Information processing method, device, electronic device and computer-readable medium
By obtaining device and user information, determining device status and security information, and dynamically adjusting client permissions, the problem of users forging new mobile phone terminals to collect coupon transactions is solved, effective anti-fraud control is achieved, and corporate losses are avoided.
Patent Information
- Application Number
- CN202110736816.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-30
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2041-06-30
AI Technical Summary
Users forged new mobile phone terminals to collect coupons and trade in order to enjoy new user discounts, resulting in losses to the company.
By receiving information processing requests, obtaining device information and user information, determining the device aggregation status, operating environment and security information, and matching them with preset control rules, dynamically adjusting the client's application permissions, identifying fraudulent behavior in real time, and coordinating the client and server to make anti-fraud judgments.
Effectively prevent enterprises from suffering losses due to fraudulent activities, identify and respond to fraudulent activities through continuous monitoring and hierarchical control, dynamically adjust the anti-fraud control level, and achieve collaborative anti-fraud judgment between the client and the server.
Smart Images

Figure CN113450149B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, specifically to the field of automatic programming technology, and more particularly to an information processing method, device, electronic device, and computer-readable medium. Background Art
[0002] Currently, mobile apps for internet finance, e-commerce, and lifestyle services offer numerous coupons and promotions to attract users and boost daily activity. Users who redeem coupons can enjoy various discounts and offers. To maximize user access, apps are restricted, limiting users or devices to one coupon or one promotion. However, users inevitably resort to various methods to forge new mobile devices to redeem coupons or participate in promotions, resulting in losses for businesses.
[0003] During the implementation of this application, the inventors discovered that the prior art has at least the following problems:
[0004] Users forged new mobile phone terminals to collect coupons and trade in order to enjoy new user discounts, resulting in losses to the company. Summary of the Invention
[0005] In view of this, the embodiments of the present application provide an information processing method, device, electronic device and computer-readable medium, which can solve the problem that existing users forge new mobile phone terminals to obtain coupons and trade in order to enjoy new user discounts, resulting in loss of corporate profits.
[0006] To achieve the above objectives, according to one aspect of an embodiment of the present application, there is provided an information processing method, comprising:
[0007] Receive information processing requests and obtain device information and user information corresponding to the information processing requests;
[0008] Determine the device aggregation status based on device information and user information;
[0009] Based on the device information, determine the device operating environment and determine the device security information;
[0010] The device aggregation status, device operating environment and device security information are matched with the preset control rules, and then the client's application permissions are hierarchically controlled based on the matching results.
[0011] Optionally, receiving an information processing request includes:
[0012] The client's device information and user information are detected in real time. In response to determining that any one of the device information and user information is abnormal, an information processing task is generated and sent to the information processing task list.
[0013] Optionally, before receiving the information processing request, the method further includes:
[0014] Obtaining an information processing task list, and determining the execution time of each information processing task in the information processing task list;
[0015] In response to determining that the current time reaches one of the execution times, an information processing request is generated according to the information processing task corresponding to the arrived execution time.
[0016] Optionally, determining the device aggregation state based on the device information and the user information includes:
[0017] Obtain terminal network information, terminal security information, and terminal operation status information from device information;
[0018] Obtain user behavior information from the user information, and then determine the device aggregation status based on the terminal network information, terminal security information, terminal operation status information and user behavior information.
[0019] Optionally, determining a device aggregation state includes:
[0020] Determine the shared network based on the network address in the terminal network information;
[0021] Determine the terminal control state based on the debugging mode in the terminal security information;
[0022] Determine the terminal usage status based on the terminal operation status information and user behavior information;
[0023] The device aggregation state of terminals located in a shared network, whose terminal control state is unified controlled and whose usage state remains unchanged is determined as a terminal pool.
[0024] Optionally, determine the device operating environment, including:
[0025] Obtain positioning information, battery voltage, and gyroscope output information from the device information;
[0026] In response to determining that the positioning information, the battery voltage, and the output information of the gyroscope are unchanged, it is determined that the device operating environment is a simulator.
[0027] Optionally, determine device security information, including:
[0028] determining, based on the device information, whether the device corresponding to the device information has obtained root authority, and in response to determining that the device has obtained root authority, determining that the device security information indicates that the device has obtained root authority;
[0029] determining, based on the device information, whether the device corresponding to the device information has installed a preset application framework, and in response to determining that the preset application framework has been installed, determining that the device security information indicates that the preset application framework has been installed;
[0030] It is determined based on the device information whether the device corresponding to the device information has already started the debugging mode. In response to determining that the debugging mode has already been started, the device security information is determined to indicate that the debugging mode has already been started.
