Abnormal user analysis system based on big data

Through multi-dimensional analysis of game user behavior characteristics, and using machine learning and deep learning models to evaluate abnormal situations, the accuracy of abnormal user identification under dynamic changes in the existing technology is solved, effective management of the game environment and in-depth analysis of user behavior are achieved, and the game experience is improved.

CN120324913AActive Publication Date: 2025-07-18HANGZHOU KAIKAI NETWORK TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510488869.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-18
Estimated Expiration
2045-04-18

AI Technical Summary

Technical Problem

The existing abnormal user analysis system based on big data cannot adapt to the dynamic changes in the game environment and user behavior, resulting in a decrease in the accuracy of abnormal user identification and lack of in-depth exploration of user behavior patterns and internal logic.

Method used

By obtaining the behavioral characteristic data of the game platform users, multi-dimensional division and collection, calculate the deviation between user behavior and normal behavior, combine machine learning and deep learning models to evaluate user abnormalities, and determine whether the user is in an abnormal state.

Benefits of technology

It realizes timely identification and handling of abnormal users, maintains the fairness and normal order of the game, enhances player trust and satisfaction, and ensures the health of the game environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120324913A_ABST
    Figure CN120324913A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal user analysis system based on big data, and relates to the technical field of big data, and the technical scheme is characterized in that the system comprises a division module which is used for obtaining behavior characteristic data of game platform users, and performing category division on the game platform users according to the abnormal degree of the behavior characteristic data to obtain a user category division result set; collecting behavior data of a second type of users in the user type division result set according to different monitoring dimensions to obtain a first behavior data set, a second behavior data set and a third behavior data set; extracting abnormal deviation degrees between the user behaviors of the second type of users in different monitoring dimensions and the normal behaviors to obtain a first risk data set, a second risk data set and a third risk data set respectively; the method has the effect that fairness and normal order of the game are guaranteed by effectively identifying and processing the abnormal users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data technology, and more specifically, to an abnormal user analysis system based on big data. Background Art

[0002] In today's digital age, the game industry has developed vigorously, and the number of users on game platforms has shown an explosive growth. With the continuous expansion of the player group, game platforms are facing a series of management and operation challenges, among which the identification and handling of abnormal user behaviors have become key issues to be solved urgently.

[0003] With the rise of big data technology, some game platforms have begun to try to use data statistical analysis to identify abnormal users. However, existing abnormal user analysis systems based on big data often only focus on the surface data of user behaviors, such as the number of logins, consumption amounts, etc., lacking in-depth exploration of user behavior patterns and internal logics. Moreover, these analyses are mostly static analyses and cannot adapt to the dynamic changes of the game environment and user behaviors. For example, during game promotion activities, user recharge behaviors and game durations may change, but traditional static analysis methods cannot adjust the judgment criteria in a timely manner, resulting in a decrease in the accuracy of abnormal user identification. Summary of the Invention

[0004] Aiming at the deficiencies of the existing technology, the purpose of the present invention is to provide an abnormal user analysis system based on big data.

[0005] To achieve the above purpose, the present invention provides the following technical solutions: An abnormal user analysis system based on big data, including: A classification module: obtaining the behavior characteristic data of users on the game platform, and classifying the users on the game platform according to the degree of abnormality of the behavior characteristic data to obtain a user classification result set; An acquisition module: collecting the behavior data of the second type of users in the user classification result set according to different monitoring dimensions to obtain a first behavior data set, a second behavior data set, and a third behavior data set; An extraction module: extracting the abnormal deviation degrees of the user behaviors of the second type of users in different monitoring dimensions from the normal behaviors respectively to obtain a first risk data set, a second risk data set, and a third risk data set; An evaluation module: evaluating the abnormal situations of the second type of users in the user classification result set according to the first behavior data set, the second behavior data set, the third behavior data set, the first risk data set, the second risk data set, and the third risk data set to obtain a first to-be-processed evaluation result set, a second to-be-processed evaluation result set, and a third to-be-processed evaluation result set; Judgment module: Determine whether the second - type users in the user category division result set are in an abnormal state according to the first to - be - processed evaluation result set, the second to - be - processed evaluation result set, and the third to - be - processed evaluation result set.

[0006] Preferably, the behavioral characteristic data of the game platform users includes the login time pattern, game duration, game operation frequency, recharge amount, and recharge frequency of the game platform users.

[0007] Preferably, the game platform users are classified into a user category division result set according to the degree of abnormality of the behavioral characteristic data, which specifically includes the following steps: Set corresponding normal range thresholds according to different behavioral characteristic data; Classify users whose all behavioral characteristic data are within the normal range thresholds as the first - type users; Classify users whose part of the behavioral characteristic data are within the normal range thresholds as the second - type users; Classify users whose all behavioral characteristic data are not within the normal range thresholds as the third - type users; Among them, the first - type users, the second - type users, and the third - type users form the user category division result set.

[0008] Preferably, the acquisition module specifically includes the following steps: Set the first monitoring and acquisition dimension, the second monitoring and acquisition dimension, and the third monitoring and acquisition dimension for the data monitoring and acquisition of the second - type users; Collect the game social behavior and item usage situation of the second - type users according to the first monitoring and acquisition dimension to obtain the first behavior data set, collect the game battle results and matching opponent situation of the second - type users according to the second monitoring and acquisition dimension to obtain the second behavior data set, and collect the login situation and IP address change situation of the second - type users according to the third monitoring and acquisition dimension to obtain the third behavior data set.

