Abnormal user determination method, apparatus, device, and storage medium

By acquiring user attribute and behavior information and combining rules of multiple verification types to comprehensively verify users, the problem of low accuracy in identifying abnormal users in existing technologies has been solved, achieving more efficient identification of abnormal users and improving user experience.

CN114240476BActive Publication Date: 2026-01-02彩讯科技股份有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111402087.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-22
Publication Date
2026-01-02
Estimated Expiration
2041-11-22

AI Technical Summary

Technical Problem

Existing technologies have low accuracy in identifying malicious users who engage in fraudulent transactions, leading to a waste of internet resources and negatively impacting user experience.

Method used

By responding to user activity participation commands, user attribute information is obtained. Based on the correlation between the target activity and the verification type, the target verification type is determined. Then, based on multiple verification rules, the user behavior is comprehensively verified to determine whether the user is an abnormal user.

Benefits of technology

It improves the accuracy of identifying abnormal users, prevents third parties from maliciously stealing activity rewards, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114240476B_ABST
    Figure CN114240476B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose an abnormal user determination method, device and equipment and a storage medium. The method comprises: in response to a target activity participation instruction issued by a user, determining a target activity and obtaining user attribute information of the user; determining at least one target check type according to the target activity and a preset association relationship between activities and check types; checking the user based on a target check rule of the at least one target check type according to the user attribute information and user behavior information of the user issued for the target activity, to obtain a check result; and judging whether the check result satisfies a user abnormal condition, and if so, determining that the user is an abnormal user. The embodiments of the present application improve the accuracy of abnormal user identification.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to data processing technology, and particularly relate to an abnormal user determination method and device, equipment and a storage medium. BACKGROUND

[0002] With the continuous development of Internet technology, user-oriented Internet resource marketing methods are increasing day by day. With the diversification of Internet resource marketing methods, the situation of Internet resources being maliciously stolen by third parties is increasing, which causes waste of Internet resources and affects the user experience.

[0003] In the prior art, the identification of maliciously stolen abnormal users usually adopts a single abnormal user identification method such as common user account identification, device identification or network environment identification, and the accuracy of the identification result is low. SUMMARY

[0004] Embodiments of the present application provide an abnormal user determination method, device, equipment and storage medium to improve the accuracy of abnormal user identification.

[0005] In a first aspect, the embodiments of the present application provide an abnormal user determination method, which comprises:

[0006] In response to a target activity participation instruction issued by a user, determining a target activity and obtaining user attribute information of the user;

[0007] According to the target activity and a preset association relationship between activities and verification types, determining at least one target verification type;

[0008] According to the user attribute information and user behavior information of the user issued for the target activity, verifying the user based on a target verification rule of at least one target verification type to obtain a verification result;

[0009] Judging whether the verification result meets a user abnormal condition, and if so, determining that the user is an abnormal user.

[0010] In a second aspect, the embodiments of the present application further provide an abnormal user determination device, which comprises:

[0011] A user attribute information acquisition module configured to, in response to a target activity participation instruction issued by a user, determine a target activity and obtain user attribute information of the user;

[0012] A target verification type determination module configured to, according to the target activity and a preset association relationship between activities and verification types, determine at least one target verification type;

[0013] The check result determination module is configured to determine a check result of the user according to the user attribute information and the user behavior information of the user to the target activity, and based on a target check rule of at least one target check type.

[0014] The abnormal user determination module is configured to determine whether the check result satisfies a user abnormal condition, and if yes, determine that the user is an abnormal user.

[0015] In a third aspect, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor, wherein the processor implements the abnormal user determination method according to any of the embodiments of the present application when executing the program.

[0016] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, wherein the program is executed by a processor to implement the abnormal user determination method according to any of the embodiments of the present application.

[0017] The embodiments of the present application determine at least one target check type according to a target activity and a preset association between the activity and the check type, determine a check result of the user according to user attribute information and user behavior information of the user to the target activity, and based on a target check rule of at least one target check type, and determine whether the user is an abnormal user according to the check result. The above scheme determines an abnormal user based on at least one target check type corresponding to a target activity and a target check rule of the at least one target check type, and combines multiple check types, rather than using a single check type to determine an abnormal user, thereby improving the accuracy of abnormal user determination. Through accurate identification of an abnormal user, the situation of a third party maliciously stealing and obtaining an activity reward is avoided, and a good experience is provided for the user. BRIEF DESCRIPTION OF DRAWINGS

[0018] Figure 1 is a flowchart of an abnormal user determination method in the first embodiment of the present application;

[0019] Figure 2 is a flowchart of an abnormal user determination method in the second embodiment of the present application;

[0020] Figure 3 is a flowchart of an abnormal user determination method in the third embodiment of the present application;

[0021] Figure 4A is a structural diagram of an abnormal user determination system in the fourth embodiment of the present application;

[0022] Figure 4Bis a configuration page schematic diagram of segment configuration in embodiment four of the present application;

[0023] Figure 4C is a configuration page schematic diagram of link configuration in embodiment four of the present application;

[0024] Figure 5 is a structural block diagram of an abnormal user determination device in embodiment five of the present application;

[0025] Figure 6 is a structural schematic diagram of an electronic device in embodiment six of the present application. DETAILED DESCRIPTION

[0026] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.

[0027] Embodiment one

[0028] Figure 1 A flowchart of an abnormal user determination method provided for embodiment one of the present application, the present embodiment can be applicable to the case of identifying normal users and abnormal users when users access internet resources, and the method can be executed by an abnormal user determination device, which can be realized in the form of software and / or hardware. As shown in the figure, the method specifically includes the following steps: Figure 1

[0029] S110, in response to a target activity participation instruction issued by the user, determining the target activity and obtaining user attribute information of the user.

[0030] The target activity can be any one of the activity tasks selected by the current user in at least one activity task. The activity task can be a recharge activity or a cloud disk resource sharing activity, etc., which can be pre-set by relevant technical personnel according to actual needs. Different activities can correspond to different prizes and activity scenarios, wherein the activity scenario can include winning or claiming a prize. For example, the prize of the recharge activity can be 5 yuan of airtime or 10 yuan of airtime, and correspondingly, the activity scenario corresponding to the recharge activity can be winning. The user attribute information can include the user's mobile phone number, user name and user account, etc.

[0031] The user can select the target activity to participate in the display interface corresponding to the activity task according to actual needs; the target activity participation instruction issued by the user in the display interface corresponding to the activity task is obtained, the target activity participated by the user is determined, and the user attribute information of the user is obtained.

