Website detection method and device, electronic equipment and storage medium
By combining the semantic consistency, text categories and dynamic behavior characteristics of the website, and using a large language model to detect website abnormalities, the problem of static characteristics in the existing technology cannot cope with weak dynamic detection and migration, and efficient and accurate website detection is achieved.
Patent Information
- Application Number
- CN202510570292.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-25
AI Technical Summary
The existing website anomaly detection methods rely on static characteristics and cannot cope with the website's dynamic detection methods. They require a large amount of labeled data to train the model, and have weak migration.
By determining the semantic consistency between the site attributes of the website and the web page text, the text category of the web page text content, and the dynamic behavior characteristics of the website, we comprehensively determine whether the website is abnormal and use a large language model for detection.
It improves the accuracy of website detection, reduces dependence on labeled data, reduces model deployment costs, and enhances the efficiency and interpretability of detection.
Smart Images

Figure CN120372116A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, and particularly to the fields of network security, deep learning, natural language processing, and large model technology. More specifically, the present disclosure provides a website detection method, apparatus, electronic device, storage medium, and computer program product. Background Art
[0002] Currently, the detection of website anomalies usually relies on static features preset manually, such as text keywords, picture textures, etc., and cannot cope with high-frequency dynamic anti-detection means of websites. Moreover, existing detection schemes require a large amount of labeled data to train the model and need to be maintained manually, with weak migration ability. Summary of the Invention
[0003] The present disclosure provides a website detection method, apparatus, electronic device, storage medium, and computer program product.
[0004] According to a first aspect, there is provided a website detection method, the method including: determining the semantic consistency between the site attributes and the web page text according to the site attribute information of the website and the web page text content; determining the text category of the web page text content according to the intent type of the risk text in the web page text content; determining the dynamic behavior characteristics of the web page according to the source code of the website; and determining a detection result indicating whether the website is abnormal according to at least one of the semantic consistency, the text category, and the dynamic behavior characteristics.
[0005] According to a second aspect, there is provided a website detection apparatus, the apparatus including: a semantic consistency determination module for determining the semantic consistency between the site attributes and the web page text according to the site attribute information of the website and the web page text content; a text category determination module for determining the text category of the web page text content according to the intent type of the risk text in the web page text content; a dynamic behavior characteristic determination module for determining the dynamic behavior characteristics of the web page according to the source code of the website; and a detection module for determining a detection result indicating whether the website is abnormal according to at least one of the semantic consistency, the text category, and the dynamic behavior characteristics.
[0006] According to a third aspect, there is provided an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method provided by the present disclosure.
[0007] According to a fourth aspect, there is provided a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method provided by the present disclosure.
[0008] According to a fifth aspect, there is provided a computer program product including a computer program stored on at least one of a readable storage medium and an electronic device, the computer program, when executed by a processor, implementing the method provided according to the present disclosure.
[0009] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0012] Figure 1 is a schematic diagram of an exemplary system architecture to which the website detection method and apparatus according to an embodiment of the present disclosure can be applied;
[0013] Figure 2 is a flowchart of a website detection method according to an embodiment of the present disclosure;
[0014] Figure 3 is a schematic diagram of determining the text category of web page text content according to an embodiment of the present disclosure;
[0015] Figure 4 is a schematic diagram of a website detection method according to an embodiment of the present disclosure;
[0016] Figure 5 is a block diagram of a website detection apparatus according to an embodiment of the present disclosure; and
[0017] Figure 6 is a block diagram of an electronic device for a website detection method according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to help understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0019] A website being hacked means that an unauthorized third party (such as a hacker, attacker) illegally intrudes into a target website through technical means, implants malicious code, disrupts normal services and tampers with its content. A hacked website usually loads or redirects to illegal content, and such behavior poses a potential threat to users' network experience and security.
[0020] Traditional website detection methods based on static features cannot adapt to the content update frequencies of different websites. For example, they are prone to misjudgment for high-frequency update sites such as news websites. In addition, this traditional method requires a large amount of labeled data to train the model. In actual scenarios, it is difficult to manually collect a large number of hacked web page samples for training, and the feature library needs to be frequently maintained manually, so the method has weak migration ability.
[0021] In the technical solution of the present disclosure, the processing of collection, storage, use, processing, transmission, provision, and disclosure of user personal information complies with the provisions of relevant laws and regulations and does not violate public order and good customs.
