Abnormal network resource detection method and device, electronic equipment, storage medium and program product

By constructing format, behavior and semantic information sets to screen deep packet detection data, combined with QR code decoding and cross-view attention model, the problem of low efficiency in abnormal link recognition in QR code is solved, and efficient and accurate abnormal network resource detection is achieved.

CN120528641APending Publication Date: 2025-08-22CHINA MOBILE GROUP ZHEJIANG +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510624549.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing abnormal network resource identification methods are inefficient and difficult to accurately identify abnormal links carried in QR codes. Traditional methods cannot adapt to the rapidly changing network threat patterns and pose security risks.

Method used

By constructing a format information set, a behavior information set and a semantic information set, the target data in the deep packet detection DPI data is filtered out, simulation loading and QR code feature picture decoding, and abnormal network resources are identified in combination with a cross-view attention collaborative model.

Benefits of technology

It improves the identification efficiency and accuracy of abnormal network resources, expands the monitoring range, avoids omissions, and improves network security performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528641A_ABST
    Figure CN120528641A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal network resource detection method and device, electronic equipment, a storage medium and a program product, and relates to the technical field of network monitoring. By constructing the format information set, the behavior information set and the semantic information set, survival scenes of various abnormal network resources are comprehensively considered, and the accuracy of obtaining the target DPI data is improved. According to the method, the space-time attribute data of the DPI data and the content attribute data of the DPI data are matched with the format information set, the behavior information set and the semantic information set, the target DPI data are screened out, the static limitation of a traditional rule engine is broken through by applying a dynamic recall architecture, the target DPI data are accurately obtained, and the DPI data processing efficiency is improved. The efficiency and the accuracy of obtaining the target network resource are improved, and the efficiency and the accuracy of identifying the abnormal network resource are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network monitoring, and in particular to a method, device, electronic device, storage medium and program product for detecting abnormal network resources. Background Art

[0002] With the evolution of information technology, cybersecurity issues have become increasingly complex. In addition to traditional risks, we now must contend with a host of new security threats, such as the illegal modification of website content, the concealed insertion of harmful code, unwanted electronic communications, database manipulation attacks, the manipulation of controlled networks, and traffic blocking attacks. These new threats, coupled with ever-changing and unpredictable attack vectors, pose a significant challenge to protecting the online environment. While advances in information technology have significantly increased the efficiency of data exchange and processing, they have also given rise to a host of new security concerns, particularly regarding the identification and prevention of harmful activities conducted through websites.

[0003] As a highly efficient two-dimensional barcode, the Quick Response (QR) code has gained widespread adoption nationwide, particularly in the mobile payment industry, due to its high capacity, robust error correction capabilities, and rapid parsing. However, due to the transparent nature of its encoding mechanism, QR codes can easily become a tool for phishing attacks, posing a security risk to mobile device users. These codes can lead users to visit unauthorized web pages or download unauthorized software, potentially leading to personal information leakage or account theft, posing a serious threat to mobile device security. Given that the security of the content linked to a QR code cannot be determined solely from its appearance, relatively few methods exist for proactively detecting and preventing unauthorized links carried by QR codes.

[0004] Several studies have focused on identifying potentially anomalous links by analyzing web content. These include methods for detecting harmful websites by extracting Uniform Resource Locators (URL) features based on predefined rules. This involves examining static URL attributes, such as structure and URL information, as well as dynamic attributes, such as registration details and validity. Feature selection and optimization techniques have been explored, such as using random forest algorithms for feature selection or filtering algorithms to find the most relevant feature sets and combining them with algorithms such as support vector machines to evaluate the effectiveness of these features. Other research focuses on combining deep learning models with multiple classifiers to reduce data dimensionality and improve representation. Research is also underway to improve machine learning algorithms to enhance feature extraction and classification accuracy. Commonly used algorithms include decision trees, Bayesian classifiers, support vector machines, maximum entropy models, logistic regression, neural networks, and the K-nearest neighbor algorithm.

[0005] Current methods for identifying anomalous links can only address the detection of common, overtly harmful URLs. These methods are relatively effective for threats that are public and easily identifiable. However, with the increasing complexity of cybersecurity, when anomalous content is encoded in hidden carriers such as QR codes, traditional methods cannot be used to identify it. Currently, the most common method for identifying anomalous network resources is based on deep packet inspection (DPI). However, crawler resources for extracting DPI URLs are relatively limited, and automated tools for extracting network addresses have limited functionality. Attempts to apply existing anomalous website detection mechanisms to QR code-related threat analysis typically require the use of a sandbox environment to simulate user access behavior and perform content parsing. However, this approach is not only slow but also difficult to adapt to rapidly evolving threat models and may even pose additional security risks to users in real-world applications. With the rapid evolution and increasing diversity of anomalous link features, identifying and distinguishing these links from legitimate ones is becoming increasingly complex. The subtle differences between the two make it difficult to accurately filter anomalous links from massive amounts of data. The lack of flexibility in traditional feature extraction methods limits the ability to accurately identify anomalous links, thus impacting the overall accuracy of research. In summary, the efficiency of existing identification of abnormal network resources (eg, abnormal network links) is low. Summary of the Invention

[0006] The present invention provides a method, device, electronic device, storage medium and program product for detecting abnormal network resources, which are used to solve the defect of low efficiency in identifying abnormal network resources in the prior art and improve the efficiency of identifying abnormal network resources.

