A method for handling abnormal access in token-based electronic resource services

By adopting token-based abnormal access processing methods in electronic resource services, using a three-dimensional access control list to identify and restrict abnormal access behavior, the problems of resource crowding and service quality decline caused by abnormal access by electronic resources are solved, and a more effective anti-crawling effect is achieved.

CN115550027BActive Publication Date: 2025-05-16TONGFANG KNOWLEDGE NETWORK TECH CO LTD (BEIJING)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211180127.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2025-05-16
Estimated Expiration
2042-09-27

AI Technical Summary

Technical Problem

The risk of electronic resources being accessed abnormally is becoming increasingly serious, resulting in the crowding of service resources, increasing service costs and declining service quality. It is difficult for existing anti-crawling methods to effectively deal with the iterative update of network crawling technology.

Method used

The processing method of abnormal access in token-based electronic resource services is adopted. By receiving a request to verify whether the user access is normal by receiving the product server, the access control list (login token, IP, account) in three dimensions is determined whether there is abnormal access, and corresponding restrictions are carried out, the user access log is recorded and the access control list is updated.

Benefits of technology

Effectively identify and restrict individual users who are not normally accessed within the organization, prevent network crawling, protect service resources, reduce service costs, and improve service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550027B_ABST
    Figure CN115550027B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for processing abnormal access in a token-based electronic resource service, including: receiving a request initiated by a product service end to verify whether user access is normal; judging whether there is abnormal access according to a three-dimensional access control list; if there is abnormal access, entering relevant business processing; recording user access logs; updating the three-dimensional access control list; and returning the product service request processing result. The present invention can judge whether there is abnormal access to user access based on the behavior analysis related to the login token, and further analyze and judge whether there is abnormal access to the user IP and account based on the relationship between the user IP, account and the login token; and provides a solution for active defense protection of electronic resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and relates to relevant active defense technologies for anti-batch crawling of electronic resources, and in particular to a method for processing abnormal access in a token-based electronic resource service. Background Art

[0002] With the rapid development of digital information resources and the Internet, the risk of abnormal access to electronic resources is becoming more and more serious. Especially in the digital publishing industry, electronic resources are the lifeblood of the company. It is very important to identify abnormal access behaviors and take measures to protect them. At the same time, the load capacity used to provide electronic resource services is very expensive and limited. A large number of abnormal accesses occupy a large number of service resources, resulting in increased service costs and reduced service quality.

[0003] Many institutions such as universities and research institutes purchase cloud services from operators to provide electronic resource services to internal staff. Usually, readers of the same institution will use the same institutional account and use the electronic resource service through automatic IP login. It is common for institutional accounts or IP addresses to be blocked due to abnormal access by individual readers.

[0004] Most of the abnormal access to electronic resources comes from web crawlers or scripts running on the machine. There are many ways to prevent crawling, such as configuring Robots protocol, restricting IP, smart verification code, etc. Anti-crawling and crawling is an ever-evolving offensive and defensive game process. Summary of the invention

[0005] In order to solve the above technical problems, the purpose of the present invention is to provide a method for processing abnormal access in a token-based electronic resource service.

[0006] The purpose of the present invention is achieved through the following technical solutions:

[0007] A method for processing abnormal access in a token-based electronic resource service, comprising:

[0008] A. Receive a request from the product server to verify whether the user access is normal;

[0009] B. Determine whether there is abnormal access based on the access control list of three dimensions;

[0010] C. If there is abnormal access, relevant business processing will be carried out;

[0011] D. Record user access logs;

[0012] E. Update the access control lists of three dimensions;

[0013] F. Return the product service request processing results.

[0014] Compared with the prior art, one or more embodiments of the present invention may have the following advantages:

[0015] The access control lists based on three dimensions can be combined to adapt to more business scenarios. In particular, the access control list based on the login token can identify individual users with abnormal access within the organization and restrict them.

[0016] It can effectively deal with the problem of failure of related active defense technologies caused by iterative updates of network crawling technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flow chart of a method for handling abnormal access in a token-based electronic resource service;

[0018] Figure 2 It is to determine whether there is an abnormal access flow chart based on the access control list of three dimensions;

[0019] Figure 3 It is a flowchart for updating the access control list in three dimensions;

[0020] Figure 4 It is a flowchart for updating the login token access control list;

[0021] Figure 5 It is the flow chart for updating IP access control list;

[0022] Figure 6 This is the flow chart for updating the account access control list. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention will be further described in detail below in conjunction with embodiments and drawings.

