Anti-malicious-link authoritative attribute base detection and risk removal method of anti-malicious-link authoritative attribute base detection

By installing a dedicated anti-malicious link APP on the mobile terminal, using the dedicated data module for legal links and the known malicious link data dictionary module for detection and analysis, the problem of mobile phone users lacking identification and interception technology when opening the link is solved, effectively identifying and blocking malicious links is achieved, and the risk of property loss is reduced.

CN120151053APending Publication Date: 2025-06-13INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510354645.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Mobile phone users lack effective identification and interception technology when opening links, which leads to easily being deceived by malicious links and causing property damage.

Method used

By installing a dedicated anti-malicious link APP on the mobile terminal, the legal link dedicated data module and known malicious link data dictionary module are used for detection, and the connection of malicious links is blocked, and the unidentified links are technically analyzed and overwritten through authoritative nodes to ensure the security of the link.

Benefits of technology

It effectively avoids property losses caused by malicious links, which are particularly suitable for the elderly. By promptly identifying and blocking malicious links, the risk of being cheated is significantly reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151053A_ABST
    Figure CN120151053A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-malicious-link authoritative attribute base detection and risk removal method, and relates to a malicious link risk removal method, which comprises a structure module, an individual user public authentication system node, an authoritative node authentication module and a mobile phone terminal anti-malicious-link special APP. Identifying legal links or known malicious links by utilizing a legal link special data module and a known malicious link data dictionary module of a built-in detection system of the mobile phone terminal anti-malicious link special APP; according to the method, the legal link special database downloaded by the authoritative node is used for matching and opening, and property loss caused by opening of malicious links is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for de-risking malicious links. Specifically, the present disclosure relates to an authoritative attribute-based detection of anti-malicious links and its de-risking method. Background Art

[0002] Currently, common fraud means mainly target people who are not very clear about mobile networks or the elderly. The reason for these problems is that there is no effective identification and interception technology or means when the mobile phone's camera scans a code, logs in to a browser to download an APP, or opens a link. Most deceptive websites or phishing websites have some errors and are easy to identify, but there are also many that look exactly the same as legitimate websites, which is difficult for mobile phone users to simply identify; there are also many fraud calls that come in and deceive mobile phone users into installing software, revealing personal information or financial information, and using fake APPs for screen sharing in order to obtain various account passwords, verification codes, device passwords, etc. of mobile phone users to control the mobile phone, which are the main reasons for being deceived. Summary of the Invention

[0003] The purpose of the present disclosure is to disclose an authoritative attribute-based detection of anti-malicious links and its de-risking method based on the existing deficiencies, and use a dedicated database of legitimate links downloaded by authoritative nodes for matching and opening to avoid property losses caused by opening malicious links.

[0004] In order to achieve the invention purpose of the present disclosure, the following technical solutions are disclosed in this application: An authoritative attribute-based detection of anti-malicious links and its de-risking method, including a structure module, an individual user at a public authentication system node, an authoritative node authentication module, and a dedicated anti-malicious link APP for mobile terminals; An individual user registration module, using an individual mobile terminal for user registration; The authoritative node authentication module processes the individual user registration information and signs a smart contract; After the dedicated anti-malicious link APP for mobile terminals is downloaded and installed, it scans the QR code and clicks on the link for detection authorization; The dedicated data module of legitimate links and the known malicious link data dictionary module of the built-in detection system of the dedicated anti-malicious link APP for mobile terminals are used to identify legitimate links or known malicious links. When the dedicated data module of legitimate links and the known malicious link data dictionary module confirm that the link is legitimate, the link is opened for further operations. At this time, the detection of the dedicated anti-malicious link APP for mobile terminals is aborted, and the detection continues after the next link appears; When a link cannot be recognized, the dedicated anti-malicious link APP on the mobile terminal first blocks the connection of the link and uploads the unrecognizable link to the public authentication system node. Then, the authoritative node conducts a technical analysis on the JS code of the unrecognizable link. After obtaining the key JS functions of the JS code, the key JS functions are overwritten and injected into the JS code query interface of the collaborative anti-virus website. Next, the response data is released. After confirming harmlessness, it is replied to the dedicated anti-malicious link APP on the mobile terminal that it can log in. If it is a malicious link, the information of the malicious link object is recorded in the result dictionary, and the login is blocked through the mobile interface and a risk notification is shown to obtain the de-risking of the malicious link.

