SaaS-based interactive server website Cookie scanning method and system
By injecting hook scripts into web pages and listening to HTTP response header information, combined with DOM structure monitoring and user interaction behavior upload, the problem of difficulty in dealing with complex user interaction and dynamic content generation in the existing technology is solved, and comprehensive capture of cookie information and dynamic page updates are achieved.
Patent Information
- Application Number
- CN202411838040.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-16
AI Technical Summary
Existing cookie management technology based on SaaS architecture is difficult to effectively deal with complex user interaction and dynamic content generation problems.
By injecting hook scripts into the web page and listening to HTTP response header information, all set cookie information are captured; crawling the DOM structure of the web page and generating DOM snapshots, monitoring the changes in the DOM structure and redrawing the page; collecting user interaction behavior and uploading it to the server, updating DOM and cookies and passing them back to the client; storing cookies according to the source category, and displaying and managing them on the interface.
It realizes comprehensive capture and management of cookie information set by the client and server, monitors changes in the DOM structure, and realizes real-time redrawing and dynamic updates of the page, and supports interactive scanning of website cookies.
Smart Images

Figure CN120011670A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data security and management, and in particular to a SaaS-based server-side website Cookie scanning method and system. Background Art
[0002] With the continuous development of Internet technology, user privacy protection and data security have become important issues worldwide. Especially after the introduction of laws and regulations such as the General Data Protection Regulation and the Personal Information Protection Law, the collection and use of user data have been subject to stricter supervision. Cookies are a technology widely used for network user identity identification and behavior tracking. The legality and transparency of their use and management are increasingly valued. All types of personal device identification numbers used in the current Internet industry, including Cookie IDs, are personal information. The use of such information for marketing requires explicit personal authorization. Scanning existing websites, identifying various active and third-party cookies generated during the use of the website, and classifying and managing cookies is the first step in website compliance.
[0003] Existing cookie scanning technologies are mainly divided into two categories: active scanning and passive scanning. Some existing mature website cookie scanning products, such as Mozilla Observatory, OneTrust, etc., all support active scanning in terms of function, that is, after the user enters the domain name to be scanned, the scanning tool automatically completes the subsequent link crawling and cookie scanning functions. Active scanning usually uses crawlers to traverse web pages, capture and analyze the cookie information on the page. However, active scanning is difficult to cope with complex user interaction scenarios, such as dynamic content generated by JavaScript or interactive behaviors that require user input. There are also solutions based on passive scanning, such as Xray, which supports submitting the traffic of visiting websites to the scanner for scanning by configuring a proxy server. Passive scanning captures the traffic when users visit the website through a proxy server and extracts the cookie information therein. Although it can obtain the cookies when the user actually operates, this method has high technical requirements for users and cannot be directly integrated into the SaaS platform, limiting its wide application.
[0004] Current cookie scanning tools have many limitations when dealing with modern complex web pages, and it is difficult to meet the cookie scanning problem in scenarios that require user interaction: existing active scanning tools are difficult to simulate the behavior of real users, resulting in many key cookies not being captured. Active scanning is difficult to simulate the complete behavior of real users. For example, login and registration behaviors that require SMS verification codes are difficult to complete through link crawling or crawler simulation clicks. For single-page applications (SPA) rendered by JavaScript, it is difficult to effectively discover cookies that require user interaction; although passive scanning can obtain more comprehensive cookie information by capturing traffic, its complex configuration and operation process make it difficult for non-technical users to use it. Passive scanning has high technical requirements for users and requires a series of operations such as installing root certificates and configuring proxy servers. It cannot be provided to users as a SaaS service. Traditional scanning methods need to be improved in capturing and tracking dynamically loaded content and generating cookies. How to effectively distinguish and manage these cookies has become an urgent problem to be solved. Summary of the invention
[0005] In view of the problems existing in the above-mentioned existing SaaS-based interactive server-side website Cookie scanning method and system, the present invention is proposed.
[0006] Therefore, the problem to be solved by the present invention is that the existing Cookie management technology based on the SaaS architecture is usually unable to effectively deal with complex user interaction and dynamic content generation problems.
