Domain name filtering method and device, equipment, medium and program product

By building a matching rule tree for domain name filtering, the resource consumption and performance reduction caused by character matching methods in the existing technology are solved, and efficient and fast domain name filtering is achieved.

CN119945750APending Publication Date: 2025-05-06JIANGSU BOZHI SOFTWARE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510008500.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, domain name filtering mainly adopts character matching method based on filtering rules, resulting in a large number of matches and a large number of system resources, which reduces the performance of domain name filtering.

Method used

By building a matching rule tree, the domain name filtering requirements of the domain name to be matched are determined, and the matching type is matched with the corresponding matching rule tree, thereby achieving rapid filtering of domain names.

Benefits of technology

Improve the efficiency and performance of domain name filtering, save the resources required for filtering, and maintain efficient matching while the number of rules increases.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945750A_ABST
    Figure CN119945750A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a domain name filtering method and device, equipment, a medium and a program product. The method comprises the following steps: acquiring a domain name to be matched; determining a domain name matching type corresponding to the to-be-matched domain name according to the domain name filtering requirement of the to-be-matched domain name; the domain name to be matched is matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, the matching rule tree is generated based on a matching rule corresponding to the domain name matching type, node information of each layer in the matching rule tree is stored through an array, and node information of each layer in the matching rule tree is stored through the array. The array comprises target values of all characters capable of serving as domain names. According to the technical scheme provided by the invention, the domain name filtering speed is increased through the matching rule tree, the domain name filtering performance is improved, and the resource quantity consumed by domain name filtering is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing, and in particular to a domain name filtering method, device, equipment, medium and program product. Background Art

[0002] Domain filtering is a network security technology that protects users from malicious websites and unsafe content by limiting access to specific domain names. This filtering is essential to prevent phishing, malware spread, and protect user privacy.

[0003] In the prior art, domain name filtering mainly adopts character matching based on filtering rules to filter domain names. However, the character matching method requires single characters to be judged one by one, and the number of matching times is large, which requires a large amount of system resources and reduces the domain name filtering performance. If the number of filtering rules to be matched increases, the impact on the domain name filtering performance will be greater. Summary of the invention

[0004] The technical solution of the present invention discloses a domain name filtering method, device, equipment, medium and program product. Through the technical solution of the embodiment of the present invention, the efficiency of domain name filtering can be improved, the domain name filtering performance can be enhanced, and the resources required for filtering can be saved.

[0005] In a first aspect, an embodiment of the present invention provides a domain name filtering method, including:

[0006] Get the domain name to be matched;

[0007] Determine a domain name matching type corresponding to the domain name to be matched according to a domain name filtering requirement of the domain name to be matched;

[0008] The domain name to be matched is matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

[0009] In a second aspect, an embodiment of the present invention provides a domain name filtering device, including:

[0010] A domain name acquisition module is used to obtain the domain name to be matched;

[0011] A type determination module, used to determine the domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirement of the domain name to be matched;

[0012] A domain name matching module is used to match the domain name to be matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

[0013] In a third aspect, an embodiment of the present invention provides an electronic device, the electronic device comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform any domain name filtering method according to any one of the embodiments of the present invention.

[0017] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement any domain name filtering method according to any one of the embodiments of the present invention when executed.

[0018] In a fifth aspect, an embodiment of the present invention provides a computer program product, the computer program product comprising a computer program, and the computer program, when executed by a processor, implements the domain name filtering method according to any one of the embodiments of the present invention.

[0019] The technical solution of the embodiment of the present invention provides a domain name filtering method, device, equipment, medium and program product, the method comprising: obtaining a domain name to be matched; determining a domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirements of the domain name to be matched; matching the domain name to be matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names. The embodiment of the present invention can achieve rapid filtering of domain names by adopting a rule matching tree, improve the efficiency and performance of domain name filtering, and save resources required for domain name filtering, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0021] Figure 1 A flowchart of a domain name filtering method provided in Embodiment 1 of the present invention;

[0022] Figure 2 A schematic diagram of a matching rule tree for prefix matching provided by an embodiment of the present invention;

