Redundant information filtering method and device, equipment and storage medium

By obtaining the request parameters and type of business requests and combining them with a unified filter to filter out redundant information, the problem of inaccurate filtering of redundant information in existing technologies is solved, achieving fast and secure information filtering.

CN120934808APending Publication Date: 2025-11-11AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511088318.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies cannot accurately filter out redundant information in the returned data, resulting in low efficiency, high error rates, large workload, and incomplete coverage.

Method used

By obtaining the request parameters from the business request, determining the field list based on the request header, and combining the request type and a unified filter, redundant information is filtered out from the business data to achieve a return result that does not contain redundant information.

Benefits of technology

It enables the rapid and accurate filtering of redundant information without modifying the original system's business logic code, reducing the risk of data leakage and improving management efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934808A_ABST
    Figure CN120934808A_ABST
Patent Text Reader

Abstract

The invention discloses a redundant information filtering method, device and equipment and a storage medium, and the method comprises the steps: obtaining a service request which comprises a request parameter; based on a request header in the request parameter, determining a field list returned by the service request; determining a return mode of the field list based on a request type corresponding to the service request; and based on the return mode and a unified filter, determining a return result corresponding to the field list from the service data, the unified filter being used for filtering redundant information. According to the method, the field list to be returned by the service request is determined, and the redundant information is filtered in combination with the unified filter when the return result is determined, so that the return result which does not contain the redundant information can be obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of network security technology, and in particular to a method, apparatus, device and storage medium for filtering redundant information. Background Technology

[0002] Redundant information return is a common security vulnerability. Currently, the approach to addressing this vulnerability in various systems is to rectify each instance as it is discovered, reducing the number of fields returned by the relevant interfaces as needed, and then fixing it through a series of processes including testing, production deployment, and retesting. The drawbacks of this approach are low efficiency, error-proneness, heavy workload, and incomplete coverage. Currently, to improve efficiency, developers mostly use standardized query interfaces, such as uniformly generating single-table transactions and returning all queried information to the client. Therefore, regardless of whether it's an existing system or a newly developed system, redundant information return vulnerabilities are prevalent and require close attention.

[0003] The traditional approach is to identify and rectify each problem as it arises, reducing the fields returned by the relevant interfaces as required, and then fixing them through a series of processes such as testing, production deployment, and retesting. However, this approach is still prone to errors when filtering excessive information. Summary of the Invention

[0004] This invention provides a method, apparatus, device, and storage medium for filtering redundant information, in order to solve the problem that existing technologies cannot accurately filter redundant information in the returned information.

[0005] According to one aspect of the present invention, a method for filtering redundant information is provided, the method comprising:

[0006] Obtain a business request, which includes request parameters;

[0007] Based on the request headers in the request parameters, determine the list of fields to be returned by the business request;

[0008] Based on the request type corresponding to the business request, determine the return method of the field list;

[0009] Based on the return method and a unified filter, the return result corresponding to the field list is determined from the business data. The unified filter is used to filter out redundant information.

[0010] According to another aspect of the present invention, a redundant information filtering device is provided, the device comprising:

[0011] The acquisition module is used to acquire business requests, which include request parameters;

[0012] The first determining module is used to determine the list of fields returned by the business request based on the request header in the request parameters;

[0013] The second determining module is used to determine the return method of the field list based on the request type corresponding to the business request;

[0014] The third determination module is used to determine the return result corresponding to the field list from the business data based on the return method and the unified filter.

[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: at least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the redundant information filtering method according to any embodiment of the present invention.

[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the redundant information filtering method described in any embodiment of the present invention.

[0019] This invention discloses a method, apparatus, device, and storage medium for filtering redundant information. The method includes: acquiring a business request, the business request including request parameters; determining a list of fields to be returned by the business request based on request headers in the request parameters; determining a return method for the field list based on the request type corresponding to the business request; and determining a return result corresponding to the field list from business data based on the return method and a unified filter, wherein the unified filter is used to filter redundant information. This method, by determining the list of fields to be returned by the business request and combining it with a unified filter to filter redundant information when determining the return result, can obtain a return result that does not contain redundant information, thus solving the problem in the prior art of accurately filtering redundant information in the returned information.

