Method and device for identifying abnormal accounts in instant messaging system

Through the combination of Apriori algorithm and fuzzification processing, account exceptions in the instant communication system are identified, user information security issues are solved, and abnormal identification accuracy and system security are improved.

CN115080934BActive Publication Date: 2025-07-18BEIJING NORTH CAROLINA STAR TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210144909.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-17
Publication Date
2025-07-18
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

The account abnormality in the instant communication system causes the user information security to be unprotected.

Method used

The Apriori algorithm is used to mine the association rules of the user behavior set, and strong association rules are filtered out through fuzzy processing to identify the abnormal behavior of users in the instant communication system.

Benefits of technology

It improves the accuracy of abnormal identification of account numbers, ensures the security of user information, and prevents illegal login and data theft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115080934B_ABST
    Figure CN115080934B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method, device, equipment and medium for identifying account anomalies in an instant messaging system, which relates to the field of computer technology. Among them, the method includes: determining a behavior set containing at least one behavior item set; using the Apriori algorithm to perform association rule mining on the behavior items in the behavior set to obtain at least one association rule and its confidence; performing fuzzy processing on the confidence of at least one association rule to obtain at least one fuzzy confidence of the association rule; based on the fuzzy confidence of at least one association rule, screening at least one strong association rule from at least one association rule and adding at least one strong association rule to the strong association rule set; identifying the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set. This application solves the problem that the user information security cannot be guaranteed due to account anomalies in the instant messaging system existing in the related technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology. Specifically, this application relates to a method and device for identifying abnormal accounts in an instant messaging system. Background Art

[0002] With the development of communication technology, the instant messaging system has become the main tool for people to communicate, which stores a large amount of important information related to users. Since the instant messaging system avoids the need for users to frequently enter verification information when logging in, after a user successfully logs in to the instant messaging system using an account on a certain electronic device (such as a smart phone), the method of keeping the user logged in to the instant messaging system for a long time is adopted. If criminals illegally obtain the right to use this electronic device through hacking technology, they may use this account to steal data and spread illegal information.

[0003] As can be seen from the above, abnormal accounts in the instant messaging system will lead to the lack of guarantee of user information security. How to identify abnormal accounts in the instant messaging system remains to be solved. Summary of the Invention

[0004] Each embodiment of this application provides a method, device, electronic device and storage medium for identifying abnormal accounts in an instant messaging system, which can solve the problem in the related technology that the lack of guarantee of user information security is caused by abnormal accounts in the instant messaging system. The technical solutions are as follows:

[0005] According to one aspect of the embodiments of this application, a method for implementing abnormal account identification in an instant messaging system, the method includes: determining a behavior set including at least one behavior item set, the behavior item set including at least one behavior item, the behavior item being used to represent the usage behavior of a user in the instant messaging system; using the Apriori algorithm to perform association rule mining on the behavior items in the behavior set to obtain at least one association rule and its confidence, the association rule being used to indicate a first associated behavior item and a second associated behavior item that are mutually associated; performing fuzzy processing on the confidence of at least one association rule to obtain at least one fuzzy confidence of the association rule; based on the fuzzy confidence of at least one association rule, screening at least one strong association rule from at least one association rule and adding at least one strong association rule to a strong association rule set; and identifying the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set.

[0006] According to one aspect of the embodiments of the present application, a device for realizing account anomaly recognition in an instant messaging system includes: a behavior set generation module, configured to determine a behavior set including at least one behavior item set, the behavior item set including at least one behavior item, and the behavior item being used to represent the usage behavior of a user in the instant messaging system; an association rule mining module, configured to use the Apriori algorithm to mine association rules for the behavior items in the behavior set, to obtain at least one association rule and its confidence, the association rule being used to indicate a first associated behavior item and a second associated behavior item that are mutually associated; an association rule confidence fuzzification processing module, configured to perform fuzzification processing on the confidence of at least one association rule, to obtain the fuzzy confidence of at least one association rule; a strong association rule set generation module, configured to screen out at least one strong association rule from at least one association rule based on the fuzzy confidence of at least one association rule, and add at least one strong association rule to the strong association rule set; and an account anomaly recognition module, configured to recognize the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set.

[0007] According to one aspect of the embodiments of the present application, an electronic device includes: at least one processor, at least one memory, and at least one communication bus. Among them, a computer program is stored on the memory, and the processor reads the computer program in the memory through the communication bus; when the computer program is executed by the processor, it implements the method for realizing account anomaly recognition in the instant messaging system as described above.

[0008] According to one aspect of the embodiments of the present application, a storage medium stores a computer program thereon, and when the computer program is executed by a processor, it implements the method for realizing account anomaly recognition in the instant messaging system as described above.

[0009] According to one aspect of the embodiments of the present application, a computer program product includes a computer program, the computer program is stored in a storage medium, a processor of a computer device reads the computer program from the storage medium, and the processor executes the computer program, so that when the computer device executes, it implements the method for realizing account anomaly recognition in the instant messaging system as described above.

[0010] The beneficial effects brought by the technical solution provided by the present application are:

[0011] In the above technical solution, based on a behavior set including at least one behavior item set, the Apriori algorithm is used to mine association rules for the behavior items in the behavior set, obtaining at least one association rule and its confidence level, and performing a fuzzification process on the confidence levels of the at least one association rule to obtain the fuzzy confidence levels of the at least one association rule. Based on the fuzzy confidence levels of the at least one association rule, at least one strong association rule is screened from the at least one association rule and added to the strong association rule set. Finally, based on the strong association rules in the strong association rule set, the usage behaviors of users in the instant messaging system are identified. That is to say, by combining the Apriori algorithm and the fuzzification process, using the fuzzified association rules to mine the characteristics of the usage behaviors of users in the instant messaging system, not only can the account anomalies in the instant messaging system be effectively identified, thus solving the problem in the related technology that the account anomalies in the instant messaging system will lead to the insecurity of user information, but also the accuracy of account anomaly identification can be effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments of the present application.

