Webpage detection processing method and device

By utilizing user action data to perform anomaly detection within the detection container deployed in the application and converting it into a trust level, and then matching the anomalies with response strategies, the system addresses the lack of flexibility and security in third-party webpage detection, thereby improving application stability and user experience.

CN120915692APending Publication Date: 2025-11-07ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510976095.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

As applications become more complex and integrate more third-party pages, the flexibility and security of anomaly detection become insufficient, impacting application stability and user experience.

Method used

The detection container deployed in the application determines the anomaly detection method based on user operation data, acquires webpage detection data for anomaly detection, converts it into a trust level using a trust conversion model, and matches the response strategy for anomaly response handling, reducing code interference to third-party webpages.

Benefits of technology

It enhances the flexibility and security of anomaly detection, ensures stable application operation, reduces interference with third-party web pages, and improves the timeliness and accuracy of anomaly response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915692A_ABST
    Figure CN120915692A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a webpage detection processing method and device.The webpage detection processing method comprises the steps that in the webpage detection process, an anomaly detection mode of a third-party webpage is determined through user operation data of the third-party webpage in an application program, acquiring corresponding webpage detection data according to the exception detection mode, performing exception detection to obtain an exception type and an exception index, converting the exception index into a credible level of the exception type, performing response strategy matching by combining the exception type and the credible level to obtain an exception response strategy, and performing exception response processing. Therefore, the abnormal response to the third-party webpage is realized through the detection container deployed by the application program.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present document relates to the technical field of data processing, and particularly relates to a webpage detection processing method and device. BACKGROUND

[0002] With the continuous development and popularization of Internet technology, application programs based on Internet technology bring convenience to a large number of users, and the services provided by powerful application programs to users may exist in a multi-party cooperation situation, for example, some pages in the application program need to be provided by a third party, and the overall service capability of the application program is improved through the pages provided by the third party, so that the service of the application program is more perfect, but with the gradual increase of the complexity of the application program, the pages provided by the third party accessed in the application program are also increasing, which brings a certain challenge to the provider of the application program. SUMMARY

[0003] One or more embodiments of the present specification provide a webpage detection processing method applied to a detection container of an application program deployment, the method comprising: determining an abnormal detection mode of a third-party webpage in the application program according to user operation data of the third-party webpage. The third-party webpage is loaded through a webpage container of the application program deployment. Webpage detection data corresponding to the abnormal detection mode is obtained and abnormal detection is performed according to the abnormal detection mode, to obtain an abnormal type and an abnormal index. The abnormal index is input into a trust conversion model to convert the trust level of the abnormal type to obtain a trust level. The abnormal response strategy is obtained and abnormal response processing is performed according to the response strategy matching of the abnormal type and the trust level.

[0004] One or more embodiments of the present specification provide a webpage detection processing device running in a detection container of an application program deployment, the device comprising: a mode determination module configured to determine an abnormal detection mode of a third-party webpage in the application program according to user operation data of the third-party webpage. The third-party webpage is loaded through a webpage container of the application program deployment. An abnormal detection module configured to obtain webpage detection data corresponding to the abnormal detection mode and perform abnormal detection according to the abnormal detection mode, to obtain an abnormal type and an abnormal index. A level conversion module configured to input the abnormal index into a trust conversion model to convert the trust level of the abnormal type to obtain a trust level. An abnormal response module configured to obtain an abnormal response strategy and perform abnormal response processing according to the response strategy matching of the abnormal type and the trust level.

[0005] The one or more embodiments of the specification provide a webpage detection processing device, comprising: a processor; and a memory configured to store computer executable instructions which, when executed, cause the processor to: determine an abnormality detection manner of a third-party webpage according to user operation data of the third-party webpage in an application. The third-party webpage is loaded through a webpage container deployed by the application. Webpage detection data corresponding to the abnormality detection manner is obtained and abnormality detection is performed according to the abnormality detection manner, to obtain an abnormality type and an abnormality index. The abnormality index is input into a trust conversion model to convert a trust level of the abnormality type to obtain a trust level. A response strategy matching is performed according to the abnormality type and the trust level, to obtain an abnormality response strategy and perform abnormality response processing.

[0006] The one or more embodiments of the specification provide a computer readable storage medium for storing computer executable instructions which, when executed, implement the following steps: determining an abnormality detection manner of a third-party webpage according to user operation data of the third-party webpage in an application. The third-party webpage is loaded through a webpage container deployed by the application. Webpage detection data corresponding to the abnormality detection manner is obtained and abnormality detection is performed according to the abnormality detection manner, to obtain an abnormality type and an abnormality index. The abnormality index is input into a trust conversion model to convert a trust level of the abnormality type to obtain a trust level. A response strategy matching is performed according to the abnormality type and the trust level, to obtain an abnormality response strategy and perform abnormality response processing. BRIEF DESCRIPTION OF DRAWINGS

[0007] In order to more clearly illustrate the technical solutions in the one or more embodiments of the specification or the prior art, the drawings needed in the embodiment or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the specification, and other drawings can be obtained by those skilled in the art without creative labor. Figure 1 A schematic diagram of an embodiment environment of a webpage detection processing method provided by the one or more embodiments of the specification; Figure 2 A webpage detection processing method processing flowchart provided by the one or more embodiments of the specification; Figure 3 A schematic diagram of a third-party webpage provided by the one or more embodiments of the specification; Figure 4 A webpage detection processing method processing flowchart applied to a car insurance service scene provided by the one or more embodiments of the specification; Figure 5A schematic diagram of an embodiment of a webpage detection processing device provided for one or more embodiments of the present specification; Figure 6 A structural schematic diagram of an embodiment of a webpage detection processing device provided for one or more embodiments of the present specification. DETAILED DESCRIPTION

[0008] In order to enable persons skilled in the art to better understand the technical solutions in one or more embodiments of the present specification, the technical solutions in one or more embodiments of the present specification will be described clearly and completely in conjunction with the accompanying drawings of one or more embodiments of the present specification. Obviously, the described embodiments are only a part of the embodiments of the present specification, rather than all the embodiments. Based on one or more embodiments of the present specification, all other embodiments obtained by persons skilled in the art without creative labor should belong to the protection scope of the present document.

[0009] The webpage detection processing method provided by one or more embodiments of the present specification can be applied to the implementation environment of webpage detection, and the implementation environment comprises at least: Figure 1 a detection container 101 for application deployment, a webpage container 102 for application deployment; The detection container 101 for application deployment is configured to determine an abnormal detection manner of a third-party webpage according to user operation data of the third-party webpage in the application, perform abnormal detection on webpage detection data according to the abnormal detection manner to obtain an abnormal type and an abnormal index, perform a trust level conversion of the abnormal type on the abnormal index to obtain a trust level, and perform an abnormal response processing according to the trust level and the abnormal index. The application can run on a terminal device, which can be a mobile phone, a personal computer, a tablet computer, an e-book reader, a wearable device, a device for information interaction based on AR (Augmented Reality) / VR (Virtual Reality), a laptop computer, etc.

