Web system user operation intelligent auditing method and device, medium and program product

Through full-link data collection and comprehensive analysis, evaluating and responding to user operation behaviors, the problem of inability to record and analyze user operation behaviors in detail in the existing technology is solved, and accurate auditing and dynamic security protection of the Web system is realized.

CN120091013APending Publication Date: 2025-06-03BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510153147.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The prior art cannot record the user's operating behavior in detail in the Web system, which makes it difficult to deeply analyze user behavior and troubleshoot problems, and lacks real-time monitoring and analysis capabilities, so it is impossible to detect and respond to security incidents in a timely manner.

Method used

Through full-link data collection and comprehensive analysis, user interface interaction data, front-end and back-end context information are obtained, and the evaluation level of user operation behavior is evaluated. When the level is greater than the preset security level, corresponding security measures are implemented.

Benefits of technology

It realizes accurate audits and dynamic security protection of user operation behaviors, improves the security and reliability of the Web system, and can detect and respond to security incidents in a timely manner and prevent potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091013A_ABST
    Figure CN120091013A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a Web system user operation intelligent auditing method and device, a medium and a program product. The method comprises the steps of obtaining user interface interaction data in response to an operation request of a user on a front-end interface; when the user operation triggers the front-end event, front-end context information is obtained based on the front-end environment where the user operation is located; the method comprises the following steps: when a user operates to trigger a front end to send an HTTP request to a back end, acquiring back-end interaction data and back-end context information based on a plurality of processing stages of the HTTP request; and based on the user interface interaction data, the front-end context information, the rear-end interaction data and the rear-end context information, obtaining an evaluation level of the user operation behavior, and when the evaluation level is greater than a preset security level, obtaining a target security policy and executing a corresponding security measure. According to the method, accurate auditing and dynamic safety protection of user operation behaviors can be realized through full-link data acquisition and comprehensive analysis, and the safety and reliability of a Web system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technologies, and in particular, to an intelligent auditing method, device, medium, and program product for user operations in a Web system. Background Art

[0002] In the context of the rapid development of information technology, Web systems have become the core tools for enterprise and personal business processing, and their security is crucial for protecting user data, maintaining corporate reputation, and complying with laws and regulations. User operation auditing, as a key link in ensuring the security of Web systems, records and monitors user behaviors for effective tracking and analysis in the event of security incidents.

[0003] However, existing technologies usually can only provide coarse-grained audit logs and cannot record the specific operation behaviors of users in detail, resulting in difficulties in deeply analyzing user behaviors and troubleshooting problems. Moreover, many existing systems lack real-time monitoring and analysis capabilities and cannot detect and respond to security incidents in a timely manner, missing the best opportunity for prevention and intervention. Summary of the Invention

[0004] In view of this, embodiments of the present disclosure provide an intelligent auditing method, device, medium, and program product for user operations in a Web system, which can achieve accurate auditing of user operation behaviors and dynamic security protection through full-link data collection and comprehensive analysis, effectively improving the security and reliability of the Web system.

[0005] In a first aspect, embodiments of the present disclosure provide an intelligent auditing method for user operations in a Web system, adopting the following technical solutions:

[0006] In response to an operation request of a user on a front-end interface, obtain user interface interaction data;

[0007] When a user operation triggers a front-end event, obtain front-end context information based on the front-end environment where the user operation is located;

[0008] When a user operation triggers an HTTP request sent from the front-end to the back-end, obtain back-end interaction data and back-end context information based on multiple processing stages of the HTTP request;

[0009] Based on the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information, obtain an evaluation level of the user operation behavior;

[0010] When the evaluation level is greater than a preset security level, obtain a target security policy;

[0011] Based on the target security policy, execute corresponding security measures.

[0012] Optionally, the obtaining of the user interface interaction data includes:

[0013] Based on the business scenario, determine several event types to be captured;

[0014] Based on the event types to be captured, create event listeners;

[0015] When the user operates on the front-end interface, trigger the generation of an operation request;

[0016] When generating the operation request, obtain the user interface interaction data based on the event listener.

[0017] Optionally, based on the front-end environment where the user operates, obtain front-end context information, including:

[0018] Based on the front-end environment where the user operates, determine the target information capturer;

[0019] Based on the target information capturer, obtain the front-end context information.

[0020] Optionally, the multiple processing stages of the HTTP request include an initialization stage, a back-end application response stage, a method call stage, and a server response stage;

[0021] The back-end context information includes first context information, second context information, and third context information;

[0022] In the method call stage, obtain the back-end interaction data;

[0023] In the initialization stage, obtain the first context information of the front-end application initiating the HTTP request;

[0024] In the back-end application response stage, obtain the second context information of the HTTP request entering the back-end application;

[0025] In the server response stage, obtain the third context information of the back-end server processing the HTTP request.

