A payment website identification method and device, electronic equipment and storage medium

By identifying access features, webpage features, and website association features of payment URLs, this technology solves the problems of low efficiency and accuracy in payment URL identification in existing technologies, and achieves fast and accurate payment URL identification, especially improving the identification efficiency and accuracy in the identification of third-party payment URLs.

CN114329470BActive Publication Date: 2025-12-16EVERSEC BEIJING TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111613069.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-27
Publication Date
2025-12-16
Estimated Expiration
2041-12-27

AI Technical Summary

Technical Problem

Existing payment URL identification methods are unable to quickly and accurately identify payment URLs, resulting in low identification efficiency and accuracy.

Method used

By acquiring the payment URL to be identified, we perform access feature identification, payment webpage feature identification, and payment website association feature identification, and combine these with preset conditions to determine the target payment URL.

Benefits of technology

It enables fast and accurate identification of payment URLs, improving identification efficiency and accuracy, especially enhancing the ability to detect illegal platforms when identifying third-party payment URLs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329470B_ABST
    Figure CN114329470B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a payment website identification method and device, electronic equipment and storage medium. The payment website identification method can include the following steps: obtaining a payment website to be identified, and performing access feature identification on the payment website to be identified; in the case that the access feature identification result meets the preset access feature condition, performing payment webpage feature identification on the payment website to be identified; in the case that the payment webpage feature identification result meets the preset payment webpage feature condition, performing payment website association feature identification on the payment website to be identified; and in the case that the payment website association feature identification result meets the preset payment website association feature condition, determining the payment website to be identified as a target payment website. The technical solution of the embodiments of the present application can quickly and accurately identify the payment website, thereby improving the efficiency and accuracy of payment website identification.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of Internet, and particularly relate to a payment website identification method and device, an electronic device and a storage medium. BACKGROUND

[0002] In recent years, with the development of information technology and mobile Internet, the Internet has penetrated into people's daily life. People can query data, buy goods or socialize through the Internet, which brings great convenience to people. However, while the Internet brings convenience to people's life, the security situation of the Internet is not optimistic, for example, various types of Trojan viruses disguised as normal files spread at will, phishing websites imitate normal websites to steal user account passwords, or use false orders of third-party payment platforms to collect illegal funds to complete illegal payment transactions online.

[0003] The existing payment website identification method is usually through setting a payment website whitelist feature library or setting a payment website blacklist feature library and the like. However, the payment website whitelist feature library cannot list all normal payment websites, and the payment website blacklist feature library cannot identify payment websites outside the blacklist feature library, and the like, so it is unable to quickly and accurately identify payment websites. SUMMARY

[0004] Embodiments of the present application provide a payment website identification method, device, electronic device and storage medium, which can quickly and accurately identify payment websites, thereby improving the efficiency and accuracy of payment website identification.

[0005] In a first aspect, embodiments of the present application provide a payment website identification method, comprising:

[0006] obtaining a payment website to be identified, and performing access feature identification on the payment website to be identified;

[0007] performing payment webpage feature identification on the payment website to be identified in a case where the access feature identification result meets a preset access feature condition;

[0008] performing payment website association feature identification on the payment website to be identified in a case where the payment webpage feature identification result meets a preset payment webpage feature condition;

[0009] determining the payment website to be identified as a target payment website in a case where the payment website association feature identification result meets a preset payment website association feature condition.

[0010] In a second aspect, embodiments of the present application further provide a payment website identification device, comprising:

[0011] The access feature recognition module is configured to acquire a payment website to be identified and perform access feature recognition on the payment website to be identified.

[0012] The payment webpage feature recognition module is configured to perform payment webpage feature recognition on the payment website to be identified when the access feature recognition result meets a preset access feature condition.

[0013] The payment website association feature recognition module is configured to perform payment website association feature recognition on the payment website to be identified when the payment webpage feature recognition result meets a preset payment webpage feature condition.

[0014] The target payment website determination module is configured to determine the payment website to be identified as a target payment website when the payment website association feature recognition result meets a preset payment website association feature condition.

[0015] In a third aspect, an electronic device is provided, and the electronic device includes:

[0016] one or more processors;

[0017] a storage device configured to store one or more programs;

[0018] When the one or more programs are executed by the one or more processors, the one or more processors implement the payment website identification method provided by any of the embodiments of the present application.

[0019] In a fourth aspect, a computer storage medium is provided, and the computer storage medium stores a computer program, which, when executed by a processor, implements the payment website identification method provided by any of the embodiments of the present application.

