Communication processing method and platform, electronic equipment and computer readable storage medium

By detecting and decrypting communication request data in the communication processing platform, determining security categories based on risk information and encrypting it, the network security problem of the HTTPS protocol in the face of man-in-the-middle attacks is solved, and secure communication between the client and the target server is realized.

CN119995908APending Publication Date: 2025-05-13BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311507545.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When the HTTPS protocol faces a man-in-the-middle attack (MITM), the user's network communication request data is easily tampered with or stolen by third parties, making it difficult to ensure network security.

Method used

By detecting communication request data between the client and the target server in the communication processing platform, obtaining and decrypting the data, determining the security category of the data based on risk information, and encrypting and decrypting if necessary, avoiding man-in-the-middle attacks.

Benefits of technology

It effectively avoids man-in-the-middle attacks, ensures the security of communication between the client and the target server, and protects the user's network data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995908A_ABST
    Figure CN119995908A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a communication processing method and platform, an electronic device and a computer readable storage medium, after the communication processing platform obtains first communication risk information of communication request data, the security category of the communication request data is determined based on the first communication risk information, and if the security category is a common category, the communication request data is sent to the electronic device. If yes, sending the communication request data to the target server, thereby avoiding man-in-the-middle attack between the client and the communication processing platform; and after the communication processing platform obtains the second communication risk information corresponding to the response data, the communication processing platform determines the security category of the response data based on the second communication risk information, and if the security category of the response data is a common category, the response data is sent to the client, so that man-in-the-middle attack between the target server and the communication processing platform is avoided. And the communication processing platform carries out communication security risk review between the client and the communication processing platform and between the communication processing platform and the target server, so that the communication security of the communication between the client and the target server is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a communication processing method, platform, electronic device and computer-readable storage medium. Background Art

[0002] With the rapid development of information technology, the HTTPS (Hypertext Transfer Protocol Secure) protocol has become the mainstream network security transmission protocol due to its strong encryption and integrity protection, which can effectively protect the security of user data. However, with the emergence of MITM (Man-in-the-Middle Attack) attack mode against the HTTPS protocol, the network communication request data between two communication devices can be easily tampered or stolen by a third party, making it difficult to ensure the user's network security. Summary of the invention

[0003] The embodiments of the present application provide a communication processing method, platform, electronic device and computer-readable storage medium, which can solve the technical problem that the emergence of the MITM attack mode against the HTTPS protocol makes the network communication request data between two communication devices easy to be tampered with or stolen by a third party, making it difficult to ensure the user's network security.

[0004] In a first aspect, an embodiment of the present application provides a communication processing method, wherein the method includes:

[0005] Detecting communication request data sent by a client to a target server, and acquiring the communication request data sent by the client;

[0006] Acquire first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, send the communication request data to the target server;

[0007] detecting response data sent by the target server to the client in response to the communication request data, and acquiring the response data sent by the target server;

[0008] The second communication risk information corresponding to the response data is obtained, and the security category of the response data is determined based on the second communication risk information. If the security category of the response data is a common category, the response data is sent to the client.

[0009] Optionally, detecting communication request data sent by the client to the target server and acquiring the communication request data sent by the client includes:

[0010] Obtaining a communication connection request sent by the client to the target server, and determining a target domain name corresponding to the communication connection request based on the communication connection request;

[0011] Generate first key information for the target domain name, and send the first key information to the client;

[0012] Detecting the communication request data sent by the client to the target server, receiving the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

[0013] Optionally, after receiving the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client, the method further includes:

[0014] Decrypting the second key information encrypted by the first key information based on the first key information to obtain the decrypted second key information;

[0015] The communication request data encrypted by the second key information is decrypted based on the second key information to obtain the decrypted communication request data.

[0016] Optionally, if the security category of the communication request data is a common category, sending the communication request data to a target server includes:

[0017] If the security category of the communication request data is a common category, generating third key information, encrypting the communication request data based on the third key information, and obtaining the communication request data encrypted by the third key information;

[0018] Obtaining a public key certificate corresponding to the target domain name, and determining public key information corresponding to the target domain name based on the public key certificate;

[0019] Encrypting the third key information based on the public key information to obtain the third key information encrypted by the public key information;

[0020] The third key information encrypted by the public key information and the communication request data encrypted by the third key information are sent to the target server.

[0021] Optionally, the acquiring the response data sent by the target server further includes:

[0022] Receive response data sent by the target server and encrypted by the third key information, and decrypt the response data based on the third key information to obtain decrypted response data.

[0023] Optionally, if the security category of the response data is a common category, sending the response data to the client includes:

[0024] If the security category of the response data is a common category, the response data is encrypted based on the second key information, and the encrypted response data is sent to the client.

[0025] Optionally, the acquiring first communication risk information corresponding to the communication request data, and determining the security category of the communication request data based on the first communication risk information includes:

[0026] Acquire first communication risk information carried by the communication request data, where the first communication risk information includes at least one of a first request method, a first request header, and a first status code;

[0027] The acquired first communication risk information is matched with a pre-established first communication risk database to obtain a first matching result, and the security category of the communication request data is determined based on the first matching result.

[0028] Optionally, the acquiring second communication risk information corresponding to the response data, and determining the security category of the response data based on the second communication risk information includes:

[0029] Acquire second communication risk information carried by the response data, where the first communication risk information includes at least one of a second request method, a second request header, and a second status code;

[0030] The acquired second communication risk information is matched with a pre-established second communication risk database to obtain a second matching result, and the security category of the response data is determined based on the second matching result.

[0031] Optionally, the method further comprises:

[0032] If the security category of the communication request data is a malicious category, intercepting the communication request data; and / or,

[0033] If the security category of the response data is a malicious category, the response data is intercepted.

[0034] In a second aspect, an embodiment of the present application provides another communication processing method, the method comprising:

[0035] Sending communication request data to the target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client;

[0036] enabling the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enabling the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enabling the communication processing platform to send the communication request data to the target server;

[0037] Enable the communication processing platform to detect response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to obtain the response data sent by the target server;

[0038] And enable the communication processing platform to obtain second communication risk information corresponding to the response data, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, enable the communication processing platform to send the response data to the client, and receive the response data sent by the communication processing platform.

[0039] In a third aspect, an embodiment of the present application provides another communication processing method, the method comprising:

[0040] Detecting communication request data sent by the client to the target server based on the communication processing platform, and acquiring the communication request data sent by the client based on the communication processing platform;

[0041] Acquiring first communication risk information corresponding to the communication request data based on the communication processing platform, and causing the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, causing the communication processing platform to send the communication request data to the target server, and receiving the communication request data;

[0042] Sending response data to the communication request data to the client, based on the communication processing platform detecting the response data to the communication request data sent by the target server to the client, and acquiring the response data sent by the target server based on the communication processing platform;

[0043] Based on the communication processing platform, second communication risk information corresponding to the response data is obtained, and the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client.

[0044] In a fourth aspect, an embodiment of the present application provides a communication processing platform, the platform comprising:

[0045] A first detection module, adapted to detect communication request data sent by a client to a target server, and obtain the communication request data sent by the client;

[0046] a first processing module, adapted to obtain first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and send the communication request data to the target server if the security category of the communication request data is a common category;

[0047] A second detection module, adapted to detect response data sent by the target server to the client in response to the communication request data, and obtain the response data sent by the target server;

[0048] The second processing module is adapted to obtain second communication risk information corresponding to the response data, determine the security category of the response data based on the second communication risk information, and send the response data to the client if the security category of the response data is a common category.

