Control method and equipment of security acquisition component, medium and computer program product

By monitoring the performance metrics of web applications and dynamically adjusting the collection strategies and behaviors of the security collection SDK, the impact of security collection on performance is resolved, achieving automatic load reduction and improved user experience under performance constraints.

CN121901048APending Publication Date: 2026-04-21KE COM (BEIJING) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
KE COM (BEIJING) TECHNOLOGY CO LTD
Filing Date
2025-11-28
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing secure data collection SDKs continuously monitor page DOM changes and process a large number of events in web applications, leading to performance impact, especially when user devices have weak performance or web pages are highly complex, making it impossible to balance secure data collection and performance optimization.

Method used

By monitoring preset performance indicators, the collection strategy level and behavior are dynamically adjusted, including short-term fluctuations, long-term trend optimization, and device adaptability adjustments, to achieve hierarchical collection control, automatically reduce the load on the security collection components, and ensure page smoothness.

Benefits of technology

Automatically adjust data collection behavior under performance constraints, reduce manual intervention, improve user experience, achieve fine-grained control, adapt to different device performance, reduce operation and maintenance costs, and prevent page crashes and lag.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121901048A_ABST
    Figure CN121901048A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a control method and device for a security acquisition component, a medium and a computer program product. Under the condition that a monitoring value of a preset performance index is abnormal, a first abnormal level is determined, and a corresponding relation between the abnormal level and an acquisition strategy level is utilized; determining a first acquisition strategy level corresponding to the first abnormal level; determining a first acquisition behavior corresponding to the first acquisition strategy level by using a corresponding relationship between the acquisition strategy level and the acquisition behavior; therefore, the collection behavior of the security collection component is adjusted to be the first collection behavior, so that the load of the security collection component is automatically reduced under the condition that the performance is limited, and the page fluency is guaranteed; a hierarchical acquisition strategy can be implemented according to actual performance conditions instead of simple acquisition switch control, so that finer acquisition control is realized; the hierarchical acquisition strategy is adopted, so that the performance problem can be responded in time without waiting for manual intervention, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and in particular to a control method, device, medium, and computer program product for a secure data acquisition component. Background Technology

[0002] Currently, in web applications, secure data collection software development kits (SDKs) are used for security analysis and risk assessment. Security data collection SDKs typically monitor changes to the document object model (DOM), user interaction events, etc., and report the relevant data to the server for analysis.

[0003] However, because the security data collection SDK needs to continuously monitor page DOM changes and process a large number of events, it may have a significant impact on the performance of web applications, especially when the user's device performance is weak or the web page is complex.

[0004] With users demanding greater fluency in web applications and the increasing prevalence of performance-constrained devices such as mobile devices, how to reduce the impact of secure data collection SDKs on web application performance while ensuring secure data collection has become a pressing technical challenge for the industry. Summary of the Invention

[0005] To solve the above-mentioned technical problems, or at least partially solve them, this disclosure provides a control method, device, medium, and computer program product for a secure data acquisition component.

[0006] In a first aspect, embodiments of this disclosure provide a control method for a secure data acquisition component, the method comprising: If the monitored value of a preset performance indicator is abnormal, determine the first level of abnormality; Based on the preset correspondence between the anomaly level and the collection strategy level, the first collection strategy level corresponding to the first anomaly level is determined. Based on the preset correspondence between the collection strategy level and the collection behavior, the first collection behavior corresponding to the first collection strategy level is determined; Adjust the collection behavior of the security collection component to the first collection behavior.

[0007] In some embodiments, determining a first abnormality level when the monitored value of a preset performance indicator is abnormal includes: If the monitored value of a preset performance indicator is abnormal, a first gap value between the monitored value and the performance threshold is determined; Based on the preset correspondence between the difference value and the anomaly level, the first anomaly level corresponding to the first difference value is determined.

[0008] In some embodiments, the performance threshold is a dynamic threshold, which is determined by at least one of the following methods: Short-term fluctuation adjustment, wherein the short-term fluctuation adjustment is to adjust the initial performance threshold based on the threshold adjustment index related to the page when the page is running, wherein the initial performance threshold is the threshold determined based on device information when the system starts; Mid-term trend adjustment, wherein the mid-term trend adjustment is based on the trend of preset performance indicators within a preset first time period, and the initial performance threshold is adjusted accordingly; Long-term strategy optimization, wherein the long-term strategy optimization is based on the performance index data corresponding to the collection behavior of different collection strategy levels within a preset second time period, and the initial performance threshold is adjusted, wherein the second time period is longer than the first time period.

[0009] In some embodiments, the threshold adjustment metrics associated with the page include: context adjustment factor and / or resource status; The context adjustment factor includes at least one of the following: Page importance factor; User interaction frequency factor; Page lifecycle factor; The resource status includes at least one of the following: Network status; Battery status; Background and / or foreground status.

