URL (Uniform Resource Locator) parameter anomaly detection method and device and electronic equipment

By introducing a classification model in URL parameter detection, based on the type of feature information and sample URL parameters, the problem of low detection accuracy in the prior art is solved, and higher detection flexibility and accuracy are achieved.

CN120498803APending Publication Date: 2025-08-15BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510692870.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the detection of URL parameters based on rule matching is low in abnormality, making it difficult to adapt to the differences in different services and complex and changeable attack methods.

Method used

The classification model is adopted to determine the type of URL parameters by obtaining the feature information of URL parameters and inputting the pre-trained classification model. The classification model is established based on the type and feature information of the sample URL parameters in the URL parameter sample set. The sample URL parameters are the same as the parameter name of the URL parameters to be tested.

Benefits of technology

It improves the accuracy of detection of abnormal URL parameters, can better adapt to complex and changeable attack methods, and deeply integrates with business, improving the flexibility and accuracy of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498803A_ABST
    Figure CN120498803A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a URL parameter anomaly detection method and device and electronic equipment. The method comprises the following steps: acquiring a parameter name and a parameter value of a URL parameter to be tested; if the parameter value meets the target condition, obtaining feature information of the URL parameter to be detected based on the parameter value; the feature information is input into a pre-trained classification model, the type of the URL parameter to be detected is determined through the classification model, and the classification model is established based on the type of a sample URL parameter in a URL parameter sample set and the feature information of the sample URL parameter; and based on the type of the URL parameter to be tested, determining whether the URL parameter to be tested is abnormal. According to the embodiment, the accuracy of abnormal URL parameter detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and specifically to a method, device, and electronic device for detecting URL parameter anomalies. Background Art

[0002] With the development of network technology, websites are facing an increasing number of security threats, such as SQL (Structured Query Language) injection and XSS (Cross Site Scripting). Most of these attacks are carried out by modifying URL (Uniform Resource Locator) parameters.

[0003] Conventional technology typically uses rule-based matching to detect abnormal URL parameters. However, URL parameters for different businesses often have different characteristics. This approach fails to account for these differences and struggles to accurately identify URL parameters without clear rules. Consequently, the accuracy of detecting abnormal URL parameters is low. Summary of the Invention

[0004] The embodiments of the present application provide a URL parameter anomaly detection method, device, and electronic device, which improve the accuracy of abnormal URL parameter detection.

[0005] In the first aspect, an embodiment of the present application provides a URL parameter anomaly detection method, which includes: obtaining the parameter name and parameter value of the URL parameter to be tested; if the parameter value meets the target condition, obtaining the feature information of the URL parameter to be tested based on the parameter value; inputting the feature information into a pre-trained classification model, and determining the type of the URL parameter to be tested through the classification model, the classification model is established based on the type of sample URL parameters in the URL parameter sample set and the feature information of the sample URL parameters, and the sample URL parameters have the same parameter name as the URL parameter to be tested; based on the type of the URL parameter to be tested, determining whether the URL parameter to be tested is abnormal.

[0006] In the second aspect, an embodiment of the present application provides a URL parameter anomaly detection device, which includes: an acquisition unit, used to obtain the parameter name and parameter value of the URL parameter to be tested; an extraction unit, used to obtain the characteristic information of the URL parameter to be tested based on the parameter value if the parameter value meets the target condition; a type detection unit, used to input the characteristic information into a pre-trained classification model, and determine the type of the URL parameter to be tested through the classification model, the classification model is established based on the type of the sample URL parameter in the URL parameter sample set and the characteristic information of the sample URL parameter, and the sample URL parameter has the same parameter name as the URL parameter to be tested; a first determination unit, used to determine whether the URL parameter to be tested is abnormal based on the type of the URL parameter to be tested.

[0007] In a third aspect, an embodiment of the present application provides an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any embodiment of the first aspect.

[0008] In a fourth aspect, an embodiment of the present application provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method described in any embodiment of the first aspect.