[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart illustrating a redundant information filtering method provided in Embodiment 1 of the present invention;

[0023] Figure 2 A flowchart illustrating a method for filtering redundant information provided in an embodiment of the present invention;

[0024] Figure 3 A flowchart for automatically reading system interface information is provided as an embodiment of the present invention;

[0025] Figure 4 This invention provides a schematic diagram of a process for returning data requested by a business request, as provided in an embodiment of the invention.

[0026] Figure 5 A flowchart illustrating a method for filtering redundant information provided in an embodiment of the present invention;

[0027] Figure 6 This is a schematic diagram of the structure of a redundant information filtering device provided in Embodiment 2 of the present invention;

[0028] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention. It should be understood that the various steps described in the method embodiments of the present invention can be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.

[0030] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, any variations of the terms "comprising" and "having," etc., are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0032] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0033] The names of the messages or information exchanged between the multiple devices in the embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0034] Example 1

[0035] Figure 1 This is a flowchart illustrating a redundant information filtering method provided in Embodiment 1 of the present invention. This method is applicable to situations where the backend filters out redundant information when returning data requested from the frontend. This method can be executed by a redundant information filtering device, which can be implemented by software and / or hardware and is generally integrated into an electronic device. In this embodiment, the electronic device includes, but is not limited to, devices such as computers.

[0036] like Figure 1 As shown, the redundant information filtering method provided in Embodiment 1 of the present invention includes the following steps:

[0037] S110. Obtain a business request, wherein the business request includes request parameters.

[0038] The business request can be a request from the frontend to retrieve data, such as retrieving user data or retrieving fields from a table. Request parameters can be the fields that the business request needs to return.

[0039] In this embodiment, the business request sent by the front end can be obtained, and the business request may include request parameters. For example, when the business request is "submit order", the request parameters may include "product list", "shipping address ID", "payment method", etc.

[0040] S120. Based on the request header in the request parameters, determine the list of fields to be returned by the business request.

[0041] In this embodiment, the fields that the business request should return can be determined based on the request header in the request parameters, and a field list can be generated based on these fields.

[0042] In one embodiment, determining the list of fields returned by the business request based on the request header in the request parameters includes: parsing the request parameters to determine whether the request header in the request parameters defines a set of fields; if so, decoding the set of fields to obtain the fields in the request header; otherwise, obtaining the corresponding fields from the system configuration table based on the interface corresponding to the business request; and generating a list of fields based on the fields.

[0043] The field set can be a collection of fields requested in the business request. The system configuration table can include parameter information corresponding to each interface, as well as subsequent return parameters, sensitive parameters, and other information.

[0044] In this embodiment, the request parameters can be parsed. By determining whether the request header in the request parameters defines a set of fields, it can be determined whether the business request specifies any parameters to be returned. If so, the set of fields can be directly decoded to obtain the fields in the request header. The decoding method can be set according to the actual situation, such as ASCII, Base64 decoding, Uniform Resource Locator (URL) decoding, JSON decoding, etc. If not, the interface corresponding to the business request is automatically read, the field corresponding to that interface is obtained from the system configuration table, and that field is used as the field to be returned by the business request.

[0045] For example, Figure 2 This is a flowchart illustrating a method for filtering redundant information provided in an embodiment of the present invention, as shown below. Figure 2 As shown, the backend can be responsible for the unified management of interface and parameter information, mainly including steps such as automatic interface reading, creating a single-table transaction class, adding unified filters, and class and interface annotations:

[0046] Automatic interface reading can include creating a system configuration table and adding interface scanning classes. The table is primarily used to store the interfaces and parameter information automatically scanned by the program, as well as subsequent return parameters and sensitive parameter information. To implement privilege escalation control, system menus (or system roles) can be dynamically managed with interfaces, and a menu-interface table can be built to store the association between menus and interfaces. For example, Figure 3 A flowchart for automatically reading system interface information is provided as an embodiment of the present invention, such as... Figure 3 As shown, it can retrieve a specified Bean instance, iterate through processing methods, automatically obtain class and method descriptions, retrieve URLs, request methods, types, and method names, construct system interface control and entity classes, and validate path entities. Path entity validation refers to performing legality checks on the parameters (path parameters) contained in the URL path to ensure they conform to expected rules (such as format, range, type, etc.) and avoid invalid or malicious requests. If valid, the validated legal data is added to a list and batch-inserted into the database. It also supports exception handling, handling errors that may occur during the process. The automatic loading of system entity classes and interfaces can be implemented based on annotations; that is, adding annotations to the corresponding methods enables automatic loading of class and interface path information. One-click scanning of interface paths allows for rapid automatic loading of code classes and interface information.

[0047] Creating a single-table transaction class can refer to building a system interface access path information table, primarily used to store and use interface path parameter information. A system menu interface table can be used to associate menus with interface paths for access control. If user access to menus and interfaces needs to be controlled, an access control interceptor needs to be added.

[0048] Adding a unified filter involves first defining annotation classes, then implementing specific aspect processing classes for concrete logic processing and operations. The specific implementation steps of the aspect implementation class include: using the `@Around` annotation to obtain request parameters, distinguishing between actual interface requests and requests to retrieve fields, retrieving field information from the request header, returning the front-end defined list of return fields as needed, retrieving data from the system configuration table, filtering sensitive fields, retrieving data from the system configuration table when the front-end parameters are empty, finding the intersection of front-end and back-end fields, executing the request method, obtaining the request result, and processing the return fields according to different return types. In Aspect-Oriented Programming (AOP), `@Around` is a core annotation used to define around advice.

[0049] Adding annotations to classes and interfaces refers to adding annotations to the classpath and interface path. This is used for automatic scanning of interface paths, improving scanning speed. By adding this annotation and calling the aspect class, the interface can quickly return redundant information and filter sensitive information.

[0050] In one embodiment, after determining the list of fields returned by the business request, the method further includes: determining whether the interface corresponding to the business request has a corresponding system configuration; if so, then taking the intersection between the returned fields corresponding to the system configuration and the field list as a new field list.

[0051] System configuration refers to a set of rules, parameters, or settings predefined in the system to constrain, control, or assist the execution of business logic. Returned fields can refer to the parameters returned, i.e., the fields that the interface can return after system configuration.

[0052] In this embodiment, after determining the list of fields returned by the business request, it is also possible to determine whether the interface corresponding to the business request has a corresponding system configuration. Whether there is a corresponding system configuration can be understood as determining whether the interface has a corresponding system configuration in the system configuration table. If so, the intersection between the returned fields corresponding to the system configuration and the field list can be used as a new field list, thereby preventing the field list from containing fields that the interface cannot return.

[0053] S130. Based on the request type corresponding to the business request, determine the return method of the field list.

[0054] The request type can include the returned fields and the values ​​of the returned fields.

[0055] In this embodiment, the method of returning the field list can be determined according to the request type corresponding to the business request.

[0056] In one embodiment, determining the return method of the field list based on the request type corresponding to the business request includes: when the request type corresponding to the business request is to return a field, determining the return method of the field list to return only the field; when the request type corresponding to the business request is to return the value of a field, determining the return method of the field list to return both the field and the value.

[0057] In this embodiment, if the request type corresponding to the business request is to return fields, the return method for the field list is determined to be returning only the fields; when the request type corresponding to the business request is to return the value of a field, the return method for the field list is determined to be returning both the field and the value, thereby speeding up request processing efficiency. For example, if both fields and values ​​are returned, the processing object is the field + corresponding value. The field set must first be matched to ensure the field is valid, and then the value is anonymized (e.g., hiding the middle 4 digits of a phone number). If only fields are returned, the processing object is the field name. The field set must be matched to remove invalid / sensitive field names. In this case, the filtering targets the field name itself, rather than anonymizing the value.

