Access control method and device, electronic equipment and storage medium
By generating the target address and asynchronously detecting the initial address, and controlling the gateway to perform interception or release operations, the problems of high pressure on the gateway and low user efficiency in the existing technology are solved, and efficient interception of abnormal URLs and improvement of user experience are achieved.
Patent Information
- Application Number
- CN202510252343.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art relies on synchronous detection results when identifying and intercepting potential threats, resulting in high pressure on the gateway and affecting the efficiency of users in normal processing of emails or information.
By generating the target address and replacing the initial address, detecting the initial address asynchronously, controlling the gateway to perform interception or release operations based on the detection results, achieving efficient interception of abnormal URLs.
Reduces the impact of access control operations on users, improves user experience, and enhances user information security.
Smart Images

Figure CN119996034A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technology, in particular to the field of smart office and information security technology, and specifically to an access control method, device, electronic device and storage medium. Background Art
[0002] With the development of network technology, users' awareness of network security is getting higher and higher. URLs that threaten network security are usually sent to users in the form of unknown links through emails, instant messaging or text messages to guide users to click and install Trojan viruses, or collect user information through phishing websites. Summary of the invention
[0003] The present disclosure provides an access control method, device, electronic device and storage medium.
[0004] According to one aspect of the present disclosure, an access control method is provided, including: in response to receiving first information including an initial address, generating a target address based on a predetermined domain name parameter and the initial address; replacing the initial address included in the first information with the target address to obtain second information; sending the target address to a target device; in response to receiving the first information, performing asynchronous detection on the initial address to generate a target detection result; and in response to receiving an access request for the target address, controlling the gateway to perform an interception operation or a release operation on the access request based on the target detection result.
[0005] According to another aspect of the present disclosure, an access control device is provided, including: a first generating module, a replacing module, a sending module, a second generating module and a first controlling module.
[0006] The first generation module is used to generate a target address based on a predetermined domain name parameter and the initial address in response to receiving the first information including the initial address. The replacement module is used to replace the initial address included in the first information with the target address. The sending module is used to send the target address to the target device. The second generation module is used to detect the initial address in response to receiving the first information and generate a target detection result. The first control module is used to control the gateway to perform an interception operation or an interception operation on the access request based on the target detection result in response to receiving the access request for the target address.
[0007] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described above.
[0008] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method described above.
[0009] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the method described above is implemented.
[0010] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The accompanying drawings are used to better understand the present solution and do not constitute a limitation of the present disclosure.
[0012] Figure 1 An exemplary system architecture to which the access control method and apparatus according to an embodiment of the present disclosure can be applied is schematically shown;
[0013] Figure 2 A flowchart of an access control method according to an embodiment of the present disclosure is schematically shown;
[0014] Figure 3 A schematic diagram schematically shows an access control method according to an embodiment of the present disclosure;
[0015] Figure 4A A schematic diagram schematically shows a method of asynchronously detecting an initial URL according to an embodiment of the present disclosure;
[0016] Figure 4B A schematic diagram schematically shows a method of asynchronously detecting an initial URL according to another embodiment of the present disclosure;
[0017] Figure 4C A schematic diagram schematically shows a method of asynchronously detecting an initial URL according to another embodiment of the present disclosure;
[0018] Figure 5 A schematic diagram of a logic diagram of a gateway controlling an access request based on a detection result according to an embodiment of the present disclosure is shown;
[0019] Figure 6 A schematic diagram of a logic diagram of a gateway controlling an access request based on user input and detection results according to an embodiment of the present disclosure is schematically shown;
[0020] Figure 7 A block diagram schematically shows an access control device according to an embodiment of the present disclosure; and
[0021] Figure 8A block diagram of an electronic device suitable for implementing an access control method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0022] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0023] Gateway interception is an important defense mechanism for improving network security. It can monitor and detect network traffic at the gateways where it enters and leaves the network, identify and intercept potential threats, prevent malicious traffic from entering the internal network system, and protect network security.
[0024] Since it takes a long time to identify potential threats, if the gateway's interception operation completely relies on the synchronous detection results of emails or messages to be distributed, it will not only put a lot of pressure on the gateway, but also affect the user's processing efficiency of normal emails or messages.
[0025] In view of this, the disclosed embodiment provides an access control method, which changes the initial URL of the target webpage and sends the changed target address to the user, so that the user can process emails or information in time, reducing the impact of the access control operation on the user and further improving the user experience. When the user accesses the target address, the access request first reaches the gateway, so that the gateway determines whether to perform an interception operation for the access request based on the result of asynchronous detection, thereby achieving efficient interception of access requests for abnormal URLs and further improving the user's information security.
[0026] Figure 1 An exemplary system architecture to which the access control method and apparatus according to an embodiment of the present disclosure can be applied is schematically shown.
[0027] It should be noted that Figure 1 The examples shown are only examples of system architectures to which the embodiments of the present disclosure can be applied, in order to help those skilled in the art understand the technical content of the present disclosure, but do not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios. For example, in another embodiment, the exemplary system architecture to which the access control method and apparatus can be applied may include a terminal device, but the terminal device may implement the access control method and apparatus provided by the embodiments of the present disclosure without interacting with the server.
[0028] like Figure 1As shown, the system architecture 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used to provide a medium for a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.