[0010] In some embodiments, the method further includes: Periodically determine the correspondence between collection behavior and performance overhead based on the monitored values ​​of the preset performance indicators and the performance indicator data corresponding to the collection behavior of the security collection component; Based on the correspondence between the collection behavior and performance overhead, the collection behavior corresponding to different collection strategy levels of the security collection component is optimized.

[0011] In some embodiments, the method further includes: Periodically determine the performance index profile of the equipment type based on the monitoring values ​​of the preset performance indicators and the equipment type; Based on the performance metric profile of the device type, optimize the default data collection behavior configuration for devices or device groups with the device type.

[0012] In some embodiments, the method further includes: Periodically, based on the monitored values ​​of the preset performance indicators and the performance indicator data corresponding to the collection behavior of the security collection component, determine the collection behaviors that cause performance problems; Based on the collection behaviors that cause performance problems, optimization strategies for collection behaviors are preset for the abnormal scenarios corresponding to the performance problems.

[0013] Secondly, embodiments of this disclosure also provide an electronic device, the electronic device comprising: A storage device on which computer programs are stored; A processing device is configured to execute the computer program in the storage device to implement the steps of the control method for the secure acquisition component according to any embodiment of the first aspect.

[0014] Thirdly, embodiments of this disclosure also provide a computer-readable storage medium storing a computer program for executing the control method of the security acquisition component described in any embodiment of the first aspect.

[0015] Fourthly, this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the control method for the security acquisition component described in any embodiment of the first aspect.

[0016] The technical solution provided in this disclosure, when the monitored value of a preset performance indicator is abnormal, determines a first abnormality level. Utilizing the correspondence between the abnormality level and the collection strategy level, a first collection strategy level corresponding to the first abnormality level can be determined. Furthermore, utilizing the correspondence between the collection strategy level and the collection behavior, a first collection behavior corresponding to the first collection strategy level can be determined. This adjusts the collection behavior of the security collection component to the first collection behavior, automatically reducing the load on the security collection component when performance is limited, ensuring page smoothness, and improving user experience. It eliminates the need for real-time response from developers, reducing manual intervention. It enables the implementation of a tiered collection strategy based on actual performance conditions, rather than simple collection switch control, achieving more refined collection control. Due to the tiered collection strategy, performance issues can be addressed promptly without waiting for manual intervention, further improving user experience.

[0017] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0018] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0019] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating a control method for a secure data acquisition component provided in an embodiment of this disclosure; Figure 2 A flowchart illustrating another control method for a secure data acquisition component provided in this embodiment of the present disclosure; Figure 3 A schematic diagram of the structure of a control device for a secure data acquisition component provided in an embodiment of this disclosure; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0021] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0022] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0023] The most common solution in the industry at present is to use a passive response processing mechanism, including the following 1 to 4: 1. Deploy error monitoring and performance monitoring systems; 2. Trigger an alarm when an error or performance problem occurs on the user's end; 3. After receiving the alarm, the R&D personnel can manually disable or adjust the collection behavior of the security collection SDK through the configuration interface; 4. Re-enable the secure data collection SDK function after the problem is resolved.

[0024] In addition, some systems attempt to mitigate the performance impact of the security data collection SDK by: • Employ throttle and debounce techniques to limit the frequency of event processing; • Implement a sampling strategy that collects full data only from a subset of user sessions; • Use Web Workers to offload data processing logic to background threads.

[0025] However, the passive response processing mechanism has the following problems: 1. Delayed response: There is a significant time lag between the occurrence of the problem and manual intervention, during which the user experience is continuously compromised; 2. Reliance on manual intervention: Requires R&D personnel to respond to alarms and take action in real time; 3. Incomplete coverage: Some performance degradation may not have reached the alarm threshold, but it has already affected the user experience; 4. Lack of fine-grained control: Usually, the security data collection SDK can only be fully enabled or disabled, lacking the ability to dynamically adjust according to actual conditions; 5. Alarm storm: Large-scale problems may generate a large number of alarms in a short period of time, increasing the difficulty of handling them; 6. Inability to handle sudden performance fluctuations: Unable to respond promptly to brief performance fluctuations; 7. Lack of equipment adaptability: It cannot adaptively adjust to the performance characteristics of different equipment.

[0026] This disclosure provides a control method, device, medium, and computer program product for a secure data acquisition component, which can achieve the following effects: 1. Adaptive performance monitoring: Real-time monitoring of page performance metrics, memory usage, and other key resource consumption; 2. Dynamic threshold control: Dynamically adjusts performance thresholds based on factors such as device performance and network conditions; 3. Intelligent data acquisition and adjustment: When performance indicators are abnormal, the data acquisition frequency of the security data acquisition SDK is automatically paused or reduced, and data acquisition is automatically resumed after resources are restored; 4. Tiered data collection strategy: Implement different levels of data collection strategies based on performance conditions, rather than simply turning them on or off; 5. Self-learning optimization: Continuously optimize control strategies by recording and analyzing performance data; 6. Context-aware data collection: Dynamically adjusts collection priority based on the current page state and importance; 7. Hybrid Mode Control: A hybrid control mechanism that combines immediate response and long-term strategy optimization.