[0005] For the authoritative attribute-based detection and de-risking method of anti-malicious links, the dedicated APP detection system for anti-malicious links on the mobile terminal also includes the detection trusteeship of camera-scanned links, mobile text message links, social APP push links, and browser web page links. When performing shopping payments, transfers, deposits and withdrawals, and bill inquiries during the login of a legal link financial APP, the dedicated anti-malicious link APP on the mobile terminal automatically shuts down. When clicking on a link in the dialog box or scanning a QR code link using the camera during the operation, the dedicated anti-malicious link APP on the mobile terminal is always in a triggered startup and monitoring state, and detects the link or the scanned QR code link.

[0006] For the authoritative attribute-based detection and de-risking method of anti-malicious links, the following steps are performed based on the JS code: First, detect the key JS functions of the target element, discover harmful object information, and start page recording. Call the preset code to overwrite the target element and prohibit the triggering of corresponding events for various behaviors of the target element; determine whether a user instruction to continuously execute the JS code is received; if a user instruction is received, loop back to detect all the links to be detected from the static response content of the target web page; if no user instruction is received, stop executing the JS code; traverse all the recorded harmful object information to obtain the corresponding position information; sort each harmful object information in the order of the horizontal axis coordinate / vertical axis coordinate of the corresponding position information; call the preset function to convert the element style corresponding to the harmful object information into a rendered picture; record the rendered html code corresponding to the harmful object information; arrange the rendered pictures and the html code in one-to-one correspondence in the sorted order and generate a detection report; upload the page recording result and the detection report to the public authentication system node, and the public authentication system node stores the malicious link in the result dictionary of the known malicious link data module.

[0007] For the authoritative attribute-based detection and de-risking method of anti-malicious links, the legal link dedicated data module and the known malicious link data module perform update processing on mobile users regularly after data update.

[0008] The described authoritative attribute-based detection of malicious links and its risk mitigation method. The dedicated APP detection system for mobile terminals to resist malicious links includes: a monitoring module for camera scanning links, mobile phone text message links, social APP push links, and browser web page links; an interception module; an extraction module; an analysis module; an overwriting module; and a release execution module. The monitoring module is used to monitor the target link to be detected and the browser web page link when receiving an access request. The interception module is used to call the link and browser web page link interfaces to intercept the response before the target link and browser web page link are rendered. The extraction module is used to extract JS code based on the target link and browser web page link. The analysis module is used to perform integrated analysis on the JS code to obtain all the key JS functions. The overwriting module is used to call the overwriting function to overwrite the key JS functions to obtain the second key JS functions. The release execution module is used to inject the JS code into the browser of the target website, release the response data, and perform the next step based on the JS code.

[0009] The described authoritative attribute-based detection of malicious links and its risk mitigation method. The JS code performs the following steps: extracting all the links to be detected from the static response content of the target link and browser web page link; using a preset blacklist to detect each link to be detected and browser web page link to obtain the target elements and their corresponding position information; calling a preset style processing function to modify the styles of the target elements to obtain the corresponding element styles; and recording the element styles and the corresponding position information as the first harmful object information in the public authentication system node result dictionary.

[0010] The described authoritative attribute-based detection of malicious links and its risk mitigation method. The personal user registration module uses the personal mobile terminal to connect to the public authentication system node. The public authentication system node verifies according to the mobile phone number, name, ID number filled in by the individual and the biometric information of face recognition and verifies the identity information. The public authentication system node is processed by the authoritative node, and the authoritative node authentication module of the public authentication system node performs on-chain processing. The authoritative node authentication module is used for node AID. First, it downloads the authoritative node AID to generate a public key, and then submits an application. The authoritative node AID is used to process whether the mobile phone number for personal user registration is consistent with the information stored by legitimate users, and whether the filled ID number is standardized, accurate, and consistent with the information stored by legitimate users. After the authentication module confirms, the authoritative node issues an authentication interface on the mobile terminal and signs a smart contract. The authentication interface includes a timestamp, phone number, and name that are updated in real time. Then, the dedicated APP for mobile terminals to resist malicious links is downloaded and installed in the authoritative node authentication module. After the dedicated APP for anti-malicious links on the mobile terminal is downloaded and installed, open the APP to scan the QR code and click on the link detection authorization option. The dedicated APP for anti-malicious links on the mobile terminal detects links including camera scan links, mobile phone text message links, social APP push links, and browser web page links, and then the dedicated APP for anti-malicious links on the mobile terminal synchronously monitors the camera and interface links.