[0022] In the technical solution of the present disclosure, before obtaining or collecting user personal information, the authorization or consent of the user is obtained.
[0023] Figure 1 is a schematic diagram of an exemplary system architecture to which a website detection method and apparatus according to an embodiment of the present disclosure can be applied. It should be noted that Figure 1 The illustration is only an example of the system architecture to which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0024] As Figure 1 shown, the system architecture 100 according to this embodiment can include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired and / or wireless communication links, etc.
[0025] Users can use the terminal devices 101, 102, 103 to browse various types of application programs or websites. The terminal devices 101, 102, 103 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop portable computers, etc.
[0026] The server 105 can be a server that provides various services, such as a background management server (only an example) that provides support and supervision for the websites browsed by users using the terminal devices 101, 102, 103. The background management server can obtain data such as the filing information, web page content, and source code of the websites browsed by users through the terminal devices 101, 102, 103, detect the websites, and implement supervision of the websites according to the detection results. The server 105 can be deployed with a trained predetermined model, and the predetermined model can be a large language model (LLM).
[0027] At least one of the website detection methods provided by the embodiments of the present disclosure can generally be executed by the server 105. Correspondingly, the website detection device provided by the embodiments of the present disclosure can generally be disposed in the server 105. The website detection methods provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103, and / or the server 105. Correspondingly, the website detection device provided by the embodiments of the present disclosure can also be disposed in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103, and / or the server 105.
[0028] Figure 2 is a flowchart of a website detection method according to an embodiment of the present disclosure.
[0029] As Figure 2 shown, the website detection method 200 includes operations S210 to S240.
[0030] In operation S210, according to the site attribute information of the website and the web page text content, determine the semantic consistency between the site attributes and the web page text.
[0031] In the embodiments of the present disclosure, the website may refer to the website to be detected, and the site attribute information may include information such as the filing information, registration information, website content attributes, website uses, server information, etc. of the website. The web page text content may refer to the text information included in the web page of the website.
[0032] For example, the filing information may refer to ICP (Internet Content Provider) filing metadata, including the filing subject type, filing validity period, filing type description, etc. The registration information may be the whois information of the website obtained by querying the whois database, including the domain name registration time, registrant, DNS (Domain Name System) server geographical location, etc. of the website. The server information may be the IP address (Internet Protocol Address) ownership of the website.
[0033] The semantic consistency can characterize whether the web page text conforms to the site attributes of the website. If the semantic consistency is high, it can be determined that the site attributes of the web page conform to the web page text content, and the probability that the website is at risk of being hacked is low; if the semantic consistency is low, it means that the site attributes of the web page do not conform to the web page text content, and the probability that the website is at risk of being hacked is low.
[0034] For example, the site attribute of webpage A indicates that the website is used as a literary forum, and the webpage text content is related to literary discussions. It can be determined that the semantic consistency between the site attribute of website A and the webpage text is relatively high.
[0035] For example, the site attribute of website N indicates that the website is used for e-commerce, and the webpage text content is related to chatting and making friends. It can be determined that the semantic consistency between the site attribute of website N and the webpage text is relatively low, and there may be abnormal risks on website N.
[0036] In operation S220, according to the intention type of the risk text in the webpage text content, determine the text category of the webpage text content.
[0037] In the embodiments of the present disclosure, the risk text may refer to keywords related to illegal behaviors screened from the webpage text content. The text category of the webpage text content may include normal text and abnormal text. The appearance of risk text in the webpage text content indicates that the webpage text content may contain illegal content, that is, the webpage text content may be abnormal content.
[0038] To further determine whether the webpage text content is abnormal content, the intention type of the risk text can be determined. The intention type of the risk text may refer to the role of the risk text in the webpage text content. For example, it may be an intention type that plays a positive role such as for popular science, news reporting, etc., or an intention type that plays a negative role such as for promotion, guiding clicks, etc.
[0039] According to the intention type, the text category of the webpage text content can be determined. For example, when the intention type is an intention type that plays a positive role such as for popular science, news reporting, etc., it can be determined that the webpage text content is normal text. When the intention type is an intention type that plays a negative role such as for promotion, guiding clicks, etc., it can be determined that the webpage text content is abnormal text.
[0040] In operation S230, determine the dynamic behavior characteristics of the webpage according to the source code of the website.
[0041] In the embodiments of the present disclosure, the dynamic behavior characteristics can be determined by the jump situation of the webpage. The jump situation may include the number of redirects, the home location of the external domain name of the redirect, and the filing information.
