A site-wide isolation method

By implementing a site-wide isolation method in browsers and edge gateways, the source code of sensitive resources is hidden, solving the problem that browsers cannot automatically fulfill security requirements, improving user experience and data security, and reducing the complexity of security operations.

CN119814365BActive Publication Date: 2025-10-31CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411773102.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2025-10-31
Estimated Expiration
2044-12-04

AI Technical Summary

Technical Problem

In existing technologies, browsers cannot automatically meet users' security needs, leading to frequent web attacks such as SQL injection, XSS, and CSRF, which threaten user data security and website service stability.

Method used

By implementing a site-wide isolation method in the browser and edge gateway, a resource request to obtain the target page is sent to the edge gateway. The isolation framework is received and run to hide the source code of sensitive resources. The isolation framework is used to set up a protective barrier to prevent attackers from directly obtaining and using these resources.

Benefits of technology

It effectively hides the source code of sensitive resources, reduces page loading delays caused by security attacks, improves user experience, reduces the complexity and cost of security operations, and enables timely detection and response to potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814365B_ABST
    Figure CN119814365B_ABST
Patent Text Reader

Abstract

This disclosure provides a site-wide isolation method designed to address the issue of target browsers failing to meet security requirements. The method includes: sending a first request to an edge gateway to retrieve a first resource of a target page; receiving an isolation framework transmitted by the edge gateway, wherein the isolation framework is sent by the edge gateway when the first resource of the target page meets isolation conditions; and using the isolation framework to hide the source code of sensitive resources of the target page; wherein the sensitive resources are characterized as resources that could lead to site vulnerabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of content delivery network technology, and in particular to a site-wide isolation method. Background Technology

[0002] Content Delivery Network (CDN) acceleration is now widely used by major websites, effectively solving the problem of user experience being affected by large geographical distances due to global user base expansion. By deploying nodes globally, content can be retrieved from the nearest server, significantly reducing latency. However, with the rapid development of internet technology, websites face increasingly complex and diverse threats, including frequent occurrences of web attacks such as SQL injection, XSS (Cross-Site Scripting), and CSRF (Cross-Site Request Forgery), posing a serious threat to user data security and website service stability.

[0003] However, current browsers cannot automatically meet users' aforementioned security needs. Without security strategies and technical support, accelerated websites will face potential security vulnerabilities, business logic attacks, data breaches, and compliance issues. Summary of the Invention

[0004] To overcome the problems existing in related technologies, this disclosure provides a site-wide isolation method. The technical solution of this disclosure is as follows:

[0005] According to a first aspect of the present disclosure, a site-wide isolation method is provided, applied to a browser, comprising:

[0006] Send a first request to the edge gateway to retrieve the first resource of the target page;

[0007] Receive the isolation framework transmitted by the edge gateway, the isolation framework being sent by the edge gateway when the first resource of the target page meets the isolation conditions;

[0008] The isolation framework is used to hide the source code of sensitive resources on the target page; the sensitive resources are characterized as resources that could lead to vulnerabilities in the site.

[0009] According to a second aspect of the present disclosure, a site-wide isolation method is provided, applied to an edge gateway, comprising:

[0010] Receive the first retrieval request sent by the browser to obtain the first resource of the target page;

[0011] Based on the first acquisition request, obtain the first resource of the target page from the backend;

[0012] Determine whether the first resource of the target page meets the isolation conditions;

[0013] If the first resource of the target page meets the isolation conditions, the sending of the first resource of the target page to the browser is cancelled, and an isolation frame is returned to the browser; so that the browser hides the source code of the sensitive resources of the target page.

[0014] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, it implements the steps of the full-site isolation method as described in the first aspect, or the steps of the full-site isolation method as described in the second aspect.

[0015] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, wherein when the computer program is executed by a processor, it implements the steps of the full-site isolation method as described in the first aspect, or the steps of the full-site isolation method as described in the second aspect.

[0016] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the full-site isolation method as described in the first aspect, or the steps of the full-site isolation method as described in the second aspect.

[0017] This disclosure implements a site-wide isolation method within the browser, proactively hiding the source code of sensitive resources on a target page. This source code hiding creates a protective barrier for these sensitive resources, making it difficult for attackers to directly access and exploit them. While this disclosure does not directly accelerate page loading, it indirectly improves user experience by reducing page loading delays caused by security attacks. Unified management and monitoring of the isolation framework's operation allow for timely detection and response to potential security threats, reducing security operation complexity and manpower costs. Attached Figure Description

[0018] Figure 1 This is a schematic diagram illustrating the steps of a site-wide isolation method according to an embodiment of this disclosure;

[0019] Figure 2 This is a schematic diagram of the code for a target page that has not been completely isolated, as shown in an embodiment of this disclosure;

[0020] Figure 3This is a schematic diagram of the code for a target page that performs site-wide isolation, as shown in an embodiment of this disclosure;

[0021] Figure 4 This is a schematic diagram illustrating the display code of an isolated target file according to an embodiment of this disclosure;

[0022] Figure 5 This is a schematic diagram illustrating the display code of an isolated target third resource according to an embodiment of this disclosure;

[0023] Figure 6 This is a schematic diagram illustrating the steps of another site-wide isolation method shown in an embodiment of this disclosure;

[0024] Figure 7 This is a schematic diagram illustrating a response to a fifth acquisition request, as shown in an embodiment of this disclosure;

[0025] Figure 8 This is a schematic diagram illustrating a complete site isolation process according to an embodiment of this disclosure;

[0026] Figure 9 This is a schematic diagram of an isolation framework processing flow shown in an embodiment of the present disclosure;

[0027] Figure 10 This is a schematic diagram of an electronic device shown in an embodiment of this disclosure. Detailed Implementation

[0028] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0029] The terms "first," "second," etc., used in this disclosure and in the claims are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this disclosure can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0030] To facilitate understanding, the technical terms used in this disclosure will be explained first.

[0031] CDN (Content Delivery Network Acceleration): An internet service designed to accelerate the delivery of website content or other internet services through a globally distributed network of servers.

[0032] WS (WebSocket): The WebSocket protocol is a network protocol that provides low-latency, full-duplex communication between clients and servers.

[0033] JavaScript (JS) is a widely used programming language, especially in the development of web pages and web applications. JavaScript was originally designed as a client-side scripting language for implementing dynamic web pages and user-interactive functionality in a browser.

[0034] XSS is a common cybersecurity vulnerability that allows attackers to inject and execute malicious script code into users' browsers on a target website.

[0035] CSRF is a type of cyberattack that uses a user's credentials (such as cookies or sessions) already logged into another website to trick the user into performing malicious actions pre-set by the attacker without their knowledge.

[0036] SQL injection is a network security attack technique in which attackers insert malicious SQL code into web forms, URL parameters, or other user input fields to trick database servers into executing unauthorized queries or operations.

[0037] With the rapid development of Internet technology, websites face increasingly complex and diverse threats, including frequent web attack methods such as SQL injection, XSS, and CSRF, which pose a serious threat to user data security and the stability of website services.

[0038] To protect sensitive data and business logic, and to reduce the possibility of site vulnerabilities, this disclosure proposes a site-wide isolation method that enhances user security.

[0039] Figure 1 This is a schematic diagram illustrating the steps of a site-wide isolation method according to an embodiment of this disclosure, the method being applied to a browser. According to... Figure 1 Specifically, this may include the following steps:

[0040] Step S11: Send a first request to the edge gateway to obtain the first resource of the target page.