[0026] Optionally, the obtaining of the back-end interaction data in the method call stage includes:

[0027] Create an aspect class and set a pointcut in the aspect class;

[0028] Based on the pointcut, match all method functions marked with the @AuditLog annotation;

[0029] Adopt the around advice method to collect information for the matched method functions, and the information of the collected method functions constitutes the back-end interaction data.

[0030] Optionally, obtaining an evaluation level of the user operation behavior based on the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information includes:

[0031] Obtaining the input data types of a preset machine learning model;

[0032] Based on the input data types, filtering out target data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information;

[0033] Preprocessing the target data;

[0034] Inputting the preprocessed target data into the machine learning model to obtain a classification probability distribution;

[0035] Based on the classification probability distribution, obtaining an evaluation level of the user operation behavior.

[0036] Optionally, filtering out target data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information based on the input data types includes:

[0037] Extracting the required input data types from the configuration file or metadata of the machine learning model;

[0038] Determining the required format for each input data type;

[0039] Setting filtering conditions based on the input data types;

[0040] Filtering out available data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information according to the filtering conditions;

[0041] Based on the required format for each input data type, performing format conversion on the available data to obtain the target data.

[0042] In a second aspect, an intelligent audit system for user operations of a Web system provided by an embodiment of the present disclosure adopts the following technical solutions:

[0043] A front-end data acquisition module, configured to acquire user interface interaction data in response to an operation request of a user on a front-end interface;

[0044] A front-end information acquisition module, configured to acquire front-end context information based on the front-end environment where the user operation is located when the user operation triggers a front-end event;

[0045] An HTTP request triggering module, configured to obtain backend interaction data and backend context information based on multiple processing stages of an HTTP request when a user operation triggers the frontend to send an HTTP request to the backend;

[0046] An evaluation level obtaining module, configured to obtain an evaluation level of a user operation behavior based on the user interface interaction data, the frontend context information, the backend interaction data, and the backend context information;

[0047] A security policy obtaining module, configured to obtain a target security policy when the evaluation level is greater than a preset security level;

[0048] A security measure execution module, configured to execute corresponding security measures based on the target security policy.

[0049] In a third aspect, an embodiment of the present disclosure further provides a computer device, adopting the following technical solution:

[0050] The computer device includes:

[0051] At least one processor; and,

[0052] A memory communicatively connected to the at least one processor; wherein,

[0053] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the Web system user operation intelligent auditing method described in any one of the above.

[0054] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute the Web system user operation intelligent auditing method described in any one of the above.

[0055] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in any one of the above are implemented.

[0056] The intelligent auditing method for user operations in the Web system provided by the embodiments of the present disclosure can comprehensively record the user's behavior trajectory by capturing the operation data of the user at the front end in real time, providing basic data support for subsequent auditing and analysis. Combining the front-end environment information, it can capture the front-end context information directly related to the user, which helps to more accurately understand the background and intention of the user's operations, improving the accuracy of auditing. Moreover, with the front-end events as the triggering conditions, the timeliness of capturing the front-end context information is improved, so as to provide data support for the real-time analysis of the user's operation behavior in a timely manner. The user's operation behavior usually triggers the generation and processing of HTTP requests. By monitoring each processing stage of the HTTP requests, the impact of the user's operations on the back-end system can be deeply analyzed to ensure the comprehensiveness of auditing. Integrating the data from the front end and the back end can improve the granularity of auditing, obtain the context information often overlooked in traditional methods, ensure the comprehensiveness of the data, evaluate the user's operations from multiple dimensions, deeply analyze the user's behavior and troubleshoot problems, and accurately judge its security risks. By implementing targeted security measures, security risks can be effectively prevented and addressed, ensuring the security of the Web system. Moreover, the fine-grained auditing can help quickly locate system failures or errors, accelerating the problem-solving process. In summary, by integrating and analyzing the data from the front end and the back end, this method can achieve full-link auditing from user operations to system responses, not only improving the accuracy and comprehensiveness of auditing, but also dynamically adjusting security policies to timely respond to potential threats, thus significantly enhancing the security of the Web system.

[0057] The above description is only an overview of the technical solutions of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present disclosure more obvious and understandable, the following specific preferred embodiments are given and described in detail in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0059] Figure 1 It is a schematic flowchart of the intelligent auditing method for user operations in the Web system provided by the embodiments of the present disclosure;

[0060] Figure 2 It is a principle block diagram of the intelligent auditing method for user operations in the Web system provided by the embodiments of the present disclosure;

[0061] Figure 3Flow diagram of the method for creating an event listener provided by an embodiment of the present disclosure;

[0062] Figure 4 Flow diagram of the method for obtaining front - end context information provided by an embodiment of the present disclosure;

[0063] Figure 5 Flow diagram of the method for obtaining an evaluation level provided by an embodiment of the present disclosure;

[0064] Figure 6 Principle block diagram of the intelligent audit system for user operations in a Web system provided by an embodiment of the present disclosure;

[0065] Figure 7 Structure diagram of a computer device provided by an embodiment of the present disclosure. Detailed implementation manners

[0066] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0067] It should be clear that the embodiments of the present disclosure are described below through specific specific examples. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.

