Application auditing method, program product, electronic device and storage medium

By monitoring and determining the relationship between users' operations on the application page, the problem of excessive redundant data in the existing technology is solved, efficient screening and analysis of audit data is realized, and system pressure is reduced.

CN119938467APending Publication Date: 2025-05-06SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411832868.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When using audits, it is difficult to effectively screen out meaningless operations, resulting in too much redundant data and increasing the system's pressure on reporting and analysis of audit data.

Method used

By listening to the user's operations on the application page, obtaining page content requests, and determining the association between the changing content, page content requests and user operations when the content of the application page changes, and determining audit data based on this association relationship.

Benefits of technology

Ensure the integrity of audit data, be able to trace the requests and operations corresponding to the page content, and screen out meaningless operations, reduce the amount of audit data, and reduce the system's pressure on reporting and analysis of audit data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938467A_ABST
    Figure CN119938467A_ABST
Patent Text Reader

Abstract

The embodiment of the invention is suitable for the technical field of computers, and provides an application auditing method, a program product, electronic equipment and a storage medium, and the method comprises the following steps: monitoring the operation of a user on an application page; under the condition that the operation of the user triggers the sending of the page content request, obtaining the page content request; under the condition that it is monitored that the content of the application page changes, the incidence relation between the change content of the application page and the page content request and the operation of the user is determined; and determining auditing data of the application based on the association relationship.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an application audit method, a program product, an electronic device and a storage medium. Background Art

[0002] In related technologies, when auditing an application, all relevant data is often recorded in full. However, since users will perform a large number of meaningless operations when using the application, these operations will generate a large amount of redundant data, making it difficult to determine the correlation between the data, and placing a heavy burden on the system when reporting and analyzing subsequent audit data. Summary of the invention

[0003] In view of this, an embodiment of the present application provides an application audit method, a program product, an electronic device and a storage medium.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] This application embodiment provides an application audit method, the method comprising:

[0006] Monitor the user's operations on the application page; when the user's operations trigger the sending of a page content request, obtain the page content request; when changes in the content of the application page are monitored, determine the association between the changed content of the application page and the page content request and the user's operations; determine the audit data of the application based on the association.

[0007] In the above solution, before monitoring the user's operation on the application page, the method further includes:

[0008] User operations are defined based on a selector; wherein the defined user operations include selecting content in the application page and inputting content through a hardware device; correspondingly, monitoring the user's operations on the application page includes: monitoring the user's operations on the application page based on the selector.

[0009] In the above scheme, monitoring the user's operation on the application page based on the selector includes: determining the similarity between the user's operation and the user operation defined by the selector; if the similarity is greater than a threshold, obtaining operation data corresponding to the user's operation.

[0010] In the above scheme, determining the similarity between the user's operation and the user operation defined by the selector includes at least one of the following: determining the similarity between the cursor trajectory of the user when performing the selection operation and the cursor trajectory of the user operation defined by the selector; determining the overlap between the position clicked by the user's selection operation and the area of ​​the user operation defined by the selector, and using the overlap as the similarity.

[0011] In the above scheme, before obtaining the page content request, the method also includes: adding the identity identifier of the user to the address of the application page; correspondingly, after obtaining the page content request, the method also includes: determining a first correspondence between the page content request and the user's operation based on the address of the application page to which the identity identifier is added, and the first correspondence is used to determine the association relationship.

[0012] In the above scheme, after obtaining the page content request, the method also includes: adding an identifier to the page content request; sending the page content request with the identifier added to the application server; based on the identifier, determining a second correspondence between the page content request and the page content included in the corresponding response; correspondingly, determining the association between the changed content of the application page and the page content request and the user operation includes: determining the association based on the first correspondence and the second correspondence.

[0013] In the above scheme, the audit data of the application is obtained based on the association relationship, including: based on the association relationship, the changed content of the application page, the page content request corresponding to the changed content of the application page, and the operation data corresponding to the user's operation are determined as the audit data.

[0014] An embodiment of the present application also provides an electronic device, comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is used to execute the steps of the method in the above scheme when running the computer program.

