Application auditing method, program product, electronic device and storage medium

By inserting preset scripts on the proxy gateway, non-aware auditing of applications that support audits is achieved, and the problems of business system transformation and client program installation in the prior art are solved, improving user experience and audit efficiency.

CN119938468APending Publication Date: 2025-05-06SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411844243.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing technology requires the transformation of the business system and the installation of additional client programs during application audits, resulting in user resistance, and not all applications require auditing. The audit method based on client programs will generate large memory and disk usage, affecting user experience and network bandwidth.

Method used

By implementing the application audit method on the proxy gateway, the browser's access request is obtained. If the accessed application supports auditing, a preset script is inserted into the application's response and forward the response to the browser, so that the browser can audit based on the script and obtain audit data.

Benefits of technology

It realizes auditing of applications without the user's perception, avoids transformation of business systems, reduces the risk of browsers occupying too much resources, improves user experience, and issues scripts only when applications that require auditing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938468A_ABST
    Figure CN119938468A_ABST
Patent Text Reader

Abstract

The embodiment of the invention is suitable for the technical field of computers, and provides an application auditing method, a program product, electronic equipment and a storage medium, and the method comprises the following steps: obtaining a first access request sent by a browser; if the application accessed by the first access request is the application supporting auditing, inserting a preset script in a first response of the first access request returned by the application; and forwarding the first response to the browser to enable the browser to obtain a preset script from the first response, and auditing the application based on the preset script to obtain auditing data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an application audit method, a program product, an electronic device and a storage medium. Background Art

[0002] In the related technology, when auditing an application, it is generally necessary to transform the business system and implement the audit of the application based on the client, but it is necessary to install an additional client program, which is easily resisted by users, and not all applications need to be audited. The audit method based on the client program will generate large memory and disk usage when working, which will have a negative impact on the user experience and network bandwidth. Summary of the invention

[0003] In view of this, an embodiment of the present application provides an application audit method, a program product, an electronic device and a storage medium.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] The present application embodiment provides an application audit method, which is applied to a proxy gateway, and the method includes:

[0006] Obtain a first access request sent by a browser; if the application accessed by the first access request is an application that supports auditing, insert a preset script into a first response to the first access request returned by the application; forward the first response to the browser so that the browser obtains the preset script from the first response, and audits the application based on the preset script to obtain audit data.

[0007] In the above solution, before forwarding the first response to the browser, the method further includes:

[0008] caching the static files in the first response; correspondingly, after forwarding the first response to the browser, the method further includes: if a second access request for a page corresponding to the static file is received from the browser, generating a second response based on the static file; and sending the second response to the browser.

[0009] In the above scheme, after caching the static file in the first response, the method further includes: determining whether the page content corresponding to the static file has changed; if the page content has changed, updating the static file based on the changed page content.

[0010] In the above solution, after updating the static file based on the changed page content, the method further includes:

[0011] The audit data and the updated static file are sent to a preset analysis center; the preset analysis center is used to generate a playback page based on the audit data and the updated static file.

[0012] In the above scheme, the method includes: sending a first access request to a proxy gateway; receiving a first response of the application forwarded by the proxy gateway; if the application accessed by the first access request is an application that supports auditing, the first response contains a preset script inserted by the proxy gateway; if the preset script is inserted in the first response, auditing the application accessed by the first access request based on the preset script.

[0013] In the above scheme, the audit of the application accessed by the first access request based on the preset script includes: generating a snapshot of the corresponding page content when the page content of the application supporting the audit changes; and recording the operation information of the browser when the page content of the application supporting the audit changes.

[0014] In the above scheme, after recording the operation information of the browser when the page content of the application supporting auditing changes, the method also includes: saving the snapshot and the operation information into an event stream; associating the event stream with the user's identity information to obtain audit data.

[0015] An embodiment of the present application also provides an application auditing device, including: a first receiving module, used to obtain a first access request sent by a browser; a first processing module, used to insert a preset script into a first response to the first access request returned by the application if the application accessed by the first access request is an application that supports auditing; a first sending module, used to forward the first response to the browser, so that the browser obtains the preset script from the first response, and audits the application based on the preset script to obtain audit data.

