Page anomaly detection method and device, storage medium and terminal
By obtaining user behavior sequence data in web applications and matching with exception rules, the problem of difficult page interaction exceptions is solved, and efficient and accurate abnormality detection is achieved to ensure user experience and system security.
Patent Information
- Application Number
- CN202510318038.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-07-04
AI Technical Summary
The prior art is difficult to effectively detect page interaction abnormalities in web applications, affecting user experience and application reputation.
By obtaining the user's behavior sequence data on the target page, extracting operation feature data, and matching it with the preset page exception rules, the abnormality detection result is determined.
It improves the efficiency and accuracy of page abnormality detection, can promptly detect and handle interactive abnormalities, and ensure user experience and system security.
Smart Images

Figure CN120256242A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and in particular, to a method, apparatus, storage medium, and terminal for detecting page anomalies. Background Art
[0002] Currently, Web applications are becoming increasingly complex. However, this increase in complexity also makes it more difficult to capture and accurately locate potential anomalies that may occur during page runtime. Traditional Web application monitoring methods mostly focus on the server side. However, traditional monitoring methods often fail to effectively perceive actual experience problems on the user side. These problems directly affect the user experience, leading to user churn and even having a serious negative impact on the reputation of the application. Summary of the Invention
[0003] The embodiments of this specification provide a method, apparatus, storage medium, and terminal for detecting page anomalies, which can solve the technical problem of difficult detection of page interaction anomalies in related technologies.
[0004] In a first aspect, the embodiments of this specification provide a method for detecting page anomalies, the method comprising:
[0005] Obtaining the behavior sequence data of the user based on the user operations triggered by the user in the target page;
[0006] Extracting the operation feature data corresponding to the user operations from the behavior sequence data;
[0007] Matching the operation feature data with page anomaly rules, and determining the anomaly detection result of the target page according to the matching result.
[0008] In a possible implementation, obtaining the behavior sequence data of the user based on the user operations triggered by the user in the target page includes: listening for the user operations triggered by the user in the target page, and obtaining the behavior data of the user based on the user operations; constructing the behavior data into the behavior sequence data corresponding to the user according to the triggering time sequence of each listened user operation.
[0009] In a possible implementation, constructing the behavior data into the behavior sequence data corresponding to the user according to the triggering time sequence of each listened user operation includes: at every preset time interval, constructing the behavior data within the preset time interval into behavior sequence data according to the triggering time sequence of each listened user operation, and generating a unique identifier for each behavior sequence data.
[0010] In a possible implementation, the above method further includes: in response to an access operation for the above target page, obtaining the DOM tree structure of the above target page, and binding an event listener to the interactive elements in the above target page based on the above DOM tree structure; the above monitoring of the user operations triggered by the user in the target page includes: monitoring the user operations triggered by the user in the target page through the above event listener.
[0011] In a possible implementation, the above obtaining the behavior data of the above user based on the above user operation includes: obtaining the initial operation data of the above user based on the above user operation, and performing desensitization processing on the above initial operation data to obtain the behavior data of the above user; the above desensitization processing methods include at least one of encrypted transmission and anonymization processing.
[0012] In a possible implementation, after the above obtaining the behavior data of the above user based on the above user operation, it further includes: preprocessing the behavior data of the above user to remove the invalid behavior data in all the behavior data; storing the behavior data after the above preprocessing in a database.
[0013] In a possible implementation, the above method further includes: defining at least one page exception rule for at least one exception type, where at least one characteristic threshold condition for judging an abnormal situation is set in each page exception rule.
[0014] In a possible implementation, the above matching the above operation characteristic data with the page exception rules and determining the abnormal detection result of the above target page according to the matching result includes: matching the above operation characteristic data with the characteristic threshold conditions in each page exception rule; if the above operation characteristic data hits the characteristic threshold condition in any page exception rule, it is determined that the above target page has an abnormality.
[0015] In a possible implementation, after the above determining that the above target page has an abnormality, it further includes: generating an abnormal report for the above target page, and sending out a prompt message corresponding to the above abnormal report.
[0016] In a possible implementation, after the above generating the abnormal report for the above target page, it further includes: dynamically adjusting the parameters of each page exception rule according to the above abnormal report.
[0017] In a second aspect, an embodiment of this specification provides a page abnormality detection device, and the device includes:
[0018] A data acquisition module, configured to obtain the behavior sequence data of the above user based on the user operations triggered by the user in the target page;
[0019] A feature extraction module, configured to extract operation feature data corresponding to the above user operations from the above behavior sequence data;
[0020] A rule matching module, configured to match the above operation feature data with page exception rules, and determine the exception detection result of the above target page according to the matching result.
[0021] In a possible implementation manner, the above data acquisition module is further configured to monitor user operations triggered by the user on the target page, and acquire the behavior data of the user based on the above user operations; and construct the above behavior data into behavior sequence data corresponding to the above user according to the triggering time sequence of each monitored user operation.
[0022] In a possible implementation manner, the above data acquisition module is further configured to, every preset duration, construct the behavior data within the above preset duration into behavior sequence data according to the triggering time sequence of each monitored user operation, and generate a unique identifier for each behavior sequence data.
