Method, system, electronic device and storage medium for collecting clues of Internet-related incidents
By automatically obtaining and classifying the source code of the target website, extracting web page elements and linking clues based on feature information, the problem of cracking down on the difficulty of obtaining evidence in online events is solved, and evidence collection efficiency and evidence retention rate are improved.
Patent Information
- Application Number
- CN202110918126.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-11
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-08-11
AI Technical Summary
In the existing technology, it is difficult to crack down on evidence collection in network-related events. It is time-consuming and labor-intensive to compare manual data, low evidence collection efficiency and lag, and there is a lot of evidence loss.
By obtaining the source code of the target website, extracting web page elements and classifying them, and determining effective website information as clues based on feature information to achieve automated evidence collection.
It has improved the efficiency of evidence collection in cracking down on online events, reduced the loss of evidence, and improved the level of automation of investigation.
Smart Images

Figure CN113609396B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet security technology, and in particular to methods, systems, electronic devices, and storage media for collecting clues of Internet-related incidents. Background Art
[0002] With the continuous improvement of informatization, illegal activities involving computer information are becoming more and more common. Internet-related illegal activities are rapid, hidden, random, and irreversible, making effective investigation and evidence collection difficult.
[0003] Currently, the primary method for combating internet-related incidents is through offline reporting, which then infers the underlying industry chain of the organizations behind the incidents based on the victimization patterns. However, much of the data comparison and analysis is done manually, which is time-consuming and labor-intensive, resulting in a relatively long search cycle. Furthermore, this requires high-level cyber investigation skills from those combating internet-related incidents. Furthermore, counter-investigation through reporting is inherently time-consuming, leading to significant evidence loss during the evidence collection phase, further complicating the fight against internet-related incidents.
[0004] There is currently no effective solution to the problem of difficulty in collecting evidence to combat Internet-related incidents in relevant technologies. Summary of the Invention
[0005] In this embodiment, a method, system, electronic device and storage medium for collecting clues of Internet-related incidents are provided to solve the problem of difficulty in collecting evidence in combating Internet-related incidents existing in related technologies.
[0006] First, in this embodiment, a method for collecting clues of Internet-related incidents is provided, including:
[0007] Obtaining information to be processed, and obtaining source codes of multiple target websites based on the information to be processed, wherein the information to be processed includes IP, domain name, and website information;
[0008] Extracting web page elements carried by the source code of each target website according to source code rules, and classifying the multiple target websites according to the similarity between the multiple source codes, aggregating IP addresses, domain names, and web page elements of different target websites belonging to the same category, and generating multiple website intelligence based on target website categories;
[0009] Acquire characteristic information of an Internet-related event, determine effective website intelligence among the plurality of website intelligence according to the characteristic information, and associate the effective website intelligence with the Internet-related event as a clue.
[0010] In some embodiments, the webpage elements further include interesting words. After extracting the webpage elements carried in the source code of each target website according to the source code rules, the method further includes:
[0011] The corresponding target websites are marked according to the interesting words, and the website nature of each target website is determined.
[0012] In some embodiments, the characteristic information of the Internet-related event includes website properties, and determining valid website intelligence from the multiple website intelligence based on the characteristic information, and associating the valid website intelligence with the Internet-related event as a clue includes: determining the website properties of each of the target websites, matching the website properties of each of the target websites with the website properties of the Internet-related event, determining the website intelligence of the target website that has been successfully matched as the valid website intelligence, and associating the valid website intelligence with the Internet-related event as a clue; and / or,
[0013] The characteristic information of the Internet-related event includes the type of web page elements. Determining the valid website intelligence among the multiple website intelligences based on the characteristic information, and associating the valid website intelligence with the Internet-related event as a clue includes: matching the web page elements of each target website with the web page element type of the Internet-related event, determining the website intelligence corresponding to the successfully matched web page elements as the valid website intelligence, and associating the valid website intelligence with the Internet-related event as a clue.