[0009] Preferably, the acquisition module specifically includes the following steps: Calculate the deviation degree between the user behavior of the second - type users and the normal behavior under the first monitoring and acquisition dimension, the second monitoring and acquisition dimension, and the third monitoring and acquisition dimension respectively to obtain the first deviation degree data set, the second deviation degree data set, and the third deviation degree data set; Predict the user abnormal behavior risk of the second - type users according to the first deviation degree data set to obtain the first risk data set; Predict the user abnormal behavior risk of the second - type users according to the second deviation degree data set to obtain the second risk data set; Extract the abnormal deviation degree situation between each user behavior in the third monitoring and acquisition dimension and the normal behavior to obtain the third risk data set.

[0010] Preferably, the evaluation module specifically includes the following steps: Evaluate the abnormal conditions of the second type of users in the user category division result set according to the first risk data set and the first behavior data set to obtain a first to-be-processed evaluation result set; Evaluate the abnormal conditions of the second type of users in the user category division result set according to the second risk data set and the second behavior data set to obtain a second to-be-processed evaluation result set; Perform processing and evaluation according to the first behavior data set, the second behavior data set, the third deviation data set, and the third behavior data set to obtain a third to-be-processed evaluation result set.

[0011] Preferably, performing processing and evaluation according to the first behavior data set, the second behavior data set, the third deviation data set, and the third behavior data set to obtain a third to-be-processed evaluation result set specifically includes the following steps: Collect a first time data set and a second time data set of the key nodes of the normal operation behavior mode of the second type of users based on the first behavior data set and the second behavior data set; Collect a third time data set of the key nodes of the operation behavior information set of the second type of users based on the third behavior data set; Calculate the difference in the time to reach the key nodes for the first time data set, the second time data set, and the third time data set to obtain a time difference data set; Judge the internal behavior abnormal behavior risk of the second type of users based on the time difference data set and the third deviation data set to obtain a third risk data set; Evaluate the abnormal conditions of the second type of users in the user category division result set based on the third risk data set and the third behavior data set to obtain a third to-be-processed evaluation result set.

[0012] Preferably, the judgment module specifically includes the following steps: Perform a difference operation on the data in the first to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain a first verification difference set; Perform a difference operation on the data in the second to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain a second verification difference set; Perform a difference operation on the data in the third to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain a third verification difference set; Calculate the average value of the first verification difference set, the second verification difference set, and the third verification difference set to obtain a verification average difference; Compare the verification average difference with a preset verification threshold to judge whether the second type of users in the user category division result set are in an abnormal state.

[0013] Preferably, compare the verification average difference with a preset verification threshold to determine whether the second type of users in the user category division result set is in an abnormal state, which specifically includes the following steps: If the verification average difference is less than or equal to the preset verification threshold, the second type of users in the user category division result set is in a normal state; If the verification average difference is greater than the preset verification threshold, the second type of users in the user category division result set is in an abnormal state.

[0014] Compared with the prior art, the present invention has the following beneficial effects: This application uses user behavior characteristic data in multiple aspects such as login time pattern, game duration, game operation frequency, recharge amount, and recharge frequency. The comprehensive use of such multi-dimensional data avoids the one-sidedness of judging abnormalities based on only one or a few dimensions. Calculate the deviation degree of user behavior from normal behavior under different monitoring dimensions, and predict the risk of abnormal behavior accordingly. Through the analysis of data such as game battle results and matching opponents, it can be timely discovered whether players have cheating behaviors such as using external programs or exploiting game loopholes. If such abnormal users are found, the operator can timely take measures such as banning accounts and restricting game functions, effectively maintaining the fair competition environment of the game, ensuring that the majority of players can play games in a fair environment, enhancing players' trust and satisfaction with the game. By effectively identifying and handling abnormal users, the system guarantees the fairness and normal order of the game, creating a healthy game ecological environment for players. In such an environment, players can be more focused on the game itself, enjoy the game fun, and improve the game experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a module schematic diagram of an abnormal user analysis system based on big data proposed by the present invention; Figure 2 It is a step schematic diagram of an acquisition module in an abnormal user analysis system based on big data proposed by the present invention; Figure 3 It is a step schematic diagram of an evaluation module in an abnormal user analysis system based on big data proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Refer to Figures 1 to 3 as shown

[0017] The embodiments are used to further illustrate the abnormal user analysis system based on big data proposed by the present invention.

[0018] The abnormal user analysis system based on big data includes: A division module: Obtain the behavior characteristic data of game platform users, and classify the game platform users according to the abnormal degree of the behavior characteristic data to obtain a user category division result set; Collection module: Collect the behavior data of the second type of users in the user category division result set according to different monitoring dimensions to obtain the first behavior data set, the second behavior data set, and the third behavior data set; Obtaining module: Extract the abnormal deviation degrees of the user behaviors of the second type of users in different monitoring dimensions from the normal behaviors to obtain the first risk data set, the second risk data set, and the third risk data set; Evaluation module: Evaluate the abnormal conditions of the second type of users in the user category division result set according to the first behavior data set, the second behavior data set, the third behavior data set, the first risk data set, the second risk data set, and the third risk data set to obtain the first to-be-processed evaluation result set, the second to-be-processed evaluation result set, and the third to-be-processed evaluation result set; Judgment module: Judge whether the second type of users in the user category division result set are in an abnormal state according to the first to-be-processed evaluation result set, the second to-be-processed evaluation result set, and the third to-be-processed evaluation result set.

[0019] The game platform of this application obtains the behavior characteristic data of users in real time through methods such as background log records, covering login time rules, game duration, game operation frequency, recharge amount, and recharge frequency, etc.