[0058] S140. Based on the return method and a unified filter, determine the return result corresponding to the field list from the business data. The unified filter is used to filter out redundant information.

[0059] A unified filter can be a component that centrally intercepts and processes specific logic within the request processing flow. It can uniformly process incoming requests and outgoing responses, avoiding the duplication of code across different business modules. A unified filter can perform value anonymization (e.g., format processing for sensitive information such as ID card numbers and mobile phone numbers) and compliance filtering for field names (e.g., removing field names not on the whitelist to prevent the exposure of sensitive field names). Redundant information refers to unnecessary returned information fields. Returning redundant information is a common security vulnerability, indicating that the system returns too many unnecessary information fields in its normal response messages. Although the vulnerability level is low-risk, if important sensitive information is leaked and exploited by an attacker, it can cause very serious consequences. It is one of the typical vulnerabilities that system risk audits focus on reporting, investigating, and requiring rectification of.

[0060] In this embodiment, sensitive information refers to information returned when a request is processed in an information system that contains sensitive data. This sensitive information may involve personal privacy, corporate secrets, or other important data, and requires special protection to prevent leakage or misuse. The content of the returned sensitive information may include the following categories: (1) Personal identification information: such as name, ID number, mobile phone number, email address, biometric information; (2) Account information: user account, password, transaction records; (3) Corporate information: corporate secrets, business plans, financial data, customer lists, supplier information, contract content; (4) System information: system logs, configuration files, database information, system source code, application programming interface (API) keys, server information; (5) Other sensitive information: health information, geographical location information, device information. In practical applications, the return of sensitive information needs to be protected by encryption, access control, data anonymization and other technical means to ensure that only authorized users can access it and that it will not be stolen or tampered with during transmission.

[0061] In this embodiment, the method of returning data can be determined by the return method, and the data corresponding to the field list can be obtained from the business data based on the field list. After filtering out the redundant information through a unified filter, the return result is obtained.

[0062] In one embodiment, determining the return result corresponding to the field list from the business data based on the return method and a unified filter includes: when the return method is to return fields and values, obtaining the corresponding set of fields of the data to be returned from the business data based on the return type of the field list; if a field in the field list is in the set of fields of the data to be returned, then performing desensitization processing on the value corresponding to the field in the data to be returned based on the unified filter to obtain the return result; when the return method is a field, obtaining the corresponding field from the business data based on the field list, and performing compliance filtering on the field based on the unified filter to obtain the return result.

[0063] The return type can include Page, List, Map, etc., but this embodiment does not limit it.

[0064] In this embodiment, if the return method is to return fields and values, the corresponding set of fields for the data to be returned can be obtained from the business data based on the return type of the field list. Depending on the type of data returned by the interface, specific data processing logic can be adopted. For example, if the return type is Page, the actual business data list can be extracted from the Page object, and then each record in the list can be processed. If the return type is List, no additional extraction is needed; the entire original list can be traversed, filtered, and transformed directly. If the return type is Map, the corresponding value is extracted by key, and then processed according to the type of the value. By adapting the processing logic based on the type, it can be ensured that data of any structure returned by the interface can be correctly parsed and processed, avoiding errors caused by type mismatch. If a field in the field list is in the set of fields for the data to be returned, the corresponding value of the field in the data to be returned can be anonymized using a unified filter to obtain the returned result; if not, the field can be discarded. For example, if the return type is a set of fields [id, name], and the field list contains the phone field, but this field is not in the set, the field is removed to prevent information leakage. When the return method is a field, the corresponding field is retrieved from the business data based on the field list, and the field is filtered for compliance based on a unified filter to obtain the return result.

[0065] This invention provides a method for filtering redundant information. The method involves obtaining a business request, which includes request parameters; determining a list of fields to be returned by the business request based on the request headers in the request parameters; determining a return method for the field list based on the request type corresponding to the business request; and determining a return result corresponding to the field list from business data based on the return method and a unified filter, where the unified filter is used to filter redundant information. This method, by determining the list of fields to be returned by the business request and combining it with a unified filter to filter redundant information when determining the return result, can obtain a return result that does not contain redundant information, thus solving the problem in existing technologies where redundant information cannot be accurately filtered in the returned information.