[0041] A browser is an application that users use on computers or mobile devices to access and display internet content. An edge gateway is a network node located between the user and the origin server, typically used in content delivery networks. Its main function is to cache and distribute content to improve access speed and reduce latency.

[0042] The first resource can be an HTML file. The first resource of the target page can be represented as an index.HTML file. The index.HTML file is the entry point of the website or webpage and is used as the homepage or default page.

[0043] The first request can be a GET request, where the browser sends a GET request to index.HTML to the edge gateway to retrieve the target page.

[0044] Step S12: Receive the isolation framework transmitted by the edge gateway, which is sent by the edge gateway when the first resource of the target page meets the isolation conditions.

[0045] Normally, after a browser sends a first request to retrieve the first resource of a target page, it can obtain the target page through the edge gateway.

[0046] However, in this embodiment, if the first resource of the target page meets the isolation conditions, the edge gateway will not send the first resource of the target page to the browser, but will instead send the isolation framework to the browser.

[0047] Isolation conditions can be confirmed at the domain level, directory level, or URL level, thereby achieving site-wide isolation at the domain level, directory level, or URL level.

[0048] Step S13: The source code of sensitive resources of the target page is hidden through the isolation framework; the sensitive resources are characterized as resources that could lead to vulnerability attacks on the site.

[0049] An isolation framework can be an isolation business script. Running this isolation business script enables site-wide isolation functionality.

[0050] The first resource can include a second and a third resource. The second resource can be CSS (Cascading Style Sheets) code, and the third resource can be JavaScript code. JavaScript technology has become standard and is easily exploited by malware attacks.

[0051] By running isolated business scripts, the source code of sensitive resources on the target page, such as JavaScript code, can be hidden.

[0052] Figure 2 This is a code diagram illustrating a target page that has not undergone full site isolation, as shown in an embodiment of this disclosure. According to... Figure 2 As shown, when a website enables CDN acceleration but does not implement site-wide isolation, when a browser accesses the origin server's HTML page, it can right-click and select "View Page Source" to obtain the specific element composition of the webpage, including JavaScript code that may expose sensitive business processing logic. Attackers can analyze the JavaScript code in the primary resource to understand the backend interface calling methods, verification logic, etc., and then potentially use this information to attempt SQL injection, XSS cross-site scripting attacks, CSRF cross-site request forgery, etc., to maliciously manipulate the website or steal data. They can even use the exposed JavaScript code to conduct business logic penetration attacks and steal confidential information.

[0053] However, after hiding the source code of sensitive resources in the first resource, attackers can no longer use the source code of sensitive resources to attack the website. (Reference) Figure 3 As shown, Figure 3 This is a code diagram illustrating a target page for site-wide isolation, as shown in an embodiment of this disclosure. When site-wide isolation is enabled, browser access to and from the target page is restricted. Figure 2 After clicking "View Page Source" on the same HTML page, a fixed embedded bundle.js tag is returned, completely hiding the original page's element composition.

[0054] This embodiment, by overlaying CDN acceleration with site-wide isolation technology, makes the accelerated website's source code invisible, thus proactively hiding the website's attack surface. Site-wide isolation technology implements appropriate technical measures to ensure data security and privacy. By isolating sensitive code, the potential attack surface is limited; even if a part is compromised, it will not immediately affect the entire website or expose core data. The site-wide isolation method provides a centralized security management strategy. Website administrators only need to configure and manage the isolation framework to achieve security protection for the entire website, without needing to configure security settings for each page or resource individually, simplifying the complexity and workload of security management.

[0055] In one optional embodiment, receiving the isolation framework transmitted by the edge gateway includes: receiving an isolation first resource of the isolation framework sent by the edge gateway; the isolation first resource carrying an isolation service script link; automatically loading the isolation first resource and sending a second acquisition request to the edge gateway to acquire the isolation framework according to the isolation service script link; and receiving the isolation framework transmitted by the edge gateway.

[0056] The isolation framework is not sent to the browser all at once.

[0057] After the browser sends a first request to the edge gateway to retrieve the first resource of the target page, if the edge gateway determines that the first resource of the target page meets the isolation conditions, it cancels the original response to the browser. That is, instead of sending the first resource of the target page to the browser, it sends the isolated first resource of the isolation framework. The isolated first resource of the isolation framework is a fixed HTML page containing only JS tags. Each JS tag is actually a link to an isolated business script, pointing to one or more isolated business scripts that need to be loaded and executed.

[0058] After receiving this first isolated resource, the browser will automatically parse and execute the JavaScript tags within it, thus loading the isolated business script pointed to by the isolated business script link. This means that the browser will send a second retrieval request to the edge gateway based on the URL in the JavaScript tags to obtain the actual isolated business script.

[0059] After receiving the second request, the edge gateway sends the corresponding isolation business script to the browser. The isolation business script contains all the necessary logic and code to implement the site-wide isolation function.

[0060] The browser ultimately obtains the complete isolation framework by receiving the first isolated resource and the subsequent isolated business scripts.

[0061] In this embodiment, the isolated first resource contains only JavaScript tags. Upon receiving this resource, the browser automatically parses and executes the JavaScript tags, thereby loading the isolated business script. This dynamic loading mechanism allows the browser to load and execute necessary scripts as needed, avoiding resource waste. The introduction of isolated business script links makes the updating and maintenance of the isolation framework more flexible and convenient. When adding new features or fixing security vulnerabilities, only the isolated business script needs to be updated, without modifying the isolated first resource. This design improves the system's scalability and maintainability. As a fixed HTML page containing only JavaScript tags, the isolated first resource is relatively small in size, easy to transmit and load quickly, helping to reduce browser rendering time and user waiting time, thus improving the user experience.

[0062] In one optional embodiment, hiding the source code of sensitive resources of the target page through the isolation framework includes: sending a third acquisition request to the edge gateway through the isolation framework, the third acquisition request being used to acquire the header tag content of the access origin domain; receiving the header tag content sent by the edge gateway for accessing the origin domain; sending a fourth acquisition request carrying the header tag content to the edge gateway through the isolation framework, the fourth acquisition request being used to acquire the target page; receiving a first resource of the target page sent by the edge gateway, and determining a target second resource and a target third resource that need to be isolated in the first resource; hiding the target second resource and the target third resource through the isolation framework; wherein, the target second resource is a second resource located on the same site as the first resource and is externally referenced, the second resource being used to implement the layout style of the target page; the target third resource is a third resource located on the same site as the first resource; the third resource is used to implement the business logic of the target page.

[0063] After obtaining the isolation framework, the browser runs the isolation framework and sends a third retrieval request to the edge gateway. The third retrieval request is used by the browser to obtain the header tag content required to return the origin server domain name.

[0064] The third retrieval request can be an empty request. An empty request does not carry any specific data or parameters; it is only intended to trigger a response, allowing the edge gateway to return some necessary information, without needing to transmit specific resources or data. After receiving the third retrieval request, the edge gateway will process it according to preset logic or rules, and can determine which header information needs to be returned based on the source of the request.

[0065] In one specific implementation of a third-party retrieval request, the browser can initiate a third-party retrieval request to the edge gateway's HTTP interface / obfuscate / req_init, thereby receiving the header tag content for accessing the origin server's domain name.

[0066] After receiving the header tag content for accessing the origin server domain, the browser continues to run the isolation framework and sends a fourth fetch request carrying the header tag content. This fourth fetch request is used to retrieve the first resource of the target page. The first resource retrieved by the fourth fetch request is the original response that the edge gateway rejected during the first fetch request.