[0007] In a first aspect, the present invention provides a method for detecting abnormal network resources, comprising: matching the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of the DPI data with a preset format information set, a behavior information set, and a semantic information set, screening out target DPI data based on the matching results, wherein any format information in the format information set is used to characterize the format characteristics of the abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of the abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of the abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; simulating the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image; obtaining the target network resource encapsulated in the QR code feature image; and identifying the abnormal network resources in the target network resource.

[0008] In one embodiment, the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of the DPI data are matched with a preset format information set, a behavior information set, and a semantic information set, and target DPI data is screened out based on the matching results, including: obtaining a probability that the DPI data contains target format information based on the matching result of the content attribute data of the DPI data with any format information, and if the probability is greater than a set probability, the DPI data is used as the target DPI data; if it is determined that the DPI data contains target behavior information based on the matching result of the content attribute data of the DPI data with any behavior information, and if it is determined that the DPI data occurs within the time range and spatial range of the target behavior information based on the matching result of the spatiotemporal attribute data of the DPI data with the target behavior information, the DPI data is used as the target DPI data; and extracting a semantic vector of the content attribute data of the DPI data, and if the similarity between the semantic vector of the content attribute data of the DPI data and any semantic information is greater than a set similarity, the DPI data is used as the target DPI data.

[0009] In one embodiment, the loading of the URL to be loaded corresponding to the target DPI data is simulated to obtain a QR code feature image, including: in the process of simulating the loading of the URL to be loaded, a snapshot capture method based on pixel-level rendering is used to capture the loaded web page image; the loaded web page image is encoded and stored in a standard red, green and blue three-channel format to obtain a QR code feature image.

[0010] In one embodiment, identifying abnormal network resources in target network resources includes: extracting structural features of the target network resources to obtain a structural feature vector; extracting content features of the target network resources to obtain a content feature vector; fusing the structural feature vector and the content feature vector to obtain a fusion vector; and determining a target probability that the target network resource belongs to an abnormal network resource based on the fusion vector, and determining that the target network resource belongs to an abnormal network resource when the target probability is greater than a set value.

[0011] In one embodiment, the structural feature vector and the content feature vector are fused to obtain a fused vector, including: generating a query vector based on the structural feature vector and the query weight matrix; generating a key vector based on the content feature vector and the key weight matrix; generating a value vector based on the content feature vector and the value weight matrix; and performing attention fusion on the query vector, the key vector, and the value vector to obtain a fused vector.

[0012] In one embodiment, obtaining a target network resource encapsulated in a QR code feature image includes: inputting the QR code feature image into a QR code decoding model, and obtaining feature data of the QR code feature image output by the QR code decoding model; wherein the QR code decoding model uses convolution kernels with different strides to extract features of different scales on the QR code feature image to obtain multiple multi-scale feature maps, and performing deformable convolution, aggregation and activation on each adjacent multi-scale feature map in the multiple multi-scale feature maps to obtain feature data; based on the version information of the QR code and the format information of the QR code, the feature data is decoded to obtain the target network resource.

[0013] In a second aspect, the present invention provides a device for detecting abnormal network resources, including: a first acquisition module, used to match the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of DPI data with a preset format information set, a behavior information set and a semantic information set, and screen out target DPI data based on the matching results, any format information in the format information set is used to characterize the format characteristics of the abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of the abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of the abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; a second acquisition module, used to simulate the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image; a third acquisition module, used to obtain the target network resource encapsulated in the QR code feature image; and an identification module, used to identify abnormal network resources in the target network resource.

[0014] In a third aspect, the present invention further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for detecting abnormal network resources as described above is implemented.

[0015] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-mentioned methods for detecting abnormal network resources.

[0016] In a fifth aspect, the present invention further provides a computer program product, comprising a computer program, which implements any of the above-mentioned methods for detecting abnormal network resources when executed by a processor.

[0017] The method, device, electronic device, storage medium, and program product for detecting abnormal network resources provided by the present invention comprehensively consider the survival scenarios of various abnormal network resources by constructing a format information set, a behavior information set, and a semantic information set, thereby facilitating improved accuracy in acquiring target DPI data. The present invention screens out target DPI data by matching the spatiotemporal attribute data and the content attribute data of DPI data with the format information set, the behavior information set, and the semantic information set. By applying a dynamic recall architecture, the present invention overcomes the static limitations of traditional rule engines, enabling accurate acquisition of target DPI data, improving the efficiency and accuracy of acquiring target network resources, and facilitating improved efficiency and accuracy in identifying abnormal network resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0019] Figure 1 This is one of the flow charts of the abnormal network resource detection method provided by the present invention.

