Abnormality processing method and device, electronic equipment and storage medium

By detecting abnormal behavior in cloud storage services, identifying target objects and implementing processing permissions, we solve the resource waste and information security problems of malicious users in cloud storage services, and achieve timely and accurate identification and processing of abnormal behavior.

CN119670074BActive Publication Date: 2025-10-10BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411865080.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-10-10
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

In cloud storage services, malicious users may exploit resources, causing waste and information security issues. Existing technologies make it difficult to identify and handle abnormal behavior in a timely and accurate manner.

Method used

By detecting whether the traffic meets the predetermined abnormal conditions, the target object (resource or address) is determined, and the abnormality level is determined based on the number of visits and content, and corresponding processing permissions are implemented, such as disabling or prompting.

Benefits of technology

It achieves timely and accurate identification and processing of cloud resources and access addresses, reduces resource waste and information security risks, and improves the information security of the platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119670074B_ABST
    Figure CN119670074B_ABST
Patent Text Reader

Abstract

The present disclosure provides an exception processing method and device, electronic equipment and storage medium, relates to the technical field of data processing, and particularly relates to the technical field of big data, image processing, artificial intelligence and the like. The specific implementation scheme is as follows: in response to detecting that traffic meets a predetermined exception condition, at least one target object is determined from a plurality of objects according to a number of accesses associated with the objects; in response to detecting that the target object is a target resource that is accessed, an exception level of the target resource is determined according to at least one of content of the target resource and the number of accesses within a first predetermined time length; in response to detecting that the target object is a target address of a resource that is actively accessed, an exception level of the target address is determined according to at least one of a number of active accesses of the target address within a second predetermined time length and content of the resource that is actively accessed; and the target object is processed according to the exception level of the target object and a processing authority for the target object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data processing technology, in particular to technical fields such as big data, image processing, and artificial intelligence. More specifically, the present disclosure provides an exception handling method, device, electronic device, storage medium, and computer program product. Background Art

[0002] In actual applications, resources can be stored using cloud storage services, such as object storage services. Users can upload resources to the cloud or request access to cloud resources based on actual needs.

[0003] However, some users may use cloud storage services maliciously, such as using storage services as image hosting, maliciously increasing traffic, etc., which not only causes waste of resources but also easily leads to information security issues. Summary of the Invention

[0004] The present disclosure provides an exception handling method, apparatus, electronic device, storage medium, and computer program product.

[0005] According to one aspect of the present disclosure, there is provided an exception handling method, comprising: in response to detecting that traffic satisfies a predetermined exception condition, determining at least one target object from a plurality of objects based on the number of accesses associated with the object; in response to detecting that the target object is an accessed target resource, determining an abnormality level of the target resource based on the content of the target resource and at least one of the number of accesses within a first predetermined time period; in response to detecting that the target object is a target address for actively accessing a resource, determining an abnormality level of the target address based on at least one of the number of active accesses to the target address within a second predetermined time period and the content of the actively accessed resource; and processing the target object based on the abnormality level of the target object and the processing authority for the target object.

[0006] According to another aspect of the present disclosure, there is provided an exception handling device, comprising: an object determination module, a resource level determination module, an address level determination module, and a processing module. The object determination module is used to, in response to detecting that traffic meets a predetermined exception condition, determine at least one target object from a plurality of objects based on the number of accesses associated with the object. The resource level determination module is used to, in response to detecting that the target object is an accessed target resource, determine the exception level of the target resource based on at least one of the content of the target resource and the number of accesses within a first predetermined time period. The address level determination module is used to, in response to detecting that the target object is a target address that actively accesses a resource, determine the exception level of the target address based on at least one of the number of active accesses to the target address within a second predetermined time period and the content of the actively accessed resource. The processing module is used to process the target object based on the exception level of the target object and the processing authority for the target object.

[0007] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method provided by the present disclosure.

[0008] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to execute the method provided by the present disclosure.

[0009] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, which implements the method provided in the present disclosure when executed by a processor.

[0010] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.

[0012] Figure 1 Schematic diagram of an application scenario of the exception handling method and apparatus according to an embodiment of the present disclosure;

[0013] Figure 2 is a schematic flow chart of an exception handling method according to an embodiment of the present disclosure;

[0014] Figure 3 is a schematic diagram of an exception handling method according to an embodiment of the present disclosure;

[0015] Figure 4 is a schematic diagram of an exception handling method according to another embodiment of the present disclosure;

[0016] Figure 5 is a schematic structural block diagram of an exception handling device according to an embodiment of the present disclosure; and

[0017] Figure 6 It is a structural block diagram of an electronic device used to implement the exception handling method of an embodiment of the present disclosure. DETAILED DESCRIPTION

[0018] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0019] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0020] In the technical solution disclosed herein, the user's authorization or consent is obtained before obtaining or collecting the user's personal information.