[0016] An embodiment of the present application also provides an application auditing device, including: a second sending module, used to send a first access request to a proxy gateway; a second receiving module, used to receive a first response of the application forwarded by the proxy gateway; if the application accessed by the first access request is an application that supports auditing, the first response contains a preset script inserted by the proxy gateway; a second processing module, used to audit the application accessed by the first access request based on the preset script if the preset script is inserted in the first response.

[0017] An embodiment of the present application also provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for application auditing applied to a browser or the steps of the method for application auditing applied to a proxy gateway in the above-mentioned scheme are implemented.

[0018] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the method for application auditing applied to a browser or the steps of the method for application auditing applied to a proxy gateway in the above-mentioned scheme.

[0019] The embodiment of the present application obtains the first access request sent by the browser. If the application accessed by the first access request is an application that supports auditing, a preset script is inserted into the first response to the first access request returned by the application, and the first response is forwarded to the browser, so that the browser obtains the preset script from the first response and audits the application based on the preset script. In the embodiment of the present application, when the browser requests to access an application that supports auditing, the proxy gateway sends a script for auditing the application to the browser, and there is no need to modify the business system of the application. The audit of the application is achieved without the user's perception, which improves the user experience. At the same time, the script is only sent when the application requested to access is an application that supports auditing, so as to avoid the browser from occupying too many resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 A flowchart of an application audit method applied to a proxy gateway provided in an embodiment of the present application;

[0021] Figure 2 A flowchart of an application auditing method applied to a browser provided in an embodiment of the present application;

[0022] Figure 3 A flowchart of another application audit method provided in an embodiment of the present application;

[0023] Figure 4 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0024] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0026] Zero trust refers to a security concept of "never trust, always verify", and has developed a security framework of "identity-centric, continuous trust assessment, and dynamic access control". The mainstream technical implementations include software-defined perimeter (SDP), unified identity management (Identity and Access Management, IAM), and micro-isolation (MSG). The concept of "zero trust" in the embodiments of this application can be an SDP software-defined perimeter product.

[0027] SDP software-defined perimeter refers to a network access control security architecture based on the concept of zero trust, which is used to protect enterprise applications and services. It is a type of zero-trust access control system. It defines a set of security policies and rules to limit users and devices that access applications and services, and prevent unauthorized access and attacks. SDP products are generally composed of three major components: SDP control center and proxy gateway (also called "SDP server"), SDP connection initiator host (also called "SDP client").

[0028] Browser scripts refer to a piece of code that runs in a web browser environment. In zero-trust business security access scenarios, they are usually used to optimize web proxy compatibility, page protection, and auditing. These scripts are usually written in JavaScript and rely on the application programming interface (API) provided by the browser to interact with web page content.

[0029] Auditing generally refers to recording, analyzing and reviewing the behaviors of individuals or organizations during network use. Usually, auditing can be achieved by monitoring network traffic, analyzing bandwidth usage, reviewing web browsing history, monitoring the use of email and instant messaging tools, and tracking file download and upload behaviors.

[0030] In related technologies, the means for application auditing is mainly to record the application pages to be audited, including the following methods:

[0031] Headless engine recording solution: Use the Headless Chrome engine on the server to load the corresponding page, output the video file through the engine interface, and play back the recorded application page through the video file.

[0032] Browser API recording solution: Use the browser's API to read the page display content and save the video stream, thereby recording the web page as a video.

[0033] Front-end screenshot solution: Draw the content of the Document Object Model (DOM) onto the canvas, and then convert the canvas into a picture format to save the web page as a picture. After obtaining the complete screenshot, you can check the page changes later, take screenshots of the different parts of the page that have changed, and record the coordinate position and time node of each change. During playback, overlay and load according to the time node and the coordinate position of the picture to restore the display effect of the page on the spot.

[0034] Browser extension recording solution: Through the browser extension interface, the web page content can be fully recorded and output as a single HTML file. For example, the browser SingleFile extension program is implemented by capturing web page content, reconstructing the DOM structure, compressing encoding resources and generating a single HTML file to save the web page as a single file. This makes it easier for users to save and share web pages and reduces dependence on external resources.