[0068] It should be noted that the following describes various aspects of embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. In addition, this device can be implemented and this method can be practiced using other structures and / or functions in addition to one or more of the aspects described herein.

[0069] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure in a schematic manner. The diagrams only show the components related to the present disclosure, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0070] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0071] Referring to Figure 1 , the present disclosure provides a method for intelligent auditing of user operations in a Web system, including the following steps:

[0072] S1: In response to a user operation request on the front-end interface, obtain user interface interaction data;

[0073] S2: When a user operation triggers a front-end event, obtain front-end context information based on the front-end environment where the user operation is located;

[0074] S3: When a user operation triggers an HTTP request sent from the front-end to the back-end, obtain back-end interaction data and back-end context information based on multiple processing stages of the HTTP request;

[0075] S4: Based on the user interface interaction data, front-end context information, back-end interaction data, and back-end context information, obtain the evaluation level of the user operation behavior;

[0076] S5: When the evaluation level is greater than a preset security level, obtain the target security policy;

[0077] S6: Based on the target security policy, execute corresponding security measures.

[0078] The intelligent auditing method for Web system user operations provided by the present disclosure can comprehensively record the user's behavior trajectory by capturing the operation data of the user at the front end in real time, providing basic data support for subsequent auditing and analysis. Combining with the front-end environment information, it can capture the front-end context information directly related to the user, which helps to more accurately understand the background and intention of the user's operations, improve the accuracy of auditing, and moreover, taking the front-end events as the triggering conditions, it improves the timeliness of capturing the front-end context information, so as to provide data support for the real-time analysis of the user's operation behavior in a timely manner. The user's operation behavior usually triggers the generation and processing of HTTP requests. By monitoring each processing stage of the HTTP requests, it is possible to deeply analyze the impact of the user's operations on the back-end system and ensure the comprehensiveness of auditing. Integrating the data of the front end and the back end can improve the granularity of auditing, obtain the context information that is often ignored in traditional methods, ensure the comprehensiveness of the data, evaluate the user's operations from multiple dimensions, deeply analyze the user's behavior and troubleshoot problems, and accurately judge its security risks. By implementing targeted security measures, it is possible to effectively prevent and respond to security risks, ensure the security of the Web system, and moreover, the fine-grained auditing can help quickly locate system failures or errors and accelerate the problem-solving process.

[0079] In summary, by integrating and analyzing the data of the front end and the back end, this method can achieve full-link auditing from user operations to system responses, not only improving the accuracy and comprehensiveness of auditing, but also being able to dynamically adjust security policies and timely respond to potential threats, thus significantly enhancing the security of the Web system.

[0080] In S1, referring to Figure 2 the principle block diagram of the intelligent auditing method for Web system user operations shown, a front-end log capture module is set up and deployed at the front end using JavaScript code. When the user operates on the front-end interface through the UI, it will trigger the JavaScript code integrated at the front end to capture all the interaction behaviors of the user at the UI layer. In order to add a layer of data verification and integrity check, a custom event listener is set up in the front-end log capture module to capture all the operation behaviors of the user.

[0081] Referring to Figure 3 the schematic flowchart of the method for creating an event listener shown, "obtaining user interface interaction data in response to the user's operation request on the front-end interface" includes the following steps:

[0082] S11: Based on the business scenario, determine several event types to be captured;

[0083] S12: Based on the event types to be captured, create an event listener;

[0084] S13: When the user operates on the front-end interface, trigger the generation of an operation request;

[0085] S14: When generating an operation request, use an event listener to obtain user interface interaction data.

[0086] In S11, cooperate with the business team to understand the business process and key points of user interaction, and determine the user behaviors that need to be monitored. According to the results of the requirements analysis, define the types of events to be captured, namely the event types to be captured. The event types to be captured include at least one of click event, input event, change event, submit event, error event, DOMContentLoaded event, and load event. Among them, the click event is used to monitor user click operations and can capture information such as the click position and element; the input event is used to monitor changes in the content of the input box and can capture the input content and time point; the change event is used to monitor changes in the values of form elements and is applicable to checkboxes, radio buttons, etc.; the submit event is used to monitor form submission behaviors and can capture the form data submitted; the error event is used to monitor JavaScript errors and can capture error information and stack traces; both the DOMContentLoaded event and the load event are used to monitor page loading behaviors. However, the DOMContentLoaded event is applicable to execute operations that depend on the DOM structure and scripts that do not depend on the completion of other resource loading, such as modifying the DOM structure, while the load event is applicable to execute operations that can only be performed after the page is fully loaded, such as initializing complex scripts, animation effects, or analysis and tracking code after the page is fully loaded.