[0015] An embodiment of the present application also provides an application auditing device, including: a monitoring module, used to monitor the user's operations on the application page; an acquisition module, used to acquire the page content request when the user's operation triggers the sending of the page content request; a determination module, used to determine the association between the changed content of the application page and the page content request and the user's operation when the content of the application page changes; and determine the audit data of the application based on the association.

[0016] An embodiment of the present application further provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in the above scheme are implemented.

[0017] An embodiment of the present application also provides a computer program product, including a computer program, which implements the steps of the method in the above solution when executed by a processor.

[0018] The embodiment of the present application monitors the user's operation on the application page, obtains the page content request when the user's operation triggers the sending of the page content request, and determines the association between the changed content of the application page and the page content request and the user's operation when the content of the application page changes, and obtains the audit data of the application based on the association relationship. The embodiment of the present application monitors the user's operation on the application page, determines the audit data according to the association between the changed content of the application page and the page content request and the user's operation, and can ensure the integrity of the audit data, can trace the requests and operations corresponding to the page content, and screens out meaningless operations that will not cause page changes, reducing the amount of audit data, thereby reducing the pressure on the system to report and analyze audit data. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 A flowchart of an application audit method provided in an embodiment of the present application;

[0020] Figure 2 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0021] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0023] Zero trust refers to a security concept of "never trust, always verify", and has developed a security framework of "identity-centric, continuous trust assessment, and dynamic access control". The mainstream technical implementations include software-defined perimeter (SDP), unified identity management (Identity and Access Management, IAM), and micro-isolation (MSG). The concept of "zero trust" in the embodiments of this application can be an SDP software-defined perimeter product.

[0024] SDP software-defined perimeter refers to a network access control security architecture based on the concept of zero trust, which is used to protect enterprise applications and services. It is a type of zero-trust access control system. It defines a set of security policies and rules to limit users and devices that access applications and services, and prevent unauthorized access and attacks. SDP products are generally composed of three major components: SDP control center and proxy gateway (also called "SDP server"), SDP connection initiator host (also called "SDP client").

[0025] Browser scripts refer to a piece of code that runs in a web browser environment. In zero-trust business security access scenarios, they are usually used to optimize web proxy compatibility, page protection, and auditing. These scripts are usually written in JavaScript and rely on the application programming interface (API) provided by the browser to interact with web page content.

[0026] Auditing generally refers to recording, analyzing and reviewing the behaviors of individuals or organizations during the use of the Internet. Usually, auditing can be achieved by monitoring network traffic, analyzing bandwidth usage, reviewing web browsing history, monitoring the use of email and instant messaging tools, tracking file download and upload behaviors, etc. The relationship between data plays a very important role in auditing. The relationship between data can help managers more clearly understand the operation process of network users and analyze their purpose. At the same time, this relationship can also be used to classify data to achieve better audit data management.

[0027] In related technologies, the means for application auditing is mainly to record the application pages to be audited, including the following methods:

[0028] Headless engine recording solution: Use the Headless Chrome engine on the server to load the corresponding page, output the video file through the engine interface, and play back the recorded application page through the video file.

[0029] Browser API recording solution: Use the browser's API to read the page display content and save the video stream, thereby recording the web page as a video.

[0030] Front-end screenshot solution: Draw the content of the Document Object Model (DOM) onto the canvas, and then convert the canvas into a picture format to save the web page as a picture. After obtaining the complete screenshot, you can check the page changes later, take screenshots of the different parts of the page that have changed, and record the coordinate position and time node of each change. During playback, overlay and load according to the time node and the coordinate position of the picture to restore the display effect of the page on the spot.

[0031] Browser extension recording solution: Through the browser extension interface, the web page content can be fully recorded and output as a single HTML file. For example, the browser SingleFile extension program is implemented by capturing web page content, reconstructing the DOM structure, compressing encoding resources and generating a single HTML file to save the web page as a single file. This makes it easier for users to save and share web pages and reduces dependence on external resources.