[0032] ​Before responding to the target activity participation instruction issued by the user, a configuration file of the activity task can be pre-configured according to different activity tasks, different prizes corresponding to different activity tasks, and activity scenes corresponding to different activity tasks. The configuration file of the activity task can include segment configuration and link configuration. The segment configuration is a configuration of check rules of different check types, and the configuration parameters of the segment configuration can include a segment name, a check type, a check time range, a check time range unit, an activity scene, a weight of the check type, and a check type enable state, etc. The check type enable state can be used to control the enablement and disablement of the check type, that is, the check type can be turned on and off with one key. For example, if a check type is disabled, all activity tasks using the check type are stopped from using the check type; if a check type is enabled, all activity tasks using the check type can use the check type. The link configuration is a configuration of activity parameters for different activities, and the configuration parameters of the link configuration can include a link name, an activity name, a prize name, an activity enable state, an abnormal user list threshold, an abnormal user IP (Internet Protocol) threshold, a success threshold, and a check point list, etc. The activity enable state can be used to control the start and stop of the activity, and the success threshold can be a threshold of the check score of the successful execution of the activity task. In the check point list, the check type corresponding to the activity task can be selected, and the corresponding burying point can also be configured according to different check types. The related technical personnel can set the related configuration parameters in advance according to the actual needs of the activity task, and the present embodiment does not limit this.

[0033] S120, determining at least one target check type according to the target activity and a preset association relationship between the activity and the check type.

[0034] The check type can include front-end burying point check, client active check, user login mode check, user device number check, abnormal user list check, and abnormal user IP check, etc.

[0035] The target check type can be a check type associated with the target activity. Different check types can be configured for different activity tasks. For example, the recharge activity can be configured with front-end burying point check, client active check, user login mode check, user device number check, abnormal user list check, and abnormal user IP check; the cloud disk resource sharing activity can be configured with client active check, user login mode check, user device number check, abnormal user list check, and abnormal user IP check. The related technical personnel can configure different check types according to the actual task requirements of the activity task.

[0036] Different parameters can be configured in the segment configuration and the link configuration according to different activities, different prizes and different activity scenarios. For example, the name corresponding to the activity task can be configured in the activity name of the link configuration, for example, a recharge activity; the prize name of the activity task can be configured in the prize name of the link configuration, for example, a 5-yuan phone card; the check type corresponding to the activity task and the corresponding buried point event of the check type can be configured in the checkpoint list of the link configuration. For example, different activity tasks can correspond to at least one buried point event, and the buried point event can be preset according to different activity tasks, prizes and activity scenarios. The checkpoint list can include the selection of the check type and the filling of the buried point event name. For the check types of the client active check, the user login mode check, the user device number check, the abnormal user list check and the abnormal user IP check, there is only one buried point, and therefore, the number of the buried point events of the five check types can be set as a default value in the checkpoint list to indicate that there is only one buried point for the current check type, for example, the default value can be 1 or 0. For example, if the activity task is a recharge activity and the prize is a 5-yuan phone card, and the corresponding number of buried points is 3, then 3 buried point events can be configured in the buried point event input box corresponding to the front-end buried point check type in the checkpoint list corresponding to the recharge activity, and the event names of the three buried point events can be input.

[0037] The segment configuration parameters of the check type can include the weight, the check time range and the activity scenario corresponding to each check type. For example, different activity tasks can correspond to different check types. If different activity tasks all include the same check type, the check type can be uniformly configured for each activity task. For different check types corresponding to different activity tasks, the different check types can be configured respectively in the segment configuration. For example, if any activity task includes the abnormal user list check, the check rule of the abnormal user list check can be preconfigured in the segment configuration, and the configured check rule can be named as “public-abnormal user list check”. When the abnormal user list check of each activity is configured, “public-abnormal user list check” can be selected in the configuration position of the abnormal user list, and each parameter does not need to be configured again. If the client active check of the recharge activity of the 5-yuan phone card needs to be configured, and the configuration parameters of the client active check of other activity tasks are different from the configuration parameters of the client active check of the recharge activity of the 5-yuan phone card, the client active check of the recharge activity of the 5-yuan phone card needs to be configured in the segment configuration. The segment name facilitates relevant technical personnel to distinguish different related configurations corresponding to different activity tasks.

[0038] S130, according to the user attribute information and the user behavior information of the user to the target activity, the user is checked based on the target check rule of at least one target check type, and a check result is obtained.

[0039] The user behavior information may include information related to the target task selected by the user in at least one activity task. That is, user behavior information is the information emitted by the user when performing the target task, and can be determined through user actions such as clicking or swiping. For example, it may include the activity name, prize name, and activity scenario corresponding to the target task selected by the user.

[0040] Different target verification types can correspond to different target verification rules. These rules are pre-configured configuration files, which may include segmentation configuration, link configuration, and anomaly judgment data files. Upon receiving a target task, the system can obtain user attribute information such as the account and phone number entered by the user when logging into the client for the activity task, as well as the activity name and prize name corresponding to the target task. Based on the activity name, prize name, and activity scenario, the system retrieves the relevant parameters configured in the link configuration and the segment configuration, among other target verification rules. Different anomaly judgment data files are pre-set for different verification types. These files include conditions for determining whether a user is an abnormal or normal user. For example, if the verification type is a user login method verification type, the anomaly judgment data file includes conditions for normal user login and abnormal login. Normal user login can be CAPTCHA login, while abnormal user login can be third-party login. The system retrieves the anomaly judgment data file associated with the verification type. Based on the anomaly judgment data file and the relevant parameters in the segment and link configurations, and using a pre-defined verification result determination algorithm, the system calculates the user behavior information to determine the verification result for the verification type.

[0041] The data files for front-end event tracking verification can include event tracking data for any activity task; the data files for client-side activity verification can include normal file upload behavior data for any activity task, which can be the standard number of times a user uploads files when performing an activity task; the data files for user login method verification can include normal login methods and abnormal login methods, such as CAPTCHA login for normal login and third-party login for abnormal login; the data files for abnormal user list verification can be a list of abnormal users, including attribute information of at least one abnormal user, such as the abnormal user's mobile phone number; and the data files for abnormal user IP verification can be a list of abnormal user IPs, including the IP address of at least one abnormal user. These data files for different verification types can be added, deleted, or updated by relevant technical personnel according to actual needs.

[0042] Exemplarily, the user attribute information and the user behavior information issued by the user performing the target activity are acquired, the related parameters in the segment configuration and the link configuration corresponding to the target activity are acquired according to the user behavior information, the target verification types associated with the target activity are determined according to the related parameters in the segment configuration and the link configuration, the target verification rules such as the abnormal judgment data file and the segment configuration corresponding to the target verification types are determined according to the target verification types, the scores of each target verification type are determined, and the verification result is determined according to the scores of each target verification.

[0043] Exemplarily, the scores of the target verification types can be added, the score obtained after the addition is compared with the preset success score threshold, and the result after the score comparison is taken as the verification result. The verification result can include that the score obtained after the addition of the scores corresponding to the target verification types is greater than or equal to the success score threshold, and the score obtained after the addition of the scores is less than the success score threshold.

[0044] In S140, it is judged whether the verification result meets the user abnormal condition, and if yes, the user is determined as an abnormal user.