[0029] The user may use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as knowledge reading applications, web browser applications, search applications, instant messaging tools, email clients, and / or social platform software, etc. (only as examples).
[0030] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0031] The server 105 may be a server that provides various services, such as a background management server (only as an example) that provides support for the content browsed by the user using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0032] It should be noted that the access control method provided in the embodiment of the present disclosure can generally be executed by the first terminal device 101, the second terminal device 102, and the third terminal device 103. Accordingly, the access control device provided in the embodiment of the present disclosure can also be set in the first terminal device 101, the second terminal device 102, and the third terminal device 103.
[0033] Alternatively, the access control method provided in the embodiment of the present disclosure may also be generally executed by the server 105. Accordingly, the access control device provided in the embodiment of the present disclosure may generally be arranged in the server 105. The access control method provided in the embodiment of the present disclosure may also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the access control device provided in the embodiment of the present disclosure may also be arranged in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0034] For example, when the email sent by user A to user B via the first terminal device 101 via the network 104 includes an unknown address, after receiving the email, the server 105 changes the unknown address and then sends it to the second terminal device 102 used by user B. At the same time, the server 105 performs asynchronous detection on the unknown address. After receiving the email, user B clicks on the changed address and sends an access request to the server 105. The server 105 controls whether the gateway performs an interception operation on the access request based on the asynchronous detection result.
[0035] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to the implementation requirements.
[0036] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, disclosure and application of user personal information involved comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good morals.
[0037] In the technical solution of the present disclosure, the user's authorization or consent is obtained before obtaining or collecting the user's personal information.
[0038] Figure 2 The flowchart of the access control method according to the embodiment of the present disclosure is schematically shown.
[0039] like Figure 2 As shown, the access control method 200 includes operations S210 to S250.
[0040] In operation S210, in response to receiving first information including an initial address, a target address is generated based on a predetermined domain name parameter and the initial address.
[0041] In operation S220, the initial address included in the first information is replaced with the target address to generate second information.
[0042] In operation S230, the second information is transmitted to the target device.
[0043] In operation S240, in response to receiving the first information, asynchronous detection is performed on the initial address to generate a target detection result.
[0044] In operation S250 , in response to receiving an access request for a target address, the gateway is controlled to perform an interception operation or a release operation for the access request based on a target detection result.
[0045] According to an embodiment of the present disclosure, the first information includes but is not limited to an email, an instant message or a text message. The initial address may be a web address in the email content, instant message or text message, for example: "http: / / target...xxx.com". The predetermined domain name parameter may be a user-defined security domain name, for example: an internal domain name of a company, "gate$$way.com". The generated target address may be "http: / / gate$$way.com / redirect= http: / / target...xxx.com". Then, the initial address in the first information is replaced with the target address, and the second information containing the target address is sent to the target device.
[0046] By changing the initial address, when the user visits the target address, the target web page will not be accessed directly. Instead, the access request will first reach the gateway, which will decide whether to release it based on the asynchronous detection result. Only after the gateway releases it can the user access the target web page. This process is imperceptible to the user.
[0047] In actual application scenarios, when a user receives an email or instant message containing an unknown address, the user will usually be cautious in accessing the unknown address.
[0048] Therefore, in the disclosed embodiment, by changing the initial address, the changed target address is sent to the target object, that is, the user, so that the user can process the normal email in time, for example: the email does not contain a web address, or the web address contained in the email is a normal address. This further reduces the impact of the gateway access control process on the efficiency of information distribution and improves the user experience.
[0049] Since there are many types of abnormal addresses, different types of detection modules can be configured according to actual needs to meet the detection requirements of the initial address.
[0050] In some embodiments, for scenarios with high requirements for timeliness of message distribution, the initial address can be tested for characteristic parameters of the URL (Universal Resource Locator), such as: URL length parameter, whether it is https (Hyper Text Transfer Protocol over Secure Socket Layer), domain name parameter, whether it exists in the whitelist, whether it contains a predetermined email suffix parameter, etc.
[0051] The detection time based on URL feature parameter detection is usually within 5 seconds, which can meet the timeliness requirements of the application scenario.
[0052] In some embodiments, for scenarios where message distribution requires high security, static content detection can be performed on the initial address, for example: by simulating a user accessing a target web page to obtain the static content of the web page, such as: whether it contains sensitive fields, whether it contains a user information collection form, whether the web page code or web page structure is abnormal, etc.
[0053] The detection accuracy based on static content detection is higher, but the detection time is also longer, usually within 1 minute, which can meet the security requirements of the application scenario.
[0054] When a user accesses the target address, the access request will first reach the gateway and wait for the asynchronous detection result of the initial URL at the gateway. If the initial address is determined to be normal, the control gateway will perform a release operation on the access request. If the initial address is determined to be abnormal, the control gateway will perform an interception operation on the access request.
[0055] According to the embodiments of the present disclosure, by changing the initial URL of the target webpage, the changed target address is sent to the user. Compared with the method of sending the message to the user only when the initial URL is determined to be a normal URL in the related examples, the user can process the email or information in time, which reduces the impact of the access control operation on the user and further improves the user experience. When the user accesses the target address, the access request first reaches the gateway, so that the gateway determines whether to perform an interception operation for the access request based on the result of asynchronous detection, thereby realizing efficient interception of access requests for abnormal URLs and further improving the user's information security.
[0056] Figure 3 A schematic diagram of an access control method according to an embodiment of the present disclosure is schematically shown.