[0009] The URL parameter anomaly detection method, device, and electronic device provided in the embodiments of the present application first obtain the parameter name and parameter value of the URL parameter to be tested; if the parameter value meets the target condition, characteristic information of the URL parameter to be tested is obtained based on the parameter value, the characteristic information is input into a pre-trained classification model, and the type of the URL parameter to be tested is determined by the classification model, wherein the classification model is established based on the type of the sample URL parameter in the URL parameter sample set and the characteristic information of the sample URL parameter, and the parameter name of the sample URL parameter is the same as that of the URL parameter to be tested; finally, based on the type of the URL parameter to be tested, it is determined whether the URL parameter to be tested is abnormal. On the one hand, since the classification model is introduced in the process of detecting the URL parameter to be tested, the classification and identification of the URL parameter to be tested is performed by the classification model, which is more intelligent and flexible than the traditional rule matching method, and can better adapt to complex and changeable attack methods, thereby improving the accuracy of abnormal URL parameter detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Other features, objects and advantages of the present application will become more apparent upon reading the detailed description of non-limiting embodiments made with reference to the following drawings:

[0011] Figure 1This is a flowchart of an embodiment of the URL parameter anomaly detection method of the present application;

[0012] Figure 2 This is a flowchart of another embodiment of the URL parameter anomaly detection method of the present application;

[0013] Figure 3 This is a schematic diagram of the structure of an embodiment of the URL parameter anomaly detection device of the present application;

[0014] Figure 4 It is a structural diagram of an electronic device used to implement an embodiment of the present application. DETAILED DESCRIPTION

[0015] All actions of acquiring signals, information or data in this application are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.

[0016] The present application will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the relevant invention and are not intended to limit the invention. It should also be noted that, for ease of description, only portions relevant to the relevant invention are shown in the accompanying drawings.

[0017] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0018] Please refer to Figure 1 , which illustrates a process 100 of an embodiment of a method for detecting URL parameter anomalies according to the present application. The method for detecting URL parameter anomalies can be applied to various electronic devices with data processing capabilities, such as servers. The execution subject of the method for detecting URL parameter anomalies can be a processor in the aforementioned electronic devices.

[0019] The URL parameter anomaly detection method includes the following steps:

[0020] Step 101: Obtain the parameter name and parameter value of the URL parameter to be tested.

[0021] In this embodiment, the URL parameter is a parameter in the URL, specifically a key-value pair appended after the question mark "?" in the URL. In the case where the URL includes multiple URL parameters, the multiple URL parameters are separated by the symbol "&". Each URL parameter may include a parameter name and a parameter value, and the parameter name and parameter value are connected with an equal sign "=". Common uses of URL parameters include page jumps, paging, identity authentication, etc. URL parameters can be used to transmit information. The URL parameter to be tested is the URL parameter to be detected for anomalies, and specifically can be the URL parameter in the request sent by the client in real time.

[0022] In this embodiment, the above-mentioned execution entity can obtain the parameter name and parameter value of the URL parameter to be tested by identifying characters such as "?", "&", and "=" in the URL to be tested. As an example, the URL is " / / www.baidu.com / s?ie=utf-8&f=8&rsv_bp=1&rsv_idx=1", and the above-mentioned execution entity can first detect the question mark "?" in the URL, and extract the character string "ie=utf-8&f=8&rsv_bp=1&rsv_idx=1" after the question mark "?". Then identify the "&" symbol in the character string. The character string includes three "&" symbols, so it contains a total of four URL parameters to be tested, namely "ie=utf-8", "f=8", "rsv_bp=1", and "rsv_idx=1". For each URL parameter to be tested, the character string before the equal sign "=" is the parameter name, and the character string after "=" is the parameter value. For each URL parameter, the following steps 102 to 104 can be executed.

[0023] Step 102: If the parameter value meets the target condition, characteristic information of the URL parameter to be tested is obtained based on the parameter value.

[0024] In this embodiment, the execution entity may first determine whether the parameter value of the URL parameter to be tested meets the target condition. If the parameter value meets the target condition, characteristic information of the URL parameter to be tested may be obtained based on the parameter value. The characteristic information may include, but is not limited to, at least one of the following: the parameter value, the parameter value type, the parameter value length, the parameter value purpose, etc. The parameter value type may include, but is not limited to, a number, a string, a Boolean value, a date, a time, etc. The parameter value length may be the number of characters in the parameter value. The parameter value purpose may include, but is not limited to, generating webpage content, tracking the source of users or traffic, etc.

