Malicious group determination method and device, electronic equipment and storage medium
A technology for determining methods and groups, applied in the computer field, can solve problems such as rapid occurrence time and difficulty in effectively finding malicious groups, and achieve the effect of improving efficiency and accuracy
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2021-01-01
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The embodiments of the present invention relate to computer technology, and in particular to a method, device, electronic equipment and storage medium for determining a malicious party. Background technique
[0002] With the integration and development of digital technology and the financial industry, there have been malicious gangs engaged in illegal activities such as online scamming and order swiping, which has led to the continuous expansion of financial fraud risks and the increasingly severe situation of online financial risk control.
[0003] In the prior art, when a security problem breaks out, different scenarios are observed and analyzed mainly through manual analysis, so as to formulate corresponding strategies. However, it is difficult for a single-dimensional risk control strategy to obtain the behavior of malicious groups in multiple directions, and the behavior of malicious groups occurs quickly, and it is difficult to effectively discov...
Examples
Embodiment 1
[0027] figure 1 It is a flow chart of a method for determining a malicious party provided by Embodiment 1 of the present invention. This embodiment is applicable to the situation of determining a malicious party from historical fraud data. This method can be implemented by the device for determining a malicious party provided in this embodiment Execution, the device may be implemented by software and / or hardware. see figure 1 , the method for determining a malicious group provided in this embodiment includes:
[0028] Step 110, determine the knowledge graph according to the relationship between the initial entity and the initial entity in the historical fraud data.
[0029] Wherein, the historical fraud data is data that has been determined to be related to fraudulent behavior, such as fraudulent transactions, fraudulent accounts, and the like. The initial entity is an entity object obtained based on historical fraud data. For example, if the historical fraud data is fraudu...
Embodiment 2
[0062] figure 2 It is a flow chart of a method for determining a malicious party provided by Embodiment 2 of the present invention. This technical solution is supplementary explanation for the process of determining the degree of similarity among different initial entities in the knowledge map. Compared with the above scheme, the specific optimization of this scheme is to determine the similarity between different initial entities in the knowledge map, including:
[0063] Matching the basic attribute value and relational attribute value of the initial entity belonging to any entity category in the knowledge graph with the candidate feature value range of the entity category to obtain the target feature value range of the initial entity;
[0064] According to the target eigenvalue intervals of different initial entities under the entity category, the similarity between different initial entities is determined. Specifically, the flow chart of the malicious group determination...
Embodiment 3
[0082] image 3 It is a schematic structural diagram of a malicious party device provided by Embodiment 3 of the present invention. The device can be realized by hardware and / or software, can execute a malicious party method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method. like image 3 As shown, the device includes:
[0083] The knowledge map determination module 310 is used to determine the knowledge map according to the relationship between the initial entity and the initial entity in the historical fraud data;
[0084] A candidate entity selection module 320, configured to determine the degree of similarity between different initial entities in the knowledge graph, and select candidate entities from the initial entities according to the degree of similarity;
[0085] A knowledge graph division module 330, configured to divide the knowledge graph determined by the candidate enti...