Webpage request processing method and device, electronic equipment and storage medium

The authenticity of web page requests is judged through the human-machine weight algorithm, and the interface signature key is used for security verification, which solves the problem of malicious simulated requests in web page access and improves security and user experience.

CN120223422AActive Publication Date: 2025-06-27SHENZHEN FENXIANG INTERNET TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510495323.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-06-27
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

When a user accesses a web page, there are fake web page requests through the machine, resulting in malicious access, which seriously affects the security of the web page access process.

Method used

The human-machine weight algorithm is used to determine the human-machine evaluation score based on user behavior data and the number of requests for web page requests, and determine that the web page request is a user's real request or machine simulation request. When determining that the user's real request is made, the interface signature key generated by the front-end service and the back-end service are compared to determine whether to access the target web page.

Benefits of technology

It improves the security of the web access process, avoids waste of resources caused by machine simulation requests, does not need to interrupt user browsing behavior, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223422A_ABST
    Figure CN120223422A_ABST
Patent Text Reader

Abstract

The invention provides a webpage request processing method and device, electronic equipment and a storage medium, and the method comprises the steps: receiving a webpage request for a target webpage, and detecting user behavior data and the request frequency of the webpage request within a preset time period after the webpage request is received; the webpage request does not contain user identity information; determining a man-machine evaluation score based on the user behavior data and the request frequency of the webpage request by adopting a man-machine weight algorithm, and judging whether the webpage request is a real user request or a machine simulation request based on the man-machine evaluation score; and under the condition that the webpage request is the real request of the user, determining whether to access the target webpage or not based on a first interface signature key which is generated by calling the front-end service and aims at the webpage request and a second interface signature key which is generated by calling the back-end service and aims at the webpage request. According to the embodiment of the invention, the security in the webpage access process can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of web access, and in particular, to a method for processing web requests, a device for processing web requests, an electronic device, and a computer-readable storage medium. Background Art

[0002] With the development of computer technology, malicious access to web pages has gradually increased, so network security protection has gradually attracted people's key attention. During the process of a user accessing a web page, there is usually a situation where a machine simulates and forges a web request, and maliciously accesses the web page through the forged web request, thus seriously affecting the security of the web access process. Summary of the Invention

[0003] Embodiments of the present disclosure at least provide a method for processing web requests, a device for processing web requests, an electronic device, and a computer-readable storage medium, which can improve the security during the web access process.

[0004] Embodiments of the present disclosure provide a method for processing web requests, including: Receiving a web request for a target web page, and detecting user behavior data within a preset time period after receiving the web request and the number of requests of the web request; the web request does not contain user identity information; Using a human-machine weight algorithm, based on the user behavior data and the number of requests of the web request, determining a human-machine evaluation score, and based on the human-machine evaluation score, determining whether the web request is a real user request or a machine-simulated request; In the case where the web request is the real user request, based on a first interface signature key generated by invoking a front-end service for the web request and a second interface signature key generated by invoking a back-end service for the web request, determining whether to access the target web page.

[0005] In the embodiments of the present disclosure, a human-machine weight algorithm is used to determine a human-machine evaluation score based on user behavior data and the number of requests of the web request, and then based on the human-machine evaluation score, it is determined whether the web request is a real user request or a machine-simulated request, and in the case where the web request is a real user request, it is further determined whether to access the target page based on the subsequently generated key. In this way, the security of the web access process can be improved.

[0006] In addition, since the web request for the target web page does not contain user identity information, this can play a role in protecting the user's identity.

[0007] Furthermore, compared with the detection method of "verification code and human-machine recognition component" in the related art, it is not necessary to interrupt the user's behavior of browsing the web page, which is beneficial to improving the user experience.

[0008] In an alternative embodiment, when the web page request is the machine simulation request, the front-end service is called to perform a first interception process on the web page request.

[0009] In the embodiments of the present disclosure, if the web page request is a machine simulation request, the front-end service is called to intercept the web page request, so that resource waste caused by the machine simulation request can be avoided.

[0010] In an alternative embodiment, the human-machine weight algorithm is used to determine a human-machine evaluation score based on the user behavior data and the number of requests of the web page request, including: Determine a first score corresponding to the user behavior according to the user behavior data, and determine a second score corresponding to the number of requests according to the number of requests of the web page request within the preset time period; Obtain a basic score, and determine the human-machine evaluation score based on the basic score, the first score, and the second score.

[0011] In the embodiments of the present disclosure, by determining a first score corresponding to the user behavior and a second score corresponding to the number of requests, the accuracy of the human-machine evaluation score is improved, thereby improving the accuracy of the judgment on the web page request.

[0012] In an alternative embodiment, the user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; the determining a first score corresponding to the user behavior according to the user behavior data includes: Construct a first vector according to the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; Construct a second vector based on the weights corresponding to the keyboard input behavior, the mouse control behavior, and the touchpad control behavior respectively; Determine the first score based on the first vector and the second vector.

[0013] In the embodiments of the present disclosure, since the user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors, the number of these behaviors can usually characterize whether it is a real user operation. For example, if it is a real user operation, the number of various operation behaviors is usually limited. Therefore, determining the first score based on the number of the above behaviors can improve the accuracy of the first score.

[0014] In an alternative embodiment, the preset time period includes a plurality of time windows, and each time window corresponds to a scoring weight; determining a second score corresponding to the number of requests of the web request within the preset time period includes: For each time window, determine a score corresponding to the time window according to the number of requests of the web request within the time window and the scoring weight corresponding to the time window; Obtain a preset abnormal deduction score, and determine the second score based on the abnormal deduction score and the sum of the scores corresponding to each time window respectively.

[0015] Here, by setting a plurality of time windows and respectively determining corresponding scores for each time window, the accuracy of the second score can be improved in this way.

[0016] In an alternative embodiment, determining that the web request is a real user request or a machine-simulated request based on the human-computer evaluation score includes: If the human-computer evaluation score is less than a preset threshold, determine that the web request is the machine-simulated request.

[0017] In the embodiments of the present disclosure, comparing the human-computer evaluation score with the preset threshold, that is, determining whether the web request is a machine-simulated request in a quantitative manner. In this way, the accuracy can be improved.