[0031] Optionally, the device aggregation status, device operating environment, and device security information are matched with preset control rules, and then the application permissions of the client are hierarchically controlled according to the matching results, including:
[0032] In response to determining that the device operating environment is a simulator, the device security information indicates that the root permission has been obtained, or the device security information indicates that a preset application framework has been installed, a pop-up window prompt is displayed, and the client terminates use;
[0033] In response to determining that the device aggregation state is a terminal pool, blocking the calling of the client's coupon transaction interface;
[0034] In response to determining that the device security information indicates that the debug mode has been enabled, determining the number of times the coupons have been received, and in response to determining that the number of times the coupons have been received is greater than a preset threshold, disabling the client's coupon transaction authority;
[0035] In response to determining that the device security information indicates that the debugging mode has been turned on, a coupon transaction is performed at a preset coupon transaction frequency.
[0036] In addition, the present application also provides an information processing device, comprising:
[0037] a receiving unit configured to receive an information processing request and obtain device information and user information corresponding to the information processing request;
[0038] a device aggregation state determining unit configured to determine a device aggregation state based on device information and user information;
[0039] an operating environment and security information determining unit, configured to determine a device operating environment and device security information based on the device information;
[0040] The hierarchical control unit is configured to match the device aggregation status, device operating environment and device security information with preset control rules, and then perform hierarchical control on the client's application permissions based on the matching results.
[0041] Optionally, the receiving unit is further configured to:
[0042] The client's device information and user information are detected in real time. In response to determining that any one of the device information and user information is abnormal, an information processing task is generated and sent to the information processing task list.
[0043] Optionally, the information processing apparatus further includes a request generating unit configured to:
[0044] Obtaining an information processing task list, and determining the execution time of each information processing task in the information processing task list;
[0045] In response to determining that the current time reaches one of the execution times, an information processing request is generated according to the information processing task corresponding to the arrived execution time.
[0046] Optionally, the device aggregation state determining unit is further configured to:
[0047] Obtain terminal network information, terminal security information, and terminal operation status information from device information;
[0048] Obtain user behavior information from the user information, and then determine the device aggregation status based on the terminal network information, terminal security information, terminal operation status information and user behavior information.
[0049] Optionally, the device aggregation state determining unit is further configured to:
[0050] Determine the shared network based on the network address in the terminal network information;
[0051] Determine the terminal control state based on the debugging mode in the terminal security information;
[0052] Determine the terminal usage status based on the terminal operation status information and user behavior information;
[0053] The device aggregation state of terminals located in a shared network, whose terminal control state is unified controlled and whose usage state remains unchanged is determined as a terminal pool.
[0054] Optionally, the operating environment and security information determination unit is further configured to:
[0055] Obtain positioning information, battery voltage, and gyroscope output information from the device information;
[0056] In response to determining that the positioning information, the battery voltage, and the output information of the gyroscope are unchanged, it is determined that the device operating environment is a simulator.
[0057] Optionally, the operating environment and security information determination unit is further configured to:
[0058] determining, based on the device information, whether the device corresponding to the device information has obtained root authority, and in response to determining that the device has obtained root authority, determining that the device security information indicates that the device has obtained root authority;
[0059] determining, based on the device information, whether the device corresponding to the device information has installed a preset application framework, and in response to determining that the preset application framework has been installed, determining that the device security information indicates that the preset application framework has been installed;
[0060] It is determined based on the device information whether the device corresponding to the device information has already started the debugging mode. In response to determining that the debugging mode has already been started, the device security information is determined to indicate that the debugging mode has already been started.
[0061] Optionally, the hierarchical control unit is further configured to:
[0062] In response to determining that the device operating environment is a simulator, the device security information indicates that the root permission has been obtained, or the device security information indicates that a preset application framework has been installed, a pop-up window prompt is displayed, and the client terminates use;
[0063] In response to determining that the device aggregation state is a terminal pool, blocking the calling of the client's coupon transaction interface;
[0064] In response to determining that the device security information indicates that the debug mode has been enabled, determining the number of times the coupons have been received, and in response to determining that the number of times the coupons have been received is greater than a preset threshold, disabling the client's coupon transaction authority;
[0065] In response to determining that the device security information indicates that the debugging mode has been turned on, a coupon transaction is performed at a preset coupon transaction frequency.
[0066] In addition, the present application also provides an information processing electronic device, comprising: one or more processors; a storage device for storing one or more programs, when the one or more programs are executed by one or more processors, the one or more processors implement the information processing method as described above.
[0067] In addition, the present application also provides a computer-readable medium on which a computer program is stored, and when the program is executed by a processor, the above-mentioned information processing method is implemented.
[0068] One embodiment of the above invention has the following advantages or beneficial effects: This application receives an information processing request and obtains the device information and user information corresponding to the information processing request; determines the device aggregation state based on the device information and user information; determines the device operating environment and device security information based on the device information; matches the device aggregation state, device operating environment, and device security information with preset control rules, and then performs hierarchical control on the client's application permissions based on the matching results. This allows for continuous monitoring, collection, and identification of user behavior, device information, and device status, and then adopts different response plans based on the identification results, thereby identifying fraudulent behavior in real time, dynamically adjusting the client's anti-fraud control level, and enabling the client and server to collaboratively perform anti-fraud judgments, thereby effectively preventing losses to the enterprise.
