Method and apparatus for detecting a site of a pirated link

By extracting keywords and link jump flows in network behavior data and matching them with the authorized site collection of target pages, unauthorized links are identified, which solves the security problem of link theft on the Internet and improves the security of website access.

CN110298006BActive Publication Date: 2025-05-27BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910579576.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-06-28
Publication Date
2025-05-27
Estimated Expiration
2039-06-28

AI Technical Summary

Technical Problem

Some website links on the Internet are often stolen by unauthorized websites, resulting in the security cannot be guaranteed.

Method used

By obtaining network behavior data, extracting keywords and keyword-related link jump streams, based on these data and the preset authorized site collection of target pages, the corresponding sites in the link jump stream that are not authorized by the target page are determined.

Benefits of technology

It uses massive network behavior data to monitor link theft behavior, thereby improving the security of website access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110298006B_ABST
    Figure CN110298006B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a method, apparatus, electronic device, and computer-readable medium for detecting sites that steal links. A specific implementation of the method includes: obtaining network behavior data; extracting keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords; determining, based on the keywords, the link jump flows related to the keywords, and a preset authorized site set of a target page, sites corresponding to links in the link jump flows that are not authorized by the target page, where the target page is the page to which the link jump flow jumps. This implementation can monitor link stealing behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technologies, specifically to network data processing methods, and particularly to methods and devices for detecting sites that steal links. Background Art

[0002] In the Internet, some website links have high requirements for link security, such as the links of bank websites. These websites usually authorize some other sites to use their links so that users can securely jump to these websites through the links provided by the authorized sites.

[0003] However, these website links are often stolen by some unauthorized websites, and the security cannot be guaranteed when accessing through unauthorized websites. Summary of the Invention

[0004] Embodiments of the present disclosure provide a method, a device, an electronic device, and a computer-readable medium for detecting a site that steals a link.

[0005] In a first aspect, an embodiment of the present disclosure provides a method for detecting a site that steals a link, including: obtaining network behavior data; extracting keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords; determining, based on the keywords, the link jump flows related to the keywords, and a preset authorized site set of a target page, sites corresponding to links in the link jump flows that are not authorized by the target page, where the target page is the page to which the link jump flow jumps.

[0006] In some embodiments, the determining, based on the keywords, the link jump flows related to the keywords, and the preset authorized site set of the target page, sites corresponding to links in the link jump flows that are not authorized by the target page includes: performing intent analysis on the keywords to determine target keywords that include the intent to access a preset page; using the link jump flow related to the target keywords as a target link jump flow, and determining the target page to which the target link jump flow jumps; determining, based on the target link jump flow and the preset authorized site set of the target page, sites corresponding to links in the link jump flows that are not authorized by the target page.

[0007] In some embodiments, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the target link jump flow and the preset authorized site set of the target page includes: parsing the target link jump flow to obtain at least one sub-link included in the target link jump flow; performing data crawling on the sites corresponding to the sub-links, and determining whether the sites corresponding to the sub-links include the link jump behavior represented by the target link jump flow according to the crawled data; in response to determining that the sites corresponding to the sub-links include the link jump behavior represented by the target link jump flow, determining whether the sites corresponding to the sub-links are in the preset authorized site set of the target page; if the sites corresponding to the sub-links are not in the preset authorized site set of the target page, determining the sub-links as the links not authorized by the target page.

[0008] In some embodiments, performing intent analysis on the network behaviors related to the keywords to determine the target keywords that include the intent to access the preset page includes: using the keywords that match the intent keywords in the preset intent keyword set among the extracted keywords as the target keywords, where the preset intent keyword set includes the intent keywords that have been determined to include the intent to access the preset page.

[0009] In some embodiments, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the keywords, the link jump flow related to the keywords, and the preset authorized site set of the target page includes: in response to determining that the sites corresponding to the links included in the link jump flow are not in the preset authorized site set of the target page, inputting the keywords and the link jump flow related to the keywords into the trained recognition model to identify the sites corresponding to the links in the link jump flow that are not authorized by the target page; where the recognition model is trained based on the keyword features and link jump flow features related to the known unauthorized sites of the target page.

