Game cheat detection method and device, storage medium, and computer equipment

By determining whether the device is suspicious when logging into a game account and determining the supervision level based on historical and current plug-in usage data, the problem of lag in plug-in program monitoring is solved, rapid response and efficient supervision are achieved, and game security and balance are improved.

CN114904276BActive Publication Date: 2025-09-23BEIJING PERFECT WORLD SOFTWARE TECH DEV CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210404660.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-26
Publication Date
2025-09-23
Estimated Expiration
2040-08-26

AI Technical Summary

Technical Problem

The collection and monitoring of plug-in programs in existing technologies have a lag, making it difficult to respond quickly and narrow the scope of supervision, affecting game balance and security.

Method used

By determining whether the login device is a suspicious device when logging into a game account, obtaining and combining the first plug-in usage data and the second plug-in usage data, determining the supervision level, and dynamically updating the supervision strategy, suspicious devices can be supervised at different levels.

Benefits of technology

It improves the response efficiency of plug-in programs, enhances game security and balance, and reduces the time and manpower costs of anti-plug-in staff.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114904276B_ABST
    Figure CN114904276B_ABST
Patent Text Reader

Abstract

The present application discloses a method and apparatus for detecting game plug-ins, a storage medium, and a computer device. The method includes: when a game account login is detected, obtaining the device identification of the login device of the game account, and judging whether the login device is a suspicious device based on the device identification; if the login device is a suspicious device, obtaining the first plug-in usage data corresponding to the game account and the second plug-in usage data corresponding to the login device, wherein the second plug-in usage data includes historical plug-in usage data corresponding to the login device; determining the supervision level of the login device based on the first plug-in usage data and the second plug-in usage data, so as to track the plug-in usage status of the login device based on the supervision level. On the basis of narrowing the scope of plug-in supervision, the present application helps to quickly respond to plug-in programs, and ultimately improves the efficiency of plug-in response.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the Chinese patent application filed with the China Patent Office on August 26, 2020, with application number 202010870148.6 and titled “Game Cheats Detection Method and Device, Storage Medium, and Computer Equipment.” Technical Field

[0002] The present application relates to the field of computer technology, and in particular to a method and device for detecting game cheats, a storage medium, and a computer device. Background Art

[0003] With the widespread adoption of the internet, the online gaming industry, a pillar of the internet, has experienced rapid growth. As a form of entertainment, it has become integrated into people's daily lives, forming a "cyber culture" centered around gaming. Along with this rapid growth, the emergence of cheats has disrupted game balance, accelerated player turnover, harmed the profits of game manufacturers, and negatively impacted the entire gaming industry. The process of identifying cheat programs typically involves anti-cheating personnel manually or through programs to collect suspicious programs. They then assess the program's behavior to determine if it is a cheat. The signature code fields of programs identified as cheats are added to a cheat signature database, which is then used to identify cheat programs.

[0004] During the process of collecting cheat programs, anti-cheating staff face a difficult task, like searching for a needle in a haystack among a vast number of game accounts. Therefore, two existing approaches have been proposed to narrow the scope of cheat program collection: one is to provide a player reporting function, allowing players to report suspicious accounts in-game; the other is to focus on tracking and monitoring accounts with a history of using cheat programs.

[0005] However, anti-cheating is a process of attack and defense. No one side can always completely suppress the other; it can only be said that one side has the upper hand at certain times. Therefore, continuous tracking of cheat versions and timely updates are particularly important in the fight against cheating. Extensive practice has found that the two aforementioned methods have a certain lag in detecting cheats. How to set a reasonable cheat collection range and implement specific cheat program monitoring measures for accounts within the range, shorten the time anti-cheating personnel spend tracking down cheats, and improve the speed of cheat program response have always been key issues in the gaming industry. Summary of the Invention

[0006] In view of this, the present application provides a method and device for detecting game plug-ins, a storage medium, and a computer device. On the basis of narrowing the scope of plug-in program supervision, it helps to quickly respond to plug-in programs, ultimately improving the response efficiency of plug-in programs, enhancing game security, and protecting game balance.