[0069] The further effects of the above-mentioned non-conventional optional manner will be described below in conjunction with specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] The accompanying drawings are provided to facilitate a better understanding of the present application and do not constitute an undue limitation on the present application.
[0071] Figure 1 is a schematic diagram of the main flow of the information processing method according to the first embodiment of the present application;
[0072] Figure 2 is a schematic diagram of the main process of the information processing method according to the second embodiment of the present application;
[0073] Figure 3 is a schematic diagram of an application scenario of the information processing method according to the third embodiment of the present application;
[0074] Figure 4 is a schematic diagram of main modules of an information processing device according to an embodiment of the present application;
[0075] Figure 5 is an exemplary system architecture diagram to which embodiments of the present application may be applied;
[0076] Figure 6 It is a structural diagram of a computer system of a terminal device or server suitable for implementing an embodiment of the present application. DETAILED DESCRIPTION
[0077] The following description of exemplary embodiments of the present application is made in conjunction with the accompanying drawings, including various details of the embodiments of the present application to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present application. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0078] Figure 1 is a schematic diagram of the main process of the information processing method according to the first embodiment of the present application, such as Figure 1 As shown, the information processing method includes:
[0079] Step S101: receiving an information processing request and obtaining device information and user information corresponding to the information processing request.
[0080] In this embodiment, the execution subject of the information processing method (for example, it can be a server) can receive the information processing request through a wired connection or a wireless connection. Specifically, the execution subject can receive from the client an information processing request generated and sent by the client based on the collected device information and user information. Of course, it is understandable that the execution subject can also receive the device information and user information collected by the client, and call the request generation unit to generate an information processing request based on the device information and user information, and send it to the receiving unit in the execution subject, and the receiving unit in the execution subject receives the information processing request generated by the request generation unit, and then performs information processing. This application does not limit the method of generating the information processing request.
[0081] Specifically, device information may include terminal network information, terminal firmware information, terminal security information, and terminal operating status information. Terminal network information may include network IP addresses, MAC addresses, and other information. Terminal firmware information may include the terminal device ID, baseband version information, manufacturer information, and system version number. Terminal security information may include Xposed installation status, ADB debugging mode enabled, root enabled, and VPN enabled. The terminal device ID on a mobile device refers to the IMEI. The IMEI (International Mobile Equipment Identity) is a unique identification number for mobile devices and varies from phone to phone. Xposed: An application framework running on Android devices. Its function is to affect program operation by modifying the operating status of the phone's system services or programs without modifying the app installation files, thereby modifying app functionality or removing certain restrictions. It is often used to implement certain custom features or crack apps. Root privilege is the highest privilege on an Android device. Rooting refers to gaining root privileges and taking over system ownership by exploiting various system vulnerabilities, replacing or adding the "su" program to the device's system directory. After rooting, the phone's system can be modified arbitrarily.
[0082] The user information may include terminal operation status information, specifically including positioning information, gyroscope output information, and device battery voltage and device battery temperature information.
[0083] In this embodiment, receiving an information processing request includes: real-time detection of the client's device information and user information, generating an information processing task in response to determining any abnormality in the device information and user information, and sending it to the information processing task list. For example, when the execution subject determines that there is an abnormality in the device information, it can be that the execution subject can determine based on the device information that the operating environment of the user device is a simulator or has obtained root permissions (i.e., it has been rooted) or has installed a preset application framework (such as Xposed) and other dangerous situations, then determine that the device information is abnormal. When the execution subject determines that there is an abnormality in the user information, it can be that the execution subject determines through a certain algorithm based on the status information of the gyroscope in the user information whether it is a normal user usage state or whether the device has always maintained a certain angle (such as being placed on a rack). If it has always maintained a certain angle, the execution subject can determine that the user information is abnormal.
[0084] The execution subject can generate an information processing task based on the abnormal information, set the task execution time, and then send it to the information processing task list.
[0085] Specifically, before receiving the information processing request, the method further includes:
[0086] Obtaining an information processing task list, and determining the execution time of each information processing task in the information processing task list;
[0087] In response to determining that the current time reaches one of the execution times, an information processing request is generated according to the information processing task corresponding to the arrived execution time.
[0088] Specifically, when the execution time of any information processing task in the information processing task list arrives, the execution subject may execute the information processing task, and then generate a corresponding information processing request for the receiving unit to receive and process the information processing request.
[0089] Step S102: Determine the device aggregation state based on the device information and user information.