[0067] Specifically, a WebSocket connection can be established to the gateway WS service. In this case, the fourth request can be understood as a WS protocol request. A WebSocket connection is a protocol for establishing persistent, bidirectional communication between a client and a server, allowing bidirectional data transmission over a single connection. Once a WebSocket connection is established, both parties can send and receive messages at any time during the connection period without needing to re-establish the connection. Compared to traditional HTTP requests, WebSocket reduces the repeated connection establishment and closing processes, thus saving network bandwidth and server resources. Furthermore, transmission via WebSocket is more secure than traditional HTTP requests.

[0068] Through the fourth retrieval request, the browser receives the first resource of the target page. This first resource is the original resource before isolation, existing as a string. It needs to be parsed and transformed into an object that the browser can understand and manipulate. Specifically, after obtaining the original index.html resource before isolation, the browser performs DOMParser parsing and stores it as a DOM object.

[0069] After parsing the first resource, sensitive resources that need to be hidden within the original first resource are identified. These sensitive resources include target second resources and target third resources. The target second resource is a second resource located on the same site as the first resource and referenced externally. This second resource is used to implement the layout style of the target page and can be a CSS resource. The target third resource is a third resource located on the same site as the first resource. This third resource is used to implement the business logic of the target page and can be a JS resource. The target second resource only includes CSS resources referenced externally from this site; embedded CSS resources in the first resource are not considered for hiding. The target third resource includes all JS resources from this site within the first resource. This is because JavaScript code typically contains business logic-related content, and if this content is attacked, it can cause significant losses to the customer. Therefore, both externally referenced and internally referenced JS resources are sensitive resources that need to be hidden.

[0070] The target second and third resources can be identified through the tags included in the first resource. In specific implementations, after parsing the original first resource, the browser can recognize the various tags included in the target page's first resource. This can be done through tags with specific formats, such as... <link stylesheet href="”xxx”"> It can identify target secondary resources. It can also identify target tertiary resources through tags with specific formats, such as script tags.

[0071] After identifying the target second and third resources, an isolation framework is used to hide them. Hiding the target second and third resources means hiding their respective source code. This prevents issues such as abnormal page display, user data leakage, or business logic being compromised due to the leakage or modification of sensitive information or business logic contained in CSS and JS resources.

[0072] This embodiment effectively prevents malicious users or attackers from directly accessing or tampering with sensitive resources of the target page by hiding them through an isolation framework. By identifying and hiding secondary and tertiary resources related to the target page, attackers can be prevented from reverse engineering and understanding the application's internal workings, thereby protecting core business logic and sensitive operations. Hiding the target page's layout style and business logic resources prevents the leakage of sensitive data and implementation details, protecting user privacy and corporate trade secrets, and ensuring compliance.

[0073] In one optional embodiment, hiding the target second resource through the isolation framework includes: determining a first target link of the target second resource; sending a fifth acquisition request to the edge gateway to acquire the target second resource based on the first target link of the target second resource; receiving the original second resource corresponding to the target second resource sent by the edge gateway; inserting the original second resource into the first resource in a target format; and deleting the target second resource from the first resource.

[0074] If a target secondary resource is identified, a fifth acquisition request is initiated for each target secondary resource. This fifth acquisition request can establish a WebSocket connection with the edge gateway's WS service. For example, if there are ten target secondary resources, then there should be ten WebSocket connections with the edge gateway's WS service, one for each target secondary resource. Creating a separate WebSocket connection with the edge gateway for each target secondary resource means that the request and response for each resource are independent. This allows for encryption and control of each target secondary resource during transmission, thereby enhancing security.

[0075] After sending the fifth retrieval request to the edge gateway, the corresponding original second file is obtained through the edge gateway.

[0076] For example, a target second resource is identified in the first resource by a tag, and the target second resource is identified in the first resource in the following way:

[0077] <link rel="stylesheet" href="https: / / obfuscate.test1.com / styles1.css">

[0078] A fifth acquisition request is initiated for the target second resource, and the original second resource of the target second resource is obtained through the edge gateway.

[0079] The original secondary resource can be the following code:

[0080] / * styles1.css * /

[0081] .yellow-background {

[0082] background-color: yellow;

[0083] }

[0084] After obtaining the original second resource, the corresponding target second resource is deleted from the first resource, and the original second resource is inserted into the first resource as a stylesheet. This ensures that the original second resource in the first resource performs the same function as the target second resource. This avoids the browser directly loading the original target second resource, which could lead to attacks, and only loads the processed original second resource, thus strengthening network security control. Specifically, the front-end removes the reference to the CSS resource from the DOM structure and inserts the original CSS resource as a stylesheet at the end of index.html. For example, upon identifying the target second resource, a fifth retrieval request is initiated to obtain the corresponding original second resource. After obtaining the original second resource, the target second resource is deleted from the first resource, and the original second resource is inserted into the first resource in the target format.

[0085] By filtering out all target second resources and processing them individually, this embodiment effectively controls which styles are loaded, preventing malicious or unnecessary externally referenced second resources from being directly introduced and reducing potential security risks. After obtaining the original second resources, deleting the target second resources from the first resource avoids direct loading of the target second resources by the browser, reducing the attack surface. Inserting the original second resources corresponding to the target second resources into the first resource in the target format ensures consistent style application across all second resources in the first resource and avoids style conflicts caused by improper stylesheet loading order.

[0086] In one optional embodiment, the target third resource includes external third resources and internal third resources. Hiding the target third resources through the isolation framework includes: identifying each target third resource in the first resource to obtain a target array; adding the content corresponding to the internal third resource to the text content at the corresponding index of the array; determining a second target link corresponding to the external third resource; sending a fifth acquisition request to the edge gateway to acquire the external third resource based on the second target link of the external third resource; receiving the original third resource corresponding to the external third resource sent by the edge gateway; adding the content corresponding to the original third resource to the text content at the corresponding index of the target array; concatenating the text content included in the target array according to the index order to obtain concatenated text, and deleting the target third resource from the first resource. The concatenated text is used to: achieve the same function as the target third resource by calling a target function.

[0087] Within the first resource, targeting the specific tag, all third-party resources are filtered out. All third-party resources included in the first resource are considered as target third-party resources to be isolated. Third-party resources are represented in a fixed format within the first resource. These third-party resources can be JavaScript resources. Since JavaScript resources involve the target page's business logic, any attack on a JavaScript resource can lead to significant losses for the client; therefore, all JavaScript resources are considered target third-party resources to be isolated.

[0088] Based on the referencing relationship, target third-party resources are divided into external third-party resources and internal third-party resources. External third-party resources are JS resources referenced by external files, while internal third-party resources are JS resources referenced inline.

[0089] The difference between JS resources referenced by external files and those referenced inline lies in their loading method and location.

[0090] JS resources referenced by external files refer to those accessed through... <script>标签的src属性引入的JavaScript文件。这些文件通常存储在服务器上,并通过URL进行访问。

[0091] 以下是一种外部文件引用的JS资源在第一资源中的表现形式:

[0092] <script src="https: / / example.com / script.js">< / script>

[0093] Inline-referenced JavaScript resources refer to JavaScript code embedded directly within the HTML document, rather than being included as an external file via the src attribute. This type of code is typically placed in... <script>标签之间。

[0094] 以下是一种内联引用的JS资源在第一资源中的表现形式:

[0095] <script>

[0096] console.log("This is an inline script.");

[0097] < / script>

[0098] A target array is created based on the third resources, and each identified target third resource is added as an element to the target array. The number of array elements in the target array is the same as the number of target third resources, and an association is established between each array element and each third resource. The association between array elements and target third resources is 1:1. The association can be established by the index of each array element and the identification order of each target third resource. For example, if there is an array element 1 in the target array, its value should be [0], indicating that array element 1 is the first array element in the target array. In the first resource, the execution order of the third resources is used as the identification order of the third resources. The first target third resource is identified, so an association is established between array element 1 and the target third resource.