[0020] Users with all behavior characteristic data within the normal range threshold are classified as the first type of users, that is, normal users. For example, for the above-mentioned player A, all data meet the set threshold range and can be classified as the first type of users. Users with some behavior characteristic data within the normal range threshold are classified as the second type of users, that is, suspected abnormal users. For example, for player C, the login time and game duration are normal, but the recharge amount has exceeded 1000 yuan continuously for three months, far exceeding the normal range threshold, and other operation frequency and other data are normal. Then player C belongs to the second type of users. Users with all behavior characteristic data not within the normal range threshold are classified as the third type of users, that is, abnormal users. For example, for player D, the login time is chaotic, the game duration is extremely short or extremely long, the operation frequency is extremely low, and the recharge amount and frequency both seriously exceed the normal range, and can be classified as the third type of users. These three types of users form the user category division result set.

[0021] For the data monitoring and collection of the second type of users, set the first monitoring and collection dimension (game social behavior and item usage situation), the second monitoring and collection dimension (game battle results and matching opponent situation), and the third monitoring and collection dimension (login situation and IP address change situation).

[0022] Calculate the deviation degree of the user behavior of the second type of users from the normal behavior under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension respectively. For example, under the first monitoring and collection dimension, by comparing data such as the average friend - adding frequency and chat times of normal users, calculate the friend - adding frequency deviation degree and chat - times deviation degree of player E, etc., to obtain the first deviation - degree data set; similarly, under the second monitoring and collection dimension, calculate the win - rate deviation degree and matched - opponent level deviation degree of player F, etc., to obtain the second deviation - degree data set; under the third monitoring and collection dimension, calculate the login - device replacement frequency deviation degree and IP - address change deviation degree of player G, etc., to obtain the third deviation - degree data set.

[0023] Predict the user abnormal - behavior risk of the second type of users based on the first deviation - degree data set to obtain the first risk data set. For example, based on the first deviation - degree data set of player E, predict the risk probability of using cheats or participating in game - cheating social behaviors. Similarly, predict the abnormal - behavior risk of player F based on the second deviation - degree data set to obtain the second risk data set, and extract the abnormal - deviation degree situation of each user behavior of player G from the normal behavior based on the third deviation - degree data set to obtain the third risk data set.

[0024] Evaluate the abnormal situation of the second type of users in the user - category division result set according to the first risk data set and the first behavior data set to obtain the first to - be - processed evaluation result set. For example, for player E, based on the predicted cheating - social - behavior risk probability in its first risk data set, combined with the specific social behaviors and item - using situations in the first behavior data set, perform weighted scoring to obtain the evaluation result of its abnormal situation in game social interaction and item use.

[0025] Evaluate the abnormal situation of the second type of users according to the second risk data set and the second behavior data set to obtain the second to - be - processed evaluation result set. For example, player F is evaluated and scored based on the abnormal battle - risk probability in its second risk data set, combined with the battle results and matched - opponent situations in the second behavior data set, to obtain the evaluation result of its abnormal situation in game battles.

[0026] Collect the first time data set and the second time data set of the key nodes of the normal operation behavior patterns of the second type of users based on the first behavior data set and the second behavior data set. For example, the time points when player E uses certain key items, the key time points when player F wins in battles, etc.

[0027] Collect the third time data set of the key nodes of the operation - behavior information set of the second - type users based on the third behavior data set, such as the time point when player G replaces the login device.

[0028] Evaluate the abnormal situation of the second type of users in the user - category division result set according to the third risk data set and the third behavior data set to obtain the third to - be - processed evaluation result set.

[0029] The data in the first evaluation result set to be processed is subtracted from the corresponding data in the standard evaluation set to obtain the first verification difference set. Then, the difference is calculated to obtain the data related to the first verification difference set. Similarly, the same operation is performed on the second evaluation result set to be processed and the third evaluation result set to be processed, respectively obtaining the second verification difference set and the third verification difference set.

[0030] The average value of the first verification difference set, the second verification difference set, and the third verification difference set is calculated to obtain the verification average difference.

[0031] The behavioral characteristic data of game platform users includes the login time pattern, game duration, game operation frequency, recharge amount, and recharge frequency of game platform users.

[0032] The game platform users are classified into a user category classification result set according to the abnormality degree of the behavioral characteristic data, which specifically includes the following steps: Set the corresponding normal range threshold according to different behavioral characteristic data; The users whose all behavioral characteristic data are within the normal range threshold are classified as the first category users; The users whose part of the behavioral characteristic data are within the normal range threshold are classified as the second category users; The users whose all behavioral characteristic data are not within the normal range threshold are classified as the third category users; Among them, the first category users, the second category users, and the third category users are combined into the user category classification result set.

[0033] This application obtains the login time distribution law of most normal users by collecting a large amount of historical login data on the game platform. Suppose a mobile game statistics shows that 70% of users are used to logging in to the game between 7 pm and 10 pm, and the login time fluctuation range is within ±1 hour, then the normal login time range threshold is set to 6 pm - 11 pm.

[0034] According to the game type and player activity statistics, for example, for a role-playing game, the average daily game duration of ordinary players is 2 - 4 hours. Considering the individual differences of players and special situations such as weekends, the normal range threshold of game duration is set to 1 - 6 hours per day.

[0035] Count the various operations in the game. For example, for an action game, the normal players perform about 40 - 60 operations such as skill release and movement per hour. Therefore, the normal range threshold of game operation frequency is set to 30 - 70 times per hour.

[0036] Statistically analyze the payment situation and players' consumption ability in the game. If the price setting of in-game items makes the monthly recharge amount of ordinary players mostly between 50 - 300 yuan, the normal range threshold of the recharge amount can be set at 0 - 500 yuan per month (0 yuan represents non-recharging players).

[0037] Statistically analyze the time interval and frequency of players' recharges. For example, if most players recharge 1 - 3 times a month, then the normal range threshold of the recharge frequency can be set at 0 - 5 times per month.