[0021] In related technologies, the resource usage process involves operators, resource platforms, and users. Resource platforms can collaborate with operators and use the traffic provided by operators to support cloud storage services, enabling functions such as resource upload and download. Users can upload or download resources to the cloud based on their actual needs.

[0022] In practice, some users may maliciously exploit cloud storage services. For example, some users may upload resources containing inappropriate content or copyright-free resources, compromising the information security of the resource platform. Alternatively, some users may maliciously increase download traffic, impacting the resource platform and affecting other users. However, the resource platform cannot accurately detect any abnormalities in resources or users in a timely manner.

[0023] The embodiment of the present disclosure aims to provide an exception handling method, which, when detecting that the traffic meets a predetermined abnormal condition, will first determine at least one target object. The target objects are divided into two categories, one is the target resource stored in the cloud to be accessed, and the other is the target address that actively accesses the cloud resource. For the target resource, the abnormality level of the target resource is determined based on the content of the target resource and at least one of the number of times it is accessed within a first predetermined time period. For the target address, the abnormality level of the target address is determined based on the number of active accesses to the target address within a second predetermined time period and at least one of the content of the actively accessed resource. The target object is then processed based on the abnormality level of the target object and the processing authority for the target object. In this way, it is possible to promptly and accurately determine whether the resources in the cloud are abnormal, and whether the destination address for accessing the resource is abnormal, and to make processing based on the abnormal situation, so that the resource platform can perceive the abnormal situation in a timely and accurate manner.

[0024] The technical solutions provided by the present disclosure will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0025] Figure 1 Schematic diagram of an application scenario of the exception handling method and apparatus according to an embodiment of the present disclosure.

[0026] It should be noted that Figure 1 The examples shown are merely examples of system architectures to which the embodiments of the present disclosure may be applied, to help those skilled in the art understand the technical content of the present disclosure, but do not mean that the embodiments of the present disclosure may not be used in other devices, systems, environments or scenarios.

[0027] like Figure 1 As shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used as a medium for providing communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.

[0028] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Terminal devices 101, 102, and 103 can be various electronic devices with display screens and support web browsing, including but not limited to smartphones, tablet computers, laptop computers, and desktop computers, etc.

[0029] Server 105 may be a server that provides various services, such as a backend management server (for example only) that supports websites browsed by users using terminal devices 101, 102, and 103. The backend management server may analyze and process received data such as user requests, and provide feedback to the terminal device regarding the processing results (e.g., cloud resources obtained in response to user requests, or upload results fed back to the user based on the user's uploaded resources).

[0030] In actual applications, the resource platform can deploy cloud storage services through server 105 and provide users with resource upload and download services. Server 105 can also detect whether the cloud resources are abnormal, and detect whether the address of the resource access is abnormal, and take corresponding measures based on the abnormal situation.

[0031] It should be noted that the exception handling method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the exception handling device provided in the embodiment of the present disclosure can generally be set in the server 105. The exception handling method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the exception handling device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105.

[0032] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0033] Figure 2 is a schematic flowchart of an exception handling method according to an embodiment of the present disclosure.

[0034] like Figure 2 As shown, the exception handling method 200 may include operations S210 to S240.

[0035] In operation S210 , in response to detecting that traffic satisfies a predetermined abnormal condition, at least one target object is determined from a plurality of objects according to a number of access times associated with the object.

[0036] For example, whether the predetermined abnormal condition is met may be determined based on the rate of change of the flow rate, the amount of flow usage, etc. This embodiment does not limit the predetermined abnormal condition.

[0037] For example, an object may include an accessed resource, and the number of accesses associated with a resource may include the number of times the resource is accessed, or the number of times each resource is accessed by the address accessing the resource.

[0038] For example, an object may include an address (such as an IP address) that actively accesses cloud resources, and the number of accesses associated with the address may include the number of times the address accesses the resource, or the number of times the resource accessed by the address is accessed.

[0039] For example, an object whose access times exceed a threshold may be determined as a target object.

[0040] In operation S220 , in response to detecting that the target object is an accessed target resource, an abnormality level of the target resource is determined based on at least one of content of the target resource and a number of accesses within a first predetermined time period.

[0041] For example, when the target object is a target resource, it is possible to detect whether the content of the target resource stores any inappropriate content. The more inappropriate content is contained, the higher the abnormality level is.

[0042] For example, it is possible to detect whether the target resource's access frequency is significantly higher than that of other resources or higher than its own historical access frequency. The higher the access frequency, the higher the abnormality level.

[0043] In operation S230 , in response to detecting that the target object is a target address that actively accesses a resource, an abnormality level of the target address is determined based on at least one of the number of active accesses by the target address within a second predetermined time period and the content of the active access to the resource.

[0044] For example, when the target object is a target address, it is possible to detect whether the resources accessed by the target address contain inappropriate content. If the amount of inappropriate content is greater, the higher the abnormality level.