[0020] The embodiments of the present application acquire a payment website to be identified, perform access feature recognition on the payment website to be identified, perform payment webpage feature recognition on the payment website to be identified when the access feature recognition result meets a preset access feature condition, perform payment website association feature recognition on the payment website to be identified when the payment webpage feature recognition result meets a preset payment webpage feature condition, and determine the payment website to be identified as a target payment website when the payment website association feature recognition result meets a preset payment website association feature condition, thereby solving the problem that the existing payment website identification method cannot quickly and accurately identify a payment website, and enabling the payment website to be quickly and accurately identified, thereby improving the efficiency and accuracy of payment website identification. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 is a flowchart of a payment website identification method provided by an embodiment of the present application;

[0022] Figure 2 is a specific example flowchart of a payment website identification method provided by the embodiment one of the present application;

[0023] Figure 3 is a schematic diagram of a payment website identification device provided by the embodiment two of the present application;

[0024] Figure 4 is a structural schematic diagram of an electronic device provided by the embodiment three of the present application. DETAILED DESCRIPTION

[0025] The present application will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application.

[0026] In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the contents. Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted by flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of the operations can be implemented in parallel, concurrently or simultaneously. In addition, the order of the operations can be rearranged. The processes can be terminated when the operations are completed, but can also have additional steps not included in the drawings. The processes can correspond to methods, functions, procedures, subroutines, subprograms, etc.

[0027] The terms "first" and "second" and the like in the specification and claims and drawings of the embodiments of the present application are used to distinguish different objects, but not to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can include steps or units not listed.

[0028] Embodiment one

[0029] Figure 1 is a flowchart of a payment website identification method provided by the embodiment one of the present application. The embodiment can be applicable to the case of quickly and accurately identifying payment website. The method can be executed by a payment website identification device, which can be realized by software and / or hardware, and can be directly integrated in an electronic device that executes the method. The electronic device can be a terminal device or a server device, and the present application does not limit the type of the electronic device that executes the payment website identification method. Specifically, as shown in the figure, the payment website identification method can include the following steps: Figure 1 ​

[0030] S110, acquire a payment website to be identified, and perform access feature identification on the payment website to be identified.

[0031] The payment website to be identified can be any payment website to be identified, for example, can be a four-party payment website to be identified, or a three-party payment website to be identified, and the like, and the embodiments of the present application do not limit this. The access feature identification can be identification of any access feature of the payment website to be identified, for example, can be identification of an access user quantity feature of the payment website to be identified, or identification of an access time feature of the payment website to be identified, or identification of an access frequency feature of the payment website to be identified, and the like, and the embodiments of the present application do not limit this.

[0032] In the embodiments of the present application, the payment website to be identified is acquired, and access feature identification is performed on the payment website to be identified, to obtain an access feature identification result of the payment website to be identified. Specifically, acquiring the payment website to be identified can be acquiring a payment website to be identified provided by an operator. It should be noted that the embodiments of the present application do not limit the specific manner of acquiring the payment website to be identified, as long as the identification of the payment website to be identified can be achieved.

[0033] Optionally, before the access feature identification on the payment website to be identified, the method further includes: acquiring a payment main domain name to be identified of the payment website to be identified; performing white list filtering on the payment main domain name to be identified; and performing record website screening on the payment website to be identified, to perform website data cleaning on the payment website to be identified, in a case where the payment main domain name to be identified does not satisfy a white list filtering condition.

[0034] The payment main domain name to be identified can be a main domain name of the payment website to be identified, for example, can be a four-party payment main domain name to be identified, or a three-party payment main domain name to be identified, and the like, and the embodiments of the present application do not limit this. The white list filtering condition can be a condition of filtering the payment main domain name to be identified using a white list, for example, can be that the payment main domain name to be identified can 100% match the white list, or the matching rate of the payment main domain name to be identified and the white list reaches a certain threshold, and the like, and the embodiments of the present application do not limit this. The record website screening can be screening of a website that has completed record in a national industrial and information technology department. The website data cleaning can be data cleaning of the payment website to be identified that has been determined.

[0035] Specifically, before the access feature recognition of the to-be-recognized payment website, a to-be-recognized payment main domain name of the to-be-recognized payment website can be acquired to perform whitelist filtering on the to-be-recognized payment main domain name, and it is determined whether the to-be-recognized payment main domain name meets the whitelist filtering condition. If the to-be-recognized payment main domain name does not meet the whitelist filtering condition, the to-be-recognized payment website can be subjected to the record website screening, so as to further perform website data cleaning on the to-be-recognized payment website. It can be understood that the whitelist can store the main domain names of known normal payment websites. The whitelist filtering on the to-be-recognized payment main domain name can filter out the to-be-recognized payment website of the known normal payment website, and retain the unknown to-be-recognized payment website. The to-be-recognized payment main domain name does not meet the whitelist filtering condition, which indicates that the to-be-recognized payment main domain name is not the main domain name of the known normal payment website, and the to-be-recognized payment website can be further subjected to the record website screening. If the to-be-recognized payment main domain name meets the whitelist filtering condition, it can be determined that the to-be-recognized payment website is a normal payment website.

