Network Access Analysis Method, Device, Computer Equipment and Storage Medium

By extracting and analyzing the target fields and field values in the URL, determining their types, and generating access parsing results, the problem of inefficient URL query of unknown parameters is solved, and efficient URL query is achieved.

CN112579931BActive Publication Date: 2025-07-11TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011437017.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-11
Publication Date
2025-07-11
Estimated Expiration
2040-12-11

AI Technical Summary

Technical Problem

In the prior art, users are unable to efficiently query URLs of unknown parameters, resulting in low URL query efficiency.

Method used

By obtaining the target access address set, the target field and field values in each access address are extracted, the field type is determined based on the characteristic information of the field value, and the access parsing results are generated to process the access address to be queried.

Benefits of technology

It improves the efficiency of URL query, so that users can query the corresponding access address without knowing the detailed parameters of the access address to be queried, simplifying the query process of access address.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112579931B_ABST
    Figure CN112579931B_ABST
Patent Text Reader

Abstract

The present application relates to a network access analysis method, apparatus, computer device, and storage medium. The method includes: obtaining a set of target access addresses; the set of target access addresses includes a plurality of target access addresses; extracting target fields and corresponding field values included in each target access address; determining a field type of a corresponding target field based on feature information of each field value corresponding to the same target field; generating an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on a to-be-processed access address. Using this method can improve the efficiency of access query and access analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a network access analysis method, apparatus, computer device, and storage medium. Background Art

[0002] With the development of computer technology, information resources on the network are becoming increasingly rich. Users can access resources on the network through a URL (Uniform Resource Locator). A URL refers to the unified and unique address of an information resource on the network.

[0003] In traditional technologies, for the query of a URL, the user needs to accurately know the parameters included in the URL to be queried and query the corresponding URL based on the known parameters. However, for a URL with unknown parameters, the user cannot query the corresponding URL, resulting in low URL query efficiency. Summary of the Invention

[0004] Based on this, it is necessary to provide a network access analysis method, apparatus, computer device, and storage medium that can improve the URL query efficiency for the above technical problems.

[0005] A network access analysis method, the method includes:

[0006] Obtain a set of target access addresses; the set of target access addresses includes multiple target access addresses;

[0007] Extract the target fields and corresponding field values included in each target access address;

[0008] Determine the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field;

[0009] Generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on the access address to be processed.

[0010] In one embodiment, obtaining the set of target access addresses includes: obtaining multiple candidate access addresses; aggregating the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface; and determining the set of target access addresses from each set of candidate access addresses.

[0011] In one embodiment, aggregating candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface, including: extracting access host information and access path information included in the candidate access addresses; aggregating candidate access addresses corresponding to the same access host information and access path information to obtain a set of candidate access addresses corresponding to each access interface.

[0012] In one embodiment, extracting target fields and corresponding field values included in each target access address, including: obtaining a segmentation identifier; splitting the target access address into multiple candidate fields and corresponding candidate field values based on the segmentation identifier; determining a target field from the multiple candidate fields based on the type of the segmentation identifier to obtain the target field and the corresponding field value.

[0013] In one embodiment, determining the field type of a corresponding target field based on the characteristic information of each field value corresponding to the same target field, including: counting the occurrence times of each character in each field value corresponding to the current field and the number of field values corresponding to the current field; calculating the occurrence probability of each character based on the occurrence times of each character and the number of field values; determining the probability distance between characters based on the occurrence probability of each character; when the probability distance is less than a second preset threshold, determining that the field type corresponding to the current field is an invalid field type.

[0014] A network access analysis device, the device includes:

[0015] An access address acquisition module, configured to acquire a set of target access addresses; the set of target access addresses includes multiple target access addresses;

[0016] A field information acquisition module, configured to extract target fields and corresponding field values included in each target access address;

[0017] A field type determination module, configured to determine the field type of a corresponding target field based on the characteristic information of each field value corresponding to the same target field;

[0018] An access parsing result determination module, configured to generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on a to-be-processed access address.

[0019] In one embodiment, the access address acquisition module is further configured to acquire multiple candidate access addresses; aggregate candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface; and determine a set of target access addresses from each set of candidate access addresses.

[0020] In one embodiment, the access address acquisition module is further configured to extract the access host information and access path information included in the candidate access addresses; aggregate the candidate access addresses corresponding to the same access host information and access path information to obtain a set of candidate access addresses corresponding to each access interface.

[0021] In one embodiment, the field information acquisition module is further configured to obtain a segmentation identifier; segment the target access address into multiple candidate fields and corresponding candidate field values based on the segmentation identifier; determine a target field from the multiple candidate fields based on the type of the segmentation identifier to obtain the target field and the corresponding field value.

[0022] In one embodiment, the field type determination module is further configured to determine a reference field value from each of the field values corresponding to the current field; determine the reference field type of the current field based on the characteristic information of the reference field value; select a target proportion of the field values corresponding to the current field as intermediate field values; parse the characteristic information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result; when the field value parsing result meets a preset condition, determine that the field type corresponding to the current field is the reference field type.

[0023] In one embodiment, the field type determination module is further configured to parse the characteristic information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type to obtain the field value parsing results corresponding to each field type parsing algorithm; use the preset field type corresponding to the field type parsing algorithm with a successful field value parsing result as the reference field type.

[0024] In one embodiment, the field type determination module is further configured to parse the characteristic information of the reference field value based on the field type parsing algorithm corresponding to the basic field type to obtain a first field value parsing result; the basic field type includes at least one of a time type, a sensitive type, and a service type; parse the characteristic information of the reference field value based on the field type parsing algorithm corresponding to the custom field type to obtain a second field value parsing result; parse the characteristic information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type to obtain a third field value parsing result.

[0025] In one embodiment, the field type determination module is further configured to, when the base field type is a time type, parse the feature information of the reference field value based on at least one time parsing function to obtain a first field value parsing result. The field type determination module is further configured to, when the base field type is a sensitive type, obtain the standard feature information corresponding to multiple preset sensitive information, match the feature information of the reference field value with each standard feature information respectively, and obtain a first field value parsing result according to the matching result. The field type determination module is further configured to, when the base field type is a service type, identify substrings from the reference field value to obtain multiple reference strings, match each reference string with the standard strings in the preset standard dictionary respectively, and obtain a first field value parsing result according to the matching result.

[0026] In one embodiment, the field type determination module is further configured to obtain a configuration file; the configuration file includes multiple custom fields and the field value description information corresponding to each custom field, and the field value description information includes at least one of a regular expression, a logical expression, and an operator expression; match the feature information of the reference field value with the field value description information; and obtain a second field value parsing result according to the matching result.

[0027] In one embodiment, the field type determination module is further configured to calculate the information entropy corresponding to the reference field value according to each character of the reference field value, obtain a standard information entropy, and obtain a third field value parsing result based on the comparison result between the information entropy corresponding to the reference field value and the standard information entropy. The field type determination module is further configured to input the feature information of the reference field value into a field value parsing model to obtain a third field value parsing result; the field value parsing model is trained based on positive field value samples and negative field value samples corresponding to invalid field types.

[0028] In one embodiment, the field type determination module is further configured to calculate a parsing success rate based on the field value parsing result; when the parsing success rate is greater than a first preset threshold, determine that the field type corresponding to the current field is the reference field type.

[0029] In one embodiment, the field type determination module is further configured to count the occurrence times of each character in each field value corresponding to the current field and the number of field values corresponding to the current field; calculate the occurrence probability of each character based on the occurrence times of each character and the number of field values; determine the probability distance between characters based on the occurrence probability of each character; and when the probability distance is less than a second preset threshold, determine that the field type corresponding to the current field is an invalid field type.

[0030] A computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0031] Obtain a set of target access addresses; the set of target access addresses includes multiple target access addresses;

[0032] Extract the target fields and corresponding field values included in each target access address;

[0033] Determine the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field;

[0034] Generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on the access address to be processed.

[0035] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0036] Obtain a set of target access addresses; the set of target access addresses includes multiple target access addresses;

[0037] Extract the target fields and corresponding field values included in each target access address;

[0038] Determine the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field;

[0039] Generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on the access address to be processed.

[0040] A network access analysis method, the method includes:

[0041] Obtain an access query request; the access query request carries the type of the field to be queried corresponding to the access address to be queried;

[0042] Obtain a set of target access addresses and the corresponding access parsing result; the set of target access addresses includes multiple target access addresses, and the access parsing result is obtained by extracting the target fields and corresponding field values included in each target access address, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, and based on each target field and the corresponding field type;

[0043] Obtain the target field corresponding to the type of the field to be queried from the access parsing result;

[0044] Obtain a target query result that matches the target field corresponding to the type of the field to be queried from the set of target access addresses; the target query result includes at least one of the target access address and the field value;

[0045] Return a target query result to the sender corresponding to the access query request.

[0046] A network access analysis device, the device comprising:

[0047] A request acquisition module, configured to acquire an access query request; the access query request carries a to-be-query field type corresponding to a to-be-query access address;

[0048] An access parsing result acquisition module, configured to acquire a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing result is obtained by extracting target fields and corresponding field values included in each target access address, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, and obtaining based on each target field and the corresponding field type;

[0049] A field information determination module, configured to acquire a target field corresponding to the to-be-query field type from the access parsing result;

[0050] A query result determination module, configured to acquire a target query result that matches the target field corresponding to the to-be-query field type from the set of target access addresses; the target query result includes at least one of a target access address and a field value;

[0051] A query result sending module, configured to return the target query result to the sender corresponding to the access query request.

[0052] In one embodiment, the request acquisition module is further configured to acquire an access analysis request; the access analysis request carries a to-be-analyzed access address. The field information determination module is further configured to extract a to-be-analyzed field and a corresponding to-be-analyzed field value included in the to-be-analyzed access address; acquire a target field type corresponding to the to-be-analyzed field from the access parsing result; generate access analysis reference information corresponding to the to-be-analyzed access address based on the target field type and the to-be-analyzed field value. The query result sending module is further configured to return the access analysis reference information to the sender corresponding to the access analysis request.

[0053] A computer device, comprising a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program:

[0054] Acquire an access query request; the access query request carries a to-be-query field type corresponding to a to-be-query access address;

[0055] Obtain a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing results are obtained by extracting the target fields and corresponding field values included in each target access address, determining the field types of the corresponding target fields based on the feature information of each field value corresponding to the same target field, and based on each target field and the corresponding field type;

[0056] Obtain the target field corresponding to the field type to be queried from the access parsing results;

[0057] Obtain a target query result that matches the target field corresponding to the field type to be queried from the set of target access addresses; the target query result includes at least one of a target access address and a field value;

[0058] Return the target query result to the sender corresponding to the access query request.

