Website link security detection method
By adding website links identified as security status to multi-level whitelists and setting their security levels and detection rules, the problems of lag and time-consuming website risk identification in the prior art are solved, and more accurate and efficient website link security detection is achieved.
Patent Information
- Application Number
- CN202311607810.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the risk identification of the website is lagging behind, and it is difficult to predict whether a website is risky in advance, and there is a problem of time-consuming, so it is impossible to accurately identify risky websites with different display contents during the period.
Provide a security detection method for website links, by adding website links identified as security status to multiple whitelists and setting their security levels and detection rules, including detection frequency and/or detection methods, updating the security level of website links based on the detection results or removing them from the whitelist.
This avoids the possible security risks caused by the fact that one-time detection of the website link is not continuously carried out in security testing, and realizes more accurate identification of unsafe website links, and improves the security detection efficiency of website links.
Smart Images

Figure CN120045804A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communications, and more particularly, to a method for detecting the security of website links. Background Art
[0002] In the related art, the risk identification of websites has a lag, and it is difficult to predict in advance whether a website has risks. At the same time, there is a problem of long time consumption, and some "risky websites" have the characteristics that the content displayed is different at different times, making it difficult to accurately identify. Although the privacy security technology of terminal products has developed rapidly, illegal activities against customers are still very rampant, and there are still various deficiencies in the prevention of risk factors in the network. Summary of the Invention
[0003] The embodiments of the present application provide a method for detecting the security of website links to at least solve the problem that security risks may be caused by the lack of continuous security detection for website links that are detected as safe in one detection.
[0004] According to an embodiment of the present application, a method for detecting the security of website links is provided, including: adding website links identified as in a safe state to a multi-level whitelist, and setting the security level of the website links and the detection rules for each security level, where the detection rules include detection frequency and / or detection method; performing security detection on the website links in the multi-level whitelist according to the detection rules corresponding to the security level of the website links, and updating the security level of the website links or removing the website links from the multi-level whitelist according to the detection results.
[0005] According to another embodiment of the present application, a computer-readable storage medium is further provided, where a computer program is stored in the computer-readable storage medium, and the computer program is configured to execute the steps in any one of the above method embodiments when running.
[0006] According to another embodiment of the present application, an electronic device is further provided, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0007] In the embodiments of the present application, since website links identified as safe are added to the whitelist for subsequent security detection, the potential security risks caused by no longer paying attention after identifying a risky website that displays different contents at different times as safe are avoided. Meanwhile, in order to rationally utilize resources and efficiently detect website links, different security levels are set for different website links in the embodiments of the present application, and each security level corresponds to different detection rules, where the detection rules include detection frequency and / or detection method. The security level of a website link is not fixed. After performing security detection on the website link according to the detection rules corresponding to the security level of the website link, it is determined whether the security level of the website link needs to be updated based on the detection result, or the multi-level whitelist is directly removed. Therefore, the problem that potential security risks may be caused by not continuously performing security detection on a website link that is detected as safe once can be solved, and thus the effect of more accurately identifying unsafe website links through a perfect website link security detection method is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 is a block diagram of the hardware structure of a computer terminal for the website link security detection method according to an embodiment of the present application;
[0009] Figure 2 is a flowchart of the website link security detection method according to Embodiment (I) of the present application;
[0010] Figure 3 is a flowchart of the website link security detection method according to Embodiment (II) of the present application;
[0011] Figure 4 is a flowchart of the website link security detection method according to Embodiment (III) of the present application;
[0012] Figure 5 is a block diagram of the structure of the website link security detection device according to an embodiment of the present application;
[0013] Figure 6 is a flowchart of the website link security detection method according to Embodiment (IV) of the present application;
[0014] Figure 7 is a flowchart of the website link security detection method according to Embodiment (V) of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0015] The embodiments of the present application will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0016] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence.