[0090] Specifically, determining the device aggregation state based on the device information and user information includes:
[0091] Obtain terminal network information, terminal security information, and terminal operating status information from the device information. Obtain user behavior information from the user information, and then determine the device aggregation state based on the terminal network information, terminal security information, terminal operating status information, and user behavior information. Specifically, the aggregation state can be a terminal pool, such as a mobile phone pool, which can be a mobile phone pool composed of multiple mobile phones controlled by a unified terminal, which can be used to control the unified terminal to perform operations such as grabbing coupons and red envelopes.
[0092] Specifically, determining the device aggregation status includes:
[0093] Determine the shared network based on the network address in the terminal's network information. Determine the terminal's control status based on the debugging mode in the terminal's security information. Determine the terminal's usage status based on the terminal's operating status and user behavior information. A terminal pool is formed by aggregating the devices of all terminals in the shared network that are in a unified control state and have unchanged usage status.
[0094] That is to say, when there are multiple terminals located in the same shared network and are uniformly controlled, and the positioning data, gyroscope output data, battery voltage, and temperature data of the multiple terminals have not changed or the change amplitude is less than the preset threshold, the executing entity can determine that the multiple terminals are composed of a terminal pool that is gathered together in the form of a pool to facilitate unified coupon grabbing.
[0095] Step S103: Based on the device information, determine the device operating environment and device security information.
[0096] Specifically, determine the device operating environment, including:
[0097] Obtain the positioning information, battery voltage and gyroscope output information in the device information. In response to determining that the positioning information, battery voltage and gyroscope output information are unchanged, determine that the device operating environment is a simulator. That is to say, when the positioning information and the gyroscope status information in the terminal operating status information in the user information do not change or the change amplitude is less than a preset threshold (for example, it may include the positioning information change threshold corresponding to the positioning information and the spatial position angle change threshold corresponding to the gyroscope status information), the execution subject may determine that the device may have been placed on the rack; when the battery voltage in the terminal operating status information does not change or the change amplitude is less than the preset battery voltage change threshold, the execution subject may determine that the device operating environment may be a simulator.
[0098] Specifically, determine the device security information (device security information may include whether the device has Xposed installed, whether the device's adb debugging mode is turned on, whether VPN is turned on, and whether root is turned on), including:
[0099] Determine based on the device information whether the device corresponding to the device information has obtained root permissions (whether root is turned on). In response to determining that the root permissions have been obtained (root is turned on), determine that the device security information is that the root permissions have been obtained (root is turned on), indicating that the device is in a high-risk state, the user's device may have been cracked to obtain relevant information of the client App, or the device number has been modified. Determine based on the device information whether the device corresponding to the device information has installed the preset application framework. In response to determining that the preset application framework has been installed, determine that the device security information is that the preset application framework (Xposed framework) has been installed, indicating that the device is in a high-risk state, the user's device may have been cracked to obtain relevant information of the client App, or the device number has been modified. Determine based on the device information whether the device corresponding to the device information has turned on debugging mode. In response to determining that the debugging mode has been turned on, determine that the device security information is that the debugging mode has been turned on. The device may be controlled by the PC and may be a device in the mobile phone pool.
[0100] Step S104 , matching the device aggregation state, device operating environment and device security information with preset control rules, and then performing hierarchical control on the application permissions of the client according to the matching results.
[0101] Preset control rules may include: High Risk: Rooted or with the Xposed framework or a PC emulator installed. Medium Risk: Devices in a mobile phone pool or with VPN enabled. Low Risk: Devices with ADB debugging enabled. The execution entity can match the determined device aggregation status, device operating environment, and device security information against the preset control rules to determine whether the device on which the user's client is logged in is classified as high, medium, or low risk for anti-fraud purposes. Based on the determined high, medium, or low risk classification, the client's application permissions are then controlled in a tiered manner. For high-risk classification, control measures may include client usage restrictions; for medium-risk classification, restrictions on sending coupon redemption transactions; and for low-risk classification, flow control measures may include limiting the flow of coupon redemption transactions. For example, if the matching result indicates rooted, Xposed installed, or a PC emulator, the classification is high risk, and client usage restrictions are implemented. If the matching result indicates a mobile phone pool, the classification is medium risk, and flow control on sending coupon redemption transactions is implemented. If the matching result indicates ADB debugging is enabled, the matching result is low risk, and flow control on coupon redemption transactions is implemented.
[0102] This embodiment receives an information processing request and obtains the device information and user information corresponding to the information processing request; determines the device aggregation status based on the device information and user information; determines the device operating environment and device security information based on the device information; matches the device aggregation status, device operating environment, and device security information with preset control rules, and then performs hierarchical control on the client's application permissions based on the matching results. This allows for continuous monitoring, collection, and identification of user behavior, device information, and device status, and then adopts different response plans based on the identification results, thereby identifying fraudulent behavior in real time, dynamically adjusting the client's anti-fraud control level, and enabling the client and server to collaboratively perform anti-fraud judgments, thereby effectively preventing losses to the enterprise.
