Network environment detection method, device, equipment and storage medium
By automatically activating and allocating keep-alive time during network switching behavior, the network access security detection module solves the problems of long network environment detection time and low efficiency in the existing technology, and realizes fast and accurate network environment detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2021-11-19
- Publication Date
- 2026-08-04
AI Technical Summary
Existing network environment detection methods require manual operation by users and are time-consuming, resulting in low timeliness and efficiency, and are easily affected by network latency.
When a network switching behavior occurs on a target terminal device, the automatic detection module activates the network access security detection module, allocates a keep-alive time for it to perform network security detection, obtains the detection results, and pushes them to the terminal device.
It enables rapid and accurate detection of the network environment without user intervention or waiting, improving the timeliness and efficiency of detection and enabling timely discovery of suspicious risks.
Smart Images

Figure CN116156503B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security management technology, and in particular to a network environment detection method, apparatus, device, and storage medium. Background Technology
[0002] With the rapid development of computer networks, wireless network access has brought many conveniences to people's lives. However, people also face many practical network security problems when using wireless networks. Data theft and website attacks are rampant, and the situation is not optimistic. In addition, due to human factors, several system vulnerabilities may occur during the use of programs. These defects and vulnerabilities are highly destructive, and criminals often use them to steal user information, causing significant security problems. To solve these problems, many network security detection software or modules have been developed on the market.
[0003] However, when using these security detection software or modules for network detection, users need to manually enter the relevant network detection software or modules, click to perform network speed test, connected device test, and other operations, and need to wait for a long time to obtain the current network environment detection results. Due to the long operation path and susceptibility to network latency, the timeliness of network environment detection is poor and the detection efficiency is low. Summary of the Invention
[0004] This application provides a network environment detection method, apparatus, device, and storage medium, which is used to detect target terminal devices and the current network environment by automatically activating a network security detection module. It can complete the network environment detection process without the user of the target terminal device being aware of it, improve the timeliness of network detection, and discover suspicious risks in the current network environment more quickly and accurately. At the same time, the user of the target terminal device can directly obtain the detection results without any operation or waiting.
[0005] This application provides a network environment detection method, including:
[0006] Acquire network events from the target terminal device;
[0007] When a network event indicates that the target terminal device has engaged in network switching behavior, the network access security detection module is activated.
[0008] Allocate a keep-alive time for network environment detection to the activated network access security detection module;
[0009] During the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain the target detection result.
[0010] Push and display the target detection results to the target terminal device.
[0011] Another aspect of this application provides a network environment detection device, comprising:
[0012] The acquisition unit is used to acquire network events of the target terminal device.
[0013] The processing unit is used to activate the network access security detection module when a network event characterizes a network switching behavior of a target terminal device;
[0014] The processing unit is also used to allocate a keep-alive time for network environment detection to the activated network access security detection module;
[0015] The processing unit is also used to perform network access security detection on the target terminal device and the network connected to the target terminal device through the network access security detection module during the keep-alive period, and obtain the target detection result;
[0016] The display unit is used to push and display the target detection results to the target terminal device.
[0017] In one possible design, in another implementation of the embodiments of this application,
[0018] The acquisition unit is also used to acquire historical network detection results corresponding to the network connected to the target terminal device;
[0019] The processing unit is also used to allocate a keep-alive time for network environment detection to the activated network access security detection module if the historical detection time of the historical network detection result meets the re-detection conditions.
[0020] In one possible design, in another implementation of the embodiments of this application, the processing unit may specifically be used for:
[0021] During the keep-alive period, a preset configuration file is downloaded using the network connected to the target terminal device. The network download traffic and download time corresponding to the download of the preset configuration file are recorded by the network access security detection module.
[0022] Download speed is calculated based on network download traffic and download time to obtain network speed test results.
[0023] In one possible design, in another implementation of the embodiments of this application, the processing unit may specifically be used for:
[0024] During the keep-alive period, obtain the network service set identifier (SSID) and the corresponding basic service set identifier (BSSID);
[0025] The network access security detection module obtains a list of trusted identifiers and identifies the network's SSID and BSSID based on the list to obtain network anomaly detection results.
[0026] In one possible design, in another implementation of the embodiments of this application, the processing unit may specifically be used for:
[0027] If the network access security detection operation is not completed after the first keep-alive time, a second keep-alive time will be allocated to the network access security detection module according to the polling mechanism.
[0028] During the second keep-alive period, network access security detection operations continue to be performed to obtain the target detection results.
[0029] In one possible design, in another implementation of the embodiments of this application,
[0030] The processing unit is also used to register the listening permissions between the network access security detection module and the network event for the target terminal to perform network switching behavior;
[0031] The processing unit can specifically be used for:
[0032] Based on the listening permissions, if a network event is detected indicating that the target terminal has switched networks, the network access security detection module will be activated.
[0033] In one possible design, in another implementation of the embodiments of this application,
[0034] The processing unit is also used to generate result record identifiers and target push messages based on the target detection results;
[0035] The processing unit is also used to save the target detection results, the result record identifier, and the target push message accordingly;
[0036] The display unit can be specifically used for:
[0037] Push and display target push messages to target terminal devices;
[0038] When a touch signal corresponding to a target push message is received, the target detection result is displayed to the target terminal device.
[0039] Another aspect of this application provides a computer device, including: a memory, a transceiver, a processor, and a bus system;
[0040] The memory is used to store programs;
[0041] When a processor executes a program in memory, it implements the methods described above.
[0042] Bus systems are used to connect memory and processor to enable communication between them.
[0043] Another aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described above.
[0044] One aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the text category determination method provided in any of the above aspects.
[0045] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:
[0046] By acquiring network events from the target terminal device, when the acquired network event indicates that the target terminal device has undergone network switching behavior, the network access security detection module is activated. A keep-alive time for network environment detection is allocated to the activated network access security detection module. Then, within the keep-alive time, the network security detection module performs network access security detection on both the target terminal device and the network it is connected to, obtaining the target detection results, which are then pushed and displayed to the target terminal device. Through this method, when the network event corresponding to the target terminal device indicates that the target terminal device has undergone network switching behavior, the network access security detection module can be automatically activated to detect the target terminal device and the current network environment, and the target detection results can be displayed on the target terminal device in real time. This allows the network environment detection process to be completed without the user's awareness, improving the timeliness of network detection and enabling faster and more accurate identification of suspicious risks in the current network environment. Furthermore, the user of the target terminal device can directly obtain the detection results without any operation or waiting. Attached Figure Description
[0047] Figure 1 This is a schematic diagram of the network detection system in an embodiment of this application;
[0048] Figure 2 This is a flowchart of one embodiment of the network environment detection method in this application;
[0049] Figure 3 This is a flowchart of another embodiment of the network environment detection method in this application;
[0050] Figure 4 This is a schematic diagram illustrating the principle of the network environment detection method in this application embodiment;
[0051] Figure 5 This is another schematic diagram of the principle of the network environment detection method in the embodiments of this application;
[0052] Figure 6 This is a schematic diagram of a network environment detection method in an embodiment of this application;
[0053] Figure 7 This is a flowchart of a keep-alive mechanism of the network environment detection method in the embodiments of this application;
[0054] Figure 8 This is a schematic diagram of a time-monitoring process for a network environment detection method in an embodiment of this application;
[0055] Figure 9 This is a schematic diagram illustrating the network environment detection method in the embodiments of this application;
[0056] Figure 10 This is a schematic diagram of a push information interface of the network environment detection method in this application embodiment;
[0057] Figure 11 This is a schematic diagram of a detection result interface of the network environment detection method in this application embodiment;
[0058] Figure 12 This is another schematic diagram of the detection result interface of the network environment detection method in this application embodiment;
[0059] Figure 13 This is a schematic diagram of one embodiment of the network environment detection device in this application;
[0060] Figure 14 This is a schematic diagram of one embodiment of the computer device described in this application. Detailed Implementation
[0061] This application provides a network environment detection method, apparatus, device, and storage medium, which is used to detect target terminal devices and the current network environment by automatically activating a network access security detection module. It can complete the network environment detection process without the user of the target terminal device being aware of it, improve the timeliness of network detection, and discover suspicious risks in the current network environment more quickly and accurately. At the same time, the user of the target terminal device can directly obtain the detection results without any operation or waiting.