[0045] According to the verification result, it can be judged whether the verification result meets the user abnormality, and if yes, the user is determined as an abnormal user, and if not, the user is determined as a normal user.

[0046] Exemplarily, if the score obtained after the addition of the scores corresponding to the target verification types is greater than or equal to the success score threshold, the user can be determined as a normal user, and if the score obtained after the addition of the scores corresponding to the target verification types is less than the success score threshold, the user can be determined as an abnormal user.

[0047] According to the target activity and the preset association relationship between the activity and the verification type, at least one target verification type is determined, the user is verified based on the target verification rules of the at least one target verification type according to the user attribute information and the user behavior information issued by the user performing the target activity, the verification result is obtained, and whether the user is an abnormal user is determined according to the verification result. The above scheme realizes the determination of the abnormal user based on at least one target verification type corresponding to the target activity and the target verification rules of the at least one target verification type, and determines the abnormal user in combination with at least one verification type instead of using a single verification type, thereby improving the accuracy of the abnormal user determination. Through the accurate identification of the abnormal user, the situation that the third party maliciously steals the activity rewards is avoided, and a good experience is brought to the user.

[0048] Embodiment Two

[0049] Figure 2 A flowchart of an abnormal user determination method provided by Embodiment Two of the application is provided. Embodiment Two is optimized and improved on the basis of the above technical solutions.

[0050] Further, after the step of "determining at least one target verification type according to the target activity and the preset association between the activity and the verification type", a step of "obtaining the current time and the target verification rule associated with any target verification type; determining whether the current time is within the verification time range in any target verification rule according to the verification time range; if yes, performing the verification of the user according to the target verification rule based on at least one target verification type according to the user attribute information and the user behavior information of the user issuing the target activity." is added to perfect the verification method of each verification type.

[0051] As shown in the method, the method comprises the following specific steps: Figure 2

[0052] S210, in response to the target activity participation instruction issued by the user, determining the target activity and obtaining the user attribute information of the user.

[0053] S220, determining at least one target verification type according to the target activity and the preset association between the activity and the verification type.

[0054] S230, obtaining the current time and the target verification rule associated with any target verification type.

[0055] Different verification time ranges can correspond to different verification types, and the verification time range is the effective time for the user to complete the target activity task, that is, the user needs to complete the activity task within the corresponding verification time range. Among them, the verification time range corresponding to the verification type can be set by the relevant technical personnel according to the actual demand, and the verification time range and the verification time range unit under different verification types of different activity tasks can be configured in the segmented configuration. For example, the verification time range of the front-end point verification type can be 24 hours, that is, the user needs to complete the activity task corresponding to the target activity within 24 hours, and if more than 24 hours, the front-end point verification can be determined as an invalid verification type, that is, the target activity is not verified by using the verification type.

[0056] The current time and the target activity currently performed by the user are obtained, the relevant parameters configured in the segmented configuration and the link configuration corresponding to the target activity are obtained according to the target activity, the target verification type corresponding to the target activity and the target verification rule associated with any target verification type are determined according to the configured relevant parameters.

[0057] S240, determining whether the current time is within the verification time range according to the verification time range in any target verification rule.

[0058] ​obtaining a check time range parameter in the link configuration corresponding to the target activity, and judging whether the current time is within the check time range according to the obtained check time range. For example, if the obtained check time range is 24 hours, i.e., 00:00:00-23:59:59 of a certain day, it is judged whether the current time is within the check time range.

[0059] S250, if yes, performing a check on the user according to the user attribute information and the user behavior information of the user issuing the target activity, based on the target check rule of the at least one target check type.

[0060] If the current time is within the check time range, a check is performed on the user according to the user attribute information and the user behavior information of the user issuing the target activity, based on the target check rule of the at least one target check type. The user attribute information can be a user mobile phone number, and the user behavior information can be a target activity and a prize currently selected by the user. According to the obtained user behavior information and user attribute information, relevant parameters corresponding to the target activity can be obtained in the segment configuration and the link configuration; at least one target check type corresponding to the target activity is determined according to the obtained relevant parameters, and a check is performed on the user based on the target check rule of the at least one target check type.

[0061] In an optional embodiment, after judging whether the current time is within the check time range, it further includes: if the current time is not within the check time range, determining that the target check type corresponding to the check time range is a to-be-deleted check type; and determining that the check score of the to-be-deleted check type is a preset to-be-deleted score.

[0062] If the current time is not within the check time range, the target check type not within the check time range can be determined as a to-be-deleted check type. The check score of the to-be-deleted check type is determined as a preset to-be-deleted score. The preset to-be-deleted score can be determined by a relevant technical person according to actual needs, for example, the preset to-be-deleted score can be 0. By setting the target check type not within the check time range as a to-be-deleted check type and setting the preset to-be-deleted score for the to-be-deleted check type, the influence of the to-be-deleted check type score on the final score result is avoided.

[0063] S260, according to the user attribute information and the user behavior information of the user issuing the target activity, a check is performed on the user based on the target check rule of the at least one target check type, and a check result is obtained.

[0064] S270, judging whether the check result meets a user abnormal condition, if yes, determining that the user is an abnormal user.

[0065] The embodiment obtains the current time and a target check rule associated with any target check type, judges whether the current time is within a check time range in any target check rule according to the check time range, and checks the user according to the judgment result. The above scheme avoids that the user does not complete the corresponding task within the specified time range or completes the corresponding task overtime by judging whether the current time is within the check time range of the target check type. The check time range specifies the scores of each check type, so that the result of determining the abnormal user is more accurate.

[0066] Embodiment three

[0067] Figure 3 A flowchart of an abnormal user determination method provided for embodiment three of the present application is provided. The embodiment is optimized and improved on the basis of the above technical solutions.

[0068] Further, the "checking the user according to the target check rule based on at least one target check type according to the user attribute information and the user behavior information of the user to the target activity to obtain a check result" is refined as "obtaining the user behavior information of the user to the target task; determining the check score of the target check type based on at least one target check type according to the user attribute information and the user behavior information; determining the total check score of the user according to the check score of the target check type; judging whether the total check score exceeds the preset check score threshold; if not, checking the user login mode and the number of user devices according to the preset user login mode check rule and the user device number check rule to obtain the first check score of the user login mode and the second check score of the number of user devices." to improve the determination method of the check result.

[0069] As shown in Figure 3 , the method comprises the following specific steps:

[0070] S310, in response to the target activity participation instruction issued by the user, determining the target activity and obtaining the user attribute information of the user.

[0071] S320, determining at least one target check type according to the target activity and the preset association relationship between the activity and the check type.

[0072] S330, obtaining the user behavior information of the user to the target task.

[0073] The user behavior information can include the task name, the prize name and the activity scene of the user currently performing the target task.

[0074] S340, determining a check score of the target check type according to the user attribute information and the user behavior information and based on a target check rule of the target check type.