[0035] The application audit method in the relevant technology also has the following disadvantages:

[0036] 1. Audit based on API request response:

[0037] a) The fields and results seen on some interfaces are usually codes, which are difficult to read.

[0038] b) The result of the API request response is inconsistent with the user operation. For example, the query function of a table needs to request two APIs, but the two API response information will be spliced ​​into one table content.

[0039] c) Some API request and response parameters will be encoded in Unicode, which also affects readability.

[0040] d) Due to the performance of the application proxy gateway, the length of the audit field is limited, and usually only part of the content can be audited.

[0041] e) Audit data cannot be associated with user identity information.

[0042] 2. Audit through client program screen recording:

[0043] a) It requires additional installation of client programs, which is likely to cause user resistance.

[0044] b) It will take up a lot of memory and disk space during operation, and the recording results need to be uploaded to the server, which will have a negative impact on the end-user experience and network bandwidth.

[0045] c) The audit content cannot be analyzed directly and needs to be analyzed in conjunction with identification technologies such as ORC.

[0046] d) There is no way to ensure that audit data can be associated with user identity information.

[0047] 3. Business system transformation:

[0048] a) Many businesses usually lack audit functions. Due to low development priority and the inability to supplement audit capabilities through outsourcing of business systems, they are unable to have business audit capabilities, and the security team is unable to conduct traceability analysis based on audit logs.

[0049] b) Some business audit log contents do not meet security requirements and cannot be connected to security analysis components.

[0050] Based on the problems existing in the above-mentioned related technologies, an embodiment of the present application provides an application auditing method, which sends scripts on demand and selectively audits applications based on scripts, which is unaware to users and does not affect the access speed.

[0051] Figure 1 A flowchart of an application audit method applied to a proxy gateway provided in an embodiment of the present application is provided. Figure 1 , the method comprising:

[0052] Step 101: Obtain a first access request sent by a browser.

[0053] In some embodiments, the proxy gateway can be a zero-trust proxy gateway, which is the core part of the zero-trust architecture and is usually deployed at the network entrance or the front end of the application server to separate users and resources and enforce access control policies on all traffic. The zero-trust proxy gateway usually includes components such as a security client, a dynamic access control engine, an intelligent security brain, and identity management. It uses technologies such as application proxy, SPA single package authorization, enhanced identity management, and AI, and has functions such as application access proxy, application resource hiding, multi-dimensional authentication of access subjects, dynamic access control, secure data transmission, access log auditing, and API security protection.

[0054] In some embodiments, the first access request may be a request for an application page or resource issued by a user on a browser, and the user also needs to verify the identity information, that is, the first access request received by the proxy gateway may include the user's identity authentication information, and the proxy gateway may decide whether to forward the access request to the corresponding application interface based on the user's identity authentication information.

[0055] In some embodiments, when a user logs in to an application, he needs to enter the corresponding account name, password and other authentication information. After the user logs in successfully, the corresponding page of the application can be displayed. The user clicks links, searches for content, etc. on the page, which will generate an access request. After receiving the corresponding response, he will jump to the new application page.

[0056] Step 102: If the application accessed by the first access request is an application that supports auditing, insert a preset script into the first response to the first access request returned by the application.

[0057] In some embodiments, the preset script can be a pre-configured code stored in the gateway. The script can be designed according to different audit needs. For example, the script can be strengthened to audit the user input content, the audit of the relationship between jump pages, etc. The applications that need to be audited can also be classified, and corresponding identifiers can be set for each type of application, and corresponding scripts can be designed. When the user accesses each type of application, the corresponding script can be issued for audit. Furthermore, a separate script can be designed for a certain application to perform a full quantitative audit of the application.

[0058] In some embodiments, a list of applications that need to be audited can be pre-configured. The applications involved in the list are applications that support auditing. For applications that need to be audited, when the application returns a response, the proxy gateway will insert a preset script in the response. The preset script here can be a recorded script.

[0059] For example, when a user accesses a service through zero trust, after being authenticated and authorized by the zero trust proxy gateway, the zero trust proxy gateway can issue a script for the corresponding response of the application configured with audit capabilities. Since not all applications have audit requirements, the script is issued on demand and after user authentication, and the audit data can be associated with the user's identity information during the application audit process.