[0059] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0060] Obtain an access query request; the access query request carries the field type to be queried corresponding to the access address to be queried;

[0061] Obtain a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing results are obtained by extracting the target fields and corresponding field values included in each target access address, determining the field types of the corresponding target fields based on the feature information of each field value corresponding to the same target field, and based on each target field and the corresponding field type;

[0062] Obtain the target field corresponding to the field type to be queried from the access parsing results;

[0063] Obtain a target query result that matches the target field corresponding to the field type to be queried from the set of target access addresses; the target query result includes at least one of a target access address and a field value;

[0064] Return the target query result to the sender corresponding to the access query request.

[0065] The above network access analysis method, device, computer device, and storage medium obtain a set of target access addresses, where the set of target access addresses includes multiple target access addresses, extract the target fields and corresponding field values included in each target access address, determine the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type, and the access parsing result is used to perform access processing on the access address to be processed. In this way, the field type of the corresponding target field can be analyzed based on the feature information of each field value corresponding to the same target field, the function of the target field can be determined based on the field type of the target field, and then when querying the access address later, it is not necessary to know the detailed parameters of the access address to be queried, and the corresponding access address can be queried based on the function of the access address to be queried, improving the query efficiency of the access address. In addition, when analyzing a new access address later, the function of the access address to be analyzed can be determined based on the access parsing result and the specific parameters of the access address to be analyzed. The function of the access address can facilitate the user to quickly understand the access address, so that the access address with a known function can be applied to business analysis and algorithm development. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 FIG. is an application environment diagram of the network access analysis method in an embodiment;

[0067] Figure 2 FIG. is a flowchart of the network access analysis method in an embodiment;

[0068] Figure 3 FIG. is a flowchart of determining the field type of the target field in an embodiment;

[0069] Figure 4 FIG. is a flowchart of determining the reference field type of the current field in an embodiment;

[0070] Figure 5 FIG. is a flowchart of determining the reference field type of the current field in another embodiment;

[0071] Figure 6 FIG. is a flowchart of the network access analysis method in another embodiment;

[0072] Figure 7 FIG. is a flowchart of the network access analysis method in yet another embodiment;

[0073] Figure 8 FIG. is a flowchart of generating an access parsing result in an embodiment;

[0074] Figure 9A FIG. is a schematic diagram of the access parsing interface in an embodiment;

[0075] Figure 9B It is a schematic diagram of an interface for accessing a query interface in an embodiment;

[0076] Figure 9C It is a schematic diagram of an interface for accessing an analysis interface in an embodiment;

[0077] Figure 10 It is a block diagram of the structure of a network access analysis device in an embodiment;

[0078] Figure 11 It is a block diagram of the structure of a network access analysis device in another embodiment;

[0079] Figure 12 It is an internal structure diagram of a computer device in an embodiment;

[0080] Figure 13 It is an internal structure diagram of a computer device in another embodiment. Detailed implementation manners

[0081] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0082] The network access analysis method provided by the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The terminal 102 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices, and the server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0083] Both the terminal 102 and the server 104 can be separately used to execute the network access analysis method provided in the embodiments of the present application. For example, the terminal 102 obtains a set of target access addresses, and the set of target access addresses includes multiple target access addresses. The terminal 102 extracts the target fields and corresponding field values included in each target access address, determines the field type of the corresponding target field based on the feature information of the field values corresponding to the same target field, and generates an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type. The access parsing result is used to perform access processing on the access address to be processed.

[0084] The terminal 102 and the server 104 can also be used in cooperation to execute the network access analysis method provided in the embodiments of the present application. For example, the server 104 obtains a set of target access addresses from the terminal 102, and the set of target access addresses includes multiple target access addresses. The server 104 extracts the target fields and the corresponding field values included in each target access address, determines the field type of the corresponding target field based on the feature information of the field values corresponding to the same target field, and generates an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type. The access parsing result is used to perform access processing on the access address to be processed.

[0085] In one embodiment, as Figure 2 shown, a network access analysis method is provided. Taking the case where this method is applied to Figure 1 the computer device as an example for description, the computer device can be the above Figure 1 terminal 102 or server 104. Referring to Figure 2 , the network access analysis method includes the following steps:

[0086] Step S202, obtain a set of target access addresses, where the set of target access addresses includes multiple target access addresses.

[0087] Among them, the access address refers to the access address of the information resource on the network. For example, the access address can be the URL in the http request, or the post request body in the http request. The set of target access addresses includes multiple target access addresses. The target access address refers to the access address to be processed.

[0088] Specifically, the computer device can obtain the set of target access addresses from different channels, and the channels include but are not limited to various databases, middleware, log files, user input, etc. Among them, the middleware is a type of software between the application system and the system software. It uses the basic services (functions) provided by the system software to connect various parts of the application system on the network or different applications, and can achieve the purpose of resource sharing and function sharing. Therefore, the set of target access addresses can be obtained from the middleware. Usually, the middleware will store the target access addresses in the log file, so the set of target access addresses can be read from the log file.

[0089] In one embodiment, since the target access addresses obtained from different channels are complex, in order to improve the efficiency and accuracy of access processing, the computer device may first use the access addresses obtained from different channels as candidate access addresses, classify each candidate access address, obtain multiple candidate access address sets, and use each candidate access address set as a target access address set for access analysis to obtain the access parsing results corresponding to each candidate access address set. Among them, the classification can specifically be to classify the candidate access addresses corresponding to the same access interface into the same candidate access address set.

[0090] Step S204, extract the target fields and corresponding field values included in each target access address.

[0091] Among them, the target field refers to the target parameter passed through the target access address. At least one parameter can be passed through the access address, and one parameter can correspond to at least one parameter value, that is, at least one target field and the field values corresponding to each target field can be extracted from one access address. Different target access addresses may contain the same target field or different target fields. The same target field may correspond to the same field value or different field values in different target access addresses.

[0092] Specifically, the computer device may extract the target fields and corresponding field values from the target access address based on the structure of the target access address. When the target access address set includes a large number of target access addresses, multiple target fields and multiple field values respectively corresponding to each target field can finally be extracted.

[0093] In one embodiment, get and post are two request methods of http requests. The get request method passes parameters through the URL, so the target parameters and corresponding parameter values can be extracted from the URL. The post request passes parameters through the request body, so the target parameters and corresponding parameter values can be extracted from the request body.

[0094] In one embodiment, extracting the target fields and corresponding field values included in each target access address includes: obtaining a segmentation identifier; segmenting the target access address into multiple candidate fields and corresponding candidate field values based on the segmentation identifier; and determining the target fields from the multiple candidate fields based on the type of the segmentation identifier to obtain the target fields and corresponding field values.

[0095] Among them, the structure of the access address can be [protocol type]: / / [domain name or server address]:[port number] / [directory] / [file name]?[query]#[information segment]. The [protocol type] can correspond to protocols such as the HTTP protocol and the HTTPS protocol that conform to the above structure. The [query] is used to pass target parameters. The number of target parameters passed can be at least one. When multiple target parameters are passed, each target parameter is separated by an "&" symbol, and each target parameter and its corresponding parameter value are separated by an "=" symbol. The delimiter identifiers can be " / ", "&", "?", and "#".

[0096] Specifically, the computer device can split the target access address based on the delimiter identifier, splitting the target access address into multiple candidate fields and corresponding candidate field values. Among them, some candidate fields have no field values, and some candidate fields have corresponding field values. The computer device then determines the target fields from each candidate field based on the type of the delimiter identifier, and finally obtains the target fields and corresponding field values. Specifically, the candidate fields between "?" and "&" can be used as target fields, the candidate fields between "&" and "&" can be used as target fields, and the candidate fields between the last "&" and "#" can be used as target fields. In addition, if the last delimiter identifier is "&", the candidate fields after the last "&" are also used as target fields.

[0097] For example, a target access address is http: / / x.com / index.php?a=1&a=2&b=login. The candidate fields and corresponding field values obtained by splitting based on the delimiter identifier are: http:, x.com, index.php, a=1, a=2, b=login. The target fields among them include "a" and "b". The field values corresponding to the target field "a" include 1 and 2, and the field value corresponding to the target field "b" is login.

[0098] Step S206, determine the field type of the corresponding target field based on the characteristic information of each field value corresponding to the same target field.

[0099] Among them, the characteristic information of the field value includes information such as each character of the field value and the length of the field value.

[0100] Specifically, the target field (target parameter) is often identified by a simple string, which itself does not reflect the specific meaning and function of the target field. However, there are certain commonalities among the field values corresponding to the same target field. Therefore, the field type of the corresponding target field can be determined through big data analysis of the field values, and the specific meaning and function of the target field can be determined based on the field type of the target field. The computer device can determine the field type of the corresponding target field based on the characteristic information of the field values corresponding to the same target field.

[0101] For example, the target field is "a", and the field values corresponding to this target field include "2020-10-26 11:21:23", "1600508494", and "2020 / 8 / 19 17:41:34". Based on the analysis of the characteristic information of the field values, it is obtained that these field values all represent timestamps. Therefore, it can be determined that the field type of the target field "a" is the time type, and the target field "a" is used as a timestamp.

[0102] In one embodiment, the field values corresponding to the target field of a field type have the proprietary characteristics of this field type. Therefore, the corresponding field type parsing algorithm can be set based on the proprietary characteristics of the field type, and the field type of the target field can be determined based on various field type parsing algorithms. Specifically, the computer device can respectively parse the characteristic information of the field values corresponding to the same target field based on the field type parsing algorithms corresponding to each preset field type, and obtain the field value parsing results corresponding to each field type parsing algorithm. When the field value parsing result corresponding to one of the field type parsing algorithms is that most of the field values are successfully parsed or all of the field values are successfully parsed, it can be determined that the field type corresponding to this target field is the preset field type corresponding to this field type parsing algorithm. Among them, the preset field types include at least one of the time type, the sensitive information type, the business type, the custom type, and the invalid type.

[0103] Step S208, generate an access parsing result corresponding to the target access address set based on each target field and the corresponding field type; the access parsing result is used to perform access processing on the access address to be processed.

[0104] Among them, the access address to be processed includes at least one of the access address to be queried and the access address to be analyzed. Correspondingly, the access processing includes at least one of access query and access analysis. The access query is used to query a specific access address or query specific parameters and parameter values from a large number of access addresses. The access analysis is used to analyze the access function of a specific access address.

[0105] Specifically, the computer device can generate an access parsing result corresponding to the target access address set based on each target field and the corresponding field type. The computer device can store the access parsing result locally. For example, it can generate a log file and store it in a database, or it can also display the access parsing result to the user, such as through a page. Subsequently, based on the access parsing result, the computer device can perform at least one of an access query task and an access analysis task.