[0010] The webpage container 102 for application deployment is configured to load the third-party webpage, and can also be configured to provide a webpage service of the third-party webpage to a user.

[0011] In addition, the implementation environment can also comprise an application 103 and a server 104 for the application, which can be configured to provide relevant services in cooperation with the application. The server 104 can run on a server. The server can be one or more servers, a server cluster composed of several servers, or a cloud server of a cloud computing platform. ​The implementation environment can also include a web service end 105 of a third-party webpage, which can be used to load the third-party webpage in cooperation with the web container 102 of the application deployment, and can also be used to provide web services of the third-party webpage to users in cooperation with the web container 102 of the application deployment. The web service end 105 can run on a web server. The web server can be one or more servers, a server cluster composed of several servers, or a cloud server of a cloud computing platform.

[0012] In the implementation environment, the detection container 101 of the application deployment determines an abnormality detection mode of the third-party webpage according to user operation data of the third-party webpage in the application, acquires corresponding web detection data according to the abnormality detection mode and performs abnormality detection, obtains an abnormality type and an abnormality index, converts the abnormality index into a trust level of the abnormality type to obtain a trust level, matches a response strategy in combination with the abnormality type and the trust level, obtains an abnormality response strategy and performs abnormality response processing, so as to realize abnormality response of the third-party webpage through the detection container of the application deployment. In this process, the third-party webpage is loaded through the web container 102 of the application deployment.

[0013] One or more embodiments of the web detection processing method provided in the specification are as follows: Referring to Figure 2 The web detection processing method provided in the embodiment can be applied to the detection container of the application deployment, and specifically includes steps S202 to S208.

[0014] Step S202: Determine an abnormality detection mode of a third-party webpage according to user operation data of the third-party webpage in an application.

[0015] The application program in the embodiment refers to an application program providing any service function, such as a payment application program, a transaction application program, a social application program, a function application program, or a guarantee application program. The guarantee application program can be an insurance application program. The application program can be a non-browser application, that is, the application program can be an application program other than a browser.

[0016] The third-party webpage refers to a webpage provided by a third-party institution, and the webpage can be an H5 (Hyper Text Markup Language 5, fifth generation Hyper Text Markup Language) page. Optionally, the third-party webpage is loaded through a webpage container deployed by the application program. Specifically, the third-party webpage can be loaded based on a third-party webpage address through the webpage container deployed by the application program. The third-party webpage address can be a URL (Uniform Resource Locator, uniform resource locator) address. The third-party webpage can be displayed in any one service in the application program, such as a guarantee service (insurance service) in the application program, a government service in the application program, or a resource service in the application program. Optionally, the third-party webpage is displayed in a vehicle guarantee service in the application program. The vehicle guarantee service includes a lightweight application for vehicle guarantee. Specifically, the vehicle guarantee service can be a vehicle insurance service. The vehicle guarantee service can be a lightweight application or a light application for vehicle guarantee, such as a vehicle insurance light application. The light application can be a small program, a public number, a service number, or a webpage application in the application program. The webpage application can be an H5 service or an H5 application. Specifically, the application or service can be provided through an H5 page. Optionally, the third-party webpage is used to provide a guarantee quotation for vehicle guarantee to the user through the third-party institution. For example, the third-party webpage can be used to provide a vehicle insurance quotation, vehicle insurance participation, or vehicle insurance claim to the user through the third-party institution. The third-party institution can be a third-party guarantee institution or a third-party insurance institution.

[0017] The user operation data of the third-party webpage in the application program refers to operation data obtained by the user performing an operation on the third-party webpage. The user operation data can include an operation link of the user on the third-party webpage, a stay duration of the user on the third-party webpage, and / or an operation frequency of the same operation performed by the user on the third-party webpage. The abnormal detection mode of the third-party webpage refers to an abnormal detection mode for detecting the third-party webpage.

[0018] In order to improve the timeliness and convenience of the detection container for detecting the third-party webpage, the detection container can deploy a webpage detection script. The webpage detection script is executed after the third-party webpage is loaded in the webpage container.

[0019] In specific implementation, the abnormal detection manner of the third-party webpage is determined according to the user operation data of the third-party webpage in the application program, so as to improve the detection flexibility of the third-party webpage through different abnormal detection manners of the third-party webpage. Optionally, the abnormal detection manner is determined after the user operation data triggers a detection condition, and the user operation data triggering the detection condition includes that the user's stay duration on the third-party webpage exceeds a duration threshold, and / or the operation frequency of the same operation performed by the user on the third-party webpage exceeds a frequency threshold.

[0020] Specifically, the user's stay duration on the third-party webpage or the operation frequency of the same operation performed by the user on the third-party webpage can be obtained, and if the stay duration exceeds the duration threshold or the operation frequency exceeds the frequency threshold, it is determined that the user operation data triggers the detection condition. Alternatively, the user's stay duration on the third-party webpage can be obtained, and the operation frequency of the same operation performed by the user on the third-party webpage can be determined according to the operation link of the third-party webpage in the application program, and if the stay duration exceeds the duration threshold or the operation frequency exceeds the frequency threshold, it is determined that the user operation data triggers the detection condition. Alternatively, the user's stay duration on the third-party webpage and the operation frequency of the same operation performed by the user on the third-party webpage can be determined, and if the stay duration exceeds the duration threshold or the operation frequency exceeds the frequency threshold, it is determined that the user operation data triggers the detection condition. Alternatively, the user's stay duration on the third-party webpage and the operation frequency of the same operation performed by the user on the third-party webpage can be determined, and if the stay duration exceeds the duration threshold and the operation frequency exceeds the frequency threshold, it is determined that the user operation data triggers the detection condition.

[0021] In actual application, in the case that the third-party webpage is abnormal, the user operation data of the third-party webpage is different, which may represent different abnormal situations or types of the third-party webpage. To improve the detection flexibility of the abnormal detection of the third-party webpage, different abnormal detection manners are provided for different abnormal situations or types, to improve the effectiveness and pertinence of the abnormal detection. In an optional implementation provided by the embodiment, in the process of determining the abnormal detection manner of the third-party webpage according to the user operation data of the third-party webpage in the application program, the following operation is performed: obtaining an operation category according to the user operation data, and determining the abnormal detection manner based on the operation category.

[0022] Optionally, the operation category includes a refresh category in which the refresh frequency of the third-party webpage exceeds a frequency threshold, an exit category in which the trigger frequency of an exit control triggering exit from the third-party webpage exceeds a preset frequency, a trigger category in which the trigger frequency of a webpage control contained in the third-party webpage exceeds a specific frequency, or a non-operation category in which the non-operation duration of the third-party webpage exceeds a duration threshold.