[0042] For example, according to the HTTP source code of the webpage, the redirect path (HTTP redirect) of the webpage can be determined. According to the redirect path, the external domain name, the home location information of the domain name, and the filing information of the redirect can be determined. If the external domain name of the HTTP redirect lacks filing information, or among multiple external domain names, the proportion of unfiled domain names is higher than a certain ratio (for example, 50%), it can be determined that the dynamic behavior characteristics indicate that the webpage is abnormal.
[0043] In operation S240, determine a detection result indicating whether the website is abnormal according to at least one of semantic consistency, text category, and dynamic behavior characteristics.
[0044] In one embodiment, the semantic consistency score can be obtained by calculating the semantic consistency between the site attributes and the web page text, and whether the website is abnormal can be detected according to the semantic consistency score.
[0045] For example, the semantic consistency score between the site attributes of website A and the web page text is 90 points, and the site attributes of website A are close to the web page text, so it can be determined that the website detection result is normal.
[0046] In another embodiment, whether the website is abnormal can also be determined by determining the text category of the web page text content.
[0047] For example, there is risk text in the web page text content. The risk text is a keyword related to illegal behavior A, but the intention type of the risk text determined according to the context of the risk text is to popularize the harm of behavior A, so it can be determined that the text category of the web page text content is normal text and the website detection result is normal.
[0048] In another embodiment, whether the website is abnormal can also be detected by determining the abnormality degree of the dynamic behavior characteristics of the web page.
[0049] For example, the dynamic behavior characteristics indicate that the number of redirects of the web page is three times, and two of the external domain names lack record filing information, so it can be determined that the website detection result is abnormal.
[0050] In the embodiments of the present disclosure, the detection result indicating whether the website is abnormal can be comprehensively determined according to multiple features among semantic consistency, text category, and dynamic behavior characteristics. According to actual requirements, the website can be determined to be an abnormal website when multiple features all meet the abnormal conditions, or the website can be determined to be an abnormal website when at least one of the multiple features meets the abnormal conditions.
[0051] According to the embodiments of the present disclosure, by collecting multi-dimensional feature information of the website and detecting whether the website has abnormalities or risks according to multiple features such as the site attributes, text content, and jump information of the website, the accuracy of website detection is improved.
[0052] Figure 3 It is a schematic diagram of determining the text category of the web page text content according to an embodiment of the present disclosure.
[0053] According to an embodiment of the present disclosure, determining the text category of the web page text content 301 includes: determining the intent type of the risk text 302 according to the context of the risk text 302 in the web page text content 301; in response to the intent type being the promotion type 303, determining the text category as the abnormal text 305; and in response to the intent type being the non-promotion type 304, determining the text category as the normal text 306.
[0054] The risk text 302 may refer to keywords related to violations in the web page text content 301. The risk text 302 can be extracted from the web page text content. For example, the risk text 302 may include keywords related to violation A, keywords related to violation B, etc.
[0055] In an embodiment of the present disclosure, the intent type of the risk text 302 can be determined by the first large model 310. The prompt words of the first large model 310 may include discrimination rules for violation content. Specifically, it may include discrimination rules for various violation contents.
[0056] For example, for violation A, the prompt words of the first large model 310 may include: information related to the active promotion, encouragement to participate, or provision of services related to violation A should be classified as content belonging to violation A. Note that content that simply describes, discusses, reports, or conducts cultural analysis of behavior A should be carefully judged according to the context and purpose. The prompt words of the first large model 310 may also include discrimination prompt words for various violation contents such as violation B.
[0057] For example, the prompt words of the first large model 310 may also include discrimination rules for normal content. For example, the prompt words of the first large model 310 may also include: content that does not belong to preset violations (such as behavior A, behavior B, etc.) includes daily communication, news, educational materials, etc. Content related to film and television dramas or entertainment videos (even if it contains plots or terms related to violation A or B), such as movies, TV dramas, videos on video sharing platforms, should be classified as normal content.
[0058] According to the above prompt words, the first large model 310 can discriminate the intent type of the risk text, and the intent type is one of the promotion type 303 and the non-promotion type 304. For example, if the risk text 302 is a keyword of violation A, and the first large model 310 discriminates that the role of the risk text in the web page text content 301 is to popularize the harm of behavior A, the intent type can be determined as the non-promotion type. If the first large model 310 discriminates that the role of the risk text in the web page text content 301 is to encourage users to participate in violation A, the intent type can be determined as the promotion type.