[0049] In a fifth aspect, an embodiment of the present application provides a client, the client comprising:

[0050] A sending module, adapted to send communication request data to a target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client;

[0051] a security judgment module, adapted to enable the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server;

[0052] an acquisition module, adapted to enable the communication processing platform to detect response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to acquire the response data sent by the target server;

[0053] A receiving module is suitable for enabling the communication processing platform to obtain second communication risk information corresponding to the response data, and enabling the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, enabling the communication processing platform to send the response data to the client, and receiving the response data sent by the communication processing platform.

[0054] In a sixth aspect, an embodiment of the present application provides a server, the server comprising:

[0055] A detection and acquisition module, adapted to detect, based on the communication processing platform, communication request data sent by the client to the target server, and acquire, based on the communication processing platform, the communication request data sent by the client;

[0056] a security receiving module, adapted to obtain first communication risk information corresponding to the communication request data based on the communication processing platform, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server, and receive the communication request data;

[0057] A server sending module, adapted to send response data to the client for the communication request data, based on the communication processing platform detecting the response data sent by the target server to the client for the communication request data, and acquiring the response data sent by the target server based on the communication processing platform;

[0058] A secure sending module is adapted to obtain second communication risk information corresponding to the response data based on the communication processing platform, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, the communication processing platform sends the response data to the client.

[0059] In a seventh aspect, an embodiment of the present application provides an electronic device, the electronic device comprising:

[0060] Processor; and

[0061] A memory arranged to store computer executable instructions which, when executed, cause the processor to perform any of the methods described above.

[0062] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores one or more programs, and when the one or more programs are executed by a processor, implement any of the methods described above.

[0063] The beneficial effects brought about by the technical solutions provided in some embodiments of the embodiments of the present application include at least: when the communication processing platform detects communication request data sent by the client to the target server, the communication processing platform obtains the communication request data sent by the client, and the communication processing platform at this time is used to disguise itself as a "target server" to communicate with the client to be compatible with the existing communication protocol. After the communication processing platform obtains the first communication risk information corresponding to the communication request data, the security category of the communication request data is determined based on the first communication risk information. If the security category of the communication request data is a common category, the communication request data is sent to the target server, thereby avoiding man-in-the-middle attacks between the client and the communication processing platform.

[0064] Afterwards, the communication processing platform sends the communication request data to the target server. At this time, the communication processing platform is used to disguise as a "client" to communicate with the target server to be compatible with the existing communication protocol. When the communication processing platform detects the response data sent by the target server to the client for the communication request data, the communication processing platform obtains the response data sent by the target server. Similarly, after the communication processing platform obtains the second communication risk information corresponding to the response data, the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the response data is sent to the client, thereby avoiding man-in-the-middle attacks between the target server and the communication processing platform. In the solution provided in the present application, a communication security risk review is performed on the man-in-the-middle attack behavior between the client and the communication processing platform and between the communication processing platform and the target server based on the communication processing platform, so as to ensure the communication security between the client and the target server, thereby solving the technical problem that the MITM attack mode for the HTTPS protocol appears, making the network communication request data between the two communication devices easy to be tampered with or stolen by a third party, making it difficult to ensure the user's network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0066] Figure 1 An exemplary system architecture diagram of a communication processing method provided in an embodiment of the present application;

[0067] Figure 2 A flow chart of a communication processing method provided in an embodiment of the present application;

[0068] Figure 3 A schematic diagram of a process for obtaining communication request data provided in an embodiment of the present application;

[0069] Figure 4 A schematic diagram of a process for decrypting communication request data provided in an embodiment of the present application;

[0070] Figure 5 A schematic diagram of a process for sending communication request data to a target server provided in an embodiment of the present application;

[0071] Figure 6 A schematic diagram of a process for determining the security category of communication request data provided in an embodiment of the present application;

[0072] Figure 7 A schematic diagram of a process for determining the security category of response data provided in an embodiment of the present application;

[0073] Figure 8 A flowchart of another communication processing method provided in an embodiment of the present application;

[0074] Fig. 9 A flowchart of another communication processing method provided in an embodiment of the present application;

[0075] Fig.10 A schematic diagram of the structure of a communication processing platform provided in an embodiment of the present application;

[0076] Fig.11 A schematic diagram of the structure of a client provided in an embodiment of the present application;

[0077] Fig.12 A schematic diagram of the structure of a server provided in an embodiment of the present application;

[0078] Fig.13 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0079] In order to make the features and advantages of the embodiments of the present application more obvious and easy to understand, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of them. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the embodiments of the present application.

[0080] When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the attached claims.

[0081] In recent years, with the rapid development of information technology, the HTTPS protocol has become the mainstream network security transmission protocol. The HTTPS protocol has strong encryption and integrity protection, and can effectively protect the security of user data. However, some malicious attackers take advantage of the characteristics of the HTTPS protocol to steal user data and information through man-in-the-middle attacks, which poses a great challenge to network security. Man-in-the-middle attacks intercept normal network communication data and tamper with and sniff the normal network communication data, making the network communication request data between two communication devices easily tampered or stolen by a third party, making it difficult to ensure the user's network security, while the two parties in communication are unaware. Therefore, there is a need for a communication processing method to protect the privacy and information security of users.

[0082] In order to overcome the above-mentioned technical problems, the present application provides a communication processing method. When a communication processing platform detects communication request data sent by a client to a target server, the communication processing platform obtains the communication request data sent by the client. At this time, the communication processing platform is used to disguise itself as a "target server" to communicate with the client to be compatible with the existing communication protocol. After the communication processing platform obtains the first communication risk information corresponding to the communication request data, the security category of the communication request data is determined based on the first communication risk information. If the security category of the communication request data is a common category, the communication request data is sent to the target server, thereby avoiding man-in-the-middle attacks between the client and the communication processing platform.

[0083] Afterwards, the communication processing platform sends the communication request data to the target server. At this time, the communication processing platform is used to disguise as a "client" to communicate with the target server to be compatible with the existing communication protocol. When the communication processing platform detects the response data sent by the target server to the client for the communication request data, the communication processing platform obtains the response data sent by the target server. Similarly, after the communication processing platform obtains the second communication risk information corresponding to the response data, the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the response data is sent to the client, thereby avoiding man-in-the-middle attacks between the target server and the communication processing platform. In the solution provided in the present application, a communication security risk review is performed on the man-in-the-middle attack behavior between the client and the communication processing platform and between the communication processing platform and the target server based on the communication processing platform, so as to ensure the communication security between the client and the target server, thereby solving the technical problem that the MITM attack mode for the HTTPS protocol appears, making the network communication request data between the two communication devices easy to be tampered with or stolen by a third party, making it difficult to ensure the user's network security.

[0084] See also Figure 1 , Figure 1 An exemplary system architecture diagram of a communication processing method provided in an embodiment of the present application.

[0085] like Figure 1 As shown, the system architecture may include a client 101, a communication processing platform 102, and a server 103. The client 101 and the communication processing platform 102, as well as the communication processing platform 102 and the server 103 communicate via a network. The network is used to provide a medium for a communication link between the client 101 and the communication processing platform 102, and to provide a medium for a communication link between the communication processing platform 102 and the server 103. The network may include various types of wired communication links or wireless communication links, for example: a wired communication link includes an optical fiber, a twisted pair, or a coaxial cable, and a wireless communication link includes a Bluetooth communication link, a Wi-Fi (Wireless-Fidelity) communication link, or a microwave communication link, etc.

