Network address detection method and device, readable medium, electronic equipment and product

By comparing the memory snapshot information of the browser's built-in functions, detecting the abnormality of the network address, the problem of the inability to fully cover potential network threats in the existing technology is solved, and the precise detection of the browser's built-in functions is achieved, and the system security is improved.

CN120455161APending Publication Date: 2025-08-08BYTEDANCE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510884173.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The prior art cannot fully cover potential network security threats, especially the inability to detect low-level coverage operations or machine code tampering within the browser engine, and relies on exception lists and URL sandbox detection to detect false positives and vulnerabilities.

Method used

By obtaining the memory snapshot information of the browser's built-in functions, we can detect whether the network address is abnormal, including the comparison of rendering and memory snapshots of script engine functions, and identify unauthorized modifications.

Benefits of technology

It significantly improves the coverage of abnormal detection, can promptly identify unauthorized modifications of browser built-in functions, and provides strong system security guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455161A_ABST
    Figure CN120455161A_ABST
Patent Text Reader

Abstract

The invention discloses a network address detection method and device, a readable medium, electronic equipment and a product. The detection method comprises the following steps: acquiring a to-be-detected first network address; obtaining memory snapshot information corresponding to a built-in function of the browser, wherein the memory snapshot information comprises first memory snapshot information corresponding to the built-in function before the browser loads the first network address and second memory snapshot information corresponding to the built-in function after the browser loads the first network address; the first memory snapshot information and the second memory snapshot information are compared, a detection result of the first network address is obtained, and the detection result is used for representing whether the first network address is abnormal or not. By comparing the memory snapshot information of the built-in function of the browser before and after the network address is loaded, any unauthorized modification of the built-in function of the browser can be accurately detected, and the coverage range of anomaly detection is remarkably expanded, so that powerful guarantee is provided for system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a method, device, readable medium, electronic device, and product for detecting a network address. Background Art

[0002] A URL (Uniform Resource Locator) is an address identifier used to identify the location of a specific resource on the Internet. With the rapid development of the Internet, cyberspace is flooded with a massive number of URLs, many of which contain malicious links. These malicious links may spread malware, commit online fraud, and pose a huge threat to network security.

[0003] In related technologies, the URL detection method that relies on anomaly lists cannot detect abnormal URLs that have not yet been discovered, and the URL detection method that detects anomalies by detecting the calls of application programming interfaces cannot detect low-level overwriting operations within the browser engine or direct tampering with machine code. It cannot fully cover potential security threats and has certain security loopholes. Summary of the Invention

[0004] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides a method for detecting a network address, the method comprising: Obtaining a first network address to be detected; Obtaining memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; The first memory snapshot information and the second memory snapshot information are compared to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

[0006] In a second aspect, the present disclosure provides a device for detecting a network address, the device comprising: An acquisition module, configured to acquire a first network address to be detected; a snapshot module, configured to obtain memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address, and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; A comparison module is used to compare the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which implements the steps of the method described in the first aspect when executed by a processing device.

[0008] In a fourth aspect, the present disclosure provides an electronic device, comprising: a storage device having a computer program stored thereon; A processing device is used to execute the computer program in the storage device to implement the steps of the method in the first aspect.

[0009] In a fifth aspect, the present disclosure provides a computer program product, comprising a computer program, which implements the steps of the method described in the first aspect when executed by a processor.

[0010] Through the above technical solution, it is possible to obtain first memory snapshot information corresponding to a built-in function of the browser before loading the first network address, and second memory snapshot information corresponding to the built-in function of the browser after loading the first network address. Then, by comparing the first memory snapshot information and the second memory snapshot information, a detection result is obtained that indicates whether the first network address is abnormal. By using this method, by comparing the memory snapshot information of the browser's built-in functions before and after loading the network address, any unauthorized modifications to the browser's built-in functions can be accurately detected. Regardless of the hook mechanism used for the abnormal network address, it can be promptly and effectively identified during the browser loading process, significantly improving the coverage of anomaly detection and thus providing strong protection for system security.