[0059] The text category of the web page text content 301 can be determined according to the intention type. For example, when the intention type is determined to be the promotion type 303, the text category of the web page text content 301 can be determined as the abnormal text 305, and when the intention type is determined to be the non-promotion type 304, the text category of the web page text content 301 can be determined as the normal text 306.
[0060] It should be noted that when the intention type is the promotion type 303, according to the promotion categories of different violation behaviors, the abnormal text can be specifically classified into violation behavior A text, violation behavior B text, etc.
[0061] According to the embodiments of the present disclosure, when it is detected that the web page text content contains risk texts such as violation behavior keywords, the embodiments of the present disclosure do not directly determine the website as an abnormal website, but further determine the text category of the web page text content by determining whether the intention type of the risk text is the promotion type or the non-promotion type, which can improve the accuracy of text category determination and reduce the misjudgment probability of detecting whether the website has been hacked.
[0062] Figure 4 It is a schematic diagram of a website detection method according to an embodiment of the present disclosure.
[0063] As Figure 4 shown, the site attribute information 411, the web page text content 412, the risk text 413, the source code script content 414, and the source code external link information 415 of the website 410 can be obtained according to the website 410.
[0064] In the embodiments of the present disclosure, the site attribute information 411 may include the record description information. The record description information may refer to the text information describing the permitted uses and content types of the website.
[0065] Determining the semantic consistency between the site attribute and the web page text according to the site attribute information 411 of the website and the web page text content 412 may include: determining the semantic similarity between the record description information and the web page text content 412; and determining the semantic consistency 421 according to the semantic similarity.
[0066] In the embodiments of the present disclosure, the semantic similarity can be determined by calculating the text distance between the record description information and the web page text content 412 as the semantic consistency. For example, the record description information and the web page text content 412 can be converted into vectors, and the distance between the vectors can be calculated to determine the semantic similarity.
[0067] The semantic consistency 421 can be classified according to semantic similarity. For example, the levels of semantic consistency 421 can include three levels: strong, medium, and weak. If the semantic similarity between the record-filing description information and the web page text content 412 is greater than the first threshold (e.g., 80%), the level of semantic consistency 421 can be determined to be strong. If the similarity between the record-filing description information and the web page text content 412 is not greater than the first threshold but greater than the second threshold (e.g., 50%), the level of semantic consistency 421 can be determined to be medium. If the semantic similarity between the record-filing description information and the web page text content 412 is less than or equal to the second threshold, the level of semantic consistency 421 can be determined to be weak.
[0068] For the web page text content 412, a first large model can be used to determine the text category 422. For example, risk text 413 involving keywords of illegal behaviors is extracted from the web page text content 412, and the first large model is used to determine the intent type based on the context of the risk text 413. In the case where the intent type is the promotion type, the text category 422 is determined to be abnormal text. In the case where the intent type is the non-promotion type, the text category 422 is determined to be normal text.
[0069] In the embodiments of the present disclosure, the dynamic behavior features can include malicious script features and the abnormality degree of jump behaviors; determining the dynamic behavior features of a web page according to the source code of the website includes: determining the malicious script features of the web page according to the script content in the source code; and determining the abnormality degree of the jump behaviors of the web page according to the external link information in the source code.
[0070] For example, the HTML source code can include script tags and iframe tags. The content in the script tags can be extracted from the HTML source code to obtain the source code script content 414. The content in the iframe tags can be extracted from the HTML source code to obtain the source code external link information 415.
[0071] The malicious script features 423 can be determined according to the source code script content 414. For example, if the source code script content 414 is code for obtaining user information without the user's permission, it can be determined that the source code script content 414 is a malicious script.
[0072] In the embodiments of the present disclosure, determining the abnormality degree of the jump behaviors of the web page according to the source code external link information 415 includes: determining the abnormality degree of the jump behaviors according to at least one of the number of external link jumps, the proportion of external links with unrecorded domain names, and the domain name belonging place of the last-level external link in multi-level external links.
[0073] For example, if the number of external link jumps is greater than or equal to 1 and the final domain name is overseas, it can be determined that the abnormality degree of the jump behaviors is 90%, indicating that the website has a high risk of being hacked.