[0086] The communication processing platform 102 can interact with the server 103 through the network to receive messages from the server 103 or send messages to the server 103, or the communication processing platform 102 can interact with the server 103 through the network to receive messages or data sent by other users to the server 103. The communication processing platform 102 can interact with the client 101 through the network to receive messages from the client 101 or send messages to the client 101, or the communication processing platform 102 can interact with the client 101 through the network to receive messages or data sent by other users to the client 101.

[0087] The communication processing platform 102 may be hardware or software. When the communication processing platform 102 is hardware, it may be various terminals, including but not limited to smart watches, smart phones, tablet computers, laptop portable computers, and desktop computers. When the communication processing platform 102 is software, it may be installed in the terminals listed above, and it may be implemented as multiple software or software modules (for example, to provide distributed services), or it may be implemented as a single software or software module, which is not specifically limited here.

[0088] In an embodiment of the present application, the communication processing platform 102 can detect the communication request data sent by the client to the target server, and obtain the communication request data sent by the client; obtain the first communication risk information corresponding to the communication request data, and determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, the communication request data is sent to the target server; detect the response data sent by the target server to the client for the communication request data, and obtain the response data sent by the target server; obtain the second communication risk information corresponding to the response data, and determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, the response data is sent to the client.

[0089] The client 101 may be various terminals, including but not limited to smart watches, smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0090] The server 103 may be a business server that provides various services. It should be noted that the server 103 may be hardware or software. When the server 103 is hardware, it may be implemented as a distributed server cluster consisting of multiple servers, or it may be implemented as a single server. When the server 103 is software, it may be implemented as multiple software or software modules (for example, for providing distributed services), or it may be implemented as a single software or software module, which is not specifically limited here.

[0091] It should be understood that Figure 1The number of clients, communication processing platforms, and servers in the figure is only illustrative, and any number of clients, communication processing platforms, and servers may be used according to implementation requirements.

[0092] See also Figure 2 , Figure 2 A flow chart of a communication processing method provided for an embodiment of the present application. The execution subject of the embodiment of the present application can be a communication processing platform that executes the communication processing method, or a processor in the communication processing platform that executes the communication processing method, or a communication processing service in the communication processing platform that executes the communication processing method. For the convenience of description, the specific execution process of the communication processing method is introduced below by taking the execution subject as a processor in the communication processing platform as an example.

[0093] like Figure 2 As shown, the communication processing method may at least include:

[0094] S202: Detecting communication request data sent by the client to the target server, and acquiring the communication request data sent by the client.

[0095] When the communication processing platform detects the communication request data sent by the client to the target server, the communication processing platform may intercept the communication request data sent by the client to the target server, thereby obtaining the communication request data sent by the client.

[0096] Before sending communication request data to the target server, the client will initiate a communication connection to the target server, such as a TCP (Transmission Control Protocol) connection. TCP is a transmission protocol used to establish a reliable connection in the network for data transmission between two parties. When a client wants to establish a TCP connection with a server, it sends a connection request to the server.

[0097] When the communication processing platform detects a communication connection initiated by the client to the target server, the communication connection is intercepted and a communication connection between the communication processing platform and the client is established based on the communication connection, so as to disguise the communication processing platform as the "target server", thereby achieving the purpose of obtaining the communication request data sent by the client when the client subsequently sends the communication request data to the target server. Therefore, step S202 at least includes the following embodiments:

[0098] Optionally, the communication processing platform detects the communication request data sent by the client to the target server, and intercepts the communication request data sent by the client.

[0099] Optionally, when the communication processing platform detects a communication connection initiated by the client to the target server, it intercepts the communication connection and establishes a communication connection between the communication processing platform and the client based on the communication connection, and receives communication request data sent by the client to the target server.

[0100] S204: Obtain first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, send the communication request data to the target server.

[0101] After the communication processing platform obtains the communication request data, it obtains the first communication risk information corresponding to the communication request data. The communication processing platform is used to perform a communication security risk review on the communication request data based on the first communication risk information to determine whether there is a man-in-the-middle attack or other tampering or theft by a third party between the client and the communication processing platform.

[0102] Therefore, the communication processing platform can determine the security category of the communication request data based on the first communication risk information, where the security category of the communication request data includes a common category and a malicious category. The security category of the common category indicates that the communication request data is safe. Therefore, if the security category of the communication request data is the common category, the communication request data is sent to the target server. The security category of the malicious category indicates that the communication request data is risky. Therefore, if the security category of the communication request data is the malicious category, the communication request data is intercepted.

[0103] S206: Detect response data sent by the target server to the client in response to the communication request data, and obtain the response data sent by the target server.

[0104] After the target server receives the communication request data sent by the communication processing platform, the target server sends the response data to the client for the communication request data. After the communication processing platform detects the response data sent by the target server to the client for the communication request data, it intercepts and obtains the response data sent by the target server.

[0105] Similarly, before the target server sends response data to the client in response to the communication request data, it establishes a communication connection with the client.

[0106] When the communication processing platform detects a communication connection initiated by the target server to the client, it intercepts the communication connection and establishes a communication connection between the communication processing platform and the target server based on the communication connection, so as to disguise the communication processing platform as a "client" and thereby achieve the purpose of obtaining the response data sent by the target server when the target server subsequently sends communication request data to the client.

[0107] S208: Obtain second communication risk information corresponding to the response data, determine the security category of the response data based on the second communication risk information, and if the security category of the response data is a common category, send the response data to the client.

[0108] When the communication processing platform receives the response data, it obtains the second communication risk information corresponding to the response data. The communication processing platform is also used to perform a communication security risk review on the response data based on the second communication risk information to determine whether there is a man-in-the-middle attack or other tampering or theft by a third party between the target server and the communication processing platform.

[0109] Therefore, the communication processing platform can determine the security category of the response data based on the second communication risk information, where the security category of the response data also includes a common category and a malicious category. The security category of the common category indicates that the response data is safe. Therefore, if the security category of the response data is the common category, the response data is sent to the target server. The security category of the malicious category indicates that the response data is risky. Therefore, if the security category of the communication request data is the malicious category, the communication request data is intercepted.

[0110] Furthermore, if the security category of the communication request data is a malicious category, the communication request data is intercepted; and / or if the security category of the response data is a malicious category, the response data is intercepted.

[0111] An embodiment of the present application provides a communication processing method. When a communication processing platform detects communication request data sent by a client to a target server, the communication processing platform obtains the communication request data sent by the client. At this time, the communication processing platform is used to disguise itself as a "target server" to communicate with the client to be compatible with the existing communication protocol. After the communication processing platform obtains first communication risk information corresponding to the communication request data, the security category of the communication request data is determined based on the first communication risk information. If the security category of the communication request data is a common category, the communication request data is sent to the target server, thereby avoiding man-in-the-middle attacks between the client and the communication processing platform.

