Abnormal account detection method, device and equipment and storage medium
By analyzing resource usage records and account association information, a set of target abnormal accounts is generated, which solves the problem of low detection accuracy in multi-platform isolated environments and achieves efficient identification of abnormal accounts.
Patent Information
- Application Number
- CN202110695187.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-23
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-06-23
AI Technical Summary
Existing technologies struggle to effectively detect merchant accounts and their associated individual accounts exhibiting abnormal resource usage in multi-platform isolated environments, resulting in low detection accuracy.
By analyzing resource usage records within a specified historical time period, a first set of candidate accounts whose first resource usage characteristics meet the set conditions is detected. A third set of candidate accounts is generated based on account association information. Finally, the union of the second and third set of candidate accounts is output as the target abnormal account set.
It improves the accuracy and efficiency of abnormal account detection, and can effectively identify abnormal accounts in the resource usage platform.
Smart Images

Figure CN115511549B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computers, in particular to the technical field of electronic finance, and provides an abnormal account detection method and device, equipment and a storage medium. BACKGROUND
[0002] In recent years, with the popularity of Internet financial business, online shopping has provided a lot of convenience for people's daily life, and in order to obtain a better search ranking of an e-commerce store, unscrupulous merchants will provide the purchase cost and employment cost required for purchasing goods, and hire people to pretend to be customers to purchase goods, so as to improve the sales volume, credit and praise rate of the e-commerce store.
[0003] In order to evade the detection mechanism of the e-commerce platform for abnormal promotion of store ranking operation, unscrupulous merchants will hire people to pretend to be customers to purchase goods through a third-party platform, and then transfer a corresponding amount of resources to the individual account of the hired object through a resource use platform. Since the information of different platforms is not communicated with each other, the resource use platform is difficult to obtain the resource use information of the individual account and the merchant account of the unscrupulous merchant on other platforms, and only with the historical resource use record set recorded in the platform itself, the resource use platform cannot detect the merchant account with abnormal resource use operation and the individual account associated therewith from a large number of accounts on the resource use platform. SUMMARY
[0004] The embodiments of the present application provide an abnormal account detection method, device, equipment and storage medium to solve the problem of low detection accuracy.
[0005] In a first aspect, the embodiments of the present application provide an abnormal account detection method, comprising:
[0006] obtaining a historical resource use record set corresponding to a specified first historical time period, wherein each resource use record contains at least one resource use operation of a corresponding original account in the first historical time period;
[0007] Based on the historical resource use record set, a first candidate account set in which a first resource use feature satisfies a first set condition is detected, and based on the resource use record corresponding to each first candidate account, a second candidate account set in which a second resource use feature satisfies a second set condition is detected;
[0008] Based on the account association information of each second candidate account in the second candidate account set, an original account associated with any second candidate account is taken as a third candidate account, and a corresponding third candidate account set is generated;
[0009] The union of the second candidate account set and the third candidate account set is taken as a target abnormal account set and output.
[0010] In a second aspect, the embodiments of the present application further provide an abnormal account detection apparatus, comprising:
[0011] an obtaining unit, configured to obtain a historical resource usage record set corresponding to a specified first historical time period, wherein each resource usage record contains at least one resource usage operation of a corresponding original account in the first historical time period;
[0012] a detecting unit, configured to detect a first candidate account set in which a first resource usage feature meets a first set condition based on the historical resource usage record set, and detect a second candidate account set in which a second resource usage feature meets a second set condition based on resource usage records corresponding to each first candidate account;
[0013] based on account association information of each second candidate account in the second candidate account set, an original account having an association relationship with any second candidate account is taken as a third candidate account, and a corresponding third candidate account set is generated;
[0014] a union of the second candidate account set and the third candidate account set is taken as a target abnormal account set and output.
[0015] Optionally, after the target abnormal account set is output, the apparatus further comprises a management and control unit, which performs at least one of the following operations:
[0016] receiving a first resource usage request, and if an initiating end account of the first resource usage request is a target abnormal account having an abnormal resource usage operation, stopping providing a corresponding resource usage service for the initiating end account when it is determined that the initiating end account does not meet a preset management and control rule;
[0017] receiving a second resource usage request, and if a receiving end account of the second resource usage request has an association relationship with any target abnormal account, stopping providing a corresponding resource usage service for the receiving end account when it is determined that the receiving end account does not meet the management and control rule.
[0018] Optionally, the management and control unit performs at least one of the following operations:
[0019] obtaining resource usage identifier information associated with the initiating end account, and if it is determined that the number of resource usage operations of the initiating end account has reached a set second threshold value based on the resource usage identifier information, it is determined that the initiating end account does not meet the management and control rule;
[0020] obtaining access address information associated with the initiator account, and determining that the initiator account does not meet the control rule if it is determined, based on the access address information, that a calling number of the access address information of the initiator account has reached a third threshold value.
[0021] Optionally, the control unit is configured to:
[0022] obtaining account identification information of the receiver account, and determining that the receiver account does not meet the control rule if it is determined, based on the account identification information, that a resource transfer number of the receiver account in a specified second historical time period has reached a fourth threshold value.
[0023] In a third aspect, an embodiment of the present application further provides a computer device, including a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes steps of any one of the above-mentioned abnormal account detection methods.
[0024] In a fourth aspect, an embodiment of the present application further provides a computer readable storage medium, including program code, and when the program product is run on a computer device, the program code is used to make the computer device execute steps of any one of the above-mentioned abnormal account detection methods.