[0074] In an embodiment of the present disclosure, the second large model 430 can be used to generate a detection result based on site attribute information, semantic consistency 421, text category 422, malicious script features 423, and the anomaly degree of jump behavior 424. For example, the site attribute information, semantic consistency 421, text category 422, malicious script features 423, and the anomaly degree of jump behavior 424 are integrated into a prompt template to obtain prompt information; an instruction for indicating that the second large model 430 generates a detection result and the determination basis of the detection result is determined; and the prompt information and the instruction are input into the large model to obtain the detection result 440 generated by the large model and the determination basis of the detection result.
[0075] The prompt information may refer to descriptive information formed by presenting the information of the website in a manner convenient for the large model to understand and analyze. The instruction may refer to request information input in a manner convenient for the large model to understand.
[0076] For example, the prompt template may be: The site attribute information of the website is XX. The level of semantic consistency is X. The text category is normal / anomalous. The source code is XXX. The number of external link jumps is N times. The proportion of unrecorded external links in the domain name is x%. The domain name attribution of the last-level external link in multi-level external links is within / outside the country. The instruction may be: You are a website detector. Please detect whether the website has been hacked based on the above content and generate the determination basis of the detection result.
[0077] In an embodiment of the present disclosure, by integrating the features of multiple dimensions of the website to obtain prompt information, and inputting the prompt information and the instruction into the large model together, the large model can output the detection result and the discrimination basis of the detection result, making the detection result highly interpretable.
[0078] According to an embodiment of the present disclosure, by utilizing the generalization ability of the large model and based on zero-shot and a small amount of information features, it is possible to determine whether there is an anomaly in the website, which can reduce the model deployment cost and improve the website detection efficiency.
[0079] According to an embodiment of the present disclosure, the present disclosure also provides a website detection device.
[0080] Figure 5 It is a block diagram of a website detection device according to an embodiment of the present disclosure.
[0081] As Figure 5 shown, the website detection device 500 includes a semantic consistency determination module 510, a text category determination module 520, a dynamic behavior feature determination module 530, and a detection module 540.
[0082] The semantic consistency determination module 510 is used to determine the semantic consistency between the site attribute and the web page text according to the site attribute information of the website and the web page text content.
[0083] The text category determination module 520 is configured to determine the text category of the web page text content according to the intent type of the risk text in the web page text content.
[0084] The dynamic behavior feature determination module 530 is configured to determine the dynamic behavior features of the web page according to the source code of the website.
[0085] The detection module 540 is configured to determine a detection result indicating whether the website is abnormal according to at least one of semantic consistency, text category, and dynamic behavior features.
[0086] According to an embodiment of the present disclosure, the site attribute information includes record-filing description information, and the semantic consistency determination module 510 includes a semantic similarity determination sub-module and a semantic consistency determination sub-module.
[0087] The semantic similarity determination sub-module is configured to determine the semantic similarity between the record-filing description information and the web page text content. The semantic consistency determination sub-module is configured to determine semantic consistency according to the semantic similarity.
[0088] According to an embodiment of the present disclosure, the text category is one of abnormal text and normal text, and the text category determination module 520 includes an intent determination sub-module, a first type determination sub-module, and a second type determination sub-module.
[0089] The intent determination sub-module is configured to determine the intent type of the risk text according to the context of the risk text in the web page text content. The first type determination sub-module is configured to determine the text category as abnormal text in response to the intent type being the promotion type. The second type determination sub-module is configured to determine the text category as normal text in response to the intent type being a non-promotion type.
[0090] According to an embodiment of the present disclosure, the dynamic behavior features include malicious script features and abnormal jump behavior degree; the dynamic behavior feature determination module 530 includes a malicious script feature determination sub-module and an abnormal degree determination sub-module.
[0091] The malicious script feature determination sub-module is configured to determine the malicious script features of the web page according to the script content in the source code. The abnormal degree determination sub-module is configured to determine the abnormal jump behavior degree of the web page according to the external link information in the source code.
[0092] According to an embodiment of the present disclosure, the abnormal degree determination sub-module includes an abnormal degree determination unit. The abnormal degree determination unit is configured to determine the abnormal jump behavior degree according to at least one of the number of external link jumps, the proportion of unrecorded external links in the domain names, and the domain name ownership of the last-level external link in the multi-level external links.
[0093] According to an embodiment of the present disclosure, the detection module 540 includes a generation sub-module. The generation sub-module is configured to generate a detection result using a large model based on site attribute information, semantic consistency, text category, and dynamic behavior characteristics.