[0112] Afterwards, the communication processing platform sends the communication request data to the target server. At this time, the communication processing platform is used to disguise as a "client" to communicate with the target server to be compatible with the existing communication protocol. When the communication processing platform detects the response data sent by the target server to the client for the communication request data, the communication processing platform obtains the response data sent by the target server. Similarly, after the communication processing platform obtains the second communication risk information corresponding to the response data, the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the response data is sent to the client, thereby avoiding man-in-the-middle attacks between the target server and the communication processing platform. In the solution provided in the present application, a communication security risk review is performed on the man-in-the-middle attack behavior between the client and the communication processing platform and between the communication processing platform and the target server based on the communication processing platform, so as to ensure the communication security between the client and the target server, thereby solving the technical problem that the MITM attack mode for the HTTPS protocol appears, making the network communication request data between the two communication devices easy to be tampered with or stolen by a third party, making it difficult to ensure the user's network security.

[0113] See also Figure 3 , Figure 3 A schematic diagram of a process for obtaining communication request data provided in an embodiment of the present application.

[0114] like Figure 3 As shown, in an embodiment provided by the present application, in step S202, detecting the communication request data sent by the client to the target server, obtaining the communication request data sent by the client includes:

[0115] S302: Obtain a communication connection request sent by the client to the target server, and determine a target domain name corresponding to the communication connection request based on the communication connection request.

[0116] The communication connection request sent by the client to the target server includes the target domain name corresponding to the communication connection request. Here, since the IP (Internet Protocol) address and the domain name are one-to-one corresponding, the information of the domain name address is stored in a host called a domain name server. The user only needs to understand the easy-to-remember domain name address, and the corresponding conversion work is left to the domain name server. The domain name server is a server that provides conversion services between IP addresses and domain names. Therefore, the communication processing platform can determine the target domain name corresponding to the communication connection request based on the communication connection request, and then determine the IP address corresponding to the communication connection request.

[0117] After determining the target domain name corresponding to the communication connection request, the communication processing platform can detect the public key certificate of the IP corresponding to the target domain name based on the CA (Certificate Authority). The authenticity of the target website can be confirmed by checking the validity and legitimacy of the digital certificate. At the same time, it can help communication reviewers identify and intercept forged digital certificates, thereby preventing man-in-the-middle attacks and data theft.

[0118] S304: Generate first key information for the target domain name, and send the first key information to the client.

[0119] The communication processing platform generates the first key information for the target domain name based on its own root certificate. By generating the first key information for the target domain name, each target domain name has its own corresponding first key information, thereby improving communication security. The root certificate can be a certificate issued by the CA certification center to the communication processing platform, which is the starting point of the trust chain. Installing the root certificate means trust in this CA certification center. The root certificate can contain at least three parts of information: information about the communication processing platform, the public key of the communication processing platform, and the signature of the CA center on the information in the certificate. Therefore, the first key information can be generated based on one or more of the information of the communication processing platform, the public key of the communication processing platform, and the signature of the CA center on the information in the certificate. Generally, since the public key of the communication processing platform will be public, when the first key information is generated using the public key of the communication processing platform, the first key information can be generated based on the random number generated by the communication processing platform and the public key of the communication processing platform.

[0120] Here, the first key information may be obtained based on an asymmetric encryption algorithm or a symmetric encryption algorithm. When the first key information is obtained based on an asymmetric encryption algorithm, the first key information may include a first public key and a first private key that match each other. At this time, sending the first key information to the client includes: sending the first public key to the client so that the client encrypts based on the first public key when sending information, and when the communication processing platform receives the information encrypted by the client based on the first public key, it can decrypt based on the first private key corresponding to the first public key.

[0121] When the first key information is obtained based on a symmetric encryption algorithm, the key information corresponding to the communication processing platform and the client is the same. At this time, sending the first key information to the client includes: sending the first key information to the client so that the client encrypts based on the first key information when sending information, and when the communication processing platform receives the information encrypted by the client based on the first key information, it can decrypt based on the first key information.

[0122] S306: Detecting communication request data sent by the client to the target server, receiving second key information encrypted by the first key information and communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

[0123] When the communication processing platform detects the communication request data sent by the client to the target server, it intercepts the communication request data sent by the client to the target server, receives the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

[0124] The second key information can be a symmetric key randomly generated by the client or other feasible key. After receiving the second key information encrypted by the first key information sent by the client, the second key information encrypted by the first key information can be decrypted based on the first key information in the communication processing platform to obtain the decrypted second key information. Thereafter, the communication request data encrypted by the second key information can be decrypted based on the decrypted second key information to obtain the decrypted communication request data. Through multiple encryption, the communication security is further improved.

[0125] In an embodiment provided by the present application, if the security category of the response data is a common category in step S208, sending the response data to the client includes:

[0126] If the security category of the response data is a common category, the response data is encrypted based on the second key information, and the encrypted response data is sent to the client.

[0127] Since the second key information is generated by the client, the client can decrypt the encrypted response data based on the second key information to obtain the decrypted response data.

[0128] See also Figure 4 , Figure 4 A schematic diagram of a process for decrypting communication request data provided in an embodiment of the present application.

[0129] like Figure 4 As shown, after receiving the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client in step S306, the method further includes:

[0130] S402: Decrypt the second key information encrypted by the first key information based on the first key information to obtain the decrypted second key information.

[0131] After the communication processing platform sends the first key information to the client, the communication processing platform still retains the first key information. Therefore, after the communication processing platform receives the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client, the second key information encrypted by the first key information is decrypted based on the first key information to obtain the decrypted second key information. The second key information is used to decrypt the communication request data encrypted by the second key information.

[0132] S404: Decrypt the communication request data encrypted by the second key information based on the second key information to obtain decrypted communication request data.

[0133] After obtaining the decrypted second key information in S402, the communication request data encrypted by the second key information can be decrypted based on the second key information to obtain the decrypted communication request data. After decrypting the communication request data, the security category is determined based on the decrypted communication request data. In addition, in other embodiments, after decrypting the communication request data, the message in the communication request data can be displayed so that the communication security personnel can perform additional auxiliary review.

[0134] See also Figure 5 , Figure 5 A flow chart of sending communication request data to a target server is provided in accordance with an embodiment of the present application.

[0135] like Figure 5 As shown, in step S204, if the security category of the communication request data is a common category, the communication request data is sent to the target server, including:

[0136] S502: If the security category of the communication request data is a common category, generate third key information, encrypt the communication request data based on the third key information, and obtain the communication request data encrypted by the third key information.

[0137] When the security category of the communication request data is a common category, it indicates that there is no data leakage or change in the communication request data during transmission. At this time, the communication processing platform can generate the third key information, encrypt the communication request data based on the third key information, and obtain the communication request data encrypted by the third key information, thereby improving the communication security level of the subsequent transmission of the communication request data to the target server. Here, the third key information can be a symmetric key randomly generated by the communication processing platform.

[0138] HTTPS uses encrypted data transmission internally, and the encryption algorithm is usually an asymmetric encryption algorithm that cannot be symmetrically decrypted, so it has high security, which makes this traditional technical solution unable to present the civilized text of the interactive HTTPS traffic message. Therefore, using the communication request data encrypted by the third key information can effectively present the civilized text of the interactive HTTPS traffic message.

[0139] S504: Obtain a public key certificate corresponding to the target domain name, and determine public key information corresponding to the target domain name based on the public key certificate.

[0140] In order to be compatible with existing communication protocols, the communication processing platform can obtain the public key certificate corresponding to the target domain name, and obtain the public key information corresponding to the target domain name from the public key certificate. The public key information of the target domain name has matching private key information. The public key information is used for encryption, and the private key information is used to decrypt data encrypted by the public key information.