[0024] like Figure 1 As shown, a method for handling abnormal access in a token-based electronic resource service includes:

[0025] Step 10: receiving a request initiated by the product server to verify whether the user access is normal;

[0026] Receiving requests initiated by the product server to verify whether user access is normal is the final service form provided by this solution and is also the main data input channel. The request content contains four types of information: login token, user IP, operation type, and operation object. Among them, the login token is the pass code obtained by the user after logging into the system. The login token can be used to obtain the account information used for login; the user IP is the IP of the user's terminal device; the operation type can be browsing, downloading, online reading and other operations for electronic resources; the operation object refers to specific electronic resources such as documents, books, and videos.

[0027] Step 20 determines whether there is abnormal access based on the access control list of the three dimensions;

[0028] The three-dimensional access control lists include the login token access control list, IP access control list, and account access control list, which are obtained by the system through analyzing the user access log according to the rule algorithm, and respectively store the login tokens, IPs, and accounts with abnormal access, as well as the abnormal information codes of abnormal access. The abnormal information code is a code after exhaustively enumerating all abnormal access situations.

[0029] like Figure 2 As shown in FIG. 1 , a flowchart for determining whether there is abnormal access based on the access control list of three dimensions is shown, which specifically includes:

[0030] Step 1: Check whether there is any abnormal access in this login. Query the login token access control list based on the login token. If it exists, enter the process of restricting the use of the login token.

[0031] Step 2: Whether there is abnormal access using the IP. First, determine whether the IP exists in the IP whitelist. If so, proceed directly to the next step. Secondly, considering the situation where multiple accounts share the same IP access, the account and IP can be combined as the primary key of the IP access control list; query the account and the association relationship between the login token to obtain the account, query the IP access control list based on the combination of the account and IP, and if it exists, enter the process of restricting the use of the IP.

[0032] Step 3: Whether there is any abnormal access using the account. First, determine whether the account exists in the account whitelist. If so, proceed directly to the next step. Secondly, query the account and the login token based on the association relationship to obtain the account, and query the account access control list based on the account. If it exists, enter the process of restricting the use of the account.

[0033] Step 4: If the above three steps are passed, return to normal access.

[0034] Step 30: If there is abnormal access, enter the relevant business processing flow;

[0035] When a user has abnormal access, corresponding restriction measures are taken on the user's access according to the rules based on the different situations in the three dimensions of login token, IP and account. The method includes:

[0036] (1) When there is abnormal access to the login token, the use of the login token is restricted. The restriction method is mainly to introduce a human-machine verification process, and block the access of machine behavior by asking the user to enter a verification code. If the abnormal access still exists after the user enters the verification code n times, the login token will be directly invalidated and the user needs to log in again. The parameter n can be regularly obtained through positive and negative sample set training of historical user log data or direct statistics, allowing business personnel to modify the settings.

[0037] (2) When an IP has abnormal access, restrict the use of the IP.

[0038] The abnormal access IP analyzed based on the login token and the abnormal access IP analyzed based on the situation of re-login for each operation will only be used for the relevant account to import the human-machine verification process during the use of the IP. If the abnormal access situation still exists after an account enters the verification code m times, the account will be directly prohibited from using the service through the IP for n hours. The parameters m and n can be regularly obtained through positive and negative sample set training of historical user log data or direct statistics, allowing business personnel to modify the settings.

[0039] According to the number of accounts and operation times of a single IP, the IP with abnormal access is directly banned from using the service for n hours. The parameter n can be regularly obtained through positive and negative sample set training of historical user log data or direct statistics, and business personnel are allowed to modify the settings.

[0040] (3) When an account has abnormal access, the account is prohibited from using the service for n hours. The parameter n can be obtained regularly through positive and negative sample set training of historical user log data or direct statistics, and business personnel are allowed to modify the setting.