[0011] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1is a schematic flow chart of a method for detecting a network address according to an exemplary embodiment of the present disclosure; Figure 2 is a structural diagram of a network address detection system according to an exemplary embodiment of the present disclosure; Figure 3 is a structural block diagram of a network address detection device according to an exemplary embodiment of the present disclosure; Figure 4 The figure is a schematic structural diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION

[0013] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0014] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0015] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.

[0016] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0017] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0018] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0019] It is understandable that before using the technical solutions disclosed in the various embodiments of this disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0020] For example, in response to a user's active request, a prompt message is sent to the user to clearly inform the user that the operation requested will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the electronic device, application, server, storage medium, or other software or hardware that performs the operations of the disclosed technical solution based on the prompt message.

[0021] As an optional but non-limiting implementation, in response to receiving a user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. Furthermore, the pop-up window may also contain a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0022] It is understandable that the above notification and user authorization process are merely illustrative and do not limit the implementation of the present disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0023] At the same time, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.

[0024] Related technologies rely on URL detection methods based on anomaly lists, which can only detect known hook signatures that have been recorded in the anomaly list, but cannot detect new or undiscovered hook signatures. Furthermore, when attackers obfuscate hook signatures, their characteristics change, making it difficult for detectors to identify these disguised anomaly URLs. Furthermore, heuristic detection methods based on anomaly lists are subject to false positives and maintenance difficulties.

[0025] The URL detection method that detects anomalies by detecting the calls to the application programming interface lacks architectural awareness and mainly focuses on the calls to the upper-level interface. It is difficult to detect modifications at the underlying code level, such as low-level overwrite operations within the browser engine or direct tampering with the machine code.

[0026] Furthermore, attackers can bypass anomaly detection through dynamic script injection. Specifically, attackers conditionally deliver seemingly benign content based on the execution context. In the sandbox environment used for URL detection, this content will not trigger any detection mechanisms. However, once these scripts are loaded into the real user environment, they will exhibit malicious behavior based on the preset conditions.

[0027] Detection technologies that rely on URL sandboxes and automated scanning tools often identify anomaly indicators by crawling and rendering web pages in a controlled environment, collecting DOM (Document Object Model) structures, network calls, and script-generated artifacts. However, front-end evasion techniques, such as tampering with browser engine functions at runtime, render anomaly detection ineffective, resulting in an inability to fully cover potential security threats and leaving certain security vulnerabilities.

[0028] In view of this, the present disclosure provides a method, device, readable medium, electronic device and product for detecting a network address to solve the above technical problems.

[0029] The following further explains the embodiments of the present disclosure with reference to the accompanying drawings.

[0030] Figure 1 is a flow chart of a method for detecting a network address according to an exemplary embodiment of the present disclosure, with reference to Figure 1 , the detection method may include the following steps: S101: Acquire a first network address to be detected.

[0031] The network address may refer to a URL that needs to be detected, or may be a network address in other forms, which may be determined based on the business scenario and is not limited in this disclosure.

[0032] S102: Obtain memory snapshot information corresponding to a built-in function of the browser, wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address.

[0033] In a possible manner, the built-in function of the browser includes a rendering engine function and / or a script engine function.

[0034] For example, the built-in functions of a browser are predefined functions provided by the browser engine, which are used to implement various functions. The browser engine includes a rendering engine, a scripting engine, etc., which can be specifically determined according to the business scenario, and this disclosure does not impose any restrictions on this.

[0035] It should be understood that in related technologies, evading detection by tampering with browser engine functions will cause memory changes of the corresponding functions. Therefore, the memory snapshot information of the built-in function after the browser loads the network address can be obtained as detection data to determine whether the browser engine function has been tampered with, and then determine whether the network address is abnormal.

[0036] This makes it possible to detect zero-day vulnerabilities or customized hook signatures without pre-determining anomaly lists, significantly improving the coverage of anomaly detection and reducing false positives and maintenance overhead of heuristic detection methods.