[0062] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “corresponding to,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0063] With the rapid development of information technology, cloud technology is gradually permeating all aspects of people's lives. Cloud technology is a general term encompassing network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring data to be transmitted to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will require robust system support, which can only be achieved through cloud computing.
[0064] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and unknown virus behavior detection. It uses a large network of clients to monitor abnormal software behavior on the network, obtain the latest information on Trojans and malware on the internet, and send it to the server for automatic analysis and processing. Finally, solutions for viruses and Trojans are distributed to each client. The network environment detection method provided in this application embodiment can be implemented using cloud computing technology and cloud security technology.
[0065] It should be understood that the network environment detection method provided in this application can be applied to fields such as cloud technology, artificial intelligence, and intelligent transportation, for scenarios where network environment detection is used to perceive whether the network environment is secure. For example, when terminal device A using an iOS system switches from wireless network B to wireless network C, the network environment of wireless network C is automatically detected, and the detection result is pushed to terminal device A. As another example, when terminal device X using an iOS system changes from a state of no network connection to a successful connection to wireless network Y, the network environment of wireless network Y is automatically detected, and the detection result is pushed to terminal device X. For example, ... For example, when a terminal device S using the iOS system switches from mobile network Q to wireless network P, the network environment of wireless network P is automatically detected, and the detection results are pushed to the terminal device S. In all the above scenarios, in order to achieve network security detection, when using security detection software or modules to perform network detection, users need to manually enter the relevant network detection software or modules, click to perform network speed test, device connection test, and other operations, and wait for a long detection time to obtain the current network environment detection results. Due to the long operation path and the susceptibility to network latency, the timeliness of network environment detection is poor and the detection efficiency is low.
[0066] To address the aforementioned problems, this application proposes a network environment detection method, which is applied to... Figure 1 Please refer to the network detection system shown. Figure 1 , Figure 1 This is a schematic diagram of the architecture of the network detection system in an embodiment of this application, such as... Figure 1 As shown, the server acquires network events from the target terminal device. When a network event indicates that the target terminal device has switched networks, the server activates the network access security detection module. A keep-alive time for network environment detection is allocated to the activated network access security detection module. Then, within the keep-alive time, the network security detection module performs network access security detection on both the target terminal device and the network it connects to, obtaining the detection results, which are then pushed to and displayed to the target terminal device. Through this method, when a network event corresponding to the target terminal device indicates that it has switched networks, the network access security detection module automatically starts detecting the target terminal device and the current network environment, and displays the detection results to the target terminal device in real time. This allows the network environment detection process to be completed without the user's awareness, improving the timeliness of network detection and enabling faster and more accurate identification of suspicious risks in the current network environment. Furthermore, the user of the target terminal device receives the detection results directly without any operation or waiting.
[0067] Understandable Figure 1Only one type of terminal device is shown in the diagram. In real-world scenarios, many more types of terminal devices can participate in the data processing. These include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. The specific number and types depend on the actual scenario and are not limited here. Furthermore, Figure 1 The diagram shows one server, but in real-world scenarios, multiple servers can be involved, especially in scenarios involving multi-model training and interaction. The number of servers depends on the specific scenario and is not limited here.
[0068] It should be noted that in this embodiment, the server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. Terminal devices and servers can be directly or indirectly connected via wired or wireless communication, and terminal devices and servers can be connected to form a blockchain network; this application does not impose any limitations on this.
[0069] To address the aforementioned issues, this application proposes a network environment detection method, which is generally executed by a server or terminal device. Correspondingly, the network environment detection device is generally installed in the server or terminal device.
[0070] It is understood that, as disclosed in this application, the network environment detection method, apparatus, device, and storage medium can comprise multiple servers or terminal devices that form a blockchain, with the servers or terminal devices acting as nodes on the blockchain. In practical applications, data sharing between nodes is required within the blockchain, and each node can store network data, etc.
[0071] The network environment detection method in this application will be described below. Please refer to [link / reference]. Figure 2 One embodiment of the network environment detection method in this application includes:
[0072] In step S101, network events of the target terminal device are acquired;
[0073] In this embodiment, as Figure 4 As shown, when a network event occurs on the target terminal device, the server can listen for the network event to obtain the current network event of the target terminal device.
[0074] The target terminal device is a mobile phone or computer, etc., and the specific number and type are not specifically limited. The network event can be manifested as scanning nearby networks, failure to connect to the network, success to connect to the network, etc., or other network events. There are no specific restrictions here.
[0075] Specifically, when the user of the target terminal device uses the target terminal device to connect to or switch networks, the network events can be monitored in real time through a service component that supports event listening. This allows for the timely acquisition of pre-registered network events, enabling the subsequent triggering or activation of the security detection module to perform network security detection on the network connected to the target terminal device based on the acquired network events.
[0076] For example, when target object A uses target terminal device B on the iOS system to change from a state of no network connection to a state of successfully connected wireless network (WiFi), the network event of changing from a state of no network connection to a state of successfully connected wireless network (WiFi) can be obtained through the service component.
[0077] In step S102, when a network event characterizes a network handover behavior of the target terminal, the network access security detection module is activated;
[0078] In this embodiment, as Figure 4 As shown, when a network event actually occurs on the target terminal device, the server can first listen for the network event. If the listened network event indicates that the target terminal device has switched networks, it can be understood that the current network connection method has changed. Then, based on the binding relationship between the network event indicating that the target terminal device has switched networks and the network access security detection module, the server can activate and call back the network access security detection module, so that the subsequent network access security detection module can quickly and timely perform security detection and processing operations on the obtained network events and information.
[0079] Among them, network events characterize network switching behaviors of target terminal devices, including switching network connection channels or changing network connection objects. Switching network connection channels can specifically manifest as switching from wireless network B to wireless network C; changing network connection objects can specifically manifest as changing from a state of no network connection to a successful connection to wireless network Y, or connecting from mobile network Z to wireless network Y, etc., without specific limitations. The security detection module can specifically manifest as security detection software or applications, such as mobile phone managers or security managers, without specific limitations.
[0080] Specifically, after obtaining information about a network event that actually occurred on the target terminal device, the network access security detection module can be queried based on the binding relationship between the network event characterizing the network switching behavior of the target terminal device and the network access security detection module. Specifically, this can be done by iterating through the registration list on the service component based on the registration records between the network event characterizing the network switching behavior of the target terminal and the network access security detection module, in order to find the security detection modules that have been registered to listen for network events that occur when the target terminal device switches networks. Then, the service component activates the queried network access security detection module so that the activated network access security detection module can perform network security detection on the network connected to the target terminal device.
[0081] For example, when target device S1 uses iOS device A to switch from wireless network B to wireless network C, i.e., target device A undergoes a network switching behavior, the phone manager will automatically activate and perform a security network check on wireless network C. Similarly, when target device S2 uses iOS device X to change from a state of no network connection to a successful connection to wireless network Y, or connects to wireless network Y from mobile network Z, i.e., target device B undergoes a network switching behavior, the phone manager will automatically activate and perform a security network check on wireless network Y.
