Account abnormal behavior detection method, device, electronic device and storage medium

By constructing the topological structure of account event groups and a two-round detection method, and utilizing variant association rule algorithms and trust calculations, the problem of difficulty in identifying abnormal accounts in existing technologies is solved, and high-accuracy abnormal behavior detection is achieved, which is suitable for multiple information security scenarios.

CN114117402BActive Publication Date: 2025-09-16SHANJIE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111382757.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-22
Publication Date
2025-09-16
Estimated Expiration
2041-11-22

AI Technical Summary

Technical Problem

Existing technologies make it difficult to effectively detect and identify abnormal account behavior, resulting in serious information security threats and hidden dangers, especially losses caused by data leaks and data system attacks.

Method used

By constructing the topological structure of account event groups, a two-round account abnormal behavior detection method is adopted. First, initial detection is performed based on the relationship between event nodes within the group, and then final detection is performed based on the relationship between groups. Abnormal behavior is identified using the variant association rule algorithm and trust calculation.

Benefits of technology

It improves the accuracy of detecting abnormal account behavior and can effectively identify abnormal accounts. It is suitable for multiple scenarios such as e-commerce websites, banks, medical consultations and corporate databases.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117402B_ABST
    Figure CN114117402B_ABST
Patent Text Reader

Abstract

The present application provides a method, device, electronic device and storage medium for detecting abnormal behavior of an account. The method for detecting abnormal behavior of an account of the present application includes: obtaining account behavior data to be processed; grouping the account behavior data according to the account information to which it belongs to obtain multiple different account event groups; constructing a topological structure of multiple different account event groups; based on the intra-group event node relationship information of each account event group in the topological structure, performing a first round of account abnormal behavior detection on the account behavior data to obtain an initial detection result; based on the inter-group relationship information and intra-group event node relationship information of multiple different account event groups in the topological structure, performing a second round of account abnormal behavior detection to obtain a final detection result. Therefore, the present application constructs a hierarchical topological structure based on a variant association rule algorithm, and performs two rounds of account abnormal behavior detection through the hierarchical topological structure, effectively detecting abnormal behavior of the account with high accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and more specifically, to a method, device, electronic device, and storage medium for detecting abnormal account behavior. Background Art

[0002] In the information age, especially with the rapid development of computer and network technologies, information systems are becoming increasingly widespread. This increasing diversity of information also places higher demands on information security. In recent years, countless businesses have suffered losses from data breaches, data system attacks, and other data security issues. Among these, the various hazards and hidden dangers posed by anomalous accounts pose a serious threat to the information security of both individual users and businesses. Therefore, detecting these anomalous accounts is a pressing technical challenge. Summary of the Invention

[0003] The purpose of the embodiments of the present application is to provide a method, device, electronic device and storage medium for detecting abnormal account behavior, so as to detect abnormal account behavior.

[0004] In a first aspect, the present application provides a method for detecting abnormal account behavior, including: obtaining account behavior data to be processed; grouping the account behavior data according to the account information to which it belongs to obtain multiple different account event groups, each account event group including at least one event record; marking each event record in the multiple different account event groups as an event node, and constructing a topological structure of multiple different account event groups; based on the intra-group event node relationship information of each account event group in the topological structure, performing a first round of account abnormal behavior detection on the account behavior data to obtain an initial detection result; based on the inter-group relationship information and intra-group event node relationship information of the multiple different account event groups in the topological structure, performing a second round of account abnormal behavior detection to obtain a final detection result.

[0005] In one embodiment, each event record in multiple different account event groups is marked as an event node, and a topological structure of the multiple different account event groups is constructed, including: marking each event record in the multiple different account event groups as an event node, and determining all field values in each event node and the field names corresponding to all field values respectively; classifying the field values of all event nodes in each account event group according to the field names, obtaining multiple different field name sets, and each field name set includes the field values of the same field name in the same account event group; based on the statistical result of the occurrence times of the same field values in each field name set, determining the sequence numbers of different field values in each field name set; determining the importance measurement value of each field name in each account event group as the occurrence times value of the field value with the first sequence number in each field name set; based on the importance measurement value of each field name in each account event group and the sequence numbers of the field values in each field name set, determining the coding value of each event node in each account event group; based on the coding values of each event node, according to the variant association rule algorithm, determining the dissimilarity between any two event nodes in each account event group; establishing an intra-group event node connection line between any two event nodes in each account event group with a dissimilarity lower than the first preset threshold; establishing an inter-group connection line between any two account event groups with the number of target field names greater than or equal to the preset number, where the target field name is the field name whose occurrence times ratio value of the field value with the first sequence number in its own field name set in the other's field name set exceeds the second preset threshold in any two account event groups; constructing a topological structure based on the intra-group event node connection line and the inter-group connection line.

[0006] In one embodiment, determining the dissimilarity between any two event nodes in each account event group includes: using the following formula to determine the dissimilarity between any two event nodes in each account event group:

[0007]

[0008] where node represents the coding value of the first event node, node' represents the coding value of the second event node, and Dissim(node, node') represents the dissimilarity between the first event node and the second event node; n represents the total number of bits of the event node coding value; i is an integer representing the number of bits of the event node coding value, and 1 ≤ i < n; x represents the dissimilarity between the coding value of the first event node and the coding value of the second event node at the i-th bit, and the calculation formula of x is as follows:

[0009]

[0010] where node i_code is the value representing the first event node code value at position i, node' i _code is the value representing the second event node code value at position i.

[0011] In one embodiment, a first round of abnormal account behavior detection is performed based on the intra-group event node relationship information in the topological structure to obtain initial detection results, including: extracting the connection situation of the intra-group event nodes as the intra-group event node relationship information; judging whether there is a first target event node without a connection; if there is a first target event node without a connection, then determining the first target event node as abnormal account behavior.

[0012] In one embodiment, a second round of account abnormal behavior detection is performed based on the inter-group relationship information and the intra-group event node relationship information in the topological structure to obtain a final detection result, including: determining the initial trust score of each event node based on the intra-group event node relationship information; extracting the inter-group connection situation as the inter-group relationship information; determining the final trust score of each event node based on the inter-group relationship information and the initial trust score of each event node; judging whether there is a second target event node whose final trust score is less than a third preset threshold; if there is a second target event node whose final trust score is less than the third preset threshold, the second target event node is determined to be account abnormal behavior.