[0037] S103: Compare the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

[0038] By using the above method, by comparing the memory snapshot information of the browser's built-in functions before and after loading the network address, any unauthorized modification of the browser's built-in functions can be accurately detected. No matter what hook mechanism is used for the abnormal network address, it can be identified in a timely and effective manner during the browser loading process, significantly improving the coverage of anomaly detection, thereby providing strong protection for system security.

[0039] Figure 2 FIG. 1 is an architecture diagram of a network address detection system according to an exemplary embodiment of the present disclosure. Figure 2 As shown, the detection system includes a controller, a snapshot manager, an execution engine, and a comparison module. The controller is connected to the snapshot manager, the execution engine, and the comparison module respectively, and the snapshot manager is connected to the execution model and the comparison module respectively.

[0040] For example, the controller is used to control the snapshot manager to obtain memory snapshots, control the execution engine to load URLs, and control the comparison module to compare memory snapshots. In addition, the detection results representing URL anomalies can be uploaded to the downstream analysis system for anomaly analysis or visual display. The specific settings can be based on needs, and this disclosure does not impose any restrictions on this.

[0041] It should be noted that Figure 2 The two snapshot managers shown in the figure illustrate the process of acquiring two memory snapshots. In practice, the same snapshot manager can be used to acquire both memory snapshots. The snapshot manager can be injected into the browser's page loading process, and using the browser's built-in function identifier, it retrieves the memory snapshot information corresponding to the built-in function and transmits the memory snapshot information to the comparison module. The comparison module compares the two acquired memory snapshots and outputs the corresponding comparison results.

[0042] For example, the execution engine can be an automated tool or instance that can load URLs and execute corresponding scripts in the background (headless mode). In addition, to avoid page loading failures, a timeout period or loading completion condition can be set.

[0043] The detection method provided by the embodiment of the present disclosure is described in detail below in conjunction with the above-mentioned detection system.

[0044] In a possible embodiment, the browser has multiple built-in functions, and obtaining memory snapshot information corresponding to the built-in functions of the browser includes: traversing the multiple built-in functions to obtain memory snapshot information corresponding to each built-in function. Comparing the first memory snapshot information with the second memory snapshot information to obtain a detection result for the first network address includes: for each built-in function, comparing the first memory snapshot information with the second memory snapshot information to obtain a detection sub-result for the built-in function; wherein the detection sub-result is used to indicate whether the first memory snapshot information and the second memory snapshot information of the built-in function are consistent; and obtaining a detection result for the first network address based on the detection sub-result of each built-in function.

[0045] For example, a browser usually has multiple built-in functions, and a list of built-in functions for which memory snapshot information needs to be obtained can be pre-built. The built-in function list includes built-in function identifiers corresponding to the built-in functions. It can be all built-in functions of the browser, or it can be selected as needed. This disclosure does not limit this.

[0046] Furthermore, the snapshot manager can sequentially obtain the memory snapshot information corresponding to each built-in function according to the built-in function list to avoid omissions.

[0047] In addition, the comparison module needs to obtain two memory snapshots of each built-in function and compare them to obtain the corresponding detection sub-results. If the memory snapshots obtained twice for any built-in function are inconsistent, it means that loading the network address has tampered with the browser's function, and the network address is then determined to be an abnormal network address. If the memory snapshots obtained twice for all built-in functions are consistent, it means that loading the network address has not tampered with the browser's function, and the network address is then determined to be a normal network address. This can accurately detect any unauthorized modifications to the browser's built-in functions, significantly improving the coverage of anomaly detection and providing strong protection for system security.

[0048] In a possible embodiment, the detection method further includes: parsing an offset address and a module base address corresponding to the built-in function, and determining a memory address of the built-in function based on the offset address and the module base address, wherein the module base address represents a starting address of the built-in function in memory, and the offset address represents a relative offset between the memory address of the built-in function and the module base address. Obtaining memory snapshot information corresponding to the built-in function of the browser includes: obtaining the memory snapshot information corresponding to the built-in function from the memory address.