[0141] S506: Encrypt the third key information based on the public key information to obtain the third key information encrypted by the public key information.

[0142] Since the communication request data is encrypted by the third key information, the third key information can be encrypted based on the public key information before sending the third key information, thereby improving the security level of communication transmission and satisfying the existing communication protocol.

[0143] S508: Send the third key information encrypted by the public key information and the communication request data encrypted by the third key information to the target server.

[0144] After obtaining the third key information encrypted by the public key information and the communication request data encrypted by the third key information, the communication processing platform sends the third key information encrypted by the public key information and the communication request data encrypted by the third key information to the target server.

[0145] In an embodiment provided by the present application, the step S206 of obtaining the response data sent by the target server further includes:

[0146] Receive response data sent by the target server and encrypted by the third key information, decrypt the response data based on the third key information, and obtain decrypted response data.

[0147] After receiving the third key information encrypted by the public key information and the communication request data encrypted by the third key information, the target server decrypts the third key information encrypted by the public key information based on the private key information corresponding to the public key information to obtain the decrypted third key information, and then decrypts the communication request data encrypted by the third key information based on the decrypted third key information to obtain the decrypted communication request data.

[0148] The target server receives the decrypted communication request data, and sends the response data encrypted by the third key information to the client for the decrypted communication request data. The communication processing platform intercepts and receives the response data encrypted by the third key information, and decrypts the response data based on the third key information to obtain the decrypted response data. In addition, in other embodiments, after the response data is decrypted, the message in the response data can be displayed so that the communication security personnel can perform additional auxiliary review.

[0149] It should be noted that after the target server receives the third key information encrypted by the public key information, based on the existing protocol, the target server uses the third key information as the "public key information" corresponding to the "client". Therefore, the target server will encrypt the response data based on the third key information. Since the third key information is a symmetric key, the third key information of the communication processing platform and the third key information corresponding to the target server are the same. Therefore, using the communication request data encrypted by the third key information can effectively present the civilized text of the interactive HTTPS traffic messages, avoiding the use of asymmetric keys that cause the civilized text of the HTTPS traffic messages to be unable to be presented.

[0150] See also Figure 6 , Figure 6 A schematic diagram of a process for determining the security category of communication request data provided in an embodiment of the present application.

[0151] like Figure 6 As shown, in step S204, obtaining first communication risk information corresponding to the communication request data, and determining the security category of the communication request data based on the first communication risk information includes:

[0152] S602: Obtain first communication risk information carried in the communication request data, where the first communication risk information includes at least one of a first request method, a first request header, and a first status code.

[0153] The first request method belongs to the request method. There are currently 8 commonly used request methods in the HTTP protocol, namely GET, POST, HEAD, PUT, DELETE, OPTIONS, TRACE and CONNECT.

[0154] The PUT method is used to send data to the server to create or update resources. It can replace all current content in the target resource with the uploaded content; the POST method is used to send data to the server to create or update resources. It requires the server to confirm that the content contained in the request is another subordinate item of the Web (World Wide Web) resource distinguished by the Uniform Resource Locator; the OPTIONS method is used to describe the communication options of the target resource and will return the HTTP policy of the server supporting the predefined URL (Uniform Resource Locator); the GET method is used to retrieve information from a given server using a given URI (Uniform Resource Identifier), that is, to request data from the specified resource; the CONNECT method is used to establish a tunnel to the server identified by the given URI; the TRACE method is used to perform a message loopback test along the path to the target resource; it responds to the received request so that the client can see what progress or increments have been made by the intermediate server; the DELETE method is used to delete the specified resource, which will delete all current content of the target resource given by the URI. The HEAD method is the same as the GET method, but there is no response body, only the status line and the header part are transmitted.

[0155] The first request header is a request header, which includes some information of the client itself and the action it wants to perform. The security category of the communication request data can be determined based on the information of the client itself and the action it wants to perform. The first status code is a status code, which indicates the status information of the communication request data. The security category of the communication request data can be determined based on the comparison between the normal status code and the first status code.

[0156] S604: Match the acquired first communication risk information with a pre-established first communication risk database to obtain a first matching result, and determine a security category of the communication request data based on the first matching result.

[0157] The pre-established first communication risk database can be established based on at least one of the request method, request header and status code in the blacklist with communication risk. The acquired first communication risk information is matched with the pre-established first communication risk database to obtain a first matching result. If the first matching result is a match, the security category of the communication request data is a malicious category; if the first matching result is a mismatch, the security category of the communication request data is a normal category.

[0158] See also Figure 7 , Figure 7 A schematic diagram of a process for determining the security category of response data provided in an embodiment of the present application.

[0159] like Figure 7 As shown, in step S208, obtaining the second communication risk information corresponding to the response data, and determining the security category of the response data based on the second communication risk information includes:

[0160] S702: Obtain second communication risk information carried in the response data, where the first communication risk information includes at least one of a second request method, a second request header, and a second status code.

[0161] The second request method belongs to the request method, the second request header belongs to the request header, and the second status code belongs to the request header. The relevant description can refer to step S602, which will not be repeated here.

[0162] S704: Match the acquired second communication risk information with a pre-established second communication risk database to obtain a second matching result, and determine a security category of the response data based on the second matching result.

[0163] The pre-established second communication risk database can be established based on at least one of the request method, request header and status code in the blacklist with communication risk. The acquired second communication risk information is matched with the pre-established second communication risk database to obtain a second matching result. If the second matching result is a match, the security category of the response data is a malicious category; if the second matching result is a mismatch, the security category of the response data is a normal category.

[0164] Of course, in other embodiments, the fields in the response data or communication request data may be classified and filtered based on a machine learning model, and the corresponding categories may be output to determine the security category of the response data or communication request data.

[0165] See also Figure 8 , Figure 8 A flowchart of another communication processing method provided for an embodiment of the present application. The execution subject of the embodiment of the present application can be a client that executes the communication processing method, or a processor in the client that executes the communication processing method, or a communication processing service in the client that executes the communication processing method. For the convenience of description, the specific execution process of the communication processing method is introduced below by taking the execution subject as an example of a processor in the client.

[0166] like Figure 8 As shown, the method includes:

[0167] S802: Send communication request data to the target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client.

[0168] The specific description of step S802 can refer to step S202 and will not be repeated here.

[0169] S804: Enable the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server.

[0170] The specific description of step S804 may refer to step S204 and will not be repeated here.

[0171] S806: Enable the communication processing platform to detect response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to obtain the response data sent by the target server.

[0172] The specific description of step S806 can refer to step S206 and will not be repeated here.

[0173] S808: The communication processing platform obtains the second communication risk information corresponding to the response data, and determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client, and receives the response data sent by the communication processing platform.

[0174] The specific description of step S808 can refer to step S208 and will not be repeated here.

[0175] See also Fig. 9 , Fig. 9 A flowchart of another communication processing method provided for an embodiment of the present application. The execution subject of the embodiment of the present application can be a target server that executes the communication processing method, or a processor in the target server that executes the communication processing method, or a communication processing service in the target server that executes the communication processing method. For the convenience of description, the specific execution process of the communication processing method is introduced below by taking the execution subject being the processor in the target server as an example.

[0176] like Fig. 9 As shown, the method includes:

[0177] S902: Detecting communication request data sent by the client to the target server based on the communication processing platform, and acquiring the communication request data sent by the client based on the communication processing platform.