[0013] Figure 1 is a schematic diagram of the implementation environment related to the present application;

[0014] Figure 2 is a flowchart of a method for implementing account anomaly identification in an instant messaging system according to an exemplary embodiment;

[0015] Figure 3 is a flowchart of a method for screening frequent sets according to the Apriori algorithm according to an exemplary embodiment;

[0016] Figure 4 is a flowchart of a method for calculating the fuzzy confidence level of an association rule according to an exemplary embodiment;

[0017] Figure 5 is a flowchart of another method for implementing account anomaly identification in an instant messaging system according to an exemplary embodiment;

[0018] Figure 6 is a flowchart of a method for updating a behavior set according to an exemplary embodiment;

[0019] Figure 7 is a block diagram of the structure of a device for implementing account anomaly identification in an instant messaging system according to an exemplary embodiment;

[0020] Figure 8It is a schematic structural diagram of a server shown according to an exemplary embodiment;

[0021] Figure 9 It is a block diagram of the structure of an electronic device shown according to an exemplary embodiment. Detailed implementation manners

[0022] The embodiments of the present application will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions from beginning to end. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present application, and cannot be construed as a limitation to the present application.

[0023] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say that an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The phrase "and / or" used herein includes all or any unit and all combinations of one or more related listed items.

[0024] The following is an introduction and explanation of several terms related to the present application:

[0025] The Apriori algorithm, a frequent item set algorithm for mining association rules, aims to discover the association rules between different items in a data set.

[0026] An instant messaging system allows two or more people to transmit text, pictures, files, voice and video in real time over the network, and can instantaneously send and receive Internet messages and other services.

[0027] An account, which is used to log in to the instant messaging system and can be composed of Chinese characters, numbers or English, or even some symbols. That is to say, after a user logs in to the instant messaging system using an account, he can transmit text, pictures, files, voice and video with others in real time over the network, and can also instantaneously send and receive Internet messages and other services.

[0028] As described above, in order to avoid frequent input of verification information when a user logs in to an instant messaging system, after a user successfully logs in to the instant messaging system using an account on a certain electronic device, the method of keeping the user logged in to the instant messaging system for a long time may allow an illegal element to steal data and spread illegal information using the account if they illegally obtain the right to use the electronic device through hacking techniques.

[0029] It can be seen that there are still defects in the related art that the security of user information cannot be guaranteed due to abnormal accounts in the instant messaging system.

[0030] In view of the above problems, the present application proposes a method, apparatus, electronic device, and storage medium for realizing account anomaly recognition in an instant messaging system, which can effectively identify account anomalies in the instant messaging system, thereby solving the problem in the related art that the security of user information cannot be guaranteed due to abnormal accounts in the instant messaging system. Correspondingly, this method is applicable to an apparatus for realizing account anomaly recognition in an instant messaging system, and this apparatus can be deployed on an electronic device with a von Neumann architecture, and this electronic device can be a desktop computer, a laptop computer, a server, etc.

[0031] To make the purpose, technical solution, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0032] Figure 1 It is a schematic diagram of the implementation environment involved in a method for realizing account anomaly recognition in an instant messaging system. This implementation environment includes a terminal 100 and a server 200.

[0033] Specifically, the terminal 100 can be used to run a client (such as an instant messaging system), and can be an electronic device such as a desktop computer 110, a laptop computer 130, a tablet computer 150, a smart phone 170, etc., which is not limited here.

[0034] Among them, the client, such as an instant messaging system, provides instant messaging functions, and can be in the form of an application program or a web page. Correspondingly, the user interface for the client to perform instant messaging can be in the form of a program window or a web page, which is not limited here either.

[0035] The server 200 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. For example, in this implementation environment, the server 200 provides account anomaly recognition services for the terminal 100.

[0036] A communication connection is established in advance between the terminal 100 and the server 200 by means of wired / wireless or the like, so as to realize data transmission between the terminal 100 and the server 200 through the established communication connection. The data to be transmitted may be an item of behavior to be recognized, a set of strong association rules, an identity authentication message, and so on.

[0037] As the instant messaging system runs on the terminal 100, the usage behavior of the user in the instant messaging system will be reported to the server 200 as an item of behavior to be recognized, requesting the server 200 to provide an account anomaly recognition service.

[0038] Through the interaction between the terminal 100 and the server 200, the server 200 can receive the item of behavior to be recognized, and then recognize the item of behavior to be recognized according to the strong association rules in the set of strong association rules.

[0039] Please refer to Figure 2 In the embodiment of the present application, a method for realizing account anomaly recognition in an instant messaging system is provided. This method is applicable to Figure 1 the server 200 in the implementation environment shown.

[0040] In the following method embodiments, for the sake of convenience of description, the execution subject of each step is described as the server, but this is not a specific limitation thereto.

[0041] As Figure 2 shown, the method may include the following steps:

[0042] Step 310, determine a behavior set including at least one behavior item set.

[0043] Among them, the behavior item set includes at least one behavior item, and the behavior item is used to represent the usage behavior of the user in the instant messaging system.

[0044] The following is an introduction and explanation of several terms involved in step 310:

[0045] A behavior item refers to the usage behavior of the user in the instant messaging system, specifically referring to various interaction behaviors and results that occur between the user and the page elements in the instant messaging system during the process of using the account to log in to the instant messaging system.

[0046] A behavior item set is a set of behavior items. In one embodiment, the behavior item set includes, but is not limited to, a user identifier and a behavior item. Among them, the user identifier is used to uniquely represent the user who logs in to the instant messaging system using the account. In one embodiment, within a set period, multiple behavior items corresponding to the same user generate a behavior item set, and the set period can be flexibly adjusted according to the actual needs of the application scenario. For example, the set period is 12 hours in this embodiment.

[0047] A behavior set is composed of multiple behavior item sets.

[0048] For example, the usage behaviors of user Xiaoming in the instant messaging system include: login behavior, conversation behavior, transfer behavior, logout behavior, etc. Correspondingly, the behavior items at least include: login, conversation, transfer, logout, etc.

[0049] For user Xiaoming, the behavior item set can be at least expressed as {login, conversation, transfer, logout}.

[0050] By analogy, for a large number of users, the behavior set can actually contain behavior item sets corresponding to different users. That is to say, the behavior set contains at least one behavior item set.

[0051] After determining the behavior set that contains at least one behavior item set, it is possible to implement account anomaly recognition in the instant messaging system based on this behavior set.

[0052] Step 330: Use the Apriori algorithm to mine association rules for the behavior items in the behavior set, and obtain at least one association rule and its confidence.