[0057] like Figure 3 As shown, in the embodiment 300, first, the initial address 311 is changed by using the website address replacement module 310 to generate a target address 312, and the target address is sent to the user.
[0058] At the same time, the initial address is sent to the website detection module 320 for asynchronous detection, and the website detection module 320 can asynchronously push the detection result to the gateway 330.
[0059] When the user accesses the target address 312, the access request first reaches the gateway 330. The gateway 330 performs operation S330 based on the detection result asynchronously pushed by the URL detection module 320 to determine whether the URL is abnormal. If so, it performs operation S331 to intercept the access request. If not, it performs operation 332 to release the access request.
[0060] In some embodiments, the initial address may include certain special characters, non-ASCII characters, spaces, etc., which may easily lead to parsing errors and affect the normal communication and transmission of information.
[0061] Therefore, generating a target address based on the predetermined domain name parameters and the initial address may include the following operations: encoding the initial address to generate an encoded address, and concatenating the encoded address with the predetermined domain name parameters to generate the target address.
[0062] For example, the special symbol “: / / ” in the http: / / in the initial address can be encoded as %3A%2F%2F, and then the encoded address “http%3A%2F%2Ftarget…xxx.com” is concatenated with the predetermined domain name parameter “gate$$way.com” to obtain the target address “http: / / gate$$way.com / redirect= http%3A%2F%2Ftarget...xxx.com”.
[0063] In some embodiments, a user identifier may also be added to the target address, for example, the target address may be "http: / / gate$$way.com / redirect= http%3A%2F%2F target...xxx.com=user ID" to record each user's access history and promptly notify the user whether the visited web page has risks, so as to prevent the user from continuing to visit the web page and affecting the user's information security.
[0064] According to the embodiments of the present disclosure, by encoding the initial address, the parameters influencing the URL resolution contained in the initial address are optimized. When the user accesses the target address, the access request can be smoothly transmitted to the gateway, further improving the efficiency of access control.
[0065] According to an embodiment of the present disclosure, the target detection result may include a first detection result, a second detection result, and a third detection result. Performing asynchronous detection on the initial address to generate the detection result may include the following operations: performing parameter detection on the initial address to generate a first detection result; performing static content detection on the initial address to generate a second detection result; performing dynamic content detection on the initial address to generate a third detection result.
[0066] Figure 4A The figure schematically shows a schematic diagram of asynchronously detecting an initial URL according to an embodiment of the present disclosure.
[0067] like Figure 4A As shown, in this embodiment 220A, the network detection module 320 is configured with a parameter detection unit 320_1, a static content detection unit 320_2 and a dynamic content detection unit 320_3.
[0068] Parameter detection for the initial address 311 can be performed in the parameter detection unit 320_1, and the obtained detection result R1321 may include at least one of the following: whether the url length parameter meets the predetermined threshold, whether it is https, whether the domain name parameter is safe, whether it exists in the whitelist, whether it contains a predetermined email suffix parameter, etc.
[0069] Static content detection can be performed on the initial address 311 in the static content detection unit 320_2, and the obtained detection result R2322 can include at least one of the following: whether it contains sensitive fields, whether it contains a user information collection form, whether the web page code or the web page structure is abnormal, etc.
[0070] In some embodiments, performing static content detection on the initial address to generate a second detection result may include the following operations: accessing the initial address by simulating a target object to obtain static content of a target web page corresponding to the initial address; and detecting the static content to generate a second detection result.
[0071] For example, by simulating the target object to access the initial address, the target webpage code can be obtained. The target webpage code can be compared with the predetermined abnormal webpage code for similarity. When it is determined that the similarity between the target webpage code and the predetermined abnormal webpage code is greater than a predetermined threshold, the generated second detection result can be that the initial URL is abnormal.
[0072] In some embodiments, the static content detection result may be combined with the URL parameter detection result to determine whether the initial URL is abnormal.
[0073] For example, based on the url parameter detection result, the domain name of the initial URL can be obtained, and the domain name can be used to determine the abnormal web page with a high similarity to the domain name from the predetermined abnormal web page address. Then, by comparing the static content of the obtained target web page with the static content of the abnormal web page, it can be determined whether the initial URL is abnormal.
[0074] By detecting the static content of the initial address, the accuracy of the detection result can be further improved while the detection time is shorter.
[0075] Some malicious websites will use various means to hide abnormal content in the web page associated with the initial address. Therefore, in some embodiments, dynamic content detection is performed on the initial address to generate a third detection result, which may include the following operations: simulating the target object to interact with the target web page based on the initial address to obtain the dynamic content of the web page associated with the target web page; and detecting the dynamic content to generate a third detection result.
[0076] For example, by simulating the target object to interact with the target web page based on the initial address, the obtained dynamic content of the web page associated with the target web page may include: pop-up windows, associated web page content, jump links, etc.
[0077] Detecting dynamic content and generating a third detection result may include at least one of the following: whether the target web page is automatically redirected to the associated web page or redirected by a click, whether a pop-up window exists, whether sensitive information such as a username and password is requested, whether users can enter any information to jump to the associated web page, etc.
[0078] By detecting the dynamic content of the initial address, information hidden in a web page associated with the target web page can be detected, further improving the accuracy of the detection result.