[0017] The method embodiments provided in the embodiments of this application can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 is a hardware structure block diagram of a computer terminal for a method of detecting the security of website links in an embodiment of this application. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in Figure 1 processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a field programmable gate array FPGA) and a memory 104 for storing data. Among them, the above-mentioned computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned computer terminal. For example, the computer terminal may further include more or fewer components than Figure 1 shown in
[0018] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the method of detecting the security of website links in the embodiments of this application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided with respect to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0019] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of a computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0020] In this embodiment, a method for detecting the security of website links running on the above computer terminal or network architecture is provided. Figure 2 It is a flowchart of the method for detecting the security of website links according to Embodiment (1) of the present application. As Figure 2 shown, the process includes the following steps:
[0021] Step S202, add the website links identified as in a secure state to a multi-level whitelist, and set the security level of the website links and the detection rules for each security level, where the detection rules include detection frequency and / or detection method;
[0022] Figure 3 It is a flowchart of the method for detecting the security of website links according to Embodiment (2) of the present application. As Figure 3 shown, it includes: Step S2021, obtain the website link, and perform website security detection on the website link when the website link is not in the multi-level whitelist; Step S2022, when the website link passes the security detection, mark the website link as in a secure state and add it to the multi-level whitelist.
[0023] For website security detection, the method of pulling the md5 data corresponding to the JavaScript code of the website can be used. Md5 is an algorithm for calculating the hash value of a file, which can convert the file content into a fixed-length string. This string is usually used to verify the integrity and security of the file. The md5 data in the md5 data corresponding to the JavaScript of the website represents the md5 hash value of the JavaScript file, which is used to verify the integrity of the file and detect whether the file has been tampered with or damaged.
[0024] Step S204, perform security detection on the website links in the multi-level whitelist according to the detection frequency and detection method corresponding to the security level of the website links, and update the security level of the website links or remove the website links from the multi-level whitelist according to the detection results.
[0025] For website links removed from the low-level whitelist, mark the website links as "identified as risky websites" according to the detection results, add them to the blacklist, and prevent users from accessing them.
[0026] In step S204 of the embodiment of the present application, it includes at least one of the following: performing a security detection on the website links of the first security level according to the first detection frequency and the first detection method, and when the number of times the website links of the first security level pass the security detection reaches the first preset threshold, updating the website links of the first security level to the website links of the second security level, and when the website links of the first security level do not pass the security detection, removing the website links of the first security level from the multi-level whitelist; performing a security detection on the website links of the first security level according to the first detection frequency and the first detection method, and when the website links of the first security level pass the security detection within the first preset time period, updating the website links of the first security level to the website links of the second security level, and when the website links of the first security level do not pass the security detection, removing the website links of the first security level from the multi-level whitelist.
[0027] It should be noted that for the website links of the first security level, security detections will be performed multiple times at different time periods according to preset rules. For website links that reach the preset number of security detections and pass the security detections in all time periods, the level of the website links can be updated from the first security level to the second security level. Since the detection time periods are preset, it can be ensured that the website links added to the whitelist are safe at different times, avoiding the risk that risky websites with different displayed contents at different times cannot be identified.
[0028] In step S204 of the embodiment of the present application, Figure 4 is a flowchart of the security detection method for website links according to Embodiment (3) of the present application, as Figure 4 shown, including: step S2041, performing a security detection on the website links of the second security level according to the second detection frequency and the second detection method; step S2042, when the website links of the second security level do not pass the security detection, removing the website links of the second security level from the multi-level whitelist.
[0029] In an exemplary embodiment, update the security level of the website links that maintain the first security level in the multi-level whitelist for a preset duration to the second security level.
[0030] Website links that are at the first security level within the preset duration in the multi-level whitelist indicate that the links have passed multiple security detections and all have passed, ensuring a certain level of security. Therefore, they can be updated to the second security level, and the detection rules for security detection will change accordingly after the update.
[0031] In an exemplary embodiment, the security level of website links that maintain the second security level within the preset duration in the multi-level whitelist is updated to the third security level.