[0178] The specific description of step S902 can refer to step S202 and will not be repeated here.

[0179] S904: Obtain the first communication risk information corresponding to the communication request data based on the communication processing platform, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server and receive the communication request data.

[0180] The specific description of step S904 can refer to step S204 and will not be repeated here.

[0181] S906: Send response data to the client for the communication request data, based on the communication processing platform detecting the response data sent by the target server to the client for the communication request data, and obtaining the response data sent by the target server based on the communication processing platform.

[0182] The specific description of step S906 can refer to step S206 and will not be repeated here.

[0183] S908: Obtain second communication risk information corresponding to the response data based on the communication processing platform, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, enable the communication processing platform to send the response data to the client.

[0184] The specific description of step S908 can refer to step S208 and will not be repeated here.

[0185] See also Fig.10 , Fig.10 A schematic diagram of the structure of a communication processing platform provided in an embodiment of the present application.

[0186] The communication processing platform 1000 includes:

[0187] The first detection module 1010 is adapted to detect the communication request data sent by the client to the target server and obtain the communication request data sent by the client;

[0188] The first processing module 1020 is adapted to obtain first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and send the communication request data to the target server if the security category of the communication request data is a common category;

[0189] The second detection module 1030 is adapted to detect response data sent by the target server to the client in response to the communication request data, and obtain the response data sent by the target server;

[0190] The second processing module 1040 is adapted to obtain second communication risk information corresponding to the response data, determine the security category of the response data based on the second communication risk information, and send the response data to the client if the security category of the response data is a common category.

[0191] In an embodiment provided in the present application, the first detection module 1010, the first processing module 1020, the second detection module 1030 and the second processing module 1040 can be integrated into a network proxy component, a protocol filtering component and a data communication component.

[0192] The network proxy component is mainly responsible for forwarding and proxying HTTPS communication traffic. By monitoring the network card interface, the HTTPS traffic passing through the network interface is intercepted and parsed, including decryption, verification, parsing, and reorganization. When performing decryption operations, the network proxy component needs to use certificates and keys to decrypt HTTPS traffic. To improve efficiency, the network proxy component will cache the decrypted certificates and keys to facilitate subsequent decryption operations. When the decryption operation is completed, the network proxy component will forward the decrypted HTTPS traffic and send it to the target server or client. In order to improve network transmission efficiency, the network proxy component supports group forwarding of decrypted HTTPS traffic to reduce the size and complexity of a single flow and improve transmission efficiency.

[0193] The main function of the protocol filtering component is to filter and decrypt the data transmitted in HTTPS communication for monitoring and review. This component can identify the HTTP part in the HTTPS request and decrypt it so as to monitor and filter the content in the request. At the same time, it can also filter and intercept HTTP requests that have not been authenticated to ensure the security of communication. HTTPS communication uses encryption technology to protect the security of data, but this also means that the monitor cannot directly obtain the content of the communication. The protocol filtering component can obtain the content of the communication by decrypting the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocol in HTTPS communication, thereby realizing the review and monitoring of the communication. The protocol filtering component can also check the integrity of the data transmitted in HTTPS communication to ensure that the data has not been tampered with or damaged. For tampered or damaged data, this component can promptly detect and block its transmission to ensure the security of communication. HTTPS communication uses the SSL / TLS communication protocol. The protocol filter needs to parse the SSL / TLS communication protocol to obtain the various fields in the communication data and classify and filter them. In the network proxy, HTTPS communication is encrypted through the SSL / TLS protocol. The protocol filter needs to decrypt these encrypted contents to help auditors monitor and analyze network messages and logs.

[0194] The main function of the data communication component is to realize the decryption and reorganization of encrypted data, so that the communication processing platform can obtain the plaintext data in the HTTPS communication for review and analysis. During the SSL / TLS handshake process, the data communication component needs to verify the legitimacy of the certificate to prevent security issues such as man-in-the-middle attacks. Due to the encrypted nature of HTTPS communication, the data is contained in the TLS record, and the TLS record needs to be parsed and reorganized to obtain the original HTTP request and response data. In order to improve performance, the data communication component needs to cache the decrypted and reorganized data to avoid repeated decryption and reorganization operations on the same connection. After the data communication component decrypts and reorganizes the HTTPS communication data, it needs to forward the data to the protocol filtering component for further processing. Due to the large amount of HTTPS communication data, data compression and encryption technology need to be used during the transmission process to reduce the amount of transmitted data and ensure the security of the transmitted data. In order to ensure the reliability and efficiency of data transmission, it is necessary to design protocols suitable for data transmission, such as HTTP, TCP, etc. At the same time, it is also necessary to optimize the transmission protocol, such as using fragmented transmission, compressed transmission and other technologies to improve the efficiency and reliability of data transmission.

[0195] Through in-depth review of HTTPS communication traffic, potential security threats and attacks can be discovered. In addition, the solution can also intercept and isolate malicious traffic and attack traffic to ensure network security. HTTPS communication review can monitor and analyze network communications in real time, quickly discover and locate network communication problems, and provide targeted solutions to improve the efficiency and performance of network applications. In addition, the solution can also reduce redundant data transmission, reduce network congestion and latency. Through the analysis and statistics of HTTPS communication traffic, decision makers can better understand the status and characteristics of network communications, so as to formulate more scientific network security and optimization strategies. At the same time, the solution can also provide enterprises with more data support to assist enterprise decision-making and business development. HTTPS communication review can provide comprehensive management and monitoring of network communications, which can better understand network conditions and maintain network security for network managers. In addition, the solution can also provide remote management and control of network equipment, reduce maintenance costs and improve management efficiency.

[0196] Optionally, the first detection module 1010 includes:

[0197] A first acquisition submodule, adapted to acquire a communication connection request sent by a client to a target server, and determine a target domain name corresponding to the communication connection request based on the communication connection request;

[0198] A first generating submodule, adapted to generate first key information for a target domain name, and send the first key information to a client;

[0199] The first detection submodule is adapted to detect the communication request data sent by the client to the target server, and receive the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

[0200] Optionally, the first detection module 1010 includes:

[0201] A first decryption module, adapted to decrypt the second key information encrypted by the first key information based on the first key information to obtain the decrypted second key information;

[0202] The second decryption module is adapted to decrypt the communication request data encrypted by the second key information based on the second key information to obtain the decrypted communication request data.

[0203] Optionally, the first processing module 1020 includes:

[0204] a communication request data encryption submodule adapted to generate third key information if the security category of the communication request data is a common category, encrypt the communication request data based on the third key information, and obtain the communication request data encrypted by the third key information;

[0205] A public key certificate acquisition submodule, adapted to acquire a public key certificate corresponding to a target domain name, and determine the public key information corresponding to the target domain name based on the public key certificate;

[0206] A third key information encryption submodule, adapted to encrypt the third key information based on the public key information to obtain the third key information encrypted by the public key information;

[0207] The sending submodule is adapted to send the third key information encrypted by the public key information and the communication request data encrypted by the third key information to the target server.

[0208] Optionally, the second detection module 1030 is suitable for receiving response data sent by the target server and encrypted by the third key information, and decrypting the response data based on the third key information to obtain the decrypted response data.

[0209] Optionally, the second processing module 1040 is further adapted to encrypt the response data based on the second key information if the security category of the response data is a common category, and send the encrypted response data to the client.