[0075] Different check types correspond to different check rules. The check rule of the front-end point check is as follows: obtaining the user attribute information and the user behavior information; obtaining the activity name, the prize name and the activity scene of the target activity according to the user behavior information; obtaining the configuration parameters in the link configuration and the segmentation configuration according to the activity name, the prize name and the activity scene of the target activity; determining whether the current time is within the check time range of the front-end point check, if yes, obtaining the point events triggered by the user in the process of performing the target task, and performing point event retrieval in the data file corresponding to the front-end point check; if no, determining the front-end point check as a to-be-deleted check type, and setting the score of the front-end point check as a preset to-be-deleted score. If the current time is within the check time range of the front-end point check, determining the check score of the front-end point check according to the retrieval result. The data file corresponding to the front-end point check stores all point events corresponding to the activity tasks.

[0076] The number of point events triggered by the user in the process of performing the target task can be determined after retrieving the data file corresponding to the front-end point check. The check score of the front-end point check can be determined according to the number of point events and the weight corresponding to the front-end point check. Specifically, the check score of the front-end point check can be obtained by multiplying the number of point events by the weight. The weight of the front-end point check corresponding to the target activity can be pre-configured in the segmentation configuration.

[0077] For example, if the number of point events triggered by the user in the process of performing the target task is 5 after retrieving the data file corresponding to the front-end point check, and the weight corresponding to the front-end point check is 5 points, then the check score of the front-end point check of the user in the target activity is 25 points.

[0078] The check rule of the client active check is as follows: obtaining user attribute information and user behavior information; obtaining the activity name, prize name and activity scene of the target activity according to the user behavior information; obtaining the configuration parameters in the link configuration and the segmentation configuration according to the activity name, prize name and activity scene of the target activity; judging whether the current time is within the check time range of the client active check, if yes, obtaining the operation frequency of the file upload behavior of the user in the process of performing the target task, and determining the check score of the client active check according to the operation frequency; if no, determining the client active check as a to-be-deleted check type, and setting the score thereof as a preset to-be-deleted score. The file upload behavior can be the behavior of the user uploading the file of the activity task corresponding to the target activity. For example, the higher the frequency of file upload is, the better the completion of the target task by the user can be determined; the lower the frequency of file upload is, the worse the completion of the target task by the user can be determined.

[0079] The check score of the client active check can be determined according to the frequency of the user uploading the file of the activity task in the target activity and the weight corresponding to the client active check, which can be the product of the frequency of file upload and the weight branch to obtain the check score of the front-end burying point check. The weight of the client active check corresponding to the target activity can be configured in the present segmentation configuration.

[0080] For example, if the frequency of file upload determined in the client active check is 0.5 times per minute, and the weight branch corresponding to the client active check is 20 points, then the check score of the client active check in the target activity of the user is 10 points.

[0081] The verification rule of the user login mode verification is as follows: obtaining user attribute information and user behavior information; obtaining the activity name, prize name and activity scene of the target activity according to the user behavior information; obtaining the configuration parameters in the link configuration and the segmentation configuration according to the activity name, prize name and activity scene of the target activity; judging whether the current time is within the verification time range of the user login mode, if yes, obtaining at least one login mode of the user in the process of performing the target task according to the user attribute information, for example, the user's mobile phone number, for example, the login mode can be verification code login, third-party login and password login, etc.; if not, determining the user login mode verification as a to-be-deleted verification type, and setting the score thereof as a preset to-be-deleted score. If the current time is within the verification time range of the user login mode, the obtained login mode is compared with the abnormal login mode in the abnormal judgment data file corresponding to the user login mode based on the abnormal judgment data file corresponding to the user login mode, and the proportion of the abnormal login mode in the obtained at least one login mode is determined according to the comparison result. Among them, the abnormal judgment data file corresponding to the user login mode contains user normal login mode and user abnormal login mode.

[0082] Specifically, the data file of the user login mode can be searched according to the obtained at least one login mode, and the abnormal proportion of the user abnormal login mode in the obtained at least one login mode is determined according to the search result. The verification score of the user login mode verification is determined according to the abnormal proportion and the weight corresponding to the user login mode verification, which can be the product of the abnormal proportion and the weight. The weight of the user login mode verification corresponding to the target activity can be pre-configured in the segmentation configuration.

[0083] For example, if there are 4 user login modes obtained, and after searching the data file corresponding to the user login mode, it is determined that 2 of the 4 user login modes are abnormal user login modes, then the abnormal proportion of the user abnormal login is 1 / 2, and if the weight corresponding to the user login mode verification is-10 points, then the verification score of the user login mode verification in the target activity is-5 points. Since the proportion of the abnormal login mode is determined, the weight of the user login mode verification is usually set to a negative number.

[0084] The check rule of the number of user devices is as follows: obtaining user attribute information and user behavior information; obtaining an activity name, a prize name and an activity scene of a target activity according to the user behavior information; obtaining configuration parameters in link configuration and segmentation configuration according to the activity name, the prize name and the activity scene of the target activity; judging whether the current time is within a check time range of the number of user devices check, if yes, obtaining at least one login mode of the user, if no, determining the user device tree check as a to-be-deleted check type, and setting a score of the user device tree check as a preset to-be-deleted score.

[0085] If the current time is within the check time range of the number of user devices check, at least one device of the user in a file uploading process of a target task is obtained, for example, a mobile phone, a tablet computer or a computer, and the obtained at least one device is taken as a first device list. At least one login mode of the user in the target task is obtained, at least one device of the user in the at least one login mode is determined based on a data file corresponding to the login mode of the user, and the obtained at least one device is taken as a second device list. According to the first device list and the second device list, a de-duplication processing is performed to remove repeated devices, and the number of devices after de-duplication is determined.

[0086] According to the number of devices after de-duplication and a weight corresponding to the number of user devices check, a check score of the number of user devices check is determined. Specifically, if the number of devices after de-duplication is not greater than a preset normal device quantity threshold, the check score of the number of user devices check can be a preset normal device number check score. For example, the preset normal device quantity is 1, and the preset normal device number check score is 0; if the number of devices after de-duplication is greater than the preset normal device quantity, the check score of the number of user devices check can be a product of the number of devices after de-duplication and the weight corresponding to the number of user devices check. The weight of the number of user devices check corresponding to the target activity can be pre-configured in the segmentation configuration.

[0087] For example, if the preset normal device quantity is 1, the preset normal device number check score is 0, and the weight of the number of user devices check is -10. If the number of user devices after de-duplication is 1, the check score of the number of user devices check is 0; if the number of user devices after de-duplication is 3, the check score of the number of user devices check is -30. Generally, the number of devices of a normal user is one and only one, and therefore, the weight of the number of user devices check is generally set to a negative number.