[0011] Through the above disclosure, the beneficial effects of the present disclosure are: The authoritative attribute-based detection of anti-malicious links and its risk mitigation method described in the present disclosure match legal link-specific data for camera scan links, mobile phone text message links, social APP push links, and browser web page links by authorizing the dedicated APP for anti-malicious links on the mobile terminal, and identify legal links or known malicious links by the known malicious link data dictionary module, avoiding property losses caused by the current inability to effectively monitor mobile phones; the present disclosure is particularly suitable for use by the elderly who are not easily able to distinguish mobile networks, and plays a certain role in promoting the timely identification and prevention of installation of malicious links; the present disclosure is particularly suitable for installation by elderly people living alone. After installation with the assistance of the community or children, the probability of being deceived can be greatly reduced. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a schematic diagram showing the principle of the present disclosure; Figure 2 is a schematic diagram of the registration process of the present disclosure; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0013] The following will describe in detail the preferred embodiments of the present disclosure with reference to the accompanying drawings, so as to more clearly understand the inventive purpose, features, and advantages of the present disclosure. It should be understood that the embodiments shown in the drawings are not limitations on the scope of the present disclosure, but only explanations of the embodiments of the technical solution of the present disclosure that are not limited to one type.

[0014] Combined with the attached Figure 1 The authoritative attribute-based detection of anti-malicious links and its risk mitigation method described in Attachment 1 or 2 includes structural modules, individual users, public authentication system nodes, authoritative node authentication modules, and dedicated APPs for anti-malicious links on mobile terminals; The individual user registration module uses an individual mobile terminal to connect to the public authentication system node. The public authentication system node verifies and verifies the identity information based on the mobile phone number, name, ID number, and face recognition biometric information filled in by the individual. The public authentication system node is processed through the authoritative node, and the authoritative node authentication module of the public authentication system node performs on-chain processing; The authoritative node authentication module is used for node AID. First, it downloads the authoritative node AID to generate a public key, and then submits an application. The authoritative node AID is used to process whether the mobile phone number filled in by the individual user for registration is consistent with the information stored by the legitimate user, and whether the filling of the ID number is standardized and accurate and consistent with the information stored by the legitimate user; After the authentication module confirms, the authoritative node issues a verification interface on the mobile terminal and signs a smart contract. The verification interface includes a timestamp, a phone number, and a name that are updated in real time; then, the mobile terminal anti-malicious link dedicated APP is downloaded and installed in the authoritative node authentication module; The mobile terminal anti-malicious link dedicated APP detection system includes: a monitoring module, an interception module, an extraction module, an analysis module, an overwriting module, and a release execution module for monitoring links scanned by the camera, mobile phone text message links, social APP push links, and browser web page links; the monitoring module is used to monitor the target link to be detected and the browser web page link to receive an access request; the interception module is used to call the link and browser web page link interfaces to intercept the response before the target link and the browser web page link are rendered; the extraction module is used to extract JS code based on the target link and the browser web page link; the analysis module is used to integrally analyze the JS code to obtain all the JS key functions; the overwriting module is used to call an overwriting function to overwrite the JS key functions to obtain a second JS key function; the release execution module is used to inject the JS code into the browser of the target website, release the response data; and execute the next step based on the JS code; After the mobile terminal anti-malicious link dedicated APP is downloaded and installed, open the APP to scan the QR code and click the link detection authorization option. The mobile terminal anti-malicious link dedicated APP detects links including those scanned by the camera, mobile phone text message links, social APP push links, and browser web page links, and then the mobile terminal anti-malicious link dedicated APP synchronously monitors the camera and the interface links; Use the legitimate link dedicated data module and the known malicious link data dictionary module in the built-in detection system of the mobile terminal anti-malicious link dedicated APP to identify legitimate links or known malicious links. When the legitimate link dedicated data module and the known malicious link data dictionary module confirm that the link is legitimate, open the link for further operations. At this time, the detection of the mobile terminal anti-malicious link dedicated APP is aborted, and the detection continues after the next link appears; When a link cannot be recognized, the dedicated anti-malicious link APP on the mobile terminal first blocks the connection of the link and uploads the unrecognizable link to the public authentication system node. Then, the authoritative node conducts a technical analysis on the JS code of the unrecognizable link. After obtaining the JS key function of the JS code, the JS key function is overwritten and injected into the JS code query interface of the collaborative anti-virus website. Next, the response data is released. After confirming harmlessness, it is replied that the dedicated anti-malicious link APP on the mobile terminal can log in. If it is a malicious link, the malicious link object information is recorded in the result dictionary, and the login is blocked through the mobile interface and a risk notification is shown to obtain the de-risking of the malicious link.