[0023] In a possible implementation manner, the above page exception detection device further includes: an event listening module, configured to, in response to an access operation on the above target page, acquire the DOM tree structure of the above target page, and bind event listeners to interactive elements in the above target page based on the above DOM tree structure; the data acquisition module is further configured to monitor user operations triggered by the user on the target page through the above event listeners.
[0024] In a possible implementation manner, the above data acquisition module is further configured to acquire the initial operation data of the above user based on the above user operation, and perform desensitization processing on the above initial operation data to obtain the behavior data of the above user; the desensitization processing method includes at least one of encrypted transmission and anonymization processing.
[0025] In a possible implementation manner, the above page exception detection device further includes: a data processing module, configured to preprocess the behavior data of the above user to remove invalid behavior data in all behavior data; and store the behavior data after the above preprocessing in a database.
[0026] In a possible implementation manner, the above page exception detection device further includes: a rule configuration module, configured to define at least one page exception rule for at least one exception type, where at least one feature threshold condition for judging an exception situation is set in each page exception rule.
[0027] In a possible implementation, the above-mentioned rule matching module is further configured to match the above-mentioned operation feature data with the feature threshold conditions in each page exception rule; if the above-mentioned operation feature data hits the feature threshold conditions in any page exception rule, it is determined that the above-mentioned target page has an exception.
[0028] In a possible implementation, the above-mentioned page exception detection device further includes: an exception handling module, configured to generate an exception report for the above-mentioned target page and send out a prompt message corresponding to the above-mentioned exception report.
[0029] In a possible implementation, the above-mentioned page exception detection device further includes: a rule adjustment module, configured to dynamically adjust the parameters of each page exception rule according to the above-mentioned exception report.
[0030] In a third aspect, an embodiment of this specification provides a computer program product including instructions. When the above-mentioned computer program product runs on a computer or a processor, the above-mentioned computer or the above-mentioned processor is caused to execute the steps of the above-mentioned method.
[0031] In a fourth aspect, an embodiment of this specification provides a computer storage medium. The above-mentioned computer storage medium stores multiple instructions, and the above-mentioned instructions are suitable for being loaded and executed by a processor to execute the steps of the above-mentioned method.
[0032] In a fifth aspect, an embodiment of this specification provides a terminal, including a memory, a processor, and a computer program stored on the memory and executable on the processor. The above-mentioned computer program is suitable for being loaded and executed by the processor to execute the steps of the above-mentioned method.
[0033] The beneficial effects brought by the technical solutions provided by some embodiments of this specification at least include:
[0034] An embodiment of this specification provides a page exception detection method, which obtains the behavior sequence data of a user based on the user operations triggered by the user on a target page; extracts the operation feature data corresponding to the user operations from the behavior sequence data; matches the operation feature data with the page exception rules, and determines the exception detection result of the target page according to the matching result. In the embodiment of this specification, the behavior sequence data is obtained based on the interaction operations of the user on the page, and an accurate model of the user's movement line (that is, the movement trajectory and behavior order of the user on the page) is realized. This enables the system to more deeply discover the exceptions existing in the page from the user's interaction behaviors. Based on this, by matching the user's movement line with the page exception rules, the efficiency and accuracy of exception detection are greatly improved, so that the interaction exceptions occurring in the page can be discovered and processed in a timely manner, effectively ensuring the user experience and the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of this specification. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0036] Figure 1 Exemplary system architecture diagram of a page anomaly detection method provided by an embodiment of this specification;
[0037] Figure 2 Flow schematic diagram of a page anomaly detection method provided by an embodiment of this specification;
[0038] Figure 3 Flow schematic diagram of a page anomaly detection method provided by an embodiment of this specification;
[0039] Figure 4 Structural block diagram of a page anomaly detection device provided by an embodiment of this specification;
[0040] Figure 5 Structural schematic diagram of a terminal provided by an embodiment of this specification. Detailed implementation
[0041] To make the features and advantages of the embodiments of this specification more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of this specification in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only some embodiments of this specification, not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the embodiments of this specification.
[0042] When the following description involves drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of this specification. On the contrary, they are only examples of devices and methods consistent with some aspects of the embodiments of this specification as detailed in the appended claims. And in the description of the embodiments of this specification, unless otherwise stated, " / " means "or". For example, A / B can represent A or B: "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this specification, "a plurality of" means two or more than two.
[0043] Hereinafter, the terms "first" and "second" are for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features.
[0044] Currently, with the continuous evolution of Web applications, various front-end frameworks such as React, Vue, Angular, etc., as well as rich interactive technologies such as Ajax, WebSockets, etc., are widely used in the development process, greatly enhancing the functionality and user experience of Web applications. However, this increase in complexity also makes it more difficult to capture and precisely locate potential abnormal problems that may occur during page runtime.
[0045] Traditional Web application monitoring methods mostly focus on the server side. They mainly evaluate the running state of the application by collecting and analyzing server-side error logs and performance metrics (such as response time, request success rate, server load, etc.). These monitoring data undoubtedly have important value for understanding the health status and performance bottlenecks of the server. However, traditional monitoring methods often cannot effectively perceive actual experience problems on the user side. For example, when page elements are misaligned due to layout issues, the server-side logs and performance metrics may not show any abnormalities. Similarly, when interactive functions fail due to JavaScript errors or network latency, or when data fails to load due to backend service exceptions, these problems are often difficult to be reflected in traditional monitoring data.