[0007] To solve the above technical problems, the present invention provides the following technical solutions: a SaaS-based interactive server-side website Cookie scanning method, which comprises:
[0008] Build a server-side website cookie scanning system based on SaaS architecture;
[0009] Inject the hook script into the web page and monitor the response header information to capture all set Cookie information;
[0010] After capturing the cookie information, it crawls the DOM structure of the web page and generates a DOM snapshot, monitors changes in the DOM structure and redraws the page;
[0011] Collect user interaction behaviors and upload them to the server, update DOM and Cookies and send them back to the client;
[0012] Cookies are stored according to source categories and displayed and managed on the interface.
[0013] As a preferred solution of the SaaS-based interactive server-side website Cookie scanning method of the present invention, wherein: the server-side website Cookie scanning system constructed based on the SaaS architecture includes:
[0014] Choose to use the SaaS architecture, configure and start the Electron scanner kernel;
[0015] Use the virtual frame buffer Xvfb to simulate the display device and configure the resolution and color depth of Xvfb;
[0016] Configure the Electron scanner kernel to headless mode, specify Xvfb as the display output, open the debug port, and start remote debugging;
[0017] Encapsulate the configured Electron scanner kernel into a container and deploy and manage it through Kubernetes.
[0018] As a preferred solution of the SaaS-based interactive server-side website cookie scanning method of the present invention, wherein: the step of encapsulating the configured Electron scanner kernel into a container and deploying and managing it through Kubernetes refers to defining the basic image, dependencies, configuration and startup commands of the Electron scanner kernel and Xvfb of the container in a Dockerfile;
[0019] Collect the code of Electron scanner kernel, hook scripts, MutationObserver listener, API, Kubernetes monitoring and management tools from the developer's code base and copy them to the container, and use the Kubernetes container orchestration tool to start, stop, scale, and monitor the container;
[0020] Dynamically adjust the number of containers and resource allocation based on business needs;
[0021] Create container images, each of which includes the application code, runtime environment, and dependencies, and save the container images to the image repository;
[0022] Write Kubernetes configuration files and use the Kubernetes command line tool to deploy container images to the Kubernetes cluster based on the configuration files;
[0023] After the deployment is complete, the running status of the server-side website cookie scanning system is monitored in real time through Kubernetes monitoring and management tools;
[0024] Set a trigger in the code base. If the code is submitted to the main branch, the CI / CD tool will be automatically started. After each code update, the server-side website cookie scanning system will automatically build a new container image to the image repository and deploy it to the Kubernetes cluster.
[0025] As a preferred solution of the SaaS-based interactive server-side website Cookie scanning method of the present invention, wherein: the injecting of a hook script into a web page and monitoring the response header information, capturing all set Cookie information means that when the Electron scanner kernel loads a web page, the hook script is automatically injected, and the Cookie is recorded and stored;
[0026] After the Electron scanner kernel is started, the HTTP request and response interception technology is used to monitor and capture all HTTP response header information in real time, and the cookies in the `Set-Cookie` field are extracted from the HTTP response header information and stored;
[0027] Store each cookie in a table in a relational database. The table includes the cookie name, value, domain name, path, expiration time, and cookie source.
[0028] When a new cookie is captured, it is automatically inserted into the relational database for storage and data verification is automatically performed.
[0029] As a preferred solution of the SaaS-based interactive server-side website cookie scanning method of the present invention, wherein: the DOM structure of the web page is captured and a DOM snapshot is generated after the cookie information is captured, and the changes in the DOM structure are monitored and the page is redrawn, which means that after the cookie information is captured, the DOM structure of the entire page is firstly captured and a DOM snapshot is generated, and the DOM structures the web page into a tree structure, in which each node data represents a part of the web page, including HTML tags, attributes and text;
[0030] The first captured DOM snapshot is compressed using the `gzip` algorithm;
[0031] Use the MutationObserver monitor to monitor changes in the DOM structure in the Electron scanner kernel, record the changed node data, serialize the changed node data and transmit it to the client through the network;
[0032] After receiving the changed node data, the client browser uses the DOM snapshot and the changed node data to redraw the page;
[0033] After the initial DOM snapshot is transferred, continue to use the MutationObserver monitor to continuously monitor changes in the DOM structure in the Electron scanner core;
[0034] Each time the changed node data is transmitted, a unique version number is created for each DOM snapshot by combining the timestamp with the page identifier;
[0035] In the client browser, the DOM snapshot is cached, and the snapshot version that has not been accessed for the longest time is eliminated first based on the timestamp of the version number by using the LRU algorithm.