[0082] In step S103, a keep-alive time for network environment detection is allocated to the activated network access security detection module;
[0083] In this embodiment, as Figure 4 As shown, when the network access security detection module is activated, a keep-alive mechanism can be started to allocate keep-alive time to the activated network access security detection module, so that the network access security detection module is not suspended during the keep-alive time and has sufficient time to complete a complete security detection of the target terminal device and the current network connected to the target terminal device in order to obtain the security detection results.
[0084] The protection mechanism ensures the network access security detection module remains operational during the keep-alive period, preventing it from being suspended or terminated by other processes. The keep-alive period is the time during which the network access security detection module can perform security checks on the target terminal device and the network it is connected to.
[0085] It is understandable that after the network access security detection module is activated, a frequency control mechanism can also be started to control the security detection time and frequency of the activated network access security detection module, so as to maintain the execution of the security detection process and avoid repeated and redundant security detection. Other mechanisms can also be used to maintain the security detection process, and no specific restrictions are made here.
[0086] Specifically, after the network access security detection module is activated, a pre-set keep-alive mechanism can be started or triggered. According to the keep-alive mechanism, the network access security detection module can send a request to the server to obtain keep-alive time. Then, the server can allocate keep-alive time to the network access security detection module according to the request, so that the network access security detection module has sufficient detection time to perform a complete security detection on the target terminal device and the current network connected to the target terminal device, without being affected by other processes, thereby obtaining the target detection results better and more accurately.
[0087] For example, when target object S1 switches from wireless network B to wireless network C using target terminal device A on iOS system, the phone manager is automatically activated to perform a security network detection on wireless network C. In order to prevent the security network detection process on wireless network C from being interrupted and the security detection results from being lost, the network access security detection module can request a keep-alive time from the server. Then the server can allocate a corresponding keep-alive time, such as 20 seconds, to the network access security detection module according to the pre-set keep-alive mechanism.
[0088] It is understandable that this keep-alive mechanism can also be applied to other types of systems to provide keep-alive time to complete security checks on the network environment; no specific restrictions are made here.
[0089] In step S104, during the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain the target detection result.
[0090] In this embodiment, as Figure 4 As shown, after the server allocates a keep-alive time for the network access security detection module, the security detection process of the network access security detection module will not be suspended during the keep-alive time. Therefore, the network access security detection module can be used to perform security detection on the target terminal device and the network connected to the target terminal device, so as to obtain the target detection results better and more accurately. It can also reduce the operation threshold for users of the target terminal device to perform network detection, reduce operation time, and thus improve the timeliness and efficiency of network security detection.
[0091] The network access security detection module performs security checks on the target terminal device and the network it connects to. Specifically, this can involve testing the network speed (e.g., 3.92 MB / s), detecting whether the network is a phishing Wi-Fi network, or a fake public Wi-Fi network, etc. There are no specific limitations on this. It can also perform checks on the target terminal device and other devices connected to the network, such as Trojan horse detection, virus detection, fault detection, or vulnerability detection, or other security checks. The detection results can be displayed as the current network speed, the total number of devices connected to the current network, or the security level of the current network, or other detection results, without specific limitations on this.
[0092] Specifically, after the server allocates keep-alive time to the network access security detection module, since there is sufficient detection time available for the network access security detection module without being affected by other processes, i.e., keep-alive time, the security detection algorithm encapsulated in the network access security detection module can be activated to perform security detection on the target terminal device and the network connected to the target terminal device. Specifically, this can be done by performing network speed tests on the current network connected to the target terminal device, performing anomaly detection on the current network, or performing anomaly detection on the target terminal device and other terminal devices connected to the current network, in order to generate target detection results.
[0093] For example, when target object S2 uses target terminal device X of iOS system to connect to wireless network Y from mobile network Z, the phone manager is automatically activated to perform a security network detection on wireless network Y. The server can allocate 20 seconds of keep-alive time to the phone manager according to the pre-set keep-alive mechanism, detect the current network speed of wireless network Y, count the total number of terminal devices currently connected to wireless network Y, and detect whether there are Trojans or viruses on the terminal devices currently connected to wireless network Y. It can be obtained that the current network speed of wireless network Y is 4.11MB / s, the total number of terminal devices currently connected to wireless network Y is 18, and it is detected that there are no Trojans or viruses on the terminal devices currently connected to wireless network Y. Thus, a target detection result with high security of wireless network Y can be obtained.
[0094] In step S105, the target detection results are pushed to and displayed to the target terminal device.
[0095] In this embodiment, as Figure 4As shown, after obtaining the target detection results, the target terminal device can push and display the obtained target detection results to the users of the target terminal device, so that the users of the target terminal device can directly obtain the detection results without operation and waiting, and are not easily affected by network latency, thereby improving the timeliness and efficiency of obtaining detection results. It can also reduce the operational threshold for users of the target terminal device to perform network detection and enhance the users of the target terminal device's security awareness of the current network environment.
[0096] Specifically, after obtaining the detection results of the target, the detection results can be pushed to the users of the target terminal device. This allows the users of the target terminal device to automatically detect and push network environment information such as the current network speed and the number of connected terminal devices without having to manually enter and operate the security detection software or module or wait for a long detection time. This can promptly inform the users of the target terminal device of potential security risks in the current network environment.
[0097] Specifically, pushing and displaying the target detection results to the target terminal device can take the form of a pop-up window, timely information, or email, or other display methods, without specific restrictions here.
[0098] For example, when the target detection result is obtained, the target detection result can be displayed in the form of a pop-up window on the application interface or display interface of the target terminal device, which includes the following: the current network speed of wireless network Y is 4.11MB / s, the total number of terminal devices currently connected to wireless network Y is 18, and none of the terminal devices currently connected to wireless network Y contain Trojans or viruses, indicating that wireless network Y has a high level of security.
[0099] In this embodiment of the application, a network environment detection method is provided. In this way, when the network event corresponding to the target terminal device indicates that the target terminal device has a network switching behavior, the network access security detection module is automatically started to detect the target terminal device and the current network environment, and the target detection results are displayed on the target terminal device in real time. The network environment detection process can be completed without the user of the target terminal device being aware of it, which improves the timeliness of network detection, discovers suspicious risks in the current network environment more quickly and accurately, and the user of the target terminal device can directly obtain the detection results without operation or waiting.
[0100] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3As shown, when a network event characterizes a network handover behavior of a target terminal, after activating the network access security detection module, the method further includes:
[0101] In step S201, historical network detection results corresponding to the network connected to the target terminal device are obtained;
[0102] In step S202, if the historical detection time of the historical network detection result meets the re-detection conditions, then the network environment detection keep-alive time is allocated to the activated network access security detection module.
[0103] In this embodiment, as Figure 5 As shown, when a network event characterizes a network switching behavior of a target terminal, after activating the network access security detection module, it can obtain historical network detection results corresponding to the network connected to the target terminal device to further determine whether it is necessary to perform security detection on both the target terminal device and the network connected to it separately through the network access security detection module. If the historical detection time of the historical network detection results meets the re-detection conditions, it can be understood that the current network needs to undergo security detection again; conversely, if the historical detection time of the historical network detection results meets the re-detection conditions, it can be understood that the current network needs to undergo security detection again. Figure 5 As shown, a keep-alive mechanism can be activated to allocate keep-alive time for network environment detection to the activated network access security detection module. This can better control the frequency of security detection of the network environment, avoid frequent triggering of security detection on the same network, avoid unnecessary bandwidth consumption and redundant notifications, and thus avoid repeated redundant detection.