[0013] In one embodiment, based on the inter-group relationship information and the initial trust scores of the event nodes, determining the final trust of each event node includes: using the following formula to determine the final trust of each event node:

[0014] Credibility' node =Credibility node +input;

[0015] Among them, node represents the event node to be tested; Credibility node Represents the initial trust score of the event node to be tested, Credibility' node Represents the final trust score of the event node to be tested, and input represents the control input, which is used as the update of the trust value of the event node to be tested. The calculation formula of input is as follows:

[0016]

[0017] in, represents the intra-group information received by the event node to be tested, f(node) represents the set of neighboring event nodes directly connected to the event node to be tested, and n represents the number of neighboring event nodes;

[0018] Indicates the neighbor group information received by the event node to be tested, F(node) indicates the set of neighbor groups directly connected to the account event group where the event node to be tested is located, and N indicates the number of neighbor groups; Credibility I Represents the group information of the account event group numbered I, which is a convex combination of the initial trust scores of all event nodes in the account event group numbered I. Credibility I The calculation formula is as follows:

[0019]

[0020] Among them, μ m represents the convex combination coefficient of the event node; M represents the number of event nodes in the account event group numbered I; Credibility m Represents the initial trust score of the mth event node in the account event group numbered 1.

[0021] In one embodiment, each event record in the account behavior data carries at least account information, operation type, device information, and operation time.

[0022] In the second aspect, the present application provides an account abnormal behavior detection device, including: an acquisition module, a grouping module, a construction module, an initial detection module and a final detection module, the acquisition module is used to obtain the account behavior data to be processed; the grouping module is used to group the account behavior data according to the account information to which it belongs, and obtain multiple different account event groups, each account event group including at least one event record; the construction module is used to mark each event record in the multiple different account event groups as an event node, and construct a topological structure of multiple different account event groups; the initial detection module is used to perform a first round of account abnormal behavior detection on the account behavior data based on the intra-group event node relationship information of each account event group in the topological structure, and obtain an initial detection result; the final detection module is used to perform a second round of account abnormal behavior detection based on the inter-group relationship information and intra-group event node relationship information of the multiple different account event groups in the topological structure, and obtain a final detection result.

[0023] In one embodiment, the construction module is further configured to: label each event record in multiple different account event groups as an event node, and determine all field values in each event node and the field names corresponding to all field values respectively; classify the field values of all event nodes in each account event group according to the field names, to obtain multiple different field name sets, where each field name set includes the field values with the same field name in the same account event group; determine the sequence numbers of different field values in each field name set based on the statistical results of the occurrence times of the same field values in each field name set; determine the importance measurement value of each field name in each account event group as the occurrence times value of the field value with the first sequence number in each field name set; determine the coding value of each event node in each account event group based on the importance measurement value of each field name in each account event group and the sequence numbers of the field values in each field name set; determine the dissimilarity between any two event nodes in each account event group according to the variant association rule algorithm based on the coding values of each event node; establish an intra-group event node connection between any two event nodes in each account event group with a dissimilarity lower than the first preset threshold; establish an inter-group connection between any two account event groups with the number of target field names greater than or equal to the preset number, where the target field name is a field name for which the proportion value of the occurrence times of the field value with the first sequence number in their respective field name sets in the other's field name set exceeds the second preset threshold; construct a topological structure based on the intra-group event node connections and the inter-group connections.

[0024] In one embodiment, the construction module is further configured to: determine the dissimilarity between any two event nodes in each account event group by using the following formula:

[0025]

[0026] where node represents the coding value of the first event node, node' represents the coding value of the second event node, Dissim(node, node') represents the dissimilarity between the first event node and the second event node; n represents the total number of bits of the event node coding value; i is an integer representing the number of bits of the event node coding value, and 1 ≤ i < n; x represents the dissimilarity between the first event node coding value and the second event node coding value at the i-th bit, and the calculation formula of x is as follows:

[0027]

[0028] where node i _code represents the value of the first event node coding value at the i-th bit, node' i _code represents the value of the second event node coding value at the i-th bit.

[0029] In one embodiment, the initial detection module is further used to: extract the connection status of event nodes within the group as the relationship information of event nodes within the group; determine whether there is a first target event node without a connection; if there is a first target event node without a connection, then determine the first target event node as abnormal account behavior.

[0030] In one embodiment, the final detection module is also used to: determine the initial trust score of each event node based on the relationship information of event nodes within the group; extract the situation of the connection between groups as the inter-group relationship information; determine the final trust score of each event node based on the inter-group relationship information and the initial trust score of each event node; determine whether there is a second target event node with a final trust score less than a third preset threshold; if there is a second target event node with a final trust score less than the third preset threshold, the second target event node is determined to be an abnormal account behavior.

[0031] In one embodiment, the final detection module is further configured to determine the final trustworthiness of each event node using the following formula:

[0032] Credibility' node =Credibility node +input;

[0033] Among them, node represents the event node to be tested; Credibility node Represents the initial trust score of the event node to be tested, Credibility' node Represents the final trust score of the event node to be tested, and input represents the control input, which is used as the update of the trust value of the event node to be tested. The calculation formula of input is as follows:

[0034]

[0035] in, represents the intra-group information received by the event node to be tested, f(node) represents the set of neighboring event nodes directly connected to the event node to be tested, and n represents the number of neighboring event nodes;

[0036] Indicates the neighbor group information received by the event node to be tested, F(node) indicates the set of neighbor groups directly connected to the account event group where the event node to be tested is located, and N indicates the number of neighbor groups; Credibility I Represents the group information of the account event group numbered I, which is a convex combination of the initial trust scores of all event nodes in the account event group numbered I. Credibility I The calculation formula is as follows:

[0037]

[0038] Among them, μ m represents the convex combination coefficient of the event node; M represents the number of event nodes in the account event group numbered I; Credibility m Represents the initial trust score of the mth event node in the account event group numbered 1.

