US2018219907A1PendingUtilityA1

Method and apparatus for detecting website security

Assignee: BEIJING QIHOO TECHNOLOGY COPriority: Apr 11, 2014Filed: Mar 28, 2018Published: Aug 2, 2018
Est. expiryApr 11, 2034(~7.7 yrs left)· nominal 20-yr term from priority
Inventors:Zhuan Long
H04L 63/1433
33
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention discloses a method and an apparatus for detecting website security. The method includes: performing bypass interception on a network to snatch a hypertext transfer protocol request packet; acquiring a link corresponding to the hypertext transfer protocol request packet; determining whether the link is new; or determining whether a domain name of the link is new; inserting the link into a to-be-scanned queue as a priority task to be scanned in response to a determination that the link is new; or inserting the domain name into the to-be-scanned queue as a priority task to be scanned in response to a determination that the domain name is new; and performing vulnerability scanning on the task to be scanned in the to-be-scanned queue.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting website security, comprising:
 performing bypass interception on a network to snatch a hypertext transfer protocol request packet;   acquiring a link corresponding to the hypertext transfer protocol request packet;   determining whether the link is new; or determining whether a domain name of the link is new;   inserting the link into a to-be-scanned queue as a priority task to be scanned in response to a determination that the link is new; or inserting the domain name into the to-be-scanned queue as a priority task to be scanned in response to a determination that the domain name is new; and   performing vulnerability scanning on the task to be scanned in the to-be-scanned queue.   
     
     
         2 . The method according to  claim 1 , wherein the determining whether a domain name of the link is new further comprises:
 detecting whether there is flow of the domain name within a preset time range; and   determining that the domain name is new when there is no flow of the domain name within the predetermined period of time.   
     
     
         3 . The method according to  claim 1 , wherein the determining whether a domain name of the link is new further comprises:
 determining the domain name is new domain name of a holder of the domain name when a validated domain name of the holder is present in an IP address or an IP address range to which the domain name belongs upon detection.   
     
     
         4 . The method according to  claim 1 , wherein the determining whether the link is new further comprises:
 comparing the link with links pre-stored in a link library; and   determining the link is new when there is no identical link in the link library.   
     
     
         5 . The method according to  claim 1 , further comprises:
 adding the link into a link library.   
     
     
         6 . The method according to  claim 5 , wherein before the adding the link into the link library, the method further comprises:
 analyzing whether the link is a valid link.   
     
     
         7 . The method according to  claim 5 , wherein the adding the link into the link library further comprises:
 summarizing links having an identical domain name in the link library.   
     
     
         8 . The method according to  claim 7 , wherein the determining whether a domain name of the link is new further comprises:
 detecting whether there is flow of the domain name within a preset time range; and   determining that the domain name is new when there is no flow of the domain name within the predetermined period of time.   
     
     
         9 . The method according to  claim 7 , wherein the determining whether a domain name of the link is new further comprises:
 determining the domain name is new domain name of a holder of the domain name when a validated domain name of the holder is present in an IP address or an IP address range to which the domain name belongs upon detection.   
     
     
         10 . The method according to  claim 1 , wherein the performing vulnerability scanning on the task to be scanned in the to-be-scanned queue specifically comprises:
 sending a test request to a target website corresponding to the task to be scanned, and performing vulnerability scanning according to a webpage returned by the target website.   
     
     
         11 . An electronic device for detecting website security, comprising:
 a memory having instructions stored thereon;   a processor configured to execute the instructions to perform operations for detecting website security, the operations comprising:   performing bypass interception on a network to snatch a hypertext transfer protocol request packet;   acquiring a link corresponding to the hypertext transfer protocol request packet;   determining whether the link is new; or determining whether a domain name of the link is new;   inserting the link into a to-be-scanned queue as a priority task to be scanned in response to a determination that the link is new; or inserting the domain name into the to-be-scanned queue as a priority task to be scanned in response to a determination that the domain name is new; and   performing vulnerability scanning on the task to be scanned in the to-be-scanned queue.   
     
     
         12 . The electronic device according to  claim 11 , wherein the operation of determining whether a domain name of the link is new further comprise:
 detecting whether there is flow of the domain name within a preset time range; and   determining that the domain name is new when there is no flow of the domain name within the predetermined period of time.   
     
     
         13 . The electronic device according to  claim 11 , wherein the operation of determining whether a domain name of the link is new further comprise:
 determining the domain name is new domain name of a holder of the domain name when a validated domain name of the holder is present in an IP address or an IP address range to which the domain name belongs upon detection.   
     
     
         14 . The electronic device according to  claim 11 , wherein the operation of determining whether the link is new further comprise:
 comparing the link with links pre-stored in a link library; and   determining the link is new when there is no identical link in the link library.   
     
     
         15 . The electronic device according to  claim 11 , wherein the operations further comprise:
 adding the link into a link library.   
     
     
         16 . The electronic device according to  claim 15 , wherein the operation of adding the link into the link library further comprises:
 summarizing links having an identical domain name in the link library.   
     
     
         17 . The electronic device according to  claim 16 , wherein the operation of determining whether a domain name of the link is new further comprise:
 detecting whether there is flow of the domain name within a preset time range; and   determining that the domain name is new when there is no flow of the domain name within the predetermined period of time.   
     
     
         18 . The electronic device according to  claim 16 , wherein the operation of determining whether a domain name of the link is new further comprise:
 determining the domain name is new domain name of a holder of the domain name when a validated domain name of the holder is present in an IP address or an IP address range to which the domain name belongs upon detection.   
     
     
         19 . The electronic device according to  claim 11 , wherein the operation of performing vulnerability scanning on the task to be scanned in the to-be-scanned queue specifically comprises:
 sending a test request to a target website corresponding to the task to be scanned, and performing vulnerability scanning according to a webpage returned by the target website.   
     
     
         20 . A non-transitory computer-readable medium having computer programs stored thereon that, when executed by one or more processors of an electronic device, cause the electronic device to perform operations for detecting website security, the operations comprising:
 performing bypass interception on a network to snatch a hypertext transfer protocol request packet;   acquiring a link corresponding to the hypertext transfer protocol request packet;   determining whether the link is new; or determining whether a domain name of the link is new;   inserting the link into a to-be-scanned queue as a priority task to be scanned in response to a determination that the link is new; or inserting the domain name into the to-be-scanned queue as a priority task to be scanned in response to a determination that the domain name is new; and   performing vulnerability scanning on the task to be scanned in the to-be-scanned queue.

Join the waitlist — get patent alerts

Track US2018219907A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.