[0046] These problems, such as page element misalignment, interactive failure, data loading anomalies, etc., although they may not directly cause server crashes or performance degradation, they will directly affect the user experience. When users encounter these problems, they may feel confused and dissatisfied, which will not only lead to an increase in the user churn rate but also have a negative impact on the word-of-mouth image of the application.
[0047] Therefore, the embodiments of this specification provide a page anomaly detection method to solve the above technical problem of difficult detection of page interaction anomalies.
[0048] Please refer to Figure 1 , Figure 1 which is an exemplary system architecture diagram of a page anomaly detection method provided by the embodiments of this specification.
[0049] As shown in Figure 1As shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 is used to provide a medium for a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired communication links or wireless communication links. For example, the wired communication links include optical fibers, twisted pairs, or coaxial cables, and the wireless communication links include Bluetooth communication links, Wireless-Fidelity (Wi-Fi) communication links, or microwave communication links, etc.
[0050] The terminal 101 may interact with the server 103 through the network 102 to receive messages from the server 103 or send messages to the server 103. Alternatively, the terminal 101 may interact with the server 103 through the network 102 to receive messages or data sent by other users to the server 103. The terminal 101 may be hardware or software. When the terminal 101 is hardware, it may be various electronic devices, including but not limited to smartphones, tablets, laptop portable computers, and desktop computers, etc. When the terminal 101 is software, it may be installed in the above-listed electronic devices, which may be implemented as multiple software or software modules (for example, used to provide distributed services), or may be implemented as a single software or software module, and no specific limitation is made here.
[0051] In the embodiments of this specification, first, the terminal 101 obtains the user's behavior sequence data based on the user operation triggered by the user on the target page; then, the terminal 101 extracts the operation feature data corresponding to the user operation from the behavior sequence data; based on this, the terminal 101 further matches the operation feature data with the page exception rule, and determines the exception detection result of the target page according to the matching result.
[0052] The server 103 may be a business server that provides various services. It should be noted that the server 103 may be hardware or software. When the server 103 is hardware, it may be implemented as a distributed server cluster composed of multiple servers, or may be implemented as a single server. When the server 103 is software, it may be implemented as multiple software or software modules (for example, used to provide distributed services), or may be implemented as a single software or software module, and no specific limitation is made here.
[0053] Alternatively, the system architecture may not include the server 103. In other words, the server 103 may be an optional device in the embodiments of this specification. That is, the method provided in the embodiments of this specification may be applied to a system structure that only includes the terminal 101, and no limitation is made in the embodiments of this specification.
[0054] It should be understood, Figure 1The numbers of terminals, networks, and servers in [it] are only illustrative. According to the implementation requirements, there can be any number of terminals, networks, and servers.
[0055] Please refer to Figure 2 , Figure 2 Figure 2 is a schematic flowchart of a page anomaly detection method provided by an embodiment of this specification. The execution subject of the embodiment of this specification can be a terminal that performs page anomaly detection, a processor in the terminal that performs the page anomaly detection method, or a page anomaly detection service in the terminal that performs the page anomaly detection method. For ease of description, hereinafter, taking the execution subject as the processor in the terminal as an example, the specific execution process of the page anomaly detection method will be introduced.
[0056] As Figure 2 shown, the page anomaly detection method can at least include:
[0057] S202. Obtain the user's behavior sequence data based on the user operations triggered by the user on the target page.
[0058] Optionally, when a user accesses a website, the website usually provides multiple components for the user to interact with, such as buttons, sliders, single / multi-selection boxes, text input boxes, drop-down selection boxes, and / or list boxes, etc. Based on these interactive components, the user can perform interactive behaviors on this interface (such as clicking a link, clicking a button, clicking to view the list details, clicking to jump to a new page, swiping up and down to view text, clicking to play a video, etc.) to trigger corresponding functions. The interactive behaviors of the user on the website can reflect the user's operation rules, thereby reflecting whether there is an interface anomaly on the website. Therefore, in the embodiment of this specification, based on the user operations triggered by the user on the target page, the user's interactive behaviors are monitored to obtain the user's behavior sequence data.
[0059] Specifically, for the target page that the user is accessing, the system can, based on the log recording ability of front-end technology, capture and record in real time all the user operations triggered by the user on the target page. These operations include but are not limited to clicking, swiping, inputting text, submitting a form, etc., thereby forming a detailed user behavior path based on the occurrence of these operations and obtaining the user behavior sequence data corresponding to the behavior path. The real-time log recording ability ensures that every interaction between the user and the page elements is accurately recorded, providing a reliable data source for subsequent analysis.
[0060] S204. Extract the operation feature data corresponding to the user operations from the behavior sequence data.
[0061] Optionally, after obtaining the user's behavioral sequence data, the system will deeply analyze this behavioral sequence data to extract the operation feature data corresponding to the user's operations. These feature data may cover operation information in multiple dimensions, including but not limited to the type of operation, the timestamp of occurrence, the ID or class name of the operation target element, the frequency of operation, and the logical relationship between operations, etc. This process not only requires a high level of data analysis ability but also needs to combine the understanding of transaction logic to ensure that the extracted features can truly reflect the user's intentions and behavior patterns.