[0210] Optionally, the first processing module 1020 further includes:

[0211] A first communication risk information acquisition submodule, adapted to acquire first communication risk information carried in the communication request data, the first communication risk information including at least one of a first request method, a first request header, and a first status code;

[0212] The first matching result determination submodule is adapted to match the acquired first communication risk information with a pre-established first communication risk database to obtain a first matching result, and determine the security category of the communication request data based on the first matching result.

[0213] Optionally, the second processing module 1040 further includes:

[0214] A second communication risk information acquisition submodule, adapted to acquire second communication risk information carried in the response data, the first communication risk information including at least one of a second request method, a second request header, and a second status code;

[0215] The second matching result determination submodule is adapted to match the acquired second communication risk information with a pre-established second communication risk database to obtain a second matching result, and determine the security category of the response data based on the second matching result.

[0216] Optionally, if the security category of the communication request data is a malicious category, the communication request data is intercepted; and / or, if the security category of the response data is a malicious category, the response data is intercepted.

[0217] See also Fig.11 , Fig.11 A schematic diagram of the structure of a client provided in an embodiment of the present application.

[0218] The client 1100 includes:

[0219] The sending module 1110 is adapted to send communication request data to the target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client;

[0220] The security judgment module 1120 is adapted to enable the communication processing platform to obtain first communication risk information corresponding to the communication request data, and to enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server;

[0221] The acquisition module 1130 is adapted to enable the communication processing platform to detect the response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to acquire the response data sent by the target server;

[0222] The receiving module 1140 is suitable for enabling the communication processing platform to obtain the second communication risk information corresponding to the response data, and enabling the communication processing platform to determine the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client and receives the response data sent by the communication processing platform.

[0223] See also Fig.12 , Fig.12 A schematic diagram of the structure of a server provided in an embodiment of the present application.

[0224] The server 1200 includes:

[0225] The detection and acquisition module 1210 is adapted to detect the communication request data sent by the client to the target server based on the communication processing platform, and acquire the communication request data sent by the client based on the communication processing platform;

[0226] The security receiving module 1220 is adapted to obtain first communication risk information corresponding to the communication request data based on the communication processing platform, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server, and receive the communication request data;

[0227] The server sending module 1230 is adapted to send response data to the client for the communication request data, based on the communication processing platform detecting the response data to the communication request data sent by the target server to the client, and obtaining the response data sent by the target server based on the communication processing platform;

[0228] The secure sending module 1240 is suitable for obtaining the second communication risk information corresponding to the response data based on the communication processing platform, and enabling the communication processing platform to determine the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client.

[0229] An embodiment of the present application further provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the steps of any method in the above embodiments.

[0230] See also Fig.13 , Fig.13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Fig.13 As shown, the electronic device 1300 may include: at least one processor 1301 , at least one network interface 1304 , a user interface 1303 , a memory 1305 , and at least one communication bus 1302 .

[0231] The communication bus 1302 is used to realize the connection and communication between these components.

[0232] The user interface 1303 may include a display screen (Display) and a camera (Camera), and the optional user interface 1303 may also include a standard wired interface and a wireless interface.

[0233] The network interface 1304 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).

[0234] Among them, the processor 1301 may include one or more processing cores. The processor 1301 uses various interfaces and lines to connect various parts within the entire electronic device 1300, and executes various functions and processes data of the electronic device 1300 by running or executing instructions, programs, code sets or instruction sets stored in the memory 1305, and calling data stored in the memory 1305. Optionally, the processor 1301 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 1301 can integrate one or a combination of CPU (Central Processing Unit), GPU (Graphics Processing Unit) and modem. Among them, the CPU mainly processes the operating system, user interface and application program, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above-mentioned modem may not be integrated into the processor 1301, and it can be implemented by a single chip.

[0235] Among them, the memory 1305 may include RAM (Random Access Memory) and may also include ROM (Read-Only Memory). Optionally, the memory 1305 includes a non-transitory computer-readable storage medium. The memory 1305 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 1305 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store data involved in the above-mentioned method embodiments, etc. The memory 1305 may optionally be at least one storage device located away from the aforementioned processor 1301. As Fig.13 As shown, the memory 1305 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a communication processing program.

[0236] exist Fig.13In the electronic device 1300 shown, the user interface 1303 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 1301 can be used to call the communication processing program stored in the memory 1305. When applied to the communication processing platform, the processor 1301 specifically performs the following operations:

[0237] Detect communication request data sent by the client to the target server, and obtain the communication request data sent by the client; obtain first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, send the communication request data to the target server; detect response data for the communication request data sent by the target server to the client, and obtain response data sent by the target server; obtain second communication risk information corresponding to the response data, determine the security category of the response data based on the second communication risk information, and if the security category of the response data is a common category, send the response data to the client.

[0238] Optionally, when the processor 1301 detects the communication request data sent by the client to the target server and obtains the communication request data sent by the client, specifically executes:

[0239] Obtain a communication connection request sent by the client to the target server, and based on the communication connection request, determine the target domain name corresponding to the communication connection request; generate first key information for the target domain name, and send the first key information to the client; detect the communication request data sent by the client to the target server, receive the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

[0240] Optionally, the processor 1301 is further adapted to execute:

[0241] Decrypting the second key information encrypted by the first key information based on the first key information to obtain the decrypted second key information;

[0242] The communication request data encrypted by the second key information is decrypted based on the second key information to obtain the decrypted communication request data.

[0243] Optionally, when the processor 1301 executes sending the communication request data to the target server if the security category of the communication request data is a common category, the processor 1301 specifically executes:

[0244] If the security category of the communication request data is a general category, generate third key information, encrypt the communication request data based on the third key information, and obtain the communication request data encrypted by the third key information; obtain the public key certificate corresponding to the target domain name, and determine the public key information corresponding to the target domain name based on the public key certificate; encrypt the third key information based on the public key information, and obtain the third key information encrypted by the public key information; send the third key information encrypted by the public key information and the communication request data encrypted by the third key information to the target server.

[0245] Optionally, when the processor 1301 executes to obtain the response data sent by the target server, it specifically executes:

[0246] Receive response data sent by the target server and encrypted by the third key information, decrypt the response data based on the third key information, and obtain decrypted response data.

[0247] Optionally, if the security category of the response data is a common category, the processor 1301 sends the response data to the client by specifically performing:

[0248] If the security category of the response data is a common category, the response data is encrypted based on the second key information, and the encrypted response data is sent to the client.

[0249] Optionally, when the processor 1301 executes obtaining first communication risk information corresponding to the communication request data and determining the security category of the communication request data based on the first communication risk information, specifically executes:

[0250] Obtain first communication risk information carried by the communication request data, the first communication risk information including at least one of a first request method, a first request header and a first status code; match the obtained first communication risk information with a pre-established first communication risk database to obtain a first matching result, and determine the security category of the communication request data based on the first matching result.

[0251] Optionally, when the processor 1301 acquires the second communication risk information corresponding to the response data and determines the security category of the response data based on the second communication risk information, specifically:

[0252] Obtain second communication risk information carried by the response data, where the first communication risk information includes at least one of a second request method, a second request header, and a second status code; match the obtained second communication risk information with a pre-established second communication risk database to obtain a second matching result, and determine the security category of the response data based on the second matching result.

[0253] Optionally, if the security category of the communication request data is a malicious category, the communication request data is intercepted; and / or, if the security category of the response data is a malicious category, the response data is intercepted.

