Flow detection method, device, electronic device and storage medium

By acquiring and aggregating the detection dimensions and statistical indicators of business traffic data and determining the relevance of traffic distribution data, we solve the problem of detecting abnormal user behavior from massive traffic data and achieve efficient and extensive abnormal traffic detection.

CN115499231BActive Publication Date: 2025-10-03BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211172330.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-10-03
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

How to detect abnormal traffic data of abnormal user behavior from the massive traffic data of visiting various websites, especially the traffic data of abnormal user behavior such as machine crawling and cheating by abnormal user groups.

Method used

By obtaining the detection dimensions and statistical indicators of business traffic data, multiple dimension values ​​and indicator values ​​are determined, aggregated, and traffic distribution data is obtained, and target business traffic data is determined based on relevance.

Benefits of technology

It realizes the efficient detection of abnormal traffic data from business traffic data, has a wide range of applications, low complexity and high detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115499231B_ABST
    Figure CN115499231B_ABST
Patent Text Reader

Abstract

The present disclosure provides a flow detection method, device, electronic device and storage medium, which relate to the fields of computer technology such as the Internet and big data. The specific implementation scheme is: obtaining the business flow data to be detected, the corresponding detection dimensions and statistical indicators; determining multiple dimension values ​​of the detection dimensions and determining multiple index values ​​of the statistical indicators; based on the multiple dimension values ​​and the multiple index values, aggregating the business flow data to obtain the flow distribution data of each dimension value under the multiple index values; determining the correlation between the flow distribution data of each dimension value under the multiple index values, and determining the target business flow data in the business flow data based on the correlation. In this way, it is achieved that the target business flow data with abnormalities can be detected from the business flow data to be detected, and it has strong versatility, low complexity and high detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, specifically to the Internet, big data and other technical fields, and in particular to flow detection methods, devices, electronic devices and storage media. Background Art

[0002] With the development of internet technology, traffic data from websites has begun to show abnormal user behavior, such as machine crawling and cheating by irregular user groups. Detecting abnormal traffic data from this massive amount of traffic data is an urgent problem. Summary of the Invention

[0003] The present disclosure provides a flow detection method, device, electronic device and storage medium.

[0004] According to one aspect of the present disclosure, a traffic detection method is provided, which includes: obtaining business traffic data to be detected, corresponding detection dimensions and statistical indicators; determining multiple dimension values ​​of the detection dimensions and determining multiple index values ​​of the statistical indicators; aggregating the business traffic data based on the multiple dimension values ​​and the multiple index values ​​to obtain traffic distribution data of each dimension value under the multiple index values; determining the correlation between the traffic distribution data of each dimension value under the multiple index values, and determining the target business traffic data in the business traffic data based on the correlation.

[0005] According to another aspect of the present disclosure, a traffic detection device is provided, which includes: an acquisition module for acquiring business traffic data to be detected, corresponding detection dimensions and statistical indicators; a first determination module for determining multiple dimension values ​​of the detection dimensions and determining multiple index values ​​of the statistical indicators; an aggregation module for aggregating the business traffic data based on the multiple dimension values ​​and the multiple index values ​​to obtain traffic distribution data of each dimension value under the multiple index values; a second determination module for determining the correlation between the traffic distribution data of each dimension value under the multiple index values, and determining the target business traffic data in the business traffic data based on the correlation.

[0006] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the flow detection method of the present disclosure.

[0007] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the flow detection method disclosed in the embodiment of the present disclosure.

[0008] According to another aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the steps of the flow detection method of the present disclosure.

[0009] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.

[0011] Figure 1 is a flow chart of a flow detection method according to the first embodiment of the present disclosure;

[0012] Figure 2 is a flow chart of a flow detection method according to the second embodiment of the present disclosure;

[0013] Figure 3 is a flow chart of a flow detection method according to the third embodiment of the present disclosure;

[0014] Figure 4 is a flow chart of a flow detection method according to a fourth embodiment of the present disclosure;

[0015] Figure 5 is a structural schematic diagram of a flow detection device according to a fifth embodiment of the present disclosure;

[0016] Figure 6 is a structural schematic diagram of a flow detection device according to a sixth embodiment of the present disclosure;

[0017] Figure 7 It is a block diagram of an electronic device used to implement the flow detection method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0018] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0019] It should be noted that the acquisition, storage and application of user personal information involved in the technical solution of this disclosure are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0020] The embodiments of the present disclosure provide a flow detection method, device, electronic device, non-transient computer-readable storage medium, and computer program product. The flow detection method includes: obtaining the business flow data to be detected, the corresponding detection dimension, and the statistical index; determining multiple dimension values ​​of the detection dimension and determining multiple index values ​​of the statistical index; based on the multiple dimension values ​​and the multiple index values, aggregating the business flow data to obtain the flow distribution data of each dimension value under the multiple index values; determining the correlation between the flow distribution data of each dimension value under the multiple index values, and determining the target business flow data in the business flow data based on the correlation. In this way, it is achieved that the target business flow data with abnormalities is detected from the business flow data to be detected, and the method has strong versatility, low complexity, and high detection efficiency.

[0021] Among them, the traffic detection method, device, electronic device, non-transitory computer-readable storage medium and computer program product provided by the present disclosure relate to the field of computer technology, specifically the field of the Internet and big data technology.

[0022] Internet technology refers to an information technology developed on the basis of computer technology. The widespread application of Internet technology is a sign of entering the information society.

[0023] The flow detection method, apparatus, electronic device, non-transitory computer-readable storage medium, and computer program product according to embodiments of the present disclosure are described below with reference to the accompanying drawings.

[0024] First, the flow detection method provided by the embodiment of the present disclosure is described.

[0025] Figure 1 This is a flow chart of a flow detection method according to the first embodiment of the present disclosure. It should be noted that the flow detection method of this embodiment is executed by a flow detection device, which can be implemented by software and / or hardware. The flow detection device can be configured in an electronic device, which may include but is not limited to a terminal device, a server, etc. This embodiment does not specifically limit the electronic device.

[0026] like Figure 1 As shown, the flow detection method may include:

[0027] Step 101: Obtain the business traffic data to be detected, the corresponding detection dimensions and statistical indicators.

[0028] Among them, business traffic data refers to the traffic data of accessing a certain website within a preset time period. Specifically, it can be the data included in the access log of a certain website within the preset time period, such as the user ID of the accessing user corresponding to each access request of the website, the model of the device used, the IP (Internet Protocol) address of the device used, the access time, the type of browser used, the JA3 fingerprint of the browser used, the region where the device used is located, the IPC segment where the IP address of the device used is located, and other data. Among them, the IPC segment refers to a Class C IP address, which means that in the four segments of the IP address, the first three segments are network numbers and the remaining segment is the number of the local computer. JA3 is a method for fingerprinting transport layer security applications, and the JA3 fingerprint can uniquely identify the corresponding browser. Among them, the preset time period can be set as needed, such as 1 day, 3 days, 7 days, one month, etc.

[0029] The detection dimension is a pre-set dimension for detecting business traffic data, which can be set as needed, for example, it can be set to time dimension, user dimension, IP dimension, IPC dimension, JA3 dimension, etc. This disclosure does not impose any restrictions on this.

[0030] Statistical indicators are used to collect statistics on business traffic data, such as time series, region, device type, IPC segment, JA3, browser type, and other indicators.

[0031] The number of detection dimensions or statistical indicators obtained may be one or more, and this disclosure does not impose any restrictions on this.

[0032] It should be noted that after obtaining the business traffic data to be tested, the business traffic data can be cleaned and standardized by extracting and converting fields such as IP addresses and device types, and then subsequent processing can be performed based on the standardized business traffic data to improve the accuracy of traffic detection.

[0033] Step 102: determine multiple dimension values ​​of the detection dimension and determine multiple indicator values ​​of the statistical indicator.

[0034] The detection dimension has corresponding multiple dimensional values, such as each dimensional value of the time dimension is each time period, each dimensional value of the user dimension is each user ID, each dimensional value of the IP dimension is each IP address, each dimensional value of the IPC dimension is each IPC segment, each dimensional value of the JA3 dimension is each JA3 fingerprint, etc. The user ID can be the application account used by the user, the user's ID number, etc., which is not limited in this disclosure.

[0035] Statistical indicators have corresponding multiple indicator values. For example, the indicator values ​​of time series indicators are for each time period, the indicator values ​​of regional indicators are for each region, the indicator values ​​of device type indicators are for each device model, the indicator values ​​of IPC segment indicators are for each specific IPC segment, the indicator values ​​of JA3 indicators are for each JA3 fingerprint, and the indicator values ​​of browser type indicators are for each browser type and version number.

[0036] Each time period of the time series indicator can be used to count at least one of the traffic data such as the number of access requests, the number of users, and the number of devices whose access time falls within the corresponding time period in the business traffic data. For example, if a day is divided into 24*60 / 10 time periods at 10-minute intervals, the time period of "0:00 to 0:10" can be used to count the number of access requests within the time period in the business traffic data, that is, the total number of access requests for a certain website within the time period; or the time period of "0:00 to 0:10" can be used to count the number of users within the time period in the business traffic data, that is, the total number of users who visit a certain website within the time period; or the time period of "0:00 to 0:10" can be used to count the number of devices within the time period in the business traffic data, that is, the total number of devices who visit a certain website within the time period.