[0103] Figure 2 is a schematic diagram of the main flow of the information processing method according to the second embodiment of the present application, such as Figure 2 As shown, the information processing method includes:
[0104] Step S201: Receive an information processing request and obtain device information and user information corresponding to the information processing request.
[0105] Step S202: Determine the device aggregation state based on the device information and user information.
[0106] Step S203: Based on the device information, determine the device operating environment and device security information.
[0107] Step S204 : matching the device aggregation state, device operating environment, and device security information with preset control rules, and then performing hierarchical control on the application permissions of the client according to the matching results.
[0108] The principles of steps S201 to S204 are similar to those of steps S101 to S104 and will not be described in detail here.
[0109] Specifically, step S204 can also be implemented through steps S2041 to S2044:
[0110] In step S2041, in response to determining that the device operating environment is a simulator, the device security information indicates that the root permission has been obtained, or the device security information indicates that a preset application framework has been installed, a pop-up window prompt is displayed, and the client terminates the use.
[0111] Step S2042: In response to determining that the device aggregation state is a terminal pool, blocking the calling of the client's coupon transaction interface.
[0112] Step S2043: In response to determining that the device security information indicates that the debugging mode has been turned on, the number of times the coupons have been received is determined; in response to determining that the number of times the coupons have been received is greater than a preset threshold, the client's coupon transaction authority is closed.
[0113] Step S2044: In response to determining that the device security information indicates that the debugging mode has been turned on, the coupon transaction is performed at the preset coupon transaction frequency.
[0114] For example, if a device is rooted, has Xpose installed, or is a PC emulator, it is classified as high-risk, and the enforcement entity restricts users from opening the client. That is, when a user opens the client, a pop-up window displays an error message, prompting the user to terminate the client.
[0115] When the device is identified as a mobile phone pool device, or VPN is turned on for middleman packet capture, it is classified as medium risk. The execution entity blocks the call of the client's coupon transaction interface, restricts participation in activities, restricts users from receiving coupons, and does not send coupon transactions, but users can browse the page normally.
[0116] When a device is in ADB debugging mode, it may be a user using automated scripts to automatically grab coupons. This device is classified as low-risk. The execution entity limits the number of times a user can participate in an event, internally limits the frequency with which the user can claim additional coupons, and implements transaction throttling. When a device is classified as low-risk, even if a user frantically clicks the "Grab Coupons" button in the foreground, the transaction will only be sent after 5 seconds. This limits the frequency of user coupon redemption transactions and effectively prevents losses for the enterprise.
[0117] This embodiment continuously monitors, collects, and identifies user behavior, device information, and device status, and then adopts different response plans based on the identification results to identify fraudulent behavior in real time, dynamically adjust the client's anti-fraud control level, and achieve collaborative anti-fraud judgment between the client and the server, thereby effectively preventing enterprises from suffering losses.
[0118] Figure 3 This is a schematic diagram of an application scenario of the information processing method according to the third embodiment of the present application. The information processing method of the embodiment of the present application can be applied to scenarios where users use various means to forge new mobile phone terminals to receive coupons or participate in activities in order to enjoy the benefits of new users. Figure 3 As shown, when the server detects that the user has opened the client, it can call the device and user behavior collection service to collect terminal network information, terminal firmware information, terminal security information and terminal operation status information.
[0119] Specifically, the network information of the terminal may include network IP, MAC address, etc. The server can determine which terminals are in a shared network based on the network information of the terminal, analyze the aggregation status of the device, and further analyze and determine whether it is a mobile phone pool.
[0120] The terminal firmware information may include the terminal device number, baseband version information, manufacturer information, and system version number. The server can identify whether the terminal is a PC simulator based on the terminal firmware information.
[0121] Terminal security information can include Xposed installation, adb debugging mode enabled, root enabled, and VPN enabled. Xposed and rooting are high-risk, indicating the user's device may have been cracked to obtain app information, or the device ID may have been modified. If VPN is enabled, app interface packets may be captured; if adb debugging mode is enabled, the device may be controlled by a PC or may be in a mobile phone pool.
[0122] Terminal operating status information can include positioning information, gyroscope output, device battery voltage, and device battery temperature. Based on this gyroscope status information, the server can use algorithms to determine whether the device is being used normally or if it has been held at a constant angle (for example, placed in a rack). The device's battery voltage can also be used to determine whether it is a PC emulator or a normal mobile device.