[0045] For example, it is possible to detect whether the number of active accesses to the target address is significantly higher than the access frequency of other addresses or higher than its own historical active access frequency. If the active access frequency is higher, the abnormality level is higher.

[0046] In operation S240 , the target object is processed according to the abnormality level of the target object and the processing authority for the target object.

[0047] For example, different prompts can be given according to the abnormality level, thereby prompting the resource platform that there is an abnormality in the target object and the resource platform can focus on the target object.

[0048] For example, the processing permission may include a disabling permission. If the target object is a target resource, access to the target resource may be prohibited if the disabling permission is granted. If the target object is a target address, access to cloud resources may be prohibited if the disabling permission is granted.

[0049] According to the exception handling method provided by the embodiment of the present disclosure, when it is detected that the traffic meets the predetermined abnormal conditions, at least one target object will be determined first. The target objects are divided into two categories, one is the target resource stored in the cloud to be accessed, and the other is the target address that actively accesses the cloud resource. For the target resource, the abnormality level of the target resource is determined based on the content of the target resource and at least one of the number of times it is accessed within the first predetermined time period. For the target address, the abnormality level of the target address is determined based on the number of active accesses to the target address within the second predetermined time period and at least one of the content of the actively accessed resource. The target object is then processed based on the abnormality level of the target object and the processing authority for the target object. In this way, it is possible to promptly and accurately determine whether the resources in the cloud are abnormal, and whether the target address of the accessed resource is abnormal, and to make processing based on the abnormal situation, so that the resource platform can perceive the abnormal situation in a timely and accurate manner.

[0050] Next, a process of determining whether the flow rate satisfies a predetermined abnormal condition will be described.

[0051] In this embodiment, a reference amount of traffic can be determined based on the traffic type. A rate of change in traffic can then be determined based on the reference amount and the actual traffic usage over a predetermined period of time. If the rate of change is greater than or equal to a rate of change threshold, the traffic can be determined to have met a predetermined abnormality condition.

[0052] For example, traffic categories may include intranet inflow, intranet outflow, extranet inflow, extranet outflow, cross-regional replication traffic, etc. The reference usage of each category of traffic can be pre-configured, or the reference usage can be calculated based on historical usage. For example, the usage of a certain category in the past period of time is counted, and the usage is adjusted proportionally based on the ratio between the period and the predetermined period. The adjusted usage can be used as the reference usage for the category. For example, the difference between the reference usage and the actual usage of the traffic in the predetermined period of time can be calculated, and the ratio between the difference and the actual usage can be used as the rate of change. If the rate of change is greater than the rate of change threshold, it means that the traffic usage of this category has changed significantly compared to the historical usage, which needs to attract the attention of the resource platform, so it is determined that the traffic meets the predetermined abnormal conditions.

[0053] In some embodiments, the same type of traffic can correspond to at least two metering modes, such as a total amount, a peak value, a fee, a bandwidth, etc., and accordingly, the reference usage includes at least two sub-reference usages corresponding to the at least two metering modes respectively, the actual usage includes at least two sub-usage corresponding to the at least two metering modes respectively, and the change rate includes at least two sub-change rates corresponding to the at least two metering modes respectively, which are determined according to the sub-reference usage and the sub-usage. In determining whether the traffic meets the predetermined abnormal condition, the traffic can be determined to meet the predetermined abnormal condition if any of the sub-change rates is greater than the corresponding sub-change rate threshold. For example, for the internal network inflow traffic, the total amount of the internal network inflow traffic can be counted, which is a sub-usage. A sub-change rate can be determined according to the total amount of the internal network inflow traffic and the sub-reference usage, and the internal network inflow traffic can be determined to meet the predetermined abnormal condition if the sub-change rate is greater than the corresponding total amount of the sub-change rate.

[0054] According to another embodiment of the present disclosure, the process of determining at least one target object from the plurality of objects according to the number of accesses associated with the objects can include: for a candidate resource in the plurality of objects, determining the candidate resource as a target resource in response to detecting that the number of times the candidate resource is accessed within a first predetermined time length is greater than or equal to a first threshold.

[0055] For example, the first predetermined time length can be 1 hour, 1 day, 1 week, etc., and the present embodiment does not limit the first predetermined time length. The candidate resource is frequently accessed within the first predetermined time length, which can be due to the resource containing abnormal content attracting bad users, or being used by some users to maliciously brush traffic, and the abnormality can be more easily located through the candidate resource. Therefore, the present embodiment determines the candidate resource with high access frequency as the target resource.

[0056] After determining the target resource, the abnormal level of the target resource can be determined in the following manner.