[0025] In some optional implementations of this embodiment, the following steps may be used to determine whether the parameter value of the URL parameter to be tested meets the target condition:

[0026] The first step is to determine whether the length of the parameter value is less than or equal to a length threshold. The length threshold can be predetermined by a technician based on experience. For example, it can be set to 128.

[0027] The second step is to determine whether the parameter value contains the target characters. The target characters are uncommon characters in the parameter value under the parameter name. The target characters can be pre-defined by a technician. For example, they may include, but are not limited to, characters commonly used by hackers to perform malicious SQL injection and XSS attacks.

[0028] In the third step, if the length of the parameter value is less than or equal to the length threshold and the parameter value does not include the target character, it is determined that the parameter value meets the target condition.

[0029] In the fourth step, if the length of the parameter value is greater than the length threshold, or the parameter value includes the target character, it is determined that the parameter value does not meet the target condition.

[0030] It's understandable that for a given parameter name, its value typically falls within a certain length range. If this length range is exceeded, meaning the parameter value exceeds the length threshold, it indicates a significant anomaly, and the URL parameter being tested is clearly abnormal. Furthermore, if the parameter value includes target characters, it indicates a high probability of being targeted by hackers, such as through SQL injection or XSS attacks, and the URL parameter being tested is clearly abnormal.

[0031] By determining whether the length of the parameter value is less than or equal to the length threshold and whether the parameter value includes the target character, obviously abnormal URL parameters to be tested can be determined, eliminating the need for subsequent category detection steps and improving the speed of detecting obviously abnormal URL parameters to be tested.

[0032] In some optional implementations of this embodiment, if the parameter value of the URL parameter to be tested does not meet the target condition, the URL parameter to be tested may be determined to be a security threat parameter. Security threat parameters are parameters that pose a security threat to the system. For example, they may include but are not limited to URL parameters that may be susceptible to malicious SQL injection by hackers or URL parameters that may be susceptible to XSS attacks.

[0033] Furthermore, since the security threat type parameter is an abnormal URL parameter, if the URL parameter to be tested is determined to be a security threat type parameter, it can be determined that the URL parameter to be tested is abnormal.

[0034] By determining that the parameter value of the URL parameter to be tested does not meet the target conditions, it is determined to be a security threat parameter, which can directly determine that the URL parameter to be tested is abnormal, eliminating the subsequent category detection step and improving the speed of detecting obviously abnormal URL parameters to be tested.

[0035] Step 103: input the feature information into a pre-trained classification model, and determine the type of the URL parameter to be tested through the classification model. The classification model is established based on the type of the sample URL parameter in the URL parameter sample set and the feature information of the sample URL parameter.

[0036] In this embodiment, a classification model for detecting the type of URL parameters can be pre-trained and stored. The classification model can be obtained by training a model with classification capabilities, such as a naive Bayesian classifier, a support vector machine (SVM), or a convolutional neural network (CNN). The execution entity can input feature information of the URL parameter to be tested into the pre-trained classification model, and determine the type of the URL parameter to be tested using the classification model.

[0037] The classification model can be trained using a machine learning method. Specifically, the feature information of the sample URL parameter can be input into the classification model to be trained to obtain the classification result output by the classification model. Then, the loss value can be determined based on the classification result and the type of the sample URL parameter. The above loss value is the value of the loss function, which is a non-negative real-valued function that can be used to characterize the difference between the detection result and the true result. Generally speaking, the smaller the loss value, the better the robustness of the model. The loss function can be set according to actual needs. Afterwards, the loss value can be used to update the parameters of the classification model. Thus, each time the feature information of the sample URL parameter is input, the loss value of the classification model can be calculated, thereby updating the parameters of the classification model until the training is completed.

[0038] Whether training is complete can be determined in a variety of ways. For example, training can be determined to be complete when the accuracy of the classification results output by the classification model reaches a preset value (e.g., 99%). For another example, training can be determined to be complete when the number of times the classification model is trained equals a preset number of times. For another example, training can be determined to be complete when the loss value of the classification model converges.