[0007] According to one aspect of the present application, a method for detecting game plug-ins is provided, comprising: when a game account login is detected, obtaining a device identification of the login device of the game account, and judging whether the login device is a suspicious device based on the device identification; if the login device is a suspicious device, obtaining first plug-in usage data corresponding to the game account and second plug-in usage data corresponding to the login device, wherein the second plug-in usage data includes historical plug-in usage data corresponding to the login device; determining the supervision level of the login device based on the first plug-in usage data and the second plug-in usage data, so as to track the usage status of the plug-in program of the login device according to the supervision level.

[0008] According to another aspect of the present application, a game plug-in detection device is provided, including: a suspicious device judgment module, which is used to obtain the device identification of the login device of the game account when detecting that a game account is logged in, and determine whether the login device of the game account is a suspicious device based on the device identification; a plug-in data acquisition module, which is used to obtain first plug-in usage data corresponding to the game account and second plug-in usage data corresponding to the login device if the login device is a suspicious device, wherein the second plug-in usage data includes historical plug-in usage data corresponding to the login device; a first supervision level determination module, which is used to determine the supervision level of the login device based on the first plug-in usage data and the second plug-in usage data, so as to track the usage status of the plug-in program of the login device according to the supervision level.

[0009] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned game plug-in detection method is implemented.

[0010] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned method for detecting game plug-ins when executing the program.

[0011] By means of the above technical solution, the present application provides a method and device for detecting game cheats, a storage medium, and a computer device. When a game account is logged in, first, it is determined whether the login device of the game account is a suspicious device that has used cheat programs in the past. Secondly, after determining that the login device is a suspicious device, first cheat usage data is obtained for the current game experience behavior of the game account, and second cheat usage data corresponding to the login device's historical game behavior is obtained. Finally, the supervision level of the login device is determined based on the first cheat usage data corresponding to the current login of the game account and the second cheat usage data corresponding to the login device's historical game behavior. The embodiment of the present application sets a supervision level for suspicious devices with a cheat usage record, and updates the supervision level of the suspicious device based on the newly generated cheat usage data of the login device logging into the game account, so that anti-cheating personnel can perform different levels of supervision on the gaming behavior of the suspicious device based on the supervision level. On the basis of narrowing the scope of cheat program supervision, it helps to quickly respond to cheat programs, ultimately improving the response efficiency of cheat programs, enhancing game security, and protecting game balance.

[0012] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0014] Figure 1 A schematic diagram showing a flow chart of a method for detecting game cheats provided in an embodiment of the present application is shown;

[0015] Figure 2 A schematic diagram showing a flow chart of another method for detecting game cheats provided in an embodiment of the present application is shown;

[0016] Figure 3 A flowchart illustrating another method for detecting game cheats provided in an embodiment of the present application is shown;

[0017] Figure 4 A flowchart illustrating another method for detecting game cheats provided in an embodiment of the present application is shown;

[0018] Figure 5 A flowchart illustrating another method for detecting game cheats provided in an embodiment of the present application is shown;

[0019] Figure 6 A schematic diagram of the structure of a game cheat detection device provided in an embodiment of the present application is shown;

[0020] Figure 7 A structural diagram of another game plug-in detection device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0021] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.

[0022] In this embodiment, a method for detecting game cheats is provided. Figure 1 As shown, the method includes:

[0023] Step 101: When a game account login is detected, determine whether the login device of the game account is a suspicious device;

[0024] Step 102: If the login device is a suspicious device, obtain first cheat usage data corresponding to the game account and second cheat usage data corresponding to the login device;

[0025] Step 103: Determine the supervision level of the login device based on the first plug-in usage data and the second plug-in usage data, so as to track the usage status of the plug-in program of the login device according to the supervision level.