[0027] Figure 1 This is a flowchart illustrating a control method for a secure data acquisition component according to an embodiment of the present disclosure. This method can be executed by a control device for the secure data acquisition component, which can be implemented using software and / or hardware, and is generally integrated into an electronic device. Figure 1 As shown, the method includes, but is not limited to, steps 101 to 104: In step 101, if the monitored value of the preset performance index is abnormal, the first abnormality level is determined.

[0028] In this embodiment, upon system startup, the control device of the secure data acquisition component collects device information, including device type, device model, browser version, and other information affecting the performance of web applications. Then, the control device sets an initial performance threshold based on the device information and starts the secure data acquisition component to collect data based on the initial acquisition configuration. The secure data acquisition component can be a secure data acquisition software development kit (SDK).

[0029] In this embodiment, the control device of the security acquisition component collects monitoring values ​​of preset performance indicators and determines whether the monitoring values ​​of the preset performance indicators are abnormal based on an initial performance threshold. If the monitoring values ​​of the preset performance indicators are abnormal, the control device of the security acquisition component can determine the first abnormality level corresponding to the monitoring values ​​of the preset performance indicators. The control device of the security acquisition component can pre-set multiple abnormality levels, each corresponding to a different range of monitoring values. Thus, when the monitoring values ​​of the preset performance indicators fall within different monitoring value ranges, the corresponding abnormality level will also be different.

[0030] The preset performance indicators include at least one of the following 1 to 4: 1. Page loading performance metrics.

[0031] Page load performance metrics include at least one of the following 1.1 to 1.3: 1.1 First Contentful Paint (FCP).

[0032] FCP is the point in time when a page first renders non-blank content (such as text, images, and Scalable Vector Graphics (SVG)), reflecting the initial speed at which the page loads as perceived by the user.

[0033] 1.2 Largest Contentful Paint (LCP).

[0034] LCP is the time it takes for the largest visible content (such as large images or text blocks) in the viewport to be rendered, and it measures the visual loading completion rate of the page.

[0035] 1.3 Cumulative Layout Shift (CLS).

[0036] CLS is the sum of layout instabilities caused by changes in element size or position during page loading. The lower the value, the more stable the user experience.

[0037] 2. Runtime performance metrics.

[0038] Runtime performance metrics include at least one of the following 2.1 to 2.3: 2.1 frame rate.

[0039] 2.2 Central Processing Unit (CPU) utilization.

[0040] 2.3 Memory usage.

[0041] 3. Network status indicators.

[0042] Network condition indicators include at least one of the following 3.1 and 3.2: 3.1 Network latency.

[0043] 3.2 Bandwidth usage.

[0044] 4. Resource consumption indicators.

[0045] Resource consumption indicators include at least one of the following 4.1 and 4.2: 4.1 Battery status.

[0046] 4.2 Equipment temperature.

[0047] In step 102, based on the preset correspondence between the anomaly level and the acquisition strategy level, the first acquisition strategy level corresponding to the first anomaly level is determined.

[0048] In this embodiment, for different anomaly levels, the control device of the security acquisition component pre-sets the corresponding acquisition strategy level to obtain the correspondence between the anomaly level and the acquisition strategy level. In this way, when the anomaly level of the monitoring value of the preset performance index is determined to be the first anomaly level, the first acquisition strategy level corresponding to the first anomaly level can be determined based on the correspondence between the anomaly level and the acquisition strategy level.

[0049] In step 103, based on the preset correspondence between the acquisition strategy level and the acquisition behavior, the first acquisition behavior corresponding to the first acquisition strategy level is determined.

[0050] In this embodiment, for different acquisition strategy levels, the control device of the security acquisition component pre-sets corresponding acquisition behaviors to obtain the correspondence between acquisition strategy levels and acquisition behaviors. In this way, when the acquisition strategy level corresponding to the abnormal level is determined to be the first acquisition strategy level, the first acquisition behavior corresponding to the first acquisition strategy level can be determined based on the correspondence between the acquisition strategy level and the acquisition behavior.

[0051] In some embodiments, the data collection strategy is divided into five levels (Level 0 to Level 4), and the data collection behavior corresponding to each level is described as follows: 1. Normal data collection (Level 0) includes at least one of the following collection behaviors: 1.1 to 1.3: 1.1 Full collection of user interactions and DOM changes.

[0052] 1.2 Real-time processing and reporting of data.

[0053] 1.3 Applicable to situations with good performance and sufficient resources.