[0036] Optionally, the access feature recognition of the to-be-recognized payment website can include: acquiring a to-be-recognized payment website access user quantity of users accessing the to-be-recognized payment website within a first preset time; in a case where the to-be-recognized payment website access user quantity meets a preset access user quantity condition, determining a to-be-recognized website corresponding to the to-be-recognized payment website; determining a to-be-recognized website access user and a first access user quantity of users accessing the to-be-recognized website within the first preset time; determining a visited URL quantity of the to-be-recognized website accessed by the to-be-recognized website access user within the first preset time; and performing access feature recognition on the to-be-recognized payment website according to the first access user quantity and the visited URL quantity.

[0037] The first preset time can be a preset time, for example, can be a preset week, or can be a preset number of days, and the embodiment of the application does not limit this. The number of users accessing the to-be-identified payment website can be the number of users accessing the to-be-identified payment website. The preset access user number condition can be a condition for the number of users accessing the to-be-identified payment website, for example, can be a condition of being more than a preset access user number threshold, or can be a condition of being less than a preset access user number threshold, and the embodiment of the application does not limit this. The to-be-identified website can be a website corresponding to the to-be-identified payment website. It can be understood that one website can correspond to multiple websites, that is, one website can be accessed through different websites. The to-be-identified website access user can be a user accessing the to-be-identified website. It can be understood that a user accessing the to-be-identified website through any website in the to-be-identified website can be determined as a to-be-identified website access user. The first access user number can be the number of users accessing the to-be-identified website. The number of accessed URLs can be the number of URLs (Uniform Resource Locator, Uniform Resource Locator) accessed by the user in the to-be-identified website. It can be understood that one website can include multiple URLs, and a user can access one or more URLs in the to-be-identified website when accessing the to-be-identified website.

[0038] Specifically, after obtaining the to-be-identified payment website, the number of to-be-identified payment website access users accessing the to-be-identified payment website within the first preset time can be further obtained, and it is determined whether the number of to-be-identified payment website access users satisfies the preset access user number condition. If the number of to-be-identified payment website access users satisfies the preset access user number condition, the to-be-identified website corresponding to the to-be-identified payment website can be determined, and the number of to-be-identified website access users accessing the to-be-identified website within the first preset time and the first access user number can be determined, so as to determine the number of accessed URLs of the to-be-identified website accessed by the to-be-identified website access user within the first preset time, and to identify the access feature of the to-be-identified payment website according to the first access user number and the number of accessed URLs.

[0039] Optionally, identifying the access feature of the to-be-identified payment website according to the first access user number and the number of accessed URLs can include: obtaining a second access user number of the number of accessed URLs being less than a target number of accessed URLs; and identifying the access feature of the to-be-identified payment website according to the first access user number and the second access user number.

[0040] The target accessed URL quantity can be a target value of the number of accessed URLs. The second access user quantity can be a number of users whose number of accessed URLs in the to-be-identified website is less than the target value. For example, if the second access user quantity is 5 and the target accessed URL quantity is 4, it indicates that there are 5 users whose number of accessed URLs in the to-be-identified website is less than 4 when accessing the to-be-identified website.

[0041] Specifically, the second access user quantity whose number of accessed URLs is less than the target accessed URL quantity is obtained, and the access feature of the to-be-identified payment website is identified according to the first access user quantity and the second access user quantity. Specifically, the access feature of the to-be-identified payment website can be identified according to a ratio of the second access user quantity to the first access user quantity.

[0042] S120, in a case where the access feature identification result meets a preset access feature condition, performing payment webpage feature identification on the to-be-identified payment website.

[0043] The access feature identification result can be a result obtained by performing access feature identification on the to-be-identified payment website, for example, can be a number of users accessing the to-be-identified payment website, can be a frequency of accessing the to-be-identified payment website, or can be a ratio of the second access user quantity to the first access user quantity, and the embodiments of the present application do not limit this. The preset access feature condition can be a condition of the access feature of the to-be-identified payment website, for example, can be a condition of the access frequency feature of the to-be-identified payment website, or can be a condition of the access user quantity feature of the to-be-identified payment website, and the embodiments of the present application do not limit this. The payment webpage feature identification can be identification of any webpage feature of the payment website to be identified, for example, can be identification of the payment webpage code feature of the payment website to be identified, or can be identification of the payment webpage picture feature of the payment website to be identified, and the embodiments of the present application do not limit this.