[0014] In some embodiments, extracting web page elements carried in the source code of each target website according to source code rules includes:
[0015] According to the regular matching rule, the source code slice containing Arabic numerals is intercepted;
[0016] The source code slice is semantically analyzed according to preset keywords to obtain the web page elements, which include at least one of the following: a social account, a social name, a contact number, and an external link.
[0017] In some embodiments, before performing semantic analysis on the source code slices according to preset keywords to obtain the web page elements, the method further includes: obtaining multiple types of Internet-related events and extracting the preset keywords from the website source codes corresponding to the multiple types of Internet-related events; and
[0018] After performing semantic analysis on the source code slices according to preset keywords to obtain the web page elements, the method further includes: obtaining multiple types of Internet-related events, extracting real-time keywords from the website source codes corresponding to the multiple types of Internet-related events, and correcting the preset keywords according to the real-time keywords.
[0019] In some embodiments, classifying the target websites according to the similarity between the source codes includes:
[0020] A plurality of website source code templates are obtained, the source codes of the plurality of target websites are matched one by one with the plurality of website source code templates, and the plurality of target websites that successfully match the same website source code template are determined as mutually similar target websites.
[0021] In some embodiments, the method further comprises:
[0022] Obtaining webpage screenshots of multiple target websites according to the information to be processed;
[0023] Aggregate the IP addresses, domain names, web page elements, and web page screenshots of different target websites belonging to the same category to generate website intelligence based on the target website category.
[0024] In a second aspect, a system for collecting clues of network-related events is provided in this embodiment, including: a targeted analysis module, an investigation module, and a preliminary investigation event module, wherein the targeted analysis module is coupled with the investigation module and the preliminary investigation event module;
[0025] The targeted analysis module is used to execute the method for collecting clues of Internet-related incidents described in the first aspect above;
[0026] The detection module is used to verify the information to be processed in the targeted analysis module;
[0027] The preliminary investigation event module is used to create network-related events and / or convert the website intelligence generated by the targeted analysis module into preliminary investigation events.
[0028] In a third aspect, an electronic device is provided in this embodiment, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for collecting clues of Internet-related events described in the first aspect above is implemented.
[0029] In a fourth aspect, a storage medium is provided in this embodiment, on which a computer program is stored. When the program is executed by a processor, the method for collecting clues of Internet-related events described in the first aspect is implemented.
[0030] Compared with the related art, the method, system, electronic device and storage medium for collecting clues of Internet-related incidents provided in this embodiment obtain information to be processed, and obtain the source code of multiple target websites based on the information to be processed, and the information to be processed includes IP, domain name and website information; extract the web page elements carried by the source code of each target website according to the source code rules, and classify the multiple target websites according to the degree of similarity between the multiple source codes, aggregate the IP, domain name and web page elements of different target websites belonging to the same category, and generate multiple website intelligence based on the target website category; obtain characteristic information of Internet-related incidents, determine the effective website intelligence in the multiple website intelligence based on the characteristic information, and associate the effective website intelligence with the Internet-related incidents as clues, thereby solving the problem of difficulty in collecting evidence in combating Internet-related incidents in the related art and improving the efficiency of collecting evidence in combating Internet-related incidents.
[0031] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0033] Figure 1 This is a hardware structure block diagram of a terminal of the method for collecting clues of network-related incidents according to this embodiment;
[0034] Figure 2 This is a flow chart of the method for collecting clues of Internet-related incidents according to this embodiment;
[0035] Figure 3 This is a schematic diagram of the structure of a system for collecting clues related to Internet events according to an embodiment of the present application;
[0036] Figure 4 This is a diagram showing the operating principle of the Internet-related incident clue collection system of the preferred embodiment;
[0037] Figure 5 This is a schematic diagram of the principle of extracting web page source code by the targeted analysis module of this preferred embodiment. DETAILED DESCRIPTION
[0038] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0039] Unless otherwise defined, the technical terms or scientific terms involved in this application should have the general meaning understood by people with ordinary skills in the technical field to which this application belongs. The words "one", "an", "a", "the", "these" and the like in this application do not indicate quantitative restrictions, and they can be singular or plural. The terms "include", "comprise", "have" and any variants thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method and system, product or device comprising a series of steps or modules (units) is not limited to the listed steps or modules (units), but may include unlisted steps or modules (units), or may include other steps or modules (units) inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "plurality" involved in this application refers to two or more. "And / or" describes the relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, and B exists alone. Generally, the character " / " indicates that the related objects are in an "or" relationship. The terms "first," "second," and "third," etc., used in this application, simply distinguish between similar objects and do not indicate a specific ordering of the objects.