[0060] Step 103: forward the first response to the browser, so that the browser obtains the preset script from the first response, and audits the application based on the preset script to obtain audit data.

[0061] In some embodiments, the first response can be forwarded to the corresponding page in the browser. Specifically, the browser can open multiple pages and request access to multiple applications respectively. For the page requesting access to the application that needs to be audited, the proxy gateway can forward the response to the browser. The browser updates the page content according to the response and installs the script to the browser. Only the page can be audited, and other pages opened by the browser will not be audited. In some cases, when a user requests access to a script that needs to be audited, it can first be detected whether the user's browser has the corresponding script installed. If it is installed, the script can be directly enabled without having to repeatedly send the script.

[0062] In some embodiments, the preset script is used to audit the applications that need to be audited. Specifically, it can record the user's operations in the application page, save information such as the pages the user has browsed, and use this information as audit data for later verification of the user's operation behavior.

[0063] The embodiment of the present application obtains the first access request sent by the browser. If the application accessed by the first access request is an application that supports auditing, a preset script is inserted into the first response to the first access request returned by the application, and the first response is forwarded to the browser, so that the browser obtains the preset script from the first response and audits the application based on the preset script. In the embodiment of the present application, when the browser requests to access an application that supports auditing, the proxy gateway sends a script for auditing the application to the browser, and there is no need to modify the business system of the application. The audit of the application is achieved without the user's perception, which improves the user experience. At the same time, the script is only sent when the application requested to access is an application that supports auditing, so as to avoid the browser from occupying too many resources.

[0064] In some embodiments, before forwarding the first response to the browser, the method further includes:

[0065] Cache the static files in the first response;

[0066] Correspondingly, after forwarding the first response to the browser, the method further includes:

[0067] If a second access request for a page corresponding to the static file is received from the browser, a second response is generated based on the static file;

[0068] The second response is sent to the browser.

[0069] In some embodiments, since static files occupy a large amount of the entire data stream, in order to reduce the user's Internet bandwidth occupation caused by browser reporting files and affect the user's office experience, the proxy gateway caches the static files to the local disk when obtaining the response returned by the application. The static files here may include text, images, sounds, flash animations, client scripts, ActiveX controls, Java applets, etc.

[0070] In some embodiments, if the user uses the current browser to issue an access request again, that is, a second access request, and the content accessed by the access request has been cached in the proxy gateway, the proxy gateway may no longer forward the access request to the corresponding application interface or business system, and directly generate a response based on the cached static file and return it to the user. In some cases, when other users use other browsers to request access to application pages or resources through the proxy gateway, if the requested content has been cached in the proxy gateway, a response can also be generated directly based on the cached content and returned to the user.

[0071] Based on the above embodiment, when the proxy gateway forwards the response of the application, it will cache the static files locally. When the user requests the related content again, it can directly generate a response without having to request the application interface again, thereby reducing the occupation of Internet bandwidth by data transmission and the service pressure of the application server, and improving the user's office experience.

[0072] In some embodiments, after caching the static file in the first response, the method further includes:

[0073] Determine whether the page content corresponding to the static file has changed;

[0074] If the page content changes, the static file is updated based on the changed page content.

[0075] In some embodiments, the proxy gateway is allowed to periodically query whether the cached content has changed, for example, whether the page content corresponding to the cached static file has changed, such as changes in image content, changes in text, etc. The proxy gateway can be set to periodically send query requests to the corresponding page to confirm whether the page content corresponding to the cached static file has changed. It can also determine whether the page has changed based on the response information in the response returned by the application server. If it has changed, the relevant application or page is requested to send the response content again to update the static file.

[0076] In some embodiments, the proxy gateway can be set to perform query operations during idle periods to avoid performing queries during busy network periods, such as at night or during lunch breaks. In the case of a large number of static files and large volumes, they can also be replaced in batches.

[0077] Based on the above embodiment, when the page corresponding to the static file changes, the static file is updated in time, and the latest page static file data can be cached without occupying network bandwidth, thereby improving the user's office experience.