[0036] As a preferred solution of the SaaS-based interactive server-side website cookie scanning method of the present invention, wherein: the collecting of user interaction behaviors and uploading to the server, updating DOM and Cookie and transmitting back to the client refers to using a JavaScript interface to collect all user interaction behaviors, including mouse clicks, form inputs and page scrolling;
[0037] Encapsulate the collected interaction behaviors into JSON data and send it to the server-side API gateway using `XMLHttpRequest`;
[0038] After receiving the interactive behavior, the server parses the JSON data and sends the operation instructions to the rendering process through the Electron API. The rendering process finds the corresponding DOM node data in the web page through the JavaScript interface and performs the corresponding operation. After the operation is performed, the Electron scanner kernel generates a new DOM snapshot, re-captures the latest cookie and transmits it back to the client through the API gateway, updates the page and displays the new cookie.
[0039] As a preferred solution of the SaaS-based interactive server-side website Cookie scanning method of the present invention, wherein: the storing of Cookies according to source classification and displaying and managing on the interface refers to classifying Cookies into client settings and server settings according to different sources of the client and the server, initializing the data structure, and the data structure uses a hash table to store different types of Cookies;
[0040] Set up the user interface, divide the interface into the client display area and the server display area to display the classified cookies, and provide cookie sorting and filtering functions in the display area.
[0041] Another object of the present invention is to provide a SaaS-based interactive server-side website Cookie scanning system, which comprises:
[0042] Build a system module to build a server-side website cookie scanning system based on SaaS architecture;
[0043] Cookie capture module, which is used to inject hook scripts into web pages and monitor response header information to capture all set Cookie information;
[0044] DOM snapshot and redraw module, which is used to capture the DOM structure of the web page after capturing the cookie information and generate a DOM snapshot, monitor the changes of the DOM structure and redraw the page;
[0045] User interaction module, used to collect user interaction behaviors and upload them to the server, update DOM and Cookies and transmit them back to the client;
[0046] The storage and display module is used to store cookies according to source classification and display and manage them on the interface.
[0047] A computer device comprises: a memory and a processor; the memory stores a computer program, and the processor implements the steps of the above-mentioned SaaS-based interactive server-side website Cookie scanning method when executing the computer program.
[0048] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned SaaS-based interactive server-side website Cookie scanning method.
[0049] The beneficial effects of the present invention are as follows: by adopting the SaaS architecture, combining the containerized deployment of the Electron scanner kernel and Kubernetes management, the cross-platform operation efficiency and automated operation and maintenance capabilities are significantly improved. By injecting hook scripts into web pages and monitoring HTTP response header information, the cookie information set by the client and server can be fully captured and managed, and the mechanism of monitoring changes in the DOM structure and transmitting the changed node data can be realized, thus realizing real-time redrawing and dynamic updating of the page. The technical solution of this application supports interactive scanning of cookies of websites by linking the server through remote control. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0051] Figure 1 The figure is a flowchart of a cookie scanning method for an interactive server-side website based on SaaS.
[0052] Figure 2 This is an overall architecture diagram of the interactive Cookie scanning service in one embodiment of the present application;
[0053] Figure 3 This is a timing diagram of the interactive cookie scanning service operation in an embodiment of the present application.
[0054] Figure 4 The Electron scanner kernel architecture in one embodiment of the present application;
[0055] Figure 5 A diagram showing how MutationObserver works for HTML5.
[0056] Figure 6 This is a structural diagram of the Cookie scanning system for interactive server-side websites based on SaaS. DETAILED DESCRIPTION
[0057] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below in conjunction with the accompanying drawings.
[0058] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0059] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or selective embodiment that is mutually exclusive with other embodiments.
[0060] Example 1
[0061] Reference Figure 1-Figure 3 , which is the first embodiment of the present invention, and this embodiment provides a SaaS-based interactive server-side website Cookie scanning method, the SaaS-based interactive server-side website Cookie scanning method includes:
[0062] S1. Build a server-side website cookie scanning system based on SaaS architecture;
[0063] Specifically, building a server-side website cookie scanning system based on the SaaS architecture includes:
[0064] Choose to use the SaaS architecture, configure and start the Electron scanner kernel; the Electron scanner kernel architecture is as follows Figure 4 As shown;
[0065] The Electron scanner kernel usually requires a physical display device for page rendering, uses a virtual frame buffer Xvfb to simulate a display device, and configures the resolution and color depth of Xvfb; the Electron scanner kernel is a client application based on Chromium. The default operating mode requires a display device to be connected, and the display device is an exclusive resource and cannot be horizontally expanded through containerization technology. In order to use the Electron scanner kernel in a container to load a complete page, Cookie scanning is performed. This application uses Xvfb to simulate a dummy display device, runs Electron in a non-display mode, and displays the output to Xvfb instead of real display resources. This embodiment uses a service-based Headless method to run the Electron scanner kernel program.
