A network information risk detection method and system
By clustering and feature extraction of network interaction data, generating a saliency description set and optimizing key nodes, the accuracy and reliability issues of network information risk detection are solved, and more efficient risk detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI QIWANG NETWORK TECH CO LTD
- Filing Date
- 2022-08-02
- Publication Date
- 2026-07-24
AI Technical Summary
Existing technologies are unable to effectively detect risks in online information, leading to an increased possibility of user information loss and device damage.
By clustering network interaction data, a salient network interaction description set is generated, and the percentage coefficients of key nodes are optimized. Combined with updated variables and feature extraction, the accuracy and reliability of risk detection are improved.
This improves the accuracy and reliability of network information risk detection, and ensures the accuracy and credibility of the processing results.
Smart Images

Figure CN115455406B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of risk data detection technology, and more specifically, to a method and system for detecting risks in network information. Background Technology
[0002] With the continuous development of internet technology, the amount of online information is constantly increasing, leading to significant security risks in network security, which may result in the loss of user information and damage to devices. Therefore, there is an urgent need for a technology to detect risks in online information. Summary of the Invention
[0003] To address the technical problems existing in related technologies, this application provides a method and system for detecting network information risks.
[0004] Firstly, a method for risk detection of network information is provided. The method includes at least: clustering network interaction data to be risk-detected to obtain a first network interaction description set; performing security coefficient distribution processing on the first network interaction description set to obtain a salient network interaction description set, wherein the salient network interaction description set includes percentage results of key nodes in the first network interaction description set; optimizing the percentage coefficients of key nodes in the first network interaction description set based on the salient network interaction description set to obtain a second network interaction description set; and determining the processing result of the network interaction data to be risk-detected based on the second network interaction description set.
[0005] In one standalone embodiment, the step of performing security coefficient distribution processing on the first network interaction description set to obtain a salient network interaction description set includes: updating each transmission path of the first network interaction description set; determining a first update variable for the first network interaction description set, wherein the number of transmission paths for the first update variable is consistent with the number of transmission paths for the first network interaction description set; and matching the update dimension and update interval of the first update variable with a pre-set update template. Then, combining the first update variable, feature extraction processing is performed on the first network interaction description set to obtain the salient network interaction description set.
[0006] In one standalone embodiment, the step of combining the first update variable to perform feature extraction processing on the first network interaction description set to obtain the saliency network interaction description set includes: combining the first update variable of the first network interaction description set and a number of pre-set data completion instructions to classify the first network interaction description set to obtain a number of fourth network interaction description sets of the first network interaction description set; activating the number of fourth network interaction description sets to obtain a number of fifth network interaction description sets; and combining the number of fifth network interaction description sets to determine the saliency network interaction description set of the first network interaction description set.
[0007] In one independently implemented embodiment, the step of updating each transmission path of the first network interaction description set to determine the first update variable of the first network interaction description set includes: performing iterative processing on the first network interaction description set to obtain an important network interaction description set and a sample network interaction description set, wherein the description range of the important network interaction description set is consistent with the description range of the first network interaction description set, the update dimension and update interval of the sample network interaction description set are consistent with the update dimension and update interval of the first network interaction description set, and the number of transmission paths of the sample network interaction description set matches the update template; performing clustering processing on the important network interaction description set and the sample network interaction description set to obtain a first key content cluster of the important network interaction description set and a second key content cluster of the sample network interaction description set; performing weighted processing on the first key content cluster and the second key content cluster to obtain a third key content cluster of the first network interaction description set; and combining the third key content cluster to determine the first update variable of the first network interaction description set.
[0008] In one standalone embodiment, determining the first update variable of the first network interaction description set by combining the third key content cluster includes: performing clustering processing on the third key content cluster to obtain a second update variable of the first network interaction description set; and performing dimensionless simplification processing on the second update variable to determine the first update variable of the first network interaction description set.
[0009] In one standalone embodiment, the step of optimizing the key nodes in the first network interaction description set with percentage coefficients to obtain a second network interaction description set by combining the salient network interaction description set includes: performing attribute weighting processing on the first network interaction description set and the salient network interaction description set to obtain the second network interaction description set.