[0078] In some embodiments, after updating the static file based on the changed page content, the method further includes:

[0079] The audit data and the updated static file are sent to a preset analysis center; the preset analysis center is used to generate a playback page based on the audit data and the updated static file.

[0080] In some embodiments, the proxy gateway receives the audit data sent by the browser script and forwards it to the analysis center. In some cases, if the static file changes, the updated static file will be sent to the analysis center together. If the static file does not change, only the audit data can be sent to the analysis center. The analysis center here can be a zero-trust analysis center. When the administrator needs to replay the user's operation, the previously recorded data, that is, the audit data, can be obtained in the analysis center through the interface. After deserialization and conversion, these data will be used to generate a web page similar to the recording, thereby reproducing the user's operation. Specifically, the recorded data includes the starting time node, the length of the recorded video, etc. At the same time, a state machine will be maintained inside the system to control the playback speed, progress bar rotation and other functions. The administrator can easily control the playback process. At the same time, combined with the zero-trust authentication mechanism, the recording data is associated with a unified user identity and terminal information.

[0081] Based on the above embodiment, a page is generated through audit data and static files to play back the user's operations, which takes up less space than traditional recorded videos and can achieve the same effect for managers to review user operations.

[0082] Figure 2 A flowchart of an application audit method applied to a browser provided in an embodiment of the present application is provided. Figure 2 , the method comprising:

[0083] Step 201: Send a first access request to a proxy gateway.

[0084] In some embodiments, the first access request sent by the browser may include the object requested to be accessed, such as an application or resource interface, etc., and may also include the user's identity authentication information, such as a user name, password, verification code, etc. The first access request must be verified by the proxy gateway before it can be forwarded to the corresponding interface to obtain a corresponding response.

[0085] Step 202, receiving a first response of the application forwarded by the proxy gateway; if the application accessed by the first access request is an application that supports auditing, the first response includes a preset script inserted by the proxy gateway.

[0086] In some embodiments, the first access request sent by the browser will be forwarded by the proxy gateway to the application or business system, and then the application or business system will return a corresponding first response to the proxy gateway, and then the proxy gateway will forward the first response to the browser. If the application requested for access in step 201 is an application that needs to be audited, the first response will also include a preset script inserted by the proxy gateway, and the browser can record the user's operations and related pages for the application based on the script.

[0087] In some embodiments, if the browser has installed the script, the first response may also include an instruction to enable the script, so as to enable the recording script separately for the application that needs to be audited.

[0088] Step 203: If the preset script is inserted into the first response, audit the application accessed by the first access request based on the preset script.

[0089] In some embodiments, if a preset script or an instruction to start a script is inserted in the first response, the browser audits the application accessed by the first access request based on the preset script, obtains audit data, and uploads the audit data to the proxy gateway, which then reports the audit data to the analysis center.

[0090] Based on the above embodiment, a response containing a preset script or a response containing a script start instruction will only be received when the browser requests access to an application that needs to be audited. Audits can be performed on specific applications without the need to modify the business system. Users are unaware of this and normal network access is not affected.

[0091] In some embodiments, auditing the application accessed by the first access request based on the preset script includes:

[0092] When the page content of the audit-supported application changes, generating a snapshot of the corresponding page content;

[0093] Recording operation information of the browser when the page content of the audit-supported application changes.

[0094] In some embodiments, in order to accurately reproduce the state of the web page, a snapshot of the current DOM structure is taken at each time, and the hierarchical structure, attributes, styles and other information of the DOM elements are recorded and saved. After the page jumps, new recorded data needs to be appended to the original recorded data. Due to user operations, such as clicking a link, submitting a form, etc., the page jumps. In order to avoid the recorded data not being reported and to ensure the integrity of the recorded data, an asynchronous background submission method can be used for processing.

[0095] In some embodiments, since users may perform some meaningless operations when browsing pages, such as randomly clicking the mouse, tapping the keyboard, etc., only the operation information corresponding to the operation that causes the page content to change can be recorded, which may specifically include the text information of the clicked element and its target, the page it is located on, and the time point, and the data is reported for playback display and jump. Because it is not convenient to parse the specific location and display information in the recorded data, it is necessary to perform real-time analysis when the user operates. The front end has a mechanism for events to bubble up, which can trigger events of superior elements. Therefore, the element clicked by the user is not the element that is really to be triggered, but may be his superior. The accuracy of the audit is ensured by element type, content matching, attribute field, size, hierarchical distance and related relationships.

