种步骤的各个程序代码531。这些程序代码可以从一个或者多个计算机程序产品中读出或者写入到这一个或者多个计算机程序产品中。这些计算机程序产品包括诸如硬盘,紧致盘(CD)、存储卡或者软盘之类的程序代码载体。这样的计算机程序产品通常为如参考图6所述的便携式或者固定存储单元。该存储单元可以具有与图5的计算设备中的存储器520类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元包括计算机可读代码531’,即可以由例如诸如510之类的处理器读取的代码,这些代码当由计算设备运行时,导致该计算设备执行上面所描述的方法中的各
个步骤。
本文中所称的“一个实施例”、“实施例”或者“一个或者多个实施例”意味着,结合实施例描述的特定特征、结构或者特性包括在本发明的至少一个实施例中。此外,请注意,这里“在一个实施例中”的词语例子不一定全指同一个实施例。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
此外,还应当注意,本说明书中使用的语言主要是为了可读性和教导的目的而选择的,而不是为了解释或者限定本发明的主题而选择的。因此,在不偏离所附权利要求书的范围和精神的情况下,对于本技术领域的普通技术人员来说许多修改和变更都是显而易见的。对于本发明的范围,对本发明所做的公开是说明性的,而非限制性的,本发明的范围由所附权利要求书限定。
Claims (23)
- 一种处理浏览器被劫持的方法,包括:识别浏览器是否被劫持;在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;基于所述地址信息,获取所述原始页面的页面内容;在所述浏览器中加载所述页面内容,以显示所述页面内容。
- 如权利要求1所述的方法,其中,在所述从本地存储设备中获取所述原始网页的地址信息之前,所述方法还包括:预先在所述本地存储设备中存储有预设网页的地址信息,所述预设网页中包含有所述原始网页。
- 如权利要求1所述的方法,其中,所述获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标志信息,具体包括:获取所述被劫持网页对应的跳转信息;基于所述跳转信息,获取所述未被劫持的原始网页的标志信息,所述标志信息包括所述原始网页的名称。
- 如权利要求1所述的方法,其中,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器。
- 如权利要求1~4任一项所述的方法,其中,所述在所述浏览器中加载所述页面内容,具体包括:在所述浏览器中加载所述页面内容,将所述页面内容覆盖所述被劫持网页的显示内容。
- 如权利要求1~4任一项所述的方法,其中,所述在所述浏览器中加载所述页面内容,具体包括:在所述浏览器中加载所述页面内容,将所述被劫持网页的显示内容替换为所述页面内容。
- 如权利要求1所述的方法,其中,所述标识信息为参数信息;所述获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息,具体包括:获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网 页的参数信息;所述根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息,具体包括:根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容。
- 如权利要求7所述的方法,其中,所述获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息,具体包括:获取所述被劫持网页对应的跳转信息;基于所述跳转信息,获取所述原始网页的参数信息。
- 如权利要求8所述的方法,其中,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器。
- 如权利要求7~9任一项所述的方法,其特征在于,所述在所述浏览器中加载所述页面内容,具体包括:在所述浏览器中加载所述页面内容,将所述页面内容覆盖所述被劫持网页的显示内容。
- 如权利要求7~9任一项所述的方法,其特征在于,所述在所述浏览器中加载所述页面内容,具体包括:在所述浏览器中加载所述页面内容,将所述被劫持网页的显示内容替换为所述页面内容。
- 一种处理浏览器被劫持的设备,包括:识别单元,用于识别浏览器是否被劫持;原始网页获取单元,用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的标识信息;地址信息获取单元,用于根据所述原始网页的标识信息,从本地存储设备中获取所述原始网页的地址信息;页面内容获取单元,用于基于所述地址信息,获取所述原始页面的页面内容;加载单元,用于在所述浏览器中加载所述页面内容,以显示所述页面内容加载单元。
- 如权利要求12所述的设备,其中,所述设备还包括:预存单元,用于在所述从本地存储设备中获取所述原始网页的地址信息之前,预先在所述本地存储设备中存储有预设网页的地址信息,所述预设网页中包含有所述原始网页。
- 如权利要求12所述的设备,其中,所述设备还包括:跳转信息获取单元,用于获取所述被劫持网页对应的跳转信息;地址信息获取单元,用于基于所述跳转信息,获取所述未被劫持的原始网页的标志信息,所述标志信息包括所述原始网页的名称
- 如权利要求12~14任一项所述的设备,其中,所述加载单元,具体用于在所述浏览器中加载所述页面内容,并将所述页面内容覆盖所述被劫持网页的显示内容。