[0032] The application audit method in related technologies also has the following disadvantages:

[0033] 1. Audit based on API request response:

[0034] a) The fields and results seen on some interfaces are usually codes, which are difficult to read.

[0035] b) The result of the API request response is inconsistent with the user operation. For example, the query function of a table requires requesting two APIs, but the two API response information will be spliced ​​into one table content.

[0036] c) Some API request and response parameters will be encoded in Unicode, which also affects readability.

[0037] d) Due to the performance of the application proxy gateway, the length of the audit field is limited, and usually only part of the content can be audited. When there is a lot of redundant data, key data is easily missing.

[0038] e) Audit data cannot be associated with user identity information.

[0039] 2. Audit through client program screen recording:

[0040] a) It requires additional installation of client programs, which is likely to cause user resistance.

[0041] b) A full audit will be performed during work, resulting in large memory and disk usage. At the same time, the recording results need to be uploaded to the server, which has a negative impact on the end-user experience and network bandwidth.

[0042] c) The audit content cannot be analyzed directly and needs to be analyzed in conjunction with identification technologies such as ORC.

[0043] d) There is no way to ensure that audit data can be associated with user identity information.

[0044] 3. Business system transformation:

[0045] a) Many businesses usually lack audit functions. Due to low development priority and the inability to supplement audit capabilities through outsourcing of business systems, they are unable to have business audit capabilities, and the security team is unable to conduct traceability analysis based on audit logs.

[0046] b) Some business audit log contents do not meet security requirements and cannot be connected to security analysis components.

[0047] Based on the problems existing in the above-mentioned related technologies, an embodiment of the present application provides an application auditing method, which obtains audit data that causes page changes and has a correlation relationship between internal data through a preset script, so as to reduce redundant data in the audit data.

[0048] Figure 1 A flowchart of an application audit method provided in an embodiment of the present application is provided in Figure 1 , the method comprising:

[0049] Step 101: monitor the user's operations on the application page.

[0050] The method steps executed in the embodiment of the present application can be performed based on a zero-trust system, that is, the user's operations and the page content requests issued will only be executed or issued after being verified by the zero-trust system. The user also needs to perform identity authentication before accessing the application to verify whether the user has the authority to access the corresponding application. On this basis, the audit data can be associated with the user's identity information.

[0051] In some embodiments, the preset script can be a script designed for the audited application, or it can be a general script directly sent to the application that needs to be audited. The preset script can record user operation information, page information and other information, and generate audit data for subsequent analysis.

[0052] In some embodiments, the user's operations on the application page can be fully monitored, where the user's operations can be recorded. In order to avoid recording too much data, a time window can be designed to record only operations within the time window, such as 24 hours. That is, the operation data whose operation time is more than 24 hours different from the current time will be deleted, and only the user's operations within 24 hours will be recorded.

[0053] In some embodiments, it is also possible to detect and identify only the user's operations, and determine whether to record the operation information or operation data corresponding to these operations and related page information based on the methods in subsequent steps to determine the audit data.

[0054] Step 102: when it is monitored that the user's operation triggers sending a page content request, the page content request is obtained.

[0055] In some embodiments, when a user performs operations such as clicking on a link, searching for content, refreshing a page, etc., a corresponding page content request will be generated to request the corresponding content from the application server. After the page application request is generated, the preset script will obtain the page content request. In some cases, a single operation of the user may generate multiple page content requests in sequence. For example, when the user clicks a load button, the page jumps to the loading page, and then jumps to the loaded page after the loading is completed. Here, the preset script can determine the association relationship between multiple page content requests, determine whether there is a trigger relationship between multiple page content requests, and also obtain multiple page content requests that are continuously triggered by a single operation of the user.

[0056] In some embodiments, obtaining a page content request may be to hook the page content request. Hook is a system mechanism provided in Windows for replacing a terminal under DOS, which may be referred to as a "hook" or "hook". After hooking a specific system event, once a hooked event occurs, the program that hooks the event will receive a notification from the system. At this time, the program can respond to the event as soon as possible. In an embodiment of the present application, a preset script will respond to the issued page content request and obtain the generated request in a timely manner.