[0010] In one standalone embodiment, the method further includes: performing feature recognition processing on the first network interaction description set to obtain an identified network interaction description set, wherein the description range of the identified network interaction description set is consistent with the description range of the first network interaction description set; and determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set, including: integrating the second network interaction description set with the identified network interaction description set to obtain an integrated network interaction description set; and classifying the integrated network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
[0011] In one standalone embodiment, feature recognition processing is performed on the first network interaction description set to obtain an identified network interaction description set of the first network interaction description set, including: performing saliency label recognition on the first network interaction description set to obtain a first variable of the first network interaction description set; performing feature extraction on the first variable to obtain a second variable; and performing expansion processing on the second variable to obtain an identified network interaction description set of the first network interaction description set.
[0012] In one standalone embodiment, determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set includes: classifying the second network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
[0013] Secondly, a network information risk detection system is provided, including a processor and a memory that communicate with each other, wherein the processor is used to read a computer program from the memory and execute it to implement the above-described method.
[0014] The network information risk detection method and system provided in this application can perform security coefficient distribution processing on the network interaction description set of the network interaction data to be risk detected, and obtain a significant network interaction description set including the percentage results of key nodes in the network interaction description set; optimize the key nodes in the network interaction description set according to the significant network interaction description set; determine the processing result of the network interaction data according to the optimized network interaction description set, thereby improving the accuracy and reliability of risk detection, and effectively ensuring the accuracy and credibility of the processing result of the network interaction data to be risk detected. Attached Figure Description
[0015] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a flowchart illustrating a network information risk detection method provided in an embodiment of this application.
[0017] Figure 2 This is a block diagram of a network information risk detection device provided in an embodiment of this application.
[0018] Figure 3 This is an architecture diagram of a network information risk detection system provided in an embodiment of this application. Detailed Implementation
[0019] To better understand the above technical solutions, the technical solutions of this application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of this application and the specific features in the embodiments are detailed descriptions of the technical solutions of this application, rather than limitations on the technical solutions of this application. In the absence of conflict, the embodiments of this application and the technical features in the embodiments can be combined with each other.
[0020] Please see Figure 1 This paper illustrates a method for detecting risks in network information, which may include the technical solutions described in steps 100-400.
[0021] Step 100: Cluster the network interaction data to be detected for risk to obtain the first network interaction description set of the network interaction data to be detected for risk.
[0022] Step 200: Perform security coefficient distribution processing on the first network interaction description set to obtain a salient network interaction description set of the first network interaction description set, wherein the salient network interaction description set includes the percentage results of key nodes in the first network interaction description set.
[0023] Step 300: Based on the saliency network interaction description set, optimize the percentage coefficients of key nodes in the first network interaction description set to obtain the second network interaction description set.
[0024] Step 400: Combine the second network interaction description set to determine the processing result of the network interaction data to be risk detected.
[0025] It is understood that by performing the steps described in steps 100-400 above, the network interaction description set of the network interaction data to be risk-detected can be processed with a security coefficient distribution to obtain a saliency network interaction description set including the percentage results of key nodes in the network interaction description set; the key nodes in the network interaction description set are optimized based on the saliency network interaction description set; and the processing result of the network interaction data is determined based on the optimized network interaction description set, thereby improving the accuracy and reliability of risk detection and effectively ensuring the accuracy and credibility of the processing result of the network interaction data to be risk-detected.
[0026] In one possible implementation, the step of performing security coefficient distribution processing on the first network interaction description set to obtain a salient network interaction description set includes: updating each transmission path of the first network interaction description set; determining a first update variable for the first network interaction description set, wherein the number of transmission paths for the first update variable is consistent with the number of transmission paths for the first network interaction description set; and matching the update dimension and update interval of the first update variable with a pre-set update template. Then, combining the first update variable, feature extraction processing is performed on the first network interaction description set to obtain the salient network interaction description set.
[0027] In one possible implementation, the step of combining the first update variable to perform feature extraction processing on the first network interaction description set to obtain the saliency network interaction description set includes: combining the first update variable of the first network interaction description set and a number of pre-set data completion instructions to classify the first network interaction description set to obtain a number of fourth network interaction description sets of the first network interaction description set; activating the number of fourth network interaction description sets to obtain a number of fifth network interaction description sets; and combining the number of fifth network interaction description sets to determine the saliency network interaction description set of the first network interaction description set.