[0106] In one embodiment, the target field and the corresponding field type can be normalized and output to obtain the access parsing result. For example, the access parsing result can be that the field type of the target field "a" is a time type, and "a" is used as a timestamp, the field type of the target field "b" is a sensitive type, and "b" is used as sensitive information, the field type of the target field "g" is an invalid type, and the "g" parameter is used as a random number. Further, the access parsing result can also include an access interface to distinguish the role of the same target field in the access addresses corresponding to different access interfaces. For example, the field type of the target field "a" in interface A is a time type, and "a" in interface A is used as a timestamp, the field type of the target field "a" in interface B is a sensitive type, and "a" in interface B is used as passing sensitive information. Further, the access parsing result can also include the parsing success rate of the field value. For example, the parsing success rate of the target field "a" in interface A is 80%, the corresponding field type is probably a time type, and the corresponding role is probably used as a timestamp. The parsing success rate can be used as a reference parameter or a usage parameter for business analysts and algorithm developers.

[0107] In one embodiment, performing access analysis can specifically be to obtain an access query request. The access query request carries the to-be-query field type corresponding to the to-be-query access address, obtain the target field corresponding to the to-be-query field type from the access parsing result, obtain the target access information that matches the target field corresponding to the to-be-query field type from the target access address set, where the target access information includes at least one of a target access address and a target field value, and return the target access information to the sender corresponding to the access query request.

[0108] Among them, the access query request is used to request to query at least one access information such as an access address and a field value (parameter value). The to-be-query access address refers to the access address to be queried. The to-be-query field type refers to the field type of the target field included in the to-be-query access address.

[0109] Specifically, when a user wants to query a specific access address or a specific parameter value, the user can set corresponding query conditions and generate an access query request based on the query conditions. The query conditions can specifically be the types of fields to be queried corresponding to the access address to be queried. The computer device can receive the access query request sent by the user through another computer device or the access query request generated locally by the user. After receiving the access query request, the computer device can search for the target field corresponding to the type of field to be queried from the access parsing results corresponding to the target access address set, and then search for the target access information that matches the target field from the target access address set. When the user wants to query a specific access address, the target access information is at least one target access address that matches the target field. When the user wants to query a specific parameter value, the target access information can be at least one field value that matches the target field. Finally, the computer device returns the queried target access information to the sender corresponding to the access query request.

[0110] For example, if the user wants to query the target access addresses that contain time information and sensitive information, the user can trigger the generation of an access query request. The query conditions carried by the access query request can be that the target fields in the access address include fields of time type and sensitive type. After the computer device obtains the access query request, it can query from the access parsing results that the target field corresponding to the time type field is "a" and the target field corresponding to the sensitive type is "b", and then query the target access addresses that contain "a" and "b" from the target access address set, and return the queried target access addresses to the user.

[0111] In one embodiment, the access query request can further carry an access interface to narrow the query scope and improve the query efficiency.

[0112] In one embodiment, performing access analysis can specifically be to obtain an access analysis request. The access analysis request carries the access address to be analyzed, extract the fields to be analyzed and the corresponding values of the fields to be analyzed included in the access address to be analyzed, obtain the type of the target field corresponding to the field to be analyzed from the access parsing results, generate the access analysis reference information corresponding to the access address to be analyzed based on the type of the target field and the value of the field to be analyzed, and return the access analysis reference information to the sender corresponding to the access analysis request.

[0113] Among them, the access analysis request is used to request the analysis of the access address. The access analysis reference information refers to the reference analysis result of the access function of the access address to be analyzed, which is used to describe the access function of the access address to be analyzed for the user's reference.

[0114] Specifically, when a user wants to understand the function of an access address, the user can trigger the generation of an access analysis request, which carries the access address to be analyzed. The computer device can receive the access analysis request sent by the user through other computer devices or the access analysis request generated locally by the user. After receiving the access analysis request, the computer device can extract the corresponding fields to be analyzed and the corresponding field values from the access address to be analyzed, find the field type corresponding to the field to be analyzed from the access parsing result, and generate the access analysis reference information corresponding to the access address to be analyzed based on the field type and field value corresponding to the field to be analyzed. Finally, the computer device can return the access analysis reference information to the sender corresponding to the access analysis request.

[0115] For example, the access address to be analyzed is http: / / x.com / index.php?a=x&b=xx&c=xxx. Based on the access parsing result, it can be known that the field type of "a" is the time type, the field type of "b" is the sensitive type, and the field type of "c" is the business type, and the corresponding business is the query business. Combining the above information, the access analysis reference information for the access address to be analyzed can be obtained as that this access address to be analyzed is applied in the query business scenario, in which sensitive information needs to be transmitted, and this sensitive information is "xx", and "x" represents the timestamp for sending or generating this sensitive information. By checking and receiving this access analysis reference information, the user can generally know the function of this access address to be analyzed, which is helpful for business analysis and algorithm development.

[0116] In the above network access analysis method, by obtaining the set of target access addresses, where the set of target access addresses includes multiple target access addresses, extracting the target fields and the corresponding field values included in each target access address, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, generating the access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type, and the access parsing result is used to perform access processing on the access address to be processed. In this way, based on the feature information of each field value corresponding to the same target field, the field type of the corresponding target field can be analyzed, and based on the field type of the target field, the function of the target field can be determined. Subsequently, when querying the access address, it is not necessary to know the detailed parameters of the access address to be queried, and the corresponding access address can be queried based on the function of the access address to be queried, improving the query efficiency of the access address. In addition, when analyzing a new access address subsequently, based on the access parsing result and the specific parameters of the access address to be analyzed, the function of the access address to be analyzed can be determined, and the function of the access address can facilitate the user to quickly understand the access address, so as to apply the access address with known functions to business analysis and algorithm development.

[0117] In one embodiment, obtaining a set of target access addresses includes: obtaining a plurality of candidate access addresses; aggregating the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface; and determining the set of target access addresses from each set of candidate access addresses.

[0118] Specifically, to improve the efficiency and accuracy of access processing, before processing the access addresses, the computer device can classify the access addresses. The computer device can obtain a large number of candidate access addresses from different channels, and aggregate the candidate access addresses corresponding to the same access interface, that is, classify the candidate access addresses corresponding to the same access interface into one category, so as to obtain a set of candidate access addresses corresponding to each access interface. The computer device can randomly select a set of candidate access addresses from each set of candidate access addresses as the set of target access addresses, or sequentially use each set of candidate access addresses as the set of target access addresses, perform access processing on the set of target access addresses, and obtain the corresponding access parsing result. Among them, when the access host information and access path information in two access addresses are both the same, it can be determined that these two access addresses are access addresses with the same access interface.

[0119] In one embodiment, aggregating the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface includes: extracting the access host information and access path information included in the candidate access addresses; and aggregating the candidate access addresses corresponding to the same access host information and access path information to obtain a set of candidate access addresses corresponding to each access interface.

[0120] Among them, the access host information refers to the access domain name or server address in the access address. The access path information refers to the directory and file name in the access address. For example, http: / / x.com / index.php?a=1 and https: / / x.com / index.php?a=2, although the protocol types are different, one is http and the other is https, but the access host information is the same, both are x.com, and the access path information is the same, both are index.php, so the two have the same interface. http: / / x.com / index.php?a=1 and http: / / x.com / start.php?a=1 do not have the same interface because the access path information is different, one is index.php and the other is start.php. http: / / x.com:8080 / index.php?a=1, http: / / x.com:8088 / index.php?a=1 and http: / / x.com / index.php?a=1 have the same interface, although the port numbers are different, one is 8080, one is 8088, and the other is the default port number 80.

[0121] Specifically, the computer device extracts the access host information and access path information contained in the candidate access address, and aggregates the candidate access addresses corresponding to the same access host information and access path information, that is, classifies the candidate access addresses corresponding to the same access host information and access path information into one category, so as to obtain the set of candidate access addresses corresponding to each access interface.

[0122] It can be understood that the field values of the same target field contained in each candidate access address corresponding to the same access interface have commonalities. Therefore, processing the target fields and the corresponding field values contained in each candidate access address corresponding to the same access interface can obtain a relatively accurate access parsing result. In addition, the candidate access addresses corresponding to different access interfaces may contain the same target field, but the field types corresponding to the target field may be different, and the specific meanings of the target fields may be different. Therefore, processing the target fields and the corresponding field values contained in each candidate access address corresponding to the same access interface can obtain a relatively accurate access parsing result, effectively avoiding the field values of the same target field in the candidate access addresses corresponding to other access interfaces from disturbing the access parsing result corresponding to the current access interface.

[0123] In this embodiment, by aggregating the candidate access addresses corresponding to the same access host information and access path information, the candidate access address sets corresponding to each access interface are obtained, and the target access address set is determined from each candidate access address set, which can ensure that the access interfaces corresponding to the target access addresses in the target access address set are the same, and further ensure the accuracy of the subsequent access resolution result, thereby ensuring the accuracy of the subsequent access analysis and access query.

[0124] In one embodiment, as Figure 3 shown, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field includes:

[0125] Step S302, determine a reference field value from each field value corresponding to the current field.

[0126] Specifically, in order to improve the determination efficiency of the field type of the current field, the computer device can randomly select a field value from each field value corresponding to the current field as the reference field value, first determine a field type as the reference field type from among many field types according to the reference field value, and then determine whether the reference field type is the final field type of the current field according to the remaining field values of the current field. In this way, the determination direction of the field type of the current field can be quickly determined, thereby improving the determination efficiency of the field type of the current field.

[0127] Step S304, determine the reference field type of the current field based on the feature information of the reference field value.

[0128] Specifically, after determining the reference field value, the computer device can determine the reference field type of the current field based on the feature information of the reference field value. Determining the reference field type of the current field can specifically be to parse the feature information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type to obtain the field value parsing results corresponding to each field type parsing algorithm. When the field value parsing result corresponding to one of the field type parsing algorithms is successfully parsed, it can be determined that the reference field type of the current field is the preset field type corresponding to this field type parsing algorithm.

[0129] Step S306, select a target proportion of the field values corresponding to the current field as intermediate field values.

[0130] Step S308, parse the feature information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain the field value parsing result.

[0131] Specifically, after determining the reference field type of the current field, the computer device can select field values with a target proportion from the respective field values corresponding to the current field as intermediate field values. At this time, there is no need to parse the feature information of each intermediate field value based on the field type parsing algorithms corresponding to all preset field types. Instead, the feature information of each intermediate field value can be directly parsed based on the field type parsing algorithm corresponding to the reference field type to obtain the corresponding field value parsing result. The target proportion can be a proportion set according to actual needs, such as 80%.