[0018] In an alternative embodiment, the calling the front-end service to generate a first interface signature key for the web request based on a first preset encryption rule includes: Obtain an initial key and a time stamp for the current signature; Determine the sum of the American Standard Code for Information Interchange (ASCII) code values of the initial key; Generate a random number, and generate the first interface signature key based on the human-computer evaluation score, the sum of the ASCII code values, the time stamp, and the random number.

[0019] In the embodiments of the present disclosure, since the time stamp is unique and the random number is random, generating the first interface signature key dynamically based on the human-computer evaluation score, the sum of the ASCII codes of the initial key, the time stamp, and the random number. In this way, it is beneficial to increase the complexity and unpredictability of the first interface signature key, thereby reducing the risk of key leakage.

[0020] In an alternative embodiment, when the web page request is a genuine request from the user, determining whether to access the target web page based on a first interface signature key generated by invoking a front-end service for the web page request and a second interface signature key generated by invoking a back-end service for the web page request includes: When the web page request is a genuine request from the user, invoke the front-end service to generate a first interface signature key for the web page request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encryption code block; Send the web page request carrying the first interface signature key to the back-end service, and invoke the back-end service to generate a second interface signature key for the web page request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule; Determine whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

[0021] In the embodiments of the present disclosure, after determining that the web page request is a genuine request from the user, a first interface signature key is generated by invoking the front-end service, and a second interface signature key is generated by invoking the back-end service. Whether to access the target web page is determined based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key. That is, the keys generated by the front-end service and the back-end service are compared respectively to avoid errors during the process of sending the web page request, thereby further enhancing the security of web page access.

[0022] In an alternative embodiment, the determining whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key includes: When the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is the unused status, determine to access the target web page.

[0023] When the first interface signature key is different from the second interface signature key, and / or the usage status of the first interface signature key is the used status, perform a second interception process on the web page request based on the back-end service.

[0024] In the disclosed embodiment, by comparing the first interface signature key generated by the front-end service with the second interface signature key generated by the back-end service, and determining the usage status of the first interface signature key, the web page request can be verified again, thereby further improving the security of the web page request. If the first interface signature key is different from the second signature and / or the usage status of the first interface signature key is in the used state, it means that the back-end service fails to verify the web page request, and a second interception process is required to be performed on it, so that malicious requests can be avoided.

[0025] In an optional implementation manner, after receiving a webpage request for a target webpage, the method further includes: Obtain device information of a target device that initiates the webpage request; Based on the device information of the target device, a human-machine evaluation storage field uniquely corresponding to the target device is generated; the human-machine evaluation storage field is used to store the human-machine evaluation score.

[0026] In the disclosed embodiment, a human-machine evaluation storage field uniquely corresponding to the target device is generated based on the device information of the target device. Since the human-machine evaluation score may change in real time, the human-machine evaluation score is stored in this field to facilitate the management of the human-machine evaluation score.

[0027] In an optional implementation manner, the encryption code block including the human-machine weight algorithm and the first preset encryption rule is obtained according to the following steps: Using a code obfuscation tool to perform compression and obfuscation processing on an initial code block including the human-machine weight algorithm and the first preset encryption rule to obtain a first processing result; The first processing result is encoded and encrypted to obtain the encrypted code block.

[0028] In the disclosed embodiment, the initial code block is compressed and obfuscated, and then encoded and encrypted, so that the confidentiality of the encrypted code block can be improved, thereby improving the uniqueness and irreversibility of the key.

[0029] In an optional implementation manner, the webpage request is generated based on a user input operation on a browser, and the method further includes: Detecting whether the browser is in the debugging mode, and if it is determined that the browser is in the debugging mode, refreshing the current page displayed by the browser.

[0030] In the disclosed embodiment, when the browser is in debugging mode, the current page displayed by the browser is refreshed, so that code debugging of the page can be avoided, further improving the security of page access.

[0031] The embodiments of the present disclosure also provide a web page request processing device, including: A request receiving module, configured to receive a web page request for a target web page, and detect user behavior data within a preset time period after receiving the web page request and the number of requests of the web page request; the web page request does not include user identity information; A request judging module, configured to use a human-machine weight algorithm to determine a human-machine evaluation score based on the user behavior data and the number of requests of the web page request, and judge whether the web page request is a real user request or a machine-simulated request based on the human-machine evaluation score; A web page access module, configured to determine whether to access the target web page based on a first interface signature key generated by invoking a front-end service for the web page request and a second interface signature key generated by invoking a back-end service for the web page request when the web page request is the real user request.

[0032] The embodiments of the present disclosure also provide another web page request processing device, and the device further includes a request interception module, and the request interception module is configured to: In the case that the web page request is the machine-simulated request, call the front-end service to perform a first interception process on the web page request.

[0033] In an optional implementation manner, the request judging module is specifically configured to: Detect user behavior data within a preset time period after receiving the web page request and the number of requests of the web page request; Determine a first score corresponding to the user behavior according to the user behavior data, and determine a second score corresponding to the number of requests according to the number of web page requests within the preset time period; Obtain a basic score, determine a human-machine evaluation score based on the basic score, the first score and the second score, and determine whether the web page request is a real user request or a machine-simulated request based on the human-machine evaluation score.

[0034] In an optional implementation manner, the user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; the request judging module is specifically configured to: Construct a first vector according to the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; Construct a second vector based on the weights corresponding to the keyboard input behavior, the mouse control behavior, and the touchpad control behavior respectively; Determine the first score based on the first vector and the second vector.

[0035] In an alternative embodiment, the preset time period includes a plurality of time windows, and each time window corresponds to a scoring weight; specifically, the request judgment module is configured to: For each time window, determine a score corresponding to the time window according to the number of requests of the web request within the time window and the scoring weight corresponding to the time window; Obtain a preset abnormal deduction score, and determine the second score based on the abnormal deduction score and the sum of the scores corresponding to each time window respectively.

[0036] In an alternative embodiment, the request judgment module is specifically configured to: If the human-machine evaluation score is less than a preset threshold, determine that the web request is the machine simulation request.

[0037] In an alternative embodiment, the first key generation module is configured to: Obtain an initial key and a time stamp for the current signature; Determine the sum of the American Standard Code for Information Interchange (ASCII) code values of the initial key; Generate a random number, and generate the first interface signature key based on the human-machine evaluation score, the sum of the ASCII code values, the time stamp, and the random number.