[0026] The embodiment of the present application can be applied to an anti-cheating server. After a game account logs in at a client (i.e., a login device), when the anti-cheating server receives the login information of the game account, it first determines whether the login device of the game account is a suspicious device. In the statistical results of big data, it is found that if a game account logged in by a certain device has used a cheat program, then this device is very likely to use cheats when logging in to other game accounts. Therefore, the embodiment of the present application records the device that has used the cheat program as a suspicious device and saves the cheat program usage record of the suspicious device; then, when it is determined that the login device of the game account is a suspicious device, it is detected whether the game account used the cheat program when logging in to the game experience this time. If the cheat program was used during the game experience, the cheat usage data of this login, i.e., the first cheat usage data, is collected, and the corresponding cheat program of the login device is further obtained. Finally, the supervision level of the login device is determined based on the first plug-in usage data corresponding to the game account and the second plug-in usage data corresponding to the login device, that is, the use of plug-ins by the game account during this game experience (or the use of plug-ins by the login device during this game experience) and the use of plug-ins by the login device of the game account in historical game experiences are combined to determine the supervision level of the login device. Anti-plug-in staff can supervise clients of different supervision levels. For example, they can focus on supervising the gaming behaviors of some clients with a large number of plug-in usage records, so as to timely discover new and variant plug-in programs with strong concealment, and conduct spot checks on the gaming behaviors of clients that occasionally use plug-ins, so as to save time and manpower costs, improve supervision efficiency, enhance game security, and protect game balance.

[0027] It should be noted that whether a game account uses plug-ins is usually determined by comparing and judging based on the feature code fields of the plug-in programs that have been discovered. For some new, variant, or packed plug-ins, the feature code fields of the plug-in programs that have been discovered may not cover the characteristics of these plug-ins. In other words, even if the game account is not detected as using plug-ins, it cannot be proved that the account does not use plug-ins. Therefore, in the embodiment of the present application, if the login device of the game account is a suspicious device, but the game account is not found to have used plug-in programs during the current game experience, the supervision level of the game device can also be re-determined based on the current game experience behavior of the game account. For example, because such devices are likely to use new, variant, or packed plug-ins, a special device database can be established for such devices, focusing on monitoring whether the devices in the database use new plug-ins, thereby facilitating the timely discovery of new plug-ins and improving game security.

[0028] By applying the technical solution of this embodiment, when a game account is logged in, first, it is determined whether the login device of the game account is a suspicious device that has used plug-in programs in the past. Secondly, after determining that the login device is a suspicious device, the first plug-in usage data is obtained for the current game experience behavior of the game account, and the second plug-in usage data corresponding to the login device is obtained. Finally, the supervision level of the login device is determined by combining the first plug-in usage data corresponding to the current login of the game account and the second plug-in usage data corresponding to the historical game behavior of the login device. The embodiment of the present application sets a supervision level for suspicious devices with a record of plug-in use, and updates the supervision level of the suspicious device based on the newly generated plug-in usage data when the login device logs in to the game account, so that anti-plug-in staff can perform different levels of supervision on the gaming behavior of the suspicious device based on the supervision level. On the basis of narrowing the scope of supervision of plug-in programs, it helps to quickly respond to plug-in programs, ultimately improving the response efficiency of plug-in programs, enhancing game security, and protecting game balance.

[0029] Furthermore, as a refinement and expansion of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another game cheat detection method is provided, such as Figure 2 As shown, the method includes:

[0030] Step 201: When a game account login is detected, the device identifier of the login device is obtained, and the device identifier is checked to see if it belongs to a suspicious device identifier included in a suspicious device database;

[0031] In step 201, a determination can be made as to whether the login device is a suspicious device based on the device identifier of the game account login device. Specifically, a query can be made in a pre-established suspicious device database to determine whether the login device identifier matches one of the suspicious device identifiers recorded in the database. If the device identifier matches one of the suspicious device identifiers, the login device is determined to be a suspicious device; otherwise, the login device is determined to be not a suspicious device. The devices corresponding to the suspicious device identifiers recorded in the suspicious device database are all devices that have been found to use cheat programs. Since these devices are likely to use cheat programs again, the corresponding suspicious device identifiers are recorded to form a database. The database can also record specific cheat usage data, such as the number of times the suspicious device has used cheat programs, the number of types of cheat programs used, and the amount of damage caused to other players or game developers by the suspicious device due to the use of cheat programs. Based on the cheat usage data corresponding to the suspicious device, the suspicious device can also be assigned a hazard level rating. In some scenarios, the hazard level rating can serve as a basis for determining the regulatory level of the suspicious device. The higher the hazard level of the device, the higher the corresponding regulatory level, i.e., the most stringent monitoring is applied to the most hazard-prone devices.