[0066] Configure the Electron scanner kernel to headless mode, specify Xvfb as the display output, open the debug port, and start remote debugging;
[0067] Encapsulate the configured Electron scanner kernel into a container and deploy and manage it through Kubernetes.
[0068] By building a server-side website cookie scanning system based on the SaaS architecture, starting the Electron scanner kernel, and using the virtual frame buffer Xvfb to simulate the display device, the Electron scanner can render pages in an environment without a physical display device, run in headless mode, support remote debugging, encapsulate the configured scanner kernel into a container, and deploy and manage it through Kubernetes, we can achieve efficient deployment of the system, dynamic allocation and management of resources, and cross-platform compatibility, ultimately improving the scalability and maintainability of the system.
[0069] Furthermore, in order to monitor and schedule the operation of the Electron scanner kernel, we use a SpringBoot-based Java web service to start the Electron application, submit commands, and encapsulate the service and the Electron application in a Docker container. The life cycle of the Electron application is managed through the Java application service, such as starting the Electron application. Encapsulating the configured Electron scanner kernel into the container and deploying and managing it through Kubernetes means defining the container's base image, dependencies, Electron scanner kernel, and Xvfb configuration and startup commands in the Dockerfile. The Dockerfile is a text file that defines the build process of a container. The container is an independent, lightweight virtualization environment created by Docker technology. It encapsulates the application and all its dependencies so that the application can run consistently in different operating environments;
[0070] Determine dependencies and configure the corresponding operating environment in the container. Dependencies refer to all external resources and environment configurations required for the normal operation of the application.
[0071] Collect the code of Electron scanner kernel, hook scripts, MutationObserver listener, API, Kubernetes monitoring and management tools from the developer's code base and copy them to the container, and use the Kubernetes container orchestration tool to start, stop, scale, and monitor the container;
[0072] Dynamically adjust the number of containers and resource allocation according to business needs. The specific steps of dynamic adjustment include writing Kubernetes deployment configuration files, defining the configuration of each container, including resource requirements, environment variables and port mappings, configuring services and load balancers, and setting automatic expansion policies to automatically change the number of container instances based on the server-side website cookie scanning system load. The number of container instances refers to the number of actual copies of a specific container running in a containerized environment;
[0073] Create container images, each of which includes the application code, runtime environment, and dependencies, and save the container images to the image repository;
[0074] Write Kubernetes configuration files and use the Kubernetes command line tool to deploy container images to the Kubernetes cluster based on the configuration files;
[0075] After the deployment is complete, the running status of the server-side website cookie scanning system is monitored in real time through Kubernetes monitoring and management tools;
[0076] Set a trigger in the code base. If the code is submitted to the main branch, the CI / CD tool will be automatically started. After each code update, the server-side website cookie scanning system will automatically build a new container image to the image repository and deploy it to the Kubernetes cluster.
[0077] By encapsulating the configured Electron scanner kernel into a container and using Kubernetes for deployment and management, cross-platform consistency of the application, efficient use of resources, and dynamic expansion are achieved. By defining the basic image and dependencies of the container, the consistent operation of the application in different environments is ensured. Kubernetes is used for container orchestration and monitoring, and the number of container instances can be dynamically adjusted according to the system load to optimize resource allocation. The automated CI / CD process ensures that after each code update, the system can automatically build and deploy the latest container image, thereby improving the maintainability and update efficiency of the system and ensuring the continuous availability and efficiency of the service.
[0078] S2. Inject the hook script into the web page and monitor the response header information to capture all set Cookie information;
[0079] Specifically, injecting a hook script into a web page and monitoring the response header information to capture all set cookie information means that when the Electron scanner kernel loads a web page, the hook script is automatically injected to record and store the cookies. The hook script intercepts access to and modification of the `document.cookie` attribute to ensure that each time a cookie is written, it can be recorded, including the name, value, path, domain name, and expiration time.