[0038] Classification of the first category of users: For example, player Li logs in to the game around 8 pm every day, with a game duration of about 3 hours, a game operation frequency of about 50 times per hour, a monthly recharge amount of 200 yuan, and a recharge frequency of 2 times per month. All the behavioral characteristic data of Li's login time, game duration, game operation frequency, recharge amount, and recharge frequency are within the normal range thresholds set above. Therefore, Li is classified as a user of the first category, that is, a normal user. This type of user has stable behavior and conforms to the normal game ecosystem, and is the basic active group of the game platform.

[0039] Classification of the second category of users: For example, player Zhang's login time, game duration, and game operation frequency are all within the normal range, but the recharge amount in the recent month has suddenly reached 800 yuan, far exceeding the normal range threshold of 0 - 500 yuan per month, while other behavioral characteristic data are normal. Since some of Zhang's behavioral characteristic data are within the normal range threshold, he is classified as a user of the second category, that is, a suspected abnormal user. This type of user may have some special circumstances or start to show a trend of deviating from normal behavior and requires further monitoring and analysis.

[0040] Classification of the third category of users: For example, player Zhao's login time is extremely irregular, sometimes logging in in the early morning and sometimes during the day, far exceeding the normal range of 6 pm - 11 pm; the game duration is either only a few minutes or up to more than 8 hours, not conforming to the normal range of 1 - 6 hours; the game operation frequency is extremely low, less than 20 times per hour, and also not within the range of 30 - 70 times; moreover, the recharge amount and frequency are almost 0, completely outside the normal threshold. All of Zhao's behavioral characteristic data are not within the normal range threshold, so he is classified as a user of the third category, that is, a confirmed abnormal user. This type of user may be engaged in malicious data brushing, using cheats, or other serious behaviors that disrupt the game ecosystem.

[0041] The acquisition module specifically includes the following steps: Set the first monitoring and acquisition dimension, the second monitoring and acquisition dimension, and the third monitoring and acquisition dimension for the data monitoring and acquisition of the second category of users; Collect the first behavior dataset by collecting the game social behaviors and item usage situations of the second type of users according to the first monitoring and collection dimension, collect the second behavior dataset by collecting the game battle results and opponent matching situations of the second type of users according to the second monitoring and collection dimension, and collect the third behavior dataset by collecting the login situations and IP address change situations of the second type of users according to the third monitoring and collection dimension.

[0042] The second monitoring and collection dimension: Focus on game social behaviors and item usage situations. Game social behaviors cover behaviors such as adding friends, forming teams, and chatting and interacting among players; item usage situations include information such as the frequency, timing, and types of various items used. For example, in a large-scale multiplayer online role-playing game, the social interactions among players are frequent and the item system is rich and diverse. This dimension can effectively capture the behavioral characteristics of players in terms of social interactions and item usage.

[0043] The second monitoring and collection dimension: Mainly target game battle results and opponent matching situations. Game battle results include data such as wins and losses, scores, and kill counts; opponent matching situations involve information such as the levels, ranks, and win rates of opponents. Taking competitive games as an example, battles are the core gameplay, and this dimension can accurately obtain the performance of players in the battle session and relevant information about opponents.

[0044] The third monitoring and collection dimension: Focus on login situations and IP address change situations. Login situations include login time, login device, login location, etc.; IP address change situations record information such as the change frequency and source region of the IP address when players log in. Regardless of the type of game, player login is a basic behavior, and this dimension can track various dynamics related to player login.

[0045] Collection of the first behavior dataset: Taking player Xiao Wang as an example, he belongs to the second type of users. According to the first monitoring and collection dimension, the game system records through the social module the number of friends Xiao Wang adds every day. For example, the number of friends he added per month was originally between 5 and 10, and recently it suddenly increased to 30 per month; records the frequency of Xiao Wang forming teams with other players. In the past, he formed teams 2 - 3 times a week, and now it has reached 5 - 6 times a week; at the same time, monitors the number of times and content tendencies of Xiao Wang's speeches in the game chat channel and finds that he has recently frequently asked about game cheats. In terms of item usage, statistics show that the frequency of Xiao Wang using high-level equipment items was originally once every two weeks, and recently it has become 2 - 3 times a week. These data on game social behaviors and item usage situations are aggregated to form Xiao Wang's first behavior dataset.

[0046] The second line is for data set collection: Still taking player Xiao Wang as an example, in the battle mode of this game, according to the second monitoring and collection dimension, the game server records Xiao Wang's recent battle results. Originally, his winning rate maintained at 40%-50%, but in the recent week, it soared to 80%. At the same time, the information of the opponents he matched with is recorded. It is found that most of the opponents he originally matched with were players of similar levels to him with a winning rate of 40%-60%, while among the opponents he matches with now, there are a large number of players whose levels are significantly lower than his and whose winning rates are below 20%. After integrating the data of these battle results and the situations of the matched opponents, the second behavior data set of Xiao Wang is formed.

[0047] The third line is for data set collection: Continuing to take player Xiao Wang as an example, according to the third monitoring and collection dimension, the game login system records that Xiao Wang has always logged in to the game on the same mobile phone in his residential city in the past. But recently, he has started to frequently change the login device, having used a tablet computer, mobile phones of different models, etc. successively; the login location has also changed from the originally fixed residential city to multiple different cities, and the corresponding IP address sources are also very scattered, frequently changing between different provinces and even different countries. The data set of these login situations and the changes in IP addresses constitutes the third behavior data set of Xiao Wang.

[0048] The obtaining module specifically includes the following steps: Calculate the deviation degrees of the user behaviors of the second type of users from the normal behaviors respectively under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension to obtain the first deviation data set, the second deviation data set, and the third deviation data set; Predict the user abnormal behavior risks of the second type of users based on the first deviation data set to obtain the first risk data set; Predict the user abnormal behavior risks of the second type of users based on the second deviation data set to obtain the second risk data set; Extract the abnormal deviation degrees of the user behaviors of each user in the third monitoring and collection dimension from the normal behaviors to obtain the third risk data set.