[0039] In practice, different classification models can be pre-trained for different businesses. Classification models for different businesses can be trained using the same model structure and have different model parameter files. During use, the corresponding model parameter file can be retrieved based on the business and the corresponding classification model can be loaded. In practice, each business can be assigned a parameter name. For example, the parameter name for the order query business is "order number." The parameter name for the red envelope query business is "red envelope number," and so on.

[0040] In this embodiment, the classification model used can be established based on the type and feature information of sample URL parameters in the URL parameter sample set, where the sample URL parameters have the same parameter name as the URL parameter to be tested. The type of the sample URL parameter can be set by a technician and can serve as a label for the sample URL parameter. The method for extracting the feature information of the sample URL parameter is essentially the same as the method for extracting the feature information of the URL parameter to be tested described above and will not be repeated here.

[0041] In some optional implementations of this embodiment, the classification model may employ a Naive Bayesian model. The execution entity may first input the characteristic information of the URL parameter to be tested into the empirical probability formula of the Naive Bayesian model to determine the probability that the URL parameter to be tested belongs to each preset parameter type. The preset parameter type corresponding to the maximum value of the determined probabilities is then determined as the type of the URL parameter to be tested.

[0042] In practice, a URL parameter document can be created in advance. The URL parameter document may include the types of multiple URL parameters and information such as the parameter name, parameter value, parameter value type, parameter value length, parameter value purpose, parameter value range, parameter value length limit, and parameter value necessity identifier of each URL parameter in the above multiple URL parameters. The above-mentioned execution entity can use the parameter name of the URL parameter to be tested as the target parameter name, and the URL parameter with the target parameter name in the URL parameter document as the sample URL parameter, and summarize the relevant data of the sample URL parameters to obtain a URL parameter sample set. The empirical probability formula of the naive Bayes model is fitted through the data in the URL parameter sample set.

[0043] Specifically, the empirical probability formula can be established through the following steps:

[0044] First, calculate the prior probability P(C k ), C k represents the kth type. The prior probability refers to the probability of each type occurring when there is no observed data. It can be obtained by counting the types of sample URL parameters in the URL parameter sample set.

[0045] Next, calculate the conditional probability P(x i ∣C k ). Conditional probability refers to the probability of a given type C k In the case of feature x i The probability of occurrence, x i Denotes the i-th feature. For each feature, such as parameter name, parameter value, parameter value type, parameter value length, parameter value purpose, parameter value range, parameter value length limit, parameter value necessity flag, etc., calculate its conditional probability under each type. For example, P(xi ∣C k )=(Type C k has feature x i Number of samples of type C k + N), where N is the number of samples of feature x i The number of possible values of , that is, the number of all possible discrete values of the feature.

[0046] Next, construct the empirical probability formula. According to Bayes' theorem, the URL parameter to be tested belongs to type C k The posterior probability is: Where X=(x1,x2,…x n ) is the feature information, and n is the number of features in the feature information.

[0047] Finally, the type that maximizes the posterior probability is selected as the type to which the predicted URL parameter to be tested belongs.

[0048] As a classification model, the Naive Bayes model can classify and identify URL parameters to be tested. Compared with traditional rule matching methods, it is more intelligent and flexible and can better adapt to complex and changing attack methods, thereby improving the accuracy of abnormal URL parameter detection.

[0049] In some optional implementations of this embodiment, the sample URL parameters and the URL parameters to be tested have the same parameter names. This ensures that the sample URL parameters and the URL parameters to be tested are parameters of the same business, allowing the classification model to be deeply integrated with the business and specifically classify and identify URL parameters under the same business, thereby making the parameter category detection results of the URL parameters to be tested more accurate and further improving the accuracy of abnormal URL parameter detection.

[0050] It should be noted that the URL parameter sample set may also include the type and feature information of sample URL parameters that are different from the parameter names of the URL parameters to be tested. At this time, the classification model trained by this sample set can be adapted to the business corresponding to the URL to be tested, and can also be applied to other businesses.

[0051] Step 104: Determine whether the URL parameter to be tested is abnormal based on the type of the URL parameter to be tested.

