Abnormal account detection method, electronic device, and storage medium

By acquiring application data and selecting appropriate detection conditions, multi-dimensional abnormal account detection is performed, solving the problem of users cheating to obtain resources and improving platform security and user experience.

CN114117403BActive Publication Date: 2026-05-12BEIJING DEJIAN TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING DEJIAN TECH CO LTD
Filing Date
2021-11-22
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively identify and prevent users from obtaining resources from target platforms through cheating, thus affecting platform security.

Method used

By monitoring account detection trigger events, the system acquires application data and selects appropriate target detection conditions from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account. This includes multi-dimensional detection based on factors such as touch location, touch characteristics, resource exchange behavior, and fraud risk in the account logic tree.

Benefits of technology

It enables accurate identification and handling of abnormal accounts, improves the security and user experience of the target platform, and prevents cheating.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114117403B_ABST
    Figure CN114117403B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an abnormal account detection method, an electronic device and a storage medium. The abnormal account detection method comprises: in response to monitoring an account detection trigger event, obtaining application data matched with a to-be-detected account; determining a target detection condition corresponding to the application data among a plurality of preset account detection conditions; judging whether the application data meets the target detection condition; if the application data meets the target detection condition, determining that the to-be-detected account is an abnormal account, and the abnormal account is an account that obtains resources from a target platform in a cheating manner. According to the embodiments of the present disclosure, the security of the target platform can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and in particular to an abnormal account detection method, electronic device, and storage medium. Background Technology

[0002] As computer-related functions and needs gradually develop, users can access resources from target platforms through their platform accounts. For example, some reading platforms that provide e-reading services often offer corresponding rewards to users to incentivize reading and improve retention rates.

[0003] However, some users often exploit vulnerabilities in target platforms to cheat and obtain resources, thus compromising the platform's security. Therefore, identifying abnormal accounts that use cheating methods to obtain resources from target platforms is of great importance. Summary of the Invention

[0004] To solve the above-mentioned technical problems, or at least partially solve them, this disclosure provides an abnormal account detection method, an electronic device, and a storage medium.

[0005] Firstly, this disclosure provides a method for detecting abnormal accounts, including:

[0006] In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected;

[0007] Among multiple preset account detection conditions, determine the target detection condition corresponding to the application data;

[0008] Determine whether the application data meets the target detection conditions;

[0009] If the application data meets the target detection criteria, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform by cheating.

[0010] In a second aspect, this disclosure provides an electronic device, including a processor and a memory, the memory being used to store executable instructions that cause the processor to perform the following operations:

[0011] In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected;

[0012] Among multiple preset account detection conditions, determine the target detection condition corresponding to the application data;

[0013] Determine whether the application data meets the target detection conditions;

[0014] If the application data meets the target detection criteria, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform by cheating.

[0015] Thirdly, this disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the abnormal account detection method of the first aspect.

[0016] The technical solution provided in this disclosure has the following advantages compared with the prior art:

[0017] The abnormal account detection method, electronic device, and storage medium of this disclosure, when detecting an account detection trigger event, can acquire application data matching the account to be detected, and flexibly select target detection conditions corresponding to the application data from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to the embodiments of this disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform. Attached Figure Description

[0018] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent when taken in conjunction with the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0019] Figure 1 A flowchart illustrating an abnormal account detection method provided in an embodiment of this disclosure is shown.

[0020] Figure 2 A flowchart illustrating another abnormal account detection method provided in an embodiment of this disclosure is shown;

[0021] Figure 3 A flowchart illustrating an optional abnormal account detection method provided in an embodiment of this disclosure is shown.

[0022] Figure 4 A schematic diagram illustrating an exemplary touch position provided by an embodiment of this disclosure is shown.

[0023] Figure 5 A schematic diagram of an exemplary target control provided by an embodiment of this disclosure is shown;

[0024] Figure 6 A flowchart illustrating another abnormal account detection method provided in this disclosure embodiment is shown;

[0025] Figure 7A flowchart illustrating another abnormal account detection method provided in an embodiment of this disclosure is shown;

[0026] Figure 8 A flowchart illustrating another abnormal account detection method provided in an embodiment of this disclosure is shown;

[0027] Figure 9 This illustration shows a schematic diagram of an exemplary account logic tree provided in an embodiment of the present disclosure;

[0028] Figure 10 A flowchart illustrating another abnormal account detection method provided in an embodiment of this disclosure is shown;

[0029] Figure 11 A schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure is shown. Detailed Implementation

[0030] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0031] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0032] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0033] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0034] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0035] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0036] This disclosure provides an abnormal account detection method, electronic device, and storage medium capable of detecting abnormal accounts that obtain resources from a target platform through cheating.

[0037] The following is a combination of... Figure 1-10 The abnormal account detection method provided in the embodiments of this disclosure will be described.

[0038] The abnormal account detection method provided in this disclosure can be applied to target platforms that can provide resources to platform accounts. For example, the target platform can be a platform that provides electronic reading services to users, such as an e-book reading platform or an article reading platform, etc., without specific limitation.

[0039] Figure 1 A flowchart illustrating an abnormal account detection method provided in an embodiment of this disclosure is shown.

[0040] like Figure 1 As shown, the abnormal account detection method may include the following steps.

[0041] Step S110: In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected.

[0042] In this embodiment of the disclosure, the target platform can monitor account detection trigger events and respond to such events when they are detected.

[0043] The account detection trigger event can be any event that can trigger the abnormal account detection function, or any event that requires the abnormal account detection function to be performed, without any specific limitations.

[0044] The account to be tested can be a platform account capable of logging in and using the target platform's functions. Specifically, the account to be tested can obtain resources from the target platform under certain conditions, such as reaching a certain reading time or number of reads. Furthermore, the account to be tested can also extract resources obtained from the platform to a resource extraction account.

[0045] In some embodiments, the account to be detected may be a platform account for which abnormal account detection needs to be performed. For example, a platform account that has been monitored to trigger an account detection event may be used as the account to be detected.

[0046] For application data, it can be data that assesses the probability of cheating in the process of a user acquiring resources from a target platform and / or extracting those resources to a resource extraction account. The resources can be those used by the target platform to incentivize accounts, such as reward-based resources like coins or platform feature usage frequency / duration.

[0047] Next, we will use several examples to explain the application data in detail.

[0048] In one example, the target platform may allocate resources based on the number of pages a user turns or the duration of their browsing. Some users, in order to obtain resources, may use devices such as automatic page turners to cheat by manipulating the touchscreen to turn pages or accumulate browsing time.

[0049] Accordingly, in order to assess the probability of obtaining resources through cheating by touching the machine's screen, the application data may include multiple touch locations of the user of the account to be detected on the content browsing page within a first time period.

[0050] Optionally, the content browsing page can be a page for browsing electronic content, such as an e-book reading interface or an e-news reading interface, etc., without specific limitations.

[0051] Optionally, the first duration can be set according to the actual situation or specific scenario. For example, it can be a preset value or the duration after the user's cumulative touch count reaches a preset threshold. There is no specific limitation on this.

[0052] In another example, to assess the probability of obtaining resources through cheating methods such as machine touch screens, the application data includes touch operation data monitored during touch monitoring of a content browsing page displaying target controls.