[0037] Each area of ​​the regional indicator can be used to count at least one of the traffic data such as the number of access requests, the number of users and the number of devices located in the corresponding area in the business traffic data. For example, assuming that each area of ​​the regional indicator includes "Province A", "Province A" can be used to count the number of access requests located in Province A in the business traffic data, that is, for a certain website, how many devices corresponding to the access requests are located in Province A; or "Province A" can be used to count the number of users located in Province A in the business traffic data, that is, for a certain website, how many users use devices located in Province A to access the website; or "Province A" can be used to count the number of devices located in Province A in the business traffic data, that is, for a certain website, how many devices located in Province A access the website.

[0038] Each device model in the device type indicator can be used to count at least one of the traffic data such as the number of access requests, the number of users, and the number of devices using the corresponding device model to access a website in the business traffic data. For example, assuming that the device models in the device type indicator include "model b", "model b" can be used to count the number of access requests using model b devices to access a website in the business traffic data, that is, for the website, the total number of access requests corresponding to the device model b; or, "model b" can be used to count the number of users using model b devices to access a website in the business traffic data, that is, the total number of users using model b devices to access the website; or, "model b" can be used to count the number of devices using model b devices to access a website in the business traffic data, that is, the total number of model b devices accessing the website.

[0039] Each specific IPC segment of the IPC segment indicator can be used to count at least one of the traffic data such as the number of access requests, the number of users, and the number of devices whose IP addresses of devices accessing a certain website are within the corresponding IPC segment in the business traffic data. For example, assuming that each specific IPC segment of the IPC segment indicator includes a certain IPC segment, the IPC segment can be used to count the number of access requests whose IP addresses of devices accessing a certain website are within the IPC segment in the business traffic data, that is, for the website, the total number of devices whose IP addresses corresponding to the access requests are within the IPC segment; or, the IPC segment can be used to count the number of users whose IP addresses of devices accessing a certain website are within the IPC segment in the business traffic data, that is, the total number of users who use devices with IP addresses within the IPC segment to access the website; or, the IPC segment can be used to count the number of devices whose IP addresses of devices accessing a certain website are within the IPC segment in the business traffic data, that is, the total number of devices whose IP addresses of devices accessing the website are within the IPC segment.

[0040] Each JA3 fingerprint of a JA3 indicator can be used to count at least one of the traffic data, such as the number of access requests, the number of users, and the number of devices, that access a website using a browser having the corresponding JA3 fingerprint. For example, assuming that each JA3 fingerprint of a JA3 indicator includes a certain JA3 fingerprint, the JA3 fingerprint can be used to count the number of access requests to a website using a browser having the JA3 fingerprint, i.e., the total number of access requests corresponding to the browser having the JA3 fingerprint; or, the JA3 fingerprint can be used to count the number of users accessing a website using a browser having the JA3 fingerprint, i.e., the total number of users accessing the website using a browser having the JA3 fingerprint; or, the JA3 fingerprint can be used to count the number of devices accessing a website using a browser having the JA3 fingerprint, i.e., the total number of devices accessing the website using a browser having the JA3 fingerprint.

[0041] Each browser type and version number in the browser type indicator can be used to count at least one of the traffic data, such as the number of access requests, the number of users, and the number of devices, that access a website using a browser with the corresponding browser type and version number in the business traffic data. For example, assuming that each browser type and version number in the browser type indicator includes "C-type browser version 2.0," the "C-type browser version 2.0" can be used to count the number of access requests to a website using the C-type browser version 2.0 in the business traffic data, i.e., how many access requests to the website correspond to browsers with the C-type browser version 2.0; or, the "C-type browser version 2.0" can be used to count the number of users that access a website using the C-type browser version 2.0 in the business traffic data, i.e., how many users use the C-type browser version 2.0 to access the website; or, the "C-type browser version 2.0" can be used to count the number of devices that access a website using the C-type browser version 2.0 in the business traffic data, i.e., how many devices use the C-type browser version 2.0 to access the website.

[0042] Step 103: Aggregate the business traffic data based on multiple dimension values ​​and multiple indicator values ​​to obtain traffic distribution data of each dimension value under multiple indicator values.

[0043] In an embodiment of the present disclosure, a data engine may be used to aggregate business traffic data based on multiple dimension values ​​and multiple indicator values ​​to obtain traffic distribution data for each dimension value under multiple indicator values.

[0044] Among them, the traffic distribution data of a certain dimension value under multiple indicator values ​​can represent the distribution characteristics of business traffic data under the dimension value and the multiple indicator values, and may include at least one of the data such as the number of access requests, the number of users, and the number of devices under each indicator value for the dimension value. For example, when the dimension value is the time dimension and the statistical indicator is the regional indicator, the traffic distribution data of a certain dimension value under each indicator value represents the distribution characteristics of business traffic data in each region within a certain time period, and may include at least one of the data such as the number of access requests, the number of users, and the number of devices in each region within the time period. Or, for example, when the dimension value is the user dimension and the statistical indicator is the IPC segment indicator, the traffic distribution data of a certain dimension value under each indicator value represents the distribution characteristics of business traffic data corresponding to a certain user identifier in each IPC segment, and may include the number of access requests of the user corresponding to the user identifier to access a website using devices with IP addresses in each IPC segment. Alternatively, for example, when the dimension is an IPC dimension and the statistical indicator is a time series indicator, the traffic distribution data for a certain dimension value under each indicator value represents the distribution characteristics of the service traffic data of a certain IPC segment in each time period, and may include, for example, the number of access requests to a certain website by devices whose IP addresses fall within the IPC segment in each time period. Aggregating service traffic data based on a certain dimension value and an indicator value can yield at least one of the following data: the number of access requests, the number of users, the number of devices, etc., for the dimension value under the indicator value.

[0045] Furthermore, it is understood that the traffic distribution data for each dimension value under multiple indicator values ​​can be specifically in the form of a feature matrix. Where M represents the number of dimension values ​​for the detection dimension, and N represents the number of indicator values ​​for the statistical indicator, the dimension of the feature matrix can be M*N. That is, each row of the feature matrix corresponds to a dimension value, and each column corresponds to an indicator value. Each element in the feature matrix represents the dimension corresponding to the row, and data such as the number of access requests, users, or devices under the indicator value corresponding to the column.

[0046] For example, let's take traffic distribution data specifically representing the number of devices. Assume the detection dimension is time, and its multiple dimension values ​​include three time periods: "January 3," "January 2," and "January 1." The statistical indicator is a region, and its multiple indicator values ​​include "Province A," "Province B," and "Province C." Aggregating business traffic data based on the time period "January 3," "Province A," "Province B," and "Province C" yields traffic distribution data for the three indicator values ​​of "Province A," "Province B," and "Province C" for the time period "January 3." This traffic distribution data includes the number of devices in Province A, Province B, and Province C that accessed website X on January 3. Among them, the number of devices located in Province A among the devices that visited a certain website X on January 3 can be obtained by aggregating the business traffic data based on the time period of "January 3" and "Province A". The number of devices located in Province B among the devices that visited a certain website X on January 3 can be obtained by aggregating the business traffic data based on the time period of "January 3" and "Province B". The number of devices located in Province C among the devices that visited a certain website X on January 3 can be obtained by aggregating the business traffic data based on the time period of "January 3" and "Province C". Similarly, by aggregating the business traffic data based on the time period of "January 2nd", "Province A", "Province B" and "Province C", we can obtain the traffic distribution data for the time period of "January 2nd" under the three indicator values ​​of "Province A", "Province B" and "Province C", where the traffic distribution data includes the number of devices located in Province A, the number of devices located in Province B and the number of devices located in Province C among the devices that visited a certain website X on January 2nd; by aggregating the business traffic data based on the time period of "January 1st", "Province A", "Province B" and "Province C", we can obtain the traffic distribution data for the time period of "January 1st" under the three indicator values ​​of "Province A", "Province B" and "Province C", where the traffic distribution data includes the number of devices located in Province A, the number of devices located in Province B and the number of devices located in Province C among the devices that visited a certain website X on January 1st.

[0047] The traffic distribution data for the time period of "January 1st" under the three indicator values ​​of "Province A," "Province B," and "Province C," the traffic distribution data for the time period of "January 2nd" under the three indicator values ​​of "Province A," "Province B," and "Province C," and the traffic distribution data for the time period of "January 3rd" under the three indicator values ​​of "Province A," "Province B," and "Province C" can be specifically in the form of a feature matrix with a dimension of 3*3. The first row corresponds to the time period of "January 1st," the second row corresponds to the time period of "January 2nd," and the third row corresponds to the time period of "January 3rd." The first column corresponds to the indicator value of "Province A," the second column corresponds to the indicator value of "Province B," and the third column corresponds to the indicator value of "Province C." Taking the first row as an example, the first row represents the traffic distribution data in Province A, Province B, and Province C on January 1. The elements in the first column of the first row represent the number of devices located in Province A among the devices that visited website X on January 1, the elements in the second column of the first row represent the number of devices located in Province B among the devices that visited website X on January 1, and the elements in the third column of the first row represent the number of devices located in Province C among the devices that visited website X on January 1.

[0048] It should be noted that, in the embodiment of the present disclosure, when the business traffic data is aggregated based on each dimension value and multiple indicator values, the arrangement order of the multiple indicator values ​​can be the same. For example, in the above example, after obtaining the number of devices located in Province A, the number of devices located in Province B, and the number of devices located in Province C among the devices that visited a certain website X on January 3, Province A, Province B, and Province C can be arranged in order from small to large according to the corresponding number of devices, such as the arrangement order is Province B, Province C, and Province A, and then according to the same arrangement order, the number of devices located in Province B, the number of devices located in Province C, and the number of devices located in Province A among the devices that visited a certain website X on January 2 are counted, and the number of devices located in Province B, the number of devices located in Province C, and the number of devices located in Province A among the devices that visited a certain website X on January 1 are counted, thereby obtaining the traffic distribution data of each time period under multiple indicator values ​​of the same arrangement order, and then executing the subsequent steps based on the traffic distribution data of each time period under multiple indicator values ​​of the same arrangement order.