[0054] 2. The data collection behavior corresponding to minor adjustments (Level 1) includes at least one of the following 2.1 to 2.3: 2.1 Maintain full data collection, but reduce processing and reporting frequency.

[0055] 2.2 Transfer some non-critical data processing to Web Workers.

[0056] 2.3 Applicable to situations with slight performance fluctuations.

[0057] 3. The data collection behavior corresponding to moderate adjustment (Level 2) includes at least one of the following 3.1 to 3.4: 3.1 Reduce the scope of DOM change monitoring and focus on key elements.

[0058] 3.2 Reduce the frequency of listening to non-core events.

[0059] 3.3 Batch processing and periodic reporting of data.

[0060] 3.4 Applicable to situations where there is a significant performance degradation.

[0061] 4. The data collection behavior corresponding to heavy adjustment (Level 3) includes at least one of the following 4.1 to 4.4: 4.1 Only monitor core security events (such as form submissions, sensitive operations, etc.).

[0062] 4.2 Pause non-critical DOM listening.

[0063] 4.3 Minimize data processing and delay reporting.

[0064] 4.4 Applicable to situations with severe performance problems.

[0065] 5. Minimized acquisition (Level 4) corresponds to acquisition behavior including at least one of the following 5.1 to 5.4: 5.1 Only retain necessary security monitoring (such as key anti-fraud nodes).

[0066] 5.2 Suspend all real-time processing and only log critical events.

[0067] 5.3 Wait for performance to recover before processing and reporting data.

[0068] 5.4 Applicable to situations of extreme performance degradation.

[0069] In step 104, the acquisition behavior of the security acquisition component is adjusted to the first acquisition behavior.

[0070] In this embodiment, after the control device of the security collection component determines the first collection behavior, it adjusts the collection behavior of the security collection component to the first collection behavior. When the monitoring value of the preset performance index is abnormal, that is, when the performance is limited, the load of the security collection component is automatically reduced to ensure page smoothness and improve user experience.

[0071] As can be seen, in this embodiment, when the monitored value of the preset performance indicator is abnormal, by determining the first abnormality level and utilizing the correspondence between the abnormality level and the collection strategy level, the first collection strategy level corresponding to the first abnormality level can be determined; then, by utilizing the correspondence between the collection strategy level and the collection behavior, the first collection behavior corresponding to the first collection strategy level can be determined; thereby, the collection behavior of the security collection component is adjusted to the first collection behavior, so that when performance is limited, the load of the security collection component is automatically reduced, ensuring page smoothness and improving user experience; no real-time response from R&D personnel is required, reducing manual intervention; a hierarchical collection strategy can be implemented according to the actual performance situation, rather than a simple collection switch control, achieving more refined collection control; due to the adoption of a hierarchical collection strategy, performance issues can be responded to in a timely manner without waiting for manual intervention, improving user experience.

[0072] In some embodiments, step 101, in the event that the monitored value of a preset performance indicator is abnormal, determines a first abnormality level, including the following steps 1011 and 1012: 1011. When the monitored value of the preset performance index is abnormal, determine the first gap value between the monitored value and the performance threshold.

[0073] In this embodiment, the control device of the security acquisition component can be pre-set with multiple anomaly levels, each anomaly level corresponding to a different range of gap values. Thus, when the first gap value between the monitored value and the performance threshold is in different ranges of monitored values, the corresponding anomaly level is also different.

[0074] 1012. Based on the preset correspondence between the difference value and the anomaly level, determine the first anomaly level corresponding to the first difference value.

[0075] The performance threshold is a dynamic threshold, and the performance threshold is determined by at least one of the following methods (1) to (3): (1) Short-term fluctuation adjustment: Short-term fluctuation adjustment is to adjust the initial performance threshold based on the threshold adjustment index related to the page when the page is running. The initial performance threshold is the threshold determined based on the device information when the system starts.

[0076] Among them, short-term fluctuation adjustments can quickly respond to sudden performance issues without waiting for manual intervention, thus improving the user experience.

[0077] (2) Mid-term trend adjustment: The mid-term trend adjustment is based on the trend of the preset performance index within the first time period, and the initial performance threshold is adjusted.

[0078] The first time period is, for example, a period measured in hours or days. Mid-term trend adjustments ensure that performance thresholds align with actual performance trends, improving the accuracy of data acquisition and control.

[0079] (3) Long-term strategy optimization: Long-term strategy optimization is to adjust the initial performance threshold based on the performance index data corresponding to the collection behavior of different collection strategy levels within the preset second time period. The second time period is longer than the first time period.

[0080] The second time period can be, for example, a weekly or monthly period. Long-term strategy optimization ensures that performance thresholds better match historical performance metrics, providing a more accurate basis for subsequent performance problem assessment.

[0081] In some embodiments, in (1), the threshold adjustment metrics related to the page include: context adjustment factor and / or resource status; The context adjustment factor includes at least one of the following: 1.1 to 1.3 1.1 Page Importance Factor.