[0044] In the embodiments of the present application, after obtaining the to-be-identified payment website and performing access feature identification on the to-be-identified payment website, the payment webpage feature identification can be further performed on the to-be-identified payment website in a case where the access feature identification result meets the preset access feature condition. For example, if the access feature identification result is a ratio of the second access user quantity to the first access user quantity, and the preset access feature condition is greater than a preset ratio, when the ratio of the second access user quantity to the first access user quantity is greater than the preset ratio, it can be determined that the access feature identification result meets the preset access feature condition.

[0045] It should be noted that the payment webpage feature of the payment website to be identified can be acquired after the payment website to be identified is acquired, or can be acquired after the access feature recognition result meets the preset access feature condition, and the execution sequence of acquiring the payment webpage feature of the payment website to be identified is not limited in the embodiments of the present application.

[0046] Optionally, the payment webpage feature recognition on the payment website to be identified can include: acquiring the payment webpage code and / or the payment two-dimensional code to be identified of the payment website to be identified; and recognizing the webpage feature of the payment website to be identified according to the payment webpage code and / or the payment two-dimensional code to be identified.

[0047] In the embodiments of the present application, the payment webpage code to be identified can be the payment-related code in the webpage corresponding to the payment website to be identified. The payment two-dimensional code to be identified can be the payment two-dimensional code in the webpage corresponding to the payment website to be identified.

[0048] Specifically, after the payment website to be identified is acquired and the access feature recognition on the payment website to be identified is performed, the payment webpage code to be identified or the payment two-dimensional code to be identified of the payment website to be identified can be acquired, or the payment webpage code to be identified and the payment two-dimensional code to be identified of the payment website to be identified can be acquired simultaneously, in the case that the access feature recognition result meets the preset access feature condition, so as to recognize the webpage feature of the payment website to be identified according to the payment webpage code to be identified or the payment two-dimensional code to be identified, or to recognize the webpage feature of the payment website to be identified according to the payment webpage code to be identified and the payment two-dimensional code to be identified. It can be understood that if the webpage corresponding to the payment website to be identified has no payment-related code and no payment two-dimensional code, it means that the payment website to be identified has no payment behavior, and then it can be determined that the payment website to be identified is a non-payment website.

[0049] S130, in the case that the payment webpage feature recognition result meets the preset payment webpage feature condition, performing payment website association feature recognition on the payment website to be identified.

[0050] The payment webpage feature recognition result can be a result of performing payment webpage feature recognition on the payment website to be identified, for example, a result of whether the webpage corresponding to the payment website to be identified includes payment-related code, or a result of whether the webpage corresponding to the payment website to be identified includes a payment two-dimensional code, and the like. The preset payment webpage feature condition can be a condition that the payment webpage feature needs to be met by the payment website to be identified, for example, a condition that the webpage corresponding to the payment website to be identified includes payment-related code or a payment two-dimensional code, or a condition that the webpage corresponding to the payment website to be identified includes both payment-related code and a payment two-dimensional code, and the like. The payment website association feature recognition can be to recognize the features of the website associated with the payment website to be identified, for example, to recognize the features of the website having payment demand, and the like.

[0051] In the embodiment of the present application, after performing payment webpage feature recognition on the payment website to be identified, the payment website association feature recognition can be further performed on the payment website to be identified in a case where the payment webpage feature recognition result meets the preset payment webpage feature condition. It can be understood that by recognizing the features of the website associated with the payment website to be identified, the reason for the user to generate the payment behavior can be further determined. For example, if the features of the website associated with the payment website to be identified are electronic products or cosmetics having payment demand, and the like, it indicates that the reason for the user to generate the payment behavior is to purchase electronic products or cosmetics, and the like, and then it can be determined that the payment website to be identified is a normal payment website. If the features of the website associated with the payment website to be identified are sensitive websites having payment demand, it indicates that the reason for the user to generate the payment behavior is to watch sensitive information or participate in sensitive activities, and the like, and then it can be determined that the payment website to be identified is an abnormal payment website.

[0052] It should be noted that the payment website association features of the payment website to be identified can be acquired after acquiring the payment website to be identified, or can be acquired after the payment webpage feature recognition result meets the preset payment webpage feature condition, and the execution order of acquiring the payment website association features of the payment website to be identified is not limited in the embodiment of the present application.

