A network security protection method and device, an electronic terminal and a storage medium
Patent Information
- Application Number
- CN202311085058.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-28
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2043-08-28
AI Technical Summary
[0002]爬虫是一种设定的规则,自动地对互联网上信息的程序或者脚本进行抓取,爬虫可以帮助快速的获取网络上的大量数据,但一些恶意爬虫可能会侵犯用户隐私,或者增大服务器的负荷影响其提供正常的服务,而反爬系统就更多的是为了阻止恶意爬虫的使用;反爬虫策略本质上是对访问请求添加限制条件,这些限制是不区分爬虫或用户的,是否触发限制条件,是根据是否存在爬虫特征决定的,越严格和复杂的限制条件对用户操作的宽容度越低,也就意味着正常访客也可能被识别为爬虫,但如果是简单的限制条件则意味着很容易被爬虫用户绕过去
[0040] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: The present invention can perform state analysis on the operating characteristics of the anti-crawling system in each unit cycle based on the crawler data and non-crawler data generated by the anti-crawling system in each unit cycle, evaluate and detect the performance of the anti-crawling system in identifying data crawlers in different unit cycles, detect the adaptability of the anti-crawling system to the current anti-crawling technology in real time, promptly detect the lag of the anti-crawling strategies contained in the anti-crawling system, and improve the efficiency and accuracy of the anti-crawling system in identifying and blocking crawlers.
Smart Images

Figure CN116962075B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security management technology, specifically to a network security protection method, device, electronic terminal, and storage medium. Background Technology
[0002] A web crawler is a program or script that automatically retrieves information from the internet according to predefined rules. Web crawlers can help quickly obtain large amounts of data online, but some malicious crawlers may infringe on user privacy or increase server load, affecting the provision of normal services. Anti-crawling systems are mainly designed to prevent the use of malicious crawlers. Anti-crawling strategies essentially add restrictions to access requests. These restrictions do not distinguish between crawlers and users. Whether a restriction is triggered depends on the presence of crawler characteristics. The stricter and more complex the restrictions, the lower the tolerance for user operations, which means that normal visitors may also be identified as crawlers. However, simple restrictions mean that they are easily bypassed by crawler users.
[0003] Web crawling technology is always surpassed by anti-web crawling technology, but there is always a lag in researching countermeasures and vulnerabilities of anti-web crawling strategies, which affects the efficiency and accuracy of anti-web crawling systems in identifying and blocking web crawlers. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a network security protection method, device, electronic terminal and storage medium to promptly detect the lag of anti-crawling strategies contained in anti-crawling systems and improve the efficiency and accuracy of anti-crawling systems in identifying and intercepting crawlers.
[0005] To achieve the above objectives, the present invention is implemented using the following technical solution:
[0006] In a first aspect, the present invention provides a network security protection method, the method comprising:
[0007] Obtain crawler user data and non-crawler user data after the target anti-crawler system performs anti-crawler identification on the access data generated in each unit period;
[0008] Based on the crawler user data and non-crawler user data, the characteristic operation information of the target anti-crawler system presented in each unit period is extracted respectively.
[0009] Based on the characteristic operation information corresponding to adjacent unit cycles, the characteristic operation trend association result of the target anti-crawling system during adjacent weeks is determined, and adjacent unit cycles that satisfy the characteristic operation trend association are obtained.
[0010] Taking adjacent unit cycles as a trend node and taking adjacent unit cycles that satisfy the associated feature operation trends as a feature trend node, corresponding security protection strategies are adopted for the target anti-crawling system based on the distribution of the feature trend nodes presented by the target anti-crawling system within a preset detection period, where the detection period includes at least three unit cycles.
[0011] Further, the extraction of the feature operation information presented by the target anti-crawling system in each unit cycle includes:
[0012] Obtaining associated marking information between the crawler user and the crawler strategy that identifies the crawler user, sorting the associated marking information corresponding to each anti-crawling strategy within the unit cycle to obtain a strategy sequence, and using the strategy sequence as the first feature operation information corresponding to the target anti-crawling system in the unit cycle.
