Login detection method and device, storage medium and electronic equipment

By matching the system environment information of the remote login terminal with the baseline environment information, identifying the login type and performing risk control, the problem of remote login attacks is solved, security protection for remote login is achieved, and the risk of data leakage is reduced.

CN120658419APending Publication Date: 2025-09-16BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410303154.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-15
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In remote login scenarios, existing technologies are unable to effectively identify and prevent remote login attacks such as lateral penetration of the intranet, resulting in a high probability of successful ransomware delivery and an increased risk of data leakage and loss.

Method used

By obtaining the target terminal's system environment information and the baseline system environment information to match environmental features, the login type is determined, and risk control processing is performed based on the matching results, including normal access control or abnormal access control, and the risk access control model is used to determine the defense level and method.

Benefits of technology

It effectively blocks lateral penetration-type remote login attacks, reduces the success rate of ransomware delivery, and reduces data leakage and loss on the service side.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658419A_ABST
    Figure CN120658419A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a login detection method and device, a storage medium and electronic equipment, and the method comprises the steps: determining that a target terminal account passes verification based on target account verification information, obtaining the target system environment information of a target terminal, obtaining the reference system environment information, and obtaining the target terminal account verification information; and carrying out risk login detection on the target terminal based on the target system environment information and the reference system environment information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a login detection method, device, storage medium, and electronic device. Background Art

[0002] In a remote login access scenario, a client (remote access user) establishes a network connection with a service device (such as a target computer or system). Once the remote connection is established, the remote access user provides identity information to prove their identity. Common identity information includes username and password, digital certificates, tokens, or biometrics. The service device verifies the provided identity information and decides whether to grant access to the client device. Summary of the Invention

[0003] The present application provides a login detection method, device, storage medium, and electronic device. The technical solution is as follows:

[0004] In a first aspect, an embodiment of the present application provides a login detection method, the method comprising:

[0005] Determining that the target terminal account verification is successful based on the target account verification information, and obtaining target system environment information of the target terminal;

[0006] Obtain baseline system environment information, and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

[0007] In a feasible implementation manner, the performing risk login detection on the target terminal based on the target system environment information and the reference system environment information includes:

[0008] Performing environmental feature matching on the target system environment information and the reference system environment information to obtain a login environment matching result;

[0009] Perform risk login control processing on the target terminal based on the login environment matching result.

[0010] In a feasible implementation manner, performing risk login control processing on the target terminal based on the login environment matching result includes:

[0011] Determining a baseline environment login type of the baseline system environment information;

[0012] Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

[0013] In a feasible implementation manner, performing risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result includes:

[0014] If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, the target terminal is determined to be an abnormal login access type;

[0015] If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, the target terminal is determined to be a normal login access type;

[0016] performing normal access control processing on the target terminal based on the normal login access type, or performing abnormal access control processing on the target terminal based on the abnormal login access type;

[0017] In a feasible implementation manner, before obtaining the baseline system environment information, the method further includes:

[0018] Collecting historical system environment information of the target terminal within a preset period and using the historical system environment information as the baseline system environment information; and / or,

[0019] Determining a first terminal of a normal login access type, collecting first system environment information of the first terminal within a preset period, and using the first system environment information as reference system environment information of a normal login environment type; and / or,

[0020] Determine a second terminal of an abnormal login access type, collect second system environment information of the second terminal within a preset period, and use the second system environment information as benchmark system environment information of the abnormal login environment type.

[0021] In a feasible implementation manner, performing abnormal access control processing on the target terminal based on the abnormal login access type includes:

[0022] Determine a target login environment matching result corresponding to the abnormal login access type;

[0023] Inputting the target login environment matching result and target system environment information into a risk access control model, determining a target risk defense level for the target terminal through the risk access control model, and outputting the target risk defense level;

[0024] A target risk defense method corresponding to the target risk defense level is determined, and abnormal access control processing is performed on the target terminal using the target risk defense method.

[0025] In a feasible implementation manner, performing abnormal access control processing on the target terminal using the target risk defense method includes:

[0026] If the target risk defense mode is a defense alarm mode, outputting abnormal access information for the target terminal to the system management end;

[0027] If the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

[0028] In a feasible implementation manner, the target system environment information includes at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

[0029] In a second aspect, an embodiment of the present application provides a login detection device, the device comprising:

[0030] An acquisition module, configured to determine whether the target terminal account verification has passed based on the target account verification information, and acquire target system environment information of the target terminal;

[0031] The detection module is used to obtain the baseline system environment information and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

[0032] In a feasible implementation, the detection module includes:

[0033] A feature matching unit, configured to perform environment feature matching on the target system environment information and the reference system environment information to obtain a login environment matching result;

[0034] A login control unit is used to perform risk login control processing on the target terminal based on the login environment matching result.

[0035] In a feasible implementation manner, the login control unit is used to:

[0036] Determining a baseline environment login type of the baseline system environment information;

[0037] Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

[0038] In a feasible implementation manner, the login control unit is used to:

[0039] If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, the target terminal is determined to be an abnormal login access type;

[0040] If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, the target terminal is determined to be a normal login access type;

[0041] performing normal access control processing on the target terminal based on the normal login access type, or performing abnormal access control processing on the target terminal based on the abnormal login access type;

[0042] In a feasible implementation manner, the detection module is used to:

[0043] Collecting historical system environment information of the target terminal within a preset period and using the historical system environment information as the baseline system environment information; and / or,

[0044] Determining a first terminal of a normal login access type, collecting first system environment information of the first terminal within a preset period, and using the first system environment information as reference system environment information of a normal login environment type; and / or,

[0045] Determine a second terminal of an abnormal login access type, collect second system environment information of the second terminal within a preset period, and use the second system environment information as benchmark system environment information of the abnormal login environment type.