[0080] After the Electron scanner kernel is started, HTTP request and response interception technology is used to monitor and capture all HTTP response header information in real time, extract the cookies in the `Set-Cookie` field from the HTTP response header information and store them. The response header contains metadata about the response, including content type, content length, cache control instructions, and cookie setting information;
[0081] Store each cookie in a table in a relational database. The table includes the cookie name, value, domain name, path, expiration time, and cookie source.
[0082] When a new cookie is captured, it is automatically inserted into the relational database for storage and data verification is automatically performed.
[0083] By automatically injecting hook scripts when a web page is loaded and monitoring HTTP response header information, the system can fully capture and accurately manage all Cookie information set by the client and the server. The hook script intercepts the access and modification of the `document.cookie` attribute to ensure that each time the client sets or modifies the cookie through JavaScript, the system can record its detailed information in real time, including the name, value, path, domain name and expiration time, ensuring the transparency and traceability of all Cookie operations set on the front end. After the Electron scanner kernel is started, the system uses HTTP request and response interception technology to monitor and capture the `Set-Cookie` field in all HTTP response headers in real time, which makes the system The system can capture all Cookie information set by the server, further improving the comprehensiveness of Cookie capture. All captured Cookie information will be stored in a table in the relational database, which stores the detailed data of the Cookie in a structured manner. After capturing a new Cookie, the system will automatically insert it into the database and perform data verification to ensure data consistency and integrity. It can not only fully record and manage all Cookie information, but also ensure data accuracy and reliability through structured storage and data verification in the database, which improves the system's comprehensive monitoring and management capabilities for Cookies in complex network environments, helps to achieve more accurate data analysis and compliance management, and ensures the security and controllability of user data.
[0084] Implement Cookie traceability through Cookie Hook:
[0085] Cookie scanning usually hopes to know the source of each cookie as a basis for blocking cookies on demand.
[0086] When a web page is loaded, there are two ways to write cookies:
[0087] 1. The front-end JavaScript script calls document.cookie and writes the cookie content.
[0088] 2. In the HTTP response header returned by the server, there is a set-cookie field. The browser recognizes this field and writes the cookie.
[0089] This solution uses hook scripts and HTTP response packet capture to track the source of cookie writing. The following is an overview of the two methods:
[0090] (1)Hook script
[0091] Through Object.defineProperty, document.cookie is hijacked. The purpose is to record all operations on cookies through front-end JavaScript. When the Electron scanner loads the page, it will automatically inject the Cookie Hook script into the current site to complete the hijacking of the Cookie write API.
[0092] (2) HTTP response header
[0093] Cookies set by the server are implemented by capturing the Set-Cookie field in the HTTP response header during page loading. Electron provides a monitoring function for monitoring cookies of content pages.
[0094] S3, after capturing the cookie information, crawl the DOM structure of the web page and generate a DOM snapshot, monitor the changes of the DOM structure and redraw the page;
[0095] The view state of a web page can be described in the form of a DOM tree. When crawling a page, it does not take a screenshot of the current page, but records the state of the DOM tree. This state is called a snapshot.
[0096] The size of DOM tree snapshot is very large (usually 2MB-10MB). In order to reduce the transmission size, except for the first full snapshot, the incremental part is transmitted in the subsequent process. We use the MutationObserver provided by HTML5 to observe and record DOM changes and pass the changes to the client's browser. The working principle of MutationObserver is as follows Figure 5 As shown. The captured DOM snapshot is transmitted to the customer's browser through the network, and the DOM tree is rebuilt in a sandbox (iframe in this solution), so that the web page in the Electron scanner can be presented to the user, which we call redrawing. The first redraw requires a complete page snapshot, and subsequent rendering only requires incremental parts.
[0097] Specifically, after capturing the cookie information, the DOM structure of the web page is captured and a DOM snapshot is generated. Monitoring the changes in the DOM structure and redrawing the page means that after capturing the cookie information, the DOM structure of the entire page is firstly captured and a DOM snapshot is generated. The DOM structures the web page into a tree structure, in which each node data represents a part of the web page, including HTML tags, attributes and text.