[0032] In an exemplary embodiment, the security detection of website links at the second security level according to the second detection frequency and the second detection method includes: detecting whether the change in the website page corresponding to the website links at the second security level exceeds a second preset threshold according to the second detection frequency, and performing a security detection on the website page when it is determined that the change in the website page exceeds the second preset threshold.
[0033] It should be noted that since the website links at the second security level have already passed multiple security detections and a certain level of security is ensured, there is no need to perform a complete detection at a high frequency. It is only necessary to detect whether the page has changed significantly at a certain frequency. If the change in the website page exceeds the second preset threshold, it indicates that the website page has changed significantly and a complete detection is required. If the website page has not changed much, there is no need to perform a complete detection on the website page corresponding to the website link, which can save resources while ensuring the security of the website links in the whitelist.
[0034] In an exemplary embodiment, the authenticated website links are added to the multi-level whitelist, and the security level of the website links is set to the third security level.
[0035] It should be noted that the authentication method for the website links at the third security level can be manual authentication or official authentication. The update of the website links at the second security level to the third security level can also be through manual authentication or official authentication, and no security detection will be automatically performed on the websites at the third security level. Since some officially or manually authenticated websites have passed strict security detections and have a high level of security, they can be trusted without the need for multiple security detections and are set to a higher security level. This way of setting or updating the security level is relatively flexible.
[0036] In an exemplary embodiment, the recognition status of website links is displayed in real time in the local website recognition queue, where the recognition status includes: unrecognized, recognizing, recognized as a secure website, and recognized as a risky website.
[0037] In an exemplary embodiment, when a request from a user to open a website link with an unrecognized recognition status in the local recognition queue is received, a message prompting that the recognition status of the website link is unrecognized is sent to the user; when a request from a user to open a website link with a recognition status of a risky website in the local recognition queue is received, the user is blocked from opening the website link with the recognition status of a risky website.
[0038] In an exemplary embodiment, the website link with the recognition status of being recognized as a risky website is added to the blacklist; when a request for an appeal against the website link in the blacklist is received, the website link in the blacklist is automatically detected or manually detected; when the automatic detection or manual detection passes, the website link in the blacklist is removed.
[0039] The embodiments of the present application not only perform security detection on the website links in the whitelist, but also re-detect the website links recognized as risky websites and added to the blacklist, and determine whether to remove the website links in the blacklist according to the detection results, providing a scientific and reliable method for detecting website links.
[0040] In an exemplary embodiment, the security levels of the website links in the multi-level whitelist are displayed in real time in the local website recognition queue.
[0041] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0042] In this embodiment, a security detection device for website links is also provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0043] Figure 5 is a structural block diagram of a security detection device for website links according to an embodiment of the present application, as Figure 5As shown in the figure, the device includes: a setting module 10 and a detection module 20.
[0044] The setting module 10 is used to add website links identified as in a safe state to a multi-level whitelist, and set the security level of the website links and the detection rules for each security level, where the detection rules include detection frequency and / or detection method;
[0045] The detection module 20 is used to perform security detection on the website links in the multi-level whitelist according to the detection rules corresponding to the security levels of the website links, and update the security levels of the website links according to the detection results or remove the website links from the multi-level whitelist.
[0046] It should be noted that the above-mentioned various modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: all the above-mentioned modules are located in the same processor; or, the above-mentioned various modules are respectively located in different processors in any combination form.
[0047] Figure 6 It is a flowchart of the method for detecting the security of website links according to Embodiment (4) of the present application. As Figure 6 shown, the process includes the following steps:
[0048] Step S401, obtain a website link;
[0049] Specifically, the terminal device identifies website links from social software chat messages and text messages through reading and analysis, adds them to the local website identification queue, and marks them as "unidentified". When attempting to open at this time, it reminds that the website has not been fully identified, and adjusts the website to the top of the queue for priority identification.
[0050] Step S402, determine whether the website link is in the whitelist;
[0051] Specifically, compare the website link with the server-side whitelist. If the website link is in the whitelist, go to step S403; if the website link is not in the whitelist, go to step S404.