[0057] In some embodiments, for some page content requests that are not caused by user operations, such as pop-up advertisements, etc., a preset script can block these requests.

[0058] Step 103: when the content of the application page changes, determine the association relationship between the changed content of the application page, the page content request, and the user's operation.

[0059] In some embodiments, the user may perform multiple operations on the application page at the same time, and some operations are meaningless and will not cause changes to the page, so these operations need to be identified and excluded. Therefore, when the content of the application page changes, the operation that causes the content change can be considered a valid operation, and the association between the operation and the corresponding page content request and the changed content is determined. For valid operations, a corresponding page content request will be generated, and the application server will return a corresponding response after receiving the page content request. It can be considered that the operation, page content request and response in this process are associated, and these three constitute a complete request response process.

[0060] Step 104: Determine the audit data of the application based on the association relationship.

[0061] In some embodiments, determining whether the page content has changed needs to be based on whether the application server returns a response and whether the returned response content is the same as the current page content. The application server may not return a response because the operation did not trigger the page content request or the page content request failed to be sent. Here, the focus is on the case where the application server returns a response. When it is determined that the page content has changed based on the response returned by the application server, it is necessary to reversely search for the corresponding page content request and user operation. Specifically, the search can be based on the association relationship determined in step 103. At least the operation data of the user operation that causes the page change and has an association relationship, the changed content of the application page, and the page content request are used as audit data.

[0062] In addition, the original page content, user identity information, and response data of key points that the page content request passes through during the flow process can also be used as audit data.

[0063] The embodiment of the present application monitors the user's operation on the application page, obtains the page content request when the user's operation triggers the sending of the page content request, and determines the association between the changed content of the application page and the page content request and the user's operation when the content of the application page changes, and obtains the audit data of the application based on the association relationship. The embodiment of the present application monitors the user's operation on the application page, determines the audit data according to the association between the changed content of the application page and the page content request and the user's operation, and can ensure the integrity of the audit data, can trace the requests and operations corresponding to the page content, and screens out meaningless operations that will not cause page changes, reducing the amount of audit data, thereby reducing the pressure on the system to report and analyze audit data.

[0064] In some embodiments, before monitoring the user's operation on the application page, the method further includes:

[0065] Defining user operations based on the selector; wherein the defined user operations include selecting content in the application page and inputting content through a hardware device;

[0066] Correspondingly, monitoring the user's operation on the application page includes:

[0067] The user's operation on the application page is monitored based on the selector.

[0068] A selector generally refers to a CSS selector. Each CSS style definition consists of two parts, and its format is as follows: [code] selector {style} [ / code] The part before {} is the "selector". The "selector" specifies the object of the "style" in {}, that is, which elements of the web page the "style" acts on. In the embodiment of the present application, the object of the selector is a specific operation.

[0069] In some embodiments, through the definition of the selector, the user operation can be defined more accurately to ensure that the same action is consistent for all users. For example, in a click action, different users may control the mouse to slide over different tracks and finally click. For the selector, these actions can be defined as click actions. When the selector defines an action, the length of the defined action needs to be controlled. For example, if a user double-clicks an option and long-presses the mouse to drag it, this is a long action composed of multiple small actions. Try to avoid defining longer actions to avoid affecting the accuracy of recognition and occupying too much storage space. Further, it is necessary to avoid defining too fine actions, because the selector will recognize the element identifier automatically generated by the front-end framework, so as to avoid the automatic change of the element identifier in actual use, resulting in recognition failure. At the same time, the selector can recognize a class of operations, such as click actions, drag actions, etc. On this basis, if refined recognition is required, it is necessary to combine the user name for customized recognition. In general, only the selector can be used to recognize the action, and a certain degree of mismatch is allowed. At the same time, considering the performance consumption of user action recognition, the number of defined actions needs to be limited. Due to the deep level of complex pages, excessive performance consumption will affect the normal operation of users.