[0087] In S12, the event listener is the core mechanism of the front-end log capture module. It is used to monitor and respond to user behaviors. In JavaScript, use the `addEventListener` method to construct and add event listeners according to the event types to be captured. For each event type to be captured, write the corresponding handling function, that is, the callback function, and these functions will be executed when the corresponding event is triggered. Specifically, use JavaScript to bind event listeners to specific DOM elements so that they can respond immediately when user interactions occur. If a front-end framework such as React or Vue is used in the project, utilize the event binding mechanisms provided by these frameworks to more efficiently manage event listeners and callback functions. The callback function is a key part of the event listening process. It defines the operations that should be executed when a specific event occurs, enabling the front-end application to react dynamically to user behaviors.

[0088] In S13, when the user performs operations such as clicking a button or submitting a form on the front-end interface, the front-end application (such as a browser) will automatically trigger the corresponding operation request, that is, an event.

[0089] In S14, the callback function of the event listener is automatically executed when the operation request is triggered, capturing user interface interaction data without the need for additional code intervention. User interface interaction data includes the timestamp, interaction event type, and user behavior data when the user interacts with the front end. Among them, the interaction event type refers to the type of event triggered when the user interacts with the front end; the timestamp refers to the time when the interaction event is triggered; and the user behavior data refers to the result of the user's operation on the front-end interface. For example, if the triggered interaction event type is an input event, the user behavior data includes the specific data entered by the user; if the triggered interaction event type is a change event, the user behavior data includes the content filled in by the user in the form; if the triggered interaction event type is a submit event, the user behavior data includes the form data submitted by the user; if the triggered interaction event type is an error event, the user behavior data includes the system response, such as error messages, warning messages, etc.

[0090] By determining the event types to be captured based on the business scenario, this method can ensure that the audit system focuses on user behaviors that are crucial to the business process, thereby improving the relevance and accuracy of audit data. Creating a dedicated event listener can ensure that all necessary interaction data can be captured promptly and accurately when the user performs critical operations, avoiding data omission and enhancing the integrity of audit data. The operation request triggered by the user operation can be immediately recognized and responded to by the system, which is crucial for a security audit system that requires real-time monitoring and quick response. The event listening is the starting stage of audit log recording, mainly focusing on the user's direct interaction with the interface. By accurately capturing user interface interaction data, this method not only improves the efficiency and accuracy of Web system user operation auditing, enables the intelligent audit system to better understand user behaviors, thereby providing more personalized services and optimizing the user experience, but also provides front-end interaction data for subsequent risk assessment, facilitating the timely discovery of potential security threats and taking corresponding security measures to enhance the security of the Web system.

[0091] In S2, when the user interacts with the front end, the traditional method only listens to and records some events, ignoring the context information directly related to the user interaction, resulting in insufficient audit granularity. This method further refines the capture of information in the user-front-end interaction stage, adding a richer context dimension to the audit log. Specifically, refer to Figure 4 the flowchart of the front-end context information acquisition method shown, "obtaining front-end context information based on the front-end environment where the user operation is located" includes the following steps:

[0092] S21: Determine the target information capturer based on the front-end environment where the user operation is located;

[0093] S22: Obtain the front-end context information based on the target information capturer.

[0094] In the above, when the user operation triggers a front-end event, the target information capturer will be immediately determined in the front-end log capture module, and these target information capturers will be called to collect the corresponding information. The target information capturer includes a user identity information capturer and at least one environment information capturer. Regardless of which front-end environment, the user identity information capturer is used to obtain the user's identity information, including the user ID and user name, etc. The user identity information capturer is built based on front-end storage. After the user logs in, the storage mechanisms such as localStorage or sessionStorage are usually used to store information such as the user ID and user name into the preset space, and the user identity information capturer is constructed to read the preset space to obtain the user's identity information. At the same time, the environment information capturer is used to obtain the front-end environment information, and the user's identity information and the front-end environment information constitute the front-end context information.

[0095] To cope with the possible operations of users in various different front-end environments, a series of environment information capturers are pre-designed and created. These environment information capturers are specifically for different front-end environments and can accurately capture the relevant information in that environment. A mapping relationship is established to associate each front-end environment with its corresponding environment information capturer. When the user performs an operation in the front-end environment and triggers a relevant event, in addition to obtaining the user's identity information, the corresponding environment information capturer is automatically identified and called according to the current front-end environment, so as to collect important information related to the front-end environment in real time. These information are directly related to the user and can further reflect the user's operation behavior.