[0104] Among them, historical network detection results refer to the network that the target network device connected to during a historical period is the same network that it is currently connected to, and there are corresponding historical network detection records or content during the historical period, as well as the historical detection time when the network historical detection was carried out. In other words, historical network detection results include historical network detection records and historical detection time.
[0105] The re-detection conditions can specifically be manifested as the detection time interval between the historical detection time and the current detection time being greater than or equal to the preset interval, or the frequency of triggering the historical detection time being less than the preset trigger frequency, etc., or other detection conditions, which are not specifically limited here.
[0106] Specifically, such as Figure 6As shown, after activating the security detection module, it can first traverse the database to see if there are any detection records and historical detection times that match the current network connected to the target terminal device, i.e., historical network detection results. If no such records exist, it can be understood that the current network connected to the target terminal device is the first connection and security network detection is required to obtain the target detection results, thereby promptly informing the user of the target terminal device of the potential security risks in the current network environment when the target terminal device is first connected.
[0107] Furthermore, such as Figure 6 As shown, if such a network exists, it can be understood that the current network connected to the target terminal device has undergone security network testing. Whether a retest of the current network connected to the target terminal device is needed can be determined by judging whether the historical testing time of the historical network testing results meets the retesting conditions. If the historical testing time of the historical network testing results does not meet the retesting conditions, it can be understood that the current network has been repeatedly subjected to security network testing, not that there is a security network problem. Therefore, there is no need to continue security network testing on the current network, and the current security network testing process can be terminated. If the historical testing time of the historical network testing results meets the retesting conditions, it can be understood that too much time has passed since the historical testing, and a retest of the current network environment's security is required. In this case, security testing can continue to be initiated. According to the keep-alive mechanism, a keep-alive time is allocated to the activated security testing module to allow the network access security testing module to continue performing security network testing on the target terminal device and the network connected to the target terminal device to obtain the target testing results.
[0108] Furthermore, such as Figure 6 As shown, when the detection is successful, the target detection result can also be recorded for the next security network detection decision, that is, to determine whether the current network needs to be detected again for the next connection.
[0109] For example, if the detection record contains 7 historical network detection results of the current network Y within 10 seconds, it is because the current network Y is unstable, causing the target terminal device X to repeatedly disconnect and reconnect 8 times in a short period of time, such as 10 seconds. Assuming the preset trigger frequency is 3 times, it can be seen that the frequency of triggering the historical detection time is greater than the preset trigger frequency, so the security network detection process of the current network can be terminated.
[0110] For example, if the detection record contains one historical network detection result of the current network B within 5 minutes, and the user of the target terminal device leaves the current network environment in a short period of time, such as 5 minutes, for example, to pick up a package and then reconnect to the current network, assuming the preset interval is 30 minutes, it can be known that the time interval between the historical detection time and the current detection time is greater than the preset interval, so the security detection module can be activated to perform a near-security detection on the current network.
[0111] It is understandable that, such as Figure 4 As shown, after obtaining a network event and activating the network access security detection module based on it, the module is passively activated by the service component based on the binding relationship or registration record, since it registers a network event listener with the service component. This eliminates the need for the target terminal device user to manually open the security management application or access the network access security detection module. Therefore, the passively activated security management application or network access security detection module may be in the background at this time. However, iOS strictly manages the foreground and background states of the security management application or network access security detection module. When the security management application or network access security detection module is in the background, iOS considers it unnecessary to perform many tasks. Therefore, under the default pause or suspension mode of iOS, only a very short activity time is allocated to the security management application or network access security detection module, and it is quickly suspended. This can easily lead to the security detection process being suspended, preventing the rapid and accurate acquisition of complete target detection results. Furthermore, it cannot push and display the target detection results to the user on the target terminal device. Figure 4 As shown, this embodiment can detect the current activation status of the network access security detection module. If it is determined that the current activation status is a background activation status, the background keep-alive mechanism can be started through the background keep-alive module to allocate keep-alive time for network environment detection to the activated network access security detection module, so as to maintain or ensure that the network security detection work of the security detection module can be fully executed.
[0112] Among them, such as Figure 7 As shown, the current activation status can be specifically represented as foreground activation status and background activation status, such as... Figure 7 As shown, the foreground activation state can be understood as the target terminal device being used or viewing the network access security detection module performing security checks on the current network connected to the target terminal device. That is, when the target terminal device is using or viewing the network access security detection module for a period of time, such as after the detection is complete, it will exit the background. The background activation state refers to the network access security detection module not being used or viewed by the target terminal device; it is a state where a service component is passively activated and running in the background.
[0113] Specifically, such as Figure 7As shown, after obtaining a network event and activating the network access security detection module based on the network event, it is necessary to first confirm whether the obtained network access security detection module is activated in the background. Specifically, this can be done by checking the current activation status of the obtained network access security detection module. If it is determined that the current activation status is not in the background, the target terminal device can be used or viewed by the network access security detection module for a period of time. After the detection completion time, it will exit the background and check whether the security detection work is completed. If it is completed, the target detection result can be obtained.
[0114] Furthermore, such as Figure 7 As shown, if the current activation state is determined to be background activation, a background keep-alive mechanism can be activated to allocate keep-alive time for network environment detection to the activated network access security detection module, so as to maintain or ensure that the network security detection work of the network access security detection module can be fully executed to obtain the target detection results.
[0115] For example, when target object S3 uses target terminal device S of iOS system to connect to wireless network P from mobile network Q, the mobile security management application is automatically activated to perform security network detection on wireless network P. When it is detected that the current activation state of the mobile security management application is background activation state, the server can allocate 30 seconds of keep-alive time to the mobile security management application according to the pre-set keep-alive mechanism.
[0116] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3 As shown, the target detection results include network speed detection results; during the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device respectively, and obtains the target detection results, including:
[0117] In step S301, during the keep-alive time, a preset configuration file is downloaded using the network connected to the target terminal device, and the network download traffic and download time corresponding to the download of the preset configuration file are recorded by the network access security detection module.
[0118] In step S302, the download speed is calculated based on the network download traffic and download time to obtain the network speed detection result.
[0119] In this embodiment, after the server allocates a keep-alive time for the network access security detection module, the security detection process of the network access security detection module will not be suspended during the keep-alive time. Therefore, the network access security detection module can download a preset configuration file from the server using the network connected to the target terminal device. The network access security detection module can record the network download traffic and download time corresponding to the download of the preset configuration file, and calculate the download speed based on the network download traffic and download time to obtain the current network speed, i.e., the network speed detection result. This allows the network speed detection result to be directly pushed to the target terminal device, enabling the target user to understand the current network speed status in a timely manner. It also lowers the operational threshold for users of the target terminal device to perform network detection, reduces operation time, and thus improves the timeliness and efficiency of network security detection.
[0120] Among them, the preset configuration file is a file stored on the server that is bound to the network access security detection module. The preset configuration file is a network speed test file set according to actual application needs, such as data packets. It is a file with a relatively large memory size, usually configured in GB.
[0121] Specifically, after the server allocates keep-alive time for the network access security detection module, the security detection algorithm encapsulated in the module can be activated to perform security detection on the target terminal device and the network connected to it. Specifically, based on the binding relationship between the network access security detection module and the preset configuration file, the preset configuration file can be downloaded from the server through the network connected to the target terminal device. Then, the network access security detection module can simultaneously record the changes in network card download traffic and the time taken to completely download the preset configuration file, thus obtaining the network download traffic and download time consumed in downloading the preset configuration file. Further, the obtained network download traffic and download time can be calculated using formulas such as: Network Download Traffic / Download Time = Download Speed, to obtain the download speed of the preset configuration file downloaded through the network connected to the target terminal device. This download speed can be used as the current network speed, i.e., the network speed detection result. For example, if downloading a 5GB preset configuration file takes 5 seconds, the current network speed can be calculated as 1GB / s.
