Multi-dimensional hybrid anti-crawler method, system, medium and equipment

Through a multi-dimensional hybrid anti-crawler method, combined with multiple algorithms and real-time update models, the problem of low anti-crawler detection in the existing technology is solved, accurate identification and effective defense of crawler behavior is achieved, and sensitive information in the web page is protected.

CN120234465APending Publication Date: 2025-07-01INSPUR FINANCIAL INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510378407.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing web anti-crawler technology has low detection of crawler behavior, resulting in sensitive information leaking user privacy.

Method used

The multi-dimensional hybrid anti-crawler method is adopted to collect user access logs, extract multi-dimensional features, and use a hybrid detection model (including isolated forest algorithm, local outlier factor algorithm and a type of support vector machine algorithm) to calculate the abnormal score, and trigger countermeasures when crawler behavior is detected, while the model is updated in real time and the threshold is adjusted to adapt to the new crawler behavior pattern.

Benefits of technology

It significantly improves the accuracy of crawler detection, reduces false positives and missed reports, effectively prevents crawlers from crawling data, enhances the adaptability and stability of the model, and protects the security of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234465A_ABST
    Figure CN120234465A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional mixed anti-crawler method and system, a medium and equipment, and the method comprises the following steps: S1, collecting user access logs, and extracting multi-dimensional features, including request times, unique path number, request time distribution, user agent type, geographic position and equipment information; s2, the extracted features are subjected to standardization processing and input into a hybrid detection model, and the hybrid detection model comprises an isolated forest algorithm, a local outlier factor algorithm and a first-class support vector machine algorithm; s3, calculating an abnormal score of each access behavior according to an output result of the mixed detection model; s4, when the abnormal score exceeds a preset threshold value, judging that the behavior is a crawler behavior, and triggering a countering measure; and S5, updating the hybrid detection model in real time, and dynamically adjusting an abnormal score threshold to adapt to a new crawler behavior mode. The method has the advantages that the multi-dimensional features and the hybrid model are integrated, and the accuracy of crawler detection is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and particularly to a multi-dimensional hybrid anti-crawler method, system, medium and device. Background Art

[0002] Crawler technology can automatically capture web page data. In some web pages containing sensitive information, once the data is captured by crawlers, the privacy of users will be leaked. The existing web page anti-crawler technology has a low detection rate for crawler behavior.

[0003] In view of this, it is necessary to provide a multi-dimensional hybrid anti-crawler method, system, medium and device. Summary of the Invention

[0004] A multi-dimensional hybrid anti-crawler method, system, medium and device provided by the present invention effectively solves the problem of the low existing web page anti-crawler technology.

[0005] The technical solution adopted by the present invention is as follows:

[0006] A multi-dimensional hybrid anti-crawler method includes the following steps:

[0007] S1. Collect user access logs and extract multi-dimensional features, including the number of requests, the number of unique paths, the request time distribution, the user agent type, the geographical location, and the device information;

[0008] S2. Standardize the extracted features and input them into a hybrid detection model, where the hybrid detection model includes the Isolation Forest algorithm, the Local Outlier Factor algorithm, and the One-Class Support Vector Machine algorithm;

[0009] S3. Calculate the anomaly score for each access behavior according to the output result of the hybrid detection model;

[0010] S4. When the anomaly score exceeds a preset threshold, it is determined as a crawler behavior, and countermeasures are triggered, including returning false data, restricting the access frequency, or blocking the IP;

[0011] S5. Update the hybrid detection model in real time and dynamically adjust the anomaly score threshold to adapt to new crawler behavior patterns.

[0012] Furthermore: The multi-dimensional features further include the variance of the request interval and the access order of the request paths.

[0013] Furthermore: The hybrid detection model combines the output results of the Isolation Forest algorithm, the Local Outlier Factor algorithm, and the One-Class Support Vector Machine algorithm through a weighted voting method.

[0014] Furthermore: The countermeasures further include setting up a honeypot page to trap crawlers and record their behaviors.

[0015] Furthermore, the method further includes encrypting and storing sensitive information during transmission, and adding differential privacy noise during data publication.

[0016] Furthermore, the hybrid detection model further includes a deep learning model, and the deep learning model is trained and optimized through the following steps: constructing a training set using historical access log data, and labeling normal users and crawler behaviors; inputting multi-dimensional features into a long short-term memory network (LSTM) to train the model to capture abnormal patterns in the time series; performing weighted fusion on the output of the LSTM model and the results of the isolation forest algorithm and the local outlier factor algorithm to generate a final abnormal score; and updating the parameters of the deep learning model in real time through an online learning mechanism to adapt to new crawler behavior patterns.