[0079] In embodiment 220A, the detection results of each detection unit in the URL detection module 320 can be sent to the gateway 330 in an asynchronous push manner. The gateway 330 can determine whether to perform an interception operation on the initial URL based on the detection results R1321, R2322 and R3323.
[0080] According to the embodiments of the present disclosure, by respectively performing parameter detection, static content detection and dynamic content detection, detection results with different detection accuracies can be obtained to meet different requirements for timeliness and accuracy in message distribution scenarios, thereby further improving the flexibility of detection.
[0081] In some embodiments, the access control of the gateway 330 for the initial URL needs to meet the requirements of both control efficiency and information security.
[0082] Figure 4BThe figure schematically shows a schematic diagram of asynchronously detecting an initial URL according to another embodiment of the present disclosure.
[0083] like Figure 4B As shown, the difference between the embodiment 220B and 220A is that each detection unit in the URL detection module 320 determines whether to perform a detection operation based on the detection results of other detection units.
[0084] In some embodiments, performing static content detection on the initial address to generate a second detection result may include the following operations: in response to determining that the first detection result indicates normal, performing static content detection on the initial address to generate a second detection result.
[0085] For example, a determination may be made based on the detection result R1321. When the detection result R1321 indicates an abnormality, the detection result R1321 is directly sent to the gateway 330 by asynchronous push. The static content detection unit 320_2 and the dynamic content detection unit 320_3 may not need to detect the initial address. The gateway 330 may intercept the access request based on the detection result R1321.
[0086] Parameter detection usually takes less than 5 seconds. Gradient detection can shorten the waiting time for detection results and further improve the efficiency of the control gateway in intercepting or releasing access requests.
[0087] When the detection result R1321 indicates normal, the static content detection unit 320_2 is used to detect the initial address. The gateway 330 can determine whether to intercept the access request based on at least the detection result R1321 and the detection result R2322.
[0088] In some embodiments, performing dynamic content detection on the initial address to generate a third detection result may include the following operations: in response to determining that both the first detection result and the second detection result indicate normal, performing dynamic content detection on the initial address to generate a third detection result.
[0089] For example, a determination may also be made based on the detection result R2322. When the detection result R2322 indicates an abnormality, the detection result R2322 is directly sent to the gateway 330 by asynchronous push. The dynamic content detection unit 320_3 may not need to detect the initial address. The gateway 330 may intercept the access request based on the detection result R2322.
[0090] Static content detection usually takes less than 1 minute, and dynamic content detection usually takes less than 5 minutes. Through gradient detection, the detection accuracy can be improved while shortening the waiting time for detection results, further improving the efficiency of the control gateway in intercepting or releasing access requests.
[0091] In actual application scenarios, abnormal URLs are usually sent to multiple users. Therefore, the waiting time for the detection results can be further shortened by recording the detection results or detection items of the URLs.
[0092] In some embodiments, before performing asynchronous detection on the initial address, the following operations may be included: obtaining historical detection items for historical addresses; wherein the historical detection items include at least one of the following: parameter detection, static content detection, and dynamic content detection; in response to determining that the initial address and the historical address are of the same type, determining that the detection item for the initial address is a historical detection item.
[0093] According to an embodiment of the present disclosure, a historical detection item may represent a detection item that can detect whether a historical address is abnormal.
[0094] For example, the result of the parameter detection for the historical address indicates normal, and the result of the static content detection for the historical address indicates abnormal. Therefore, it can be determined that the historical detection item is static content detection.
[0095] When it is determined that the initial address and the historical address belong to the same type of address, only static content detection can be performed on the initial address, further shortening the waiting time for the detection result and improving the efficiency of the control gateway in performing interception or release operations on access requests.
[0096] Figure 4C The figure schematically shows a schematic diagram of asynchronously detecting an initial URL according to another embodiment of the present disclosure.
[0097] like Figure 4C As shown, in the embodiment 220C, operation S410 may be performed on the initial address 311 and the historical address 301 to determine whether the initial address 311 and the historical address are of the same type, so as to determine which detection item to perform on the initial address.
[0098] In some embodiments, operation S410 may include the following operations: extracting a first feature of the initial address and a second feature of the historical address respectively; and determining whether the initial address and the historical address are of the same type based on the similarity between the first feature and the second feature.
[0099] First, since the URL parameter feature can be directly extracted from the initial address or the historical address, the time required for information processing is relatively short. Therefore, both the first feature and the second feature can be URL parameter features.
[0100] Then, in some embodiments, the cosine similarity between the first feature and the second feature may be calculated, and when the cosine similarity is greater than a predetermined similarity threshold, it may be determined whether the initial address and the historical address are of the same type.
[0101] In some embodiments, since there are many types of URL parameter features, various types of parameter features can be spliced to obtain the first feature or the second feature. Then, the trained model can be used to process the first feature and the second feature respectively, and the classification results of the initial address and the classification results of the historical address can be output to determine whether the initial address and the historical address belong to the same type.
[0102] If it is determined that the types are the same, then operation S420 is performed to test the historical test items and obtain the test result R i 421, and the test result R i 421 asynchronously pushed to gateway 330.
[0103] When it is determined that the types are different, operation S430 is executed to perform detection on all detection items based on the detection strategy described above, obtain multiple detection results, and asynchronously push the multiple detection results to the gateway 330.