[0099] Each element of the target array has the same target structure, which includes at least text content and download status. The text content stores the content of the target third-party resource associated with that array element, and the download status indicates whether the content of the target third-party resource has been successfully downloaded.

[0100] An array is a front-end concept; it's an ordered collection of data of the same type, where elements can be accessed using numbers as indices. Arrays can be used to store and manipulate data. Array indices are integers, typically starting from 0 and incrementing sequentially. Each element in the array can be accessed and modified using its corresponding index.

[0101] After classifying the target third resources into external and internal third resources, different methods are used to isolate the third resources in each category.

[0102] For internal third-party resources, directly add the content corresponding to the internal third-party resource to the text content at the corresponding index in the target array.

[0103] For external third-party resources, after obtaining the corresponding original third-party resource, the original third-party resource needs to be added to the text content at the corresponding index of the target array.

[0104] To obtain the original third-party resource corresponding to the external third-party resource, a fifth retrieval request can be initiated by the browser to the edge gateway. This fifth retrieval request can involve establishing a WebSocket connection with the edge gateway's WS service. A corresponding fifth retrieval request is initiated for each external third-party resource.

[0105] Through each fifth acquisition request, the original third-party resource corresponding to the external third-party resource is obtained. The content of the original third-party resource is added to the text content at the corresponding index of the external third-party resource in the target array. The original third-party resource sent by the edge gateway is encrypted. First, the data sent by the edge gateway needs to be decrypted to obtain the unencrypted original third-party resource, and then the unencrypted original third-party resource is added to the text content at the corresponding index in the target array.

[0106] After the text content corresponding to each array element of the target array is added, the download status of that array element will be changed to "complete". With the download status of each array element in the target array complete, the text content corresponding to each array element can be concatenated in index order using an isolation frame to obtain the concatenated text, and then each target third resource can be deleted from the first resource.

[0107] The concatenated text includes the isolated content corresponding to all third resources in the first resource, and the concatenated text can achieve the same functionality as the target third resource by calling the target function. The target function can be eval().

[0108] By using this embodiment, obtaining concatenated text that achieves the same function as the target third-party resource and then deleting the target third-party resource can hide the target third-party resource. By hiding the original code of the target third-party resource, the risk of malicious attackers directly accessing and exploiting this code is reduced. Integrating the target third-party resources into a target array and concatenating them according to index order can avoid errors in the target page due to execution order.

[0109] Whether it's a fifth retrieval request initiated for the target second resource or a fifth retrieval request initiated for an external third resource, the browser sends them uniformly after determining that a re-retrieval is needed. After receiving the response data corresponding to each fifth retrieval request, the browser caches the response data. Only after receiving the response data corresponding to all fifth retrieval requests will the browser decrypt the content of the original resource included in each response data. Then, after decrypting the original second resource and the original third resource, the browser appends them to the first resource according to their respective operations.

[0110] All fifth retrieval requests can use the same format. The following is a convention for sending fifth retrieval requests:

[0111] {

[0112] "taskId": "1",

[0113] "type": "html|js|css",

[0114] "needFetch": "true", #Whether to download

[0115] "src": "http: / / www.test.com / index.html", #URI encoding

[0116] "text": "",

[0117] "headers": {

[0118] "cookie": "xxxx",

[0119] "refer": "xxxx"

[0120] },

[0121] "endFlag" : "false|true"

[0122] }

[0123] Here, `taskId` represents a unique identifier for the request, used to distinguish different request tasks; `type` represents the file type requested, which can be HTML, JavaScript (JS), or CSS; `needFetch` is a boolean value indicating whether the resource needs to be downloaded, with `true` indicating download is required and `false` indicating it is not required; `src` represents the URL address of the requested resource, using URI encoding format, specifically, it can be the first target link of a target second resource or the second target link corresponding to an external third resource; `text` represents the content of the returned file, which is an empty string here, indicating that the content has not yet been received; `headers` represents the request header information; `cookie` represents cookie information used for authentication or session management; `refer` represents the reference address of the request source, which can be used to track the source; `endFlag` is a boolean value indicating whether the resource has been sent completely, with `true` indicating completion and `false` indicating incompleteness.

[0124] For example, a target second resource on a target page is rendered in the first resource using the following code:

[0125] <link rel="stylesheet" href="https: / / obfuscate.test1.com / styles1.css">

[0126] The format of the fifth request for the second resource targeting this objective can be presented using the following code:

[0127] {

[0128] "taskId": "1",

[0129] "type": "css",

[0130] "needFetch": "true", #Whether to download

[0131] "src": "https: / / obfuscate.test1.com / styles1.css",#URI encoding

[0132] "text": "",

[0133] "headers": {

[0134] "cookie": "xxxx",

[0135] "refer": "xxxx"

[0136] },

[0137] "endFlag" : "false|true"

[0138] }

[0139] A browser's fifth fetch request may not necessarily retrieve the original second or third resource. Retrieval of the original second and third resources may fail. In some cases, the browser may receive an error field from the edge gateway for a fifth fetch request. Upon receiving this error field, the browser knows that the fifth fetch request failed to retrieve the resource and will close the fifth fetch request to prevent it from consuming resources.

[0140] If the fifth fetch request is used to retrieve the original third-party resource corresponding to the target third-party resource, and this fifth fetch request receives an error field sent by the edge gateway, then the browser will not only close the fifth fetch request but also process the target array. The browser determines which target third-party resource the fifth fetch request was based on, finds the index of the target third-party resource in the target array, sets the text content value corresponding to that index to null, and changes the download status to complete. Changing the download status to complete prevents the browser from initiating a fifth fetch request for that target third-party resource and ensures the smooth concatenation of the subsequent text content.

[0141] Figure 4 This is a schematic diagram illustrating the display code of an isolated target file according to an embodiment of this disclosure. According to... Figure 4 As shown, the CSS resource identified as the second target resource is inserted at the end of the first resource. JS resources not belonging to this site are not hidden, while JS resources belonging to this site are all hidden. (See reference) Figure 5 As shown, Figure 5 This is a schematic diagram illustrating the display code of an isolated target third resource according to an embodiment of this disclosure. Figure 5 middle <script scr="” / obfuscate / bundle.js”">就是对各个目标第三资源隐藏后的结果。

[0142] 基于同样的技术构思,本公开提出的全站隔离方法还可以应用于边缘网关。

[0143] 图6是本公开实施例示出的另一种全站隔离方法的步骤示意图,所述方法应用于边缘网关。按照图6所示,具体可以包括如下步骤:

[0144] 步骤S61:接收浏览器发送的用于获取目标页面的第一资源的第一获取请求。

[0145] 边缘网关监听并接收来自浏览器的HTTP或HTTPS请求。接收到一个用于获取目标页面第一资源的第一获取请求,第一获取请求可以包括URL、请求方法(如GET)、请求头信息。