[0053] Optionally, the target control can be a control that interrupts the user's access to resources from the content browsing page. For example, it could be a page redirect link that leads to another page, such as an advertisement redirect link. Yet another example is a content container for other content, such as an advertisement container.

[0054] Optionally, the touch operation data can represent subsequent actions taken by the user on the content browsing page displaying the target control. For example, it could be data on whether the user triggered actions such as returning to the content browsing page or closing the target control. For instance, it could be data on whether the user clicked the close function sub-control of the target control, or whether the user navigated to the content browsing page from another page.

[0055] In another example, target platforms often require users to meet certain time limits or achieve certain data milestones before distributing resources. Some users exploit platform bugs to obtain these resources. For instance, for e-book reading platforms, to increase user engagement, a spin-the-wheel offer might be provided when a user reaches a preset reading time. Some users exploit platform bugs to repeatedly spin the wheel to obtain resources.

[0056] Accordingly, in order to assess the probability of obtaining resources by cheating through program bugs, the application data may include resource exchange data of the users to be tested.

[0057] Optionally, the resource exchange data can be data related to the resource exchange behavior of the user to be tested.

[0058] For example, the resource exchange data includes at least one of exchange data 1 and exchange data 2 described below.

[0059] Exchange Data 1: Resource exchange amount of the user to be tested within the second time period. This resource exchange amount can be the sum of the user's total resource exchange amounts within the second time period.

[0060] Exchange data 2: Resource exchange data includes the target exchange time interval for the user to be tested. The target time interval is the time interval between the current resource exchange and the previous resource exchange for the user to be tested.

[0061] In another example, some users, in order to obtain resources from a target platform, often register multiple accounts on the target platform using bots.

[0062] Accordingly, in order to assess the probability of obtaining resources through cheating methods such as bot registration, the application data may include the fraud risk value of the account logic tree to which the account to be detected belongs.

[0063] The account logic tree can be built based on accounts that have a direct or indirect registration invitation relationship with the account to be tested.

[0064] In another example, in order to acquire resources as much as possible, the same user often uses multiple accounts to acquire resources.

[0065] Accordingly, in order to assess the probability of obtaining resources through cheating by having the same user use multiple accounts, the application data may include the number of accounts linked to the resource extraction account.

[0066] The platform account can withdraw resources issued by the target platform to a resource withdrawal account. Optionally, the resource withdrawal account can be a third-party payment account.

[0067] Step S120: Among multiple preset account detection conditions, determine the target detection condition corresponding to the application data.

[0068] In this embodiment of the disclosure, in order to improve the accuracy of abnormal account diagnosis, different account detection conditions can be set for different application data.

[0069] For account detection conditions, they can be detection conditions that can detect whether the account to be detected is an abnormal account that obtains resources from the target platform by cheating.

[0070] Optionally, account detection conditions may include one or more of the following detection conditions 1-5.

[0071] Detection condition 1: Multiple touch positions are located within the same preset area; and / or, multiple touch positions exhibit a pattern of positional change.

[0072] For details regarding the multiple touch locations, please refer to the relevant descriptions in the above sections of the embodiments of this disclosure, which will not be repeated here.

[0073] Detection condition 2: The touch operation data obtained from monitoring the content browsing page displaying the target control conforms to the robot touch characteristics.

[0074] The target display page is a content browsing page that overlays the target controls. The specific content of the touch operation data can be found in the relevant descriptions above in the embodiments of this disclosure, and will not be repeated here.

[0075] Robot touch characteristics can be features summarized based on the patterns of robot touch screen interactions. For example, these could be operation characteristics such as not redirecting back to the content browsing page, or operation characteristics such as not triggering the close function sub-control of the target control.

[0076] Detection condition 3: The amount of resources redeemed by the user under test within the second time period is greater than the preset resource redemption threshold; and / or, the time interval between the current resource redemption and the previous resource redemption by the user under test is less than the preset time period threshold.

[0077] The preset resource exchange threshold represents the maximum amount of resources a user can acquire within the second time period. The preset resource exchange threshold can be set according to actual conditions and specific needs, and will not be elaborated further.

[0078] The preset duration threshold can be the time interval between two resource exchanges. This threshold can be set according to actual circumstances and specific needs, and is not specifically limited. For example, if a user can spin a wheel to obtain resources for every hour of accumulated reading time, the preset duration threshold could be 1 hour. Or, if a user can exchange for resources once they have watched 15 seconds of ads, the preset duration threshold could be 15 seconds.

[0079] Detection condition 4: The fraud risk value is greater than the preset risk threshold.

[0080] The preset risk threshold is used as a critical threshold to determine whether the account to be detected is a machine-registered account. Specifically, the preset risk threshold can be set according to specific scenarios and actual needs, and is not subject to any specific limitations.

[0081] Detection condition 5: The number of bound accounts exceeds the preset threshold.

[0082] The preset quantity threshold represents the maximum number of platform accounts that the target platform allows a resource extraction account to be bound to. Specifically, the preset quantity threshold can be set according to specific scenarios and actual needs, such as one or three accounts, without any specific limitation.

[0083] It should be noted that the multiple preset account detection conditions may also include other conditions besides the detection conditions 1-5 mentioned above, which can be used to determine whether an account is abnormal, and no specific limitations are made on this.

[0084] Step S130: Determine whether the application data meets the target detection conditions.

[0085] Optionally, one or more target detection conditions can be selected from multiple account detection conditions, and then a judgment can be made according to the selected target detection condition. For example, the target detection condition can be at least one of the detection conditions 1-5 mentioned above.

[0086] Step S140: If the application data meets the target detection conditions, the account to be detected is determined to be an abnormal account. An abnormal account is one that obtains resources from the target platform through cheating.

[0087] In some embodiments, if there are multiple target detection conditions, the account to be detected can be determined as an abnormal account if at least one target detection condition is met.

[0088] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0089] Furthermore, in this embodiment of the disclosure, since detection condition 1 can detect accounts from the dimension of the user's resource exchange behavior on the touch screen, detection condition 2 can detect accounts from the dimension of the user's touch features on the target control that prevents the user from continuing to exchange resources, detection condition 3 can detect accounts from the dimension of the features of the resources exchanged by the account to be detected, detection condition 4 can detect accounts from the dimension of the relationship between accounts, and detection condition 5 can detect accounts from the dimension of resource withdrawal, therefore, if multiple of the above detection conditions 1-5 are used for abnormal account diagnosis, multi-dimensional abnormal account detection can be achieved, thereby enabling comprehensive detection of abnormal accounts and further ensuring the security of the target platform.

[0090] In some embodiments, after step S140, the abnormal account detection method may further include determining the abnormal type to which the abnormal account belongs.

[0091] In one example, if the target detection condition is the above detection condition 1 and / or detection condition 2, then the anomaly type can be determined to be a robot touch-related anomaly account.

[0092] In another example, if the target detection condition is the above detection condition 3, then the anomaly type can be determined to include platform program bug-type abnormal accounts.

[0093] In another example, if the target detection condition is the above detection condition 4, then the anomaly type can be determined to include robot account anomaly accounts.

[0094] In another example, if the target detection condition is the above detection condition 5, then the anomaly type can be determined to include abnormal withdrawal accounts.