[0104] According to the embodiments of the present disclosure, by extracting URL parameter features to determine the detection items for the initial address from historical detection items, the time required for redundant detection is reduced, the waiting time for the detection results can be further shortened, and the access control efficiency is improved.
[0105] In order to further improve the accuracy of feature similarity calculation and reduce the interference of specific characters in the initial address on the calculation result, in the embodiment of the present disclosure, the first feature of the initial address and the second feature of the historical address are extracted respectively, which may include the following operations: encoding the initial address to generate an encoded address; encoding the historical address to generate an encoded historical address; extracting the first feature from the encoded address; and extracting the second feature from the encoded historical address.
[0106] In some embodiments, special characters in the initial address and the historical address may be encoded according to predetermined rules, for example, the character “:” is encoded as “%3F”, etc.
[0107] By encoding the initial address and the historical address, the influence of special characters on the results of similarity calculation or model classification is reduced, and the accuracy of type discrimination of the initial address and the historical address is further improved.
[0108] In some embodiments, in order to further reduce the pressure on the gateway, the following operations may also be included: obtaining an initial domain name from an initial address; in response to determining that the initial domain name is an abnormal domain name, generating a target address based on predetermined domain name parameters and the initial address.
[0109] For example, a whitelist can be pre-configured, and the whitelist can include multiple secure domain names. When it is determined that the initial domain name in the initial address is in the whitelist, the information containing the initial address can be directly sent to the user without performing a change operation or a detection operation on the initial URL. When the user accesses the initial address, since no gateway jump link is added to the initial address, the gateway's access control on the address can be directly skipped and access can be made directly.
[0110] Based on the whitelist mechanism, URLs containing domain names in the whitelist are exempted from asynchronous detection operations and are directly released, further reducing the pressure on the gateway and improving access control efficiency.
[0111] In some embodiments, in order to further shorten the waiting time for retrieval results, the following operations may also be included: obtaining historical detection results of historical addresses; in response to determining that the historical address includes an abnormal domain name and receiving an access request for the target address, based on the historical detection results, controlling whether the gateway performs an interception operation on the access request.
[0112] For example, when the initial address and the historical address include the same domain name, and the domain name is not in the whitelist, it is still necessary to perform a change operation on the initial address, generate a target address, and send the target address to the user. It is not necessary to perform a detection operation on the initial address.
[0113] When the user accesses the target address, the gateway can directly obtain the historical detection result of the historical address to determine whether to perform an interception operation on the access request.
[0114] For example, if the detection result of the historical address indicates an abnormality, the control gateway intercepts the access request. If the detection result of the historical address indicates a normality, the control gateway releases the access request.
[0115] By comparing the domain name of the historical address with the domain name of the initial address, the historical detection results with the same domain name as the initial address are directly used to control the gateway, further shortening the waiting time of the access request at the gateway and improving the access control efficiency.
[0116] Since different detection items take different time to detect, the time between when the user receives the target address and when the user performs the access operation on the target address is also unpredictable. Therefore, in actual application scenarios, when the gateway obtains the access request, some detection items may be in an unfinished state.
[0117] In some embodiments, in response to receiving an access request for a target address, based on the detection result, controlling whether the gateway performs an interception operation on the access request may include the following operations: in response to determining that the detection result indicates normal and at least one detection item is not completed, generating a prompt message; in response to determining to continue to perform the detection operation, controlling the gateway to perform an interception operation on the access request; and in response to determining to continue to perform the access operation, controlling the gateway to perform a release operation on the access request.
[0118] According to an embodiment of the present disclosure, the prompt information is used to prompt the detection progress and the access risk level of the target web page.
[0119] For example, when the gateway receives an access request for a target web page, the detection result asynchronously obtained from the URL detection module includes: the parameter detection result indicates normal, the static content detection is not completed, and the dynamic content detection is not started.
[0120] At this time, the generated prompt information may include: the test results of the completed test items, the test progress, and the security risks faced by accessing the target webpage when all the test items are not completed.
[0121] For example: the risk of Trojan viruses, the risk of sensitive information being stolen without authorization, etc.
[0122] In some embodiments, the prompt information can be displayed in the visual interface of the user end in various forms such as pop-up windows, highlighted web page content, etc. The embodiments of the present disclosure do not specifically limit the display method of the prompt information.
[0123] According to an embodiment of the present disclosure, in response to receiving an access request for a target address, based on a detection result, controlling whether the gateway performs an interception operation on the access request may include the following operations: in response to determining that the detection result indicates normal, controlling the gateway to perform a release operation on the access request.
[0124] According to an embodiment of the present disclosure, the detection result includes: a first detection result, a second detection result and a third detection result.
[0125] Figure 5 The diagram schematically shows a logic diagram of a gateway controlling an access request based on a detection result according to an embodiment of the present disclosure.
[0126] like Figure 5As shown, in this embodiment 230A, after obtaining the detection result 531, operation S531 can be performed first to determine whether all the detection items have been completed. If all have been completed, operation S535 is performed to determine whether the detection result R1 is normal. If it is determined that the detection result R1 is normal, operation S536 is performed to determine whether the detection result R2 is normal. If it is determined that the detection result R2 is normal, operation S537 is performed to determine whether the detection result R3 is normal. If it is determined that the detection result R3 is normal, operation S539 is performed to control the gateway to perform a release operation on the access request.