[0057] In an example, if the target object is the target resource accessed, and the content of the target resource contains abnormal content, the abnormal level of the target resource can be determined to be the first level. For example, at least one abnormality detection operator can be used to detect the content of the target resource to determine whether the target resource contains abnormal content, and the category of the abnormality includes, for example, image resources embedding videos, resources containing bad language, resources containing sensitive information, etc. If it is determined that the target resource contains abnormal content using the abnormality detection operator, it can be directly determined that the target resource has a high risk, and therefore the abnormal level is directly determined to be the first level. The abnormality detection operator can be implemented based on an artificial intelligence model, such as a classification model, and the present embodiment does not limit the abnormality detection operator.

[0058] In another example, if the target object is an accessed target resource, the target resource's content does not contain abnormal content, and the number of accesses within a first predetermined time period is greater than or equal to a first threshold and less than a second threshold, the target resource's abnormality level can be determined to be level two, where the first level is higher than the second level. For example, after using several anomaly detection operators to detect the target resource's content, no abnormalities are found in the target resource's content. At the same time, the target resource has been accessed a high number of times, but not exceptionally high. Therefore, the target resource's abnormality level can be determined to be level two.

[0059] In another example, if the target object is an accessed target resource, and the content of the target resource does not contain abnormal content, and the number of times it has been accessed within a first predetermined time period is greater than or equal to a second threshold, the abnormality level of the target resource can be determined to be level 1. For example, after using several anomaly detection operators to detect the content of the target resource, no abnormality is found in the content of the target resource. However, the number of times the target resource has been accessed is too high, and therefore, the target resource still has a great risk, and there is a possibility that the anomaly detection operator has missed detection or the anomaly detection coverage is incomplete. Therefore, the abnormality level of the target resource can be determined to be level 1.

[0060] According to another embodiment of the present disclosure, the above-mentioned process of determining at least one target object from multiple objects based on the number of accesses associated with the object may include: for a candidate address among the multiple objects, in response to detecting that the number of times the candidate address actively accesses resources within a second predetermined time period is greater than or equal to a third threshold, determining the candidate address as the target address.

[0061] For example, the second predetermined duration can be 1 hour, one day, one week, etc. This embodiment does not limit the second predetermined duration, and the second predetermined duration can be the same as or different from the first predetermined duration. In actual applications, regular users mostly browse resources in the cloud and rarely upload resources, that is, regular users mostly use downstream traffic and rarely use upstream traffic. However, some bad users (such as some malicious router vendors) need to upload resources to provide resources to other users. In order to circumvent the platform's detection, these users need to use a large amount of downstream traffic to control the ratio of upstream traffic to downstream traffic within a reasonable range. However, these bad users occupy a large amount of downstream traffic, which will affect the normal use of other users. Therefore, this embodiment determines the candidate address with a higher number of active resource accesses as the target address.

[0062] After the target object is determined, the abnormality level of the target object can be determined in the following manner.

[0063] In one example, if the target object is a target address that actively accesses a resource, and the resource being actively accessed contains abnormal content, the target address's abnormality level is determined to be Level 1. In this embodiment, if the target address has been actively accessed many times and the accessed resource also contains abnormal content, then the target address presents a high risk and can be directly determined to be Level 1.

[0064] In another example, if the target object is a target address that actively accesses a resource, and the resource actively accessed does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to the third threshold and less than the fourth threshold, the abnormality level of the target address is determined to be the second level. For example, although the resource accessed by the target object is a normal resource, and the number of active accesses of the target object is high, but not particularly high, the target object has the risk of malicious traffic brushing, but the confidence level of the risk is low, so the abnormality level of the target resource can be determined to be the second level.

[0065] In another example, if the target object is a target address that actively accesses a resource, the actively accessed resource does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to a fourth threshold, the abnormality level of the target address is determined to be level 1. For example, although the resource accessed by the target object is a normal resource, the number of active accesses by the target object is too high. Therefore, the target object is likely to be maliciously increasing traffic, and therefore the abnormality level of the target resource can be determined to be level 1.

[0066] In another example, a database may be pre-built, the database containing malicious addresses. If the target address matches the malicious address in the database, it may be determined that the abnormality level of the target address is the first level.

[0067] After determining the abnormality level of the target object, the target object can be processed according to the abnormality level and the processing authority for the target object.

[0068] In one example, if the exception level is level 1 and the processing permission includes disabling permissions, an alert message may be generated for the target object, and the target object's access status may be restricted. If the target object is a target resource, restricting the target object's access status may include restricting access to the target resource. If the target object is a target address, restricting the target object's access status may include restricting the target address's access to various cloud resources.

[0069] In another example, if the detected abnormality level is the second level and the processing permission includes disabling permission, a prompt message can be generated for the target object and the access status of the target object can be restricted. For example, the prompt intensity of the prompt message can be weaker than the prompt intensity of the alarm message. For example, the alarm can be issued by phone notification or by email notification.

[0070] In another example, if the abnormality level is the first level and the processing authority does not include the disable authority, an alarm message for the target object may be generated.