[0020] Figure 2 This is the second flow chart of the abnormal network resource detection method provided by the present invention.

[0021] Figure 3 It is a schematic diagram of the process of processing a QR code feature image by the QR code decoding model provided by the present invention.

[0022] Figure 4 It is a structural diagram of the device for detecting abnormal network resources provided by the present invention.

[0023] Figure 5 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0024] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0025] The following combination Figure 1-Figure 5 The present invention describes a method, device and electronic device for detecting abnormal network resources.

[0026] Figure 1 This is one of the flow charts of the abnormal network resource detection method provided by the present invention, such as Figure 1 and Figure 2 As shown, the method for detecting abnormal network resources includes steps S100 to S300, and each step is specifically described as follows.

[0027] S100: Match the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of DPI data with the preset format information set, behavior information set and semantic information set, and filter out the target DPI data based on the matching results. Any format information in the format information set is used to characterize the format characteristics of abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of abnormal DPI data. Abnormal DPI data includes DPI data carrying abnormal network resources.

[0028] Based on the preset format information set, behavior information set, and semantic information set, the target DPI data is filtered out from the DPI data. Since the process of using deep learning models to infer web page snapshots is both time-consuming and requires high machine resource consumption, especially when faced with an average daily data volume of tens of millions, it directly leads to a significant increase in processing costs. Based on this, the web page rule recall of QR codes at the front end of the process is designed to prioritize high recall rates (Recall) without overly emphasizing precision (Precision). This strategic choice is because a dedicated precision recognition module has been planned in the system architecture to capture and correct information that may have been missed or misjudged in the previous steps, thereby ensuring the accuracy and efficiency of the entire system.

[0029] The format information set includes all format features of abnormal DPI data. The behavior information set includes all behavioral features of abnormal DPI data. The semantic information set includes all semantic features of abnormal DPI data. Abnormal DPI data includes DPI data containing abnormal network resources. Feature extraction is performed on the identified abnormal DPI data to construct the format information set, behavior information set, and semantic information set. The spatiotemporal attribute data and content attribute data of the deep packet inspection DPI data are matched with the preset format information set, behavior information set, and semantic information set to identify the target DPI data.

[0030] S200: Simulate loading of the to-be-loaded URL corresponding to the target DPI data to obtain a QR code feature image.

[0031] Recall the URL corresponding to the target DPI data to obtain the URL to be loaded. A script program controls the browser automation module to simulate the loading of the URL to be loaded. Given the layout characteristics of web pages, where video content is often located in the lower half of the page, empirical analysis determined that the browser zoom ratio should be optimized to 67%. This parameter setting can avoid the problem of missing out-of-view content caused by full-screen zoom (≥100%) while ensuring the complete capture of key visual elements. A snapshot of the loaded webpage is obtained to obtain the QR code feature image.

[0032] S300: Acquire the target network resource encapsulated in the QR code feature image.

[0033] Decode the QR code feature image and obtain the target network resource encapsulated in the QR code feature image.

[0034] S400: Identify abnormal network resources among target network resources.

[0035] Perform security authentication on the target network resource (target URL) and identify anomalous network resources. For example, extract structural and content features from the target URL to obtain a feature vector. Build a Cross-Attention Alignment Model (CAAM) based on "structural heterogeneity + content encoding." Input the feature vector into the CAAM. The CAAM calculates the feature vector and identifies anomalous network resources (abnormal URLs) based on the calculation results.

[0036] The method for detecting abnormal network resources provided by an embodiment of the present invention comprehensively considers the survival scenarios of various abnormal network resources by constructing a format information set, a behavior information set, and a semantic information set, thereby facilitating improved accuracy in acquiring target DPI data. The present invention screens out target DPI data by matching the spatiotemporal attribute data and the content attribute data of DPI data with the format information set, the behavior information set, and the semantic information set. By applying a dynamic recall architecture, this method overcomes the static limitations of traditional rule engines, enabling accurate acquisition of target DPI data, improving the efficiency and accuracy of acquiring target network resources, and facilitating improved efficiency and accuracy in identifying abnormal network resources.

[0037] Optionally, before filtering out target DPI data from DPI data based on a preset format information set, behavior information set, and semantic information set, the method further includes: obtaining basic attribute data of the DPI data, preliminarily screening the DPI data based on the basic attribute data, and identifying target network resources.

[0038] The target network resource includes a target Uniform Resource Locator (URL).

[0039] Obtain basic attribute data of DPI data. The specific basic attribute data of DPI data is shown in Table 1.