[0095] In this embodiment of the disclosure, the type of account abnormality can be determined while detecting abnormal accounts, thereby improving the detection accuracy of abnormal accounts.

[0096] In some embodiments, after determining the exception type to which the exception account belongs, the exception account detection method may further include executing an exception handling strategy corresponding to the exception type.

[0097] In one example, the exception handling strategy for a robot touch-related abnormal account may include: overlaying a target control on the content browsing page, wherein the target control is used by the terminal to detect the user to obtain resources from the content browsing page.

[0098] In another example, the exception handling strategy for an account exhibiting a platform program bug could include: stopping the allocation of resources to the account under investigation; and / or sending exception notifications to relevant technical personnel to enable them to promptly address the program bug and / or investigate which resource source is abnormal.

[0099] In yet another example, the exception handling strategy for abnormal accounts in the robot account category could include: prohibiting the platform account corresponding to the account logic tree from performing resource exchange and / or resource extraction.

[0100] In another example, the exception handling strategy for abnormal withdrawal accounts may include: prohibiting resource withdrawals by the corresponding resource withdrawal account and / or prohibiting the establishment of a binding relationship between the account to be detected and the resource withdrawal account.

[0101] In this embodiment, an appropriate exception handling strategy can be selected based on the type of account anomaly, improving the accuracy of exception handling. Furthermore, exception types can be processed without affecting the use of other platform functions or other normal resource exchange functions, thus improving the user experience.

[0102] Figure 2 A flowchart illustrating another abnormal account detection method provided by an embodiment of this disclosure is shown. This embodiment is an optimization based on the above embodiments, and can be combined with various optional solutions from one or more of the above embodiments.

[0103] like Figure 2 As shown, the abnormal account detection method may include the following steps.

[0104] Step S210 involves monitoring whether a page retrieval request has been received from the user of the account to be monitored. The page retrieval request is used to request the opening of a content browsing page.

[0105] In this embodiment of the disclosure, when a user of the account to be detected wants to browse content, they can send a page retrieval request to the target platform.

[0106] S220, if a page retrieval request is received, it is confirmed that an account detection trigger event has been detected.

[0107] In this embodiment of the disclosure, if the target platform receives a page retrieval request sent by the user of the account to be detected, it determines that an account detection trigger event has been detected. Optionally, it can be determined that an account detection trigger event corresponding to the above-mentioned detection condition 1 has been detected.

[0108] Step S230: Obtain multiple touch locations within a first duration sent by the client, wherein the multiple touch locations are obtained during the client's touch monitoring of the content browsing page.

[0109] The client can be a client logged into an account to be tested. Optionally, the client can be a mobile terminal such as a smartphone, laptop, personal digital assistant (PDA), tablet (PAD), portable multimedia player (PMP), in-vehicle terminal (e.g., in-vehicle navigation terminal), wearable device, etc., as well as a fixed terminal such as digital TV, desktop computer, smart home device, etc.

[0110] Step S240: Among multiple preset account detection conditions, determine the target detection condition corresponding to the touch position.

[0111] Optionally, the target detection conditions include the above detection condition 1, namely, multiple touch positions are located within the same preset area; and / or, multiple touch positions exhibit a positional change pattern.

[0112] Specifically, the details of the target detection conditions can be found in the above description of detection condition 1 in the embodiments of this disclosure, and will not be repeated here.

[0113] Step S250: Determine whether multiple touch locations meet the target detection conditions.

[0114] Optionally, step S250 may include: determining whether multiple touch positions are located in the same preset area; and / or determining whether multiple touch positions exhibit a positional change pattern.

[0115] Step S260: If multiple touch locations meet the target detection conditions, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform through cheating.

[0116] Optionally, if multiple touch positions are located in the same preset area; and / or, if multiple touch positions exhibit a pattern of positional change, then the account to be detected can be determined as an abnormal account.

[0117] Optionally, if multiple touch locations do not meet the target detection conditions, it can be further determined whether the account to be detected is an abnormal account or a normal account based on other application data, without limitation.

[0118] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0119] It should also be noted that when a machine touches a screen, the touch position is often located within the same fixed area or changes according to a preset pattern, while the touch position of a real user is often random. Therefore, using the touch position within the first time period as application data can accurately assess the cheating risk of machine touch screens, thereby improving the accuracy of abnormal user diagnosis.

[0120] In some embodiments, Figure 3 A flowchart illustrating an optional abnormal account detection method provided in an embodiment of this disclosure is shown. Figure 3 and Figure 2 The difference in the abnormal account detection method shown is that, after step S260, the abnormal detection method may also include step S270.

[0121] Step S270: Send control display information to the client. This control display information is used to control the client to display the target page.

[0122] In this embodiment of the disclosure, after determining that the account to be detected is an abnormal account, the target platform can send control display information to the client corresponding to the account to be detected. After receiving the control display information, the client can display the target display page within its display area.

[0123] The target display page is a content browsing page that overlays a target control on the target display area. The target control is used to interrupt the user being detected from obtaining resources from the content browsing page. The specific content of the target display page can be found in the relevant descriptions above in the embodiments of this disclosure, and will not be repeated here.

[0124] The target display area is determined based on the touch areas of multiple touch positions and / or the changing patterns of multiple touch positions.

[0125] In one example, if multiple touch locations are located in the same touch area, the target control can be displayed in that touch area.

[0126] In another example, if multiple touch positions change according to a certain pattern, the touch position of the user to be detected at the next moment can be predicted according to the pattern, and then the target control can be displayed with that touch position as the center.

[0127] For ease of understanding, the following parts of the embodiments of this disclosure will be combined with Figure 4 and Figure 5 The display method of the target control will be explained in detail.

[0128] Figure 4 A schematic diagram illustrating an exemplary touch position provided by an embodiment of this disclosure is shown. Figure 5 A schematic diagram of an exemplary target control provided by an embodiment of the present disclosure is shown.

[0129] like Figure 4 and Figure 5 As shown, if the touch position 41 of the account to be detected moves along the trajectory 42, the target control 51 can move along the same trajectory.

[0130] In this embodiment, for abnormal accounts, a target control can be displayed based on their touch location. This ensures that when the abnormal account touches the screen in its original touch manner, it will touch the target control, thereby terminating the resource acquisition process and ensuring the security of the target platform. Simultaneously, for genuine users who frequently touch the same area or follow a preset pattern, the triggering of the target control can be actively avoided, guaranteeing a better touch experience for genuine users.

[0131] Figure 6 This illustration shows a flowchart of another abnormal account detection method provided by an embodiment of the present disclosure. The embodiments of the present disclosure are optimizations based on the above embodiments, and can be combined with various optional solutions from one or more of the above embodiments.

[0132] like Figure 6 As shown, the abnormal account detection method may include the following steps.

[0133] Step S610: Receive multiple touch locations within a first time period sent by the client. These multiple touch locations are obtained during the client's touch monitoring of the content browsing page.

[0134] The specific implementation of step S610 is similar to that of S210, and will not be described in detail here.

[0135] Step S620: Determine whether multiple touch positions conform to the position change pattern.

[0136] The specific implementation of step S620 is similar to that of S250, and will not be described again.