[0096] Based on the above embodiment, by generating a snapshot of the page and recording the user's operation information, the page can be accurately generated based on this information when playback is needed to restore the page content and the user's actual operation.

[0097] In some embodiments, after recording the operation information of the browser when the page content of the audit-supported application changes, the method further includes:

[0098] Saving the snapshot and the operation information into an event stream;

[0099] The event stream is associated with the user's identity information to obtain audit data.

[0100] In some embodiments, in order to reduce the size of the event stream, compression algorithms and techniques can be used to encode event types and use relative coordinates to represent the mouse position. At the same time, on the user side, packAPI is used to compress event data for reporting, thereby reducing the size of the reported data and improving the transmission efficiency of the report. Correspondingly, on the proxy gateway side, a node middleware can be pre-placed to decompress the event data.

[0101] In some embodiments, the user's identity information, such as identity authentication information, can be added to the event stream to associate the user's operations and browsed pages with the user's identity, facilitating unified identity management in subsequent playback.

[0102] Based on the above embodiment, by associating user identity information with event streams, auditing can be performed based on user identity, making it easier for management personnel to trace back based on identity.

[0103] Figure 3 A flowchart of another application audit method provided in the embodiment of the present application is provided in Figure 3 , the method comprising:

[0104] 1. Configure the application that needs to be audited.

[0105] The Zero Trust Control Center pre-configures the applications that need to be audited for the Zero Trust Proxy Gateway, so that when the Zero Trust Proxy Gateway receives an access request from a browser, it can determine whether a script needs to be inserted into its response.

[0106] 2. Application of user access audit.

[0107] The user initiates an access request. If the application requesting access needs to be audited, a preset script will be received when the response is received.

[0108] 3. The proxy accesses the service and returns the response content.

[0109] The zero-trust proxy gateway forwards the browser's request to the corresponding business system and receives the response returned by the business system.

[0110] 4. Cache static files to the gateway (if the cached data changes, upload the changed data to the Zero Trust Analysis Center).

[0111] Here, the zero-trust proxy gateway can query whether the cached data has changed.

[0112] 5. Inject the recording script.

[0113] The Zero Trust Proxy Gateway forwards the response and inserts the preset recording script.

[0114] 6. Record and report operation data.

[0115] The script records the pages browsed and operations performed by users, and reports the corresponding data to the zero-trust proxy gateway.

[0116] 7. Upload recorded data, operation logs, and static files to the Zero Trust Analysis Center (static files are only uploaded when they change).

[0117] The zero-trust proxy gateway reports the audit data (including recording data, operation logs, and user identity information) to the zero-trust analysis center. If the static files change, the changed static files will be uploaded as well.

[0118] In some embodiments, the method in the above embodiments can also be implemented by installing a browser plug-in, without the need for a proxy gateway to send scripts, and by modifying the business system to send scripts to the browser through the business system.

[0119] Based on the above embodiments, the following technical effects can be achieved:

[0120] (1) No user awareness: It is implemented purely in the browser and does not rely on the client or browser extensions. Users do not need to install additional software or plug-ins. Users can automatically record without additional operation confirmation when accessing the application. The performance impact is small and will not have a perceptible performance impact on the normal use of the application, such as: it does not affect the page loading speed, does not block the user's normal mouse clicks, and has reasonable memory and CPU usage.

[0121] (2) No business transformation required: The business system does not need any transformation. By sending scripts to the user's browser through the zero-trust proxy gateway, business audit capabilities can be achieved. The recording function can be turned on or off according to the configuration, which is convenient for control according to actual needs.

[0122] (3) Visualization of audit content: Administrators can replay the corresponding recorded content in the console according to the application and user selection. The playback effect is consistent with the visual effect actually used by the end user. The icons of the user's main operations are marked at the corresponding position of the progress bar. The user's main operation list can be displayed. For example, click the B button on page A, and the playback progress will jump synchronously after clicking. The playback can be paused, played, the progress can be adjusted, the speed can be set, and the non-action part can be skipped. The page display security must be guaranteed during playback to prevent the content script of the recorded page from executing dangerous scripts.