[0123] Furthermore, the server can call the runtime environment security identification service to determine whether it meets the simulator characteristics, whether the device has been rooted, and whether the preset application framework has been installed. Specifically, the runtime environment security identification service can identify whether the terminal belongs to a PC simulator through the baseband version, system version, manufacturer information, etc. in the terminal firmware information. If it is a simulator, the reporting rules are triggered. The runtime environment security identification service can determine whether the device has been rooted, that is, whether it has been rooted. Rooted devices are at high risk, the client's information may be stolen, the device number may be tampered with, and thus trigger reporting rules. The runtime environment security identification service can determine whether the device has a preset application framework (such as the Xposed framework) installed. If so, the device is at high risk, the client's information may be stolen, and the device number may be tampered with, and thus trigger reporting rules.
[0124] If a device doesn't meet the simulator requirements, isn't rooted, and doesn't have the default application framework installed, the server can call the User Behavior Identification Service to collect gyroscope data over time, charting changes in the device's spatial position and angle. This allows the server to determine whether the device is being used by a normal user or is constantly on a desktop or rack. If there's any doubt, a reporting rule is triggered. Suspicion can mean the device's spatial position and angle haven't changed. The User Behavior Identification Service also collects battery voltage and temperature data. For PC simulators, the battery temperature and voltage remain constant for extended periods, while for normal mobile devices, the voltage and temperature change dynamically. If the battery voltage remains constant, a reporting rule is triggered. Furthermore, if a reporting rule is triggered, each service (including the Operating Environment Security Identification Service and the User Behavior Identification Service) reports this information to the server for further analysis. The server receives the reported information and continues to collect device and user behavior information from the client, performing both operating environment security identification and user behavior identification. The server can then call the coupon claim anti-fraud control service to determine device aggregation and historical login history, identifying clustered terminals, multiple users logging into the same terminal simultaneously, or the same user logging into different terminals. The coupon claim anti-fraud control service further evaluates the information and issues instructions and control rules to the client. The client, based on the instructions and rules issued by the coupon claim anti-fraud control service, determines whether the user's device matches the anti-fraud rules. Specifically, anti-fraud rules may include: A. High Risk: Restricts client access, preventing users from opening the client app. This applies to rooted devices, devices with Xpose installed, or devices running PC emulators. B. Medium Risk: Restricts coupon claim transactions, including restricting access to the coupon claim interface, limiting participation in events, and restricting users from claiming coupons. Rejecting coupon claim transactions and disabling the coupon claim interface, but users can browse the page normally. This applies to devices identified as mobile phone pool devices or devices with VPN enabled for man-in-the-middle packet capture. C. Low Risk: Limits coupon claim transactions, including limiting participation in events, internally limiting the frequency with which users can claim other coupons, and limiting the number of coupon claim transactions. This is suitable for users who are connected to ADB debug mode and may use automated scripts to automatically grab coupons. For example, even if a user quickly clicks the "Grab Coupon" button on the client frontend, the transaction will not be sent until 5 seconds later. If the user does not encounter the above anti-fraud rules, they can use the client to claim coupons and trade normally without restrictions. This implements detailed terminal device and user behavior collection methods; local terminal operating environment and user behavior identification; client and server collaborative anti-fraud judgment; and hierarchical user terminal device control methods.
[0125] Figure 4 Schematic diagram of the main modules of the information processing device according to the embodiment of the present application. Figure 4 As shown, the information processing apparatus includes a receiving unit 401 , a device aggregation state determining unit 402 , an operating environment and security information determining unit 403 , and a hierarchical control unit 404 .
[0126] The receiving unit 401 is configured to receive an information processing request and obtain device information and user information corresponding to the information processing request.
[0127] The device aggregation state determining unit 402 is configured to determine the device aggregation state according to the device information and the user information.
[0128] The operating environment and security information determining unit 403 is configured to determine the device operating environment and the device security information based on the device information.
[0129] The hierarchical control unit 404 is configured to match the device aggregation state, device operating environment and device security information with preset control rules, and then perform hierarchical control on the application permissions of the client according to the matching results.
[0130] In some embodiments, the receiving unit 401 is further configured to: detect the device information and user information of the client in real time, and in response to determining that any one of the device information and user information is abnormal, generate an information processing task and send it to the information processing task list.
[0131] In some embodiments, the information processing device also includes a request generation unit, which is configured to: obtain an information processing task list, determine the execution time of each information processing task in the information processing task list; in response to determining that the current time reaches one of the execution times, generate an information processing request according to the information processing task corresponding to the arrived execution time.
[0132] In some embodiments, the device aggregation status determination unit 402 is further configured to: obtain terminal network information, terminal security information and terminal operation status information in the device information; obtain user behavior information in the user information, and then determine the device aggregation status based on the terminal network information, terminal security information, terminal operation status information and user behavior information.
[0133] In some embodiments, the device aggregation status determination unit 402 is further configured to: determine a shared network based on the network address in the terminal network information; determine the terminal control status based on the debugging mode in the terminal security information; determine the terminal usage status based on the terminal operation status information and user behavior information; and determine the device aggregation status of each terminal located in the shared network, with a terminal control status of being uniformly controlled and an unchanged usage status, as a terminal pool.