[0132] Step S310, when the field value parsing result meets the preset condition, determine that the field type corresponding to the current field is the reference field type.

[0133] Specifically, when the field value parsing result obtained by parsing the feature information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type meets the preset condition, the computer device can determine that the field type corresponding to the current field is the reference field type. When the field value parsing result does not meet the preset condition, the computer device can reselect a field value from the respective field values corresponding to the current field as the new reference field value, and repeat the above process until the field value parsing result meets the preset condition, and use the corresponding reference field type as the field type corresponding to the current field.

[0134] In one embodiment, when the field value parsing result meets the preset condition, determining that the field type corresponding to the current field is the reference field type includes: calculating the parsing success rate based on the field value parsing result; when the parsing success rate is greater than the first preset threshold, determining that the field type corresponding to the current field is the reference field type.

[0135] Specifically, the computer device can calculate the parsing success rate according to the field value parsing results respectively corresponding to each intermediate field value. When the calculated parsing success rate is greater than the first preset threshold, the computer device can determine that the field type corresponding to the current field is the reference field type. The first preset threshold can be a threshold set according to actual needs, such as 80%.

[0136] For example, randomly select a field value from each of the field values corresponding to the target field "a" as the reference field value, and parse the reference field value through a time parsing function. If the parsing is successful, it is preliminarily determined that the reference field type of the target field "a" is a time type. If the parsing fails, the reference field value is parsed through other field value parsing algorithms. If the parsing is successful, 80% of the field values corresponding to the target field "a" are taken out as intermediate field values, and each intermediate field value is parsed through the time parsing function. If all can be parsed successfully, it is finally determined that the field type of the target field "a" is a time type, and an access parsing result such as "the 'a' field of the xxx interface is used as a timestamp" can be generated. If not all can be parsed successfully, but the parsing success rate is greater than 80%, it can also be finally determined that the field type of the target field "a" is a time type, and an access parsing result such as "the 'a' field of the xxx interface is used as a timestamp" or "the 'a' field of the xxx interface is probably used as a timestamp" can be generated. If the parsing success rate is 50%, it is considered that the parsing fails, and the reference field value is continuously parsed through other field value parsing algorithms. For example, the characteristic information of the reference field value is matched with the characteristic information of common sensitive information. If the match is successful, it is determined that the parsing is successful, and it is preliminarily determined that the reference field type of the target field "a" is a sensitive type. Further, 80% of the field values corresponding to the target field "a" are taken out as intermediate field values, and the characteristic information of each intermediate field value is matched with the characteristic information of common sensitive information. If all the matches are successful, it is finally determined that the field type of the target field "a" is a sensitive type, and an access parsing result such as "the 'a' field of the xxx interface is used to transmit sensitive information" can be generated. If not all can be parsed successfully, but the parsing success rate is greater than 80%, it can also be finally determined that the field type of the target field "a" is a sensitive type, and an access parsing result such as "the 'a' field of the xxx interface is used to transmit sensitive information" or "the 'a' field of the xxx interface is probably used to transmit sensitive information" can be generated. And so on, the field types of each target field are finally determined.

[0137] In this embodiment, by determining a reference field value from each field value corresponding to the current field, determining a reference field type of the current field based on the characteristic information of the reference field value, selecting a target proportion of field values from each field value corresponding to the current field as intermediate field values, parsing the characteristic information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type, obtaining a field value parsing result, and when the field value parsing result meets a preset condition, determining that the field type corresponding to the current field is the reference field type. In this way, first, preliminarily judge the field type of the current field based on a small sample, and then finally determine the field type of the current field based on a large sample, which can improve the determination efficiency and accuracy of the field type, and further improve the determination efficiency of the access parsing result, thereby improving the efficiency of access query and access analysis.

[0138] In one embodiment, as Figure 4 shown, determining a reference field type of the current field based on the characteristic information of the reference field value includes:

[0139] Step S402, parsing the characteristic information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type, and obtaining the field value parsing results corresponding to each field type parsing algorithm.

[0140] Step S404, taking the preset field type corresponding to the field type parsing algorithm with a successful parsing result of the field value as the reference field type.

[0141] Specifically, the computer device can obtain the field type parsing algorithms corresponding to each preset field type, parse the characteristic information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type, and obtain the field value parsing results corresponding to each field type parsing algorithm. When the field value parsing result corresponding to one of the field type parsing algorithms is a successful parsing, determine that the reference field type is the preset field type corresponding to this field type parsing algorithm. Since the characteristic information of the field values corresponding to each preset field type is quite different from each other, therefore, when a successful parsing appears for the first time, it is possible to stop parsing the characteristic information of the reference field value through other field type parsing algorithms, thereby saving parsing time and improving parsing efficiency.

[0142] In one embodiment, as Figure 5 shown, parsing the characteristic information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type, and obtaining the field value parsing results corresponding to each field type parsing algorithm, includes:

[0143] Step S502: Parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the basic field type to obtain the first field value parsing result; the basic field type includes at least one of the time type, sensitive type, and business type.

[0144] Among them, the basic field type refers to simple, basic, and common field types. The basic field type includes at least one of the time type, sensitive type, and business type. The field value corresponding to the time type field is specific time information. The field value corresponding to the sensitive type field is specific sensitive information, such as ID number / mobile phone number / bank card or other common sensitive information, and the sensitive information represents the user's identity and privacy. The field value corresponding to the business type field is specific business parameters, such as business parameters like login, query, delete, etc.

[0145] Specifically, the preset field types can be divided into three major categories, including basic field types, custom field types, and invalid field types. The basic field type includes at least one of the time type, sensitive type, and business type. Different field types correspond to different field type parsing algorithms. The computer device can parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the basic field type to obtain the first field value parsing result. The computer device can determine whether the reference field type of the current field is a basic field type based on the first field value parsing result, and can further determine whether the reference field type of the current field is specifically the time type, sensitive type, or business type.

[0146] Step S504: Parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the custom field type to obtain the second field value parsing result.

[0147] Among them, the custom field type refers to the field type defined by the user.

[0148] Specifically, the computer device can parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the custom field type to obtain the second field value parsing result. The computer device can determine whether the reference field type of the current field is a custom field type based on the second field value parsing result, and can further determine which specific custom field the reference field type of the current field is.

[0149] Step S506: Parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type to obtain the third field value parsing result.

[0150] Among them, the field value corresponding to the invalid field type is a random number without practical meaning. Both the basic field type and the custom field type are valid and useful field types.

[0151] Specifically, the computer device can parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type to obtain the parsing result of the third field value. The computer device can determine whether the reference field type of the current field is an invalid field type according to the parsing result of the third field value.

[0152] In one embodiment, the computer device can count the parsing time required by various field type parsing algorithms to obtain the parsing time corresponding to various field type parsing algorithms, and determine the parsing priority of various field type parsing algorithms in the chronological order of the parsing time. The shorter the parsing time, the higher the parsing priority. For example, if the chronological order of the parsing time is time type < sensitive type < business type < custom field type < invalid field type, then the parsing priority of various field type parsing algorithms is time type > sensitive type > business type > custom field type > invalid field type. Therefore, the computer device can first parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the time type. If the parsing is successful, there is no need to parse through other field type parsing algorithms. If the parsing fails, then parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the sensitive type. If the parsing is successful, there is no need to parse through other field type parsing algorithms. If the parsing fails, then parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the business type, and so on. In this way, parsing the feature information of the reference field value based on the field type parsing algorithm with a shorter parsing time first can effectively save the parsing time and improve the parsing efficiency.

[0153] In this embodiment, by parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the basic field type, the parsing result of the first field value is obtained. By parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the custom field type, the parsing result of the second field value is obtained. By parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type, the parsing result of the third field value is obtained. In this way, based on a variety of pre-set field type parsing algorithms, the reference field type of the current field can be determined quickly and accurately.

[0154] In one embodiment, the feature information of the reference field value is parsed based on the field type parsing algorithm corresponding to the basic field type, and the first field value parsing result is obtained in at least one of the following ways: when the basic field type is a time type, the feature information of the reference field value is parsed based on at least one time parsing function to obtain the first field value parsing result; when the basic field type is a sensitive type, the standard feature information corresponding to multiple preset sensitive information is obtained, the feature information of the reference field value is respectively matched with each standard feature information, and the first field value parsing result is obtained according to the matching result; when the basic field type is a service type, substrings are identified from the reference field value to obtain multiple reference strings, each reference string is respectively matched with the standard strings in the preset standard dictionary, and the first field value parsing result is obtained according to the matching result.

[0155] Specifically, when the basic field type is a time type, the computer device can parse the feature information of the reference field value based on at least one time parsing function to obtain the first field value parsing result. The time parsing function is a function for parsing time. For example, the timestamp function, the timestamp usually includes a 10-bit or 13-bit pure digital string, representing the total number of seconds from 00:00:00 on January 1, 1970, Greenwich Mean Time (08:00:00 on January 1, 1970, Beijing Time) to the present, and the timestamp parsing function can convert the total number of seconds into the current time. For example, through the timestamp function, the timestamp "1600508494" can be successfully converted into a time format such as "2020 / 9 / 19 17:41:34". When all the characters of the reference field value are numbers, the feature information of the reference field value can be parsed through the timestamp function to determine whether the reference field type of the current field is a time type. When the characters of the reference field value include other letters or symbols in addition to numbers, other common time parsing functions can be used for parsing.

[0156] When the basic field type is a sensitive type, the computer device can obtain the standard feature information corresponding to various preset sensitive information, match the feature information of the reference field value with each standard feature information respectively, and obtain the parsing result of the first field value according to the matching result. The preset sensitive information includes at least one of common sensitive information such as ID card numbers, mobile phone numbers, bank card numbers, etc. For example, if the preset sensitive information is an ID card number, the standard feature information (format) of the ID card number can include 18 characters. The 1st and 2nd digits are the codes of provinces, autonomous regions, and municipalities directly under the Central Government. The 3rd and 4th digits are the codes of prefecture-level cities, leagues, and autonomous prefectures. The 5th and 6th digits are the codes of counties, county-level cities, and districts. The 7th to 14th digits are the date of birth. The 15th and 16th digits are the sequence numbers. The 17th digit is the gender code. The digits from the 1st to the 17th are 0-9. The 18th digit is the check code, and the digits are 0-9 and X. When the feature information of the reference field value meets the above format requirements, it is determined that the reference field type of the current field is a sensitive type. When the preset sensitive information is a mobile phone number, the standard feature information (format) of the mobile phone number can include 11 digits. The 1st to 3rd digits are the operator codes. The 4th to 7th digits are the area codes. The 8th to 11th digits are random numbers. When the feature information of the reference field value meets the above format requirements, it is determined that the reference field type of the current field is a sensitive type. The standard feature information (format) of the bank card number can include 19 digits. The 1st to 6th digits are the issuer identification. The 7th to 18th digits are the personal account identification. The 19th digit is the check code. When the feature information of the reference field value meets the above format requirements, it is determined that the reference field type of the current field is a sensitive type.