[0038] In an alternative embodiment, the web access module is specifically configured to: When the web request is a real request of the user, call the front-end service to generate a first interface signature key for the web request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encryption code block; Send the web request carrying the first interface signature key to the back-end service, and call the back-end service to generate a second interface signature key for the web request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule; Determine whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

[0039] In an alternative embodiment, the web access module is specifically configured to: When the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is the unused status, determine to access the target web page; In the case where the first interface signature key is different from the second interface signature key, and / or the usage status of the first interface signature key is the used status, a second interception process is performed on the web page request based on the backend service.

[0040] In an optional implementation, the device further includes a field generation module, and the field generation module is configured to: Obtain the device information of the target device that initiates the web page request; Based on the device information of the target device, generate a human-machine evaluation storage field that is uniquely corresponding to the target device; the human-machine evaluation storage field is used to store the human-machine evaluation score.

[0041] In an optional implementation, the device further includes a code encryption module, and the code encryption module is configured to: Use a code obfuscation tool to perform compression and obfuscation processing on the initial code block including the human-machine weight algorithm and the first preset encryption rule to obtain a first processing result; Perform encoding and encryption processing on the first processing result to obtain the encrypted code block.

[0042] An embodiment of the present disclosure further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of any of the above possible web page request processing methods are executed.

[0043] An embodiment of the present disclosure further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, the steps of any of the above possible web page request processing methods are executed.

[0044] For the effect descriptions of the above web page request processing device, electronic device, and computer-readable storage medium, refer to the descriptions of the above web page request processing method, and details are not described herein again.

[0045] It should be understood that the above general description and subsequent detailed descriptions are only exemplary and explanatory, and do not limit the technical solutions of the present disclosure.

[0046] To make the above objects, features, and advantages of the present disclosure more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, is described in detail as follows. Description of the Drawings

[0047] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for the embodiments will be briefly introduced below. The accompanying drawings herein are incorporated into the specification and form a part of this specification. These accompanying drawings illustrate the embodiments consistent with the present disclosure and, together with the specification, are used to explain the technical solutions of the present disclosure. It should be understood that the following accompanying drawings only illustrate certain embodiments of the present disclosure and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related accompanying drawings can be obtained based on these accompanying drawings without creative efforts.

[0048] Figure 1 It shows a flowchart of a web page request processing method provided by an embodiment of the present disclosure; Figure 2 It shows an interaction schematic diagram between a front-end service and a back-end service provided by an embodiment of the present disclosure; Figure 3 It shows a flowchart of another web page request processing method provided by an embodiment of the present disclosure; Figure 4 It shows a structural schematic diagram of a web page request processing device provided by an embodiment of the present disclosure; Figure 5 It shows a structural schematic diagram of another web page request processing device provided by an embodiment of the present disclosure; Figure 6 It shows a structural schematic diagram of an electronic device provided by an embodiment of the present disclosure. Detailed Embodiments

[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some of the embodiments of the present disclosure, rather than all the embodiments. Usually, the components of the embodiments of the present disclosure described and illustrated in the accompanying drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the accompanying drawings is not intended to limit the scope of the present disclosure claimed, but merely represents selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present disclosure.

[0050] It should be noted that: Similar reference numerals and letters denote similar items in the following accompanying drawings. Therefore, once an item is defined in one accompanying drawing, it does not need to be further defined and explained in subsequent accompanying drawings.

[0051] As used herein, the term "and / or" merely describes an associated relationship and indicates that three relationships may exist. For example, A and / or B may represent three cases: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the term "at least one" as used herein means any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A, B, and C may mean including any one or more elements selected from the set composed of A, B, and C.

[0052] With the development of computer technology, malicious access to web pages has gradually increased, so network security protection has gradually received key attention from people.

[0053] It has been found through research that during the process of a user accessing a web page, there is usually a situation where a machine simulates and forges a web page request, and maliciously accesses the web page through the forged web page request, thus seriously affecting the security of the web page access process.

[0054] In addition, in order to improve access security, the solution adopted in related technologies is to detect whether the current web page request is a malicious request through a verification code or a human-machine recognition component. However, the above detection methods often require the user to interrupt the current access process. For example, when a user is browsing a certain web page, a verification prompt box will pop up on the page, and the user needs to interrupt the behavior of browsing the web page and first perform a verification operation before continuing to browse the page, which will affect the user's browsing experience.

[0055] Based on the above research, the present disclosure provides a method for processing a web page request. First, a web page request for a target web page is received, and user behavior data and the request count of the web page request within a preset time period after receiving the web page request are detected; the web page request does not contain user identity information; a human-machine weight algorithm is used to determine a human-machine evaluation score based on the user behavior data and the request count of the web page request, and based on the human-machine evaluation score, it is determined whether the web page request is a user's real request or a machine-simulated request; in the case where the web page request is the user's real request, based on a first interface signature key generated by invoking a front-end service and a second interface signature key generated by invoking a back-end service for the web page request, it is determined whether to access the target web page.

[0056] In the embodiments of the present disclosure, a human-machine weight algorithm is used to determine a human-machine evaluation score based on user behavior data and the request count of a web page request, and then based on the human-machine evaluation score, it is determined whether the web page request is a user's real request or a machine-simulated request. And in the case where the web page request is the user's real request, it is further determined whether to access the target page based on the subsequently generated key. In this way, the security of the web page access process can be improved.

[0057] In addition, since the web request for the target web page does not contain user identity information, it can play a role in protecting the user's identity.

[0058] Furthermore, compared with the detection method of "verification code and human-machine recognition component" in the related art, there is no need to interrupt the user's behavior of browsing the web page, which is beneficial to improving the user experience.

[0059] To facilitate the understanding of this embodiment, first, a web request processing method disclosed in the embodiments of the present disclosure will be introduced in detail. The execution subject of the web request processing method provided in the embodiments of the present disclosure is generally an electronic device. The electronic device can be a server, which can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, big data, and artificial intelligence platforms. In some other embodiments, the electronic device can also be a terminal device, where the terminal device can be a mobile device, a user terminal, a terminal, a handheld device, a computing device, a vehicle-mounted device, a wearable device, and so on.

[0060] In other embodiments, the method can also be applied to an implementation environment composed of a terminal device and a server. In addition, the web request processing method can also be implemented by a processor calling computer-readable instructions stored in a memory.

[0061] The following will illustrate a web request processing method provided in the embodiments of the present disclosure with reference to the accompanying drawings.