[0041] Step 40 records user access logs;

[0042] The recorded user access log content includes the login token, account, user IP, operation type, operation object, and operation time; the account is obtained by querying the association relationship through the login token, the operation time is the system time, and the login token, user IP, operation type, and operation object are obtained from the request initiated by the receiving product server to verify whether the user access is normal.

[0043] Step 50 updates the access control list of three dimensions;

[0044] First, the user access log is analyzed through the rule algorithm to obtain the login token of abnormal access and store it in the login token access control list; then based on the relationship between the user IP, account and token, the rule algorithm is used to analyze the IP and account of abnormal access and store them in the IP access control list and account access control list. Since this process requires a lot of calculations, the system should calculate and update the access control list of three dimensions through offline services.

[0045] like Figure 3 As shown in FIG. 1 , a flowchart for updating the access control list in three dimensions is shown, which specifically includes:

[0046] Step 1: Update the login token access control list.

[0047] like Figure 4 As shown, it is a flow chart for updating the login token access control list, and the method includes:

[0048] (1) According to the login token and operation type, the user access log of the day is aggregated to obtain the login token access statistics table of the day including the login token, operation type, number of operations, earliest operation time, latest operation time, and operation frequency. The operation frequency calculation formula is as follows:

[0049]

[0050] Among them, F is the operation frequency of the login token, in times / second; OperateTimes is the number of operations of a certain operation of the login token on that day; MaxTime is the latest operation time of the login token on that day; MinTime is the earliest operation time of the login token on that day.

[0051] (2) Screen login tokens with abnormal access based on operation frequency. Set n groups of thresholds, each of which contains m operations and has an average time interval of up to t seconds. The thresholds should be regularly trained through positive and negative sample sets of historical user log data or directly obtained through statistics, and business personnel should be allowed to modify the settings; analyze the login token access statistics table for the day, make n groups of calculations, and save the login tokens that reach each group of thresholds and the abnormal access exception information code into the temporary list of abnormal access login tokens.

[0052] (3) Filter out login tokens with abnormal access based on the number of operations. Set a threshold value, which represents the maximum number of operations of a login token on that day. This can be obtained through regular training of positive and negative sample sets of historical user log data or direct statistics, and business personnel are allowed to modify the settings; analyze the login token access statistics table of the day, and save the login tokens that reach the threshold and the abnormal access exception information code into the temporary list of abnormal access login tokens.

[0053] (4) After deduplication of the above temporary list according to the login token, the login token access control list is updated. When deduplication is performed, for the data of multiple login tokens, the record with the most operations is retained.

[0054] Step 2: Update the IP access control list.

[0055] like Figure 5 As shown, it is a flow chart for updating an IP access control list, and the method includes:

[0056] (1) Filter the user access logs of the day according to the temporary list of abnormal access login tokens to obtain the user abnormal access log data.

[0057] (2) Perform statistical analysis on the user's abnormal access log data to obtain a statistical table of the IP abnormal access of the day, including the IP, account, operation type, number of abnormal access login tokens, total number of operations, average number of operations, earliest operation time, latest operation time, highest operation frequency, and average operation frequency.

[0058] (3) Screen and determine the IP and account with abnormal access based on the number of abnormal access login tokens. First, set a threshold, which represents the maximum number of abnormal access tokens allowed to be generated by an account using a single IP. This can be regularly obtained through positive and negative sample set training of historical user log data or directly statistically obtained and business personnel are allowed to modify the settings. Secondly, analyze the daily IP abnormal access statistics table, and save the IP, account and abnormal access abnormal information codes that reach the threshold into the temporary list of abnormal access IPs on that day.

[0059] (4) Analyze the situation where each operation requires re-login, and screen and determine the IP and account of abnormal access. This step can make up for the deficiency that the login token analysis cannot cover each operation. First, count the user access logs of the day to obtain a list containing IP, account, P1, and P2; P1 refers to the number of login tokens that are only operated once; P2 refers to the proportion of situations where the login token is only operated once, which is equal to P1 divided by the total number of operations using the IP for the account. Secondly, set a set of thresholds, that is, the maximum value of P1 and P2, which can be regularly trained through positive and negative sample sets of historical user log data or directly obtained through statistics and allow business personnel to modify the settings. Finally, analyze the list and save the abnormal information codes of IP, account and abnormal access that reach the threshold into the temporary list of abnormal access IP for the day.