[0062] In a possible implementation, an operation feature data extraction model can be used to extract operation feature data from the behavioral sequence data. The data extraction model can be a pre-trained deep learning neural network that can parse various operation events occurring in the behavioral sequence data and the user's movement lines in each operation event, so as to output quantitative and readable user operation feature data for subsequent detection of page anomalies based on the feature data.
[0063] S206. Match the operation feature data with the page anomaly rules, and determine the anomaly detection result of the target page according to the matching result.
[0064] Optionally, the system matches these operation feature data with the preset page anomaly rules. These anomaly rules are carefully designed based on the analysis of historical data, the understanding of transaction logic, and the identification of potential risk points, aiming to identify a series of abnormal interaction patterns that do not conform to the normal user behavior pattern, such as frequent unexpected clicks, sudden submissions after a long time of inactivity, or accessing page areas that should not be accessed, etc. The matching process uses an efficient algorithm to ensure good performance and accuracy even when dealing with large-scale data.
[0065] Optionally, according to the matching result, the system can automatically determine the anomaly detection result of the target page. If the matching result shows that the user behavior features hit the preset page anomaly rules, the system will mark the page as having an anomaly and may trigger further response mechanisms, such as sending an alarm to notify the administrator, recording the anomaly details for subsequent analysis, or automatically adjusting the page layout to avoid potential problems, etc. On the contrary, if the page anomaly rules are not hit, it means that all the interactive modules in the page are normal and can support the normal operation behavior of the user.
[0066] In the embodiments of this specification, a page anomaly detection method is provided. Behavioral sequence data of a user is obtained based on a user operation triggered by the user on a target page; operation feature data corresponding to the user operation is extracted from the behavioral sequence data; the operation feature data is matched with page anomaly rules, and an anomaly detection result of the target page is determined according to the matching result. In the embodiments of this specification, behavioral sequence data is obtained based on the interaction operations of the user on the page, and an accurate model of the user's movement path (i.e., the movement trajectory and behavioral order of the user on the page) is realized. This enables the system to more deeply discover anomalies existing in the page from the user's interaction behaviors. Based on this, by matching the user's movement path with page anomaly rules, the efficiency and accuracy of anomaly detection are greatly improved, so that interaction anomalies occurring in the page can be discovered and processed in a timely manner, effectively ensuring the user experience and the security of the system.
[0067] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of a page anomaly detection method provided by the embodiments of this specification.
[0068] As Figure 3 shown, the page anomaly detection method may at least include:
[0069] S302. In response to an access operation on a target page, obtain the DOM tree structure of the target page, and bind event listeners to the interactive elements in the target page based on the DOM tree structure.
[0070] Optionally, when a user accesses a website, the front-end JavaScript code will be automatically loaded and run. Then, in order to monitor and capture the user's interaction behaviors in real time on the web page, event listeners for interaction events can be predefined in the code so that the web page code can obtain the DOM (Document Object Model) tree structure of the current page when it runs. The DOM tree is a hierarchical representation of the web page content, which contains the structural information of all elements on the page. By parsing the DOM tree, event listeners can be bound to all interactive elements (such as buttons, links, sliders, etc.). Once the user triggers these interaction behaviors, such as actions or gestures like clicking, swiping, dragging, etc., the corresponding event listeners will be immediately activated and record the events.
[0071] S304. Monitor the user operations triggered by the user in the target page, and obtain the behavioral data of the user based on the user operations.
[0072] Optionally, after binding an event listener to an interactive element, the event listener can be used to monitor user operations triggered by the user on the target page. Specifically, the activated event listener quickly captures relevant information about the event, including but not limited to the type of the event (click, swipe, etc.), the element identifier that triggered the event, the timestamp when the event occurred, etc. This information is crucial for subsequent data analysis and user behavior serialization.
[0073] In the embodiments of this specification, the user's behavior data specifically includes the text of the web page and all DOM nodes, click events, DOM diff events (comparing the differences between two virtual DOM objects generated before and after rendering updates, that is, the amount of change in the DOM object before and after the operation), and data of swipe events. The anomalies of these events directly affect the user's interaction experience. Therefore, these events can be the key focus. In actual applications, the acquisition of specific behavior data can be adjusted according to actual needs, and the embodiments of this specification do not limit this.
[0074] Optionally, to ensure the security of data acquisition, transmission, and storage, the initial operation data of the user obtained can also be desensitized to obtain the user's behavior data. Among them, the desensitization methods include at least one of encrypted transmission and anonymization processing.
[0075] Specifically, encryption transmission technology such as the HTTPS protocol can be adopted to ensure that data is not eavesdropped on or tampered with during transmission. At the same time, during the data processing stage, anonymization processing methods are also implemented. Not only can the user's identity information be protected from leakage by deleting or replacing personal identification information in the data, but also codes or specific identifiers can be used to distinguish various types of operations. For example, a click event can be defined as "event a", and a swipe event can be defined as "event b". Then, in the data, various types of events will be directly recorded in the form of codes, rather than directly in the actual names, ensuring the security of the behavior data.