[0023] The operation category refers to a category of operations performed by the user on the third-party webpage. The webpage control included in the third-party webpage can be an interactive control included in the third-party webpage for interaction. The webpage control can be the same webpage control, that is, the triggering category can be a triggering category in which the triggering frequency of triggering the same webpage control included in the third-party webpage exceeds a specific frequency. The unoperation category can specifically be an unoperation category in which the unoperation duration of the user on the third-party webpage exceeds a duration threshold.

[0024] Specifically, the operation category can be obtained according to operation category identification based on the user operation data, and the abnormality detection manner matched with the operation category can be queried in the detection manner table.

[0025] It should be noted that the operation of determining the abnormality detection manner of the third-party webpage according to the user operation data of the third-party webpage in the application program can be replaced by determining the abnormality detection manner of the third-party webpage according to the user operation data of the third-party webpage in the application program, and other processing steps provided in the present embodiment form a new implementation manner.

[0026] In step S204, corresponding webpage detection data is obtained according to the abnormality detection manner, and abnormality detection is performed to obtain an abnormality type and an abnormality index.

[0027] In the present step, corresponding webpage detection data is obtained according to the abnormality detection manner of the third-party webpage, and abnormality detection is performed to obtain an abnormality type and an abnormality index of the third-party webpage. In this way, the flexibility and pertinence of abnormality detection are improved by providing different abnormality detection manners for abnormality detection of the third-party webpage.

[0028] The webpage detection data described in the present embodiment refers to detection data required for abnormality detection of the third-party webpage. The webpage detection data can include webpage attribute data of the third-party webpage, and can also include webpage association data of the third-party webpage. The webpage association data can be association data associated with the third-party webpage. Optionally, the webpage detection data includes at least one of the following: user operation data, webpage snapshot log obtained by loading the third-party webpage in a webpage container, webpage loading log, webpage running log of the third-party webpage collected by the webpage container, and device state data of a terminal device on which the application program runs.

[0029] The webpage loading log refers to a loading log obtained by loading the third-party webpage in a webpage container. The webpage snapshot log can be a webpage snapshot log collected by the webpage container by loading the third-party webpage. The webpage running log can be collected during the interaction between the third-party webpage and the user in the webpage container. Specifically, the webpage running log can be collected by the webpage container during the interaction between the third-party webpage and the user in the webpage container. The device state data includes network state data and / or power state data.

[0030] The abnormal type refers to an abnormal type of the third-party webpage, and the abnormal type can include a white screen type, a trigger non-response type, and / or an abnormal type in which an abnormal prompt exists on the third-party webpage, and the abnormal type can further include other abnormal types. The abnormal index can be an index representing an abnormal probability of the third-party webpage or an index representing an abnormal degree of the third-party webpage, and the abnormal index can include an abnormal probability, an abnormal degree, or an abnormal score.

[0031] In specific implementation, in order to ensure flexibility of performing abnormal detection while improving comprehensiveness of performing abnormal detection, in the first optional implementation provided by the embodiment, in the process of acquiring corresponding webpage detection data according to an abnormal detection manner and performing abnormal detection to obtain an abnormal type and an abnormal index, the abnormal type and the abnormal index can be obtained by performing abnormal type identification and abnormal index calculation according to user operation data of the third-party webpage, webpage snapshot logs obtained by the webpage container loading the third-party webpage, webpage loading logs, and webpage running logs, and the following operations can be specifically performed: The webpage snapshot logs obtained by the webpage container loading the third-party webpage and the webpage loading logs are acquired according to the abnormal detection manner, and the webpage running logs of the third-party webpage collected by the webpage container are acquired; The abnormal type and the abnormal index are obtained by performing abnormal type identification and abnormal index calculation according to the user operation data, the webpage snapshot logs, the webpage loading logs, and the webpage running logs.

[0032] The abnormal detection manner herein can be an abnormal detection manner corresponding to the exit category, an abnormal detection manner corresponding to the refresh category, or an abnormal detection manner corresponding to the non-operation category, or the abnormal detection manner herein can be an abnormal detection manner corresponding to the refresh category, an abnormal detection manner corresponding to the exit category, an abnormal detection manner corresponding to the trigger category, or an abnormal detection manner corresponding to the non-operation category.

[0033] On this basis, in the optional implementation provided by the embodiment, in the process of performing abnormal type identification and abnormal index calculation according to the user operation data, the webpage snapshot logs, the webpage loading logs, and the webpage running logs to obtain the abnormal type and the abnormal index, the abnormal type is determined according to an abnormal keyword of the third-party webpage in the user operation data and the webpage snapshot logs, and warning content in the webpage loading logs and the webpage running logs, and the abnormal index is calculated based on a warning level in both the user operation data and the abnormal keyword, the webpage loading logs, and the webpage running logs, and the following operations can be specifically performed: The webpage snapshot logs are parsed, the abnormal keyword of the third-party webpage is extracted from the parsed result, and the warning content and the warning level are extracted from the webpage loading logs and the webpage running logs; The abnormal type is determined according to the user operation data, the abnormal keyword and the early warning content, and the abnormal index is calculated based on the user operation data, the abnormal keyword and the early warning level.

[0034] The abnormal keyword of the third-party webpage can be an abnormal keyword representing an abnormality of the third-party webpage, for example, the abnormal keyword is a current network abnormality or a payment failure; the analysis processing can include image recognition and / or optical character recognition (OCR).

[0035] Specifically, in the process of analyzing the webpage snapshot log, the webpage snapshot log can be filtered and the filtering result can be analyzed; in the process of determining the abnormal type according to the user operation data, the abnormal keyword and the early warning content, the abnormal type can be determined according to the operation category, the abnormal keyword and the early warning content, specifically, the operation category, the abnormal keyword and the early warning content can be input into a type identification model to identify the abnormal type and obtain the abnormal type.

[0036] Further, in order to improve the comprehensiveness and accuracy of the abnormal index, the abnormal index is calculated from multiple dimensions; in an optional implementation provided by the embodiment, in the process of calculating the abnormal index based on the user operation data, the abnormal keyword and the early warning level, the following operations are performed: The user operation data is input into an operation index model to calculate an operation abnormal index and obtain the operation abnormal index, and a webpage abnormal index is calculated based on the abnormal keyword; The early warning level is converted into a log abnormal index, and the abnormal index is calculated according to the operation abnormal index, the webpage abnormal index and the log abnormal index.

[0037] Specifically, in the process of calculating the webpage abnormal index based on the abnormal keyword, the abnormal keyword can be input into a webpage index model to calculate the webpage abnormal index and obtain the webpage abnormal index; in the process of calculating the abnormal index according to the operation abnormal index, the webpage abnormal index and the log abnormal index, the operation abnormal index, the webpage abnormal index and the log abnormal index can be weighted to obtain the abnormal index.