[0040] Table 1 Basic attribute data of DPI data

[0041] Based on basic attribute data, DPI data whose corresponding geographical location of the base station is within the required area and the data packet transmission time is within the required time period is filtered out. Then, basic filtering and deduplication based on server IP address, server port, primary domain, URL address, user agent, server IP location, etc. are performed to obtain the target network resource (for example, the target URL).

[0042] The embodiment of the present invention adopts an active discovery technology route rather than one-by-one detection, which can better expand the monitoring scope, avoid omissions, improve security performance, upgrade business processes, and comprehensively ensure network security.

[0043] Based on the above embodiment, the spatiotemporal attribute data of deep packet inspection DPI data and the content attribute data of DPI data are matched with the preset format information set, behavior information set and semantic information set, and the target DPI data is filtered out based on the matching results, including the following steps.

[0044] Based on the matching result between the content attribute data of the DPI data and any format information, the probability that the DPI data contains the target format information is obtained. If the probability is greater than the set probability, the DPI data is used as the target DPI data.

[0045] If, based on the matching result of the content attribute data of the DPI data and any behavior information, it is determined that the DPI data contains target behavior information, and based on the matching result of the spatiotemporal attribute data of the DPI data and the target behavior information, it is determined that the occurrence of the DPI data is within the time range and spatial range of the occurrence of the target behavior information, then the DPI data will be used as the target DPI data.

[0046] The semantic vector of the content attribute data of the DPI data is extracted. If the similarity between the semantic vector of the content attribute data of the DPI data and any semantic information is greater than a set similarity, the DPI data is used as the target DPI data.

[0047] Assume that the DPI data stream is Among them, each data record includes spatiotemporal attribute data and content attribute data The spatiotemporal attribute data includes the base station ID, access start time, etc. The content attribute data includes the webpage title, webpage Hypertext Markup Language (HTML), webpage text, etc.

[0048] Based on the matching result of the content attribute data of the DPI data and any format information, the probability of the DPI data containing the target format information is obtained. If the probability is greater than the set probability, the DPI data is used as the target DPI data. The format information includes HTML tags, and the content contained therein may be the main body of the QR code image, so consider matching HTML tags. At the same time, for <object>、 <embed> Tags, etc., consider recalling web pages that match the file name suffix.

[0049] ; in, The target DPI data is determined according to the format information set. is the target format information, is the format information set, Target format information In DPI data The probability of existence in It is a content extraction function that converts DPI data into a structured representation. To set the probability, is the target DPI dataset.

[0050] If the DPI data's content attribute data matches any behavior information and it is determined that the DPI data contains target behavior information, and if the DPI data's spatiotemporal attribute data matches the target behavior information and it is determined that the DPI data occurred within the time and space ranges of the target behavior information, then the DPI data will be used as the target DPI data. For example, from the user DPI traffic side, if the URL contains a web page jump relationship in a user's DPI record, it means that the page may contain a QR code image, and the recall will be based on this jump relationship. Summarize the temporal behavior of mobile users, summarize the behavior patterns, and extract suspicious URLs within a specified time period.

[0051] The behavioral information set includes a dynamically updated set of suspicious URLs, for example, H1={'%antchats.im%','%ya.cn%','%smallchat.chat%','%isweetalk.com%','%zhifeiji.chat%','%ourchat.com.cn%'}.

[0052] ; in, The target DPI data is determined based on the behavior information set. For DPI data The domain name information extracted from is the behavior information set, To set time periods based on time-sensitive functions The returned value is used to represent the recorded DPI data Whether the timestamp is within the set time period (the time range when the target behavior information occurs), is the time decay factor, DPI data Time attributes (spatial attribute data), DPI data spatial attributes (spatial and temporal attribute data), is the area code, Set the area code for the region.

[0053] The semantic information set includes a set of keywords that imply network resources, such as "login," "register," "scan," and "transfer." The semantic vector of the content attribute data of the DPI data is extracted. If the similarity between the semantic vector of the content attribute data of the DPI data and any semantic information in the semantic information set is greater than a set similarity, the DPI data is used as the target DPI data.

[0054] ; in, is the target DPI data determined based on the semantic information set, Semantic information set Any semantic information in Semantic information The semantic vector of DPI data The semantic vector of the content attribute data, is the arc cosine function, which is used to calculate the angle between two semantic vectors. is the semantic matching parameter threshold (in radians), It is based on the setting similarity. When , it indicates that the similarity between the semantic vector of the content attribute data of the DPI data and the semantic information is greater than the set similarity.

[0055] The target DPI data determined according to the format information set, the target DPI data determined according to the behavior information set, and the target DPI data determined according to the semantic information set are merged to obtain the final target DPI data set. .

[0056] The present invention identifies target DPI data based on format information sets, behavior information sets, and semantic information sets, comprehensively considering the survival scenarios of various hidden network resources, and applies a dynamic recall architecture to break through the static limitations of traditional rule engines, thereby achieving accurate acquisition of target DPI data.