[0013] Further, the extraction of the feature operation information presented by the target anti-crawling system in each unit cycle further includes:
[0014] Performing feature extraction on the access data of non-crawler users to obtain feature access data;
[0015] Comparing the feature access data of every two non-crawler users to obtain a similarity, selecting the two non-crawler users with the smallest similarity as the first central user and the second central user, and then comparing to obtain the similarity f between the two central users;
[0016] Obtaining the similarity between other non-crawler users and the central users, when the similarity between a non-crawler user and the first central user is greater than the similarity between the non-crawler user and the second central user, classifying the non-crawler user and the first central user into one cluster category, otherwise classifying the non-crawler user and the second central user into two cluster categories;
[0017] Calculating the distribution ratio G = K1:K2 between the two cluster categories, where K1 < K2, and K1 and K2 respectively represent the number of non-crawler users contained in the cluster category with a smaller value and the number of non-crawler users contained in the cluster category with a larger value in the two cluster categories;
[0018] Taking the distribution index D = Gf as the second feature operation information corresponding to the target anti-crawling system in a certain unit cycle.
[0019] Further, the determination of the associated result of the feature operation trends of the target anti-crawling system between adjacent unit cycles based on the feature operation information corresponding to adjacent unit cycles includes:
[0020] Successively extracting two adjacent unit cycles T i and T i+1The corresponding first feature operation information and second feature operation information are used to obtain the target anti-crawling system in the (i+1)th unit period T. i+1 The corresponding strategy sequence and the i-th unit period T i The correlation value R(T) between the corresponding policy sequences i T i+1 );
[0021] Obtain the target anti-crawling system in the (i+1)th unit period T. i+1 The corresponding strategy sequence in the i-th unit period T i The corresponding distribution index D(T) i ) and the distribution index D(T) corresponding to the (i+1)th unit period i+1 ), calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The change in the distribution index P(T) between them i T i+1 )=|D(T i )-D(T i+1 )|;
[0022] Based on the change value of the distribution index P(T) i T i+1 ) and correlation value R(T) i T i+1 ) Calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The characteristic trend index value β(T) exhibited between them i T i+1 )=R(T i T i+1 )+P(T i T i+1 );
[0023] When β(T) i T i+1 )>α, the target anti-crawling system in two adjacent unit periods T i T i+1 If there is a correlation in the characteristic operating trend between them, then there is no correlation, where α is the set exponential threshold.
[0024] Furthermore, the target anti-crawling system acquires the target in the (i+1)th unit period T. i+1 The corresponding strategy sequence and the i-th unit period T i The correlation value R(T) between the corresponding policy sequences i T i+1 ),include:
[0025] The i-th unit period T iThe policy sequence H within the range is reversed to obtain the policy sequence H', and the (i+1)th unit period T is... i+1 The similarity between the corresponding policy sequence U and policy sequence H' is used as the association value R(T) between the corresponding policy sequences. i T i+1 ).
[0026] Furthermore, based on the characteristic trend node distribution of the target anti-crawling system within a preset detection period, corresponding security protection strategies are adopted for the target anti-crawling system, including:
[0027] The interval time between every two adjacent feature trend nodes is captured sequentially, and the average interval time T of the feature trend node in each detection cycle is calculated.
[0028] The target anti-crawling system's operational trend characteristic value δ = (m / M)*T is calculated based on the average interval time T in each detection cycle; where m represents the total number of characteristic trend nodes in each detection cycle, and M represents the total number of trend nodes in each detection cycle.
[0029] When the running trend characteristic value δ is greater than the set running trend characteristic value threshold δ max When necessary, a warning message is sent to the administrator's port indicating that the target anti-scraping system needs to be optimized or adjusted; otherwise, no warning message is sent.
[0030] Secondly, the present invention provides a network security protection device, the device comprising:
[0031] Data acquisition module: used to acquire crawler user data and non-crawler user data obtained by the target anti-crawler system after anti-crawler identification of access data generated in each unit period;
[0032] Feature operation information extraction module: used to extract the feature operation information of the target anti-crawler system in each unit period based on the crawler user data and non-crawler user data;
[0033] Feature trend node judgment and management module: used to judge the feature operation trend association result of the target anti-crawling system in adjacent weeks based on the feature operation information corresponding to adjacent unit cycles, and obtain adjacent unit cycles that satisfy the feature operation trend association;
[0034] Early warning module: It is used to take adjacent unit cycles as a trend node and adjacent unit cycles that meet the characteristic operation trend association as a characteristic trend node. Based on the distribution of characteristic trend nodes presented by the target anti-crawling system within a preset detection period, it adopts corresponding security protection strategies for the target anti-crawling system. The detection period contains at least three unit cycles.