[0122] Furthermore, after obtaining the current network speed of the network connected to the target terminal device, this embodiment can also obtain the current broadband speed corresponding to the current network speed. Specifically, this can be achieved by pre-testing and collecting data on the maximum and average download speeds achievable by different broadband specifications to establish a correspondence between different broadband specifications and different network speeds. Therefore, after obtaining the current network speed of the network connected to the target terminal device, the network access security detection module can quickly and accurately obtain the current broadband speed corresponding to the current network speed based on the correspondence between different broadband specifications and different network speeds. For example, a 32M broadband connection can reach a maximum of 4MB / s, and a 40M broadband connection can reach a maximum of 5MB / s. Figure 11 As shown, 4.81 MB / s is equivalent to a current 40 Mbps broadband connection.
[0123] Furthermore, to help the target audience understand more intuitively the network speed when using the target terminal device to access the current network, this embodiment can pre-collect and record different network speeds and the corresponding user experiences of the target audience, such as the different target audiences watching videos at different network speeds. This allows for the establishment of a correspondence between viewing experiences such as ultra-fast, smooth, average, and stuttering, and different network speeds, which can be used to reflect the current network speed. Since descriptions like "ultra-fast" and "smooth" may have different user experiences for different target audiences—for example, some target audiences might consider web browsing smooth, while others might consider video playback smooth—this embodiment can obtain the frame rate and frame size range for videos of different resolutions, and calculate the minimum file transfer speed required to achieve a "no dropped frames" effect using a common algorithm. This gives the minimum network speed required for smooth playback of a certain resolution video. Therefore, when the current network speed of the target terminal device is obtained, the corresponding video viewing experience can be quickly and accurately obtained based on the correspondence between video viewing experience and network speed. Figure 12 As shown, if the current network speed is 4.81MB / s, the corresponding video viewing experience is "super fast". Then, based on the video viewing experience being "super fast", the corresponding video clarity can be obtained, such as "able to watch Blu-ray videos", "able to watch ultra-high-definition videos", etc.
[0124] Furthermore, after obtaining the current network speed of the network connected to the target terminal device, this embodiment can also obtain the file download speed corresponding to the current network speed, so that the target can more intuitively understand how fast the target terminal device can download files when accessing the current network. Similar to the method of calculating the current network speed, this embodiment can use a network access security detection module to upload a preset detection file, such as a file with a size of several hundred MB, to the server through the current network. The network access security detection module can simultaneously record the changes in network card upload traffic during the download process and the time to completely upload the preset detection file, so as to obtain the network upload traffic and upload time consumed in uploading the preset detection file. Then, the upload speed corresponding to the current network can be accurately calculated according to the formula such as: file size / upload time = upload speed. For example, if it takes 5 seconds to upload a 10MB preset detection file, the upload speed of the current network can be calculated to be 2MB / s.
[0125] Furthermore, to enable the target device to more intuitively understand the network speed when accessing the current network using the target terminal device, this embodiment can also call the Packet Internet Groper (PING) through the network access security detection module. Utilizing the uniqueness of the Internet Protocol Address (IP) address accessed by the target terminal device connecting to the current network, a data packet is sent to the target IP address and the sending time is recorded. Then, the target terminal device is requested to return a data packet of the same size and the return time is recorded. Network latency can then be calculated by calculating the sending and return times. For example, the following can be obtained: Figure 11 The network latency shown, such as "router latency 1ms" and "total game latency 37ms", can be used to conclude, based on the principle that most users can tolerate latency of less than 250ms, that "there is no significant latency when playing games using the current network speed".
[0126] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3 As shown, the target detection results include network anomaly detection results; during the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device respectively, and obtains the target detection results, including:
[0127] In step S401, during the keep-alive time, the network service set identifier SSID and the basic service set identifier BSSID corresponding to the SSID are obtained.
[0128] In step S402, a list of trusted identifiers is obtained through the network access security detection module, and the SSID and BSSID of the network are identified according to the list of trusted identifiers to obtain the network anomaly detection result.
[0129] In this embodiment, after the server allocates a keep-alive time for the network access security detection module, the security detection process of the network access security detection module will not be suspended during the keep-alive time. Therefore, the network access security detection module can obtain the network's Service Set Identifier (SSID) and the corresponding Basic Service Set Identifier (BSSID), obtain a trusted identifier list from the server, and identify the network's SSID and BSSID based on the trusted identifier list. The identification result is used as the network anomaly detection result, so that the network anomaly detection result can be directly pushed to the target terminal device. This allows the target user of the target terminal device to understand whether there is a risk in the current network in a timely manner through the obtained network anomaly detection result, avoiding economic losses, loss of important files, or leakage of private information.
[0130] The Service Set Identifier (SSID) is used to distinguish different networks. Wireless network cards can access different networks by setting different SSIDs. SSIDs are usually broadcast by Wireless Access Points (APs). It can be understood that the SSID is the name of a local area network. Only terminal devices with the same SSID value can communicate with each other. The SSID can divide a wireless LAN into several sub-networks that require different authentication. Each sub-network requires independent authentication. Only the target object that has been authenticated can enter the corresponding sub-network, which can prevent other unauthorized objects from entering the network. For example, when a target object uses a target terminal device such as a laptop to search for accessible networks, the network name displayed is the SSID. The Basic Service Set Identifier (BSSID) refers to the MAC address of a site, which is essentially the address of the Access Point (AP). The BSSID identifies the Basic Service Set (BSS) managed by the AP. Within the same AP, there is a one-to-one mapping between BSSIDs and SSIDs; that is, if an AP can support multiple SSIDs simultaneously, the AP will assign multiple different BSSIDs to each SSID. Specifically, the trusted identifier list can be represented as a list of trusted SSIDs and BSSIDs corresponding to public Wi-Fi networks, used to indicate the SSIDs and BSSIDs corresponding to multiple securely verified and trusted networks.
[0131] Specifically, after the server allocates keep-alive time for the network access security detection module, it can activate the security detection algorithm encapsulated in the module to perform security checks on the target terminal device and the network it connects to. Specifically, the module can send a trusted network query request to the server to retrieve a list of trusted identifiers. It can also obtain the SSID and BSSID of the current network (connected to by the target terminal device) by checking if the SSID and BSSID match any identifiers in the trusted identifier list. If they match, it indicates that the current network is similar to a known public Wi-Fi network in the list, or that there are public Wi-Fi networks with similar names in the vicinity. In this case, it can be determined that the current network does not pose a phishing or spoofing risk. Phishing risk refers to situations where phishing websites use viruses to steal the target's property or leak their private information. Conversely, if no identifier matches, it suggests that the current network may have security risks or network anomalies.
[0132] Furthermore, while performing security identification of the network's SSID and BSSID based on the trusted identifier list, the network access security detection module can also detect whether the current network is attempting automatic redirection. If an automatic redirection is attempted, it can detect whether the website the current network is about to redirect to is a risky website. The website address can be queried from the maintained risky URL database. If the website address of the website the current network is about to redirect to can be found in the URL database, the website can be considered a safe website, and a network anomaly detection result indicating that the current network is not currently at risk can be obtained and pushed to the target terminal device. Conversely, if the website address of the website the current network is about to redirect to cannot be found in the URL database, the website can be considered a risky website, and the network access security detection module can intercept the network redirection and push and display the network anomaly detection result indicating that the current network has security risks to the target terminal device.
