Risk Disposal Measure Adjustment Method, Its Device, Equipment, and Medium

Through the second-stage risk control detection method, the risk treatment methods are dynamically adjusted, which solves the problems of singleness of risk control detection services and waste of resources on the existing platform, and improves the platform's risk resistance and user retention rate.

CN115665447BActive Publication Date: 2025-07-04GUANGZHOU FANGGUI INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211289390.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-07-04
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

Existing platform risk control and detection services usually use a single risk treatment method, resulting in the platform's weak risk resistance and does not conform to the user's risk response operations, and wastes computing resources and network traffic.

Method used

The second-stage risk control detection method is adopted to quickly determine risks by executing the first stage risk control detection rules in parallel, and the second stage risk control detection rules in series are implemented to adjust risk treatment methods, and dynamically adjust risk treatment strategies to adapt to different user behaviors.

Benefits of technology

It improves the flexibility and efficiency of the platform's risk control services, ensures severe disposal against malicious users, mild disposal against non-malicious users, and protects platform stability and user retention rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115665447B_ABST
    Figure CN115665447B_ABST
Patent Text Reader

Abstract

The present application discloses a method and apparatus, device, and medium for adjusting risk disposal means. The method includes: responding to a platform operation request pushed by a user terminal, and obtaining platform behavior information and a platform service identifier corresponding to the platform operation request; according to the platform behavior information, invoking a plurality of parallel first risk control detection rules in a first risk control detection rule set corresponding to the platform service identifier to detect whether the platform operation request is a risk operation request. If so, obtaining corresponding multiple first risk disposal means; according to each first risk disposal means and the platform behavior information, invoking a plurality of second risk control detection rules connected in series in a second risk control detection rule set corresponding to the platform service identifier to obtain one or more second risk disposal means; and performing a risk disposal service on the user terminal that acts on the platform operation request according to each second risk disposal means. The present application can dynamically adjust the risk disposal means in the platform and accurately combat various risk behaviors of platform users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of platform business risk control, and in particular to a method for adjusting risk management measures. In addition, it also relates to corresponding devices, equipment and non-volatile storage media of the method. Background Art

[0002] Most of the existing platforms have corresponding risk control detection services to prevent the platform from being maliciously attacked and behaviors that violate platform rules and threaten platform security. For example, in an online live broadcast platform, excessive visits to the live broadcast room will cause network congestion and affect the live broadcast business of the live broadcast room, or participate in live broadcast activities through non-compliant means to undermine the fairness of the activities. The platform can maintain the platform through risk control detection services to provide platform users with a safe and excellent platform environment, but the existing risk control detection services usually only perform a single risk control detection, that is, determine the risk disposal measures, which makes the platform's risk resistance weak, and the risk disposal measures determined by a single risk control detection may not necessarily meet the risk response operations of the detected users. For example, invalid risk control disposal measures such as the risk disposal measures of performing SMS verification on users who have not registered their mobile phone numbers occupy unnecessary computing resources and network traffic of the risk control detection service.

[0003] In view of the problems existing in the use of risk control detection services in existing platforms, the applicant has made corresponding explorations in order to solve the problem. Summary of the invention

[0004] The purpose of this application is to meet user needs and provide a risk management means adjustment method. In addition, it also involves corresponding devices, equipment, non-volatile storage media and computer program products of the method.

[0005] In order to achieve the purpose of this application, the following technical solutions are adopted:

[0006] A risk management adjustment method proposed for the purpose of this application includes the following steps:

[0007] Respond to the platform operation request pushed by the user end, and obtain the platform behavior information and platform service identifier corresponding to the platform operation request;

[0008] According to the platform behavior information, a first risk control detection rule set corresponding to the platform business identifier is obtained, and multiple first risk control detection rules in the first risk control detection rule set are executed in parallel to detect whether the platform operation request is a risk operation request, and if so, multiple corresponding first risk handling means are obtained; if so, multiple corresponding first risk handling means are obtained;

[0009] According to each of the first risk handling means and the platform behavior information, obtain a second risk control detection rule set corresponding to the platform service identifier, serially execute multiple second risk control detection rules in the second risk control detection rule set, and obtain one or more second risk handling means;

[0010] According to each of the second risk handling means, perform a risk handling service on the user side for the platform operation request.

[0011] In a further embodiment, in the step of obtaining the platform behavior information corresponding to the platform operation request and the live broadcast platform service in response to the platform operation request pushed by the user side, the following steps are included:

[0012] Receive a platform operation request pushed by the user side, parse the platform operation request, and obtain the user feature identifier and the platform service identifier included in the platform operation request;

[0013] Query the platform behavior information corresponding to the user feature identifier from the user historical behavior library to obtain the platform behavior information.

[0014] In a further embodiment, in the step of obtaining a first risk control detection rule set corresponding to the platform service identifier according to the platform behavior information, serially executing multiple first risk control detection rules in the first risk control detection rule set, and detecting whether the platform operation request is a risk operation request, if so, obtaining corresponding multiple first risk handling means, the following steps are included:

[0015] Query a first risk control detection rule set corresponding to the platform service identifier from the first rule set pool;

[0016] According to the detection factors corresponding to the multiple first risk control detection rules included in the first risk control detection rule set, push the corresponding user behavior data in the platform behavior information to each of the first risk control detection rules;

[0017] Serially execute each of the first risk control detection rules to perform risk control detection based on the obtained user behavior data, determine the first risk detection rule with a higher risk degree among the multiple first risk control detection rules with a risk control detection result of risk, and obtain the first risk handling means corresponding to each of the first risk detection rules.

[0018] In a further embodiment, in the step of obtaining a second risk control detection rule set corresponding to the platform service identifier according to each of the first risk handling means and the platform behavior information, serially executing multiple second risk control detection rules in the second risk control detection rule set, and obtaining one or more second risk handling means, the following steps are included:

[0019] Query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool;

[0020] Sequentially execute multiple second risk control detection rules in series in the second risk control detection rule set. According to the detection factor or target disposal means corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first disposal means in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection;

[0021] After sequentially executing multiple second risk control detection rules in series in the second risk control detection rule, obtain the second risk disposal means corresponding to the second risk control detection rule whose risk re-detection result is that the disposal means needs to be adjusted.

[0022] In a further embodiment, in the step of obtaining the second risk control detection rule set corresponding to the platform service identifier according to each of the first risk disposal means and the platform behavior information, sequentially executing multiple second risk control detection rules in the second risk control detection rule set, and obtaining one or more second risk disposal means, the following steps are included:

[0023] Query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool;

[0024] Sequentially execute multiple second risk control detection rules in series in the second risk control detection rule set. According to the detection factor or target disposal means corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first disposal means in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection;

[0025] When the risk re-detection result of the currently executed second risk control detection rule is that there is no need to adjust the disposal means, determine the previous second risk control detection rule of the currently executed second risk control detection rule, and obtain the second risk disposal means corresponding to the previous second risk control detection rule.

[0026] In a further embodiment, in the step of obtaining the second risk control detection rule set corresponding to the platform service identifier according to each of the first risk disposal means and the platform behavior information, sequentially executing multiple second risk control detection rules in the second risk control detection rule set, and obtaining one or more second risk disposal means, the following steps are included:

[0027] When the target disposal means corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, detect whether there is a first risk disposal means that prohibits access to the live broadcast room among the currently obtained first risk disposal means;

[0028] When there is the first risk handling measure for prohibiting access to the live broadcast room, obtain the user behavior data including the number of visits to the live broadcast room in the platform behavior information;

[0029] Judge whether the number of visits to the live broadcast room exceeds the preset restricted access number. If not, output a risk re-detection result indicating the existence of a risk. The second risk handling measure corresponding to the second risk control detection rule is to ask about the current type of the live broadcast room being accessed.

