Data anti-crawler method and system based on user behavior dynamic encryption

By collecting real-time interactive behavior data from the user side to generate dynamic keys, and combining multi-layer salt values ​​and machine learning algorithms to verify user behavior, the problem of existing anti-crawler technology being easily bypassed is solved, and efficient data protection effects are achieved.

CN120658391AActive Publication Date: 2025-09-16DAODATIANJI SOFTWARE TECH BEIJING

Patent Information

Application Number
CN202510971367.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-09-16
Estimated Expiration
2045-07-15

AI Technical Summary

Technical Problem

Most existing anti-crawler technologies rely on front-end detection and lack encryption protection for the data itself, making it easy for crawler programs to bypass them. Traditional methods are difficult to increase the difficulty of cracking crawlers.

Method used

Collect real-time user interaction behavior data from the user end, generate user behavior feature values, combine dynamic regularized multi-layer salt values ​​to generate dynamic keys, calculate the legitimacy score through machine learning algorithms, verify the legitimacy of user behavior, and perform data protection based on the verification results.

Benefits of technology

It improves data security, enhances the accuracy of crawler recognition, improves the protection level, makes it difficult for crawlers to imitate user behavior and cracks, and enhances the randomness and complexity of protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658391A_ABST
    Figure CN120658391A_ABST
Patent Text Reader

Abstract

The invention discloses a data anti-crawler method and system based on user behavior dynamic encryption, and relates to the technical field of network data anti-crawler. According to the method, the real-time user interaction behavior data of the user side is collected, the corresponding user behavior characteristic value is generated, the unique dynamic secret keys of different users are generated in combination with the dynamic regularized multilayer salt values, and the inconsistency of the dynamic secret keys is increased, so that a crawler is difficult to break through the secret keys and cannot simulate the complex behaviors of the users, and the user experience is improved. Therefore, the data security is improved, and the cracking difficulty of the crawler is improved; according to the method, abnormal real-time user interaction behavior data is captured, the activity type of the current session is judged, the effective recognition accuracy of crawler activities is improved, unauthorized crawler programs are effectively prevented from capturing website data, the protection level of the data is improved, and the randomness and complexity of protection are enhanced through unique user behaviors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network data anti-crawler technology, and in particular to a data anti-crawler method and system based on dynamic encryption of user behavior. Background Art

[0002] With the rapid development of network technology, crawler programs have been widely used for data capture and information processing. However, unauthorized crawler activities are also becoming increasingly rampant, posing security risks to website operators such as data leakage and increased service load. Currently, traditional anti-crawler technologies such as IP blocking, verification codes, and frequency limiting strategies have many flaws and are easily bypassed by crawler programs. Most existing anti-crawler technologies rely on front-end detection methods and lack encryption protection for the data itself. Even if anti-crawler measures are effective, crawlers can still bypass protection by intercepting page data packets or simulating browser behavior. Therefore, there is an urgent need for a novel encryption technology that can deepen protection measures into the data level and make it more difficult for crawlers to crack. Summary of the Invention

[0003] The purpose of the present invention is to provide a data anti-crawler method and system based on dynamic encryption of user behavior to improve the above technical problems.

[0004] In order to achieve the above-mentioned object of the invention, the embodiment of the present invention provides the following technical solutions:

[0005] A data anti-crawler method based on dynamic encryption of user behavior, comprising:

[0006] Collect real-time user interaction behavior data from the user end and generate user behavior feature values; real-time user interaction behavior data includes mouse behavior trajectory data and keyboard behavior data;

[0007] Obtain the original data of the current session on the user side, randomly generate the initial encryption key in real time and process it to generate the initial ciphertext;

[0008] Generate a dynamic key based on the initial encryption key and user behavior feature value;

[0009] Calculate the legitimacy score of the user behavior feature value and verify it to obtain the verification result;

[0010] Based on the verification result, the activity type of the current session is determined and data protection is performed.

