A website real-time monitoring system
By combining the server and agent sides, the original files are directly analyzed to identify hidden links or keywords on web pages, solving the problem of not being able to monitor server hardware resources in real time in existing technologies. This enables real-time website monitoring and performance overload protection, improving monitoring efficiency and accuracy.
Patent Information
- Application Number
- CN202211262899.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2042-10-12
AI Technical Summary
Existing website security monitoring methods cannot monitor server hardware resources in real time, resulting in false alarms or missed alarms. Furthermore, the hardware equipment is complex to deploy, making it impossible to perform real-time analysis of server CPU, memory, disk, and other resource usage.
The architecture adopts a server-side and agent-side approach. The agent side identifies hidden links or keywords on web pages by directly analyzing the original files, scans hardware resources in real time to see if they exceed the configured thresholds, and initiates performance overload protection when CPU and memory usage are too high. It combines log storage, configuration center, analysis center and alarm center to achieve real-time monitoring and protection.
It enables real-time monitoring of websites, avoids false alarms or missed alarms, provides real-time analysis of server hardware resources and performance overload protection, and improves monitoring efficiency and accuracy.
Smart Images

Figure CN115695548B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of website monitoring, in particular to a website real-time monitoring system. BACKGROUND
[0002] With the development of information technology, the information infrastructure such as the website of an enterprise becomes particularly important, and the monitoring of the security of the internal website of the enterprise is also a top priority. If the website is maliciously tampered with or attacked, it will cause serious damage to the image of the enterprise.
[0003] The commonly used website security monitoring method at present is to use a commercial website security monitoring platform to monitor the dark chain and running state of the website through a bypass deployment method. However, the traditional monitoring method needs to deploy hardware devices in the management network, and the architecture is complex and not easy to use. Since the working principle is to directly access the target web service for business analysis, the CPU, memory, disk and other occupancies of the server cannot be monitored in real time. Moreover, the existing detection method has a certain false positive or false negative, the hardware device deployment is complex, the network environment needs to be invaded, and the server hardware resources cannot be analyzed in real time. SUMMARY
[0004] The present application aims at the deficiencies of the prior art, and provides a website real-time monitoring system to solve the problems in the background art.
[0005] To achieve the above-mentioned purpose, the present application provides the following technical scheme: a website real-time monitoring system comprising a Server end and an Agent end, wherein the Server end comprises six modules of log storage, configuration center, analysis center, alarm center and Server-GUI, the Server-GUI module is the main interface display module, can display alarm information and configuration information functions, and can intuitively show the alarm information and configuration information to the staff, the Agent end synchronously acquires the configuration items when connecting the server for message transmission, and performs real-time scanning on the local, the scanning content is whether the hardware resources exceed the configuration threshold, whether the webpage file exists a dark chain or a malicious keyword, etc., the website can be monitored in real time, the identification of the webpage dark chain or keyword in the Agent end currently adopts direct analysis of the original file for identification, which can directly avoid a certain false positive or false negative, and the monitoring efficiency is higher. At the same time, if the CPU and memory are scanned, the performance overload protection will be started when the CPU and memory occupancy are too high. After the scanning is completed, the Agent end will actively contact the message distribution center in the Agent end, and send the scanning result to the analysis center, and the real-time analysis of the resources of all server hardware such as CPU and memory is also realized.
[0006] As a preferred technical scheme of the present application, the log storage comprises a log analysis management system, which can uniformly collect, process, store and query analyze discrete logs, and can upload logs through the Agent end, can master and sort logs in real time, and can manage logs in real time.
[0007] As a preferred technical scheme of the present application, the configuration center can configure the related configurations of its website through the configuration center, and the information and data configured by the configuration center can be displayed through the interface display module in the Server-GUI module, the configuration information can be displayed, the website can be monitored through the configuration information, and the website can be protected.
[0008] As a preferred technical scheme of the present application, the analysis center can accept the log files uploaded by the Agent end, analyze the logs, filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and store the fact in the log storage center, which can be displayed on the interface display in the Server-GUI module through the alarm center, the servers with hidden links or malicious keywords or hardware resources exceeding the threshold on the website can be filtered and analyzed, and the website can be monitored in real time.
[0009] As a preferred technical scheme of the present application, the alarm center can analyze the log files uploaded by the Agent end, analyze the logs, filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and display the corresponding analysis through the interface display module in the Server-GUI module through the alarm center, the alarm center can filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold on the website through the analysis center, and display the same on the interface display module in the Server-GUI module through the alarm center, which can be processed by relevant personnel.
[0010] As a preferred technical scheme of the present application, the Server-GUI module is a main interface display module, which can display alarm information and configuration information, and can provide a direct display function for relevant personnel to process the servers with hidden links or malicious keywords or hardware resources exceeding the threshold on the website analyzed by the analysis center.