[0038] It should be noted that in the process of identifying the exception type and calculating the exception index according to the user operation data, the webpage snapshot log, the webpage loading log and the webpage running log, the webpage snapshot log can also be filtered and parsed, the abnormal keywords of the third-party webpage are extracted from the parsing result, the warning content and the warning level are extracted from the webpage loading log and the webpage running log, the exception type is determined according to the user operation data, the webpage loading log, the webpage running log, the abnormal keywords and the warning content, and the exception index is calculated based on the user operation data, the webpage loading log, the webpage running log, the abnormal keywords and the warning level.

[0039] In addition, in the process of detecting the third-party webpage, in order to improve the comprehensiveness of the abnormal detection, and further improve the accuracy of the abnormal detection, the device state data of the terminal device running the application program can be introduced to assist in detecting the third-party webpage, and the device state data is combined with the attribute data of the third-party webpage to improve the effectiveness of the abnormal detection. In the second optional implementation provided by the embodiment, in the process of obtaining the webpage detection data according to the abnormal detection mode and performing abnormal detection to obtain the exception type and the exception index, the exception type is identified according to the user operation data and the webpage loading log obtained by loading the third-party webpage in the webpage container, and the exception index is calculated based on the user operation data, the webpage loading log, the webpage running log and the device state data. The specific operations can be as follows: According to the abnormal detection mode, the webpage loading log obtained by loading the third-party webpage in the webpage container is obtained, and the webpage running log of the third-party webpage collected by the webpage container and the device state data of the terminal device running the application program are obtained. According to the user operation data and the webpage loading log, the exception type is determined, and the exception index is calculated based on the user operation data, the webpage loading log, the webpage running log and the device state data.

[0040] The abnormal detection mode here can be the abnormal detection mode corresponding to the exit category, or the abnormal detection mode here can be the abnormal detection mode corresponding to the refresh category, the abnormal detection mode corresponding to the exit category, the abnormal detection mode corresponding to the trigger category or the abnormal detection mode corresponding to the non-operation category.

[0041] Specifically, in the process of determining the exception type according to the user operation data and the webpage loading log, the user operation data and the webpage loading log can be input into a type identification model to identify the exception type.

[0042] On this basis, in an optional implementation provided by the embodiment, in the process of calculating the abnormality index based on the user operation data, the webpage loading log, the webpage running log and the device state data, the user's stay duration on the third-party webpage and / or the operation frequency of the same operation performed by the user is determined based on the user operation data, the operation abnormality index is calculated based on the stay duration and / or the operation frequency, and the abnormality index is calculated according to the operation abnormality index, the webpage loading log, the webpage running log, the webpage snapshot log and the device state data. Specifically, the following operations can be performed: The user's stay duration on the third-party webpage and / or the operation frequency of the same operation performed by the user is determined according to the user operation data, and the operation abnormality index is calculated based on the stay duration and / or the operation frequency. The log abnormality index is calculated according to the webpage loading log and the webpage running log, the device abnormality index is calculated according to the device state data, and the abnormality index is calculated based on the operation abnormality index, the log abnormality index and the device abnormality index.

[0043] Specifically, in the process of calculating the log abnormality index according to the webpage loading log and the webpage running log, the log abnormality index can be calculated according to the warning level in the webpage loading log and the webpage running log. In the process of calculating the abnormality index based on the operation abnormality index, the log abnormality index and the device abnormality index, the abnormality index can be obtained by weighted calculation based on the operation abnormality index, the log abnormality index and the device abnormality index.

[0044] It should be noted that, in the process of obtaining the abnormality type and the abnormality index by acquiring corresponding webpage detection data according to the abnormality detection mode and performing abnormality detection, the abnormality type can also be identified according to the user operation data and the webpage loading log obtained by loading the third-party webpage in the webpage container to obtain the abnormality type, and the abnormality index is calculated based on the user operation data, the webpage loading log, the webpage snapshot log, the webpage running log and the device state data.

[0045] In addition, in the process of obtaining the corresponding webpage detection data according to the abnormality detection mode, performing abnormality detection, obtaining the abnormality type and the abnormality index, the user operation data, the device state data, the webpage snapshot log, the webpage running log and / or the webpage loading log can also be obtained according to the abnormality detection mode, and the abnormality detection is performed based on the user operation data, the device state data, the webpage snapshot log, the webpage running log and / or the webpage loading log to obtain the abnormality type and the abnormality index. In the process of obtaining the abnormality type and the abnormality index based on the user operation data, the device state data, the webpage snapshot log, the webpage running log and / or the webpage loading log, the abnormality type can be identified based on the user operation data, the device state data, the webpage snapshot log, the webpage running log and / or the webpage loading log to obtain the abnormality type, the operation abnormality index, the device abnormality index, the webpage abnormality index and / or the log abnormality index are calculated based on the user operation data, the device state data, the webpage snapshot log and / or the webpage loading log and the webpage running log, and the operation abnormality index, the device abnormality index, the webpage abnormality index and / or the log abnormality index are weighted to obtain the abnormality index. In the process of calculating the operation abnormality index, the device abnormality index, the webpage abnormality index and / or the log abnormality index based on the user operation data, the device state data, the webpage snapshot log and / or the webpage loading log and the webpage running log, the user operation data can be input into the operation index model to calculate the operation abnormality index, the device abnormality index can be calculated based on the device state data, the webpage snapshot log can be input into the webpage index model to calculate the webpage abnormality index, and / or the log abnormality index can be calculated based on the webpage loading log and the webpage running log. The operation index model and the webpage index model can be trained by operation abnormality samples and webpage snapshot samples, respectively.

[0046] As described above, the operation category can include a refresh category, an exit category, a trigger category or a non-operation category, the abnormality detection mode of the third-party webpage is determined based on the operation category, the corresponding webpage detection data is obtained according to the abnormality detection mode, and the abnormality detection is performed to obtain the abnormality type and the abnormality index. Specifically, the user operation data, the device state data, the webpage snapshot log, the webpage loading log and / or the webpage running log can be obtained according to the abnormality detection mode corresponding to the refresh category, the exit category, the trigger category or the non-operation category, and the abnormality detection is performed to obtain the abnormality type and the abnormality index.

[0047] It should be noted that the operation of obtaining the corresponding webpage detection data according to the abnormality detection mode, performing the abnormality detection, obtaining the abnormality type and the abnormality index can be replaced by obtaining the corresponding webpage detection data according to the abnormality detection mode, performing the abnormality detection, obtaining the abnormality type or the abnormality index, and forming a new implementation mode with other processing steps provided in the embodiment.

[0048] Step S206, input the abnormality indicator into the trust conversion model to convert the trust level of the abnormality type to obtain the trust level.