[0057] Based on the above embodiment, simulating the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image includes the following steps.

[0058] In the process of simulating the loading of the URL to be loaded, a snapshot capture method based on pixel-level rendering is used to capture the loading web page image.

[0059] The loaded web page image is encoded and stored according to the red, green and blue three-channel standard format to obtain a QR code feature image.

[0060] The loading of the URL to be loaded is simulated. During the webpage snapshot acquisition phase, pixel-level rendering snapshot capture methods (e.g., Canvas rendering) are used to dynamically generate QR code features for 83.6% of malicious URLs in the current online ecosystem (traditional crawler techniques based on Document Object Model (DOM) parsing cannot effectively identify them). This pixel-level rendering-based snapshot capture technology is then used to capture data. Finally, the captured screenshots are encoded and stored in a standard red, green, and blue (RGB) three-channel format to obtain QR code feature images. To ensure the consistency of the training dataset with real-world business scenarios, 12 technical parameters, such as browser kernel version, window resolution, and color space, are strictly synchronized between the collection environment and the production environment.

[0061] The present invention intercepts the loaded web page image through a snapshot capture method of pixel-level rendering, encodes and stores the loaded web page image in a standard red, green and blue three-channel format, and obtains a QR code feature image, solving the problem that traditional methods cannot detect dynamically generated QR codes (such as Canvas rendering).

[0062] Based on the above embodiment, obtaining the target network resource encapsulated in the QR code feature image includes the following steps.

[0063] The QR code feature image is input into the QR code decoding model to obtain feature data of the QR code feature image output by the QR code decoding model; wherein the QR code decoding model uses convolution kernels with different strides to extract features of different scales on the QR code feature image to obtain multiple multi-scale feature maps, and deformable convolution, aggregation and activation are performed on each adjacent multi-scale feature map in the multiple multi-scale feature maps to obtain feature data.

[0064] Based on the version information and format information of the QR code, the feature data is decoded to obtain the target network resource.

[0065] The QR code decoding model is based on the Faster Region-based Convolutional Neural Network (Faster R-CNN), trained based on sample QR code feature images and labels of sample target network resources.

[0066] The QR code feature image is input into the QR code decoding model, which extracts and fuses features from the QR code feature image to obtain fused features. The QR code decoding model decodes the fused features to obtain the target network resource (target URL).

[0067] like Figure 3 As shown in the figure, the QR code decoding model adds an improved Deformable Feature Pyramid Network (DFPN) to the traditional Faster R-CNN. By adding sub-pixel convolution, the high-level feature map is enlarged to the same size as the previous layer and then combined with the corresponding feature map of the previous layer.

[0068] First, the QR code feature image input to the QR code decoding model is processed by a set of basic convolutional units in the model. Convolutional kernels with different amplitudes are then used to perform multi-scale feature sampling, outputting a multi-scale feature map. This method uses the conv1-conv4_x layers of the Residual Network-50 (ResNet-50) to output the multi-scale feature map. Secondly, based on the Feature Pyramid Network (FPN), deformable convolution is introduced, with its offset field predicted by a lightweight subnetwork. Deformable convolution is then performed on the multi-scale feature map.

[0069] ; in, is the offset of the deformable convolution, for, For the Layer multi-scale feature map, is a lightweight convolutional subnetwork, is the number of convolution kernel sampling points.

[0070] By aggregating feature maps of the same size, higher-level convolutional layers will have higher-level feature semantics. This feature pyramid network can effectively aggregate high-level semantic features with low-level positional features, effectively improving the detection and recognition of small-sized QR codes. The formulas for deformable convolution, aggregation, and activation are as follows.

[0071] ; in, is the feature data of the QR code feature image, is the feature map, For the The feature map of the layer is adjacent to the feature layer index set (for example, ), is a deformable convolution operation, For the feature map Perform deformation alignment, is the activation function.

[0072] Based on the QR code's data encoding rules, information is decoded by reading the characteristic data of the QR code's feature image module by module. This process begins with the QR code's outer modules and gradually scans inward. Combining the QR code's version information and format information, the corresponding bit sequence is accurately parsed. Version information determines the QR code's size and data capacity, while format information includes key parameters such as the error correction level and masking mode, which are crucial for correctly parsing the characteristic data. After completing the initial characteristic data parsing, the decoded bit sequence is further processed according to the standard QR code protocol, ultimately extracting the target network resource (target URL information) encapsulated in the QR code.

[0073] This invention obtains feature data by acquiring multi-scale feature maps and performing deformable convolution, aggregation, and activation on adjacent multi-scale feature maps, thereby improving the robustness of detecting distorted or tilted QR codes. Furthermore, the QR code decoding model of the present invention can effectively aggregate high-level semantic features with low-level positional features, effectively improving the detection and recognition of small-sized QR codes and significantly increasing the fault tolerance of the QR code decoding model. Through deformation perception and multi-scale fusion, the geometric distortion problem of web QR codes is resolved.