[0134] In some embodiments, the operating environment and security information determination unit 403 is further configured to: obtain positioning information, battery voltage and gyroscope output information in the device information; in response to determining that the positioning information, battery voltage and gyroscope output information are unchanged, determine that the device operating environment is a simulator.
[0135] In some embodiments, the operating environment and security information determination unit 403 is further configured to: determine whether the device corresponding to the device information has obtained root authority based on the device information, and in response to determining that the root authority has been obtained, determine the device security information as having obtained root authority; determine whether the device corresponding to the device information has installed a preset application framework based on the device information, and in response to determining that the preset application framework has been installed, determine the device security information as having installed the preset application framework; determine whether the device corresponding to the device information has turned on debugging mode based on the device information, and in response to determining that the debugging mode has been turned on, determine the device security information as having turned on debugging mode.
[0136] In some embodiments, the hierarchical control unit 404 is further configured to: in response to determining that the device operating environment is a simulator, the device security information is that root permissions have been obtained, or the device security information is that a preset application framework has been installed, a pop-up window prompts that the client terminates use; in response to determining that the device aggregation state is a terminal pool, blocking the call of the client's coupon transaction interface; in response to determining that the device security information is that the debugging mode has been turned on, determining the number of coupons that have been received, and in response to determining that the number of coupons that have been received is greater than a preset threshold, closing the client's coupon transaction permission; in response to determining that the device security information is that the debugging mode has been turned on, performing coupon transactions at the preset coupon transaction frequency.
[0137] It should be noted that the information processing method and information processing device of this application have corresponding relationships in terms of specific implementation contents, so the repeated contents will not be described again.
[0138] Figure 5 An exemplary system architecture 500 is shown to which the information processing method or information processing apparatus according to the embodiments of the present application can be applied.
[0139] like Figure 5 As shown, system architecture 500 may include terminal devices 501, 502, 503, a network 504, and a server 505. Network 504 is used to provide a medium for communication links between terminal devices 501, 502, 503 and server 505. Network 504 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0140] Users can use terminal devices 501, 502, and 503 to interact with server 505 via network 504 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 501, 502, and 503, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0141] The terminal devices 501 , 502 , and 503 may be various electronic devices having an information processing screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0142] Server 505 can be a server that provides various services, such as a background management server that provides support for information processing requests submitted by users using terminal devices 501, 502, and 503 (for example only). The background management server can receive information processing requests, obtain device information and user information corresponding to the information processing requests; determine the device aggregation status based on the device information and user information; determine the device operating environment and device security information based on the device information; match the device aggregation status, device operating environment, and device security information with preset control rules, and then perform hierarchical control of the client's application permissions based on the matching results. This is achieved by continuously monitoring, collecting, and identifying user behavior, device information, and device status, and then taking different response plans based on the identification results, so as to identify fraudulent behavior in real time, dynamically adjust the client's anti-fraud control level, and achieve collaborative anti-fraud judgment between the client and the server, thereby effectively preventing the company from suffering losses.
[0143] It should be noted that the information processing method provided in the embodiment of the present application is generally executed by the server 505 , and accordingly, the information processing device is generally set in the server 505 .
[0144] It should be understood that Figure 5 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0145] Reference below Figure 6 , which shows a structural diagram of a computer system 600 of a terminal device suitable for implementing an embodiment of the present application. Figure 6 The terminal device shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0146] like Figure 6As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage unit 608 into a random access memory (RAM) 603. Various programs and data required for the operation of the computer system 600 are also stored in the RAM 603. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0147] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, and the like; an output section 607 including displays such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 608 including a hard disk; and a communication section 609 including a network interface card such as a LAN card or a modem. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 610 as needed, so that computer programs read therefrom can be installed into the storage section 608 as needed.
[0148] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from a removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-mentioned functions defined in the system of the present application are executed.
[0149] It should be noted that the computer-readable medium described in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. Computer-readable storage media can include, for example, but are not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. This propagated data signal can take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wireline, optical fiber cable, RF, or any suitable combination thereof.
[0150] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0151] The units involved in the embodiments described in this application can be implemented in software or hardware. The units described can also be set in a processor. For example, it can be described as follows: a processor includes a receiving unit, a device aggregation state determination unit, an operating environment and security information determination unit, and a hierarchical control unit. In some cases, the names of these units do not constitute limitations on the units themselves.
[0152] As another aspect, the present application also provides a computer-readable medium, which may be included in the device described in the above embodiment; or it may exist independently and not be assembled into the device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by a device, the device receives an information processing request and obtains device information and user information corresponding to the information processing request; determines the device aggregation state based on the device information and user information; determines the device operating environment and device security information based on the device information; matches the device aggregation state, device operating environment, and device security information with preset control rules, and then performs hierarchical control on the client's application permissions based on the matching results.