[0157] In one embodiment, to further determine whether the reference string is a mobile phone number, it can also be verified whether the mobile phone number exists by calling a public interface or service. If it exists, it is determined that the reference field type of the current field is a sensitive type.

[0158] Business parameters are used to represent the purpose of an access address in a business scenario. When the field value includes foreign words or Chinese words, it can be determined that the field type of the target field corresponding to the field value is a business type. For example, if an access address is applied to the login business, the field value of a target field in the access address can be "login", and "login" is used to represent the meaning of login; if an access address is applied to the query business, the field value of a target field in the access address can be "query", and "query" is used to represent the meaning of query. Specifically, when the basic field type is a business type, the computer device can identify substrings from the reference field value to obtain multiple reference strings, match each reference string with the standard strings in the preset standard dictionary respectively, and obtain the first field value parsing result according to the matching result. Identifying substrings from the reference field value to obtain multiple reference strings can specifically be to cyclically intercept strings with a length between x and y from the reference field value, that is, to cyclically intercept strings with a length within the preset length range from the reference field value to obtain multiple reference strings. For example, cyclically intercept strings with a length between 3 and 6 from the reference field value. If the reference field value is "aName", first intercept from a length of 3, and the interception results include "aNa", "Nam", "ame", then intercept strings with a length of 4, and the interception results include "aNam" and "Name", and finally intercept strings with a length of 5, and the interception result is "aName". Based on the standard dictionary, it can be determined that "Name" is an English word among all the interception results, so it can be determined that the reference field type of the current field is a business type. Identifying substrings from the reference field value to obtain multiple reference strings can also specifically be to segment the reference parameter value based on a word segmentation dictionary to obtain multiple reference strings. Among them, the word segmentation dictionary includes various common function words, pause words, quantifiers, etc., which are words or phrases used to segment short or long sentences. The standard dictionary includes various common words or phrases.

[0159] In one embodiment, when a foreign word or Chinese word included in the field value is identified, natural language recognition can also be performed on the specific foreign word or Chinese word to determine the specific language meaning, so as to determine the detailed business purpose. For example, the Chinese meaning of the English word "login" is login. When all the field values of the target field are "login", it can be determined that the field type of the target field is a business type, and the specific corresponding business is the login business.

[0160] In this embodiment, based on at least one field type parsing algorithm corresponding to various preset field types, the reference field type of the current field can be determined quickly and accurately.

[0161] In one embodiment, the feature information of the reference field value is parsed based on the field type parsing algorithm corresponding to the custom field type to obtain the second field value parsing result, including: obtaining a configuration file; the configuration file includes multiple custom fields and the field value description information corresponding to each custom field, and the field value description information includes at least one of a regular expression, a logical expression, and an operator expression; matching the feature information of the reference field value with the field value description information; and obtaining the second field value parsing result according to the matching result.

[0162] Among them, the configuration file is used to configure the custom field types defined by the user and the corresponding field value parsing algorithms. The field value description information is used to describe the overall feature information of the field values corresponding to the custom fields. The field value description information supports at least one of the description methods of regular expressions, logical expressions, and operator expressions. A regular expression is a "rule string" composed of some predefined specific characters and combinations of these specific characters, and this "rule string" is used to express a judgment logic for a string. A logical expression is a "rule string" composed of logical operators, and this "rule string" is used to express a judgment logic for a string. An operator expression is a combination of special operators such as arithmetic operators (for numerical operations), relational operators (for comparison operations), logical operators (for logical operations), and assignment operators (for assignment operations), which forms a "rule string", and this "rule string" is used to express a judgment logic for a string.

[0163] Specifically, the computer device can obtain the configuration file, read various custom fields and the field value description information corresponding to each custom field from the configuration file, then match the feature information of the reference field value with each field value description information respectively, and obtain the second field value parsing result according to the matching result. When the reference field value matches any one of the field value description information successfully, it can be determined that the reference field type of the current field is a custom type. Further, the specific custom field corresponding to the successfully matched field value description information can be used as the specific custom field type.

[0164] For example, the field value description information is "*name*" and "login". "*name*" is the regular expression for matching, and "login" means that the field type of the custom field is the login type and is the field used for login. According to this regular expression, if the reference field value of the current field "a" contains the string name, it can be determined that the reference field type of the current field "a" is a custom field type, and an access parsing result such as "the 'a' field of the xxx interface meets the user's custom rules, is a custom field type, and is specifically used as a login parameter" can be generated.

[0165] The field value description information is "name and user" and "login". "name and user" is a logical expression for matching, and "login" indicates that the field type of the custom field is login and it is a field used for login. "A and B" means that the field value must contain both A and B. According to this logical expression, if the reference field value contains both the string "name" and the string "user" at the same time, it can be determined that the reference field type of the current field is a custom field type.

[0166] The field value description information is "name<user && name*2" and "login". "name<user, name*2" is an operator expression for matching, and "login" indicates that the field type of the custom field is login and it is a field used for login. Among them, the operator "<" means that a certain string should appear after a certain string, the operator "*" means the number of times a certain string should appear, and the operator "&&" means that the front and back conditions must be satisfied at the same time. Then according to this operator expression, if the reference field value contains the strings "name" and "user", and the string "name" needs to appear after the string "user", and there are two strings "name", it can be determined that the reference field type of the current field is a custom field type.

[0167] In this embodiment, by obtaining a configuration file, the configuration file includes multiple custom fields and the field value description information corresponding to various custom fields. The field value description information includes at least one of a regular expression, a logical expression, and an operator expression. The characteristic information of the reference field value is matched with the field value description information, and the second field value parsing result is obtained according to the matching result. In this way, for uncommon field types, it can be judged based on custom rules through the configuration file, and the flexibility is relatively high. The configuration file supports flexible custom rules, enabling developers to quickly configure corresponding parsing rules according to actual needs. And as the usage time increases, the configuration file can cover more custom fields that need to be parsed.

[0168] In one embodiment, the characteristic information of the reference field value is parsed based on the field type parsing algorithm corresponding to the invalid field type, and the third field value parsing result is obtained in at least one of the following ways: calculating the information entropy corresponding to the reference field value according to each character of the reference field value, obtaining the standard information entropy, and obtaining the third field value parsing result based on the comparison result between the information entropy corresponding to the reference field value and the standard information entropy; inputting the characteristic information of the reference field value into the field value parsing model to obtain the third field value parsing result; the field value parsing model is trained based on the positive field value samples and negative field value samples corresponding to the invalid field type.

[0169] Among them, information entropy is used to represent the occurrence probability of field values, which can reflect the uncertainty and randomness of field values. The greater the information entropy, the greater the randomness of field values. Standard information entropy refers to the comprehensive information entropy obtained by analyzing the field values corresponding to a large number of invalid type fields. For example, calculate the information entropy of a large number of random numbers, and take the average value of the calculated information entropy to obtain the standard information entropy.

[0170] In one embodiment, the calculation formula of information entropy can be . H represents information entropy, n represents the character length in the field value, represents the random occurrence probability of the i-th character in the field value. For example, the length of the string "use" is 3, and each position has m possible characters, then the random occurrence probability of the string "use" is .

[0171] Specifically, the computer device can calculate the information entropy corresponding to the reference field value according to each character of the reference field value, and compare the calculated information entropy with the standard information entropy. When the calculated information entropy is greater than or equal to the standard information entropy, it can be determined that the reference field type of the current field is an invalid type. When the calculated information entropy is less than the standard information entropy, it can be determined that the reference field type of the current field is not an invalid type.

[0172] In one embodiment, in order to improve the judgment accuracy, different standard information entropies can correspond to field values of different lengths. The computer device can calculate the information entropy of the reference field value, obtain the standard information entropy corresponding to a random string of the same length, and compare the information entropy of the reference field value with the standard information entropy. When the information entropy of the reference field value is greater than or equal to the standard information entropy, it can be determined that the reference field value is a random number, and the reference field type of the current field is an invalid type.

[0173] The computer device can also pre-collect training samples for model training. The training samples include positive field value samples and negative field value samples. The positive field value samples include a large number of random numbers, and the negative field value training samples include a large number of strings that are not random numbers, such as words, ID card numbers, etc. The computer device performs supervised training on the field value parsing model according to the training samples, using the field value as the input and the corresponding field label (positive or negative) as the expected output, and finally trains the field value parsing model. When applying the model, the computer device can input the feature information of the reference field value into the trained field value parsing model. The field value parsing model outputs the third field value parsing result. When the output result of the field value parsing model is a positive label, it can be determined that the reference field type of the current field is an invalid type. When the output result of the field value parsing model is a negative label, it can be determined that the reference field type of the current field is not an invalid type. Among them, the field value parsing model can be a specific one or more algorithms in machine learning and deep learning, such as support vector machines, AdaBoosting, convolutional neural networks, etc.

[0174] In this embodiment, the reference field type of the current field can be quickly and accurately determined through information entropy calculation or the field value parsing model.

[0175] In one embodiment, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field includes: counting the occurrence times of each character in each field value corresponding to the current field and the number of field values corresponding to the current field; calculating the occurrence probability of each character based on the occurrence times of each character and the number of field values; determining the probability distance between characters based on the occurrence probability of each character; when the probability distance is less than the second preset threshold, determining that the field type corresponding to the current field is an invalid field type.

[0176] Among them, the occurrence probability refers to the probability of each character appearing in all field values corresponding to the current field. Specifically, the occurrence probability can be the ratio of the occurrence times of the character to the number of field values. The number of field values refers to the total number of all field values corresponding to the current field. For example, if there are 100 field values corresponding to the current field and the character 'a' appears 10 times in the 100 field values, then the occurrence probability of the character 'a' is 10%. The probability distance is used to determine the probability difference between at least two occurrence probabilities. Specifically, it can be the difference between the occurrence probabilities pairwise, or statistical values such as the variance and standard deviation of all occurrence probabilities.