[0039] In a third aspect, the present application provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing a method as described in any one of the aforementioned embodiments.

[0040] In a fourth aspect, the present application provides a non-transitory computer-readable storage medium, comprising: a program, which, when executed by an electronic device, enables the electronic device to execute any one of the methods in the aforementioned embodiments.

[0041] The account abnormal behavior detection method, device, electronic device and storage medium of the present application can perform two rounds of account abnormal behavior detection through a layered topology structure, effectively detect abnormal behavior of the account with high accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0043] Figure 1 This is a schematic structural diagram of an electronic device according to an embodiment of the present application.

[0044] Figure 2 This is a flowchart of a method for detecting abnormal account behavior according to an embodiment of the present application.

[0045] Figure 3 This is an embodiment of the present application. Figure 2 Detailed flowchart of step S130 in the corresponding embodiment.

[0046] Figure 4 This is a schematic diagram of a topological structure according to an embodiment of the present application.

[0047] Figure 5 This is an embodiment of the present application. Figure 2 Detailed flowchart of step S140 in the corresponding embodiment.

[0048] Figure 6 This is an embodiment of the present application. Figure 2 Detailed flowchart of step S150 in the corresponding embodiment.

[0049] Figure 7 This is a schematic diagram of the structure of an account abnormal behavior detection device according to an embodiment of the present application.

[0050] Icon: 100 - electronic device; 101 - bus; 102 - memory; 103 - processor; 400 - account abnormal behavior detection device; 410 - acquisition module; 420 - grouping module; 430 - construction module; 440 - initial detection module; 450 - final detection module. DETAILED DESCRIPTION

[0051] In the description of this application, the terms "first", "second", etc. are only used to distinguish the description and do not indicate the order of arrangement, nor can they be understood as indicating or implying relative importance.

[0052] In the description of this application, the terms "include", "comprising", etc. indicate the existence of the described features, integers, steps, operations, elements and / or components, but do not exclude the existence or addition of one or more other features, steps, operations, elements, components and / or their collections.

[0053] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0054] Please refer to Figure 1 , which is a structural diagram of an electronic device 100 according to an embodiment of the present application. The electronic device 100 includes: at least one processor 103 and a memory 102, Figure 1 In the embodiment, a processor 103 is used as an example. The processor 103 and the memory 102 are connected via a bus 101. The memory 102 stores instructions executable by the processor 103. The instructions are executed by the processor 103 so that the electronic device 100 can execute all or part of the process of the method in the following embodiment to detect abnormal behavior of an account.

[0055] The electronic device 100 may be a mobile phone, a laptop computer, a desktop computer, or a computing system composed of multiple computers. Figure 1 More or fewer components than shown, or with Figure 1 For example, the electronic device 100 further includes input and output devices for human-computer interaction.

[0056] In one embodiment, the processor 103 may be a general-purpose processor, including but not limited to a central processing unit (CPU), a network processor (NP), etc., and may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc. The processor 103 is the control center of the electronic device 100, and uses various interfaces and lines to connect various parts of the entire electronic device 100. The processor 103 may implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application.

[0057] In one embodiment, the memory 102 can be implemented by any type of volatile or non-volatile memory device or a combination thereof, including but not limited to random access memory (RAM), read-only memory (ROM), static random access memory (SRAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), and electrically erasable programmable read-only memory (EEPROM).

[0058] Please refer to Figure 2 , which is a flow chart of a method for detecting abnormal account behavior according to an embodiment of the present application. Figure 1 The electronic device 100 shown is executed to detect abnormal behavior of an account. The method includes the following steps: Step S110 to Step S150.

[0059] Step S110: Obtain account behavior data to be processed.

[0060] The source of the account behavior data to be processed in this step can be actual business event log records, including one or more event records representing account behavior. Each event record in the account behavior data contains at least account information, operation type, device information, and operation time. The device information can be client or server information, for example, the user's login device.

[0061] Step S120: Group the account behavior data according to the account information to obtain multiple different account event groups.

[0062] The account information in this step may be a user name. Each account event group includes at least one event record.

[0063] Step S130: Mark each event record in the multiple different account event groups as an event node, and construct a topological structure of the multiple different account event groups.

[0064] This step constructs a hierarchical topology by analyzing the relationships between the event nodes in each account event group, as well as the relationships between multiple different account event groups. This structure is used to represent the relationships between the event records in the account behavior data to be processed, which facilitates the two rounds of account abnormal behavior detection in steps S140 and S150.

[0065] Step S140: Based on the intra-group event node relationship information of each account event group in the topological structure, a first round of account abnormal behavior detection is performed on the account behavior data to obtain an initial detection result.

[0066] The event node relationship information within each account event group in the topology structure represents the relationship between each user's behaviors. This information can be used to determine which of all event nodes within this account event group are normal operations of the user and which are abnormal operations of the user, and thus serve as the basis for the first round of account abnormal behavior detection.

[0067] Step S150: Based on the inter-group relationship information and intra-group event node relationship information of multiple different account event groups in the topological structure, a second round of account abnormal behavior detection is performed to obtain a final detection result.

[0068] Because a user's behavior is not only affected by the behavior of other users, but also by other users, the second round of account abnormal behavior detection considers the user's usual behavior while also considering the impact of other users on the user.

[0069] Among them, the inter-group relationship information of multiple different account event groups in the topological structure represents the relationship between the behaviors of each user, which can serve as one of the bases for the second round of account abnormal behavior detection.

[0070] It should be noted that the first round of abnormal account behavior detection and the second round of abnormal account behavior detection can be performed in parallel or in a progressive manner. "Parallel" means the same detection targets are used in both rounds, while "progressive" means different detection targets are used in both rounds. In this embodiment, the first round of abnormal account behavior detection and the second round of abnormal account behavior detection are performed in a progressive manner. The second round of abnormal account behavior detection targets account behaviors that initially appear normal after the first round of abnormal account behavior detection. This configuration allows the second round of abnormal account behavior detection to address any gaps in the first round, thereby improving the accuracy of abnormal account behavior detection.