[0030] In a further embodiment, in the step of performing a risk handling service on the user side for the platform operation request according to each of the second risk handling measures, the following steps are included:

[0031] When the second risk handling measure is to ask about the current type of the live broadcast room being accessed, obtain the target live broadcast room type corresponding to the target live broadcast room currently accessed by the user side and other live broadcast room types;

[0032] Push the target live broadcast room type and other live broadcast room types to the user side, and drive the user side to output the target live broadcast room type and other live broadcast room types to be displayed in the live broadcast room type selection window;

[0033] Respond to the live broadcast room type selection instruction pushed by the user side, and judge whether the live broadcast room type corresponding to the live broadcast room type selection instruction is the target live broadcast room type. If not, stop opening the live broadcast room access permission of the target live broadcast room to the user side.

[0034] A risk handling measure adjustment device proposed to meet the purpose of the present application, which includes:

[0035] An operation request response module, configured to respond to a platform operation request pushed by a user side, and obtain the platform behavior information and platform service identifier corresponding to the platform operation request;

[0036] A first risk control detection module, configured to obtain a first risk control detection rule set corresponding to the platform service identifier according to the platform behavior information, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain corresponding multiple first risk handling measures. If so, obtain corresponding multiple first risk handling measures;

[0037] A second risk control detection module, configured to obtain a second risk control detection rule set corresponding to the platform service identifier according to each of the first risk handling measures and the platform behavior information, and execute multiple second risk control detection rules in the second risk control detection rule set in series to obtain one or more second risk handling measures;

[0038] A disposal means execution module, configured to perform a risk disposal service for the platform operation request on the client according to each of the second risk disposal means.

[0039] In a further embodiment, the operation request response module includes:

[0040] An operation request response sub-module, configured to receive a platform operation request pushed by the client, parse the platform operation request, and obtain the user feature identifier and the platform service identifier included in the platform operation request;

[0041] A behavior information acquisition sub-module, configured to query the platform behavior information corresponding to the user feature identifier from the user historical behavior library and obtain the platform behavior information.

[0042] In a further embodiment, the first risk control detection module includes:

[0043] A rule set query sub-module, configured to query a first risk control detection rule set corresponding to the platform service identifier from a first rule set pool;

[0044] A detection factor determination sub-module, configured to push the corresponding user behavior data in the platform behavior information to each of the first risk control detection rules according to the detection factors corresponding to the multiple first risk control detection rules included in the first risk control detection rule set;

[0045] A rule parallel execution sub-module, configured to perform risk control detection on each of the first risk control detection rules based on the obtained user behavior data in parallel, determine the first risk detection rule with a higher risk degree among the multiple first risk control detection rules whose risk control detection results indicate risks, and obtain the first risk disposal means corresponding to each of the first risk detection rules.

[0046] In a further embodiment, the second risk control detection module includes:

[0047] A rule set query sub-module, configured to query a second risk control detection rule set corresponding to the platform service identifier from a second rule set pool;

[0048] A rule series execution sub-module, configured to sequentially execute the multiple second risk control detection rules in series in the second risk control detection rule set, and perform risk re-detection on the current to-be-executed second risk control detection rule according to the detection factor or the target disposal means corresponding to the current to-be-executed second risk control detection rule, using the corresponding user behavior data or the corresponding first disposal means in the platform behavior information;

[0049] A disposal method acquisition sub-module, configured to sequentially execute multiple second risk control detection rules connected in series in the second risk control detection rules, and acquire a second risk disposal method corresponding to the second risk control detection rule whose risk re-detection result is that the disposal method needs to be adjusted.

[0050] In a preferred embodiment, the second risk control detection module further includes:

[0051] A rule set query sub-module, configured to query a second risk control detection rule set corresponding to the platform service identifier from a second rule set pool;

[0052] A rule series execution sub-module, configured to sequentially execute multiple second risk control detection rules connected in series in the second risk control detection rule set, and use corresponding user behavior data or corresponding first disposal methods in the platform behavior information according to detection factors or target disposal methods corresponding to the currently to-be-executed second risk control detection rule, and execute the currently to-be-executed second risk control detection rule for risk re-detection;

[0053] A disposal method acquisition sub-module, configured to, when the risk re-detection result of the currently executed second risk control detection rule is that the disposal method does not need to be adjusted, determine the previous second risk control detection rule of the currently executed second risk control detection rule, and acquire a second risk disposal method corresponding to the previous second risk control detection rule.

[0054] In a preferred embodiment, the second risk control detection module further includes:

[0055] A target method detection sub-module, configured to, when the target disposal method corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, detect whether there is a first risk disposal method that prohibits access to the live broadcast room among the currently acquired first risk disposal methods;

[0056] A behavior data acquisition sub-module, configured to, when there is a first risk disposal method that prohibits access to the live broadcast room, acquire user behavior data including the number of live broadcast room accesses in the platform behavior information;

[0057] A disposal method adjustment sub-module, configured to determine whether the number of live broadcast room accesses exceeds a preset restricted access number, and if not, output a risk re-detection result indicating that there is a risk, and the second risk disposal method corresponding to the second risk control detection rule is to question the current live broadcast room access type.

[0058] In a further embodiment, the disposal method execution module includes:

[0059] A live broadcast room type acquisition sub-module, which is used to obtain the target live broadcast room type corresponding to the target live broadcast room currently accessed by the user terminal and other live broadcast room types when the second risk handling measure is to query the current accessed live broadcast room type;

[0060] A live broadcast room type push sub-module, which is used to push the target live broadcast room type and other live broadcast room types to the user terminal, and drive the user terminal to output the target live broadcast room type and other live broadcast room types to be displayed in the live broadcast room type selection window;

[0061] An access permission detection sub-module, which is used to respond to the live broadcast room type selection instruction pushed by the user terminal, and determine whether the live broadcast room type corresponding to the live broadcast room type selection instruction is the target live broadcast room type. If not, the live broadcast room access permission of the target live broadcast room will be stopped from being opened to the user terminal.

[0062] To solve the above technical problems, an embodiment of the present application further provides a computer device, including a memory and a processor. Computer-readable instructions are stored in the memory. When the computer-readable instructions are executed by the processor, the processor is caused to execute the steps of the above-mentioned risk handling measure adjustment method.

[0063] To solve the above technical problems, an embodiment of the present application further provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, one or more processors are caused to execute the steps of the above-mentioned risk handling measure adjustment method.

[0064] To solve the above technical problems, an embodiment of the present application further provides a computer program product, including a computer program and computer instructions. When the computer program and computer instructions are executed by a processor, the processor is caused to execute the steps of the above-mentioned risk handling measure adjustment method.

[0065] Compared with the prior art, the advantages of the present application are as follows:

[0066] This application adjusts risk disposal measures through two-stage risk control detection. By invoking the risk control detection rules in the second stage, it adjusts the risk disposal measures determined by the risk control detection in the first stage to enhance the flexibility of the platform's risk control service. Compared with the existing first-stage risk control detection method, performing two-stage risk control detection on the platform can more flexibly adjust the disposal measures for users. For platform users who are not malicious, the severe risk disposal measures are adjusted to lighter ones to ensure the user retention rate of the platform. For malicious platform users, more severe risk disposal measures can be given to protect the platform's risk resistance ability. For example, for an online live streaming platform, the access restriction of the live streaming room can be adjusted. For platform users who access the live streaming room in large numbers, the measure of prohibiting access to the live streaming room is given to ensure the stability of the live streaming service of the online live streaming platform. For platform users who access the live streaming room excessively, the measure of prohibiting access to the live streaming room can be adjusted to conventional verification measures such as live streaming room type verification for detection, preventing excessive restriction of the access right of viewer users to the live streaming room of the online live streaming platform to ensure the number of viewers of the online live streaming platform.