[0123] (4) Low storage space usage: The video is not actually recorded, but data merging and compression are used to make the storage space occupied by the recorded data controllable. The appropriate data storage format is used to support convenient and fast retrieval and analysis of the recorded data.

[0124] (5) Identity-based tracing: Based on the concept of zero-trust identity continuous verification, it can ensure that audit records contain identity information, allowing administrators to search based on user name, organizational structure, role, time, location and other information, completely solving the problem of business audit without identity and difficult tracing in the past. It also has good business compatibility: it is compatible with mainstream front-end frameworks and naturally supports all operating systems. It does not need to adapt to operating systems one by one (such as Windows, Mac, Linux, iOS, Android, etc.) like client solutions, and has strong business availability.

[0125] (6) Business value can grow: While solving the audit and traceability needs of security personnel related to data security, it can also be used in scenarios such as business usage analysis, user access experience and quality analysis, and business value can grow sustainably.

[0126] The embodiment of the present application also provides an application auditing device, which corresponds to the above-mentioned application auditing method applied to the proxy gateway, and each step in the above-mentioned application auditing method embodiment is also fully applicable to the embodiment of the present device.

[0127] The application auditing device comprises:

[0128] A first receiving module, used for obtaining a first access request sent by a browser;

[0129] A first processing module, configured to insert a preset script into a first response to the first access request returned by the application if the application accessed by the first access request is an application that supports auditing;

[0130] The first sending module is used to forward the first response to the browser, so that the browser obtains the preset script from the first response and audits the application based on the preset script to obtain audit data.

[0131] The first processing module is further used to cache static files in the first response.

[0132] The first sending module is further configured to generate a second response based on the static file if a second access request for a page corresponding to the static file is received from the browser; and send the second response to the browser.

[0133] The first processing module is further used to determine whether the page content corresponding to the static file has changed; if the page content has changed, update the static file based on the changed page content.

[0134] The first sending module is further used to send the audit data and the updated static file to a preset analysis center; the preset analysis center is used to generate a playback page based on the audit data and the updated static file.

[0135] The embodiment of the present application also provides an application auditing device, which corresponds to the above-mentioned application auditing method applied to the browser, and each step in the above-mentioned application auditing method embodiment is also fully applicable to the embodiment of the present device.

[0136] The application audit module includes:

[0137] A second sending module, used for sending a first access request to the proxy gateway;

[0138] A second receiving module is used to receive a first response of the application forwarded by the proxy gateway; if the application accessed by the first access request is an application that supports auditing, the first response includes a preset script inserted by the proxy gateway;

[0139] The second processing module is configured to audit the application accessed by the first access request based on the preset script if the preset script is inserted into the first response.

[0140] The second processing module is further used to generate a snapshot of the corresponding page content when the page content of the audit-supported application changes; and record the operation information of the browser when the page content of the audit-supported application changes.

[0141] The second processing module is further used to save the snapshot and the operation information into an event stream; and associate the event stream with the user's identity information to obtain audit data.

[0142] In actual application, the first receiving module, the first processing module and the first sending module can be implemented by a processor in an application audit device corresponding to the application audit method applied to the proxy gateway, and the second sending module, the second receiving module and the second processing module can be implemented by a processor in an application audit device corresponding to the application audit method applied to the browser. Of course, the processor needs to run the computer program in the memory to realize its function.

[0143] It should be noted that: when the device provided in the above embodiment is applied, only the division of the above program modules is used as an example. In actual application, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the device and method embodiments provided in the above embodiment belong to the same concept and will not be repeated here.

[0144] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiment of the present application, the embodiment of the present application also provides an electronic device, for example, the electronic device can be a proxy gateway. Figure 4 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 4 As shown, the electronic device includes:

[0145] Communication interface 401, capable of exchanging information with other devices such as network devices;

[0146] The processor 402 is connected to the communication interface 401 to implement information exchange with other devices and is used to execute the method provided by one or more technical solutions when running a computer program. The computer program is stored in the memory 403.