[0053] Optionally, the payment website association feature recognition on the payment website to be identified can include: determining a payment website to be identified access user of the payment website to be identified; acquiring an associated payment website to be identified accessed by the payment website to be identified access user within a second preset time; and recognizing the payment website association features of the payment website to be identified according to the associated payment website to be identified.

[0054] The user to be identified accessing the payment website can be a user accessing the payment website to be identified. The second preset time can be another time set in advance. The associated website to be identified can be a website associated with the payment website to be identified and having a payment demand, for example, can be an associated sensitive website to be identified, and the like. The embodiments of the present application do not limit this.

[0055] Specifically, after the payment webpage feature identification of the payment website to be identified, the user to be identified accessing the payment website to be identified can be determined in a case where the payment website feature identification result meets a preset payment webpage feature condition, and the associated website to be identified accessed by the user to be identified accessing the payment website to be identified within a second preset time is obtained, so as to identify the payment website association feature of the payment website to be identified according to the associated website to be identified. It can be understood that the reason for the user to generate the payment behavior can be determined according to the website accessed by the user before the payment.

[0056] S140, in a case where the payment website association feature identification result meets a preset payment website association feature condition, the payment website to be identified is determined as a target payment website.

[0057] The payment website association feature identification result can be a result obtained by identifying the payment website association feature, for example, can be that the associated website to be identified is a sensitive website, or can be that the associated website to be identified is an electronic product website, and the like. The embodiments of the present application do not limit this. The preset payment website association feature condition can be a condition of the payment website association feature that the payment website to be identified needs to meet. The target payment website can be a target result obtained by identifying the payment website to be identified, for example, can be a normal payment website, or can be an abnormal payment website, and the like. The embodiments of the present application do not limit this.

[0058] In the embodiments of the present application, after the payment website association feature identification of the payment website to be identified, the payment website to be identified can be determined as a target payment website in a case where the payment website association feature identification result meets a preset payment website association feature condition. For example, if the payment website association feature identification result is that the associated website to be identified is a sensitive website, and the preset payment website association feature condition is that the associated website to be identified is a sensitive website, it is indicated that the payment website association feature identification result meets the preset payment website association feature condition, and then the payment website to be identified can be determined as an abnormal payment website.

[0059] The technical scheme of the embodiment is characterized in that: the payment website to be identified is obtained, and access feature identification is performed on the payment website to be identified; in a case where the access feature identification result meets a preset access feature condition, payment webpage feature identification is performed on the payment website to be identified, and in a case where the payment webpage feature identification result meets a preset payment webpage feature condition, payment website association feature identification is performed on the payment website to be identified; in a case where the payment website association feature identification result meets a preset payment website association feature condition, the payment website to be identified is determined as a target payment website. The technical scheme solves the problem that the existing payment website identification method cannot quickly and accurately identify a payment website, and can quickly and accurately identify a payment website, thereby improving the efficiency and accuracy of payment website identification.

[0060] In order for those skilled in the art to better understand the payment website identification method of the embodiment of the present application, the application scenario of identifying a four-party payment website is taken as an example for specific description. With the popularization of online payment services, a large number of regular platforms providing online payment services have emerged. At the same time, many lawbreakers also pay attention to the emerging field of Internet payment, and they register false merchants on regular third-party payment platforms, use computer technology to generate false orders on the third-party payment platform, and collect illegal funds by using the false orders, thereby completing illegal payment transactions through the Internet. Since the four-party payment process is realized through the network, and the four-party payment platform may be closed at any time, and the traffic data also has real-time nature, the identification of the four-party payment website is more difficult, and it is of great significance to quickly and accurately identify the four-party payment website. Figure 2 is a specific example flowchart of the payment website identification method provided by the first embodiment of the present application, as shown in Figure 2 , which can specifically include the following steps:

[0061] (1) performing website data cleaning on the payment website to be identified: obtaining the payment website to be identified accessed by the user, the access time of the payment website to be identified and the webpage content corresponding to the payment website to be identified in the user traffic call log provided by the operator; extracting the payment main domain name to be identified of the payment website to be identified, and performing whitelist filtering on the payment main domain name to be identified to obtain the payment website to be identified which is not filtered; and calling a record information query interface to perform record website screening on the payment website to be identified which is not filtered to obtain the payment website to be identified which is not recorded.