[0052] In this embodiment, the classification method of URL parameters can be set as needed and is not specifically limited here. For example, it can include legal parameters and illegal parameters. If the URL parameters to be tested are legal parameters, it can be determined that the URL parameters to be tested are normal. If the URL parameters to be tested are illegal parameters, it can be determined that the URL parameters to be tested are abnormal.

[0053] In some optional implementations of this embodiment, the types of URL parameters include legal parameters and illegal parameters. Illegal parameters may include but are not limited to at least one of the following: security threat parameters, functional error parameters, or statistical error parameters.

[0054] Among them, the above-mentioned security threat type parameters are parameters that pose a security threat to the system. For example, they may include but are not limited to URL parameters that have been maliciously SQL injected by hackers, URL parameters that have XSS attacks, etc. The above-mentioned functional error type parameters are parameters that cause business errors. For example, if the parameter value of a URL parameter cannot be queried, then the URL parameter is a functional error type parameter. The above-mentioned statistical error type parameters are parameters that do not pose a security threat to the system and do not cause business errors but affect data statistics. For example, if a URL parameter is used to record the source of traffic, and its parameter value is wrong, it means that the source of traffic is wrong. The URL parameter does not affect the business function, but affects the statistics of the source of traffic. Therefore, the URL parameter can be used as a statistical error type parameter.

[0055] On this basis, if the type of the URL parameter to be tested is the above-mentioned security threat parameter, the above-mentioned functional error parameter or the above-mentioned statistical error parameter, then the above-mentioned URL parameter to be tested can be determined to be an abnormal parameter. Otherwise, it can be determined that the above-mentioned URL parameter to be tested is a normal parameter.

[0056] By setting the type of URL parameters in the above manner, it can be deeply integrated with the business, giving substantive meaning to subsequent URL parameter anomaly alerts, and improving the reference value of URL parameter anomaly detection.

[0057] The method provided by the above-mentioned embodiment of the present application introduces a classification model in the process of detecting the URL parameters to be tested. The URL parameters to be tested are classified and identified through the classification model. Compared with the traditional rule matching method, it is more intelligent and flexible and can better adapt to complex and changeable attack methods, thereby improving the accuracy of abnormal URL parameter detection.

[0058] In some optional embodiments, after determining whether the above-mentioned URL parameters to be tested are abnormal, the following steps may be further performed:

[0059] In the first step, the URL parameters to be tested are used as the tested URL parameters, and the number of each type of tested URL parameters within a preset time period is determined. The preset time period can be set as needed, for example, the last hour, the last day, the last week, etc. As an example, the number of legitimate parameters, security threat parameters, functional error parameters, and statistical error parameters within the last day can be counted separately.

[0060] The second step is to determine the distribution of each type of measured URL parameter within the preset time period based on the parameter names of each type of measured URL parameter within the preset time period. Measured URL parameters with the same parameter name can be considered the same service parameter. For each type, the number of service parameters of that type within the preset time period can be counted to obtain the distribution of each service parameter of that type.

[0061] The third step is to generate a URL parameter detection report for the preset period based on the above quantity and the above distribution. Here, the above quantity and distribution can be summarized to obtain the URL parameter detection report for the preset period.

[0062] Therefore, it can not only provide technical personnel with abnormal detection results of URL parameters obtained in real time, but also provide technical personnel with detection reports of URL parameters within any statistical period, so that technical personnel can understand the abnormal situations of URL parameters in different periods and provide support and guidance for attack prevention in different periods.

[0063] In some optional embodiments, see Figure 2 After executing the above step 104, you may also execute the following steps:

[0064] Step 105: If the URL parameter to be tested is an abnormal parameter, the priority of the URL parameter to be tested is determined based on the type of the URL parameter to be tested.

[0065] Here, a correspondence between the type and priority of the URL parameter can be pre-set. Based on this correspondence, the priority of the URL parameter to be tested can be determined. As an example, the types of URL parameters include legal parameters, security threat parameters, functional error parameters, and statistical error parameters. Security threat parameters, functional error parameters, and statistical error parameters are abnormal parameters. Security threat parameters can be set to the highest priority, functional error parameters to the second highest priority, and statistical error parameters to the lowest priority.