[0076] S306. Preprocess the user's behavior data to remove invalid behavior data from all behavior data; store the preprocessed behavior data in a database.
[0077] Further, considering that when users interact, there may be some meaningless operations. For example, after a user clicks the "Confirm" control once, the web page loads the operation result corresponding to this click action. Before the result is loaded, the user clicks the "Confirm" control multiple times in a row. In order not to affect the response to valid requests, the backend will block the redundant and invalid operations. Then these operations that do not send requests are actually meaningless operations, and these operations are not needed for user movement analysis. Therefore, it is necessary to filter and process these operation data.
[0078] Specifically, after receiving these data, the server will immediately start a series of preliminary processing processes. These processes may include data formatting (converting the data into a unified format for subsequent processing), deduplication (deleting duplicate data items to reduce storage space and computational burden), etc. After these processes, the data will be securely stored in the database for subsequent data analysis and mining. These front-end data processing methods ensure the real-time and accuracy of the data. Even in high-concurrency access or complex interaction scenarios, the integrity and consistency of the data can be maintained.
[0079] S308. Construct the behavior data into the behavior sequence data corresponding to the user according to the trigger time sequence of each user operation monitored.
[0080] Optionally, in order to construct the behavior sequence data that can reflect the user movement, the behavior data can be sorted according to the trigger time sequence based on the timestamp information of each user operation. This can ensure the accuracy and coherence of the behavior sequence, enabling us to track the real occurrence order of user behaviors. After sorting, the complete and ordered user behavior sequence data can be obtained, and this sequence intuitively shows the timeline of all the user's behaviors within a period of time.
[0081] Further, considering that if the operation timeline of the user on the web page is long, then directly analyzing the obtained long and continuous behavior sequence is likely to lead to low efficiency and may also be difficult to capture the key behavior patterns due to the density of information. Then, in order to improve the readability and analyzability of the behavior sequence, the segmentation strategy based on time windows can be used as an optimization means.
[0082] Specifically, the continuous user behavior data stream is cut at fixed time intervals, for example, every 10 seconds is used as a time window. This means that from the time the user first generates a behavior, every 10 seconds, all behavior events during this period are classified as an independent subsequence. Each subsequence represents a series of continuous behaviors of the user in a short period of time, reflecting his or her immediate interests and preferences. In order to facilitate subsequent tracking and management, a unique identifier (such as a timestamp + sequence number) is also generated for each subsequence. This approach not only ensures the distinction between subsequences, but also greatly facilitates the rapid location of user behaviors within a specific time period in a large data set. Using this time window-based segmentation strategy, the originally lengthy and continuous user behavior sequence is cleverly cut into multiple subsequences. This processing method not only significantly improves the readability of the behavior sequence, but also simplifies the subsequent analysis and processing process, which helps to more efficiently mine valuable behavior information and patterns from massive behavior data.
[0083] S310: Extract operation feature data corresponding to the user operation from the behavior sequence data.
[0084] Regarding step S310, please refer to the detailed description in step S204, which will not be repeated here.
[0085] S312: Match the operation feature data with the feature threshold conditions in each page exception rule; if the operation feature data hits the feature threshold condition in any page exception rule, it is determined that the target page is abnormal.
[0086] Optionally, in order to match the user behavior sequence data with the anomaly rules when detecting abnormal behavior, it is necessary to pre-define at least one page anomaly rule for at least one anomaly type. Each page anomaly rule is provided with at least a characteristic threshold condition for judging an abnormal situation, that is, these rules are intended to accurately capture behavior patterns that may indicate system anomalies or potential security risks.
[0087] Optionally, when formulating page exception rules, first of all, considering that the actual data can reflect the long-term trends and laws of system or user behavior, historical data statistics can be used as the basis for formulating page exception rules. Through in-depth analysis of a large amount of historical data, the characteristics and boundaries of normal behavior patterns can be identified, thereby setting benchmark features that can distinguish normal from abnormal behaviors. Secondly, page exception rules can also be formulated in combination with expert experience. Based on the knowledge and experience of experts, abnormal patterns that may not be easily reflected directly by data can be identified. In addition, machine learning models can also be used to generate exception rules. Machine learning models can learn and extract complex patterns from large amounts of data, and can identify abnormal behaviors by training models, so as to achieve rapid response to anomalies.
[0088] Specifically, to ensure the accuracy and robustness of the exception rules, a threshold-based anomaly detection method can be adopted. The core of this method lies in setting reasonable threshold conditions for each exception rule, matching the operation feature data with the feature threshold conditions in each page exception rule. When a certain feature value in the monitored user behavior sequence exceeds the corresponding threshold, it is determined that there is an anomaly on the target page. Specifically, taking page loading failure and user click behavior as examples to illustrate the application of exception rules. If a certain page experiences N loading failures within a short period of time, this may indicate that there are technical problems with the page or it has been maliciously attacked; similarly, if the number of clicks on a certain control by the user reaches 50 times within 10 seconds, this may indicate that the user is attempting to perform some abnormal operation or has been misled.