[0070] In some embodiments, after the action is defined by the selector, the operation performed by the user in the application page can be monitored based on the selector, and the monitoring can be performed in the manner of the aforementioned step 101.

[0071] Based on the above embodiment, the user's operation is monitored by defining an action through a selector in the script, without the need to install an additional client program, thereby achieving user operation monitoring without the user's awareness.

[0072] In some embodiments, monitoring the user's operation on the application page based on the selector includes:

[0073] Determining the similarity between the user's operation and the user's operation defined by the selector;

[0074] If the similarity is greater than a threshold, the operation data corresponding to the user's operation is obtained.

[0075] In some embodiments, the user's operation can be matched with the operation defined by the selector. If the similarity between the two is greater than a threshold, such as 80%, the recognition is successful and the operation is monitored. Specifically, the frequency and number of times the user clicks the mouse and / or the content input by the user on the keyboard can be detected. For example, the mouse clicking operation is defined as a frequency of no more than two mouse clicks per second. If the frequency is higher than this or the clicking is continuous and uninterrupted, it is considered that the user may be clicking the mouse meaninglessly.

[0076] In some embodiments, focus events can also be defined. By identifying user action combinations or user-performed specific actions, events performed by the current user can be defined. For example, the user's current identity information is recorded. When the user clicks on the input box, an input event is triggered, indicating that the user may enter content in the input box. At this time, if the user enters content and presses Enter, the operation can be directly audited. In some cases, if the user clicks outside the input box again, it means that the user has stopped the input event. Here, the input box position of the application page is monitored, and the user's operation on the area can be matched with the corresponding operation event. Further, when the user enters content, the text entered by the user can be recorded. For security reasons, the input content of the password type is not recorded. Here, the type of the input box can be identified to shield the input content of the password type. At the same time, the length of the recorded text is limited. The content exceeding the limited length is truncated. In order to avoid excessive repeated content occupying the recording space, the content that appears repeatedly in the input content can be reduced. For example, a long noun can be represented by A and A is annotated. The content repeated continuously can be merged.

[0077] In some embodiments, different recording methods can be used for different texts input by users. For example, when a user inputs Chinese characters through an input method, the text content input is not recorded when the text is displayed in the input method candidate column and is not selected to be displayed in the input box. The text input is recorded when the user presses a space or selects the text in the input method candidate column. For other types of input content, such as inputting English, the content input by the user in real time will be directly displayed in the input box, and the text input by the user can be recorded in real time.

[0078] In some embodiments, the operation data may include the user's operation actions recorded in the aforementioned embodiments, as well as the text content input by the user, etc., and may also include the user's operation time, user information, etc.

[0079] Based on the above embodiment, by identifying the actual operation of the user and monitoring when the similarity is large, the occupation of the monitoring operation on the system performance is reduced and the efficiency of monitoring is improved.

[0080] In some embodiments, determining the similarity between the user's operation and the user's operation defined by the selector comprises at least one of the following:

[0081] Determine the similarity between the cursor track of the user when performing the selection operation and the cursor track of the user operation defined by the selector;

[0082] The degree of overlap between the position clicked by the user's selection operation and the area of ​​the user operation defined by the selector is determined, and the degree of overlap is used as the similarity.

[0083] In some embodiments, conventional clicks, keyboard input and other operations can be directly monitored, while some continuous actions or operations in specific areas require targeted identification. For example, for gesture operations, the trajectory of the user's cursor can be monitored. It can be understood that even the trajectories of the same gesture when different users swipe will not be exactly the same. Here, a fuzzy matching method can be adopted to record the starting and end points of different trajectories and fit the middle trajectory. If the fitting result indicates that the similarity is greater than the set value, it is considered to be the same type of gesture or trajectory.

[0084] In some embodiments, for the interactive area, the user can click on the area to jump to the page. However, some button options are set to be small or the user is not proficient in operation, which may require multiple clicks to select the button option or interactive area. At this time, the locations of the user's multiple clicks can be recorded and matched with the predefined operation area. If the user clicks multiple times around the area, it can be considered that the user wants to select the corresponding button or area, and the user's operation can also be identified.