[0071] In summary, this application can effectively screen out abnormal account behavior with high accuracy through two rounds of abnormal account behavior detection in steps S140 and S150. Furthermore, this method has a wide range of applications and can be applied to scenarios such as e-commerce websites, banks, medical consultations, accounting approval and bookkeeping, or corporate databases.

[0072] Please refer to Figure 3 , which is shown in an embodiment of the present application Figure 2 Please refer to the detailed flow chart of step S130 in the corresponding embodiment. Figure 4 , which is a schematic diagram of the topological structure shown in an embodiment of the present application. Figure 1 The electronic device 100 shown in FIG. 1 is used for execution. Step S130 includes the following steps: Step S131 to Step S139.

[0073] Step S131: Mark each event record in a plurality of different account event groups as an event node, and determine all field values ​​in each event node and the field names corresponding to all field values.

[0074] In this step, the account event group can be used Figure 4 The big circle in the middle indicates that the events are grouped according to the account information in step S120, namely account event group A, account event group B and account event group C. An account event group can include one or more event records. Event nodes can be used Figure 4 The small circle in the big circle represents the event node, and the number in the small circle can represent the encoding value of this event node.

[0075] Wherein, an event node includes multiple field values, and each field value may correspond to a different field name. In another embodiment, an event node includes multiple fields consisting of a field value and a field name.

[0076] In database application scenarios, an event node is an operation information. For example, "Account A logged in with the first IP address at 10:30." This event node has two field values, "10:30" and "First IP Address." The field names of these two field values ​​are login time and login address, respectively.

[0077] Step S132: Classify the field values ​​of all event nodes in each account event group according to the field name to obtain multiple different field name sets.

[0078] In this step, each field name set includes the field values ​​of the same field name in the same account event group. In the field name set, the same field values ​​can be deduplicated and the number of occurrences is recorded.

[0079] Continuing with the above example: in the field name set (pro_set set) whose field name is login time in account event group A, the field values ​​of the field name of login time contained in different event nodes in account event group A are stored, such as "09:30", "10:30", "02:30", etc.

[0080] In the field name set whose field name is login address in account event group A, field values ​​whose field name is login address contained in different event nodes in account event group A, such as "first IP address" and "second IP address", are stored.

[0081] Step S133: Based on the statistical result of the number of occurrences of the same field value in each field name set, determine the sequence numbers of different field values ​​in each field name set.

[0082] Continuing with the above example: In account event group A, in the field name set of login time, the field value "09:30" appears 10 times, the field value "10:30" appears 7 times, and the field value "02:30" appears 1 time. Then, in this field name set of login time, the sequence number of the field value "09:30" is 1, the sequence number of the field value "10:30" is 2, and the sequence number of the field value "02:30" is 3. The sequence numbers are accumulated in sequence, and the maximum value of the sequence number is limited to 9.

[0083] In account event group A, in the field name set of the login address, the field value "First IP Address" appears 11 times, and the field value "Second IP Address" appears 7 times. In the field name set of this login time, the sequence number of the field value "First IP Address" is 1, and the sequence number of the field value "Second IP Address" is 2. The sequence numbers are accumulated in sequence, and the maximum value is limited to 9.

[0084] It should be noted that the maximum value of the sequence number is limited to 9, which means: assuming there are 11 field values ​​in the field name set, the sequence numbers of the first 8 field values ​​are 1-8, and the sequence numbers of the 9th, 10th, and 11th field values ​​are all 9.

[0085] Step S134: Determine the importance metric value of each field name in each account event group as the occurrence count value of the first field value in each field name set.

[0086] Continuing with the above example: in the field name set of login time, the field value "09:30" appears the most times and is ranked first. The importance measure of this login time field name is the number of times the field value "09:30" appears, which is 10 times.

[0087] In the field name set of the login address, the field value "first IP address" appears the most times and is ranked first. The importance measurement value of the field name of the login time is the number of times the field value "first IP address" appears, which is 11 times.

[0088] Step S135: Determine the encoding value of each event node in each account event group based on the importance measurement value of each field name in each account event group and the sequence number of the field value in each field name set.

[0089] In this step, the coded value of each event node is composed of the serial number of each field value in each event node in the corresponding field name set, where the number of digits (order) of each serial number in the coded value is determined by the importance measure of each field name.

[0090] Continuing with the above example: for this account event group, the importance metric value of the field name "login address" is 11 times greater than the importance metric value of the field name "login time" is 10 times, so the field value sequence number of the field name "login address" should be ranked before the field value sequence number of the field name "login time".

[0091] For this event node "Account A logged in with the first IP address at 10:30", the field value "10:30" is numbered 2 in the field name set of login time, and the field value "first IP address" is numbered 1 in the field name set of login address. The field value sequence number of the field name "login address" must be arranged before the field value sequence number of the field name "login time". Finally, it can be determined that the encoding value of this event node is 12.

[0092] In summary, the number of digits of the encoding value of an event node can represent the number of field names corresponding to all field values in this event node. For example, the encoding value "12" indicates that this event node has two field names. The field name represented by the tens digit is more important than the field name represented by the units digit. In addition, the smaller the numerical value of the encoding value, the more times it appears, and the more conventional this event node is.

[0093] It should be noted that if the importance measurement values of two field names are equal, the sequence numbers corresponding to these two field names can be sorted according to the rules input by the user or the computer default.

[0094] Step S136: Based on the encoding values of each event node, according to the variant association rule algorithm, determine the dissimilarity between any two event nodes in each account event group.

[0095] In the prior art, the association rule algorithm can be used to obtain the frequent item sets of event records through iteration. In this embodiment, the variant association rule algorithm is adopted. Instead of directly obtaining the frequent item sets of users, the dissimilarity of the encoding values of each event node is calculated for any node pair in the group according to a certain rule. Then, in step S136, the event nodes with dissimilarity values lower than a certain threshold are connected. Those event nodes that are connected together will overlap greatly with the frequent item sets statistically obtained by the association rule algorithm in the prior art. Therefore, this embodiment can find the frequent item sets of users through the variant association rule algorithm, and the accuracy is high.