[0096] For example, if the front-end environment is a browser, the triggered environment information catcher at least includes a browser information catcher and a page information catcher. Among them, the browser information catcher obtains browser information by calling the navigator object, specifically including the browser name, version, etc.; the page information catcher obtains page information by calling the window.location object, specifically including the page URL, page title, etc.; the browser information and page information constitute the front-end environment information. If the front-end environment is a device management application (referring to an application program for managing and monitoring devices), the triggered environment information catcher at least includes a device information catcher and a network information catcher. Among them, the device information catcher obtains basic device information by calling the window.screen object and navigator.userAgent, specifically including the screen resolution, device pixel ratio, device model, etc.; the network information catcher obtains device network information by calling the navigator.connection object, specifically including the network type, downstream speed, round-trip time, etc.; the basic device information and device network information constitute the front-end environment information.

[0097] According to different business scenarios and business requirements, the mapping relationship between the front-end environment and the environment information catcher can be adjusted.

[0098] In S3, the multiple processing stages of an HTTP request include an initialization stage, a back-end application response stage, a method call stage, and a server response stage. Among them, the initialization stage refers to the stage where the front-end application prepares and sends an HTTP request; the back-end application response stage is the stage where the HTTP request is transmitted to the back-end application and the back-end application conducts preliminary processing on the HTTP request; the method call stage refers to the stage where the back-end application calls a method function based on the HTTP request, which belongs to in-depth processing of the HTTP request; the server response stage is the stage where the back-end server constructs and sends an HTTP response back to the front-end.

[0099] Different information is obtained at different processing stages. Specifically, in the method call stage, back-end interaction data is obtained; in the initialization stage, the first context information of the front-end application initiating the HTTP request is obtained; in the back-end application response stage, the second context information of the HTTP request entering the back-end application is obtained; in the server response stage, the third context information of the back-end server processing the HTTP request is obtained. A context-aware module is created, and the context-aware module integrates the methods for obtaining back-end context information. The back-end context information includes the first context information, the second context information, and the third context information, which constitute the back-end context information.

[0100] Furthermore, a specific implementation solution for "in the initialization stage, obtain the first context information of the front-end application initiating the HTTP request" is as follows:

[0101] Build a first filter in the front-end application. The first filter is an interceptor or middleware, such as express-http-context and Axios interceptors. The front-end application generates an API request according to the triggered event, sends the API request via the HTTP protocol to form an HTTP request. The first filter intercepts the HTTP request and records the original information of the HTTP request, including the complete URL of the HTTP request, the request method, and adds preset information such as user agent and device information to the request headers of the HTTP request. These preset information can facilitate the back-end to correctly process the HTTP request, such as for logging, security checking, personalized response, etc. After adding the preset information, the modified HTTP request is transmitted to the back-end application, and at the same time, the first context information includes the recorded original information and preset information.

[0102] A specific implementation solution for "obtaining the second context information when the HTTP request enters the back-end application during the back-end application response phase" is as follows:

[0103] Build a second filter in the back-end application. The second filter is an interceptor or middleware, such as the HandlerInterceptor interceptor in the Spring framework. When the HTTP request is transmitted to the back-end application, the second filter intercepts the HTTP request and captures the second context information, which includes request header information, the IP address of the request source, etc.

[0104] A specific implementation solution for "obtaining the back-end interaction data during the method call phase" is as follows:

[0105] Build an application server module as a bridge between the front end and the back end. The application server module receives and processes requests sent by the front end and interacts with back-end systems (such as databases, external services, etc.). Through an AOP aspect framework (such as Spring AOP or AspectJ), without modifying the business logic code, it automatically records the detailed information of method calls, that is, back-end interaction data. Specifically, create an aspect class named AuditLogAspect in the application server module for fine-grained audit log recording of service layer methods. In the aspect class, set a pointcut. Specifically, the @Pointcut annotation can be used to define the pointcut, and based on the pointcut, match all method functions marked with the @AuditLog annotation. Adopt the around advice method to collect information on the matched method functions, and the collected method function information constitutes the back-end interaction data. In the aspect class, using the around advice can perform enhancement operations before and after the execution of the matched method functions, and record the key information of the method functions, including the method name (the name of the called method function), parameters (parameters in the method function), return value (the return result after the method function is executed), and exception information (if an exception occurs during the method execution, record the exception information), etc. An exception handling mechanism can also be added to ensure that exceptions during the log recording process do not affect the execution of the main business process. Use performance monitoring tools (such as Micrometer and Prometheus) to monitor and optimize the performance of the AOP aspect in real time to ensure the efficient operation of the system.

[0106] A specific implementation solution for "obtaining the third context information of the back-end server processing the HTTP request in the server response phase" is as follows:

[0107] Deploy a distributed tracing system on the server side, such as OpenTelemetry. This system provides unified APIs and SDKs to collect and export tracing data, and can capture the third context information during the stage of the back-end server processing the HTTP request. The third context information includes server node information for processing the HTTP request, transaction ID, call chain information, response time, and other performance metrics for processing the request, etc.

[0108] In S4, use an asynchronous request to send the user interface interaction data from the front-end log capture module to the application server module to avoid blocking the main thread. The application server module performs formatted processing and summarization on the user interface interaction data and the back-end interaction data to form multiple log entries, and these multiple log entries constitute the complete log data.