[0177] Specifically, the computer device can count the occurrence times of each character in the field values corresponding to the current field and the number of field values corresponding to the current field based on all the field values corresponding to the current field, calculate the ratio of the occurrence times of the characters to the number of field values, and obtain the occurrence probability of each character. When the occurrence probabilities of each character are close, it can be determined that all the field values corresponding to the current field are random numbers, and the field type of the current field is an invalid field type. Specifically, it can be to calculate the probability difference between the occurrence probabilities of any two characters. When all the probability differences are less than the second preset threshold, it can be determined that the field type of the current field is an invalid field type. It can also be to calculate the variance of all the occurrence probabilities. When the variance is less than the second preset threshold, it indicates that the difference between each occurrence probability and the average value of the occurrence probabilities is not large, and there is no occurrence probability that deviates greatly from the average value. Therefore, it can be determined that the field type of the current field is an invalid field type. Among them, the second preset threshold can be a ratio set according to actual needs, such as 1%.

[0178] In one embodiment, it is also possible to determine whether the field type of the current field is an invalid field type according to the field name of the current field. For example, if the field name of the current field contains common words used in requests to represent random strings, such as words used to represent random numbers like random, token, etc., then it can also be roughly determined that the field type of the current field is an invalid field type.

[0179] In this embodiment, by calculating the probability distance between the occurrence probabilities of characters based on all the field values corresponding to the current field, when the probability distance is less than the second preset threshold, it is determined that the field type corresponding to the current field is an invalid field type. In this way, by comprehensively considering the characteristic information of all the field values, the accuracy of determining the invalid field type can be effectively improved.

[0180] In one embodiment, as Figure 6 shown, a network access analysis method is provided. Taking the case where this method is applied to the computer device in Figure 1 as an example for illustration, the computer device can be the terminal 102 or the server 104 in the above Figure 1 . Referring to Figure 6 , the network access analysis method includes the following steps:

[0181] Step S602, obtain an access query request; the access query request carries the field type to be queried corresponding to the access address to be queried.

[0182] Among them, the access query request is used to request to query at least one piece of access information such as the access address and the field value (parameter value). The access address to be queried refers to the access address to be queried. The field type to be queried refers to the field type of the target field included in the access address to be queried.

[0183] Specifically, when a user is conducting business analysis or algorithm development, if the user wants to query a specific access address or a specific parameter value, the user can set corresponding query conditions, and trigger and generate an access query request according to the query conditions. The query conditions can specifically be the types of fields to be queried corresponding to the access addresses to be queried. The computer device can receive the access query request sent by the user through other computer devices or the access query request triggered and generated locally by the user. The access query request carries the types of fields to be queried corresponding to the access addresses to be queried.

[0184] Step S604: Obtain a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing results are obtained by extracting the target fields and corresponding field values included in each target access address, determining the field types of the corresponding target fields based on the characteristic information of the field values corresponding to the same target field, and based on each target field and the corresponding field type.

[0185] Specifically, before processing the access query request or the access analysis request, the computer device can collect target access addresses from different channels, form a set of target access addresses, and perform access parsing on the target access addresses in the set of target access addresses. When performing access parsing, the computer device can extract the target fields and corresponding target field values from the target access addresses, determine the field types of the corresponding target fields based on the characteristic information of the field values corresponding to the same target field, obtain the field types of each target field, and finally generate the access parsing results corresponding to the set of target access addresses based on each target field and the corresponding field type. Furthermore, the computer device can process the access query service or the access analysis service based on the access parsing results.

[0186] Among them, the specific processing process of obtaining the corresponding access parsing results based on the set of target access addresses can refer to the methods described in the foregoing embodiments.

[0187] Step S606: Obtain the target fields corresponding to the types of fields to be queried from the access parsing results.

[0188] Step S608: Obtain the target query results that match the target fields corresponding to the types of fields to be queried from the set of target access addresses; the target query results include at least one of the target access addresses and the field values.

[0189] Specifically, after receiving an access query request, the computer device can search for the target field corresponding to the field type to be queried from the access parsing results corresponding to the target access address set, and then search for the target access information that matches the target field from the target access address set. When the user wants to query a specific access address, the target access information can be at least one target access address that matches the target field. When the user wants to query a specific parameter value, the target access information can be at least one field value that matches the target field. For example, when the user is performing algorithm analysis on the access time, and needs to obtain the parameter value representing the time in the URL as the analysis data, then the user can trigger the generation of an access query request for obtaining all the parameter values corresponding to the time type parameters in the URL to obtain all the parameter values representing the time.

[0190] Step S610, return the target query result to the sender corresponding to the access query request.

[0191] Specifically, after obtaining the target query result, the computer device can return the queried target access information to the sender corresponding to the access query request to display the query result to the user.

[0192] In the above network access analysis method, by obtaining an access query request; the access query request carries the field type to be queried corresponding to the access address to be queried; obtaining the target access address set and the corresponding access parsing results; the target access address set includes multiple target access addresses, and the access parsing results are obtained by extracting the target fields and the corresponding field values included in each target access address, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, and obtaining based on each target field and the corresponding field type; obtaining the target field corresponding to the field type to be queried from the access parsing results; obtaining the target query result that matches the target field corresponding to the field type to be queried from the target access address set; the target query result includes at least one of the target access address and the field value, and returning the target query result to the sender corresponding to the access query request. In this way, when querying the access address, there is no need to know the detailed parameters of the access address to be queried, and the corresponding access address can be queried based on the function of the access address to be queried, improving the query efficiency of the access address.

[0193] In one embodiment, as Figure 7 shown, the network access analysis method further includes:

[0194] Step S702, obtain an access analysis request; the access analysis request carries the access address to be analyzed.

[0195] Among them, the access analysis request is used to request an analysis of the access address.

[0196] Specifically, when a user is conducting business analysis or algorithm development and wants to understand the function of an access address, the user can trigger the generation of an access analysis request, which carries the access address to be analyzed. The computer device can receive the access analysis request sent by the user through other computer devices or the access analysis request generated locally by the user, and the access analysis request carries the access address to be analyzed.

[0197] Step S704: Extract the fields to be analyzed and the corresponding field values contained in the access address to be analyzed.

[0198] Specifically, the computer device can obtain the access address to be analyzed from the access analysis request, and extract the fields to be analyzed and the corresponding field values from the access address to be analyzed. Among them, the extraction method of the fields to be analyzed and the corresponding field values can refer to the method of extracting the target fields and the corresponding field values from the target access address in the foregoing embodiments. The fields to be analyzed can be at least one, and the field values to be analyzed can also be at least one.

[0199] Step S706: Obtain the target field type corresponding to the field to be analyzed from the access parsing result.

[0200] Step S708: Generate access analysis reference information corresponding to the access address to be analyzed based on the target field type and the field values to be analyzed.

[0201] Among them, the access analysis reference information refers to the reference analysis result of the access function of the access address to be analyzed, which is used to describe the access function of the access address to be analyzed for the user's reference.

[0202] Specifically, after obtaining the fields to be analyzed and the field values to be analyzed corresponding to the access address to be analyzed, the computer device can obtain the access parsing result, find the field type corresponding to the field to be analyzed from the access parsing result, and generate the access analysis reference information corresponding to the access address to be analyzed based on the field type corresponding to the field to be analyzed and the field values to be analyzed. For example, if the field to be analyzed of the access URL to be analyzed is a, and the field value to be analyzed is a1, and it is determined from the access parsing result that the field type corresponding to a is a sensitive type, then the generated access analysis reference information can be that a is a sensitive type field, a1 is the specific sensitive information, and the access URL to be analyzed is used to transmit sensitive information.

[0203] Step S710: Return the access analysis reference information to the sender corresponding to the access analysis request.

[0204] Specifically, after obtaining the access analysis reference information, the computer device can return the access analysis reference information to the sender corresponding to the access analysis request and display the access analysis reference information to the user.

[0205] In this embodiment, when analyzing a new access address, the function of the access address to be analyzed can be determined based on the access parsing result and the specific parameters of the access address to be analyzed. The function of the access address can facilitate users to quickly understand the access address, so as to apply the access address with known functions to business analysis and algorithm development.

[0206] The present application also provides an application scenario that applies the above network access analysis method. Specifically, the application of the network access analysis method in this application scenario is as follows:

[0207] As Figure 8 shown, Figure 8 is a schematic flowchart of generating an access parsing result in an embodiment

[0208] 1. Obtain the data to be analyzed

[0209] Specifically, the computer device can obtain URL data that needs to be parsed and processed from different sources. The sources include but are not limited to various databases, middleware, log files, user inputs, etc.

[0210] 2. Data initialization

[0211] Specifically, the computer device can classify the obtained URL data, and group the URLs belonging to the same access interface into one category. After extracting the URLs of the same access interface category, traverse the URLs, and extract the parameters and their corresponding parameter values from each URL. Then, for each parameter of each access interface category, aggregate its parameter values. For example, the parameters of the access interface xxx.com / index.php include a and b, the corresponding parameter values of a are a1, a2, a3,..., an, and the corresponding parameter values of b are b1, b2, b3,..., bm.

[0212] 3. Determine whether each parameter is a basic type parameter

[0213] Specifically, the basic type parameters include time type parameters, sensitive type parameters, and business type parameters. The computer device can parse each parameter value of the same parameter based on the parameter value parsing algorithm (field value parsing algorithm) corresponding to the time type parameter, and determine whether the parameter is a time type parameter according to the parsing result. When the parsing result is that all parameter values are parsed successfully or most parameter values are parsed successfully, it can be determined that the parameter is a time type parameter. Similarly, the computer device can parse each parameter value of the same parameter based on the parameter value parsing algorithm corresponding to the sensitive type parameter, and determine whether the parameter is a sensitive type parameter according to the parsing result. The computer device can parse each parameter value of the same parameter based on the parameter value parsing algorithm corresponding to the business type parameter, and determine whether the parameter is a business type parameter according to the parsing result.

[0214] 4. Determine whether each parameter is a custom type parameter

[0215] Specifically, when it is determined according to the above parsing result that the parameter is not a basic type parameter, it can be further determined whether the parameter is a custom type parameter. The computer device can parse each parameter value of the same parameter based on the parameter value parsing algorithm (field value parsing algorithm) corresponding to the custom type parameter, and determine whether the parameter is a custom type parameter according to the parsing result.

[0216] 5. Determine whether each parameter is an invalid type parameter

[0217] Specifically, when it is determined according to the above parsing result that the parameter is not a custom type parameter either, it can be further determined whether the parameter is an invalid type parameter. The computer device can parse each parameter value of the same parameter based on the parameter value parsing algorithm (field value parsing algorithm) corresponding to the invalid type parameter, and determine whether the parameter is an invalid type parameter according to the parsing result.

[0218] The above judgment order is not necessarily to first determine whether it is a basic type parameter, then determine whether it is a custom type parameter, and finally determine whether it is an invalid type parameter. The specific judgment order can be set according to actual needs, or determined according to the parsing time corresponding to various type parameters.