[0032] In an embodiment of the present application, for any suspicious device corresponding to the suspicious device database, specifically, if the type of plug-ins used in the history of any suspicious device is greater than a preset type threshold and / or the number of plug-ins used in the history of any suspicious device is greater than a preset number threshold, the game account login set on any suspicious device will be denied.

[0033] In this embodiment, the danger level of a suspicious device can be determined by the type of plug-in used and / or the number of times the plug-in is used. In the above implementation, if the type of plug-in used in the history of any suspicious device corresponding to the suspicious device database is greater than a preset value and / or the number of times the plug-in is used is greater than a preset value, such a "bad-record" device can be directly identified as a disabled device and prohibited from logging into any game account. In a specific application scenario, when a game account applies to log in, it can be determined whether the login device is the above-mentioned disabled device based on the device identifier corresponding to the login device of the game account, and the account login behavior on the disabled device can be rejected; or when it is determined that the login device is the above-mentioned disabled device, the logged-in account will be forced to exit or block.

[0034] In addition, embodiments of the present application may further include determining the hazard level of any suspicious device based on the types and / or frequency of historical plug-in usage corresponding to any suspicious device, and determining the regulatory level of the suspicious device based on the hazard level. For example, suspicious devices that use more than 10 types of plug-ins are placed in set A, and suspicious devices that use more than 20 plug-ins are placed in set B. The intersection of sets A and B is taken, and the corresponding suspicious devices in the A∩B set are regarded as the devices with the highest hazard level, and such devices are subject to the strictest regulation.

[0035] In the embodiment of the present application, specifically, the method for obtaining the device identification of the login device in step 201 may include:

[0036] Step 201-1, obtain the motherboard UUID return value of the login device through a preset function;

[0037] Step 201-2: If the motherboard UUID return value is a valid value, the motherboard UUID return value is used as the device identifier of the login device;

[0038] Step 201-3: If the motherboard UUID return value is an invalid value, obtain the GUID of the login device and determine the device identifier based on the GUID of the login device.

[0039] In this embodiment, in order to distinguish different devices, the unique feature code of each device should be recorded. Specifically, a preset function can be used to obtain the universal unique identification code UUID return value of the login device motherboard as the device identification of the device. In some cases, the preset function cannot obtain the UUID. At this time, the function will obtain a null return value, that is, the return value is an invalid value. At this time, the GUID value of the device can be obtained and used as the device identification through the MD5 algorithm (message digest algorithm) or other encryption algorithm. Or, based on the GUID value and preset parameters, the MD5 algorithm or other encryption algorithm can be run to obtain the device identification to ensure the uniqueness of the device identification. Different game login devices can be distinguished and identified through the device identification.

[0040] Step 202: If the login device is a suspicious device, then based on the cheat program database, check whether the game account has used a cheat program during this login;

[0041] In step 202, if the login device is determined to be a suspicious device based on the device identification of the login device, the current gaming behavior of the game account can be further detected to determine whether the account has used a plug-in program during the current gaming process. Specifically, the feature codes corresponding to the relevant gaming behaviors can be compared based on a preset anti-plug-in feature code database (the feature code database pre-stores feature codes of discovered plug-in programs). If a feature code matching a plug-in program is found, it indicates that the game account has used a plug-in program during the current gaming process. Otherwise, it is considered that the game account has not used a plug-in program or that the game account has not been found to have used a plug-in program in the current game.

[0042] Step 203: If the game account currently uses a cheat program, the type of cheat used by the game account currently is obtained, and historical cheat usage data of a suspicious device that matches the device identifier of the logged-in device is obtained from the suspicious device database as second cheat usage data.

[0043] In step 203, after discovering that the game account has used a plug-in program, it is possible to further identify which type of plug-in program the game account has used based on the specific comparison results of the plug-in program. For example, the game account has used the automatic aiming plug-in 1 and the full map view plug-in 2 this time. It is also possible to further read the historical plug-in usage data corresponding to the device identifier of the login device from the suspicious device database based on the device identifier of the login device. The historical plug-in usage data may specifically include the type of plug-in used by the corresponding suspicious device and the number of times each plug-in is used or the total number of times the plug-in is used.