[0011] Furthermore, the mouse behavior trajectory data includes the mouse movement trajectory, stop point, click frequency, click position, click time interval, scrolling times, scrolling time and scrolling rate; the keyboard behavior data includes the keyboard typing rate and typing time interval.

[0012] Furthermore, the generating of a dynamic key based on the initial encryption key and the user behavior characteristic value includes:

[0013] Set the number of iterations and output length, and set multiple layers of salt based on dynamic rules;

[0014] Construct a key derivation function based on multiple layers of salt values;

[0015] Based on the initial encryption key and user behavior characteristic value, a dynamic key is generated through a key derivation function.

[0016] Furthermore, the setting of multi-layer salt values ​​based on dynamic rules includes:

[0017] Real-time acquisition of the current session's time and environment information; environment information includes network latency, geographic location, and device parameters; device parameters include screen resolution, display refresh rate, browser type, User-Agent string, and operating system information;

[0018] Based on time information and user behavior feature values, a time sub-salt value is generated using a hash function;

[0019] Based on the environmental information and user behavior feature values, a hash function or encryption algorithm is used to generate an environmental sub-salt value;

[0020] Based on the time sub-salt value and the environment sub-salt value, multi-layer salt values ​​are generated through weighted calculation.

[0021] Furthermore, the legitimacy score of the user behavior feature value is calculated and verified to obtain a verification result, including:

[0022] Utilize machine learning algorithms to calculate the legitimacy score of user behavior feature values;

[0023] Extracting abnormal real-time user interaction behavior data from real-time user interaction behavior data;

[0024] Calculate the abnormal data ratio of abnormal real-time user interaction behavior data;

[0025] The verification result is determined based on the legitimacy score and the proportion of abnormal data.

[0026] Furthermore, the abnormal real-time user interaction behavior data refers to real-time user interaction behavior data that meets a threshold condition;

[0027] The threshold conditions include:

[0028] Sub-condition 1: The frequency and time interval between mouse clicks show a repetitive or periodic pattern;

[0029] Sub-condition 2: The number of mouse scrolls exceeds the preset maximum number of scrolls, or the number of scrolls corresponding to the continuous scrolling behavior shows regularity;

[0030] Sub-condition 3: The similarity of the movement trajectories corresponding to multiple mouse movements exceeds the preset similarity threshold;

[0031] Sub-condition 4: The typing time intervals in the keyboard behavior data show regularity or the typing rate is 0;

[0032] Sub-condition 5: The stop point corresponding to multiple mouse moves is the same as the stop point of the previous adjacent move;

[0033] Subcondition 6: The mouse scroll speed is 0;

[0034] When the three sub-conditions in the threshold condition are met, the corresponding real-time user interaction behavior data is regarded as abnormal real-time user interaction behavior data.

[0035] Furthermore, if the verification result is qualified, the activity type of the current session is real user behavior; otherwise, the activity type of the current session is crawler behavior;

[0036] If the activity type is real user behavior, the request of the current session is approved, and the initial ciphertext is decrypted based on the dynamic key to restore the original data; if the activity type is crawler behavior, the request of the current session is rejected and the crawler behavior is blocked.

[0037] A data anti-crawler system based on dynamic encryption of user behavior, comprising:

[0038] User behavior monitoring module, used to monitor user interaction behavior;

[0039] Data collection module, used to collect raw data and real-time user interaction behavior data;

[0040] The key and ciphertext generation module is used to randomly generate the initial encryption key and generate the initial ciphertext based on the original data of crawler activities;

[0041] The user behavior feature value extraction module includes: a real-time user interaction behavior data preprocessing unit for denoising and normalizing the real-time user interaction behavior data to obtain real-time user interaction behavior preprocessing data; a user behavior feature value extraction subunit for extracting user behavior feature values ​​from the real-time user interaction behavior preprocessing data;

[0042] A dynamic key generation module, used to generate a dynamic key based on an initial encryption key and a user behavior characteristic value;

[0043] The legitimacy score calculation module is used to calculate the legitimacy score of user behavior feature values ​​through a machine learning model, extract abnormal real-time user interaction behavior data from the real-time user interaction behavior data, and calculate the proportion of abnormal data;

[0044] User verification module, used to verify the current session using verification code or fingerprint verification and obtain user verification results;

[0045] Verification result judgment module, used to determine the verification result based on the legitimacy score or the proportion of abnormal data or the user verification result;

[0046] The data protection module is used to determine the activity type of the current session and perform data protection based on the verification result.