[0025] The present application has the following beneficial effects:
[0026] The embodiments of the present application provide an abnormal account detection method, device, equipment and storage medium. The method includes: detecting a first candidate account set in which a first resource use feature meets a first set condition based on a historical resource use record set in a specified first historical time period, and detecting a second candidate account set in which a second resource use feature meets a second set condition based on resource use records corresponding to each first candidate account; detecting a third candidate account set by taking an original account associated with any second candidate account as a third candidate account based on account association information of each second candidate account in the second candidate account set; and finally outputting a union set of the second candidate account set and the third candidate account set as a target abnormal account set. The embodiments of the present application detect candidate abnormal accounts with abnormal resource use operations by analyzing resource use records of accounts, further detect other candidate abnormal accounts based on account association information of the identified candidate abnormal accounts, and finally determine a target abnormal account set based on the two types of abnormal accounts, which can effectively detect abnormal accounts in a resource use platform and improve the detection accuracy and work efficiency of abnormal accounts.
[0027] Other features and advantages of the present application will be set forth in the following specification, and in part will be apparent from the description, or can be learned by practice of the application. The objects and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS
[0028] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the present application and together with the description serve to explain the present application. In the drawings:
[0029] Figure 1a A schematic diagram of a traditional brushing mode;
[0030] Figure 1b A schematic diagram of a new brushing mode;
[0031] Figure 2a An optional schematic diagram of one application scenario in an embodiment of the present application;
[0032] Figure 2b A schematic diagram of an architecture of an abnormal account detection system provided by an embodiment of the present application;
[0033] Figure 2c A schematic diagram of a flow of an abnormal account detection method provided by an embodiment of the present application;
[0034] Figure 3 A schematic diagram of logic of training a first account classification model provided by an embodiment of the present application;
[0035] Figure 4a A schematic diagram of logic of a third-party platform initiating a payment instruction to a resource use platform provided by an embodiment of the present application;
[0036] Figure 4b A schematic diagram of a payment interface provided by an embodiment of the present application;
[0037] Figure 5a A schematic diagram of logic of detecting a target abnormal account set provided by an embodiment of the present application;
[0038] Figure 5b A schematic diagram of logic of managing and controlling brushing operations of a brushing platform merchant provided by an embodiment of the present application;
[0039] Figure 5c A schematic diagram of logic of a specific embodiment provided by an embodiment of the present application;
[0040] Figure 6 A schematic diagram of a structure of an abnormal account detection device provided by an embodiment of the present application;
[0041] Figure 7 A constituent structure schematic diagram of a computer device provided for an embodiment of the present application is shown in FIG. 1.
[0042] Figure 8 A structure schematic diagram of a computing device in an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION
[0043] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the present application will be described below in detail with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments described in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the technical solutions of the present application.
[0044] Some terms in the embodiments of the present application are explained below to facilitate understanding by those of ordinary skill in the art.
[0045] 1. Account: refers to an account opened on a resource use platform by a merchant or an individual object as a registration subject, including a merchant account and an individual account.
[0046] The resource use platform is a mobile payment platform specially applied to a business-to-customer (B2C) transaction scenario. A merchant performs payment operations such as transferring and remitting to an individual account through a merchant account registered on the mobile payment platform. For example, a merchant performs promotion in the form of issuing a coupon, a merchant performs rebate promotion in the form of issuing a cash red envelope, and a merchant refunds an individual object.
[0047] 2. Resource use operation: refers to a transaction between a merchant account and another account in the form of transferring out resources, or a transaction between an individual account and another account in the form of transferring in resources. A service for performing the resource use operation is referred to as a resource use service. For example, a merchant issues a 5-yuan coupon to an individual account, an individual account receives a 3-yuan good review rebate red envelope from a merchant, or an enterprise pays monthly wages to an employee.
[0048] 3. Abnormal resource use operation: In order to improve the search ranking of an e-commerce store, unscrupulous merchants will provide the purchase cost required to purchase goods and employment fees, hire people to pretend to be customers to purchase goods, improve the sales, credit and praise rate of the e-commerce store, and the operation of transferring the above two fees into the individual account of the employed object through the resource use platform is called abnormal resource use operation, which can also be called brushing operation. If a resource use operation is detected as an abnormal resource use operation, the merchant account as the payer in the resource use operation is determined as the target abnormal account, and the individual account as the payee is detected as the abnormal object.
[0049] 4. Multi-platform isolated brushing mode: In order to evade the detection mechanism of the abnormal operation of improving the ranking of the e-commerce platform, unscrupulous merchants will hire people to improve the search ranking of the e-commerce store through a third-party platform (such as a brushing platform), and then transfer a corresponding amount of resources to the individual account of the employed object through the resource use platform. In this way, the fund flow will be deposited on two different platforms, making it difficult for the resource use platform to obtain the resource use information of the individual account and the merchant account on other platforms, and only relying on the historical resource use record set recorded in the platform itself, the resource use platform cannot detect the merchant account with abnormal resource use operation and the individual account associated with it from the numerous accounts of the resource use platform.
[0050] 5. Application program account (Application Identification, APPID): refers to the identification information automatically allocated by the resource use platform when the merchant opens an account on the platform. APPID is used to uniquely identify the merchant account.
[0051] 6. Single price: refers to the average transaction amount corresponding to each transaction record. Generally measured by total consumption amount divided by the number of transactions.
[0052] 7. Repurchase: refers to the total number of transactions of the merchant divided by the total number of people of the merchant. The higher the repurchase value, the higher the possibility of abnormal resource use operation of the corresponding merchant account.