[0049] Calculation of deviation under the first monitoring and collection dimension of this application: In terms of game social behavior, the average number of friends added by normal players per month is 8, while player Wang has recently added 30 friends per month. Calculate the deviation through the formula (assuming the formula here is: deviation = (actual value - average value) ÷ standard deviation, and the specific formula depends on the actual statistical method). Assuming that the standard deviation of the number of friends added by normal players is 2 after statistics, then the deviation of Wang's behavior of adding friends = (30 - 8) ÷ 2 = 11. In terms of chat interaction, normal players speak 5 times a day in the game chat channel, and Wang has recently spoken 20 times a day. If the standard deviation of the normal number of speeches is 3, the deviation of his chat speech = (20 - 5) ÷ 3 = 5. Combining these data, the relevant content of the first deviation data set in Wang's game social behavior is obtained.

[0050] In terms of the use of items, normal players use high-level equipment items once every two weeks, while Wang uses them 2 - 3 times a week. Assuming that the standard deviation of the use frequency of high-level items is 0.5, taking the example of using them 2 times a week to calculate, the deviation = (2 - 0.5) ÷ 0.5 = 3. Integrate these deviation data of item use with the deviation data of social behavior to form a complete first deviation data set.

[0051] Calculation of deviation under the second monitoring and collection dimension: In terms of the results of game battles, Wang's original winning rate maintained at 40% - 50%, and recently soared to 80%. Assuming that the standard deviation of the winning rate of normal players is 5%, calculate through the formula (deviation = (actual winning rate - average winning rate) ÷ standard deviation), the deviation of Wang's winning rate = (80% - 45%) ÷ 5% = 7. In terms of battle scores, the original average score per game was 50 points, and recently the average score per game reached 80 points. If the standard deviation of the scores is 10 points, the score deviation = (80 - 50) ÷ 10 = 3.

[0052] In terms of the situation of matching opponents, normally the average level of the opponents matched by Wang is similar to his, and the level difference is within ±5 levels. Recently, the average level of the opponents he matched with is 20 levels lower than his. Assuming that the standard deviation of the level difference of the opponents is 3 levels, the deviation of the level of the matched opponents = (20) ÷ 3 ≈ 6.67. Combining the deviation data of these battle results and the situation of matching opponents, the second deviation data set is obtained.

[0053] Calculation of deviation under the third monitoring and collection dimension: In terms of the login situation, Wang has always logged in to the game using the same mobile phone in his residential city. Recently, he has frequently changed the login device and has used 3 different devices successively. While normal players change devices once every six months on average. Assuming that the standard deviation of the device change frequency is 0.5 times per six months, calculate with a six-month time period, the deviation of the change of the login device = (3 - 0.5) ÷ 0.5 = 5.

[0054] Regarding the IP address changes, the IP addresses from which Xiao Wang originally logged in were all from his residential city. Recently, the IP addresses have changed frequently and come from 5 different provinces. The average number of IP address changes for normal players does not exceed 1 time per quarter. Assuming the standard deviation of IP address changes is 0.3 times / quarter, calculated on a quarterly time cycle, the deviation degree of his IP address changes = (5 - 0.5) ÷ 0.3 ≈ 15. Integrating these data, the third deviation dataset is obtained.

[0055] Based on the prediction of the second deviation dataset: The deviation data of game social behavior and item usage in the first deviation dataset are input into a pre-trained machine learning model, which has learned the data characteristics of a large number of normal players and abnormal players in these dimensions. According to the output result of the model, it is predicted that Xiao Wang has a risk of abnormal behavior in game social interaction and item usage. For example, he may be trying to use cheating items to attract other players to add friends or conduct illegal social interactions, etc., to obtain the first risk dataset, which records information such as the predicted risk type and risk probability. For example, the predicted risk probability of Xiao Wang using cheating items is 80%.

[0056] Based on the prediction of the second deviation dataset: The deviation data of game battle results and matched opponents in the second deviation dataset are input into a deep learning model specifically for battle behavior analysis, which has learned the data characteristics of a large number of normal players and abnormal players in these dimensions. The model predicts that Xiao Wang may be cheating in the game battle session, such as using cheating programs to increase the winning rate, matching with lower-level opponents to gain unfair advantages, etc., to obtain the second risk dataset, which includes the battle cheating risk type and the corresponding risk probability. For example, the predicted risk probability of Xiao Wang's battle cheating is 75%.

[0057] Extract the risk data of the third monitoring and collection dimension: Extract the situation of frequent replacement of Xiao Wang's logged-in devices and abnormal changes in IP addresses from the third deviation dataset, and combine the case data of account theft and malicious login in history to judge that Xiao Wang's account may be at risk of being stolen, or he himself may be performing abnormal login operations, such as trying to bypass the game security detection mechanism through different IP addresses, etc., to obtain the third risk dataset and record the relevant risk situations.

[0058] The evaluation module specifically includes the following steps: Evaluate the abnormal situation of the second type of users in the user category division result set according to the first risk dataset and the first behavior dataset to obtain the first to-be-processed evaluation result set; Evaluate the abnormal situation of the second type of users in the user category division result set according to the second risk dataset and the second behavior dataset to obtain the second to-be-processed evaluation result set; The third set of evaluation results to be processed is obtained by processing and evaluating the dataset in the first row, the dataset in the second row, the third deviation dataset, and the dataset in the third row.