[0047] Furthermore, it also includes a decryption security verification module and a key fallback module;

[0048] The decryption security verification module is used to decrypt the initial ciphertext based on the dynamic key in the data protection module. If the dynamic key decryption fails, re-verification or triggering the alarm mechanism control instruction to the key fallback module;

[0049] The key fallback module is used to receive the control instructions sent by the decryption security verification module, and generate a temporary key to attempt decryption based on the fallback mechanism through historical legal behavior feature values ​​or auxiliary verification mechanism.

[0050] The beneficial effects of the present invention are:

[0051] The present invention collects real-time user interaction behavior data from the user end, generates corresponding user behavior feature values, and combines them with dynamically regularized multi-layer salt values ​​to generate dynamic keys unique to different users, thereby increasing the inconsistency of the dynamic keys, making it difficult for crawlers to break the keys and imitate the user's complex behavior, thereby improving data security and increasing the difficulty of crawler cracking; capturing abnormal real-time user interaction behavior data, judging the activity type of the current session, improving the effective recognition accuracy of crawler activities, effectively preventing unauthorized crawler programs from crawling website data, improving the protection level of data, and enhancing the randomness and complexity of protection through unique user behavior. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0053] Figure 1This is a flow chart of the method in Example 1 of the present invention;

[0054] Figure 2 This is a system structure diagram in Example 1 of the present invention;

[0055] Figure 3 This is a flow chart of the method under the electronic commodity platform in Example 2 of the present invention;

[0056] Figure 4 This is a flow chart of the method under social network in Example 3 of the present invention. DETAILED DESCRIPTION

[0057] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of the embodiments. The components of the embodiments of the present invention generally described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present invention.

[0058] Example 1:

[0059] See also Figure 1 This embodiment provides a data anti-crawler method based on dynamic encryption of user behavior, which includes:

[0060] S1. Collect real-time user interaction behavior data from the user end and generate user behavior feature values; the real-time user interaction behavior data includes mouse behavior trajectory data and keyboard behavior data; the mouse behavior trajectory data includes the mouse movement trajectory, stop point, click frequency, click position, click time interval, scrolling number, scrolling time and scrolling rate; the keyboard behavior data includes the keyboard typing rate and typing time interval.

[0061] Said S1 comprises:

[0062] S1-1. Real-time user interaction behavior data of the user terminal is collected through real-time monitoring and denoised and normalized to obtain real-time user interaction behavior pre-processed data;

[0063] S1-2. Use a feature extraction algorithm to extract feature vectors from the real-time user interaction behavior preprocessing data to generate user behavior feature values ​​of fixed length; the feature extraction algorithm may adopt a hash function.

[0064] S2. Obtain the original data of the current session on the user side, randomly generate an initial encryption key in real time, and process it to generate the initial ciphertext;

[0065] Use a high-strength random number generator to generate the corresponding initial encryption key K init , determine the generated K init unpredictability.

[0066] Generate initial ciphertext C init The corresponding formula is:

[0067]

[0068] Where D represents the original data, Indicates the encryption function. The encryption function can be AES-256-GCM encryption function.

[0069] S3. Generate a dynamic key based on the initial encryption key and the user behavior feature value;

[0070] The S3 includes:

[0071] S3-1. Set the number of iterations and output length, and set multiple layers of salt values ​​based on dynamic rules; multiple layers of salt values ​​are used to ensure the uniqueness of key derivation, and the number of iterations is used to improve resistance to brute force cracking; the output length is set according to the requirements of the encryption algorithm. In this embodiment, the output length is 256 bits.