[0010] In a second aspect, an embodiment of the present disclosure provides a device for detecting sites that steal links, including: an acquisition unit configured to acquire network behavior data; an extraction unit configured to extract keyword features and link jump features from the network behavior data to obtain keywords and a link jump flow related to the keywords; a detection unit configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the keywords, the link jump flow related to the keywords, and the preset authorized site set of the target page, where the target page is the page that the link jump flow jumps to.

[0011] In some embodiments, the above detection unit is further configured to determine the sites corresponding to the links in the link jump stream that are not authorized by the target page in the following manner: perform intent analysis on the keywords to determine target keywords that include the intent to access a preset page; use the link jump stream related to the target keywords as the target link jump stream, and determine the target page to which the target link jump stream jumps; based on the target link jump stream and the preset authorized site set of the target page, determine the sites corresponding to the links in the link jump stream that are not authorized by the target page.

[0012] In some embodiments, the above detection unit is further configured to determine the sites corresponding to the links in the link jump stream that are not authorized by the target page in the following manner: parse the target link jump stream to obtain at least one sub-link included in the target link jump stream; perform data crawling on the sites corresponding to the sub-links, and determine whether the sites corresponding to the sub-links include the link jump behavior characterized by the target link jump stream according to the crawled data; in response to determining that the site corresponding to the sub-link includes the link jump behavior characterized by the target link jump stream, determine whether the site corresponding to the sub-link is in the preset authorized site set of the target page; if the site corresponding to the sub-link is not in the preset authorized site set of the target page, determine the sub-link as a link not authorized by the target page.

[0013] In some embodiments, the above detection unit is further configured to perform intent analysis on the network behaviors related to the keywords in the following manner to determine target keywords that include the intent to access a preset page: use the keywords that match the intent keywords in the preset intent keyword set among the extracted keywords as the target keywords, where the preset intent keyword set includes the intent keywords that have been determined to include the intent to access a preset page.

[0014] In some embodiments, the above detection unit is further configured to determine the sites corresponding to the links in the link jump stream that are not authorized by the target page in the following manner: in response to determining that the site corresponding to the link included in the link jump stream is not in the preset authorized site set of the target page, input the keywords and the link jump stream related to the keywords into a trained recognition model to identify the sites corresponding to the links in the link jump stream that are not authorized by the target page; where the recognition model is trained based on the keyword features and link jump stream features related to the known unauthorized sites of the target page.

[0015] In a third aspect, an embodiment of the present disclosure provides an electronic device, including: one or more processors; a storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the method for detecting sites of misappropriated links provided in the first aspect.

[0016] In a fourth aspect, embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, it implements the method for detecting a site that steals links provided in the first aspect.

[0017] The method and apparatus for detecting a site that steals links, an electronic device, and a computer-readable medium provided by the embodiments of the present disclosure obtain network behavior data, extract keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords, and determine, based on the keywords, the link jump flows related to the keywords, and a preset authorized site set of a target page, sites corresponding to links in the link jump flows that are not authorized by the target page, where the target page is the page to which the link jump flow jumps, thereby realizing monitoring of link stealing behavior using a large amount of network behavior data and improving the security of website access. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Other features, objects, and advantages of the present application will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings:

[0019] Figure 1 is an exemplary system architecture diagram to which embodiments of the present disclosure can be applied;

[0020] Figure 2 is a flowchart of an embodiment of the method for detecting a site that steals links according to the present disclosure;

[0021] Figure 3 is a flowchart of another embodiment of the method for detecting a site that steals links according to the present disclosure;

[0022] Figure 4 is a schematic diagram of the effect of the link jump flow parsing process;

[0023] Figure 5 A schematic structural diagram of an embodiment of the apparatus for detecting a site that steals links according to the present disclosure;

[0024] Figure 6 is a schematic structural diagram of a computer system of an electronic device suitable for implementing embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only for explaining the related invention and not for limiting the invention. Additionally, it should be noted that for the sake of description, only parts related to the relevant invention are shown in the drawings.

[0026] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0027] Figure 1 An exemplary system architecture is shown that can apply the method for detecting a website with stolen links or the device for detecting a website with stolen links of the present application.