[0066] Step 106: Outputting an alarm message indicating that the URL parameter to be tested is abnormal by using an alarm message output method corresponding to the priority.

[0067] Here, the alarm information may include information such as the type of the URL parameter to be tested, the parameter name, the number of abnormal triggering frequencies, the parameter value, etc. Different priorities may correspond to different alarm information output methods, and the alarm information output methods corresponding to different priorities may be pre-set.

[0068] Continuing with the above example, security threat parameters have the highest priority. The more security threat parameters there are, the more frequently the website is attacked by criminals, and this should be brought to the attention of the website administrator. The corresponding alarm information output method can be to immediately output an alarm message when a security threat parameter is detected, or to output an alarm message when a security threat parameter is detected and the number of security threat parameters within the statistical period exceeds a first threshold.

[0069] Functional error parameters have the second highest priority. The more data in this category, the more vulnerable the website's functionality is to being affected. This could be due to a misspelling of parameters during website URL promotion, or a problem with the robustness of the website's functionality. This should be brought to the attention of website administrators and developers, who should promptly investigate the issue. The corresponding alarm information output method can be to output an alarm message when a security threat parameter is detected and the number of security threat parameters within the statistical period exceeds a second threshold. The second threshold may be greater than the first threshold.

[0070] Statistically incorrect parameters will not cause website functionality issues; they will only affect data statistics. In production practice, the frequency of alarm output should be appropriately reduced. The corresponding alarm output method can be to output an alarm when a security threat parameter is detected and the number of security threat parameters within the statistical period exceeds a third threshold. This third threshold can be greater than the second threshold.

[0071] When abnormal URL parameters are detected, the alarm mechanism is automatically triggered, reducing manual intervention, improving the response speed and efficiency to abnormal URL parameters, and enabling administrators to take timely measures to deal with potential security threats.

[0072] Further references Figure 3 As an implementation of the methods shown in the above figures, this application provides an embodiment of a device for detecting abnormal URL parameters. Figure 1 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.

[0073] like Figure 3As shown, the URL parameter anomaly detection device 300 of this embodiment includes: an acquisition unit 301, used to obtain the parameter name and parameter value of the URL parameter to be tested; an extraction unit 302, used to obtain the characteristic information of the URL parameter to be tested based on the parameter value if the parameter value meets the target condition; a type detection unit 303, used to input the characteristic information into a pre-trained classification model, and determine the type of the URL parameter to be tested through the classification model, and the classification model is established based on the type of the sample URL parameter in the URL parameter sample set and the characteristic information of the sample URL parameter; a first determination unit 304, used to determine whether the URL parameter to be tested is abnormal based on the type of the URL parameter to be tested.

[0074] In some optional implementations of this embodiment, the device also includes a second determination unit, which is used to: determine whether the length of the parameter value is less than or equal to a length threshold; determine whether the parameter value includes a target character; if the length of the parameter value is less than or equal to the length threshold, and the parameter value does not include the target character, determine that the parameter value meets the target condition; if the length of the parameter value is greater than the length threshold, or the parameter value includes the target character, determine that the parameter value does not meet the target condition.

[0075] In some optional implementations of this embodiment, the classification model includes a naive Bayes model; the type detection unit 303 is further used to: input the characteristic information of the URL parameter to be tested into the empirical probability formula of the naive Bayes model to obtain the probability that the URL parameter to be tested belongs to each preset parameter type; and determine the preset parameter type corresponding to the maximum value of the determined probability as the type of the URL parameter to be tested.

[0076] In some optional implementations of this embodiment, the types of URL parameters include legal parameters, security threat parameters, functional error parameters or statistical error parameters, the security threat parameters are parameters that pose a security threat to the system, the functional error parameters are parameters that cause business errors, and the statistical error parameters are parameters that do not pose a security threat to the system and do not cause business errors but affect data statistics; the first determination unit 304 is also used to: if the type of the URL parameter to be tested is the security threat parameter, the functional error parameter or the statistical error parameter, then determine that the URL parameter to be tested is an abnormal parameter.

[0077] In some optional implementations of this embodiment, the apparatus further includes a third determining unit configured to determine the URL parameter to be tested as the security threat parameter if the parameter value does not satisfy the target condition.