[0072] A multi-layered salt value consists of multiple sub-salts, each generated based on different user behavior characteristics, time information, and environmental data. These sub-salts are weighted and combined at different levels to create the final salt value. This allows the salt value to not only change with user behavior but also dynamically adapt to external environmental and temporal factors. In this example, the number of sub-salts is two.

[0073] Thus, the multi-layer salt value setting based on dynamic rules includes:

[0074] S3-1-1. Real-time acquisition of time and environment information for the current session. Environment information includes network latency, geographic location (e.g., the region code in the IP address), and device parameters. Device parameters include screen resolution, display refresh rate, browser type, browser fingerprint, User-Agent string, and operating system information.

[0075] S3-1-2. Generate a time sub-salt value using a hash function (SHA-256 hash function) based on time information and user behavior feature values;

[0076] S3-1-3. Generate an environmental sub-salt value using a hash function (SHA-256 hash function) or encryption algorithm based on environmental information and user behavior feature values;

[0077] S3-1-4. Based on the time sub-salt value and the environment sub-salt value, a multi-layer salt value is generated through weighted calculation; the weighted calculation includes weighted average and weighted XOR operation. In particular, different weighted synthesis strategies are adopted for the time sub-salt value and the environment sub-salt value according to their data types:

[0078] For numerical continuous features (such as timestamp, resolution, etc.) and geographic location information, weighted averaging is used (based on weights such as time decay coefficient and environmental confidence); for discrete or hash-type features (such as User-Agent, IP segment, hash value), weighted XOR synthesis is used to ensure the security and uniqueness of multi-source information fusion.

[0079] The above weighted results are combined to generate the final multi-layer salt value, which is used in the dynamic key derivation function to enhance the uniqueness and unpredictability of the derived key.

[0080] The present invention introduces dynamic regularization, and the resulting multi-layer salt value will be dynamically adjusted as time, environmental information and user behavior change, ensuring that each user session generates a unique salt value that is difficult to predict or simulate.

[0081] S3-2. Construct a key derivation function based on the multi-layer salt value. The key derivation function can use PBKDF2 and HKDF. Since the process of constructing the key derivation function is existing technology, it will not be described in detail.

[0082] S3-3. Based on the initial encryption key and the user behavior characteristic value, a dynamic key is generated through a key derivation function.

[0083] This invention introduces a dynamic key generated from behavioral user characteristics. This key is closely tied to the user. Different users have different operating habits, and even the same user's operations vary from one operation to another. Based on these differences, combined with dynamically regularized, multi-layered salt values, a unique dynamic key is generated for each user, increasing the inconsistency of the dynamic key. Because the dynamic key incorporates the user's specific behavioral habits, it is highly random and personalized, making it difficult for crawlers to crack the key and mimic the user's complex behavior, thereby improving data security.

[0084] S4. Calculate the legitimacy score of the user behavior feature value and verify it to obtain a verification result;

[0085] The S4 includes:

[0086] S4-1. Use a machine learning algorithm to calculate the legitimacy score of the user behavior feature value; the machine learning model can adopt a random forest and a neural network; optionally, the neural network can adopt an LSTM network.

[0087] Screen the user behavior feature values ​​and select the user behavior feature values ​​involving time series (such as mouse tracks, mouse click intervals, keyboard typing intervals) as time-user behavior feature values, and the remaining user behavior feature values ​​as non-time-user behavior feature values;

[0088] Random forest is used to calculate the first legitimacy score of non-time-user behavior feature values;

[0089] A second legitimacy score is calculated using the time-user behavior feature values ​​using an LSTM network. During LSTM network training, historical time-user behavior feature values ​​from real users are collected and labeled as either legal or illegal. All time-historical user behavior feature values ​​are input into the LSTM network to obtain the corresponding second trained legitimacy score. Based on the second trained legitimacy score, the corresponding objective function is calculated, and the LSTM network parameters are adjusted based on the objective function to obtain an initially trained LSTM network. The verified time-historical user behavior feature values ​​are input into the initially trained LSTM network, and the accuracy and recall of the initially trained LSTM network are calculated. When both accuracy and recall reach the preset target values, the trained LSTM network is obtained; otherwise, training is repeated.