[0028] As Figure 1 shown, the system architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used as a medium to provide a communication link between the terminal devices 101, 102, 103 and the server 105. The network may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0029] The terminal devices 101, 102, 103 may be electronic devices with a display screen, such as a smart phone, a laptop computer, a desktop computer, a tablet computer, a smart watch, etc. Various resource access applications may be installed on the terminal devices 101, 102, 103, such as search applications, audio and video playback applications, information clients, browser applications, social platform software, etc. Users can use various applications in the terminal devices 101, 102, 103 to obtain network resources.

[0030] The server 105 may be a server that provides background support for various applications on the terminal devices 101, 102, 103. For example, it may be the background server of a search engine. The server 105 can obtain the network access behavior data of users through the terminal devices 101, 102, 103, and analyze and detect the network resources based on the network access behavior data of a large number of users, determine the unsafe network resource data, and perform corresponding warning or blocking processing.

[0031] It should be noted that the server 105 may be hardware or software. When the server 105 is hardware, it can be implemented as a distributed server cluster composed of multiple servers, or as a single server. When the server 105 is software, it can be implemented as multiple software or software modules (such as multiple software or software modules for providing distributed services), or as a single software or software module. No specific limitation is made here.

[0032] The above terminal devices 101, 102, and 103 can also be software. When the terminal devices 101, 102, and 103 are software, they can be installed in the above-listed electronic devices. They can be implemented as multiple software or software modules (such as multiple software or software modules for providing distributed services), or can be implemented as a single software or software module. No specific limitation is made here.

[0033] It should be noted that the method for detecting a site with a stolen link provided by the embodiments of the present disclosure can be executed by the server 105. Correspondingly, the device for detecting a site with a stolen link can be disposed in the server 105.

[0034] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in

[0035] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 2 Continuing to refer to

[0036] which shows a flow 200 of an embodiment of the method for detecting a site with a stolen link according to the present disclosure. The method for detecting a site with a stolen link includes the following steps:

[0037] In this embodiment, the execution subject of the method for detecting a site with a stolen link (such as Figure 1 the server shown) can collect network behavior data of a large number of users, or can receive network behavior data of a large number of users from other electronic devices. Here, the network behavior data is access behavior data generated when users access the network, such as data generated by accessing network resources through a browser or various application software, and can include search data, social platform data, browsing records, forum communication data, online shopping data, and so on.

[0038] In practice, users can access network data through application programs installed on user-side electronic devices (such as mobile phones, computers, etc.), such as searching for information through a search engine, watching audio and video resources through an audio and video playback application, accessing specified page content through a browser, and posting articles through a forum application or a social platform application. The background servers of each application can obtain the access behavior data generated when users access the network through the corresponding application programs, including the text, pictures, and voices input by users, and the operation data such as the operation objects and operation times of the users' clicks, searches, browsing, subscriptions, likes, and other operations. The above execution subject can obtain the network behavior data by establishing a connection with the background servers of each application.

[0039] Step 202: Extract keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords.

[0040] Subsequently, text-related data can be filtered out from the network behavior data, such as search information, articles published in social platforms and forum applications, etc., for keyword feature extraction. Specifically, the text-related data can be tokenized first, and then keyword analysis techniques can be used to extract keywords. For example, algorithms such as PLSA (Probabilistic Latent Semantic Analysis) can be used to extract keywords.

[0041] Link-related data can be extracted from the network behavior data, such as data related to the automatic jump behavior of pages and data related to the user's click behavior on links, and then the link jump flow can be extracted from the link-related data. Here, the link jump flow represents the jump timing behavior of clicking on a link. For example, a link jump timing behavior is: jumping from site A to site B, and then jumping to site C after clicking on the link to site C in site B. Then a link jump flow can be obtained as: "A→B→C".

[0042] In this embodiment, the keyword features and link jump flow features can be associated and extracted to obtain keywords and link jump flows related to the keywords. Here, the link jump flow related to the keyword refers to the link jump flow formed by realizing link jumps based on operations related to the keyword. For example, in the search results based on a search keyword, the user clicks on one of the links X, and after jumping to the page of link X, the user clicks on the user option that links to page Y in the page of link X. Then the link jump flow from X to Y is related to the search keyword.