[0049] The above obtains the abnormality type and the abnormality indicator by acquiring corresponding webpage detection data according to the abnormality detection mode and performing abnormality detection. In this step, the abnormality indicator is converted into the trust level of the abnormality type to obtain the trust level. Specifically, the abnormality indicator is input into the trust conversion model to convert the trust level of the abnormality type to obtain the trust level. In this way, the abnormality indicator is converted into the trust level to improve the convenience of subsequent abnormality response.

[0050] The trust level described in this embodiment can be the trust level of the abnormality type. The trust level can represent the trust degree of the abnormality type or the occurrence probability of the abnormality type. The trust level of the abnormality type can be positively correlated with the abnormality indicator. The larger the abnormality indicator is, the higher the trust level is. The smaller the abnormality indicator is, the lower the trust level is.

[0051] In specific implementation, in order to improve the accuracy of abnormality response and reduce the calculation amount in the abnormality response process, the abnormality indicator is input into the trust conversion model to convert the trust level of the abnormality type to obtain the trust level when the abnormality indicator meets the abnormality response condition. The abnormality response condition can include that the abnormality indicator is greater than an indicator threshold. In the case where the abnormality indicator does not meet the abnormality response condition, no processing is performed.

[0052] In the specific execution process, in order to improve the convenience of subsequent abnormality response, which helps to improve the timeliness of abnormality response. In an optional implementation provided in this embodiment, the following operation is performed in the process of converting the trust level of the abnormality type: The abnormality indicator is matched with the trust interval corresponding to the plurality of trust levels to obtain the trust level matched by the abnormality indicator as the trust level of the abnormality type.

[0053] The plurality of trust levels can be a plurality of pre-set trust levels. The number of the plurality of trust levels can be any number.

[0054] For example, the plurality of trust levels include a high trust level, a medium trust level, and a low trust level. The trust intervals corresponding to the plurality of trust levels are [a, b), [b, c), and [c, d). The abnormality indicator m is matched with the trust interval corresponding to the plurality of trust levels to obtain the trust level corresponding to the trust interval matched by the abnormality indicator as the trust level of the abnormality type.

[0055] It should be noted that the operation of inputting the abnormal index into the trusted conversion model to convert the trusted level of the abnormal type to obtain the trusted level can be replaced by converting the trusted level of the abnormal type of the abnormal index or classifying the trusted level of the abnormal type of the abnormal index to obtain the trusted level; and other processing steps provided in the embodiment form a new implementation mode.

[0056] In step S208, the response strategy matching is performed according to the abnormal type and the trusted level, the abnormal response strategy is obtained, and the abnormal response processing is performed.

[0057] In the above step, the abnormal index is input into the trusted conversion model to convert the trusted level of the abnormal type to obtain the trusted level, in this step, the response strategy matching is performed according to the abnormal type and the trusted level, the abnormal response strategy is obtained, and the abnormal response processing is performed.

[0058] The abnormal response strategy described in the embodiment can be an abnormal response strategy for responding to a third-party webpage, such as a text reminder strategy and / or a label reminder strategy. The label reminder strategy can be a pop-up reminder strategy. The abnormal response strategy can correspond to the execution mode of the abnormal response strategy. The execution mode corresponding to the text reminder strategy can include a text reminder mode of reminding the text at an edge position, a text reminder mode of reminding the text at a middle position, a fixed text reminder mode, and / or a scrolling text reminder mode. The execution mode corresponding to the label reminder strategy can include a label reminder mode of reminding the label at an edge position, a label reminder mode of reminding the label at a middle position, a fixed label reminder mode, and / or a scrolling label reminder mode.

[0059] In specific implementation, in the process of matching the response strategy according to the abnormal type and the trusted level to obtain the abnormal response strategy, the matching abnormal response strategy can be found in the response strategy table according to the abnormal type and the trusted level. For example, in the case that the abnormal type is a white screen type and the trusted level is a high trusted level, the abnormal response strategy found in the response strategy table according to the abnormal type and the trusted level is a label reminder strategy. Alternatively, the matching abnormal response strategy can be found in the response strategy table according to the abnormal type, and the execution mode of the abnormal response strategy can be found according to the trusted level. For example, the matching abnormal response strategy found in the response strategy table according to the white screen type is a label reminder strategy, and the execution mode of the abnormal response strategy found according to the high trusted level is a label scrolling label reminder mode.

[0060] In the process of performing the abnormal response processing, if the abnormal response strategy is the script reminding strategy, a script component can be called to generate a guarantee reminding script and perform rendering processing of the guarantee reminding script on the upper layer of the webpage of the third-party webpage; if the abnormal response strategy is the label reminding strategy, a rendering component can be called to generate a guarantee access label containing a guarantee access entry and a guarantee access reminder, and perform rendering processing of the guarantee access label on the upper layer of the webpage of the third-party webpage.

[0061] In actual application, stable operation of the third-party webpage is crucial for stable operation of the application program. Since the third-party webpage is provided by a third-party institution and is not a native page in the application program, in the case of an abnormality of the third-party webpage, a response needs to be made in a timely manner to avoid causing use troubles to the user; in an optional implementation manner provided in the embodiment, in the process of performing the abnormal response processing, the following operation is performed: A rendering component is called to generate a guarantee access label containing a guarantee access entry and a guarantee access reminder, and perform rendering processing of the guarantee access label on the upper layer of the webpage of the third-party webpage.

[0062] Optionally, the guarantee access entry is used to access guarantee quotation information of the vehicle guarantee provided by the remaining third-party institutions to the user.

[0063] The guarantee access label can be a guarantee access interface or a guarantee access pop-up window; the remaining third-party institutions can be the remaining third-party institutions except the third-party institution corresponding to the third-party webpage.

[0064] Specifically, in the process of calling the rendering component to generate the guarantee access label containing the guarantee access entry and the guarantee access reminder, the rendering component can be called to generate the guarantee access label containing the guarantee access entry and the guarantee access reminder according to the abnormal response strategy and the execution mode of the abnormal response strategy; for example, according to the label reminding strategy and the label scrolling label reminding mode, the rendering component is called to generate the guarantee access label containing the guarantee access entry and the guarantee access reminder, and perform scrolling rendering processing of the guarantee access label on the upper layer of the webpage of the third-party webpage.

[0065] For example, after the rendering component is called to generate the guarantee access label containing the guarantee access entry and the guarantee access reminder, and perform scrolling rendering processing of the guarantee access label on the upper layer of the webpage of the third-party webpage, the third-party webpage is as shown in FIG. 3. Figure 3 As shown in FIG. 3, the 301 area displays a guarantee access pop-up window, the guarantee access pop-up window is displayed on the upper layer of the webpage of the third-party webpage, the guarantee access entry 302 is to view other quotations, and the guarantee access reminder 303 is “Having difficulty in purchasing insurance? You can try to obtain quotations of other insurance companies”.