[0137] In step S630, if multiple touch positions do not conform to the position change pattern, control display information is sent to the client. This control display information controls the client to display a target display page, which is a content browsing page overlaid with the target control.

[0138] The specific implementation of step S630 is similar to that of S270, and will not be described again.

[0139] Step S640: Monitor whether interface trigger information for the target display page has been received.

[0140] In this embodiment of the disclosure, it is possible to monitor whether the user of the account to be detected has triggered an interface on the target display page.

[0141] Step S650: If interface trigger information is received, it is confirmed that an account detection trigger event has been detected.

[0142] In this embodiment of the disclosure, if the user of the account to be detected performs an interface triggering operation on the target display page, it is determined that an account detection triggering event has been detected.

[0143] Step S660: Obtain touch operation data.

[0144] The touch operation data can be found in the relevant descriptions above in the embodiments of this disclosure, and will not be repeated here.

[0145] Step S670: Among multiple preset account detection conditions, determine the target detection condition corresponding to the touch operation data.

[0146] Optionally, the target detection conditions include: the touch operation data conforms to the robot's touch characteristics.

[0147] Step S680: Determine whether the touch operation data meets the target detection conditions.

[0148] Optionally, S680 may specifically include: determining whether the touch operation data conforms to the robot's touch characteristics.

[0149] The robot touch features can be found in the above-described relevant parts of the embodiments of this disclosure, and will not be repeated here.

[0150] Step S690: If the touch operation data meets the target detection conditions, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform by cheating.

[0151] Optionally, if the touch operation data matches the robot's touch characteristics, the account to be detected is determined to be an abnormal account.

[0152] Accordingly, if the touch operation data does not conform to the robot's touch characteristics, it is possible to further determine whether the account to be tested is an abnormal account or to determine whether the account to be tested is a normal account based on other application data, without any limitation.

[0153] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0154] Furthermore, in this embodiment of the disclosure, it is possible to determine whether the touch is by a robot based on the trigger characteristics of the user to be detected on the target display page displaying the target control, thereby preventing the intelligent robot from avoiding being identified as an abnormal account by randomly touching the screen and improving the accuracy of abnormal account identification.

[0155] Figure 7 This illustration shows a flowchart of another abnormal account detection method provided by an embodiment of the present disclosure. The embodiments of the present disclosure are optimizations based on the above embodiments, and can be combined with various optional solutions from one or more of the above embodiments.

[0156] like Figure 7 As shown, the abnormal account detection method may include the following steps.

[0157] Step S710 involves monitoring whether a resource exchange request for the target resource has been received from the user under test. The resource exchange request can be a request from the account under test to the target platform to exchange for relevant resources.

[0158] In this embodiment of the disclosure, when the account to be detected meets the resource distribution requirements of the target platform, it can send a resource redemption request to the target platform. For example, this could be due to the user participating in a resource-drawing activity via a lucky draw. Another example is when the user's content browsing time reaches a preset duration. It should be noted that the resource distribution requirements can also be set according to the actual scenario and specific needs, and are not specifically limited thereto.

[0159] Step S720: If a resource exchange request is received, confirm that an account detection trigger event has been detected.

[0160] In this embodiment of the disclosure, if the target platform receives a resource exchange request sent by the client corresponding to the account to be detected, it can be determined that an account detection trigger event has been detected.

[0161] Step S730: Obtain resource exchange data.

[0162] The resource exchange data can be found in the above description of the resource exchange data in the embodiments of this disclosure, and will not be repeated here.

[0163] Step S740: Among multiple preset account detection conditions, determine the target detection condition corresponding to the resource exchange data.

[0164] Optionally, if the resource exchange data includes the amount of resources exchanged by the user to be detected within the second time period, the target detection condition includes the amount of resources exchanged being greater than a preset resource exchange threshold.

[0165] Optionally, if the resource exchange data includes the target exchange time interval of the user to be detected, the target detection condition includes that the target time interval is less than a preset duration threshold, and the target time interval is the time interval between the current resource exchange and the previous resource exchange of the user to be detected.

[0166] The relevant content regarding the target detection conditions mentioned above can be found in the detailed description of the relevant content in the above-mentioned embodiments of this disclosure, and will not be repeated here.

[0167] Step S750: Determine whether the resource exchange data meets the target detection conditions.

[0168] Optionally, S750 may include: determining that the resource exchange amount is greater than a preset resource exchange threshold, and / or that the target time interval is less than a preset duration threshold.

[0169] In one example, S750 may specifically include: First, determining whether the account to be detected has a preset user tag, wherein the preset user tag is set when the user requests resource exchange. Second, if the user to be detected has a preset user tag, determining that the time interval between the user's last resource exchange and the current resource exchange is less than a second duration. Third, if the time interval is less than the second duration, determining that the user to be detected is an abnormal user.

[0170] Step S760: If the resource exchange data meets the target detection conditions, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform through cheating.

[0171] Optionally, if the target detection conditions include: sub-condition 1, the resource exchange amount is greater than the preset resource exchange threshold, and sub-condition 2, the target time interval is less than the preset duration threshold, then the account to be detected can be determined as an abnormal account when at least one of the sub-conditions 1 and 2 is met.

[0172] Optionally, if the resource exchange data does not meet the target detection conditions, it can be further determined whether the account to be detected is an abnormal account or a normal account based on other application data, without limitation.

[0173] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0174] Furthermore, in this embodiment of the disclosure, abnormal accounts can be monitored from the resource characteristic dimension of the resources redeemed by the user, thereby improving the accuracy of abnormal account detection.

[0175] Figure 8 This illustration shows a flowchart of another abnormal account detection method provided by an embodiment of the present disclosure. The embodiments of the present disclosure are optimizations based on the above embodiments, and can be combined with various optional solutions from one or more of the above embodiments.

[0176] like Figure 8 As shown, the abnormal account detection method may include the following steps.

[0177] Step S810: Obtain the account logic tree of the account to be tested. The parent and child nodes in the account logic tree correspond to accounts with a registration invitation relationship.

[0178] For example, Figure 9 A schematic diagram of an exemplary account logic tree structure provided in an embodiment of this disclosure is shown. Figure 9 As shown, the account logic tree includes multiple nodes, each corresponding to a platform account. Within any parent-child node relationship, the platform account corresponding to the child node was invited by the platform account corresponding to the parent node. For example, the account to be tested was invited to register by account 8, and that account then invited accounts 10 and 11 to register.

[0179] Step S820: Determine the feature values ​​of each of the multiple cheating evaluation dimensions of the account logic tree.

[0180] In some embodiments, the feature value may include at least one of the following feature values ​​1-5:

[0181] Feature value 1: The first feature value corresponding to the account name of each node in the account logic tree. Optionally, the first feature value can be determined based on dimensions such as the similarity of account names and whether the account names conform to the robot account naming format. The robot account naming format can be a naming format composed of strings and data, or other regular naming formats that can be distinguished from user naming formats.

[0182] In one example, if the ratio or number of accounts with similar names is greater than a preset threshold, the first feature value can be selected as a first numerical value, such as "1". Conversely, if the ratio or number of accounts with similar names is less than or equal to the preset threshold, the first feature value can be selected as a second numerical value, such as "0". The first numerical value is greater than the second numerical value.