[0089] It should be noted that the page exception rules can also configure some conditions that do not judge based on user behavior to effectively reduce noise in a large amount of access data. For example, if a white screen is detected, it can be directly determined that there is an anomaly on the current web page; if a full-screen error page is detected, it can also be determined that there is an anomaly on the current web page; if specific error copywriting or code appears, it can also be determined that there is an anomaly on the current web page. These exception rule conditions are conducive to directly detecting simple and intuitive anomalies, reducing the calculation of unnecessary user data, and saving computing resources.
[0090] S314. Generate an exception report for the target page and send a prompt message corresponding to the exception report.
[0091] Optionally, once it is determined that there is an anomaly on the target page, the system will use advanced algorithms and technical means to automatically generate a detailed exception behavior report. This report not only accurately points out the type of anomaly, such as page element misalignment, interaction failure, data loading anomaly, etc., but also precisely records the exact time when the anomaly occurred and the scope of influence, such as the data of specific users, a certain functional module, or the stability of the entire system.
[0092] Furthermore, to ensure that relevant personnel are informed of the anomaly situation in a timely manner, the system will adopt multiple communication means, such as sending emails, instant text messages, or pushing messages through the enterprise's internal communication platform, to ensure that key information can be quickly conveyed to relevant personnel. Such a multi-channel notification mechanism greatly improves the response speed and collaboration efficiency. In addition, through the log recording function, all log information related to abnormal behavior can be automatically captured and recorded. These logs include but are not limited to the system state before the anomaly is triggered, the specific operation details when the anomaly occurs, and the preliminary measures taken by the system to deal with the anomaly. These detailed log data provide valuable basis for subsequent in-depth analysis of the anomaly cause, optimization of the system security strategy, and improvement of the overall protection ability.
[0093] S316. Dynamically adjust the parameters of each page exception rule according to the exception report.
[0094] Furthermore, in order to improve the robustness of the page exception rule in practical applications, a dynamic adjustment mechanism is also introduced to optimize the exception detection process. Since the system environment and user behavior are constantly changing, static thresholds may not always maintain their effectiveness and accuracy. Therefore, the change situation of real-time data and the detected exception situation can be used to automatically adjust the size of the threshold parameters in the page exception rule to ensure that the exception detection system can adapt to different requirements. This dynamic adjustment mechanism not only improves the flexibility of the system, but also continuously improves the exception detection ability and accuracy of the system.
[0095] In the embodiments of this specification, a page exception detection method is provided, which accurately captures user behavior through an event listener. According to the trigger time sequence of each user operation monitored, the behavior data is constructed into behavior sequence data corresponding to the user. This sequence intuitively shows the timeline of all behaviors of the user within a period of time, which is conducive to accurately analyzing the user's movement route. Set reasonable threshold conditions for each exception rule, and match the operation feature data with the feature threshold conditions in each page exception rule. When a certain feature value in the monitored user behavior sequence exceeds the corresponding threshold, it is determined that there is an exception on the target page, ensuring the accuracy and effectiveness of the exception rule. Once it is determined that there is an exception on the target page, an exception report of the target page is immediately generated and a prompt message corresponding to the exception report is sent, ensuring that the problem can be managed quickly and effectively. Dynamically adjust the parameters of each page exception rule according to the exception report. This dynamic adjustment mechanism not only improves the robustness in practical applications, but also enhances its ability to respond to unknown threats.
[0096] Please refer to Figure 4 , Figure 4 which is the structural block diagram of a page exception detection device provided by the embodiments of this specification. As Figure 4 shown, the page exception detection device 400 includes:
[0097] A data acquisition module 410, configured to acquire the behavior sequence data of the user based on the user operations triggered by the user on the target page;
[0098] A feature extraction module 420, configured to extract the operation feature data corresponding to the user operation from the behavior sequence data;
[0099] A rule matching module 430, configured to match the operation feature data with the page exception rule, and determine the exception detection result of the target page according to the matching result.
[0100] Optionally, the data acquisition module 410 is further configured to monitor user operations triggered by the user on the target page, acquire the user's behavior data based on the user operations; and construct the behavior data into behavior sequence data corresponding to the user in the order of the triggering times of the monitored user operations.
[0101] Optionally, the data acquisition module 410 is further configured to, every preset time period, construct the behavior data within the preset time period into behavior sequence data in the order of the triggering times of the monitored user operations, and generate a unique identifier for each behavior sequence data.
[0102] Optionally, the page anomaly detection device 400 further includes: an event monitoring module, configured to, in response to an access operation on the target page, acquire the DOM tree structure of the target page, and bind event listeners to the interactive elements in the target page based on the DOM tree structure; the data acquisition module 410 is further configured to monitor user operations triggered by the user on the target page through the event listeners.
[0103] Optionally, the data acquisition module 410 is further configured to acquire the user's initial operation data based on the user operations, and perform desensitization processing on the initial operation data to obtain the user's behavior data; the desensitization processing methods include at least one of encrypted transmission and anonymization processing.
[0104] Optionally, the page anomaly detection device 400 further includes: a data processing module, configured to preprocess the user's behavior data to remove invalid behavior data from all behavior data; and store the preprocessed behavior data in a database.
[0105] Optionally, the page anomaly detection device 400 further includes: a rule configuration module, configured to define at least one page anomaly rule for at least one anomaly type, where at least one characteristic threshold condition for determining an abnormal situation is set in each page anomaly rule.