[0146] 步骤S62:根据所述第一获取请求,从后端获取所述目标页面的第一资源。

[0147] 边缘网关解析第一获取请求,提取出目标页面的URL、请求的资源类型等。根据解析后的请求信息,边缘网关向后端服务器发送请求,以获取目标页面的第一资源。后端服务器处理该请求,并返回相应的资源数据给边缘网关。

[0148] 步骤S63:判断所述目标页面的第一资源是否符合隔离条件。

[0149] 边缘网关从后端获取到第一资源后,对第一资源进行分析,确定第一资源是否符合隔离条件。可以通过第一资源所属的站点信息判断所属第一资源是否符合隔离条件。

[0150] 步骤S64:在所述目标页面的第一资源符合隔离条件的情况下,取消将所述目标页面的第一资源发送给所述浏览器,并向所述浏览器返回隔离框架;以使所述浏览器对所述目标页面的敏感资源的源代码进行隐藏。

[0151] 如果目标页面的第一资源符合隔离条件,即被认为是敏感资源,则边缘网关准备一个隔离框架。边缘网关不直接将敏感资源发送给浏览器,而是将准备好的隔离框架返回给浏览器。

[0152] 隔离框架可以是一个特殊的HTML页面或容器。本公开实施例中,隔离框架是一个隔离业务脚本,浏览器通过运行该隔离业务脚本,实现隔离功能。具体可以按照预定的逻辑加载和处理敏感资源,同时确保这些资源的源代码不会被直接显示或访问。

[0153] 采用本实施例,通过判断目标页面的第一资源是否符合隔离条件,能够针对性地降低数据泄露的风险。隔离框架的引入使得浏览器无法直接访问原始页面的HTML、CSS和JavaScript代码,从而保护了网站的核心业务逻辑,防止被恶意用户利用。用户在查看网页源代码时,看到的是经过处理的内容,而不是原始的敏感源代码。这种隐蔽性使得攻击者更难以进行有效的攻击。

[0154] 其中,在一种可选的实施例中,在所述目标页面的第一资源符合隔离条件的情况下,取消将所述目标页面的第一资源发送给所述浏览器,并向所述浏览器返回隔离框架,包括:向所述浏览器发送隔离框架的隔离第一资源;所述隔离第一资源携带隔离业务脚本链接;接收所述浏览器发送的用于获取隔离业务脚本的第二获取请求;根据所述第二获取请求,向所述浏览器发送所述隔离业务脚本;以使所述浏览器接收所述隔离框架。

[0155] 边缘网关并不是一次性将隔离框架发送给浏览器,首先在取消将目标页面的第一资源发送给浏览器后,会将一个携带隔离业务脚本链接的隔离第一资源发送给浏览器。隔离第一资源是固定的,只要一个页面的第一资源被判断为符合隔离条件,都会拒绝响应这个页面的第一资源,而是发送一个固定的隔离资源给请求该页面的浏览器。

[0156] 浏览器收到隔离第一资源后,基于隔离业务脚本链接会自动发起第二获取请求,边缘网关在接收到第二获取请求后,将隔离框架送给浏览器。隔离框架可以是隔离业务脚本。

[0157] 采用本实施例,隔离框架提供了一个安全的中间层,用于处理和隔离敏感资源,减少了浏览器直接暴露于潜在风险中的可能性。通过调整隔离条件和隔离框架的实现方式,可以灵活地适应不同的安全需求和业务场景,易于在不同的Web应用和浏览器环境中实现和扩展。

[0158] 其中,在一种可选的实施例中,判断所述目标页面的第一资源是否符合隔离条件,包括:确定所述第一资源是否属于需要进行全站隔离的站点;在所述第一资源属于需要进行全站隔离的站点的情况下,确定所述第一资源符合隔离条件;在所述第一资源不属于需要进行全站隔离的站点的情况下,确定所述第一资源不符合隔离条件。

[0159] 本公开支持根据不同的层级和范围来实施隔离策略。具体可以包括:域名粒度、目录粒度、具体URL粒度。

[0160] 按域名粒度,意味着可以针对整个域名进行隔离处理。例如,如果一个网站有多个子域名(如 www.example.com 和 api.example.com),可以设置隔离策略,使得所有来自某个特定域名的请求都受到相同的隔离措施。按域名粒度适用于需要对整个域名下的资源进行统一管理和保护的场景。

[0161] 按目录粒度,允许用户根据特定目录来实施隔离。例如,一个网站可能有多个目录(如 / user、 / admin、 / public),可以对某个特定目录下的资源进行隔离处理。这样,只有特定目录下的资源会受到隔离措施,而其他目录的资源则可以按照不同的策略处理。按目录粒度适合于需要对网站不同部分进行差异化保护的场景。

[0162] 具体URL粒度,可以针对特定的URL进行隔离处理,可以提供了更细致的控制。例如,可以为某个特定的API接口(如 / api / v1 / getUser)设置隔离策略,而对其他URL不进行隔离。具体URL粒度适用于需要对特定功能或资源进行重点保护的场景。

[0163] 边缘网关在接收到目标页面的第一资源后,判断所述第一资源是否属于需要进行全站隔离的站点。站点可以是域名、目录、具体url等。一个站点需要进行全站隔离表示该站点开启了全站隔离功能。

[0164] 具体可以分析所述第一资源所属的域名、目录、具体url等层级信息;在第一资源所属的任意一个或多个层级开启了全站隔离功能后,边缘网关即判断该第一资源符合全站隔离条件。

[0165] 采用本实施例,通过判断目标页面的第一资源是否符合隔离条件,能够有效识别出可能存在的安全风险。通过对第一资源的判断和隔离,可以实现对资源的灵活管理,基于不同的场景,可以采取不同的判断策略,确保网站在提供功能的同时,最大程度地保护用户数据和业务逻辑。

[0166] 其中,在一种可选的实施例中,还包括:接收所述浏览器发送的第三获取请求;根据所述第三获取请求,获取用于访问源站域名的头标签内容,并将所述头标签内容发送给所述浏览器;接收所述浏览器发送的携带所述头标签内容的第四获取请求;根据所述第四获取请求,从后端获取所述目标页面的第一资源;将所述目标页面的第一资源发送给所述浏览器。

[0167] 浏览器在接收到隔离框架,并通过隔离框架隐藏敏感资源的源代码的过程中,会自动执行隔离框架。

[0168] 浏览器会通过隔离框架发送第三获取请求,第三获取请求是一个空请求,边缘网关可以通过一个特定的接口接收到第三获取请求。

[0169] 通过第三获取请求,边缘网关会获取访问源站所需的头标签内容。在边缘网关成功获取到所需的头标签内容后,将这些信息作为响应返回给浏览器。可以确保浏览器在后续请求中能够携带正确的头标签内容,从而使边缘网关顺利访问源站。

[0170] 浏览器接收到边缘网关返回的头标签内容后,会继续运行隔离框架,发送携带头标签内容的第四获取请求,第四获取请求用于重新获取目标文件的第一资源。第四获取请求是通过WS协议请求到边缘网关。

[0171] 边缘网关接收到第四获取请求后,通过HTTP协议转发请求到后端,从后端获取目标页面的第一资源。HTTP协议是Web通信的标准协议,使用HTTP转发请求可以确保与后端系统的兼容性。

[0172] 边缘网关从后端获取到目标页面的第一资源后,将该第一资源发送给浏览器。

[0173] 采用本实施例,通过接收浏览器发送的第三获取请求,系统能够动态获取用于访问源站域名的头标签内容。接收浏览器发送的第四获取请求后,系统能够根据请求从后端获取目标页面的第一资源。这种机制确保了浏览器能够快速、准确地获取所需的资源。