[0067] Secondly, this application ensures the rapid determination of disposal measures by executing the risk control detection rules in the first stage in parallel, and ensures the rationality of the adjusted disposal measures by executing the risk control detection rules in the second stage regarding the adjustment of disposal measures in series, so as to ensure the user retention rate of the platform while performing risk control detection on the platform. Brief Description of the Drawings

[0068] The above and / or additional aspects and advantages of this application will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:

[0069] Figure 1 A schematic diagram of a typical network deployment architecture related to implementing the technical solution of this application;

[0070] Figure 2 A schematic flowchart of a typical embodiment of the risk disposal measure adjustment method of this application;

[0071] Figure 3 A schematic diagram of a graphical user interface of a live streaming room interface showing a live streaming room type selection window in this application;

[0072] Figure 4 A schematic diagram of a graphical user interface of a live streaming room interface showing a notice window for prohibiting access to the live streaming room in this application;

[0073] Figure 5 A schematic flowchart formed by the specific implementation manner of obtaining the user behavior information of the user terminal in this application;

[0074] Figure 6It is a flowchart formed by the specific implementation manner of parallelly executing multiple first risk control detection rules in the first risk control detection rule set in this application;

[0075] Figure 7 It is a flowchart formed by the specific implementation manner of serially executing multiple second risk control detection rules in the second risk control detection rule set in this application;

[0076] Figure 8 It is a flowchart formed by the specific implementation manner of another embodiment of serially executing multiple second risk control detection rules in the second risk control detection rule set in this application;

[0077] Figure 9 It is a flowchart formed by the specific implementation manner of adjusting the first risk disposal means by executing the second risk control detection rule in this application;

[0078] Figure 10 It is a flowchart formed by the specific implementation manner of executing the second risk disposal means in this application;

[0079] Figure 11 It is a principle block diagram of a typical embodiment of the risk disposal means adjustment device of this application;

[0080] Figure 12 It is a basic structure block diagram of a computer device according to an embodiment of this application. Specific Embodiment

[0081] The embodiments of the present application will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described by referring to the drawings below are exemplary and are only used to explain the present application and cannot be construed as a limitation to the present application.

[0082] Those skilled in the art of this technology can understand that unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "including" used in the specification of the present application means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein includes all or any unit and all combinations of one or more related listed items.

[0083] Those skilled in the art can understand that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which this application belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the context of the prior art, and will not be interpreted in an idealized or overly formal sense unless specifically defined as here.

[0084] Those skilled in the art can understand that the "client", "terminal", and "terminal device" used herein include both devices with a wireless signal receiver that only has the ability to receive and no ability to transmit, and devices with receiving and transmitting hardware that can perform two-way communication on a two-way communication link. Such devices can include: cellular or other communication devices such as personal computers, tablets, etc., which have a single-line display or a multi-line display or a cellular or other communication device without a multi-line display; PCS (Personal Communications Service), which can combine voice, data processing, fax, and / or data communication capabilities; PDA (Personal Digital Assistant), which can include a radio frequency receiver, pager, Internet / intranet access, web browser, notepad, calendar, and / or GPS (Global Positioning System) receiver; traditional laptop and / or palm computers or other devices, which are traditional laptop and / or palm computers or other devices with and / or including a radio frequency receiver. The "client", "terminal", and "terminal device" used herein can be portable, transportable, installed in a vehicle (air, sea, and / or land), or suitable for and / or configured to run locally, and / or run in a distributed manner at any other location on the earth and / or in space. The "client", "terminal", and "terminal device" used herein can also be a communication terminal, an Internet access terminal, a music / video playback terminal, such as a PDA, MID (Mobile Internet Device), and / or a mobile phone with music / video playback functions, or can also be devices such as a smart TV, a set-top box, etc.

[0085] The hardware referred to by names such as "server", "client", and "worker node" in this application is essentially an electronic device with the equivalent capabilities of a personal computer. It is a hardware device with the necessary components as revealed by the von Neumann principle, including a central processing unit (including an arithmetic unit and a controller), a memory, an input device, and an output device. The computer program is stored in its memory, and the central processing unit loads the program stored in the external memory into the internal memory for execution, executes the instructions in the program, and interacts with the input / output devices to complete specific functions.

[0086] It should be noted that the concept of "server" in this application can similarly be extended to apply to the case of a server cluster. According to the network deployment principles understood by those skilled in the art, the various servers should be logically divided. Physically, these servers can either be independent of each other but can be invoked through interfaces, or integrated into a single physical computer or a set of computer clusters. Those skilled in the art should understand this flexibility and should not be restricted by it in the implementation of the network deployment method of this application.

[0087] Please refer to Figure 1 , the hardware foundation required for the implementation of the relevant technical solutions of this application can be deployed according to the architecture shown in the figure. The server 80 referred to in this application is deployed in the cloud. As an online server, it can be responsible for further connecting relevant data servers and other servers providing relevant support, etc., to form a logically related service cluster to provide services for relevant terminal devices such as the smartphone 81 and personal computer 82 shown in the figure or a third-party server (not shown). The smartphone and the personal computer can both access the Internet through well-known network access methods and establish a data communication link with the server 80 in the cloud to run the terminal application programs related to the services provided by the server.

[0088] For the server, the application program is usually built as a service process and opens corresponding program interfaces for remote invocation by the application programs running on various terminal devices. The relevant technical solutions suitable for running on the server in this application can be implemented in the server in this way.

[0089] The application program mentioned above refers to the application program running on the server or terminal device. This application program implements the relevant technical solutions of this application in a programming manner. Its program code can be saved in a non-volatile storage medium recognizable by the computer in the form of computer-executable instructions and be loaded into the internal memory by the central processing unit for execution. The relevant device of this application is constructed through the operation of this application program on the computer.

[0090] For a server, the application mentioned above is usually built as a service process, and corresponding program interfaces are opened for remote calls by applications running on various terminal devices. The relevant technical solutions suitable for running on the server in this application can be implemented in the server in this way.

[0091] Those skilled in the art should be aware that: Although various methods of this application are described based on the same concept and thus show commonality with each other, unless otherwise specified, these methods can be executed independently. Similarly, for each embodiment disclosed in this application, they are all proposed based on the same inventive concept. Therefore, concepts with the same expression, as well as concepts that are only appropriately transformed for convenience although the expression is different, should be equivalently understood.

[0092] Please refer to Figure 2 , in a typical embodiment of a method for adjusting a risk disposal means of this application, it includes the following steps:

[0093] Step S11, in response to a platform operation request pushed by the user terminal, obtain the platform behavior information and platform service identifier corresponding to the platform operation request:

[0094] The platform operation request refers to a request generated by the user terminal when using the corresponding platform service in the platform. For example, a live room access instruction triggered when the user terminal uses the live service to access a live room in a network live platform, or a user login instruction triggered when the user terminal uses the user login service to log in to an account. These instructions are all related to platform risk control of the platform. For example, the live room access operation corresponding to the live room service instruction, a large number of live room access operations for a certain live room may cause the collapse of the live service of the network live platform, and the account login operation corresponding to the user login instruction involves the security of the user account of the platform. Therefore, by responding to the platform operation request pushed by the user terminal, the platform operation request is subjected to risk control detection to prevent platform risk problems from occurring on the platform.