[0066] This embodiment treats program processing as a "black box," filtering only the returned results. This general, non-intrusive method for managing redundant information returns can automatically map and centrally manage interfaces and their returned information. This allows for rapid interface-level information filtering without modifying the original system's business logic code, effectively reducing the risk of data leakage. It features configurability, modularity, high efficiency, and low risk. Through configuration and parameterization, business personnel can quickly implement dynamic control over redundant interface information returns, sensitive information, and unauthorized access.

[0067] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.

[0068] In one embodiment, before obtaining the business request, the method further includes: when an annotation is added to the business request, filtering the business request based on the decorator to obtain a filtered business request; and processing the filtered business request based on a unified request format to obtain a standardized business request.

[0069] Annotations can be metadata tags used to mark, configure, or enhance request processing logic. Decorators can be seen as "wrappers" that add extra functionality to components without modifying their code. This approach is highly flexible and improves code reusability and maintainability. Decorators enable code reuse, modular development, and performance optimization, thereby improving development efficiency and code quality. Decorators can be used to enhance components in frameworks like React and Vue. For example, they can add features such as loading status, error handling, and logging. Decorators can also be page decorators, a powerful tool that helps developers dynamically enhance the functionality of components or functions without modifying existing code. A unified request format refers to a consistent format for the output of requests.

[0070] In this embodiment, business requests can be filtered using front-end decorators. Specifically, it can be determined whether the business request contains annotations. If so, the business request is filtered using the decorator to obtain the filtered business request. Then, the filtered business request is processed based on a unified request format to obtain a standardized business request. By quickly associating request methods and filtering logic with annotations, it is not necessary to manually call the filtering function in each method, simplifying the code. Outputting business requests in a unified request format ensures that all data sent in requests conforms to backend requirements (such as field specifications and correct format), reducing interface errors and unifying the front-end request processing flow.

[0071] For example, Figure 4 This is a schematic diagram of a process for returning data requested in a business request, provided by an embodiment of the present invention. Figure 4 As shown, front-end filtering mainly includes the following steps: defining front-end decorators, injecting interface parameters, adding annotations to methods, and unifying request output.

[0072] Front-end decorators can be defined in the JS file, for example, by injecting specific return parameter values ​​through `descriptor.value` in the decorator function. The specific logic of a decorator is defined as follows: custom parameter retrieval keywords, system compilation and actual function call (closure), backup of the annotated function, overriding of the annotated function, and injection of special handling functions. Here, "custom parameter retrieval keywords" refers to the fact that the decorator may need some custom parameters when enhancing the function (e.g., the "filter sensitive fields" decorator needs to know which fields are sensitive). The "keywords" here are the parameter identification rules. A closure refers to the execution container of the decorator. The decorator itself is usually a closure function (the outer function defines the parameters, and the inner function implements the enhancement logic). The system automatically calls this closure during compilation to wrap the target function, saving custom parameters and isolating the decorator's internal logic to avoid global pollution. Backup of the annotated function is to prevent the original logic from being lost after overriding; therefore, the decorator will first back up the original annotated function. Overriding an annotated function involves creating a new function, executing the enhanced logic within the new function, calling the backed-up original function, and finally replacing the original function with the new one. This logic can be modified as needed. A simple example is as follows: multiple locations (referring to fields from different sources) retrieve different fields for evaluation, return the original function, use the `apply` method to ensure the call remains unchanged, pass `args` as the original function parameter, `obj` as the injected parameter, compile the required decorators, and return the result.

[0073] The JavaScript file allows you to define and manage the parameters to be returned, facilitating subsequent use. You can also assemble request headers in the request JavaScript file, encrypting or encoding request parameters before sending them to the backend.