[0074] Based on the above embodiment, identifying abnormal network resources in target network resources includes: extracting structural features of the target network resources to obtain a structural feature vector; extracting content features of the target network resources to obtain a content feature vector; fusing the structural feature vector and the content feature vector to obtain a fusion vector; and determining a target probability that the target network resource belongs to an abnormal network resource based on the fusion vector, and when the target probability is greater than a set value, determining that the target network resource belongs to an abnormal network resource.

[0075] Structural features are extracted from the target web resource (target URL) to obtain a structural feature vector. The structural feature vector is shown in Table 2.

[0076] Table 2 Structural feature vectors of target URLs

[0077] Content features are extracted from the target network resource to obtain a content feature vector. The content feature vector is shown in Table 3. To ensure user network security, many websites typically restrict cross-domain access. This is because every time a user initiates a Hypertext Transfer Protocol (HTTP) request, it carries cookie information corresponding to the request address. For example, when a user logs into their online banking account, the browser sends a cookie containing user authentication information to the bank's server. The bank server records the unique identifier associated with the user account (such as the user ID) in this cookie. If arbitrary cross-domain access is allowed, if a user mistakenly visits a counterfeit bank website (an anomaly) and executes anomalous code, the anomaly website can send an HTTP request containing the forged cookie information to the bank's server. Because the bank server verifies the cookie to confirm that the request comes from a legitimate user, the request will be responded to, resulting in the leakage of sensitive user information. Therefore, legitimate websites typically prohibit cross-domain requests to avoid such security risks. By analyzing the HTML source code of the counterfeit bank website, it is possible to identify differences in the content feature vectors between it and the legitimate website.

[0078] Table 3 Content feature vectors of target URLs

[0079] The structural feature vector and the content feature vector are fused to obtain a fused vector, including: generating a query vector based on the structural feature vector and the query weight matrix; generating a key vector based on the content feature vector and the key weight matrix; generating a value vector based on the content feature vector and the value weight matrix; and performing attention fusion on the query vector, the key vector, and the value vector to obtain a fused vector.

[0080] A cross-view collaborative attention model (CAAM) based on "structural heterogeneity + content encoding" is constructed. CAAM is used to identify the security of target URLs and identify abnormal URLs. The formula for calculating the fusion vector is as follows.

[0081] ; in, is the query vector, is the key vector, is a value vector, is the query weight matrix, is the key weight matrix, is the value weight matrix, is the structural feature vector, is the content feature vector, is the fusion vector, For dimension.

[0082] The present invention improves the accuracy of target network resource feature extraction and feature fusion by performing attention fusion on structure feature vectors and content feature vectors.

[0083] Based on the fusion vector, the target probability that the target network resource (target URL) belongs to an abnormal network resource is obtained.

[0084] ; in, is the target probability that the target URL belongs to an abnormal network resource, is the weight matrix, is the fusion vector, is the initial base.

[0085] When the target probability is greater than the set value, the target network resource (target URL) is determined to be an abnormal URL. When the target probability is less than or equal to the set value, the target URL is determined to be a normal URL.

[0086] The present invention achieves accurate identification of abnormal network resources by performing attention fusion on structural feature vectors and content feature vectors to obtain target probability.

[0087] Optional, such as Figure 2 As shown, before performing security appraisal on the target network resources and identifying abnormal network resources, it also includes screening and identifying abnormal network resources through a pre-built gray list library (for example, URLs that have been identified as phishing websites).

[0088] Furthermore, the Cross-View Attention Collaborative Model (CAAM), based on "structural heterogeneity + content encoding," is trained on a pre-set model based on sample web resources (e.g., sample URLs) and labels indicating whether the sample URLs are abnormal or normal. The loss function for the Cross-View Attention Collaborative Model (CAAM) is as follows.

[0089] ; in, is the loss function, is the balance coefficient, is the cross entropy loss, is the maximum mean difference loss, is the number of abnormal sample URLs, is the number of normal sample URLs, and For the sample URL, is the mapping function of the reproducing kernel Hilbert space, and the Gaussian kernel is used by default. is the abnormal sample URL, This is a normal sample URL.

[0090] The following describes the abnormal network resource detection device provided by the present invention. The abnormal network resource detection device described below and the abnormal network resource detection method described above can refer to each other.

[0091] like Figure 4 As shown, a device for detecting abnormal network resources includes an acquisition module 401, a decoding module 402 and an identification module 403.

[0092] The first acquisition module 401 is used to match the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of DPI data with a preset format information set, behavior information set and semantic information set, and filter out target DPI data based on the matching results. Any format information in the format information set is used to characterize the format characteristics of abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of abnormal DPI data. Abnormal DPI data includes DPI data carrying abnormal network resources.