[0094] According to an embodiment of the present disclosure, the generation sub-module includes an integration unit, an instruction determination unit, and a detection unit.
[0095] The integration unit is configured to integrate the site attribute information, semantic consistency, text category, and dynamic behavior characteristics into a prompt template to obtain prompt information. The instruction determination unit is configured to determine an instruction for instructing the large model to generate a detection result and the basis for determining the detection result. The detection unit is configured to input the prompt information and the instruction into the large model to obtain the detection result generated by the large model and the basis for determining the detection result.
[0096] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0097] Figure 6 FIG. shows a schematic block diagram of an exemplary electronic device 600 that can be used to implement the embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0098] As Figure 6 shown, the device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0099] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as a keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as a disk, optical disc, etc.; and communication unit 609, such as a network card, modem, wireless communication transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0100] Computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 601 executes the various methods and processes described above, such as the website detection method. For example, in some embodiments, the website detection method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by computing unit 601, one or more steps of the website detection method described above can be executed. Alternatively, in other embodiments, computing unit 601 can be configured to execute the website detection method in any other suitable manner (e.g., by means of firmware).
[0101] The various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0102] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0103] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0104] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and the input received from the user can be in any form (including acoustic input, speech input, or tactile input).
[0105] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0106] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs that run on the respective computers and have a client-server relationship with each other.
[0107] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.
[0108] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A website detection method, comprising: Determining the semantic consistency between the site attributes and the web page text according to the site attribute information of the website and the web page text content; Determining the text category of the web page text content according to the intent type of the risk text in the web page text content; Determining the dynamic behavior characteristics of the web page according to the source code of the website; And Determining a detection result indicating whether the website is abnormal according to at least one of the semantic consistency, the text category, and the dynamic behavior characteristics.
2. The method according to claim 1, wherein The site attribute information includes record-filing description information; the determining the semantic consistency between the site attributes and the web page text according to the site attribute information of the website and the web page text content includes: Determining the semantic similarity between the record-filing description information and the web page text content; and Determining the semantic consistency according to the semantic similarity.
3. The method according to claim 1, wherein, The text category is one of abnormal text and normal text; the determining the text category of the web page text content according to the intent type of the risk text in the web page text content includes: Determining the intent type of the risk text according to the context of the risk text in the web page text content; In response to the intent type being a promotion type, determining the text category as abnormal text; and In response to the intent type being a non-promotion type, determining the text category as normal text.
4. The method according to claim 1, wherein, The dynamic behavior characteristics include malicious script characteristics and jump behavior abnormality; the determining the dynamic behavior characteristics of the web page according to the source code of the website includes: Determining the malicious script characteristics of the web page according to the script content in the source code; and Determining the jump behavior abnormality of the web page according to the external link information in the source code.
5. The method according to claim 4, wherein The determining the jump behavior abnormality of the web page according to the external link information in the source code includes: Determining the jump behavior abnormality according to at least one of the number of external link jumps, the proportion of external links with unrecorded domains, and the domain ownership of the last-level external link in multi-level external links.
6. The method according to claim 1, wherein The determining a detection result indicating whether the website is abnormal according to at least one of the semantic consistency, the text category, and the dynamic behavior characteristics includes: Using a large model to generate the detection result based on the site attribute information, semantic consistency, text category, and dynamic behavior characteristics.
7. The method according to claim 6, wherein, The using a large model to generate the detection result based on the site attribute information, semantic consistency, text category, and dynamic behavior characteristics includes: Integrating the site attribute information, semantic consistency, text category, and dynamic behavior characteristics into a prompt template to obtain prompt information; Determining an instruction for instructing the large model to generate a detection result and the basis for determining the detection result; and Inputting the prompt information and the instruction into the large model to obtain the detection result generated by the large model and the basis for determining the detection result.
8. A website detection device, comprising: A semantic consistency determination module, configured to determine the semantic consistency between the site attributes and the web page text according to the site attribute information of the website and the web page text content; A text category determination module, configured to determine the text category of the web page text content according to the intent type of the risk text in the web page text content; A dynamic behavior feature determination module, configured to determine the dynamic behavior features of a web page according to the source code of the website; And A detection module, configured to determine a detection result indicating whether the website is abnormal according to at least one of the semantic consistency, the text category, and the dynamic behavior features.
9. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, the computer program being stored on at least one of a readable storage medium and an electronic device, and the computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.