[0088] The check rule of the abnormal user name list check is as follows: obtaining user attribute information and user behavior information; obtaining the activity name, prize name and activity scene of the target activity according to the user behavior information; obtaining the configuration parameters in the link configuration and segmentation configuration according to the activity name, prize name and activity scene of the target activity; judging whether the current time is within the time range of the abnormal user name list check, if yes, obtaining the user attribute information, for example, the user mobile phone number; if no, determining the abnormal user name list check as a to-be-deleted check type, and setting the score thereof to a preset to-be-deleted score. If the current time is within the check time range of the abnormal user name list check, the user attribute information is searched in the abnormal user name list according to the user attribute information, it is judged whether the user is in the abnormal user name list, and the check score of the abnormal user name list check is determined according to the judgment result. The attribute information of at least one abnormal user is stored in the abnormal user name list.

[0089] The check score of the abnormal user name list check can be determined according to the judgment result and the weight corresponding to the abnormal user name list check. Specifically, if the judgment result is that the user is in the abnormal user name list, the check score of the abnormal user name list check is the weight itself; if the judgment result is that the user is not in the abnormal user name list, the check score of the abnormal user name list check can be a preset normal score, for example, the preset normal score can be 0 points.

[0090] For example, the weight corresponding to the preset abnormal user name list check is-20 points, and the normal score is 0 points. If the judgment result is that the user is in the abnormal user name list, the check score of the corresponding abnormal user name list check is-20 points; if the judgment result is that the user is not in the abnormal user name list, the check score of the corresponding abnormal user name list check is 0 points.

[0091] The check rule of the abnormal user IP check is as follows: obtaining user attribute information and user behavior information; obtaining the activity name, prize name and activity scene of the target activity according to the user behavior information; obtaining the configuration parameters in the link configuration and segmentation configuration according to the activity name, prize name and activity scene of the target activity; judging whether the current time is within the check time range of the abnormal user IP check, if yes, obtaining the user attribute information, for example, the user mobile phone number; if no, determining the abnormal user IP check as a to-be-deleted check type, and setting the score thereof to a preset to-be-deleted score.

[0092] If the current time is within the check time range of the abnormal user IP check, the events triggered by the user during the target task are obtained, the corresponding data file of the front-end event check is retrieved based on the event check, at least one IP address of the user during the event activity task is determined according to the retrieval result, and the at least one obtained IP address is taken as a first IP address list. At least one IP address of the user during the file uploading process of the target task is obtained, and the at least one obtained IP address is taken as a second IP address list. At least one login mode of the user during the target task is obtained, at least one IP address of the user under the at least one login mode is determined based on the corresponding data file of the user login mode, and the at least one obtained IP address is taken as a third IP address list. According to the first IP address list, the second IP address list and the third IP address list, the de-duplication processing is performed, the repeated user IP addresses are removed, and the at least one IP address after de-duplication is taken as the user IP address. According to the user IP address, the abnormal user IP list is searched to determine the abnormal proportion of the abnormal user IP in the user IP address.

[0093] Specifically, according to the abnormal proportion and the weight corresponding to the abnormal user IP check, the check score of the abnormal user IP check is determined, which can be obtained by multiplying the abnormal proportion and the weight. The weight of the abnormal user IP check corresponding to the target activity can be pre-configured in the segment configuration.

[0094] For example, if the number of user IP addresses after de-duplication is 5, and 3 of the 5 user IP addresses are determined to be abnormal user IP addresses after searching the abnormal user IP list, the abnormal proportion of the abnormal user IP is 3 / 5, and the weight corresponding to the abnormal user IP check is-10 points, then the check score of the abnormal user IP check in the target activity is-6 points. Since the abnormal proportion of the abnormal user IP is determined, the weight of the abnormal user IP check is usually set to a negative number.

[0095] S350, according to the check score of the target check type, determine the total check score of the user.

[0096] The total check score of the user can be the sum of the check scores of the target check types. For example, if the check score of the front-end event check is 25 points, the check score of the client active check is 10 points, the check score of the user login mode check is-5 points, the check score of the user device number check is 0 points, the check score of the abnormal user list check is-10 points, and the check score of the abnormal user IP check is-5 points, then the total check score of the user is 15 points.

[0097] S360, judge whether the total check score exceeds the preset check score threshold.

[0098] The preset check score threshold can be preconfigured, and the same or different check score thresholds can be configured for different target activities by a related technical person in a link configuration. It is determined whether the check total score exceeds the preset check score threshold. If yes, it is determined that the current user is a normal user, and a winning or prize claiming notification can be sent to the user according to the target prize selected by the user.

[0099] For example, if the preset check threshold of the target task currently performed by the user is 40 points, and the check total score of the user is 45 points according to the check score of the target check type, it is determined that the user is a normal user. If the preset check threshold of the target task currently performed by the user is 40 points, and the check total score of the user is 35 points according to the check score of the target check type, the user is prohibited from sending a winning or prize claiming notification, and the user is further verified according to S370, that is, whether the user is an abnormal user.

[0100] When the check total score of the user exceeds the preset check score threshold, it is determined that the user is a normal user, and a prize claiming and winning notification can be sent to the normal user. When the check total score does not exceed the preset check score threshold, the user is prohibited from sending a prize claiming and winning notification, and the user whose check total score does not exceed the preset check score threshold needs to be further verified to determine whether the user is an abnormal user.

[0101] S370, if not, the user login mode and the number of user devices are checked according to the preset user login mode checking rule and the number of user devices checking rule, to obtain a first check score of the user login mode and a second check score of the number of user devices.

[0102] If the check total score does not exceed the preset check score threshold, the user can be further verified whether the user is an abnormal user. For example, the user login mode and the number of user devices can be checked according to the preset user login mode checking rule and the number of user devices checking rule, to obtain a first check score of the user login mode and a second check score of the number of user devices.

[0103] Specifically, if the user login manner and the number of user devices have been checked in the process of determining the check score of the target check type, the check score of the user login manner check can be directly obtained as the first check score, and the check score of the number of user devices check can be obtained as the second check score. If the user login manner and / or the number of user devices have not been checked in the process of determining the check score of the target check type, the user login manner and / or the number of user devices can be checked according to the preset user login manner check rule and / or the number of user devices check rule to obtain the first check score of the user login manner and / or the second check score of the number of user devices.

[0104] S380, determining whether the first check score and / or the second check score meet a preset user abnormal condition, if yes, determining that the user is an abnormal user.

[0105] The user abnormal condition can be preset by a related technical person in advance. For example, the user abnormal condition can be that the first check score is less than zero and the second check score is less than zero, and then it can be determined that the user is an abnormal user. The user abnormal condition can also be that the first check score or the second check score is less than zero, and then it can be determined that the user is an abnormal user. The user abnormal condition can be set according to actual conditions, and the embodiment is not limited in this regard.

[0106] It should be noted that the abnormal user name list and the abnormal user IP list used in the process of checking the abnormal user name list and the abnormal user IP can be constantly updated, so that the check score of the abnormal user name list check and the check score of the abnormal user IP check are more accurate.