[0023] Figure 3 A schematic diagram of a matching rule tree for suffix matching provided in an embodiment of the present invention;

[0024] Figure 4 A schematic diagram of a matching rule tree for intermediate separation matching provided by an embodiment of the present invention;

[0025] Figure 5 A schematic diagram of a matching rule tree for intermediate fuzzy matching provided by an embodiment of the present invention;

[0026] Figure 6 Schematic diagram of the front and back matching rule tree provided by the embodiment of the present invention

[0027] Figure 7 A flowchart of a domain name filtering method provided in Embodiment 2 of the present invention;

[0028] Figure 8 A schematic diagram of the structure of a domain name filtering device provided in Embodiment 3 of the present invention;

[0029] Fig. 9 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. DETAILED DESCRIPTION

[0030] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0032] It should be noted that the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the technical solution of the present disclosure are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0033] Embodiment 1

[0034] Figure 1 A flowchart of a domain name filtering method provided in Embodiment 1 of the present invention is specifically applicable to filtering or matching Internet domain names. The method in the embodiment of the present invention can be executed by a domain name filtering device, which can be implemented by software and / or hardware and configured in a computer or server.

[0035] like Figure 1 As shown, including:

[0036] Step 110: Obtain the domain name to be matched.

[0037] The domain name is composed of various characters, numbers and fields, which are used to access specific web pages. Furthermore, the domain name can include a domain prefix, a domain suffix and a middle field, which are determined by the position of the field in the domain name. For example, for www.abcd.com.cn, the domain prefix can be "www." The domain suffix can be: ".com.cn" and the middle field is "abcd".

[0038] Optionally, step 110 includes: obtaining a network access request, and determining a domain name to be matched according to the network access request.

[0039] Specifically, the network access request includes the domain name to be accessed, that is, the domain name to be matched. Then, the method of the embodiment of the present invention can be used to determine whether the domain name to be matched includes the target field. If it does, the domain name is identified as a dangerous domain name and needs to be filtered.

[0040] Step 120: Determine the domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirement of the domain name to be matched.

[0041] The domain name filtering requirement is the requirement corresponding to this domain name filtering task. The domain name filtering requirement can be the requirement to filter a specific location of the domain name. For example, whether the domain name prefix, domain name suffix, and middle field of the domain name include the target field. The domain name matching type represents different ways of matching domain names, which can include prefix matching, suffix matching, middle separation matching, middle fuzzy matching, and matching domain name prefix and domain name suffix.

[0042] Step 130: Match the domain name to be matched with the matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

[0043] Wherein, the matching rule tree is generated based on the matching rule corresponding to the domain name matching type. The matching rule includes a rule character, wherein the rule character represents the character to be matched for the rule matching, and is used to determine whether the character to be matched is included in the domain name to be matched. The domain name matching result is that the domain name to be matched satisfies the matching rule or does not satisfy the matching rule. Further, the order of each node in the node path of the matching rule tree is determined by the arrangement order of the characters to be matched in the matching rule. For example, if the matching rule includes "abc and abd", the node path is root node-abc and root node-abd. Further, the child nodes with the same parent node constitute an array. For example, in the above example, the parent nodes of "c and d" are both b, then c and d constitute the array of the next layer of node b. The node information can be the target value of the character. Wherein, the target value represents the characteristic identifier of the character represented by the node, such as a hash value. Optionally, the node information also includes node attributes. The node attributes corresponding to the end character in the matching rule include an end identifier. The end identifier is used to indicate that the node is an end node.

[0044] Specifically, the node information of each layer of the matching rule tree is stored in an array. The node information of each layer is used to determine whether the matching field of the domain name to be matched hits a node of the layer. The domain name is composed of characters, usually including data, letters and special symbols. Therefore, the target value of the characters to be matched can be pre-stored in the array. Then, in the matching stage, the matching value of the characters in the domain name to be matched can be determined first, and then the matching value can be matched with the target value to determine whether the match is successful.

[0045] Exemplarily, the target value and the value to be matched may be hash values. The hash value of the character is calculated by a hash function. By matching the target value and the value to be matched, it is determined whether the domain name to be matched matches the filtering rule, which can improve the matching performance.