[0046] In a feasible implementation manner, the detection module is used to:

[0047] Determine a target login environment matching result corresponding to the abnormal login access type;

[0048] Inputting the target login environment matching result and target system environment information into a risk access control model, determining a target risk defense level for the target terminal through the risk access control model, and outputting the target risk defense level;

[0049] A target risk defense method corresponding to the target risk defense level is determined, and abnormal access control processing is performed on the target terminal using the target risk defense method.

[0050] In a feasible implementation manner, the detection module is used to:

[0051] If the target risk defense mode is a defense alarm mode, outputting abnormal access information for the target terminal to the system management end;

[0052] If the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

[0053] In a feasible implementation manner, the target system environment information includes at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

[0054] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.

[0055] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.

[0056] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:

[0057] In one or more embodiments of the present application, after the service device determines that the target terminal account verification has passed based on the target account verification information, it obtains the target system environment information and the baseline system environment information of the target terminal, and performs risk login detection on the target terminal based on the target system environment information and the baseline system environment information, rather than directly granting device access rights after the account verification has passed. Risk login detection based on system environment information can prevent remote login attacks such as lateral penetration types, reduce login risks, reduce the success rate of ransomware delivery, and reduce data leakage and data loss losses on the service side. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0059] Figure 1 This is a scenario diagram of a login detection system provided by an embodiment of the present application;

[0060] Figure 2 This is a flowchart of a login detection method provided in an embodiment of the present application;

[0061] Figure 3 This is a flowchart of another login detection method provided in an embodiment of the present application;

[0062] Figure 4 This is a structural diagram of a landing detection device provided in an embodiment of the present application;

[0063] Figure 5 This is a schematic diagram of the structure of a detection module provided in an embodiment of the present application;

[0064] Figure 6 This is a schematic structural diagram of an electronic device provided in an embodiment of the present application;

[0065] Figure 7 This is a schematic diagram of the structure of the operating system and user space provided in an embodiment of the present application;

[0066] Figure 8 yes Figure 7 The architecture diagram of the Android operating system;

[0067] Figure 9 yes Figure 7 Architecture diagram of the IOS operating system. DETAILED DESCRIPTION

[0068] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0069] In the description of this application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood to indicate or imply relative importance. In the description of this application, it should be noted that, unless otherwise expressly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. In addition, in the description of this application, unless otherwise specified, "multiple" refers to two or more. "and / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

[0070] In related technologies, since methods such as lateral penetration of the intranet can quickly obtain remote login account passwords, the login user uses the correct username and password, and the login is successful once, without multiple attempts. From a technical perspective, it becomes very difficult to identify and intercept such risky login behaviors, leaving opportunities for remote ransomware and poisoning.

[0071] Based on this, it can be seen that the login detection method in the related art has certain limitations.

[0072] See Figure 1 , is a scene diagram of a login detection system provided in this specification. Figure 1 As shown, the login detection system may include at least a client cluster and a service platform 100 .

[0073] The client cluster may include at least one client, such as Figure 1 As shown, it specifically includes client 1 corresponding to user 1, client 2 corresponding to user 2, ..., client n corresponding to user n, where n is an integer greater than 0.

[0074] Each client in the client cluster can be an electronic device with communication capabilities, including but not limited to wearable devices, handheld devices, personal computers, tablet computers, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem. Electronic devices may be called different names in different networks, such as user equipment, access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), electronic devices in 5G network or future evolution network, etc.

[0075] The service platform 100 can be a separate server device, such as a rack-mounted, blade, tower, or cabinet-mounted server device, or a workstation, mainframe computer, or other hardware device with strong computing capabilities; it can also be a server cluster composed of multiple servers. The servers in the service cluster can be symmetrically composed, wherein each server has equivalent functions and status in the transaction link, and each server can provide services to the outside world independently. The independent service can be understood as not requiring the assistance of other servers.

[0076] In one or more embodiments of the present specification, the service platform 100 may establish a communication connection with at least one client in the client cluster, and complete data interaction during the login detection process based on the communication connection.

[0077] It should be noted that the service platform 100 and at least one client in the client cluster establish a communication connection through a network for interactive communication, wherein the network can be a wireless network or a wired network, the wireless network includes but is not limited to a cellular network, a wireless local area network, an infrared network or a Bluetooth network, and the wired network includes but is not limited to Ethernet, a universal serial bus (USB) or a controller area network. In one or more embodiments of the specification, technologies and / or formats including Hypertext Markup Language (HTML) and Extensible Markup Language (XML) are used to represent data exchanged over the network (such as a target compressed package). In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.

[0078] The login detection system embodiments provided herein share the same concept as the login detection methods described in one or more embodiments. The execution entity of the login detection methods described in one or more embodiments may be the service device corresponding to the aforementioned service platform 100, depending on the actual application environment. The implementation process of the login detection system embodiments can be found in the following method embodiments and will not be further elaborated here.

[0079] based on Figure 1 The scene diagram shown is a detailed introduction to the login detection method provided by one or more embodiments of this specification.