[0062] (2) Access feature identification of unrecorded payment website to be identified: determining the number of users accessing the unrecorded payment website to be identified within a preset time, and obtaining the payment website to be identified whose number of users accessing is below a certain threshold; determining the website to be identified corresponding to the payment website to be identified, and determining the number of users accessing the website to be identified, the number of URLs in the website to be identified accessed by the users, and the number of users whose number of accessed URLs is less than or equal to 3, so as to obtain the website to be identified whose number of users whose number of accessed URLs is less than or equal to 3 is more than 95% of the number of users accessing the website to be identified, so as to determine the payment website to be identified corresponding to the website to be identified according to the website to be identified.

[0063] (3) Payment webpage feature identification of the determined payment website to be identified: obtaining the webpage corresponding to the payment website to be identified, and determining whether the webpage contains a payment code or a payment QR code; screening the payment website to be identified corresponding to the webpage containing the payment code or the payment QR code, and obtaining the domain name of the payment website to be identified.

[0064] (4) Payment website association feature identification of the payment website to be identified corresponding to the webpage containing the payment code or the payment QR code: determining the user accessing the payment website to be identified, and obtaining all access records of the user; determining whether the user accesses a sensitive website requiring payment within 10 minutes; when it is determined that the user accesses the sensitive website requiring payment within 10 minutes, the payment website to be identified is determined as a four-party payment website.

[0065] (5) Obtaining the website and domain name information of the payment website to be identified.

[0066] The above technical solution identifies the access feature, payment webpage feature and payment website association feature of the payment website to be identified, does not need to maintain a feature library, reduces the work of extracting and maintaining the feature library, can match the four-party payment platform outside the feature library, increases the ability to discover the four-party payment platform, and can directly find the four-party payment platform and the sensitive information of the corresponding service through the association of the website accessed by multiple users.

[0067] Embodiment Two

[0068] Figure 3 is a schematic diagram of a payment website identification device provided by Embodiment Two of the application, as shown in Figure 3 The device includes an access feature identification module 310, a payment webpage feature identification module 320, a payment website association feature identification module 330 and a target payment website determination module 340, wherein:

[0069] The access feature recognition module 310 is configured to obtain a payment website to be identified, and perform access feature recognition on the payment website to be identified.

[0070] The payment webpage feature recognition module 320 is configured to, when the access feature recognition result meets a preset access feature condition, perform payment webpage feature recognition on the payment website to be identified.

[0071] The payment website association feature recognition module 330 is configured to, when the payment webpage feature recognition result meets a preset payment webpage feature condition, perform payment website association feature recognition on the payment website to be identified.

[0072] The target payment website determination module 340 is configured to, when the payment website association feature recognition result meets a preset payment website association feature condition, determine the payment website to be identified as a target payment website.

[0073] The technical scheme of the embodiment is configured to obtain a payment website to be identified, and perform access feature recognition on the payment website to be identified, so as to, when the access feature recognition result meets a preset access feature condition, perform payment webpage feature recognition on the payment website to be identified, and, when the payment webpage feature recognition result meets a preset payment webpage feature condition, perform payment website association feature recognition on the payment website to be identified, so as to, when the payment website association feature recognition result meets a preset payment website association feature condition, determine the payment website to be identified as a target payment website. The technical scheme solves the problem that the existing payment website identification method cannot quickly and accurately identify a payment website, and can quickly and accurately identify a payment website, thereby improving the efficiency and accuracy of payment website identification.

[0074] Optionally, the access feature recognition module 310 can be specifically configured to obtain a payment main domain name of the payment website to be identified, perform white list filtering on the payment main domain name, and, when the payment main domain name does not meet the white list filtering condition, perform record website screening on the payment website to be identified, so as to perform website data cleaning on the payment website to be identified.

[0075] Optionally, the access feature recognition module 310 can be further specifically configured to obtain a number of payment website to be identified access users accessing the payment website to be identified within a first preset time, determine a website to be identified corresponding to the payment website to be identified when the number of payment website to be identified access users meets a preset access user number condition, determine a number of first access users and a number of accessed URLs of the website to be identified accessed by the website to be identified access users within the first preset time, and perform access feature recognition on the payment website to be identified according to the number of first access users and the number of accessed URLs.

[0076] Optionally, the access feature identification module 310 can be further configured to: obtain a second access user quantity whose accessed URL quantity is less than the target accessed URL quantity; and identify the access feature of the payment website to be identified according to the first access user quantity and the second access user quantity.

[0077] Optionally, the payment webpage feature identification module 320 can be specifically configured to: obtain the payment webpage code to be identified and / or the payment two-dimensional code to be identified of the payment website to be identified; and identify the webpage feature of the payment website to be identified according to the payment webpage code to be identified and / or the payment two-dimensional code to be identified.