[0044] Step 204: Update the historical cheat usage data of the logged-in device in the suspicious device database based on the type of cheat used by the game account for the current login and the type and number of cheats used historically by the logged-in device.

[0045] Step 205: Re-determine the supervision level of the login device based on the updated historical plug-in usage data corresponding to the login device.

[0046] In steps 204 and 205, the suspicious device database is updated according to the type of plug-in used by the game account this time, so that the suspicious device database can be dynamically updated according to real-time game behavior, which facilitates timely adjustment of the supervision level of the suspicious device based on the plug-in usage data of the suspicious device. Specifically, the hazard level of the device can be first calculated based on the plug-in usage data of the logged-in device, and then the supervision of the logged-in device can be re-determined based on the hazard level.

[0047] like Figure 3 As shown, the embodiment of the present application provides another method for detecting game cheats, the method comprising:

[0048] Step 301: When a game account login is detected, the device identifier of the login device is obtained, and the device identifier is checked to see if it belongs to a suspicious device identifier included in a suspicious device database;

[0049] Step 302: If the login device is a suspicious device, then based on the cheat program database, check whether the game account currently logged in uses a cheat program;

[0050] Step 303: If no cheat program is found in the current login of the game account, the supervision level corresponding to the login device in the suspicious device database is obtained and increased.

[0051] In the above embodiment, if the device identifier of the game account's login device is a suspicious device identifier, the login device can be determined to be a suspicious device. However, no cheat programs have been found to be used during the current game of this account. Therefore, no cheats have been found on the current suspicious device. There are two possible scenarios: 1. The device does not use cheats; 2. The device uses cheats, but its cheat signature is not in the anti-cheating signature database. In the second case, anti-cheating engineers need to focus on tracking such devices and discovering new cheat signatures. Therefore, when no cheat programs are found on the suspicious device, in order to promptly detect new cheats that may exist in such devices, the device's supervision level can be increased by 1.

[0052] In an embodiment of the present application, if it is the first case mentioned above, that is, the suspicious device does not use the plug-in anymore, specifically, the time when any suspicious device in the suspicious device database last used the plug-in is obtained; if the time when any suspicious device last used the plug-in is earlier than the preset time, then any suspicious device is removed from the suspicious device database.

[0053] In this embodiment, the suspicious device database can also store the time when the suspicious device uses the plug-in, specifically the time when the suspicious device last used the plug-in. Furthermore, if a suspicious device has not been found to use the plug-in program for a long time, the suspicious device can be removed from the suspicious device database or the supervision level of the suspicious device can be lowered. Anti-plug-in staff can focus more on supervising devices that are more likely to use plug-in programs.

[0054] like Figure 4 As shown, the embodiment of the present application provides another method for detecting game cheats, which includes:

[0055] Step 401: When a game account login is detected, the device identifier of the login device is obtained, and the device identifier is checked to see if it belongs to a suspicious device identifier included in a suspicious device database;

[0056] In step 402, if the login device is not a suspicious device, when it is detected that the game account has used a plug-in program for this login, the suspicious device database is updated based on the type of plug-in program used for this login by the game account and the device identifier of the login device.

[0057] In this embodiment, if the device identifier of the game account's login device does not belong to a suspicious device identifier, it can be determined that the login device is not a suspicious device. However, if the account uses a plug-in program in this game, the login device will be recorded as a suspicious device, and the suspicious device identifier and the type of plug-in program used by the device will be recorded in the suspicious device database, and the number of times the plug-in is used will be recorded as 1.

[0058] In addition, any embodiment of the present application also includes: obtaining the IP information corresponding to the game account logged in on a suspicious device whose supervision level is greater than a preset level threshold; based on the IP information, obtaining the target game account that matches the IP information to track the usage of the plug-in program of the target game account.

[0059] In the above embodiment, if the supervision level or hazard level of the suspicious device is high, the network address corresponding to the game account logged in on the device can be obtained, the target game account in the same network segment as the network address can be obtained, and the game behavior data of the target game account can be fed back to the anti-cheating staff for judgment, so as to discover high-risk accounts and high-risk devices in the same network segment and improve game security.