[0085] In some embodiments, the user's operations can also be monitored from the hardware level. For example, when a user clicks on an option, he needs to press and release the mouse to complete a click action. Here, the monitoring can be performed when the user presses the mouse, indicating that the user has pressed the mouse, and the time interval from the user pressing the mouse to releasing the mouse can be analyzed to identify whether the user's operation is a click or a drag operation.

[0086] Based on the above embodiment, by identifying the user's operation trajectory and selection position, the user's actual operation is accurately identified, and fuzzy matching is performed, which can neutralize the erroneous operations caused by the operation habits and other factors of some users and improve the recognition success rate.

[0087] In some embodiments, before obtaining the page content request, the method further includes:

[0088] Adding the user's identity to the address of the application page;

[0089] Correspondingly, after obtaining the page content request, the method further includes:

[0090] Based on the address of the application page to which the identity identifier is added, a first corresponding relationship between the page content request and the user's operation is determined, and the first corresponding relationship is used to determine the association relationship.

[0091] In some embodiments, the user's identity identifier can be added to the application page address. It can be understood that the user's operations and the corresponding requests can be bound to the page application address. Since other users may access the application page at the same time, the user's identity identifier can be added to associate the operations of a single user with the page content requests generated by the corresponding operations. Specifically, there is a first correspondence between the operations in the same application page and the corresponding page content requests. The first correspondence represents the correspondence between the user operations and the page content requests. One user operation can correspond to at least one page application request, and multiple operations can also correspond to one page application request. The specific correspondence needs to be determined based on the triggering conditions of the actual page content request. Here, it is only explained that there is a certain correspondence between the two.

[0092] In some embodiments, in order to protect the user's information security, a corresponding identity code may be generated for each user based on the identity identifier and added to the address of the application page to replace the identity identifier.

[0093] Based on the above embodiment, by adding the user's identity identifier in the application page, the user's operation is associated with the corresponding page content request, which is convenient for subsequent tracing.

[0094] In some embodiments, after obtaining the page content request, the method further includes:

[0095] adding an identifier to the page content request;

[0096] Sending a page content request with the identifier added to the application server;

[0097] Based on the identifier, determining a second correspondence between the page content request and the page content included in the corresponding response;

[0098] Correspondingly, determining the association between the changed content of the application page and the page content request and the user operation includes:

[0099] The association relationship is determined based on the first corresponding relationship and the second corresponding relationship.

[0100] In some embodiments, when an application page generates a page content request, a preset script obtains the request and adds a unique identifier to each request to facilitate tracking of the entire page content request process to match requests and responses. Specifically, after the preset script adds an identifier to the page content request, the page content request with the identifier added is sent to the application server. Correspondingly, the response returned by the application server also contains a corresponding identifier. In this way, the page content request corresponding to the response can be traced based on the identifier, that is, a second corresponding relationship between the two can be determined. Here, the second corresponding relationship represents the association relationship between the request and the response. Furthermore, combined with the first corresponding relationship determined in the aforementioned embodiment, the association relationship between the user operation, the page content request, and the page change content in the response can be determined. It should be noted that the page content included in the response can be regarded as having the same identifier as the response, so as to achieve the determination of the association relationship between the aforementioned three.

[0101] Based on the above embodiment, by determining the first corresponding relationship and the second corresponding relationship, the user operation, the page change content and the page content request are associated, and the complete content request process triggered by the user operation is obtained, which facilitates the acquisition and analysis of audit data, and can further trace the operation in combination with the user identity.

[0102] In some embodiments, obtaining the audit data of the application based on the association relationship includes:

[0103] Based on the association relationship, the changed content of the application page, the page content request corresponding to the changed content of the application page, and the operation data corresponding to the user's operation are determined as the audit data.

