Man-machine identification authentication method and system
By analyzing JavaScript and JA3 fingerprints, and combining verification code authentication, identifying and blocking malicious client requests, the problem of difficulty in effectively identifying and resisting complex automation attacks in the existing technology is solved, and the security and stability of web applications are significantly improved.
Patent Information
- Application Number
- CN202510092708.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-13
AI Technical Summary
Existing network security products are difficult to effectively identify and resist complex automation attacks, resulting in the limitation of the security of web applications and a high false alarm rate.
By analyzing JavaScript fingerprint and JA3 fingerprint, identifying tool client traffic, and performing secondary authentication on requests, using the traffic forwarding engine and fingerprint extraction components to work together, regularly update the malicious JA3 fingerprint library, and performing security verification in combination with verification code authentication services.
It significantly reduces the false positive rate, improves the accurate identification of malicious client tools and tool-like client requests, enhances the security of web applications, and prevents automated attacks and malicious tools from intrusion.
Smart Images

Figure CN119989320A_ABST
Abstract
Description
Technical Field
[0001] The invention discloses a human-machine identification authentication method and system, and relates to the technical field of data authentication. Background Art
[0002] With the popularization and development of the Internet, Web applications play an important role in daily life and business. However, at the same time, various tools are used to automatically access Web applications, obtain data from Web applications, and consume system resources. Although current network security products can detect and resist attacks to a certain extent, the effectiveness and coverage of previous protection methods are limited as attack methods become increasingly complex. Summary of the invention
[0003] In view of the problems of the prior art, the present invention provides a human-machine identification and authentication method and system, which identifies tool client traffic by analyzing JavaScript fingerprints, JA3 fingerprints and other means, and performs secondary authentication on requests, thereby enhancing the security of Web applications and greatly reducing the false alarm rate.
[0004] The specific scheme proposed by the present invention is:
[0005] The present invention provides a human-machine identification authentication method, which analyzes the request initiated by the client through a traffic forwarding engine, extracts the JA3 fingerprint of the request using a fingerprint extraction component, and matches it with the JA3 fingerprint in a malicious JA3 fingerprint library. If a match is found, the client initiating the request is considered to be a malicious client, and the request is blocked. If a match is not found, the request is forwarded to the source server.
[0006] The fingerprint extraction component is used to call the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends the request again with the generated JavaScript fingerprint, and continues to forward the request to the source server through the traffic forwarding engine; if the client does not load the JavaScript script, the JavaScript fingerprint cannot be generated and the fingerprint authentication cannot be passed. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification passed identifier, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
[0007] Furthermore, the human-machine identification authentication method described in the invention uses a fingerprint extraction component to extract a JA3 fingerprint from a request, including: extracting the TLS version number, the cipher suite and other protocol parameter information from the TLS handshake information initiated by the client in the request, calculating a summary of the extracted information, and calculating a JA3 fingerprint based on the summary.
[0008] Furthermore, in the human-machine identification authentication method, the client generates a JavaScript fingerprint, including: obtaining the browser version number, mouse sliding trajectory, and screen resolution information used by the client, calculating a summary of the obtained information, and generating a JavaScript fingerprint based on the summary.
[0009] Furthermore, the calling of the verification code authentication service to perform verification code authentication on the client in the human-machine identification authentication method includes: calling the verification code authentication service to perform slider authentication and character verification on the verification code authentication page.
[0010] Furthermore, in the human-machine identification and authentication method, the malicious JA3 fingerprint library is regularly updated through the traffic forwarding engine, and the malicious JA3 fingerprint library stores the JA3 fingerprints of all malicious tool clients.
[0011] The present invention also provides a human-machine identification and authentication system, including a traffic forwarding engine, a fingerprint extraction component and a fingerprint analysis component.
[0012] The traffic forwarding engine analyzes the request initiated by the client, uses the fingerprint extraction component to extract the JA3 fingerprint of the request, and matches it with the JA3 fingerprint in the malicious JA3 fingerprint library. If a match is found, the client initiating the request is considered to be a malicious client and the request is blocked. If a match is not found, the request continues to be forwarded to the source server.
[0013] The fingerprint extraction component is used to call the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends the request again with the generated JavaScript fingerprint, and continues to forward the request to the source server through the traffic forwarding engine; if the client does not load the JavaScript script, the JavaScript fingerprint cannot be generated and the fingerprint authentication cannot be passed. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification passed identifier, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
[0014] Furthermore, a fingerprint extraction component is used in the human-machine identification and authentication system to extract JA3 fingerprints from requests, including: extracting TLS version number, cipher suite and other protocol parameter information from TLS handshake information initiated by the client in the request, calculating a summary of the extracted information, and calculating a JA3 fingerprint based on the summary.