[0106] Optionally, the rule matching module 430 is further configured to match the operation characteristic data with the characteristic threshold conditions in each page anomaly rule; if the operation characteristic data hits the characteristic threshold condition in any page anomaly rule, it is determined that the target page has an anomaly.
[0107] Optionally, the page anomaly detection device 400 further includes: an anomaly processing module, configured to generate an anomaly report for the target page and issue a prompt message corresponding to the anomaly report.
[0108] Optionally, the page anomaly detection device 400 further includes: a rule adjustment module, configured to dynamically adjust the parameters of each page anomaly rule according to the anomaly report.
[0109] In the embodiments of this specification, a page anomaly detection device is provided. Among them, a data acquisition module is used to acquire the behavior sequence data of a user based on the user operations triggered by the user on a target page; a feature extraction module is used to extract the operation feature data corresponding to the user operations from the behavior sequence data; a rule matching module is used to match the operation feature data with the page anomaly rules and determine the anomaly detection result of the target page according to the matching result. In the embodiments of this specification, the behavior sequence data is acquired based on the interaction operations of the user on the page, and an accurate model of the user movement track (i.e., the movement track and behavior sequence of the user on the page) is realized. This enables the system to more deeply discover the anomalies existing in the page from the interaction behaviors of the user. Based on this, by matching the user movement track with the page anomaly rules, the efficiency and accuracy of anomaly detection are greatly improved, so that the interaction anomalies occurring in the page can be discovered and processed in the first time, effectively guaranteeing the user experience and the security of the system.
[0110] The embodiments of this specification provide a computer program product containing instructions. When the computer program product runs on a computer or a processor, it causes the computer or the processor to execute the steps of the method in any one of the above embodiments.
[0111] The embodiments of this specification also provide a computer storage medium. The computer storage medium can store multiple instructions, and the instructions are suitable for being loaded and executed by a processor to execute the steps of the method in any one of the above embodiments.
[0112] Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of a terminal provided by the embodiments of this specification. As Figure 5 shown, the terminal 500 may include: at least one processor 501, at least one network interface 504, a user interface 503, a memory 505, and at least one communication bus 502.
[0113] Among them, the communication bus 502 is used to realize the connection and communication between these components.
[0114] Among them, the user interface 503 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 503 may further include a standard wired interface and a wireless interface.
[0115] Among them, the network interface 504 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0116] Among them, the processor 501 may include one or more processing cores. The processor 501 connects various parts within the entire terminal 500 through various interfaces and lines, and executes various functions of the terminal 500 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 505, and by calling data stored in the memory 505. Optionally, the processor 501 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 501 may integrate one or a combination of several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 501 and may be implemented separately by a single chip.
[0117] Among them, the memory 505 may include random access memory (RAM) and may also include read-only memory (ROM). Optionally, the memory 505 includes a non-transitory computer-readable storage medium. The memory 505 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 505 may also be at least one storage device located far from the aforementioned processor 501. As Figure 5 shown, the memory 505, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a page exception detection program.
[0118] In Figure 5In the terminal 500 shown, the user interface 503 is mainly used to provide an interface for the user to input and obtain the data input by the user; and the processor 501 can be used to call the page exception detection program stored in the memory 505 and specifically perform the following operations:
[0119] Obtain the user's behavior sequence data based on the user operations triggered by the user in the target page;
[0120] Extract the operation feature data corresponding to the user operations from the behavior sequence data;
[0121] Match the operation feature data with the page exception rules, and determine the exception detection result of the target page according to the matching result.
[0122] In some embodiments, when the processor 501 executes to obtain the user's behavior sequence data based on the user operations triggered by the user in the target page, the following steps are specifically executed: Listen for the user operations triggered by the user in the target page, and obtain the user's behavior data based on the user operations; According to the trigger time sequence of each user operation listened to, construct the behavior data into the behavior sequence data corresponding to the user.
[0123] In some embodiments, when the processor 501 executes to construct the behavior data into the behavior sequence data corresponding to the user according to the trigger time sequence of each user operation listened to, the following steps are specifically executed: Every preset duration, construct the behavior data within the preset duration into the behavior sequence data according to the trigger time sequence of each user operation listened to, and generate a unique identifier for each behavior sequence data.
[0124] In some embodiments, the processor 501 also specifically executes the following steps: In response to the access operation for the target page, obtain the DOM tree structure of the target page, and bind event listeners to the interactive elements in the target page based on the DOM tree structure; When the processor 501 executes to listen for the user operations triggered by the user in the target page, the following steps are specifically executed: Listen for the user operations triggered by the user in the target page through the event listeners.
[0125] In some embodiments, when the processor 501 executes to obtain the user's behavior data based on the user operations, the following steps are specifically executed: Obtain the user's initial operation data based on the user operations, and perform desensitization processing on the initial operation data to obtain the user's behavior data; The desensitization processing methods include at least one of encrypted transmission and anonymization processing.
[0126] In some embodiments, after the processor 501 executes to obtain the user's behavior data based on the user operations, the following steps are also specifically executed: Preprocess the user's behavior data to remove the invalid behavior data in all the behavior data; Store the preprocessed behavior data in the database.