[0043] The above execution entity can parse each piece of network behavior data, extract the keywords and link jump behaviors therein, and associate the extracted keywords with the link jump flow.

[0044] Since the extracted link jump flow is related to the keyword, it indicates that the extracted link jump flow is generated due to operations related to the keyword. This can ensure that the links included in the link jump flow extracted in step 202 are available links.

[0045] Step 203: Based on the keywords, the link jump flows related to the keywords, and the preset authorized site set of the target page, determine the sites corresponding to the links in the link jump flow that are not authorized by the target page.

[0046] For the extracted link jump flow, the page it jumps to can be determined as the target page. Optionally, the last page that the link jump flow jumps to is used as the target page. Then, based on the preset authorized site set of the target page, it is determined whether there is a link in the links included in the link jump flow that is not authorized by the target page.

[0047] The preset authorized site set of the target page is defaulted to the whitelist sites provided by the search engine. Optionally, if the target page is a specific site with high security requirements for access paths, such as a bank site or a database site, some sites can be specified in advance as the authorized site set. The behavior of accessing the target page through a site not in the preset authorized site set can be considered a risky access. If a site not in the preset authorized site set accesses the target page through link jump, it can be determined that the site not in the preset authorized site set has the behavior of stealing the link of the target page.

[0048] The above link jump flow can be parsed to obtain all the links passed by the link jump flow, and then it is sequentially determined whether each link is in the preset authorized site set of the target page that the corresponding link jump flow jumps to. If the link in the link jump flow is not in the preset authorized site set of the corresponding target page, it is determined that the site corresponding to the link not authorized by the target page, that is, it is determined that the link is the site that steals the link of the target page.

[0049] Through the above embodiments, by extracting the keyword features and link jump flow features from the massive network data, and analyzing whether the link jump flow contains the link of the site corresponding to the link not authorized by the target page, the sites with link stealing behavior in the network can be detected in batches, realizing the comprehensive monitoring of the link stealing behavior, and then the illegal access behavior can be safely controlled, improving the security of website access.

[0050] In some alternative implementation manners, the site corresponding to the link not authorized by the target page in the links included in the link jump flow can be determined in the following manner: in response to determining that the site corresponding to the link included in the link jump flow is not in the preset authorized site set of the target page, the keyword and the link jump flow related to the keyword are input into the trained recognition model to identify the site corresponding to the link not authorized by the target page in the links included in the link jump flow.

[0051] Here, the recognition model can be trained based on the keyword features and link jump flow features related to known unauthorized sites of the target page. The known unauthorized sites of the target page are sites that are known to be unauthorized by the target page and are included in the sites that jump to the target page through keyword-related operations. The recognition model can output the confidence score of the illegal link that the link included in the link jump flow is a link stealing the target page. When the confidence score is greater than a certain threshold, it can be determined that the corresponding link is an illegal link stealing the target page.

[0052] During training, these known unauthorized sites can be used to extract keyword features and link jump features related to keywords in the same or similar way as in step 202, and then the extracted features are input into the recognition model for identifying sites that steal links. The parameters of the recognition model are adjusted iteratively based on the recognition accuracy of the recognition model. When the recognition accuracy of the recognition model is improved to the preset threshold, the training is stopped to obtain the trained recognition model.

[0053] In this way, after screening through the preset authorized sites of the target page and then using the trained recognition model for further identification and detection, illegal links that steal the links of the target page can be detected more comprehensively and accurately.

[0054] Continue to refer to Figure 3 , which shows a schematic flowchart of another embodiment of the method for detecting sites that steal links according to the present disclosure. As Figure 3 shown, the process 300 of the method for detecting sites that steal links in this embodiment includes the following steps:

[0055] Step 301, obtain network behavior data.

[0056] In this embodiment, the execution subject of the method for detecting sites that steal links can obtain network behavior data generated by collecting data on the network access behaviors of a large number of users from a database. The network behavior data can include search data, social platform data, browsing records, forum communication data, online shopping data, and so on. Each piece of network behavior data can include the network resources accessed by a user during a network access and operation behavior data.

[0057] Step 302, extract keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords.