[0062] See Figure 1 As shown, it is a flowchart of a web request processing method provided in the embodiments of the present disclosure. As shown in Figure 1 it, the method includes steps S101 to S104, where: S101: Receive a web request for a target web page, and detect the user behavior data within a preset time period after receiving the web request and the number of requests of the web request; the web request does not contain user identity information.

[0063] Here, the target web page can be any browser web page or the web page of any application program, which is not limited herein.

[0064] Among them, the web request for the target web page can be a web request initiated by a user through a target device for the target web page. Among them, the target device can be a terminal device, such as a mobile phone, a computer, and other devices. In other embodiments, the web request for the target web page can also be a forged request.

[0065] Among them, the preset time period can be set according to actual needs. For example, it can be 30 seconds, 60 seconds, etc., and no limitation is made here.

[0066] In this embodiment, the user behavior data may include the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors. Among them, the mouse control behaviors may include mouse click behaviors (such as single-click behaviors and double-click behaviors), mouse movement behaviors, and mouse scroll bar rotation behaviors. In some other embodiments, the keyboard input behaviors may include character input behaviors, shortcut key click behaviors, etc., and the touchpad control behaviors may include touchpad click behaviors (such as single-click behaviors or double-click behaviors), and touchpad sliding behaviors.

[0067] After receiving a web page request for a target web page, there may be a situation where the user refreshes the request or there is a forged web page request for high-frequency malicious access. Therefore, it is necessary to detect the number of requests of the web page request. Here, it should be noted that in this embodiment, multiple web page requests are all for the same target web page.

[0068] Among them, the user identity information may include user login information or account information, etc., and no limitation is made here.

[0069] Optionally, based on the foregoing, the web page request can be generated based on the user's input operation on the browser. At this time, it is possible to detect whether the browser is in the debug mode. When it is determined that the browser is in the debug mode, the current page displayed by the browser is refreshed.

[0070] Here, some users may debug the target page when accessing the target page (such as viewing the page code, etc.). In order to avoid malicious debugging of the target page by users (such as decrypting and modifying the page code, etc.), in this embodiment, when the browser is in the debug mode, the current page is refreshed.

[0071] S102: Use the human-machine weight algorithm to determine a human-machine evaluation score based on the user behavior data and the number of requests of the web page request, and determine whether the web page request is a real user request or a machine simulation request based on the human-machine evaluation score.

[0072] Among them, the real user request may refer to a real request for the target web page initiated by the user through an electronic device; the machine simulation request may refer to a simulated request for the target web page. In the scenario of a distributed denial of service attack (DDoS), the attacked target can be attacked through a large number of machine simulation requests.

[0073] In the embodiment of the present disclosure, a human-machine weight algorithm is used to determine a human-machine evaluation score based on user behavior data for a target web page and the number of web page requests, and to determine whether the web page request is a real user request or a machine simulated request based on the human-machine evaluation score. It should be understood that user behavior data can indicate whether the user has an operation behavior, and the number of web page requests can indicate whether the target web page is frequently visited. Therefore, the human-machine evaluation score can be determined based on user behavior data and the number of web page requests.

[0074] In some embodiments, after receiving a web page request for a target web page, device information of the target device that initiated the web page request can also be obtained, and based on the device information of the target device, a human-machine evaluation storage field uniquely corresponding to the target device is generated; the human-machine evaluation storage field is used to store the human-machine evaluation score.

[0075] As can be seen from the foregoing, the target device may include a terminal device, and therefore the device information may include the hardware information of the device. Of course, since the device information between different target devices may be the same, an identification number for uniquely identifying the target device may also be set for each target device, thereby generating a human-machine evaluation storage field uniquely corresponding to the target device. From using this human-machine evaluation storage field to store the human-machine evaluation score generated in the following text, it can be understood that since the web page request processing method provided in this embodiment is real-time, the human-machine evaluation score may also change in real time. Storing the human-machine evaluation score through this field facilitates the management of the human-machine evaluation score.

[0076] The details of step S102 will be introduced later.

[0077] S103: When the web page request is a genuine request of the user, determine whether to access the target web page based on a first interface signature key for the web page request generated by calling a front-end service and a second interface signature key for the web page request generated by calling a back-end service.

[0078] It can be understood that if the web page request is a real request from the user, the subsequent access process can continue. Specifically, whether to access the target web page can be determined based on the first interface signature key for the web page request generated by calling the front-end service and the second interface signature key for the web page request generated by calling the back-end service.

[0079] Optionally, for step S103, when the web page request is a real request of the user, when determining whether to access the target web page based on the first interface signature key generated by invoking the front-end service for the web page request and the second interface signature key generated by invoking the back-end service for the web page request, the following steps (1) to (3) may be included: (1) When the web page request is a real request of the user, invoke the front-end service to generate a first interface signature key for the web page request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encryption code block.

[0080] It can be understood that if the web page request is a real request of the user, the subsequent access process can continue, that is, invoke the front-end service to generate a first interface signature key for the web page request based on the first preset encryption rule.

[0081] In addition, the encryption code blocks of the human-machine weight algorithm and the first preset encryption rule can be obtained through the following steps: use a code obfuscation tool to perform compression and obfuscation processing on the initial code containing the human-machine weight algorithm and the first preset encryption rule to obtain a first processing result, and then perform encoding and encryption processing on the first processing result to obtain an encrypted code module, so as to increase the unreadability of the code, thereby enhancing the security of the code.

[0082] Among them, the code obfuscation tool may include JShaman. JShaman is a tool for obfuscating and encrypting JavaScript code, aiming to prevent the JavaScript code from being read, modified, and decompiled.

[0083] In engineering implementation, JShaman can be used to encrypt the initial code to obtain an independent code block. Specifically, JShaman converts the initial code into an abstract syntax tree AST and then performs encryption processing to obtain the code block. In this way, the code block is not readable and cannot be restored, so as to avoid the code from being read or tampered with, which is beneficial to enhancing the security of the code.

[0084] In other embodiments, if the web page request is a machine simulation request, the front-end service is invoked to perform a first interception process on the web page request, so as to avoid malicious access.

[0085] Optionally, for step S103, when invoking the front-end service to generate a first interface signature key for the web page request based on the first preset encryption rule, the following steps (a) to (c) are included: (a) Obtain the initial key and the timestamp for the current signature.