[0183] It should be noted that, depending on the actual situation and specific needs, the first feature value can also be quantified into three or three values, without any limitation.

[0184] In another example, a first feature value can be calculated using a preset calculation function. Specifically, the smaller the ratio or number of accounts with similar names, the smaller the first feature value calculated using the preset function.

[0185] It should be noted that other methods can be selected to calculate the first eigenvalue based on the actual situation and specific needs, and no specific restrictions are imposed on this.

[0186] Feature value 2: The second feature value corresponding to the number of levels in the account logic tree.

[0187] The number of levels in the account logic tree can represent the maximum number of nodes between the root node and child nodes of the logical resource tree. For example, continuing with... Figure 9 For example, Figure 9 The account logic tree is divided into multiple levels by horizontal dotted lines, with a total of 6 levels.

[0188] Optionally, the calculation method for the second eigenvalue is similar to that for the first eigenvalue, and will not be repeated here.

[0189] For example, when the number of layers is less than 3, the second characteristic value is 0; when the number of layers is greater than 3 but less than 6, the second characteristic value is 0.5-0.8, and so on.

[0190] Feature value 3: The third feature value corresponding to the total number of nodes in the account logic tree.

[0191] The total number of nodes can be the total number of accounts contained in the account logical tree. For example, continuing with... Figure 9 For example, including the account to be tested and accounts 0-19, there are a total of 21 nodes.

[0192] Optionally, the calculation method for the third eigenvalue is similar to that for the first eigenvalue, and will not be repeated here.

[0193] Feature value 4: The fourth feature value corresponding to the number of nodes in each subtree of the account logic tree. For example, continuing with... Figure 9 For example, the account logic tree includes three subtrees: the first subtree consisting of accounts 1 to 7, the second subtree consisting of accounts 8 to 13 and the account to be tested, and the third subtree consisting of accounts 14 to 19.

[0194] Optionally, the calculation method for the fourth eigenvalue is similar to that for the first eigenvalue, and will not be repeated here.

[0195] Feature value 5: The fifth feature value corresponding to the resource extraction account name of each node in the account logic tree.

[0196] Optionally, the calculation method for the fifth eigenvalue is similar to that for the first eigenvalue, and will not be repeated here.

[0197] Step S830: Determine the fraud risk value of the account logic tree based on the feature value.

[0198] Optionally, S830 may include: performing a weighted summation of multiple feature values ​​to obtain the fraud risk value of the account logic tree.

[0199] In one example, if the number of feature values ​​is N, the formula for calculating the fraud risk value can be expressed as the following formula (1):

[0200]

[0201] Among them, a k Let e ​​represent the k-th eigenvalue. k This represents the weight value of the k-th feature. Here, k can be any positive integer less than or equal to N.

[0202] It should be noted that the embodiments disclosed herein may also select other methods to calculate the fraud risk value according to actual needs and specific scenarios. For example, the sum of the feature values ​​may be calculated directly, and no specific limitation is made in this regard.

[0203] Step S840: Among multiple preset account detection conditions, determine the target detection condition corresponding to the fraud risk value.

[0204] Optionally, the target detection condition includes: the fraud risk value is greater than a preset risk threshold.

[0205] Step S850: Determine whether the fraud risk value meets the target detection conditions.

[0206] Optionally, step S850 includes determining whether the fraud risk value is greater than a preset risk threshold.

[0207] Step S860: If the fraud risk value meets the target detection criteria, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform through cheating.

[0208] Optionally, if the fraud risk value is greater than a preset risk threshold, the account to be detected can be identified as an abnormal account.

[0209] Optionally, if the fraud risk value is less than or greater than the preset risk threshold, it can be further determined whether the account to be tested is an abnormal account or a normal account based on other application data, without limitation.

[0210] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0211] Furthermore, in this embodiment of the disclosure, the relationship between accounts can be used to determine whether the account to be detected is an abnormal account, thereby improving the accuracy and comprehensiveness of abnormal account detection.

[0212] Figure 10 This illustration shows a flowchart of another abnormal account detection method provided by an embodiment of the present disclosure. The embodiments of the present disclosure are optimizations based on the above embodiments, and can be combined with various optional solutions from one or more of the above embodiments.

[0213] like Figure 10 As shown, the abnormal account detection method may include the following steps.

[0214] Step S1010 involves monitoring whether an account binding request has been received from the user to whom the account to be tested belongs. The account binding request is used to request the establishment of a binding relationship between the account to be tested and the resource extraction account.

[0215] In this embodiment of the disclosure, if the user of the account to be detected wishes to establish a binding relationship between the account to be detected and the resource extraction account, they can send an account binding request to the target platform.

[0216] Optionally, the account to be tested can be a registered account or a guest account on the platform, without specific restrictions.

[0217] The specific details of the resource extraction account can be found in the relevant descriptions in the above sections of the embodiments of this disclosure, and will not be repeated here.

[0218] Step S1020: If an account binding request is received, confirm that an account detection trigger event has been detected.

[0219] In this embodiment of the disclosure, if the target platform receives an account binding request sent by the user to which the account to be detected belongs, it can determine that an account detection trigger event has been detected.

[0220] Step S1030: Obtain the number of bound accounts for the resource extraction account.

[0221] In some embodiments, the account binding request may include an account identifier, such as the account name, of the resource extraction account to be bound, and then the number of accounts already bound to the resource extraction account can be queried through the account identifier.

[0222] Step S1040: Among multiple preset account detection conditions, determine the target detection condition corresponding to the number of bound accounts.

[0223] In some embodiments, the target determination condition may include determining that the number of bound accounts of the resource extraction account is greater than a preset quantity threshold. The preset quantity threshold can be found in the relevant descriptions above in the embodiments of this disclosure, and will not be repeated here.

[0224] Step S1050: Determine whether the number of bound accounts meets the target detection conditions.

[0225] Optionally, step S1050 may specifically include determining whether the number of bound accounts of the resource extraction account is greater than a preset number threshold.

[0226] Step S1060: If the number of bound accounts meets the target detection criteria, the account to be detected is determined to be an abnormal account. An abnormal account is an account that obtains resources from the target platform through cheating.

[0227] Optionally, if the number of bound accounts exceeds a preset threshold, the account to be tested can be determined as an abnormal account. If the number of bound accounts is less than or equal to the preset threshold, further determination can be made based on other application data to determine whether the account to be tested is an abnormal account, or to determine whether the account to be tested is a normal account.

[0228] In this embodiment of the disclosure, when an account detection trigger event is detected, application data matching the account to be detected can be obtained, and a target detection condition corresponding to the application data can be flexibly selected from multiple preset account detection conditions to determine whether the account to be detected is an abnormal account that obtains resources from the target platform through cheating. According to this embodiment of the disclosure, appropriate detection conditions can be flexibly selected to accurately detect abnormal accounts, thereby improving the security of the target platform.

[0229] In addition, since the number of bound accounts of the resource extraction account can be used to detect abnormal accounts in this embodiment, abnormal account diagnosis can be performed on both guest accounts and registered accounts, which improves the comprehensiveness of abnormal account diagnosis.

[0230] Figure 11 A schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure is shown.

[0231] The electronic device provided in this disclosure may include a target platform capable of providing resources to a platform account. For example, the target platform may be a platform that provides electronic reading services to users, such as an e-book reading platform or an article reading platform, etc., and is not specifically limited thereto.