[0015] Furthermore, in the human-machine identification authentication system, the verification code authentication service is called to perform verification code authentication on the client, including: calling the verification code authentication service to perform slider authentication and character verification on the verification code authentication page.
[0016] Furthermore, in the human-machine identification and authentication system, the traffic forwarding engine regularly updates the malicious JA3 fingerprint library, and the malicious JA3 fingerprint library stores the JA3 fingerprints of all malicious tool clients.
[0017] The benefits of the method of the present invention are:
[0018] Through the collaborative work of multiple components, the JA3 fingerprint library and JavaScript fingerprint technologies are integrated to achieve accurate identification of requests initiated by malicious client tools and tool-type clients. First, the JA3 fingerprint library is used to analyze client requests to identify potential malicious activities. When a suspected malicious request is detected, the verification code authentication mechanism is triggered and the client is required to complete the verification. Only requests that pass the verification will be released, which effectively reduces the false alarm rate and ensures that normal users' access is not affected. In order to cope with the ever-changing security threats, not only the detection accuracy of malicious requests is improved, but also the verification code authentication step is used to further enhance the security of Web application services. And it can effectively prevent the intrusion of automated attacks and malicious tools without affecting the user experience. Significantly improve the overall security and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic diagram of the functional module architecture of the present invention.
[0020] Figure 2 It is a schematic diagram of the application process of the method of the present invention.
[0021] Figure 3 It is a schematic diagram of updating the malicious JA3 fingerprint library according to the method of the present invention. DETAILED DESCRIPTION
[0022] The present invention is further described below in conjunction with the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it, but the embodiments are not intended to limit the present invention.
[0023] Example 1
[0024] The present invention provides a human-machine identification and authentication method, which analyzes the request initiated by the client through a traffic forwarding engine.
[0025] Step 1: Use the fingerprint extraction component to extract the JA3 fingerprint of the request and match it with the JA3 fingerprint in the malicious JA3 fingerprint library. If a match is found, the client initiating the request is considered to be a malicious client and the request is blocked. If a match is not found, the request is forwarded to the source server.
[0026] Extracting the JA3 fingerprint may further include: extracting the TLS version number, cipher suite and other protocol parameter information in the TLS handshake information initiated by the client in the request, calculating a summary of the extracted information, and calculating the JA3 fingerprint based on the summary.
[0027] Step 2: Use the fingerprint extraction component to call the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends the request again with the generated JavaScript fingerprint, and continues to forward the request to the source server through the traffic forwarding engine; if the client does not load the JavaScript script, it cannot generate the JavaScript fingerprint and cannot pass the fingerprint authentication. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification pass mark, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
[0028] The client generates a JavaScript fingerprint, including: obtaining the browser version number, mouse sliding trajectory, and screen resolution information used by the client, calculating a summary of the obtained information, and generating a JavaScript fingerprint based on the summary.
[0029] When calling the verification code authentication service to perform verification code authentication on the client, it can further include: calling the verification code authentication service to perform slider verification, character verification, etc. on the verification code authentication page. After passing the verification, the client will carry the verification pass mark and continue to send the request. According to the validity of the verification mark, if the authentication is passed, such as the default one-time verification, the validity period is 5 minutes, then continue to forward the request to the source server.
[0030] The method of the present invention ensures the access speed and experience of ordinary users, while effectively filtering out potential malicious traffic. This method can not only effectively distinguish normal users from tool clients, but also significantly improve the security and stability of the system while maintaining the user experience. It is suitable for various application scenarios that require protecting server resources and preventing automated attacks.
[0031] Example 2
[0032] Based on Example 1, the malicious JA3 fingerprint library is regularly updated through the traffic forwarding engine, and the malicious JA3 fingerprint library stores the JA3 fingerprints of all malicious tool clients to cope with new changes and improve security protection capabilities.
[0033] Example 3
[0034] The present invention also provides a human-machine identification and authentication system, including a traffic forwarding engine, a fingerprint extraction component and a fingerprint analysis component.
[0035] The traffic forwarding engine analyzes the request initiated by the client, uses the fingerprint extraction component to extract the JA3 fingerprint of the request, and matches it with the JA3 fingerprint in the malicious JA3 fingerprint library. If a match is found, the client initiating the request is considered to be a malicious client and the request is blocked. If a match is not found, the request continues to be forwarded to the source server.