[0133] Furthermore, while detecting whether the website the current network is about to redirect to is a risky website, the network access security detection module can also call the Internet packet explorer to obtain the IP addresses that can be connected to the current network. Based on the uniqueness of the IP address of the target terminal device connecting to the current network, the number of terminal devices connected to the current network can be determined according to the obtained IP addresses. This allows the target users of the current network to understand the current network usage status in a timely manner, such as... Figure 12 As shown, there are 23 terminal devices connected to the current network of the target terminal device.
[0134] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3 As shown, the keep-alive time includes a first keep-alive time and a second keep-alive time. During the keep-alive time, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device, respectively, and obtains the target detection results, including:
[0135] In step S501, if the network access security detection operation is not completed after the first keep-alive time, a second keep-alive time is allocated to the network access security detection module according to the polling mechanism.
[0136] In step S502, during the second keep-alive time, the network access security detection operation continues to be performed to obtain the target detection result.
[0137] In this embodiment, as Figure 6 As shown, after allocating a keep-alive time for network environment detection to the activated network access security detection module, there may be a situation where the network access security detection module has not completed the security detection operation on the target terminal device and the current network connected to the target terminal device after the first keep-alive time has expired. In order to obtain accurate and complete target detection results, this embodiment can establish a polling mechanism through the background keep-alive module. This mechanism allows the security detection module to continuously request more keep-alive time from the server while it is in a background active state, i.e., repeatedly request a second keep-alive time. This allows the server to repeatedly and fixedly allocate multiple second keep-alive times to the network access security detection module, enabling it to continue performing network access security detection operations until the detection work is completed, thus obtaining target detection results more accurately.
[0138] The survival time includes the first survival time and the second survival time. The first survival time and the second survival time can be the same or different, and there are no specific restrictions here.
[0139] Specifically, such as Figure 6 As shown, after allocating a keep-alive time for network environment detection to the activated network access security detection module, if the network access security detection module has not completed the network access security detection operation after the first keep-alive time expires, multiple second keep-alive times can be allocated to the network access security detection module in sequence and repeatedly according to the polling mechanism established in advance through the background keep-alive module. This allows the network access security detection module to continue performing network access security detection operations until the detection work is completed and the target detection result is obtained.
[0140] For example, when target object S3 uses target terminal device S of iOS system to connect to wireless network P from mobile network Q, the mobile security management application is automatically activated to perform security network detection on wireless network P. When the current activation state of the mobile security management application is detected to be background activation state, the server can allocate a first keep-alive time of 10 seconds to the mobile security management application according to the pre-set keep-alive mechanism. When the first keep-alive time expires and the mobile security management application has not completed the security detection operation, the server will allocate a second keep-alive time of 15 seconds twice to the mobile security management application according to the polling mechanism to complete the security detection work.
[0141] Understandably, if the network access security detection module has not completed the security detection operation after the first keep-alive time expires, a second keep-alive time that can be pre-allocated can be set by the server. That is, the server allocates a second keep-alive time with a longer time span to the network access security detection module, so that the network access security detection module can continue to perform network access security detection operations until the detection work is completed and the target detection result is obtained.
[0142] For example, when target object S3 uses target terminal device S of iOS system to connect to wireless network P from mobile network Q, the mobile security management application is automatically activated to perform security network detection on wireless network P. When the current activation state of the mobile security management application is detected to be background activation state, the server can allocate a first keep-alive time of 10 seconds to the mobile security management application according to the pre-set keep-alive mechanism. When the first keep-alive time expires and the mobile security management application has not completed the security detection operation, the server can allocate a second keep-alive time of 30 seconds to the mobile security management application to complete the security detection work.
[0143] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3 As shown, before activating the network access security detection module when a network event characterizes a network handover behavior of the target terminal device, the method further includes:
[0144] In step S601, the network access security detection module is registered to have listening permissions between the network event and the network event indicating a network handover behavior of the target terminal device;
[0145] In step S602, based on the listening permission, if a network event is detected indicating that the target terminal device has performed a network switching behavior, the network access security detection module is activated.
[0146] In this embodiment, as Figure 8As shown, before activating the network access security detection module, support for the HotspotConfiguration component provided by the iOS system can be added. By utilizing the feature of this component that can be automatically activated when the network status changes, the network access security detection module, in conjunction with the support of the HotspotConfiguration component, can monitor network events occurring in the system in real time. It can achieve the following: even if the network access security detection module is not activated in the foreground, it can still receive an activation callback instruction when the network changes, so as to intelligently activate the network access security detection module, detect the network environment such as the security, network speed, and number of connected devices of the target terminal device, analyze the risk of the current network environment, and inform the target terminal device user of the target detection results in real time.
[0147] Specifically, such as Figure 8 As shown, after the system starts, the HotspotConfiguration component also starts. At this time, the security detection module can request access from the system. At the same time, it can also register network events that need to be monitored with the HotspotConfiguration component, such as scanning nearby networks, network connection failure, network connection success, etc. However, in this embodiment, the network events that need to be monitored include: the target terminal device user going from a state without network to successfully connecting to the wireless network WiFi, switching from a mobile network to a wireless network, or switching from wireless network A to wireless network B, etc.
[0148] Furthermore, such as Figure 8 As shown, when a target terminal device experiences a network event, such as transitioning from a network-less state to a wireless network connection, the component, upon detecting the network event, can first determine if a third-party module, such as a security detection module, has registered the network event. If so, the component can filter out the registered third-party module from the registration list and activate it by sending an event activation callback command. Then, the component transmits the network event to the third-party module, enabling it to perform corresponding processing operations based on the obtained network event and information. For example, if the third-party module is a security detection module, it can perform network access security network detection operations on the network event transitioning from a network-less state to a wireless network connection to obtain the target detection results.
[0149] Optionally, in the above Figure 2 Based on the corresponding embodiments, in another optional embodiment of the network environment detection method provided in this application, such as... Figure 3 As shown, before pushing and displaying the target detection results to the target terminal device, the method further includes:
[0150] In step S701, a result record identifier and a target push message are generated based on the target detection results;
[0151] In step S702, the target detection result, the result record identifier, and the target push message are saved accordingly;
[0152] In step S703, a target push message is pushed to and displayed to the target terminal device;
[0153] In step S704, when a touch signal corresponding to the target push message is received, the target detection result is displayed to the target terminal device.
[0154] In this embodiment, as Figure 9 As shown, after the security detection module completes the security detection of the target terminal device and the current network connected to the target terminal device and obtains the target detection result, it can generate a result record identifier and a target push message based on the target detection result, and save the detection result, that is, save the current detection time, result record identifier, target push message and the current target detection result. This allows the target push information displayed on the target terminal device to be quickly and accurately indexed to the target detection result through the result record identifier and displayed on the target terminal device without having to re-perform security network detection on the same connected network. It can also reduce the operational threshold for users of the target terminal device to perform network detection and improve the users of the target terminal device's security awareness of the current network environment.
[0155] Furthermore, such as Figure 9 As shown, after the target detection result, result record identifier, and target push message are saved accordingly, since the current detection time, target push message, and current target detection result can all be associated with or saved under the result record identifier, the target push information can be displayed on the target terminal device. When a touch signal corresponding to the target push message is received, the target detection result can be quickly and accurately indexed through the association between the target push information and the result record identifier, and the queried target detection result can be displayed on the target terminal device. There is no need to reactivate the security detection module to perform security network detection on the same connected network. This also reduces the operational threshold for users of the target terminal device to perform network detection and improves the users of the target terminal device's security awareness of the current network environment.
[0156] The result record identifier is an information identifier (ID) used to indicate the target detection result of the network. It can be represented as an integer (int) string or a string, etc. The target push message can be in the form of an email or timely message containing summary information or key information of the target detection result, or it can be in other message forms, such as a pop-up window or status bar. There are no specific restrictions here.