[0011] As a preferred technical scheme of the present application, the Agent end can monitor the running state of the website, upload the monitored running state of the website to the log storage, and the analysis center can analyze the log of the uploaded running state of the website, so as to ensure the normal operation of the website.
[0012] As a preferred technical scheme of the present application, the identification of the webpage dark link or keyword in the Agent end is currently achieved by directly analyzing the original file, which can be replaced by active detection or crawler identification.
[0013] As a preferred technical scheme of the present application, if the CPU and memory occupation are too high during scanning of the Agent end, performance overload protection is started, and after the CPU and memory occupation decrease, scanning and identification are continued, and after scanning is completed, the Agent end actively contacts the message distribution center in the Agent end and sends the scanning result to the analysis center, thereby achieving real-time analysis of all server hardware resources and providing performance overload protection.
[0014] Compared with the prior art, the present application provides a website real-time monitoring system, which has the following beneficial effects:
[0015] 1. The website real-time monitoring system sets the Server end and the Agent end, the identification of the webpage dark link or keyword in the Agent end is currently achieved by directly analyzing the original file, which can be replaced by active detection or crawler identification, and the purpose of directly avoiding false positives or false negatives is achieved by directly analyzing the original file.
[0016] 2. The website real-time monitoring system sets the Server end and the Agent end, if the CPU and memory occupation are too high during scanning of the Agent end, performance overload protection is started, and after the CPU and memory occupation decrease, scanning and identification are continued, and after scanning is completed, the Agent end actively contacts the message distribution center in the Agent end and sends the scanning result to the analysis center, thereby achieving real-time analysis of all server hardware resources and providing performance overload protection. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 FIG. 1 is a system architecture schematic diagram of a website real-time monitoring system;
[0018] Figure 2 FIG. 4 is a Server end display structure schematic diagram of a website real-time monitoring system. DETAILED DESCRIPTION
[0019] With reference to the accompanying drawings: clearly and fully describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of the present application.
[0020] Embodiment one:
[0021] Please refer to Figure 1 and Figure 2 A website real-time monitoring system includes a server end and an agent end. The server end includes six modules of log storage, configuration center, analysis center, alarm center, server-GUI. The server-GUI module is the main interface display module, which can display alarm information and configuration information functions, and can intuitively show alarm information and configuration information to staff. When the agent end connects the server end for message transmission, it synchronously acquires configuration items and performs real-time scanning locally. The scanning content includes whether the hardware resources exceed the configuration threshold, whether the web page file exists a dark link or malicious keyword, etc. The website can be monitored in real time. The identification of web page dark link or keyword in the agent end currently uses direct analysis of original files for identification, which can directly avoid certain false positives or omissions, and has higher monitoring efficiency. At the same time, if the CPU and memory are too high during scanning, the performance overload protection will be started. After scanning is completed, the agent end will actively contact the message distribution center in the agent end and send the scanning results to the analysis center. At the same time, real-time analysis of resources of all server hardware such as CPU and memory is also realized. The management personnel can configure related configuration items through the server-GUI, including threshold configuration of CPU occupation, memory occupation, and disk occupation of the website. The agent end will perform real-time scanning and monitoring on the configuration items. If it is found that the server exceeds the configuration threshold, real-time alarm will be performed. In addition, the files under the web service directory will be analyzed separately. If a dark link or malicious keyword is found, real-time alarm display will be performed.
[0022] Embodiment two:
[0023] Please refer to Figure 1 and Figure 2The log storage includes a log analysis management system, which can uniformly collect, process, store and query and analyze discrete logs, and can upload logs through an Agent end, can master and sort logs in real time, and can manage logs in real time. The configuration center can configure the related configurations of its website through the configuration center, and the information and data configured by the configuration center can be displayed through the interface display module in the Server-GUI module, and the configuration information can be displayed. The website can be monitored and protected through the configuration information. The analysis center can accept the log files uploaded by the Agent end, analyze the logs, filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and store them in the log storage center. The alarm center can display the analysis on the Server-GUI module interface display, filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold on the website, monitor the website in real time, and the alarm center can analyze the log files uploaded by the Agent end, analyze the logs, filter and analyze the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and display the corresponding analysis on the Server-GUI module interface display module of the alarm center through the analysis of the analysis center. The relevant personnel can process it, and the Server-GUI module is the main interface display module, which can display alarm information and configuration information, and can provide a direct display function for relevant personnel to analyze and process the servers with hidden links or malicious keywords or hardware resources exceeding the threshold on the website through the analysis center. By setting the Server end and the Agent end, the Agent end can identify the web hidden link or keyword by directly analyzing the original file, which can be replaced by active detection or crawler identification, and the direct analysis of the original file can directly avoid the existence of false positives or omissions.