[0098] The first captured DOM snapshot is compressed using the `gzip` algorithm;
[0099] Use the MutationObserver monitor to monitor changes in the DOM structure in the Electron scanner kernel, record the changed node data, serialize the changed node data and transmit it to the client through the network. MutationObserver is an API provided by the browser that allows developers to monitor changes in the DOM structure in JavaScript;
[0100] After receiving the changed node data, the client browser uses the DOM snapshot and the changed node data to redraw the page;
[0101] After the initial DOM snapshot is transferred, continue to use the MutationObserver monitor to continuously monitor changes in the DOM structure in the Electron scanner core;
[0102] Each time the changed node data is transmitted, a unique version number is created for each DOM snapshot by combining the timestamp with the page identifier;
[0103] In the client browser, the DOM snapshot is cached, and the snapshot version that has not been accessed for the longest time is eliminated first based on the timestamp of the version number by using the LRU algorithm.
[0104] By capturing the DOM structure of the web page and generating a DOM snapshot after capturing the cookie information, accurate monitoring and dynamic updating of the web page content and structure are achieved. When the system loads the web page for the first time, the DOM structure of the entire page is captured and a DOM snapshot is generated. This structured tree representation method enables each element and attribute of the web page to be accurately recorded. The DOM snapshot captured for the first time is compressed using the `gzip` algorithm, which effectively reduces the bandwidth requirement for data transmission and improves the transmission efficiency of the system. Using the `MutationObserver` monitor, the system can continuously monitor changes in the DOM structure, record and serialize these changes, and transmit them to the client browser through the network. After receiving these changes, the client browser redraws the page in combination with the initial DOM snapshot, thereby achieving real-time updates of the web page content. The system ensures the accuracy of version management by creating a unique version number for each DOM snapshot, and uses the LRU algorithm to cache the DOM snapshot, giving priority to eliminating the snapshot version that has not been accessed for the longest time. This not only optimizes the utilization of the cache space, but also ensures that users can quickly load the latest page content when accessing, improves the dynamic response capability of complex web pages, and ensures the consistency and fluency of the page in user interaction.
[0105] S4, collect user interaction behaviors and upload them to the server, update DOM and Cookie and send them back to the client;
[0106] Synchronous user interaction: Usually, cookies on websites are generated after user interaction. For example, when visiting the homepage of a website, the user is prompted whether to authorize the use of cookies. In addition, cookies are also generated during user registration, login, and operating system operation. These interactive behaviors cannot be completely completed through active scanning link crawling or crawler simulation clicks. This solution collects the user's interactive behavior on the redrawn DOM structure and forwards it to the Electron scanning kernel program of the corresponding container through the API gateway. In the process, to ensure that the interactive behavior is load balanced to the container instance that generates the snapshot, it is necessary to maintain the session according to the source address (ClientIP). The interactive behaviors that need to be forwarded include: mouse clicks, page or element scrolling, and input. After the user's interactive behavior on the redrawn DOM structure is transmitted to the Electron scanning kernel program of the corresponding container through the network, the JS command executor will find the element corresponding to the xPath and execute the statement to modify the value attribute. And generate the increment of the DOM snapshot and send it back to the client browser for redrawing. After the redrawing is successful, the cookies in the Electron scanning kernel program will be re-captured and sent back to the client browser to complete a round of interactive cookie scanning process.
[0107] Specifically, collecting user interaction behaviors and uploading them to the server, updating DOM and cookies and transmitting them back to the client means using JavaScript interfaces to collect all user interaction behaviors, including mouse clicks, form inputs, and page scrolling;
[0108] Encapsulate the collected interaction behaviors into JSON data and send it to the server-side API gateway using `XMLHttpRequest`;
[0109] After receiving the interactive behavior, the server parses the JSON data and sends the operation instructions to the rendering process through the Electron API. The rendering process finds the corresponding DOM node data in the web page through the JavaScript interface and performs the corresponding operation. After the operation is performed, the Electron scanner kernel generates a new DOM snapshot, re-captures the latest cookie and transmits it back to the client through the API gateway, updates the page and displays the new cookie.
[0110] By collecting user interaction behaviors and uploading them to the server, dynamic updates and real-time interactions of web page content are achieved. The system uses JavaScript interfaces to comprehensively collect user interaction behaviors, including mouse clicks, form inputs, and page scrolling, and encapsulates these behavior data into JSON format.