[0090] The legitimacy score is calculated based on the first legitimacy score and the second legitimacy score, wherein the legitimacy score may be calculated using a weighted calculation method.

[0091] S4-2. Extracting abnormal real-time user interaction behavior data from the real-time user interaction behavior data;

[0092] Abnormal real-time user interaction behavior data refers to real-time user interaction behavior data that meets the threshold conditions. Since user operation behaviors are generally continuous, such as the smooth changes in mouse trajectory and the natural intervals between clicks and scrolling, and user operations are diverse, their user behavior feature values ​​should include feature values ​​corresponding to mouse, keyboard, scrolling, and other operations. During use, their operation intervals, click frequency, and other behaviors should not show excessively high frequencies or regular patterns. Therefore, the threshold conditions include:

[0093] Sub-condition 1: The frequency and time interval between mouse clicks show a repetitive or periodic pattern;

[0094] Sub-condition 2: The number of mouse scrolling times exceeds a preset maximum number of scrolling times, or the number of scrolling times corresponding to the continuous scrolling behavior is regular; for example, the number of scrolling times corresponding to the continuous scrolling behavior is the same, or increases, decreases, or changes according to a certain function.

[0095] Sub-condition 3: The similarity of the movement trajectories corresponding to multiple mouse movements exceeds a preset similarity threshold.

[0096] Sub-condition 4: The typing time intervals in the keyboard behavior data show regularity or the typing rate is 0; for example, the intervals between multiple consecutive typing times are the same, or n typing time intervals among different typing time intervals are the same, similar to the first typing time interval being the same as the second typing time interval, and the t-th typing time interval to the T-th typing time interval being the same.

[0097] Sub-condition 5: The stop point corresponding to multiple mouse moves is the same as the stop point of the previous adjacent move;

[0098] Sub-condition 6: The scrolling speed of the mouse is 0. When the scrolling speed is 0, it means that the scrolling speed of the mouse is uniform. Real users cannot meet this characteristic of uniform speed when scrolling the mouse.

[0099] When the three sub-conditions in the threshold condition are met, the corresponding real-time user interaction behavior data is regarded as abnormal real-time user interaction behavior data.

[0100] S4-3. Calculate the abnormal data ratio of abnormal real-time user interaction behavior data; the abnormal data ratio refers to the proportion of abnormal real-time user interaction behavior data in all real-time user interaction behavior data.

[0101] S4-4. Determine the verification result based on the legitimacy score and the proportion of abnormal data;

[0102] Determine whether the legitimacy score is greater than the legitimacy score threshold. If so, the verification result is considered qualified, indicating a high degree of consistency between the current user and the real user's historical behavior. Otherwise, determine whether the abnormal data ratio exceeds the abnormal data ratio threshold. If so, the verification result is considered unqualified; otherwise, the verification result is considered qualified. The legitimacy score threshold and abnormal data ratio threshold are set according to actual needs.

[0103] S5. Based on the verification result, determine the activity type of the current session and perform data protection. If the verification result is qualified, the activity type of the current session is real user behavior; otherwise, the activity type of the current session is crawler behavior. If the activity type is real user behavior, agree to the request of the current session, decrypt the initial ciphertext based on the dynamic key, and restore the original data. If the activity type is crawler behavior, reject the request of the current session and prevent the crawler behavior.

[0104] In summary, this method collects real-time user interaction behavior data from the client, generates corresponding user behavior feature values, and combines them with dynamic, regularized, multi-layer salt values ​​to generate dynamic keys unique to each user. This deeply integrates encryption mechanisms with user behavior, ensuring that each user and each session generates a unique key. This significantly increases the difficulty of crawler simulation and enhances data security. The use of a lightweight symmetric encryption algorithm to generate dynamic keys ensures the efficiency of the encryption process, making it particularly suitable for applications in high-concurrency scenarios.