[0080] In one embodiment, Figure 2As shown, a login detection method is proposed, which can be implemented by a computer program and can be run on a login detection device based on the von Neumann architecture. The computer program can be integrated into an application or run as an independent tool application. The login detection device can be a service device, including but not limited to: a personal computer, a tablet computer, a handheld device, a vehicle-mounted device, a wearable device, a computing device or other processing device connected to a wireless modem. In different networks, terminal devices can be called different names, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, service device in 5G network or future evolution network, etc.

[0081] Specifically, the login detection method includes:

[0082] S102: Determine that the target terminal account verification is successful based on the target account verification information, and obtain target system environment information of the target terminal;

[0083] The target terminal can apply for remote access to the service device based on the target account verification information provided. The remote login access process generally includes the following steps:

[0084] Establishing a connection: When remote login access begins, the target terminal (remote accessor) establishes a network connection with the service device. This network connection can be established through various protocols, such as SSH (Secure Shell), RDP (Remote Desktop Protocol), or VPN (Virtual Private Network).

[0085] Authentication: Once the network connection is established, the target terminal can provide target account verification information to prove its identity. Common target account verification information includes username and password, digital certificate, token, or biometric identification. The service device verifies that the provided target account verification information is correct and determines whether the target terminal account is authenticated.

[0086] In order to avoid the related art whereby remote account verification information can be quickly obtained through methods such as intranet lateral penetration, the risky login user uses the correct account verification information and the account verification is successful once, and to avoid subsequent risky behaviors by the risky login user after the account verification is successful, the login detection method of one or more embodiments of this specification can be executed. After determining that the target terminal account verification has passed based on the target account verification information, the target system environment information of the target terminal is obtained, the baseline system environment information is obtained, and a risk login detection is performed on the target terminal based on the target system environment information and the baseline system environment information. After the risk login detection passes, a session is established;

[0087] Session Establishment: Once a successful risky login detection method based on system environment information is detected, the target terminal will be granted access and a session will be established with the service device. During this session, the target terminal can perform operations such as viewing files, running programs, and managing the device, just like directly accessing the device locally.

[0088] Data transmission: During a session, the target terminal, acting as a remote visitor, can interact with the target computer through a remote desktop or terminal window. Input commands, keyboard input, and other operations are transmitted over the network to the service device, while responses and output from the service device are also transmitted back to the target terminal over the network.

[0089] Disconnect: When the remote access task is completed or the user actively disconnects, the session ends. The network connection between the target terminal and the service device is closed, and no more data is transmitted.

[0090] The target system environment information includes but is not limited to at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

[0091] The human-machine input device characteristics may be device characteristics of human-machine input devices such as keyboard characteristics and mouse characteristics.

[0092] S104: Obtaining baseline system environment information, and performing risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

[0093] Specifically, executing the risk login detection on the target terminal based on the target system environment information and the baseline system environment information can be: matching the target system environment information with the baseline system environment information for environmental features to obtain a login environment matching result, and performing risk login control processing on the target terminal based on the login environment matching result.

[0094] In one possible implementation, as follows:

[0095] First, terminal system environment information tagged with login type tags (such as normal login type tags and abnormal login type tags) can be collected within a certain collection period. First, the terminal login access process is recorded, including the logged-in user's IP address, operating system type and version, login time, terminal device information, etc. This collected information can be obtained through system logs, audit logs, or security tools.

[0096] Next, establish a baseline environment and its corresponding baseline system environment information. The terminal system environment information collected during the normal login process is used as the baseline system environment information for the baseline environment. This baseline system environment information can be used as a reference standard. The baseline system environment information and the target terminal's target system environment information can be extracted from the collected information during the login access process.

[0097] The baseline system environment information includes but is not limited to at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

[0098] Again, in actual application, after determining that the target terminal account has passed the verification, the target system environment information is matched with the reference system environment information to obtain the login environment matching result, and the target terminal is subjected to risk login control processing based on the login environment matching result.

[0099] Indicatively, if the login environment matching result indicates a mismatch, then the target system environment information may be the system environment information of a new remote login terminal that appears for the first time. At this time, risk login defense can be performed, for example, a risk login event for the target device can be output to the service management device, or for example, remote access to the target device can be blocked.

[0100] Optionally, a benchmark environment can be established in advance for each account verification information. Different account verification information is configured with benchmark system environment information under different benchmark environments. Based on this, an account-benchmark environment mapping relationship is established between the reference account verification information and the reference benchmark system environment information. Based on this "account-benchmark environment mapping relationship", in actual applications, after determining that the target terminal account verification has passed, the benchmark system environment information corresponding to the target account verification information can be quickly indexed, and the target system environment information is matched with the benchmark system environment information to obtain the login environment matching result.

[0101] Illustratively, the basic environment may be the baseline system environment information of a normal login terminal under a normal login type label, or the baseline system environment information of an abnormal login terminal under an abnormal login type label.

[0102] In one or more embodiments of the present specification, after the service device determines that the target terminal account verification has passed based on the target account verification information, it obtains the target system environment information and the baseline system environment information of the target terminal, and performs risk login detection on the target terminal based on the target system environment information and the baseline system environment information, rather than directly granting device access rights after the account verification has passed. Risk login detection based on system environment information can prevent remote login attacks such as lateral penetration types, reduce login risks, reduce the success rate of ransomware delivery, and reduce data leakage and data loss losses on the service side.

