An access request processing method and apparatus
By forcibly downloading and displaying data carrying attack scripts in the browser terminal, the problem of attack scripts directly running attack servers in the data is solved, and data security protection is achieved.
Patent Information
- Application Number
- CN202310571774.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-19
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-05-19
AI Technical Summary
In the prior art, the attack scripts carried in the data can be directly run through the browser, attacking the server, resulting in the problem of the website being attacked.
When it is determined that there is a risk of script attack on the target object data, send the target object data to the browser and return the forced download instruction to save it in the target storage area of the browser terminal. The data is displayed through other applications to avoid opening directly in the browser.
Effectively prevent attack scripts from running in the browser, reducing the risk of server being attacked and ensuring data security.
Smart Images

Figure CN116566694B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a method and device for processing access requests. Background Art
[0002] With the continuous development of computer technology, people will use various multimedia data in the process of working or studying, such as: PDF, Word documents, audio, and video, etc. For the convenience of information sharing, people will upload some data to the server for continued use by users in need.
[0003] However, there are often some lawbreakers who take advantage of the loopholes in the website to carry attack scripts in the uploaded data, and then use these attack scripts to attack the website or obtain information of the website. For example, a hacker carries an attack script in a PDF document uploaded to the server. When other users access the PDF document through a browser, the browser will directly open the PDF document for preview, so that the attack script carried in the PDF will be automatically triggered, enabling lawbreakers to obtain relevant information of the website. Based on this, how to reduce the attack on the website by attack scripts carried in data is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0004] In view of this, this application provides a method and device for processing access requests to reduce the situation of the website being attacked by attack scripts carried in data.
[0005] To achieve the above object, the following solutions are proposed:
[0006] On the one hand, this application provides a method for processing access requests, including:
[0007] Obtain an object access request sent by a browser, where the object access request includes address identification information for indicating target object data to be requested;
[0008] Based on the address identification information, obtain the target object data;
[0009] When it is determined that the target object data belongs to object data with a risk of script attack, send the target object data and a forced download instruction to the browser. The forced download instruction is used to instruct the browser to save the target object data to a target storage area of the terminal where the browser is located, so that the user can use an application other than the browser to display the target object data stored in the target storage area, and the target storage area does not belong to the storage area corresponding to the browser.
[0010] In a possible implementation, determining that the target object data belongs to the object data at risk of script attack includes at least one of the following:
[0011] If the address identification information belongs to the set data addresses at risk of script attack, determine that the target object data belongs to the object data at risk of script attack;
[0012] If the target object data belongs to the object data of the target type, determine that the target object data belongs to the object data at risk of script attack, where the object data of the target type is the set object data that can carry attack scripts.
[0013] In another possible implementation, obtaining the target object data based on the address identification information includes:
[0014] If the address identification information is encrypted address information, based on the encrypted address information, determine the actual storage address of the target object data;
[0015] Based on the actual storage address, obtain the target object data;
[0016] The step of determining that the target object data belongs to the object data at risk of script attack if the address identification information belongs to the set data addresses at risk of script attack includes:
[0017] If the address identification information belongs to encrypted address information, determine that the target object data belongs to the object data at risk of script attack.
[0018] In another possible implementation, it further includes:
[0019] If the address identification information does not belong to encrypted address information and the address identification information belongs to the marked prohibited access address, do not respond to the object access request, where the fact that the address identification information belongs to the prohibited access address indicates that the object data pointed to by the address identification information is the object data that can carry attack scripts.
[0020] In another possible implementation, the step of determining the actual storage address of the target object data based on the encrypted address information includes:
[0021] Decrypt the encrypted address information to obtain the actual identification information contained in the encrypted address information, where the actual identification information is used to uniquely identify the actual storage address of the target object data;
[0022] Based on the actual identification information, determine the actual storage address of the target object data.
[0023] In yet another possible implementation manner, before obtaining the object access request sent by the browser, it further includes:
[0024] Obtaining target object data sent by the user terminal;
[0025] If the target object data belongs to object data with a script attack risk, storing the target object data and setting the target object data as object data that needs to be forced to be downloaded.
[0026] In yet another possible implementation manner, setting the target object data as object data that needs to be forced to be downloaded includes:
[0027] Determining the address identification information of the target object data;
[0028] Setting the address identification information of the target object data as a data address with a script attack risk.