[0049] It should be noted that the browser will randomize the memory addresses of built-in functions based on ASLR (Address Space Layout Randomization) technology, so it is necessary to parse the actual memory address of the built-in function to obtain the corresponding memory snapshot information.

[0050] For example, the module base address represents the starting address of the built-in function in the memory. Based on the starting address, the relative offset between the memory address of the built-in function and the module base address is added to determine the real memory address of the built-in function, and then the memory snapshot information corresponding to the built-in function is read from the memory address, thereby avoiding memory snapshot information reading errors.

[0051] It is worth noting that, in the process of reading the memory snapshot information corresponding to the built-in function twice, the snapshot manager can store the read memory snapshot information into a preset buffer, and then select the data to be compared according to the needs to construct a data tuple and transmit it to the comparison module. For example, the data tuple of (built-in function identifier, memory address, summary) can be stored, and the summary is the encrypted memory snapshot information. The specific setting can be based on the needs, and the present disclosure does not impose any restrictions on this, thereby reducing data redundancy and improving comparison efficiency.

[0052] In a possible embodiment, the detection method further includes: loading a first network address in a browser via a first thread, and loading the second network address in the browser via a second thread when a loaded page corresponding to the first network address includes the second network address. Obtaining memory snapshot information corresponding to a built-in function of the browser includes: after the browser completes loading the first network address and the second network address, obtaining second memory snapshot information corresponding to the built-in function via the first thread and the second thread.

[0053] For example, after a browser loads a network address, a new network address may appear in the browser page. That is, a new URL may be nested within the URL. In this case, a new thread can be started to continue loading the new network address. Therefore, after loading the network address and the new network address, the snapshot manager can coordinate the reading of memory snapshot information corresponding to built-in functions across multiple renderer threads to avoid misjudgments caused by incomplete reading of memory snapshot information, further improving the accuracy and reliability of anomaly detection.

[0054] It should be understood that before instructing the execution engine to load the network address, the controller first instructs the snapshot manager to read the memory snapshot information corresponding to the built-in function. It then instructs the execution engine to load the network address. The execution engine captures network traffic while independently rendering the page, so that all injected hooks and code coverage are executed within the same process context. After loading is complete, the snapshot manager is again instructing the snapshot manager to read the memory snapshot information corresponding to the built-in function. These two memory snapshots are then transmitted to the comparison module as the data to be compared, and the final detection results are obtained.

[0055] It should be noted that this embodiment can pre-store the memory snapshot information corresponding to the built-in functions of the browser. In this way, after the network address to be detected is loaded, the memory snapshot information corresponding to the built-in function can be obtained and compared with the stored memory snapshot information, thereby reducing the memory snapshot information acquisition process once and improving the efficiency of anomaly detection.

[0056] Alternatively, when detecting each network address, you can first obtain memory snapshot information, and then obtain memory snapshot information again after the network address is loaded. In this way, the memory snapshot information for each comparison is new, avoiding misjudgment caused by changes in memory snapshot information due to browser updates, and improving the accuracy and reliability of anomaly detection.

[0057] Alternatively, different identifiers can be used to distinguish static functions and dynamic functions for the above data tuples. Static functions usually refer to functions that have been determined not to change at runtime before the program runs, and dynamic functions usually refer to functions that will change while the program runs. Therefore, for static functions, memory snapshot information can be stored in advance and obtained once after the network address is loaded. For dynamic functions, memory snapshot information needs to be obtained once before and after the network address is loaded. By obtaining memory snapshot information on demand, data redundancy is avoided and the efficiency of anomaly detection is improved.

[0058] In a possible manner, the first memory snapshot information and the second memory snapshot information are compared to obtain a detection result of the first network address, including: determining the first memory data in the first memory snapshot information and the second memory data in the second memory snapshot information; comparing the first memory data and the second memory data in bytes, and when the first memory data and the second memory data are inconsistent, determining a detection result characterizing an abnormality of the first network address.

[0059] The first memory data and the second memory data are corresponding numerical data, and / or the first memory data and the second memory data are corresponding operation data, and the operation data is memory data corresponding to the control flow in the built-in function.

