Access request monitoring method and device and related equipment

By deploying agents to listen and forwarding access requests on the front-end page, the problem of complexity of browser tool monitoring is solved, and unified monitoring across browsers is realized and intelligent performance analysis and security audit is improved, and the performance and security of the application are improved.

CN120263704APending Publication Date: 2025-07-04NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510281248.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the data exchange behavior of monitoring web applications through browser developer tools is complex and incompatible, making it difficult to achieve unified monitoring across browsers.

Method used

Deploy an agent on the front-end page, listen to access requests to access back-end services, record relevant information, and forward the request agent to the back-end server for processing, and analyze the access request behavior.

Benefits of technology

It realizes unified monitoring across browsers, provides real-time performance analysis, intelligent logging, security auditing and data visualization, and improves application performance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263704A_ABST
    Figure CN120263704A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to an access request monitoring method and device and related equipment. The method is applied to a front-end page, and an agent program used for monitoring and accessing back-end service is deployed on the front-end page. The method comprises the following steps: when an access request triggered by a user and used for accessing a back-end service is monitored, monitoring a generation process and a sending process of the access request, and recording related information of the access request; forwarding the access request to a back-end server in a proxy manner, so that the back-end server processes the access request based on a preset rule; receiving response data fed back by the back-end server based on the access request, processing the response data, and recording response information of the response data; and analyzing the access request behavior based on the related information of the access request and the response information of the response data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and particularly relates to a method and device for monitoring access requests and related devices. Background Art

[0002] As the complexity of business systems increases, the tasks of operation and maintenance personnel are heavy and difficult. Therefore, how to monitor data exchange behaviors in web application programs has become an urgent problem to be solved.

[0003] Currently, most of them view all requests through the developer tools of the browser. Among them, the network panel can be used to monitor all network requests in the page, including AJAX requests. Developers can view the detailed information of requests and responses through this tool for debugging and performance analysis. It is relatively complex for non-professionals to handle, and using browser developer tools or plugins for monitoring requires relying on a specific browser environment, and sometimes it may be incompatible or have limited functions on certain browsers. Summary of the Invention

[0004] This application provides a method and device for monitoring access requests and related devices.

[0005] In a first aspect, this application provides a 1. A method for monitoring access requests, which is applied to a front-end page, and a proxy program for listening to access to a back-end service is deployed on the front-end page; the method includes:

[0006] When an access request for accessing the back-end service triggered by a user is monitored, listen to the generation process and sending process of the access request, and record relevant information of the access request;

[0007] Proxy-forward the access request to the back-end server so that the back-end server processes the access request based on preset rules;

[0008] Receive response data fed back by the back-end server based on the access request, process the response data, and record response information of the response data;

[0009] Analyze the access request behavior based on the relevant information of the access request and the response information of the response data.

[0010] Optionally, the step of listening to the generation process and sending process of the access request and recording relevant information of the access request includes:

[0011] Intercept and parse the access request, obtain and record the business service address accessed by the access request, the method and request headers used by the access request, and record the time taken to generate the access request and the sending timestamp information of the access request.

[0012] Optionally, the step of recording the response information of the response data includes:

[0013] Recording a status code for characterizing whether the access request is successful, a response header, and a reception timestamp information for receiving the response data.

[0014] Optionally, an identifier for characterizing the access request as a legitimate access request is maintained on the front-end web page and the back-end server; the step of proxy-forwarding the access request to the back-end server includes:

[0015] Adding a preset identifier to the access request;

[0016] Sending the access request added with the preset identifier to the back-end server.

[0017] In a second aspect, the present application provides an access request monitoring device, which is applied to a front-end page, and a proxy program for listening to access to a back-end service is deployed on the front-end page; the device includes:

[0018] A listening unit, configured to listen to the generation process and the sending process of the access request when monitoring an access request triggered by a user for accessing a back-end service, and record relevant information of the access request;

[0019] A forwarding unit, configured to proxy-forward the access request to a back-end server, so that the back-end server processes the access request based on a preset rule;

[0020] A receiving unit, configured to receive response data fed back by the back-end server based on the access request, process the response data, and record response information of the response data;

[0021] An analysis unit, configured to analyze the access request behavior based on the relevant information of the access request and the response information of the response data.

[0022] Optionally, when listening to the generation process and the sending process of the access request and recording relevant information of the access request, the listening unit is specifically configured to:

[0023] Intercept and parse the access request, obtain and record the business service address accessed by the access request, the device and the request header used by the access request, and record the time taken to generate the access request and the sending timestamp information of the access request.