[0060] Figure 5 FIG. 1 shows a flow chart of a cheat detection method provided by an embodiment of the present application. Figure 5As shown, after the game account logs in, it first determines whether the login device is a suspicious device, and further determines whether the game account uses plug-ins. Based on the above judgment results, the supervision level of the login device is determined and the suspicious device database is updated.

[0061] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a detection device for game plug-ins, such as Figure 6 As shown, the device includes:

[0062] A suspicious device determination module 51 is used to determine whether the login device of the game account is a suspicious device when a game account login is detected;

[0063] The cheat data acquisition module 52 is used to acquire first cheat usage data corresponding to the game account and second cheat usage data corresponding to the login device if the login device is a suspicious device;

[0064] The first supervision level determination module 53 is used to determine the supervision level of the login device according to the first plug-in usage data and the second plug-in usage data, so as to track the usage status of the plug-in program of the login device according to the supervision level.

[0065] In specific application scenarios, such as Figure 7 As shown, the suspicious device determination module 51 specifically includes:

[0066] The first device identification obtaining unit 511 is configured to obtain the device identification of the login device and query whether the device identification belongs to the suspicious device identifications included in the suspicious device database;

[0067] The first suspicious device determining unit 512 is configured to determine that the login device is a suspicious device if the device identifier is a suspicious device identifier, and otherwise determine that the login device is not a suspicious device.

[0068] In specific application scenarios, such as Figure 7 As shown, the first plug-in usage data includes the plug-in type, and the suspicious device database includes the historical plug-in usage data of the suspicious device; the plug-in data acquisition module 52 specifically includes:

[0069] A cheat program detection unit 521 is used to detect whether a cheat program is used in the current login of the game account based on the cheat program database;

[0070] The cheat data acquisition unit 522 is used to obtain the type of cheat used by the game account during this login if the game account uses a cheat program, and to obtain historical cheat usage data of the suspicious device that matches the device identifier of the login device from the suspicious device database as the second cheat usage data.

[0071] In specific application scenarios, such as Figure 7 As shown, the second plug-in usage data includes the type and number of plug-in usage history corresponding to the login device, and the suspicious device database includes the supervision level of the login device; the first supervision level determination module 53 specifically includes:

[0072] The cheat data updating unit 531 is used to update the historical cheat usage data of the logged-in device in the suspicious device database based on the type of cheat used by the game account during the current login and the type and number of cheats used in the history of the logged-in device;

[0073] The supervision level determination unit 532 is used to re-determine the supervision level of the login device according to the updated historical plug-in usage data corresponding to the login device.

[0074] In specific application scenarios, such as Figure 7 As shown, the suspicious device database also includes the supervision level of the suspicious device; the device also includes:

[0075] The second supervision level determination module 54 is used to detect whether the game account has used a plug-in program for this login. If the game account has not used a plug-in program for this login, the supervision level corresponding to the login device in the suspicious device database is obtained and increased.

[0076] In specific application scenarios, such as Figure 7 As shown, the suspicious device determination module 51 specifically includes:

[0077] The second device identification obtaining unit 513 is used to obtain the device identification of the login device and query whether the device identification belongs to the suspicious device identification included in the suspicious device database;

[0078] A second suspicious device determining unit 514 is configured to determine that the login device is not a suspicious device if the device identifier does not belong to a suspicious device identifier;

[0079] The device also includes:

[0080] The database update module 55 is used to determine whether the login device of the game account is a suspicious device. If the login device is not a suspicious device, when it is detected that the game account has used a plug-in program for this login, the suspicious device database is updated based on the type of plug-in program used for this login of the game account and the device identification of the login device.

[0081] In a specific application scenario, not shown in the figure, the device identification acquisition unit 511 specifically includes:

[0082] The identification acquisition subunit 5111 is used to obtain the motherboard UUID (Universally Unique Identifier) ​​return value of the login device through a preset function;

[0083] The first identification determination subunit 5112 is configured to use the motherboard UUID return value as the device identification of the login device if the motherboard UUID return value is a valid value;

[0084] The second identification determination subunit 5113 is used to obtain the GUID (Globally Unique Identifier) ​​of the login device if the motherboard UUID return value is an invalid value, and determine the device identification based on the GUID of the login device.

