CN107786537B - Isolated page implantation attack detection method based on Internet cross search - Google Patents
Isolated page implantation attack detection method based on Internet cross search Download PDFInfo
- Publication number
- CN107786537B CN107786537B CN201710845948.0A CN201710845948A CN107786537B CN 107786537 B CN107786537 B CN 107786537B CN 201710845948 A CN201710845948 A CN 201710845948A CN 107786537 B CN107786537 B CN 107786537B
- Authority
- CN
- China
- Prior art keywords
- page
- link
- illegal
- website
- links
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/955—Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
- G06F16/9558—Details of hyperlinks; Management of linked annotations
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/955—Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
- G06F16/9566—URL specific, e.g. using aliases, detecting broken or misspelled links
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/30—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Databases & Information Systems (AREA)
- Theoretical Computer Science (AREA)
- Data Mining & Analysis (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Technology Law (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
本发明涉及信息安全技术,旨在提供一种基于互联网交叉搜索的孤页植入攻击检测方法。该种基于互联网交叉搜索的孤页植入攻击检测方法包括步骤:将互联网上的网站整理成网站库,对每一个站点的首页进行暗链和关键词检索;对于可疑程度较高网站,将其风险链接模块中的风险链接进行逐条解析;将非法链接的源页面和指向页面进行组合分析,进一步确认被非法篡改或植入的可能性;从非法链接指向的页面所在的WEB系统找出并确认是孤页。本发明确认非法模块、非法链接、非法内容的概率是可变化、可学习的;本发明从整体多个角度分析比单一内容更准确,更可信。
The invention relates to information security technology and aims to provide an orphan page implantation attack detection method based on Internet cross search. The method for detecting orphan page implantation attacks based on Internet cross-search includes the steps of: arranging websites on the Internet into a website library, and searching for dark links and keywords on the homepage of each website; The risk links in the risk link module are analyzed one by one; the source page and the pointing page of the illegal link are combined and analyzed to further confirm the possibility of illegal tampering or implantation; find and confirm from the WEB system where the page pointed to by the illegal link is located. is an orphan page. The present invention confirms that the probability of illegal modules, illegal links and illegal contents is changeable and learnable; the present invention is more accurate and more credible than single content analysis from the whole and multiple angles.
Description
Claims (1)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710845948.0A CN107786537B (en) | 2017-09-19 | 2017-09-19 | Isolated page implantation attack detection method based on Internet cross search |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710845948.0A CN107786537B (en) | 2017-09-19 | 2017-09-19 | Isolated page implantation attack detection method based on Internet cross search |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN107786537A CN107786537A (en) | 2018-03-09 |
| CN107786537B true CN107786537B (en) | 2020-04-07 |
Family
ID=61437609
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201710845948.0A Active CN107786537B (en) | 2017-09-19 | 2017-09-19 | Isolated page implantation attack detection method based on Internet cross search |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN107786537B (en) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110309667B (en) * | 2019-04-16 | 2022-08-30 | 网宿科技股份有限公司 | Website hidden link detection method and device |
| CN110298006B (en) * | 2019-06-28 | 2025-05-27 | 北京百度网讯科技有限公司 | Method and apparatus for detecting sites that use stolen links |
| CN111460442A (en) * | 2020-04-24 | 2020-07-28 | 怀化学院 | An Attack Detection Method Based on Internet Cross-Search Defects |
| CN111814643B (en) * | 2020-06-30 | 2024-07-05 | 杭州科度科技有限公司 | Black ash URL identification method and device, electronic equipment and medium |
| CN112199573B (en) * | 2020-08-05 | 2023-12-08 | 宝付网络科技(上海)有限公司 | Illegal transaction active detection method and system |
| CN112039885B (en) * | 2020-08-31 | 2022-09-02 | 绿盟科技集团股份有限公司 | Website risk assessment method and device |
| CN112347327B (en) * | 2020-10-22 | 2024-03-19 | 杭州安恒信息技术股份有限公司 | Website detection methods, devices, readable storage media and computer equipment |
| CN112487321A (en) * | 2020-12-08 | 2021-03-12 | 北京天融信网络安全技术有限公司 | Detection method, detection device, storage medium and electronic equipment |