[0053] The design idea of the embodiments of the present application is briefly introduced as follows:
[0054] In recent years, with the popularity of Internet financial business, online shopping has provided a lot of convenience for people's daily life, and in order to obtain a good search ranking of an e-commerce store, unscrupulous merchants will provide the purchase cost required to purchase goods and employment fees, hire people to pretend to be customers to purchase goods, improve the sales, credit and praise rate of the e-commerce store.
[0055] Illegal merchants provide purchase fees and hiring fees to hire people to pretend to be customers to buy goods, and improve the search ranking of e-commerce stores. This is also called brushing operation. As shown in the traditional brushing mode Figure 1a , the store owner of the e-commerce store hires a brush to pretend to be a customer to buy goods, and returns the corresponding purchase fee and hiring fee to the brush through the e-commerce platform.
[0056] With the e-commerce platform's severe crackdown on brushing operations, in order to evade the e-commerce platform's detection mechanism for abnormal store ranking operations (i.e. brushing operation), illegal merchants will also use a new brushing mode as shown in Figure 1b , specifically, illegal merchants hire brushes to perform brushing operations through a third-party platform, and then return the corresponding purchase fee and hiring fee to the hired brushes through the third-party platform.
[0057] Because the information of different platforms is not communicated with each other, the fund flow will be deposited on two different system platforms, forming a multi-platform isolated brushing mode, so that the resource use platform is difficult to obtain the resource use information of individual accounts and merchant accounts on other platforms, and only relying on the historical resource use record set recorded in the platform itself, it is impossible to detect the merchant account with abnormal resource use operation and the individual account associated with it from the numerous accounts of the resource use platform.
[0058] Therefore, the embodiments of the present application provide an abnormal account detection method, device, equipment and storage medium. The method comprises: obtaining a historical resource use record set corresponding to a specified first historical time period, wherein each resource use record contains at least one resource use operation of the corresponding original account in the first historical time period; based on the historical resource use record set, detecting a first candidate account set whose first resource use feature satisfies a first set condition, and based on the resource use record corresponding to each first candidate account, detecting a second candidate account set whose second resource use feature satisfies a second set condition; then based on the account association information of each second candidate account in the second candidate account set, regarding the original account associated with any second candidate account as a third candidate account, generating a corresponding third candidate account set, and finally outputting the union of the second candidate account set and the third candidate account set as a target abnormal account set.
[0059] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0060] Referring to Figure 2aThe illustrated application scenario diagram includes a first terminal device 21, a second terminal device 23, and a server 24.
[0061] The first terminal device 21 and the second terminal device 23 communicate with the server 24 via a communication network. Illegal merchants log into the application interface 22 through the first terminal device 21 and send resource usage requests to the resource usage platform deployed on the server 24. This causes the server 24 to transfer the corresponding amount of digital currency from the resource usage request to the corresponding individual account, completing the online transaction between the illegal merchant and the "brushing" user. Similarly, the "brushing" user can also log into the application interface 22 through the second terminal device 23 to receive the corresponding amount of digital currency transferred from the server 24, thus realizing an online transaction between the two.
[0062] In one optional implementation, the communication network can be either a wired network or a wireless network. Therefore, the first terminal device 21 can directly establish a communication connection with the server 24 via a wired network or indirectly establish a communication connection with the server 24 via a wireless network. This application does not impose any limitations on this. Similarly, the second terminal device 23 can also directly establish a communication connection with the server 24 via a wired network or indirectly establish a communication connection with the server 24 via a wireless network. This application does not impose any limitations on this either.
[0063] Specifically, in the embodiments of this application, the first terminal device 21 and the second terminal device 23 are both electronic devices used by individuals or merchants. The electronic devices can be computer devices with certain computing capabilities and that support electronic payments, such as personal computers, mobile phones, tablets, laptops, payment terminals, e-book readers, and smart home devices.
[0064] The server 24 in this application embodiment can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. This application does not impose any limitations on this. If the resource identification method for abnormal account groups disclosed in this application is used, multiple servers can form a blockchain, and the server is a node on the blockchain.
[0065] This application provides an abnormal account detection system 200, the architecture of which is shown in the following diagram. Figure 2b As shown, the system 200 consists of three parts: a non-marketing merchant account detection module 210, a fake order platform detection module 220, and a fake order platform control module 230.
[0066] The merchant can issue coupons, issue cash red envelopes and other promotional methods to individual accounts through the resource use platform to attract customers to purchase goods, increase the turnover and sales volume of the e-commerce store, and achieve the purpose of product marketing. Therefore, the legal merchant account using the above promotion method will have multiple small transactions on the resource use platform in a short period of time, and each small transaction has different transaction objects, such as a legal merchant account issuing a 3-yuan good review cash red envelope to multiple individual accounts.
[0067] And the abnormal merchant account using the brushing method needs to bear the purchase cost and the hiring cost. In order to save labor costs as much as possible and reduce the expenditure of hiring fees, each brusher will register multiple e-commerce platform accounts to brush the single of the abnormal merchant account's e-commerce store. Therefore, the abnormal merchant account will have a small number of large transactions on the resource use platform in a short period of time, and each large transaction has different transaction objects, such as an abnormal merchant account issuing a 500-yuan cash red envelope to an individual account.