[0111] `XMLHttpRequest` is sent to the server. After receiving the data, the server parses it and passes the operation instructions to the rendering process through the ElectronAPI. The rendering process locates the corresponding DOM node and performs corresponding operations to ensure that the user's interaction can be reflected immediately on the page. The Electron scanner kernel generates a new DOM snapshot and re-grabs the latest cookie information. The updated data is sent back to the client through the API gateway, and finally the latest content and cookie status are displayed on the page, which improves the system's response speed and user experience, ensures fast feedback and content updates of complex web pages after user operations, and realizes highly dynamic and personalized web page interactions.
[0112] S5. Store cookies according to source classification and display and manage them on the interface;
[0113] Specifically, storing cookies by source classification and displaying and managing them on the interface means classifying cookies into client settings and server settings according to the different sources of the client and server, initializing the data structure, and using a hash table to store different types of cookies;
[0114] Set up the user interface, divide the interface into the client display area and the server display area to display the classified cookies, and provide cookie sorting and filtering functions in the display area.
[0115] By storing cookies according to their source and displaying and managing them on the interface, we have achieved systematized cookie management and intuitive user interface. Cookies are divided into client settings and server settings according to their source, and efficiently stored through a hash table structure to ensure fast and accurate data access. On the user interface, the system divides cookies into client display areas and server display areas, clearly displays the classified cookie information, and provides sorting and filtering functions to facilitate users to quickly locate and manage specific cookies. This not only improves the efficiency of cookie management, but also enhances the user's visibility and control over cookie data, so that complex cookie information can be displayed in a concise and clear manner, improving user experience and the convenience of data management.
[0116] Example 2
[0117] Reference Figure 6 , which is the second embodiment of the present invention. This embodiment is different from the previous embodiment and provides a SaaS-based server-side website Cookie scanning system, including:
[0118] Build a system module to build a server-side website cookie scanning system based on SaaS architecture;
[0119] Cookie capture module, which is used to inject hook scripts into web pages and monitor response header information to capture all set Cookie information;
[0120] DOM snapshot and redraw module, which is used to capture the DOM structure of the web page after capturing the cookie information and generate a DOM snapshot, monitor the changes of the DOM structure and redraw the page;
[0121] User interaction module, used to collect user interaction behaviors and upload them to the server, update DOM and Cookies and transmit them back to the client;
[0122] The storage and display module is used to store cookies according to source classification and display and manage them on the interface.
[0123] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.
[0124] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0125] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0126] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0127] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A SaaS-based interactive server-side website cookie scanning method, characterized in that: include, Build a server-side website cookie scanning system based on SaaS architecture; Inject the hook script into the web page and monitor the response header information to capture all set Cookie information; After capturing the cookie information, it crawls the DOM structure of the web page and generates a DOM snapshot, monitors changes in the DOM structure and redraws the page; Collect user interaction behaviors and upload them to the server, update DOM and Cookies and send them back to the client; Cookies are stored according to source categories and displayed and managed on the interface.
2. The SaaS-based interactive server-side website Cookie scanning method according to claim 1, characterized in that: The server-side website cookie scanning system constructed based on SaaS architecture includes: Choose to use the SaaS architecture, configure and start the Electron scanner kernel; Use the virtual frame buffer Xvfb to simulate the display device and configure the resolution and color depth of Xvfb; Configure the Electron scanner kernel to headless mode, specify Xvfb as the display output, open the debug port, and start remote debugging; Encapsulate the configured Electron scanner kernel into a container and deploy and manage it through Kubernetes.
3. The SaaS-based interactive server-side website Cookie scanning method according to claim 2, characterized in that: Encapsulating the configured Electron scanner kernel into a container and deploying and managing it through Kubernetes means defining the container's base image, dependencies, configuration and startup commands of the Electron scanner kernel and Xvfb in a Dockerfile; Determine dependencies and configure the corresponding operating environment in the container; Collect the code of Electron scanner kernel, hook scripts, MutationObserver listener, API, Kubernetes monitoring and management tools from the developer's code base and copy them to the container, and use the Kubernetes container orchestration tool to start, stop, scale, and monitor the container; Dynamically adjust the number of containers and resource allocation based on business needs; Create container images, each of which includes the application code, runtime environment, and dependencies, and save the container images to the image repository; Write Kubernetes configuration files and use the Kubernetes command line tool to deploy container images to the Kubernetes cluster based on the configuration files; After the deployment is complete, the running status of the server-side website cookie scanning system is monitored in real time through Kubernetes monitoring and management tools; Set a trigger in the code base. If the code is submitted to the main branch, the CI / CD tool will be automatically started. After each code update, the server-side website cookie scanning system will automatically build a new container image to the image repository and deploy it to the Kubernetes cluster.