[0127] When the detection results of parameter detection, static content detection, and dynamic content detection all indicate normal, the gateway is controlled to release the access request to the target web page, further protecting the user's information security when accessing unfamiliar addresses.
[0128] In some embodiments, in response to receiving an access request for a target address, based on the detection results, controlling whether the gateway performs an interception operation on the access request may include the following operations: in response to determining that the detection result of at least one detection item indicates an abnormality, controlling the gateway to perform an interception operation on the access request.
[0129] For example, when any of the above detection results indicates an abnormality, operation S538 is executed to control the gateway to perform an interception operation on the access request.
[0130] When the acquired test results indicate that at least one test item is not completed, operation S532 is performed to determine whether the parameter test is completed. If the parameter test is completed, operation S533 is performed to determine whether the static test is completed, and operation S535 is performed to determine whether the test result R1 is normal. If the static test is completed, operation S534 is performed to determine whether the dynamic test is completed, and operation S534 is performed.
[0131] When it is determined that at least one of the parameter detection, static content detection, and dynamic content detection is not completed, prompt information 532 is generated to prompt the user whether to continue access or continue detection.
[0132] According to the embodiments of the present disclosure, the user is given the choice of whether to continue to perform the detection operation on the unfinished detection items, which increases the flexibility of gateway access control and further improves the user experience.
[0133] According to an embodiment of the present disclosure, in response to determining to continue to perform a detection operation, the control gateway performs an interception operation on the access request, which may also include the following operations: waiting for the detection result of at least one detection item; in response to determining that the detection result of at least one detection item indicates normal, the control gateway performs a release operation on the access request; in response to determining that the detection result of at least one detection item indicates abnormality, the control gateway performs an interception operation on the access request.
[0134] Figure 6 The schematic diagram of the logic block diagram of gateway controlling access request based on user input and detection result according to an embodiment of the present disclosure is shown.
[0135] like Figure 6 As shown, in this embodiment 230B, when the user chooses to continue the detection based on the prompt information 532, the control gateway first performs an interception operation on the access request and waits for the detection results of the detection items in an unfinished state.
[0136] After receiving the detection result R asynchronously pushed by the URL detection module 220 i 631, perform operation S631 to determine the detection result R i 631 is abnormal, if yes, then execute operation S632, control the gateway to perform an interception operation on the access request. If no, then execute operation S641, control the gateway to perform a release operation on the access request.
[0137] Based on the user's autonomous selection and combined with asynchronous detection results, access control can further improve the flexibility of access control and further enhance the user experience.
[0138] According to an embodiment of the present disclosure, in response to determining to continue to perform an access operation, the control gateway performs a release operation on the access request, and may also include the following operations: in response to receiving a detection result indicating an abnormality for at least one detection item, sending an alarm message to the target object to prompt the target object to abandon the access operation on the target web page.
[0139] When the user still chooses to continue accessing the target web page after knowing the risks of continuing access, the control gateway first performs a release operation on the access request.
[0140] Since the detection result for the initial URL is not completely completed, there are still certain risks for the user to visit the target web page. Therefore, the URL detection module 220 can continue to perform asynchronous detection of the detection items in the unfinished state for the initial URL, and after obtaining the detection result R j When the detection result R is determined, operation S641 is performed. jIs there an abnormality? If an abnormality is confirmed, the gateway can no longer intercept the access request because the access request has jumped out of the gateway. Therefore, an alarm message can be sent to the user to remind the user not to continue accessing the target web page, thereby further protecting the user's information security.
[0141] Figure 7 A block diagram of an access control device according to an embodiment of the present disclosure is schematically shown.
[0142] like Figure 7 As shown, the access control device 700 may include: a first generating module 710 , a replacing module 720 , a sending module 730 , a second generating module 740 and a first controlling module 750 .
[0143] The first generating module 710 is configured to generate a target address based on a predetermined domain name parameter and the initial address in response to receiving the first information containing the initial address, and send the target address to the target object.
[0144] The replacement module is used 720 to replace the initial address included in the first information with the target address to obtain the second information.
[0145] The sending module 730 is used to send the second information to the target device.
[0146] The second generating module 740 is used to detect the initial address and generate a target detection result in response to receiving the first information.
[0147] The first control module 750 is used to control the gateway to perform an interception operation or a release operation on the access request based on the target detection result in response to receiving the access request for the target address.
[0148] According to an embodiment of the present disclosure, the first generation module includes: an encoding submodule and a splicing submodule.
[0149] The encoding submodule is used to encode the initial address to generate the encoded address. The concatenation submodule is used to concatenate the encoded address with the predetermined domain name parameter to generate the target address.
[0150] According to an embodiment of the present disclosure, the access control device further includes: a first acquisition module and a first determination module.
[0151] The first acquisition module is used to acquire a historical detection item for the historical address, wherein the historical detection item includes at least one of the following: parameter detection, static content detection, and dynamic content detection. The first determination module is used to determine that the detection item for the initial address is a historical detection item in response to determining that the initial address and the historical address are of the same type.
[0152] According to an embodiment of the present disclosure, the first determination module includes an extraction submodule and a determination submodule.
[0153] The extraction submodule is used to extract the first feature of the initial address and the second feature of the historical address respectively. The determination submodule is used to determine whether the initial address and the historical address are of the same type based on the similarity between the first feature and the second feature.