[0024] Optionally, when recording the response information of the response data, the listening unit is specifically configured to:

[0025] Record the status code indicating whether the access request is successfully requested, the response header, and the reception timestamp information for receiving the response data.

[0026] Optionally, an identifier for characterizing the access request as a legitimate access request is maintained on the front-end web page and the back-end server; when proxy-forwarding the access request to the back-end server, the forwarding unit is specifically configured to:

[0027] Add a preset identifier to the access request;

[0028] Send the access request after adding the preset identifier to the back-end server.

[0029] In a third aspect, an embodiment of the present application provides an access request monitoring device, and the access request monitoring device includes:

[0030] A memory for storing program instructions;

[0031] A processor for calling the program instructions stored in the memory and executing the steps of the method according to any one of the above first aspects according to the obtained program instructions.

[0032] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, and the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause the computer to execute the steps of the method according to any one of the above first aspects.

[0033] In summary, the access request monitoring method provided by the embodiment of the present application is applied to a front-end page, and a proxy program for listening to access to a back-end service is deployed on the front-end page; the method includes: when monitoring an access request triggered by a user for accessing a back-end service, listening to the generation process and the sending process of the access request, and recording relevant information of the access request; proxy-forwarding the access request to the back-end server so that the back-end server processes the access request based on a preset rule; receiving response data fed back by the back-end server based on the access request, processing the response data, and recording response information of the response data; analyzing the access request behavior based on the relevant information of the access request and the response information of the response data.

[0034] By using the access request monitoring method provided in the embodiments of the present application, it is possible to monitor access requests and combine with real-time performance analysis tools to achieve real-time monitoring and analysis of page loading and interaction performance. Based on the monitored data, an intelligent logging function can be implemented, such as automatically identifying abnormal requests, high-latency requests, etc., to achieve more intelligent logging. Combining with security audit tools, security audit and vulnerability detection of access requests can be achieved, thereby enhancing the security of the application. Visualize the monitored access request and response data and intuitively display it in the form of charts, graphs, etc. to help developers better understand data exchange behaviors. Based on the monitored performance data and request information, automated performance optimization suggestions can be implemented to help developers quickly locate and solve performance problems. Description of the Drawings

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present application or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings of the embodiments of the present application.

[0036] Figure 1 Detailed flowchart of an access request monitoring method provided by an embodiment of the present application;

[0037] Figure 2 Structural schematic diagram of an access request monitoring device provided by an embodiment of the present application;

[0038] Figure 3 Hardware architecture schematic diagram of an access request monitoring device provided by an embodiment of the present application. Detailed Implementation Modes

[0039] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments and do not limit the present application. The singular forms of "a", "the" and "said" used in the present application and the claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations including one or more of the associated listed items.

[0040] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "when" or "while" or "in response to a determination".

[0041] Exemplarily, referring to Figure 1 As shown, it is a detailed flowchart of an access request monitoring method provided by an embodiment of the present application. This method is applied to a front-end page, and a proxy program for listening to access to a back-end service is deployed on the front-end page; the method includes the following steps:

[0042] Step 100: When an access request for accessing a back-end service triggered by a user is monitored, listen to the generation process and sending process of the access request, and record the relevant information of the access request.

[0043] In the embodiment of the present application, an operation and maintenance personnel pre-writes a script (such as, script script) and injects it into the front-end page. This script can be used to listen to access requests for accessing the back-end service through this front-end web page. Specifically, this script can be used to proxy and forward each access request for accessing the back-end service through this front-end web page. When a user accesses the back-end service through this front-end web page, the access request will be intercepted by this script.

[0044] In the embodiment of the present application, when listening to the generation process and sending process of the access request and recording the relevant information of the access request, a preferred implementation method is:

[0045] Intercept and parse the access request, obtain and record the business service address accessed by the access request, the method and request headers used by the access request, and record the time-consuming for generating the access request and the sending timestamp information for sending the access request.

[0046] For example, in the XHR proxy object, listen to the open() and send() methods of the XMLHttpRequest object. In this way, the access request can be intercepted and the relevant information of the access request can be recorded, such as the request URL, request method, request headers, the time-consuming for generating the access request based on the user instruction on the previous page, and the sending timestamp for sending this access request, etc.

[0047] In practical applications, the backend server provides multiple business services, and each business service can also include multiple request access methods. Then, the recorded request URL represents which business service the user accesses, and the request method represents which specific method is used to access the business service.

[0048] In this way, when analyzing and counting the performance of access requests subsequently, it is possible to analyze and count the performance of access requests for different business services and for accessing the same business service using different access methods.