[0046] Optionally, the matching rule tree corresponding to the domain name matching type includes:

[0047] If the domain name matching type includes prefix matching, a prefix matching rule tree is formed according to the character sequence in the prefix matching rule. For example, for the prefix matching rule api, the node sequence of the matching rule tree is root-api, where root is the root node, a blank node can be used as the root node, and i is the end node.

[0048] The prefix matching is to perform string matching on the domain name prefix of the domain name, and the prefix matching rule includes a target string, which is used to determine whether the domain name prefix of the domain name includes the target string.

[0049] Exemplarily, the prefix matching order is to match one by one starting from the first character of the domain name. Therefore, a prefix matching rule tree can be constructed according to a preset character order.

[0050] Figure 2 A schematic diagram of a matching rule tree for prefix matching provided in an embodiment of the present invention, wherein the domain name to be matched is api.taoxiao.com. root is the root node, and the rule to be matched is to determine whether the domain name to be matched includes the api field. It should be noted that since the matching rule represents a string, it is necessary to specify the end mark of the string, and the node containing the end mark represents the last character of the target string of the matching rule. When the character is matched, the matching rule ends. Specifically, for the domain name to be matched, it will be determined whether a exists in the child node of the root node. If so, it is necessary to determine whether p exists in the child node of a. If so, it is necessary to determine whether i exists in the child node of p. If so, it means that the match is successful. Among them, the white node does not contain the end mark, and the black node contains the end mark. Further, if the domain name to be matched is: apb.taoxiao.com, then after finding p in the second-layer node, the b character is not found in the child node of the p node, and the p node is not the end node, so, in all the matching rules, no rule with apb as the prefix is ​​found, and the match fails.

[0051] If the domain name matching type includes suffix matching, the suffix matching rule tree is constructed according to the reverse order of the characters in the suffix matching rule. The domain name suffix matching is only matched when a domain name ends with a certain fixed string. For example, if the suffix matching rule is .com.cn, the node order of the matching rule tree is root-nc-.-moc.

[0052] The suffix matching is to perform string matching on the domain name suffix of the domain name, and the suffix matching rule includes a target string, which is used to determine whether the domain name suffix of the domain name includes the target string.

[0053] Figure 3 A schematic diagram of a matching rule tree for suffix matching provided in an embodiment of the present invention, wherein the domain name to be matched is http: / / xxj ing.gov. First, the domain name to be matched is sorted in reverse order to obtain vog.gnijxx / / :ptth. root is the root node, and the rule to be matched is to determine whether the domain name to be matched includes the com.cn or .gov field. White nodes do not contain an end mark, and black nodes contain an end mark. Specifically, the hierarchical order of each node of the same rule in the suffix matching in the tree is the reverse order of the order of the target string in the matching rule, that is, the matching method is to match characters from the last character of the domain name to be matched, in sequence. For the domain name to be matched after reverse sorting, it will be determined whether v exists in the child node of the root node. Since there is v in the child node of root, the o node is then found in the child node of the v node, the g node is found in the child node of the o node, and finally the dot is found in the child node of the g node. Further, the dot node is the end mark, and the match is successful.

[0054] If the domain name matching type includes middle separation matching, a target string of the middle separation matching rule is determined according to the separator in the middle separation matching rule, and a middle separation matching rule tree is constructed according to the target string.

[0055] Among them, the middle separation match is to match the string between the delimiters of the domain name, and the middle separation match rule includes a target string, which is used to determine whether the target string is included between the delimiters of the domain name. Specifically, in the domain name, delimiters such as periods are often included to separate multiple strings. The child nodes of the matching rule tree of the middle separation match can represent the string composition, and the string includes at least one character. For example, the nodes of the matching rule tree are the strings separated by periods in the matching rule. If the matching rule is .edu.gov, the order of the nodes that make up the matching rule tree is root-edu-gov, where gov is the end node.