[0060] It's important to note that memory snapshot information can include numerical data, which refers to the memory contents storing actual data—specific data values generated when a built-in function runs. Memory snapshot information can also include control flow operation data. Control flow operation data refers to data related to the execution process of a built-in function, used to control the execution order and logic of the built-in function. Changes to the process will also cause changes to the operation data.

[0061] For example, continue to refer to Figure 2 The comparison module can compare the memory data obtained twice in byte units. If there is a difference, the network address can be determined to be an abnormal network address. Therefore, based on the difference in byte units, it can be accurately located whether there is modified memory data, improving the accuracy of anomaly detection. In addition, by comparing the operation data corresponding to the control flow obtained twice, the integrity of the control flow can be verified. If there is a difference, it can be determined that loading the network address will tamper with the control flow of the built-in function. In this case, the network address can be determined to be an abnormal network address, which improves the coverage of anomaly detection and further improves the reliability of anomaly detection.

[0062] In a possible manner, the first memory snapshot information and the second memory snapshot information are compared to obtain a detection result of the first network address, including: determining a first function pointer table in the first memory snapshot information and a second function pointer table in the second memory snapshot information; when the first function pointer table and the second function pointer table are inconsistent, determining a detection result characterizing an abnormality of the first network address.

[0063] For example, the memory snapshot information can also include a function pointer table. By comparing the function pointer tables obtained twice, if there is a difference, it can be determined that loading the network address will tamper with the function pointer table of the built-in function, and the network address can be determined to be an abnormal network address, further improving the coverage of anomaly detection.

[0064] In a possible manner, the first memory snapshot information and the second memory snapshot information are compared to obtain a detection result of the first network address, including: determining a first encrypted digest after the first memory snapshot information is encrypted and a second encrypted digest after the second memory snapshot information is encrypted; when the first encrypted digest is inconsistent with the second encrypted digest, determining a detection result characterizing an abnormality of the first network address.

[0065] For example, to protect data privacy and security, if the specific memory snapshot information cannot be obtained, the encrypted digest corresponding to the memory snapshot information can be obtained for comparison. This is because if loading a network address tampered with the memory snapshot information, the corresponding encrypted digest would also be inconsistent. Therefore, by comparing the memory encrypted digests before and after loading the network address, it is possible to determine whether the network address is abnormal. This allows for the detection of network address anomalies while protecting data privacy and security.

[0066] It is worth noting that when the detection result output by the comparison module indicates that the network address is an abnormal network address, a more in-depth anomaly analysis can be performed. For example, when the detection result obtained by anomaly detection in a sandbox environment indicates that the network address is an abnormal network address, the network address is loaded in a simulation environment to accurately locate the content that will be tampered with by loading the network address.

[0067] For example, the above-mentioned method of bypassing anomaly detection through dynamic script injection, although it is possible to determine whether there is an anomaly in the network address through the detection method provided by this embodiment, since unauthorized modifications will not be triggered in the sandbox environment, the specific modification content cannot be determined. In this case, by loading the network address in a simulation environment, unauthorized modifications can be triggered, and then the content that will be tampered with by loading the network address can be accurately located, so that the anomaly network address can be further analyzed, such as determining the impact scope of the anomaly network address.

[0068] Based on the same concept, the embodiment of the present disclosure also provides a network address detection device, such as Figure 3 As shown, the detection device 300 may include: An acquisition module 301 is configured to acquire a first network address to be detected; The snapshot module 302 is configured to obtain memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address, and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; The comparison module 303 is configured to compare the first memory snapshot information with the second memory snapshot information to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

[0069] Optionally, the comparison module 303 is used to: Determining first memory data in the first memory snapshot information and second memory data in the second memory snapshot information; The first memory data and the second memory data are compared in bytes, and when the first memory data and the second memory data are inconsistent, a detection result indicating that the first network address is abnormal is determined.

[0070] Optionally, the first memory data and the second memory data are corresponding numerical data, and / or the first memory data and the second memory data are corresponding operation data, and the operation data is memory data corresponding to the control flow in the built-in function.