[0103] See Figure 3 , Figure 3 This is a flow chart of another embodiment of a login detection method proposed in this application. Specifically:

[0104] S200: Setting baseline system environment information;

[0105] The baseline system environment information can be understood as the system environment information used as a reference for risk login detection on the current terminal. The baseline system environment information can provide a baseline environment. The baseline system environment information can be composed of terminal system environment elements such as screen resolution, human-computer input device characteristics, host name, user name, and login domain.

[0106] In a feasible implementation, historical system environment information of the target terminal within a preset period is collected and used as the baseline system environment information;

[0107] The preset period can be customized, such as one month, one year, etc. System environment information statistics and historical access behaviors for a period of time indicated by the preset period can be used to construct baseline system environment information under a baseline environment.

[0108] Schematically, the historical system environment information of the target terminal within a preset period can be collected with reference to the account verification information. After logging in using the account verification information within the preset period, the login access behavior of the device and the historical system environment information of the device are monitored. Based on the login behavior, it can be determined whether the login access behavior of the device belongs to a normal access type or an abnormal access type. The normal access type corresponds to the normal historical system environment information, and the abnormal access type corresponds to the abnormal historical system environment information. Both the normal historical system environment information and the abnormal historical system environment information can be used as baseline system environment information and then marked with the normal login environment type or the abnormal login environment type, so as to facilitate subsequent targeted access control processing based on the matching results.

[0109] Optionally, a benchmark environment can be established in advance for each account verification information. Different account verification information is configured with benchmark system environment information under different benchmark environments. Based on this, an account-benchmark environment mapping relationship is established between the reference account verification information and the reference benchmark system environment information. Based on this "account-benchmark environment mapping relationship", in actual applications, after determining that the target terminal account verification has passed, the benchmark system environment information corresponding to the target account verification information can be quickly indexed, and the target system environment information is matched with the benchmark system environment information to obtain the login environment matching result.

[0110] In a feasible implementation, a first terminal of a normal login access type is determined, first system environment information of the first terminal within a preset period is collected, and the first system environment information is used as a benchmark system environment information of a normal login environment type;

[0111] Among them: the first terminal is a device that belongs to the normal login access type among the terminal devices. The access behavior of a batch of terminal devices can be continuously monitored in advance to collect login access process information, so as to call expert services to judge whether the login access process information is normal login access or abnormal login access, so as to calibrate the first terminal of the normal login access type.

[0112] The first system environment information of the first terminal within a preset period, such as IP address, screen resolution, human-machine input device characteristics, host name, user name, login domain, etc., can be obtained through system logs, audit logs or security tools.

[0113] In a feasible implementation, a second terminal of an abnormal login access type is determined, second system environment information of the second terminal within a preset period is collected, and the second system environment information is used as benchmark system environment information of the abnormal login environment type.

[0114] Among them: the second terminal is a device that belongs to the abnormal login access type among the terminal devices. The access behavior of a batch of terminal devices can be continuously monitored in advance to collect login access process information, so as to call expert services to judge whether the login access process information is normal login access or abnormal login access, so as to calibrate the second terminal of the abnormal login access type.

[0115] S202: Determine that the target terminal account verification is successful based on the target account verification information, and obtain target system environment information of the target terminal;

[0116] For details, please refer to the method steps in other embodiments of this specification, which will not be repeated here.

[0117] S204: Obtaining baseline system environment information, performing environment feature matching between the target system environment information and the baseline system environment information, and obtaining a login environment matching result;

[0118] Optionally, the information similarity between the target system environment information and each benchmark system environment information can be calculated, and the login environment matching result can be used based on the information similarity;

[0119] Furthermore, a similarity threshold can be set. If the information similarity is greater than the similarity threshold, the matching type indicated by the login environment matching result is the result matching type. If the information similarity is less than or equal to the similarity threshold, the matching type indicated by the login environment matching result is the result mismatch type. The login environment matching result can also include the similarity level of each system environment element.

[0120] Optionally, the target system environment information and the baseline system environment information are composed of parameter values ​​of each system environment element, such as a parameter value of a screen resolution element, a parameter value of a human-machine input device feature element, a parameter value of a host name element, a parameter value of a user name element, and a parameter value of a login domain element;

[0121] By matching the target system environment information with the baseline system environment information through environmental feature matching, the parameter values ​​of the system environment elements of the target system environment information can be compared to see whether they are consistent with the baseline parameter values ​​in the baseline system environment information. In this way, the matching results of each system environment element in the target system environment information can be obtained. The matching results of all system environment elements are also the login environment matching results.

[0122] S206: Determine the baseline environment login type of the baseline system environment information;

[0123] Optionally, the baseline environment login type may include a normal login environment type and an abnormal login environment type. In one or more embodiments of this specification, the baseline system environment information of different baseline environment login types will assist in how to perform risk access control.

[0124] S208: Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

[0125] In a feasible implementation, the following method may be adopted:

[0126] B2: If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, then the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, then the target terminal is determined to be an abnormal login access type;

[0127] B4: If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, then the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, then the target terminal is determined to be a normal login access type;

[0128] B6: performing normal access control processing on the target terminal based on the normal login access type, or performing abnormal access control processing on the target terminal based on the abnormal login access type;

[0129] Illustratively, after determining that the target terminal is of a normal login access type, the target terminal may be granted normal access authority, and the target terminal may perform data transmission with the service device normally.