[0232] It should be noted that, Figure 11 The illustrated electronic device 1100 is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0233] The electronic device 1100 typically includes a processor 1110 and a computer program product or computer-readable medium in the form of a memory 1120. The memory 1120 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 1120 has storage space 1121 for executable instructions (or program code) 11211 for performing any of the method steps in the above-described note-taking method. For example, the storage space 1121 for executable instructions may include various executable instructions 11211 for implementing the various steps in the above-described note-taking method. These executable instructions can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, optical discs (CDs), memory cards, or floppy disks. Such computer program products are typically portable or fixed storage units. The storage unit may have... Figure 11The memory 1120 in the electronic device 1100 is arranged in a similar manner as a storage segment or storage space. Executable instructions may be compressed, for example, in a suitable form. Typically, the storage unit includes executable instructions for performing the steps of the note-taking method according to this disclosure, i.e., code that can be read by a processor, such as processor 1110, which, when executed by the electronic device 1100, causes the electronic device 1100 to perform the various steps in the note-taking method described above.

[0234] Of course, for the sake of simplicity, Figure 11 Only some of the components of the electronic device 1100 relevant to this disclosure are shown, omitting components such as buses, input / output interfaces, input devices, and output devices. In addition, the electronic device 1100 may include any other suitable components depending on the specific application.

[0235] This disclosure also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the note-taking methods provided in the embodiments of this disclosure.

[0236] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0237] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0238] In embodiments of this disclosure, program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include, but are not limited to, object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0239] This application discloses:

[0240] A1. An abnormal account detection method, comprising:

[0241] In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected;

[0242] Among multiple preset account detection conditions, the target detection condition corresponding to the application data is determined;

[0243] Determine whether the application data meets the target detection conditions;

[0244] If the application data meets the target detection conditions, the account to be detected is determined to be an abnormal account, which is an account that obtains resources from the target platform by cheating.

[0245] A2. According to the method described in A1, the application data includes multiple touch positions within a first duration;

[0246] Prior to acquiring application data matching the account to be detected, the method further includes:

[0247] Monitor whether a page retrieval request is received from the user of the account to be detected. The page retrieval request is used to request the opening of a content browsing page.

[0248] If the page retrieval request is received, it is determined that the account detection trigger event has been detected;

[0249] The acquisition of application data matching the account to be detected includes:

[0250] The plurality of touch locations sent by the client are obtained during the client's touch monitoring of the content browsing page.

[0251] A3. According to the method described in A2, where,

[0252] The target detection conditions include:

[0253] The multiple touch positions are located within the same preset area; and / or,

[0254] The multiple touch positions exhibit a pattern of positional change.

[0255] A4. According to the method described in A2, after determining that the account to be detected is an abnormal account, the method further includes:

[0256] The system sends control display information to the client, wherein the control display information is used to control the client to display a target display page, the target display page being a content browsing page with target controls overlaid in a target display area, and the target controls being used to interrupt the user being tested from obtaining resources from the content browsing page.

[0257] The target display area is determined based on the touch area of ​​the plurality of touch positions and / or the variation pattern of the plurality of touch positions.

[0258] A5. According to the method described in A1, the application data includes touch operation data, which is obtained during touch monitoring of a content browsing page displaying a target control;

[0259] Prior to acquiring application data matching the account to be detected, the method further includes:

[0260] The system receives multiple touch locations within a first time period sent by the client, wherein the multiple touch locations are obtained during the client's touch monitoring of the content browsing page;

[0261] Determine whether the multiple touch positions conform to a position change pattern;

[0262] If the multiple touch positions do not conform to the position change pattern, control display information is sent to the client. The control display information is used to control the client to display the target display page, which is a content browsing page with the target control superimposed.

[0263] Monitor whether interface trigger information for the target display page is received.

[0264] If the interface trigger information is received, it is determined that the account detection trigger event has been detected;

[0265] The acquisition of application data matching the account to be detected includes:

[0266] Obtain the touch operation data.

[0267] A6. According to the method described in A5, the target detection conditions include: the touch operation data conforms to the robot touch characteristics.

[0268] A7. According to the method described in A1, the application data includes the resource exchange data of the user to be detected;

[0269] Prior to acquiring application data matching the account to be detected, the method further includes:

[0270] Monitor whether a resource exchange request for the target resource has been received from the user to be tested;

[0271] If the resource exchange request is received, it is determined that the account detection trigger event has been detected;

[0272] The acquisition of application data matching the account to be detected includes:

[0273] Obtain the resource exchange data.

[0274] A8. According to the method described in A7, where,

[0275] The resource exchange data includes the resource exchange amount of the user to be detected within a second time period, and the target detection condition includes the resource exchange amount being greater than a preset resource exchange threshold; and / or...

[0276] The resource exchange data includes the target exchange time interval of the user to be detected, and the target detection condition includes that the target time interval is less than a preset duration threshold. The target time interval is the time interval between the current resource exchange and the previous resource exchange of the user to be detected.

[0277] A9. According to the method described in A1, the step of obtaining application data matching the account to be detected includes:

[0278] Obtain the account logic tree of the account to be detected, wherein there is a registration invitation relationship between the parent and child nodes of the account logic tree;

[0279] Determine the feature values ​​of each of the multiple cheating evaluation dimensions of the account logic tree;

[0280] Based on the aforementioned feature values, the fraud risk value of the account logic tree is determined.

[0281] A10. According to the method described in A9, wherein,

[0282] The process of determining the fraud risk value of the account logic tree based on the feature value includes:

[0283] The fraud risk value of the account logic tree is obtained by weighted summation of the multiple feature values.

[0284] A11. According to the method described in A9, the feature value includes at least one of the following:

[0285] The account name of each node in the account logic tree has the first feature value, the number of layers in the account logic tree has the second feature value, the total number of nodes in the account logic tree has the third feature value, the number of nodes in each subtree in the account logic tree has the fourth feature value, and the resource extraction account name of each node in the account logic tree has the fifth feature value.

[0286] A12. According to the method described in A9, the target detection condition includes: the fraud risk value is greater than a preset risk threshold.

[0287] A13. According to the method described in A1, the application data includes the number of accounts bound to the resource extraction account;

[0288] Prior to acquiring application data matching the account to be detected, the method further includes:

[0289] Monitor whether an account binding request is received from the user to whom the account to be tested belongs. The account binding request is used to request the establishment of a binding relationship between the account to be tested and the resource extraction account.

[0290] If the account binding request is received, it is determined that the account detection trigger event has been detected;

[0291] The acquisition of application data matching the account to be detected includes:

[0292] Get the number of accounts that have been bound to the resource extraction account.

[0293] A14. According to the method described in A13, the target detection condition includes: the number of bound accounts is greater than a preset number threshold.

[0294] B15. An electronic device comprising a processor and a memory, the memory for storing executable instructions that cause the processor to perform the following operations:

[0295] In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected;

[0296] Among multiple preset account detection conditions, the target detection condition corresponding to the application data is determined;

[0297] Determine whether the application data meets the target detection conditions;

[0298] If the application data meets the target detection conditions, the account to be detected is determined to be an abnormal account, which is an account that obtains resources from the target platform by cheating.