[0068] From the foregoing introduction, it can be known that the marketing merchant account generally has the characteristics of a large number of payers, low single price, and low payback rate. The characteristic information of the non-marketing merchant account is obviously distinguishable from the marketing merchant account, and the linear feature is significant. Therefore, the first account classification model 2101 in the non-marketing merchant account detection module 210 distinguishes the marketing merchant account and the non-marketing merchant account in the resource use platform according to the transaction characteristics of the legal merchant account and the abnormal merchant account, and detects a first candidate account set that satisfies the first set condition according to the first resource use characteristic. The first candidate account can also be referred to as a non-marketing merchant account, which will not be described in detail hereinafter.
[0069] The brushing platform detection module 220 distinguishes the legal non-marketing merchant account and the suspicious non-marketing merchant account in the non-marketing merchant account based on the built-in second account classification model 2201. The brushing platform detection module 220 can further detect other suspicious non-marketing merchant accounts in the resource use platform and the brusher accounts associated with the suspicious non-marketing merchant accounts through the brushing detection algorithm and the account association relationship of the suspicious non-marketing merchant account.
[0070] In the embodiments of the present application, the suspicious non-marketing merchant account is referred to as a second candidate account, the other suspicious non-marketing merchant account is referred to as a third candidate account, and the brusher account is referred to as an abnormal object, which will not be described in detail hereinafter.
[0071] The embodiments of the present application provide two ways of determining the target abnormal account set, one is to output the union of the second candidate account set and the third candidate account as the target abnormal account set; in order to improve the detection accuracy, the other is to output the intersection of the second candidate account set and the third candidate account set as the target abnormal account set. In addition, the target abnormal account in the embodiments of the present application can also be called a single platform merchant (that is, a merchant who performs single operation through a third party platform).
[0072] The single platform management module 230 includes an APPID management component 2301, a single hand management component 2302, and an Internet Protocol (IP) address management component 2303 interconnected by a network. For each identified single platform merchant, the single platform management module 230 performs gradient management of the single operation of the single platform merchant according to the single striking means deployed in each component, ensures the striking intensity of the system on the single operation, and ensures the payment security of the entire system.
[0073] Next, referring to the flowchart shown in FIG. 2, the abnormal account detection method proposed in the embodiments of the present application is introduced. Figure 2c
[0074] S201: Obtain a historical resource usage record set corresponding to a specified first historical time period, wherein each resource usage record contains at least one resource usage operation of the corresponding original account in the first historical time period.
[0075] The resource usage platform is a mobile payment platform specially applied to a B2C transaction scenario, which only supports resource usage operations of enterprises paying individuals, that is, the payment party of each resource usage operation is a merchant account, and the paid party is an individual account. Therefore, in order to detect the merchant accounts with abnormal resource usage operations and the individual accounts associated with them from the numerous accounts on the resource usage platform, it is necessary to first obtain a historical resource usage record set of all merchant accounts in a specified first historical time period from the resource usage platform, each merchant account corresponding to a historical resource usage record, and each historical resource usage record containing at least one resource usage operation of the merchant account in the specified first historical time period.
[0076] For example, a daily payment record set of all merchant accounts on a mobile payment platform is obtained, each merchant account corresponding to a daily payment record, and each daily payment record containing at least one payment record of the merchant account on that day. Therefore, the original account in the embodiments of the present application refers to the original merchant account, which will not be described again.
[0077] S202: Based on the set of historical resource usage records, a first candidate account set in which the first resource usage feature meets the first set condition is detected, and based on the resource usage records corresponding to each first candidate account, a second candidate account set in which the second resource usage feature meets the second set condition is detected.
[0078] In step 202, each resource usage record in the set of historical resource usage records is input into the preset first account classification model to obtain the first candidate account set; wherein, by reading one resource usage record by the account classification model, based on the first resource usage information carried by the resource usage record, the first account classification probability of the corresponding original account is obtained, if the first account classification probability exceeds the set first classification probability threshold, it is determined that the first resource usage feature of the original account meets the first set condition, and the original account is attributed to a first candidate account.
[0079] The resource usage record of the original account contains at least one resource usage operation of the original account in the first historical time period, therefore, based on the multiple resource usage operations recorded in the resource usage record, the average price per transaction of the original account in the first historical time period, the amount of money in the first historical time period, the number of people in the first historical time period, and multiple feature information such as the time interval of the payment can be calculated, and the above-mentioned multiple feature information is collectively referred to as the first resource usage feature carried by the resource usage record in the embodiment of the application.
[0080] Suppose the daily payment record of the original account is obtained, based on the daily payment record, the average price per transaction of the original account, the amount of money, the number of people, and multiple feature information such as the time interval of the payment can be calculated.
[0081] Referring to Figure 3 The logic diagram for training the first account classification model is shown, which briefly introduces the training process of the first account classification model.
[0082] From the merchant daily flow database 301 of the resource usage platform, the set of daily payment records of all merchants is obtained, and then the daily payment records of each merchant are input into the feature calculation platform 302 in turn to obtain the corresponding initial resource usage feature group; wherein, the feature calculation platform 302 reads one daily payment record each time, and generates an initial resource usage feature group such as (average price per transaction, amount of money, number of people, time interval of payment) through calculation.
[0083] Each initial resource use feature group contains up to 50 feature information, in order to reduce the training pressure of the model, after the feature information in each initial resource use feature group is standardized, the feature screening module 303 screens out the feature information with high correlation with the account classification, and outputs the screened feature information as the final target resource use feature group.
[0084] Through the artificial auditing system 304 and the artificial marking system 305, the actual label information of the marketing type merchant account or the non-marketing type merchant account is marked for each target feature group, and each marked target resource use feature group is output as a training sample set of the first account classification model.