[0147] Of course, in actual application, the various components in the electronic device are coupled together through the bus system 404. It can be understood that the bus system 404 is used to realize the connection and communication between these components. In addition to the data bus, the bus system also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 4 Various buses are labeled as bus system 404 .

[0148] The memory 403 in the embodiment of the present application is used to store various types of data to support the operation of the computer device. Examples of such data include: any computer program used to operate on the electronic device.

[0149] It can be understood that the memory 403 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), direct memory bus random access memory (DRRAM). The memory described in the embodiments of the present application is intended to include but is not limited to these and any other suitable types of memory.

[0150] The method disclosed in the above embodiment of the present application can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software. The above processor may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in a memory, and the processor reads the program in the memory and completes the steps of the above method in combination with its hardware.

[0151] Optionally, when the processor 402 executes the program, it implements the corresponding processes implemented by the computer device in each method of the embodiments of the present application, which will not be described here for the sake of brevity.

[0152] In an exemplary embodiment, the present application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a first memory storing a computer program, and the computer program can be executed by a processor of a computer device to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0153] In the several embodiments provided in the present application, it should be understood that the disclosed devices, computer equipment and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0154] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0155] In addition, all functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may be a separate unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0156] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium, which, when executed, executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.

[0157] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present application can be essentially or partly embodied in the form of a software product that contributes to the relevant technology. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.

[0158] In an exemplary embodiment, the embodiment of the present application also provides a computer program product, including a computer program, which can be executed by the processor 402 of the electronic device to complete the steps described in the application audit method applied to the proxy gateway or the application audit method applied to the browser in the embodiment of the present application.

[0159] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0160] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0161] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An application audit method, applied to a proxy gateway, characterized in that: The method comprises: Get the first access request sent by the browser; If the application accessed by the first access request is an application that supports auditing, inserting a preset script into a first response to the first access request returned by the application; The first response is forwarded to the browser, so that the browser obtains the preset script from the first response, and audits the application based on the preset script to obtain audit data.

2. The method according to claim 1, characterized in that: Before forwarding the first response to the browser, the method further includes: Cache the static files in the first response; Correspondingly, after forwarding the first response to the browser, the method further includes: If a second access request for a page corresponding to the static file is received from the browser, a second response is generated based on the static file; The second response is sent to the browser.

3. The method according to claim 2, characterized in that: After caching the static file in the first response, the method further includes: Determine whether the page content corresponding to the static file has changed; If the page content changes, the static file is updated based on the changed page content.

4. The method according to claim 3, characterized in that: After updating the static file based on the changed page content, the method further includes: The audit data and the updated static file are sent to a preset analysis center; the preset analysis center is used to generate a playback page based on the audit data and the updated static file.

5. An application audit method, applied to a browser, characterized in that: The method comprises: Sending a first access request to the proxy gateway; receiving a first response of the application forwarded by the proxy gateway; if the application accessed by the first access request is an application that supports auditing, the first response includes a preset script inserted by the proxy gateway; If the preset script is inserted into the first response, the application accessed by the first access request is audited based on the preset script.

6. The method according to claim 5, characterized in that: The auditing the application accessed by the first access request based on the preset script includes: When the page content of the audit-supported application changes, generating a snapshot of the corresponding page content; Recording operation information of the browser when the page content of the audit-supported application changes.

7. The method according to claim 6, characterized in that: After recording the operation information of the browser when the page content of the audit-supported application changes, the method further includes: Saving the snapshot and the operation information into an event stream; The event stream is associated with the user's identity information to obtain audit data.

8. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, it implements the steps of the application audit method described in any one of claims 1 to 4 or the application audit method described in any one of claims 5 to 7.

9. An electronic device, characterized in that: include: A processor and a memory for storing a computer program that can be executed on the processor, wherein: The processor is used to execute the steps of the application audit method described in any one of claims 1 to 4 or the application audit method described in any one of claims 5 to 7 when running a computer program.

10. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the application audit method described in any one of claims 1 to 4 or the application audit method described in any one of claims 5 to 7 are implemented.