[0153] According to the technical solution of the embodiment of the present application, it is possible to continuously monitor, collect and identify user behavior, device information and device status, and then adopt different response plans based on the identification results, so as to identify fraudulent behavior in real time, dynamically adjust the anti-fraud control level of the client, and realize the collaborative anti-fraud judgment between the client and the server, thereby effectively avoiding losses to the enterprise.
[0154] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. An information processing method, characterized in that: include: Receive an information processing request, and obtain device information and user information corresponding to the information processing request; Determining a device aggregation state based on the device information and user information; Based on the device information, determine the device operating environment and determine device security information; The device aggregation state, the device operating environment and the device security information are matched with preset control rules, and then the application permissions of the client are hierarchically controlled according to the matching results, including: in response to determining that the device operating environment is a simulator, the device security information is that the root permission has been obtained, or the device security information is that the preset application framework has been installed, a pop-up window prompts, and the client terminates the use; in response to determining that the device aggregation state is a terminal pool, the client's coupon transaction interface is blocked from being called; in response to determining that the device security information is that the debugging mode has been turned on, the number of coupons that have been received is determined, and in response to determining that the number of coupons that have been received is greater than a preset threshold, the client's coupon transaction permission is closed; in response to determining that the device security information is that the debugging mode has been turned on, coupon transactions are performed at the preset coupon transaction frequency.
2. The method according to claim 1, characterized in that The receiving of the information processing request includes: The device information and user information of the client are detected in real time. In response to determining that any one of the device information and the user information is abnormal, an information processing task is generated and sent to the information processing task list.
3. The method according to claim 2, characterized in that Before receiving the information processing request, the method further includes: Obtaining the information processing task list, and determining the execution time of each information processing task in the information processing task list; In response to determining that the current time reaches one of the execution times, an information processing request is generated according to the information processing task corresponding to the arrived execution time.
4. The method according to claim 1, wherein The determining of the device aggregation state according to the device information and the user information includes: Obtain terminal network information, terminal security information, and terminal operation status information from the device information; Obtain user behavior information from the user information, and then determine the device aggregation state based on the terminal network information, terminal security information, terminal operation status information and user behavior information.
5. The method according to claim 4, characterized in that Determining the device aggregation state includes: Determining a shared network according to the network address in the terminal network information; Determining a terminal control state according to a debugging mode in the terminal security information; Determining a usage status of the terminal based on the terminal operation status information and the user behavior information; The device aggregation state of terminals located in the shared network, whose terminal control state is unified controlled and whose usage state is unchanged, is determined as a terminal pool.
6. The method according to claim 5, characterized in that Determining the device operating environment includes: Obtaining positioning information, battery voltage, and gyroscope output information from the device information; In response to determining that the positioning information, the battery voltage, and the output information of the gyroscope are unchanged, it is determined that the device operating environment is a simulator.
7. The method according to claim 6, characterized in that The determining of device security information includes: determining, based on the device information, whether the device corresponding to the device information has obtained root authority, and in response to determining that the device has obtained root authority, determining that the device security information indicates that the device has obtained root authority; determining, based on the device information, whether the device corresponding to the device information has installed a preset application framework, and in response to determining that the preset application framework has been installed, determining that the device security information indicates that the preset application framework has been installed; It is determined based on the device information whether the device corresponding to the device information has already started the debugging mode. In response to determining that the debugging mode has already been started, the device security information is determined to indicate that the debugging mode has already been started.
8. An information processing device, characterized in that include: a receiving unit configured to receive an information processing request and obtain device information and user information corresponding to the information processing request; a device aggregation state determining unit, configured to determine a device aggregation state based on the device information and user information; an operating environment and security information determining unit, configured to determine a device operating environment and device security information based on the device information; A hierarchical control unit is configured to match the device aggregation state, the device operating environment and the device security information with preset control rules, and then perform hierarchical control on the application permissions of the client according to the matching results, including: in response to determining that the device operating environment is a simulator, the device security information is that the root permission has been obtained, or the device security information is that a preset application framework has been installed, a pop-up window prompts that the client terminates use; in response to determining that the device aggregation state is a terminal pool, blocking the call of the client's coupon transaction interface; in response to determining that the device security information is that the debugging mode has been turned on, determining the number of coupons that have been received, and in response to determining that the number of coupons that have been received is greater than a preset threshold, closing the client's coupon transaction permission; in response to determining that the device security information is that the debugging mode has been turned on, performing coupon transactions at a preset coupon transaction frequency.
9. The device according to claim 8, characterized in that The receiving unit is further configured to: The device information and user information of the client are detected in real time. In response to determining that any one of the device information and the user information is abnormal, an information processing task is generated and sent to the information processing task list.
10. An information processing electronic device, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.
11. A computer-readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Equipment information processing method and device
CN111932269A