- 如权利要求12~14任一项所述的设备,其中,所述加载单元,具体用于在所述浏览器中加载所述页面内容,并将所述被劫持网页的显示内容替换为所述页面内容。
- 如权利要求12所述的设备,其中,所述标识信息为参数信息;所述识别单元,具体用于识别浏览器是否被劫持;所述原始网页获取单元,具体用于在识别出所述浏览器被劫持时,获取加载在所述浏览器上的被劫持网页对应的未被劫持的原始网页的参数信息;所述页面内容获取单元,具体用于根据所述原始网页的参数信息,从本地存储设备中获取与所述原始网页的页面内容;所述加载单元,具体用于在所述浏览器中加载所述页面内容,以在所述浏览器中显示所述页面内容。
- 如权利要求17所述的设备,其中,所述设备还包括:跳转信息获取单元,用于获取所述被劫持网页对应的跳转信息;所述原始网页获取单元,具体用于基于所述跳转信息,获取所述未被劫持的原始网页的参数信息。
- 如权利要求17所述的设备,其中,所述本地存储设备包括安装所述浏览器的用户终端和与所述用户终端连接的本地服务器。
- 如权利要求17~19任一项所述的设备,其特征在于,所述加载单元,具体用于在所述浏览器中加载所述页面内容,并将所述页面内容覆盖所述被劫持网页的显示内容。
- 如权利要求17~19任一项所述的设备,其特征在于,所述加载单元,具体用于在所述浏览器中加载所述页面内容,并将所述被劫持网页的显示内容替换为所述页面内容。
- 一种计算机程序,包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据权利要求1-11中的任一个所述的处理浏览器被劫持的方法。
- 一种计算机可读介质,其中存储了如权利要求22所述的计算机程序。
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510640727.0A CN105243134B (zh) | 2015-09-30 | 2015-09-30 | 一种处理被劫持浏览器的方法及设备 |
| CN201510639660.9A CN105354490B (zh) | 2015-09-30 | 2015-09-30 | 一种处理被劫持浏览器的方法及设备 |
| CN201510639660.9 | 2015-09-30 | ||
| CN201510640727.0 | 2015-09-30 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017054731A1 true WO2017054731A1 (zh) | 2017-04-06 |
Family
ID=58422694
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/100574 Ceased WO2017054731A1 (zh) | 2015-09-30 | 2016-09-28 | 处理被劫持浏览器的方法及设备 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2017054731A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108595957A (zh) * | 2018-05-02 | 2018-09-28 | 腾讯科技(深圳)有限公司 | 浏览器主页篡改检测方法、装置及存储介质 |
| CN110334301A (zh) * | 2018-03-21 | 2019-10-15 | 深圳市腾讯计算机系统有限公司 | 一种页面还原方法及装置 |
| US10997290B2 (en) | 2018-10-03 | 2021-05-04 | Paypal, Inc. | Enhancing computer security via detection of inconsistent internet browser versions |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060041757A1 (en) * | 2004-08-21 | 2006-02-23 | Ko-Cheng Fang | Computer data protecting method |
| CN103699840A (zh) * | 2013-12-12 | 2014-04-02 | 北京奇虎科技有限公司 | 网页劫持的检测方法和装置 |
| CN104125215A (zh) * | 2014-06-30 | 2014-10-29 | 新浪网技术(中国)有限公司 | 网站域名劫持检测方法和系统 |
| CN105243134A (zh) * | 2015-09-30 | 2016-01-13 | 北京奇虎科技有限公司 | 一种处理被劫持浏览器的方法及设备 |
| CN105354490A (zh) * | 2015-09-30 | 2016-02-24 | 北京奇虎科技有限公司 | 一种处理被劫持浏览器的方法及设备 |
-
2016
- 2016-09-28 WO PCT/CN2016/100574 patent/WO2017054731A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060041757A1 (en) * | 2004-08-21 | 2006-02-23 | Ko-Cheng Fang | Computer data protecting method |