[0157] Specifically, the touch signal corresponding to the target push message can be generated by the user of the target terminal device clicking, moving the cursor, or long-pressing the target push information displayed on the target terminal device. It can also be generated by other means, without specific restrictions here.
[0158] Specifically, such as Figure 9 As shown, after the security detection module completes the security detection of the target terminal device and the current network connected to the target terminal device, it can first check whether the target detection result is obtained. If the target detection result is not obtained, it can be understood that the target terminal device and the current network connected to the target terminal device do not need to be detected for security network, such as the existence of historical network detection results with a short detection interval. Therefore, there is no need to send a security detection prompt to the target terminal device.
[0159] Furthermore, if the target detection result is obtained, it can be understood that the security detection module has performed a complete security detection on the target terminal device and the current network connected to the target terminal device. Therefore, based on the target detection result, a result record identifier and a target push message can be generated. The current detection time, the target push message, and the current target detection result are all associated with or stored under the result record identifier. This allows the target push information displayed on the target terminal device to be quickly and accurately indexed to the target detection result through the result record identifier and displayed on the target terminal device. Secondly, it can also be used for the next security detection of the same network to obtain the target detection result of this time as a historical network detection result to determine whether a security detection is needed, so as to avoid duplicate and redundant security detection.
[0160] For example, suppose a target detection result indicates that the current network speed of wireless network Y is 4.11 MB / s, the total number of terminal devices currently connected to wireless network Y is 18, none of the terminal devices currently connected to wireless network Y are infected with Trojans or viruses, wireless network Y is not a phishing WiFi, and wireless network Y has high security. Based on this target detection result, a result record identifier Y001 is generated. The target push message contains a pop-up message indicating that the current network speed of wireless network Y is 4.11 MB / s, the total number of terminal devices currently connected to wireless network Y is 18, and wireless network Y has high security. The current detection time, such as 2020.10.30 13:30:12, the target push message, and the current target detection result are all associated with the result record identifier Y001.
[0161] Furthermore, such as Figure 9 As shown, after saving the target detection results, result record identifiers, and target push messages, the target push information can be displayed on the target terminal device. When the user of the target terminal device needs to perform security awareness of the current network environment, the user can generate corresponding touch signals by clicking, moving the cursor, or long-pressing the target push information displayed on the target terminal device. This allows the server to receive the touch signals corresponding to the target push message and quickly and accurately index the corresponding target detection results in the database through the association between the target push information and the result record identifier. Then, the retrieved target detection results can be displayed on the target terminal device, specifically in the form of a report or list, or other display formats. There are no specific restrictions here. It can be understood that after the network security detection is completed, target push information of the current network can be pushed to the user of the target terminal device. The user of the target terminal device can click on the target push information to view the corresponding target detection results. The user of the target terminal device can immediately view the generated target detection results without a long wait, which can improve the user's security awareness of the current network environment.
[0162] For example, Figure 10As shown, suppose that the target terminal device X, used by user S2, displays a pop-up message indicating that the current network speed of wireless network Y is 4.11 MB / s, the total number of terminal devices currently connected to wireless network Y is 18, and wireless network Y has high security. User S2 can generate a corresponding touch signal by clicking on this push message. The server can then quickly index the target detection results in the database based on the correlation between the push message and the result record identifier Y001. The results include: the current network speed of wireless network Y is 4.11 MB / s, the total number of terminal devices currently connected to wireless network Y is 18, none of the terminal devices connected to wireless network Y are infected with Trojans or viruses, wireless network Y is not a phishing WiFi, and wireless network Y has high security.
[0163] For example, Figure 11 As shown, assuming a target detection result includes a current network speed of 4.17 MB / s for wireless network Q, a router latency of 1 ms under the current connection to wireless network Q, a community network latency of 4 ms under the current connection to wireless network Q, and a game latency of 1 ms under the current connection to wireless network Q, we can obtain the detection result that the total latency of the game application D under the current connection to wireless network Q is no significant latency, and the detection result that the current connection to wireless network Q has a very fast network speed, allowing for the viewing of high-resolution videos such as Blu-ray or ultra-high-definition.
[0164] For example, Figure 12 As shown, suppose there is a target detection report that includes a total of 18 terminal devices currently connected to wireless network Y, and these 18 terminal devices are secure devices, the currently connected wireless network Y is not a fake public WiFi, and will not automatically redirect to dangerous or phishing websites under the current wireless network Y, and the current wireless network Y has high security and no security risks.
[0165] It is understandable that users of the target terminal device who have been tested typically need to wait about half a minute to a minute to complete the network detection by manually entering the security detection software. However, the time for the automatic security detection and acquisition of the target detection results in this embodiment is much less than half a minute.
[0166] The network environment detection device in this application is described in detail below. Please refer to [link / reference]. Figure 13 , Figure 13 This is a schematic diagram of one embodiment of the network environment detection device in this application. The network environment detection device 20 includes:
[0167] Acquisition unit 201 is used to acquire network events of the target terminal device;
[0168] Processing unit 202 is used to activate the network access security detection module when a network event characterizes a network switching behavior of the target terminal device;
[0169] The processing unit 202 is also used to allocate a keep-alive time for network environment detection to the activated network access security detection module;
[0170] The processing unit 202 is also used to perform network access security detection on the target terminal device and the network connected to the target terminal device through the network access security detection module during the keep-alive time, and obtain the target detection result;
[0171] The display unit 203 is used to push and display the target detection results to the target terminal device.
[0172] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application,
[0173] The acquisition unit 201 is also used to acquire historical network detection results corresponding to the network connected to the target terminal device;
[0174] The processing unit 202 is also configured to allocate a keep-alive time for network environment detection to the activated network access security detection module if the historical detection time of the historical network detection result meets the re-detection conditions.
[0175] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application, the processing unit 202 can specifically be used for:
[0176] During the keep-alive period, a preset configuration file is downloaded using the network connected to the target terminal device. The network download traffic and download time corresponding to the download of the preset configuration file are recorded by the network access security detection module.
[0177] Download speed is calculated based on network download traffic and download time to obtain network speed test results.
[0178] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application, the processing unit 202 can specifically be used for:
[0179] During the keep-alive period, obtain the network service set identifier (SSID) and the corresponding basic service set identifier (BSSID);
[0180] The network access security detection module obtains a list of trusted identifiers and identifies the network's SSID and BSSID based on the list to obtain network anomaly detection results.
[0181] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application, the processing unit 202 can specifically be used for:
[0182] If the network access security detection operation is not completed after the first keep-alive time, a second keep-alive time will be allocated to the network access security detection module according to the polling mechanism.
[0183] During the second keep-alive period, network access security detection operations continue to be performed to obtain the target detection results.
[0184] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application,
[0185] Processing unit 202 is also used to register the listening permissions between the network access security detection module and the network event being a network switching behavior of the target terminal;
[0186] Processing unit 202 can specifically be used for:
[0187] If a network event is detected indicating that the target terminal has switched networks, the network access security detection module will be activated.
[0188] Optionally, in the above Figure 13 Based on the corresponding embodiments, in another embodiment of the network environment detection device provided in this application,
[0189] The processing unit 202 is also used to generate a result record identifier and a target push message based on the target detection result;
[0190] The processing unit 202 is also used to save the target detection result, the result record identifier, and the target push message accordingly.
[0191] Display unit 203 can be specifically used for:
[0192] Push and display target push messages to target terminal devices;
[0193] When a touch signal corresponding to a target push message is received, the target detection result is displayed to the target terminal device.