[0017] Furthermore, the multi-dimensional features further include user behavior pattern features, and the behavior pattern features are extracted through the following steps: analyzing the time series data of user accesses, and calculating the time interval distribution of requests; extracting the sequential pattern of the user access path to identify whether there is a fixed path access behavior; combining the user's geographical location and device information to determine whether there is abnormal access behavior; and combining the behavior pattern features with the request count and unique path count features and inputting them into the hybrid detection model for anomaly detection.

[0018] A multi-dimensional hybrid anti-crawler system

[0019] A log collection module for collecting user access logs;

[0020] A feature extraction module for extracting multi-dimensional features from access logs;

[0021] A hybrid detection module for calculating an abnormal score based on multi-dimensional features;

[0022] A countermeasure module for triggering countermeasures when crawler behavior is detected;

[0023] A model update module for updating the hybrid detection model in real time and dynamically adjusting the abnormal score threshold.

[0024] A computer-readable storage medium stores a computer program, and when the computer program is processed and executed, it implements the steps of the multi-dimensional hybrid anti-crawler method.

[0025] A computer device includes a processor, a communication interface, a memory, and a communication bus, and the processor, the communication interface, and the memory complete communication with each other through the communication bus: wherein:

[0026] The memory is used for storing a computer program;

[0027] The processor is configured to execute the steps of the multi-dimensional hybrid anti-crawler method by running the program stored in the memory.

[0028] Advantages of the invention:

[0029] 1. By integrating multi-dimensional features and hybrid models, it can describe user behavior more comprehensively, significantly improving the accuracy of crawler detection. Combining multiple algorithms such as Isolation Forest, Local Outlier Factor, and One-Class Support Vector Machine can avoid the limitations of a single algorithm, enhancing the adaptability and stability of the model; by updating the model in real-time and dynamically adjusting the anomaly score threshold, it can quickly adapt to new crawler behavior patterns, reducing false positives and false negatives. After detecting crawler behavior, anti-countermeasures are automatically triggered (such as returning false data, restricting access frequency, etc.) to effectively prevent the crawler from further scraping data.

[0030] 2. By setting up a honeypot page, the honeypot page can be used to set up a page with false sensitive information, and the crawler can be trapped by capturing the sensitive information, providing support for subsequent analysis and model optimization.

[0031] 3. Through deep learning, it can automatically adapt to the gradually improved crawler behavior patterns, improving the detection ability.

[0032] 4. Weightedly fuse the output of the deep learning model with the results of other algorithms to further improve the detection accuracy. Description of the drawings

[0033] Figure 1 It is a flowchart of the multi-dimensional hybrid anti-crawler method provided by the embodiments of the present application. Detailed implementation manners

[0034] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific implementation manners of the present invention will be given in conjunction with the accompanying drawings.

[0035] The first embodiment provided by the present application is a multi-dimensional hybrid anti-crawler method, including the following steps:

[0036] S1. Collect user access logs and extract multi-dimensional features, including the number of requests, the number of unique paths, the request time distribution, user agent type, geographical location, and device information;

[0037] S2. Standardize the extracted features and input them into a hybrid detection model, where the hybrid detection model includes an Isolation Forest algorithm, a Local Outlier Factor algorithm, and a One-Class Support Vector Machine algorithm;

[0038] S3. Calculate the anomaly score for each access behavior according to the output result of the hybrid detection model;

[0039] S4. When the anomaly score exceeds the preset threshold, it is determined as crawler behavior, and countermeasures are triggered, including returning false data, restricting the access frequency, or blocking the IP.

[0040] S5. Update the hybrid detection model in real time and dynamically adjust the anomaly score threshold to adapt to new crawler behavior patterns.

[0041] In the above design, by integrating multi-dimensional features and a hybrid model, the user behavior can be described more comprehensively, and the accuracy of crawler detection can be significantly improved. Combining multiple algorithms such as Isolation Forest, Local Outlier Factor, and One-Class Support Vector Machine can avoid the limitations of a single algorithm and enhance the adaptability and stability of the model. By updating the model in real time and dynamically adjusting the anomaly score threshold, it can quickly adapt to new crawler behavior patterns and reduce false positives and false negatives. After detecting crawler behavior, countermeasures (such as returning false data, restricting the access frequency, etc.) are automatically triggered to effectively prevent crawlers from further scraping data.

[0042] Specifically, the multi-dimensional features further include the variance of the request interval and the access order of the request path.