[0130] Illustratively, after determining that the target terminal is of an abnormal login access type, an abnormal access control process is performed on the target terminal, and the abnormal access control process adopts a preset abnormal access control policy.

[0131] Optionally, after determining that the target terminal has an abnormal login access type, you can use the following methods:

[0132] 1. Determine the target login environment matching result corresponding to the abnormal login access type;

[0133] 2. Input the target login environment matching result and target system environment information into a risk access control model, determine a target risk defense level for the target terminal through the risk access control model, and output the target risk defense level;

[0134] Schematically, a risk access control model based on a machine learning model can be trained in advance, and the risk access control model can be used to adaptively decide the target risk defense level based on the target login environment matching results and the target system environment information. The risk access control model can be associated with the baseline system environment information. The risk access control model can determine the risk defense level through model training by combining the target login environment matching results and calling the security system risk library to compare the target system environment information. The security system risk library can include a public security risk library and local basic system environment information. The risk access control model can be called only when it is determined that the current access terminal is an abnormal login access type to save computing and processing resources.

[0135] In the actual application phase, the target login environment matching results and target system environment information are input into the risk access control model. The target risk defense level for the target terminal is determined through the risk access control model, and the target risk defense level is output.

[0136] In a feasible implementation, a model training process of a risk access control model is illustrated as follows:

[0137] Model creation: Create an initial risk access control model for risky access scenarios based on the machine learning model, and associate the initial risk access control model with the security system risk library;

[0138] Sample data acquisition: Acquire a large amount of sample data. The sample data consists of the sample login environment matching results of the sample terminal and the sample system environment information.

[0139] Sample data labeling: Based on the needs of risk access scenarios, expert services are introduced to manually label the sample data with corresponding sample labels. The sample labels are risk defense level labels.

[0140] Model training process: The sample data is input into the initial risk access control model for at least one round of model training. The initial risk access control model can combine the target login environment matching results and call the security system risk library to compare the target system environment information to predict the risk defense level. Based on the predicted risk defense level and the risk defense level label, the model loss value is determined using the model loss function. Based on the model loss value, the model parameters of the initial risk access control model are adjusted until the model training end conditions are met to obtain a feature matching model.

[0141] Optionally, the model loss function can be a Euclidean distance loss function, a hinge loss function, a cross entropy loss function, etc.

[0142] Optionally, the model training termination conditions may include, for example, the loss function value being less than or equal to a preset loss function threshold, the number of iterations reaching a preset number threshold, etc. Specific model training termination conditions may be determined based on actual conditions and are not specifically limited here.

[0143] It should be noted that the machine learning models involved in one or more embodiments of this specification include but are not limited to convolutional neural network (CNN) models, deep neural network (DNN) models, recurrent neural network (RNN) models, embedding models, gradient boosting decision tree (GBDT) models, logistic regression (LR) models and other machine learning models.

[0144] 3. Determine a target risk defense method corresponding to the target risk defense level, and use the target risk defense method to perform abnormal access control processing on the target terminal.

[0145] A level defense method mapping relationship is preset between one or more reference risk defense levels and the reference risk defense methods corresponding to the reference risk defense levels. In actual applications, the level defense method mapping relationship can be used to query the target risk defense method corresponding to the target risk defense level, and the target risk defense method can be used to perform abnormal access control processing on the target terminal subsequently.

[0146] Exemplarily, if the target risk defense mode is a defense alarm mode, abnormal access information for the target terminal is output to the system management end;

[0147] Exemplarily, if the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

[0148] It should be noted that the reference risk defense method corresponding to the reference risk defense level can be customized based on actual application conditions and is not limited here.

[0149] In one or more embodiments of the present specification, after the service device determines that the target terminal account verification has passed based on the target account verification information, it obtains the target system environment information and the baseline system environment information of the target terminal, and performs risk login detection on the target terminal based on the target system environment information and the baseline system environment information, rather than directly granting device access rights after the account verification has passed. Risk login detection based on system environment information can prevent remote login attacks such as lateral penetration types, reduce login risks, reduce the success rate of ransomware delivery, and reduce data leakage and data loss losses on the service side.

[0150] The following will be combined Figure 4 , the landing detection device provided in the embodiment of the present application is introduced in detail. It should be noted that, Figure 4 The login detection device shown is used to execute this application Figures 1 to 3 For the convenience of explanation, only the part related to the embodiment of the present application is shown. For the specific technical details not disclosed, please refer to the present application. Figures 1 to 3 The embodiment shown.

[0151] See Figure 4 , which shows a schematic diagram of the structure of the login detection device of an embodiment of the present application. The login detection device 1 can be implemented as all or part of the device through software, hardware, or a combination of both. According to some embodiments, the login detection device 1 includes an acquisition module 11 and a detection module 12, which are specifically used to:

[0152] An acquisition module 11 is configured to determine whether the target terminal account verification has passed based on the target account verification information, and to obtain target system environment information of the target terminal;

[0153] The detection module 12 is configured to obtain baseline system environment information and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

[0154] Optional, such as Figure 5 As shown, the detection module 12 includes:

[0155] A feature matching unit 121 is configured to perform environment feature matching on the target system environment information and the reference system environment information to obtain a login environment matching result;

[0156] The login control unit 122 is configured to perform risk login control processing on the target terminal based on the login environment matching result.