[0060] (5) Determine the IP of abnormal access based on the number of accounts and the number of operations used by a single IP. This step can strengthen defense against abnormal access through a list of accounts using several IPs. First, count the user access logs of the day to obtain a list of IPs, number of accounts, and number of operations. Secondly, set a set of thresholds, namely the maximum number of accounts used by a single IP m and the maximum number of operations n per day using a single account using a single IP. m and n can be regularly obtained through positive and negative sample set training of historical user log data or directly obtained through statistics, and business personnel are allowed to modify the settings. Finally, analyze the list and save the IPs that reach the threshold and the abnormal access exception information code into the temporary list of abnormal access IPs for the day.

[0061] (6) If there is abnormal access to the IP and account, relevant personnel will be notified via mobile phone text message or email; the relevant personnel are business personnel or customer contacts related to the account configured by the system.

[0062] (7) The system sets up an IP whitelist. The IPs in the whitelist are not restricted by the IP access control list and are managed by business personnel according to business needs. The main content of this process is to transfer the expired IP whitelist records to the historical records.

[0063] (8) Update the IP access control list after deduplication based on the temporary list of IP addresses with abnormal access on that day. When deduplication is performed, for data with multiple IP addresses and accounts, only the records with the most operations are retained.

[0064] Step 3: Update the account access control list.

[0065] like Figure 6 As shown, it is a flow chart for updating the account access control list, and the method includes:

[0066] (1) Based on the login token access control list and the IP access control list, a statistical table of abnormal access of the account on the day is statistically analyzed, including the account number, the number of abnormal access IPs, the number of abnormal access login tokens, the number of abnormal access operations, the earliest abnormal access operation time, the latest abnormal access operation time, the highest abnormal access operation frequency, and the average abnormal access operation frequency.

[0067] (2) Set a set of thresholds, i.e., the maximum number of IP addresses m that can be used to access an account abnormally and the maximum number of login tokens n that can be used to access an account abnormally. m and n can be obtained regularly through positive and negative sample set training of historical user log data or directly through statistics, and business personnel are allowed to modify the settings.

[0068] (3) Analyze the daily account abnormal access statistics table, filter out the accounts that reach the threshold and the abnormal information codes of abnormal access, and update them into the account access control list.

[0069] (4) If there is any abnormal access to the account, relevant personnel will be notified via text message or email; the relevant personnel are business personnel or customer contacts related to the account configured by the system.

[0070] (5) The system sets up an account whitelist. Accounts in the whitelist are not restricted by the account access control list and are managed by business personnel according to business needs. The main content of this process is to transfer the expired account whitelist records to the historical records.

[0071] Step 60 returns the product service request processing result;

[0072] The processing result of the returned product service request includes whether there is abnormal use and the information code of the abnormal use; the information code is encoded after exhaustively listing all abnormal use situations.

[0073] Although the embodiments disclosed in the present invention are as above, the above contents are only embodiments adopted for facilitating the understanding of the present invention and are not intended to limit the present invention. Any technician in the technical field to which the present invention belongs can make any modifications and changes in the form and details of the implementation without departing from the spirit and scope disclosed in the present invention, but the patent protection scope of the present invention shall still be subject to the scope defined in the attached claims.

Claims

1. A method for handling abnormal access in a token-based electronic resource service, characterized in that: include: A. Receive a request from the product server to verify whether the user access is normal; B. Determine whether there is abnormal access based on the access control list of three dimensions; C. If there is abnormal access, relevant business processing will be carried out; D. Record user access logs; E. Update the access control lists of three dimensions; F. Return the processing result of product service request; The step E specifically includes: updating the login token access control list, updating the IP access control list, and updating the account access control list; The updating of the login token access control list specifically includes: 1) According to the login token and operation type, aggregate the user access log of the day to obtain the login token access statistics table of the day including the login token, operation type, number of operations, earliest operation time, latest operation time and operation frequency; wherein the operation frequency calculation formula is: F is the operation frequency of the login token, OperateTimes is the number of operations of a certain operation on the login token on the same day, MaxTime is the latest operation time of the login token on the same day, and MinTime is the earliest operation time of the login token on the same day; 2) Screening login tokens with abnormal access based on operation frequency; 3) Filter login tokens with abnormal access based on the number of operations; Set a threshold value, which represents the maximum number of operations of the login token on the same day. Regularly train the positive and negative sample sets of historical user log data or directly obtain the statistics and allow business personnel to modify the settings; analyze the login token access statistics table of the day, and save the login tokens that reach the threshold and the abnormal access exception information codes into the temporary list of abnormal access login tokens; 4) After deduplicating the temporary list of abnormal accesses according to the login token, update the login token access control list; when deduplicating, for the data of multiple login tokens, retain the record with the most operations.

2. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: The request content in A includes four types of information: login token, user IP, operation type, and operation object.

3. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: The three-dimensional access control list includes the login token access control list, the IP access control list, and the account access control list; B specifically includes: B1. Determine whether there is any abnormal access in this login. If yes, restrict the use of login token; otherwise, execute B2. B2. Determine whether the IP is in the IP whitelist. If yes, determine whether the account used is in the account whitelist. Otherwise, determine whether the IP is used for abnormal access. If the IP is used abnormally, restrict the use of the IP. Otherwise, execute B3. B3. Determine whether the account is in the account whitelist. If yes, record the user behavior log. Otherwise, determine whether the account has abnormal access. If the account has abnormal access, restrict the account use. Otherwise, record the user behavior log. B4. Perform normal access.

4. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: The C specifically includes: C1. When there is abnormal access to the login token, limit the use of the login token C2: When there is abnormal access to an IP, restrict the use of the IP; C3. When an account is accessed abnormally, the account will be prohibited from using the service for n hours.

5. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: The user access log content recorded in the D includes: login token, account, user IP, operation type, operation object, and operation time; the account is obtained by querying the association relationship through the login token, and the operation time is the system time; the login token, user IP, operation type, and operation object are obtained from the request initiated by the receiving product service end to verify whether the user access is normal.

6. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: The updating of the IP access control list specifically includes: 1) Filter the user access logs of the day according to the temporary list of abnormal access login tokens to obtain the user's abnormal access log data; 2) Perform statistical analysis on the user's abnormal access log data to obtain a statistical table of abnormal IP access on the day, including IP, account, operation type, number of abnormal access login tokens, total number of operations, average number of operations, earliest operation time, latest operation time, highest operation frequency, and average operation frequency; 3) Screen and identify the IP and account of abnormal access based on the number of abnormal access login tokens; 4) Analyze the situation of re-login for each operation, and screen and identify the IP and account of abnormal access; 5) Determine the IP with abnormal access based on the number of accounts and operations using a single IP; 6) If there is abnormal access to the IP and account, notify relevant personnel via SMS or email; 7) Establish an IP whitelist, which will be managed by business personnel according to business needs; 8) Update the IP access control list after deduplication based on the temporary list of IP addresses with abnormal access on that day.

7. The method for processing abnormal access in a token-based electronic resource service according to claim 1, characterized in that: Update the account access control list including: 1) According to the login token access control list and the IP access control list, statistical analysis is performed to produce a table of abnormal access statistics for the account number on the day, including the account number, number of abnormal access IPs, number of abnormal access login tokens, number of abnormal access operations, earliest abnormal access operation time, latest abnormal access operation time, highest abnormal access operation frequency, and average abnormal access operation frequency; 2) Set a set of thresholds, i.e., the maximum number of IP addresses m that can be used to access an account abnormally and the maximum number of login tokens n that can be used to access an account abnormally. m and n can be obtained regularly through positive and negative sample set training of historical user log data or directly through statistics, and business personnel are allowed to modify the settings; 3) Analyze the daily account abnormal access statistics table, filter out the accounts that have reached the threshold and the abnormal information codes of abnormal access, and update them into the account access control list; 4) If there is any abnormal access to the account, notify relevant personnel; 5) Establish an account whitelist, which will be managed by business personnel according to business needs; 6) Return the product service request processing result.

Citation Information

Patent Citations

  • Access authentication method and device

    CN112887284A

  • Request processing method and device, storage medium and electronic equipment

    CN113225351A