[0219] 6. Format the judgment result

[0220] Specifically, when the parameter types of each parameter are determined, the computer device can generate a formatted and standardized access parsing result based on each parameter and the corresponding parameter type.

[0221] Illustrate the generation process of access parsing results. Suppose the parameters of the access interface xxx.com / index.php include a and b. The parameter values corresponding to a are a1, a2, a3, …, an, and the parameter values corresponding to b are b1, b2, b3, …, bm. The parsing of parameter a can specifically be randomly selecting a3 from the parameter values corresponding to a as the reference parameter value, and parsing a3 through at least one time parsing function. If the parsing is successful, it is initially determined that parameter a is a time type parameter, and the role of parameter a is to act as a timestamp. Then, 80% of the data from the parameter values corresponding to a is selected as intermediate parameter values, and each intermediate parameter value is parsed through at least one time parsing function. If all can be parsed successfully, it is finally determined that parameter a is a time type parameter, and the role of parameter a is to act as a timestamp, and an access parsing result such as "The a parameter of the xxx.com / index.php access interface is a time type parameter and is used as a timestamp" can be generated. If not all can be parsed successfully, calculate its parsing success rate. If it is greater than 80% (controllable by the user), it is considered that this parameter is probably a timestamp parameter, and an access parsing result such as "The a parameter of the xxx.com / index.php access interface is probably a time type parameter, probably used as a timestamp, and the parsing success rate is 80%" can be generated. If the parsing success rate is less than 80%, it is considered that parameter a is not a time type parameter. Then, judge the parameter type of parameter a through the parameter value parsing methods corresponding to other parameter types. For example, through the parameter value parsing methods corresponding to sensitive type parameters, business type parameters, custom type parameters, and invalid type parameters.

[0222] 7. Output the access parsing result

[0223] Specifically, the computer device can output the final access parsing result. Specifically, it can generate a log file based on the access parsing result and store it, or store the access parsing result in a database, or display the access parsing result through a page, etc.

[0224] Reference Figure 9A , the user can enter the URL parsing interface by clicking on the URL parsing module on the URL management page. The user can click the "Select" button to select the URL data in the target file as the target URL data from among numerous files stored locally. When the user clicks the "Parse" button, the computer device will parse the target URL data through the above method to obtain the access parsing result, and then display the access parsing result on the URL parsing interface. As Figure 9AAs can be seen from the displayed access parsing results, the target URL data includes URLs corresponding to two types of access interfaces. One type of URL corresponds to the access interface xxx.com / index.php, and the other type of URL corresponds to the access interface xxx.com / start.php. The parameter type of parameter a of the xxx.com / index.php access interface is a time type parameter, and the parameter type of parameter b is a sensitive type parameter. The parameter type of parameter a of the xxx.com / start.php access interface is a business type parameter. Further, the user can view the specific parameter values corresponding to the specific parameters by clicking the drop-down button in the parameter value column. For example, if the parameter values corresponding to parameter a of the xxx.com / start.php access interface include a1, a2, and a3, then the drop-down box corresponding to parameter a of the xxx.com / start.php access interface will display a1, a2, and a3.

[0225] Subsequently, based on the access parsing results, the computer device can perform at least one of an access query task and an access analysis task.

[0226] For example, if a user wants to quickly locate a problem of sensitive information leakage, the user needs to obtain the URL containing sensitive information as the analysis data. Then the user can set the corresponding query conditions to query the URL containing sensitive information in the target URL data. Refer to Figure 9B , the user can enter the URL query interface by clicking the URL query module on the URL management page. The user can select "sensitive type parameter" as the target query condition in the drop-down button corresponding to the query condition. When the user clicks the "query" button, the computer device will query the URL containing the sensitive type parameter from the target URL data, and then display the access parsing results on the URL query interface. As Figure 9B As can be seen from the displayed access query results, the URL with the access interface xxx.com / index.php contains a sensitive type parameter, and the parameter name of the sensitive type parameter is b. The URL with the access interface xxx.com / start.php also contains a sensitive type parameter, and the parameter name corresponding to the sensitive type parameter is a. In addition, the URL with the access interface xxx.com / index.php also contains parameter a, and parameter a is a time type parameter. The URL with the access interface xxx.com / start.php also contains parameter c, and parameter c is a business type parameter. Further, the user can view the specific URL by clicking the drop-down button in the URL column and learn the specific sensitive information contained in the URL.

[0227] For example, if a user wants to analyze the function of a URL, the user can determine the function of the URL to be analyzed based on the access resolution results of other URLs corresponding to the same access interface. Refer to Figure 9C , the user can enter the URL analysis interface by clicking on the URL analysis module on the URL management page. The user can enter the URL to be analyzed, "http: / / xxx.com / index.php?a=x&b=xx", in the corresponding input box for the URL. When the user clicks the "Analyze" button, the computer device will query the access resolution results corresponding to the xxx.com / index.php access interface from the access resolution results of the target URL data, and determine the parameter types of parameter a and parameter b from the access resolution results, so as to determine the function of the URL to be analyzed. As Figure 9C shown in the access analysis results, parameter a in the URL to be analyzed is a time type parameter, parameter b is a sensitive type parameter, the function of the URL to be analyzed is to transmit sensitive information, and the sensitive information is xx, and the generation time or sending time of the sensitive information is x.

[0228] In this embodiment, it is possible to perform multi-dimensional analysis on the parameters of the URL, obtain the actual parameter meanings and parameter functions of each parameter of the URL, so that analysts or readers can quickly understand the function of the parameter and the URL. In addition, the parameter value parsing algorithm for determining whether the parameter type is a custom type parameter supports flexible custom rules, which enables users to quickly configure corresponding parsing rules according to actual needs, and as the usage time increases, more parameters to be parsed are covered. In addition, the access resolution results support formatted output and can be integrated with other platforms or other services and algorithms, so as to provide relevant analysis raw materials or supporting materials for other services.

[0229] It should be understood that although Figures 2 - 8 the steps in the flowchart of Figures 2 - 8 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover,

[0230] In one embodiment, as Figure 10As shown, a network access analysis device is provided. This device can be a software module, a hardware module, or a combination of both to form part of a computer device. Specifically, the device includes: an access address acquisition module 1002, a field information acquisition module 1004, a field type determination module 1006, and an access parsing result determination module 1008, where:

[0231] The access address acquisition module 1002 is used to acquire a set of target access addresses; the set of target access addresses includes multiple target access addresses.

[0232] The field information acquisition module 1004 is used to extract the target fields and corresponding field values included in each target access address.

[0233] The field type determination module 1006 is used to determine the field type of the corresponding target field based on the characteristic information of each field value corresponding to the same target field.

[0234] The access parsing result determination module 1008 is used to generate an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used to perform access processing on the access address to be processed.

[0235] In one embodiment, the access address acquisition module is further used to acquire multiple candidate access addresses; aggregate the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface; and determine the set of target access addresses from each set of candidate access addresses.

[0236] In one embodiment, the access address acquisition module is further used to extract the access host information and access path information included in the candidate access addresses; aggregate the candidate access addresses corresponding to the same access host information and access path information to obtain a set of candidate access addresses corresponding to each access interface.

[0237] In one embodiment, the field information acquisition module is further used to acquire a segmentation identifier; based on the segmentation identifier, split the target access address into multiple candidate fields and corresponding candidate field values; and determine the target field from the multiple candidate fields based on the type of the segmentation identifier to obtain the target field and the corresponding field value.

[0238] In one embodiment, the field type determination module is further configured to determine a reference field value from each field value corresponding to the current field; determine the reference field type of the current field based on the feature information of the reference field value; select a target proportion of field values from each field value corresponding to the current field as intermediate field values; parse the feature information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result; and when the field value parsing result meets a preset condition, determine that the field type corresponding to the current field is the reference field type.

[0239] In one embodiment, the field type determination module is further configured to parse the feature information of the reference field value respectively based on the field type parsing algorithms corresponding to each preset field type to obtain field value parsing results corresponding to each field type parsing algorithm; and use the preset field type corresponding to the field type parsing algorithm with a successful field value parsing result as the reference field type.

[0240] In one embodiment, the field type determination module is further configured to parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the basic field type to obtain a first field value parsing result; the basic field type includes at least one of a time type, a sensitive type, and a service type; parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the custom field type to obtain a second field value parsing result; and parse the feature information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type to obtain a third field value parsing result.

[0241] In one embodiment, when the basic field type is a time type, the field type determination module is further configured to parse the feature information of the reference field value based on at least one time parsing function to obtain a first field value parsing result. When the basic field type is a sensitive type, the field type determination module is further configured to obtain the standard feature information corresponding to multiple preset sensitive information, match the feature information of the reference field value with each standard feature information respectively, and obtain a first field value parsing result according to the matching result. When the basic field type is a service type, the field type determination module is further configured to identify substrings from the reference field value to obtain multiple reference strings, match each reference string with the standard strings in the preset standard dictionary respectively, and obtain a first field value parsing result according to the matching result.

[0242] In one embodiment, the field type determination module is further configured to obtain a configuration file; the configuration file includes multiple custom fields and field value description information corresponding to each custom field, and the field value description information includes at least one of a regular expression, a logical expression, and an operator expression; match the feature information of the reference field value with the field value description information; and obtain a second field value parsing result according to the matching result.

[0243] In one embodiment, the field type determination module is further configured to calculate the information entropy corresponding to the reference field value according to each character of the reference field value, obtain the standard information entropy, and obtain the third field value parsing result based on the comparison result between the information entropy corresponding to the reference field value and the standard information entropy. The field type determination module is further configured to input the feature information of the reference field value into the field value parsing model to obtain the third field value parsing result; the field value parsing model is trained based on the positive field value samples and negative field value samples corresponding to the invalid field types.

[0244] In one embodiment, the field type determination module is further configured to calculate the parsing success rate based on the field value parsing result; when the parsing success rate is greater than the first preset threshold, it is determined that the field type corresponding to the current field is the reference field type.

[0245] In one embodiment, the field type determination module is further configured to count the occurrence times of each character in each field value corresponding to the current field and the number of field values corresponding to the current field; calculate the occurrence probability of each character based on the occurrence times of each character and the number of field values; determine the probability distance between characters based on the occurrence probability of each character; when the probability distance is less than the second preset threshold, it is determined that the field type corresponding to the current field is the invalid field type.

[0246] In one embodiment, as Figure 11 shown, a network access analysis device is provided. The device can be a software module or a hardware module, or a combination of both to form a part of a computer device. The device specifically includes: a request acquisition module 1102, an access parsing result acquisition module 1104, a field information determination module 1106, a query result determination module 1108, and a query result sending module 1110, where:

[0247] The request acquisition module 1102 is configured to acquire an access query request; the access query request carries the to-be-query field type corresponding to the to-be-query access address.