[0105] like Figure 2 As shown, a data anti-crawler system based on dynamic encryption of user behavior includes:

[0106] The user behavior monitoring module is used to monitor user interaction behavior; for example, a script (IavaScript) is embedded in the web page to monitor and record user interaction behavior in real time, that is, to monitor events such as mouse movement, clicks, scrolling, keyboard input, and record event type, timestamp, coordinates and other information.

[0107] Data collection module, used to collect raw data and real-time user interaction behavior data;

[0108] The key and ciphertext generation module is used to randomly generate the initial encryption key and generate the initial ciphertext based on the original data of crawler activities;

[0109] The user behavior feature value extraction module includes: a real-time user interaction behavior data preprocessing unit for denoising and normalizing the real-time user interaction behavior data to obtain real-time user interaction behavior preprocessing data; a user behavior feature value extraction subunit for extracting user behavior feature values ​​from the real-time user interaction behavior preprocessing data;

[0110] A dynamic key generation module, used to generate a dynamic key based on an initial encryption key and a user behavior characteristic value;

[0111] The legitimacy score calculation module is used to calculate the legitimacy score of user behavior feature values ​​through a machine learning model, extract abnormal real-time user interaction behavior data from the real-time user interaction behavior data, and calculate the proportion of abnormal data;

[0112] User verification module, used to verify the current session using verification code or fingerprint verification and obtain user verification results;

[0113] Verification result judgment module, used to determine the verification result based on the legitimacy score or the proportion of abnormal data or the user verification result;

[0114] The data protection module is used to determine the activity type of the current session and perform data protection based on the verification result; when the verification result is qualified, the activity type of the current session is real user behavior; otherwise, the activity type of the current session is crawler behavior; if the activity type is real user behavior, the request of the current conversation is approved, and the initial ciphertext is decrypted based on the dynamic key to restore the original data; if the activity type is crawler behavior, the request of the current session is rejected and the crawler behavior is prevented.

[0115] The system also includes a decryption security verification module and a key rollback module. The decryption security verification module is used to decrypt the initial ciphertext based on the dynamic key in the data protection module. If the dynamic key decryption fails, it will re-verify or trigger the control instruction of the alarm mechanism to the key rollback module.

[0116] The key fallback module is used to receive the control instructions sent by the decryption security verification module and generate a temporary key to attempt decryption based on the fallback mechanism through the historical legal behavior feature value or auxiliary verification mechanism. The fallback mechanism includes:

[0117] 1) Fallback decryption based on historical behavior feature values;

[0118] 2) Auxiliary decryption based on dynamically generated one-time keys after human-machine verification;

[0119] 3) When both fallback decryption and auxiliary decryption fail, the key fallback module will perform behavior logging and security alarm processing.

[0120] This system introduces a key fallback module, which is beneficial to enhancing the system's fault tolerance and user identification robustness.

[0121] In summary, this system verifies user behavior feature values ​​to ensure that real-time user interaction behavior data has not been forged or tampered with, and combines machine learning algorithms to monitor user behavior in real time and identify abnormal behavior patterns, further improving the protection effect, preventing crawlers from bypassing protection by simulating normal user behavior, and improving the protection level of data.

[0122] Example 2:

[0123] On e-commerce platforms, user access behavior generates unique behavioral signatures. Combined with the platform's product information, the server returns encrypted product data. Only legitimate user behavior can decrypt product data, preventing crawlers from effectively obtaining product information.

[0124] Thus, if Figure 3 As shown, the method in Example 1 is applied to the scenario of an e-commerce platform, and the corresponding steps are:

[0125] A1. When a user visits a product page on an e-commerce platform, real-time user interaction behavior data is collected and used to generate user behavior feature values. Real-time user interaction behavior data also includes product browsing time and product click frequency.

[0126] A2. Obtain the original data of the current session on the user end, randomly generate an initial product encryption key in real time, and process it to generate the initial product ciphertext;

[0127] A3. Generate a dynamic product key based on the initial encryption key and the user behavior feature value;

[0128] A4. Calculate and verify the legitimacy score of the user behavior feature value to obtain the product verification result.