[0299] B16. The electronic device according to B15, wherein the application data includes multiple touch positions within a first duration;

[0300] Prior to acquiring application data matching the account to be detected, the method further includes:

[0301] Monitor whether a page retrieval request is received from the user of the account to be detected. The page retrieval request is used to request the opening of a content browsing page.

[0302] If the page retrieval request is received, it is determined that the account detection trigger event has been detected;

[0303] The acquisition of application data matching the account to be detected includes:

[0304] The plurality of touch locations sent by the client are obtained during the client's touch monitoring of the content browsing page.

[0305] B17. The electronic device according to B16, wherein the target detection conditions include:

[0306] The multiple touch positions are located within the same preset area; and / or,

[0307] The multiple touch positions exhibit a pattern of positional change.

[0308] B18. The electronic device according to B16, wherein after determining that the account to be detected is an abnormal account, the method further includes:

[0309] The system sends control display information to the client, wherein the control display information is used to control the client to display a target display page, the target display page being a content browsing page with target controls overlaid in a target display area, and the target controls being used to interrupt the user being tested from obtaining resources from the content browsing page.

[0310] The target display area is determined based on the touch area of ​​the plurality of touch positions and / or the variation pattern of the plurality of touch positions.

[0311] B19. The electronic device according to B15, wherein the application data includes touch operation data, which is obtained during touch monitoring of a content browsing page displaying a target control;

[0312] Prior to acquiring application data matching the account to be detected, the method further includes:

[0313] The system receives multiple touch locations within a first time period sent by the client, wherein the multiple touch locations are obtained during the client's touch monitoring of the content browsing page;

[0314] Determine whether the multiple touch positions conform to a position change pattern;

[0315] If the multiple touch positions do not conform to the position change pattern, control display information is sent to the client. The control display information is used to control the client to display the target display page, which is a content browsing page with the target control superimposed.

[0316] Monitor whether interface trigger information for the target display page is received.

[0317] If the interface trigger information is received, it is determined that the account detection trigger event has been detected;

[0318] The acquisition of application data matching the account to be detected includes:

[0319] Obtain the touch operation data.

[0320] B20. The electronic device according to B19, wherein,

[0321] The target detection conditions include: the touch operation data conforms to the robot touch characteristics.

[0322] B21. The electronic device according to B15, wherein the application data includes the resource exchange data of the user to be detected;

[0323] Prior to acquiring application data matching the account to be detected, the method further includes:

[0324] Monitor whether a resource exchange request for the target resource has been received from the user to be tested;

[0325] If the resource exchange request is received, it is determined that the account detection trigger event has been detected;

[0326] The acquisition of application data matching the account to be detected includes:

[0327] Obtain the resource exchange data.

[0328] B22. The electronic device according to B21, wherein,

[0329] The resource exchange data includes the resource exchange amount of the user to be detected within a second time period, and the target detection condition includes the resource exchange amount being greater than a preset resource exchange threshold; and / or...

[0330] The resource exchange data includes the target exchange time interval of the user to be detected. The target detection condition includes that the target time interval is less than a preset duration threshold. The target time interval is the time interval between the current resource exchange and the previous resource exchange of the user to be detected.

[0331] B23. The electronic device according to B15, wherein acquiring application data matching the account to be detected includes:

[0332] Obtain the account logic tree of the account to be detected, wherein there is a registration invitation relationship between the parent and child nodes of the account logic tree;

[0333] Determine the feature values ​​of each of the multiple cheating evaluation dimensions of the account logic tree;

[0334] Based on the aforementioned feature values, the fraud risk value of the account logic tree is determined.

[0335] B24. The electronic device according to B23, wherein,

[0336] The process of determining the fraud risk value of the account logic tree based on the feature value includes:

[0337] The fraud risk value of the account logic tree is obtained by weighted summation of the multiple feature values.

[0338] B25. The electronic device according to B23, wherein the characteristic value includes at least one of the following:

[0339] The account name of each node in the account logic tree has the first feature value, the number of layers in the account logic tree has the second feature value, the total number of nodes in the account logic tree has the third feature value, the number of nodes in each subtree in the account logic tree has the fourth feature value, and the resource extraction account name of each node in the account logic tree has the fifth feature value.

[0340] B26. The electronic device according to B23, wherein the target detection condition includes: the fraud risk value is greater than a preset risk threshold.

[0341] B27. The electronic device according to B15, wherein the application data includes the number of bound accounts of the resource extraction account;

[0342] Prior to acquiring application data matching the account to be detected, the method further includes:

[0343] Monitor whether an account binding request is received from the user to whom the account to be tested belongs. The account binding request is used to request the establishment of a binding relationship between the account to be tested and the resource extraction account.

[0344] If the account binding request is received, it is determined that the account detection trigger event has been detected;

[0345] The acquisition of application data matching the account to be detected includes:

[0346] Get the number of accounts that have been bound to the resource extraction account.

[0347] B28. The electronic device according to B27, wherein the target detection condition includes: the number of bound accounts is greater than a preset number threshold.

[0348] C29. A computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement the abnormal account detection method described in any one of A1-A14 above.

[0349] The various component embodiments of this disclosure can be implemented in hardware in whole or in part, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to embodiments of this disclosure. This disclosure can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing some or all of the methods described herein. Such an implementation of this disclosure can be stored on a computer-readable medium or can take the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0350] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0351] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0352] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for detecting abnormal accounts, characterized in that, include: In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected; Among multiple preset account detection conditions, the target detection condition corresponding to the application data is determined; Determine whether the application data meets the target detection conditions; If the application data meets the target detection conditions, the account to be detected is determined to be an abnormal account, which is an account that obtains resources from the target platform by cheating. The acquisition of application data matching the account to be detected includes: Obtain the account logic tree of the account to be detected, wherein there is a registration invitation relationship between the parent and child nodes of the account logic tree; Determine the feature values ​​of each of the multiple cheating evaluation dimensions of the account logic tree; wherein the feature values ​​include at least one of the following: a first feature value corresponding to the account name of each node in the account logic tree, a second feature value corresponding to the number of layers of the account logic tree, a third feature value corresponding to the total number of nodes in the account logic tree, a fourth feature value corresponding to the number of nodes in each subtree of the account logic tree, and a fifth feature value corresponding to the resource extraction account name of each node in the account logic tree; Based on the feature values, the fraud risk value of the account logic tree is determined; wherein, determining the fraud risk value of the account logic tree based on the feature values ​​includes: performing a weighted summation of multiple feature values ​​to obtain the fraud risk value of the account logic tree; Among multiple preset account detection conditions, the target detection condition corresponding to the fraud risk value is determined; Determine whether the fraud risk value meets the target detection conditions; wherein, the target detection conditions include: the fraud risk value is greater than a preset risk threshold; If the fraud risk value meets the target detection conditions, the account to be detected is determined to be an abnormal account.

2. The method according to claim 1, characterized in that, The application data includes multiple touch locations within a first time period; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether a page retrieval request is received from the user of the account to be detected. The page retrieval request is used to request the opening of a content browsing page. If the page retrieval request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: The plurality of touch locations sent by the client are obtained during the client's touch monitoring of the content browsing page.