[0053] First of all, it should be noted that this association rule is used to indicate the first associated behavior item and the second associated behavior item that are mutually associated.

[0054] The following is an introduction and explanation of several terms involved in step 330:

[0055] Support: The support of the behavior item in the behavior item set, specifically referring to the probability of the behavior item appearing in this behavior item set. Among them, the calculation formula of the support is as follows:

[0056]

[0057] In the formula: P sup (A) is the support of behavior item A, c(A) is the number of times behavior item A appears in the behavior item set I in the behavior set C, is the total number of all behavior item sets I in the behavior set C.

[0058] Confidence: The confidence of the association rule. On the premise that the association rule indicates the first associated behavior item and the second associated behavior item that are mutually associated, the confidence of this association rule specifically refers to the confidence of the mutual association between the first associated behavior item and the second associated behavior item. Among them, the calculation formula of the confidence is as follows:

[0059]

[0060] In the formula: is the association rule Confidence, specifically refers to the confidence that the first associated behavior item A and the second associated behavior item B are associated with each other, P sup (A ∪ B) is the support degree that the first associated behavior item A and the second associated behavior item B are associated with each other, specifically referring to the probability that the first associated behavior item A and the second associated behavior item B appear in the same behavior item set at the same time, P sup (A) is the support degree of the behavior item A;

[0061] Now, in combination with the above nouns, the process of mining association rules using the Apriori algorithm is described as follows:

[0062] Step 331, according to the support degree of each behavior item in the behavior set, filter out the frequent items from the behavior items in the behavior set, and form the frequent item set of the behavior set from the filtered frequent items.

[0063] Among them, a frequent item refers to a behavior item whose support degree in the behavior item set is greater than the set support degree; a frequent item set refers to a set of frequent items.

[0064] Specifically, the formation process of the frequent item set of the behavior set can include the following steps:

[0065] The first step is to generate the first candidate item set according to each behavior item in the behavior set.

[0066] Table 1 Behavior set C

[0067]

[0068] As shown in Table 1 above, in the behavior set C, there are 10 behavior item sets I, and each behavior item set I contains at least one behavior item. Among them, the behavior items in each behavior item set I can be any one or more of transfer, session, open email, logout, and login. It is worth mentioning that the above 10 behavior item sets can correspond to the same set period of different users, or different set periods of the same user, which is not limited here.

[0069] As Figure 3 shown, the candidates in the first candidate item set C1 include: {transfer}, {session}, {open email}, {logout}, {login}.

[0070] The second step is to filter the candidates in the first candidate item set based on the support degree of the candidates in the first candidate item set, and generate the frequent item set from the filtered candidates.

[0071] Among them, the calculation formula for the support degree of candidate A in the first candidate item set C1 is as follows:

[0072]

[0073] Wherein: P sup (A) is the support degree of candidate item A, c(A) is the number of times candidate item A appears in the behavior item set I of the behavior set C, and is the total number of all behavior item sets I in the behavior set C (10);

[0074] Taking the transfer as an example of the candidate item, the number of times the transfer appears in each behavior item set I of the behavior set C in Table 1 is 7 times, then the support degree of the transfer is 7 / 10 = 0.7. And so on, as Figure 3 shown, the support degrees of the remaining candidate items (session, open email, log out, log in) in the first candidate item set are 0.8, 0.7, 0.2, and 0.3 respectively.

[0075] In one embodiment, screening the candidate items in the first candidate item set specifically means that if the support degree of the candidate item in the first candidate item set is greater than the set support degree, then this candidate item is used as a frequent item. Based on this, if the set support degree is 0.2, then, among the candidate items {transfer}, {session}, {open email}, {log out}, {log in} in the first candidate item set C1, the support degrees are all greater than 0.2 and can all be used as frequent items.

[0076] Thus, as Figure 3 shown, the frequent item set L1 is obtained, and the frequent items in this frequent item set L1 include: {transfer}, {session}, {open email}, {log out}, {log in}. That is to say, the frequent items in this frequent item set L1 include one behavior item, and then this frequent item set L1 can also be considered as a 1-item frequent item set.

[0077] The third step is to generate a second candidate item set according to the frequent items in the frequent item set.

[0078] Specifically, as Figure 3 shown, in the frequent item set L1, any two frequent items are selected as candidate items to generate the second candidate item set C2, and the candidate items in this second candidate item set C2 include: {transfer, session}, {transfer, open email}, {transfer, log out}, {transfer, log in}, {session, open email}, {session, log out}, {session, log in}, {open email, log out}, {open email, log in}, {log out, log in}.

[0079] The fourth step is to screen the candidate items in the second candidate item set based on the support degrees of the candidate items in the second candidate item set, and generate a frequent item set from the screened candidate items.

[0080] Similarly to the candidate item screening process in the first candidate item set, if the set support degree is 0.2, as Figure 3As shown in the figure, the candidate items in the second candidate item set with a support greater than 0.2 include: {Transfer, Session}, {Transfer, Open Email}, {Transfer, Login}, {Session, Open Email}, {Session, Logout}, {Open Email, Login}, which can be used as frequent items.

[0081] Thus, as Figure 3 shown in the figure, the frequent item set L2 is obtained. The frequent items in the frequent item set L2 include: {Transfer, Session}, {Transfer, Open Email}, {Transfer, Login}, {Session, Open Email}, {Session, Logout}, {Open Email, Login}. That is to say, the frequent items in this frequent item set L2 include two behavior items, so this frequent item set L2 can also be regarded as a 2-item frequent item set.

[0082] Step 5: Return to execute the third step of generating the second candidate item set according to the frequent items in the frequent item set until the support of the candidate items in the second candidate item set is less than the set support, and form the frequent item set of the behavior set from the generated frequent item set.

[0083] For example, as Figure 3 shown in the figure, after obtaining the frequent item set L3, select any two frequent items as candidate items to generate the second candidate item set C4. The candidate items in the second candidate item set C4 include: {Transfer, Session, Open Email, Login}. Combining Table 1, it is determined that the support of this candidate item is 1 / 10 = 0.1. Since the support of this candidate item 0.1 is less than the set support 0.2, no frequent item set can be obtained again. At this time, do not return to the third step, and form the frequent item set of the behavior set from the generated frequent item set.