[0049] Step 104: Determine the correlation between the traffic distribution data of each dimension value under multiple indicator values, and determine the target business traffic data in the business traffic data based on the correlation.

[0050] The target business flow data is the business flow data to be determined from the business flow data to be detected. The target business flow data can be determined based on the needs of a specific application scenario. For example, in the embodiment of the present disclosure, the target business flow data can be business flow data with abnormalities.

[0051] Among them, similarity determination methods such as Pearson correlation coefficient and cosine distance can be used to determine the correlation between traffic distribution data of each dimension value under multiple indicator values, and this disclosure does not limit this.

[0052] In an embodiment of the present disclosure, when the traffic distribution data of each dimensional value under multiple index values ​​is specifically in the form of a feature matrix, the correlation between the row vectors corresponding to every two dimensional values ​​in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data of every two dimensional values ​​under multiple index values.

[0053] Furthermore, based on the correlation between the traffic distribution data for each dimension value under multiple indicator values, target traffic distribution data whose correlation with other traffic distribution data satisfies set conditions can be determined from the traffic distribution data for each dimension value under multiple indicator values, and target business traffic data in the business traffic data can be determined based on the target traffic distribution data. The set conditions can be set according to the application scenario, and this disclosure does not impose any restrictions on this.

[0054] For example, assuming the detection dimension is a time dimension, the multiple dimension values ​​of the time dimension include multiple dates, and the statistical indicator is a regional indicator, the multiple indicator values ​​of the regional indicator include multiple regions. For a website, the distribution of business traffic data in various regions on different dates is generally stable, that is, the number of access requests, users, and devices in each region on different dates is generally stable. For example, on the same day and within the previous three days, the number of devices accessing a website in Province A is generally greater than the number of devices in Province B. Based on multiple dates and multiple regions, the business traffic data is aggregated to obtain traffic distribution data for each date in multiple regions. The correlation between traffic distribution data in multiple regions on each date is generally high. Traffic distribution data with low correlation with traffic distribution data in multiple regions on other dates may be abnormal traffic data caused by machine crawlers or other reasons. Therefore, a set condition can be set to ensure that the correlation between the target traffic distribution data and other traffic distribution data is low. Therefore, in the disclosed embodiments, abnormal target business traffic data can be determined based on traffic distribution data with low correlation with traffic distribution data in multiple regions on other dates.

[0055] It should be noted that the detection dimensions and statistical indicators shown in the embodiments of the present disclosure are only exemplary illustrations and cannot be understood as limitations on the present technical solution. In actual applications, those skilled in the art can arbitrarily set the detection dimensions and statistical indicators in the scenario according to the application scenario, as long as the traffic distribution data of any dimension value under multiple indicator values ​​has practical significance, and the present disclosure does not impose any restrictions on this. For example, when the detection dimension is the time dimension and the statistical indicator is the regional indicator, the traffic distribution data of any dimension value under multiple indicator values ​​represents the distribution characteristics of the business traffic data in each area within a certain time period. Or, for example, when the dimension value is the user dimension and the statistical indicator is the IPC segment indicator, the traffic distribution data of any dimension value under each indicator value represents the distribution characteristics of the business traffic data corresponding to a certain user identifier in each IPC segment. Or, for example, when the dimension is the IPC dimension and the statistical indicator is the time series indicator, the traffic distribution data of any dimension value under each indicator value represents the distribution characteristics of the business traffic data of a certain IPC segment in each time period, etc.

[0056] Because the traffic detection method provided by the embodiments of the present disclosure can set corresponding detection dimensions and statistical indicators according to different application scenarios, it can determine target business traffic data from business traffic data based on the corresponding detection dimensions and statistical indicators for various application scenarios, thus having a wide range of applications. In addition, the traffic detection method provided by the embodiments of the present disclosure is simple to implement and has low complexity, thereby enabling rapid detection of abnormal target business traffic data from business traffic data.

[0057] In summary, the traffic detection method provided by the embodiment of the present disclosure obtains the business traffic data to be detected, the corresponding detection dimensions and statistical indicators; determines multiple dimension values ​​of the detection dimensions and determines multiple index values ​​of the statistical indicators; aggregates the business traffic data based on the multiple dimension values ​​and the multiple index values ​​to obtain the traffic distribution data of each dimension value under the multiple index values; determines the correlation between the traffic distribution data of each dimension value under the multiple index values, and determines the target business traffic data in the business traffic data based on the correlation. In this way, it is possible to detect abnormal target business traffic data from the business traffic data to be detected, and the method has strong versatility, low complexity and high traffic detection efficiency.

[0058] The flow detection method provided by the embodiment of the present disclosure can be applied to the scenario where the flow data of a certain time period in the business flow data of different time periods is abnormal, and the target business flow data can be determined from the business flow data of different time periods. In this scenario, the detection dimension is the time dimension, and the multiple dimension values ​​of the detection dimension are multiple time periods. Figure 2 , the implementation process of the flow detection method provided by the embodiment of the present disclosure in the above scenario is explained.

[0059] Figure 2 FIG. 1 is a flow chart of a flow detection method according to the second embodiment of the present disclosure. Figure 2 As shown, the flow detection method may include the following steps:

[0060] Step 201: Obtain the business traffic data to be detected, the corresponding detection dimensions and statistical indicators, wherein the detection dimensions include the time dimension.

[0061] Step 202: determine multiple dimension values ​​of the time dimension and determine multiple indicator values ​​of the statistical indicator, wherein the multiple dimension values ​​include multiple time periods to which the business traffic data belongs.

[0062] Among them, the time units of the multiple time periods to which the business traffic data belongs can be preset, such as set to days, weeks, etc., and the present disclosure does not impose any restrictions on this.

[0063] In an embodiment of the present disclosure, multiple time periods of the time dimension can be determined based on the multiple time periods to which the business traffic data to be detected belongs. For example, assuming that the time unit of the multiple time periods to which the business traffic data belongs is day, and the business traffic data to be detected is business traffic data from January 1 to January 3, then the multiple time periods of the time dimension can be determined to include the three time periods of "January 1," "January 2," and "January 3."

[0064] Among them, statistical indicators can be set based on the traffic distribution characteristics of business traffic data under multiple dimensional values ​​in specific application scenarios.

[0065] For example, taking the detection dimension as the time dimension, for a certain website, the distribution of business traffic data in various regions on different dates is usually stable, that is, the number of access requests, users and devices in various regions on different dates is usually stable. For example, on the same day and within the previous three days, the number of devices in Province A accessing a certain website is greater than the number of devices in Province B. In this case, the statistical indicator can be set as a regional indicator.

[0066] Alternatively, taking the detection dimension as the time dimension as an example, for a certain website, the distribution of business traffic data for each device type on different dates is usually stable, that is, the number of access requests, the number of users, and the number of devices using each device model to access a website on different dates are usually stable. For example, the number of devices using each device type to access a website on the same day is not much different from the number of devices using each device type to access the website in the previous three days. In this case, the statistical indicator can be set as the device type indicator.

[0067] In an embodiment of the present disclosure, for statistical indicators that can quickly enumerate corresponding indicator values, multiple preset indicator values ​​of the statistical indicator can be pre-set based on the multiple enumerated indicator values, and then the flow detection device can determine the multiple preset indicator values ​​of the statistical indicator as multiple indicator values ​​of the statistical indicator. For example, for regional indicators, the corresponding areas can be quickly enumerated, so that the flow detection device can determine the multiple enumerated areas as multiple indicator values ​​of the regional indicator. Or for example, for time series indicators, the corresponding time periods can be quickly enumerated, such as dividing a day into multiple time periods of 1 minute, 10 minutes or 20 minutes, so that the flow detection device can determine the multiple enumerated time periods as multiple indicator values ​​of the time series indicator.

[0068] In the embodiments of the present disclosure, for statistical indicators whose corresponding index values ​​are relatively dispersed, such as the device type index, there are too many device types that can be exhaustively enumerated, and some of them are infrequently used device types with few users. For such statistical indicators, multiple preset index values ​​of the statistical indicator can be pre-set based on the multiple index values ​​that are exhaustively enumerated. Then, the flow detection device can determine the multiple index values ​​of the statistical indicator in the following manner:

[0069] Based on multiple preset indicator values ​​of the statistical indicator, the service traffic data is aggregated to obtain traffic distribution data under the multiple preset indicator values; based on the traffic distribution data and service traffic data under each preset indicator value, the traffic coverage corresponding to each preset indicator value is determined; and the multiple preset indicator values ​​whose corresponding traffic coverage is higher than a fourth preset threshold are determined as the multiple indicator values ​​of the statistical indicator. The fourth preset threshold can be set as needed, for example, to 90%, 95%, etc., and this disclosure does not limit this.

[0070] For example, taking the device type indicator as an example, the long tail of each device type can be removed to obtain multiple preset device types. Therefore, the traffic detection device can aggregate the business traffic data based on the multiple preset device types corresponding to the device type indicator to obtain the number of access requests under the multiple preset device types, that is, the number of access requests using devices of each preset device type to access a website. Then, based on the number of access requests using devices of each preset device type to access a website and the total number of access requests to the website in the business traffic data, the traffic coverage rate corresponding to each preset device type is determined, and the multiple preset device types with corresponding traffic coverage rates greater than 95% are determined as the multiple indicator values ​​of the device type indicator.