[0015] Specifically, the following steps are executed based on the JS code: First, the JS key function of the target element is detected, harmful object information is found, and page recording is started; Call the preset code to overwrite the target element and prohibit the triggering of corresponding events for various behaviors of the target element; Determine whether a user instruction to continuously execute the JS code is received; If a user instruction is received, loop back to detect all the links to be detected from the static response content of the target web page; If no user instruction is received, stop executing the JS code; Traverse all the recorded harmful object information to obtain the corresponding position information; Sort each piece of harmful object information in the order of the horizontal axis coordinate / vertical axis coordinate of the corresponding position information; Call the preset function to convert the element style corresponding to the harmful object information into a rendered picture; Record the rendered html code corresponding to the harmful object information; Arrange the rendered pictures and the html code in one-to-one correspondence in the sorted order and generate a detection report; Upload the page recording result and the detection report to the public authentication system node, and the public authentication system node stores the malicious link in the result dictionary of the known malicious link data module.

[0016] The JS code executes the following steps: Extract all the links to be detected from the static response content of the target link and the browser web page link; Use the preset blacklist to detect each link to be detected and the browser web page link to obtain the target element and the corresponding position information; Call the preset style processing function to modify the style of the target element to obtain the corresponding element style; Record the element style and the corresponding position information as the first harmful object information in the result dictionary of the public authentication system node.

[0017] Furthermore, the dedicated anti-malicious link APP detection system on the mobile terminal also includes the detection trusteeship of camera-scanned links, mobile text message links, social APP push links, and browser web page links; When performing shopping payments, transfers, deposits and withdrawals, and bill inquiries when logging in to a legitimate financial APP, the dedicated anti-malicious link APP on the mobile terminal automatically shuts down. That is, various shopping payment, transfer, deposit and withdrawal operations of the legitimate financial APP are not under supervision. When clicking on a link in a dialog box or using the camera to scan a QR code link during the operation, the dedicated anti-malicious link APP on the mobile terminal is always in a triggered startup and monitoring state, and detects the link or the scanned QR code link.

[0018] The dedicated data module for legitimate links and the known malicious link data module periodically update mobile users after data updates.

[0019] This disclosure has an extended function. By authorizing the call monitoring of the dedicated anti-malicious link APP on the mobile terminal, fraudulent calls from overseas can be blocked from being connected by blocking the connection.

[0020] The preferred embodiments of the present disclosure have been described in detail above. However, it should be understood that after reading the above teachings of the present disclosure, those skilled in the art can make various changes or modifications within the protection scope of the present disclosure. These equivalent forms also fall within the scope defined by the appended claims of this application.

[0021] The parts not detailed in this disclosure are prior art.

Claims

1. An authoritative attribute-based detection method for resisting malicious links and its risk removal method, characterized by: It includes structural modules, individual users in public authentication system nodes, authoritative node authentication modules and mobile terminal anti-malicious link dedicated APP; Personal user registration module, using personal mobile phone terminal to register users; The authoritative node authentication module processes individual user registration information and signs a smart contract; After downloading and installing the anti-malicious link APP on the mobile terminal, scan the QR code and click the link to detect authorization; The legitimate link or known malicious link is identified by using the legitimate link dedicated data module and the known malicious link data dictionary module of the built-in detection system of the mobile terminal anti-malicious link dedicated APP. When the legitimate link dedicated data module and the known malicious link data dictionary module confirm that the link is legitimate, the link is opened for further operation. At this time, the mobile terminal anti-malicious link dedicated APP detection is suspended, and the detection will continue after the next link appears; If an unrecognizable link appears, the mobile terminal's special anti-malicious link APP will first block the connection of the link and upload the unrecognizable link to the public authentication system node, and then conduct technical analysis on the JS code of the unrecognizable link through the authoritative node. After obtaining the JS key function of the JS code, the JS key function is overwritten and injected into the JS code query interface of the cooperative anti-virus website. Then, the response data is released to confirm that it is harmless and then reply to the mobile terminal's special anti-malicious link APP to log in. If it is a malicious link, the malicious link object information will be recorded in the result dictionary and the login will be blocked through the mobile phone interface and a risk notification will be presented to eliminate the risk of malicious links.

2. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 1 is characterized in that: The mobile terminal anti-malicious link dedicated APP detection system also includes camera scanning links, mobile phone SMS links, social APP push links and browser web page links detection hosting; When logging into a legally linked financial APP for shopping payments, transfers, deposits and withdrawals, and bill inquiries, the mobile terminal's special anti-malicious link APP is automatically closed. When entering the dialog box to click on a link or using the camera to scan a QR code link, the mobile terminal's special anti-malicious link APP is in a triggered, started, and monitored state at any time, and detects the link or scanned QR code link.

3. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 1 is characterized in that: Based on the JS code, the following steps are performed: First, the JS key functions of the target element are detected, harmful object information is found, and page recording is enabled; Calling a preset code to cover the target element and prohibiting various behaviors of the target element from triggering corresponding events; Determine whether a user instruction to continue executing JS code is received; If a user instruction is received, the process loops again to detect all links to be detected from the static response content of the target web page; If no user instruction is received, stop executing the JS code; traverse all the recorded harmful object information and obtain the corresponding location information; Sort the information of each harmful object according to the horizontal axis coordinate / vertical axis coordinate order of the corresponding position information; Call the preset function to convert the element style corresponding to the harmful object information into a rendered image; record the rendered HTML code corresponding to the harmful object information; According to the sorted order, the rendering images and the HTML codes are arranged one by one and a detection report is generated; the page video recording results and the detection report are uploaded to the public authentication system node, and the public authentication system node stores the malicious links in the known malicious link data module result dictionary.

4. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 1 is characterized by: The legitimate link dedicated data module and the known malicious link data module are updated regularly for mobile phone users after the data is updated.

5. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 1 is characterized by: The mobile terminal anti-malicious link special APP detection system includes: a monitoring module, an interception module, an extraction module, an analysis module, an overwrite module and a release execution module for camera scanning links, mobile phone text message links, social APP push links and browser web links; the monitoring module is used to monitor the target link to be detected and the browser web link to receive an access request; the interception module is used to call the link and browser web link interface, and intercept the response before the target link and the browser web link are rendered; the extraction module is used to extract the JS code based on the target link and the browser web link; the analysis module is used to integrate and analyze the JS code to obtain all JS key functions; the overwrite module is used to call the overwrite function to overwrite the JS key function to obtain a second JS key function; the release execution module is used to inject the JS code into the browser of the target website, release the response data, and execute the next step based on the JS code.

6. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 5 is characterized by: The JS code performs the following steps: extracting all links to be detected from the static response content of the target link and the browser web page link; Use the preset blacklist to detect each link to be checked and the browser web page link to obtain the target element and the corresponding location information; A preset style processing function is called to modify the style of the target element to obtain a corresponding element style; the element style and corresponding position information are recorded as first harmful object information in a public authentication system node result dictionary.

7. The authoritative attribute-based detection and risk removal method for anti-malicious links according to claim 1 is characterized by: The individual user registration module uses a personal mobile phone terminal to connect to the public authentication system node. The public authentication system node verifies and verifies the identity information based on the individual's reported mobile phone number, name, ID number, and facial recognition biometric information. The public authentication system node processes it through the authoritative node, and the authoritative node authentication module of the public authentication system node performs on-chain processing; The authoritative node authentication module is used for node AID. First, the authoritative node AID is downloaded to generate a public key, and then the application is submitted. The authoritative node AID is used to process whether the mobile phone number registered by the individual user is consistent with the information stored by the legitimate user, and whether the ID number is filled in correctly and is consistent with the stored information of the legitimate user; After the authentication module confirms, the authoritative node issues a confirmation interface on the mobile terminal and signs a smart contract. The confirmation interface includes a real-time updated timestamp, phone number, and name. Then, the authoritative node authentication module downloads and installs a special mobile terminal anti-malicious link APP. After downloading and installing the mobile terminal's special anti-malicious link APP, open the APP to scan the QR code and click the link detection authorization option. The mobile terminal's special anti-malicious link APP will detect links including camera scanning links, mobile phone SMS links, social APP push links and browser web links, and then the mobile terminal's special anti-malicious link APP will synchronize the monitoring camera and interface links.