[0129] A5. Based on the product verification results, determine the product activity type of the current session and perform data protection. If the product verification result is qualified, the product activity type of the current session is real user behavior; otherwise, the product activity type of the current session is crawler behavior;

[0130] If the product activity type is real user behavior, the request of the current session is approved, and the initial product ciphertext is decrypted based on the dynamic product key to restore the original data and display the product information of the e-commerce platform; if the product activity type is crawler behavior, the request of the current session is rejected and the crawler behavior is blocked.

[0131] Example 3:

[0132] In social networks, user personal information and dynamics are protected through encryption algorithms. User behavior data is used as the input for encryption keys to prevent crawlers from capturing large amounts of user data.

[0133] Thus, if Figure 4 As shown, the method in Example 1 is applied to the scenario of social network, and the corresponding steps are:

[0134] B1. Users log in to social networks and collect real-time user interaction behavior data from the user end to generate user behavior feature values. Real-time user interaction behavior data also includes social posting frequency and social interaction patterns.

[0135] B2. Obtain the original data of the current session on the user side, randomly generate an initial social encryption key in real time, and process it to generate the initial social ciphertext;

[0136] B3. Generate a dynamic social key based on the initial encryption key and user behavior feature value;

[0137] B4. Calculate and verify the legitimacy score of the user behavior feature value to obtain the social verification result;

[0138] B5. Based on the social verification results, determine the social activity type of the current session and perform data protection. If the social verification result is qualified, the social activity type of the current session is real user behavior; otherwise, the social activity type of the current session is crawler behavior;

[0139] If the social activity type is real user behavior, the request of the current conversation is agreed, and the initial social ciphertext is decrypted based on the dynamic key to restore the original data and display the social user information; if the social activity type is crawler behavior, the request of the current session is rejected and the crawler behavior is blocked.

[0140] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A data anti-crawler method based on dynamic encryption of user behavior, characterized in that: include: Collect real-time user interaction behavior data from the user end and generate user behavior feature values; Real-time user interaction behavior data includes mouse behavior trajectory data and keyboard behavior data; Obtain the original data of the current session on the user side, randomly generate the initial encryption key in real time and process it to generate the initial ciphertext; Generate a dynamic key based on the initial encryption key and user behavior feature value; Calculate the legitimacy score of the user behavior feature value and verify it to obtain the verification result; Based on the verification results, determine the activity type of the current session and perform data protection; Generating a dynamic key includes: Set the number of iterations and output length, and set multiple layers of salt based on dynamic rules; Construct a key derivation function based on multiple layers of salt values; Based on the initial encryption key and the user behavior characteristic value, a dynamic key is generated through a key derivation function; The multi-layer salt value setting based on dynamic rules includes: Real-time acquisition of the current session's time and environment information; environment information includes network latency, geographic location, and device parameters; device parameters include screen resolution, display refresh rate, browser type, User-Agent string, and operating system information; Based on time information and user behavior feature values, a time sub-salt value is generated using a hash function; Based on the environmental information and user behavior feature values, a hash function or encryption algorithm is used to generate an environmental sub-salt value; Based on the time sub-salt value and the environment sub-salt value, multi-layer salt values ​​are generated through weighted calculation.

2. The data anti-crawler method based on dynamic encryption of user behavior according to claim 1 is characterized in that: The mouse behavior trajectory data includes the mouse movement trajectory, stop point, click frequency, click position, click time interval, scrolling times, scrolling time and scrolling speed; the keyboard behavior data includes the keyboard typing speed and typing time interval.

3. The data anti-crawler method based on dynamic encryption of user behavior according to claim 1 is characterized in that: The calculation of the legitimacy score of the user behavior feature value and verification to obtain the verification result includes: Utilize machine learning algorithms to calculate the legitimacy score of user behavior feature values; Extracting abnormal real-time user interaction behavior data from real-time user interaction behavior data; Calculate the abnormal data ratio of abnormal real-time user interaction behavior data; The verification result is determined based on the legitimacy score and the proportion of abnormal data.