[0082] For example, payment pages have a higher tolerance, so the page importance factor value for payment pages is greater than that for non-payment pages.

[0083] 1.2 User interaction frequency factor.

[0084] For example, when users interact frequently, the performance requirements are higher, so the value of the user interaction frequency factor for high-frequency interactions is greater than that for low-frequency interactions.

[0085] 1.3 Page Lifecycle Factor.

[0086] For example, the page lifecycle includes page load time and page stable operation time.

[0087] The resource status includes at least one of the following 2.1 to 2.3: 2.1 Network status.

[0088] For example, reduce the data collection load when the network conditions are poor.

[0089] 2.2 Battery status.

[0090] For example, increasing the sensitivity of performance thresholds when the battery is low.

[0091] 2.3 Backend and / or foreground status.

[0092] For example, when running in the background, reduce the collection priority.

[0093] In some embodiments, the control device of the secure acquisition component can also perform intelligent learning, including at least one of the following 1 to 3: 1. Optimize the collection behavior corresponding to the collection strategy level based on performance overhead, involving the following 1.1 and 1.2: 1.1 Periodically determine the correspondence between collection actions and performance overhead based on the monitored values ​​of preset performance indicators and the performance indicator data corresponding to the collection actions of the security collection components. Different collection actions (such as event listening, data processing, network requests, etc.) have different performance overheads.

[0094] 1.2 Based on the correspondence between collection behavior and performance overhead, optimize the collection behavior corresponding to different collection strategy levels of the security collection component.

[0095] This involves optimizing the collection behavior corresponding to different collection strategy levels of the security collection component, and achieving a balance between performance and data collection by evaluating the performance improvement effect and data loss degree of the collection behavior corresponding to different collection strategy levels.

[0096] 2. Optimize the default data collection behavior configuration based on device type performance indicator profiling, involving the following sections 2.1 and 2.2: 2.1 Periodically determine the performance index profile of the equipment type based on the monitoring values ​​of preset performance indicators and the equipment type.

[0097] 2.2 Based on device type performance index profiles, optimize the default data collection behavior configuration for devices or device groups with device types.

[0098] 3. Based on the data collection behaviors that lead to performance issues, optimization strategies for the pre-defined data collection behaviors are proposed, involving the following sections 3.1 and 3.2: 3.1 Periodically determine the collection behaviors that cause performance problems based on the monitoring values ​​of preset performance indicators and the corresponding performance indicator data of the collection behavior of the security collection component.

[0099] 3.2 Based on the collection behaviors that cause performance problems, optimize the collection behaviors for abnormal scenarios corresponding to performance problems.

[0100] As can be seen from the descriptions of the above embodiments, the control method for the secure data acquisition component provided in this disclosure can achieve the following technical effects: 1. Improve user experience: Automatically reduce the load on the security data collection SDK when performance is limited, ensuring page smoothness.

[0101] 2. Reduced manual intervention: Performance issues can be addressed without manual intervention from R&D personnel.

[0102] 3. Refined control: Implement a tiered data acquisition strategy based on actual performance conditions, rather than simple on / off control.

[0103] 4. Adaptive capability: It can automatically adjust the collection behavior of the security collection SDK according to different device performance, network conditions and other factors.

[0104] 5. Data integrity: While ensuring performance, ensure the integrity of the collected data as much as possible.

[0105] 6. Reduce operation and maintenance costs: Reduce the number of alarms and reduce manual processing costs.

[0106] 7. Improve system stability: Prevent page crashes and lag caused by the security data collection SDK.

[0107] 8. Accelerate problem diagnosis: Provide root cause analysis data through performance and policy execution logs.

[0108] 9. Adaptable to diverse environments: Achieve stable operation under different hardware conditions, network environments, and operating systems.

[0109] Based on the above embodiments, this embodiment provides a system capable of controlling a secure data acquisition component. According to its functions, the system has the following five functional modules: (i) Performance monitoring module, used to collect and analyze key performance indicators (KPIs). KPIs include at least one of the following 1 to 4: 1. Page load performance metrics. Page load performance metrics include at least one of the following 1.1 to 1.3: 1.1 First Contentful Paint (FCP).

[0110] 1.2 Largest Contentful Paint (LCP).

[0111] 1.3 Cumulative Layout Shift (CLS).

[0112] 2. Runtime performance metrics. Runtime performance metrics include at least one of the following 2.1 to 2.3: 2.1 frame rate.

[0113] 2.2 Central Processing Unit (CPU) utilization.

[0114] 2.3 Memory usage.

[0115] 3. Network Status Indicators. Network status indicators include at least one of the following: 3.1 and 3.2: 3.1 Network latency.

[0116] 3.2 Bandwidth usage.

[0117] 4. Resource consumption indicators. Resource consumption indicators include at least one of the following 4.1 and 4.2: 4.1 Battery status.