[0109] During the process of sending user interface interaction data, capture possible errors, give corresponding feedback to the user on the interface, and at the same time, record the error information for developers to analyze and fix. For example, use the try...catch statement to capture errors in the fetch request. After capturing the error, the user can be prompted with the error information through the UI, such as: "Failed to send user interface interaction data. Please try again later", and record the error information in the console or use console.error to record detailed error information. When the user interface interaction data cannot be sent temporarily due to network or other problems, first adopt a retry strategy. After retrying to send a preset number of times, if it still fails, store the unsent user interface interaction data locally, and try to send it again when the network resumes.

[0110] Create a logging module. The logging module classifies the log data into multiple types of log data. The types of log data include error logs, access logs, system events, user operations, etc. Select a suitable logging framework for each type of log data. The logging framework includes at least one of Log4j and SLF4J. Classify each type of log data according to the importance and purpose of the log data to obtain a log level. The log level includes at least one of DEBUG, INFO, WARN, ERROR, and FATAL. The log data consists of multiple log entries. Each log entry contains the name and thread information that generated the log entry. The name is an identifier of the log entry, which helps to identify the log entry, and the thread information helps to quickly locate the source of the log entry in a multi-threaded environment. Store the log data in a preset database in the order of timestamp, log type, log level, thread information, logging framework, log entry name, and log entry content. This formatted storage method can effectively manage the log data for subsequent analysis and auditing.

[0111] Here, the user interface interaction data, front-end context information, and back-end interaction data have similar data structures and similar levels of data sensitivity, while the data sensitivity and data structure of the back-end context information are quite different from those of other data. Therefore, this method stores the user interface interaction data, front-end context information, and back-end interaction data together to form log data, and stores the back-end context information separately in the context-aware module. This separate processing method is convenient for log management and can more efficiently meet different analysis needs.

[0112] To ensure that the performance of the main business process is not affected, the logging module adopts an asynchronous logging mechanism. This mechanism logs the logs in a non-blocking manner to ensure that the log recording operation does not block the main business thread, thereby improving the overall performance and response ability of the system.

[0113] Create a real-time analysis engine module and deploy Apache Flink as a distributed stream processing framework in the real-time analysis engine module. Apache Flink is an open-source and high-performance stream processing framework suitable for real-time data stream processing tasks. Deploying Apache Flink mainly requires configuring the Flink environment. First, it is necessary to set up the Flink platform in the development environment, create the corresponding Maven or Gradle project, and introduce the necessary Flink dependencies. Subsequently, configure various parameters of Flink according to system requirements and write real-time data processing logic using Flink's DataStream API. After development, package the job into a JAR file and submit the job for running through Flink's command line or web interface. In addition, the system also integrates third-party tools such as Kafka to enhance the data stream processing ability and flexibility. To monitor the running status of the job and perform performance tuning, Flink provides rich monitoring tools and metrics, which helps to ensure the stability and efficiency of the system. This distributed stream processing framework can perform real-time processing on continuous data streams, providing low-latency response capabilities. Moreover, through the distributed architecture, it can handle high-concurrency data streams and is easy to expand to cope with the growing data volume. The distributed stream processing framework also has strong fault tolerance capabilities, which can ensure the accuracy and reliability of data processing, support complex time window operations and event correlation, and is suitable for processing complex business logics. The distributed stream processing framework supports both stream processing and batch processing, can uniformly handle different types of data processing requirements, is convenient for subsequent serving machine learning models, and provides data support for the evaluation of user operation behaviors.

[0114] Referring to Figure 5 the flowchart of the evaluation level acquisition method shown, "obtaining the evaluation level of user operation behaviors based on user interface interaction data, front-end context information, back-end interaction data, and back-end context information" includes the following steps:

[0115] S41: Obtain the input data types of the preset machine learning model;

[0116] S42: Based on the input data types, filter out the target data from the user interface interaction data, front-end context information, back-end interaction data, and back-end context information;

[0117] S43: Preprocess the target data;

[0118] S44: Input the preprocessed target data into the machine learning model to obtain the classification probability distribution;

[0119] S45: Based on the classification probability distribution, obtain the evaluation level of user operation behaviors.

[0120] In S41, extract the required input data types from the configuration file or metadata of the machine learning model, such as numerical, categorical, time series, or text data.

[0121] In S42, determine the required format for each input data type, such as whether normalization, encoding, etc. are needed. Store these input data types and their required formats in a configuration table or data dictionary for subsequent filtering and processing.

[0122] The distributed stream processing framework sets filtering conditions based on the input data types, and at the same time reads user interface interaction data, front-end context information, and back-end interaction data from the logging module, and reads back-end context information from the context awareness module. Based on the filtering conditions, the distributed stream processing framework filters these data to obtain available data. For example, filter click events, input operations, etc. in the user interface interaction data, filter user device information, browser type, network status, etc. in the front-end context information, filter method names, return values, etc. in the back-end interaction data, and filter user agent, request method, transaction ID, response time, etc. in the back-end context information.