[0085] In a cyclic iteration manner, each training sample in the training sample set is input into the first account classification model 306 to be trained in turn until the preset iteration stop condition is met, and the model of the last iteration is output as the trained first account classification model 306. Wherein, after the model 306 reads a training sample, the corresponding first account classification probability is obtained through feature extraction, normalization processing and other operations, and based on the comparison result between the first account classification probability and the set first classification probability threshold, the prediction label information of the training sample is determined; and based on the loss value between the prediction label information and the corresponding actual label information, the parameters of the model 306 are adjusted.
[0086] And the iteration stop condition can be at least one of the following conditions: reaching the set iteration number, all training samples are read, and the loss value of the model does not exceed the set loss threshold.
[0087] In order to facilitate understanding, a specific embodiment is taken as an example to introduce the training process of the first account classification model.
[0088] Suppose the training sample is (single-day payout pen price 200 yuan, single-day payout amount 2000 yuan, single-day payout number 10, payout time interval 10:00-10:30, actual label information is non-marketing type commercial account). The training sample is input into the first account classification model 306 to be trained, after a series of operations such as feature extraction, normalization processing and other operations in the model 306, the output prediction label information is marketing type commercial account, and then based on the loss value between the two label information, the parameters of the model 306 are adjusted.
[0089] After the first candidate account set is screened out, the trained second account classification model can be used to further distinguish the legal non-marketing type merchant account from the suspicious non-marketing type merchant account (i.e. the second candidate account) in the first candidate account set.
[0090] Specifically, the resource usage records corresponding to each first candidate account are respectively input into a preset second account classification model to obtain a second candidate account set; wherein, the second account classification model reads one resource usage record each time, and based on the second resource usage information carried by the resource usage record, obtains the second account classification model of the corresponding first candidate account, and if the second account classification probability exceeds the set second classification threshold, it is determined that the second resource usage feature of the first candidate account meets the second set condition, and the first candidate account is attributed to a second candidate account.
[0091] The resource usage record of the first candidate account contains at least one resource usage operation of the first candidate account in the first historical time period, so based on the multiple resource usage operations recorded in the resource usage record, multiple feature information of the first candidate account in the first historical time period, such as the first historical time period, the total amount of merchant payment, the total number of merchant payment, etc. The above-mentioned multiple feature information is collectively referred to as second resource usage feature in the embodiment of the present application. The number of features in the second resource usage feature is less than the number of features in the first resource usage feature; in addition, the feature information contained in the second resource usage feature may be completely different from the feature information contained in the first resource usage feature, or part or all of the feature information in the second resource usage feature may be the same as part of the feature information in the first resource usage feature.
[0092] S203: Based on the account association information of each second candidate account in the second candidate account set, the original account associated with any second candidate account is taken as a third candidate account, and a corresponding third candidate account set is generated.
[0093] Referring to Figure 4a The logic diagram shown simply introduces the process of the third-party platform 401 initiating a payment instruction to the resource usage platform.
[0094] The third-party platform 401 is deployed on the cloud server 402, and the third-party platform 401 shows the payment interface to the object as Figure 4b The third-party platform 401 generates a corresponding payment instruction according to the payment information obtained above, and calls the API of the cloud server 402 to send the payment instruction to the background port of the resource usage platform through the payment port of the cloud server 402, so that the resource usage platform transfers the purchase fee and the employment fee to the individual account of the brusher based on the received payment instruction.
[0095] According to the process of initiating the payment instruction described in the foregoing, the third-party platform 401 is based on the payment instruction generated by the APPID bound by the illegal merchant 403. Multiple merchant accounts on the third-party platform can use the same APPID. Therefore, when the account association information is resource usage identification information (i.e., the APPID of the second candidate account), if the resource usage identification information of the original account is the same as that of any second candidate account, the original account is attributed to the third candidate account.
[0096] Before sending the payment instruction to the background port of the resource usage platform, the cloud server 402 also needs to encapsulate the payment instruction using the IP address of the cloud server 403 itself, and then send the encapsulated payment instruction to the background port. Merchants who use the same third-party platform 401 to conduct brushing operations will also be associated with the same IP address. Therefore, when the account association information is access address information (i.e., the IP address of the second candidate account), if the access address information of the original account is the same as that of any second candidate account, the original account is attributed to the third candidate account.
[0097] In addition, the original account associated with any abnormal object in the first historical time period can also be reversely associated according to the abnormal object set associated with each second candidate account. Specifically, when the account association information is the abnormal object set associated with each second candidate account, if the original account is associated with any abnormal object in the abnormal object set, the original account is attributed to the third candidate account. Finally, the third candidate accounts obtained based on the at least one account association information are merged into a third candidate account set.
[0098] S204: Output the union of the second candidate account set and the third candidate account set as the target abnormal account set.
[0099] For ease of understanding, refer to the logic diagram for detecting the target abnormal account set shown in FIG. 8 for a brief description of the abnormal account detection method provided by the embodiments of the present application. Figure 5a
[0100] Obtain the historical resource usage record set of all merchant accounts in the specified first historical time period from the resource usage platform, and obtain a first candidate account set of first candidate accounts that satisfy first set conditions based on the resource usage records of each merchant account and the first account classification model (i.e., a set of non-marketing merchant accounts). Further distinguish the legal non-marketing merchant accounts from the suspicious non-marketing merchant accounts v1 (i.e., the second candidate accounts) in the first candidate account set based on the trained second account classification model.