[0071] In another example, if the exception level is the second level and the processing authority does not include the disable authority, a prompt message for the target object may be generated.

[0072] Figure 3 It is a schematic diagram of the exception handling method according to an embodiment of the present disclosure.

[0073] In this embodiment, the exception handling method is executed by the exception handling service 320 deployed on the server side. First, authorization from the resource platform 310 and the user is obtained. After obtaining authorization, the user's traffic usage data on the resource platform 310 can be obtained, such as the peak value and total usage of each category of traffic used by the user. The peak value and total usage of each category of traffic for the entire resource platform 310 can also be obtained. It should be noted that the user is aware of and agrees to the acquisition and use of the user's information, and it complies with the provisions of relevant laws and regulations and does not violate public order and good morals.

[0074] After the exception handling service 320 obtains the traffic usage data of the resource platform 310 and the user, it can determine whether the traffic meets the predetermined exception conditions. If the predetermined exception conditions are not met, the processing can be terminated. If the predetermined exception conditions are met, a predetermined analysis process can be performed. The predetermined analysis process can first determine the target object of the exception and then determine the abnormality level of the target object. For example, the target object can be determined from multiple objects based on the number of accesses associated with the object. The target object includes a target resource and a target address. For the target resource, the abnormality level of the target resource can be determined based on the content of the target resource and at least one of the number of times it is accessed within a first predetermined time period. For the target address, the abnormality level of the target address can be determined based on at least one of the number of active accesses to the target address within a second predetermined time period and the content of the actively accessed resource.

[0075] Next, information can be generated to the staff of the resource platform 310 according to the abnormality level of the target object. For example, when the abnormality level is the first level, alarm information can be generated. When the abnormality level is the second level, prompt information can be generated. After receiving the alarm information, the staff of the resource platform 310 can handle the abnormality. After receiving the prompt information, the staff of the resource platform 310 can further check the target object to determine whether the abnormality really exists, and if so, handle the abnormality, otherwise, end the process.

[0076] Figure 4 is a schematic principle diagram of an abnormality processing method according to another embodiment of the present disclosure.

[0077] In this embodiment, the sub-change rate 410 of the flow under each metering mode can be obtained, and each metering mode includes, for example, metering based on total amount, metering based on bandwidth, metering based on fee, etc. Then, whether the predetermined abnormality condition is met is determined by each sub-change rate 410. For example, for a certain type of flow, the flow corresponds to at least two metering modes. Based on the metering mode of fee, it can be determined whether the sub-change rate of the flow is greater than a first predetermined sub-change rate. Based on the metering mode of total amount, it can be determined whether the sub-change rate of the flow is greater than a second predetermined sub-change rate. Based on the metering mode of bandwidth, it can be determined whether the sub-change rate of the flow is greater than a third predetermined sub-change rate. If any sub-change rate is greater than or equal to the corresponding sub-change rate threshold, it can be determined that the flow meets the predetermined abnormality condition.

[0078] If not, the sub-change rate 410 of the flow under each metering mode is re-determined. If so, the target object 420 can be determined, which includes a target resource 421 and a target address 422. For example, it can be determined whether the number of times a candidate resource is accessed within a first predetermined time period is greater than or equal to a first threshold, and if so, the candidate resource can be determined as the target resource 421. For another example, it can be determined whether the number of times a candidate address actively accesses a resource within a second predetermined time period is greater than or equal to a third threshold, and if so, the candidate address can be determined as the target address 422.

[0079] After obtaining the target resource 421 and the target address 422, the abnormality level 430 of the target resource 421 and the abnormality level 430 of the target address 422 can be determined, and according to the abnormality level 430, alarm information or prompt information 440 can be generated to alarm or prompt the resource platform.

[0080] Figure 5 is a schematic structural block diagram of an abnormality processing apparatus according to an embodiment of the present disclosure.

[0081] As Figure 5As shown, the exception handling device 500 may include an object determination module 510 , a resource level determination module 520 , an address level determination module 30 , and a processing module 540 .

[0082] The object determination module 510 is configured to determine at least one target object from a plurality of objects according to the number of accesses associated with the object in response to detecting that traffic meets a predetermined abnormal condition.

[0083] The resource level determination module 520 is configured to determine the abnormality level of the target resource according to at least one of the content of the target resource and the number of times the target resource has been accessed within a first predetermined period in response to detecting that the target object is an accessed target resource.

[0084] The address level determination module 530 is used to determine the abnormality level of the target address in response to detecting that the target object is a target address that actively accesses resources, based on at least one of the number of active accesses to the target address within a second predetermined time period and the content of the actively accessed resources.

[0085] The processing module 540 is used to process the target object according to the abnormality level of the target object and the processing authority for the target object.