[0071] Therefore, for statistical indicators with relatively scattered corresponding indicator values, the traffic coverage rate corresponding to each preset indicator can be determined, and then based on the traffic coverage rate corresponding to each preset indicator value, a smaller number of indicator values ​​can be obtained, thereby reducing the amount of calculation in the traffic detection process, and by determining the preset indicator values ​​with higher corresponding traffic coverage rates as multiple indicator values ​​of the statistical indicator, the accuracy of traffic detection can be improved.

[0072] Step 203 : Aggregate the service traffic data based on multiple time periods and multiple indicator values ​​to obtain traffic distribution data for each time period under multiple indicator values.

[0073] For example, let's take traffic distribution data specifically representing the number of devices. Assume the detection dimension is time, and its multiple dimension values ​​include three time periods: "January 3," "January 2," and "January 1." The statistical indicator is a region, and its multiple indicator values ​​include "Province A," "Province B," and "Province C." Aggregating business traffic data based on the time period "January 3," "Province A," "Province B," and "Province C" yields traffic distribution data for the three indicator values ​​of "Province A," "Province B," and "Province C" for the time period "January 3." This traffic distribution data includes the number of devices in Province A, Province B, and Province C that accessed website X on January 3. Similarly, by aggregating the business traffic data based on the time period of "January 2nd", "Province A", "Province B" and "Province C", we can obtain the traffic distribution data for the time period of "January 2nd" under the three indicator values ​​of "Province A", "Province B" and "Province C", where the traffic distribution data includes the number of devices located in Province A, the number of devices located in Province B and the number of devices located in Province C among the devices that visited a certain website X on January 2nd; by aggregating the business traffic data based on the time period of "January 1st", "Province A", "Province B" and "Province C", we can obtain the traffic distribution data for the time period of "January 1st" under the three indicator values ​​of "Province A", "Province B" and "Province C", where the traffic distribution data includes the number of devices located in Province A, the number of devices located in Province B and the number of devices located in Province C among the devices that visited a certain website X on January 1st.

[0074] As a result, in the scenario where there is anomaly in the traffic data of a certain time period among the business traffic data of different time periods, the business traffic data is aggregated based on multiple time periods of the time dimension and multiple indicator values ​​of the statistical indicators, and the traffic distribution data of each time period under the multiple indicator values ​​of the statistical indicators is obtained, laying the foundation for determining the target business traffic data from the business traffic data in this scenario.

[0075] Step 204: Determine the correlation between the traffic distribution data of any two time periods in the multiple time periods under multiple indicator values.

[0076] In the embodiment of the present disclosure, the flow distribution data of any one of the multiple time periods under multiple index values ​​is represented in the form of a feature vector. The similarity determination method of the Pearson correlation coefficient shown in the following formula (1) can be used to determine the correlation between the flow distribution data of any two time periods under multiple index values ​​in the multiple time periods:

[0077]

[0078] Where X and Y represent the characteristic vectors corresponding to the traffic distribution data under multiple index values ​​in any time period. X,Y Represents the correlation coefficient between X and Y. E represents the mathematical expectation or mean, E(XY)-E(X)E(Y) represents the covariance of X and Y, represents the standard deviation of X, represents the standard deviation of Y. X,Y It is a number between -1 and +1, where 0 means there is no correlation between X and Y, a negative value means a negative correlation, and a positive value means a positive correlation.

[0079] Step 205 : Determine target flow distribution data whose correlation with other flow distribution data is lower than a first preset threshold from the flow distribution data under multiple indicator values ​​in each time period.

[0080] The first preset threshold value can be set as needed, and the present disclosure does not impose any restrictions on this.

[0081] Step 206: Determine target service flow data in the service flow data based on the target flow distribution data.

[0082] In an embodiment of the present disclosure, based on the correlation between traffic distribution data under multiple indicator values ​​for each time period, target traffic distribution data whose correlation with other traffic distribution data satisfies a set condition can be determined from the traffic distribution data under multiple indicator values ​​for each time period, and then target business traffic data in the business traffic data can be determined based on the target traffic distribution data. The set condition can be set according to the application scenario, and this disclosure does not impose any restrictions on this.

[0083] Taking the time unit of multiple time periods in the time dimension as an example, since for a certain website, the distribution of business traffic data under each indicator value of the same statistical indicator on different days is generally stable, where statistical indicators such as regional indicators and device type indicators are generally stable. For example, the number of access requests, the number of users, and the number of devices in different regions on different days are generally stable, and the number of access requests, the number of users, and the number of devices accessing a website using different device models on different days are generally stable. Based on multiple time periods and multiple indicator values, the business traffic data is aggregated to obtain traffic distribution data under multiple indicator values ​​for each time period. The correlation between the traffic distribution data under multiple indicator values ​​for each time period is generally high. Traffic distribution data with low correlation with traffic distribution data under multiple indicator values ​​for other time periods may be abnormal traffic data caused by machine crawlers or other reasons. Therefore, a set condition can be set such that the correlation between the target traffic distribution data and other traffic distribution data is lower than a first preset threshold. Therefore, the traffic detection device in the embodiment of the present disclosure can determine traffic distribution data with a correlation of the first preset threshold with traffic distribution data in multiple regions for other time periods as target traffic distribution data, and then determine whether there is abnormal target business traffic data based on the target traffic distribution data.

[0084] In an embodiment of the present disclosure, the number of statistical indicators corresponding to the business traffic data to be detected can be multiple. In this case, for the same statistical indicator among the multiple statistical indicators, the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​of the same statistical indicator can be determined, and then based on the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​of the same statistical indicator, the target business traffic data in the business traffic data can be determined.

[0085] Accordingly, step 204 can be implemented in the following manner: for the same statistical indicator among multiple statistical indicators, determine the correlation between the traffic distribution data under multiple indicator values ​​of the same statistical indicator in each time period, and step 205 can be implemented in the following manner: from the traffic distribution data under multiple indicator values ​​of the same statistical indicator in each time period, determine the target traffic distribution data whose correlation with other traffic distribution data is lower than a first preset threshold.

[0086] By setting the number of statistical indicators corresponding to the business traffic data to be detected to multiple, and then aggregating the business traffic data based on multiple dimension values ​​and multiple indicator values ​​of multiple statistical indicators, the traffic distribution data of each dimension value under multiple indicator values ​​of each statistical indicator is obtained, and then based on the correlation between the traffic distribution data of each dimension value under multiple indicator values ​​of each same statistical indicator, the target business traffic data in the business traffic data is determined. It is possible to determine the target business traffic data in the business traffic data from multiple angles, thereby improving the accuracy of traffic detection.

[0087] For example, assuming that it is known that the total number of visits to a website increased significantly on January 4, 2022, the business traffic data to be tested can be the business traffic data from January 1 to January 4. The time unit of the multiple time periods to which the business traffic data belongs is day, and the statistical indicators include regional indicators, browser type indicators, and JA3 indicators. Among them, the regional indicators include 34 regions, the browser type indicators include 21 browser types, and the JA3 indicators include 20 JA3 fingerprints. Based on the four time periods of "January 1st", "January 2nd", "January 3rd" and "January 4th" and the regions of the regional indicators, after aggregating the business traffic data, a 4*34-dimensional feature matrix can be obtained. Taking the first row as an example, the first row represents the traffic distribution data of the time period of "January 1st" in 34 regions, where the traffic distribution data may include the number of access requests located in each region in the access requests on January 1st; based on the four time periods of "January 1st", "January 2nd", "January 3rd" and "January 4th" and the browser type indicators of each browser type, a 4*21-dimensional feature matrix can be obtained. Taking the first row as an example, the first row represents the traffic distribution data of the 34 regions in the time period of "January 1st", where the traffic distribution data may include the number of access requests located in each region in the access requests on January 1st; based on the four time periods of "January 1st", "January 2nd", "January 3rd" and "January 4th" and the browser type indicators of each browser type, a 4*21-dimensional feature matrix can be obtained. One row represents the traffic distribution data for 21 browser types during the time period of "January 1st", where the traffic distribution data may include the number of access requests corresponding to each browser type in the access requests within January 1st; based on the four time periods of "January 1st", "January 2nd", "January 3rd" and "January 4th" and the JA3 fingerprints of the JA3 indicators, after aggregating the business traffic data, a 4*20-dimensional feature matrix can be obtained. Taking the first row as an example, the first row represents the traffic distribution data for 20 JA3 fingerprints during the time period of "January 1st", where the traffic distribution data may include the number of access requests corresponding to each JA3 fingerprint in the access requests within January 1st.

[0088] Furthermore, for the 4*34-dimensional feature matrix, the correlation between the row vectors corresponding to each two time periods in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data for each of the 34 regions of the regional indicator for each of the two time periods. For the 4*21-dimensional feature matrix, the correlation between the row vectors corresponding to each two time periods in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data for each of the 21 browser types of the browser type indicator for each of the two time periods. For the 4*20-dimensional feature matrix, the correlation between the row vectors corresponding to each two time periods in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data for each of the 20 JA3 fingerprints of the JA3 indicator for each of the two time periods.

[0089] Assuming the correlation between the traffic distribution data for the 34 regions of the regional indicator for the January 4th period and other time periods is below a first preset threshold, it can be determined that the traffic distribution data for the 34 regions of the regional indicator on January 4th is abnormal and identified as target service traffic data. Based on this target service traffic data, the region of the abnormal traffic data within the service traffic data accessing the network on January 4th can be located. This data can then be used to identify the characteristics of this abnormal traffic data for subsequent anti-fraud measures.