[0029] In yet another possible implementation manner, determining the address identification information of the target object data includes:
[0030] Determining the actual storage address of the target object data;
[0031] Setting the address identification information of the target object data as a data address with a script attack risk includes:
[0032] Based on the actual storage address of the target object data, constructing encrypted address information, where the encrypted address information is used to indicate that the target object data belongs to object data with a script attack risk.
[0033] In yet another possible implementation manner, setting the address identification information of the target object data as a data address with a script attack risk further includes:
[0034] Storing the actual storage address of the target object data in a prohibited access directory, where the prohibited access directory is used to store storage addresses that are prohibited from direct access.
[0035] In yet another aspect, the present application further provides an access request processing device, including:
[0036] A request obtaining unit, configured to obtain an object access request sent by the browser, where the object access request includes address identification information for indicating target object data to be requested;
[0037] A data determination unit, configured to obtain the target object data based on the address identification information;
[0038] An information sending unit, configured to send the target object data and a forced download instruction to the browser when it is determined that the target object data belongs to the object data with a risk of script attack. The forced download instruction is used to instruct the browser to save the target object data to a target storage area of the terminal where the browser is located, so that the user can use an application other than the browser to display the target object data stored in the target storage area, and the target storage area does not belong to the storage area corresponding to the browser.
[0039] As can be seen from the above, in the embodiment of the present application, if it is determined that the target object data to be requested by the object access request belongs to the object data with a risk of script attack, when sending the target object data to the browser, a forced download instruction will be returned to the browser. Through this forced download instruction, the browser can be instructed to save the target object data on the terminal of the browser, so that the user can open and display the target object data through other applications, avoiding directly previewing the target object data through the browser. Therefore, even if the target object data carries an attack script, since the attack script of the target object data is not directly opened and displayed through the browser, the attack script naturally cannot be run through the browser, and thus the server cannot be attacked through the attack script, thereby reducing the situation of running the attack script through the browser and attacking the server due to the attack script carried in the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0041] Figure 1 FIG. shows a schematic flowchart of a method for processing an access request provided by an embodiment of the present application;
[0042] Figure 2 FIG. shows a schematic flowchart of storing object data in an embodiment of the present application;
[0043] Figure 3 FIG. shows another schematic flowchart of a method for processing an access request provided by an embodiment of the present application;
[0044] Figure 4 FIG. shows a schematic structural diagram of an access request processing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0046] Next, an access request processing method provided by an embodiment of the present application will be introduced.
[0047] As Figure 1 , which shows a schematic flowchart of an access request processing method provided by an embodiment of the present application. The present application can be applied to a server providing data access services, such as a server providing various multimedia data access and storage services, etc., without limitation.
[0048] The method of this embodiment includes:
[0049] Step S101, obtain an object access request sent by a browser.
[0050] The object access request includes address identification information for indicating the target object data to be requested.
[0051] Among them, the object access request is a request for requesting to obtain a certain object data. In the present application, these object data have various forms, such as: documents, pictures, videos, audios, etc.
[0052] In order to identify the target object data to be accessed, the object access request includes the address identification information of the target object data. Among them, the target object data can be understood as the target object to be accessed by the user, such as: a document named A. And the address identification information is the identification information for locating the target object data. For example, the address identification information may be the actual storage address of the target object data, or may be the identification information after processing the actual storage address of the target object data. Different situations will be described later and will not be elaborated here.
[0053] Step S102, obtain the target object data based on the address identification information.
[0054] As introduced above, since the address identification information is used to locate the target object data, therefore, based on the address identification information, the server can obtain the target object data required by the browser to access.
[0055] Step S103, in the case where it is determined that the target object data belongs to the object data with the risk of script attack, send the target object data and a forced download instruction to the browser.
[0056] In this application, before sending the target object data to the browser, in order to reduce the situation of being attacked by malicious scripts, it is necessary to determine whether the target object data is object data with a risk of script attack. When it is determined that the target object data belongs to the object data with a risk of script attack, the target object data and a forced download instruction are sent to the browser.