[0043] In the above design, by analyzing the time series data of user access and the path order pattern, more covert crawler behavior can be identified, and complex behavior patterns can be captured. Combining geographical location and device information can further distinguish normal users from crawlers, reduce misjudgment, and enhance the feature discrimination ability. Dynamic feature extraction enables the model to adapt to different types of crawler behavior and enhance the generalization performance.

[0044] Specifically, the hybrid detection model combines the output results of the Isolation Forest algorithm, the Local Outlier Factor algorithm, and the One-Class Support Vector Machine algorithm through a weighted voting method.

[0045] In the above design, the output of the deep learning model is weighted and fused with the results of other algorithms to further improve the detection accuracy.

[0046] Specifically, the countermeasures further include setting up a honeypot page to trap crawlers and record their behavior.

[0047] In the above design, the honeypot page can set a false sensitive information page, and use the crawler's scraping of sensitive information to trap the crawler, providing support for subsequent analysis and model optimization.

[0048] Specifically, the method further includes encrypting the storage and transmission of sensitive information and adding differential privacy noise when the data is published.

[0049] In the above design, by adding noise when the data is published, it is prevented that crawlers can scrape real sensitive information, further improving the security of the data.

[0050] Specifically, the hybrid detection model further includes a deep learning model, which is trained and optimized through the following steps: constructing a training set using historical access log data and annotating normal users and crawler behaviors; inputting multi-dimensional features into a long short-term memory network (LSTM) to train the model to capture abnormal patterns in the time series; performing weighted fusion on the output of the LSTM model and the results of the isolation forest algorithm and the local outlier factor algorithm to generate a final abnormal score; and updating the parameters of the deep learning model in real time through an online learning mechanism to adapt to new crawler behavior patterns.

[0051] In the above design, through deep learning, it is possible to automatically adapt to the gradually improved crawler behavior patterns and improve the detection ability.

[0052] Specifically, the multi-dimensional features further include user behavior pattern features, which are extracted through the following steps: analyzing the time series data of user accesses and calculating the time interval distribution of requests; extracting the sequential pattern of the user access path to identify whether there is a fixed path access behavior; combining the user's geographical location and device information to determine whether there is an abnormal access behavior; and combining the behavior pattern features with the request count and unique path count features and inputting them into the hybrid detection model for anomaly detection.

[0053] In the above design, by extracting user behavior pattern features, the dynamics of the crawler can be further controlled, and the web page anomaly detection ability can be improved.

[0054] The second embodiment provided by the present application is a multi-dimensional hybrid anti-crawler system, including

[0055] a log collection module for collecting user access logs;

[0056] a feature extraction module for extracting multi-dimensional features from the access logs;

[0057] a hybrid detection module for calculating an abnormal score based on the multi-dimensional features;

[0058] a countermeasure module for triggering countermeasures when crawler behavior is detected;

[0059] a model update module for updating the hybrid detection model in real time and dynamically adjusting the abnormal score threshold.

[0060] The third embodiment provided by this application is a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is processed and executed, it implements the steps of the multi-dimensional hybrid anti-crawler method. In addition, the computer-readable storage medium in this embodiment can adopt any combination of one or more readable storage media. Among them, the readable storage medium includes systems, devices or components of electricity, light, electromagnetism, infrared or semiconductors, or any combination of the above.

[0061] The fourth embodiment provided by this application is a computer device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus. Among them:

[0062] The memory is used to store a computer program;

[0063] The processor is used to execute the steps of the multi-dimensional hybrid anti-crawler method by running the program stored on the memory. As an implementation manner of the present invention, the communication bus mentioned in the above terminal may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0064] As an implementation manner of the present invention, the communication interface is used for communication between the above terminal and other devices.

[0065] As an implementation manner of the present invention, the memory may include a Random Access Memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0066] As an implementation manner of the present invention, the above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0067] The fifth embodiment provided by this application is a multi-dimensional hybrid anti-crawler method, which includes the following steps: S1. Collect user access logs and extract multi-dimensional features, including the number of requests, the number of unique paths, the request time distribution, the user agent type, the geographical location, and device information; S2. Standardize the extracted features and input them into the hybrid detection model, which includes the isolation forest algorithm, the local outlier factor algorithm, and the one-class support vector machine algorithm; S3. Calculate the anomaly score of each access behavior according to the output result of the hybrid detection model; S4. When the anomaly score exceeds the preset threshold, it is determined as a crawler behavior and countermeasures are triggered, including returning false data, restricting the access frequency, or blocking the IP.