[0058] Keyword features and link jump features can be extracted from network behavior data. Specifically, for a piece of network behavior data, it can first be determined whether it is text-related data. If so, it is converted into standard text, such as speech-to-text conversion and text regularization processing, and then the text is tokenized, and keyword features are extracted according to a preset keyword library.

[0059] Then, based on specific features of the link behavior (such as specific characters contained in the link or a specific format of the link), link-related data can be extracted from the network behavior data, and a link jump flow can be extracted from the link-related data. The link jump flow represents the jump timing behavior of clicking on a link and includes the links of the pages sequentially passed through in the access path from the first page to the page.

[0060] The above link jump flow and keywords are extracted in an associated manner, that is, the link jump flow is formed by link jump behaviors triggered by operations (such as search, click, etc.) associated with the keywords.

[0061] The above Step 301 and Step 302 are respectively the same as Step 201 and Step 202 of the foregoing embodiment. The specific implementation manners of Step 301 and Step 302 can also respectively refer to the descriptions of Step 201 and Step 202 in the foregoing embodiment, and will not be elaborated here.

[0062] Step 303: Perform intent analysis on the keywords to determine target keywords that contain the intent to access a preset page.

[0063] In this embodiment, intent analysis can be performed on the keywords extracted in Step 302 to determine the page access intent of the user represented by the operations associated with the keywords. Specifically, according to the statistics or modeling results of historical keywords and network access behaviors associated with the historical keywords, the page finally accessed in the network access behaviors associated with the historical keywords can be determined. Then, the keywords extracted in Step 302 are matched with the historical keywords, and the page finally accessed in the network access behaviors associated with the successfully matched historical keywords is used as the page access intent included in the keywords. After performing intent analysis on each of the extracted keywords, the keywords that contain the intent to access a preset page are determined as target keywords.

[0064] Here, the preset page can be a page of a specified page type, such as a page of a bank website or a payment page. The preset page can also be a page in a preset page set. For example, pages of bank websites, payment pages, etc. can be added to the preset page set, and the corresponding page addresses are stored in the page set.

[0065] Optionally, the target keyword can be determined based on a preset set of intent keywords: among the extracted keywords, the keywords that match the intent keywords in the preset set of intent keywords are used as target keywords, where the preset set of intent keywords includes the determined intent keywords that contain the intent to access a preset page.

[0066] In the above method of determining the target keyword based on the preset set of intent keywords, the intent keywords that contain the intent to access a preset page can be preset in advance. For example, "credit card application" is an intent keyword that contains the intent to access the bank credit card application page, and "installment payment" is an intent keyword that contains the intent to access the payment page. When the keyword extracted in step 302 matches this intent keyword, it can be determined that the extracted keyword has the intent to access the preset page corresponding to this intent keyword.

[0067] By pre-collecting intent keywords, constructing a set of intent keywords, and using the method of matching the keywords extracted from the network behavior data with the set of intent keywords, the target keywords that contain the intent to access a preset page can be quickly determined.

[0068] Step 304: Use the link jump flow related to the target keyword as the target link jump flow, and determine the target page to which the target link jump flow jumps.

[0069] The keyword and the link jump flow extracted in the above step 302 are related. Here, the link jump flow related to the target keyword can be determined as the detection object and used as the target link jump flow. Then, determine the page to which the target link jump flow jumps as the target page, and this target page can be one of the above preset pages.

[0070] Step 305: Based on the target link jump flow and the preset authorized site set of the target page, determine the sites corresponding to the links in the link jump flow that are not authorized by the target page.

[0071] The preset authorized site set of the target page determined in step 304 can be obtained. This preset authorized site set contains the sites that have been authorized to access the target page, that is, the behavior of jumping to the target page through these authorized access sites is considered a legal behavior. The behavior of jumping to the target page through a site that is not authorized by the target page (that is, a site not in the preset authorized site set of the target page) is considered an act of stealing the link of the target page, and these sites not in the preset authorized sites of the target page are the sites that steal the link of the target page.

[0072] The target link jump flow can be parsed to extract all the links it contains, that is, the links of each site passed by the target link jump flow, and then it is determined in turn whether the links of these sites are in the preset authorized site set of the above target page. In this way, the links in the target link jump flow that are not in the preset authorized site set of the above target page can be extracted, so as to determine the sites that steal the links of the target page.