[0059] Generate the first set of evaluation results to be processed: The first risk dataset regarding Xiao Wang predicts that there are abnormal behavior risks in his game social interaction and item usage. For example, the risk probability of using cheating items is 80%. The first-row dataset of the acquisition module records information such as Xiao Wang adding 30 friends per month recently (the average number of friends added by normal players is 8 per month), speaking 20 times per day in the game chat channel (the average number of times normal players speak per day is 5), and using high-level equipment items 2 - 3 times per week (normal players use them once every two weeks), etc. Integrate these two datasets and use the weighted scoring method for evaluation. Assume that the weight of abnormal social behavior is 0.6, and the weight of abnormal item usage is 0.4. For social behavior, set the scoring criteria according to the deviation degree. The deviation degree of adding friends is high, getting 8 points, and the deviation degree of chatting is high, getting 7 points. The comprehensive social behavior score is (8×0.6 + 7×0.4) = 7.6 points; for item usage, according to the deviation degree of usage frequency, the score is 9 points, and after multiplying by the weight of 0.4, it gets 3.6 points. Add the two together to get the comprehensive score of Xiao Wang in game social interaction and item usage in the first set of evaluation results to be processed, which is 11.2 points. Organize the above comprehensive score, related behavior data, risk probability, etc. into the first set of evaluation results to be processed, and clearly record the evaluation conclusion of the abnormal situation of Xiao Wang in the dimensions of game social interaction and item usage, such as "Game player Xiao Wang has a relatively high abnormal risk in game social interaction and item usage, the comprehensive score is 11.2 points, and the risk probability of using cheating items is 80%".

[0060] Generate the second set of evaluation results to be processed: The second risk dataset predicts that Xiao Wang may have cheating behavior in the game battle session, and the cheating risk probability is 75%. The second-row dataset shows that Xiao Wang's recent win rate has soared to 80% (the original win rate was 40% - 50%), the average score per game has increased from 50 points to 80 points, and the average level of the opponents he matches is 20 levels lower than his, etc. First, determine the weights of the battle result and the situation of the matched opponents in the abnormal battle evaluation. Assume that the weight of the battle result is 0.7, and the weight of the situation of the matched opponents is 0.3. In the battle result, the deviation degree of the win rate is high, getting 9 points, and the deviation degree of the score is high, getting 8 points. The comprehensive battle result score is (9×0.7 + 8×0.3) = 8.7 points; according to the deviation degree of the level, the score for the situation of the matched opponents is 7 points, and after multiplying by the weight of 0.3, it gets 2.1 points. Add the two together to get the comprehensive score of Xiao Wang in the game battle, which is 10.8 points. Organize the comprehensive score, behavior data, risk probability, etc. into the second set of evaluation results to be processed, and record the evaluation conclusion of the abnormal situation of Xiao Wang in the game battle dimension, such as "Game player Xiao Wang has a relatively high abnormal risk in the game battle, the comprehensive score is 10.8 points, and the battle cheating risk probability is 75%".

[0061] Generate the third set of evaluation results to be processed: From the first row of the data set, collect the time points when user Wang used key items. For example, he used a high-level buff item 5 minutes before opening a specific dungeon. From the second row of the data set, collect the key time points when user Wang won battles. For example, in a crucial battle, he achieved a key kill when there were 10 seconds left in the countdown and won the battle. These constitute the first time data set and the second time data set. From the third row of the data set, collect the key time points when user Wang changed the login device and the IP address. For example, he immediately changed the device to log in after a certain game update, and the IP address switched from domestic to overseas within a short period, forming the third time data set. Calculate the time differences for reaching the key nodes for the first time data set, the second time data set, and the third time data set. For example, calculate the time difference between the time when user Wang used the high-level item and the time when he won the battle, as well as the time differences between these times and the time when the login device and the IP address changed, to obtain the time difference data set.

[0062] Combine the third deviation data set (the deviation of user Wang's login device change is 5, and the deviation of IP address change is 15), and use the decision tree model to judge the risk of abnormal internal behavior. The model is trained based on historical data and can judge abnormal behavior based on features such as time differences and deviations. After judgment, it is found that user Wang has the risk of obtaining improper benefits by cooperating with key in-game behaviors through abnormal login behaviors, obtaining the third risk data set.

[0063] Evaluate the abnormal situation of user Wang in the dimensions related to login and account security based on the third risk data set and the third behavior data set. Adopt the fuzzy comprehensive evaluation method, consider multiple factors such as login device change and IP address change, set the weights of different factors, and finally obtain a comprehensive score of 9 points. Organize the relevant information into the third set of evaluation results to be processed, and record that "game player Wang has a relatively high risk of abnormality in login and account security, and the comprehensive score is 9 points".

[0064] Based on the first row of the data set, the second row of the data set, the third deviation data set, and the third behavior data set, perform processing and evaluation to obtain the third set of evaluation results to be processed, which specifically includes the following steps: Based on the first behavior data set and the second behavior data set, collect the first time data set and the second time data set of the key nodes of the normal operation behavior patterns of the second type of users; Based on the third behavior data set, collect the third time data set of the key nodes of the operation behavior information set of the second type of users; Calculate the time differences for reaching the key nodes for the first time data set, the second time data set, and the third time data set to obtain the time difference data set; Based on the time difference data set and the third deviation data set, judge the risk of abnormal internal behavior of the second type of users to obtain the third risk data set; Based on the third risk data set and the third behavior data set, the abnormal conditions of the second type of users in the user category division result set are evaluated to obtain the third to-be-processed evaluation result set.

[0065] Taking the gamer Xiao Wang as an example, the first behavior data set records his social and item usage behaviors in the game. Assuming that using a key item in a game can greatly enhance the hero's ability, Xiao Wang used the item 3 minutes before an important team battle started. This usage time point became a key node of the normal operation behavior pattern and was collected into the first time data set.

[0066] The second behavior data set covers the game battle results and the situation of matching opponents. In a game, when the game reached 15 minutes, the team where Xiao Wang was launched a crucial wave of attack and won. This time point of winning the battle was collected into the second time data set.