[0254] In one embodiment provided in the present application, Fig.13 In the electronic device 1300 shown, the user interface 1303 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 1301 can be used to call the communication processing program stored in the memory 1305. When applied to the client, the processor 1301 specifically performs the following operations:

[0255] Sending communication request data to the target server so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client;

[0256] enabling the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enabling the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enabling the communication processing platform to send the communication request data to the target server;

[0257] The communication processing platform detects response data sent by the target server to the client in response to the communication request data, and the communication processing platform obtains the response data sent by the target server;

[0258] And enable the communication processing platform to obtain the second communication risk information corresponding to the response data, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client, and receives the response data sent by the communication processing platform.

[0259] In one embodiment provided in the present application, Fig.13 In the electronic device 1300 shown, the user interface 1303 is mainly used to provide an input interface for the user and obtain the data input by the user; and the processor 1301 can be used to call the communication processing program stored in the memory 1305. When applied to the target server, the processor 1301 specifically performs the following operations:

[0260] Detecting communication request data sent by the client to the target server based on the communication processing platform, and acquiring the communication request data sent by the client based on the communication processing platform;

[0261] Acquiring first communication risk information corresponding to the communication request data based on the communication processing platform, and causing the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, causing the communication processing platform to send the communication request data to the target server, and receiving the communication request data;

[0262] Sending response data to the client for the communication request data, based on the communication processing platform detecting the response data to the communication request data sent by the target server to the client, and acquiring the response data sent by the target server based on the communication processing platform;

[0263] Based on the communication processing platform, the second communication risk information corresponding to the response data is obtained, and the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client.

[0264] In the several embodiments provided in the embodiments of the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, which can be electrical, mechanical or other forms.

[0265] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0266] In addition, each functional module in each embodiment of the present application can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.

[0267] If the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, ROM (Read-Only Memory), RAM (Random Access Memory), disk or CD-ROM and other media that can store program codes.

[0268] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the described order of actions, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of the present application.

[0269] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0270] The above is a description of a communication processing method, platform, electronic device and computer-readable storage medium provided in an embodiment of the present application. For technicians in this field, according to the ideas of the embodiments of the present application, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the embodiments of the present application.

Claims

1. A communication processing method, wherein: The method comprises: Detecting communication request data sent by a client to a target server, and acquiring the communication request data sent by the client; Acquire first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, send the communication request data to the target server; detecting response data sent by the target server to the client in response to the communication request data, and acquiring the response data sent by the target server; The second communication risk information corresponding to the response data is obtained, and the security category of the response data is determined based on the second communication risk information. If the security category of the response data is a common category, the response data is sent to the client.

2. The method according to claim 1, wherein: The detecting of communication request data sent by the client to the target server and obtaining the communication request data sent by the client includes: Obtaining a communication connection request sent by the client to the target server, and determining a target domain name corresponding to the communication connection request based on the communication connection request; Generate first key information for the target domain name, and send the first key information to the client; Detecting the communication request data sent by the client to the target server, receiving the second key information encrypted by the first key information and the communication request data encrypted by the second key information sent by the client; wherein the second key information is generated by the client.

3. The method according to claim 1, wherein: If the security category of the communication request data is a common category, sending the communication request data to the target server includes: If the security category of the communication request data is a common category, generating third key information, encrypting the communication request data based on the third key information, and obtaining the communication request data encrypted by the third key information; Obtaining a public key certificate corresponding to the target domain name, and determining public key information corresponding to the target domain name based on the public key certificate; Encrypting the third key information based on the public key information to obtain the third key information encrypted by the public key information; The third key information encrypted by the public key information and the communication request data encrypted by the third key information are sent to the target server.

4. A communication processing method, wherein: The method comprises: Sending communication request data to the target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client; enabling the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enabling the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enabling the communication processing platform to send the communication request data to the target server; Enable the communication processing platform to detect response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to obtain the response data sent by the target server; And enable the communication processing platform to obtain second communication risk information corresponding to the response data, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, enable the communication processing platform to send the response data to the client, and receive the response data sent by the communication processing platform.

5. A communication processing method, wherein: The method comprises: Detecting communication request data sent by the client to the target server based on the communication processing platform, and acquiring the communication request data sent by the client based on the communication processing platform; Acquiring first communication risk information corresponding to the communication request data based on the communication processing platform, and causing the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, causing the communication processing platform to send the communication request data to the target server, and receiving the communication request data; Sending response data to the communication request data to the client, based on the communication processing platform detecting the response data to the communication request data sent by the target server to the client, and acquiring the response data sent by the target server based on the communication processing platform; Based on the communication processing platform, second communication risk information corresponding to the response data is obtained, and the communication processing platform determines the security category of the response data based on the second communication risk information. If the security category of the response data is a common category, the communication processing platform sends the response data to the client.

6. A communication processing platform, wherein: The platform includes: A first detection module, adapted to detect communication request data sent by a client to a target server, and obtain the communication request data sent by the client; a first processing module, adapted to obtain first communication risk information corresponding to the communication request data, determine the security category of the communication request data based on the first communication risk information, and send the communication request data to the target server if the security category of the communication request data is a common category; A second detection module, adapted to detect response data sent by the target server to the client in response to the communication request data, and obtain the response data sent by the target server; The second processing module is adapted to obtain second communication risk information corresponding to the response data, determine the security category of the response data based on the second communication risk information, and send the response data to the client if the security category of the response data is a common category.

7. A client, wherein: The client comprises: A sending module, adapted to send communication request data to a target server, so that the communication processing platform detects the communication request data sent by the client to the target server, and enables the communication processing platform to obtain the communication request data sent by the client; a security judgment module, adapted to enable the communication processing platform to obtain first communication risk information corresponding to the communication request data, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information, and if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server; an acquisition module, adapted to enable the communication processing platform to detect response data sent by the target server to the client in response to the communication request data, and enable the communication processing platform to acquire the response data sent by the target server; A receiving module is suitable for enabling the communication processing platform to obtain second communication risk information corresponding to the response data, and enabling the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, enabling the communication processing platform to send the response data to the client, and receiving the response data sent by the communication processing platform.

8. A server, wherein: The server comprises: A detection and acquisition module, adapted to detect, based on the communication processing platform, communication request data sent by the client to the target server, and acquire, based on the communication processing platform, the communication request data sent by the client; a security receiving module, adapted to obtain first communication risk information corresponding to the communication request data based on the communication processing platform, and enable the communication processing platform to determine the security category of the communication request data based on the first communication risk information; if the security category of the communication request data is a common category, enable the communication processing platform to send the communication request data to the target server, and receive the communication request data; A server sending module, adapted to send response data to the client for the communication request data, based on the communication processing platform detecting the response data sent by the target server to the client for the communication request data, and acquiring the response data sent by the target server based on the communication processing platform; A secure sending module is adapted to obtain second communication risk information corresponding to the response data based on the communication processing platform, and enable the communication processing platform to determine the security category of the response data based on the second communication risk information; if the security category of the response data is a common category, the communication processing platform sends the response data to the client.

9. An electronic device, wherein: The electronic device includes: Processor; and A memory arranged to store computer executable instructions which, when executed, cause the processor to perform a method according to any one of claims 1 to 3 or 4 or 5.

10. A computer-readable storage medium, wherein: The computer-readable storage medium stores one or more programs, which, when executed by a processor, implement the method of any one of claims 1 to 3 or 4 or 5.