[0068] S5. Update the hybrid detection model in real time and dynamically adjust the anomaly score threshold to adapt to new crawler behavior patterns. The multi-dimensional features further include the variance of the request interval and the access order of the request paths. The hybrid detection model combines the output results of the Isolation Forest algorithm, the Local Outlier Factor algorithm, and the One-Class Support Vector Machine algorithm through a weighted voting method. The countermeasures also include setting up a honeypot page to trap crawlers and record their behaviors. The method further includes encrypting the storage and transmission of sensitive information and adding differential privacy noise when the data is published. The hybrid detection model further includes a deep learning model, and the deep learning model is trained and optimized through the following steps: constructing a training set using historical access log data and annotating normal user and crawler behaviors; inputting the multi-dimensional features into a Long Short-Term Memory network (LSTM) to train the model to capture anomaly patterns in the time series; performing weighted fusion on the output of the LSTM model and the results of the Isolation Forest algorithm and the Local Outlier Factor algorithm to generate a final anomaly score; and updating the parameters of the deep learning model in real time through an online learning mechanism to adapt to new crawler behavior patterns. The multi-dimensional features further include user behavior pattern features, and the behavior pattern features are extracted through the following steps: analyzing the time series data of user accesses, calculating the distribution of request time intervals; extracting the sequential pattern of the user access path and identifying whether there is a fixed path access behavior; combining the user's geographical location and device information to determine whether there is an abnormal access behavior; and combining the behavior pattern features with the request count and unique path count features and inputting them into the hybrid detection model for anomaly detection.

[0069] In the above design, it is possible to effectively detect web crawler behaviors and effectively prevent sensitive information in web data from being grabbed by illegal crawler behaviors.

[0070] For further details, it should be understood that the above are only specific embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A multi-dimensional hybrid anti-crawler method, characterized in that: The following steps are involved: S1. Collect user access logs and extract multi-dimensional features, including the number of requests, the number of unique paths, the request time distribution, the user agent type, the geographic location, and the device information; S2, standardizing the extracted features and inputting them into a hybrid detection model, wherein the hybrid detection model includes an isolation forest algorithm, a local outlier factor algorithm, and a type of support vector machine algorithm; S3. Calculate the abnormal score of each access behavior based on the output results of the hybrid detection model; S4. When the anomaly score exceeds the preset threshold, it is determined to be crawler behavior and triggers countermeasures, including returning false data, limiting access frequency or banning IP; S5. Update the hybrid detection model in real time and dynamically adjust the anomaly score threshold to adapt to new crawler behavior patterns.

2. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The multi-dimensional features also include the variance of the request interval and the access sequence of the request path.

3. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The hybrid detection model combines the output results of the isolation forest algorithm, the local outlier factor algorithm and a type of support vector machine algorithm through weighted voting.

4. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The countermeasures also include setting up a honeypot page to trap crawlers and record their behavior.

5. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The method also includes encrypting the storage and transmission of sensitive information and adding differential privacy noise when publishing data.

6. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The hybrid detection model also includes a deep learning model, which is trained and optimized through the following steps: using historical access log data to build a training set and annotate normal user and crawler behaviors; inputting multidimensional features into a long short-term memory network (LSTM) to train the model to capture abnormal patterns in time series; weightedly fusing the output of the LSTM model with the results of the isolation forest algorithm and the local outlier factor algorithm to generate a final anomaly score; and updating the parameters of the deep learning model in real time through an online learning mechanism to adapt to new crawler behavior patterns.

7. The multi-dimensional hybrid anti-crawler method according to claim 1, characterized in that: The multidimensional features also include user behavior pattern features, which are extracted by: analyzing the time series data of user accesses and calculating the time interval distribution of requests; Extract the sequential pattern of the user's access path to identify whether there is fixed path access behavior; combine the user's geographic location and device information to determine whether there is abnormal access behavior; combine the behavior pattern characteristics with the number of requests and the number of unique paths, and input them into the hybrid detection model for anomaly detection.

8. A multi-dimensional hybrid anti-crawler system, characterized by: Log collection module, used to collect user access logs; Feature extraction module, used to extract multi-dimensional features from access logs; A hybrid detection module for calculating anomaly scores based on multi-dimensional features; The countermeasure module is used to trigger countermeasures when crawler behavior is detected; Model update module, which is used to update the hybrid detection model in real time and dynamically adjust the anomaly score threshold.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is processed and executed, the steps of the multi-dimensional hybrid anti-crawler method according to any one of claims 1 to 7 are implemented.

10. A computer device, characterized in that: The method comprises a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus: The memory is used to store computer programs; The processor is used to execute the steps of the multi-dimensional hybrid anti-crawler method according to any one of claims 1 to 7 by running the program stored in the memory.