[0028] In one possible implementation, the step of updating each transmission path of the first network interaction description set to determine the first update variable of the first network interaction description set includes: performing iterative processing on the first network interaction description set to obtain an important network interaction description set and a sample network interaction description set, wherein the description range of the important network interaction description set is consistent with the description range of the first network interaction description set, the update dimension and update interval of the sample network interaction description set are consistent with the update dimension and update interval of the first network interaction description set, and the number of transmission paths of the sample network interaction description set matches the update template; performing clustering processing on the important network interaction description set and the sample network interaction description set to obtain a first key content cluster of the important network interaction description set and a second key content cluster of the sample network interaction description set; performing weighted processing on the first key content cluster and the second key content cluster to obtain a third key content cluster of the first network interaction description set; and combining the third key content cluster to determine the first update variable of the first network interaction description set.
[0029] In one possible implementation, determining the first update variable of the first network interaction description set by combining the third key content cluster includes: performing clustering processing on the third key content cluster to obtain a second update variable of the first network interaction description set; and performing dimensionless simplification processing on the second update variable to determine the first update variable of the first network interaction description set.
[0030] In one possible implementation, the step of combining the salient network interaction description set and optimizing the key nodes in the first network interaction description set with percentage coefficients to obtain the second network interaction description set includes: performing attribute weighting processing on the first network interaction description set and the salient network interaction description set to obtain the second network interaction description set.
[0031] In one possible implementation, the method further includes: performing feature recognition processing on the first network interaction description set to obtain an identified network interaction description set, wherein the description range of the identified network interaction description set is consistent with the description range of the first network interaction description set; and determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set, including: integrating the second network interaction description set with the identified network interaction description set to obtain an integrated network interaction description set; and classifying the integrated network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
[0032] In one possible implementation, feature recognition processing is performed on the first network interaction description set to obtain an identified network interaction description set of the first network interaction description set, including: performing saliency label recognition on the first network interaction description set to obtain a first variable of the first network interaction description set; performing feature extraction on the first variable to obtain a second variable; and performing expansion processing on the second variable to obtain an identified network interaction description set of the first network interaction description set.
[0033] In one possible implementation, determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set includes: classifying the second network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
[0034] Based on the above, please refer to the following: Figure 2 A network information risk detection device 200 is provided, which is applied to a network information risk detection system. The device includes:
[0035] The description acquisition module 210 is used to perform clustering processing on the network interaction data to be risk detected, and obtain the first network interaction description set of the network interaction data to be risk detected.
[0036] The result determination module 220 is used to perform security coefficient distribution processing on the first network interaction description set to obtain a salient network interaction description set of the first network interaction description set, wherein the salient network interaction description set includes the percentage results of key nodes in the first network interaction description set.
[0037] The description optimization module 230 is used to combine the saliency network interaction description set and optimize the key nodes in the first network interaction description set by percentage coefficients to obtain the second network interaction description set.
[0038] The result processing module 240 is used to determine the processing result of the network interaction data to be risk detected by combining the second network interaction description set.
[0039] Based on the above, please refer to the following: Figure 3 The diagram illustrates a network information risk detection system 300, which includes a processor 310 and a memory 320 that communicate with each other. The processor 310 is used to read computer programs from the memory 320 and execute them to implement the above-described method.
[0040] Based on the above, a computer-readable storage medium is also provided, on which a computer program stored implements the above method during runtime.
[0041] In summary, based on the above scheme, the network interaction description set of the network interaction data to be risk-detected can be processed with a security coefficient distribution to obtain a saliency network interaction description set that includes the percentage results of key nodes in the network interaction description set; the key nodes in the network interaction description set are optimized based on the saliency network interaction description set; and the processing result of the network interaction data is determined based on the optimized network interaction description set, thereby improving the accuracy and reliability of risk detection and effectively ensuring the accuracy and credibility of the processing result of the network interaction data to be risk-detected.
[0042] It should be understood that the systems and modules described above can be implemented in various ways. For example, in some embodiments, the systems and modules can be implemented by hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the methods and systems described above can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The systems and modules of this application can be implemented not only by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., but also by software executed by various types of processors, or by a combination of the aforementioned hardware circuits and software (e.g., firmware).
[0043] It should be noted that different embodiments may produce different beneficial effects. In different embodiments, the beneficial effects may be any one or a combination of the above, or any other possible beneficial effects.