[0071] Optionally, the comparison module 303 is used to: Determining a first function pointer table in the first memory snapshot information and a second function pointer table in the second memory snapshot information; In a case where the first function pointer table is inconsistent with the second function pointer table, a detection result indicating that the first network address is abnormal is determined.

[0072] Optionally, the comparison module 303 is used to: Determine a first encrypted digest of the first memory snapshot information encrypted and a second encrypted digest of the second memory snapshot information encrypted; In a case where the first encryption digest is inconsistent with the second encryption digest, a detection result indicating that the first network address is abnormal is determined.

[0073] Optionally, the anomaly detection device 300 may further include an analysis module, wherein the analysis module is configured to: Parsing an offset address and a module base address corresponding to the built-in function, and determining a memory address of the built-in function based on the offset address and the module base address, wherein the module base address represents a starting address of the built-in function in the memory, and the offset address represents a relative offset between the memory address of the built-in function and the module base address; The acquisition module 301 is used to: Memory snapshot information corresponding to the built-in function is obtained from the memory address.

[0074] Optionally, the anomaly detection device 300 may further include a loading module, wherein the loading module is configured to: loading the first network address in the browser through a first thread, and loading the second network address in the browser through a second thread when the loading page corresponding to the first network address includes the second network address; The acquisition module 301 is used to: After the browser completes loading the first network address and the second network address, second memory snapshot information corresponding to the built-in function is obtained through the first thread and the second thread.

[0075] Optionally, the browser has multiple built-in functions, and the acquisition module 301 is used to: Traversing the plurality of built-in functions, and obtaining memory snapshot information corresponding to each of the built-in functions; The comparison module 303 is used to: For each of the built-in functions, comparing the first memory snapshot information and the second memory snapshot information to obtain a detection sub-result of the built-in function; wherein the detection sub-result is used to indicate whether the first memory snapshot information and the second memory snapshot information of the built-in function are consistent; The detection result of the first network address is obtained according to the detection sub-results of each built-in function.

[0076] Optionally, the built-in functions of the browser include rendering engine functions and / or script engine functions.

[0077] Based on the same concept, an embodiment of the present disclosure further provides a computer-readable medium having a computer program stored thereon, which implements the steps of any of the above-mentioned methods for detecting a network address when executed by a processing device.

[0078] Based on the same concept, an embodiment of the present disclosure further provides an electronic device, which may include: a storage device having a computer program stored thereon; The processing device is used to execute the computer program in the storage device to implement the steps of any of the above-mentioned network address detection methods.

[0079] Based on the same concept, an embodiment of the present disclosure further provides a computer program product, including a computer program, which implements the steps of any of the above-mentioned network address detection methods when executed by a processor.

[0080] Reference below Figure 4, which shows a schematic structural diagram of an electronic device 400 suitable for implementing an embodiment of the present disclosure. The terminal device in the embodiment of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0081] like Figure 4 As shown, electronic device 400 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 401, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 402 or programs loaded from a storage device 408 into a random access memory (RAM) 403. Various programs and data required for the operation of electronic device 400 are also stored in RAM 403. Processing device 401, ROM 402, and RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to bus 404.

[0082] Typically, the following devices may be connected to the I / O interface 405: an input device 406 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 408 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 409. The communication device 409 may allow the electronic device 400 to communicate with other devices wirelessly or by wire to exchange data. Figure 4 The electronic device 400 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0083] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 409, or installed from the storage device 408, or installed from the ROM 402. When the computer program is executed by the processing device 401, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.

[0084] It should be noted that the computer-readable medium described above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.

[0085] In some embodiments, communications may be conducted using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.

[0086] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0087] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: obtains a first network address to be detected; obtains memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; compares the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

[0088] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0089] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0090] The modules described in the embodiments of the present disclosure may be implemented in software or hardware, wherein the name of a module does not necessarily limit the module itself.