[0096] In one embodiment, the following formula is used to determine the dissimilarity between any two event nodes in each account event group:

[0097]

[0098] Among them, node represents the encoding value of the first event node, node' represents the encoding value of the second event node, Dissim(node, node') represents the dissimilarity between the first event node and the second event node; n represents the total number of digits of the event node encoding value; i is an integer representing the number of digits of the event node encoding value, and 1 ≤ i < n; x represents the dissimilarity between the encoding value of the first event node and the encoding value of the second event node at the i-th position. The calculation formula of x is as follows:

[0099]

[0100] Among them, node i _code represents the numerical value of the encoding value of the first event node at the i-th position, node' i _code represents the numerical value of the encoding value of the second event node at the i-th position.

[0101] Step S137: establishing an intra-group event node connection between any two event nodes in each account event group whose dissimilarity is lower than a first preset threshold.

[0102] Since dissimilarity is a numerical measure of the degree of difference between two event nodes, the higher the similarity between the two event nodes, the lower the dissimilarity. In this step, a line is connected between the two event nodes below the first preset threshold, thereby representing the frequent itemsets of the user's frequent operations corresponding to the account event group, which serves as the basis for the first round of account abnormal behavior detection.

[0103] Step S138: Establish an inter-group connection between any two of the account event groups having a number of target field names greater than or equal to a preset number, wherein the target field name is a field name whose number of occurrence ratios of the first field value in each of the two account event groups in their respective field name sets exceeds a second preset threshold in the other party's field name set.

[0104] The occurrence count of all field values ​​in each event node in each account event group can be used to represent the user's behavioral logic. Therefore, the ratio of the field value's occurrence count to the corresponding field name set can also be used to calculate the behavioral impact between two different users. If the field names of two users that meet the preset conditions are the same or roughly similar, it can be said that the two users are related to each other and have similar behavioral logic. The behaviors of the two users can influence and relate to each other, which can serve as one of the bases for the second round of account abnormal behavior detection.

[0105] Specifically, step S138 includes the following steps: Step S13801: Obtain the importance metric value of one of the field names P in the first account event group and the first field value x in the set of field names P in the first account event group.

[0106] Step S13802: Determine the occurrence ratio of the field value x in the set of field names P in the second account event group.

[0107] Step S13803: Determine whether the occurrence ratio value obtained in step S13802 is greater than a second preset threshold. If so, proceed to step S13804. If not, determine that the field name p is not the target field name. The second preset threshold can be user input or computer default.

[0108] Step S13804: Obtain the importance metric of the same field name P as in step S13801 in the second account event group and the first field value y in the set of field names P in the second account event group. The field value y and the field value X may be the same or different.

[0109] Step S13805: Determine the occurrence ratio of the field value y in the set of field names P of the first account event group.

[0110] Step S13806: Determine whether an occurrence ratio value obtained in step S13805 is greater than a second preset threshold value. If so, determine that the field name p is the target field name; if not, determine that the field name p is not the target field name.

[0111] Step S13807: Repeat steps S13801 to S13806 to judge all field names corresponding to all event nodes appearing in the two account event groups to find all target field names.

[0112] Step S13808 counts the target field names found in step S13807, determines whether the number of target field names is greater than or equal to a preset number, and then connects two account event groups whose number is greater than or equal to the preset number. The preset number can be user-entered or computer-default, and can be half of the total number of different field names in the two account event groups. Only when more than half of the field names meet the requirements of steps S13801-S13807 do the behaviors of the two account event groups indicate a certain correlation.

[0113] Step S139: construct a topology structure based on the intra-group event node connections and the inter-group connections.

[0114] The hierarchical topology of this step can be as follows Figure 4 shown.

[0115] Another example of steps S131 to S139 is given below.

[0116] Assume that the account behavior data to be processed obtained in step S110 is a database audit log table as shown below:

[0117]

[0118]

[0119] As can be seen from the above table: there are a total of 2 account event groups. Each node contains the field values ​​corresponding to the 6 field names of account name, login status, login time, access IP, operation type and operation time. For example, an event node can be recorded as "A1 Success Other IP2 Check Afternoon". When parsing the field names of the event nodes, it can be parsed according to the recorded field value order.

[0120] For account A1, the set corresponding to the field name Login is pro_set = (Success, Access, Failure). In A1, Success appears once, Failure appears once, and Access appears twice. Therefore, the set corresponding to the field name Login of A1 is pro_set = (Access, Success, Failure), and the importance metric is 2.

[0121] Similarly, for the set pro_set=(Ip1, Ip3) corresponding to the field name IP of A1, the importance measurement value is 3.

[0122] For the set pro_set = ('morning', 'other', 'afternoon') corresponding to the field name Login_time of A1, the importance measurement value is 3. It should be noted that the computer may default a certain time period to morning, another time period to afternoon, and another time period to other.

[0123] For the set pro_set=(Update, Check, Delete, Add) corresponding to the field name Type of A1, the importance measurement value is 2.

[0124] For the set pro_set=('morning', 'other', 'afternoon') corresponding to the field name Request_time of A1, the importance measurement value is 2.

[0125] In summary, after ranking each field name by importance using its importance metric, the resulting field names are IP, Login_time, Login, Type, and Request-time. The encoding is done in this order, corresponding to 5 bits. When considering the encoding values, the "Account Name" field name can be temporarily ignored.

[0126] For example, for the event node: "A1 Success Other IP2 Check Afternoon", its coding value is 32223. It should be noted that if the importance measurement values ​​of two field names are equal, the serial number sorting corresponding to the two field names can be sorted according to the user input or the computer default rules. It should be noted that under normal circumstances, the field values ​​contained in the field name set pro_set should be content that has appeared. The above is an example, and there are fewer field values ​​in the set. Among them, for the field name IP, only IP1-IP4 appear in the example here; there are a total of 4 different IPs, but if more than 10 appear in reality, there will be more than 10 IPs in the field name set. At this time, the IP addresses that are 9th or later in the set are all encoded as 9.