[0085] In specific application scenarios, such as Figure 7 As shown, the device also includes:

[0086] The plug-in usage time acquisition module 56 is used to obtain the time when any suspicious device in the suspicious device database last used a plug-in;

[0087] The suspicious device removal module 57 is configured to remove any suspicious device from the suspicious device database if the time when any suspicious device last used a plug-in is earlier than a preset time.

[0088] In specific application scenarios, such as Figure 7 As shown, the device also includes:

[0089] The disabled device determination module 58 is used to deny login to the game account set on any suspicious device if the type of cheats used in the history of any suspicious device in the suspicious device database is greater than a preset type threshold and / or the number of cheats used in the history of any suspicious device is greater than a preset number threshold.

[0090] In specific application scenarios, such as Figure 7 As shown, the device also includes:

[0091] The IP information acquisition module 59 is used to obtain the IP information corresponding to the game account logged in on the suspicious device with a supervision level greater than a preset level threshold;

[0092] The target account acquisition module 50 is used to acquire a target game account that matches the IP information based on the IP information, so as to track the usage of the plug-in program of the target game account.

[0093] It should be noted that for other corresponding descriptions of the functional units involved in the game cheat detection device provided in the embodiment of the present application, please refer to Figures 1 to 5 The corresponding description in the method will not be repeated here.

[0094] Based on the above Figures 1 to 5 The method shown in FIG. 1 is a method for performing the above-mentioned operation. Accordingly, the embodiment of the present application further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned operation is performed. Figures 1 to 5 The game cheat detection method shown.

[0095] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each implementation scenario of the present application.

[0096] Based on the above Figures 1 to 5 The method shown, and Figure 6 、 Figure 7 In order to achieve the above-mentioned purpose, the embodiment of the present application further provides a computer device, which can be a personal computer, a server, a network device, etc. The computer device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to achieve the above-mentioned Figures 1 to 5 The game cheat detection method shown.

[0097] Optionally, the computer device may further include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a Wi-Fi module, etc. The user interface may include a display, an input unit such as a keyboard, etc., and the optional user interface may also include a USB interface, a card reader interface, etc. The network interface may optionally include a standard wired interface, a wireless interface (such as a Bluetooth interface, a Wi-Fi interface), etc.

[0098] Those skilled in the art will understand that the computer device structure provided in this embodiment does not constitute a limitation on the computer device, and may include more or fewer components, or a combination of certain components, or different component arrangements.

[0099] The storage medium may also include an operating system and a network communication module. An operating system is a program that manages and stores the hardware and software resources of a computer device, supporting the execution of information processing programs and other software and / or programs. The network communication module facilitates communication between components within the storage medium, as well as with other hardware and software within the physical device.

[0100] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus the necessary general hardware platform, or by means of hardware. When a game account is logged in, first, it is determined whether the login device of the game account is a suspicious device that has used cheat programs in the past. Secondly, after determining that the login device is a suspicious device, first cheat usage data is obtained for the current game experience behavior of the game account, and second cheat usage data corresponding to the login device is obtained. Finally, the supervision level of the login device is determined by combining the first cheat usage data corresponding to the current login of the game account and the second cheat usage data corresponding to the login device's historical game behavior. The embodiment of the present application sets a supervision level for suspicious devices with a cheat usage record, and updates the supervision level of the suspicious device based on the newly generated cheat usage data of the login device logging into the game account, so that anti-cheating personnel can perform different levels of supervision on the gaming behavior of the suspicious device based on the supervision level. On the basis of narrowing the scope of supervision of cheat programs, it helps to quickly respond to cheat programs, ultimately improving the efficiency of cheat program response, enhancing game security, and protecting game balance.

[0101] Those skilled in the art will understand that the accompanying drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the accompanying drawings are not necessarily required to implement the present application. Those skilled in the art will understand that the modules in the devices in the implementation scenario can be distributed in the devices of the implementation scenario according to the implementation scenario description, or can be changed accordingly and located in one or more devices different from the implementation scenario. The modules of the above-mentioned implementation scenario can be combined into one module, or can be further split into multiple sub-modules.