| CN115033819A (en) * | 2022-04-26 | 2022-09-09 | 广东希尔文化传媒投资股份有限公司 | Internet risk monitoring method and system |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102571783A (en) * | 2011-12-29 | 2012-07-11 | 北京神州绿盟信息安全科技股份有限公司 | Phishing website detection method, device and system as well as website |
| CN104077353A (en) * | 2011-12-30 | 2014-10-01 | 北京奇虎科技有限公司 | Method and device for detecting hacking links |
| CN104378389A (en) * | 2014-12-12 | 2015-02-25 | 北京奇虎科技有限公司 | Website security detecting method and device |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102801574B (en) * | 2011-05-27 | 2016-08-31 | 阿里巴巴集团控股有限公司 | The detection method of a kind of web page interlinkage, device and system |
-
2017
- 2017-09-19 CN CN201710845948.0A patent/CN107786537B/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102571783A (en) * | 2011-12-29 | 2012-07-11 | 北京神州绿盟信息安全科技股份有限公司 | Phishing website detection method, device and system as well as website |
| CN104077353A (en) * | 2011-12-30 | 2014-10-01 | 北京奇虎科技有限公司 | Method and device for detecting hacking links |
| CN104378389A (en) * | 2014-12-12 | 2015-02-25 | 北京奇虎科技有限公司 | Website security detecting method and device |
Non-Patent Citations (1)
| Title |
|---|
| 基于Crawler技术的超链接测试系统;吉向东;《信息技术》;20090905(第9期);106-108 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN107786537A (en) | 2018-03-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN107786537B (en) | Isolated page implantation attack detection method based on Internet cross search | |
| US10885190B2 (en) | Identifying web pages in malware distribution networks | |
| Jain et al. | Two-level authentication approach to protect from phishing attacks in real time | |
| US10721271B2 (en) | System and method for detecting phishing web pages | |
| US20150033331A1 (en) | System and method for webpage analysis | |
| CN107688743B (en) | Malicious program detection and analysis method and system | |
| CN101512522B (en) | System and method for analyzing web content | |
| US9130988B2 (en) | Scareware detection | |
| US8505094B1 (en) | Detection of malicious URLs in a web page | |
| Wang et al. | Detection of malicious web pages based on hybrid analysis | |
| CN105184159A (en) | Web page falsification identification method and apparatus | |
| CN101490685A (en) | A method for increasing the security level of a user machine browsing web pages | |
| CN102446255B (en) | Method and device for detecting page tampering | |
| US20180131708A1 (en) | Identifying Fraudulent and Malicious Websites, Domain and Sub-domain Names | |
| CN104168293A (en) | Method and system for recognizing suspicious phishing web page in combination with local content rule base | |
| Chiew et al. | Building standard offline anti-phishing dataset for benchmarking | |
| Tan et al. | Phishing website detection using URL-assisted brand name weighting system | |
| CN110309667B (en) | Website hidden link detection method and device | |
| CN105959324A (en) | Regular matching-based network attack detection method and apparatus | |
| CN103716394B (en) | Download the management method and device of file | |
| CN109344614A (en) | An online detection method for Android malicious applications | |
| CN115580422B (en) | A black link identification method, device, equipment and storage medium | |
| Fatt et al. | Phishdentity: Leverage website favicon to offset polymorphic phishing website | |
| Almishari et al. | Ads-portal domains: Identification and measurements | |
| Swathi et al. | Detection of Phishing Websites Using Machine Learning |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| CB02 | Change of applicant information | ||
| CB02 | Change of applicant information |
Address after: 310051 No. 188 Lianhui Street, Xixing Street, Binjiang District, Hangzhou City, Zhejiang Province Applicant after: Dbappsecurity Co.,Ltd. Address before: Zhejiang Zhongcai Building No. 68 Binjiang District road Hangzhou City, Zhejiang Province, the 310051 and 15 layer Applicant before: Dbappsecurity Co.,ltd. |
|
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| EE01 | Entry into force of recordation of patent licensing contract | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20180309 Assignee: Hangzhou Anheng Information Security Technology Co.,Ltd. Assignor: Dbappsecurity Co.,Ltd. Contract record no.: X2024980043369 Denomination of invention: A Detection Method of Orphaned Page Implantation Attack Based on Internet Cross Search Granted publication date: 20200407 License type: Common License Record date: 20241231 |