[0035] Furthermore, the feature operation information extraction module includes a first feature operation information extraction unit and a second feature operation information extraction unit;
[0036] The first feature operation information extraction unit is used to extract the first feature operation information of the target anti-crawling system from the crawler user data within the corresponding unit period;
[0037] The second feature operation information extraction unit is used to extract the second feature operation information of the target anti-crawler system from non-crawler user data within the corresponding unit period.
[0038] Thirdly, the present invention provides an electronic terminal, including a processor and a memory connected to the processor, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the steps of any of the methods described above are performed.
[0039] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described above.
[0040] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: The present invention can perform state analysis on the operating characteristics of the anti-crawling system in each unit cycle based on the crawler data and non-crawler data generated by the anti-crawling system in each unit cycle, evaluate and detect the performance of the anti-crawling system in identifying data crawlers in different unit cycles, detect the adaptability of the anti-crawling system to the current anti-crawling technology in real time, promptly detect the lag of the anti-crawling strategies contained in the anti-crawling system, and improve the efficiency and accuracy of the anti-crawling system in identifying and blocking crawlers. Attached Figure Description
[0041] Figure 1 This is a flowchart illustrating a network security protection method based on artificial intelligence according to the present invention. Detailed Implementation
[0042] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments and specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations thereof. In the absence of conflict, the embodiments and technical features in the embodiments can be combined with each other.
[0043] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0044] Example 1:
[0045] Figure 1 This is a flowchart illustrating a network security protection method according to Embodiment 1 of the present invention. This flowchart merely shows the logical sequence of the method described in this embodiment. Provided there are no conflicts, different methods may be used in other possible embodiments of the present invention. Figure 1 Complete the steps shown or described in the order indicated.
[0046] The network security protection method provided in this embodiment can be applied to a terminal and can be executed by network security protection. This device can be implemented in software and / or hardware and can be integrated into the terminal, such as any smartphone, tablet, or computer device with communication capabilities. See also Figure 1 The method implemented in this way specifically includes the following steps:
[0047] Step 1:
[0048] Set a unit period to obtain crawler user data and non-crawler user data obtained by the target anti-crawler system after anti-crawling identification of access data generated in each unit period.
[0049] Step Two:
[0050] Based on the crawler user data and non-crawler user data, the characteristic operation information of the target anti-crawler system presented in each unit period is extracted respectively:
[0051] Based on crawler user data: obtain association tag information between crawler users and crawler strategies that identify crawler users, sort the association tag information corresponding to each anti-crawling strategy within a unit period to obtain a strategy sequence, and use the strategy sequence as the first feature operation information of the target anti-crawling system in the unit period.
[0052] Based on non-crawler user data: Feature extraction is performed on the access data of non-crawler users to obtain feature access data;
[0053] The similarity is obtained by comparing the feature access data of each pair of non-crawler users. The two non-crawler users with the smallest similarity are selected as the first central user and the second central user. The similarity f between the two central users is then compared.
[0054] Obtain the similarity between other non-crawler users and the central user. When the similarity between a non-crawler user and the first central user is greater than the similarity between the non-crawler user and the second central user, classify the non-crawler user and the first central user into one cluster; otherwise, classify the non-crawler user and the second central user into another cluster.
[0055] Calculate the distribution ratio G = K1:K2 between the two clusters, where K1 < K2, and K1 and K2 respectively represent the number of non-crawler users contained in the cluster with a smaller value and the number of non-crawler users contained in the cluster with a larger value among the two clusters.
[0056] Take the distribution index D = Gf as the second characteristic operation information corresponding to the target anti-crawler system in a certain unit cycle.
[0057] Step Three:
[0058] Based on the characteristic operation information corresponding to adjacent unit cycles, judge the characteristic operation trend association result between adjacent cycles of the target anti-crawler system, and obtain adjacent unit cycles that meet the characteristic operation trend association:
[0059] Extract the first characteristic operation information and the second characteristic operation information corresponding to two adjacent unit cycles T i 、T i+1 one by one. Reverse the policy sequence H within the i-th unit cycle T i to obtain the policy sequence H'. Take the similarity between the policy sequence U corresponding to the (i + 1)-th unit cycle T i+1 and the policy sequence H' as the association value R(T i ,T i+1 ) between the corresponding policy sequences, that is, obtain the association value R(T ) between the policy sequence corresponding to the (i + 1)-th unit cycle T i+1 of the target anti-crawler system and the policy sequence corresponding to the i-th unit cycle T i ,T i ,T i+1 );
[0060] For example: Suppose the policy sequence corresponding to a certain unit cycle T i is H = {h1, h2,..., h n-1 ,h n}; where h1, h2,..., h n respectively represent the anti-crawler strategies with the cumulative association mark frequency values in the 1st, 2nd,..., nth positions among the crawler users in a certain unit cycle; reverse the policy sequence H to obtain the policy sequence H' = {h n ,h n-1 ,..., h2, h1}.