[0102] The serial numbers of the above application are for descriptive purposes only and do not represent the advantages or disadvantages of the implementation scenarios. The above disclosure only discloses several specific implementation scenarios of the present application, but the present application is not limited thereto. Any changes that can be conceived by those skilled in the art should fall within the scope of protection of the present application.

Claims

1. A method for detecting game cheats, characterized in that: include: When a game account login is detected, the device identifier of the game account login device is obtained, and based on the device identifier, whether the login device is a suspicious device is determined; If the login device is a suspicious device, obtaining first cheat usage data corresponding to the game account and second cheat usage data corresponding to the login device, wherein the second cheat usage data includes historical cheat usage data corresponding to the login device; the historical cheat usage data includes the type of cheats used in history and the number of times the cheats were used in history corresponding to the login device; Based on the type of plug-in used for the current login of the game account and the type of plug-in used historically and the number of times the plug-in has been used historically corresponding to the login device, the historical plug-in usage data of the login device in the suspicious device database is updated; based on the updated historical plug-in usage data corresponding to the login device, the supervision level of the login device is re-determined to track the usage status of the plug-in program of the login device according to the supervision level.

2. The method according to claim 1, characterized in that The obtaining of the first cheat usage data corresponding to the game account and the second cheat usage data corresponding to the login device specifically includes: Based on the plug-in program database, detecting whether the game account currently logs in using a plug-in program; If the game account currently logs in using a cheat program, obtaining the type of cheat used by the game account currently logging in as the first cheat usage data, and obtaining historical cheat usage data of the suspicious device that matches the device identifier of the login device from the suspicious device database as the second cheat usage data; If it is found that no plug-in program is used in the current login of the game account, the supervision level corresponding to the login device is obtained and increased.

3. The method according to claim 1, characterized in that The method further comprises: If the number of cheat types used in the history of any suspicious device is greater than a preset type threshold and / or the number of cheat times used in the history of any suspicious device is greater than a preset number threshold, the game account login on any suspicious device will be denied.

4. The method according to claim 1, further comprising: If the login device is not the suspicious device, detecting whether the game account currently logs in using a cheat program based on a cheat program database; When it is detected that a plug-in program is used in the current login of the game account, the historical plug-in usage data of the login device in the suspicious device database is updated based on the type of plug-in program used in the current login of the game account and the device identification of the login device.

5. The method according to claim 1, wherein The method further comprises: Obtain the time when a suspicious device corresponding to any suspicious device identifier in the suspicious device database last used a cheat; If the time when any of the suspicious devices last used a plug-in is earlier than a preset time, the suspicious device identifier corresponding to the suspicious device is removed from the suspicious device database.

6. The method according to claim 1, wherein The method further comprises: If the supervision level of the login device is greater than the preset level threshold, obtain the IP information corresponding to the game account logged in on the login device; According to the IP information, a target game account that matches the IP information is obtained to track the usage of the plug-in program of the target game account.

7. A device for detecting game cheats, characterized in that: include: A suspicious device determination module is configured to, upon detecting a game account login, obtain a device identifier of the game account login device and determine whether the game account login device is a suspicious device based on the device identifier; a cheat data acquisition module, configured to acquire, if the login device is a suspicious device, first cheat usage data corresponding to the game account and second cheat usage data corresponding to the login device, wherein the second cheat usage data includes historical cheat usage data corresponding to the login device; the historical cheat usage data includes the type and number of cheats used in history corresponding to the login device; The first supervision level determination module is used to update the historical plug-in usage data of the login device in the suspicious device database based on the type of plug-in used for the current login of the game account and the type of plug-in used in history and the number of times the plug-in has been used corresponding to the login device; and re-determine the supervision level of the login device based on the updated historical plug-in usage data corresponding to the login device, so as to track the usage status of the plug-in program of the login device according to the supervision level.

8. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting game cheats according to any one of claims 1 to 6 is implemented.

9. A computer device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein: When the processor executes the computer program, the method for detecting game cheats according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Method and server of preventing plug-in

    CN104079525A

  • Network behavior anti-cheating method and device and storage medium

    CN110198310A

  • Method, device and equipment for preventing user from illegally logging in, and storage medium

    CN111311285A