[0104] In some embodiments, the aforementioned association relationship can be determined during the process of requesting the page content, and the steps of this embodiment can be performed in the process of tracing the corresponding requests and operations based on the page content when it is determined that the page content has changed. It can be understood that not all the content contained in the response will cause the current page content to change, but it is difficult to determine whether the subsequent response will cause the page content to change during the page content request process. Therefore, for each user operation and the corresponding page content request and response, the association relationship between the three can be determined, and then traced back when the page content changes, and used as audit data.

[0105] In some embodiments, the association relationship can also be diverged. For example, information associated with user operations includes but is not limited to operation time, operating user, number of operations, etc. These are all information associated with user operations and can also be matched in combination with the above-mentioned association relationship as audit data. For example, at key points in the life cycle of the request related to the page content request (such as start, success, failure, interruption, timeout, etc.), the status of the page content request at these key points can also be recorded. Specifically, the status can be returned by executing a predefined callback function. For the response (the page content included in the response), the page content before the change can also be used as audit data, and the content before the change can be compared with the content after the change in subsequent analysis.

[0106] Based on the above embodiment, the requests and operations corresponding to the page changes are traced back to obtain the corresponding audit data based on the determined association relationship, which can achieve efficient auditing of the application, eliminate invalid operations and requests, reduce redundant data, and provide convenience for data analysis of operation and maintenance personnel.

[0107] The embodiment of the present application also provides an application audit device, which corresponds to the above-mentioned application audit method, and each step in the above-mentioned application audit method embodiment is also fully applicable to the embodiment of the present device.

[0108] The application auditing device comprises:

[0109] The monitoring module is used to monitor the user's operations on the application page;

[0110] An acquisition module, configured to acquire the page content request when the user's operation triggers the sending of the page content request;

[0111] The determination module is used to determine the association between the changed content of the application page and the page content request and the user's operation when monitoring the change of the content of the application page; and determine the audit data of the application based on the association.

[0112] The monitoring module is also used to define user operations based on a selector; wherein the defined user operations include selecting content in the application page and inputting content through a hardware device; and monitoring the user's operations on the application page based on the selector.

[0113] The monitoring module is further used to determine the similarity between the selection operation of the user and the user operation defined by the selector; if the similarity is greater than a threshold, the operation data corresponding to the user operation is obtained.

[0114] The monitoring module is also used to determine the similarity between the cursor trajectory of the user when performing the selection operation and the cursor trajectory of the user operation defined by the selector; determine the overlap between the position clicked by the user's selection operation and the area of ​​the user operation defined by the selector, and use the overlap as the similarity.

[0115] The determination module is also used to add the user's identity identifier to the address of the application page; based on the address of the application page with the identity identifier added, determine the first correspondence between the page content request and the user's operation, and the first correspondence is used to determine the association relationship.

[0116] The determination module is further used to add an identifier to the page content request;

[0117] Sending a page content request with the identifier added to the application server;

[0118] Based on the identifier, a second correspondence between the page content request and the page content included in the corresponding response is determined; based on the first correspondence and the second correspondence, the association relationship is determined.

[0119] The determination module is further used to determine, based on the association relationship, the changed content of the application page, the page content request corresponding to the changed content of the application page, and the operation data corresponding to the user's operation as audit data.

[0120] In actual application, the above-mentioned monitoring module, determination module and acquisition module can be implemented by a processor in the application audit device. Of course, the processor needs to run the computer program in the memory to realize its function.

[0121] It should be noted that: when the device provided in the above embodiment is applied, only the division of the above program modules is used as an example. In actual application, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the device and method embodiments provided in the above embodiment belong to the same concept and will not be repeated here.

[0122] Based on the hardware implementation of the above program modules and in order to implement the method of the embodiment of the present application, the embodiment of the present application also provides an electronic device. Figure 2 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the electronic device includes:

[0123] Communication interface 201, capable of exchanging information with other devices such as network devices;

[0124] The processor 202 is connected to the communication interface 201 to implement information exchange with other devices and is used to execute the method provided by one or more technical solutions when running a computer program. The computer program is stored in the memory 203.