[0154] According to an embodiment of the present disclosure, the extraction submodule includes a first encoding unit, a second encoding unit, a first extraction unit, and a second extraction unit.
[0155] The first encoding unit is used to encode the initial address to generate an encoded address. The second encoding unit is used to encode the historical address to generate an encoded historical address. The first extraction unit is used to extract the first feature from the encoded address. The second extraction unit is used to extract the second feature from the encoded historical address.
[0156] According to an embodiment of the present disclosure, the second generation module includes: a parameter detection submodule, a static content detection submodule and a dynamic content detection submodule.
[0157] The parameter detection submodule is used to perform parameter detection on the initial address and generate a first detection result. The static content detection submodule is used to perform static content detection on the initial address and generate a second detection result. The dynamic content detection submodule is used to perform dynamic content detection on the initial address and generate a third detection result. The target detection result includes the first detection result, the second detection result and the third detection result.
[0158] According to an embodiment of the present disclosure, the static content detection submodule includes a first detection unit, which is used to perform static content detection on the initial address in response to determining that the first detection result indicates normal, and generate a second detection result.
[0159] According to an embodiment of the present disclosure, the dynamic content detection submodule includes a second detection unit for performing dynamic content detection on the initial address to generate a third detection result in response to determining that both the first detection result and the second detection result indicate normal.
[0160] According to an embodiment of the present disclosure, the static content detection submodule includes a first simulation unit and a static detection unit. The first simulation unit is used to access the initial address by simulating the target object to obtain the static content of the target webpage corresponding to the initial address. The static detection unit is used to detect the static content and generate a second detection result.
[0161] According to an embodiment of the present disclosure, the dynamic content detection submodule includes a second simulation unit and a dynamic detection unit. The second simulation unit is used to simulate the target object to interact with the target web page based on the initial address to obtain the dynamic content of the web page associated with the target web page. The dynamic detection unit is used to detect the dynamic content and generate a third detection result.
[0162] According to an embodiment of the present disclosure, the first control module includes: a first generating submodule, a first controlling submodule and a second controlling submodule.
[0163] The first generating submodule is used to generate prompt information in response to determining that the detection result indicates normal and at least one detection item is not completed; the prompt information is used to indicate the detection progress and the access risk level for the target webpage.
[0164] The first control submodule is used to control the gateway to perform an interception operation on the access request in response to determining to continue to perform the detection operation.
[0165] The second control submodule is used to control the gateway to execute a release operation for the access request in response to determining to continue to execute the access operation.
[0166] According to an embodiment of the present disclosure, the first control submodule includes a first control unit and a second control unit.
[0167] The first control unit is configured to control the gateway to execute a release operation for the access request in response to determining that the detection result of at least one detection item indicates normal.
[0168] The second control unit is configured to control the gateway to perform an interception operation on the access request in response to determining that the detection result of at least one detection item indicates an abnormality.
[0169] According to an embodiment of the present disclosure, the second control submodule includes: an alarm unit for sending an alarm message to a target object in response to receiving a detection result indicating an abnormality of at least one detection item, so as to prompt the target object to abandon the access operation to the target webpage.
[0170] According to an embodiment of the present disclosure, the first control module includes a third control submodule, which is used to control the gateway to perform an interception operation on the access request in response to determining that the detection result of at least one detection item indicates an abnormality.
[0171] According to an embodiment of the present disclosure, the first control module includes a fourth control submodule, which is used to control the gateway to perform a release operation on the access request in response to determining that the detection result indicates normal, wherein the detection result includes: a first detection result, a second detection result and a third detection result.
[0172] According to an embodiment of the present disclosure, the access control device further includes: a second acquisition module and a third generation module.
[0173] The second acquisition module is used to obtain the initial domain name from the initial address. The third generation module is used to generate the target address based on the predetermined domain name parameters and the initial address in response to determining that the initial domain name is an abnormal domain name.
[0174] According to an embodiment of the present disclosure, the access control device further includes: a third acquisition module and a second control module.
[0175] The third acquisition module is used to acquire the historical detection result of the historical address. The second control module is used to control the gateway whether to perform an interception operation on the access request based on the historical detection result in response to determining that the historical address includes an abnormal domain name and receiving an access request for the target address.
[0176] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.
[0177] According to an embodiment of the present disclosure, an electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.
[0178] According to an embodiment of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to execute the method as described above.
[0179] According to an embodiment of the present disclosure, a computer program product includes a computer program, and when the computer program is executed by a processor, the computer program implements the method as described above.
[0180] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.
[0181] like Figure 8As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 to a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0182] A number of components in the device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0183] The computing unit 801 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 801 performs the various methods and processes described above, such as the access control method. For example, in some embodiments, the access control method may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the access control method described above may be performed. Alternatively, in other embodiments, the computing unit 801 may be configured to perform the access control method in any other appropriate manner (e.g., by means of firmware).
[0184] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0185] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0186] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0187] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0188] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0189] A computer system may include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises through computer programs running on respective computers and having a client-server relationship to each other. The server may be a cloud server, a server in a distributed system, or a server combined with a blockchain.
[0190] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.
[0191] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. An access control method, comprising: In response to receiving the first information including the initial address, generating a target address based on a predetermined domain name parameter and the initial address; Replacing the initial address contained in the first information with the target address to obtain second information; sending the second information to the target device; In response to receiving the first information, performing asynchronous detection on the initial address to generate a target detection result; as well as In response to receiving an access request for the target address, the gateway is controlled to perform an interception operation or a release operation for the access request based on the target detection result.