[0084] That is to say, as Figure 3 shown in the figure, based on the behavior set C, the frequent item sets L1, L2, and L3 can be obtained.

[0085] Step 333: Based on each frequent item in the frequent item set, determine the first associated behavior item and the second associated behavior item that are mutually associated in this frequent item.

[0086] As Figure 3 shown in the figure, in the frequent item set L1, the frequent item includes one behavior item, and there are no mutually associated first associated behavior item and second associated behavior item.

[0087] In the frequent item set L2, the frequent item includes two behavior items, and then it is possible to determine the first associated behavior item and the second associated behavior item that are mutually associated in this frequent item. For example, in the frequent item {Transfer, Session}, the first associated behavior item that is mutually associated is Transfer, and the second associated behavior item is Session.

[0088] Similarly, in the frequent item set L3, the frequent items include three behavioral items, and the first associated behavioral item and the second associated behavioral item that are associated with each other in the frequent item can also be determined. For example, in the frequent item {transfer, conversation, open email}, the first associated behavioral item associated with each other is transfer, and the second associated behavioral items can be conversation and open email. Similarly, the associated behavioral items can also be: the first associated behavioral item is conversation, the second associated behavioral items are transfer and open email; the first associated behavioral item is open email, the second associated behavioral items are transfer and conversation; the first associated behavioral item is transfer and conversation, the second associated behavioral item is open email; the first associated behavioral item is transfer and open email, the second associated behavioral item is conversation; the first associated behavioral item is conversation and open email, the second associated behavioral item is transfer, and so on.

[0089] As can be seen from the above, the first / second associated behavioral item can be one behavioral item or multiple behavioral items, which is specifically related to the number of behavioral items included in the frequent item, and no specific limitation is constituted here.

[0090] Step 335: For each first associated behavioral item, calculate the confidence that the first associated behavioral item and the second associated behavioral item are associated with each other.

[0091] Among them, the calculation formula for the confidence that the first associated behavioral item and the second associated behavioral item are associated with each other is as follows:

[0092]

[0093] In the formula: represents the confidence that the first associated behavioral item A and the second associated behavioral item B are associated with each other, and P sup (A∪B) represents the support of the item set I in the behavior set C where the first associated behavioral item A and the second associated behavioral item B appear simultaneously, and P sup (A) is the support of the first associated behavioral item A;

[0094] On the premise of the first associated behavioral item and the second associated behavioral item that are associated with each other determined by the frequent item sets L1, L2, and L3, the confidence that the first associated behavioral item and the second associated behavioral item are associated with each other is shown in Table 2.

[0095] Table 2 Confidence of the Association between the First Associated Behavioral Item and the Second Associated Behavioral Item

[0096]

[0097]

[0098] Step 337: Based on the confidence that the first associated behavioral item and the second associated behavioral item are associated with each other, at least one association rule and its confidence are mined.

[0099] As shown in Table 2 above, the association rules and their confidence levels are mined. The association rules are used to indicate the first associated behavior item and the second associated behavior item that are mutually associated. For example, if the first associated behavior item is {transfer}, and the second associated behavior item is {session}, then the association rule can be expressed as transfer -> session, with a confidence level of 71.43%; or, if the first associated behavior item is {transfer, session}, and the second associated behavior item is {open email}, then the association rule can be expressed as transfer, session -> open email, with a confidence level of 60%; or, if the first associated behavior item is {login}, and the second associated behavior item is {transfer, open email}, then the association rule can be expressed as login -> transfer, open email, with a confidence level of 100%.

[0100] Step 350: Fuzzify the confidence levels of at least one association rule to obtain the fuzzy confidence levels of at least one association rule.

[0101] Among them, the fuzzification process can be implemented through Gaussian membership functions, generalized bell-shaped membership functions, S-shaped membership functions, trapezoidal membership functions, triangular membership functions, Z-shaped membership functions, etc., as well as the centroid method, maximum membership degree method, coefficient weighted average method, arithmetic average method, etc. In this embodiment, the fuzzification process is implemented through triangular membership functions and the arithmetic average method.

[0102] Specifically, as Figure 4 shown, in one embodiment, step 350 may include the following steps:

[0103] Step 351: For each association rule, based on the first associated behavior item and the second associated behavior item that are mutually associated indicated by the association rule, determine the triangular fuzzy set of the mutual association between the first associated behavior item and the second associated behavior item.

[0104] In one embodiment, step 351 may include the following steps: Obtain several triangular fuzzy numbers of the mutual association between the first associated behavior item and the second associated behavior item according to the constructed triangular fuzzy number storage table; calculate the average value based on the several triangular fuzzy numbers as the triangular fuzzy set of the mutual association between the first associated behavior item and the second associated behavior item.

[0105] It should be noted here that the triangular fuzzy number storage table actually establishes the correspondence between semantic variables and triangular fuzzy numbers. The semantic variables are used to describe the evaluation results of technicians on the occurrence probability of behavior items, specifically including 7 semantic variables such as "very high", "high", "slightly high", "medium", "slightly low", "low", "very low". Based on this, the triangular fuzzy number storage table formed by the correspondence between each semantic variable and triangular fuzzy numbers is shown in Table 3.

[0106] Table 3 Triangular Fuzzy Number Storage Table

[0107] Serial number Semantic variable Triangular fuzzy number 1 Very high (0.9,1.0,1.0) 2 High (0.7,0.9,1.0) 3 Slightly high (0.5,0.7,0.9) 4 Medium (0.3,0.5,0.7) 5 Slightly low (0.1,0.3,0.5) 6 Low (0,0.1,0.3) 7 Very low (0,0,0.1)

[0108] Then, after collecting the judgment results of multiple technicians on the occurrence probability of the behavior items, the semantic variables used to describe the judgment results of the multiple technicians on the occurrence probability of the behavior items can be converted into multiple triangular fuzzy numbers through Table 3, and each triangular fuzzy number corresponds to the judgment result of a technician on the occurrence probability of the behavior item.

[0109] Then, the arithmetic mean method is used to synthesize the judgment results of multiple technicians, that is, the average value is calculated based on multiple triangular fuzzy numbers as the triangular fuzzy set of the correlation between the first associated behavior item and the second associated behavior item, denoted as P fuz =<a, b, c>.