[0056] Figure 4A schematic diagram of a matching rule tree for intermediate separation matching provided in an embodiment of the present invention. The domain name to be matched is: www.xx.edu.gov.com, and the matching rule is to determine whether the domain name to be matched includes the .edu.gov. or .kunlun.com. field. The domain name to be matched is separated based on the period, and multiple character strings are obtained, including: www, xx, edu, gov, and com. The gov node and the com node are end nodes. Specifically, after inputting the domain name to be matched, first search for www from the child nodes of the root node. Since www does not exist in the child nodes of the root node, continue to search for xx from the child nodes of the root node. Since xx does not exist in the child nodes of the root node, continue to search for edu from the child nodes of the root node. Since edu exists in the child nodes of the root node, continue to search for gov from the child nodes of the edu node. Since gov exists in the child nodes of the edu node, and gov is the end node, the domain name to be matched ".edu.gov." is matched successfully.

[0057] Assume that the domain name to be matched is http: / / axx.edu.org.gov.cn First, we match the domain name based on the dot separator to get multiple strings, including: http: / / axx , edu, gov and cn. First, search for the child nodes of the root node. http: / / axx Since the root node does not exist in the child nodes http: / / axx , then continue to query edu from the child nodes of the root node. Since edu exists in the child nodes of the root node, continue to query org from the child nodes of edu. Since the child nodes of edu do not contain org, return to the root node. Search gov from the child nodes of the root node. Since gov does not exist in the child nodes of the root node, continue to search cn from the child nodes of the root node. Since cn does not exist in the child nodes of the root node, the matching ends. Therefore, it is determined that the matching of the domain name to be matched fails.

[0058] It should be noted that if a string does not match successfully and the string is not the end string of the domain name to be matched, the next string will be matched starting from the root node. In this matching method, the maximum number of matches is usually the number of words separated by dots in the domain name. Since the number of single matches in a domain name is usually very small, even if the number of intermediate separation matching rules is increased, it will not have a significant impact on the matching performance.

[0059] If the domain name matching type includes intermediate fuzzy matching, an intermediate fuzzy matching rule tree is constructed according to the character sequence corresponding to the wildcards in the intermediate fuzzy matching rule.

[0060] The character string between the wildcards of the intermediate fuzzy matching rule is the target character string. The wildcard can represent any character. For example, the wildcard can be *. The intermediate fuzzy matching is used to determine whether the domain name to be matched contains the target character string of the matching rule. Assume that the intermediate fuzzy matching rule is *video*, and the node order of the matching rule tree is root-video, where o is the end node.

[0061] Figure 5 A schematic diagram of a matching rule tree for intermediate fuzzy matching provided by an embodiment of the present invention, wherein http: / / 3mvideo.org is a domain name to be matched, and the matching rule is to determine whether the domain name to be matched includes *xiaobi* or *video*, where * is a wildcard. Specifically, first search from the child nodes of the root node to see whether h is included. Since the child nodes of the root node do not include h, and the currently matched node is not an end node, continue to search from the child nodes of the root node to see whether t is included. Since the child nodes of the root node do not include t, and the currently matched node is not an end node, continue to search for "p: / / 3mvideo.org" in a similar manner until v is found from the child nodes of the root node. Then, search from the child nodes containing v to see whether i exists. Since the child nodes of v include i, continue to search from the child nodes of i to see whether d exists. In a similar manner, query the d node, e node, and o node in sequence, wherein the o node is an end node. Therefore, *video* is matched successfully.

[0062] If the domain name matching type includes matching domain name prefixes and domain name suffixes, the prefix matching rule tree and the suffix matching rule tree are nested according to the prefix matching rule and the suffix matching rule to obtain the front and back matching rule tree. The front and back matching rule tree can match the domain name prefix while also meeting the matching requirements of the domain name suffix. Assume that the prefix and suffix matching rules include www.**.cn and http**.gov. First, the characters before ** are used to form a prefix matching rule tree. Then, the end node points to the reverse order of the string after ** to form a suffix matching rule tree.

[0063] Specifically, in order to increase the efficiency and strictness of successful matching, the domain name prefix and domain name suffix of the domain name can be matched at the same time. For example, a prefix matching tree can be configured below the root node, and a suffix matching tree can be configured after the end node of the prefix matching tree (the node containing the end identifier).