[0093] The second acquisition module 402 is used to simulate loading of the to-be-loaded website corresponding to the target DPI data to obtain a QR code feature image.

[0094] The third acquisition module 403 is used to acquire the target network resource encapsulated in the QR code feature image.

[0095] The identification module 404 is configured to identify abnormal network resources among the target network resources.

[0096] The abnormal network resource detection device provided by the embodiments of the present invention comprehensively considers the survival scenarios of various abnormal network resources by constructing a format information set, a behavior information set, and a semantic information set, thereby facilitating improved accuracy in acquiring target DPI data. The present invention screens out target DPI data by matching the spatiotemporal attribute data and the content attribute data of the DPI data with the format information set, the behavior information set, and the semantic information set. By applying a dynamic recall architecture, the invention overcomes the static limitations of traditional rule engines, enabling accurate acquisition of target DPI data, improving the efficiency and accuracy of acquiring target network resources, and facilitating improved efficiency and accuracy in identifying abnormal network resources.

[0097] In one embodiment, the first acquisition module 401 is used to: obtain the probability that the DPI data contains target format information based on the matching result of the content attribute data of the DPI data and any format information, and if the probability is greater than the set probability, use the DPI data as the target DPI data; if based on the matching result of the content attribute data of the DPI data and any behavior information, it is determined that the DPI data contains target behavior information, and based on the matching result of the spatiotemporal attribute data of the DPI data and the target behavior information, it is determined that the occurrence of the DPI data is within the time range and spatial range of the occurrence of the target behavior information, then use the DPI data as the target DPI data; extract the semantic vector of the content attribute data of the DPI data, and if the similarity between the semantic vector of the content attribute data of the DPI data and any semantic information is greater than the set similarity, use the DPI data as the target DPI data.

[0098] In one embodiment, the second acquisition module 402 is used to: in the process of simulating the loading of the URL to be loaded, capture the loaded web page image based on the snapshot capture method of pixel-level rendering; encode and store the loaded web page image in the red, green and blue three-channel standard format to obtain a QR code feature image.

[0099] In one embodiment, the identification module 404 is used to: extract structural features of the target network resource to obtain a structural feature vector; extract content features of the target network resource to obtain a content feature vector; fuse the structural feature vector and the content feature vector to obtain a fusion vector; based on the fusion vector, determine the target probability that the target network resource belongs to an abnormal network resource, and when the target probability is greater than a set value, determine that the target network resource belongs to an abnormal network resource.

[0100] In one embodiment, the recognition module 404 is used to: generate a query vector based on the structural feature vector and the query weight matrix; generate a key vector based on the content feature vector and the key weight matrix; generate a value vector based on the content feature vector and the value weight matrix; and perform attention fusion on the query vector, the key vector, and the value vector to obtain a fusion vector.

[0101] In one embodiment, the third acquisition module 403 is used to: input the QR code feature image into the QR code decoding model, and obtain the feature data of the QR code feature image output by the QR code decoding model; wherein the QR code decoding model uses convolution kernels with different strides to perform feature extraction of different scales on the QR code feature image to obtain multiple multi-scale feature maps, and perform deformable convolution, aggregation and activation on each adjacent multi-scale feature map in the multiple multi-scale feature maps to obtain feature data; based on the version information of the QR code and the format information of the QR code, the feature data is decoded to obtain the target network resources.

[0102] Figure 5 An example of a physical structure diagram of an electronic device is shown below. Figure 5 As shown, the electronic device may include: a processor (processor) 510, a communication interface (Communications Interface) 520, a memory (memory) 530 and a communication bus 540, wherein the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logic instructions in the memory 530 to execute a method for detecting abnormal network resources, which includes: matching the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of the DPI data with a preset format information set, a behavior information set, and a semantic information set, and filtering out target DPI data based on the matching results, wherein any format information in the format information set is used to characterize the format characteristics of the abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of the abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of the abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; simulating the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image; obtaining the target network resource encapsulated in the QR code feature image; and identifying the abnormal network resources in the target network resource.

[0103] Furthermore, the logic instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0104] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the detection method of abnormal network resources provided by the above methods, the method including: matching the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of DPI data with a preset format information set, behavior information set and semantic information set, and filtering out target DPI data based on the matching results, any format information in the format information set is used to characterize the format characteristics of abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; simulating the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image; obtaining the target network resource encapsulated in the QR code feature image; and identifying the abnormal network resources in the target network resource.

[0105] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the detection method for abnormal network resources provided by the above-mentioned methods, the method comprising: matching the spatiotemporal attribute data of deep packet inspection (DPI) data and the content attribute data of DPI data with a preset format information set, a behavior information set, and a semantic information set, screening out target DPI data based on the matching results, any format information in the format information set being used to characterize the format characteristics of the abnormal DPI data, any behavior information in the behavior information set being used to characterize the behavior characteristics of the abnormal DPI data, and any voice information in the semantic information set being used to characterize the semantic characteristics of the abnormal DPI data; the abnormal DPI data including DPI data carrying abnormal network resources; simulating the loading of the URL to be loaded corresponding to the target DPI data to obtain a QR code feature image; obtaining the target network resource encapsulated in the QR code feature image; and identifying the abnormal network resources in the target network resource.