[0110] That is to say, on the premise of considering the confidence level of the correlation between the first associated behavior item and the second associated behavior item, the triangular fuzzy set combines and considers the probabilities of the first associated behavior item and the second associated behavior item appearing in the same behavior item set simultaneously, which is conducive to improving the accuracy of account anomaly recognition.

[0111] Step 353, according to the confidence level of the correlation between the first associated behavior item and the second associated behavior item and the triangular fuzzy set, calculate the fuzzy confidence level of the correlation between the first associated behavior item and the second associated behavior item as the fuzzy confidence level of this association rule.

[0112] Specifically, assume that the triangular fuzzy set of the correlation between the first associated behavior item A and the second associated behavior item B is P fuz =<a, b, c>, then the calculation formula for the fuzzy confidence level of the association rule is as follows:

[0113]

[0114] In the formula: is the confidence level of the correlation between the first associated behavior item A and the second associated behavior item B, is the fuzzy confidence level of the correlation between the first associated behavior item A and the second associated behavior item B, that is, the fuzzy confidence level of the association rule A->B.

[0115] Step 370, based on the fuzzy confidence levels of at least one association rule, screen at least one strong association rule from at least one association rule and add at least one strong association rule to the strong association rule set.

[0116] Specifically, according to the minimum confidence level P min_con to judge the fuzzy confidence level of the association rule: if is greater than or equal to P min_con, then define this association rule as a strong association rule and add it to the set of strong association rules; if is less than P min_con , then define this association rule as a weak association rule. Among them, the minimum confidence P min_con is used to represent the lowest reliability of the association rule and can be flexibly adjusted according to the actual needs of the application scenario, which is not limited here.

[0117] For example, as shown in Table 2, assume that the minimum confidence P min_con is 70%. Then the strong association rules in the set of strong association rules include: transfer -> session; transfer -> open email; open email -> transfer; open email -> session; login -> transfer; login -> open email; logout -> session; login -> transfer, open email; transfer, login -> open email; open email, login -> transfer.

[0118] Step 390, identify the usage behavior of the user in the instant messaging system according to the strong association rules in the set of strong association rules.

[0119] Account anomaly identification is actually to identify the usage behavior of the user in the instant messaging system. If it is identified that the usage behavior of the user in the instant messaging system is abnormal, it is considered that the account used by the user to log in to the instant messaging system is abnormal.

[0120] In one embodiment, step 390 may include the following steps: receive the behavior item to be identified, where the behavior item to be identified is used to represent the usage behavior of the user waiting to be identified in the instant messaging system; in the set of strong association rules, search for the strong association rule indicating the behavior item to be identified; if a strong association rule is found, based on the first associated behavior item and the second associated behavior item indicated in the found strong association rule that are mutually associated, determine whether there is a second associated behavior item that is mutually associated with the behavior item to be identified; if not, determine that the behavior item to be identified is an abnormal behavior item, otherwise, determine that the behavior item to be identified is a normal behavior item.

[0121] For example, the behavior habit of user Xiaoming in the instant messaging system is to open an email to confirm the transfer information before making a transfer. Then, for user Xiaoming, the mutually related behavior items at least include making a transfer and opening an email. Correspondingly, based on the usage behavior of user Xiaoming in the instant messaging system, the strong association rules in the formed strong association rule set at least include transfer -> open email. Therefore, for user Xiaoming, if it is the user himself / herself logging in, the account can be recognized as normal. On the contrary, if it is an illegal login by others, since they do not understand the behavior habit of user Xiaoming in the instant messaging system. For example, they may directly make a transfer. At this time, for the server, for the to-be-recognized behavior item - making a transfer, since there is only the first associated behavior item - making a transfer, and there is no second associated behavior item - opening an email, that is to say, there is no second associated behavior item mutually related to the first associated behavior item, then it is determined that the to-be-recognized behavior item - making a transfer is an abnormal behavior item, that is, the account is recognized as abnormal.

[0122] Through the above process, by combining the Apriori algorithm and the fuzzification process, and using the fuzzy association rules to mine the characteristics of the usage behavior of users in the instant messaging system, not only can the account anomalies in the instant messaging system be effectively recognized, thus solving the problem in the related technology that the account anomalies in the instant messaging system will lead to the lack of guarantee of user information security, but also the accuracy rate of account anomaly recognition can be effectively improved.

[0123] Please refer to Figure 5 , in the embodiments of the present application, a possible implementation manner of the method for realizing account anomaly recognition in an instant messaging system is provided. After step 390, the method may further include the following steps:

[0124] Step 410, if the to-be-recognized behavior item is an abnormal behavior item, then determine the risk level of the abnormal behavior item according to the first set values of different risk levels.

[0125] Specifically, three risk levels (low risk level, medium risk level, high risk level) are set to classify the user's abnormal behavior:

[0126] P1 = P min_con ;

[0127]

[0128]

[0129] In the formula: P1 represents the low risk level probability, P2 represents the medium risk level probability, P3 represents the high risk level probability, and 0 ≤ P1 < P2 < P3 ≤ 1 is satisfied.

[0130] In other words, the first set value for the low risk level is P1, the first set value for the medium risk level is P2, and the first set value for the high risk level is P3. For example, if the fuzzy confidence level of the abnormal behavior item is less than P1, the risk level of the abnormal behavior item is the low risk level.

[0131] Step 420: Based on the risk level of the abnormal behavior item, push the corresponding identity authentication message to the instant messaging system.

[0132] Among them, the identity authentication message is used to indicate the risk level of the abnormal behavior item violating the strong association rule. That is to say, the server pushes the corresponding identity authentication message to the instant messaging system based on the risk level of the abnormal behavior item, so that the instant messaging system can initiate different intensities of challenges to the user, so as to verify whether the user logging in to the instant messaging system using the account is the user himself. That is, if the user responds and passes, it is regarded as the user himself passing, and other operations can be continued, thereby further fully guaranteeing the security of user information in the instant messaging system.

[0133] Specifically, the identity authentication mechanism is set as follows:

[0134] 1) If μ A (x i ) is less than P1, it is determined that the abnormal behavior item x i is at the low risk level, and the strong association rule involved in the abnormal behavior item x i is determined as a low-strength strong association rule. Correspondingly, the instant messaging system will set a low-difficulty identity authentication method for inputting account-related information such as the mobile phone number or email associated with the user.