| CN103699840A (zh) * | 2013-12-12 | 2014-04-02 | 北京奇虎科技有限公司 | 网页劫持的检测方法和装置 |
| CN104125215A (zh) * | 2014-06-30 | 2014-10-29 | 新浪网技术(中国)有限公司 | 网站域名劫持检测方法和系统 |
| CN105243134A (zh) * | 2015-09-30 | 2016-01-13 | 北京奇虎科技有限公司 | 一种处理被劫持浏览器的方法及设备 |
| CN105354490A (zh) * | 2015-09-30 | 2016-02-24 | 北京奇虎科技有限公司 | 一种处理被劫持浏览器的方法及设备 |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110334301A (zh) * | 2018-03-21 | 2019-10-15 | 深圳市腾讯计算机系统有限公司 | 一种页面还原方法及装置 |
| CN110334301B (zh) * | 2018-03-21 | 2024-05-03 | 深圳市腾讯计算机系统有限公司 | 一种页面还原方法及装置 |
| CN108595957A (zh) * | 2018-05-02 | 2018-09-28 | 腾讯科技(深圳)有限公司 | 浏览器主页篡改检测方法、装置及存储介质 |
| CN108595957B (zh) * | 2018-05-02 | 2023-04-14 | 腾讯科技(深圳)有限公司 | 浏览器主页篡改检测方法、装置及存储介质 |
| US10997290B2 (en) | 2018-10-03 | 2021-05-04 | Paypal, Inc. | Enhancing computer security via detection of inconsistent internet browser versions |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN104933363B (zh) | 检测恶意文件的方法和装置 | |
| US20160283592A1 (en) | Method for performing network search at a browser side and a browser | |
| CN107133165B (zh) | 浏览器兼容性检测方法及装置 | |
| US10152539B2 (en) | Webpage searching method and browser | |
| CN104331663B (zh) | web shell的检测方法以及web服务器 | |
| WO2014139300A1 (en) | Method and device for loading a plug-in | |
| CN106610988B (zh) | 网页推荐方法以及推荐装置 | |
| WO2016095689A1 (zh) | 基于终端界面多次触控操作进行识别搜索的方法及系统 | |
| CN115562992B (zh) | 一种文件检测方法、装置、电子设备及存储介质 | |
| WO2018040270A1 (zh) | 在Windows系统中加载Linux系统ELF文件的方法及装置 | |
| CN106569860A (zh) | 一种应用管理方法及终端 | |
| CN105160246A (zh) | 一种识别被劫持浏览器的方法及浏览器 | |
| CN116366338A (zh) | 一种风险网站识别方法、装置、计算机设备及存储介质 | |
| CN105354490B (zh) | 一种处理被劫持浏览器的方法及设备 | |
| CN105138912A (zh) | 钓鱼网站检测规则的自动生成方法及装置 | |
| WO2017054716A1 (zh) | 识别被劫持浏览器的方法及浏览器 | |
| CN105243134B (zh) | 一种处理被劫持浏览器的方法及设备 | |
| CN105187439A (zh) | 钓鱼网站检测方法及装置 | |
| CN104361094A (zh) | 搜索结果中文件的保存方法、装置和浏览器客户端 | |
| CN105205393A (zh) | 一种处理被劫持浏览器的方法及设备 | |
| CN102930200B (zh) | 进程识别方法、装置和终端设备 | |
| KR20190020363A (ko) | 동적 분석과 정적 분석을 연계한 프로그램을 분석하기 위한 방법 및 장치 | |
| US8751508B1 (en) | Contextual indexing of applications | |
| CN105224653B (zh) | 一种浏览器被劫持时的处理方法及处理设备 | |
| CN111859089B (zh) | 一种用于互联网信息的错词检测控制方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16850355 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16850355 Country of ref document: EP Kind code of ref document: A1 |