[0066] In addition, the optional implementation of the above abnormal response processing can be replaced by calling the rendering component to generate a security access label containing a security access portal or a security access reminder, and performing rendering processing of the security access label on the upper layer of the third-party webpage.

[0067] In addition, the optional implementation of the above abnormal response processing can also be performed on the basis of the security quotation of the third-party webpage for providing vehicle security to the user through the third-party agency.

[0068] It should be noted that the operation of matching the response strategy according to the abnormal type and the trust level, obtaining the abnormal response strategy and performing the abnormal response processing can be replaced by matching the response strategy according to the abnormal type or the trust level, obtaining the abnormal response strategy and performing the abnormal response processing, and constituting a new implementation with other processing steps provided in the present embodiment.

[0069] It should be further noted that, considering that the user operation data, webpage detection data and other related data involved in the present specification may to some extent belong to the privacy of the user, if it is desired to collect the user operation data, webpage detection data and other related data, the authorization of the user can be obtained before collecting the data, so that the operation of collecting the data complies with the relevant data management regulations, for example, the data authorization can be performed during the access to the application program, the data authorization can also be performed during the first access to the application program, the data authorization can also be performed during the access to the vehicle security service, in addition, other ways of data authorization can also be used; wherein the specific way of data authorization can be to send a user data authorization reminder to the user, and the user can obtain the data collection authorization after confirming the reminder through the instruction, or the way of data authorization can also be to sign a data authorization agreement to obtain the data collection authorization; the present embodiment will not be repeated here.

[0070] It should be noted that each optional implementation and each feasible execution mode in steps S202 to S208 provided in the present embodiment can be independently executed as needed, or can be combined with each other and referred to each other, at the same time, each specific execution step in each optional implementation or each feasible execution mode can also be independently executed and combined as needed, the execution condition of "if" or "under what circumstances" involved in each step or operation can be directly deleted, and the operation after the execution condition, the present embodiment does not make specific limitation on this; the structure of the model in the present embodiment can be transformer or conformer or other structure.

[0071] To sum up, the one or more webpage detection processing methods provided by the embodiment can be applied to a detection container of application deployment, and in the process of webpage detection, the abnormal detection mode of the third-party webpage is determined according to the user operation data of the third-party webpage in the application, the corresponding webpage detection data is obtained according to the abnormal detection mode and abnormal detection is performed, the abnormal type and abnormal index are obtained, the abnormal index is matched with the confidence interval corresponding to the plurality of confidence levels through the confidence conversion model, the confidence level matched with the abnormal index is obtained as the confidence level of the abnormal type, the response strategy matching is performed according to the abnormal type and the confidence level, the abnormal response strategy is obtained and abnormal response processing is performed; Among them, the third-party webpage is loaded through the webpage container deployed by the application; the abnormal detection of the third-party webpage is performed through the detection container deployed by the application, so as to improve the convenience and stability of the abnormal detection; the abnormal detection of the third-party webpage by the detection container is decoupled from the webpage container, without the cooperation of the third-party institution, the interference with the code running of the third-party webpage is reduced, the security of the abnormal detection is improved, and the pertinence and flexibility of the abnormal detection are improved by providing different abnormal detection modes.

[0072] The webpage detection processing method provided by the embodiment is applied to the car insurance service scene, and the webpage detection processing method provided by the embodiment is further described, referring to Figure 4 The webpage detection processing method applied to the car insurance service scene specifically includes the following steps.

[0073] In step S402, the user operation data of the third-party webpage in the car insurance service in the payment application is obtained.

[0074] In step S404, if the user operation data triggers a detection condition, the operation category is obtained by performing operation category identification according to the user operation data, and the abnormal detection mode of the third-party webpage is determined based on the operation category.

[0075] In step S406, the webpage snapshot log and webpage loading log obtained by loading the third-party webpage by the webpage container, and the webpage running log of the third-party webpage collected by the webpage container are obtained according to the abnormal detection mode.

[0076] In step S408, the abnormal type and abnormal index of the third-party webpage are obtained by performing abnormal type identification and abnormal index calculation according to the user operation data, the webpage snapshot log, the webpage loading log and the webpage running log.

[0077] In step S410, if the abnormal index is greater than the index threshold, the abnormal index is input into the confidence conversion model to obtain the confidence level of the abnormal type.

[0078] Step S412, according to the abnormal type and the trust level, the response strategy matching is carried out to obtain the abnormal response strategy.

[0079] Step S414, according to the abnormal response strategy, the rendering component is called to generate the security access label containing the security access entrance and the security access prompt, and the rendering processing of the security access label is carried out on the upper layer of the third-party webpage.

[0080] Optionally, the third-party webpage is provided by a third-party institution, and the security access entrance is used to access the security quotation information of the remaining third-party institutions to the user for vehicle security.

[0081] It should be noted that any one step or combination of any multiple steps of steps S402 to S414 can be replaced by the corresponding technical means provided in steps S202 to S208 according to the needs of implementation and deployment, and steps S402 to S414 can also be combined into a new implementation manner according to the needs of implementation and deployment. Any one step or any multiple steps of steps S402 to S414 can also be combined with one or more steps provided in steps S202 to S208 according to the actual deployment needs to form a new implementation manner, or combined with one or more optional implementation manners provided in steps S202 to S208 to form a new implementation manner, which will not be described here.

[0082] The webpage detection processing device provided in the specification implements, for example: In the above embodiment, a webpage detection processing method is provided, and a webpage detection processing device corresponding thereto is also provided, which will be described below with reference to the accompanying drawings.

[0083] Reference Figure 5 It shows a schematic diagram of an embodiment of a webpage detection processing device provided in the present embodiment.

[0084] Since the device embodiment corresponds to the method embodiment, the description is relatively simple, and the related parts can be referred to the corresponding description of the method embodiment provided above. The device embodiments described below are only illustrative.

[0085] The present embodiment provides a webpage detection processing device running in a detection container of an application program deployment, which comprises: The mode determination module 502 is configured to determine the abnormal detection mode of the third-party webpage according to the user operation data of the third-party webpage in the application program; the third-party webpage is loaded through the webpage container of the application program deployment; The abnormal detection module 504 is configured to obtain the corresponding webpage detection data and perform abnormal detection according to the abnormal detection mode to obtain the abnormal type and the abnormal index. The level conversion module 506 is configured to input the anomaly index into a trusted conversion model to perform trusted level conversion of the anomaly type to obtain a trusted level; The anomaly response module 508 is configured to perform response strategy matching according to the anomaly type and the trusted level, to obtain an anomaly response strategy and perform anomaly response processing.

[0086] The present specification provides a web page detection processing device, which implements the following, for example: According to the same technical concept, one or more embodiments of the present specification also provide a web page detection processing device for executing the web page detection processing method provided above, Figure 6 A structural schematic diagram of a web page detection processing device provided for one or more embodiments of the present specification.