[0118] 4.2 Equipment temperature.

[0119] (ii) Threshold Management Module, used to maintain and dynamically adjust performance thresholds. The threshold management module includes the following functions 1 to 3: 1. Equipment capability perception.

[0120] The threshold management module can set initial performance thresholds based on device information, which includes information that affects web application performance, such as device type, device model, and browser version.

[0121] 2. Context threshold adjustment.

[0122] The threshold management module can adjust performance thresholds based on context-sensitive adjustment factors.

[0123] The context adjustment factor includes at least one of the following 2.1 to 2.3: 2.1 Page Importance Factor.

[0124] For example, payment pages have a higher tolerance, so the page importance factor value for payment pages is greater than that for non-payment pages.

[0125] 2.2 User interaction frequency factor.

[0126] For example, when users interact frequently, the performance requirements are higher, so the value of the user interaction frequency factor for high-frequency interactions is greater than that for low-frequency interactions.

[0127] 2.3 Page Lifecycle Factor.

[0128] For example, the page lifecycle includes page load time and page stable operation time.

[0129] 3. Adaptive threshold learning.

[0130] The threshold management module can adjust performance thresholds based on historical performance data.

[0131] For example, the threshold management module adjusts the initial performance threshold based on the trend of preset performance indicators within a preset first time period, and / or adjusts the initial performance threshold based on the performance indicator data corresponding to the collection behavior at different collection strategy levels within a preset second time period. The first time period is, for example, a period in hours or days. The second time period is, for example, a period in weeks or months.

[0132] (III) Acquisition Control Module, used to adjust the acquisition behavior of the security acquisition SDK based on performance conditions. The acquisition control module includes the following functions 1 to 4: 1. Selection of acquisition strategy (select an appropriate acquisition strategy based on performance conditions).

[0133] 2. Data acquisition frequency control (adjusting the frequency of event listening and data processing).

[0134] 3. Control the scope of data collection (adjust the type of monitored events and the DOM scope).

[0135] 4. Data processing mode switching (online / offline / batch processing mode switching).

[0136] (iv) Data analysis module, used to record and analyze historical data for intelligent learning, including at least one of the following 1 to 3: 1. Optimize the collection behavior corresponding to the collection strategy level based on performance overhead, involving the following 1.1 and 1.2: 1.1 Periodically determine the correspondence between collection actions and performance overhead based on the monitored values ​​of preset performance indicators and the performance indicator data corresponding to the collection actions of the security collection components. Different collection actions (such as event listening, data processing, network requests, etc.) have different performance overheads.

[0137] 1.2 Based on the correspondence between collection behavior and performance overhead, optimize the collection behavior corresponding to different collection strategy levels of the security collection component.

[0138] This involves optimizing the collection behavior corresponding to different collection strategy levels of the security collection component, and achieving a balance between performance and data collection by evaluating the performance improvement effect and data loss degree of the collection behavior corresponding to different collection strategy levels.

[0139] 2. Optimize the default data collection behavior configuration based on device type performance indicator profiling, involving the following sections 2.1 and 2.2: 2.1 Periodically determine the performance index profile of the equipment type based on the monitoring values ​​of preset performance indicators and the equipment type.

[0140] 2.2 Based on device type performance index profiles, optimize the default data collection behavior configuration for devices or device groups with device types.

[0141] 3. Based on the data collection behaviors that lead to performance issues, optimization strategies for the pre-defined data collection behaviors are proposed, involving the following sections 3.1 and 3.2: 3.1 Periodically determine the collection behaviors that cause performance problems based on the monitoring values ​​of preset performance indicators and the corresponding performance indicator data of the collection behavior of the security collection component.

[0142] 3.2 Based on the collection behaviors that cause performance problems, optimize the collection behaviors for abnormal scenarios corresponding to performance problems.

[0143] (v) Policy Execution Module, used to control the data collection behavior of the security data collection SDK. The policy execution module includes the following functions 1 to 4: 1. Event listener adjustment (adding / removing / adjusting event listeners).

[0144] 2. Handle logical transitions (main thread / Web Worker switching).

[0145] 3. Reporting frequency control (switching between real-time / batch / delayed reporting).

[0146] 4. Adjust the acquisition precision (switch between detailed and simplified data acquisition).

[0147] Based on the control system of the aforementioned security acquisition components Figure 2 This is a schematic diagram illustrating the control flow of another secure data acquisition component provided in an embodiment of this disclosure. Figure 2 In this process, the control flow of the security acquisition component includes the following five stages: (I) Initialization Phase. The initialization phase involves the following steps 1 to 3: 1. When the system starts up, the performance monitoring module collects basic device information, including device type, device model, browser version, and other information that affects the performance of web applications.

[0148] 2. The threshold management module sets initial performance thresholds based on device information.

[0149] 3. The data acquisition control module starts the secure data acquisition SDK to collect data based on the initial data acquisition configuration.