[0024] Example three
[0025] Please refer to Figure 1 and Figure 2The Agent end can monitor the website running state and upload the monitored website running state to the log storage, the analysis center can analyze the uploaded website running state log, the normal operation of the website can be guaranteed, the identification webpage dark link or keyword in the Agent end currently adopts direct analysis of original file for identification, can be replaced by active detection or crawler identification, but the active detection or crawler identification scheme exists certain false alarm or omission if network fluctuation exists, the website has anti-crawler mechanism, the react environment, direct analysis of original file can directly avoid this situation, direct analysis of original file can avoid false alarm or omission, the CPU and memory occupation of the Agent end is too high during scanning, then the performance overload protection is started, the scanning and identification are continued after the CPU and memory occupation decrease, the Agent end actively contacts the message distribution center in the Agent end after scanning, and the scanning result is sent to the analysis center, the real-time analysis of all server hardware resources and the performance overload protection can be realized, the Server end and the Agent end are set, the real-time analysis of all server hardware resources and the performance overload protection are realized.
[0026] The working principle and use flow of the application are as follows: first, the log can be uploaded to the log storage through the Agent end, then the website can be configured through the configuration center, the configuration data can be displayed through the interface display module in the Server-GUI module, the log file uploaded by the Agent end can be analyzed by the analysis center, the server with dark link or malicious keyword or hardware resource exceeding the threshold can be filtered and analyzed, and the fact storage center can be displayed on the interface display in the Server-GUI module through the alarm center, the identification webpage dark link or keyword in the Agent end currently adopts direct analysis of original file for identification, can be replaced by active detection or crawler identification, but the active detection or crawler identification scheme exists certain false alarm or omission if network fluctuation exists, the website has anti-crawler mechanism, the react environment, direct analysis of original file can directly avoid this situation, and the identification webpage dark link or keyword in the Agent end currently adopts direct analysis of original file for identification, can be replaced by active detection or crawler identification, direct analysis of original file can directly avoid certain false alarm or omission, the CPU and memory occupation of the Agent end is too high during scanning, then the performance overload protection is started, the scanning and identification are continued after the CPU and memory occupation decrease, the Agent end actively contacts the message distribution center in the Agent end after scanning, and the scanning result is sent to the analysis center, the real-time analysis of all server hardware resources and the performance overload protection can be realized.
[0027] It should be pointed out finally that the above only describes the preferred embodiments of the present application and is not intended to limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent replacements to some technical features. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A website real-time monitoring system, comprising a server end and an agent end, characterized in that: The Server end includes six modules of log storage, configuration center, analysis center, alarm center and Server-GUI. The Server-GUI module is the main interface display module, which displays alarm information and configuration information. When the Agent end connects the server for message transmission, it synchronously acquires configuration items and performs real-time scanning locally. The scanning content includes whether the hardware resources exceed the configuration threshold and whether the web files contain hidden links or malicious keywords. The Agent end currently uses direct analysis of original files to identify hidden links or keywords in web pages, which directly avoids false positives or omissions. If the CPU and memory usage is too high during scanning, the performance overload protection is started. After the CPU and memory usage decreases, the scanning and identification are continued. After the scanning is completed, the Agent end actively contacts the message distribution center in the Agent end and sends the scanning results to the analysis center. The analysis center receives the log files uploaded by the Agent end, analyzes the logs, filters and analyzes the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and stores them in the log storage center. The alarm center displays the analysis results on the interface display of the Server-GUI module.
2. The website real-time monitoring system of claim 1, wherein: The log storage includes a log analysis management system, which uniformly collects, processes, stores and queries analysis of discrete logs, and uploads logs through the Agent end.
3. The system of claim 1, wherein: The configuration center configures the related configurations of its website through the configuration center. The information and data configured by the configuration center are displayed on the interface display module of the Server-GUI module.
4. The system of claim 1, wherein: The alarm center analyzes the log files uploaded by the Agent end, filters and analyzes the servers with hidden links or malicious keywords or hardware resources exceeding the threshold, and displays the analysis results on the interface display module of the Server-GUI module through the alarm center.
5. The system of claim 1, wherein: The Agent end monitors the website running state and uploads the monitored website running state to the log storage for the analysis center to analyze the uploaded website running state logs.
6. A website real-time monitoring system according to claim 1, characterized in that: The Agent end currently uses direct analysis of original files to identify hidden links or keywords in web pages. Instead of active detection or crawler identification, direct analysis of original files directly avoids false positives or omissions.
Citation Information
Patent Citations
Hidden link detection technology based on polymerization degree analysis
CN107729386A
Overload protection method and device, computer device and storage medium
CN110502345A