[0135] 2) If μ A (x i ) is greater than P1 and less than or equal to P2, it is determined that the abnormal behavior item x i is at the medium risk level, and the strong association rule involved in the abnormal behavior item x i is determined as a medium-strength strong association rule. Correspondingly, the instant messaging system will set a medium-difficulty identity authentication method for answering preset security questions of the account, such as preset verification questions of the account.

[0136] 3) If μ A (x i ) is greater than P2 and less than or equal to 1, it is determined that the abnormal behavior item x i is at the high risk level, and the strong association rule involved in the abnormal behavior item x i is determined as a high-strength strong association rule. Correspondingly, the instant messaging system will set a high-difficulty identity authentication method for inputting the mobile phone verification code and the account password.

[0137] Based on the above, if the user passes the corresponding identity authentication method, it is regarded that the user has passed the identity authentication, indicating that the user himself / herself logs in to the instant messaging system, and then the user can continue to perform other operations.

[0138] On the contrary, if the user fails to pass the corresponding identity authentication method, it is regarded that the user's identity authentication fails, indicating that there may be others illegally logging in to the instant messaging system, and then others cannot continue to perform other operations. In one embodiment, the instant messaging system will force the account to log out and lock the account so that it cannot be used within ten minutes, and trigger a notification mechanism to notify the user of the account abnormality information in the form of an email or a text message, etc.

[0139] In one embodiment, the server receives an identity authentication feedback message, which is used to indicate whether the user has passed the identity authentication.

[0140] Step 430, if the behavior item to be recognized is a normal behavior item, when the cumulative reception times of the behavior item to be recognized have not reached the second set value, update the behavior set according to the behavior item to be recognized.

[0141] Among them, the cumulative reception times refer to the number of times the server has cumulatively received the behavior item to be recognized sent by the instant messaging system.

[0142] In one embodiment, the second set value is 1,000,000, and this second set value can be flexibly adjusted according to the actual needs of the application scenario, and it does not constitute a specific limitation here.

[0143] In one embodiment, the update process of the behavior set can be a full update or an incremental update.

[0144] Specifically, as Figure 6 shown, the incremental update process of the behavior set can include the following steps:

[0145] Step 431, in the set of behavior items included in the behavior set, find a matching behavior item that matches the behavior item to be recognized.

[0146] If found, execute step 433; otherwise, execute step 435 or step 437.

[0147] Step 433, based on the found matching behavior item, determine whether the set of behavior items to which the matching behavior item belongs is the same as the set of behavior items to which the behavior to be recognized belongs. Specifically, step 4331, if they are the same, delete the behavior item to be recognized; otherwise, step 4333, increase the frequency of the matching behavior item in the set of behavior items to which the matching behavior item belongs.

[0148] Step 435, if no matching behavior item is found in all the behavior item sets included in the behavior set, a new behavior item set is added, and the to-be-identified behavior item and its frequency are added to the newly added behavior item set.

[0149] Step 437, if no matching behavior item is found in the behavior item set to which the to-be-identified behavior item belongs, the to-be-identified behavior item is added to the behavior item set to which the to-be-identified behavior item belongs.

[0150] Thus, the incremental update of the behavior set is realized, thereby avoiding repeated updates, effectively improving the update efficiency of the behavior set, and thus being conducive to improving the efficiency of account anomaly recognition.

[0151] Step 450, if the cumulative reception count of the to-be-identified behavior item reaches the third set value, the strongly associated rule set is updated according to the behavior set.

[0152] In one embodiment, the third set value refers to 10% of the second set value = 10% of 1000000 = 100000. This third set value can be flexibly adjusted according to the actual needs of the application scenario and does not constitute a specific limitation here.

[0153] The update process of the strongly associated rule set is the steps 310 to 370 described in the foregoing embodiment and will not be repeated here.

[0154] Further, as described above, the instant messaging system will feedback to the server whether the user passes the identity, that is, send an identity authentication feedback message to the server. Correspondingly, the server can receive the identity authentication feedback message, and thus determine whether the user passes the identity authentication based on the identity authentication feedback message.

[0155] On the one hand, if the user fails the identity authentication and the to-be-identified behavior item is an abnormal behavior item, the server will not update the cumulative reception count based on the to-be-identified behavior item.

[0156] On the other hand, if the user passes the identity authentication and at this time the to-be-identified behavior item is an abnormal behavior item, it indicates that there may be an error in the account anomaly recognition. Then, the third set value is modified to trigger the update of the strongly associated rule set, so as to improve the accuracy of the account anomaly recognition.

[0157] In one embodiment, the third set value before modification refers to 100000, and the third set value after modification refers to 10000. That is to say, the threshold for triggering the update of the strongly associated rule set is reduced, and the update frequency of the strongly associated rule set is increased, so as to fully ensure the accuracy of the account anomaly recognition.

[0158] Then, when the cumulative reception count of the to-be-identified behavior item reaches the modified third set value, the strongly associated rule set is updated according to the behavior set.

[0159] Under the action of the above embodiments, an update mechanism for the association rule set is realized. On the premise of ensuring that the number of behavior items to be recognized has statistical significance, the identity authentication mechanism is coordinated to fully ensure the balance between the update frequency and over-update, which is conducive to improving the efficiency and accuracy of account anomaly recognition.

[0160] The following is an embodiment of the device of the present application, which can be used to execute the account anomaly recognition method in the instant messaging system involved in the present application. For the details not disclosed in the embodiment of the device of the present application, please refer to the method embodiment of the account anomaly recognition method in the instant messaging system involved in the present application.

[0161] Please refer to Figure 7 , in the embodiment of the present application, there is provided an account anomaly recognition device 900 in an instant messaging system, including but not limited to: a behavior set generation module 901, an association rule mining module 902, an association rule confidence fuzzy processing module 903, a strong association rule set generation module 904, and an account anomaly recognition module 905.

[0162] Among them, the behavior set generation module 901 is used to determine a behavior set including at least one behavior item set, the behavior item set includes at least one behavior item, and the behavior item is used to represent the usage behavior of the user in the instant messaging system.