[0101] Further, based on the account association relationship of the suspicious non-marketing merchant account and the brush-up detection algorithm, the original account v2 with the same resource use identification information as any second candidate account, the original account v3 with the same access address information as any second candidate account, and the original account v4 associated with any abnormal object in the resource use platform can be detected, and v2-v4 constitute other suspicious non-marketing merchant accounts v5 in the embodiment of the application. Finally, the union or intersection of the two sets of v1 and v5 is output as the target abnormal account set.
[0102] After outputting the target abnormal account set, the method further performs at least one of the following operations on each identified brush-up platform merchant, and the brush-up operation of the brush-up platform merchant is controlled in a gradient manner as shown in the figure, so as to ensure the striking force of the system on the brush-up operation and the payment security of the entire system. Figure 5b
[0103] Operation 1: receiving a first resource use request, if the initiating end account of the first resource use request is a target abnormal account with abnormal resource use operation, when it is determined that the initiating end account does not comply with the preset control rule, the corresponding resource use service is stopped for the initiating end account.
[0104] Specifically, the APPID control component in the brush-up platform control module obtains the resource use identification information associated with the initiating end account. If it is determined based on the resource use identification information that the number of resource use operations of the initiating end account has reached a set second threshold value, it is determined that the initiating end account does not comply with the control rule, and an open message 1 is sent to the real-time striking platform and the offline audit platform to trigger the two platforms to control the initiating end account and stop providing corresponding resource use services for the initiating end account.
[0105] On the contrary, if the APPID control component determines that the initiating end account complies with the control rule, an open message 0 is sent to the two platforms to trigger the two platforms to stop controlling the initiating end account and continue to provide corresponding resource use services for the initiating end account.
[0106] The IP address control component in the brush-up platform control module obtains the access address information associated with the initiating end account. If it is determined based on the access address information that the number of calls of the access address information of the initiating end account has reached a set third threshold value, it is determined that the initiating end account does not comply with the control rule, and the corresponding resource use services are stopped for the initiating end account. On the contrary, if the IP address control component determines that the initiating end account complies with the control rule, the corresponding resource use services are continued to be provided for the initiating end account.
[0107] Operation two: receiving a second resource use request, if the receiving end account of the second resource use request is associated with any target abnormal account, then when it is determined that the receiving end account does not meet the control rules, stop providing corresponding resource use services for the receiving end account.
[0108] Specifically, the brush hand control component in the brushing platform control module obtains the account identifier information of the receiving end account. If it is determined based on the account identifier information that the resource transfer number of the receiving end account in a specified second historical time period has reached a set fourth threshold value, it is determined that the receiving end account does not meet the control rules, and the corresponding resource use service is stopped for the receiving end account. Otherwise, if the brush hand control component determines that the receiving end account meets the control rules, the corresponding resource use service is continued to be provided for the receiving end account.
[0109] For example, the brush hand control component obtains the OpenID of the individual account. If it is determined based on the OpenID that the daily collection amount of the individual account has reached the upper limit value, it is determined that the individual account does not meet the control rules, and the corresponding collection service is stopped.
[0110] In addition, the brushing operation has the characteristic of business stickiness, so the brush hands who perform brushing operations for the e-commerce stores of illegal merchants will often also participate in other abnormal business operations, such as using the rule loopholes of the e-commerce platform to obtain some illegal benefits without violating the rules established by the e-commerce platform. By closely monitoring the transaction flow of the detected brush hands, other abnormal business operation participants can be discovered and controlled in a timely manner, effectively combating other abnormal business operations.
[0111] In addition to the risk control methods mentioned above, the brushing platform control module can also use other control methods such as initiating commitment letters and initiating audit certificates to replace the risk control methods to control the identified brushing platform merchants; or use multiple control methods to control the identified brushing platform merchants.
[0112] Referring to Figure 5c the logic diagram, a specific application scenario is used for further description.
[0113] Obtain the daily transaction flow records of all merchant accounts on the payment platform, and obtain a set of non-marketing merchant accounts based on the daily flow transactions of each merchant account and the first account classification model. Further distinguish the legal non-marketing merchant accounts from the suspicious non-marketing merchant accounts v1 in the set of non-marketing merchant accounts based on the trained second account classification model.
[0114] Furthermore, based on the algorithm for detecting fraudulent transactions and the account association relationships between suspicious non-marketing merchant accounts, the algorithm can detect the original account v2 that shares the same APPID as any suspicious non-marketing merchant account, the original account v3 that shares the same IP address as any suspicious non-marketing merchant account, and the original account v4 that is associated with any fraudulent transaction participant. v2 to v4 constitute other suspicious non-marketing merchant accounts v5 in this embodiment. Finally, the union or intersection of the two sets v1 and v5 is output as the target fraudulent transaction merchant set.
[0115] If the payment platform receives the first payment request and the initiating account of the request is the target merchant who engages in fraudulent transactions, it will stop providing the corresponding payment service to the initiating account if it is determined that the initiating account does not comply with the control rules. If the payment platform receives the second payment request and the receiving account of the request is the identified fraudulent transaction target, it will stop transferring funds to the receiving account if it is determined that the receiving account does not comply with the control rules.
[0116] Based on the same inventive concept as the above-described method embodiments, this application also provides a schematic diagram of the structure of an abnormal account detection device. For example... Figure 6 As shown, device 600 may include:
[0117] The acquisition unit 601 is used to obtain a set of historical resource usage records corresponding to a specified first historical time period, wherein each resource usage record contains at least one resource usage operation of the corresponding original account within the first historical time period.