[0106] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0107] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0108] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.< / object>

Claims

1. A method for detecting abnormal network resources, characterized in that: include: Matching the spatiotemporal attribute data and content attribute data of deep packet inspection (DPI) data with a preset format information set, behavior information set, and semantic information set, and filtering out target DPI data based on the matching results, wherein any format information in the format information set is used to characterize the format characteristics of abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; Simulate loading of the to-be-loaded URL corresponding to the target DPI data to obtain a QR code feature image; Obtain the target network resource encapsulated in the QR code feature image; Abnormal network resources among the target network resources are identified.

2. The method for detecting abnormal network resources according to claim 1, characterized in that: The step of matching the spatiotemporal attribute data of the deep packet inspection (DPI) data and the content attribute data of the DPI data with a preset format information set, a behavior information set, and a semantic information set, and filtering out target DPI data based on the matching results, includes: Based on a matching result between the content attribute data of the DPI data and any of the format information, obtaining a probability that the DPI data contains the target format information, and if the probability is greater than a set probability, using the DPI data as the target DPI data; If, based on a match result between the content attribute data of the DPI data and any of the behavior information, it is determined that the DPI data contains target behavior information, and based on a match result between the spatiotemporal attribute data of the DPI data and the target behavior information, it is determined that the DPI data occurs within the time range and spatial range of the target behavior information, then the DPI data is used as the target DPI data; The semantic vector of the content attribute data of the DPI data is extracted. If the similarity between the semantic vector of the content attribute data of the DPI data and any of the semantic information is greater than a set similarity, the DPI data is used as the target DPI data.

3. The method for detecting abnormal network resources according to claim 1, wherein: The simulating loading of the to-be-loaded website corresponding to the target DPI data to obtain a QR code feature image includes: In the process of simulating the loading of the URL to be loaded, a snapshot interception method based on pixel-level rendering is used to intercept the loading web page image; The loaded web page image is encoded and stored according to a red, green and blue three-channel standard format to obtain the QR code feature image.

4. The method for detecting abnormal network resources according to claim 1, wherein: The identifying abnormal network resources in the target network resources includes: Extracting structural features of the target network resource to obtain a structural feature vector; Extracting content features of the target network resource to obtain a content feature vector; fusing the structural feature vector and the content feature vector to obtain a fused vector; Based on the fusion vector, a target probability that the target network resource belongs to the abnormal network resource is determined. When the target probability is greater than a set value, it is determined that the target network resource belongs to the abnormal network resource.

5. The method for detecting abnormal network resources according to claim 4, characterized in that: The fusing the structural feature vector and the content feature vector to obtain a fused vector includes: Generate a query vector based on the structure feature vector and the query weight matrix; generate a key vector based on the content feature vector and the key weight matrix; generate a value vector based on the content feature vector and the value weight matrix; Perform attention fusion on the query vector, the key vector, and the value vector to obtain the fused vector.

6. The method for detecting abnormal network resources according to claim 1, wherein: The obtaining of the target network resource encapsulated in the QR code feature image includes: Inputting the QR code feature image into a QR code decoding model to obtain feature data of the QR code feature image output by the QR code decoding model; wherein the QR code decoding model uses convolution kernels with different strides to extract features of different scales on the QR code feature image to obtain multiple multi-scale feature maps, and performing deformable convolution, aggregation, and activation on adjacent multi-scale feature maps in the multiple multi-scale feature maps to obtain the feature data; Based on the version information and format information of the QR code, the characteristic data is decoded to obtain the target network resource.

7. A device for detecting abnormal network resources, characterized in that: include: A first acquisition module is configured to match the spatiotemporal attribute data and content attribute data of deep packet inspection (DPI) data with a preset format information set, a behavior information set, and a semantic information set, and filter out target DPI data based on the matching results, wherein any format information in the format information set is used to characterize the format characteristics of abnormal DPI data, any behavior information in the behavior information set is used to characterize the behavior characteristics of the abnormal DPI data, and any voice information in the semantic information set is used to characterize the semantic characteristics of the abnormal DPI data; the abnormal DPI data includes DPI data carrying abnormal network resources; The second acquisition module is used to simulate loading the to-be-loaded website corresponding to the target DPI data to obtain a QR code feature image; A third acquisition module is used to acquire the target network resource encapsulated in the QR code feature image; The identification module is used to identify abnormal network resources in the target network resources.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method for detecting abnormal network resources according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting abnormal network resources according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method for detecting abnormal network resources according to any one of claims 1 to 6 is implemented.