[0150] (II) Continuous Monitoring Phase. The continuous monitoring phase involves the following 1 and 2: 1. The performance monitoring module monitors page performance metrics (frame rate, CPU usage, memory usage, etc.) in real time.

[0151] 2. When an abnormal performance is detected (such as a significant drop in frame rate or excessive memory usage), the data acquisition and adjustment process is triggered.

[0152] (III) Strategy Adjustment Phase. The strategy adjustment phase involves the following points 1 to 3: 1. The threshold management module assesses the gap between the current performance status and the threshold.

[0153] 2. The acquisition control module selects the appropriate acquisition strategy level based on the performance gap.

[0154] 3. The strategy execution module implements adjustments to the SDK behavior corresponding to the collection strategy level.

[0155] (iv) Recovery Monitoring Phase. The recovery monitoring phase involves the following 1 and 2: 1. The performance monitoring module continuously monitors the recovery status of performance indicators.

[0156] 2. Once performance metrics return to normal levels and remain stable, gradually restore the SDK's data collection capabilities.

[0157] (v) Data Analysis Phase. The data analysis phase involves the following steps 1 to 3: 1. Regularly send performance data and policy execution records to the data analysis module.

[0158] 2. The data analysis module identifies SDK behavior patterns that cause performance issues.

[0159] 3. The threshold management module optimizes long-term threshold settings based on the analysis results.

[0160] Corresponding to the aforementioned control method for the secure data acquisition component, this disclosure further provides a control device for the secure data acquisition component. Figure 3 This is a schematic diagram of the structure of a control device for a secure data acquisition component provided in an embodiment of this disclosure. This device can be implemented by software and / or hardware, and is generally integrated into an electronic device, such as... Figure 3 As shown, the control device for the secure data acquisition component includes: a first determining unit 31, a second determining unit 32, a third determining unit 33, and an adjustment unit 34. Detailed descriptions are as follows: The first determining unit 31 is used to determine the first abnormality level when the monitoring value of the preset performance index is abnormal; The second determining unit 32 is used to determine the first collection strategy level corresponding to the first abnormal level based on the preset correspondence between the abnormal level and the collection strategy level. The third determining unit 33 is used to determine the first collection behavior corresponding to the first collection strategy level based on the preset correspondence between the collection strategy level and the collection behavior. Adjustment unit 33 is used to adjust the acquisition behavior of the security acquisition component to the first acquisition behavior.

[0161] In some embodiments, the first determining unit 31 is configured to: If the monitored value of a preset performance indicator is abnormal, determine the first gap between the monitored value and the performance threshold. Based on the preset correspondence between the difference value and the anomaly level, the first anomaly level corresponding to the first difference value is determined.

[0162] In some embodiments, the performance threshold is a dynamic threshold, which is determined by at least one of the following methods: Short-term fluctuation adjustment refers to adjusting the initial performance threshold based on page-related threshold adjustment indicators during page runtime. The initial performance threshold is determined based on device information when the system starts. Mid-term trend adjustment: The mid-term trend adjustment is based on the trend of preset performance indicators within a preset first time period, and the initial performance threshold is adjusted accordingly. Long-term strategy optimization involves adjusting the initial performance threshold based on the performance metrics data corresponding to different collection strategy levels within a preset second time period, where the second time period is longer than the first time period.

[0163] In some embodiments, the threshold adjustment metrics related to the page include: context adjustment factor and / or resource status; Context adjustment factors include at least one of the following: Page importance factor; User interaction frequency factor; Page lifecycle factor; Resource status includes at least one of the following: Network status; Battery status; Background and / or foreground status.

[0164] In some embodiments, the apparatus further includes a first optimization unit for: Periodically determine the correspondence between collection behavior and performance overhead by comparing the monitored values ​​of preset performance indicators with the performance indicator data corresponding to the collection behavior of the security collection component. Based on the correlation between data collection behavior and performance overhead, optimize the data collection behavior corresponding to different data collection strategy levels of the security data collection component.

[0165] In some embodiments, the apparatus further includes a second optimization unit for: Regularly determine the performance profile of the equipment type based on the monitoring values ​​of preset performance indicators and the equipment type; Based on device type performance metrics profiles, optimize default data collection behavior configurations for devices or device groups with device types.

[0166] In some embodiments, the apparatus further includes a third optimization unit for: Periodically identify the collection behaviors that cause performance problems based on the monitoring values ​​of preset performance indicators and the corresponding performance indicator data of the collection behavior of the security collection component; Based on the data collection behaviors that lead to performance issues, optimization strategies for data collection behaviors are preset for abnormal scenarios corresponding to performance issues.

[0167] The control device for the secure data acquisition component provided in this disclosure can execute the control method for the secure data acquisition component provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects for executing the method.

[0168] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device embodiments can be referred to the corresponding process in the method embodiments, and will not be repeated here.