[0090] Therefore, the traffic detection method provided by the embodiment of the present disclosure determines the correlation between the traffic distribution data of any two time periods in multiple time periods under multiple indicator values, and determines the target traffic distribution data whose correlation with other traffic distribution data is lower than the first preset threshold from the traffic distribution data of each time period under multiple indicator values, and then determines the target business traffic data in the business traffic data based on the target traffic distribution data, so as to realize the determination of the target business traffic data from the business traffic data in the scenario where there is an anomaly in the traffic data of a certain time period in the business traffic data of different time periods, and the implementation method is simple, the complexity is low, and the traffic detection efficiency is high.

[0091] The traffic detection method provided by the embodiment of the present disclosure can be applied to the scenario where there is traffic data of cheating by abnormal user groups in the business traffic data, and the target business traffic data can be determined from the business traffic data. In this scenario, the detection dimension can be a dimension that contains more users under the corresponding dimension, such as user dimension, IP dimension, IPC dimension, JA3 dimension and other dimensions. The following takes the detection dimension as the user dimension and the multiple dimension values ​​of the detection dimension as multiple user identifiers as an example, combined with Figure 3 , the implementation process of the flow detection method provided by the embodiment of the present disclosure in the above scenario is explained.

[0092] Figure 3FIG. 1 is a flow chart of a flow detection method according to the third embodiment of the present disclosure. Figure 3 As shown, the flow detection method may include the following steps:

[0093] Step 301: Obtain the business traffic data to be detected, the corresponding detection dimensions and statistical indicators, wherein the detection dimensions include the user dimension.

[0094] Step 302: Determine multiple dimension values ​​of the user dimension and multiple index values ​​of the statistical index. The multiple dimension values ​​include multiple candidate user identifiers that meet preset conditions among the multiple user identifiers included in the business traffic data.

[0095] The preset condition can be set as needed, such as setting the number of access requests within a certain time period to exceed a set threshold, where the set threshold can be set to 1000, 2000, etc., and this disclosure does not impose any restrictions on this.

[0096] Taking the preset condition that the number of access requests exceeds 1,000 in one day as an example, the user identifications with more than 1,000 access requests in one day among the multiple user identifications included in the business traffic data can be determined as candidate user identifications, thereby determining multiple dimension values ​​of the user dimension.

[0097] Among them, statistical indicators can be set based on the traffic distribution characteristics of business traffic data under multiple dimensional values ​​in specific application scenarios.

[0098] For example, taking the user dimension as the detection dimension, since for a certain website, the distribution of access requests of each user in the cheating gang across each IP address in the IP pool is usually consistent, that is, the number of times different users in the cheating gang use each IP address in the IP pool to access a certain website is basically the same, the statistical indicator can be set as the IPC segment indicator.

[0099] Alternatively, taking the user dimension as an example of detection dimension, since for a certain website, the distribution of access requests of each user in the cheating gang on each access interface is usually consistent, that is, the number of visits to each access interface by different users in the cheating gang is basically the same, the statistical indicator can be set as the access interface indicator, and the multiple indicator values ​​of this indicator include the identifiers of each access interface.

[0100] Alternatively, taking the user dimension as an example, for a certain website, the distribution of access requests of each user in the cheating gang in each time period is usually consistent, that is, the time periods in which different users in the cheating gang visit the website are basically consistent, then the statistical indicator can be set as a time series indicator, and the multiple indicator values ​​of this indicator include each time period.

[0101] The method of determining multiple indicator values ​​of the statistical indicator can refer to the description of the above embodiment and will not be repeated here.

[0102] Step 303: Aggregate the service traffic data based on the multiple candidate user identifiers and the multiple index values ​​to obtain traffic distribution data of each candidate user identifier under the multiple index values.

[0103] For example, taking the distribution of traffic distribution data specifically as the distribution of the number of access requests as an example, assuming that the detection dimension is the user dimension, the multiple dimension values ​​of the user dimension include 1,000 candidate user identifiers, the statistical indicator is the IPC segment indicator, and the multiple indicator values ​​of the IPC segment indicator include 27 IPC segments. Based on a certain candidate user identifier and 27 IPC segments, the business traffic data is aggregated, and the traffic distribution data of the candidate user identifier in the 27 IPC segments can be obtained, wherein the traffic distribution data represents the distribution characteristics of the business traffic data corresponding to the candidate user identifier in the 27 IPC segments, and the traffic distribution data can include the number of access requests from the user corresponding to the candidate user identifier to access the website using a device with an IP address in each IPC segment. Similarly, based on any other candidate user identifier and 27 IPC segments, the business traffic data is aggregated, and the traffic distribution data of any other candidate user identifier in the 27 IPC segments can be obtained.

[0104] As a result, in the scenario where there is traffic data of cheating by abnormal user groups in the business traffic data, the business traffic data is aggregated based on multiple candidate user identifiers in the user dimension and multiple indicator values ​​of the statistical indicators, and the traffic distribution data of each candidate user identifier under the multiple indicator values ​​of the statistical indicators is obtained, laying the foundation for determining the target business traffic data from the business traffic data in this scenario.

[0105] Step 304: Determine the correlation between the traffic distribution data of any two candidate user identifiers among the multiple candidate user identifiers under multiple indicator values.

[0106] In an embodiment of the present disclosure, the traffic distribution data of any one of the multiple candidate user identifiers under multiple index values ​​is represented in the form of a feature vector, and the similarity determination method of the Pearson correlation coefficient can be used to determine the correlation between the traffic distribution data of any two of the multiple candidate user identifiers under multiple index values.

[0107] Step 305 : determining a user identification set from a plurality of candidate user identifications based on the correlation between the traffic distribution data of any two candidate user identifications under a plurality of indicator values.

[0108] The correlation between the traffic distribution data of any user identifier in the user identifier set and other user identifiers except the any user identifier under multiple indicator values ​​is higher than a second preset threshold.

[0109] The second preset threshold can be set as needed, and this disclosure does not impose any restrictions on this.

[0110] Step 306: Determine target service flow data in the service flow data based on the user identification set.

[0111] In an embodiment of the present disclosure, a user ID set can be determined from each candidate user ID based on the correlation between the traffic distribution data of each candidate user ID under multiple indicator values. The correlation between the traffic distribution data of any user ID in the user ID set and other user IDs other than the user ID under multiple indicator values ​​satisfies a set condition. Target service traffic data in the service traffic data can then be determined based on the user ID set. The set condition can be set based on the application scenario and is not limited in this disclosure.

[0112] It is understandable that for a particular website, the distribution of users within a cheating group under various indicator values ​​of the same statistical indicator is generally consistent, where the statistical indicators include, for example, the IPC segment indicator, the access interface indicator, the timing indicator, etc. For example, the time periods during which different users within the cheating group access the website are generally consistent, the distribution of access requests from users within the cheating group across various access interfaces is generally consistent, and the distribution of access requests from users within the cheating group across various IP addresses within the IP pool is generally consistent. Based on multiple candidate user identifiers and multiple indicator values ​​of the statistical indicator, traffic flow data is aggregated to obtain traffic flow distribution data for each candidate user identifier under multiple indicator values. The correlation between traffic flow distribution data for each candidate user identifier belonging to the same cheating group under multiple indicator values ​​is generally high. Therefore, a set condition can be set such that the correlation between any user identifier in the user identifier set and any other user identifier in the user identifier set other than the arbitrary user identifier is greater than a second preset threshold. Therefore, the traffic detection device in the embodiment of the present disclosure can determine a user identification set from multiple candidate user identifications based on the set conditions, and then determine the target business traffic data of cheating by abnormal user groups in the business traffic data based on the user identification set.

[0113] In an embodiment of the present disclosure, the number of statistical indicators corresponding to the business traffic data to be detected can be multiple. In this case, for the same statistical indicator among the multiple statistical indicators, the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​of the same statistical indicator can be determined, and then based on the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​of the same statistical indicator, the target business traffic data in the business traffic data can be determined.

[0114] Accordingly, step 304 can be implemented in the following manner: for the same statistical indicator among multiple statistical indicators, determine the correlation between the traffic distribution data of each candidate user identifier under multiple indicator values ​​of the same statistical indicator, and step 305 can be implemented in the following manner: based on the correlation between the traffic distribution data of any two candidate user identifiers under multiple indicator values ​​of the same statistical indicator, determine a user identifier set from multiple candidate user identifiers.

[0115] For example, assume the traffic data to be tested is all-day traffic data for a particular day. Among the multiple user IDs included in the traffic data, there are 10,000 user IDs with more than 1,000 access requests on that day. This means the multiple dimension values ​​for the user dimension include 10,000 candidate user IDs. The statistical metrics include IPC segment metrics, access interface metrics, and time series metrics. The deduplicated IPC segment metrics include 27 IPC segments, the access interface metrics include 10 access interface IDs, and the time series metrics include 24*60=1440 time periods. Based on the 10,000 candidate user identifiers and the IPC segments of the IPC segment indicators, after aggregating the business traffic data, a 10,000*27-dimensional feature matrix can be obtained, where the first row is taken as an example, the first row represents the traffic distribution data of the first candidate user identifier in the 27 IPC segments, and the 27 elements in the first row represent the number of access requests made by the user corresponding to the candidate user identifier to access the website using the devices in each of the 27 IPC segments; based on the 10,000 candidate user identifiers and the access interface identifiers of the access interface indicators, a 10,000*10-dimensional feature matrix can be obtained, where the first row is taken as an example, the first The rows represent the traffic distribution data of the first candidate user ID in the 10 access interface IDs. The 10 elements in the first row represent the number of access requests made by the user corresponding to the candidate user ID to each of the 10 access interfaces. Based on the 10,000 candidate user IDs and the time periods of the timing indicators, after aggregating the business traffic data, a 10,000*1,440-dimensional feature matrix can be obtained. Taking the first row as an example, the first row represents the traffic distribution data of the first candidate user ID in 1,440 time periods. The 1,440 elements in the first row represent the number of access requests made by the user corresponding to the candidate user ID to the website in each of the 1,440 time periods.