[0127] When establishing an inter-group connection, the target field name is determined using Login_time as an example. The importance metric for A1's Login_time field is 3, and its first field value is "morning." Next, it is determined that "morning" appears 0 times in A2's Login_time field set, and its occurrence ratio in A2's Login_time field set is 0. Since this occurrence ratio is less than the second preset threshold, Login_time is not the target field name.

[0128] It should be noted that since the field values ​​in the Login_time set and the Request_time set in the above table overlap, when determining the target field name, it is necessary to find the corresponding field name set when calculating the occurrence ratio value.

[0129] Please refer to Figure 5 , which is shown in an embodiment of the present application Figure 2 The detailed flow chart of step S140 in the corresponding embodiment is shown below. Figure 1 The electronic device 100 shown in FIG. 1 is used for execution. Step S140 includes the following steps: Step S141 to Step S144.

[0130] Step S141: extracting the connection between event nodes within the group as the relationship information between event nodes within the group.

[0131] The connection status of the event nodes within the group in this step includes the connection status of each event node in the same account event group: for example, whether the event node is connected and the number of connections of the event node.

[0132] Step S142: Determine whether there is a first target event node without a connection.

[0133] Since the connected event nodes can be approximated as the frequent item sets of the user corresponding to the account event group, and can also be regarded as the regular operations of this user, the event nodes that are not connected together are directly identified as abnormal behaviors of the user.

[0134] Therefore, this step can perform the first round of account abnormal behavior detection by determining whether there is an unconnected first target event node. If there is an unconnected first target event node, step S143 is executed; if there is no unconnected first target event node, step S144 is executed.

[0135] Step S143: Determine the first target event node as abnormal account behavior.

[0136] Step S144: All event nodes in the account event group are determined to be normal account behaviors.

[0137] Among them, steps S141 to S144 are the first round of account abnormal behavior detection for an account event group. After detecting an account event group, steps S141 to S144 can be repeatedly executed to detect all account event groups in sequence.

[0138] Please refer to Figure 6 , which is shown in an embodiment of the present application Figure 2 The detailed flow chart of step S150 in the corresponding embodiment is shown below. Figure 1 The electronic device 100 shown in FIG. 1 is used for execution. Step S150 includes the following steps: Step S151 to Step S156.

[0139] Step S151: Determine the initial trust score of each event node based on the relationship information of the event nodes within the group.

[0140] Based on the relationship information of event nodes within the group, the number of connections to each event node can be determined. Based on the number of connections to each event node, the initial trust score of each event node can be determined. The basic scoring logic is: the more other event nodes an event node is connected to, the more trusted it is, and the higher the initial trust score; the fewer other event nodes an event node is connected to, the less trusted it is, and the lower the initial trust score.

[0141] Step S152: extracting the inter-group connection information as the inter-group relationship information.

[0142] The inter-group connection status in this step includes the connection status of each account event group: for example, whether the account event group is connected and the number of connections of the account event group.

[0143] Step S153: Based on the inter-group relationship information and the initial trust score of each event node, determine the final trust score of each event node.

[0144] This step adds a control input based on the initial trust score of each event node. The control input includes information about the relationship between event nodes within a group and between groups. This allows us to consider the influence of other users on the user in addition to the user's usual behavior, thereby improving the accuracy of the second round of account abnormal behavior detection.

[0145] Among them, two directly connected event nodes in the same group are called neighbor event nodes.

[0146] In one embodiment, the following formula is used to determine the final trust level of each event node:

[0147] Credibility' node=Credibility node +input;

[0148] Among them, node represents the event node to be tested; Credibility node Represents the initial trust score of the event node to be tested, Credibility' node Represents the final trust score of the event node to be tested, and input represents the control input, which is used as the update of the trust value of the event node to be tested. The calculation formula of input is as follows:

[0149]

[0150] in, represents the intra-group information received by the event node to be tested, f(node) represents the set of neighboring event nodes directly connected to the event node to be tested, and n represents the number of neighboring event nodes;

[0151] Indicates the neighbor group information received by the event node to be tested, F(node) indicates the set of neighbor groups directly connected to the account event group where the event node to be tested is located, and N indicates the number of neighbor groups; Credibility I Represents the group information of the account event group numbered I, which is a convex combination of the initial trust scores of all event nodes in the account event group numbered I. Credibility I The calculation formula is as follows:

[0152]

[0153] Among them, μ m represents the convex combination coefficient of the event node; M represents the number of event nodes in the account event group numbered I; Credibility m Represents the initial trust score of the mth event node in the account event group numbered 1.

[0154] Step S154: Determine whether there is a second target event node whose final trust score is less than a third preset threshold.

[0155] Therefore, this step can perform a second round of account abnormal behavior detection by determining whether there is a second target event node whose final trust score is less than the third preset threshold. If there is a second target event node whose final trust score is less than the third preset threshold, execute step S155; if there is no second target event node whose final trust score is less than the third preset threshold, execute step S156.

[0156] Step S155: If there is a second target event node whose final trust score is less than the third preset threshold, the second target event node is determined to be an abnormal account behavior.

[0157] Step S156: Determine all event nodes in the account event group as normal account behavior.

[0158] Please refer to Figure 7 , which is a structural diagram of an account abnormal behavior detection device 400 shown in an embodiment of the present application. The device can be applied to Figure 1 In the electronic device 100 shown, the account abnormal behavior detection device 400 includes: an acquisition module 410, a grouping module 420, a construction module 430, an initial detection module 440 and a final detection module 450.

[0159] Among them, the principle relationship of each module is as follows: the acquisition module 410 is used to obtain the account behavior data to be processed; the grouping module 420 is used to group the account behavior data according to the account information to which it belongs, and obtain multiple different account event groups, each account event group including at least one event record; the construction module 430 is used to mark each event record in multiple different account event groups as an event node, and construct a topological structure of multiple different account event groups; the initial detection module 440 is used to perform a first round of account abnormal behavior detection on the account behavior data based on the intra-group event node relationship information of each account event group in the topological structure, and obtain an initial detection result; the final detection module 450 is used to perform a second round of account abnormal behavior detection based on the inter-group relationship information and intra-group event node relationship information of multiple different account event groups in the topological structure, and obtain a final detection result.