[0040] The method embodiment provided in this embodiment can be executed in a terminal, a computer or a similar computing device. For example, running on a terminal, Figure 1 This is a hardware structure diagram of the terminal of the network-related incident clue collection method of this embodiment. Figure 1 As shown, the terminal may include one or more ( Figure 1 (only one is shown) a processor 102 and a memory 104 for storing data, wherein the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above terminal. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0041] Memory 104 can be used to store computer programs, such as application software programs and modules, such as the computer program corresponding to the method for collecting clues related to online incidents in this embodiment. Processor 102 executes the computer program stored in memory 104 to perform various functional applications and data processing, thereby implementing the aforementioned method. Memory 104 can include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, memory 104 may further include memory located remotely from processor 102, which can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0042] The transmission device 106 is used to receive or send data via a network. The network may include a wireless network provided by the terminal's telecommunications provider. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0043] In this embodiment, a method for collecting clues of Internet-related events is provided. Figure 2 This is a flow chart of the method for collecting clues of network-related events in this embodiment. Figure 2 As shown, the process includes the following steps:
[0044] Step S201: Obtain information to be processed, and obtain source codes of multiple target websites based on the information to be processed. The information to be processed includes IP, domain name, and website information.
[0045] When obtaining the source code of a target website based on an IP (Internet Protocol), the first step is to obtain the port open information and historically bound domain names of the IP. Then, based on the port open information and historically bound domain names, the source code of the target website is obtained. If a website is mapped to the port, the URL (Uniform Resource Locator) of the website corresponding to the port and a screenshot of the homepage of the webpage can also be found.
[0046] When obtaining the source code of the target website based on the domain name and website information, you can directly obtain the source code of the target website based on the domain name and website information. In addition, you can also obtain a screenshot of the homepage of the web page, domain name WHOIS (domain name query protocol) information and resolved IP based on the domain name and website information.
[0047] In step S202, the web page elements carried by the source code of each target website are extracted according to the source code rules, and multiple target websites are classified according to the similarity between the multiple source codes, and the IP addresses, domain names and web page elements of different target websites belonging to the same category are aggregated to generate website intelligence based on the target website category.
[0048] Generally, target websites in internet-related incidents are deployed on various domain names and IP addresses to cast a wide net. To save costs and effort, these target websites use the same website template and modify the website name or other information based on the same website template to obtain multiple target websites. Based on the source code rules, multiple similar target websites can be compared and obtained. The IP addresses, domain names, and web page elements of multiple similar target websites are aggregated to expand the website intelligence of the same-source websites. In specific implementation, multiple website source code templates can be obtained, and the source codes of multiple target websites can be matched one by one with the multiple website source code templates. Multiple target websites that successfully match the same website source code template can then be identified as similar target websites.
[0049] Source code rules include, but are not limited to, regular expression matching rules and semantic analysis rules. Source code slices containing Arabic numerals can be first intercepted based on regular expression matching rules. Considering the inaccuracy of regular expression matching, semantic analysis of the source code slices can be performed based on preset keywords to obtain a more accurate representation of webpage elements. Webpage elements include, but are not limited to, social media accounts, social media names, contact numbers, and external links.
[0050] For example, to extract QQ numbers, we can create a regular matching rule based on their characteristics: "^[1-9][0-9]{4,12}$." This rule satisfies the following conditions: the first digit cannot be 0, the number starts at 10000, has a minimum of 5 digits and a maximum of 2 digits, and contains Arabic numerals. This rule can be used to extract source code slices containing Arabic numerals that meet these conditions. However, the Arabic numerals extracted solely based on this rule are often meaningless and may simply be a string of parameters in the webpage code.