[0078] In some optional implementations of this embodiment, the device also includes an alarm unit, which is used to: if the URL parameter to be tested is an abnormal parameter, determine the priority of the URL parameter to be tested based on the type of the URL parameter to be tested; and use the alarm information output method corresponding to the priority to output alarm information indicating that the URL parameter to be tested is abnormal.

[0079] In some optional implementations of this embodiment, the device also includes a generating unit, which is used to: take the URL parameters to be tested as the measured URL parameters, and determine the number of each type of measured URL parameters within a preset time period; based on the parameter names of each type of measured URL parameters within the preset time period, determine the distribution of each type of measured URL parameters within the preset time period; based on the number and the distribution, generate a URL parameter detection report for the preset time period.

[0080] In some optional implementations of this embodiment, the parameter name of the sample URL parameter is the same as the parameter name of the URL parameter to be tested.

[0081] The device provided by the above-mentioned embodiment of the present application first obtains the parameter name and parameter value of the URL parameter to be tested; if the parameter value meets the target condition, then the characteristic information of the URL parameter to be tested is obtained based on the parameter value, and the characteristic information is input into a pre-trained classification model, and the type of the URL parameter to be tested is determined by the classification model, wherein the classification model is established based on the type of the sample URL parameter in the URL parameter sample set and the characteristic information of the sample URL parameter, and the parameter name of the sample URL parameter is the same as that of the URL parameter to be tested; finally, based on the type of the URL parameter to be tested, it is determined whether the URL parameter to be tested is abnormal. On the one hand, since the classification model is introduced in the process of detecting the URL parameter to be tested, the classification and identification of the URL parameter to be tested is performed by the classification model, which is more intelligent and flexible than the traditional rule matching method, and can better adapt to complex and changeable attack methods, thereby improving the accuracy of detecting abnormal URL parameters. On the other hand, the classification model is established based on the characteristic information of the type and parameter value of the sample URL parameters. Since the parameter names of the sample URL parameters and the URL parameters to be tested are the same, the sample URL parameters and the URL parameters to be tested are parameters of the same business, which enables the classification model to be deeply integrated with the business and specifically classify and identify URL parameters under the same business, thereby making the parameter category detection results of the URL parameters to be tested more accurate, further improving the accuracy of abnormal URL parameter detection.

[0082] Reference below Figure 4 , which shows a structural schematic diagram of an electronic device for implementing some embodiments of the present application. Figure 4The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present application.

[0083] like Figure 4 As shown, the electronic device 400 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 401, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage device 408 into a random access memory (RAM) 403. Various programs and data required for the operation of the electronic device 400 are also stored in the RAM 403. The processing device 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0084] Typically, the following devices may be connected to the I / O interface 405: an input device 406 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 408 including, for example, a magnetic disk, a hard disk, etc.; and a communication device 409. The communication device 409 may allow the electronic device 400 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 4 The electronic device 400 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 4 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0085] In particular, according to some embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 409, or installed from the storage device 408, or installed from the ROM 402. When the computer program is executed by the processing device 401, the above-mentioned functions defined in the method of some embodiments of the present application are performed.

[0086] It should be noted that the computer-readable medium described in some embodiments of the present application may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present application, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present application, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0087] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0088] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When executed by the electronic device, the electronic device: obtains the parameter name and parameter value of the URL parameter to be tested; if the parameter value meets the target condition, obtains feature information of the URL parameter to be tested based on the parameter value; inputs the feature information into a pre-trained classification model, and determines the type of the URL parameter to be tested through the classification model, the classification model being established based on the type of sample URL parameters in the URL parameter sample set and the feature information of the sample URL parameters; and determines whether the URL parameter to be tested is abnormal based on the type of the URL parameter to be tested.

[0089] Computer program code for performing the operations of some embodiments of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++; and also conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, or can be connected to an external computer (for example, through the Internet using an Internet service provider). The above network includes a local area network (LAN) or a wide area network (WAN).

[0090] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0091] The units described in some embodiments of this application may be implemented in software or hardware. The units described may also be provided in a processor. For example, a processor may be described as comprising a first determination unit, a second determination unit, a selection unit, and a third determination unit. The names of these units do not, in some cases, limit the units themselves.