[0118] The detection unit 602 is used to detect a set of first candidate accounts whose first resource usage characteristics meet the first set of conditions based on a set of historical resource usage records, and to detect a set of second candidate accounts whose second resource usage characteristics meet the second set of conditions based on the resource usage records corresponding to each first candidate account.
[0119] Based on the account association information of each second candidate account in the second candidate account set, the original account that is associated with any second candidate account is taken as the third candidate account, and the corresponding third candidate account set is generated.
[0120] The union of the second and third candidate account sets is output as the target abnormal account set.
[0121] Optionally, the detection unit 602 is used for:
[0122] The detection unit 602 is configured to: input each resource usage record in the historical resource usage record set into a preset first account classification model respectively, to obtain a first candidate account set; wherein, the first account classification model reads one resource usage record each time, and obtains a first account classification probability of a corresponding original account based on first resource usage information carried by the one resource usage record; if the first account classification probability exceeds a preset first classification probability threshold, it is determined that a first resource usage feature of the one original account satisfies a first preset condition, and the one original account is attributed to a first candidate account.
[0123] Optionally, the detection unit 602 is configured to:
[0124] The detection unit 602 is configured to: input each resource usage record in the historical resource usage record set into a preset first account classification model respectively, to obtain a first candidate account set; wherein, the first account classification model reads one resource usage record each time, and obtains a first account classification probability of a corresponding original account based on first resource usage information carried by the one resource usage record; if the first account classification probability exceeds a preset first classification probability threshold, it is determined that a first resource usage feature of the one original account satisfies a first preset condition, and the one original account is attributed to a first candidate account.
[0125] Optionally, the detection unit 602 is configured to perform at least one of the following operations:
[0126] When the account association information is resource usage identifier information, if the resource usage identifier information of the original account is the same as the resource usage identifier information of any one of the second candidate accounts, the original account is attributed to a third candidate account;
[0127] When the account association information is access address information, if the access address information of the original account is the same as the access address information of any one of the second candidate accounts, the original account is attributed to a third candidate account;
[0128] When the account association information is an abnormal object set associated with each of the second candidate accounts, if the original account has an association relationship with any one of the abnormal objects in the abnormal object set, the original account is attributed to a third candidate account.
[0129] Optionally, the detection unit 602 is further configured to:
[0130] The intersection of the second candidate account set and the third candidate account set is output as a target abnormal account set.
[0131] Optionally, after outputting the target abnormal account set, the apparatus 600 further includes a management and control unit 603, and the management and control unit 603 is configured to perform at least one of the following operations:
[0132] The first resource use request is received, if the initiator account of the first resource use request is a target abnormal account with abnormal resource use operation, the corresponding resource use service is stopped for the initiator account when it is determined that the initiator account does not conform to the preset control rule;
[0133] The second resource use request is received, if the receiving end account of the second resource use request is associated with any target abnormal account, the corresponding resource use service is stopped for the receiving end account when it is determined that the receiving end account does not conform to the control rule.
[0134] Optionally, the control unit 603 performs at least one of the following operations:
[0135] The resource use identification information associated with the initiator account is obtained, if it is determined that the number of resource use operations of the initiator account has reached a second threshold based on the resource use identification information, it is determined that the initiator account does not conform to the control rule;
[0136] The access address information associated with the initiator account is obtained, if it is determined that the number of calls of the access address information of the initiator account has reached a third threshold based on the access address information, it is determined that the initiator account does not conform to the control rule.
[0137] Optionally, the control unit 603 is configured to:
[0138] The account identification information of the receiving end account is obtained, if it is determined that the number of resource transfers of the receiving end account in a specified second historical time period has reached a fourth threshold based on the account identification information, it is determined that the receiving end account does not conform to the control rule.
[0139] For the convenience of description, the above parts are divided into modules (or units) according to functions and are described respectively. Of course, in the implementation of the present application, the functions of the modules (or units) can be realized in the same or multiple software or hardware.
[0140] After introducing the abnormal account detection method and device of the example embodiment of the present application, next, the computer device according to another example embodiment of the present application is introduced.
[0141] Those skilled in the art can understand that each aspect of the present application can be implemented as a system, a method or a program product. Therefore, each aspect of the present application can be specifically implemented as follows: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" here.
[0142] Based on the same inventive concept as the above method embodiment, a computer device is also provided in the present embodiment, which is described with reference to Figure 7As shown, the computer device 700 may include at least a processor 701 and a memory 702. The memory 702 stores program code, which, when executed by the processor 701, causes the processor 701 to perform the steps of any of the aforementioned abnormal account detection methods.
[0143] In some possible implementations, the computing device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps in the abnormal account detection method according to the various exemplary embodiments of this application described above. For example, the processor may perform actions such as... Figure 2c The steps are shown in the figure.
[0144] The following reference Figure 8 To describe a computing device 800 according to this embodiment of the present application. Figure 8 The computing device 800 is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0145] like Figure 8 As shown, the computing device 800 is presented in the form of a general-purpose computing device. The components of the computing device 800 may include, but are not limited to: at least one processing unit 801, at least one storage unit 802, and a bus 803 connecting different system components (including storage unit 802 and processing unit 801).
[0146] Bus 803 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or a local bus using any of the various bus structures.
[0147] Storage unit 802 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 8021 and / or cache memory unit 8022, and may further include read-only memory (ROM) 8023.