[0174] 其中,在一种可选的实施例中,还包括:接收所述浏览器发送的用于获取原始资源的第五获取请求;所述原始资源包括原始第二资源和原始第三资源;根据所述第五获取请求,从后端获取所述原始资源;确定所述原始资源的大小;在所述原始资源大于第一阈值的情况下,将所述原始资源以分片的形式发送给所述浏览器,以使所述浏览器根据所述原始资源,对所述目标页面的敏感资源的源代码进行隐藏。

[0175] 浏览器会持续运行隔离脚本,在需要获取原始资源的时候,会向边缘网关继续发起第五获取请求。原始资源包括原始第二资源和原始第三资源。

[0176] 针对任意第五获取请求,以相同的响应格式向浏览器发送响应数据。以下是边缘网关响应数据对应的响应格式:

[0177] {

[0178] "taskId": "1",

[0179] "type": "html|js|cs",

[0180] "needFetch": "true",

[0181] "src": "http: / / a.com / aaa / index.html",#uri编码

[0182] "text": "2388234235", #经过十六进制编码

[0183] "endFlag": "false|true",

[0184] "headers": {

[0185] "Content-Type": "xxxx",

[0186] "Content-Encoding": "xxxx"

[0187] },

[0188] "err": {#err字段只在失败时出现

[0189] "code": "xxx",

[0190] "msg": "xxx"

[0191] }

[0192] }

[0193] 其中,taskId请求的唯一标识符,根据对应的第五获取请求的标识符确定;type表示请求的文件类型,可以是HTML、JavaScript或CSS;needFetch是一个布尔值,表示是否需要下载该资源,true表示需要,false表示不需要;src表示请求的资源的URL地址,使用URI编码格式;text表示对第五获取请求返回的文件内容,是一个经过十六进制编码处理后的字符串;endFlag是一个布尔值,表示资源是否已经发送完毕,true表示完成,false表示未完成;headers表示响应数据对应的头标签内容;err表示错误信息字段,仅在请求失败时出现;err包括的code表示错误代码,用于标识错误类型;err包括的msg表示错误信息的描述。

[0194] 可以通过边缘网关的缓存区的大小确定第一阈值的大小。具体可以是边缘网关的proxy_buffer_size对应的大小。proxy_buffer_size定义了边缘网关用于缓存来自后端服务器响应的单个缓冲区的大小。

[0195] 如果一个第五获取请求对应的原始资源大于第一阈值,那么对该第五获取请求对应的原始资源进行分片,使得每一个分片都不大于第一阈值。在一种具体的实施中,边缘网关的缓存区为4kb,从后端获取一个大小为10kb的原始资源,那么该原始资源基于缓存区的大小会被分为三个分片,每个分片不超过4kb。

[0196] 对每一个分片使用一个响应数据发送给浏览器,各个响应数据使用的都是相同的响应格式。也就是说一个第五获取请求可以对应一个或多个响应数据。如果一个原始资源是以分片的形式进行响应,在最后一个分片的响应数据中添加完成标识,例如将endFlag的值修改为true,表示该原始资源已经获取完成,如果一个原始资源不需要分片,那么直接在该原始资源对应的响应数据中添加完成标识。

[0197] 边缘网关在将获取到的原始资源通过响应数据发送给浏览器前,需要对从后端获取到的原始资源进行加密,将加密后的原始资源通过响应数据发送给浏览器。在原始资源大于第一阈值的情况下,分别对原始资源对应的各个分片进行加密,在原始资源不大于第一阈值的情况下,直接对原始资源进行加密。但由于加密操作,会导致数据量的增加,因此加密后的分片或加密后的不大于第一阈值的原始资源的体积会超过第一阈值。如此,浏览器基于响应数据接收到的加密后的分片或原始资源的体积同样也会大于第一阈值。例如,一个4k的原始资源的分片,在经过加密后,由于加密操作,该分片的体积会增加到20-22kb,浏览器接收到的就是该体积增加到20-22kb的分片,在经过解密后,才会获得原始的4kb的分片。

[0198] 在某些情况,边缘网关无法从后端获取到原始资源,在无法获取到原始资源的情况下,确定该原始资源对应的第五获取请求,在第五获取请求对应的响应数据中添加错误字段,以使浏览器能够接收到错误字段,从而关闭第五获取请求。

[0199] 采用本实施例,在确定原始资源的大小后,如果该资源大于第一阈值,系统将其以分片的形式发送给浏览器。这种分片传输方式可以有效降低单次传输的数据量,减少网络带宽的压力,提高传输效率。在分片传输过程中,如果某个片段传输失败,系统可以只重传失败的部分,而不是重新传输整个资源,这样可以提高系统的容错能力,减少不必要的网络资源浪费。

[0200] 参考图7所示,图7是本公开实施例示出的一种对第五获取请求进行响应的示意图。图7中一个ws_service表示一个第五获取请求,一个Binary Message表示一个响应数据,是一个原始数据或一个原始数据的分片。多个Binary Message可能是同一个第五获取请求的响应数据。

[0201] 图8是本公开实施例示出的一种全站隔离整体流程的示意图。按照图8所示,浏览器一共会发送五次请求。按照请求的顺序,对图8包括的内容进行解释:

[0202] 第一次请求的时候,浏览器向边缘网关发起第一获取请求,第一获取请求可以是GET / index.html,边缘网关基于浏览器的GET / index.html,转发第一获取请求,边缘网关向后端发起GET / index.html,后端向边缘网关响应index.html,向边缘网关发送目标页面的第一资源,目标页面的第一资源可以是index.html,边缘网关接收到index.html后,判断index.html是否符合隔离条件,在index.html符合隔离条件的情况下,拦截原始响应,即index.html,向浏览器返回一个固定隔离第一资源,隔离第一资源可以是隔离框架的html文件。

[0203] 第二次请求的时候,浏览器接收到隔离第一资源后,识别到隔离第一资源携带一个隔离业务脚本链接,隔离业务脚本链接可以是一个JS资源链接,自动加载隔离业务脚本链接。通过隔离业务脚本链接向边缘网关发起第二获取请求,第二获取请求用于获取隔离框架,边缘网关接收到第二获取请求后,直接将隔离框架发送给浏览器。

[0204] 第三次请求的时候,浏览器接收到隔离框架后,运行隔离框架,自动向边缘网关发起第三获取请求,第三获取请求可以是GET / obf / req_init,第三获取请求是一个空请求,只是用于边缘网关识别第三获取请求中访问源站所需的头标签内容,并将识别到的头标签内容返回给浏览器。

[0205] 第四次请求的时候,浏览器继续运行隔离框架,携带第三次请求的时候获取到的头标签内容,自动向边缘网关发起第四获取请求,第四获取请求用于获取目标页面的第一资源,第四获取请求可以是一种WS协议请求,可以表现为ws / wss: / index.html,边缘网关接收到第四获取请求后,将第四获取请求转发到本地http服务,向后端发起协议http请求,协议http请求可以是GET / index.html,后端接收到GET / index.html后,后端向边缘网关响应目标页面的第一资源,目标页面的第一资源可以是index.html,边缘网关接收到index.html后将其发送给浏览器。