[0123] After obtaining the available data, the distributed stream processing framework performs format conversion on the available data based on the required format for each input data type to obtain the target data.

[0124] In S43, the preprocessing includes data cleaning, data transformation, and feature engineering. Among them, data cleaning refers to removing duplicate data, filling missing values, and handling outliers; data transformation refers to normalizing or standardizing the data; feature engineering refers to converting the data into feature vectors.

[0125] In S44, the machine learning model is trained in the early stage. Since Apache Flink supports multi-source input, the data from different data sources are integrated together to provide a more comprehensive data perspective for model training.

[0126] In the subsequent actual application of the machine learning model, using Apache Flink can provide the machine learning model with target data that makes the input more comprehensive. The machine learning model analyzes the input target data to obtain a classification probability distribution. The classification probability distribution includes the classification results of user operation behaviors and the anomaly scores for each classification result.

[0127] In S45, a security engine module is constructed. The security engine module selects the highest value from the anomaly scores of each classification result and converts the highest anomaly score into an evaluation level. For example, if the highest anomaly score is less than or equal to 0.1, the evaluation level is 1; if the highest anomaly score is greater than 0.1 and less than or equal to 0.5, the evaluation level is 2; if the highest anomaly score is greater than 0.5 and less than or equal to 0.8, the evaluation level is 3; if the highest anomaly score is greater than 0.8, the evaluation level is 4.

[0128] In S5 and S6, it is determined whether the evaluation level is greater than a preset security level; if it is less, it indicates that the user operation behavior is normal and the system can run normally; if it is greater, it indicates that the user operation behavior is abnormal, the target security policy matching the security level is obtained, and corresponding security measures are executed according to the target security policy, such as sending an alarm to the auditor, restricting access rights, restricting operations, etc., to adapt to the changing security requirements and environmental conditions.

[0129] The above method has good scalability. Auditors can select appropriate machine learning models according to business requirements, and the distributed stream processing framework can provide comprehensive input data for the selected machine learning models. The intelligent audit method for Web system user operations of the present disclosure can capture all data related to user operation behaviors in a fine-grained manner by monitoring the entire process of the interaction between the user and the front end and the interaction between the front end and the back end. This method supports almost all types of machine learning models and can map the output results of the machine learning models into specific evaluation levels. In this way, when an abnormal user operation behavior is detected, corresponding security measures can be immediately triggered, thereby ensuring the normal operation of the system and the security of the environment. It also reduces the impact on system performance and the occupation of system resources through asynchronous logging and performance optimization measures. This fine-grained logging can discover and improve aspects that affect the user experience, improve system security, and detect and prevent potential security threats by real-time monitoring and analyzing user behaviors.

[0130] This method can be applied to multiple industries that require Web system user operation audits. For example, in the financial services industry, all user operations in bank systems, trading platforms, or payment systems are recorded and monitored to detect fraud or unauthorized access. In social media platforms, user behaviors on social media are monitored to prevent malicious activities such as spam, phishing, and hate speech. In human resource management systems, access by employees to sensitive human resource data is tracked to ensure data confidentiality and integrity.

[0131] A visual audit log module is also set up to transmit front-end context information, back-end interaction data, back-end context information, evaluation levels, target security policies, execution results of target security policies, etc. to the visual audit log module. The visual audit log module comprehensively processes these data and provides a visual interface for auditors to view.

[0132] Referring to Figure 6 , the present disclosure provides a Web system user operation intelligent audit system, including:

[0133] A front-end data acquisition module 101, configured to acquire user interface interaction data in response to an operation request of a user on a front-end interface;

[0134] A front-end information acquisition module 102, configured to acquire front-end context information based on the front-end environment where the user operation is located when the user operation triggers a front-end event;

[0135] An HTTP request trigger module 103, configured to acquire back-end interaction data and back-end context information based on multiple processing stages of an HTTP request when the user operation triggers the front-end to send an HTTP request to the back-end;

[0136] An evaluation level acquisition module 104, configured to acquire an evaluation level of the user operation behavior based on the user interface interaction data, front-end context information, back-end interaction data, and back-end context information;

[0137] A security policy acquisition module 105, configured to acquire a target security policy when the evaluation level is greater than a preset security level;

[0138] A security measure execution module 106, configured to execute corresponding security measures based on the target security policy.

[0139] The various change methods and specific examples in the above-provided Web system user operation intelligent audit method are equally applicable to the Web system user operation intelligent audit system provided by the present disclosure. Through the foregoing detailed description of the Web system user operation intelligent audit method, those skilled in the art can clearly know the implementation method of the Web system user operation intelligent audit system. For the sake of simplicity of the specification, it will not be elaborated herein.