[0073] In some alternative implementation manners of this embodiment, after step 304, the sites corresponding to the links in the link jump flow that are not authorized by the target page can be further determined in the following manner:

[0074] First, parse the target link jump flow to obtain at least one sub-link included in the target link jump flow.

[0075] In an exemplary scenario, as Figure 4 shown, the user clicks on link 1 in the search results, jumps to link 2, then jumps to link 3 through the anchor point in the site corresponding to link 2, and then jumps to the bank website homepage through the anchor point in the site corresponding to link 3, generating a link jump flow: link 1 → link 2 → link 3 → bank website homepage. Here, the bank website homepage is the target page. At this time, the sub-links in it can be parsed through parsing this link jump flow: link 1, link 2, link 3.

[0076] Then, perform data crawling on the sites corresponding to the sub-links, and determine whether the sites corresponding to the sub-links contain the link jump behavior characterized by the target link jump flow according to the crawled data.

[0077] A data crawling tool can be used to crawl the page content of the site corresponding to the sub-link. Specifically, the content related to the link jump behavior in the site corresponding to the sub-link can be crawled, such as extracting the anchor points in the page.

[0078] After that, in response to determining that the site corresponding to the sub-link contains the link jump behavior characterized by the target link jump flow, it is determined whether the site corresponding to the sub-link is in the preset authorized site set of the target page; if the site corresponding to the sub-link is not in the preset authorized site set of the target page, it is determined that the sub-link is a link not authorized by the target page.

[0079] It can be determined whether the site corresponding to the sub-link contains an anchor point that jumps to the next link in the link jump flow. That is, it is determined whether there is a link jump behavior in the site corresponding to the sub-link, and whether the link jump behavior in the site corresponding to the sub-link is consistent with the link jump behavior of this sub-link characterized by the link jump flow. In this way, it can be avoided that a site without a link jump behavior is determined as a site that steals the link, ensuring the accuracy of the detected sites that steal the link.

[0080] If it is determined that the site corresponding to the sub-link contains the link jump behavior characterized by the target link jump flow, it is further determined whether the site corresponding to the sub-link is a preset authorized site of the target page to which the target link jump flow jumps. If not, the sub-link is an illegal link that steals the link of the target page.

[0081] Further refer to Figure 5 , as an implementation of the methods shown in the above figures, the present application provides an embodiment of a device for detecting sites of stolen links. This device embodiment corresponds to Figure 2 and Figure 3 the method embodiments shown, and this device can be specifically applied to various electronic devices.

[0082] As Figure 5 shown, the device 500 for detecting sites of stolen links in this embodiment includes: an acquisition unit 501, an extraction unit 502, and a detection unit 503. Among them, the acquisition unit 501 is configured to acquire network behavior data; the extraction unit 502 is configured to extract keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords; the detection unit 503 is configured to determine, based on the keywords, the link jump flows related to the keywords, and the set of preset authorized sites of the target page, the sites corresponding to the links in the link jump flow that are not authorized by the target page, where the target page is the page to which the link jump flow jumps.

[0083] In some embodiments, the above detection unit 503 is further configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page in the following manner: perform intent analysis on the keywords to determine target keywords that include the intent to access a preset page; use the link jump flow related to the target keywords as the target link jump flow, and determine the target page to which the target link jump flow jumps; based on the target link jump flow and the set of preset authorized sites of the target page, determine the sites corresponding to the links in the link jump flow that are not authorized by the target page.

[0084] In some embodiments, the above detection unit 503 is further configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page in the following manner: Parse the target link jump flow to obtain at least one sub-link included in the target link jump flow; Crawl data of the sites corresponding to the sub-links, and determine whether the sites corresponding to the sub-links include the link jump behavior characterized by the target link jump flow according to the crawled data; In response to determining that the site corresponding to the sub-link includes the link jump behavior characterized by the target link jump flow, determine whether the site corresponding to the sub-link is in the preset authorized site set of the target page; If the site corresponding to the sub-link is not in the preset authorized site set of the target page, determine the sub-link as a link not authorized by the target page.