[0086] Among them, the initial key can be set according to actual requirements and is not limited herein.

[0087] Since the timestamp is unique, it is beneficial to improve the security of the first interface signature key.

[0088] (b)Determine the sum of the American Standard Code for Information Interchange (ASCII) code values of the initial key.

[0089] In this embodiment, the initial password is in the form of a string. Therefore, each character in the string can be converted into an ASCII code value, and the sum of the ASCII code values of each character can be determined to obtain the sum of the ASCII code values of the initial key.

[0090] (c)Generate a random number, and generate the first interface signature key based on the human-machine evaluation score, the sum of the ASCII code values, the timestamp, and the random number.

[0091] Here, the random number can be a random string.

[0092] In this way, based on the human-machine evaluation score, the sum of the ASCII code values, the timestamp, and the random number, the first interface signature key can be generated. In this embodiment, the first interface signature key is dynamically generated in the above manner, which is beneficial to improving the complexity and unpredictability of the first interface signature key, thereby reducing the risk of the key being copied and leaked.

[0093] In some embodiments, after generating the first interface signature key, the front-end service will splice the request parameters (request body, timestamp, random number, human-machine evaluation score, user identifier, etc.) of the web request in a random order, and then send the web request carrying the first interface signature key to the back-end service.

[0094] (2)Send the web request carrying the first interface signature key to the back-end service, and call the back-end service to generate a second interface signature key for the web request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule.

[0095] After generating the first interface signature key, send the web request carrying the first interface signature key to the back-end service, and call the back-end service to determine the second interface signature key for the web request.

[0096] Here, the back-end service will use the same encryption rule (that is, the second preset encryption rule is the same as the first preset encryption rule) to encrypt the request parameters and the key carried in the web request to obtain the second interface signature key.

[0097] The first interface signature key (sign) will be included in the request body of the web page request. At the same time, a timestamp parameter (timestamp) and a nonce parameter (nonce) will also be appended to the request body.

[0098] Here, the encryption rule can include a symmetric encryption algorithm. For example, it can be the MD5 Message-Digest Algorithm.

[0099] (3) Determine whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

[0100] Finally, by comparing the first interface signature key with the second interface signature key, and based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key, determine whether to access the target web page.

[0101] Among them, the usage status of the first interface signature key can include an unused status and a used status. It should be noted that for each web page request, the usage status of its corresponding first interface signature key can be used to characterize whether the web page request can access the target web page. If the target web page is not accessed, its usage status is the unused status. If the target web page is accessed, its usage status will change to the used status. In this way, the same key can be prevented from being reused.

[0102] Therefore, in this embodiment, the backend service will compare the first interface signature key with the second interface signature key, and determine whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

[0103] Specifically, when the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is the unused status, determine to access the target web page.

[0104] It can be understood that if the first interface signature key is the same as the second interface signature key, it is considered that the web page request is a normal request and not forged. At the same time, if the usage status of the first interface signature key is the unused status, it means that the web page request has not accessed the target web page. At this time, it can be determined to access the target web page based on this web page request.

[0105] Similarly, when the first interface signature key is different from the second interface signature key, and / or the usage status of the first interface signature key is the used status, the backend service intercepts and processes the web page request.

[0106] Here, if the first interface signature key is different from the second interface signature key, it indicates that the web page request is a forged request. If the usage status of the first interface signature key is the used status, it means that the web page request has accessed the target web page and cannot be reused. Then, the backend service can perform a second interception process on the web page request, thereby further enhancing the security of the web page access process.

[0107] In some embodiments, after generating the first interface signature key, the front-end service writes the first interface signature key into the database for storage. After generating the second interface signature key, the backend service checks whether it has received the first interface signature key. If not, it can also obtain the first interface signature key from the database and then perform subsequent key comparison.

[0108] In some embodiments, for step S102, when using the human-machine weight algorithm to determine the human-machine evaluation score based on the user behavior data and the number of requests of the web page request, the following steps (i) to (ii) may be included: (i) Determine a first score corresponding to the user behavior according to the user behavior data, and determine a second score corresponding to the number of requests according to the number of requests of the web page request within the preset time period.

[0109] As can be seen from the foregoing, the user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors. Therefore, a first score corresponding to the user behavior can be determined based on the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors.

[0110] Specifically, for step (i), when determining a first score corresponding to the user behavior according to the user behavior data, the following steps (A) to (C) may be included: (A) Construct a first vector according to the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors.

[0111] After determining the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors, a first vector is constructed based on the number of each of the above behaviors.

[0112] Exemplarily, please refer to formula (1), which is the expression of the constructed first vector: (1) Where X is the first vector, is the number of keyboard input behaviors, is the number of mouse control behaviors, is the number of touchpad control behaviors.

[0113] As can be seen from the foregoing, mouse control behaviors may include mouse click behaviors (such as single - click behavior, double - click behavior), mouse movement behavior, and mouse scroll bar rotation behavior. Therefore, the expression of the first vector can also be as shown in formula (2): (2) where X is the first vector, is the number of keyboard input behaviors, is the number of mouse single - click behaviors, is the number of mouse movement behaviors, is the number of mouse scroll bar rotation behaviors, is the number of mouse double - click behaviors, is the number of touchpad control behaviors.

[0114] (B)Construct a second vector based on the weights corresponding to the keyboard input behavior, the mouse control behavior, and the touchpad control behavior respectively.

[0115] Exemplarily, referring to formula (3), it is the expression of the second vector corresponding to formula (1): (3) where W is the second vector, is the weight corresponding to the keyboard input behavior, is the weight corresponding to the mouse control behavior, is the weight corresponding to the touchpad control behavior.

[0116] Similarly, an expression of the second vector corresponding to formula (2) can also be constructed, as shown in formula (4): (4) where W is the second vector, is the number of keyboard input behaviors, is the number of mouse single - click behaviors, is the number of mouse movement behaviors, is the number of mouse scroll bar rotation behaviors, is the number of mouse double - click behaviors, is the number of touchpad control behaviors.

[0117] (C)Determine the first score based on the first vector and the second vector.

[0118] Here, the first vector and the second vector can be subjected to a dot - product operation, so that the first score corresponding to the user behavior can be obtained, as shown in formula (5): (5) Among them, is the first score, X is the first vector, and W is the second vector.