[0116] Furthermore, for the 10000*27-dimensional feature matrix, the correlation between the row vectors corresponding to each two candidate user identifiers in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data of each two candidate user identifiers under the 27 IPC segments of the IPC segment indicator. For the 10000*10-dimensional feature matrix, the correlation between the row vectors corresponding to each two candidate user identifiers in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data of each two candidate user identifiers under the 10 access interface identifiers of the access interface indicator. For the 10000*1440-dimensional feature matrix, the correlation between the row vectors corresponding to each two candidate user identifiers in the feature matrix can be determined, thereby obtaining the correlation between the traffic distribution data of each two candidate user identifiers under the 1440 time periods of the timing indicator.

[0117] Assume that among 10,000 candidate user IDs, there are 100 candidate user IDs that meet the following condition: the correlation between the traffic distribution data of every two user IDs in the 27 IPC segments of the IPC segment indicator is greater than a second preset threshold. Then, these 100 candidate user IDs can be combined into a user ID set, and the access data corresponding to each user ID in the user ID set can be determined as the target service traffic data. Based on this target service traffic data, the characteristics of the corresponding cheating group can be discovered, which can be used for subsequent anti-cheating processing.

[0118] Therefore, the traffic detection method provided by the embodiment of the present disclosure determines the correlation between the traffic distribution data of any two candidate user identifiers among multiple candidate user identifiers under multiple indicator values, determines a user identifier set from multiple candidate user identifiers based on the correlation between the traffic distribution data of any two candidate user identifiers under multiple indicator values, and determines the target business traffic data in the business traffic data based on the user identifier set. This realizes the determination of target business traffic data from business traffic data in a scenario where there is traffic data of cheating by abnormal user groups in the business traffic data, and the implementation method is simple, the complexity is low, and the traffic detection efficiency is high.

[0119] The traffic detection method provided by the embodiment of the present disclosure can be applied to traffic data of cheating by abnormal user groups in the business traffic data, and in the scenario where one or more cheating users are known, to determine the target business traffic data from the business traffic data. In this scenario, the detection dimension can be a user dimension, an IP dimension, an IPC dimension, a JA3 dimension, and other dimensions. In the following, the detection dimension is taken as the user dimension, and the multiple dimension values ​​of the detection dimension include a specified user identifier, such as the identifier of a known cheating user, and multiple other user identifiers as an example, combined with Figure 4 , the implementation process of the flow detection method provided by the embodiment of the present disclosure in the above scenario is explained.

[0120] Figure 4 FIG. 4 is a flow chart of a flow detection method according to the fourth embodiment of the present disclosure. Figure 4 As shown, the flow detection method may include the following steps:

[0121] Step 401: Obtain the business traffic data to be detected, the corresponding detection dimensions and statistical indicators, wherein the detection dimensions include the user dimension.

[0122] Step 402, determining multiple dimension values ​​of the user dimension and multiple indicator values ​​of the statistical indicator, the multiple dimension values ​​including multiple candidate user identifiers and designated user identifiers that meet preset conditions among the multiple user identifiers included in the business traffic data.

[0123] Step 403 : Based on the multiple candidate user identifiers and the multiple index values, the service flow data is aggregated to obtain flow distribution data of each candidate user identifier under the multiple index values.

[0124] Step 404 : Aggregate the service traffic data based on the designated user identifier and multiple indicator values ​​to obtain traffic distribution data of the designated user identifier under the multiple indicator values.

[0125] Step 405 : Determine the correlation between the traffic distribution data of the designated user identifier and the plurality of candidate user identifiers under the plurality of index values.

[0126] The specific implementation process and principles of steps 401-405 can be referred to the description of the above embodiment and will not be repeated here.

[0127] Among them, step 404 and step 405 can be executed simultaneously or sequentially, and this disclosure does not limit this.

[0128] Step 406: Determine a target user identifier from the multiple candidate user identifiers, where the correlation between the target user identifier and the traffic distribution data of the designated user identifier under multiple indicator values ​​is higher than a third preset threshold.

[0129] The third preset threshold value can be set as needed, and the present disclosure does not impose any restrictions on this.

[0130] Step 407: Determine target service flow data in the service flow data based on the target user identifier.

[0131] It is understandable that for a particular website, the distribution of each user in a cheating group under various indicator values ​​of the same statistical indicator is generally consistent. Statistical indicators such as IPC segment indicators, access interface indicators, and timing indicators are examples. For example, the time periods during which different users in a cheating group visit the website are generally consistent, the distribution of access requests from each user in the cheating group across various access interfaces is generally consistent, and the distribution of access requests from each user in the cheating group across various IP addresses in the IP pool is generally consistent. By aggregating traffic flow data based on multiple candidate user identifiers and multiple indicator values ​​of the statistical indicator to obtain traffic distribution data for each candidate user identifier under multiple indicator values, and by aggregating traffic flow data based on a specified user identifier and multiple indicator values ​​to obtain traffic distribution data for the specified user identifier under multiple indicator values, the correlation between the traffic distribution data for the specified user identifier and each user identifier belonging to the same cheating group under multiple indicator values ​​is generally high. Then, a user identifier whose correlation with the traffic distribution data of the specified user identifier under multiple indicator values ​​is higher than the third preset threshold can be determined as a target user identifier belonging to the same cheating group as the specified user identifier, and then the access data corresponding to the target user identifier is determined as the target business traffic data.

[0132] Therefore, the traffic detection method provided by the embodiment of the present disclosure determines the target user identifier from multiple candidate user identifiers by determining the correlation between the traffic distribution data of the designated user identifier and multiple candidate user identifiers under multiple indicator values. The correlation between the target user identifier and the traffic distribution data of the designated user identifier under multiple indicator values ​​is higher than the third preset threshold value. Then, based on the target user identifier, the target business traffic data in the business traffic data is determined. This realizes the determination of the target business traffic data from the business traffic data in a scenario where there is traffic data of cheating by abnormal user groups in the business traffic data and the cheating users are known. The implementation method is simple, the complexity is low, and the traffic detection efficiency is high.

[0133] It should be noted that the traffic detection method provided by the embodiment of the present disclosure is applied to the scenario where there is traffic data of cheating by abnormal user groups in the business traffic data. When determining the target business traffic data from the business traffic data, when the detection dimension is IP dimension, IPC dimension, JA3 dimension or other dimensions, the process of determining the target business traffic data from the business traffic data is similar to the process of determining the target business traffic data from the business traffic data when the detection dimension is user dimension. A brief explanation is given below, and the specific implementation process will not be repeated in detail.

[0134] For example, when the detection dimension is the IPC dimension, since for a certain website, the access requests corresponding to the IPC segments of various devices belonging to the same cheating group are usually distributed consistently in different time periods, that is, the time periods in which devices with IP addresses in different IPC segments in the cheating group visit the website are basically consistent, the statistical indicator can be set as a time series indicator.

[0135] After obtaining the business traffic data to be detected, the corresponding detection dimension and the statistical indicators, the traffic detection device can determine multiple IPC segments of the IPC dimension, such as the multiple IPC segments including the IPC segments whose number of access requests in a day exceeds the set threshold value among the multiple IPC segments included in the business traffic data, and determine multiple indicator values ​​of the time series indicator, such as dividing a day into 144 time periods by 10 minutes, and using the 144 time periods as multiple indicator values. Then, based on the multiple IPC segments and the multiple indicator values, the business traffic data can be aggregated to obtain the traffic distribution data of each IPC segment under the multiple indicator values. Among them, in the case where the statistical indicator is a time series indicator and the multiple indicator values ​​include multiple time periods, the traffic distribution data of a certain IPC segment under the multiple indicator values ​​represents the distribution characteristics of the business traffic data corresponding to the IPC segment in each time period, and may include the number of access requests of the device corresponding to the IPC segment to access the website in each time period.

[0136] Furthermore, the traffic detection device can determine the correlation between traffic distribution data for any two of the multiple IPC segments under multiple index values, and based on the correlation between the traffic distribution data for any two of the multiple IPC segments under multiple index values, determine an IPC segment set from the multiple IPC segments. The correlation between the traffic distribution data for any IPC segment in the IPC segment set and other IPC segments other than the arbitrary IPC segment under multiple index values ​​is greater than a preset threshold. Furthermore, based on the IPC segment set, target service traffic data can be determined from the service traffic data.

[0137] As a result, it is possible to determine target business traffic data from business traffic data in a scenario where there is traffic data of cheating by abnormal user groups in the business traffic data, and the implementation method is simple, the complexity is low, and the traffic detection efficiency is high.