[0157] Optionally, the login control unit 122 is configured to:

[0158] Determining a baseline environment login type of the baseline system environment information;

[0159] Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

[0160] Optionally, the login control unit 122 is configured to:

[0161] If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, the target terminal is determined to be an abnormal login access type;

[0162] If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, the target terminal is determined to be a normal login access type;

[0163] performing normal access control processing on the target terminal based on the normal login access type, or performing abnormal access control processing on the target terminal based on the abnormal login access type;

[0164] Optionally, the detection module 12 is configured to:

[0165] Collecting historical system environment information of the target terminal within a preset period and using the historical system environment information as the baseline system environment information; and / or,

[0166] Determining a first terminal of a normal login access type, collecting first system environment information of the first terminal within a preset period, and using the first system environment information as reference system environment information of a normal login environment type; and / or,

[0167] Determine a second terminal of an abnormal login access type, collect second system environment information of the second terminal within a preset period, and use the second system environment information as benchmark system environment information of the abnormal login environment type.

[0168] Optionally, the detection module 12 is configured to:

[0169] Determine a target login environment matching result corresponding to the abnormal login access type;

[0170] Inputting the target login environment matching result and target system environment information into a risk access control model, determining a target risk defense level for the target terminal through the risk access control model, and outputting the target risk defense level;

[0171] A target risk defense method corresponding to the target risk defense level is determined, and abnormal access control processing is performed on the target terminal using the target risk defense method.

[0172] Optionally, the detection module 12 is configured to:

[0173] If the target risk defense mode is a defense alarm mode, outputting abnormal access information for the target terminal to the system management end;

[0174] If the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

[0175] Optionally, the target system environment information includes at least one of screen resolution, human-computer input device characteristics, host name, user name, and login domain.

[0176] It should be noted that the login detection device provided in the above embodiment, when executing the login detection method, only uses the division of the above functional modules as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the login detection device provided in the above embodiment and the login detection method embodiment are based on the same concept. The implementation process is detailed in the method embodiment and will not be repeated here.

[0177] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0178] In an embodiment of the present application, after the service device determines that the target terminal account verification has passed based on the target account verification information, it obtains the target system environment information and the baseline system environment information of the target terminal, and performs risk login detection on the target terminal based on the target system environment information and the baseline system environment information, rather than directly granting device access rights after the account verification is passed. Risk login detection based on system environment information can prevent remote login attacks such as lateral penetration types, reduce login risks, reduce the success rate of ransomware delivery, and reduce data leakage and data loss losses on the service side.

[0179] The present application also provides a computer storage medium that can store multiple instructions, which are suitable for being loaded and executed by a processor as described above. Figures 1 to 3 The login detection method of the embodiment shown in the figure can be found in the specific execution process. Figures 1 to 3 The detailed description of the illustrated embodiment will not be repeated here.

[0180] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor as described above. Figures 1 to 3 The login detection method of the embodiment shown in the figure can be found in the specific execution process. Figures 1 to 3 The detailed description of the illustrated embodiment will not be repeated here.

[0181] Please refer to Figure 6 , which shows a block diagram of the structure of an electronic device provided by an exemplary embodiment of the present application. The electronic device in the present application may include one or more of the following components: a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, the memory 120, the input device 130, and the output device 140 may be connected via the bus 150.

[0182] The processor 110 may include one or more processing cores. The processor 110 utilizes various interfaces and circuits to connect various components within the electronic device. It executes instructions, programs, code sets, or instruction sets stored in the memory 120, as well as accesses data stored in the memory 120, to perform various functions of the electronic device 100 and process data. Optionally, the processor 110 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 110 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing display content; and the modem handles wireless communications. It is understood that the modem may not be integrated into the processor 110 and may be implemented separately via a communications chip.

[0183] The memory 120 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 120 includes a non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, codes, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The operating system may be an Android system, including a system deeply developed based on the Android system, an IOS system developed by Apple, including a system deeply developed based on the IOS system or other systems. The data storage area may also store data created by the electronic device during use, such as a phone book, audio and video data, chat record data, etc.

[0184] See also Figure 7As shown, the memory 120 can be divided into operating system space and user space. The operating system runs in the operating system space, and native and third-party applications run in the user space. In order to ensure that different third-party applications can achieve better operating results, the operating system allocates corresponding system resources to different third-party applications. However, the requirements for system resources in different application scenarios in the same third-party application are also different. For example, in the local resource loading scenario, the third-party application has higher requirements for disk reading speed; in the animation rendering scenario, the third-party application has higher requirements for GPU performance. The operating system and the third-party application are independent of each other, and the operating system often cannot perceive the current application scenario of the third-party application in a timely manner, resulting in the operating system being unable to perform targeted system resource adaptation according to the specific application scenario of the third-party application.

[0185] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to open up data communication between third-party applications and the operating system so that the operating system can obtain the current scenario information of third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.