[0119] In the embodiments of the present disclosure, the preset time period includes multiple time windows, and each time window corresponds to a score weight. The score weights corresponding to different time windows may be the same or different, which is not limited herein.

[0120] Exemplarily, the start time of the preset time period is the moment when the web page request is received (it can be defaulted to the 0th second), and the end time is the moment 1 minute later. Then the multiple time windows may include 0 - 1 second, 0 - 10 seconds, and 0 - 60 seconds.

[0121] Specifically, for step (i), when determining the second score corresponding to the number of requests of the web page request within the preset time, the following steps may be included: (I) - (II): (I) For each time window, determine the score corresponding to the time window according to the number of requests of the web page request within the time window and the score weight corresponding to the time window.

[0122] Please refer to formula (6), which shows the expression for determining the score corresponding to each time window: (6) Among them, is the score corresponding to the time window, is the score weight corresponding to the time window, is the number of requests of the web page request within the time window, j is the time window.

[0123] Exemplarily, if the multiple time windows are respectively 0 - 1 second, 0 - 10 seconds, and 0 - 60 seconds, then the score expressions respectively corresponding to each time window are as shown in formulas (7) - (9): (7) (8) (9) (II) Obtain the preset abnormal deduction score, and determine the second score based on the abnormal deduction score and the sum of the scores respectively corresponding to each time window.

[0124] Among them, the abnormal deduction score can be set according to actual needs, which is not limited herein. In this embodiment, the abnormal deduction score is 10.

[0125] Please refer to formula (10) for the expression of the second score: (10) Among them, is the second score, is the score corresponding to the time window, is the abnormal deduction score.

[0126] In addition, the abnormal deduction score in formula (10) may refer to an abnormality in the web request. For example, the request frequency is greater than the preset frequency threshold, periodic requests, or there are errors in the request parameters of the web request. Among them, the preset frequency threshold is usually set relatively large, such as 1000; periodic requests may mean that the time intervals between requests are the same; errors in the request parameters may refer to the situation where parameters are missing in the request parameters or the situation where unnecessary parameters increase in the request parameters.

[0127] (ii) Obtain the basic score, and determine the human-machine evaluation score based on the basic score, the first score, and the second score.

[0128] Here, the basic score can be set according to actual needs and is not limited here. In this embodiment, the basic score is 60.

[0129] In this way, after determining the first score and the second score, the human-machine evaluation score can be determined based on the basic score, the first score, and the second score, as shown in formula (11): (11) Among them, is the human-machine evaluation score, is the basic score.

[0130] After determining the human-machine evaluation score, it is possible to determine whether the web request is a real user request or a forged machine simulation request based on the human-machine evaluation score.

[0131] Specifically, if the human-machine evaluation score is less than the preset threshold, it is determined that the web request is a machine simulation request; if the human-machine evaluation score is not less than the preset threshold, it is determined that the web request is a real user request.

[0132] Among them, the preset threshold can be set according to actual needs. For example, the preset threshold is 60.

[0133] Optionally, after determining the human-machine evaluation score, the human-machine evaluation score can be stored in the human-machine evaluation storage field described in the foregoing embodiment, and when using this human-machine evaluation score, it can be extracted from this field.

[0134] Please refer to Figure 2 , which is a schematic diagram of the interaction between the front-end service and the back-end service provided by the embodiment of the present disclosure.

[0135] As Figure 2 shown, when the web page request is a real request of the user, the front-end service is called to generate a first interface signature key, and the web page request carrying the first interface signature key is sent to the back-end service. After receiving the web page request, the back-end service generates a second interface signature key and checks whether the first interface signature key exists. If it does not exist, the first interface signature key is obtained from the database. Then, the back-end service compares the first interface signature key with the second interface signature key and obtains the usage status of the first interface signature key. If the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is the unused status, the target web page is accessed, and the web page data of the target web page is returned to the front-end service; otherwise, an interception process is performed.

[0136] Please refer to Figure 3 , which is a flowchart of another web page request processing method provided by an embodiment of the present disclosure.

[0137] As Figure 3 shown, the method includes steps S301 to S308: S301: Receive a web page request for a target web page, and detect user behavior data within a preset time period after receiving the web page request and the number of requests of the web page request; the web page request does not include user identity information.

[0138] S302: Use a human-machine weight algorithm to determine a human-machine evaluation score based on the user behavior data and the number of requests of the web page request, and determine whether the web page request is a real request of the user based on the human-machine evaluation score. If so, execute step S303; if not, execute step S308.

[0139] S303: Call the front-end service to generate a first interface signature key for the web page request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encryption code block; S304: Send the web page request carrying the first interface signature key to the back-end service, and call the back-end service to generate a second interface signature key for the web page request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule.

[0140] S305: Determine whether the first interface signature key is the same as the second interface signature key and whether the usage status of the first interface signature key is the unused status. If so, execute step S306; if not, execute step S307.

[0141] S306: Determine to access the target web page.

[0142] S307: Perform a second interception process on the web page request based on the backend service.

[0143] S308: Invoke the front-end service to perform a first interception process on the web page request.

[0144] The following combines Figure 3 with the flowchart shown to introduce the complete process of the web page request processing method.

[0145] In the embodiments of the present disclosure, after receiving a web page request for a target web page, user behavior data within a preset time period after receiving the web page request and the number of requests of the web page request are detected. Using a human-machine weight algorithm, based on the user behavior data and the number of requests of the web page request, a human-machine evaluation score is determined, and based on the human-machine evaluation score, it is determined whether the web page request is a real request from a user. If it is not a real request from a user, the front-end service is invoked to perform a first interception process on the web page request.

[0146] If it is a real request from a user, the front-end service is invoked to generate a first key based on a first preset encryption rule, and then a web page request carrying the first interface signature key is sent to the backend. The backend service is invoked to generate a second interface signature key for the web page request based on a second preset encryption rule, where the second preset encryption rule is the same as the first preset encryption rule, so that the backend service can generate the same key, and thus the first interface signature key and the second interface signature key can be compared. If the first interface signature key and the second interface signature key are the same and the usage status of the first interface signature key is the unused status, it indicates that the web page request is normal, and then the target web page is accessed. If the first interface signature key and the second interface signature key are different, and / or the usage status of the first interface signature key is the used status, it indicates that the web page request is abnormal, and then a second interception process is performed on the web page request based on the backend service.

[0147] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.