[0064] The matching rule corresponding to the front and back matching rule tree may be that the domain name prefix and the domain name suffix are both corresponding target strings. For example, the matching rule may be: "www.**.cn", that is, the matching rule is to determine whether the domain name prefix of the domain name is "www." and whether the domain name suffix is ​​".cn".

[0065] Figure 6 A schematic diagram of a front-and-backward matching rule tree provided for an embodiment of the present invention, wherein the domain name to be matched is www.xiaofeng.cn. First, the first w is found from the child nodes of the root node, and then the second w is found in the child nodes of the first w, and then the third w is found in the child nodes of the second w. The child nodes of the third w include a period. Since the node where the period is located represents the end node, it is determined that "www" is matched successfully. Since the node pointer of the end node of the prefix matching rule tree points to the root node of the suffix matching rule tree, suffix matching is performed. The suffixes of the domain name to be matched are sorted in reverse order, and n is found from the child nodes of the root node of the suffix matching rule tree. Then c is found from the child nodes of n. Then, a period is found in the child nodes of c. Since the node where the period is located represents the end node, it is determined that "nc" is matched successfully. Therefore, for the domain name to be matched, both the prefix match and the suffix match are successful.

[0066] Assume that the domain name to be matched is www.xiaofeng.org First, find the first w from the child node of the root node, then find the second w in the child node of the first w, and then find the third w in the child node of the second w. The child node of the third w includes a period. Since the node where the period is located represents the end node, it is determined that "www" matches successfully. Since the node pointer of the end node of the prefix matching rule tree points to the root node of the suffix matching rule tree, suffix matching is performed. The suffixes of the domain name to be matched are sorted in reverse order. Since g does not exist in the child nodes of the root node, the character x after the period is searched from the child nodes of the root node of the suffix matching rule tree. Since x does not exist in the child nodes of the root node, it is determined that the match failed.

[0067] Optionally, for an exact match rule, a rule set may be formed according to the hash value of the exact match rule. The rule set is queried according to the hash value of the rule to be matched. If the rule set contains the same hash value as the rule to be matched, the rule is determined to be matched successfully, otherwise, the rule is determined to be matched unsuccessfully.

[0068] The embodiment of the present invention organizes and uses the rule tree in a variety of ways, including tree nesting, node jumping and string reversal, etc., to greatly improve the matching performance when there are many filtering rules and many domain names to be matched. Through tree search, it is possible to quickly determine whether the match is successful, avoiding the situation where the matching performance slows down as the number of rules increases.

[0069] The technical solution of the embodiment of the present invention provides a domain name filtering method. The method includes: obtaining a domain name to be matched; determining a domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirements of the domain name to be matched; matching the domain name to be matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names. The embodiment of the present invention can achieve rapid filtering of domain names by adopting a rule matching tree, improve the efficiency and performance of domain name filtering, and save resources required for domain name filtering.

[0070] Embodiment 2

[0071] Figure 7 This is a flow chart of a domain name filtering method provided in Embodiment 2 of the present invention. Based on the above embodiments, this method further defines a method for obtaining a domain name matching result.

[0072] like Figure 7 As shown, including:

[0073] Step 210: Obtain the domain name to be matched.

[0074] Step 220: Determine the domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirement of the domain name to be matched.

[0075] Step 230: Determine a value to be matched according to the characters to be matched in the domain name to be matched.

[0076] Specifically, the to-be-matched value of the to-be-matched character may be determined by, for example, calculating a hash value.

[0077] Step 240: query the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the to-be-matched value to obtain a domain name matching result.

[0078] Furthermore, the value to be matched is matched with the target value in the array to be matched. If the match is successful, it means that the domain name to be matched contains the target characters corresponding to the matching rule, and the match is successful.

[0079] Optionally, step 240 includes:

[0080] Determine the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the node pointer; match the to-be-matched value with the target value in the to-be-matched array to obtain a domain name matching result.

[0081] The node pointer of the character in the array of this layer points to the array to be matched and the root node of the next layer of the matching rule tree. For example, if the matching rule is "abe and ac", the node pointer of a points to the array including b and c, and the node pointer of b points to the array including e in the next layer. The node jump object is determined according to the matching result, node pointer and domain name matching type of the current node. The node jump object includes the child node of the current node or the root node of the rule tree.