[0092] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0093] The above description is only an illustration of some preferred embodiments of the present application and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present application is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features and the technical features with similar functions disclosed in the embodiments of the present application (but not limited to) are replaced with each other to form a technical solution.

Claims

1. A URL parameter anomaly detection method, characterized in that: The method comprises: Get the parameter name and parameter value of the URL parameter to be tested; If the parameter value meets the target condition, then acquiring the characteristic information of the URL parameter to be tested based on the parameter value; Inputting the feature information into a pre-trained classification model, and determining the type of the URL parameter to be tested by the classification model, wherein the classification model is established based on the type of sample URL parameters in the URL parameter sample set and the feature information of the sample URL parameters; Based on the type of the URL parameter to be tested, determine whether the URL parameter to be tested is abnormal.

2. The method according to claim 1, characterized in that After obtaining the parameter name and parameter value of the URL parameter to be tested, the method further includes: determining whether the length of the parameter value is less than or equal to a length threshold; Determining whether the parameter value includes the target character; If the length of the parameter value is less than or equal to the length threshold, and the parameter value does not include the target character, determining that the parameter value meets the target condition; If the length of the parameter value is greater than the length threshold, or the parameter value includes the target character, it is determined that the parameter value does not meet the target condition.

3. The method according to claim 1, characterized in that The classification model includes a naive Bayes model; Inputting the feature information into a pre-trained classification model and determining the type of the URL parameter to be tested by the classification model includes: Inputting the characteristic information of the URL parameter to be tested into the empirical probability formula of the naive Bayes model to obtain the probability that the URL parameter to be tested belongs to each preset parameter type; The preset parameter type corresponding to the determined maximum probability is determined as the type of the URL parameter to be tested.

4. The method according to claim 1, wherein The types of URL parameters include legal parameters, security threat parameters, functional error parameters, or statistical error parameters. The security threat parameters are parameters that pose a security threat to the system, the functional error parameters are parameters that cause business errors, and the statistical error parameters are parameters that do not pose a security threat to the system or cause business errors but affect data statistics. Determining whether the URL parameter to be tested is abnormal includes: If the type of the URL parameter to be tested is the security threat type parameter, the functional error type parameter or the statistical error type parameter, it is determined that the URL parameter to be tested is an abnormal parameter.

5. The method according to claim 4, characterized in that The method further comprises: If the parameter value does not meet the target condition, the URL parameter to be tested is determined as the security threat type parameter.

6. The method according to claim 1, characterized in that After determining whether the URL parameter to be tested is abnormal, the method further includes: If the URL parameter to be tested is an abnormal parameter, determining the priority of the URL parameter to be tested based on the type of the URL parameter to be tested; The alarm information output mode corresponding to the priority is adopted to output the alarm information indicating that the URL parameter to be tested is abnormal.

7. The method according to claim 1, characterized in that After determining whether the URL parameter to be tested is abnormal, the method further includes: Taking the URL parameters to be tested as the tested URL parameters, determining the number of tested URL parameters of each type within a preset time period; Determining the distribution of each type of measured URL parameters within the preset time period based on the parameter names of each type of measured URL parameters within the preset time period; Based on the quantity and the distribution, a URL parameter detection report for the preset time period is generated.

8. The method according to any one of claims 1 to 7, characterized in that The sample URL parameter has the same parameter name as the URL parameter to be tested.

9. A device for detecting abnormal URL parameters, characterized in that: The device comprises: The acquisition unit is used to obtain the parameter name and parameter value of the URL parameter to be tested; an extraction unit, configured to obtain characteristic information of the URL parameter to be tested based on the parameter value if the parameter value satisfies a target condition; a type detection unit, configured to input the feature information into a pre-trained classification model and determine the type of the URL parameter to be tested by means of the classification model, wherein the classification model is established based on the type of the sample URL parameters in the URL parameter sample set and the feature information of the sample URL parameters; The first determining unit is configured to determine whether the URL parameter to be tested is abnormal based on the type of the URL parameter to be tested.

10. An electronic device, characterized in that: include: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 8.

11. A computer-readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.