[0140] A computer device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0141] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the Web system user operation intelligent auditing method of the foregoing embodiments of the present disclosure.

[0142] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, known structures such as communication buses and interfaces may also be included in this embodiment, and these known structures should also be included in the protection scope of the present disclosure.

[0143] As Figure 7 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiments of the present disclosure. Figure 7 The shown computer device is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0144] As Figure 7 As shown, the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0145] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device, etc.; an output device including, for example, a display screen, etc.; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the computer device to communicate wirelessly or wireline with other devices (such as edge computing devices) to exchange data. Although Figure 7A computer device having various devices is shown, but it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0146] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the Web system user operation intelligent auditing method of the embodiments of the present disclosure are performed.

[0147] For a detailed description of this embodiment, reference can be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.

[0148] A computer-readable storage medium according to an embodiment of the present disclosure stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the Web system user operation intelligent auditing method of the foregoing embodiments of the present disclosure are performed.

[0149] The above-mentioned computer-readable storage medium includes but is not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or removable hard disks), media having built-in rewritable non-volatile memories (such as memory cards), and media having built-in ROMs (such as ROM cartridges).

[0150] For a detailed description of this embodiment, reference can be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.

[0151] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for the purpose of illustration and easy understanding, rather than limitations, and the above details do not limit the present disclosure to necessarily adopt the above specific details to implement.

[0152] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any way. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.

[0153] In addition, as used herein, "or" in the listing of items starting with "at least one" indicates a disjunctive listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Further, the term "exemplary" does not mean that the examples described are preferred or better than other examples.

[0154] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.

[0155] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0156] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0157] The foregoing description has been presented for purposes of illustration and description. In addition, the description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.

Claims

1. A method for intelligent auditing of user operations in a Web system, characterized in that: include: Responding to the user's operation request on the front-end interface, obtaining user interface interaction data; When a user operation triggers a front-end event, obtain the front-end context information based on the front-end environment where the user operation occurs; When a user operation triggers the front-end to send an HTTP request to the back-end, the back-end interaction data and back-end context information are obtained based on multiple processing stages of the HTTP request; Based on the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information, obtaining an evaluation level of the user operation behavior; When the evaluation level is greater than a preset security level, obtaining a target security policy; Based on the target security policy, corresponding security measures are executed.

2. The method for intelligent auditing of user operations of a Web system according to claim 1, characterized in that: The obtaining of user interface interaction data includes: Based on the business scenario, determine several event types to be captured; Based on the event type to be captured, create an event listener; When the user operates on the front-end interface, the generation of the operation request is triggered; When the operation request is generated, user interface interaction data is acquired based on the event listener.

3. The method for intelligent auditing of user operations of a Web system according to claim 1, characterized in that: Based on the front-end environment where the user operates, obtain the front-end context information, including: Determine the target information capturer based on the front-end environment where the user operates; Based on the target information capturer, the front-end context information is obtained.

4. The method for intelligent auditing of user operations of a Web system according to claim 1, characterized in that: The multiple processing stages of the HTTP request include an initialization stage, a backend application response stage, a method call stage, and a server response stage; The backend context information includes first context information, second context information and third context information; In the method calling phase, obtaining the backend interaction data; In the initialization phase, first context information of an HTTP request initiated by a front-end application is obtained; In the backend application response phase, obtaining second context information of the HTTP request entering the backend application; In the server response phase, third context information of the backend server processing the HTTP request is obtained.

5. The method for intelligent auditing of user operations of a Web system according to claim 1, characterized in that: In the method calling stage, obtaining the backend interaction data includes: Create a section class and set a cut point in the section class; Match all methods and functions marked with @AuditLog annotation based on pointcut; The surround notification method is adopted to collect information of the matched method functions, and the collected method function information constitutes the back-end interaction data.

6. The method for intelligent auditing of user operations of a Web system according to claim 1, characterized in that: The obtaining of the evaluation level of the user operation behavior based on the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information includes: Get the input data type of the preset machine learning model; Based on the input data type, filter out target data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information; Preprocessing the target data; Inputting the preprocessed target data into the machine learning model to obtain a classification probability distribution; Based on the classification probability distribution, an evaluation level of the user operation behavior is obtained.

7. The method for intelligent auditing of user operations of a Web system according to claim 6, characterized in that: The step of filtering out target data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information based on the input data type includes: Extract the required input data types from the machine learning model’s configuration files or metadata; Determine the format required for each input data type; Setting filtering conditions based on the input data type; Filtering available data from the user interface interaction data, the front-end context information, the back-end interaction data, and the back-end context information according to the filtering condition; Based on the format required by each input data type, the available data is format converted to obtain the target data.

8. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the Web system user operation intelligent audit method described in any one of claims 1-7.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the Web system user operation intelligent audit method described in any one of claims 1-7.

10. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Transaction management method, system and equipment for nested execution of delivery rules and medium

    CN121563441A