[0085] In some embodiments, the above detection unit 503 is further configured to perform intention analysis on the network behaviors related to keywords in the following manner to determine the target keywords that include the intention of accessing a preset page: Use the keywords extracted that match the intention keywords in the preset intention keyword set as the target keywords, where the preset intention keyword set includes the intention keywords that have been determined to include the intention of accessing a preset page.

[0086] In some embodiments, the above detection unit 503 is further configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page in the following manner: In response to determining that the site corresponding to the link included in the link jump flow is not in the preset authorized site set of the target page, input the keyword and the link jump flow related to the keyword into the trained recognition model to identify the sites corresponding to the links in the link jump flow that are not authorized by the target page; Wherein, the recognition model is trained based on the keyword features and link jump flow features related to the known unauthorized sites of the target page.

[0087] It should be understood that the units described in the apparatus 500 correspond to the respective steps in the method described with reference Figure 2 and Figure 3 Therefore, the operations and features described above for the method also apply to the apparatus 500 and the units included therein, and will not be repeated here.

[0088] The device 500 for detecting sites with pirated links according to the above embodiments of the present disclosure obtains network behavior data through an acquisition unit, and an extraction unit extracts keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords. A detection unit determines, based on the keywords, the link jump flows related to the keywords, and a preset authorized site set of a target page, sites corresponding to links in the link jump flows that are not authorized by the target page, where the target page is the page to which the link jump flow jumps, realizing monitoring of link piracy behavior using a large amount of network behavior data, thereby enhancing the security of website access.

[0089] Reference is made below to Figure 6 , which shows a schematic structural diagram of an electronic device (such as a server in Figure 1 ) 600 suitable for implementing the embodiments of the present disclosure. Figure 6 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0090] As Figure 6 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0091] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had. Figure 6 Each block shown in

[0092] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network via the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-described functions defined in the methods of the embodiments of the present disclosure are performed. It should be noted that the computer-readable medium described in the embodiments of the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiments of the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the embodiments of the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0093] The above computer-readable medium may be included in the above electronic device; or it may exist independently without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: obtain network behavior data; extract keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords; and determine, based on the keywords, the link jump flows related to the keywords, and a preset authorized site set of a target page, sites corresponding to the links in the link jump flows that are not authorized by the target page, where the target page is the page to which the link jump flow jumps.

[0094] Computer program code for performing the operations of the embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0095] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0096] The units involved in the embodiments described in this application can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes an obtaining unit, an extracting unit, and a detecting unit. Among them, the names of these units do not constitute a limitation to the unit itself in some cases. For example, the obtaining unit can also be described as "the unit for obtaining network behavior data".

[0097] The above description is only the preferred embodiment of this application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) disclosed in this application that have similar functions.

Claims

1. A method for detecting sites with pirated links, including: Obtaining network behavior data; Extracting keyword features and link jump features from the network behavior data to obtain keywords and link jump flows related to the keywords. The link jump flow represents the jump timing behavior of clicking on a link and includes the links of the pages sequentially passed through in the access path from the first page to the target page; Based on the keywords, the link jump flows related to the keywords, and the preset authorized site set of the target page, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page, including: parsing the link jump flow to obtain all the links passed through by the link jump flow, and then sequentially determining whether the site corresponding to each link is in the preset authorized site set of the target page to which the corresponding link jump flow jumps, and determining the sites corresponding to the links in the link jump flow that are not authorized by the target page. The target page is the page to which the link jump flow jumps.

2. The method according to claim 1, wherein, the determining the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the keywords, the link jump flows related to the keywords, and the preset authorized site set of the target page includes: Performing intention analysis on the keywords to determine target keywords that include the intention of accessing a preset page; Regarding the link jump flow related to the target keywords as the target link jump flow and determining the target page to which the target link jump flow jumps; Based on the target link jump flow and the preset authorized site set of the target page, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page.

3. The method according to claim 2, wherein, the determining the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the target link jump flow and the preset authorized site set of the target page includes: Parsing the target link jump flow to obtain at least one sub-link included in the target link jump flow; Performing data crawling on the site corresponding to the sub-link and determining whether the site corresponding to the sub-link includes the link jump behavior represented by the target link jump flow according to the crawled data; In response to determining that the site corresponding to the sub-link includes the link jump behavior represented by the target link jump flow, determining whether the site corresponding to the sub-link is in the preset authorized site set of the target page; If the site corresponding to the sub-link is not in the preset authorized site set of the target page, determining the sub-link as a link not authorized by the target page.