[0206] 第五次请求的时候,浏览器接收到目标页面的第一资源后,隔离框架对第一资源进行解析,对第一资源包括的目标第二资源和外部第三资源向边缘网关并发第五获取请求,边缘网关接收到这些第五获取请求后,将所有第五获取请求转发到本地http服务,通过协议http请求分别向后端获取对应的原始资源,原始资源包括CSS资源和JS资源,后端接收到边缘网关发起的协议http请求后,向边缘网关返回原始资源,边缘网关随后再将原始资源发送给浏览器;浏览器端的隔离框架在所有第五获取请求都完成原始资源获取后,再对缓存的原始资源进行处理,并对目标页面进行渲染。

[0207] 图9是本公开实施例示出的一种隔离框架处理流程示意图。按照图9所示,

[0208] 对隔离前的第一资源进行解析;

[0209] 确定第一资源中是否包括目标第二资源;在包括目标第二资源的情况下,针对任意目标第二资源向边缘网关发起第五获取请求,并删除第一资源中的目标第二资源;判断是否完整获取目标第二资源对应的原始第二资源;在完整获取的情况下,将原始第二资源以目标格式添加到第一资源中;在不完整获取的情况下,结束对该目标第二资源的处理;在不包含目标第二资源的情况下,结束对目标第二资源的处理。

[0210] 为目标第三资源生成目标数组,目标数组用于按照各个目标第三资源的识别顺序对各个目标第三资源进行存放;确定第一资源中是否包括外部第三资源;在包括外部第三资源的情况下,针对每一个外部第三资源向边缘网关发起第五获取请求;判断第五获取请求是否完整获取外部第三资源对应的原始第三资源;在完整获取的情况下,将原始第三资源的内容添加到目标数组对应索引的文本内容中,并删除第一资源中对应的目标第三资源;在没有完整获取的情况下,将目标数组对应索引的文本内容置空,并结束对该外部第三资源的处理;在不包括外部第三资源的情况下,继续判断第一资源是否包括内部第三资源;在包括内部第三资源的情况下,将内部第三资源对应的内容添加到目标数组对应索引的文本内容中,并删除第一资源中对应的目标第三资源;按顺序将目标数组包括的各个文本内容进行拼接,得到拼接文本;基于拼接文本调用目标函数执行目标第三资源的功能;在不包含内部第三资源的情况下,取消对目标第三资源的处理。

[0211] 针对本公开提出的全站隔离方法,提出一种具体的实施例。该实施例的步骤如下所示:

[0212] 首先为具体实施例设置前置条件,前置条件如下:

[0213] 1.加速域名obfuscate.test1.com

[0214] 2.访问index.html页面包含如下css和js资源:

[0215] ##示例,假设原始index.html页面包含本站点的css和js资源如下:

[0216] #js1--外部第三资源

[0217] <script src="https: / / obfuscate.test1.com / folder331 / yourScript.js">< / script>

[0218] #js2 -- External Third-Party Resources

[0219] <script src=" / myEffects.js">引用源站js2< / script>

[0220] #js3 -- Inline third-party resources

[0221] <script data-for="result">

[0222] (function() {

[0223] var perfkey = 'resultEnd';

[0224] if (!perfkey) {

[0225] return;

[0226] }

[0227] if (!window.__perf_www_datas) {

[0228] window.__perf_www_datas = {};

[0229] }

[0230] var t = performance&&performance.now&&performance.now();

[0231] window.__perf_www_datas[perfkey] = t;

[0232] })();

[0233] < / script>

[0234] #CSS style 1 -- Target second resource

[0235] <link rel="stylesheet" href="https: / / obfuscate.test1.com / styles1.css">

[0236] / * styles1.css * /

[0237] .yellow-background {

[0238] background-color: yellow;

[0239] }

[0240] #CSS Style 2 -- Inline Second Resource

[0241] <style>

[0242] .data-vue-ssr-id {color:red}

[0243] #page {

[0244] background-color: #f5f5f6;

[0245] margin: 30px 0 0 0;

[0246] padding: 0;

[0247] font: 14px arial;

[0248] white-space: nowrap;

[0249] }

[0250] S1:客户端通过浏览器发送第一获取请求,请求一个加速站点的原始index.html(目标页面的第一资源)到达边缘网关。

[0251] S2:边缘网关回后端获取到原始index.html内容。判断符合隔离条件,拦截原始响应(目标页面的第一资源),返回一个固定html页面给浏览器(隔离第一资源),该html中包含了一个隔离框架js脚本的外部引用(隔离业务脚本链接)。

[0252] S3:浏览器自动加载html页面获取隔离框架js内容,请求(第二获取请求)再次到达边缘网关。

[0253] S4:边缘网关根据请求的特殊性,识别到是全站隔离请求,返回固定的隔离业务脚本js文件(隔离框架)给浏览器。

[0254] S5:浏览器执行此隔离业务js脚本,触发一个空请求(第三获取请求),再次到达边缘网关,网关返回源站域名所需要的header内容(头标签内容)。

[0255] S6:浏览器继续执行隔离框架js的逻辑,发起一个ws协议请求(第四获取请求)到网关ws服务,再次获取原始index.html。由网关转发回后端取回原始index.html内容并响应。

[0256] S7:浏览器获取到隔离前的原始index.html资源后,进行DOMParser解析,并存储为DOM对象。

[0257] S8:浏览器继续执行隔离框架js的逻辑,过滤出index.html中所有的目标第二资源,这里过滤到示例中的css样式1。创建一个ws的socket连接(第五获取请求),告诉网关ws服务拉取任务。并删除DOM中css样式1的引用。css样式2为内联第二资源,不需要再次拉取,不做额外处理。

[0258] #css样式1对应的拉取任务格式示例:

[0259] {

[0260] "taskId": "1",

[0261] "type": "css",

[0262] "needFetch": "true", #是否需要下载

[0263] "src": "https: / / obfuscate.test1.com / styles1.css",#uri编码

[0264] "text": "",

[0265] "headers": {

[0266] "cookie": "xxxx",

[0267] "refer": "xxxx"

[0268] },

[0269] "endFlag" : "false|true"

[0270] }

[0271] S9:边缘网关响应css样式1的内容后,隔离框架js继续执行逻辑,将此样式内容以style形式插入到head尾部。

[0272] S10:隔离框架js继续异步过滤出index.html页面所有本站点的js标签(目标第三资源),并按顺序存入到scriptArray数据(目标数组)中。

[0273] S11:隔离框架js判断,所有的js标签中是否存在外部引用方式的js(外部第三资源),这里判断出js1和js2满足。于是分别发起ws连接(第五获取请求)到边缘网关,由边缘网关回后端拉回原始js1和js2的内容并响应。隔离框架js经过解密后将内容放入scriptArray数组对应索引的text中,这里分别对应索引[0]和[1]。

[0274] #js1拉取任务格式示例:

[0275] {

[0276] "taskId": "1",

[0277] "type": "js",

[0278] "needFetch": "true", #是否需要下载

[0279] "src": "https: / / obfuscate.test1.com / folder331 / yourScript.js",#uri编码

[0280] "text": "",

[0281] "headers": {

[0282] "cookie": "xxxx",

[0283] "refer": "xxxx"

[0284] },

[0285] "endFlag" : "false|true"

[0286] }

[0287] #js2拉取任务格式示例:

[0288] {

[0289] "taskId": "2",

[0290] "type": "js",

[0291] "needFetch": "true", #是否需要下载

[0292] "src": "https: / / obfuscate.test1.com / myEffects.js",#uri编码

[0293] "text": "",

[0294] "headers": {

[0295] "cookie": "xxxx",

[0296] "refer": "xxxx"