[0082] Optionally, the node pointer includes a forward pointer and a backward pointer. The forward pointer can be a pointer of the current node pointing to the root node of the matching rule tree. The backward pointer can be a pointer of the current node pointing to the child node in the next layer array in the matching rule tree. For example, the forward pointer represents the array address of the root node of the current node. The backward pointer represents the array identifier of the child node of the current node. The array identifier includes the array address corresponding to the child node and the array position of the child node.

[0083] Optionally, matching the to-be-matched value with a target value in the to-be-matched array to obtain a domain name matching result includes:

[0084] The to-be-matched value of the to-be-matched domain name is matched with the target value in the to-be-matched array; if the to-be-matched characters of the to-be-matched domain name are all matched to the corresponding target value, then the domain name matching result of the to-be-matched domain name is determined to be a successful match.

[0085] Specifically, each time a match is made, it is necessary to calculate the value to be matched based on the characters to be matched, and then query whether the value to be matched is included in each target value of the array to be matched. If it is included, the match is successful. It should be noted that, taking prefix matching as an example, only one character can be matched each time, but the string of the matching rule is a plurality of continuous characters. Therefore, it is necessary to match layer by layer according to the arrays of each layer of the matching rule tree. When all the characters to be matched are matched to the corresponding target values, it means that the match is successful.

[0086] For example, if the matching rule includes two strings "abc" or "adc", and the domain name to be matched is abe, if the character a is matched successfully, the node pointer of a will point to the array including "b and d" (the content of the array is composed of the second character in the matching rule). Then it is determined whether the to-be-matched value of the character b in the domain name to be matched exists in the array of "b and d". If so, it means that b is also matched successfully. Next, the character b will point to the array including c (the content of the array is composed of the third character in the matching rule), and then it is determined whether the character e of the domain name to be matched exists in the array including c. Since the to-be-matched array corresponding to the child node of the character b does not exist, e fails to match, and abe does not meet the matching rule.

[0087] Optionally, matching the to-be-matched value with a target value in the to-be-matched array to obtain a domain name matching result includes:

[0088] The to-be-matched value of the to-be-matched domain name is matched with a target value in the to-be-matched array.

[0089] For the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched of the target value is not matched, if the character to be matched is not the ending character, then the next character of the character to be matched is matched starting from the root node of the matching rule tree corresponding to the domain name matching type, wherein the next character includes at least one character. For the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched of the target value is not matched, if the character to be matched is the ending character, then the domain name matching result of the domain name to be matched is determined to be a match failure.

[0090] Specifically, for the domain name matching type of middle separation matching or middle fuzzy matching, since there are multiple groups of separators or wildcards, there will be multiple characters to be matched. Starting from the first character to be matched, the first character to be matched is input into the root node. If the matching value of the character to be matched successfully matches the target value, it means that the domain name to be matched hits the matching rule. Otherwise, it is necessary to determine whether the character to be matched is the last ending character. If so, the matching is terminated. If not, the matching work of the next character of the character to be matched is continued until all the characters to be matched are matched.

[0091] If the domain name matching type is prefix matching, suffix matching, or matching a domain name prefix and a domain name suffix at the same time, and the to-be-matched character does not match the corresponding target value, then it is determined that the domain name matching result of the to-be-matched domain name is a matching failure.

[0092] Specifically, for prefix matching, if the to-be-matched value of any character in the domain name prefix does not match the corresponding target value, the match fails. For suffix matching, if the to-be-matched value of any character in the domain name suffix does not match the corresponding target value, the match fails. For matching both the domain name prefix and the domain name suffix, if the to-be-matched value of any character in the domain name prefix or the domain name suffix of the domain name to be matched does not match the corresponding target value, the match fails.

[0093] The embodiment of the present invention provides a domain name filtering method. By using the method of the embodiment of the present invention, the efficiency of domain name filtering can be improved and the matching resources required for domain name filtering can be saved.

[0094] Embodiment 3

[0095] Figure 8 This is a schematic diagram of the structure of a domain name filtering device provided by Embodiment 3 of the present invention. Figure 3 As shown, the device comprises:

[0096] The domain name acquisition module 310 is used to acquire the domain name to be matched.