[0036] The fingerprint extraction component is used to call the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends the request again with the generated JavaScript fingerprint, and continues to forward the request to the source server through the traffic forwarding engine; if the client does not load the JavaScript script, the JavaScript fingerprint cannot be generated and the fingerprint authentication cannot be passed. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification passed identifier, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
[0037] As the information interaction and execution process between the modules in the above-mentioned system are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0038] Likewise, the benefits of the system of the present invention are:
[0039] Through the collaborative work of multiple components, the JA3 fingerprint library and JavaScript fingerprint technologies are integrated to achieve accurate identification of requests initiated by malicious client tools and tool-type clients. First, the JA3 fingerprint library is used to analyze client requests to identify potential malicious activities. When a suspected malicious request is detected, the verification code authentication mechanism is triggered and the client is required to complete the verification. Only requests that pass the verification will be released, which effectively reduces the false alarm rate and ensures that normal users' access is not affected. In order to cope with the ever-changing security threats, not only the detection accuracy of malicious requests is improved, but also the verification code authentication step is used to further enhance the security of Web application services. And it can effectively prevent the intrusion of automated attacks and malicious tools without affecting the user experience. Significantly improve the overall security and stability of the system.
[0040] It should be noted that not all steps and modules in the above-mentioned processes and system structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or some components in multiple independent devices may be implemented together.
[0041] The above-described embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or changes made by those skilled in the art based on the present invention are within the protection scope of the present invention. The protection scope of the present invention shall be subject to the claims.
Claims
1. A human-machine identification and authentication method, characterized in that The traffic forwarding engine analyzes the request initiated by the client, uses the fingerprint extraction component to extract the JA3 fingerprint of the request, and matches it with the JA3 fingerprint in the malicious JA3 fingerprint library. If it hits, the client initiating the request is considered to be a malicious client and the request is blocked. If it does not hit, the request continues to be forwarded to the source server; The fingerprint extraction component calls the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends a request again with the generated JavaScript fingerprint. The traffic forwarding engine continues to forward the request to the origin server. If the client does not load the JavaScript script, the JavaScript fingerprint cannot be generated and the fingerprint authentication cannot be passed. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification pass identifier, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
2. A human-machine identification and authentication method according to claim 1, characterized in that The method of using the fingerprint extraction component to extract the JA3 fingerprint from the request includes: extracting the TLS version number, the cipher suite and other protocol parameter information from the TLS handshake information initiated by the client in the request, calculating a summary of the extracted information, and calculating the JA3 fingerprint based on the summary.
3. A human-machine identification and authentication method according to claim 1, characterized in that The client generates a JavaScript fingerprint, including: obtaining the browser version number, mouse sliding trajectory, and screen resolution information used by the client, calculating a summary of the obtained information, and generating a JavaScript fingerprint based on the summary.
4. A human-machine identification and authentication method according to claim 1, characterized in that The calling of the verification code authentication service to perform verification code authentication on the client includes: calling the verification code authentication service to perform slider authentication and character authentication on the verification code authentication page.
5. A human-machine identification and authentication method according to claim 1, characterized in that The malicious JA3 fingerprint library is regularly updated through the traffic forwarding engine, and the malicious JA3 fingerprint library stores the JA3 fingerprints of all malicious tool clients.
6. A human-machine identification and authentication system, characterized in that Including traffic forwarding engine, fingerprint extraction component and fingerprint analysis component, The traffic forwarding engine analyzes the request initiated by the client, uses the fingerprint extraction component to extract the JA3 fingerprint of the request, and matches it with the JA3 fingerprint in the malicious JA3 fingerprint library. If a match is found, the client initiating the request is considered to be a malicious client and the request is blocked. If a match is not found, the request continues to be forwarded to the source server. The fingerprint extraction component calls the fingerprint analysis component to send a JavaScript script to the client to determine whether the client parses and loads the JavaScript script. If the client loads the JavaScript script, the client generates a JavaScript fingerprint and sends a request again with the generated JavaScript fingerprint. The traffic forwarding engine continues to forward the request to the origin server. If the client does not load the JavaScript script, the JavaScript fingerprint cannot be generated and the fingerprint authentication cannot be passed. The verification code authentication service is called to perform verification code authentication on the client. If the client passes the verification code authentication, it carries the verification pass identifier, continues to send the request, and forwards the request to the source server through the traffic forwarding engine.
7. A human-machine identification and authentication system according to claim 6, characterized in that The fingerprint extraction component is used to extract the JA3 fingerprint of the request, including: extracting the TLS version number, cipher suite and other protocol parameter information in the TLS handshake information initiated by the client in the request, calculating the summary of the extracted information, and calculating the JA3 fingerprint based on the summary.
8. A human-machine identification and authentication system according to claim 6, characterized in that Call the verification code authentication service to perform verification code authentication on the client, including: calling the verification code authentication service to perform slider verification and character verification on the verification code authentication page.
9. A human-machine identification and authentication system according to claim 6, characterized in that The traffic forwarding engine regularly updates the malicious JA3 fingerprint library, which stores the JA3 fingerprints of all malicious tool clients.
Citation Information
Patent Citations
Protection method, device, equipment, system and storage medium
CN114519178A
Access request verification method and device, storage medium and server
CN114928452A
Anti-fraud man-machine identification method and system
CN116112273A
Anti-crawler method based on TLS fingerprint and JS confusion encryption
CN118740437A