[0086] According to another embodiment of the present disclosure, the apparatus further comprises: a reference usage determination module, a change rate determination module, and an anomaly determination module. The reference usage determination module is configured to determine a reference usage of the flow based on the type of flow. The change rate determination module is configured to determine a change rate of the flow based on the reference usage and actual flow usage over a predetermined period of time. The anomaly determination module is configured to determine that the flow meets a predetermined anomaly condition in response to detecting that the change rate is greater than or equal to a change rate threshold.

[0087] According to another embodiment of the present disclosure, the same category of traffic corresponds to at least two metering modes, the reference usage includes at least two sub-reference usages corresponding to the at least two metering modes respectively, the actual usage includes at least two sub-usages corresponding to the at least two metering modes respectively, the change rate includes at least two sub-change rates corresponding to the at least two metering modes respectively, and the sub-change rate is determined based on the sub-reference usage and the sub-usage; wherein, the abnormality determination module includes: an abnormality determination submodule, which is used to determine that the traffic meets a predetermined abnormal condition in response to detecting that any sub-change rate of the at least two sub-change rates is greater than or equal to the corresponding sub-change rate threshold.

[0088] According to another embodiment of the present disclosure, the object determination module includes: a resource determination submodule, which is used to determine the candidate resources among multiple objects as target resources in response to detecting that the number of times the candidate resources are accessed within a first predetermined time period is greater than or equal to a first threshold.

[0089] According to another embodiment of the present disclosure, the resource level determination module includes: a first determination submodule, a second determination submodule and a third determination submodule. The first determination submodule is used to determine that the abnormality level of the target resource is the second level in response to detecting that the target object is the target resource being accessed, and the content of the target resource does not contain abnormal content, and the number of times it is accessed within a first predetermined time period is greater than or equal to a first threshold and less than a second threshold. The second determination submodule is used to determine that the abnormality level of the target resource is the first level in response to detecting that the target object is the target resource being accessed, and the content of the target resource does not contain abnormal content, and the number of times it is accessed within a first predetermined time period is greater than or equal to a second threshold. The third determination submodule is used to determine that the abnormality level of the target resource is the first level in response to detecting that the target object is the target resource being accessed, and the content of the target resource contains abnormal content; wherein, the first level is higher than the second level.

[0090] According to another embodiment of the present disclosure, the object determination module includes: an address determination submodule, which is used to determine a candidate address among multiple objects as a target address in response to detecting that the number of times the candidate address actively accesses resources within a second predetermined time period is greater than or equal to a third threshold.

[0091] According to another embodiment of the present disclosure, the address level determination module includes: a fourth determination submodule, a fifth determination submodule and a sixth determination submodule. The fourth determination submodule is used to determine that the abnormality level of the target address is the second level in response to detecting that the target object is the target address for actively accessing resources, and the resources actively accessed do not contain abnormal content, and the number of times the resources are accessed within the second predetermined time period is greater than or equal to the third threshold and less than the fourth threshold. The fifth determination submodule is used to determine that the abnormality level of the target address is the first level in response to detecting that the target object is the target address for actively accessing resources, and the resources actively accessed do not contain abnormal content, and the number of times the resources are accessed within the second predetermined time period is greater than or equal to the fourth threshold. The sixth determination submodule is used to determine that the abnormality level of the target address is the first level in response to detecting that the target object is the target address for actively accessing resources, and the resources actively accessed contain abnormal content; wherein, the first level is higher than the second level.

[0092] According to another embodiment of the present disclosure, the processing module includes: a first processing sub-module, a second processing sub-module, a third processing sub-module and a fourth processing sub-module. The first processing sub-module is used to generate an alarm message for the target object and restrict the access status of the target object in response to detecting that the abnormality level is the first level and the processing authority includes the disabling authority. The second processing sub-module is used to generate a prompt message for the target object and restrict the access status of the target object in response to detecting that the abnormality level is the second level and the processing authority includes the disabling authority. The third processing sub-module is used to generate an alarm message for the target object in response to detecting that the abnormality level is the first level and the processing authority does not include the disabling authority. The fourth processing sub-module is used to generate a prompt message for the target object in response to detecting that the abnormality level is the second level and the processing authority does not include the disabling authority.

[0093] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, including at least one processor; and a memory communicatively connected to the at least one processor; the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned exception handling method.

[0094] According to an embodiment of the present disclosure, the present disclosure further provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute the above exception handling method.

[0095] According to an embodiment of the present disclosure, the present disclosure further provides a computer program product, including a computer program, which implements the above exception handling method when executed by a processor.

[0096] Figure 6 1 is a block diagram of an electronic device for implementing the exception handling method of an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0097] like Figure 6As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. Computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to bus 604.