4. The method according to claim 2 or 3, wherein, the performing intention analysis on the network behavior related to the keywords to determine target keywords that include the intention of accessing a preset page includes: Among the extracted keywords, the keywords that match the intent keywords in the preset intent keyword set are used as target keywords, where the preset intent keyword set includes the determined intent keywords that contain the intent of accessing a preset page.

5. The method according to claim 1, wherein, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the keywords, the link jump flow related to the keywords, and the preset authorized site set of the target page includes: In response to determining that the site corresponding to the link included in the link jump flow is not in the preset authorized site set of the target page, inputting the keywords and the link jump flow related to the keywords into a trained recognition model to identify the sites corresponding to the links in the link jump flow that are not authorized by the target page; wherein the recognition model is trained based on the keyword features and link jump flow features related to the known unauthorized sites of the target page.

6. An apparatus for detecting sites that pirate links, comprising: an acquisition unit configured to acquire network behavior data; an extraction unit configured to extract keyword features and link jump features from the network behavior data to obtain keywords and a link jump flow related to the keywords, where the link jump flow represents the jump timing behavior of clicking a link and includes the links of the pages sequentially passed through in the access path from the first page to the target page; a detection unit configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page based on the keywords, the link jump flow related to the keywords, and the preset authorized site set of the target page, where the target page is the page to which the link jump flow jumps; The detection unit is specifically configured to parse the link jump flow to obtain all the links passed through by the link jump flow, and then sequentially determine whether the site corresponding to each link is in the preset authorized site set of the target page to which the corresponding link jump flow jumps, so as to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page.

7. The apparatus according to claim 6, wherein, the detection unit is further configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page in the following manner: Performing intent analysis on the keywords to determine target keywords that contain the intent of accessing a preset page; Regarding the link jump flow related to the target keywords as the target link jump flow and determining the target page to which the target link jump flow jumps; Based on the target link jump flow and the preset authorized site set of the target page, determining the sites corresponding to the links in the link jump flow that are not authorized by the target page.

8. The apparatus according to claim 7, wherein, the detection unit is further configured to determine the sites corresponding to the links in the link jump flow that are not authorized by the target page in the following manner: Parse the target link jump flow to obtain at least one sub-link included in the target link jump flow; Perform data crawling on the site corresponding to the sub-link, and determine whether the site corresponding to the sub-link contains the link jump behavior characterized by the target link jump flow according to the crawled data; In response to determining that the site corresponding to the sub-link contains the link jump behavior characterized by the target link jump flow, determine whether the site corresponding to the sub-link is in the preset authorized site set of the target page; If the site corresponding to the sub-link is not in the preset authorized site set of the target page, determine that the sub-link is a link unauthorized by the target page.

9. The apparatus according to claim 7 or 8, wherein, The detection unit is further configured to perform intention analysis on the network behavior related to the keyword in the following manner to determine a target keyword including an intention to access a preset page: Use the keyword that successfully matches the intention keyword in the preset intention keyword set among the extracted keywords as the target keyword, where the preset intention keyword set includes the determined intention keyword including the intention to access the preset page.

10. The apparatus according to claim 6, wherein, The detection unit is further configured to determine the site corresponding to the link unauthorized by the target page among the links included in the link jump flow in the following manner: In response to determining that the site corresponding to the link included in the link jump flow is not in the preset authorized site set of the target page, input the keyword and the link jump flow related to the keyword into the trained recognition model to identify the site corresponding to the link unauthorized by the target page among the links included in the link jump flow; wherein the recognition model is trained based on the keyword features and link jump flow features related to the known unauthorized sites of the target page.

11. An electronic device, comprising: One or more processors; A storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-5.

12. A computer-readable medium, on which a computer program is stored, wherein, When the program is executed by a processor, it implements the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Method and system for treating information safety

    CN102902722A

  • Method and device for detecting phishing website

    CN103428186A