[0074] In one embodiment, the method further includes: configuring the return fields and sensitive fields corresponding to different interfaces in a visual interface based on the system interface document; and binding the association between menus and interface paths based on the system menu interface table.

[0075] The visual interface can be the menu permission management page. Return fields can include general return fields and mandatory return fields. General return fields are fields that can be returned optionally, while mandatory return fields are fields that must be returned. Sensitive fields can be fields containing sensitive information. The system interface documentation can be a complete description of all interfaces in the system (including but not limited to menu interfaces). The system menu interface table can be a table recording interfaces related to the system menu functions.

[0076] In this embodiment, the system configuration can be displayed through a visual interface. For example, in the visual interface, users can configure the return fields and sensitive fields corresponding to different interfaces based on the system interface documentation, and bind the association between menus and interface paths based on the system menu interface table. This embodiment manages and filters menus in association with system interfaces, and can also effectively prevent unauthorized access.

[0077] For example, page configuration can include page operation descriptions, return field configurations, sensitive field configurations, and menu interface association configurations. Page operation descriptions can refer to how business users can open the menu permission management page, select menus and bind them to interface permissions, and export system interface documentation with one click. Related methods (interfaces) can be expanded according to business module functions (classes).

[0078] The configuration of returned fields can be done by clicking on the interface to automatically return fields for the interface and selecting the necessary returned fields. The configuration of sensitive fields can be done by clicking on the interface to configure sensitive fields and selecting the fields that need to be de-identified. The association configuration of menu interfaces can be dynamically managed based on menus and interfaces. The system menu interface table can be used to associate menus with interface paths for interface-level access control, preventing unauthorized access by tools like Postman. Unauthorized access to an interface refers to a situation in software development where a user or system component accesses resources or performs operations they should not have access to without sufficient permissions. This usually occurs when interfaces lack strict access control or verification mechanisms, potentially leading to data leaks, data tampering, or other security issues. To prevent unauthorized access, effective authentication, access management, and security protocols must be implemented to ensure that only authorized users or systems can access the corresponding resources.

[0079] Based on the technical solutions of the above embodiments, this invention provides several specific implementation methods.

[0080] As one specific implementation method of this embodiment. Figure 5 This is a flowchart illustrating a method for filtering redundant information provided in an embodiment of the present invention, as shown below. Figure 5 As shown, during the system initialization phase, the backend automatically generates an interface field mapping table (such as a system configuration table) and data. Developers only need to maintain the mapping table or configuration file to store the request and return parameters of network requests. To improve flexibility, the frontend can dynamically specify the required return fields. The backend applies data management filtering rules based on the AOP mechanism, allowing users to select necessary return fields and anonymized fields as needed through a visual page. Unnecessary information is then filtered through the intersection of the mapping table and the frontend configuration fields. This solution provides functions such as returning redundant information, field anonymization, and managing development interfaces. Specific operations are as follows:

[0081] First, the backend filtering process, based on AOP aspects, enables automatic API entry and unified filtering. To reduce manual maintenance and improve API management efficiency, a unified aspect can be built using Java reflection and Spring AOP to achieve dynamic management of APIs and their parameters. This mainly involves steps such as one-click automatic scanning and reading of backend APIs, creating a single-table transaction class for API management, adding unified filters, and adding annotations to API methods. Second, the frontend filtering process, based on ECMAScript decorators, enables on-demand configuration of return parameters. To make frontend governance more flexible, return field information can be defined as needed, achieved through steps such as defining frontend filters, defining return parameters, adding annotations to methods, and unified output for frontend page requests. Finally, page configuration management allows for configuring API return fields and sensitive fields through a visual page, achieving configurable and parameterized API management. Configurability allows changes to program behavior without modifying code by adjusting configuration files, offering advantages such as flexibility, maintainability, security, and environmental adaptability. Parameterization refers to using parameters in functions, methods, or modules instead of hard-coded values. By passing different parameters, different functions or behaviors can be achieved. Parameterization has advantages such as code reusability, flexibility, testability, and maintainability.