[0163] The association rule mining module 902 is used to use the Apriori algorithm to mine association rules for the behavior items in the behavior set, and obtain at least one association rule and its confidence, and the association rule is used to indicate the first associated behavior item and the second associated behavior item that are mutually associated.

[0164] The association rule confidence fuzzy processing module 903 is used to perform fuzzy processing on the confidence of at least one association rule to obtain the fuzzy confidence of at least one association rule.

[0165] The strong association rule set generation module 904 is used to screen at least one strong association rule from at least one association rule based on the fuzzy confidence of at least one association rule, and add at least one strong association rule to the strong association rule set.

[0166] The account anomaly recognition module 905 is used to recognize the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set.

[0167] It should be noted that when the device for implementing the account anomaly recognition method in the instant messaging system provided in the above embodiments performs account anomaly recognition, only the division of the above functional modules is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device for implementing the account anomaly recognition method in the instant messaging system will be divided into different functional modules to complete all or part of the functions described above.

[0168] In addition, the device for implementing the account anomaly recognition method in the instant messaging system provided in the above embodiments and the embodiments of the method for implementing the account anomaly recognition in the instant messaging system belong to the same concept. The specific ways in which each module performs operations have been described in detail in the method embodiments and will not be elaborated here.

[0169] Figure 8 A schematic structural diagram of a server shown according to an exemplary embodiment. The server is applicable to Figure 1 the server 200 in the shown implementation environment.

[0170] It should be noted that this server is only an example adapted to the present application and cannot be considered as providing any limitation to the scope of use of the present application. This server cannot be interpreted as requiring dependence on or necessarily having Figure 8 one or more components in the shown exemplary server 2000.

[0171] The hardware structure of the server 2000 may vary greatly due to different configurations or performances. For example, Figure 8 as shown, the server 2000 includes: a power supply 210, an interface 230, at least one memory 250, and at least one central processing unit (CPU) 270.

[0172] Specifically, the power supply 210 is used to provide working voltage for each hardware device on the server 2000.

[0173] The interface 230 includes at least one wired or wireless network interface for interacting with external devices. For example, for Figure 1 the interaction between the terminal 100 and the server 200 in the shown implementation environment.

[0174] Of course, in other examples adapted to the present application, the interface 230 may further include at least one serial-parallel conversion interface 233, at least one input-output interface 235, and at least one USB interface 237, etc. As Figure 8 shown, this is not a specific limitation here.

[0175] The memory 250, as the carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon include an operating system 251, application programs 253, data 255, etc. The storage method can be temporary storage or permanent storage.

[0176] Among them, the operating system 251 is used to manage and control each hardware device and application program 253 on the server 200, so as to enable the central processing unit 270 to perform operations and processing on the massive data 255 in the memory 250. It can be Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSD TM, etc.

[0177] The application program 253 is a computer program that completes at least one specific task based on the operating system 251. It can include at least one module ( Figure 8 (not shown), and each module can separately contain a computer program for the server 2000. For example, the data monitoring device can be regarded as an application program 253 deployed on the server 2000.

[0178] The data 255 can be photos, pictures, etc. stored in the magnetic disk, or key-value pairs, etc., and are stored in the memory 250.

[0179] The central processing unit 270 can include one or more than one processors, and is set to communicate with the memory 250 through at least one communication bus, so as to read the computer programs stored in the memory 250, and then realize the operation and processing of the massive data 255 in the memory 250. For example, the information recommendation method is completed in the form of reading a series of computer programs stored in the memory 250 by the central processing unit 270.

[0180] In addition, the present application can also be implemented by hardware circuits or a combination of hardware circuits and software. Therefore, the implementation of the present application is not limited to any specific hardware circuit, software, and the combination of the two.

[0181] Please refer to Figure 9 , in the embodiments of the present application, an electronic device 4000 is provided. The electronic device 400 can include: a desktop computer, a laptop computer, a server, etc.

[0182] In Figure 9 , the electronic device 4000 includes at least one processor 4001, at least one communication bus 4002, and at least one memory 4003.

[0183] Among them, the processor 4001 is connected to the memory 4003, such as through the communication bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, and the transceiver 4004 may be used for data interaction between this electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in practical applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiments of the present application.

[0184] The processor 4001 may be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in connection with the disclosure of the present application. The processor 4001 may also be a combination that realizes a computing function, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0185] The communication bus 4002 may include a path for transmitting information between the above components. The communication bus 4002 may be a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus or an EISA (Extended Industry Standard Architecture, extended industry standard architecture) bus, etc. The communication bus 4002 may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 9 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0186] The memory 4003 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0187] A computer program is stored on the memory 4003, and the processor 4001 reads the computer program stored in the memory 4003 through the communication bus 4002.

[0188] When the computer program is executed by the processor 4001, it implements the account anomaly recognition method in the instant messaging system in the above-mentioned embodiments.

[0189] In addition, an embodiment of the present application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements the account anomaly recognition method in the instant messaging system in the above-mentioned embodiments.

[0190] An embodiment of the present application provides a computer program product. The computer program product includes a computer program that is stored in a storage medium. The processor of the computer device reads the computer program from the storage medium, and the processor executes the computer program, so that the computer device executes the account anomaly recognition method in the instant messaging system in the above-mentioned embodiments.

[0191] Compared with the related art, the solution of the embodiment of the present application combines the Apriori algorithm and fuzzy processing, and uses a fuzzified association rule library to mine the characteristics of users' usage behaviors in the instant messaging system, which can effectively improve the accuracy rate of account anomaly recognition; for different risk levels of abnormal behavior items, corresponding identity authentication information is pushed to the instant messaging system, which can not only prevent misjudgment, but also further ensure the accuracy rate of account anomaly recognition; the update mechanism of the association rule set, on the premise of ensuring that the number of behavior items to be recognized has statistical significance, cooperates with the identity authentication mechanism to fully guarantee the balance between the update frequency and over-update, which is beneficial to improving the efficiency and accuracy rate of account anomaly recognition.