[0057] Among them, the forced download instruction is used to instruct the browser to save the target object data in the target storage area of the terminal of the browser, so that the user can use an application other than the browser to display the target object data stored in the target storage area, thereby avoiding directly previewing the target object data through the browser.
[0058] Among them, the target storage area does not belong to the storage area corresponding to the browser. The storage area corresponding to the browser is the storage space allocated to the browser, such as the buffer area and hard disk storage area allocated to the browser.
[0059] It can be understood that after the server issues the forced download instruction to the browser, the browser will save the target object data to the local of the terminal where the browser is located, rather than directly opening and displaying the target object data through the browser. After saving the target object data to the terminal of the browser, the user can directly open the target object data stored in the target storage area. For example, if the target object data is PDF data, it can also be opened and displayed through a PDF reader, etc.; it can also be to output identification information indicating that the target object data has been downloaded, and when the user clicks to open it, the browser calls the application used to present the target object data to display the target object data. Of course, there can also be other ways to use an application other than the browser to display the target object data, and no restrictions are imposed on this.
[0060] In this application, if it is determined that the target object data to be requested by the object access request belongs to the object data with a risk of script attack, when sending the target object data to the browser, a forced download instruction will be returned to the browser. Through this forced download instruction, the browser can be instructed to save the target object data on the terminal of the browser, so that the user can open and display the target object data through other applications, avoiding directly previewing the target object data through the browser. Therefore, even if the target object data carries a malicious script, since the malicious script is not directly opened and displayed through the browser, naturally the malicious script cannot be run through the browser, thereby preventing the malicious script from attacking the server, and naturally reducing the situation of running the malicious script through the browser and attacking the server due to the malicious script carried in the data.
[0061] In this application, there are multiple possible specific implementations for determining whether the target object data belongs to the object data at risk of script attacks. The following uses several possible implementation methods as examples for illustration.
[0062] In one possible implementation method, considering that the object data that can carry attack scripts are all of specific data types, therefore, the type of the target object data can be determined first. If the target object data belongs to the object data of the target type, it is determined that the target object data belongs to the object data at risk of script attacks. Among them, the object data of the target type is the set object data that can carry attack scripts.
[0063] The object data of the target type can be set according to actual needs. The target type can include one or more types, and there is no restriction on this. For example, through research, it is found that attack scripts can be carried in PDF documents, then PDF documents can be set as the object data of the target type. Then, if the target object data belongs to a PDF document, the target object data belongs to the object data that can carry attack scripts.
[0064] In another possible implementation method, considering that the complexity of identifying the type of object data is relatively high, in order to more efficiently identify the object data that needs to be indicated for forced download, in this application, when the server stores the target object data, the address identification information of the target object data can be set as the data address at risk of script attacks. On this basis, if the server determines that the address identification information in the object access request belongs to the set data address at risk of script attacks, it is determined that the target object data is the object data at risk of script attacks.
[0065] For example, if the address identification information belongs to the address information recorded in the forced download directory, it is determined that the target object data pointed to by the address identification information belongs to the object data that can carry attack scripts, that is, the object data at risk of script attacks.
[0066] Another example is that the server can also pre-process the address information of the object data that can carry attack scripts in advance. In this way, if the server determines that the address identification information is of a specific type of address identification information, it will determine that the target object data requested to be accessed by the object access request is the object data at risk of script attacks. Among them, the specific type of address identification information is not the actual storage address of the data object, but the encrypted address information. It will be introduced in detail later and will not be elaborated here.
[0067] It can be understood that in this application, the address identification information included in the object access request can be the actual storage address of the target object data.
[0068] Specifically, when the target object data belongs to object data that can carry an attack script, in order to reduce the actual storage address of the target object data obtained by others through malicious polling access or other means, and to prevent the attack script carried in the target object data from attacking the server due to the failure of the forced download mechanism or the like; or, in order to enable the server to recognize that the object data requested by the object access request is object data with an attack risk, so as to distinguish it from a regular object access request, the address identification information in this application can also be encrypted address information. On this basis, if the address identification information is encrypted address information, based on this encrypted address information, determine the actual storage address of the target object data; based on this actual storage address, obtain the target object data.
[0069] Further, when the address identification information is encrypted address information, the server determines that this address identification information is not a regular actual address, and the server can recognize that the target object data requested to be accessed by this address identification information belongs to object data with a script attack risk.