[0160] In one embodiment, the construction module 430 is further configured to: mark each event record in multiple different account event groups as an event node, and determine all field values in each event node and the field names corresponding to all field values respectively; classify the field values of all event nodes in each account event group according to the field names, obtaining multiple different field name sets, where each field name set includes the field values of the same field name in the same account event group; based on the statistical result of the occurrence times of the same field values in each field name set, determine the sequence numbers of different field values in each field name set; determine the importance measurement value of each field name in each account event group as the occurrence times value of the field value with the first sequence number in each field name set; based on the importance measurement values of each field name in each account event group and the sequence numbers of the field values in each field name set, determine the coding values of each event node in each account event group; based on the coding values of each event node, according to the variant association rule algorithm, determine the dissimilarity between any two event nodes in each account event group; establish an intra-group event node connection line between any two event nodes in each account event group with a dissimilarity lower than the first preset threshold; establish an inter-group connection line between any two account event groups with the number of target field names greater than or equal to the preset number, where the target field name is the field name whose proportion of the occurrence times of the field value with the first sequence number in its own field name set in the other field name set exceeds the second preset threshold in any two account event groups; construct a topological structure based on the intra-group event node connection lines and the inter-group connection lines.

[0161] In one embodiment, the construction module 430 is further configured to: determine the dissimilarity between any two event nodes in each account event group by using the following formula:

[0162]

[0163] where node represents the coding value of the first event node, node' represents the coding value of the second event node, Dissim(node, node') represents the dissimilarity between the first event node and the second event node; n represents the total number of digits of the event node coding value; i is an integer representing the number of digits of the event node coding value, and 1 ≤ i < n; x represents the dissimilarity between the first event node coding value and the second event node coding value at the i-th position, and the calculation formula of x is as follows:

[0164]

[0165] where node i _code represents the value of the first event node coding value at the i-th position, node' i _code represents the value of the second event node coding value at the i-th position.

[0166] In one embodiment, the initial detection module 440 is further used to: extract the connection status of event nodes within the group as the relationship information of event nodes within the group; determine whether there is a first target event node without a connection; if there is a first target event node without a connection, then determine the first target event node as abnormal account behavior.

[0167] In one embodiment, the final detection module 450 is also used to: determine the initial trust score of each event node based on the relationship information of event nodes within the group; extract the connection between groups as the inter-group relationship information; determine the final trust score of each event node based on the inter-group relationship information and the initial trust score of each event node; determine whether there is a second target event node with a final trust score less than a third preset threshold; if there is a second target event node with a final trust score less than the third preset threshold, the second target event node is determined to be an abnormal account behavior.

[0168] In one embodiment, the final detection module 450 is further configured to determine the final trustworthiness of each event node using the following formula:

[0169] Credibility' node =Credibility node +input;

[0170] Among them, node represents the event node to be tested; Credibility node Represents the initial trust score of the event node to be tested, Credibility' node Represents the final trust score of the event node to be tested, and input represents the control input, which is used as the update of the trust value of the event node to be tested. The calculation formula of input is as follows:

[0171]

[0172] in, represents the intra-group information received by the event node to be tested, f(node) represents the set of neighboring event nodes directly connected to the event node to be tested, and n represents the number of neighboring event nodes;

[0173] Indicates the neighbor group information received by the event node to be tested, F(node) indicates the set of neighbor groups directly connected to the account event group where the event node to be tested is located, and N indicates the number of neighbor groups; Credibility I Represents the group information of the account event group numbered I, which is a convex combination of the initial trust scores of all event nodes in the account event group numbered I. Credibility I The calculation formula is as follows:

[0174]

[0175] Among them, μ m represents the convex combination coefficient of the event node; M represents the number of event nodes in the account event group numbered I; Credibility m Represents the initial trust score of the mth event node in the account event group numbered 1.

[0176] For a detailed description of the above-mentioned account abnormal behavior detection device 400, please refer to the description of the relevant method steps in the above-mentioned embodiment.

[0177] The embodiment of the present application further provides a non-transitory computer-readable storage medium including: a program, which, when running on the electronic device 100, enables the electronic device 100 to execute all or part of the process of the method in the above embodiment. Among them, the storage medium can be a disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk drive (HDD) or a solid-state drive (SSD). The storage medium can also include a combination of the above-mentioned types of memory 102.

[0178] In several embodiments provided in the present application, the disclosed devices and methods may also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a portion of a code, and a module, a program segment, or a portion of a code includes one or more executable instructions for implementing a specified logical function.

[0179] In some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the accompanying figures. For example, two consecutive blocks may actually be executed substantially in parallel, or they may sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flow charts, and combinations of blocks in the block diagrams and / or flow charts, may be implemented using a dedicated hardware-based system that performs the specified functions or actions, or may be implemented using a combination of dedicated hardware and computer instructions.

[0180] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0181] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. The above are only preferred embodiments of the present application, which are only used to illustrate the technical solutions of the present application and are not used to limit the present application. For ordinary technicians in this technical field, any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.

Claims

1. A method for detecting abnormal account behavior, characterized in that: include: Obtain account behavior data to be processed; Grouping the account behavior data according to the account information to which it belongs to obtain a plurality of different account event groups, each of the account event groups including at least one event record; Marking each of the event records in the multiple different account event groups as an event node, and constructing a topological structure of the multiple different account event groups; Based on the intra-group event node relationship information of each account event group in the topological structure, a first round of account abnormal behavior detection is performed on the account behavior data to obtain an initial detection result; Based on the inter-group relationship information of the multiple different account event groups in the topological structure and the intra-group event node relationship information, a second round of account abnormal behavior detection is performed to obtain a final detection result; The step of marking each event record in the multiple different account event groups as an event node and constructing a topological structure of the multiple different account event groups includes: Marking each of the event records in the multiple different account event groups as an event node, and determining all field values ​​in each event node and the field names corresponding to all the field values; Classifying the field values ​​of all event nodes in each account event group according to the field name to obtain multiple different field name sets, each of which includes field values ​​with the same field name in the same account event group; Determining the sequence numbers of different field values ​​in each of the field name sets based on a statistical result of the number of occurrences of the same field value in each of the field name sets; Determine the importance metric value of each field name in each account event group as the occurrence count of the first field value in the set of field names; Determining the encoding value of each event node in each account event group based on the importance measure of each field name in each account event group and the sequence number of the field value in each field name set; Based on the code value of each event node, the variant association rule algorithm is used to determine the dissimilarity between any two event nodes in each account event group. Establishing an intra-group event node connection between any two event nodes in each of the account event groups whose dissimilarity is lower than a first preset threshold; Establishing an inter-group connection between any two of the account event groups having a number of target field names greater than or equal to a preset number, wherein the target field name is a field name whose occurrence ratio of the first field value in each of the two account event groups in the field name set exceeds a second preset threshold; The topology structure is constructed based on the intra-group event node connections and the inter-group connections.