[0061] For example, there exist first unit periods, second unit periods, and third unit periods.
[0062] The strategy sequence in the first unit period is L1. Reverse L1 to obtain the associated strategy sequence L1' with the highest correlation to L1.
[0063] The strategy sequence in the second unit period is L2. L1 is reversed to obtain the associated strategy sequence L2' with the highest correlation to L1. The similarity between L2 and L1' is obtained as R(1,2).
[0064] The strategy sequence in the third unit period is L3. L1 is reversed to obtain the associated strategy sequence L3' with the highest correlation to L1. The similarity between L3 and L2' is obtained as R(2,3).
[0065] In summary, the correlation value between the second unit period and the first unit period for the corresponding strategy sequence is R(1, 2), and the correlation value between the third unit period and the second unit period for the corresponding strategy sequence is R(2, 3).
[0066] Obtain the target anti-crawling system in the (i+1)th unit period T. i+1 The corresponding strategy sequence in the i-th unit period T i The corresponding distribution index D(T) i ) and the distribution index D(T) corresponding to the (i+1)th unit period i+1 ), calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The change in the distribution index P(T) between them i T i+1 )=|D(T i )-D(T i+1 )|;
[0067] Based on the change value of the distribution index P(T) i T i+1 ) and correlation value R(T) i T i+1 ) Calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The characteristic trend index value β(T) exhibited between them i T i+1 )=R(T i T i+1 )+P(T i T i+1 );
[0068] When β(T) i T i+1)>α, the target anti-crawling system in two adjacent unit periods T i T i+1 If there is a correlation in the characteristic operating trend between them, then there is no correlation, where α is the set exponential threshold.
[0069] Step Four:
[0070] The interval time between every two adjacent feature trend nodes is captured sequentially, and the average interval time T of the feature trend node in each detection cycle is calculated.
[0071] The target anti-crawling system's operational trend characteristic value δ = (m / M)*T is calculated based on the average interval time T in each detection cycle; where m represents the total number of characteristic trend nodes in each detection cycle, and M represents the total number of trend nodes in each detection cycle.
[0072] When the running trend characteristic value δ is greater than the set running trend characteristic value threshold δ max When necessary, a warning message is sent to the administrator's port indicating that the target anti-scraping system needs to be optimized or adjusted; otherwise, no warning message is sent.
[0073] In this embodiment, the operational characteristics of the anti-crawling system are analyzed in each unit cycle by using crawler data and non-crawler data generated by the anti-crawling system. The performance of the anti-crawling system in identifying crawlers in different unit cycles is evaluated and detected. The adaptability of the anti-crawling system to current anti-crawling technologies is detected in real time, and the lag of the anti-crawling strategies contained in the anti-crawling system is detected in a timely manner, thereby improving the efficiency and accuracy of the anti-crawling system in identifying and blocking crawlers.
[0074] Example 2:
[0075] This invention also provides a network security protection device, comprising:
[0076] Data acquisition module: used to acquire crawler user data and non-crawler user data obtained by the target anti-crawler system after anti-crawler identification of access data generated in each unit period;
[0077] Feature operation information extraction module: used to extract the feature operation information of the target anti-crawler system in each unit period based on the crawler user data and non-crawler user data;
[0078] Feature trend node judgment and management module: used to judge the feature operation trend association result of the target anti-crawling system in adjacent weeks based on the feature operation information corresponding to adjacent unit cycles, and obtain adjacent unit cycles that satisfy the feature operation trend association;
[0079] Early warning module: It is used to take adjacent unit cycles as a trend node and adjacent unit cycles that meet the characteristic operation trend association as a characteristic trend node. Based on the distribution of characteristic trend nodes presented by the target anti-crawling system within a preset detection period, it adopts corresponding security protection strategies for the target anti-crawling system. The detection period contains at least three unit cycles.