[0095] The platform behavior information refers to the user behavior data generated by the user terminal when using the platform service of the platform. For example, the user login times data corresponding to the user terminal using the user login service, the live room access times corresponding to the user terminal using the live service, the gift giving times data corresponding to the user terminal using the virtual gift service, etc. These data are the user behavior data included in the platform behavior information.

[0096] The platform service identifier corresponds to the platform service pointed to by the platform operation request. For example, when the client accesses a live broadcast room by using the live broadcast service in the network live broadcast platform, the platform service identifier included in the generated platform operation request represents the live broadcast service. When the client logs in to an account by using the user login service in the platform, the platform service identifier included in the generated platform operation request represents the user account service.

[0097] Step S12: According to the platform behavior information, obtain the first risk control detection rule set corresponding to the platform service identifier, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain the corresponding multiple first risk handling measures. If so, obtain the corresponding multiple first risk handling measures:

[0098] After obtaining the platform service identifier, according to the platform service identifier, query the first risk control detection rule set corresponding to the platform service identifier from the first rule set pool. The first rule set pool stores multiple first risk control detection rule sets developed by the platform for each platform service. Each first risk control detection rule set is stored corresponding to the platform service identifier of its corresponding platform service, so as to query the first risk control detection rule set corresponding to the platform service identifier from the first rule set pool according to the platform service identifier included in the currently responded platform operation request.

[0099] The first risk control detection rule set stores multiple first risk control detection rules. Each first risk control detection rule has its corresponding detection factor and first risk handling measure. Each first risk control detection rule will obtain the user behavior data corresponding to the detection factor from the platform behavior information as a detection parameter for risk control detection according to the detection factor it has.

[0100] When the server performs risk control detection using multiple first risk control detection rules stored in the first risk control detection rule set, it will execute each of the first risk control detection rules in parallel. According to the detection factors corresponding to each of the first risk control detection rules, it will obtain the corresponding user behavior data in the platform behavior information to execute each of the first risk control detection rules, so as to obtain the risk control detection results output by each of the first risk control detection rules. Furthermore, it will determine the first risk control detection rules characterized as having risks in the output risk control detection results, so as to obtain the first risk handling means corresponding to these first risk control detection rules. It can be seen that by executing each of the first risk control detection rules in parallel, the execution efficiency of all the first risk control detection rules in the first risk control detection rule set is improved, and it is quickly determined whether the platform operation request is a risk operation request, and the corresponding first risk handling means is obtained.

[0101] When the detection factor of the first risk control detection rule is the number of live room visits, it will execute the first risk control detection rule according to the user behavior data containing the number of live room visits in the user behavior data. The first risk control detection rule will judge whether the number of visits exceeds the preset restricted number of visits according to the number of visits characterized by the user behavior data. If it exceeds, it will output a risk control detection result characterized as having risks. If it does not exceed, it will output a risk control detection result characterized as not having risks. The risk handling means corresponding to the first risk control detection rule is generally to prohibit the user from accessing the live room.

[0102] In one embodiment, the first risk handling means has a corresponding risk level. After the server obtains the first risk handling means corresponding to each of the first risk control detection rules with the output risk control detection results being risky, it will reverse-order sort these first risk handling means according to the risk levels corresponding to these first risk handling means, and use multiple risk handling means within the preset sorting range in the sorting of these first risk handling means as the finally determined first risk handling means. The preset sorting range is generally set within the sorting range of 2 to 5.

[0103] Step S13, according to each of the first risk handling means and the platform behavior information, obtain a second risk control detection rule set corresponding to the platform service identifier, and serially execute multiple second risk control detection rules in the second risk control detection rule set to obtain one or more second risk handling means:

[0104] After obtaining the corresponding first risk handling measures by executing each of the first risk control detection rules in the first risk control detection rule set in parallel, the second risk control detection rule set corresponding to the platform service identifier will be queried from the second rule set pool. Multiple second risk control detection rule sets developed by the platform for each platform service are stored in the second rule set pool, and each second risk control detection rule set is stored corresponding to the platform service identifier of the platform service it corresponds to, so as to query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool according to the platform service identifier included in the current responded platform operation request.

[0105] A plurality of the second risk control detection rules are stored in sequence in the second risk control detection rule set, so that the server can execute these second risk control detection rules in series according to the storage order of each second risk control detection rule.

[0106] Execute the plurality of second risk control detection rules in series in the second risk control detection rule set. According to the detection factor or target handling measure corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first handling measure in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection.

[0107] Specifically, taking the currently executed second risk control detection rule as an example, when the target handling measure corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, it will be detected whether there is a first risk handling measure for prohibiting access to the live broadcast room among the currently obtained first risk handling measures. When there is a first risk handling measure for prohibiting access to the live broadcast room, obtain the user behavior data including the number of times of accessing the live broadcast room in the platform behavior information, and judge whether the number of times of accessing the live broadcast room exceeds the preset restricted access times. If it does not exceed, output a risk re-detection result indicating the existence of a risk. The second risk handling measure corresponding to the second risk control detection rule is to question the type of the currently accessed live broadcast room; it can be understood that the obtained second risk handling measure is not necessarily the same as the first handling measure. Through the second risk control detection rule corresponding to the first risk handling measure, the first risk handling measure is adjusted to the corresponding second risk handling measure.

[0108] After sequentially and serially executing each of the second risk control detection rules in the second risk control detection rule set, the second risk handling means corresponding to the second risk control detection rule whose risk re-detection result is that the handling means needs to be adjusted will be obtained; it can be seen that by serially executing all the second risk control detection rules in the second risk control detection rule set, and through each of the second risk control detection rules executed in series layer by layer, each of the first risk handling means is screened to adjust and obtain each of the first risk handling means obtained previously.

[0109] In one embodiment, when the risk re-detection result of the currently executed second risk control detection rule is that the handling means does not need to be adjusted, determine the previous second risk control detection rule of the currently executed second risk control detection rule, and obtain the second risk handling means corresponding to the previous second risk control detection rule; it can be seen that through this serial execution method, based on the previously obtained first risk handling means, the finally output second risk handling means can be determined, so as to perform risk handling on the user terminal according to the finally output second risk handling means.

[0110] Step S14, according to each of the second risk handling means, perform a risk handling service on the user terminal for the platform operation request:

[0111] After obtaining each of the second risk handling means, a risk handling service for the platform operation request will be performed on the user terminal according to each of the second risk handling means.

[0112] The risk handling service corresponds to the second risk control handling means. For example, when the second risk control handling means is SMS verification, the corresponding risk handling service will be an SMS verification service, and a verification text will be pushed to the mobile phone number pre-registered by the user terminal in the platform, so that the user terminal can input the verification text on the page corresponding to the SMS verification service to complete the verification. If the input verification text is not the verification text pushed to it, the user terminal will not be able to pass the SMS verification service.