[0148] Based on the same inventive concept, in the embodiments of the present disclosure, there is also provided a web page request processing device corresponding to the above web page request processing method. Since the principle of solving problems by the device in the embodiments of the present disclosure is similar to that of the above web page request processing method in the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be elaborated.

[0149] Please refer to Figure 4 , Figure 4Schematic diagram of a web request processing device provided by an embodiment of the present disclosure. As Figure 4 shown, the web request processing device 400 provided by an embodiment of the present disclosure includes: A request receiving module 410, configured to receive a web request for a target web page, and detect user behavior data within a preset time period after receiving the web request and the number of requests of the web request; the web request does not include user identity information; A request judging module 420, configured to use a human-machine weight algorithm to determine a human-machine evaluation score based on the user behavior data and the number of requests of the web request, and judge whether the web request is a real user request or a machine simulation request based on the human-machine evaluation score; A web access module 430, configured to, when the web request is the real user request, determine whether to access the target web page based on a first interface signature key generated by invoking a front-end service for the web request and a second interface signature key generated by invoking a back-end service for the web request.

[0150] Please refer to Figure 5 , Figure 5 Schematic diagram of another web request processing device provided by an embodiment of the present disclosure. The device 400 further includes a request interception module 440, and the request interception module 440 is configured to: When the web request is the machine simulation request, call the front-end service to perform a first interception process on the web request.

[0151] In an optional implementation manner, the request judging module 420 is specifically configured to: Determine a first score corresponding to the user behavior according to the user behavior data, and determine a second score corresponding to the number of requests of the web request within the preset time period; Obtain a basic score, and determine a human-machine evaluation score based on the basic score, the first score, and the second score.

[0152] In an optional implementation manner, the user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; the request judging module 420 is specifically configured to: Construct a first vector according to the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; Construct a second vector based on the weights corresponding to the keyboard input behavior, the mouse control behavior, and the touchpad control behavior respectively; Determine the first score based on the first vector and the second vector.

[0153] In an alternative embodiment, the preset time period includes a plurality of time windows, and each time window corresponds to a scoring weight; specifically, the request judgment module 420 is configured to: For each time window, determine a score corresponding to the time window according to the number of requests of the web page request within the time window and the scoring weight corresponding to the time window; Obtain a preset abnormal deduction score, and determine the second score based on the abnormal deduction score and the sum of the scores corresponding to each time window respectively.

[0154] In an alternative embodiment, the request judgment module 420 is specifically configured to: If the human-machine evaluation score is less than a preset threshold, determine that the web page request is the machine simulation request.

[0155] In an alternative embodiment, the web page access module 430 is specifically configured to: In the case that the web page request is the user's real request, call the front-end service to generate a first interface signature key for the web page request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encryption code block; Send the web page request carrying the first interface signature key to the back-end service, and call the back-end service to generate a second interface signature key for the web page request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule; Determine whether to access the target web page based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

[0156] In an alternative embodiment, the web page access module 430 is specifically configured to: Obtain an initial key and a time stamp for the current signature; Determine the sum of the American Standard Code for Information Interchange (ASCII) code values of the initial key; Generate a random number, and generate the first interface signature key based on the human-machine evaluation score, the sum of the ASCII code values, the time stamp, and the random number.

[0157] In an alternative embodiment, the web page access module 430 is specifically configured to: In the case that the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is the unused status, determine to access the target web page; When the first interface signature key is different from the second interface signature key, and / or the usage status of the first interface signature key is the used status, a second interception process is performed on the web page request based on the backend service.

[0158] In an alternative embodiment, the device further includes a field generation module 450, and the field generation module 450 is configured to: Obtain device information of a target device that initiates the web page request; Generate a human-machine evaluation storage field that is uniquely corresponding to the target device based on the device information of the target device; the human-machine evaluation storage field is used to store the human-machine evaluation score.

[0159] In an alternative embodiment, the device further includes a code encryption module 460, and the code encryption module 460 is configured to: Use a code obfuscation tool to perform compression and obfuscation processing on an initial code block including the human-machine weight algorithm and the first preset encryption rule to obtain a first processing result; Perform encoding and encryption processing on the first processing result to obtain the encrypted code block.

[0160] In an alternative embodiment, the device further includes a refresh module 470, and the refresh module 470 is configured to: Detect whether the browser is in a debugging mode, and in the case of determining that the browser is in the debugging mode, perform a refresh process on the current page displayed by the browser.

[0161] For the processing procedures of the various modules in the above device and the interaction procedures between the various modules, reference may be made to the relevant descriptions in the above method embodiments, which will not be elaborated here.

[0162] Corresponding to the above web page request processing method, an embodiment of the present disclosure further provides an electronic device 600, as Figure 6 shown, which is a schematic structural diagram of the electronic device 600 provided by an embodiment of the present disclosure, including: A processor 610, a memory 620, and a bus 630. Among them, the memory 620 is used to store execution instructions, including an internal memory 621 and an external memory 622; here, the internal memory 621 is also called the main memory, which is used to temporarily store the operation data in the processor 610 and the data exchanged with the external memory 622 such as a hard disk, and the processor 610 exchanges data with the external memory 622 through the internal memory 621.

[0163] In the embodiments of the present application, the memory 620 is specifically configured to store the application program code for executing the solution of the present application, and the processor 610 is used to control the execution. That is, when the electronic device 600 runs, the processor 610 communicates with the memory 620 through the bus 630, so that the processor 610 executes the application program code stored in the memory 620, and further executes the web page request processing method described in the above method embodiments.

[0164] Among them, the memory 620 can be, but is not limited to, a random access memory (Random Access Memory, RAM), a read-only memory (Read Only Memory, ROM), a programmable read-only memory (Programmable Read-Only Memory, PROM), an erasable programmable read-only memory (Erasable Programmable Read-Only Memory, EPROM), an electrically erasable programmable read-only memory (Electric Erasable Programmable Read-Only Memory, EEPROM), etc.

[0165] The processor 610 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (Central Processing Unit, CPU), a network processor (Network Processor, NP), etc.; it may also be a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0166] It can be understood that the structure schematically shown in the embodiments of the present application does not constitute a specific limitation on the electronic device 600. In other embodiments of the present application, the electronic device 600 may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure can be implemented in hardware, software, or a combination of software and hardware.