[0070] To facilitate understanding of the different situations of the address identification information in this application and the specific processing of object access requests for object data with a script attack risk, the following first describes the process of storing object data after the server obtains the object data uploaded by the user. It can be understood that the user can upload the object data to be stored to the server at any time. Therefore, the order of the process of storing object data and the process of processing object access requests can be not limited to a specific order.
[0071] For the sake of description and understanding, taking the case where the server obtains the object data uploaded by the user as the target object data as an example, in this case, the process of uploading the target object data is before the browser obtains the object access request for this target object data.
[0072] In this application, after the server obtains the target object data sent by the user terminal, it can determine whether this target object data belongs to object data with a script attack risk. For example, if this target object data belongs to object data of a set target type, it is determined that the target object data belongs to object data with a script attack risk or can carry an attack script. Correspondingly, when the server determines that this target object data belongs to object data with a script attack risk, while storing the target object data and determining the address identification information of this target object data, the server will also set the target object data as object data that needs to be forced to download.
[0073] Among them, there can be multiple possible implementation methods for setting the target object data as object data that needs to be forced to download. The following takes two possible methods as examples for illustration:
[0074] In one possible way: setting the target object data as the object data that needs to be forced to download can be adding a forced download flag to the target object data, and this forced download flag indicates that when the user requests the target object data, a forced download instruction needs to be returned to the user's browser.
[0075] In another possible way, setting the target object data as the object data that needs to be forced to download can also be, after determining the address identification information of the target object data, setting the address identification information of the target object data as a data address with a risk of script attack. For example, storing the address identification information in a forced download directory, and this forced download directory is used to store the address information corresponding to the object data that needs to indicate forced download. For example, after determining the actual storage address of the target object data, storing the actual storage address in the forced download directory, or alternatively, after generating encrypted address information based on the actual storage address, storing the encrypted address information in the forced download directory.
[0076] Taking the example of setting the address identification information of the target object data as a data address with a risk of script attack to identify that the target object data is the object data that needs to be forced to download, and combining a specific implementation for illustration.
[0077] For example Figure 2 , which shows a schematic flowchart of storing a data object in an embodiment of the present application. This embodiment can be applied to a server, and this embodiment may include:
[0078] Step S201, obtaining the target object data sent by the user terminal.
[0079] For example, the user sends the target object data to the server through the user terminal to request the server to store the target object data.
[0080] Among them, there can be various data forms for the server to obtain the target object data uploaded by the user, such as: documents, pictures, audio, and videos, etc., and there is no limitation on this.
[0081] Step S202, if the target object data belongs to the object data with a risk of script attack, storing the target object data, determining the actual storage address of the target object data, and storing the actual storage address in a prohibited access directory.
[0082] Among them, there are various ways to determine whether the target object data belongs to the object data with the risk of script attack. For example: determine whether the target object data is the object data of a preset target type. If so, it is determined that the target object data belongs to the object data with the risk of script attack. The target type is the type of object data that may carry the risk of script attack. For example, the object data of the target type can be PDF data. Another example is that it is also possible to use a pre-trained or constructed data risk classifier or recognizer, etc., to identify whether the target object data belongs to the object data with the risk of script attack.
[0083] Among them, the target object data can be stored in a database or a storage area associated with a server, which can be specifically set according to needs and is not restricted here.
[0084] It can be understood that there are various types of object data uploaded by different users to the server. Some object data itself belongs to the data that cannot carry attack scripts. In order to distinguish the object data with the risk of script attack and the object data without the risk of script attack, so that the browser can be instructed to perform forced download processing for the object data with the risk of script attack subsequently, and at the same time, in order to further improve the security of the server, the actual storage address of the object data with the risk of script attack will be stored in the prohibited access directory.
[0085] Among them, the prohibited access directory is used to store the storage addresses that are prohibited from direct access.
[0086] It can be understood that if the target object data does not belong to the object data with the risk of script attack, then the target object data can be directly stored and its actual storage address can be determined.
[0087] Of course, adding the actual storage address of the target object data to the prohibited access directory is only an optional method. In scenarios where the security requirements are not particularly high, this step operation can also not be performed.