[0051] Specific websites typically leave contact information for inquiries. Using "QQ:," "QQ," and "qq" as pre-set keywords, you can perform semantic analysis on source code slices to accurately identify webpage elements. Since different target websites have different webpage display formats and semantics, you can configure pre-set keywords based on the specific display format of the webpage.
[0052] Step S203: Acquire characteristic information of the Internet-related event, determine valid website intelligence from the plurality of website intelligence according to the characteristic information, and associate the valid website intelligence with the Internet-related event as a clue.
[0053] For a specific Internet-related incident, not all collected website intelligence is valid. Therefore, it is necessary to verify the validity of the website intelligence. The validity of the website intelligence can be determined based on the characteristic information of the Internet-related incident. The website intelligence that matches the characteristic information of the Internet-related incident can be used as a clue to associate with the Internet-related incident.
[0054] In some embodiments, the characteristic information of an Internet-related event may be the nature of the website. By determining the website nature of each target website, the website nature of each target website is matched with the website nature of the Internet-related event, and the website intelligence of the successfully matched target website is determined as valid website intelligence, and the valid website intelligence is used as a clue to be associated with the Internet-related event.
[0055] In some embodiments, the characteristic information of an Internet-related event may be a web page element type, such as a social account type, a social name type, a contact number type, and a link type. By matching the web page elements of each target website with the web page element type of the Internet-related event, the website intelligence corresponding to the successfully matched web page element is determined to be valid website intelligence, and the valid website intelligence is used as a clue to be associated with the Internet-related event.
[0056] Through the above steps S201 to S203, clues of Internet-related incidents are aggregated and concretized to assist in combating Internet-related incidents, thereby solving the problem of difficulty in collecting evidence in combating Internet-related incidents in related technologies and improving the efficiency of collecting evidence in combating Internet-related incidents.
[0057] In some embodiments, web page elements also include interesting words. After extracting web page elements from the source code of each target website according to source code rules, the corresponding target website is also marked according to the interesting words to determine the website nature of each target website. In this way, the website nature can be used as an index to retrieve corresponding website intelligence.
[0058] In some embodiments, before semantically analyzing source code slices based on preset keywords to obtain webpage elements, various types of online events are obtained and preset keywords are extracted from the website source code corresponding to the various types of online events. This configuration allows for the configuration of preset keywords based on the actual needs of online events and the screening of valid website intelligence based on the preset keywords.
[0059] After semantically analyzing source code slices based on pre-set keywords to obtain webpage elements, the system then obtains various types of online events and extracts real-time keywords from the website source code corresponding to these events. The pre-set keywords are then corrected based on the real-time keywords. This setup facilitates supplementing and correcting the semantic library containing the pre-set keywords by entering additional clues as they are obtained during the investigation.
[0060] In some embodiments, in addition to obtaining the source code of multiple target websites based on the information to be processed, web page screenshots of multiple target websites will also be obtained based on the information to be processed; IP addresses, domain names, web page elements and web page screenshots of different target websites belonging to the same category are aggregated to generate website intelligence based on the target website category.
[0061] Among them, web page screenshots include screenshots of the homepage of the web page, which can provide visual evidence for evidence.
[0062] In combination with the method for collecting clues of Internet-related events in the above embodiment, this embodiment also provides a system for collecting clues of Internet-related events. Figure 3 This is a schematic diagram of the structure of the network-related incident clue collection system of the embodiment of the present application. Figure 3 As shown, the system includes:
[0063] Targeted analysis module 31 , investigation module 32 and preliminary event investigation module 33 , wherein the targeted analysis module 31 is coupled with the investigation module 32 and preliminary event investigation module 33 .
[0064] The targeted analysis module 31 is used to execute the method for collecting clues related to internet-related incidents described in any of the above-mentioned embodiments. This method includes IP address searches and website (domain name) searches. When searching for an IP address, the module retrieves the IP address's port availability information and previously bound domain names. If a port is mapped to a website, the module also retrieves the corresponding website URL and homepage screenshot. When searching for a domain name or website, the module retrieves the corresponding website's source code, homepage screenshot, domain name WHOIS information, resolved IP address, webpage elements, and homology information.