[0044] The basic concepts have been described above. Obviously, for those skilled in the art, the detailed disclosure above is merely illustrative and does not constitute a limitation of this application. Although not explicitly stated herein, those skilled in the art may make various modifications, improvements, and corrections to this application. Such modifications, improvements, and corrections are suggested in this application, and therefore remain within the spirit and scope of the exemplary embodiments of this application.
[0045] Furthermore, this application uses specific terms to describe embodiments of the application. For example, "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of the application. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the application can be appropriately combined.
[0046] Furthermore, those skilled in the art will understand that aspects of this application can be described and illustrated through several patentable types or situations, including any new and useful combination of processes, machines, products, or substances, or any new and useful improvements thereof. Accordingly, aspects of this application can be implemented entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. All of the above hardware or software may be referred to as a “data block,” “module,” “engine,” “unit,” “component,” or “system.” Furthermore, aspects of this application may manifest as a computer product located on one or more computer-readable media, the product including computer-readable program code.
[0047] Computer storage media may contain a propagated data signal containing computer program code, for example, on baseband or as part of a carrier wave. This propagated signal may take various forms, including electromagnetic, optical, and suitable combinations thereof. Computer storage media can be any computer-readable medium other than a computer-readable storage medium, which can be connected to an instruction execution system, apparatus, or device to enable communication, propagation, or transmission of a program for use. The program code located on the computer storage medium can be propagated through any suitable medium, including radio, cable, fiber optic cable, RF, or similar media, or any combination of the above media.
[0048] The computer program code required for the operation of each part of this application can be written in any one or more programming languages, including object-oriented programming languages such as Java, Scala, Smalltalk, Eiffel, JADE, Emerald, C++, C#, VB.NET, Python, etc., conventional procedural programming languages such as C, Visual Basic, Fortran 2003, Perl, COBOL 2002, PHP, ABAP, dynamic programming languages such as Python, Ruby, and Groovy, or other programming languages. This program code can run entirely on the user's computer, or as a standalone software package on the user's computer, or partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any network, such as a local area network (LAN) or wide area network (WAN), or connected to an external computer (e.g., via the Internet), or in a cloud computing environment, or used as a service such as Software as a Service (SaaS).
[0049] Furthermore, unless expressly stated in the claims, the order of processing elements and sequences, the use of numbers and letters, or other names described in this application are not intended to limit the order of the processes and methods of this application. Although the foregoing disclosure has discussed some currently considered useful embodiments of the invention through various examples, it should be understood that such details are for illustrative purposes only, and the appended claims are not limited to the disclosed embodiments; rather, the claims are intended to cover all modifications and equivalent combinations that conform to the substance and scope of the embodiments of this application. For example, while the system components described above can be implemented using hardware devices, they can also be implemented solely through software solutions, such as installing the described system on existing servers or mobile devices.
[0050] Similarly, it should be noted that, in order to simplify the description of the present application and thus aid in the understanding of one or more embodiments of the invention, the foregoing description of the embodiments of the present application sometimes combines multiple features into a single embodiment, drawing, or description thereof. However, this disclosure method does not imply that the subject matter of the application requires more features than those mentioned in the claims. In fact, the embodiments contain fewer features than all the features of the single embodiments disclosed above.
[0051] In some embodiments, numbers describing the quantity of components and attributes are used. It should be understood that such numbers used in the description of embodiments are modified in some examples with the terms "approximately," "approximately," or "generally." Unless otherwise stated, "approximately," "approximately," or "generally" indicates that the numbers are open to adaptive variation. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, which may be changed depending on the characteristics required by individual embodiments. In some embodiments, numerical parameters are taken into account a specified number of significant digits and employ a general method of digit reservation. Although the numerical ranges and parameters used to confirm their breadth of application in some embodiments of this application are approximate values, in specific embodiments, such values are set as precisely as feasible.
[0052] For each patent, patent application, patent application publication, and other material such as articles, books, specifications, publications, and documents referenced in this application, the entire contents of that patent are incorporated herein by reference. This excludes historical application documents that are inconsistent with or conflict with the content of this application, as well as documents that limit the broadest scope of the claims in this application (currently or subsequently appended to this application). It should be noted that if there are any inconsistencies or conflicts between the descriptions, definitions, and / or terminology used in the supplementary materials of this application and the content of this application, the descriptions, definitions, and / or terminology used in this application shall prevail.
