跨站脚本攻击的防御方法、装置、电子设备、介质

By combining server-side and client-side defense mechanisms, utilizing keyword recognition models and user behavior analysis, and dynamically adjusting verification rules, the problem of insufficient XSS defense capabilities in existing technologies is solved, achieving more efficient and accurate cross-site scripting attack defense, and ensuring user security and system performance.

CN119728262BActive Publication Date: 2026-07-17INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2024-12-25
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies struggle to defend against new attack variants and dynamic attack patterns when defending against cross-site scripting (XSS) attacks. They lack dynamic behavior analysis, resulting in insufficient system security and accuracy. Furthermore, full interception increases computational resource consumption.

Method used

By receiving user input data on the server side, the system dynamically adjusts the verification rules using keyword recognition models and user behavior analysis. It combines data vectorization, word segmentation, and Long Short-Term Memory (LSTM) network models to identify and filter potential attacks, implement data desensitization and encrypted storage, and verify resource loading rules on the client side.

Benefits of technology

It improves the adaptability of the defense system, reduces false positives and false blocking, increases the utilization of computing resources, protects user information security, and enhances the access experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728262B_ABST
    Figure CN119728262B_ABST
Patent Text Reader

Abstract

本公开提供了一种跨站脚本攻击的防御方法,可以应用于大数据技术领域和人工智能技术领域。该方法包括:接收用户输入的代码或文本数据,对所述代码或文本数据中的关键字进行识别,获得关键字识别结果;分析用户的输入特征和行为模式,基于所述关键字识别结果和分析结果动态调整预设的校验匹配条件;以及根据调整后的校验匹配条件,对所述代码或文本数据进行防御处理,输出处理后的安全数据。
Need to check novelty before this filing date? Find Prior Art