[0113] Please refer to Figure 3 and Figure 4 , when the second risk handling means is to ask about the current accessed live broadcast room type, obtain the target live broadcast room type corresponding to the target live broadcast room currently accessed by the user terminal and other live broadcast room types,

[0114] and push the target live broadcast room type and other live broadcast room types to the user terminal, driving the user terminal to output the target live broadcast room type and other live broadcast room types to be displayed in the live broadcast room type selection window, such as Figure 3The live room type selection window 301 shown responds to the live room type selection instruction pushed by the client, and determines whether the live room type corresponding to the live room type selection instruction is the target live room type. If not, the live room access permission of the target live room is stopped from being opened to the client. At this time, the live room interface of the client is as Figure 4 shown, and a prohibited access live room notification window 401 will be displayed in the shown live room interface.

[0115] It can be seen from the typical implementation manners of this method that this method adjusts the risk disposal means through two-stage risk control detection, and adjusts the risk disposal means determined by the first-stage risk control detection by invoking the risk control detection rules of the second stage, so as to improve the flexibility of the platform risk control service. Compared with the existing first risk control detection method, performing two-stage risk control detection on the platform can more flexibly adjust the disposal means for users. For platform users who are not malicious, adjust the severe risk disposal means to milder risk disposal means to ensure the user retention rate of the platform. For malicious platform users, more severe risk disposal means can be given to protect the risk resistance ability of the platform. For example, for an online live broadcast platform, the access restriction of the live room can be adjusted. For platform users who access the live room in large quantities, a disposal means of prohibiting access to the live room is given to ensure the stability of the live broadcast service of the online live broadcast platform. For platform users who access the live room excessively, the disposal means of prohibiting access to the live room can be adjusted to conventional verification means such as live room type verification for detection, so as to prevent excessive restriction of the live room access rights of viewer users to the online live broadcast platform and ensure the number of viewers of the online live broadcast platform.

[0116] Secondly, this method executes the risk control detection rules of the first stage in parallel to ensure the rapid determination of the disposal means, and executes the risk control detection rules of the second stage regarding the adjustment of the disposal means in series to ensure the rationality of the adjusted disposal means, so as to ensure the user retention rate of the platform while performing risk control detection on the platform.

[0117] The above typical embodiments and their variant embodiments fully disclose the implementation solutions of the risk disposal means adjustment method of this application. However, various variant embodiments of this method can still be deduced by transforming and expanding some technical means. The following briefly describes other embodiments:

[0118] In one embodiment, please refer to Figure 5 , in the step of obtaining the platform behavior information corresponding to the platform operation request and the live broadcast platform service in response to the platform operation request pushed by the client, the following steps are included:

[0119] Step S111: Receive the platform operation request pushed by the client, parse the platform operation request, and obtain the user feature identifier and platform service identifier included in the platform operation request:

[0120] The user feature identifier refers to the user ID or device feature code of the client in the platform. When the client is a logged-in client on the platform, the user feature identifier will be the user ID. When the client is a non-logged-in client on the platform, the user feature identifier will be the device feature code.

[0121] Step S112: Query the platform behavior information corresponding to the user feature identifier from the user historical behavior library, and obtain the platform behavior information:

[0122] The user historical behavior library stores the platform behavior information generated by each client using the platform services of the platform, and each platform behavior information and the user feature identifier form mapping relationship data and are stored in the user historical behavior library.

[0123] In this embodiment, the platform behavior information of the client is queried from the platform through the user feature identifier of the client that pushes the platform operation request, so as to perform risk control detection on the client according to the platform behavior information and maintain the platform rules of the platform.

[0124] In one embodiment, please refer to Figure 6 , in the step of obtaining the first risk control detection rule set corresponding to the platform service identifier according to the platform behavior information, and concurrently executing multiple first risk control detection rules in the first risk control detection rule set to detect whether the platform operation request is a risk operation request. If so, in the step of obtaining the corresponding multiple first risk disposal means, the following steps are included:

[0125] Step S121: Query the first risk control detection rule set corresponding to the platform service identifier from the first rule set pool:

[0126] The first rule set pool stores multiple first risk control detection rule sets developed by the platform for each platform service. Each first risk control detection rule set is stored corresponding to the platform service identifier of the platform service it corresponds to, so as to query the first risk control detection rule set corresponding to the platform service identifier from the first rule set pool according to the platform service identifier included in the currently responded platform operation request.

[0127] Step S122: Push the corresponding user behavior data in the platform behavior information to each first risk control detection rule according to the detection factors corresponding to the multiple first risk control detection rules included in the first risk control detection rule set:

[0128] When the server performs risk control detection using multiple first risk control detection rules stored in the first risk control detection rule set, it will execute each of the first risk control detection rules in parallel. According to the detection factors corresponding to each of the first risk control detection rules, it will obtain the corresponding user behavior data in the platform behavior information and execute each of the first risk control detection rules to obtain the risk control detection results output by each of the first risk control detection rules. Furthermore, it will determine the first risk control detection rules characterized as having risks in the output risk control detection results to obtain the first risk handling means corresponding to these first risk control detection rules.

[0129] Step S123: Execute each of the first risk control detection rules in parallel to perform risk control detection based on the user behavior data obtained thereby, determine the first risk detection rules with higher risk degrees among the multiple first risk control detection rules whose risk control detection results are characterized as having risks, and obtain the first risk handling means corresponding to each of the first risk detection rules:

[0130] The first risk handling means has a corresponding risk degree. When the server obtains the first risk handling means corresponding to each of the first risk control detection rules whose output risk control detection results are characterized as having risks, it will reverse-order these first risk handling means according to the risk degrees corresponding to these first risk handling means, and use multiple risk handling means within a preset sorting range among these first risk handling means as the finally determined first risk handling means. The preset sorting range is generally set within the sorting range of 2 to 5.

[0131] In this embodiment, by executing multiple first risk control detection rules in parallel, the execution efficiency of all the first risk control detection rules in the first risk control detection rule set is improved, and it is quickly determined whether the platform operation request is a risk operation request, and the corresponding first risk handling means is obtained.

[0132] In one embodiment, please refer to Figure 7 In the step of obtaining the second risk control detection rule set corresponding to the platform service identifier according to each of the first risk handling means and the platform behavior information, and serially executing multiple second risk control detection rules in the second risk control detection rule set to obtain one or more second risk handling means, the following steps are included:

[0133] Step S131: Query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool:

[0134] After obtaining the corresponding first risk handling measures by executing each of the first risk control detection rules in the first risk control detection rule set in parallel, the second risk control detection rule set corresponding to the platform service identifier will be queried from the second rule set pool. Multiple second risk control detection rule sets developed by the platform for each platform service are stored in the second rule set pool, and each second risk control detection rule set is stored corresponding to the platform service identifier of its corresponding platform service, so as to query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool according to the platform service identifier included in the current responded platform operation request.

[0135] Step S132, sequentially execute multiple second risk control detection rules connected in series in the second risk control detection rule set. According to the detection factor or target handling measure corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first handling measure in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection:

[0136] When the server performs risk re-detection using multiple second risk control detection rules stored in the second risk control detection rule set, it will sequentially execute these second risk control detection rules in series according to the storage order of each second risk control detection rule in each second risk control detection rule set, and according to the detection factor or target handling measure corresponding to each currently executed second risk control detection rule, obtain the corresponding user behavior data or the corresponding first risk handling measure in the platform behavior information to execute each second risk control detection rule, so as to obtain the risk re-detection results output by each second risk control detection rule.

[0137] Step S133, after sequentially executing multiple second risk control detection rules connected in series in the second risk control detection rule, obtain the second risk handling measure corresponding to the second risk control detection rule whose risk re-detection result is that the handling measure needs to be adjusted:

[0138] When the server executes each of the second risk control detection rules in series in the second risk control detection rule set, it will continuously obtain the risk re-detection results output by the already executed second risk control detection rules, and obtain the second risk handling measure corresponding to the second risk control detection rule whose risk re-detection result indicates that the handling measure needs to be adjusted.