[0138] It should be noted that the above application scenarios are only exemplary and cannot be understood as limiting the application scenarios of the present technical solution. In actual applications, those skilled in the art can also apply the traffic detection method provided by the embodiment of the present disclosure in other scenarios as needed, such as in scenarios such as black intelligence library generation, white intelligence library generation, and online misjudgment recall. The present disclosure does not limit the application scenarios of the traffic detection method. Taking the online misjudgment recall scenario as an example, the detection dimensions can be set as user dimensions, IP dimensions, IPC dimensions, JA3 dimensions, etc., the statistical indicators are time series indicators, and the traffic distribution data of a dimension value in multiple time periods of the time series indicator is given, and then the business traffic data to be detected is aggregated based on the multiple dimension values ​​of the detection dimension and the multiple time periods of the statistical indicator to obtain the traffic distribution data of each dimension value in multiple time periods, and then determine the correlation between each dimension value and the traffic distribution data of the given dimension value in multiple time periods, and determine the target dimension value from the multiple dimension values, wherein the correlation between the target dimension value and the traffic distribution data of the given dimension value in multiple time periods is high, and then determine the target business traffic data in the business traffic data based on the target dimension value. The specific implementation process will not be repeated in the embodiments of this disclosure.

[0139] The following combination Figure 5 , the flow detection device provided by the present invention is described.

[0140] Figure 5 2 is a schematic structural diagram of a flow detection device according to the fifth embodiment of the present disclosure.

[0141] like Figure 5 As shown, the flow detection device 500 provided by the present disclosure includes: an acquisition module 501, a first determination module 502, an aggregation module 503 and a second determination module 504.

[0142] The acquisition module 501 is used to obtain the service flow data to be detected, the corresponding detection dimensions and statistical indicators;

[0143] A first determining module 502 is configured to determine multiple dimension values ​​of a detection dimension and multiple indicator values ​​of a statistical indicator;

[0144] Aggregation module 503, configured to aggregate service traffic data based on multiple dimension values ​​and multiple index values ​​to obtain traffic distribution data of each dimension value under multiple index values;

[0145] The second determination module 504 is used to determine the correlation between the traffic distribution data of each dimension value under multiple indicator values, and determine the target business traffic data in the business traffic data based on the correlation.

[0146] It should be noted that the flow detection device 500 provided in this embodiment can execute the flow detection method of the aforementioned embodiment. The flow detection device 500 can be implemented by software and / or hardware and can be configured in an electronic device, which may include but is not limited to a terminal device, a server, etc. This embodiment does not specifically limit the electronic device.

[0147] It should be noted that the above description of the embodiment of the flow detection method is also applicable to the flow detection device provided in the present disclosure and will not be repeated here.

[0148] The flow detection device provided by the embodiment of the present disclosure obtains the business flow data to be detected, the corresponding detection dimension and the statistical index; determines multiple dimension values ​​of the detection dimension and determines multiple index values ​​of the statistical index; aggregates the business flow data based on the multiple dimension values ​​and the multiple index values ​​to obtain the flow distribution data of each dimension value under the multiple index values; determines the correlation between the flow distribution data of each dimension value under the multiple index values, and determines the target business flow data in the business flow data based on the correlation. In this way, it is possible to detect the target business flow data with abnormalities from the business flow data to be detected, and the method has strong versatility, low complexity and high detection efficiency.

[0149] The following combination Figure 6 , the flow detection device provided by the present disclosure is further explained.

[0150] Figure 6 2 is a schematic structural diagram of a flow detection device according to the sixth embodiment of the present disclosure.

[0151] like Figure 6 As shown, the flow detection device 600 provided by the present disclosure includes: an acquisition module 601, a first determination module 602, an aggregation module 603 and a second determination module 604. Figure 6 The acquisition module 601, the first determination module 602, the aggregation module 603 and the second determination module 604 are Figure 5 The acquisition module 501, the first determination module 502, the aggregation module 503 and the second determination module 504 have the same function and structure.

[0152] In the implementation of the present disclosure, the detection dimension includes a time dimension, multiple dimension values, including multiple time periods to which the business traffic data belongs; the aggregation module 603 includes:

[0153] The first aggregation unit 6031 is used to aggregate the service traffic data based on multiple time periods and multiple indicator values ​​to obtain traffic distribution data of each time period under multiple indicator values.

[0154] In the implementation of the present disclosure, the second determining module 604 includes:

[0155] The first determining unit 6041 is configured to determine the correlation between the traffic distribution data of any two time periods in the multiple time periods under multiple indicator values;

[0156] The second determining unit 6042 is configured to determine, from the traffic distribution data under the multiple indicator values ​​in each time period, target traffic distribution data whose correlation with other traffic distribution data is lower than a first preset threshold;

[0157] The third determining unit 6043 is configured to determine target service flow data in the service flow data based on the target flow distribution data.

[0158] In the implementation of the present disclosure, the detection dimension includes a user dimension, multiple dimension values, including multiple candidate user identifiers that meet preset conditions among multiple user identifiers included in the business traffic data; the aggregation module 603 includes:

[0159] The second aggregation unit is used to aggregate the service flow data based on multiple candidate user identifiers and multiple indicator values ​​to obtain flow distribution data of each candidate user identifier under the multiple indicator values.

[0160] In the implementation of the present disclosure, the second determining module 604 includes:

[0161] a fourth determining unit, configured to determine a correlation between traffic distribution data of any two candidate user identifiers among the plurality of candidate user identifiers under a plurality of indicator values;

[0162] a fifth determining unit, configured to determine a user identifier set from the plurality of candidate user identifiers based on a correlation between traffic distribution data of any two candidate user identifiers under a plurality of indicator values, wherein a correlation between traffic distribution data of any user identifier in the user identifier set and other user identifiers other than the any user identifier under the plurality of indicator values ​​is greater than a second preset threshold;

[0163] The sixth determining unit is configured to determine target service flow data in the service flow data based on the user identification set.

[0164] In the implementation of the present disclosure, the multiple dimension values ​​also include a specified user identifier; the aggregation module 603 also includes:

[0165] a third aggregation unit, configured to aggregate the service flow data based on the designated user identifier and the multiple indicator values, and obtain flow distribution data of the designated user identifier under the multiple indicator values;

[0166] The second determination module includes:

[0167] a seventh determining unit, configured to determine a correlation between the designated user identifier and the traffic distribution data of the plurality of candidate user identifiers under a plurality of indicator values;

[0168] An eighth determining unit is configured to determine a target user identifier from a plurality of candidate user identifiers, wherein a correlation between traffic distribution data of the target user identifier and a designated user identifier under a plurality of indicator values ​​is higher than a third preset threshold;

[0169] The ninth determining unit is configured to determine target service flow data in the service flow data based on the target user identifier.

[0170] In the implementation of the present disclosure, the first determining module 602 includes:

[0171] a fourth aggregation unit, configured to aggregate the service flow data based on a plurality of preset indicator values ​​of the statistical indicator to obtain flow distribution data under the plurality of preset indicator values;

[0172] An acquiring unit, configured to acquire the flow coverage corresponding to each preset indicator value based on the flow distribution data and the service flow data under each preset indicator value;

[0173] The tenth determining unit is configured to determine a plurality of preset indicator values ​​whose corresponding traffic coverage ratios are higher than a fourth preset threshold as a plurality of indicator values ​​of the statistical indicator.

[0174] In the implementation of the present disclosure, the number of statistical indicators is multiple;

[0175] The second determining module 604 includes:

[0176] an eleventh determining unit, configured to determine, for a same statistical indicator among the multiple statistical indicators, a correlation between traffic distribution data of each dimension value under multiple indicator values ​​of the same statistical indicator;

[0177] The twelfth determination unit is used to determine the target business traffic data in the business traffic data based on the correlation between the traffic distribution data of each dimension value under multiple indicator values ​​of each same statistical indicator.

[0178] It should be noted that the above description of the embodiment of the flow detection method is also applicable to the flow detection device provided in the present disclosure and will not be repeated here.

[0179] The flow detection device provided by the embodiment of the present disclosure obtains the business flow data to be detected, the corresponding detection dimension and the statistical index; determines multiple dimension values ​​of the detection dimension and determines multiple index values ​​of the statistical index; aggregates the business flow data based on the multiple dimension values ​​and the multiple index values ​​to obtain the flow distribution data of each dimension value under the multiple index values; determines the correlation between the flow distribution data of each dimension value under the multiple index values, and determines the target business flow data in the business flow data based on the correlation. In this way, it is possible to detect the target business flow data with abnormalities from the business flow data to be detected, and the method has strong versatility, low complexity and high detection efficiency.

[0180] Based on the above embodiments, the present disclosure also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the flow detection method of the present disclosure.

[0181] Based on the above embodiments, the present disclosure further provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable the computer to execute the flow detection method disclosed in the embodiments of the present disclosure.

[0182] Based on the above embodiments, the present disclosure further provides a computer program product, including a computer program, which implements the steps of the flow detection method of the present disclosure when executed by a processor.

[0183] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0184] Figure 7 A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0185] like Figure 7As shown, the electronic device 700 may include a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the device 700 may also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0186] Various components in device 700 are connected to I / O interface 705, including an input unit 706, such as a keyboard, mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a magnetic disk, optical disk, etc.; and a communication unit 709, such as a network card, modem, wireless communication transceiver, etc. The communication unit 709 allows device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0187] The computing unit 701 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as the flow detection method. For example, in some embodiments, the flow detection method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the flow detection method described above can be performed. Alternatively, in other embodiments, the computing unit 701 can be configured to perform the flow detection method by any other appropriate means (e.g., by means of firmware).

[0188] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0189] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0190] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0191] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0192] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), the Internet, and a blockchain network.

[0193] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. The client-server relationship is established by computer programs running on the respective computers and establishing a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, a host product within the cloud computing service ecosystem that addresses the management difficulties and poor scalability of traditional physical hosts and VPS services ("Virtual Private Servers" or simply "VPS"). The server may be a cloud server, a server in a distributed system, or a server integrated with blockchain.