[0127] In some embodiments, the processor 501 further specifically performs the following steps: defining at least one page exception rule for at least one type of exception, wherein at least a characteristic threshold condition for determining an exception situation is set in each page exception rule.
[0128] In some embodiments, when the processor 501 performs matching the operation characteristic data with the page exception rules and determining the exception detection result of the target page according to the matching result, it specifically performs the following steps: matching the operation characteristic data with the characteristic threshold conditions in each page exception rule; if the operation characteristic data hits the characteristic threshold condition in any page exception rule, it is determined that the target page has an exception.
[0129] In some embodiments, after the processor 501 determines that the target page has an exception, it further specifically performs the following steps: generating an exception report for the target page and sending out a prompt message corresponding to the exception report.
[0130] In some embodiments, after the processor 501 generates the exception report for the target page, it further specifically performs the following steps: dynamically adjusting the parameters of each page exception rule according to the exception report.
[0131] In several embodiments provided in this specification, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the apparatus or module can be in an electrical, mechanical or other form.
[0132] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they may be located in one place, or may be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0133] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The above computer program product includes one or more computer instructions. When the above computer program instructions are loaded and executed on a computer, the processes or functions described above in accordance with the embodiments of this specification are generated in whole or in part. The above computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above computer instructions can be stored in a computer-readable storage medium or transmitted through the above computer-readable storage medium. The above computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The above computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The above available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a Digital Versatile Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.
[0134] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this specification are not limited by the described order of actions, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.
[0135] In addition, it should also be noted that the information (including but not limited to user equipment information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by users or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions. For example, the user operation data, behavior data, behavior sequences, etc. involved in this specification are obtained under full authorization.
[0136] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0137] In the above embodiments, the descriptions of the various embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0138] The above is a description of a page anomaly detection method, apparatus, storage medium, and terminal provided by the embodiments of this specification. For those skilled in the art, based on the ideas of the embodiments of this specification, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the embodiments of this specification.
Claims
1. A method for detecting page anomalies, the method comprising: Obtaining the user's behavior sequence data based on the user operations triggered by the user on the target page; Extracting the operation feature data corresponding to the user operations from the behavior sequence data; Matching the operation feature data with page anomaly rules, and determining the anomaly detection result of the target page according to the matching result.
2. The method according to claim 1, wherein the obtaining the user's behavior sequence data based on the user operations triggered by the user on the target page comprises: Listening for the user operations triggered by the user on the target page, and obtaining the user's behavior data based on the user operations; Constructing the behavior data into the behavior sequence data corresponding to the user in the order of the triggering times of the listened user operations.
3. The method according to claim 1, wherein the constructing the behavior data into the behavior sequence data corresponding to the user in the order of the triggering times of the listened user operations comprises: At every preset time interval, constructing the behavior data within the preset time interval into behavior sequence data in the order of the triggering times of the listened user operations, and generating a unique identifier for each behavior sequence data.
4. The method according to claim 2, the method further comprising: In response to an access operation to the target page, obtaining the DOM tree structure of the target page, and binding event listeners to the interactive elements in the target page based on the DOM tree structure; The listening for the user operations triggered by the user on the target page comprises: Listening for the user operations triggered by the user on the target page through the event listeners.
5. The method according to claim 2, wherein the obtaining the user's behavior data based on the user operations comprises: Obtaining the user's initial operation data based on the user operations, and performing desensitization processing on the initial operation data to obtain the user's behavior data; The desensitization processing methods include at least one of encrypted transmission and anonymization processing.
6. The method according to claim 2, after the obtaining the user's behavior data based on the user operations, further comprising: Performing preprocessing on the user's behavior data to remove invalid behavior data from all behavior data; Storing the behavior data after the preprocessing in a database.
7. The method according to claim 1, the method further comprising: Defining at least one page anomaly rule for at least one anomaly type, wherein at least a feature threshold condition for judging an anomaly situation is set in each page anomaly rule.
8. The method according to claim 7, wherein the matching the operation feature data with page anomaly rules, and determining the anomaly detection result of the target page according to the matching result comprises: Matching the operation feature data with the feature threshold conditions in each page anomaly rule; If the operation feature data hits the feature threshold condition in any page anomaly rule, determining that the target page has an anomaly.
9. The method according to claim 8, after the determining that the target page has an anomaly, further comprising: Generate an exception report for the target page and issue a prompt message corresponding to the exception report.
10. The method according to claim 9, after generating the exception report for the target page, further comprising: Dynamically adjust the parameters of each page exception rule according to the exception report.
11. A page exception detection device, the device comprising: A data acquisition module, configured to acquire the behavior sequence data of the user based on the user operation triggered by the user in the target page; A feature extraction module, configured to extract the operation feature data corresponding to the user operation from the behavior sequence data; A rule matching module, configured to match the operation feature data with a page exception rule, and determine the exception detection result of the target page according to the matching result.
12. A computer program product containing instructions, when the computer program product runs on a computer or a processor, enabling the computer or the processor to execute the steps of the method according to any one of claims 1 to 10.
13. A computer storage medium, the computer storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by a processor to execute the steps of the method according to any one of claims 1 to 10.
14. A terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.