[0139] In this embodiment, by sequentially executing all the second risk control detection rules in the second risk control detection rule set, and through each second risk control detection rule connected in series executed layer by layer, the previously obtained first risk handling measures are screened to obtain the second risk detection means to adjust the previously obtained first risk handling measures.

[0140] In one embodiment, please refer toFigure 8 In the step of obtaining a second risk control detection rule set corresponding to the platform service identifier according to each of the first risk handling means and the platform behavior information, and serially executing a plurality of second risk control detection rules in the second risk control detection rule set to obtain one or more second risk handling means, the following steps are included:

[0141] Step S131’, query from the second rule set pool a second risk control detection rule set corresponding to the platform service identifier:

[0142] Please refer to the relevant implementation manners in step S131, and this step will not be elaborated here.

[0143] Step S132’, sequentially execute a plurality of second risk control detection rules connected in series in the second risk control detection rule set. According to the detection factor or target handling means corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first handling means in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection:

[0144] Please refer to the relevant implementation manners in step S132, and this step will not be elaborated here.

[0145] Step S133’, when the risk re-detection result of the currently executed second risk control detection rule is that there is no need to adjust the handling means, determine the previous second risk control detection rule of the currently executed second risk control detection rule, and obtain the second risk handling means corresponding to the previous second risk control detection rule:

[0146] When serially executing each of the second risk control detection rules, when the risk re-detection result of the currently executed second risk control detection rule is that there is no need to adjust the handling means, stop executing other unexecuted second risk control detection rules, and determine the previous second risk control detection rule of the currently executed second risk control detection rule, and obtain the second risk handling means corresponding to the previous second risk control detection rule; generally, the second risk handling means corresponding to a relatively earlier executed second risk control detection rule is more severe than the second risk handling means corresponding to a relatively later executed second risk control detection rule. For example, a second risk control detection rule with a second risk handling means of picture verification is generally executed earlier than a second risk control detection rule with a second risk handling means of SMS verification.

[0147] In this embodiment, based on the previously obtained first risk handling means, determine the finally output second risk handling means, so as to perform risk handling on the user side according to the finally output second risk handling means.

[0148] In one embodiment, please refer to Figure 9, in the step of obtaining a second risk control detection rule set corresponding to the platform service identifier according to each of the first risk disposal means and the platform behavior information, and sequentially executing a plurality of second risk control detection rules in the second risk control detection rule set to obtain one or more second risk disposal means, the following steps are included:

[0149] Step S131”, when the target disposal means corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, it is detected whether there is a first risk disposal means for prohibiting access to the live broadcast room among the first risk disposal means obtained currently:

[0150] The risk disposal means of prohibiting access to the live broadcast room refers to the disposal means of prohibiting the user terminal from accessing the live broadcast room it is currently accessing, or prohibiting the user terminal from accessing all live broadcast rooms in the network live broadcast platform. When the target disposal means corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, it is detected whether there is a first risk disposal means for prohibiting access to the live broadcast room among the first risk disposal means obtained through the first risk control detection rule set.

[0151] Step S132”, when there is a first risk disposal means for prohibiting access to the live broadcast room, user behavior data including the number of live broadcast room accesses in the platform behavior information is obtained:

[0152] If there is a first risk disposal means for prohibiting access to the live broadcast room among the first risk disposal means obtained through the first risk control detection rule set, then user behavior data including the number of live broadcast room accesses in the platform behavior information is obtained. The number of live broadcast room accesses generally refers to the number of times the user terminal accesses each live broadcast room available on the network live broadcast platform, or the number of times the user terminal accesses the currently accessed live broadcast room.

[0153] Step S133”, it is judged whether the number of live broadcast room accesses exceeds a preset restricted access number. If it does not exceed, a risk re-detection result indicating the existence of a risk is output, and the second risk disposal means corresponding to the second risk control detection rule is to question the type of the currently accessed live broadcast room:

[0154] The restricted access number is generally set in the range of 50 to 100 when accessing each live broadcast room in the live broadcast room, and generally set in the range of 20 to 50 when accessing a single live broadcast room.

[0155] The second risk disposal means of questioning the type of the currently accessed live broadcast room will ask the user terminal about the type of the live broadcast room it is currently accessing.

[0156] If the number of visits to the live broadcast room exceeds the preset limit of the number of visits, the first risk disposal means of prohibiting access to the live broadcast room will be used as the final risk disposal means to conduct risk disposal on the user terminal according to this final risk disposal means, and prohibit the user terminal from accessing each live broadcast room in the network live broadcast room or the currently accessed live broadcast room.

[0157] In this embodiment, by using the second risk disposal means to change the type of asking about the currently accessed live broadcast room to the first risk disposal means of prohibiting access to the live broadcast room, the risk disposal means for the user terminal with excessive access times to the live broadcast room is adjusted, preventing excessive restriction of the user's right to use the platform services of the network live broadcast platform, and by adjusting the second risk control detection rule to adjust the disposal means, preventing overly strict risk disposal means from affecting the user retention of the platform.

[0158] In one embodiment, please refer to Figure 3 、 Figure 4 and 10 , in the step of performing risk disposal services on the platform operation request for the user terminal according to each of the second risk disposal means, the following steps are included:

[0159] Step S141, when the second risk disposal means is to ask about the currently accessed live broadcast room type, obtain the target live broadcast room type corresponding to the target live broadcast room currently accessed by the user terminal and other live broadcast room types:

[0160] The second risk disposal means of asking about the currently accessed live broadcast room type will ask about the live broadcast room type of the live broadcast room currently accessed by the user terminal. When the second risk disposal means is to ask about the currently accessed live broadcast room type, the live broadcast room type of the live broadcast room currently accessed by the user terminal will be obtained as the target live broadcast room type, and other live broadcast room types that do not correspond to the live broadcast room will be obtained as other live broadcast room types.

[0161] Step S142, push the target live broadcast room type and other live broadcast room types to the user terminal, and drive the user terminal to output the target live broadcast room type and other live broadcast room types to be displayed in the live broadcast room type selection window:

[0162] Please refer to Figure 3 , Figure 3 , the live broadcast room type selection window 301 shown in the live broadcast room interface shown is the live broadcast room type selection window, Figure 3 The live broadcast room type of the live broadcast room corresponding to the live broadcast room interface is the chat area live broadcast room type. As shown in the live broadcast room type selection window 301, the target live broadcast room type shown as "chat area" and other live broadcast room types such as "food area" and "game area" are displayed in the live broadcast room type selection window 301.

[0163] Step S143, in response to the live broadcast room type selection instruction pushed by the client, determine whether the live broadcast room type corresponding to the live broadcast room type selection instruction is the target live broadcast room type. If not, stop opening the live broadcast room access permission of the target live broadcast room to the client:

[0164] Please refer to Figure 3 and Figure 4 , when the client selects the corresponding live broadcast room type through Figure 3 the live broadcast room type selection window 301 as shown, it will push to the server the live broadcast room type selected in the live broadcast room type selection window shown, such as Figure 3 if the selected live broadcast room type is "Food Area", Figure 3 and the target live broadcast room type of the live broadcast room corresponding to the live broadcast room interface shown is "Chat Area", then, since the live broadcast room type corresponding to the live broadcast room type selection instruction is not the target live broadcast room type, a live broadcast room access prohibited notice will be pushed to the client, as Figure 4 shown, Figure 4 and the live broadcast room access prohibited notice window 401 shown is the visual style of the live broadcast room access prohibited notice, and stop opening the live broadcast room access permission of the target live broadcast room to the client to prohibit the client from accessing Figure 4 the live broadcast room of the live broadcast room interface shown.