[0297] },

[0298] "endFlag" : "false|true"

[0299] }

[0300] S13:隔离框架js判断所有js标签中,是否有内嵌的js(内部第三资源),如果有,则直接将内容放入scriptArray数组对应索引的text中,这里识别到js3为内部第三资源,且索引为[2]。

[0301] S14:通过识别每个任务的endFlag标识判断当前任务是否拉取完结。待所有css和js资源拉取任务完结后,隔离框架js开始按顺序拼接所有js内容,在DomContentLoaded后,使用eval()函数(目标函数)执行原script逻辑,最后完成页面的渲染。鼠标查看网页源代码,隐藏了页面元素。

[0302] 本公开实施例还提供了一种电子设备,参照图10,图10是本公开实施例示出的一种电子设备的示意图。如图10所示,电子设备1000包括:存储器1010和处理器1020,存储器1010与处理器1020之间通过总线通信连接,存储器1010中存储有计算机程序,该计算机程序可在处理器1020上运行,进而实现本公开实施例公开全站隔离方法中的步骤。

[0303] 本公开实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时,实现如本公开实施例公开的全站隔离方法中的步骤。

[0304] 本公开实施例还提供一种计算机程序产品,包括计算机程序,所述计算机程序被处理器执行时,实现如本公开实施例公开的全站隔离方法中的步骤。

[0305] 本说明书中的各个实施例均采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似的部分互相参见即可。

[0306] 这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理终端设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。

[0307] 尽管已描述了本公开实施例的部分实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例做出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本公开实施例范围的所有变更和修改。

[0308] 以上对本公开所提供的一种全站隔离方法,进行了详细介绍,本文中应用了具体个例对本公开的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本公开的方法及其核心思想;同时,对于本领域的一般技术人员,依据本公开的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本公开的限制。< / style>

Claims

1. A site-wide isolation method, characterized in that, Applied to browsers, including: Send a first request to the edge gateway to retrieve the first resource of the target page; Receive the isolation framework transmitted by the edge gateway, the isolation framework being sent by the edge gateway when the first resource of the target page meets the isolation conditions; The isolation framework is used to hide the source code of sensitive resources on the target page; the sensitive resources are characterized as resources that could lead to vulnerabilities in the site, including: The isolation framework sends a third acquisition request to the edge gateway, the third acquisition request being used to acquire the header tag content of the access origin domain name; Receive the header tag content sent by the edge gateway for accessing the origin server domain name; Through the isolation framework, a fourth retrieval request carrying the header tag content is sent to the edge gateway, the fourth retrieval request being used to retrieve the target page; Receive the first resource of the target page sent by the edge gateway, and determine the target second resource and target third resource that need to be isolated in the first resource; The isolation framework is used to hide the target second resource and the target third resource. The target second resource is a second resource located on the same site as the first resource and referenced externally; the second resource is used to implement the layout style of the target page. The target third resource is a third resource located on the same site as the first resource; the third resource is used to implement the business logic of the target page.

2. The method according to claim 1, characterized in that, The isolation framework that receives the transmission from the edge gateway includes: Receive the isolation first resource of the isolation framework sent by the edge gateway; the isolation first resource carries the isolation service script link; The first isolated resource is automatically loaded, and a second acquisition request for obtaining the isolation framework is sent to the edge gateway according to the isolated business script link; The isolation framework received by the edge gateway.

3. The method according to claim 1, characterized in that, The target second resource is hidden through the isolation framework, including: Determine the first target link of the target second resource; Based on the first target link of the target second resource, a fifth acquisition request for acquiring the target second resource is sent to the edge gateway; Receive the original second resource corresponding to the target second resource sent by the edge gateway; The original second resource is inserted into the first resource in the target format, and the target second resource is deleted from the first resource.

4. The method according to claim 1, characterized in that, The target third resource includes external third resources and internal third resources. Hiding the target third resource through the isolation framework includes: Each of the target third resources in the first resource is identified to obtain a target array; Add the content corresponding to the internal third resource to the text content at the corresponding index of the target array; Determine the second target link corresponding to the external third resource; Based on the second target link of the external third resource, a fifth acquisition request for acquiring the external third resource is sent to the edge gateway; Receive the original third resource corresponding to the external third resource sent by the edge gateway; Add the content corresponding to the original third resource to the text content at the corresponding index of the target array; The text content included in the target array is concatenated according to the index order to obtain concatenated text, and the target third resource is deleted in the first resource. The concatenated text is used to: achieve the same function as the target third resource by calling the target function.

5. A site-wide isolation method, characterized in that, Applied to edge gateways, including: Receive the first retrieval request sent by the browser to obtain the first resource of the target page; Based on the first acquisition request, obtain the first resource of the target page from the backend; Determine whether the first resource of the target page meets the isolation conditions; If the first resource of the target page meets the isolation conditions, cancel sending the first resource of the target page to the browser and return the isolation frame to the browser; so that the browser hides the source code of the sensitive resources of the target page, including: The isolation framework sends a third acquisition request to the edge gateway, the third acquisition request being used to acquire the header tag content of the access origin domain name; Receive the header tag content sent by the edge gateway for accessing the origin server domain name; Through the isolation framework, a fourth retrieval request carrying the header tag content is sent to the edge gateway, the fourth retrieval request being used to retrieve the target page; Receive the first resource of the target page sent by the edge gateway, and determine the target second resource and target third resource that need to be isolated in the first resource; The isolation framework is used to hide the target second resource and the target third resource. The target second resource is a second resource located on the same site as the first resource and referenced externally; the second resource is used to implement the layout style of the target page. The target third resource is a third resource located on the same site as the first resource; the third resource is used to implement the business logic of the target page.

6. The method according to claim 5, characterized in that, If the first resource of the target page meets the isolation conditions, cancel sending the first resource of the target page to the browser and return the isolation frame to the browser, including: Send the first isolation resource of the isolation framework to the browser; the first isolation resource carries a link to the isolation business script; Receive a second request sent by the browser to obtain the isolated service script; Based on the second acquisition request, the isolation service script is sent to the browser so that the browser can receive the isolation framework.

7. The method according to claim 5, characterized in that, Determining whether the first resource of the target page meets the isolation conditions includes: Determine whether the first resource belongs to a site that needs to be completely isolated; If the first resource belongs to a site that requires full site isolation, then the first resource is determined to meet the isolation conditions. If the first resource does not belong to a site that requires full site isolation, then the first resource is determined not to meet the isolation conditions.

8. The method according to any one of claims 5-7, characterized in that, Also includes: Receive a third retrieval request sent by the browser; According to the third acquisition request, the header tag content for accessing the origin server domain name is obtained, and the header tag content is sent to the browser; Receive a fourth retrieval request sent by the browser, carrying the content of the header tag; Based on the fourth acquisition request, the first resource of the target page is obtained from the backend; Send the first resource of the target page to the browser.

9. The method according to claim 5, characterized in that, Also includes: The system receives a fifth request from the browser to obtain the original resources; the original resources include the original second resource and the original third resource. According to the fifth request, the original resource is obtained from the backend; Determine the size of the original resource; If the original resource exceeds a first threshold, the original resource is sent to the browser in the form of fragments, so that the browser can hide the source code of the sensitive resources of the target page based on the original resource.

Citation Information

Patent Citations

  • Website application isolation protection system

    CN111931170A

  • Script processing method and device, electronic equipment and readable storage medium

    CN116225397A