[0052] Step S403, mark the website link as a safe website;
[0053] Step S404, perform website security detection;
[0054] Specifically, add the identified website to the local website identification queue, and display the identification status in real time: unidentified, identifying, identified as a safe website, identified as a risky website, etc. For links identified as safe websites, it is possible to further display the level of the whitelist where it is located at this time when the detection passes.
[0055] Step S405: Determine whether the website is a secure website;
[0056] Specifically, by pulling the md5 data corresponding to the JavaScript of the website or directly providing the website to the risk identification server, it can be determined whether the current website is a risky website. If the website is a secure website, proceed to step S406; if the website is not a secure website, proceed to step S407.
[0057] Step S406: Mark the website link as secure;
[0058] Step S407: Perform corresponding other markings on the website link.
[0059] Specifically, for insecure websites, including but not limited to, handling them by means of prompts, blocking, adding to the blacklist, etc. Users reserve the right to appeal against these websites. When users appeal, the specific reasons for the problems identified in the website will be explained and shown to the users. For websites whose appeals are lifted, the reasons for the lifting can be recorded and an appeal cancellation record report can be generated. Figure 7 It is a flowchart of the method for detecting the security of website links according to Embodiment (Five) of the present application, as Figure 7 shown, the process includes the following steps:
[0060] Step S501: Add websites that have no problems in the first security detection to the low-level whitelist on the server side;
[0061] Specifically, for websites in the low-level whitelist, security detection will not be performed again when users access them within a short period of time.
[0062] Step S502: Perform multiple security detections at different time periods;
[0063] Step S503: Determine whether the website passes the detection;
[0064] Specifically, if the website detection reaches a certain number of times, a certain frequency, and at least meets the requirement of passing the security detection in each time period, proceed to step S504; otherwise, proceed to step S505;
[0065] Step S504: Add the website to the intermediate whitelist;
[0066] Specifically, for websites in the intermediate whitelist, security detection is performed at a lower frequency.
[0067] Step S505: Remove the website from the low-level whitelist;
[0068] Specifically, mark it as "identified as a risky website" according to the detection result, add it to the blacklist, and block access.
[0069] Step S506: Determine the change situation of the website snapshot detection;
[0070] Specifically, for the websites added to the intermediate whitelist, simple snapshot detection is performed at a medium frequency. When it is found that the website page has changed significantly, go to step S507. If the website has not changed significantly, go to step S509;
[0071] Step S507, perform a complete security detection;
[0072] Step S508, determine whether the website passes the detection;
[0073] Specifically, if it passes the detection, go to step S509, otherwise go to step S510.
[0074] Step S509, maintain and record the detection situation;
[0075] Step S510, remove the website from the intermediate whitelist.
[0076] It should be noted that for the websites that have been in the intermediate whitelist for a long time or the websites that have passed manual / official certification, add them to the high-level whitelist, and no longer automatically perform security detection on these websites. The initial high-level whitelist can be released by the authoritative agency of the political and legal organs.
[0077] The embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any one of the above method embodiments when running.
[0078] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs that can store computer programs.
[0079] The embodiment of the present application also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is set to run the computer program to execute the steps in any one of the above method embodiments.
[0080] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device, where the transmission device is connected to the above processor, and the input / output device is connected to the above processor.
[0081] The specific examples in this embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.
[0082] In the related art, network information (including website links) that may contain illegal activity information sent in text messages or social software is extracted and detected. However, for those that are considered not to be risk websites after detection, no further follow-up will be carried out, resulting in the inability to accurately identify websites with the characteristics of different content displayed at different times, and also unable to establish a scientific and reliable whitelist mechanism. In the embodiments of the present application, websites in the terminal machine application are extracted and analyzed and marked in advance. According to the analysis results, a multi-level whitelist mechanism is established. Websites that are determined to be okay after analysis enter the multi-level whitelist. The higher the level of the whitelist, the simpler the security detection process and the more convenient for users to use, providing a perfect security detection method for website links while ensuring user safety.