4. The SaaS-based interactive server-side website Cookie scanning method according to claim 3, characterized in that: The injecting of the hook script into the web page and monitoring the response header information, capturing all set Cookie information means that when the Electron scanner kernel loads the web page, the hook script is automatically injected, and the Cookie is recorded and stored; After the Electron scanner kernel is started, the HTTP request and response interception technology is used to monitor and capture all HTTP response header information in real time, and the cookies in the `Set-Cookie` field are extracted from the HTTP response header information and stored; Store each cookie in a table in a relational database. The table includes the cookie name, value, domain name, path, expiration time, and cookie source. When a new cookie is captured, it is automatically inserted into the relational database for storage and data verification is automatically performed.
5. The SaaS-based interactive server-side website Cookie scanning method according to claim 4, characterized in that: The method of capturing the DOM structure of the web page and generating a DOM snapshot after capturing the cookie information, monitoring the changes of the DOM structure and redrawing the page refers to capturing the DOM structure of the entire page for the first time and generating a DOM snapshot after capturing the cookie information. The DOM structures the web page into a tree structure, in which each node data represents a part of the web page, including HTML tags, attributes and text; The first captured DOM snapshot is compressed using the `gzip` algorithm; Use the MutationObserver monitor to monitor changes in the DOM structure in the Electron scanner kernel, record the changed node data, serialize the changed node data and transmit it to the client through the network; After receiving the changed node data, the client browser uses the DOM snapshot and the changed node data to redraw the page; After the initial DOM snapshot is transferred, continue to use the MutationObserver monitor to continuously monitor changes in the DOM structure in the Electron scanner core; Each time the changed node data is transmitted, a unique version number is created for each DOM snapshot by combining the timestamp with the page identifier; In the client browser, the DOM snapshot is cached, and the snapshot version that has not been accessed for the longest time is eliminated first based on the timestamp of the version number by using the LRU algorithm.
6. The SaaS-based interactive server-side website Cookie scanning method according to claim 5, characterized in that: The collecting of user interaction behaviors and uploading to the server, updating DOM and Cookie and transmitting back to the client refers to using JavaScript interface to collect all user interaction behaviors, including mouse clicks, form input and page scrolling; Encapsulate the collected interaction behaviors into JSON data and send it to the server-side API gateway using `XMLHttpRequest`; After receiving the interactive behavior, the server parses the JSON data and sends the operation instructions to the rendering process through the Electron API. The rendering process finds the corresponding DOM node data in the web page through the JavaScript interface and performs the corresponding operation. After the operation is performed, the Electron scanner kernel generates a new DOM snapshot, re-captures the latest cookie and transmits it back to the client through the API gateway, updates the page and displays the new cookie.
7. The SaaS-based interactive server-side website Cookie scanning method according to claim 6, characterized in that: The storing of cookies by source classification and displaying and managing them on the interface refers to classifying cookies into client settings and server settings according to different sources of the client and the server, initializing the data structure, and storing different types of cookies in the form of a hash table; Set up the user interface, divide the interface into the client display area and the server display area to display the classified cookies, and provide cookie sorting and filtering functions in the display area.
8. A SaaS-based interactive server-side website Cookie scanning system based on the SaaS-based interactive server-side website Cookie scanning method according to any one of claims 1 to 7, characterized in that: include, Build a system module to build a server-side website cookie scanning system based on SaaS architecture; Cookie capture module, which is used to inject hook scripts into web pages and monitor response header information to capture all set Cookie information; DOM snapshot and redraw module, which is used to capture the DOM structure of the web page after capturing the cookie information and generate a DOM snapshot, monitor the changes of the DOM structure and redraw the page; User interaction module, used to collect user interaction behaviors and upload them to the server, update DOM and Cookies and transmit them back to the client; The storage and display module is used to store cookies according to source classification and display and manage them on the interface.
9. A computer device comprising: Memory and processor; The memory stores a computer program, characterized in that: when the processor executes the computer program, the steps of the SaaS-based interactive server-side website Cookie scanning method described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the SaaS-based interactive server-side website Cookie scanning method described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Website performance monitoring method and system based on cloud
CN120602380A
A cloud-based website performance monitoring method and system
CN120602380B