[0107] In an optional embodiment, after the total check score does not exceed the preset check score threshold, it further includes: checking the user attribute information according to the check rule of the abnormal user name list check type to obtain a third check score of the user attribute information; determining a score difference between the third check score and the total check score; if the score difference is not greater than a preset abnormal user name list score threshold, updating the user to the abnormal user name list.

[0108] The third check score can be the check score of the abnormal user name list check, and the abnormal user name list score threshold can be parameter configured in the link configuration in advance. For example, the abnormal user name list score threshold can be 15 points.

[0109] If the abnormal user list has been checked in the process of determining the check score of the target check type, the check score of the abnormal user list check can be directly obtained as the third check score; if the abnormal user list has not been checked in the process of determining the check score of the target check type, the user attribute information can be checked according to the check rule of the abnormal user list check type to obtain the third check score of the user attribute information.

[0110] A score difference between the third check score and the check total score is determined; if the score difference is not greater than a preset abnormal user list score threshold, the user is updated to the abnormal user list. If the score difference between the third check score and the check total score is a negative number, the absolute value of the score difference is compared with the preset abnormal user list score threshold. For example, if the third check score is -20 points, the check total score is -30 points, and the preset abnormal user list score threshold is 15 points, the score difference between the third check score and the check total score is 10 points, and the score difference is less than the preset abnormal user list score threshold, so the attribute information of the user does not need to be updated to the abnormal user list.

[0111] For example, if the third check score is -10 points, the check total score is -30 points, and the preset abnormal user list score threshold is 15 points, the score difference between the third check score and the check total score is 20 points, and the score difference is greater than the preset abnormal user list score threshold, so the attribute information of the user is updated to the abnormal user list.

[0112] In an optional embodiment, after the check total score does not exceed the preset check score threshold, the method further includes: checking the user attribute information according to the check rule of the abnormal user IP check type to obtain a fourth check score of the user attribute information; determining a score difference between the fourth check score and the check total score; and if the score difference is not greater than a preset abnormal user IP score threshold, updating the user to the abnormal user IP list.

[0113] The fourth check score can be a check score of an abnormal user IP check, and the abnormal user IP score threshold can be parameter-configured in a link configuration in advance. For example, the abnormal user list score threshold can be 10 points.

[0114] If the abnormal user IP has been checked in the process of determining the check score of the target check type, the check score of the abnormal user IP check can be directly obtained as the fourth check score; if the abnormal user IP has not been checked in the process of determining the check score of the target check type, the user attribute information can be checked according to the check rule of the abnormal user IP check type to obtain the fourth check score of the user attribute information.

[0115] determining a score difference between the fourth check score and the check total score; if the score difference is not greater than a preset abnormal user IP score threshold, updating the user to the abnormal user IP list. If the score difference between the fourth check score and the check total score is negative, the absolute value of the score difference is compared with the preset abnormal user IP score threshold. For example, if the fourth check score is -20, the check total score is -25, and the preset abnormal user IP threshold is 10, the score difference between the fourth check score and the check total score is 5, and the score difference is less than the preset abnormal user IP score threshold, so the attribute information of the user does not need to be updated to the abnormal user IP list.

[0116] For example, if the fourth check score is -10, the check total score is -30, and the preset abnormal IP score threshold is 10, the score difference between the fourth check score and the check total score is 20, and the score difference is greater than the preset abnormal user IP score threshold, so the attribute information of the user is updated to the abnormal user IP list.

[0117] The optional embodiment adds the user whose score difference between the third check score and the check total score is not greater than the preset abnormal username list score threshold to the abnormal username list, thereby updating the abnormal username list; and adds the user whose score difference between the fourth check score and the check total score is not greater than the preset abnormal user IP score threshold to the abnormal user IP list, thereby updating the abnormal user IP list. By updating the abnormal username list and the abnormal user IP list, the check scores of the abnormal username check and the abnormal user IP check are accurately determined, thereby improving the accuracy of the abnormal user determination result.

[0118] The embodiment updates the abnormal username list and the abnormal user IP list, thereby accurately determining the check scores of the abnormal username check and the abnormal user IP check, and improving the accuracy of the abnormal user determination result.

[0119] Example 4

[0120] Based on the technical solutions of the above embodiments, this application provides a preferred implementation method.

[0121] Figure 4A A schematic diagram of the structure of an abnormal user identification system provided in this application is shown below. Figure 4A As shown, the system includes: a real-time verification interface 10, an ELK (Elasticsearch, Logstash, Kibana) data system 20, and a multi-verification condition configuration module 30. The real-time verification interface 10 receives user attribute and behavior information in real time and outputs verification results for normal and abnormal users. The ELK data system 20 stores verification data, performs fast retrieval, and calculates and outputs user scores. The multi-verification condition configuration module 30 configures relevant parameters, including settings for multiple verification types.

[0122] The ELK data system 20 is connected to both the real-time verification interface 10 and the multi-verification condition configuration module 30. It acquires data transmitted by the real-time verification interface 10 and sends verification results to the real-time verification interface. It is also connected to the multi-verification condition configuration module 30 to acquire configuration parameters from the module and perform user verification based on these parameters.

[0123] The configuration in the multi-verification condition configuration module 30 can include segmentation configuration and link configuration. Segmentation configuration is used to configure the relevant parameters corresponding to the six verification conditions. Link configuration is used to combine and configure the verification links for the six verification types according to the activity task and prize.

[0124] Figure 4B This is a schematic diagram of the configuration page for segmented configuration. The configuration page includes configurable and selectable items. Configurable items allow technical personnel to set parameters according to needs, while selectable items allow technical personnel to select parameters according to needs. Configurable items include: segment name, time range, and weight. Selectable items include: verification type, time range unit, activity scenario, and status. The verification type options include front-end event tracking verification, client activity verification, user login method verification, user device count verification, abnormal user list verification, and abnormal user IP verification. Activity scenarios include winning and claiming prizes. Status includes on and off; the "status" selectable item indicates whether the currently selected verification type is enabled.

[0125] Figure 4CThe diagram illustrates the configuration page for link configuration. This page includes configurable and selectable items. Configurable items include: link name, return value, sorting, mobile phone blacklist threshold, IP blacklist threshold, success threshold, and verification point list. The return value is set to 0 by default. The sorting value is related to the priority of verification. This solution allows for the configuration of multiple links for different activities and prizes. The verification order can be set in the sorting value, where links with lower sorting values ​​can be set as priority verification links. The mobile phone blacklist threshold is the abnormal user list score threshold, the IP blacklist threshold is the abnormal user IP score threshold, and the success threshold is the verification score threshold. The verification point list allows for selection and configuration based on the verification type. If the verification type is front-end event tracking, corresponding event tracking can be entered in the event tracking input box.

[0126] The ELK data system verifies users and determines whether they are abnormal users based on the verification rules corresponding to the six verification types and the relevant parameters configured in the multi-verification condition configuration module. Verification records are stored in Elasticsearch (ES) files within the ELK system. The lists of abnormal users and abnormal IPs stored in the ELK data system are then updated.