[0088] It can be understood that if the target object data does not belong to the object data with the risk of script attack, then after storing the target object data and determining the actual storage address, other operations and the relevant operations of subsequent steps S203 and S204 need to be performed.
[0089] Step S203: Based on the actual storage address of the target object data, construct encrypted address information to obtain the address identification information of the target object data.
[0090] Among them, the purpose of using encrypted address information to locate the target object data is to indicate that the target object data belongs to the object data with the risk of script attack through the encrypted address information.
[0091] It can be understood that the target object data is a data type that can carry an attack script. However, the target object data does not necessarily actually contain an attack script. Therefore, it is not possible to set all data that can carry an attack script as inaccessible. Based on this, in order to ensure the user's normal access to the object data while reducing the risk of the server being attacked by an attack script, in this embodiment, for the object data with a script attack risk, a new address identifier needs to be regenerated based on the actual storage address of the object data, so that the user can only access the target object data using the encrypted address, and thus the server can subsequently determine whether the target object data requested to be accessed in the object access request belongs to the object data with a script attack risk based on whether the address identifier information carried in the object access request is encrypted address information.
[0092] The following introduces a possible way to construct encrypted address information: After determining the actual storage address of the target object data, encrypt the actual storage address to obtain the generated address identifier information for the user to access the target object data using this address identifier information.
[0093] Furthermore, to prevent the actual storage address of the target object data from being decrypted, after determining the actual storage address of the target object data, this application can also store the actual storage address of the target object data in an address list. Among them, each actual storage address in the geographical list corresponds to a unique label, such as an ID in the address list. On this basis, this application can encrypt the unique label corresponding to the actual storage address of the target object data to obtain the address identifier information of the target object data. The encryption algorithm for encrypting the unique label of the actual storage address can be selected as needed and is not limited in this regard.
[0094] For example: The unique label of the actual storage address of the H document in the address list is abc, and the RSA encryption algorithm can be used to encrypt this abc to obtain the encrypted address identifier information.
[0095] Step S204: Store the encrypted address information of the target object data in the forced download directory.
[0096] Among them, the forced download directory is a pre-specified file directory used to store the address information corresponding to the object data that needs to be indicated for forced download. On this basis, if the address identifier information in the object access request obtained by the server belongs to the address information in the forced download directory, then subsequently, while returning the data object corresponding to the address identifier information to the browser, a forced download instruction will also be returned to the browser.
[0097] Of course, step S204 is merely one implementation manner of setting the address identification information as the data address with the risk of script attack. In practical applications, a specific association mark can also be added to the address identification, and there is no limitation thereto.
[0098] It should be noted that in practical applications, by encrypting the address information, it can be indicated that the target object data pointed to by the encrypted address information is the object data that can carry the risk of script attack (such as data of PDF document type). Therefore, after the server obtains the object access request, as long as it identifies that the address identification information carried in the object access request is encrypted address information, it can be determined that when returning the target object data requested by the object access request to the browser, a forced download instruction needs to be sent to the browser. Based on this, step S204 can also be merely an optional manner to more reliably identify that the target object data pointed to by the encrypted address information is the data with the risk of script attack and needs to be forcibly downloaded.
[0099] In addition, this embodiment takes the address identification information as the encrypted address information that has been encrypted as an example for illustration. However, the address identification information can also directly adopt the actual storage address of the target object. On this basis, it is not necessary to set the actual storage address as the prohibited access address, but only to store the actual storage address in the forced download directory, which will not be elaborated here.
[0100] Next, taking a possible situation as an example, the access request processing method of the present application will be described. As Figure 3 shown, it shows another flowchart of the access request processing method provided by the embodiment of the present application. This embodiment may include:
[0101] Step S301: Obtain the object access request sent by the browser.
[0102] The object access request includes address identification information for indicating the target object data to be requested.
[0103] Among them, this step can refer to the introduction of the relevant steps above and will not be elaborated here.
[0104] Step S302: If the address identification information is the encrypted address information that has been encrypted, based on the encrypted address information, determine the actual storage address of the target object data.
[0105] Among them, if the address identification information carried in the object access request is encrypted address information, then the server can determine that the target object data requested by the object access request belongs to the target type of object data or is the object data that can carry the attack script.