2. The method according to claim 1, wherein: The generating of the target address based on the predetermined domain name parameter and the initial address comprises: Encoding the initial address to generate an encoded address; and The encoded address is concatenated with the predetermined domain name parameter to generate the target address.
3. The method according to claim 1 or 2, further comprising: Before the asynchronous detection of the initial address: Acquire historical detection items for historical addresses; wherein the historical detection items include at least one of the following: parameter detection, static content detection, and dynamic content detection; and In response to determining that the initial address and the historical address are of the same type, determining the detection item for the initial address to be the historical detection item.
4. The method according to claim 3, wherein determining that the initial address and the historical address are of the same type comprises: extracting a first feature of the initial address and a second feature of the historical address respectively; as well as Based on the similarity between the first feature and the second feature, it is determined whether the initial address and the historical address are of the same type.
5. The method according to claim 4, wherein the extracting the first feature of the initial address and the second feature of the historical address respectively comprises: Encoding the initial address to generate an encoded address; Encoding the historical address to generate an encoded historical address; extracting the first feature from the encoded address; as well as The second feature is extracted from the encoded historical address.
6. The method according to claim 1, wherein: The asynchronous detection of the initial address to generate a target detection result includes: Performing parameter detection on the initial address to generate a first detection result; Performing a static content detection on the initial address to generate a second detection result; and Performing dynamic content detection on the initial address to generate a third detection result; The target detection result includes: the first detection result, the second detection result and the third detection result.
7. The method according to claim 6, wherein: The performing static content detection on the initial address to generate a second detection result includes: In response to determining that the first detection result indicates normality, a static content detection is performed on the initial address to generate a second detection result.
8. The method according to claim 6 or 7, wherein: The performing dynamic content detection on the initial address to generate a third detection result includes: In response to determining that both the first detection result and the second detection result indicate normality, dynamic content detection is performed on the initial address to generate a third detection result.
9. The method according to any one of claims 6 to 8, wherein: The performing static content detection on the initial address to generate a second detection result includes: Accessing the initial address by simulating a target object to obtain static content of a target webpage corresponding to the initial URL; and The static content is detected to generate the second detection result.
10. The method according to any one of claims 6 to 9, wherein: The performing dynamic content detection on the initial address to generate a third detection result includes: Acquire dynamic content of a web page associated with the target web page by simulating the target object to interact with the target web page based on the initial address; and The dynamic content is detected to generate the third detection result.
11. The method according to any one of claims 6 to 10, wherein: In response to receiving the access request for the target address, based on the target detection result, controlling the gateway to perform an interception operation or a release operation for the access request includes: In response to determining that the target detection result indicates normal, and at least one detection item has not been completed, generating prompt information; the prompt information indicates the detection progress and the access risk level for the target webpage; In response to determining to continue to perform the detection operation, controlling the gateway to perform an interception operation on the access request; and In response to determining to continue to perform the access operation, the control gateway performs a release operation for the access request.
12. The method according to claim 11, wherein in response to determining to continue to perform the detection operation, the controlling gateway performs an interception operation on the access request, further comprising: In response to determining that the detection result of the at least one detection item indicates normal, controlling the gateway to perform a release operation for the access request; as well as In response to determining that the detection result of the at least one detection item indicates an abnormality, the control gateway performs an interception operation on the access request.
13. The method according to claim 11, wherein: In response to determining to continue to perform the access operation, controlling the gateway to perform a release operation for the access request, further comprising: In response to receiving the target detection result indicating an abnormality of the at least one detection item, sending an alarm message to the target device to prompt the target object to abandon the access operation to the target webpage.
14. The method according to any one of claims 6 to 10, wherein: In response to receiving the access request for the target address, based on the target detection result, controlling the gateway to perform an interception operation or a release operation for the access request includes: In response to determining that the detection result of at least one detection item indicates an abnormality, the control gateway performs an interception operation on the access request.
15. The method according to any one of claims 6 to 10, wherein: In response to receiving the access request for the target address, based on the detection result, controlling whether the gateway performs an interception operation for the access request includes: In response to determining that the detection result indicates normal, the control gateway performs a release operation on the access request, wherein the target detection result includes: the first detection result, the second detection result, and the third detection result.
16. The method according to claim 1, further comprising: Obtaining an initial domain name from the initial address; as well as In response to determining that the initial domain name is an abnormal domain name, a target address is generated based on predetermined domain name parameters and the initial address.
17. The method according to claim 15, further comprising: Get historical detection results of historical addresses; as well as In response to determining that the historical address includes the abnormal domain name and receiving an access request for the target address, based on the historical detection result, the gateway is controlled whether to perform an interception operation for the access request.
18. An access control device, comprising: A first generating module, configured to generate a target address based on a predetermined domain name parameter and the initial address in response to receiving first information including the initial address; a replacement module, configured to replace the initial address included in the first information with the target address to obtain second information; A sending module, used for sending the second information to a target device; A second generating module, configured to detect the initial address and generate a target detection result in response to receiving the first information; as well as The first control module is used to control the gateway whether to perform an interception operation or a release operation on the access request based on the target detection result in response to receiving the access request for the target address.
19. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 17.
20. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-17.
21. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 17.