Unlock instant, AI-driven research and patent intelligence for your innovation.

Leak detection method and system for website user information

A user information and leakage detection technology, which is applied in the user information leakage detection and system field of the website, can solve problems such as misuse by criminals, leakage detection of user data, and easy leakage of user information, so as to prevent abuse by criminals and improve security sexual effect

Active Publication Date: 2019-02-01
SHANGHAI CTRIP COMMERCE CO LTD
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] The technical problem to be solved by the present invention is to overcome the defect that the user information of the website is easily leaked and abused by criminals in the prior art, and the traditional information leakage detection method cannot detect the leakage of user data, and provides a website Leak detection method and system for user information

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Leak detection method and system for website user information
  • Leak detection method and system for website user information

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0038] The present invention relates to a leakage detection method of website user information, such as figure 1 shown, including:

[0039] Step 101, obtain the data packet that the website server receives and responds to the user request;

[0040] The data packet includes a request packet for obtaining user information and a response packet for feeding back user information;

[0041] Specifically, mirroring the data packets generated by the user's access to the website, such as copying all the http (Hyper Text Transfer Protocol, Hypertext Transfer Protocol) traffic of the user's access to the website, can copy these flows by bypassing the core switch, and then pass through a key The word detection algorithm extracts a data packet including user information from the data packet, and uses the extracted data packet as a data packet for receiving and responding to a user request by the website server. For example, a data packet related to user information is extracted through I...

Embodiment 2

[0053] This embodiment provides a leakage detection system for user information of a website, including a data packet acquisition module, a login status judgment module, and an information leakage judgment module;

[0054] The data packet obtaining module is used to obtain the data packet received by the website server and responding to the user request, the data packet includes a request packet for requesting user information and a response packet for feeding back user information;

[0055] The data packet acquisition module includes a mirror image module and an extraction module;

[0056] The mirroring module is used for mirroring the data packets generated by the user's access to the website;

[0057] The extracting module is used to extract the data packets including user information from the data packets through a keyword detection algorithm, and use the extracted data packets as the data packets that the website server receives and responds to user requests.

[0058] Th...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a leakage detection method and system of user information of a website. The method comprises following steps of obtaining data packets that a website server receives and responds to a user request, wherein the data packets comprise a request packet for requesting to obtain user information and a response packet for feeding back the user information; judging whether a user is in an abnormal login state or not according to the contents of the request packet; when the user is in the abnormal login state, feeding back a page corresponding to the response packet of the user information as an information leakage page, wherein the abnormal login state comprises a state that login is carried out without using a login account and a state that login is carried out with a wrong login account. According to the method and the system, strict detection is carried out specific to whether the user information is leaked or not; prevention measures are carried out to the detected leaked page latterly; the security of the user data in the website is improved; and the user information is prevented from being abused by lawbreakers.

Description

technical field [0001] The invention relates to a leak detection method and system for website user information. Background technique [0002] In recent years, major e-commerce websites have been exposed to large-scale leaks of user order data due to certain code loopholes. Order data is the core data of e-commerce websites, involving user information and transaction details, and the content is very sensitive. Once these user transaction data are obtained by fraudulent groups, they will pretend to be customer service to carry out various frauds against users. Such behaviors have a negative impact on the brand of the website And the impact of word of mouth is very bad. [0003] In the prior art, the detection method for information leakage is usually to detect whether there is sensitive data in the data packet at the egress gateway of the e-commerce network, and if there is sensitive data, block the request to prevent data leakage, thereby preventing e-commerce from interna...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06
CPCH04L63/02H04L63/1425
Inventor 章锦成凌云李天爽
Owner SHANGHAI CTRIP COMMERCE CO LTD