[0065] The detection module 32 is used to verify the information to be processed in the target analysis module 31. For example, the IP address, domain name whois information, mobile phone number, and ID card location of the target website are verified.
[0066] The preliminary investigation event module 33 is used to create internet-related events and / or convert the website intelligence generated by the targeted analysis module 31 into preliminary investigation events. Preliminary investigation cases are divided into a clue repository, case profiles, and preliminary investigation reports. When converting website intelligence into preliminary investigation events, specific web page elements are collected from the website intelligence and aggregated into the clue repository. These specific web page elements include but are not limited to mobile phone numbers, ID cards, IP addresses, on-site and off-site URLs, QQ, landline numbers, WeChat, Alipay, related domain names, and homologous website information.
[0067] It should be noted that the aforementioned modules can be either functional modules or program modules, and can be implemented via software or hardware. For modules implemented via hardware, the aforementioned modules can be located in the same processor; or the aforementioned modules can be located in different processors in any combination.
[0068] The following describes the network-related incident clue collection system through a preferred embodiment.
[0069] Figure 4 This is a schematic diagram of the operation principle of the network-related incident clue collection system of the preferred embodiment. Figure 4 As shown, the Internet incident clue collection system obtains information to be processed, including IP, domain name and website information; performs data processing on the information to be processed to obtain IP intelligence and primary website intelligence; processes the primary website intelligence through investigation tools to obtain source code; uses source code rules to judge the source code to obtain intermediate website intelligence; and converts the intermediate website intelligence into preliminary investigation events.
[0070] Figure 5 This is a schematic diagram of the principle of extracting web page source code by the targeted analysis module of this preferred embodiment. Figure 5 As shown, the targeted analysis module combines regular matching, semantic analysis and similarity matching to process the web page source code and obtain the target website's tags, web page elements and homology information respectively.
[0071] This embodiment further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0072] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0073] Optionally, in this embodiment, the processor may be configured to execute the following steps through a computer program:
[0074] S1, obtaining information to be processed, and obtaining source codes of multiple target websites based on the information to be processed, wherein the information to be processed includes IP, domain name and website information.
[0075] S2, extracts the web page elements carried by the source code of each target website according to the source code rules, and classifies multiple target websites according to the similarity between multiple source codes, aggregates the IP addresses, domain names and web page elements of different target websites belonging to the same category, and generates multiple website intelligence based on the target website category.
[0076] S3, obtaining characteristic information of the Internet-related event, determining effective website intelligence from multiple website intelligences based on the characteristic information, and associating the effective website intelligence with the Internet-related event as a clue.
[0077] It should be noted that, for specific examples in this embodiment, reference may be made to the examples described in the above embodiments and optional implementation modes, and will not be repeated in this embodiment.
[0078] In addition, in conjunction with the method for collecting clues to internet-related incidents provided in the above embodiments, a storage medium may also be provided in this embodiment to implement the method. The storage medium stores a computer program; when the computer program is executed by a processor, it implements any of the methods for collecting clues to internet-related incidents provided in the above embodiments.
[0079] It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit it. Based on the embodiments provided in this application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0080] Obviously, the accompanying drawings are merely examples or embodiments of the present application. A person skilled in the art can also apply the present application to other similar situations based on these drawings without inventive effort. Furthermore, it is understandable that, although the work involved in this development process may be complex and lengthy, certain design, manufacturing, or production changes based on the technical content disclosed in this application are merely routine technical means for a person skilled in the art and should not be considered to constitute a deficiency in the disclosure of the present application.
[0081] The term "embodiment" as used in this application refers to specific features, structures, or characteristics described in conjunction with the embodiment that can be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily mean that the embodiment is the same, nor does it mean that it is mutually exclusive with other embodiments and is independent or optional. It is understood, either explicitly or implicitly, by those skilled in the art that the embodiments described in this application can be combined with other embodiments when there is no conflict.