[0192] It should be understood that although the steps in the flowchart of the accompanying drawings are shown successively according to the indication of the arrows, these steps are not necessarily executed successively in the order indicated by the arrows. Unless there is a clear indication in this document, the execution of these steps has no strict order limit and can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0193] The above are only some implementation manners of the present application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present application, several improvements and refinements can also be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for realizing account abnormality recognition in an instant messaging system, characterized in that, The method includes: Determine a behavior set including at least one behavior item set, where the behavior item set includes at least one behavior item for representing a usage behavior of a user in the instant messaging system; Use the Apriori algorithm to perform association rule mining on the behavior items in the behavior set to obtain at least one association rule and its confidence, where the association rule is used to indicate a first associated behavior item and a second associated behavior item that are associated with each other; Perform a fuzzification process on the confidence of at least one association rule to obtain at least one fuzzy confidence of the association rule; Based on the fuzzy confidence of at least one association rule, screen at least one strong association rule from at least one association rule and add at least one strong association rule to a strong association rule set; Identify the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set; The using the Apriori algorithm to perform association rule mining on the behavior items in the behavior set to obtain at least one association rule and its confidence includes: According to the support degree of each behavior item in the behavior set, screen frequent items from the behavior items in the behavior set, and form a frequent item set of the behavior set from the screened frequent items; Based on each frequent item in the frequent item set, determine a first associated behavior item and a second associated behavior item that are associated with each other in the frequent item; For each first associated behavior item, calculate the confidence that the first associated behavior item and the second associated behavior item are associated with each other; Based on the confidence that the first associated behavior item and the second associated behavior item are associated with each other, mine at least one association rule and its confidence; The performing a fuzzification process on the confidence of at least one association rule to obtain at least one fuzzy confidence of the association rule includes: For each association rule, based on the first associated behavior item and the second associated behavior item that are associated with each other indicated by the association rule, determine a triangular fuzzy set in which the first associated behavior item and the second associated behavior item are associated with each other; According to the confidence that the first associated behavior item and the second associated behavior item are associated with each other and the triangular fuzzy set, calculate the fuzzy confidence that the first associated behavior item and the second associated behavior item are associated with each other as the fuzzy confidence of the association rule.

2. The method according to claim 1, characterized in that, The based on the first associated behavior item and the second associated behavior item that are associated with each other indicated by the association rule, determining a triangular fuzzy set in which the first associated behavior item and the second associated behavior item are associated with each other includes: According to a pre-constructed triangular fuzzy number storage table, obtain several triangular fuzzy numbers in which the first associated behavior item and the second associated behavior item are associated with each other; Calculate an average value according to several triangular fuzzy numbers as the triangular fuzzy set in which the first associated behavior item and the second associated behavior item are associated with each other.

3. The method according to any one of claims 1 or 2, characterized in that, The identifying the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set includes: Receive the behavior item to be recognized, where the behavior item to be recognized is used to represent the usage behavior of the user waiting to be recognized in the instant messaging system; In the strong association rule set, search for the strong association rule indicating the behavior item to be recognized; If a strong association rule is found, based on the first association behavior item and the second association behavior item indicated in the found strong association rule and being mutually associated, determine whether there is a second association behavior item that is mutually associated with the behavior item to be recognized; If not, determine that the behavior item to be recognized is an abnormal behavior item.

4. The method according to claim 3, characterized in that After recognizing the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set, the method further includes: If the behavior item to be recognized is an abnormal behavior item, determine the risk level of the abnormal behavior item according to the first set value of different risk levels; Based on the risk level of the abnormal behavior item, push a corresponding identity authentication message to the instant messaging system, where the identity authentication message is used to indicate the risk level of the abnormal behavior item violating the strong association rule.

5. The method according to claim 3, wherein After recognizing the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set, the method further includes: If the behavior item to be recognized is a normal behavior item, when the cumulative reception times of the behavior item to be recognized have not reached the second set value, update the behavior set according to the behavior item to be recognized; If the cumulative reception times of the behavior item to be recognized reach the third set value, update the strong association rule set according to the behavior set.

6. The method according to claim 5, characterized in that The method further includes: Receive an identity authentication feedback message, where the identity authentication feedback message is used to indicate whether the user passes the identity authentication; If the user passes the identity authentication, modify the third set value so that when the cumulative reception times of the behavior item to be recognized reach the modified third set value, update the strong association rule set according to the behavior set.

7. The method according to claim 5, wherein The updating the behavior set according to the behavior item to be recognized includes: In the set of behavior items included in the behavior set, search for a matching behavior item that matches the behavior item to be recognized; Based on the found matching behavior item, determine whether the set of behavior items to which the matching behavior item belongs is the same as the set of behavior items to which the behavior item to be recognized belongs; If they are the same, delete the behavior item to be recognized; Otherwise, increase the frequency of the matching behavior item in the set of behavior items to which the matching behavior item belongs.

8. An apparatus for realizing account anomaly recognition in an instant messaging system, characterized in that, The device includes: A behavior set determination module, configured to determine a behavior set including at least one set of behavior items, where the set of behavior items includes at least one behavior item, and the behavior item is used to represent the usage behavior of the user in the instant messaging system; An association rule mining module, configured to use the Apriori algorithm to perform association rule mining on the behavior items in the behavior set, and obtain at least one association rule and its confidence level, where the association rule is used to indicate the first association behavior item and the second association behavior item that are mutually associated; The fuzzification processing module is used to perform fuzzification processing on the confidence degrees of at least one association rule to obtain the fuzzy confidence degrees of at least one association rule; The strong association rule determination module is used to screen at least one strong association rule from at least one association rule based on the fuzzy confidence degrees of at least one association rule, and add at least one strong association rule to the strong association rule set; The account anomaly recognition module is used to recognize the usage behavior of the user in the instant messaging system according to the strong association rules in the strong association rule set; The fuzzification processing module is further used for: For each association rule, based on the first associated behavior item and the second associated behavior item that are associated as indicated by the association rule, determine the triangular fuzzy set of the mutual association between the first associated behavior item and the second associated behavior item; According to the confidence degree of the mutual association between the first associated behavior item and the second associated behavior item and the triangular fuzzy set, calculate the fuzzy confidence degree of the mutual association between the first associated behavior item and the second associated behavior item as the fuzzy confidence degree of the association rule.

Citation Information

Patent Citations

  • Method for optimizing cement production parameters and adjustment intervals based on fuzzy association rules

    CN107818409A

  • Account anomaly detection method and device, server and storage medium

    CN108055281A