[0106] Among them, the process of determining the actual storage address based on the encrypted address information is the reverse process of generating the encrypted address information based on the actual storage address before. When the process of generating the encrypted address information is different, the process of obtaining the actual storage address based on the encrypted address information will also be different. For example, in a possible implementation, if the encrypted address information is generated based on the actual identification information corresponding to the actual storage address of the target object data, the encrypted address information can be decrypted first to obtain the actual identification information. This actual identification information is used to uniquely identify the actual storage address of the target object data. Correspondingly, the actual storage address of the target object data can be determined based on the actual identification information.
[0107] For example, the actual identification information can be the ID of the actual storage address of the target object data in the address list. Then, the actual storage address corresponding to this ID in the address list can be queried to obtain the actual storage address of the target object data. For example: the actual identification information decrypted from the encrypted address information is 123, and then the actual storage address www.a***b.123 is obtained. Thus, subsequently, based on the actual storage address, the target object data stored in the storage area corresponding to this actual storage address can be obtained.
[0108] Step S303: Obtain the target object data based on the actual storage address.
[0109] Among them, since the actual storage address and the target object data are in one-to-one correspondence, therefore, based on the actual storage address, the target object data can be determined.
[0110] Step S304: Send the target object data and a forced download instruction to the browser.
[0111] Among them, the forced download instruction is used to instruct the browser to save the target object data to the target storage area of the terminal where the browser is located, so that the user can use an application other than the browser to display the target object data stored in the target storage area. This target storage area does not belong to the storage area corresponding to the browser.
[0112] It can be understood that since the server recognizes that the address carried in the object access request is encrypted address information, the server can determine that the target object data requested by the object access request belongs to the object data that can carry an attack script. Therefore, the server will execute steps S302 to S304 to instruct the browser to download the target object data, so that the target object data can be opened by other applications on the terminal where the browser is located later, avoiding directly opening and displaying the target object data on the browser side, and thus preventing the attack script from running on the browser when the target object data carries an attack script, and further reducing the situation of the attack script attacking the server.
[0113] Of course, in the case where the address identification information in the object access request is encrypted address information in step S302, the server can return a forced download instruction while returning the target object data to the browser as an example. In practical applications, if the server stores the encrypted address information that can carry the target object data in the forced download directory when storing the object data, then after obtaining the encrypted address information, the server can also detect whether the encrypted address information belongs to the address in the forced download directory. If so, the relevant operations in steps S302 to S304 are executed.
[0114] Step S305: If the address identification information does not belong to the encrypted address information, confirm that the address identification information is the actual storage address of the target object data, and detect whether the address identification information belongs to the designated prohibited access address. If so, do not respond to the object access request; if not, then execute step S306.
[0115] Among them, the address identification information belonging to the prohibited access address indicates that the object data pointed to by the address identification information is object data that can carry an attack script.
[0116] It can be understood that from the previous storage process of the target object data, if the address identification information does not belong to the encrypted address information, then it means that the address identification information is the actual storage address of the target object data. In this case, if the target object data is object data with a script attack risk (such as whether it is object data of a target type), after storing the target object data, the server will also mark the actual storage address of the target object data as a prohibited access address, so that others cannot directly access the target object data using this actual storage address.
[0117] For example, if the server stores the actual storage address of the target object data with a script attack risk in the prohibited access directory, then after the server obtains the object access request, if the address identification information in the object access request is the actual storage address, then it can be determined whether the actual storage address belongs to the address in the prohibited access directory. If so, then do not respond to the object access request; if not, then just execute step S306.
[0118] S306: Obtain the target object data based on the address identification information, and return the target object data to the browser.
[0119] For example, if the address identification information in the object access request is the real actual storage address and this actual storage address does not belong to the prohibited access addresses, it indicates that the target object data required by the object access request is object data that cannot carry an attack script. For instance, assuming that an attack script is generally carried through a PDF document, it indicates that the target object required by the object access request is object data other than PDF document data. In this case, the server can, according to the conventional object access request, obtain the target object data based on this address identification information (i.e., the actual storage address) and directly return it to the process.
[0120] Correspondingly, since the browser does not receive the forced download instruction, the browser can still directly open the target object data.