[0082] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that variations and improvements are possible within the scope of the present application, as would be apparent to those skilled in the art. These variations and improvements fall within the scope of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A method for collecting clues of Internet-related events, characterized in that: include: Obtaining information to be processed, and obtaining source codes of multiple target websites based on the information to be processed, wherein the information to be processed includes IP, domain name, and website information; Extracting web page elements carried by the source code of each target website according to source code rules includes: According to the regular matching rule, a source code slice containing Arabic numerals is intercepted; the regular matching rule satisfies the following conditions: the first digit is not 0, starts from 10000, has a minimum of 5 digits and a maximum of 2 digits, and is an Arabic numeral; Before performing semantic analysis on the source code slices according to preset keywords to obtain the web page elements, multiple types of web-related events are obtained, and the preset keywords are extracted from the website source codes corresponding to the multiple types of web-related events; Performing semantic analysis on the source code slices according to preset keywords to obtain web page elements carried in the source code of each target website, wherein the web page elements include at least one of the following: a social account, a social name, a contact number, and an external link; After performing semantic analysis on the source code slices according to preset keywords to obtain the web page elements, multiple types of web-related events are obtained, and real-time keywords are extracted from the website source codes corresponding to the multiple types of web-related events, and the preset keywords are corrected according to the real-time keywords; and classifying the plurality of target websites according to the similarity between the plurality of source codes, including: Acquire multiple website source code templates, match the source codes of the multiple target websites with the multiple website source code templates one by one, and determine the multiple target websites that successfully match the same website source code template as similar target websites; Aggregate the IP addresses, domain names, and web page elements of different target websites belonging to the same category to generate multiple website intelligence based on the target website category; Acquire characteristic information of an Internet-related event, determine effective website intelligence among the plurality of website intelligence according to the characteristic information, and associate the effective website intelligence with the Internet-related event as a clue.
2. The method for collecting clues of Internet-related incidents according to claim 1, characterized in that: The webpage elements also include interesting words. After extracting the webpage elements carried by the source code of each target website according to the source code rules, the method further includes: The corresponding target websites are marked according to the interesting words, and the website nature of each target website is determined.
3. The method for collecting clues of Internet-related incidents according to claim 1 or 2, characterized in that: The characteristic information of the Internet-related event includes website properties, and determining valid website intelligence from the multiple website intelligence based on the characteristic information, and associating the valid website intelligence with the Internet-related event as a clue includes: determining the website properties of each target website, matching the website properties of each target website with the website properties of the Internet-related event, determining the website intelligence of the target website that has been successfully matched as the valid website intelligence, and associating the valid website intelligence with the Internet-related event as a clue; and / or, The characteristic information of the Internet-related event includes the type of web page elements. Determining the valid website intelligence among the multiple website intelligences based on the characteristic information, and associating the valid website intelligence with the Internet-related event as a clue includes: matching the web page elements of each target website with the web page element type of the Internet-related event, determining the website intelligence corresponding to the successfully matched web page elements as the valid website intelligence, and associating the valid website intelligence with the Internet-related event as a clue.
4. The method for collecting clues of Internet-related incidents according to claim 1, characterized in that: The method further comprises: Obtaining webpage screenshots of multiple target websites according to the information to be processed; Aggregate the IP addresses, domain names, web page elements, and web page screenshots of different target websites belonging to the same category to generate website intelligence based on the target website category.
5. A system for collecting clues of Internet-related incidents, characterized in that: include: Targeted analysis module, investigation module and preliminary event investigation module, wherein the targeted analysis module is coupled with the investigation module and the preliminary event investigation module; wherein, The targeted analysis module is used to execute the method for collecting clues of Internet-related events according to any one of claims 1 to 4; The detection module is used to verify the information to be processed in the targeted analysis module; The preliminary investigation event module is used to create network-related events and / or convert the website intelligence generated by the targeted analysis module into preliminary investigation events.
6. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for collecting clues of Internet-related events according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for collecting clues of Internet-related events according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Home location website supervision system
CN107181620A
Data association method and device, electronic equipment and computer readable storage medium
CN112804210A