[0080] Preferably, the feature trend node judgment and management module also includes a node information calculation and management unit and a feature operation trend association judgment unit;
[0081] The node information calculation and management unit is used to obtain the feature operation information corresponding to each unit cycle one by one, and calculate the feature trend index value of the anti-crawling system to be detected between each two adjacent unit cycles based on the feature operation information corresponding to each two adjacent unit cycles.
[0082] The feature operation trend correlation judgment unit is used to receive data from the node information calculation management unit and determine whether the anti-crawling system to be detected exhibits a feature operation trend correlation between every two adjacent unit cycles.
[0083] The network security protection device provided in this embodiment of the invention can execute the network security protection method provided in Embodiment 1 of the invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0084] Example 3:
[0085] This invention also provides an electronic terminal, including a processor and a memory connected to the processor, wherein a computer program is stored in the memory, and the processor is used to perform operations according to the instructions to execute the steps of the method described in Embodiment 1.
[0086] The electronic terminal provided in this embodiment of the invention can execute the network security protection method provided in Embodiment 1 of the invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0087] Example 4:
[0088] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method described in Embodiment 1.
[0089] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0090] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0091] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0092] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0093] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A network security protection method, characterized in that, The method includes: Obtaining crawler user data and non-crawler user data obtained by the target anti-crawling system after anti-crawling recognition of access data generated in each unit cycle; Based on the crawler user data and non-crawler user data, respectively extracting the characteristic operation information presented by the target anti-crawling system in each unit cycle; Based on the characteristic operation information corresponding to adjacent unit cycles, judging the characteristic operation trend association result between adjacent cycles of the target anti-crawling system, and obtaining adjacent unit cycles that meet the characteristic operation trend association; Taking adjacent unit cycles as a trend node, taking adjacent unit cycles that meet the characteristic operation trend association as a characteristic trend node, and based on the distribution of characteristic trend nodes presented by the target anti-crawling system within a preset detection period, adopting corresponding security protection strategies for the target anti-crawling system, where the detection period includes at least three unit cycles; The extraction of the characteristic operation information presented by the target anti-crawling system in each unit cycle includes: Performing feature extraction on the access data of non-crawler users to obtain feature access data; Comparing the feature access data of every two non-crawler users with each other to obtain a similarity, selecting the two non-crawler users with the smallest similarity as the first central user and the second central user, and then comparing to obtain the similarity f between the two central users; Obtaining the similarity between other non-crawler users and the central users, when the similarity between a non-crawler user and the first central user is greater than the similarity between the non-crawler user and the second central user, classifying the non-crawler user and the first central user into one cluster, otherwise classifying the non-crawler user and the second central user into the second cluster; Calculating the distribution ratio G = K1:K2 between the two clusters, where K1 < K2, and K1 and K2 respectively represent the number of non-crawler users contained in the cluster with a smaller value and the number of non-crawler users contained in the cluster with a larger value in the two clusters; Taking the distribution index D = Gf as the second characteristic operation information corresponding to the target anti-crawling system in a certain unit cycle.
2. The network security protection method according to claim 1, characterized in that, The extraction of the characteristic operation information presented by the target anti-crawling system in each unit cycle includes: Obtaining associated marking information between crawler users and the crawler strategies that identify the crawler users, sorting the associated marking information corresponding to each anti-crawling strategy within a unit cycle to obtain a strategy sequence, and taking the strategy sequence as the first characteristic operation information corresponding to the target anti-crawling system in the unit cycle.
3. The network security protection method according to claim 1, characterized in that, The judgment of the characteristic operation trend association result between adjacent cycles of the target anti-crawling system based on the characteristic operation information corresponding to adjacent unit cycles includes: Extracting two adjacent unit periods T one by one i T i+1 The corresponding first feature operation information and second feature operation information are used to obtain the target anti-crawling system in the (i+1)th unit period T. i+1 The corresponding strategy sequence and the i-th unit period T i The correlation value R(T) between the corresponding policy sequences i T i+1 ); Obtain the target anti-crawling system in the (i+1)th unit period T. i+1 The corresponding strategy sequence in the i-th unit period T i The corresponding distribution index D(T) i ) and the distribution index D(T) corresponding to the (i+1)th unit period i+1 ), calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The change in the distribution index P(T) between them i T i+1 )=|D(T i )-D(T i+1 )|; Based on the change value of the distribution index P(T) i T i+1 ) and correlation value R(T) i T i+1 ) Calculate the target anti-crawling system in two adjacent unit periods T i T i+1 The characteristic trend index value β(T) exhibited between them i T i+1 )=R(T i T i+1 )+P(T i T i+1 ); When β(T) i T i+1 )>α, the target anti-crawling system in two adjacent unit periods T i T i+1 If there is a correlation in the characteristic operating trend between them, then there is no correlation, where α is the set exponential threshold.