[0127] This application's solution employs six verification types: front-end event tracking verification, client activity verification, user login method verification, user device count verification, abnormal user list verification, and abnormal user IP verification. This multi-condition fusion verification for abnormal user identification significantly improves verification accuracy. Detailed verification results are stored in an ES file within the ELK data system, supporting subsequent analysis and real-time querying. The abnormal user list and abnormal user IP list are updated in real-time, supporting subsequent verification. Even with the fusion of six verification types, real-time differentiation between normal and abnormal users is still achieved.

[0128] Example 5

[0129] Figure 5 This is a schematic diagram of an abnormal user identification device provided in Embodiment 5 of this application. The abnormal user identification device provided in this embodiment is applicable to situations where normal users and abnormal users are identified when users access internet resources. This device can be implemented using software and / or hardware. Figure 5 As shown, the device specifically includes: a user attribute information acquisition module 501, a target verification type determination module 502, a verification result determination module 503, and an abnormal user determination module 303.

[0130] The user attribute information acquisition module 501 is used to respond to the user's instruction to participate in a target activity, determine the target activity, and acquire the user's user attribute information.

[0131] The target verification type determination module 502 is configured to determine at least one target verification type according to the target activity and a preset association between activities and verification types.

[0132] The verification result determination module 503 is configured to perform verification on the user based on a target verification rule of the at least one target verification type according to the user attribute information and user behavior information of the user on the target activity, to obtain a verification result.

[0133] The abnormal user determination module 504 is configured to determine whether the verification result satisfies a user abnormality condition, and if yes, determine that the user is an abnormal user.

[0134] The embodiments of the present application determine at least one target verification type according to a target activity and a preset association between activities and verification types, perform verification on the user based on a target verification rule of the at least one target verification type according to user attribute information and user behavior information of the user on the target activity, to obtain a verification result, and determine whether the user is an abnormal user according to the verification result. The above scheme determines an abnormal user based on at least one target verification type corresponding to a target activity and a target verification rule of the at least one target verification type, and combines at least one verification type instead of using a single verification type to determine an abnormal user, thereby improving the accuracy of abnormal user determination. Through accurate identification of abnormal users, the situation of maliciously obtaining activity rewards by a third party is avoided, and a good user experience is provided.

[0135] Optionally, the verification types include front-end point verification, client active verification, user login mode verification, user device number verification, abnormal user name list verification, and abnormal user IP verification.

[0136] Optionally, the verification result determination module 503 includes:

[0137] The user behavior information acquisition unit is configured to acquire user behavior information of the user on the target task.

[0138] The verification score determination unit is configured to determine a verification score of the target verification type based on a target verification rule of the at least one target verification type according to the user attribute information and the user behavior information.

[0139] The verification total score determination unit is configured to determine a verification total score of the user according to the verification score of the target verification type.

[0140] The verification total score judgment unit is configured to determine whether the verification total score exceeds a preset verification score threshold.

[0141] The score determination unit is configured to, if the total score does not exceed the preset threshold score, check the user login mode and the number of user devices according to preset user login mode checking rules and user device number checking rules, and obtain a first checking score of the user login mode and a second checking score of the number of user devices.

[0142] Optionally, the total score determination unit comprises:

[0143] The abnormal condition judgment subunit is configured to determine whether the first checking score and / or the second checking score satisfy preset user abnormal conditions, and if so, determine that the user is an abnormal user.

[0144] Optionally, the device further comprises:

[0145] The target checking rule acquisition module is configured to, after determining at least one target checking type according to the target activity and a preset association between activities and checking types, acquire a current time and a target checking rule associated with any target checking type;

[0146] The checking time judgment module is configured to determine whether the current time is within a checking time range in any target checking rule according to the checking time range in the target checking rule;

[0147] The user checking module is configured to, if the current time is within the checking time range, perform checking on the user according to the user attribute information and user behavior information of the user on the target activity based on the target checking rule of the at least one target checking type.

[0148] Optionally, the device further comprises:

[0149] The to-be-deleted checking type determination module is configured to, after determining whether the current time is within the checking time range, if the current time is not within the checking time range, determine that the target checking type corresponding to the checking time range is a to-be-deleted checking type;

[0150] The to-be-deleted score determination module is configured to determine that a checking score of the to-be-deleted checking type is a preset to-be-deleted score.

[0151] Optionally, the device further comprises:

[0152] The third checking score determination module is configured to, after the total score does not exceed the preset threshold score, check the user attribute information according to a checking rule of an abnormal user list checking type, and obtain a third checking score of the user attribute information;

[0153] The score difference determination module is configured to determine a score difference between the third checking score and the total score.

[0154] an abnormal user list updating module, configured to update the user into the abnormal user list if the score difference is not greater than a preset abnormal user list score threshold.

[0155] The abnormal user determination apparatus can execute the abnormal user determination method provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of executing each abnormal user determination method.

[0156] Embodiment six

[0157] Figure 6 is a structural schematic diagram of an electronic device provided by Embodiment Four of the present application. Figure 6 A block diagram of an exemplary electronic device 600 suitable for implementing the present embodiments is shown. Figure 6 The electronic device 600 shown is merely one example and should not be construed as limiting the scope of the present embodiments.

[0158] As shown in Figure 6 the electronic device 600 is in the form of a general computing device. The components of the electronic device 600 can include, but are not limited to, one or more processors or processing units 601, a system memory 602, and a bus 603 that couples various system components including the system memory 602 and the processing unit 601.

[0159] The bus 603 represents one or more of any of several bus structures, including a memory bus or memory controller, a peripheral bus, a graphics accelerator bus, a processor or local bus using any of a variety of bus architectures. By way of example, these architectures include Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0160] The electronic device 600 typically includes a variety of computer system readable media. Such media can be any available media that is accessible by the electronic device 600 and includes both volatile and non-volatile media, removable and non-removable media.

