The application provides a webpage tampering monitoring method,
system, device, medium and program product, and relates to the technical field of
network security.The method comprises the following steps: acquiring a current DOM tree,
current source code and current webpage screenshot of each webpage, which are recorded as a current
data set; acquiring a standard DOM tree, standard
source code and standard webpage screenshot of each webpage, which are recorded as a standard
data set; acquiring a webpage map, wherein the webpage map comprises a link relationship between the webpages; determining a first webpage tampering degree of each webpage according to the webpage map, the current
data set and the standard data set, which is recorded as a webpage tampering degree set; and if a second webpage tampering degree greater than or equal to a preset threshold exists in the webpage tampering degree set, it is determined that the webpage corresponding to the second webpage tampering degree has a tampering risk.The application monitors the webpage by means of the DOM tree, the webpage screenshot and the webpage
source code, thereby avoiding inaccurate monitoring caused by incomplete keyword feature libraries.