2. The method according to claim 1, characterized in that Determining the dissimilarity between any two event nodes in each account event group according to the variant association rule algorithm includes: The following formula is used to determine the dissimilarity between any two event nodes in each account event group: Where, node represents the encoding value of the first event node, node’ represents the encoding value of the second event node, and Dissim(node, node’) represents the dissimilarity between the first event node and the second event node; n represents the total number of bits of the event node encoding value; i is an integer representing the number of bits of the event node encoding value, and 1 ≤ i < n; x represents the dissimilarity between the encoding values of the first event node and the second event node at the i-th bit, and the calculation formula of x is as follows: Among them, node i _code is the value representing the first event node code value at position i, node' i _code is the value representing the second event node code value at position i.

3. The method according to claim 2, characterized in that Performing the first round of account abnormal behavior detection based on the intra-group event node relationship information in the topological structure to obtain an initial detection result, including: Extracting the connection situation of the intra-group event nodes as the intra-group event node relationship information; Judging whether there is a first target event node without a connection; If there is a first target event node without a connection, determining the first target event node as an account abnormal behavior.

4. The method according to claim 3, characterized in that Performing the second round of account abnormal behavior detection based on the inter-group relationship information in the topological structure and the intra-group event node relationship information to obtain a final detection result, including: Determining the initial trust score of each event node based on the intra-group event node relationship information; Extracting the connection situation of the inter-group connections as the inter-group relationship information; Determining the final trust score of each event node based on the inter-group relationship information and the initial trust scores of each event node; Judging whether there is a second target event node whose final trust score is less than a third preset threshold; If there is a second target event node whose final trust score is less than a third preset threshold, determining the second target event node as an account abnormal behavior.

5. The method according to claim 4, characterized in that Determining the final trust of each event node based on the inter-group relationship information and the initial trust scores of each event node, including: Determining the final trust of each event node by using the following formula: Credibility’ node =Credibility node +input; Among them, node represents the event node to be tested; Credibility node Represents the initial trust score of the event node to be tested, Credibility' node Represents the final trust score of the event node to be tested, and input represents the control input, which is used as the update of the trust value of the event node to be tested. The calculation formula of input is as follows: in, represents the intra-group information received by the event node to be tested, f(node) represents the set of neighboring event nodes directly connected to the event node to be tested, and n represents the number of neighboring event nodes; Indicates the neighbor group information received by the event node to be tested, F(node) indicates the set of neighbor groups directly connected to the account event group where the event node to be tested is located, and N indicates the number of neighbor groups; Credibility I Represents the group information of the account event group numbered I, which is a convex combination of the initial trust scores of all event nodes in the account event group numbered I. Credibility I The calculation formula is as follows: Among them, μ m represents the convex combination coefficient of the event node; M represents the number of event nodes in the account event group numbered 1; Represents the initial trust score of the mth event node in the account event group numbered 1.

6. The method according to any one of claims 1 to 5, characterized in that Each event record in the account behavior data carries at least account information, operation type, device information, and operation time.

7. A device for detecting abnormal account behavior, characterized in that: Including: An acquisition module, configured to acquire account behavior data to be processed; A grouping module, configured to group the account behavior data according to the affiliated account information to obtain a plurality of different account event groups, and each account event group includes at least one event record; A construction module, configured to mark each event record in the plurality of different account event groups as an event node, and construct a topological structure of the plurality of different account event groups; An initial detection module, configured to perform the first round of account abnormal behavior detection on the account behavior data based on the intra-group event node relationship information of each account event group in the topological structure to obtain an initial detection result; A final detection module, configured to perform the second round of account abnormal behavior detection based on the inter-group relationship information of the plurality of different account event groups in the topological structure and the intra-group event node relationship information to obtain a final detection result; The step of marking each event record in the multiple different account event groups as an event node and constructing a topological structure of the multiple different account event groups includes: Marking each of the event records in the multiple different account event groups as an event node, and determining all field values ​​in each event node and the field names corresponding to all the field values; Classifying the field values ​​of all event nodes in each account event group according to the field name to obtain multiple different field name sets, each of which includes field values ​​with the same field name in the same account event group; Determining the sequence numbers of different field values ​​in each of the field name sets based on a statistical result of the number of occurrences of the same field value in each of the field name sets; Determine the importance metric value of each field name in each account event group as the occurrence count of the first field value in the set of field names; Determining the encoding value of each event node in each account event group based on the importance measure of each field name in each account event group and the sequence number of the field value in each field name set; Based on the code value of each event node, the variant association rule algorithm is used to determine the dissimilarity between any two event nodes in each account event group. Establishing an intra-group event node connection between any two event nodes in each of the account event groups whose dissimilarity is lower than a first preset threshold; Establishing an inter-group connection between any two of the account event groups having a number of target field names greater than or equal to a preset number, wherein the target field name is a field name whose occurrence ratio of the first field value in each of the two account event groups in the field name set exceeds a second preset threshold; The topology structure is constructed based on the intra-group event node connections and the inter-group connections.

8. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the method according to any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium, characterized in that The invention comprises: a program, which, when executed by an electronic device, causes the electronic device to execute the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Social network abnormal account detection method and system based on network representation learning

    CN110191110A

  • Malicious community discovery method and device, computer equipment and readable storage medium

    CN112288528A