[0097] The type determination module 320 is used to determine the domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirement of the domain name to be matched.

[0098] The domain name matching module 330 is used to match the domain name to be matched with the matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

[0099] The device of the embodiment of the present invention obtains a domain name to be matched. According to the domain name filtering requirements of the domain name to be matched, the domain name matching type corresponding to the domain name to be matched is determined. The domain name to be matched is matched with the matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, and the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes the state values ​​of all characters that can be used as domain names, and the array identifiers of the characters in the array are determined according to the order of the characters in the array. The array includes the target values ​​of all characters that can be used as domain names. The embodiment of the present invention can achieve rapid filtering of domain names by establishing a rule matching tree, improve the efficiency of domain name filtering, and save resources required for domain name filtering, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes the state values ​​of all characters that can be used as domain names, and the array identifiers of the characters in the array are determined according to the order of the characters in the array. The array includes the target values ​​of all characters that can be used as domain names.

[0100] Optionally, the domain name acquisition module 310 is specifically used to obtain a network access request, and determine a domain name to be matched according to the network access request.

[0101] Optionally, the domain name filtering device further includes a matching rule tree generating module, which is used to generate a matching rule tree.

[0102] The matching rule tree generation module includes:

[0103] The prefix matching rule tree unit is used to construct a prefix matching rule tree according to the character sequence in the prefix matching rule if the domain name matching type includes prefix matching.

[0104] The suffix matching rule tree unit is used to construct a suffix matching rule tree according to the reverse order of characters in the suffix matching rule if the domain name matching type includes suffix matching.

[0105] The middle separation matching rule tree unit is used to determine the target string of the middle separation matching rule according to the separator in the middle separation matching rule if the domain name matching type includes middle separation matching, and to form a middle separation matching rule tree according to the target string.

[0106] The intermediate fuzzy matching rule tree unit is used to construct an intermediate fuzzy matching rule tree according to the character sequence corresponding to the wildcard in the intermediate fuzzy matching rule if the domain name matching type includes intermediate fuzzy matching.

[0107] The front and back matching rule tree unit is used to nest the prefix matching rule tree and the suffix matching rule tree according to the prefix matching rule and the suffix matching rule to obtain the front and back matching rule tree if the domain name matching type includes matching the domain name prefix and the domain name suffix at the same time.

[0108] Optionally, the domain name matching module 330 includes:

[0109] The to-be-matched value determining unit is used to determine the to-be-matched value according to the to-be-matched characters in the to-be-matched domain name.

[0110] The matching unit is used to query the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the to-be-matched value to obtain a domain name matching result.

[0111] The matching unit includes:

[0112] The pointer subunit is used to determine the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the node pointer.

[0113] The matching subunit matches the to-be-matched value with the target value in the to-be-matched array to obtain a domain name matching result.

[0114] The matching subunit is specifically used to match the to-be-matched value of the to-be-matched domain name with the target value in the to-be-matched array. If all the to-be-matched characters of the to-be-matched domain name match the corresponding target value, the domain name matching result of the to-be-matched domain name is determined to be a successful match.

[0115] Optionally, the matching unit further includes:

[0116] The target value determination subunit is used to match the to-be-matched value of the to-be-matched domain name with the target value in the to-be-matched array.

[0117] The first judgment unit is used for, for the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched of the target value is not matched, if the character to be matched is not an ending character, matching the next character of the character to be matched from the root node of the matching rule tree corresponding to the domain name matching type, wherein the next character includes at least one character. For the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched of the target value is not matched, if the character to be matched is an ending character, determining that the domain name matching result of the domain name to be matched is a matching failure.

[0118] The second judgment unit is used to determine that the domain name matching result of the domain name to be matched is a matching failure if the domain name matching type is prefix matching, suffix matching, or matching both the domain name prefix and the domain name suffix, and the character to be matched does not match the corresponding target value.

[0119] The domain name filtering device provided in the embodiment of the present invention can execute the domain name filtering method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0120] Embodiment 4

[0121] Fig. 9 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0122] like Fig. 9 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0123] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0124] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a domain name filtering method.