[0049] Step 110: Proxy-forward the access request to the backend server so that the backend server processes the access request based on a preset rule.

[0050] In the embodiments of the present application, an identifier for characterizing an access request as a legitimate access request can be pre-maintained on the front-end web page and the backend server; in this way, after receiving an access request, the backend server determines whether the access request carries a preset identifier to determine whether the access request is a legitimate access request. Then, in the embodiments of the present application, when proxy-forwarding the access request to the backend server, a preferred implementation is:

[0051] Add a preset identifier to the access request; send the access request after adding the preset identifier to the backend server.

[0052] Specifically, if the backend server receives an access request with a preset identifier added, it processes the access request; if the backend server receives an access request without a preset identifier added, it may not process the access request and directly discard the access request.

[0053] Step 120: Receive the response data fed back by the backend server based on the access request, process the response data, and record the response information of the response data.

[0054] In the embodiments of the present application, when recording the response information of the response data, a preferred implementation is:

[0055] Record the status code for characterizing whether the access request is successful, the response header, and the receive timestamp information for receiving the response data.

[0056] For example, in practical applications, the readystatechange event of the XMLHttpRequest object can be listened to, that is, the response data can be intercepted and processed after receiving the response, and the response information can be recorded. The response information can include: the status code (for characterizing whether the request is successful), the response header (corresponding to the request header), the calculated callback time, the server time, etc.

[0057] Step 130: Analyze the access request behavior based on the relevant information of the access request and the response information of the response data.

[0058] Specifically, the intercepted access requests and response data can be customized as needed, such as debugging, performance optimization, security auditing and customized processing, and can perform operations such as logging, performance analysis, and response data filtering.

[0059] For example, the request performance (eg, request time consumption, etc.) of the access request of each business service may be analyzed respectively, and the request performance corresponding to each method when a business service is accessed using different access request methods may be analyzed.

[0060] Furthermore, the analysis results can be graphically processed and displayed in the form of charts.

[0061] In summary, the access request monitoring method provided by the embodiment of the present application includes but is not limited to realizing the following functions:

[0062] 1. Real-time performance analysis can be performed: by monitoring AJAX requests and combining them with real-time performance analysis tools, real-time monitoring and analysis of page loading and interactive performance can be achieved.

[0063] 2. Intelligent logging: Based on the monitored data, intelligent logging functions are implemented, such as automatic identification of abnormal requests, time-consuming requests, etc., to achieve more intelligent logging.

[0064] 3. Security audit and risk detection: Combined with security audit tools, security audit and vulnerability detection of AJAX requests can be implemented to improve the security of the application.

[0065] 4. Data visualization: The monitored AJAX request data is visualized and presented in the form of charts, graphs, etc. to help developers better understand data exchange behavior.

[0066] 5. Automated optimization suggestions: Based on the monitored performance data and request information, automated performance optimization suggestions are implemented to help developers quickly locate and solve performance problems.

[0067] Based on the same inventive concept as the above-mentioned embodiment of the invention, for example, refer to Figure 2 FIG. 1 is a schematic diagram of a structure of an access request monitoring device provided by an embodiment of the present application. The device is applied to a front-end page, and the front-end page is deployed with an agent program for monitoring access to back-end services; the device includes:

[0068] The monitoring unit 20 is used to monitor the generation process and sending process of the access request triggered by the user for accessing the backend service, and record the relevant information of the access request;

[0069] The forwarding unit 21 is used to proxy-forward the access request to the backend server, so that the backend server processes the access request based on preset rules;

[0070] The receiving unit 22 is used to receive the response data fed back by the backend server based on the access request, process the response data, and record the response information of the response data;

[0071] The analysis unit 23 is used to analyze the access request behavior based on the relevant information of the access request and the response information of the response data.

[0072] Optionally, when monitoring the generation process and sending process of the access request and recording the relevant information of the access request, the monitoring unit 20 is specifically used for:

[0073] Intercept and parse the access request, obtain and record the business service address accessed by the access request, the device and request header used by the access request, and record the time consumption for generating the access request and the sending timestamp information of the access request.

[0074] Optionally, when recording the response information of the response data, the monitoring unit 20 is specifically used for:

[0075] Record the status code, response header used to characterize whether the access request is successfully requested, and the receiving timestamp information of the response data.

[0076] Optionally, there is an identifier maintained on the front-end web page and the backend server to characterize the access request as a legal access request; when proxy-forwarding the access request to the backend server, the forwarding unit 21 is specifically used for:

[0077] Add a preset identifier to the access request;

[0078] Send the access request added with the preset identifier to the backend server.