[0148] Storage unit 802 may also include a program / utility 8025 having a set (at least one) program module 8024, such program module 8024 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0149] Computing device 800 can also communicate with one or more external devices 804 such as a keyboard or pointing device, through I / O interface 805. One or more devices can enable a user to interact with computing device 800 in order to manipulate the processing of the objects by the computing device 800, and / or enable the computing device 800 to communicate with one or more other computing devices. Such communication can occur via I / O interface 805. Also, computing device 800 can communicate with one or more networks such as a local area network (LAN), a general wide area network (WAN), and / or a public network (e.g., the Internet) via network adapter 806. As depicted, network adapter 806 communicates with the other components of computing device 800 via bus 803. It should be understood that, although not shown, other hardware and / or software components could be used in conjunction with computing device 800. Examples, include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0150] Based on the same inventive concept as the method embodiments described above, each aspect of the abnormal account detection method provided in the present application can also be implemented in the form of a program product, which includes program codes for causing a computer device to execute the steps of the abnormal account detection method according to various exemplary embodiments of the present application described above in the specification when the program product is run on the computer device. For example, the electronic device can execute the steps as shown in Figure 2c FIG. 6, for example.
[0151] The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0152] Although preferred embodiments of the application have been described, a person of ordinary skill in the art can make additional changes and modifications to the embodiments once armed with the basic inventive concept. Therefore, the appended claims are intended to cover all changes and modifications that fall within the scope of the application.
[0153] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. An anomalous account detection method, characterized by, The application is applied to a multi-platform isolated brushing scenario in the field of electronic finance, including: obtaining a plurality of historical resource use records corresponding to a specified first historical time period, wherein each resource use record contains at least one resource use operation of the corresponding original account within the first historical time period; performing multi-dimensional statistical induction on each resource use record to obtain a respective first resource use feature, and performing classification prediction on each first resource use feature through a preset first account classification model to obtain a first account classification probability of the corresponding original account, and regarding the original account whose first account classification probability exceeds a set first classification probability threshold as a non-marketing account; performing resource analysis on the resource use records of each non-marketing account within the first historical time period to obtain a respective second resource use feature within the first historical time period, and performing classification prediction on each resource use feature through a preset second account classification model to obtain a second account classification probability of each non-marketing account, and regarding the non-marketing account whose second account classification probability exceeds a set second classification probability threshold as a suspicious non-marketing account; for each original account, performing: when the resource use identification information, access address information, and at least one information of the associated abnormal object of any suspicious non-marketing account match successfully, regarding the original account as a suspicious associated account; outputting the union of each suspicious non-marketing account and each suspicious associated account as a target abnormal account set.
2. The method of claim 1, wherein, The method further comprises: outputting the intersection of each suspicious non-marketing account and each suspicious associated account as a target abnormal account set.
3. The method of claim 1 or 2, wherein, After outputting the target abnormal account set, the method further performs at least one of the following operations: receiving a first resource use request, if the initiator account of the first resource use request is a target abnormal account with abnormal resource use operations, and determining that the initiator account does not comply with a preset control rule, stopping providing corresponding resource use services for the initiator account; receiving a second resource use request, if the receiver account of the second resource use request has an association relationship with any target abnormal account, and determining that the receiver account does not comply with the control rule, stopping providing corresponding resource use services for the receiver account.
4. The method of claim 3, wherein, The determination that the initiator account does not comply with the control rule includes at least one of the following operations: obtaining resource use identification information associated with the initiator account, if it is determined based on the resource use identification information that the number of resource use operations of the initiator account has reached a set second threshold, it is determined that the initiator account does not comply with the control rule; obtaining access address information associated with the initiator account, if it is determined based on the access address information that the number of calls of the access address information of the initiator account has reached a set third threshold, it is determined that the initiator account does not comply with the control rule.
5. The method of claim 3, wherein, The determination that the receiver account does not comply with the control rule includes: Obtaining account identification information of the receiving end account, and if it is determined based on the account identification information that the number of resource transfers of the receiving end account in a specified second historical time period has reached a set fourth threshold value, it is determined that the receiving end account does not meet the control rule.
6. An anomalous account detection apparatus characterized by comprising: The application is applied to the multi-platform isolated brushing scene in the field of electronic finance, and includes: An obtaining unit is configured to obtain a plurality of historical resource use records corresponding to a specified first historical time period, wherein each resource use record contains at least one resource use operation of a corresponding original account in the first historical time period; A detection unit is configured to perform multi-dimensional statistical induction on each resource use record to obtain a respective first resource use feature, and perform classification prediction on each first resource use feature through a preset first account classification model to obtain a first account classification probability of the corresponding original account, and take an original account with a first account classification probability exceeding a set first classification probability threshold as a non-marketing account; Perform resource analysis on the resource use records of each non-marketing account in the first historical time period to obtain a respective second resource use feature in the first historical time period, and perform classification prediction on each resource use feature through a preset second account classification model to obtain a second account classification probability of each non-marketing account, and take a non-marketing account with a second account classification probability exceeding a set second classification probability threshold as a suspicious non-marketing account; For each original account, the following is performed: when the resource use identification information, the access address information and at least one information in the associated abnormal object of the original account and any suspicious non-marketing account match successfully, the original account is taken as a suspicious associated account; The union of each suspicious non-marketing account and each suspicious associated account is taken as a target abnormal account set and output.
7. The apparatus of claim 6, wherein, The detection unit is further configured to: The intersection of each suspicious non-marketing account and each suspicious associated account is taken as the target abnormal account set and output.
8. A computer device, comprising: The application includes a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the method in any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The application includes program code, and when the program product is running on a computer device, the program code is used to make the computer device execute the steps of the method in any one of claims 1-5.
Citation Information
Patent Citations
Method and device for identifying abnormal account set and risk account set, and equipment
CN110264326A