[0121] As can be seen from the above, the server processes the actual storage address of the object data with the risk of script attack as encrypted encrypted address information, and at the same time, sets the actual storage address of the object data as a prohibited access address. On this basis, for the target object data with the risk of script attack, users cannot directly access the target object data using the actual storage address, so as to reduce the situation where the attack script carried in the target object data is run after obtaining the object data through polling and other methods and then illegally obtaining the target object data through the browser.
[0122] Moreover, even if the prohibited access mechanism for the actual storage address fails, since the actual storage address of the data object with the risk of script attack in this case is not publicly disclosed, the object access request can only be initiated using the encrypted address information of the target object data, which can further reduce the risk of script attack that may be brought about by the failure of the prohibited access mechanism for the actual storage address.
[0123] Next, the access request processing device provided in the embodiments of the present application will be introduced. The access request processing device described below can be correspondingly referred to the above access request processing method.
[0124] Such as Figure 4 , which shows a schematic structural diagram of a composition of the access request processing device in the present application. The device may include:
[0125] A request obtaining unit 401, configured to obtain an object access request sent by a browser, where the object access request includes address identification information for indicating target object data to be requested;
[0126] A data determination unit 402, configured to obtain the target object data based on the address identification information;
[0127] An information sending unit 403, configured to send the target object data and a forced download instruction to the browser when determining that the target object data belongs to object data with a risk of script attack. The forced download instruction is used to instruct the browser to save the target object data to a target storage area of the terminal where the browser is located, so that the user can use an application other than the browser to display the target object data stored in the target storage area, and the target storage area does not belong to the storage area corresponding to the browser.
[0128] In a possible implementation, the information sending unit may include at least one of the following:
[0129] A first information sending unit, configured to determine that the target object data belongs to object data with a risk of script attack and send the target object data and a forced download instruction to the browser when the address identification information belongs to a set data address with a risk of script attack;
[0130] A second information sending unit, configured to determine that the target object data belongs to object data with a risk of script attack and send the target object data and a forced download instruction to the browser if the target object data belongs to object data of a target type, where the object data of the target type is set object data that can carry an attack script.
[0131] In a possible implementation, the data determination unit includes:
[0132] An address processing unit, configured to determine the actual storage address of the target object data based on the encrypted address information if the address identification information is encrypted encrypted address information;
[0133] A data acquisition unit, configured to obtain the target object data based on the actual storage address;
[0134] The second information sending unit includes:
[0135] A second information sending subunit, configured to determine that the target object data belongs to object data with a risk of script attack and send the target object data and a forced download instruction to the browser if the address identification information belongs to encrypted address information.
[0136] In another possible implementation, the address processing unit includes:
[0137] An address decryption subunit, configured to decrypt the encrypted address information to obtain actual identification information included in the encrypted address information, where the actual identification information is used to uniquely identify the actual storage address of the target object data;
[0138] An address determination subunit, configured to determine an actual storage address of the target object data based on the actual identification information.
[0139] In another possible implementation, the apparatus further includes:
[0140] A prohibited access unit, configured to, if the address identification information does not belong to encrypted address information and the address identification information belongs to a calibrated prohibited access address, not respond to the object access request, where the fact that the address identification information belongs to a prohibited access address indicates that the object data pointed to by the address identification information is object data capable of carrying an attack script.
[0141] In another possible implementation, the apparatus further includes:
[0142] A data acquisition unit, configured to acquire target object data sent by a user terminal before the request acquisition unit acquires an object access request sent by a browser;
[0143] A storage processing unit, configured to, if the target object data belongs to object data with a script attack risk, store the target object data and set the target object data as object data that needs to be forced to be downloaded.
[0144] In another possible implementation, the storage processing unit includes:
[0145] A data storage unit, configured to, if the target object data belongs to object data with a script attack risk, store the target object data and determine the address identification information of the target object data;
[0146] An address setting unit, configured to set the address identification information of the target object data as a data address with a script attack risk.
[0147] In another possible implementation, when determining the address identification information of the target object data, the data storage unit is specifically configured to determine the actual storage address of the target object data;
[0148] The address setting unit includes:
[0149] An address encryption unit, configured to construct encrypted address information based on the actual storage address of the target object data, where the encrypted address information is used to indicate that the target object data belongs to object data with a script attack risk.