[0186] Taking the Android operating system as an example, the programs and data stored in the memory 120 are as follows: Figure 8As shown, the memory 120 may store a Linux kernel layer 320, a system runtime library layer 340, an application framework layer 360, and an application layer 380. The Linux kernel layer 320, the system runtime library layer 340, and the application framework layer 360 belong to the operating system space, and the application layer 380 belongs to the user space. The Linux kernel layer 320 provides underlying drivers for various hardware components of electronic devices, such as display drivers, audio drivers, camera drivers, Bluetooth drivers, Wi-Fi drivers, power management, etc. The system runtime library layer 340 provides major feature support for the Android system through some C / C++ libraries. For example, the SQLite library provides database support, the OpenGL / ES library provides 3D drawing support, and the Webkit library provides browser kernel support. The system runtime library layer 340 also provides the Android runtime library (Android runtime), which mainly provides some core libraries that allow developers to write Android applications using the Java language. The application framework layer 360 provides various APIs that may be used when building applications. Developers can also use these APIs to build their own applications, such as activity management, window management, view management, notification management, content provider management, package management, call management, resource management, and location management. The application layer 380 runs at least one application. These applications can be native applications that come with the operating system, such as contacts, SMS, clock, and camera applications, or third-party applications developed by third-party developers, such as games, instant messaging programs, and photo enhancement programs.

[0187] Taking the operating system as the IOS system as an example, the programs and data stored in the memory 120 are as follows: Figure 9As shown, the IOS system includes: a core operating system layer 420 (Core OS layer), a core service layer 440 (Core Services layer), a media layer 460 (Media layer), and a touchable layer 480 (Cocoa Touch Layer). The core operating system layer 420 includes the operating system kernel, drivers, and underlying program frameworks. These underlying program frameworks provide functions closer to the hardware for use by the program framework located in the core service layer 440. The core service layer 440 provides system services and / or program frameworks required by applications, such as the foundation framework, account framework, advertising framework, data storage framework, network connection framework, geographic location framework, motion framework, etc. The media layer 460 provides applications with audio-visual interfaces, such as graphics and image-related interfaces, audio technology-related interfaces, video technology-related interfaces, and wireless playback (AirPlay) interfaces for audio and video transmission technologies. The touchable layer 480 provides various commonly used interface-related frameworks for application development. The touchable layer 480 is responsible for user touch interaction operations on electronic devices. For example, local notification service, remote push service, advertising framework, game tool framework, message user interface (UI) framework, user interface UIKit framework, map framework, etc.

[0188] exist Figure 9 Among the frameworks shown, those relevant to most applications include, but are not limited to, the Foundation framework in the core services layer 440 and the UIKit framework in the touchable layer 480. The Foundation framework provides many basic object classes and data types, offering fundamental system services for all applications and having nothing to do with the UI. The classes provided by the UIKit framework are the foundational UI class library for creating touch-based user interfaces. iOS applications can use the UIKit framework to provide their UIs, providing the application infrastructure for building user interfaces, drawing, handling user interaction events, responding to gestures, and so on.

[0189] Among them, the method and principle of implementing data communication between third-party applications and operating system in the IOS system can be referred to the Android system, and this application will not go into details here.

[0190] Among them, the input device 130 is used to receive input instructions or data, and the input device 130 includes but is not limited to a keyboard, a mouse, a camera, a microphone or a touch device. The output device 140 is used to output instructions or data, and the output device 140 includes but is not limited to a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined, and the input device 130 and the output device 140 are a touch screen display, which is used to receive touch operations on or near it by the user using any suitable object such as a finger or a touch pen, and to display the user interface of each application. The touch screen display is usually provided on the front panel of the electronic device. The touch screen display can be designed as a full screen, a curved screen or a special-shaped screen. The touch screen display can also be designed as a combination of a full screen and a curved screen, or a combination of a special-shaped screen and a curved screen, which is not limited in the embodiments of the present application.

[0191] In addition, those skilled in the art will understand that the structures of the electronic devices shown in the above figures do not limit the electronic devices. The electronic devices may include more or fewer components than shown, or may combine certain components, or arrange the components differently. For example, the electronic devices may also include radio frequency circuits, input units, sensors, audio circuits, wireless fidelity (WiFi) modules, power supplies, Bluetooth modules, and other components, which are not described in detail here.

[0192] In the embodiments of the present application, the execution subject of each step can be the electronic device described above. Optionally, the execution subject of each step is the operating system of the electronic device. The operating system can be an Android system, an iOS system, or other operating systems, which are not limited in the embodiments of the present application.

[0193] The electronic device of the embodiment of the present application may further be equipped with a display device, which may be any device capable of realizing a display function, such as a cathode ray tube display (CR), a light-emitting diode display (LED), an electronic ink screen, a liquid crystal display (LCD), a plasma display panel (PDP), etc. The user may use the display device on the electronic device 101 to view displayed text, images, videos and other information. The electronic device may be a smart phone, a tablet computer, a gaming device, an AR (Augmented Reality) device, a car, a data storage device, an audio playback device, a video playback device, a notebook, a desktop computing device, a wearable device such as an electronic watch, electronic glasses, an electronic helmet, an electronic bracelet, an electronic necklace, electronic clothing, and the like.

[0194] exist Figure 6 In the electronic device shown, the processor 110 may be configured to call an application stored in the memory 120 and specifically perform the following operations:

[0195] Determining that the target terminal account verification is successful based on the target account verification information, and obtaining target system environment information of the target terminal;

[0196] Obtain baseline system environment information, and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

[0197] In one embodiment, the processor 110 performs the following operations when performing the risk login detection on the target terminal based on the target system environment information and the baseline system environment information:

[0198] Performing environmental feature matching on the target system environment information and the reference system environment information to obtain a login environment matching result;

[0199] Perform risk login control processing on the target terminal based on the login environment matching result.