[0194] This application also provides a schematic diagram of another computer device, such as... Figure 14 As shown, Figure 14This is a schematic diagram of a computer device structure provided in an embodiment of this application. The computer device 300 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 310 (e.g., one or more processors) and a memory 320, and one or more storage media 330 (e.g., one or more mass storage devices) for storing application programs 331 or data 332. The memory 320 and storage media 330 can be temporary or persistent storage. The program stored in the storage media 330 may include one or more modules (not shown in the diagram), each module including a series of instruction operations on the computer device 300. Furthermore, the CPU 310 may be configured to communicate with the storage media 330 and execute the series of instruction operations in the storage media 330 on the computer device 300.
[0195] Computer device 300 may also include one or more power supplies 340, one or more wired or wireless network interfaces 350, one or more input / output interfaces 360, and / or one or more operating systems 333, such as Windows Server. TM Mac OS X TM Unix TM Linux TM FreeBSD TM etc.
[0196] The aforementioned computer device 300 is also used to perform, for example Figures 2 to 3 The steps in the corresponding embodiments.
[0197] Another aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform actions such as... Figures 2 to 3 The steps in the method described in the illustrated embodiment.
[0198] Another aspect of this application provides a computer program product containing instructions that, when run on a computer or processor, cause the computer or processor to perform actions such as Figures 2 to 3 The steps in the method described in the illustrated embodiment.
[0199] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0200] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.
[0201] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0202] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0203] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A method for detecting network environment, characterized in that, Applied to iOS systems, including: Acquire network events from the target terminal device; When the network event indicates that the target terminal device has undergone network switching behavior, the network access security detection module is activated according to the binding relationship between the network event indicating that the target terminal device has undergone network switching behavior and the network access security detection module. Detect the current activation status of the network access security detection module; If the current activation state is a background activation state, allocate a keep-alive time for network environment detection to the activated network access security detection module so that the security detection process of the network access security detection module is not suspended during the keep-alive time. During the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain the target detection result. The target detection results are pushed to and displayed to the target terminal device.
2. The method according to claim 1, characterized in that, After activating the network access security detection module, the method further includes: Obtain historical network detection results corresponding to the network connected to the target terminal device; If the historical detection time of the historical network detection result meets the re-detection conditions, then the keep-alive time for network environment detection is allocated to the activated network access security detection module.
3. The method according to claim 1, characterized in that, The target detection results include network speed detection results; During the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain target detection results, including: During the keep-alive period, a preset configuration file is downloaded using the network connected to the target terminal device, and the network download traffic and download time corresponding to the download of the preset configuration file are recorded by the network access security detection module. The download speed is calculated based on the network download traffic and download time to obtain the network speed detection result.
4. The method according to claim 1, characterized in that, The target detection results also include network anomaly detection results; During the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain target detection results, including: During the keep-alive period, obtain the Service Set Identifier (SSID) of the network and the Basic Service Set Identifier (BSSID) corresponding to the SSID; The network access security detection module obtains a list of trusted identifiers and identifies the SSID and BSSID of the network based on the list of trusted identifiers to obtain the network anomaly detection result.
5. The method according to claim 1, characterized in that, The survival time includes a first survival time and a second survival time; During the keep-alive period, the network access security detection module performs network access security detection on the target terminal device and the network connected to the target terminal device to obtain target detection results, including: If the network access security detection operation is not completed after the first keep-alive time, the network access security detection module is allocated a second keep-alive time according to the polling mechanism. During the second keep-alive period, the network access security detection operation continues to be performed to obtain the target detection result.
6. The method according to any one of claims 1 to 4, characterized in that, Before activating the network access security detection module, the method further includes: Register the network access security detection module and the network event that is the network switching behavior of the target terminal device; When the network event indicates that the target terminal has performed a network handover, the network access security detection module is activated, including: Based on the aforementioned monitoring permissions, if the network event detected indicates that the target terminal has engaged in network switching behavior, the network access security detection module is activated.
7. The method according to any one of claims 1 to 4, characterized in that, Before pushing and displaying the target detection result to the target terminal device, the method further includes: Based on the target detection results, a result record identifier and a target push message are generated; Save the target detection result along with the result record identifier and the target push message; The step of pushing and displaying the target detection results to the target terminal device includes: Push and display the target push message to the target terminal device; When a touch signal corresponding to the target push message is received, the target detection result is displayed to the target terminal device.
8. A network environment detection device, characterized in that, Applied to iOS systems, including: The acquisition unit is used to acquire network events of the target terminal device. The processing unit is configured to activate the network access security detection module when the network event characterizes the target terminal to perform a network switching behavior, based on the binding relationship between the network event characterizes the target terminal device's network switching behavior and the network access security detection module. The processing unit is further configured to detect the current activation state of the network access security detection module; if the current activation state is a background activation state, allocate a keep-alive time for network environment detection to the activated network access security detection module so that the security detection process of the network access security detection module is not suspended during the keep-alive time. The processing unit is further configured to perform network access security detection on the target terminal device and the network connected to the target terminal device through the network access security detection module during the keep-alive period, and obtain the target detection result; The display unit is used to push and display the target detection results to the target terminal device.
9. The apparatus according to claim 8, characterized in that, The acquisition unit is also used to acquire historical network detection results corresponding to the network connected to the target terminal device; The processing unit is further configured to, if the historical detection time of the historical network detection result meets the re-detection conditions, execute the process of allocating a keep-alive time for network environment detection to the activated network access security detection module.
10. The apparatus according to claim 8, characterized in that, The target detection result includes the network speed detection result, and the processing unit is specifically used for: During the keep-alive period, a preset configuration file is downloaded using the network connected to the target terminal device, and the network download traffic and download time corresponding to the download of the preset configuration file are recorded by the network access security detection module. The download speed is calculated based on the network download traffic and download time to obtain the network speed detection result.
11. The apparatus according to claim 8, characterized in that, The target detection result also includes network anomaly detection result, and the processing unit is specifically used for: During the keep-alive period, obtain the Service Set Identifier (SSID) of the network and the Basic Service Set Identifier (BSSID) corresponding to the SSID; The network access security detection module obtains a list of trusted identifiers and identifies the SSID and BSSID of the network based on the list of trusted identifiers to obtain the network anomaly detection result.
12. The apparatus according to claim 8, characterized in that, The keep-alive time includes a first keep-alive time and a second keep-alive time; the processing unit is specifically used for: If the network access security detection operation is not completed after the first keep-alive time, the network access security detection module is allocated a second keep-alive time according to the polling mechanism. During the second keep-alive period, the network access security detection operation continues to be performed to obtain the target detection result.
13. The apparatus according to any one of claims 8 to 10, characterized in that, The processing unit is also used to register the network access security detection module's listening permission for the network event being a network switching behavior of the target terminal device; The processing unit is specifically used for: Based on the aforementioned monitoring permissions, if the network event detected indicates that the target terminal has engaged in network switching behavior, the network access security detection module is activated.
14. The apparatus according to any one of claims 8 to 10, characterized in that, The processing unit is further configured to generate a result record identifier and a target push message based on the target detection result; and to save the target detection result in correspondence with the result record identifier and the target push message. The display unit is specifically used for: Push and display the target push message to the target terminal device; When a touch signal corresponding to the target push message is received, the target detection result is displayed to the target terminal device.
15. A computer device, characterized in that, include: Memory, transceiver, processor, and bus system; The memory is used to store programs; When the processor is used to execute a program in the memory, it implements the method as described in any one of claims 1 to 7; The bus system is used to connect the memory and the processor to enable communication between the memory and the processor.
16. A computer-readable storage medium comprising instructions which, when executed on a computer, cause the computer to perform the method as claimed in any one of claims 1 to 7.
17. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 7.