[0053] Finally, it should be understood that the embodiments described in this application are merely illustrative of the principles of the embodiments of this application. Other modifications may also fall within the scope of this application. Therefore, alternative configurations of the embodiments of this application are considered as examples and not limitations, and are regarded as consistent with the teachings of this application. Accordingly, the embodiments of this application are not limited to the embodiments explicitly described and illustrated in this application.
[0054] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for detecting risks in network information, characterized in that, The method includes at least: Clustering is performed on the network interaction data to be subjected to risk detection to obtain the first network interaction description set of the network interaction data to be subjected to risk detection; The first network interaction description set is processed by a security coefficient distribution to obtain a salient network interaction description set, which includes the percentage results of key nodes in the first network interaction description set. By combining the saliency network interaction description set, the percentage coefficients of key nodes in the first network interaction description set are optimized to obtain the second network interaction description set; Based on the second network interaction description set, determine the processing result of the network interaction data to be risk detected; The step of performing security coefficient distribution processing on the first network interaction description set to obtain the salient network interaction description set of the first network interaction description set includes: Each transmission path of the first network interaction description set is updated to determine the first update variable of the first network interaction description set. The number of transmission paths of the first update variable is consistent with the number of transmission paths of the first network interaction description set. The update dimension and update interval of the first update variable are matched with the pre-set update template. By combining the first updated variable, feature extraction processing is performed on the first network interaction description set to obtain the salient network interaction description set; The step of updating each transmission path of the first network interaction description set and determining the first update variable of the first network interaction description set includes: The first network interaction description set is iteratively processed to obtain an important network interaction description set and a sample network interaction description set. The description range of the important network interaction description set is consistent with the description range of the first network interaction description set. The update dimension and update interval of the sample network interaction description set are consistent with the update dimension and update interval of the first network interaction description set. The number of transmission paths of the sample network interaction description set matches the update template. The important network interaction description set and the sample network interaction description set are respectively subjected to clustering processing to obtain the first key content cluster of the important network interaction description set and the second key content cluster of the sample network interaction description set; The first key content cluster and the second key content cluster are weighted to obtain the third key content cluster of the first network interaction description set; the first update variable of the first network interaction description set is determined by combining the third key content cluster.
2. The method according to claim 1, characterized in that, The step of combining the first updated variable with the first network interaction description set to perform feature extraction processing to obtain the salient network interaction description set includes: Combining the first update variable of the first network interaction description set with several pre-set data completion instructions, the first network interaction description set is classified to obtain several fourth network interaction description sets of the first network interaction description set. Activating each of the aforementioned fourth network interaction description sets yields a plurality of fifth network interaction description sets; By combining the aforementioned sets of fifth network interaction descriptions, the salient network interaction description set of the first network interaction description set is determined.
3. The method according to claim 1, characterized in that, The step of determining the first update variable of the first network interaction description set by combining the third key content cluster includes: The third key content cluster is divided into groups to obtain the second update variable of the first network interaction description set; the second update variable is simplified to a dimensionless form to determine the first update variable of the first network interaction description set.
4. The method according to claim 1, characterized in that, The step of combining the salient network interaction description set and optimizing the key nodes in the first network interaction description set with percentage coefficients to obtain the second network interaction description set includes: performing attribute weighting processing on the first network interaction description set and the salient network interaction description set to obtain the second network interaction description set.
5. The method according to claim 1, characterized in that, The method further includes: performing feature recognition processing on the first network interaction description set to obtain an identified network interaction description set, wherein the description range of the identified network interaction description set is consistent with the description range of the first network interaction description set; and determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set, including: integrating the second network interaction description set with the identified network interaction description set to obtain an integrated network interaction description set; and classifying the integrated network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
6. The method according to claim 5, characterized in that, The first network interaction description set is subjected to feature recognition processing to obtain the identified network interaction description set of the first network interaction description set, including: performing saliency label recognition on the first network interaction description set to obtain a first variable of the first network interaction description set; performing feature extraction on the first variable to obtain a second variable; and performing expansion processing on the second variable to obtain the identified network interaction description set of the first network interaction description set.
7. The method according to claim 1, characterized in that, The step of determining the processing result of the network interaction data to be risk-detected by combining the second network interaction description set includes: classifying the second network interaction description set to obtain the processing result of the network interaction data to be risk-detected.
8. A network information risk detection system, characterized in that, The method includes a processor and a memory that communicate with each other, the processor being configured to read a computer program from the memory and execute it to implement the method of any one of claims 1-7.