[0200] In one embodiment, when performing the risk login control process on the target terminal based on the login environment matching result, the processor 110 specifically performs the following operations:

[0201] Determining a baseline environment login type of the baseline system environment information;

[0202] Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

[0203] In one embodiment, the processor 110 performs the risk login control process on the target terminal based on the benchmark environment login type and the login environment matching result, including:

[0204] If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, the target terminal is determined to be an abnormal login access type;

[0205] If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, the target terminal is determined to be a normal login access type;

[0206] performing normal access control processing on the target terminal based on the normal login access type, or performing abnormal access control processing on the target terminal based on the abnormal login access type;

[0207] In one embodiment, before executing the step of obtaining the baseline system environment information, the processor 110 further includes:

[0208] Collecting historical system environment information of the target terminal within a preset period and using the historical system environment information as the baseline system environment information; and / or,

[0209] Determining a first terminal of a normal login access type, collecting first system environment information of the first terminal within a preset period, and using the first system environment information as reference system environment information of a normal login environment type; and / or,

[0210] Determine a second terminal of an abnormal login access type, collect second system environment information of the second terminal within a preset period, and use the second system environment information as benchmark system environment information of the abnormal login environment type.

[0211] In one embodiment, the processor 110, when performing the abnormal access control process on the target terminal based on the abnormal login access type, includes:

[0212] Determine a target login environment matching result corresponding to the abnormal login access type;

[0213] Inputting the target login environment matching result and target system environment information into a risk access control model, determining a target risk defense level for the target terminal through the risk access control model, and outputting the target risk defense level;

[0214] A target risk defense method corresponding to the target risk defense level is determined, and abnormal access control processing is performed on the target terminal using the target risk defense method.

[0215] In one embodiment, the processor 110, when executing the abnormal access control process on the target terminal using the target risk defense method, includes:

[0216] If the target risk defense mode is a defense alarm mode, outputting abnormal access information for the target terminal to the system management end;

[0217] If the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

[0218] In one embodiment, the target system environment information includes at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

[0219] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory, or a random access memory.

[0220] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.

Claims

1. A login detection method, characterized in that: The method comprises: Determining that the target terminal account verification is successful based on the target account verification information, and obtaining target system environment information of the target terminal; Obtain baseline system environment information, and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

2. The method according to claim 1, characterized in that The performing risk login detection on the target terminal based on the target system environment information and the benchmark system environment information includes: Performing environmental feature matching on the target system environment information and the reference system environment information to obtain a login environment matching result; Perform risk login control processing on the target terminal based on the login environment matching result.

3. The method according to claim 2, characterized in that The performing risk login control processing on the target terminal based on the login environment matching result includes: Determining a baseline environment login type of the baseline system environment information; Perform risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result.

4. The method according to claim 3, characterized in that The performing risk login control processing on the target terminal based on the benchmark environment login type and the login environment matching result includes: If the base environment login type is a normal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be a normal login access type; if the base environment login type is a normal login environment type and the login environment matching result is a result mismatch type, the target terminal is determined to be an abnormal login access type; If the base environment login type is an abnormal login environment type and the login environment matching result is a result matching type, the target terminal is determined to be an abnormal login access type; if the base environment login type is an abnormal login environment type and the login environment matching result is a normal matching type, the target terminal is determined to be a normal login access type; Normal access control processing is performed on the target terminal based on the normal login access type, or abnormal access control processing is performed on the target terminal based on the abnormal login access type.

5. The method according to claim 1 or 4, characterized in that Before obtaining the baseline system environment information, the method further includes: Collecting historical system environment information of the target terminal within a preset period and using the historical system environment information as the baseline system environment information; and / or, Determining a first terminal of a normal login access type, collecting first system environment information of the first terminal within a preset period, and using the first system environment information as reference system environment information of a normal login environment type; and / or, Determine a second terminal of an abnormal login access type, collect second system environment information of the second terminal within a preset period, and use the second system environment information as benchmark system environment information of the abnormal login environment type.

6. The method according to claim 4, characterized in that The performing abnormal access control processing on the target terminal based on the abnormal login access type includes: Determine a target login environment matching result corresponding to the abnormal login access type; Inputting the target login environment matching result and target system environment information into a risk access control model, determining a target risk defense level for the target terminal through the risk access control model, and outputting the target risk defense level; A target risk defense method corresponding to the target risk defense level is determined, and abnormal access control processing is performed on the target terminal using the target risk defense method.

7. The method according to claim 6, characterized in that The adopting the target risk defense method to perform abnormal access control processing on the target terminal includes: If the target risk defense mode is a defense alarm mode, outputting abnormal access information for the target terminal to the system management end; If the target risk defense mode is a defense blocking mode, the target terminal is blocked from accessing and logging in.

8. The method according to claim 1, characterized in that The target system environment information includes at least one of screen resolution, human-machine input device characteristics, host name, user name, and login domain.

9. A landing detection device, characterized in that: The device comprises: An acquisition module, configured to determine whether the target terminal account verification has passed based on the target account verification information, and acquire target system environment information of the target terminal; The detection module is used to obtain the baseline system environment information and perform risk login detection on the target terminal based on the target system environment information and the baseline system environment information.

10. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Abnormal login identification method and system, storage medium and electronic equipment

    CN108092975A

  • Account security verification method and system

    CN109753772A

  • User safety login method and device and terminal equipment

    CN112165379A

  • Mailbox login verification method and device and computer equipment

    CN112398787A

  • Flexible security control environment

    US20130125233A1