[0087] The web page detection processing device provided in the present embodiment comprises: As Figure 6 As shown, the web page detection processing device can have great differences due to different configurations or performances, and can include one or more processors 601 and memories 602. The memories 602 can store one or more storage applications or data. The memories 602 can be temporary storage or persistent storage. The applications stored in the memories 602 can include one or more modules (not shown in the figure), and each module can include a series of computer executable instructions in the web page detection processing device. Further, the processor 601 can be configured to communicate with the memory 602 and execute a series of computer executable instructions in the memory 602 on the web page detection processing device. The web page detection processing device can also include one or more power supplies 603, one or more wired or wireless network interfaces 604, one or more input / output interfaces 605, one or more keyboards 606, and the like.

[0088] In one specific embodiment, the web page detection processing device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and the one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the web page detection processing device, and the one or more processors are configured to execute the one or more programs, which include the following computer executable instructions: determining an anomaly detection manner of the third-party web page according to user operation data of the third-party web page in the application; the third-party web page is loaded through a web page container deployed by the application; According to the abnormality detection manner, corresponding webpage detection data is acquired and abnormality detection is performed, to obtain an abnormality type and an abnormality index; The abnormality index is input into a trust conversion model to perform trust level conversion of the abnormality type to obtain a trust level; According to the abnormality type and the trust level, a response strategy is matched to obtain an abnormality response strategy and perform abnormality response processing.

[0089] The computer readable storage medium provided in the specification implements, for example, the following: According to the above description, a webpage detection processing method based on the same technical concept, one or more embodiments of the specification also provide a computer readable storage medium.

[0090] The computer readable storage medium provided in the embodiment is used to store computer executable instructions, and the computer executable instructions realize the following steps when executed: According to user operation data of a third-party webpage in an application program, an abnormality detection manner of the third-party webpage is determined; the third-party webpage is loaded through a webpage container deployed by the application program; According to the abnormality detection manner, corresponding webpage detection data is acquired and abnormality detection is performed, to obtain an abnormality type and an abnormality index; The abnormality index is input into a trust conversion model to perform trust level conversion of the abnormality type to obtain a trust level; According to the abnormality type and the trust level, a response strategy is matched to obtain an abnormality response strategy and perform abnormality response processing.

[0091] It should be noted that the embodiments of the computer readable storage medium in the specification and the embodiments of the webpage detection processing method in the specification are based on the same inventive concept, so the specific implementation of the embodiments can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.

[0092] The computer program product provided in the specification implements, for example, the following: According to the above description, a webpage detection processing method based on the same technical concept, one or more embodiments of the specification also provide a computer program product.

[0093] A computer program product includes computer programs / instructions, which, when executed by a processor, realize the following steps: According to user operation data of a third-party webpage in an application program, an abnormality detection manner of the third-party webpage is determined; the third-party webpage is loaded through a webpage container deployed by the application program; According to the abnormality detection manner, corresponding webpage detection data is acquired and abnormality detection is performed, to obtain an abnormality type and an abnormality index; The abnormality index is input into a trust conversion model to perform trust level conversion of the abnormality type and obtain a trust level; According to the abnormality type and the trust level, a response strategy is matched to obtain an abnormality response strategy and perform abnormality response processing.

[0094] It should be noted that the embodiments of the computer program product in the present specification and the embodiments of the webpage detection processing method in the present specification are based on the same inventive concept, and therefore the specific implementation of the embodiments can be referred to the implementation of the corresponding method, and the repeated parts will not be described.

[0095] Each of the embodiments in the present specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment mainly describes the difference from other embodiments, such as the device embodiment, the equipment embodiment and the computer readable storage medium embodiment, which are similar to the method embodiment, so the description is relatively simple, and the related content in the device embodiment, the equipment embodiment and the computer readable storage medium embodiment can be referred to the part of the method embodiment.

[0096] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims can be performed in a different order than the order in which they are recited and still achieve desirable results. In addition, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous or possible.

[0097] In the 1930s, it was clear to distinguish whether an improvement in a technology was in hardware (e.g., improvement in circuit structure of diodes, transistors, switches, etc.) or in software (e.g., improvement in method flow). However, as technology has evolved, many improvements in method flow today can be considered as direct improvements in hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using hardware entity modules. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A digital system is "integrated" on a PLD by the designer programming it, rather than by ordering a chip manufacturer to design and fabricate a custom integrated circuit chip. Moreover, instead of manually fabricating integrated circuit chips, this programming is now mostly implemented using "logic compiler" software, which is similar to software compilers used in program development, and the original code before compilation is written in a specific programming language, which is called a hardware description language (HDL), and there are many such languages, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should be aware that only a slight logical programming of the method flow in the above-mentioned hardware description languages and programming into an integrated circuit can easily obtain a hardware circuit that implements the logical method flow.

[0098] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to implementing the controller in pure computer readable program code, it is also possible to implement the controller in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers and embedded microcontrollers, etc. to perform the same functions by logically programming the method steps. Such a controller can therefore be considered as a hardware component, and the means included therein for performing various functions can also be considered as structures within the hardware component. Alternatively, the means for performing various functions can even be considered as both a software module implementing the method and a structure within the hardware component.

[0099] The systems, apparatuses, modules or units illustrated by the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0100] For the sake of brevity, the above apparatuses are described in functional form in various units. Of course, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0101] Those skilled in the art will appreciate that one or more embodiments of the disclosure can provide a method, a system or a computer program product. Accordingly, one or more embodiments of the disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the disclosure can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.

[0102] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable test processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable test processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0103] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable test processing equipment to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0104] These computer program instructions can also be loaded onto a computer or other programmable test processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0105] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0106] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0107] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0108] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, such that processes, methods, articles or devices that include a series of features are not only limited to those features, but also include other features not explicitly listed, or inherent to such processes, methods, articles or devices. Without more limitations, the feature defined by the statement "comprising a" does not exclude the presence of other identical features in the process, method, article or device comprising the feature.

[0109] One or more embodiments of the specification can be described in the general context of computer-executable instructions being executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the specification can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0110] Each embodiment in the specification is described in a progressive manner, and the same or similar parts between each embodiment can be referred to each other, and each embodiment focuses on the difference from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0111] The above merely provides the example of the present document and is not intended to limit the present document. For those skilled in the art, the present document can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present document shall be included in the scope of claims of the present document.