[0098] Various components in device 600 are connected to I / O interface 605, including an input unit 606, such as a keyboard, mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, optical disk, etc.; and a communication unit 609, such as a network card, modem, wireless communication transceiver, etc. The communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0099] Computing unit 601 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 601 performs the various methods and processes described above, such as the exception handling method. For example, in some embodiments, the exception handling method may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed onto device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by computing unit 601, one or more steps of the exception handling method described above may be performed. Alternatively, in other embodiments, computing unit 601 may be configured to perform the exception handling method via any other suitable means (e.g., via firmware).

[0100] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-a-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0101] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0102] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0103] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0104] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0105] Computer systems may include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The client and server relationship arises through computer programs running on the respective computers and having a client-server relationship to each other.

[0106] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.

[0107] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. An exception handling method, comprising: In response to detecting that the traffic satisfies a predetermined abnormal condition, determining at least one target object from the plurality of objects based on a number of access times associated with the object; In response to detecting that the target object is an accessed target resource, determining an abnormality level of the target resource according to at least one of content of the target resource and a number of accesses within a first predetermined time period; In response to detecting that the target object is a target address that actively accesses a resource, determining an abnormality level of the target address based on at least one of a number of active accesses by the target address within a second predetermined time period and content of the actively accessed resource; as well as The target object is processed according to the abnormality level of the target object and the processing authority for the target object.

2. The method according to claim 1, further comprising: Determining a reference amount of the flow according to the type of the flow; determining a rate of change of the flow rate according to the reference usage and an actual usage of the flow rate over a predetermined period of time; as well as In response to detecting that the change rate is greater than or equal to a change rate threshold, it is determined that the flow rate meets a predetermined abnormal condition.

3. The method according to claim 2, wherein: The flow rate of the same category corresponds to at least two metering modes, the reference usage includes at least two sub-reference usages corresponding to the at least two metering modes respectively, the actual usage includes at least two sub-usages corresponding to the at least two metering modes respectively, and the change rate includes at least two sub-change rates corresponding to the at least two metering modes respectively, and the sub-change rate is determined based on the sub-reference usage and the sub-usage; In response to detecting that the change rate is greater than or equal to a change rate threshold, determining that the flow rate meets a predetermined abnormal condition includes: In response to detecting that any one of the at least two sub-change rates is greater than or equal to a corresponding sub-change rate threshold, it is determined that the flow rate meets the predetermined abnormal condition.

4. The method according to claim 1, wherein Determining at least one target object from a plurality of objects according to the number of accesses associated with the object includes: For a candidate resource among the multiple objects, in response to detecting that the number of times the candidate resource is accessed within the first predetermined time period is greater than or equal to a first threshold, the candidate resource is determined as the target resource.

5. The method according to claim 4, wherein In response to detecting that the target object is an accessed target resource, determining the abnormality level of the target resource according to at least one of content of the target resource and a number of accesses within a first predetermined period of time includes: In response to detecting that the target object is the target resource being accessed and that the content of the target resource contains abnormal content, determining that the abnormality level of the target resource is a first level; In response to detecting that the target object is the target resource being accessed, the content of the target resource does not contain abnormal content, and the number of times the target resource has been accessed within the first predetermined time period is greater than or equal to the first threshold and less than a second threshold, determining that the abnormality level of the target resource is the second level; and In response to detecting that the target object is the target resource being accessed, the content of the target resource does not contain abnormal content, and the number of times the target resource has been accessed within the first predetermined period is greater than or equal to the second threshold, determining that the abnormality level of the target resource is the first level; The first level is higher than the second level.

6. The method according to claim 1, wherein Determining at least one target object from a plurality of objects according to the number of accesses associated with the object includes: For a candidate address among the multiple objects, in response to detecting that the number of times the candidate address actively accesses resources within the second predetermined period is greater than or equal to a third threshold, the candidate address is determined as the target address.

7. The method according to claim 6, wherein: In response to detecting that the target object is a target address for actively accessing a resource, determining the abnormality level of the target address according to at least one of the number of active accesses by the target address within a second predetermined time period and the content of the actively accessed resource includes: In response to detecting that the target object is the target address of an active access resource, and the actively accessed resource contains abnormal content, determining that the abnormality level of the target address is a first level; In response to detecting that the target object is the target address of an active resource access, the actively accessed resource does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to the third threshold and less than a fourth threshold, determining that the abnormality level of the target address is the second level; In response to detecting that the target object is the target address for actively accessing a resource, the actively accessed resource does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to the fourth threshold, determining that the abnormality level of the target address is the first level; and The first level is higher than the second level.

8. The method according to claim 5 or 7, wherein: The processing of the target object according to the abnormality level of the target object and the processing authority for the target object includes: In response to detecting that the abnormality level is the first level and the processing authority includes a disable authority, generating an alarm message for the target object and restricting an access status of the target object; In response to detecting that the abnormality level is the second level and the processing authority includes the disable authority, generating prompt information for the target object and restricting the access status of the target object; In response to detecting that the abnormality level is the first level and the processing authority does not include the disabling authority, generating warning information for the target object; and In response to detecting that the abnormality level is the second level and the processing authority does not include the disabling authority, prompt information for the target object is generated.