[0083] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order from here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the present application is not limited to any specific combination of hardware and software.
[0084] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included within the protection scope of the present application.
Claims
1. A method for detecting the security of website links, characterized in that, it includes: Adding website links identified as in a secure state to a multi-level whitelist, and setting the security level of the website links and the detection rules for each security level, where the detection rules include detection frequency and / or detection method; Performing security detection on the website links in the multi-level whitelist according to the detection rules corresponding to the security level of the website links, and updating the security level of the website links or removing the website links from the multi-level whitelist according to the detection results.
2. The method according to claim 1, characterized in that, The adding the website links identified as in a secure state to the multi-level whitelist includes: Obtaining the website links, and performing website security detection on the website links when the website links are not in the multi-level whitelist; When the website links pass the security detection, marking the website links as in a secure state and adding them to the multi-level whitelist.
3. The method according to claim 1, characterized in that, The performing security detection on the website links according to the detection rules corresponding to the security level of the website links, and updating the security level of the website links or removing the website links from the multi-level whitelist according to the detection results includes at least one of the following: Performing security detection on the website links of the first security level according to the first detection frequency and the first detection method. When the number of times the website links of the first security level pass the security detection reaches the first preset threshold, updating the website links of the first security level to the website links of the second security level. When the website links of the first security level do not pass the security detection, removing the website links of the first security level from the multi-level whitelist; Performing security detection on the website links of the first security level according to the first detection frequency and the first detection method. When the website links of the first security level pass the security detection within the first preset time period, updating the website links of the first security level to the website links of the second security level. When the website links of the first security level do not pass the security detection, removing the website links of the first security level from the multi-level whitelist.
4. The method according to claim 1, characterized in that, The method further includes: Updating the security level of the website links in the multi-level whitelist that remain at the first security level for a preset duration to the second security level.
5. The method according to claim 1, characterized in that, The performing detection on the website links according to the detection rules corresponding to the security level of the website links, and updating the security level of the website links or removing the website links from the multi-level whitelist includes: Performing security detection on the website links of the second security level according to the second detection frequency and the second detection method; When the website links of the second security level do not pass the security detection, removing the website links of the second security level from the multi-level whitelist.
6. The method according to claim 5, wherein, the method further comprises: updating the security level of the website links in the multi-level whitelist that maintain the second security level within a preset time period to the third security level.
7. The method according to claim 5, wherein, the security detection of the website links at the second security level according to the second detection frequency and the second detection method includes: detecting whether the change of the website page corresponding to the website links at the second security level exceeds a second preset threshold according to the second detection frequency, and performing security detection on the website page when it is determined that the change of the website page exceeds the second preset threshold.
8. The method according to claim 1, wherein, the method further comprises: adding the authenticated website links to the multi-level whitelist and setting the security level of the website links to the third security level.
9. The method according to claim 1, wherein, the method further comprises: displaying the recognition status of the website links in the local website recognition queue in real time, wherein the recognition status includes: unrecognized, recognizing, recognized as a secure website or recognized as a risky website.
10. The method according to claim 9, wherein, the method further comprises: when receiving a request from a user to open a website link with an unrecognized status in the local recognition queue, sending a message to the user to prompt that the recognition status of the website link is unrecognized; when receiving a request from a user to open a website link with a risky website status in the local recognition queue, preventing the user from opening the website link with the risky website status.
11. The method according to claim 9, wherein, the method further comprises: adding the website links with the recognized status of being recognized as risky websites to the blacklist; when receiving a request for an appeal against the website links in the blacklist, performing automatic detection or manual detection on the website links in the blacklist; lifting the website links in the blacklist when the automatic detection or manual detection passes.
12. The method according to claim 1, wherein, the method further comprises: displaying the security levels of the website links in the multi-level whitelist in the local website recognition queue in real time.
13. A computer-readable storage medium, wherein, a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 12 are implemented.
14. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the computer program, the steps of the method according to any one of claims 1 to 12 are implemented.