[0248] The access parsing result acquisition module 1104 is configured to acquire a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing result is obtained by extracting the target fields and corresponding field values included in each target access address, and determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field.

[0249] The field information determination module 1106 is configured to acquire the target field corresponding to the to-be-query field type from the access parsing result.

[0250] A query result determination module 1108, configured to obtain a target query result that matches a target field corresponding to a field type to be queried from a set of target access addresses; the target query result includes at least one of a target access address and a field value.

[0251] A query result sending module 1110, configured to return the target query result to a sender corresponding to an access query request.

[0252] In one embodiment, the request acquisition module is further configured to acquire an access analysis request; the access analysis request carries an access address to be analyzed. The field information determination module is further configured to extract a field to be analyzed and a corresponding value of the field to be analyzed included in the access address to be analyzed; obtain a target field type corresponding to the field to be analyzed from the access parsing result; generate access analysis reference information corresponding to the access address to be analyzed based on the target field type and the value of the field to be analyzed. The query result sending module is further configured to return the access analysis reference information to a sender corresponding to the access analysis request.

[0253] For the specific limitations on the network access analysis device, reference can be made to the limitations on the network access analysis method in the foregoing text, which will not be elaborated here. Each module in the above network access analysis device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0254] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 12 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as a set of candidate access addresses, a set of target access addresses, and an access parsing result. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a network access analysis method.

[0255] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 13As shown in the figure. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a network access analysis method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0256] Those skilled in the art can understand that Figure 12 、 13 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0257] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0258] In one embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0259] In one embodiment, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the steps in the above method embodiments.

[0260] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0261] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0262] The above-described embodiments merely represent several implementation manners of the present application. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A network access analysis method, characterized in that, The method includes: Obtaining a set of target access addresses; the set of target access addresses includes multiple target access addresses; Extracting the target fields and corresponding field values included in each target access address; Determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, including: determining a reference field value from each field value corresponding to the current field; determining the reference field type of the current field based on the feature information of the reference field value; selecting a target proportion of the field values corresponding to the current field as intermediate field values; parsing the feature information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result; when the field value parsing result meets a preset condition, determining that the field type corresponding to the current field is the reference field type; Generating an access parsing result corresponding to the set of target access addresses based on each target field and the corresponding field type; the access parsing result is used for accessing and processing the access address to be processed.

2. The method according to claim 1, wherein The obtaining the set of target access addresses includes: Obtaining multiple candidate access addresses; Aggregating the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface; Determining the set of target access addresses from each set of candidate access addresses.

3. The method according to claim 2, wherein The aggregating the candidate access addresses corresponding to the same access interface to obtain a set of candidate access addresses corresponding to each access interface includes: Extracting the access host information and access path information included in the candidate access addresses; Aggregating the candidate access addresses corresponding to the same access host information and access path information to obtain a set of candidate access addresses corresponding to each access interface.

4. The method according to claim 1, characterized in that The determining the reference field type of the current field based on the feature information of the reference field value includes: Respectively parsing the feature information of the reference field value based on the field type parsing algorithms corresponding to each preset field type to obtain field value parsing results corresponding to each field type parsing algorithm; Taking the preset field type corresponding to the field type parsing algorithm with a successful field value parsing result as the reference field type.

5. The method according to claim 4, wherein The respectively parsing the feature information of the reference field value based on the field type parsing algorithms corresponding to each preset field type to obtain field value parsing results corresponding to each field type parsing algorithm includes: Parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the basic field type to obtain a first field value parsing result; the basic field type includes at least one of a time type, a sensitive type, and a service type; Parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the custom field type to obtain a second field value parsing result; Parsing the feature information of the reference field value based on the field type parsing algorithm corresponding to the invalid field type to obtain a third field value parsing result.

6. The method according to claim 5, wherein Parsing the characteristic information of the reference field value by the field type parsing algorithm corresponding to the basic field type, and obtaining the first field value parsing result includes at least one of the following methods: When the basic field type is a time type, parsing the characteristic information of the reference field value based on at least one time parsing function to obtain the first field value parsing result; When the basic field type is a sensitive type, obtaining the standard characteristic information corresponding to multiple preset sensitive information, matching the characteristic information of the reference field value with each standard characteristic information respectively, and obtaining the first field value parsing result according to the matching result; When the basic field type is a service type, identifying substrings from the reference field value to obtain multiple reference strings, matching each reference string with the standard strings in the preset standard dictionary respectively, and obtaining the first field value parsing result according to the matching result.

7. The method according to claim 5, characterized in that Parsing the characteristic information of the reference field value by the field type parsing algorithm corresponding to the custom field type, and obtaining the second field value parsing result, including: Obtaining a configuration file; the configuration file includes multiple custom fields and the field value description information corresponding to each custom field, and the field value description information includes at least one of a regular expression, a logical expression, and an operator expression; Matching the characteristic information of the reference field value with the field value description information; Obtaining the second field value parsing result according to the matching result.

8. The method according to claim 5, characterized in that, Parsing the characteristic information of the reference field value by the field type parsing algorithm corresponding to the invalid field type, and obtaining the third field value parsing result includes at least one of the following methods: Calculating the information entropy corresponding to the reference field value according to each character of the reference field value, obtaining the standard information entropy, and obtaining the third field value parsing result based on the comparison result between the information entropy corresponding to the reference field value and the standard information entropy; Inputting the characteristic information of the reference field value into a field value parsing model to obtain the third field value parsing result; the field value parsing model is trained based on the positive field value samples and negative field value samples corresponding to the invalid field type.

9. The method according to claim 3, wherein When the field value parsing result meets the preset conditions, determining that the field type corresponding to the current field is the reference field type, including: Calculating the parsing success rate based on the field value parsing result; When the parsing success rate is greater than the first preset threshold, determining that the field type corresponding to the current field is the reference field type.

10. The method according to claim 1, wherein Extracting the target fields and corresponding field values included in each target access address, including: Obtaining a segmentation identifier; Based on the segmentation identifier, splitting the target access address into multiple candidate fields and corresponding candidate field values; Determining the target field from the multiple candidate fields based on the type of the segmentation identifier to obtain the target field and the corresponding field value.

11. The method according to claim 1, characterized in that, Based on the characteristic information of each field value corresponding to the same target field, determining the field type of the corresponding target field, further including: Count the occurrence times of each character in each field value corresponding to the current field and the number of field values corresponding to the current field; Calculate the occurrence probability of each character based on the occurrence times of each character and the number of field values; Determine the probability distance between characters based on the occurrence probability of each character; When the probability distance is less than the second preset threshold, determine that the field type corresponding to the current field is an invalid field type.

12. A network access analysis method, characterized in that The method includes: Obtain an access query request; the access query request carries the field type to be queried corresponding to the access address to be queried; Obtain a set of target access addresses and corresponding access parsing results; the set of target access addresses includes multiple target access addresses, and the access parsing results are obtained by extracting the target fields and corresponding field values included in each target access address, determining the field type of the corresponding target field based on the feature information of each field value corresponding to the same target field, and obtaining based on each target field and the corresponding field type; the process of determining the field type of the target field includes: determining a reference field value from each field value corresponding to the target field, determining the reference field type of the target field based on the feature information of the reference field value, selecting a target proportion of field values from each field value corresponding to the target field as intermediate field values, parsing the feature information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result, and when the field value parsing result meets the preset condition, determining that the field type corresponding to the target field is the reference field type; Obtain the target field corresponding to the field type to be queried from the access parsing results; Obtain a target query result that matches the target field corresponding to the field type to be queried from the set of target access addresses; the target query result includes at least one of a target access address and a field value; Return the target query result to the sender corresponding to the access query request.

13. The method according to claim 12, wherein The method further includes: Obtain an access analysis request; the access analysis request carries the access address to be analyzed; Extract the field to be analyzed and the corresponding field value to be analyzed included in the access address to be analyzed; Obtain the target field type corresponding to the field to be analyzed from the access parsing results; Generate access analysis reference information corresponding to the access address to be analyzed based on the target field type and the field value to be analyzed; Return the access analysis reference information to the sender corresponding to the access analysis request.

14. A network access analysis device, characterized in that, The device includes: An access address acquisition module, configured to acquire a set of target access addresses; the set of target access addresses includes multiple target access addresses; A field information acquisition module, configured to extract the target fields and corresponding field values included in each target access address; A field type determination module, configured to determine the field type of a corresponding target field based on the characteristic information of each field value corresponding to the same target field, including: determining a reference field value from each field value corresponding to the current field; determining a reference field type of the current field based on the characteristic information of the reference field value; selecting a target proportion of field values from each field value corresponding to the current field as intermediate field values; parsing the characteristic information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result; when the field value parsing result meets a preset condition, determining that the field type corresponding to the current field is the reference field type; An access parsing result determination module, configured to generate an access parsing result corresponding to the target access address set based on each target field and the corresponding field type; the access parsing result is used to perform access processing on a to-be-processed access address.

15. A network access analysis device, characterized in that, The device includes: A request acquisition module, configured to acquire an access query request; the access query request carries a to-be-query field type corresponding to a to-be-query access address. An access parsing result acquisition module, configured to acquire a target access address set and the corresponding access parsing result; the target access address set includes multiple target access addresses, and the access parsing result is obtained by extracting target fields and corresponding field values included in each target access address, determining the field type of the corresponding target field based on the characteristic information of each field value corresponding to the same target field, and based on each target field and the corresponding field type; the determination process of the field type of the target field includes: determining a reference field value from each field value corresponding to the target field, determining a reference field type of the target field based on the characteristic information of the reference field value, selecting a target proportion of field values from each field value corresponding to the target field as intermediate field values, parsing the characteristic information of each intermediate field value based on the field type parsing algorithm corresponding to the reference field type to obtain a field value parsing result, and when the field value parsing result meets a preset condition, determining that the field type corresponding to the target field is the reference field type; A field information determination module, configured to obtain a target field corresponding to the to-be-query field type from the access parsing result. A query result determination module, configured to obtain a target query result that matches the target field corresponding to the to-be-query field type from the target access address set; the target query result includes at least one of a target access address and a field value. A query result sending module, configured to return the target query result to the sender corresponding to the access query request.

16. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 13 are implemented.

17. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 13 are implemented.

18. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 13 are implemented.

Citation Information

Patent Citations

  • Method and system for analyzing URL address

    CN107257390A

  • Delivery of personalized platform-specific content using a single URL

    US20190057161A1