4. The network security protection method according to claim 3, characterized in that, The target anti-crawling system is acquired in the (i+1)th unit period T. i+1 The corresponding strategy sequence and the i-th unit period T i The correlation value R(T) between the corresponding policy sequences i T i+1 ),include: The i-th unit period T i The policy sequence H within the range is reversed to obtain the policy sequence H', and the (i+1)th unit period T is... i+1 The similarity between the corresponding policy sequence U and policy sequence H' is used as the association value R(T) between the corresponding policy sequences. i T i+1 ).
5. The network security protection method according to claim 1, characterized in that, The adoption of corresponding security protection strategies for the target anti-crawling system based on the distribution of characteristic trend nodes presented by the target anti-crawling system within a preset detection period includes: Sequentially capturing the interval time between every two adjacent characteristic trend nodes, and calculating the average interval time T at which characteristic trend nodes appear in each detection period; Calculate the running trend eigenvalue δ=(m / M)*T corresponding to the target anti-crawling system in each detection period according to the average interval time T; where m represents the total number of characteristic trend nodes in each detection period, and M represents the total number of trend nodes in each detection period; When the running trend characteristic value δ is greater than the set running trend characteristic value threshold δ max When necessary, a warning message is sent to the administrator's port indicating that the target anti-scraping system needs to be optimized or adjusted; otherwise, no warning message is sent.
6. A network security protection device, characterized in that, The device includes: Data acquisition module: used to acquire the crawler user data and non-crawler user data obtained after the target anti-crawling system performs anti-crawling identification on the access data generated in each unit period; Characteristic running information extraction module: used to extract the characteristic running information presented by the target anti-crawling system in each unit period respectively based on the crawler user data and non-crawler user data; Characteristic trend node judgment and management module: used to judge the characteristic running trend association result of the target anti-crawling system between adjacent unit periods based on the characteristic running information corresponding to adjacent unit periods, and obtain adjacent unit periods that meet the characteristic running trend association; Early warning prompt module: used to take the adjacent unit periods as a trend node, take the adjacent unit periods that meet the characteristic running trend association as a characteristic trend node, and take corresponding security protection strategies for the target anti-crawling system based on the distribution of the characteristic trend nodes presented by the target anti-crawling system within a preset detection period, where the detection period includes at least three unit periods; The characteristic running information extraction module includes a second characteristic running information extraction unit; The second characteristic running information extraction unit is used to extract the second characteristic running information of the target anti-crawling system in the corresponding unit period from the non-crawler user data; specifically including: Extract characteristic access data by performing feature extraction on the access data of non-crawler users; Compare the characteristic access data of every two non-crawler users to obtain the similarity, select the two non-crawler users with the smallest similarity as the first central user and the second central user, and then compare to obtain the similarity f between the two central users; Obtain the similarity between other non-crawler users and the central users. When the similarity between a non-crawler user and the first central user is greater than the similarity between the non-crawler user and the second central user, classify the non-crawler user and the first central user into one cluster, otherwise classify the non-crawler user and the second central user into two clusters; Calculate the distribution ratio G=K1:K2 between the two clusters, where K1<K2, and K1 and K2 respectively represent the number of non-crawler users contained in the cluster with a smaller value and the number of non-crawler users contained in the cluster with a larger value in the two clusters; Take the distribution index D=Gf as the second characteristic running information corresponding to the target anti-crawling system in the certain unit period.
7. The network security protection device according to claim 6, characterized in that, The characteristic running information extraction module includes a first characteristic running information extraction unit; the first characteristic running information extraction unit is used to extract the first characteristic running information of the target anti-crawling system in the corresponding unit period from the crawler user data.
8. An electronic terminal, characterized in that, It includes a processor and a memory connected to the processor. A computer program is stored in the memory. When the computer program is executed by the processor, it executes the steps of the method according to any one of claims 1 to 5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Crawler detection method and device and readable storage medium
CN116599686A