[0125] Of course, in actual application, the various components in the electronic device are coupled together through the bus system 204. It can be understood that the bus system 204 is used to realize the connection and communication between these components. In addition to the data bus, the bus system also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 2 Various buses are labeled as bus system 204 .

[0126] The memory 203 in the embodiment of the present application is used to store various types of data to support the operation of the computer device. Examples of such data include: any computer program used to operate on the electronic device.

[0127] It can be understood that the memory 203 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), direct memory bus random access memory (DRRAM). The memory described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memory.

[0128] The method disclosed in the above embodiment of the present application can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software. The above processor may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in a memory, and the processor reads the program in the memory and completes the steps of the above method in combination with its hardware.

[0129] Optionally, when the processor 202 executes the program, it implements the corresponding processes implemented by the computer device in each method of the embodiments of the present application, which will not be described here for the sake of brevity.

[0130] In an exemplary embodiment, the present application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a first memory storing a computer program, and the computer program can be executed by a processor of a computer device to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0131] In the several embodiments provided in the present application, it should be understood that the disclosed devices, computer equipment and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0132] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0133] In addition, all functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may be a separate unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0134] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium, which, when executed, executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.

[0135] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present application can be essentially or partly embodied in the form of a software product that contributes to the relevant technology. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0136] In an exemplary embodiment, the embodiment of the present application further provides a computer program product, including a computer program, and the computer program can be executed by the processor 202 of the electronic device to complete the steps described in the method in the embodiment of the present application.

[0137] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0138] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0139] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An application audit method, applied to a preset script in a browser, characterized in that: The method comprises: Monitor the user's operations on the application page; In the case where it is monitored that the user's operation triggers the sending of a page content request, obtaining the page content request; When the content of the application page changes, determining the association relationship between the changed content of the application page and the page content request and the user's operation; Audit data of the application is determined based on the association relationship.

2. The method according to claim 1, characterized in that: Before monitoring the user's operation on the application page, the method further includes: Defining user operations based on the selector; wherein the defined user operations include selecting content in the application page and inputting content through a hardware device; Correspondingly, monitoring the user's operation on the application page includes: The user's operation on the application page is monitored based on the selector.

3. The method according to claim 2, characterized in that: The monitoring the user's operation on the application page based on the selector includes: Determining the similarity between the user's operation and the user's operation defined by the selector; If the similarity is greater than a threshold, the operation data corresponding to the user's operation is obtained.

4. The method according to claim 3, characterized in that: The determining of the similarity between the user operation and the user operation defined by the selector comprises at least one of the following: Determine the similarity between the cursor track of the user when performing the selection operation and the cursor track of the user operation defined by the selector; The degree of overlap between the position clicked by the user's selection operation and the area of ​​the user operation defined by the selector is determined, and the degree of overlap is used as the similarity.

5. The method according to claim 1, characterized in that: Before obtaining the page content request, the method further includes: Adding the user's identity to the address of the application page; Correspondingly, after obtaining the page content request, the method further includes: Based on the address of the application page to which the identity identifier is added, a first corresponding relationship between the page content request and the user's operation is determined, and the first corresponding relationship is used to determine the association relationship.

6. The method according to claim 5, characterized in that: After obtaining the page content request, the method further includes: adding an identifier to the page content request; Sending a page content request with the identifier added to the application server; Based on the identifier, determining a second correspondence between the page content request and the page content included in the corresponding response; Correspondingly, determining the association between the changed content of the application page and the page content request and the user operation includes: The association relationship is determined based on the first corresponding relationship and the second corresponding relationship.

7. The method according to claim 1, characterized in that: The obtaining the audit data of the application based on the association relationship includes: Based on the association relationship, the changed content of the application page, the page content request corresponding to the changed content of the application page, and the operation data corresponding to the user's operation are determined as the audit data.

8. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the application audit method described in any one of claims 1 to 7 are implemented.

9. An electronic device, characterized in that: include: A processor and a memory for storing a computer program that can be executed on the processor, wherein: The processor is used to execute the steps of the method according to any one of claims 1 to 7 when running a computer program.

10. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.