4. The data anti-crawler method based on dynamic encryption of user behavior according to claim 3 is characterized in that: The abnormal real-time user interaction behavior data refers to real-time user interaction behavior data that meets the threshold condition; The threshold conditions include: Sub-condition 1: The frequency and time interval between mouse clicks show a repetitive or periodic pattern; Sub-condition 2: The number of mouse scrolls exceeds the preset maximum number of scrolls, or the number of scrolls corresponding to the continuous scrolling behavior shows regularity; Sub-condition 3: The similarity of the movement trajectories corresponding to multiple mouse movements exceeds the preset similarity threshold; Sub-condition 4: The typing time intervals in the keyboard behavior data show regularity or the typing rate is 0; Sub-condition 5: The stop point corresponding to multiple mouse moves is the same as the stop point of the previous adjacent move; Subcondition 6: The mouse scroll speed is 0; When the three sub-conditions in the threshold condition are met, the corresponding real-time user interaction behavior data is regarded as abnormal real-time user interaction behavior data.

5. The data anti-crawler method based on dynamic encryption of user behavior according to claim 1 is characterized in that: If the verification result is qualified, the activity type of the current session is real user behavior; Otherwise, the activity type of the current session is crawler behavior; If the activity type is real user behavior, the request of the current conversation is accepted, and the initial ciphertext is decrypted based on the dynamic key to restore the original data; If the activity type is crawler behavior, the request for the current session is rejected and the crawler behavior is prevented.

6. A data anti-crawler system based on dynamic encryption of user behavior, used to implement the data anti-crawler method based on dynamic encryption of user behavior according to any one of claims 1 to 5, characterized in that: include: User behavior monitoring module, used to monitor user interaction behavior; Data collection module, used to collect raw data and real-time user interaction behavior data; The key and ciphertext generation module is used to randomly generate the initial encryption key and generate the initial ciphertext based on the original data of crawler activities; The user behavior feature value extraction module includes: a real-time user interaction behavior data preprocessing unit for denoising and normalizing the real-time user interaction behavior data to obtain real-time user interaction behavior preprocessing data; a user behavior feature value extraction subunit for extracting user behavior feature values ​​from the real-time user interaction behavior preprocessing data; A dynamic key generation module, used to generate a dynamic key based on an initial encryption key and a user behavior characteristic value; The legitimacy score calculation module is used to calculate the legitimacy score of user behavior feature values ​​through a machine learning model, extract abnormal real-time user interaction behavior data from the real-time user interaction behavior data, and calculate the proportion of abnormal data; User verification module, used to verify the current session using verification code or fingerprint verification and obtain user verification results; Verification result judgment module, used to determine the verification result based on the legitimacy score or the proportion of abnormal data or the user verification result; The data protection module is used to determine the activity type of the current session and perform data protection based on the verification result.

7. The data anti-crawler system based on dynamic encryption of user behavior according to claim 6, characterized in that: It also includes a decryption security verification module and a key fallback module; The decryption security verification module is used to decrypt the initial ciphertext based on the dynamic key in the data protection module. If the dynamic key decryption fails, re-verification or triggering the alarm mechanism control instruction to the key fallback module; The key fallback module is used to receive the control instructions sent by the decryption security verification module, and generate a temporary key to attempt decryption based on the fallback mechanism through historical legal behavior feature values ​​or auxiliary verification mechanism.

Citation Information

Patent Citations

  • User monitoring system based on artificial intelligence

    CN110910204A

  • Crawler detection method based on browser feature detection and event monitoring

    CN111090856A

  • Crawler identification method and device, equipment, medium and product

    CN114036364A

  • Anti-crawler headless browser detection and identification method and device

    CN116389069A

  • Anti-crawler method

    CN117714196A

Cited By

  • Browser tab page data storage method supporting data encryption

    CN121167054A

  • Browser tab page data storage methods that support data encryption

    CN121167054B