[0078] Optionally, the payment website association feature identification module 330 can be specifically configured to: determine the access user of the payment website to be identified; obtain the associated website to be identified accessed by the access user of the payment website to be identified within a second preset time; and identify the payment website association feature of the payment website to be identified according to the associated website to be identified.

[0079] Optionally, the payment website to be identified can include a payment website to be identified of four parties; the payment main domain name to be identified can include a payment main domain name to be identified of four parties; and the associated website to be identified can include a sensitive website to be identified.

[0080] The payment website identification device described above can execute the payment website identification method provided by any embodiment of the present application, and has the corresponding function modules and beneficial effects of the execution method. Technical details not described in detail in the present embodiment can be referred to the payment website identification method provided by any embodiment of the present application.

[0081] Since the payment website identification device described above is a device that can execute the payment website identification method in the embodiments of the present application, based on the payment website identification method described in the embodiments of the present application, those skilled in the art can understand the specific implementation of the payment website identification device of the present embodiment and its various forms, so the payment website identification device how to implement the payment website identification method in the embodiments of the present application will not be described in detail here. As long as the device used to implement the payment website identification method in the embodiments of the present application is implemented by those skilled in the art, it belongs to the scope of the present application.

[0082] Embodiment Three

[0083] Figure 4 is a structural schematic diagram of an electronic device provided by the third embodiment of the present application. Figure 4 A block diagram of an exemplary electronic device 12 suitable for use in implementing embodiments of the present application is shown. Figure 4 The electronic device 12 shown is merely an example and should not limit the function and use range of the embodiments of the present application in any way.

[0084] like Figure 4 As shown, the electronic device 12 is represented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors 16, memory 28, and bus 18 connecting different system components (including memory 28 and processor 16).

[0085] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MCA) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0086] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including volatile and non-volatile media, removable and non-removable media.

[0087] Memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 4 Not shown; usually referred to as a "hard drive"). Although Figure 4A disk drive, a floppy disk drive, a CD-ROM drive, a DVD-ROM drive, or other removable media drive, can be provided in the computing device 12 for reading from and writing to a removable nonvolatile magnetic media (e.g., a "floppy disk"), and to a removable nonvolatile optical disk (e.g., a CD-ROM, a DVD-ROM, or another optical media). In these instances, each drive can be connected to the bus 18 by one or more data media interfaces. The memory 28 can include at least one program product having a set (e.g., at least one) of program modules that are configured to carry out the functions of embodiments of the application.

[0088] The program / utility 40, having a set (at least one) of program modules 42, can be stored in memory 28 by way of example, and not limitation, as well as an operating system, one or more application programs, other program modules, and program data, each or some combination thereof, can include implementation of a networking environment. The program modules 42 generally carry out the functions and / or methodologies of embodiments of the application as described herein.

[0089] The electronic device 12 can also communicate with one or more external devices 14 such as a keyboard or a pointing device, displays 24, etc.; other devices such as devices that enable a user to interact with the electronic device 12; and / or any devices (e.g., network card, modem, etc.) that enable the electronic device 12 to communicate with one or more other computing devices. Such communication can be facilitated by the Input / Output (I / O) interface 22. Still yet, the electronic device 12 can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the Internet, through a network adapter 20. As depicted, the network adapter 20 communicates with the other Figure 4 Other hardware and / or software modules can be used in conjunction with the electronic device 12, including but not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, (Redundant Arrays of Independent Disks (RAID) systems, tape drives, and data archival storage systems, etc.

[0090] The processor 16 performs various function applications and data processing by running programs stored in the memory 28, and implements the payment website identification method provided by the embodiment of the application: obtaining a payment website to be identified, and performing access feature identification on the payment website to be identified; in the case that the access feature identification result meets preset access feature conditions, performing payment webpage feature identification on the payment website to be identified; in the case that the payment webpage feature identification result meets preset payment webpage feature conditions, performing payment website association feature identification on the payment website to be identified; in the case that the payment website association feature identification result meets preset payment website association feature conditions, determining the payment website to be identified as a target payment website.

[0091] Embodiment four

[0092] The embodiment four of the application further provides a computer storage medium storing a computer program, which, when executed by a computer processor, is used to perform the payment website identification method provided by any one of the above embodiments of the application: obtaining a payment website to be identified, and performing access feature identification on the payment website to be identified; in the case that the access feature identification result meets preset access feature conditions, performing payment webpage feature identification on the payment website to be identified; in the case that the payment webpage feature identification result meets preset payment webpage feature conditions, performing payment website association feature identification on the payment website to be identified; in the case that the payment website association feature identification result meets preset payment website association feature conditions, determining the payment website to be identified as a target payment website.