[0169] This disclosure provides an electronic device, which includes: a storage device storing a computer program thereon; and a processing device for executing the computer program in the storage device to implement the steps of any method of this disclosure.

[0170] The following is for reference. Figure 4 This diagram illustrates a structural schematic of an electronic device 400 suitable for implementing embodiments of the present disclosure. The terminal devices in these embodiments may include, but are not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0171] like Figure 4As shown, electronic device 400 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 401, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 402 or a program loaded from storage device 408 into random access memory (RAM) 403. RAM 403 also stores various programs and data required for the operation of electronic device 400. Processing device 401, ROM 402, and RAM 403 are interconnected via bus 404. Input / output (I / O) interface 405 is also connected to bus 404.

[0172] Typically, the following devices can be connected to I / O interface 405: input devices 406 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 407 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 408 including, for example, magnetic tapes, hard disks, etc.; and communication devices 409. Communication device 409 allows electronic device 400 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 4 An electronic device 400 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0173] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 409, or installed from a storage device 408, or installed from a ROM 402. When the computer program is executed by the processing device 401, it performs the functions defined in the methods of the embodiments of this disclosure.

[0174] In addition to the methods and devices described above, embodiments of this disclosure can also be computer program products, comprising computer program instructions that, when executed by a processor, cause the processor to perform the methods provided in the embodiments of this disclosure. The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this disclosure. These programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0175] Furthermore, embodiments of this disclosure may also be computer-readable storage media storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the control method of the secure acquisition component provided in embodiments of this disclosure.

[0176] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.

[0177] This disclosure also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the control method of the security acquisition component in this disclosure.

[0178] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and their authorization should be obtained.

[0179] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.

[0180] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0181] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0182] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0183] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A control method for a secure data acquisition component, characterized in that, The method includes: If the monitored value of a preset performance indicator is abnormal, determine the first level of abnormality; Based on the preset correspondence between the anomaly level and the collection strategy level, the first collection strategy level corresponding to the first anomaly level is determined. Based on the preset correspondence between the collection strategy level and the collection behavior, the first collection behavior corresponding to the first collection strategy level is determined; Adjust the collection behavior of the security collection component to the first collection behavior.

2. The method according to claim 1, characterized in that, The step of determining a first anomaly level when the monitored value of a preset performance indicator is abnormal includes: If the monitored value of a preset performance indicator is abnormal, a first gap value between the monitored value and the performance threshold is determined; Based on the preset correspondence between the difference value and the anomaly level, the first anomaly level corresponding to the first difference value is determined.

3. The method according to claim 2, characterized in that, The performance threshold is a dynamic threshold, and the performance threshold is determined by at least one of the following methods: Short-term fluctuation adjustment, wherein the short-term fluctuation adjustment is to adjust the initial performance threshold based on the threshold adjustment index related to the page when the page is running, wherein the initial performance threshold is the threshold determined based on device information when the system starts; Mid-term trend adjustment, wherein the mid-term trend adjustment is based on the trend of preset performance indicators within a preset first time period, and the initial performance threshold is adjusted accordingly; Long-term strategy optimization, wherein the long-term strategy optimization is based on the performance index data corresponding to the collection behavior of different collection strategy levels within a preset second time period, and the initial performance threshold is adjusted, wherein the second time period is longer than the first time period.

4. The method according to claim 3, characterized in that, The threshold adjustment metrics related to the page include: context adjustment factor and / or resource status; The context adjustment factor includes at least one of the following: Page importance factor; User interaction frequency factor; Page lifecycle factor; The resource status includes at least one of the following: Network status; Battery status; Background and / or foreground status.

5. The method according to claim 1, characterized in that, The method further includes: Periodically determine the correspondence between collection behavior and performance overhead based on the monitored values ​​of the preset performance indicators and the performance indicator data corresponding to the collection behavior of the security collection component; Based on the correspondence between the collection behavior and performance overhead, the collection behavior corresponding to different collection strategy levels of the security collection component is optimized.

6. The method according to claim 1, characterized in that, The method further includes: Periodically determine the performance index profile of the equipment type based on the monitoring values ​​of the preset performance indicators and the equipment type; Based on the performance metric profile of the device type, optimize the default data collection behavior configuration for devices or device groups with the device type.

7. The method according to claim 1, characterized in that, The method further includes: Periodically, based on the monitored values ​​of the preset performance indicators and the performance indicator data corresponding to the collection behavior of the security collection component, determine the collection behaviors that cause performance problems; Based on the collection behaviors that cause performance problems, optimization strategies for collection behaviors are preset for the abnormal scenarios corresponding to the performance problems.

8. An electronic device, characterized in that, The electronic device includes: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the control method for the secure acquisition component according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program for executing the control method of the security acquisition component according to any one of claims 1-7.

10. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the control method for the secure acquisition component according to any one of claims 1-7.