[0125] In some embodiments, the domain name filtering method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the domain name filtering method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to perform the domain name filtering method in any other appropriate manner (e.g., by means of firmware).

[0126] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0127] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0128] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0129] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0130] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0131] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0132] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0133] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A domain name filtering method, characterized in that: include: Get the domain name to be matched; Determine a domain name matching type corresponding to the domain name to be matched according to a domain name filtering requirement of the domain name to be matched; The domain name to be matched is matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

2. The method according to claim 1, characterized in that The obtaining of the domain name to be matched includes: A network access request is obtained, and a domain name to be matched is determined according to the network access request.

3. The method according to claim 1, characterized in that: The matching rule tree is constructed in the following manner: If the domain name matching type includes prefix matching, a prefix matching rule tree is constructed according to the character sequence in the prefix matching rule; If the domain name matching type includes suffix matching, a suffix matching rule tree is constructed according to the reverse order of characters in the suffix matching rule; If the domain name matching type includes middle separation matching, determining a target string of the middle separation matching rule according to a separator in the middle separation matching rule, and forming a middle separation matching rule tree according to the target string; If the domain name matching type includes intermediate fuzzy matching, then an intermediate fuzzy matching rule tree is constructed according to the character sequence corresponding to the wildcard in the intermediate fuzzy matching rule; If the domain name matching type includes matching a domain name prefix and a domain name suffix, the prefix matching rule tree and the suffix matching rule tree are nested according to the prefix matching rule and the suffix matching rule to obtain a front-back matching rule tree.

4. The method according to claim 1, characterized in that: The matching of the to-be-matched domain name with the matching rule tree corresponding to the domain name matching type to obtain a domain name matching result includes: Determine a value to be matched according to the characters to be matched in the domain name to be matched; The to-be-matched array of the matching rule tree corresponding to the domain name matching type is queried according to the to-be-matched value to obtain a domain name matching result.

5. The method according to claim 4, characterized in that The querying of the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the to-be-matched value to obtain the domain name matching result includes: Determine the to-be-matched array of the matching rule tree corresponding to the domain name matching type according to the node pointer; The to-be-matched value is matched with the target value in the to-be-matched array to obtain a domain name matching result.

6. The method according to claim 5, characterized in that The step of matching the to-be-matched value with the target value in the to-be-matched array to obtain a domain name matching result includes: Matching the to-be-matched value of the to-be-matched domain name with the target value in the to-be-matched array; If all the characters to be matched of the domain name to be matched match the corresponding target values, it is determined that the domain name matching result of the domain name to be matched is a successful match.

7. The method according to claim 5, characterized in that The step of matching the to-be-matched value with the target value in the to-be-matched array to obtain a domain name matching result includes: Matching the to-be-matched value of the to-be-matched domain name with the target value in the to-be-matched array; For the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched that does not match the target value, if the character to be matched is not the end character, matching the next character of the character to be matched starts from the root node of the matching rule tree corresponding to the domain name matching type, wherein the next character includes at least one character; For the domain name matching type being middle separation matching or middle fuzzy matching, and the character to be matched that does not match the target value, if the character to be matched is an end character, determining that the domain name matching result of the domain name to be matched is a matching failure; If the domain name matching type is prefix matching, suffix matching, or matching a domain name prefix and a domain name suffix at the same time, and the to-be-matched character does not match the corresponding target value, then it is determined that the domain name matching result of the to-be-matched domain name is a matching failure.

8. A domain name filtering device, characterized in that: include: A domain name acquisition module is used to obtain the domain name to be matched; A type determination module, used to determine the domain name matching type corresponding to the domain name to be matched according to the domain name filtering requirement of the domain name to be matched; A domain name matching module is used to match the domain name to be matched with a matching rule tree corresponding to the domain name matching type to obtain a domain name matching result, wherein the matching rule tree is generated based on the matching rule corresponding to the domain name matching type, wherein the node information of each layer in the matching rule tree is stored through an array, and the array includes target values ​​of all characters that can be used as domain names.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the domain name filtering method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the domain name filtering method according to any one of claims 1 to 7 when executed.

11. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the computer program implements the domain name filtering method according to any one of claims 1 to 7.