[0167] Embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes any one of the web request processing methods described in the foregoing method embodiments. Wherein, the storage medium may be a volatile or non-volatile computer-readable storage medium.

[0168] The methods in the embodiments of the present disclosure can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in this application are executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM, or other programmable devices.

[0169] The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0170] Finally, it should be noted that the above embodiments are only specific implementation manners of the present disclosure, used to illustrate the technical solutions of the present disclosure, rather than limiting them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present disclosure can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A web page request processing method, characterized in that: include: Receiving a web page request for a target web page, and detecting user behavior data and the number of requests for the web page request within a preset time period after receiving the web page request; The web page request does not include user identity information; Using a human-machine weight algorithm, based on the user behavior data and the number of requests for the web page request, a human-machine evaluation score is determined, and based on the human-machine evaluation score, it is determined whether the web page request is a real user request or a machine simulated request; In the case that the web page request is a real request of the user, whether to access the target web page is determined based on a first interface signature key for the web page request generated by calling a front-end service and a second interface signature key for the web page request generated by calling a back-end service.

2. The method according to claim 1, characterized in that The method further comprises: In the case that the web page request is the machine simulation request, the front-end service is called to perform a first interception process on the web page request.

3. The method according to claim 1, characterized in that The method of using a human-machine weight algorithm to determine a human-machine evaluation score based on the user behavior data and the number of requests for the web page request includes: Determining a first score corresponding to the user behavior according to the user behavior data, and determining a second score corresponding to the number of requests according to the number of requests for the web page within the preset time period; A basic score is obtained, and the human-machine evaluation score is determined based on the basic score, the first score, and the second score.

4. The method according to claim 3, characterized in that The user behavior data includes the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; The determining, according to the user behavior data, a first score corresponding to the user behavior includes: constructing a first vector according to the number of keyboard input behaviors, the number of mouse control behaviors, and the number of touchpad control behaviors; constructing a second vector based on weights corresponding to the keyboard input behavior, the mouse control behavior, and the touchpad control behavior respectively; Based on the first vector and the second vector, the first score is determined.

5. The method according to claim 3, characterized in that: The preset time period includes a plurality of time windows, each time window corresponds to a score weight; and determining a second score corresponding to the number of requests for the web page within the preset time period according to the number of requests, includes: For each time window, determining a score corresponding to the time window according to the number of requests for the web page within the time window and the score weight corresponding to the time window; A preset abnormal deduction score is obtained, and the second score is determined based on the abnormal deduction score and the sum of the scores corresponding to each time window.

6. The method according to claim 3, characterized in that: The determining, based on the human-machine evaluation score, whether the webpage request is a real user request or a machine-simulated request includes: If the human-machine evaluation score is less than a preset threshold, it is determined that the web page request is the machine simulation request.

7. The method according to claim 1, characterized in that In the case where the webpage request is a real request of the user, determining whether to access the target webpage based on a first interface signature key for the webpage request generated by calling a front-end service and a second interface signature key for the webpage request generated by calling a back-end service includes: In the case where the webpage request is a real request of the user, calling the front-end service to generate a first interface signature key for the webpage request based on a first preset encryption rule; the human-machine weight algorithm and the first preset encryption rule are stored in the form of an encrypted code block; Sending the webpage request carrying the first interface signature key to a backend service, and calling the backend service to generate a second interface signature key for the webpage request based on a second preset encryption rule; the second preset encryption rule is the same as the first preset encryption rule; Whether to access the target webpage is determined based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key.

8. The method according to claim 7, characterized in that The calling front-end service generates a first interface signature key for the webpage request based on a first preset encryption rule, including: Get the initial key and timestamp for the current signature; Determine the sum of the ASCII code values ​​of the initial key; Generate a random number, and generate the first interface signature key based on the human-machine evaluation score, the sum of the ASCII code values, the timestamp and the random number.

9. The method according to claim 7, characterized in that: The determining whether to access the target webpage based on whether the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key includes: In a case where the first interface signature key is the same as the second interface signature key and the usage status of the first interface signature key is unused, determining to access the target webpage; When the first interface signature key is different from the second interface signature key, and / or the usage status of the first interface signature key is already used, a second interception process is performed on the web page request based on the backend service.

10. The method according to any one of claims 1 to 9, characterized in that: After receiving a webpage request for a target webpage, the method further includes: Obtain device information of a target device that initiates the webpage request; Based on the device information of the target device, a human-machine evaluation storage field uniquely corresponding to the target device is generated; the human-machine evaluation storage field is used to store the human-machine evaluation score.

11. The method according to claim 7, characterized in that The encrypted code block including the human-machine weight algorithm and the first preset encryption rule is obtained according to the following steps: Using a code obfuscation tool to perform compression and obfuscation processing on an initial code block including the human-machine weight algorithm and the first preset encryption rule to obtain a first processing result; The first processing result is encoded and encrypted to obtain the encrypted code block.

12. The method according to claim 1, characterized in that The webpage request is generated based on a user input operation on a browser, and the method further includes: Detecting whether the browser is in the debugging mode, and if it is determined that the browser is in the debugging mode, refreshing the current page displayed by the browser.

13. A web page request processing device, characterized in that: include: A request receiving module, used to receive a web page request for a target web page, and detect user behavior data and the number of requests for the web page request within a preset time period after receiving the web page request; The web page request does not include user identity information; A request judgment module, configured to determine a human-machine evaluation score based on the user behavior data and the number of requests for the web page request by using a human-machine weight algorithm, and to judge whether the web page request is a real user request or a machine-simulated request based on the human-machine evaluation score; The web page access module is used to determine whether to access the target web page based on the first interface signature key for the web page request generated by calling the front-end service and the second interface signature key for the web page request generated by calling the back-end service when the web page request is a real request of the user.

14. An electronic device, characterized in that: It includes a processor, a memory and a bus, the memory stores machine-readable instructions executable by the processor, when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, a web page request processing method as described in any one of claims 1 to 12 is performed.

15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the web page request processing method according to any one of claims 1 to 12 is executed.

Citation Information

Patent Citations

  • Machine behavior determining method, webpage browser and webpage server

    CN102737019A

  • High-frequency access early warning method and device based on Redis

    CN115150137A

  • Dynamic key generation method and device and access method, device and system thereof

    CN117692137A

  • User verification method, device and equipment based on content distribution network

    CN119814363A

  • System and method for providing key operation of safety server

    CN1470972A