3. The method according to claim 2, characterized in that, The target detection conditions include: The multiple touch positions are located within the same preset area; and / or, The multiple touch positions exhibit a pattern of positional change.

4. The method according to claim 2, characterized in that, After determining that the account to be detected is an abnormal account, the method further includes: The system sends control display information to the client, wherein the control display information is used to control the client to display a target display page, the target display page being a content browsing page with target controls overlaid in a target display area, and the target controls being used to interrupt the user being tested from obtaining resources from the content browsing page. The target display area is determined based on the touch area of ​​the plurality of touch positions and / or the variation pattern of the plurality of touch positions.

5. The method according to claim 1, characterized in that, The application data includes touch operation data, which is obtained during touch monitoring of a content browsing page displaying target controls; Prior to acquiring application data matching the account to be detected, the method further includes: The system receives multiple touch locations within a first time period sent by the client, wherein the multiple touch locations are obtained during the client's touch monitoring of the content browsing page; Determine whether the multiple touch positions conform to a position change pattern; If the multiple touch positions do not conform to the position change pattern, control display information is sent to the client. The control display information is used to control the client to display the target display page, which is a content browsing page with the target control superimposed. Monitor whether interface trigger information for the target display page is received. If the interface trigger information is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Obtain the touch operation data.

6. The method according to claim 5, characterized in that, The target detection conditions include: the touch operation data conforms to the robot touch characteristics.

7. The method according to claim 1, characterized in that, The application data includes the resource exchange data of the user to be tested; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether a resource exchange request for the target resource has been received from the user to be tested; If the resource exchange request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Obtain the resource exchange data.

8. The method according to claim 7, characterized in that, The resource exchange data includes the amount of resources exchanged by the user under test within a second time period, and the target detection condition includes the resource exchange amount being greater than a preset resource exchange threshold; and / or, The resource exchange data includes the target exchange time interval of the user to be tested, and the detection condition includes that the target time interval is less than a preset duration threshold. The target time interval is the time interval between the current resource exchange and the previous resource exchange of the user to be tested.

9. The method according to claim 1, characterized in that, The application data includes the number of accounts that have been linked to the resource extraction account; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether an account binding request is received from the user to whom the account to be tested belongs. The account binding request is used to request the establishment of a binding relationship between the account to be tested and the resource extraction account. If the account binding request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Get the number of accounts that have been bound to the resource extraction account.

10. The method according to claim 9, characterized in that, The target detection conditions include: the number of bound accounts is greater than a preset threshold.

11. An electronic device, characterized in that, It includes a processor and a memory, the memory being used to store executable instructions that cause the processor to perform the following operations: In response to the detection of an account detection trigger event, obtain application data that matches the account to be detected; Among multiple preset account detection conditions, the target detection condition corresponding to the application data is determined; Determine whether the application data meets the target detection conditions; If the application data meets the target detection conditions, the account to be detected is determined to be an abnormal account, which is an account that obtains resources from the target platform by cheating. The acquisition of application data matching the account to be detected includes: Obtain the account logic tree of the account to be detected, wherein there is a registration invitation relationship between the parent and child nodes of the account logic tree; Determine the feature values ​​of each of the multiple cheating evaluation dimensions of the account logic tree; wherein the feature values ​​include at least one of the following: a first feature value corresponding to the account name of each node in the account logic tree, a second feature value corresponding to the number of layers of the account logic tree, a third feature value corresponding to the total number of nodes in the account logic tree, a fourth feature value corresponding to the number of nodes in each subtree of the account logic tree, and a fifth feature value corresponding to the resource extraction account name of each node in the account logic tree; Based on the feature values, the fraud risk value of the account logic tree is determined; wherein, determining the fraud risk value of the account logic tree based on the feature values ​​includes: performing a weighted summation of multiple feature values ​​to obtain the fraud risk value of the account logic tree; Among multiple preset account detection conditions, the target detection condition corresponding to the fraud risk value is determined; Determine whether the fraud risk value meets the target detection conditions; wherein, the target detection conditions include: the fraud risk value is greater than a preset risk threshold; If the fraud risk value meets the target detection conditions, the account to be detected is determined to be an abnormal account.

12. The electronic device according to claim 11, characterized in that, The application data includes multiple touch locations within a first time period; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether a page retrieval request is received from the user of the account to be detected. The page retrieval request is used to request the opening of a content browsing page. If the page retrieval request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: The plurality of touch locations sent by the client are obtained during the client's touch monitoring of the content browsing page.

13. The electronic device according to claim 12, characterized in that, The target detection conditions include: The multiple touch positions are located within the same preset area; and / or, The multiple touch positions exhibit a pattern of positional change.

14. The electronic device according to claim 12, characterized in that, After determining that the account to be detected is an abnormal account, the method further includes: The system sends control display information to the client, wherein the control display information is used to control the client to display a target display page, the target display page being a content browsing page with target controls overlaid in a target display area, and the target controls being used to interrupt the user being tested from obtaining resources from the content browsing page. The target display area is determined based on the touch area of ​​the plurality of touch positions and / or the variation pattern of the plurality of touch positions.

15. The electronic device according to claim 11, characterized in that, The application data includes touch operation data, which is obtained during touch monitoring of a content browsing page displaying target controls; Prior to acquiring application data matching the account to be detected, the method further includes: The system receives multiple touch locations within a first time period sent by the client, wherein the multiple touch locations are obtained during the client's touch monitoring of the content browsing page; Determine whether the multiple touch positions conform to a position change pattern; If the multiple touch positions do not conform to the position change pattern, control display information is sent to the client. The control display information is used to control the client to display the target display page, which is a content browsing page with the target control superimposed. Monitor whether interface trigger information for the target display page is received. If the interface trigger information is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Obtain the touch operation data.

16. The electronic device according to claim 15, characterized in that, The target detection conditions include: the touch operation data conforms to the robot touch characteristics.

17. The electronic device according to claim 11, characterized in that, The application data includes the resource exchange data of the user to be tested; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether a resource exchange request for the target resource has been received from the user to be tested; If the resource exchange request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Obtain the resource exchange data.

18. The electronic device according to claim 17, characterized in that, The resource exchange data includes the resource exchange amount of the user to be detected within a second time period, and the target detection condition includes the resource exchange amount being greater than a preset resource exchange threshold; and / or... The resource exchange data includes the target exchange time interval of the user to be detected. The target detection condition includes that the target time interval is less than a preset duration threshold. The target time interval is the time interval between the current resource exchange and the previous resource exchange of the user to be detected.

19. The electronic device according to claim 11, characterized in that, The application data includes the number of accounts that have been linked to the resource extraction account; Prior to acquiring application data matching the account to be detected, the method further includes: Monitor whether an account binding request is received from the user to whom the account to be tested belongs. The account binding request is used to request the establishment of a binding relationship between the account to be tested and the resource extraction account. If the account binding request is received, it is determined that the account detection trigger event has been detected; The acquisition of application data matching the account to be detected includes: Get the number of accounts that have been bound to the resource extraction account.

20. The electronic device according to claim 19, characterized in that, The target detection conditions include: the number of bound accounts is greater than a preset threshold.

21. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, causes the processor to implement the abnormal account detection method according to any one of claims 1-10.