[0165] In this embodiment, by asking about the risk disposal means for the currently accessed live broadcast room type, the client with excessive access times to the live broadcast room is asked about the live broadcast room type, so as to control the access times of the client to the live broadcast rooms in the network live broadcast platform, prevent malicious clients from accessing the live broadcast rooms excessively, and cause the live broadcast room service of the network live broadcast platform to crash due to high-concurrency requests, affecting the live broadcast viewing experience of other users on the platform.

[0166] Furthermore, a risk disposal means adjustment device of the present application can be constructed by functionalizing each step in the methods disclosed in the above embodiments. In accordance with this idea, please refer to Figure 11, in a typical embodiment thereof, the device includes: an operation request response module 11, configured to respond to a platform operation request pushed by a user terminal, and obtain platform behavior information and a platform service identifier corresponding to the platform operation request; a first risk control detection module 12, configured to obtain a first risk control detection rule set corresponding to the platform service identifier according to the platform behavior information, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain corresponding multiple first risk handling means; a second risk control detection module 13, configured to obtain a second risk control detection rule set corresponding to the platform service identifier according to each of the first risk handling means and the platform behavior information, and execute multiple second risk control detection rules in the second risk control detection rule set in series to obtain one or more second risk handling means; a handling means execution module 14, configured to execute a risk handling service acting on the platform operation request on the user terminal according to each of the second risk handling means.

[0167] In one embodiment, the operation request response module 11 includes: an operation request response sub-module, configured to receive a platform operation request pushed by a user terminal, parse the platform operation request, and obtain a user feature identifier and a platform service identifier included in the platform operation request; a behavior information acquisition sub-module, configured to query platform behavior information corresponding to the user feature identifier from a user historical behavior library, and obtain the platform behavior information.

[0168] In one embodiment, the first risk control detection module 12 includes: a rule set query sub-module, configured to query a first risk control detection rule set corresponding to the platform service identifier from a first rule set pool; a detection factor determination sub-module, configured to push corresponding user behavior data in the platform behavior information to each of the first risk control detection rules according to detection factors corresponding to multiple first risk control detection rules included in the first risk control detection rule set; a rule parallel execution sub-module, configured to execute in parallel each of the first risk control detection rules to perform risk control detection based on the obtained user behavior data, determine a first risk detection rule with a relatively high risk degree among multiple first risk control detection rules whose risk control detection results indicate risks, and obtain first risk handling means corresponding to each of the first risk detection rules.

[0169] In one embodiment, the second risk control detection module 13 includes: a rule set query sub-module, configured to query a second risk control detection rule set corresponding to the platform service identifier from a second rule set pool; a rule serial execution sub-module, configured to sequentially execute a plurality of second risk control detection rules in series in the second risk control detection rule set, and use the corresponding user behavior data or the corresponding first disposal means in the platform behavior information according to the detection factor or the target disposal means corresponding to the currently to-be-executed second risk control detection rule to execute the currently to-be-executed second risk control detection rule for risk re-detection; a disposal means acquisition sub-module, configured to sequentially execute a plurality of second risk control detection rules in series in the second risk control detection rules, and acquire the second risk disposal means corresponding to the second risk control detection rule whose risk re-detection result is that the disposal means needs to be adjusted.

[0170] In another embodiment, the second risk control detection module 13 further includes: a rule set query sub-module, configured to query a second risk control detection rule set corresponding to the platform service identifier from a second rule set pool; a rule serial execution sub-module, configured to sequentially execute a plurality of second risk control detection rules in series in the second risk control detection rule set, and use the corresponding user behavior data or the corresponding first disposal means in the platform behavior information according to the detection factor or the target disposal means corresponding to the currently to-be-executed second risk control detection rule to execute the currently to-be-executed second risk control detection rule for risk re-detection; a disposal means acquisition sub-module, configured to determine the previous second risk control detection rule of the currently executed second risk control detection rule and acquire the second risk disposal means corresponding to the previous second risk control detection rule when the risk re-detection result of the currently executed second risk control detection rule is that the disposal means does not need to be adjusted.

[0171] In another embodiment, the second risk control detection module 13 further includes: a target means detection sub-module, configured to detect whether there is a first risk disposal means for prohibiting access to the live broadcast room when the target disposal means corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room; a behavior data acquisition sub-module, configured to acquire the user behavior data including the number of live broadcast room accesses in the platform behavior information when there is a first risk disposal means for prohibiting access to the live broadcast room; a disposal means adjustment sub-module, configured to determine whether the number of live broadcast room accesses exceeds a preset restricted access number, and if not, output a risk re-detection result indicating the existence of a risk, and the second risk disposal means corresponding to the second risk control detection rule is to question the current type of live broadcast room access.

[0172] In one embodiment, the disposal means execution module 14 includes: a live broadcast room type acquisition sub-module, configured to acquire the target live broadcast room type corresponding to the target live broadcast room currently accessed by the user terminal and other live broadcast room types when the second risk disposal means is to query the type of the currently accessed live broadcast room; a live broadcast room type push sub-module, configured to push the target live broadcast room type and other live broadcast room types to the user terminal, and drive the user terminal to output the target live broadcast room type and other live broadcast room types to be displayed in the live broadcast room type selection window; an access permission detection sub-module, configured to respond to the live broadcast room type selection instruction pushed by the user terminal, and determine whether the live broadcast room type corresponding to the live broadcast room type selection instruction is the target live broadcast room type, and if not, stop opening the live broadcast room access permission of the target live broadcast room to the user terminal.

[0173] To solve the above technical problems, an embodiment of the present application further provides a computer device for running a computer program implemented according to the risk disposal means adjustment method. For details, please refer to Figure 12 , Figure 12 which is the basic structural block diagram of the computer device in this embodiment.

[0174] As Figure 12 shown in the internal structure schematic diagram of the computer device. The computer device includes a processor, a non-volatile storage medium, a memory, and a network interface connected through a system bus. Among them, the non-volatile storage medium of the computer device stores an operating system, a database, and computer-readable instructions. The control information sequence can be stored in the database. When the computer-readable instructions are executed by the processor, the processor can implement a risk disposal means adjustment method. The processor of the computer device is used to provide computing and control capabilities to support the operation of the entire computer device. The memory of the computer device can store computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor can execute a risk disposal means adjustment method. The network interface of the computer device is used to connect and communicate with the terminal. Those skilled in the art can understand that Figure 12 the structure shown in

[0175] In this embodiment, the processor is used to execute the specific functions of each module / sub-module in the risk handling measure adjustment device of the present application. The memory stores the program codes and various types of data required to execute the above modules. The network interface is used for data transmission between the user terminal and the server. The memory in this embodiment stores the program codes and data required to execute all modules / sub-modules in the risk handling measure adjustment device. The server can call the program codes and data of the server to execute the functions of all sub-modules.

[0176] The present application also provides a non-volatile storage medium. The risk handling measure adjustment method is written as a computer program and stored in the storage medium in the form of computer-readable instructions. When the computer-readable instructions are executed by one or more processors, it means the program runs on the computer, thereby enabling one or more processors to execute the steps of the risk handling measure adjustment method in any of the above embodiments.

[0177] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disc, a read-only memory (ROM), etc., or a random access memory (RAM), etc.