[0093] The computer storage medium of the embodiment of the application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM) or a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component.

[0094] A computer readable signal medium can include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium can be any computer readable medium that can be involved in

[0095] The computer readable program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0096] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0097] Note that the foregoing are merely preferred embodiments and the principles of the present application. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made without departing from the scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the appended claims.

Claims

1. A payment URL identification method characterized by, The method comprises the following steps: obtaining a payment website to be identified, and performing access feature identification on the payment website to be identified; in the case that the access feature identification result meets the preset access feature condition, performing payment webpage feature identification on the payment website to be identified; in the case that the payment webpage feature identification result meets the preset payment webpage feature condition, performing payment website association feature identification on the payment website to be identified; in the case that the payment website association feature identification result meets the preset payment website association feature condition, determining the payment website to be identified as a target payment website; wherein, the access feature identification on the payment website to be identified comprises: obtaining the number of payment website to be identified access users accessing the payment website to be identified within a first preset time; in the case that the number of payment website to be identified access users meets the preset access user number condition, determining the website to be identified corresponding to the payment website to be identified; determining the number of website to be identified access users and first access users accessing the website to be identified within the first preset time; determining the number of accessed URLs of the website to be identified accessed by the website to be identified access users within the first preset time; performing access feature identification on the payment website to be identified according to the first access user number and the accessed URL number; wherein, the access feature identification on the payment website to be identified according to the first access user number and the accessed URL number comprises: obtaining the second access user number whose accessed URL number is less than the target accessed URL number; identifying the access feature of the payment website to be identified according to the first access user number and the second access user number.

2. The method of claim 1, wherein, Before the access feature identification on the payment website to be identified, the method further comprises: obtaining the payment main domain name to be identified of the payment website to be identified; performing whitelist filtering on the payment main domain name to be identified; in the case that the payment main domain name to be identified does not meet the whitelist filtering condition, performing record website screening on the payment website to be identified to perform website data cleaning on the payment website to be identified.

3. The method of claim 1, wherein, The payment webpage feature identification on the payment website to be identified comprises: obtaining the payment webpage code to be identified and / or the payment two-dimensional code to be identified of the payment website to be identified; identifying the webpage feature of the payment website to be identified according to the payment webpage code to be identified and / or the payment two-dimensional code to be identified.

4. The method of claim 2, wherein, The payment website association feature identification on the payment website to be identified comprises: determining the payment website to be identified access user of the payment website to be identified; obtaining the associated website to be identified accessed by the payment website to be identified access user within a second preset time; identifying the payment website association feature of the payment website to be identified according to the associated website to be identified.

5. The method of claim 4, wherein, The payment website to be identified comprises a payment website to be identified by four parties; the payment main domain name to be identified comprises a payment main domain name to be identified by four parties; and the associated website to be identified comprises an associated sensitive website to be identified.

6. A payment URL identifying apparatus characterized by comprising: The method comprises the following steps: The access feature identification module is configured to obtain a payment website to be identified and perform access feature identification on the payment website to be identified. The payment webpage feature identification module is configured to perform payment webpage feature identification on the payment website to be identified when the access feature identification result meets a preset access feature condition. The payment website association feature identification module is configured to perform payment website association feature identification on the payment website to be identified when the payment webpage feature identification result meets a preset payment webpage feature condition. The target payment website determination module is configured to determine the payment website to be identified as a target payment website when the payment website association feature identification result meets a preset payment website association feature condition. The access feature identification module is specifically configured to: obtain a number of payment website to be identified access users accessing the payment website to be identified within a first preset time; determine a website to be identified corresponding to the payment website to be identified when the number of payment website to be identified access users meets a preset access user number condition; determine a number of website to be identified access users and a first access user number accessing the website to be identified within the first preset time; determine a number of accessed URLs of the website to be identified accessed by the website to be identified access users within the first preset time; perform access feature identification on the payment website to be identified according to the first access user number and the number of accessed URLs. The access feature identification module is further configured to: obtain a second access user number smaller than the number of accessed URLs; and identify access features of the payment website to be identified according to the first access user number and the second access user number.

7. An electronic device, comprising: The electronic device includes: one or more processors; a storage device configured to store one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the payment website identification method of any one of claims 1-5.

8. A computer storage medium having stored thereon a computer program, characterized in that The program is executed by the processor to implement the payment website identification method of any one of claims 1-5.

Citation Information

Patent Citations

  • Screen locking method, device and browser for webpage

    CN103116725A

  • Method and device for detecting security of payment type website

    CN104158789A

  • Four-party payment website identification and user analysis method

    CN113268696A