[0082] Table 1 Filtering Module

[0083]

[0084] As shown in Table 1, embodiments of the present invention can also provide an unauthorized access vulnerability management plugin. This plugin includes a backend filtering module, a frontend filtering module, and a page configuration module. The backend is mainly implemented through aspects, the frontend is mainly implemented through decorators, and the page configuration module mainly focuses on user configuration, achieving dynamic control through configuration and parameterization.

[0085] The method of this invention adds annotations and a small amount of general code to the front end, imports a tool JAR package on the back end, and adds annotations to the Imp interface implementation layer. The entire process does not involve any modification to business code. It allows for dynamic selection of which information an interface needs to return or filter through a visual interface, with the selected results for each interface stored in a configuration file. This method can quickly address vulnerabilities in existing interfaces; for example, the system completed the governance of all interfaces returning redundant information, involving a total of 249 interfaces, in just one day. It can also effectively prevent new vulnerabilities. Newly developed systems designed and coded according to this solution can effectively prevent the occurrence of vulnerabilities related to redundant information returns, avoiding the leakage of sensitive information. By implementing dynamic control over interfaces and interface fields, subsequent management measures related to interfaces and interface fields can be extended based on this, such as preventing vertical privilege escalation, extending interface management functions through platform integration, and supporting automatic detection and desensitization of sensitive fields through rules. Business personnel can combine business requirements with system management through a visual configuration page, greatly improving management efficiency and achieving dynamic management of business rules and the system. The solution also supports one-click configuration file generation. In the production environment, two methods can be used: real-time query and verification of the configuration table and reading of the configuration file, which effectively ensures the security and flexibility of system requests.

[0086] Example 2

[0087] Figure 6 This is a schematic diagram of a redundant information filtering device provided in Embodiment 2 of the present invention. The device is applicable to situations where the backend filters out redundant information when returning data requested from the frontend. The device can be implemented by software and / or hardware and is generally integrated into an electronic device.

[0088] like Figure 6 As shown, the device includes:

[0089] The acquisition module 210 is used to acquire a business request, wherein the business request includes request parameters;

[0090] The first determining module 220 is used to determine the list of fields returned by the business request based on the request header in the request parameters;

[0091] The second determining module 230 is used to determine the return method of the field list based on the request type corresponding to the business request;

[0092] The third determining module 240 is used to determine the return result corresponding to the field list from the business data based on the return method and the unified filter.

[0093] This embodiment provides a redundant information filtering device, comprising: an acquisition module for acquiring a business request, the business request including request parameters; a first determination module for determining a list of fields to be returned by the business request based on the request header in the request parameters; a second determination module for determining a return method for the field list based on the request type corresponding to the business request; and a third determination module for determining a return result corresponding to the field list from business data based on the return method and a unified filter. By determining the list of fields to be returned by the business request and combining it with a unified filter to filter redundant information when determining the return result, a return result without redundant information can be obtained, thus solving the problem in the prior art that it is impossible to accurately filter redundant information in the returned information.

[0094] Furthermore, the first determining module 220 includes:

[0095] The request parameters are parsed to determine whether the request header in the request parameters defines a set of fields;

[0096] If so, the field set is decoded to obtain the fields in the request header; otherwise, the corresponding fields are obtained from the system configuration table based on the interface corresponding to the business request.

[0097] A list of fields is generated based on the fields described.

[0098] Furthermore, the first determining module 220 also includes:

[0099] Determine whether the interface corresponding to the business request has a corresponding system configuration;

[0100] If so, the intersection of the returned fields corresponding to the system configuration and the field list will be used as the new field list.

[0101] Furthermore, the second determining module 230 includes:

[0102] When the request type corresponding to the business request is a returned field, the return method of the field list is determined to be returned field only;

[0103] When the request type corresponding to the business request is to return the value of a field, the return method of the field list is determined to be to return both the field and the value.

[0104] Furthermore, the third determining module 240 includes:

[0105] When the return method is to return fields and values, the corresponding set of fields of the data to be returned is obtained from the business data based on the return type of the field list. If a field in the field list is in the set of fields of the data to be returned, the value of the field in the data to be returned is desensitized based on a unified filter to obtain the return result.