Claims

1. A webpage detection processing method applied to a detection container of an application deployment, the method comprising: determining an abnormality detection mode of a third-party webpage according to user operation data of the third-party webpage in the application; loading the third-party webpage through a webpage container of the application deployment; obtaining webpage detection data corresponding to the abnormality detection mode and performing abnormality detection to obtain an abnormality type and an abnormality index; inputting the abnormality index into a trust conversion model to convert a trust level of the abnormality type and obtain the trust level; performing response strategy matching according to the abnormality type and the trust level, obtaining an abnormality response strategy, and performing abnormality response processing. 2.The webpage detection processing method of claim 1, wherein the obtaining webpage detection data corresponding to the abnormality detection mode and performing abnormality detection to obtain an abnormality type and an abnormality index comprises: obtaining webpage snapshot logs and webpage loading logs obtained by the webpage container loading the third-party webpage according to the abnormality detection mode, and obtaining webpage running logs of the third-party webpage collected by the webpage container; performing abnormality type identification and abnormality index calculation according to the user operation data, the webpage snapshot logs, the webpage loading logs, and the webpage running logs to obtain the abnormality type and the abnormality index. 3.The webpage detection processing method of claim 2, wherein the performing abnormality type identification and abnormality index calculation according to the user operation data, the webpage snapshot logs, the webpage loading logs, and the webpage running logs to obtain the abnormality type and the abnormality index comprises: performing parsing processing on the webpage snapshot logs, extracting abnormality keywords of the third-party webpage from the parsing results, and extracting early warning content and early warning levels from the webpage loading logs and the webpage running logs; determining the abnormality type according to the user operation data, the abnormality keywords, and the early warning content, and calculating the abnormality index based on the user operation data, the abnormality keywords, and the early warning levels. 4.The webpage detection processing method of claim 3, wherein the calculating the abnormality index based on the user operation data, the abnormality keywords, and the early warning levels comprises: inputting the user operation data into an operation index model to calculate an operation abnormality index and calculate a webpage abnormality index based on the abnormality keywords; converting the early warning levels into log abnormality indexes, and calculating the abnormality index according to the operation abnormality index, the webpage abnormality index, and the log abnormality indexes. 5.The webpage detection processing method of claim 1, wherein the obtaining webpage detection data corresponding to the abnormality detection mode and performing abnormality detection to obtain an abnormality type and an abnormality index comprises: obtaining webpage loading logs obtained by the webpage container loading the third-party webpage according to the abnormality detection mode, and obtaining webpage running logs of the third-party webpage collected by the webpage container and device state data of a terminal device running the application. Determine the abnormal type according to the user operation data and the webpage loading log, and calculate the abnormal index based on the user operation data, the webpage loading log, the webpage running log and the device state data.

6. The webpage detection processing method of claim 5, wherein the calculating the abnormal index based on the user operation data, the webpage loading log, the webpage running log and the device state data comprises: Determining a stay duration of the user on the third-party webpage and / or an operation frequency of the same operation performed by the user according to the user operation data, and obtaining an operation abnormal index by performing operation abnormal index calculation based on the stay duration and / or the operation frequency; Calculating a log abnormal index according to the webpage loading log and the webpage running log, calculating a device abnormal index according to the device state data, and calculating the abnormal index based on the operation abnormal index, the log abnormal index and the device abnormal index.

7. The webpage detection processing method of claim 1, wherein the performing the credibility level conversion of the abnormal type comprises: Performing matching processing on the abnormal index and credibility intervals corresponding to a plurality of credibility levels to obtain a credibility level matched by the abnormal index as the credibility level of the abnormal type.

8. The webpage detection processing method of claim 1, wherein the determining the abnormal detection mode of the third-party webpage according to the user operation data of the third-party webpage in the application program comprises: Obtaining an operation category by performing operation category identification according to the user operation data, and determining the abnormal detection mode based on the operation category; wherein the operation category comprises a refresh category in which a refresh frequency of the third-party webpage exceeds a frequency threshold, an exit category in which a trigger frequency of an exit control triggering exit from the third-party webpage exceeds a preset frequency, a trigger category in which a trigger frequency of a webpage control contained in the third-party webpage exceeds a specific frequency, or a non-operation category in which a non-operation duration of the third-party webpage exceeds a duration threshold.

9. The webpage detection processing method of claim 1, wherein the third-party webpage is displayed in a vehicle guarantee service in the application program; and the vehicle guarantee service comprises a lightweight application of vehicle guarantee. The third-party webpage is configured to provide a guarantee quote for vehicle guarantee to the user by a third-party institution.

10. The webpage detection processing method of claim 9, wherein the performing abnormal response processing comprises: Calling a rendering component to generate a guarantee access label containing a guarantee access portal and a guarantee access reminder, and performing rendering processing of the guarantee access label on an upper layer of the third-party webpage. wherein the guarantee access portal is configured to access guarantee quote information for vehicle guarantee to the user by a remaining third-party institution.

11. The webpage detection processing method of claim 1, wherein the detection container deploys a webpage detection script; and the webpage detection script is executed after the third-party webpage is loaded in the webpage container.

12. The webpage detection processing method of claim 1, wherein the abnormality detection manner is determined after the user operation data triggers a detection condition; and the user stays on the third-party webpage for a duration exceeding a duration threshold and / or performs the same operation on the third-party webpage for a frequency exceeding a frequency threshold. The user operation data triggers a detection condition, including:

13. The webpage detection processing method of claim 1, wherein the webpage detection data comprises at least one of: the user operation data, webpage snapshot logs obtained by the webpage container loading the third-party webpage, webpage loading logs, webpage running logs of the third-party webpage collected by the webpage container, and device state data of a terminal device on which the application program runs.

14. A webpage detection processing apparatus running on a detection container deployed by an application program, comprising: a manner determination module configured to determine an abnormality detection manner of a third-party webpage in the application program according to user operation data of the third-party webpage; the third-party webpage is loaded by a webpage container deployed by the application program; an abnormality detection module configured to acquire corresponding webpage detection data according to the abnormality detection manner and perform abnormality detection to obtain an abnormality type and an abnormality indicator; a level conversion module configured to input the abnormality indicator into a trust level conversion model to convert a trust level of the abnormality type and obtain a trust level; and an abnormality response module configured to perform response strategy matching according to the abnormality type and the trust level, obtain an abnormality response strategy, and perform abnormality response processing.

15. A webpage detection processing device, comprising: a processor; and a memory configured to store computer executable instructions that, when executed, cause the processor to: determine an abnormality detection manner of a third-party webpage in an application program according to user operation data of the third-party webpage; the third-party webpage is loaded by a webpage container deployed by the application program; acquire corresponding webpage detection data according to the abnormality detection manner and perform abnormality detection to obtain an abnormality type and an abnormality indicator; input the abnormality indicator into a trust level conversion model to convert a trust level of the abnormality type and obtain a trust level; and perform response strategy matching according to the abnormality type and the trust level, obtain an abnormality response strategy, and perform abnormality response processing.

16. A computer readable storage medium for storing computer executable instructions that, when executed, implement the steps of the method of claim 1. ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​