[0067] The third behavior data set is mainly about Xiao Wang's login situation and IP address change situation. Xiao Wang originally always logged in to the game locally using a fixed device around 8 pm. But recently, at 7:50 pm one day, that is, before a large-scale event in the game was about to start, he suddenly changed the device and logged in from a strange IP address. This login time point and related change information were collected into the third time data set.

[0068] Calculate the time difference of reaching the key nodes for the first time data set, the second time data set, and the third time data set. For example, the time difference between the time when Xiao Wang used the key item (the first time data set) and the time of winning the battle (the second time data set) is 12 minutes; the time difference between the abnormal login time of Xiao Wang (the third time data set) and the time of using the "Decisive Pearl" is -10 minutes. Organize and record these time differences to obtain the time difference data set.

[0069] Based on the time difference data set and the third deviation data set (Xiao Wang has a high deviation in device replacement for login and also a high deviation in IP address change), judge the risk of abnormal behavior. Combine the performance of normal players and abnormal players in these dimensions in historical data and use machine learning algorithms (such as support vector machines) for judgment.

[0070] Through judgment, it is found that Xiao Wang used the key item shortly after the abnormal login and won the battle. This behavior pattern is quite different from that of normal players. It is judged that Xiao Wang has the risk of using abnormal login behavior to cooperate with key operations in the game to obtain unfair advantages. For example, he may bypass the game anti-cheat detection by changing the device and IP address, thus obtaining the third risk data set, recording information such as the type and probability of the internal behavior abnormal behavior risk.

[0071] Generate the third set of evaluation results to be processed: Assume that based on a comprehensive score (with a full score of 10) considering various factors, Xiao Wang's final score is 8 points. Organize this scoring result, relevant behavioral data, risk descriptions, and other information to generate the third set of evaluation results to be processed, recording that "Player Xiao Wang has a relatively high abnormal risk in login and associated game behaviors, with a score of 8 points, and may be using abnormal logins to bypass the anti-cheat mechanism."

[0072] The judgment module specifically includes the following steps: Perform a difference operation on the data in the first set of evaluation results to be processed and the corresponding data in the standard evaluation set to obtain the first verification difference set; Perform a difference operation on the data in the second set of evaluation results to be processed and the corresponding data in the standard evaluation set to obtain the second verification difference set; Perform a difference operation on the data in the third set of evaluation results to be processed and the corresponding data in the standard evaluation set to obtain the third verification difference set; Calculate the average value of the first verification difference set, the second verification difference set, and the third verification difference set to obtain the verification average difference; Compare the verification average difference with a preset verification threshold to determine whether the second type of users in the user category division result set is in an abnormal state.

[0073] Calculation of the first verification difference set in this application: It is known that in the first set of evaluation results to be processed, Xiao Wang's comprehensive score for game social interaction and item use is 11.2 points. In the standard evaluation set, for players with normal game social interaction and item use behaviors, the comprehensive score range is 6 - 8 points, and the average value of 7 points is taken as the standard value. Through the difference operation, that is, 11.2 - 7 = 4.2, record this difference and the relevant evaluation dimension information to obtain the data related to the first verification difference set. If there are other sub-item data in the first set of evaluation results to be processed, such as the abnormal score for adding friends in social behavior and the abnormal score for item use frequency, also perform difference operations with the standard values of the corresponding sub-items in the standard evaluation set and include them in the first verification difference set together.

[0074] Calculation of the second verification difference set: In the second set of evaluation results to be processed, Xiao Wang's comprehensive score for game battles is 10.8 points. In the standard evaluation set, the comprehensive score range for players with normal game battle behaviors is 5 - 7 points, and the average value of 6 points is taken as the standard value. Calculate the difference as 10.8 - 6 = 4.8. Similarly, record this difference and the corresponding evaluation dimension information to construct the second verification difference set. If there are sub-item data such as win rate and score in the battle results, also perform difference operations with the standard values in this way and include them in the second verification difference set.

[0075] Third verification difference set calculation: In the third set of evaluation results to be processed, the score of player Xiao Wang in terms of login and account security is 8 points. In the standard evaluation set, the comprehensive score range of players with normal login and account security behaviors is 4 - 6 points, and the average value of 5 points is taken as the standard value. After calculation, the difference is 8 - 5 = 3. Record this difference and related information to form the third verification difference set. If there are sub-item data such as the frequency of login device replacement and IP address change, the differences from the standard value are also calculated separately and integrated into the third verification difference set.

[0076] Calculate the average value of the first verification difference set, the second verification difference set, and the third verification difference set. The data of the first verification difference set is 4.2, the data of the second verification difference set is 4.8, and the data of the third verification difference set is 3. Then the verification average difference is (4.2 + 4.8 + 3) ÷ 3 = 4.

[0077] Compare the verification average difference with the preset verification threshold to determine whether the second type of users in the user category division result set is in an abnormal state. The specific steps are as follows: If the verification average difference is less than or equal to the preset verification threshold, then the second type of users in the user category division result set is in a normal state; If the verification average difference is greater than the preset verification threshold, then the second type of users in the user category division result set is in an abnormal state.

[0078] Suppose the preset verification threshold is 3 (this threshold can be comprehensively set according to the actual situation of the game platform, historical data, and operation requirements, etc.). Since the calculated verification average difference of 4 is greater than the preset verification threshold of 3, according to the judgment rule, it can be determined that player Xiao Wang of the game is in an abnormal state.