[0106] When the return method is a field, the corresponding field is obtained from the business data based on the field list, and the field is filtered for compliance based on a unified filter to obtain the return result.

[0107] Furthermore, before obtaining a service request, the device also includes:

[0108] When an annotation is added to a business request, the business request is filtered based on the decorator to obtain a filtered business request.

[0109] The filtered business requests are processed based on a unified request format to obtain standardized business requests.

[0110] Furthermore, the device also includes:

[0111] In the visual interface, the return fields and sensitive fields corresponding to different interfaces are configured based on the system interface documentation;

[0112] The association between menus and interface paths is bound based on the system menu interface table.

[0113] The aforementioned redundant information filtering device can execute the redundant information filtering method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0114] Example 3

[0115] Figure 7 A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0116] like Figure 7As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0117] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0118] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as redundant information filtering methods.

[0119] In some embodiments, the redundant information filtering method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the redundant information filtering method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the redundant information filtering method by any other suitable means (e.g., by means of firmware).

[0120] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0121] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0122] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0123] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0124] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0125] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0126] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0127] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for filtering redundant information, characterized in that, The method includes: Obtain a business request, which includes request parameters; Based on the request headers in the request parameters, determine the list of fields to be returned by the business request; Based on the request type corresponding to the business request, determine the return method of the field list; Based on the return method and a unified filter, the return result corresponding to the field list is determined from the business data. The unified filter is used to filter out redundant information.

2. The method according to claim 1, characterized in that, The step of determining the list of fields to be returned by the business request based on the request header in the request parameters includes: The request parameters are parsed to determine whether the request header in the request parameters defines a set of fields; If so, the field set is decoded to obtain the fields in the request header; otherwise, the corresponding fields are obtained from the system configuration table based on the interface corresponding to the business request. A list of fields is generated based on the fields described.

3. The method according to claim 1, characterized in that, After determining the list of fields returned by the business request, the method further includes: Determine whether the interface corresponding to the business request has a corresponding system configuration; If so, the intersection of the returned fields corresponding to the system configuration and the field list will be used as the new field list.

4. The method according to claim 1, characterized in that, The step of determining the return method of the field list based on the request type corresponding to the business request includes: When the request type corresponding to the business request is a returned field, the return method of the field list is determined to be returned field only; When the request type corresponding to the business request is to return the value of a field, the return method of the field list is determined to be to return both the field and the value.

5. The method according to claim 1, characterized in that, The process of determining the return result corresponding to the field list from the business data based on the return method and a unified filter includes: When the return method is to return fields and values, the corresponding set of fields of the data to be returned is obtained from the business data based on the return type of the field list. If a field in the field list is in the set of fields of the data to be returned, the value of the field in the data to be returned is desensitized based on a unified filter to obtain the return result. When the return method is a field, the corresponding field is obtained from the business data based on the field list, and the field is filtered for compliance based on a unified filter to obtain the return result.

6. The method according to any one of claims 1-5, characterized in that, Before obtaining the business request, the method further includes: When an annotation is added to a business request, the business request is filtered based on the decorator to obtain a filtered business request. The filtered business requests are processed based on a unified request format to obtain standardized business requests.

7. The method according to any one of claims 1-5, characterized in that, The method further includes: In the visual interface, the return fields and sensitive fields corresponding to different interfaces are configured based on the system interface documentation; The association between menus and interface paths is bound based on the system menu interface table.

8. A redundant information filtering device, characterized in that, The device includes: The acquisition module is used to acquire business requests, which include request parameters; The first determining module is used to determine the list of fields returned by the business request based on the request header in the request parameters; The second determining module is used to determine the return method of the field list based on the request type corresponding to the business request; The third determination module is used to determine the return result corresponding to the field list from the business data based on the return method and the unified filter.

9. An electronic device, characterized in that, The device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the redundant information filtering method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the redundant information filtering method according to any one of claims 1-7.