[0091] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0092] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0093] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the present disclosure is not limited to technical solutions formed by specific combinations of the aforementioned technical features. It also encompasses other technical solutions formed by any combination of the aforementioned technical features or their equivalents, without departing from the scope of the above disclosure. For example, a technical solution formed by replacing the aforementioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.

[0094] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details have been included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.

[0095] Although the subject matter has been described using language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above-described embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method and will not be elaborated upon here.

Claims

1. A method for detecting a network address, characterized in that: The detection method comprises: Obtaining a first network address to be detected; Obtaining memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; The first memory snapshot information and the second memory snapshot information are compared to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

2. The method for detecting a network address according to claim 1, wherein: The comparing the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address includes: Determining first memory data in the first memory snapshot information and second memory data in the second memory snapshot information; The first memory data and the second memory data are compared in bytes, and when the first memory data and the second memory data are inconsistent, a detection result indicating that the first network address is abnormal is determined.

3. The method for detecting a network address according to claim 2, wherein: The first memory data and the second memory data are corresponding numerical data, and / or the first memory data and the second memory data are corresponding operation data, and the operation data is memory data corresponding to the control flow in the built-in function.

4. The method for detecting a network address according to claim 1, wherein: The comparing the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address includes: Determining a first function pointer table in the first memory snapshot information and a second function pointer table in the second memory snapshot information; In a case where the first function pointer table is inconsistent with the second function pointer table, a detection result indicating that the first network address is abnormal is determined.

5. The method for detecting a network address according to claim 1, wherein: The comparing the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address includes: Determine a first encrypted digest of the first memory snapshot information encrypted and a second encrypted digest of the second memory snapshot information encrypted; In a case where the first encryption digest is inconsistent with the second encryption digest, a detection result indicating that the first network address is abnormal is determined.

6. The method for detecting a network address according to any one of claims 1 to 5, characterized in that: The detection method further comprises: Parsing an offset address and a module base address corresponding to the built-in function, and determining a memory address of the built-in function based on the offset address and the module base address, wherein the module base address represents a starting address of the built-in function in the memory, and the offset address represents a relative offset between the memory address of the built-in function and the module base address; The step of obtaining memory snapshot information corresponding to a built-in function of the browser includes: Memory snapshot information corresponding to the built-in function is obtained from the memory address.

7. The method for detecting a network address according to any one of claims 1 to 5, characterized in that: The detection method further comprises: loading the first network address in the browser through a first thread, and loading the second network address in the browser through a second thread when the loading page corresponding to the first network address includes the second network address; The step of obtaining memory snapshot information corresponding to a built-in function of the browser includes: After the browser completes loading the first network address and the second network address, second memory snapshot information corresponding to the built-in function is obtained through the first thread and the second thread.

8. The method for detecting a network address according to any one of claims 1 to 5, characterized in that: The number of built-in functions of the browser is multiple, and obtaining memory snapshot information corresponding to the built-in functions of the browser includes: Traversing the plurality of built-in functions, and obtaining memory snapshot information corresponding to each of the built-in functions; The comparing the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address includes: For each of the built-in functions, comparing the first memory snapshot information and the second memory snapshot information to obtain a detection sub-result of the built-in function; wherein the detection sub-result is used to indicate whether the first memory snapshot information and the second memory snapshot information of the built-in function are consistent; The detection result of the first network address is obtained according to the detection sub-results of each built-in function.

9. The method for detecting a network address according to any one of claims 1 to 5, characterized in that: The built-in functions of the browser include rendering engine functions and / or script engine functions.

10. A network address detection device, characterized in that: The detection device comprises: An acquisition module, configured to acquire a first network address to be detected; a snapshot module, configured to obtain memory snapshot information corresponding to a built-in function of the browser; wherein the memory snapshot information includes: first memory snapshot information corresponding to the built-in function before the browser loads the first network address, and second memory snapshot information corresponding to the built-in function after the browser completes loading the first network address; A comparison module is used to compare the first memory snapshot information and the second memory snapshot information to obtain a detection result of the first network address; wherein the detection result is used to indicate whether the first network address is abnormal.

11. A computer-readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 9 are implemented.

12. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 9.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.