[0178] In summary, the present application can dynamically adjust the risk handling measures in the platform and accurately strike various risk behaviors of platform users.

[0179] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limitation and can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. Their execution order does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0180] Those skilled in the art can understand that the various operations, methods, steps, measures, and solutions in the processes discussed in this application can be alternated, changed, combined, or deleted. Further, other steps, measures, and solutions in the various operations, methods, and processes discussed in this application can also be alternated, changed, rearranged, decomposed, combined, or deleted. Further, those in the prior art that have steps, measures, and solutions in the various operations, methods, and processes disclosed in this application can also be alternated, changed, rearranged, decomposed, combined, or deleted.

[0181] The above are only some embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A method for adjusting risk disposal means, characterized in that, It includes the following steps: In response to a platform operation request pushed by the client, obtain the platform behavior information and platform service identifier corresponding to the platform operation request, where the platform behavior information is user behavior data information generated by the client using platform services; According to the platform behavior information, obtain the first risk control detection rule set corresponding to the platform service identifier, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain the corresponding multiple first risk handling measures; Obtain the second risk control detection rule set corresponding to the platform service identifier, and according to each of the first risk handling measures and the platform behavior information, sequentially execute multiple second risk control detection rules in the second risk control detection rule set to obtain one or more second risk handling measures; According to each of the second risk handling measures, perform a risk handling service on the client for the platform operation request.

2. The method according to claim 1, wherein In the step of "In response to a platform operation request pushed by the client, obtain the platform behavior information and platform service identifier corresponding to the platform operation request", it includes the following steps: Receive a platform operation request pushed by the client, parse the platform operation request, and obtain the user feature identifier and platform service identifier included in the platform operation request; Query the platform behavior information corresponding to the user feature identifier from the user historical behavior library, and obtain the platform behavior information.

3. The method according to claim 1, wherein In the step of "According to the platform behavior information, obtain the first risk control detection rule set corresponding to the platform service identifier, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain the corresponding multiple first risk handling measures", it includes the following steps: Query the first risk control detection rule set corresponding to the platform service identifier from the first rule set pool; According to the detection factors corresponding to the multiple first risk control detection rules included in the first risk control detection rule set, push the corresponding user behavior data in the platform behavior information to each of the first risk control detection rules; Execute each of the first risk control detection rules in parallel for risk control detection based on the user behavior data obtained by it, determine the first risk detection rule with a higher risk degree among the multiple first risk control detection rules with a risk control detection result of risk, and obtain the first risk handling measures corresponding to each of the first risk detection rules.

4. The method according to claim 1, wherein In the step of "Obtain the second risk control detection rule set corresponding to the platform service identifier, and according to each of the first risk handling measures and the platform behavior information, sequentially execute multiple second risk control detection rules in the second risk control detection rule set to obtain one or more second risk handling measures", it includes the following steps: Query the second risk control detection rule set corresponding to the platform service identifier from the second rule set pool; Sequentially execute multiple second risk control detection rules connected in series in the second risk control detection rule set. According to the detection factor or target disposal measure corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first risk disposal measure in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection; After sequentially executing multiple second risk control detection rules connected in series in the second risk control detection rules, obtain the second risk disposal measure corresponding to the second risk control detection rule whose risk re-detection result is that the disposal measure needs to be adjusted.

5. The method according to claim 1, wherein In the step of obtaining the second risk control detection rule set corresponding to the platform service identifier, and sequentially executing multiple second risk control detection rules in the second risk control detection rule set according to each of the first risk disposal measures and the platform behavior information to obtain one or more second risk disposal measures, the following steps are included: Query from the second rule set pool the second risk control detection rule set corresponding to the platform service identifier; Sequentially execute multiple second risk control detection rules connected in series in the second risk control detection rule set. According to the detection factor or target disposal measure corresponding to the currently to-be-executed second risk control detection rule, use the corresponding user behavior data or the corresponding first risk disposal measure in the platform behavior information to execute the currently to-be-executed second risk control detection rule for risk re-detection; When the risk re-detection result of the currently executed second risk control detection rule is that the disposal measure does not need to be adjusted, determine the previous second risk control detection rule of the currently executed second risk control detection rule, and obtain the second risk disposal measure corresponding to the previous second risk control detection rule.

6. The method according to claim 1, characterized in that, In the step of obtaining the second risk control detection rule set corresponding to the platform service identifier, and sequentially executing multiple second risk control detection rules in the second risk control detection rule set according to each of the first risk disposal measures and the platform behavior information to obtain one or more second risk disposal measures, the following steps are included: When the target disposal measure corresponding to the currently executed second risk control detection rule is to prohibit access to the live broadcast room, detect whether there is a first risk disposal measure that prohibits access to the live broadcast room among the currently obtained first risk disposal measures; When there is a first risk disposal measure that prohibits access to the live broadcast room, obtain the user behavior data including the number of live broadcast room accesses in the platform behavior information; Judge whether the number of live broadcast room accesses exceeds the preset restricted access number. If it does not exceed, output a risk re-detection result indicating the existence of risk, and the second risk disposal measure corresponding to the second risk control detection rule is to ask about the current type of live broadcast room being accessed.

7. The method according to claim 1, wherein In the step of performing a risk disposal service on the user terminal for the platform operation request according to each of the second risk disposal measures, the following steps are included: When the second risk disposal measure is to ask about the current type of live broadcast room being accessed, obtain the target live broadcast room type and other live broadcast room types corresponding to the target live broadcast room currently accessed by the user terminal; Push the target live - broadcast room type and other live - broadcast room types to the user terminal, and drive the user terminal to output the target live - broadcast room type and other live - broadcast room types for display in the live - broadcast room type selection window; Respond to the live - broadcast room type selection instruction pushed by the user terminal, and determine whether the live - broadcast room type corresponding to the live - broadcast room type selection instruction is the target live - broadcast room type. If not, stop opening the live - broadcast room access permission of the target live - broadcast room to the user terminal.

8. A risk disposal means adjustment device, characterized in that, Include: An operation request response module, configured to respond to a platform operation request pushed by the user terminal, and obtain the platform behavior information and platform service identifier corresponding to the platform operation request, where the platform behavior information is the user behavior data information generated by the user terminal using the platform service; A first risk control detection module, configured to obtain a first risk control detection rule set corresponding to the platform service identifier according to the platform behavior information, and execute multiple first risk control detection rules in the first risk control detection rule set in parallel to detect whether the platform operation request is a risk operation request. If so, obtain corresponding multiple first risk disposal measures; A second risk control detection module, configured to obtain a second risk control detection rule set corresponding to the platform service identifier, and execute multiple second risk control detection rules in the second risk control detection rule set in series according to each of the first risk disposal measures and the platform behavior information to obtain one or more second risk disposal measures; A disposal measure execution module, configured to execute a risk disposal service acting on the platform operation request on the user terminal according to each of the second risk disposal measures.

9. An electronic device, comprising a central processing unit and a memory, characterized in that, The central processing unit is used to call and run the computer program stored in the memory to execute the steps of the method according to any one of claims 1 to 7.

10. A non-volatile storage medium, characterized in that, It stores in the form of computer - readable instructions a computer program implemented according to the method according to any one of claims 1 to 7. When the computer program is called and run by a computer, it executes the steps included in the method.

Citation Information

Patent Citations

  • Data processing method and device, computer equipment and computer readable storage medium

    CN112417441A

  • Service problem processing method and device, computer equipment and storage medium

    CN112434335A