[0079] The above units may be one or more integrated circuits configured to implement the above methods, such as: one or more Application Specific Integrated Circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more Field Programmable Gate Arrays (FPGAs), etc. For another example, when a certain unit above is implemented in the form of a processing element scheduling program code, the processing element may be a general-purpose processor, such as a Central Processing Unit (CPU) or other processors that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0080] Further, for the access request monitoring device provided in the embodiments of the present application, from a hardware perspective, the schematic diagram of the hardware architecture of the access request monitoring device can be seen in Figure 3 as shown, the access request monitoring device may include: a memory 30 and a processor 31,

[0081] The memory 30 is used to store program instructions; the processor 31 calls the program instructions stored in the memory 30 and executes the above method embodiments according to the obtained program instructions. The specific implementation manners and technical effects are similar and will not be elaborated here.

[0082] Optionally, the present application further provides an access request monitoring device, including at least one processing element (or chip) for executing the above method embodiments.

[0083] Optionally, the present application further provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions for causing the computer to execute the above method embodiments.

[0084] Here, the machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.

[0085] The systems, devices, modules, or units described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, laptop computer, cellular phone, camera phone, smart phone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or a combination of any several of these devices.

[0086] For the convenience of description, when describing the above devices, they are divided into various units according to functions and described separately. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0087] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, system, or computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0088] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0089] Moreover, these computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0090] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the process Figure 1 in one process or a plurality of processes and / or blocks Figure 1 steps for the functions specified in one block or a plurality of blocks.

[0091] The foregoing is only a preferred embodiment of the present application and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of protection of the present application.

Claims

1. A method for monitoring access requests, characterized in that, Applied to the front-end page, a proxy program for listening to access to the back-end service is deployed on the front-end page; the method includes: When monitoring an access request triggered by a user for accessing the back-end service, listen to the generation process and sending process of the access request, and record the relevant information of the access request; Proxy-forward the access request to the back-end server so that the back-end server processes the access request based on preset rules; Receive the response data fed back by the back-end server based on the access request, process the response data, and record the response information of the response data; Analyze the access request behavior based on the relevant information of the access request and the response information of the response data.

2. The method according to claim 1, characterized in that The step of listening to the generation process and sending process of the access request and recording the relevant information of the access request includes: Intercept and parse the access request, obtain and record the business service address accessed by the access request, the method and request header used by the access request, and record the time taken to generate the access request and the sending timestamp information of the access request.

3. The method according to claim 1 or 2, characterized in that, The step of recording the response information of the response data includes: Record the status code, response header indicating whether the access request is successfully requested, and the receiving timestamp information of the response data.

4. The method according to claim 3, wherein An identifier for characterizing the access request as a legal access request is maintained on the front-end web page and the back-end server; the step of proxy-forwarding the access request to the back-end server includes: Add a preset identifier to the access request; Send the access request with the preset identifier added to the back-end server.

5. An access request monitoring device, characterized in that, Applied to the front-end page, a proxy program for listening to access to the back-end service is deployed on the front-end page; the device includes: A listening unit for listening to the generation process and sending process of the access request and recording the relevant information of the access request when monitoring an access request triggered by a user for accessing the back-end service; A forwarding unit for proxy-forwarding the access request to the back-end server so that the back-end server processes the access request based on preset rules; A receiving unit for receiving the response data fed back by the back-end server based on the access request, processing the response data, and recording the response information of the response data; An analyzing unit for analyzing the access request behavior based on the relevant information of the access request and the response information of the response data.

6. The device according to claim 5, characterized in that When listening to the generation process and sending process of the access request and recording the relevant information of the access request, the listening unit is specifically used for: Intercept and parse the access request, obtain and record the business service address accessed by the access request, the device and request header used by the access request, and record the time taken to generate the access request and the sending timestamp information of the access request.

7. The device according to claim 5 or 6, characterized in that, When recording the response information of the response data, the listening unit is specifically used for: Record the status code, response header indicating whether the access request is successfully requested, and the receiving timestamp information of the response data.

8. The device according to claim 7, wherein An identifier for characterizing an access request as a legitimate access request is maintained on the front-end web page and the back-end server; when proxy-forwarding the access request to the back-end server, the forwarding unit specifically is configured to: Add a preset identifier to the access request; Send the access request after adding the preset identifier to the back-end server.

9. An access request monitoring device, characterized in that, The access request monitoring device includes: A memory for storing program instructions; A processor for calling the program instructions stored in the memory and executing the steps of the method according to any one of claims 1-4 according to the obtained program instructions.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing the computer to execute the steps of the method according to any one of claims 1-4.