9. An exception handling device, comprising: an object determination module, configured to determine, in response to detecting that traffic meets a predetermined abnormal condition, at least one target object from a plurality of objects based on a number of access times associated with the object; a resource level determination module, configured to, in response to detecting that the target object is an accessed target resource, determine an abnormality level of the target resource based on at least one of content of the target resource and a number of accesses within a first predetermined time period; an address level determination module for, in response to detecting that the target object is a target address for actively accessing a resource, determining an abnormality level of the target address based on at least one of a number of active accesses by the target address within a second predetermined time period and a content of the actively accessed resource; as well as A processing module is used to process the target object according to the abnormality level of the target object and the processing authority for the target object.

10. The apparatus according to claim 9, further comprising: A reference usage determination module, configured to determine a reference usage of the flow according to the type of the flow; a change rate determination module, configured to determine a change rate of the flow rate based on the reference usage and an actual usage of the flow rate over a predetermined period of time; as well as The abnormality determination module is configured to determine that the flow rate meets a predetermined abnormality condition in response to detecting that the change rate is greater than or equal to a change rate threshold.

11. The device according to claim 10, wherein The flow rate of the same category corresponds to at least two metering modes, the reference usage includes at least two sub-reference usages corresponding to the at least two metering modes respectively, the actual usage includes at least two sub-usages corresponding to the at least two metering modes respectively, and the change rate includes at least two sub-change rates corresponding to the at least two metering modes respectively, and the sub-change rate is determined based on the sub-reference usage and the sub-usage; The abnormality determination module includes: The abnormality determination submodule is configured to determine that the flow rate satisfies the predetermined abnormality condition in response to detecting that any one of the at least two sub-change rates is greater than or equal to a corresponding sub-change rate threshold.

12. The device according to claim 9, wherein The object determination module includes: The resource determination submodule is configured to determine, for a candidate resource among the multiple objects, in response to detecting that the number of times the candidate resource is accessed within the first predetermined time period is greater than or equal to a first threshold, the candidate resource as the target resource.

13. The device according to claim 12, wherein The resource level determination module includes: a first determining submodule, configured to, in response to detecting that the target object is a target resource being accessed and that the content of the target resource contains abnormal content, determine that the abnormality level of the target resource is a first level; a second determining submodule, configured to, in response to detecting that the target object is an accessed target resource, the content of the target resource does not contain abnormal content, and the number of times the target resource has been accessed within the first predetermined time period is greater than or equal to the first threshold and less than a second threshold, determine that the abnormality level of the target resource is a second level; and a third determining submodule, configured to, in response to detecting that the target object is an accessed target resource, the content of the target resource does not contain abnormal content, and the number of times the target resource has been accessed within the first predetermined time period is greater than or equal to a second threshold, determine that the abnormality level of the target resource is a first level; The first level is higher than the second level.

14. The device according to claim 9, wherein The object determination module includes: The address determination submodule is configured to determine, for a candidate address among the multiple objects, the target address in response to detecting that the number of times the candidate address actively accesses resources within the second predetermined time period is greater than or equal to a third threshold.

15. The device according to claim 14, wherein The address level determination module includes: a fourth determining submodule, configured to, in response to detecting that the target object is a target address for actively accessing a resource, and the actively accessed resource contains abnormal content, determine that the abnormality level of the target address is a first level; a fifth determining submodule, configured to, in response to detecting that the target object is a target address for actively accessing a resource, the actively accessed resource does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to the third threshold and less than a fourth threshold, determine that the abnormality level of the target address is a second level; a sixth determining submodule, configured to, in response to detecting that the target object is a target address for actively accessing a resource, the actively accessed resource does not contain abnormal content, and the number of resource accesses within the second predetermined time period is greater than or equal to the fourth threshold, determine that the abnormality level of the target address is the first level; and The first level is higher than the second level.

16. The device according to claim 13 or 15, wherein The processing module includes: a first processing submodule, configured to, in response to detecting that the abnormality level is the first level and the processing authority includes a disable authority, generate an alarm message for the target object and restrict an access status of the target object; a second processing submodule, configured to, in response to detecting that the abnormality level is the second level and the processing authority includes the disabling authority, generate prompt information for the target object and restrict access status of the target object; a third processing submodule, configured to generate warning information for the target object in response to detecting that the abnormality level is the first level and the processing authority does not include the disabling authority; and The fourth processing submodule is configured to generate prompt information for the target object in response to detecting that the abnormality level is the second level and the processing authority does not include the disabling authority.

17. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

18. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 8.

19. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Access request processing method and device

    CN110417778A

  • Access control method and device, electronic equipment and storage medium

    CN117221019A