[0161] The system memory 602 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 604 and / or cache memory 605. The electronic device 600 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 606 can be provided for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Figure 6 not shown, commonly referred to as a "hard disk drive", for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Although not specifically shown, alternate embodiments can implement the electronic device 600 with other types of magnetic storage devices, including a floppy disk drive, a tape drive, a jaz drive, a zip drive, an optical disk drive, etc. As these examples illustrate, the storage system 606 can be a removable storage system, a non-removable storage system, or a combination of both. Figure 6A disk drive, a floppy disk drive, and / or other memory unit, a flash memory card, a Digital Versatile Disc ROM (DVD-ROM), a Blu-ray disc, and / or other device suitable to read a computer program from, can also be provided using an appropriate drive / interface. The disk drives and their associated computer-readable media provide non-volatile storage of computer-readable instructions, data structures, program modules and other data for the electronic device 600. Although the exemplary environment described herein employs a hard disk, a floppy disk and / or CD-ROM drive, it should be appreciated by those skilled in the art that other types of computer readable media which are suitable, such as a magnetic cassette, a flash memory card, a Digital Versatile Disc, a Blu-ray disc, and the like could also be used. In one embodiment, the exemplary environment receives application programs, operating systems, program modules, and program data on the above-mentioned computer readable media. Generally, these

[0162] A user can enter commands and information into the electronic device 600 through one or more input devices, for example, a keyboard, a microphone, and the like. These and other input devices are connected to the processing unit 601 through the input / output interface 611 coupled to the system bus 603. A monitor or other type of display device is also connected to the system bus 603 via an interface, such as a video and / or

[0163] The electronic device 600 can also communicate to one or more external devices 609 such as a keyboard or a pointing device, a display 610, etc.; other devices such as a printer; or one or more devices that enable a user to interact with the electronic device 600; and / or any devices (e.g., a node of a Figure 6 Other hardware and / or software modules that can be used in the electronic device 600 can also be employed. Such hardware and / or software modules can include microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0164] The processing unit 601 performs various functions and processing applications and data processing by running programs stored in the system memory 602, such as implementing a method for determining an abnormal user.

[0165] Embodiment Seven

[0166] The embodiment seven of the present application further provides a storage medium comprising computer executable instructions, and a computer program is stored on the storage medium, and the computer program is executed by a processor to implement the abnormal user determination method provided by the embodiment of the present application, including: in response to a target activity participation instruction issued by a user, determining a target activity, and obtaining user attribute information of the user; determining at least one target verification type according to the target activity and a preset association relationship between activities and verification types; verifying the user based on a target verification rule of the at least one target verification type according to the user attribute information and user behavior information of the user on the target activity, to obtain a verification result; and determining that the user is an abnormal user if the verification result meets a user abnormal condition.

[0167] The computer storage medium of the embodiment of the present application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the computer readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or component.

[0168] The computer readable signal medium can include a data signal propagated in a baseband or as a part of a carrier wave, in which a computer readable program code is carried. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination thereof. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or component.

[0169] The program code contained on the computer readable medium can be transmitted by any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination thereof.

[0170] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0171] It is noted that the foregoing examples have been provided merely for the purposes of illustration. Other variations and modifications of the examples described above will be apparent to one skilled in the art, and can be made without departing from the scope of the application as defined in the appended claims. Furthermore, where a discrete plurality of items, components, etc. are described, it should be appreciated that interruptions can occur. In addition, where a process comprising a series of steps is described, it will be appreciated that steps can be added, omitted, reordered, etc. Furthermore, separate entities performing each of the steps described are neither required nor implied. Rather, such steps could be consolidated into a single entity or party which performs multiple functions or steps and vice versa.

Claims

1. An abnormal user determining method, characterized by, The method comprises the following steps: in response to a target activity participation instruction issued by a user, determining a target activity and obtaining user attribute information of the user; determining at least one target verification type according to the target activity and a preset association relationship between activities and verification types; verifying the user based on target verification rules of the at least one target verification type according to the user attribute information and user behavior information of the user with respect to the target activity, to obtain a verification result; judging whether the verification result meets a user abnormality condition, and if so, determining that the user is an abnormal user; wherein, after determining the at least one target verification type according to the target activity and the preset association relationship between activities and verification types, the method further comprises the following steps: obtaining a current time and a target verification rule associated with any target verification type; judging whether the current time is within a verification time range in any of the target verification rules, wherein the verification time range is an effective time for the user to complete a target task; if the current time is not within the verification time range, determining that the target verification type corresponding to the verification time range is a to-be-deleted verification type; determining that a verification score of the to-be-deleted verification type is a preset to-be-deleted score.

2. The method of claim 1, wherein, The verification types include front-end point verification, client active verification, user login method verification, user device number verification, abnormal user name list verification, and abnormal user IP verification.

3. The method of claim 2, wherein, The method of verifying the user based on the target verification rules of the at least one target verification type according to the user attribute information and the user behavior information of the user with respect to the target activity to obtain the verification result comprises the following steps: obtaining user behavior information of the user with respect to a target task; determining a verification score of the target verification type based on the target verification rules of the at least one target verification type according to the user attribute information and the user behavior information; determining a total verification score of the user according to the verification score of the target verification type; judging whether the total verification score exceeds a preset verification score threshold; if not, verifying a user login method and a user device number according to preset user login method verification rules and user device number verification rules to obtain a first verification score of the user login method and a second verification score of the user device number.

4. The method of claim 3, wherein, The method of judging whether the verification result meets the user abnormality condition and, if so, determining that the user is an abnormal user comprises the following steps: judging whether the first verification score and / or the second verification score meets a preset user abnormality condition, and if so, determining that the user is an abnormal user.

5. The method of claim 1, wherein, After judging whether the current time is within the verification time range, the method further comprises the following step: if the current time is within the verification time range, performing the verification of the user based on the target verification rules of the at least one target verification type according to the user attribute information and the user behavior information of the user with respect to the target activity.

6. The method of claim 3, wherein, After the total verification score does not exceed the preset verification score threshold, the method further comprises the following steps: verifying the user attribute information according to a verification rule of an abnormal user name list verification type to obtain a third verification score of the user attribute information; determining a score difference between the third check score and the check total score; if the score difference is not greater than a preset abnormal user list score threshold, updating the user to the abnormal user list.

7. An abnormal user determining apparatus characterized by comprising: The method comprises the steps of: a user attribute information obtaining module, configured to determine a target activity in response to a target activity participation instruction issued by a user, and obtain user attribute information of the user; a target check type determining module, configured to determine at least one target check type according to the target activity and a preset association between activities and check types; a check result determining module, configured to perform check on the user based on a target check rule of at least one target check type according to the user attribute information and user behavior information of the user on the target activity, and obtain a check result; an abnormal user determining module, configured to determine that the user is an abnormal user if the check result meets a user abnormal condition; a target check rule obtaining module, configured to obtain a current time and a target check rule associated with any target check type after determining at least one target check type according to the target activity and the preset association between activities and check types; a check time judging module, configured to judge whether the current time is within a check time range in any target check rule, wherein the check time range is an effective time for the user to complete a task of the target activity; a to-be-deleted check type determining module, configured to determine that a target check type corresponding to the check time range is a to-be-deleted check type if the current time is not within the check time range after judging whether the current time is within the check time range; a to-be-deleted score determining module, configured to determine that a check score of the to-be-deleted check type is a preset to-be-deleted score.

8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to implement the abnormal user determining method in any one of claims 1-6.

9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to implement the abnormal user determining method in any one of claims 1-6.

Citation Information

Patent Citations

  • Method and apparatus for preventing resource steal

    CN105100032A

  • Method and device for processing user network behavior

    CN105592008A

  • Abnormal transaction detection method and device, equipment and computer readable storage medium

    CN110163618A