[0079] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0080] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0081] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An abnormal user analysis system based on big data, characterized in that, Including: Partitioning module: Obtain the behavioral characteristic data of game platform users, and classify the game platform users through the degree of abnormality of the behavioral characteristic data to obtain a user classification result set; Collection module: Collect the behavioral data of the second type of users in the user classification result set according to different monitoring dimensions to obtain a first behavioral data set, a second behavioral data set, and a third behavioral data set; Obtaining module: Extract the abnormal deviation degrees of the user behaviors of the second type of users in different monitoring dimensions from the normal behaviors respectively to obtain a first risk data set, a second risk data set, and a third risk data set; Evaluation module: Evaluate the abnormal conditions of the second type of users in the user classification result set according to the first behavioral data set, the second behavioral data set, the third behavioral data set, the first risk data set, the second risk data set, and the third risk data set to obtain a first to-be-processed evaluation result set, a second to-be-processed evaluation result set, and a third to-be-processed evaluation result set; Judgment module: Judge whether the second type of users in the user classification result set are in an abnormal state according to the first to-be-processed evaluation result set, the second to-be-processed evaluation result set, and the third to-be-processed evaluation result set.

2. The abnormal user analysis system based on big data according to claim 1, characterized in that, The behavioral characteristic data of the game platform users includes the login time pattern, game duration, game operation frequency, recharge amount, and recharge frequency of the game platform users.

3. The abnormal user analysis system based on big data according to claim 2, wherein Classify the game platform users through the degree of abnormality of the behavioral characteristic data to obtain a user classification result set, which specifically includes the following steps: Set corresponding normal range thresholds according to different behavioral characteristic data; Classify the users whose all behavioral characteristic data are within the normal range thresholds as the first type of users; Classify the users whose partial behavioral characteristic data are within the normal range thresholds as the second type of users; Classify the users whose all behavioral characteristic data are not within the normal range thresholds as the third type of users; Among them, the first type of users, the second type of users, and the third type of users form a user classification result set.

4. The abnormal user analysis system based on big data according to claim 1, characterized in that The collection module specifically includes the following steps: Set a first monitoring and collection dimension, a second monitoring and collection dimension, and a third monitoring and collection dimension for the data monitoring and collection of the second type of users; Collect the game social behaviors and item usage situations of the second type of users according to the first monitoring and collection dimension to obtain a first behavioral data set, collect the game battle results and matching opponent situations of the second type of users according to the second monitoring and collection dimension to obtain a second behavioral data set, and collect the login situations and IP address change situations of the second type of users according to the third monitoring and collection dimension to obtain a third behavioral data set.

5. The abnormal user analysis system based on big data according to claim 4, characterized in that The obtaining module specifically includes the following steps: Calculate the deviation degrees of the user behaviors of the second type of users from the normal behaviors respectively under the first monitoring and collection dimension, the second monitoring and collection dimension, and the third monitoring and collection dimension to obtain a first deviation degree data set, a second deviation degree data set, and a third deviation degree data set; Predict the user abnormal behavior risks of the second type of users according to the first deviation degree data set to obtain a first risk data set; Predict the user abnormal behavior risks of the second type of users according to the second deviation degree data set to obtain a second risk data set; Extract the abnormal deviation degrees of each user behavior in the third monitoring and acquisition dimension from the normal behavior to obtain the third risk data set.

6. The abnormal user analysis system based on big data according to claim 5, characterized in that, The evaluation module specifically includes the following steps: Evaluate the abnormal conditions of the second-category users in the user category division result set according to the first risk data set and the first behavior data set to obtain the first to-be-processed evaluation result set; Evaluate the abnormal conditions of the second-category users in the user category division result set according to the second risk data set and the second behavior data set to obtain the second to-be-processed evaluation result set; Perform processing and evaluation according to the first behavior data set, the second behavior data set, the third deviation data set, and the third behavior data set to obtain the third to-be-processed evaluation result set.

7. The abnormal user analysis system based on big data according to claim 6, characterized in that, Perform processing and evaluation according to the first behavior data set, the second behavior data set, the third deviation data set, and the third behavior data set to obtain the third to-be-processed evaluation result set, which specifically includes the following steps: Collect the first time data set and the second time data set of the key nodes of the normal operation behavior mode of the second-category users based on the first behavior data set and the second behavior data set; Collect the third time data set of the key nodes of the operation behavior information set of the second-category users based on the third behavior data set; Calculate the difference in the time to reach the key nodes for the first time data set, the second time data set, and the third time data set to obtain the time difference data set; Judge the internal behavior abnormal behavior risk of the second-category users based on the time difference data set and the third deviation data set to obtain the third risk data set; Evaluate the abnormal conditions of the second-category users in the user category division result set based on the third risk data set and the third behavior data set to obtain the third to-be-processed evaluation result set.

8. The abnormal user analysis system based on big data according to claim 1, characterized in that, The judgment module specifically includes the following steps: Perform a difference operation on the data in the first to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain the first verification difference set; Perform a difference operation on the data in the second to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain the second verification difference set; Perform a difference operation on the data in the third to-be-processed evaluation result set and the corresponding data in the standard evaluation set to obtain the third verification difference set; Calculate the average value of the first verification difference set, the second verification difference set, and the third verification difference set to obtain the verification average difference; Compare the verification average difference with the preset verification threshold to judge whether the second-category users in the user category division result set are in an abnormal state.

9. The abnormal user analysis system based on big data according to claim 8, wherein Compare the verification average difference with the preset verification threshold to judge whether the second-category users in the user category division result set are in an abnormal state, which specifically includes the following steps: If the verification average difference is less than or equal to the preset verification threshold, the second-category users in the user category division result set are in a normal state; If the verification average difference is greater than the preset verification threshold, the second-category users in the user category division result set are in an abnormal state.

Citation Information

Patent Citations

  • Abnormal account identification method and device, computer equipment and storage medium

    CN112329811A

  • User account risk control method and device

    CN112370793A

  • Cheating behavior identification method and device, storage medium and electronic equipment

    CN114602186A

  • Network security situation early warning method and system based on knowledge graph

    CN119603058A

  • Account anomaly detection method and system

    CN119788415A