[0194] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.

[0195] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A flow detection method, wherein: The method comprises: Obtain the business traffic data to be tested, the corresponding detection dimensions and statistical indicators; Determining multiple dimension values ​​of the detection dimension and determining multiple indicator values ​​of the statistical indicator; Based on the multiple dimension values ​​and the multiple index values, the business traffic data is aggregated to obtain traffic distribution data of each dimension value under the multiple index values, wherein the traffic distribution data is in the form of a feature matrix, each row of the feature matrix corresponds to a dimension value, and each column of the feature matrix corresponds to an index value; Determining the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determining the target business traffic data in the business traffic data based on the correlation; Determining the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​includes: Determine the correlation between row vectors corresponding to every two dimension values ​​in the feature matrix, and obtain the correlation between the traffic distribution data of each dimension value under the multiple indicator values; There are multiple statistical indicators; The determining of the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determining the target service traffic data in the service traffic data based on the correlation, further includes: For a same statistical indicator among the plurality of statistical indicators, determining the correlation between the traffic distribution data of each dimension value under the plurality of indicator values ​​of the same statistical indicator; Based on the correlation between the traffic distribution data of each dimension value under multiple indicator values ​​of the same statistical indicator, the target business traffic data in the business traffic data is determined.

2. The method according to claim 1, wherein The detection dimension includes a time dimension, and the multiple dimension values ​​include multiple time periods to which the business traffic data belongs; The aggregating the service traffic data based on the multiple dimension values ​​and the multiple indicator values ​​to obtain traffic distribution data of each dimension value under the multiple indicator values ​​includes: Based on the multiple time periods and the multiple indicator values, the business traffic data is aggregated to obtain traffic distribution data for each of the time periods under the multiple indicator values.

3. The method according to claim 2, wherein: The determining of the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determining the target service traffic data in the service traffic data based on the correlation, includes: Determine the correlation between the traffic distribution data of any two time periods in the multiple time periods under the multiple indicator values; Determining, from the flow distribution data under the multiple indicator values ​​in each of the time periods, target flow distribution data whose correlation with other flow distribution data is lower than a first preset threshold; Based on the target traffic distribution data, target service traffic data in the service traffic data is determined.

4. The method according to claim 1, wherein The detection dimension includes a user dimension, and the multiple dimension values ​​include multiple candidate user identifiers that meet preset conditions among the multiple user identifiers included in the service traffic data; The aggregating the service traffic data based on the multiple dimension values ​​and the multiple indicator values ​​to obtain traffic distribution data of each dimension value under the multiple indicator values ​​includes: Based on the multiple candidate user identifiers and the multiple index values, the service traffic data is aggregated to obtain traffic distribution data of each candidate user identifier under the multiple index values.

5. The method according to claim 4, wherein The determining of the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determining the target service traffic data in the service traffic data based on the correlation, includes: Determining a correlation between traffic distribution data of any two candidate user identifiers among the multiple candidate user identifiers under the multiple indicator values; Determining a user identification set from the multiple candidate user identifications based on a correlation between the traffic distribution data of the arbitrary two candidate user identifications under the multiple indicator values, wherein a correlation between any user identification in the user identification set and the traffic distribution data of other user identifications other than the arbitrary user identifications under the multiple indicator values ​​is higher than a second preset threshold; Based on the user identification set, target service flow data in the service flow data is determined.

6. The method according to claim 4, wherein: The plurality of dimension values ​​further include a specified user identifier; the method further includes: Aggregating the service traffic data based on the designated user identifier and the multiple indicator values ​​to obtain traffic distribution data of the designated user identifier under the multiple indicator values; The determining of the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determining the target service traffic data in the service traffic data based on the correlation, includes: Determining a correlation between the designated user identifier and the traffic distribution data of the plurality of candidate user identifiers under the plurality of indicator values; Determine a target user identifier from the multiple candidate user identifiers, where a correlation between the target user identifier and the traffic distribution data of the designated user identifier under the multiple indicator values ​​is higher than a third preset threshold; Based on the target user identifier, target service flow data in the service flow data is determined.

7. The method according to any one of claims 1 to 6, wherein Determining the multiple indicator values ​​of the statistical indicators includes: Aggregating the service traffic data based on multiple preset indicator values ​​of the statistical indicator to obtain traffic distribution data under the multiple preset indicator values; Determining the traffic coverage corresponding to each of the preset indicator values ​​based on the traffic distribution data under each of the preset indicator values ​​and the service traffic data; A plurality of preset indicator values ​​whose corresponding traffic coverage rates are higher than a fourth preset threshold are determined as the plurality of indicator values ​​of the statistical indicator.

8. A flow detection device, wherein: The device comprises: The acquisition module is used to obtain the business traffic data to be tested, the corresponding detection dimensions and statistical indicators; A first determining module, configured to determine multiple dimension values ​​of the detection dimension and multiple indicator values ​​of the statistical indicator; an aggregation module, configured to aggregate the service traffic data based on the multiple dimension values ​​and the multiple indicator values ​​to obtain traffic distribution data for each dimension value under the multiple indicator values, wherein the traffic distribution data is in the form of a feature matrix, each row of the feature matrix corresponds to a dimension value, and each column of the feature matrix corresponds to an indicator value; The second determination module is configured to determine the correlation between the traffic distribution data of each dimension value under the multiple indicator values, and determine the target business traffic data in the business traffic data based on the correlation; the determining the correlation between the traffic distribution data of each dimension value under the multiple indicator values ​​includes: Determine the correlation between row vectors corresponding to every two dimension values ​​in the feature matrix, and obtain the correlation between the traffic distribution data of each dimension value under the multiple indicator values; There are multiple statistical indicators; The second determining module includes: an eleventh determining unit, configured to determine, for a same statistical indicator among the plurality of statistical indicators, a correlation between the traffic distribution data of each dimension value under the plurality of indicator values ​​of the same statistical indicator; The twelfth determination unit is used to determine the target business traffic data in the business traffic data based on the correlation between the traffic distribution data of each dimension value under multiple indicator values ​​of the same statistical indicator.

9. The device according to claim 8, wherein The detection dimension includes a time dimension, and the multiple dimension values ​​include multiple time periods to which the business traffic data belongs; The aggregation module includes: The first aggregation unit is used to aggregate the business traffic data based on the multiple time periods and the multiple indicator values ​​to obtain traffic distribution data for each of the time periods under the multiple indicator values.

10. The device according to claim 9, wherein The second determining module includes: A first determining unit is configured to determine a correlation between the traffic distribution data of any two time periods in the multiple time periods under the multiple indicator values; a second determining unit, configured to determine, from the traffic distribution data under the multiple indicator values ​​in each of the time periods, target traffic distribution data whose correlation with other traffic distribution data is lower than a first preset threshold; The third determining unit is configured to determine target service flow data in the service flow data based on the target flow distribution data.

11. The device according to claim 8, wherein The detection dimension includes a user dimension, and the multiple dimension values ​​include multiple candidate user identifiers that meet preset conditions among the multiple user identifiers included in the service traffic data; The aggregation module includes: The second aggregation unit is used to aggregate the service traffic data based on the multiple candidate user identifiers and the multiple indicator values ​​to obtain traffic distribution data of each candidate user identifier under the multiple indicator values.

12. The device according to claim 11, wherein The second determining module includes: A fourth determining unit, configured to determine a correlation between the traffic distribution data of any two candidate user identifiers among the plurality of candidate user identifiers under the plurality of indicator values; a fifth determining unit, configured to determine a user identification set from the multiple candidate user identifications based on a correlation between the traffic distribution data of the any two candidate user identifications under the multiple indicator values, wherein a correlation between any user identification in the user identification set and the traffic distribution data of other user identifications other than the any user identification under the multiple indicator values ​​is higher than a second preset threshold; A sixth determining unit is configured to determine target service flow data in the service flow data based on the user identification set.

13. The device according to claim 11, wherein The multiple dimension values ​​also include a specified user identifier; the aggregation module further includes: a third aggregation unit, configured to aggregate the service flow data based on the designated user identifier and the multiple indicator values ​​to obtain flow distribution data of the designated user identifier under the multiple indicator values; The second determining module includes: a seventh determining unit, configured to determine a correlation between the designated user identifier and the traffic distribution data of the plurality of candidate user identifiers under the plurality of indicator values; An eighth determining unit is configured to determine a target user identifier from the multiple candidate user identifiers, wherein a correlation between the target user identifier and the traffic distribution data of the designated user identifier under the multiple indicator values ​​is higher than a third preset threshold; A ninth determining unit is configured to determine target service flow data in the service flow data based on the target user identifier.

14. The device according to any one of claims 8 to 13, wherein: The first determining module includes: a fourth aggregation unit, configured to aggregate the service flow data based on a plurality of preset indicator values ​​of the statistical indicator to obtain flow distribution data under the plurality of preset indicator values; An acquiring unit, configured to acquire the flow coverage corresponding to each of the preset indicator values ​​based on the flow distribution data under each of the preset indicator values ​​and the service flow data; The tenth determining unit is configured to determine a plurality of preset indicator values ​​whose corresponding traffic coverage ratios are higher than a fourth preset threshold as the plurality of indicator values ​​of the statistical indicator.

15. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.

16. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are configured to cause the computer to execute the method according to any one of claims 1 to 7.

17. A computer program product comprising a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Detection method, device and terminal for cheating traffic

    CN106355431A