[0150] In another possible implementation, the address setting unit further includes:
[0151] An address disabling setting unit is configured to store the actual storage address of the target object data into a prohibited access directory, and the prohibited access directory is used to store storage addresses that are prohibited from direct access.
[0152] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the embodiments can be referred to each other. At the same time, the features described in each embodiment of this specification can be replaced or combined with each other, enabling those skilled in the art to implement or use this application. For device-type embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.
[0153] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0154] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0155] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A method for processing access requests, characterized in that, Including: Obtaining an object access request sent by a browser, where the object access request includes address identification information for indicating target object data to be requested; Obtaining the target object data based on the address identification information; When it is determined that the target object data belongs to object data with a risk of script attack, sending the target object data and a forced download instruction to the browser, where the forced download instruction is used to instruct the browser to save the target object data to a target storage area of the terminal where the browser is located, so that the user can use an application other than the browser to display the target object data stored in the target storage area, and the target storage area does not belong to the storage area corresponding to the browser; 2. The method according to claim 1, wherein The determination that the target object data belongs to object data with a risk of script attack includes at least one of the following: If the address identification information belongs to a set data address with a risk of script attack, determining that the target object data belongs to object data with a risk of script attack; If the target object data belongs to object data of a target type, determining that the target object data belongs to object data with a risk of script attack, where the object data of the target type is set object data that can carry an attack script; 3. The method according to claim 2, wherein The obtaining the target object data based on the address identification information includes: If the address identification information is encrypted address information, determining the actual storage address of the target object data based on the encrypted address information; Obtaining the target object data based on the actual storage address; The determination that if the address identification information belongs to a set data address with a risk of script attack, the target object data belongs to object data with a risk of script attack includes: If the address identification information belongs to encrypted address information, determining that the target object data belongs to object data with a risk of script attack; 4. The method according to claim 3, characterized in that, Further including: If the address identification information does not belong to encrypted address information and the address identification information belongs to a calibrated prohibited access address, then not responding to the object access request, where the address identification information belonging to the prohibited access address indicates that the object data pointed to by the address identification information is object data that can carry an attack script; 5. The method according to claim 3, characterized in that, The determination of the actual storage address of the target object data based on the encrypted address information includes: Decrypting the encrypted address information to obtain actual identification information included in the encrypted address information, where the actual identification information is used to uniquely identify the actual storage address of the target object data; Determining the actual storage address of the target object data based on the actual identification information; 6. The method according to claim 1, wherein Before obtaining the object access request sent by the browser, further including: Obtaining target object data sent by a user terminal; If the target object data belongs to object data with a risk of script attack, storing the target object data and setting the target object data as object data that needs to be forced to download; 7. The method according to claim 6, wherein The setting the target object data as object data that needs to be forced to download includes: Determining the address identification information of the target object data; Set the address identification information of the target object data as a data address with script attack risk.
8. The method according to claim 7, wherein The determination of the address identification information of the target object data includes: Determine the actual storage address of the target object data; The setting of the address identification information of the target object data as a data address with script attack risk includes: Based on the actual storage address of the target object data, construct encrypted address information, where the encrypted address information is used to indicate that the target object data belongs to object data with script attack risk.
9. The method according to claim 8, wherein The setting of the address identification information of the target object data as a data address with script attack risk further includes: Store the actual storage address of the target object data into a prohibited access directory, and the prohibited access directory is used to store storage addresses that are prohibited from direct access.
10. An access request processing device, characterized in that, Includes: A request acquisition unit, configured to acquire an object access request sent by a browser, where the object access request includes address identification information for indicating target object data to be requested; A data determination unit, configured to acquire the target object data based on the address identification information; An information sending unit, configured to, when it is determined that the target object data belongs to object data with script attack risk, send the target object data and a forced download instruction to the browser, where the forced download instruction is used to instruct the browser to save the target object data to a target storage area of the terminal where the browser is located, so that a user can use an application other than the browser to display the target object data stored in the target storage area, and the target storage area does not belong to the storage area corresponding to the browser.
Citation Information
Patent Citations
Method and device for achieving safe access of video websites
CN103268442A
Browser security processing method and device, computer equipment and storage medium
CN113709154A