Data processing method and device, electronic equipment, storage medium and program product

By constructing an object relationship graph and performing role diffusion and clustering, illegal business activities such as online gambling can be identified and processed, solving the problems of limited mining scope and poor identification effect in existing technologies, and achieving more efficient processing of illegal business activities.

CN115905367BActive Publication Date: 2026-05-19TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2022-12-21
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing technologies have limited scope and poor identification effectiveness in identifying and processing illegal business activities such as online gambling, making it difficult to effectively uncover and deal with illegal business groups.

Method used

By constructing an object relationship graph, seed objects are selected based on the target application and target link to propagate roles, resulting in multiple role sets. These sets are then clustered to identify illegal business groups, and different processing strategies are adopted to handle various business roles.

Benefits of technology

It improves the accuracy and scope of illegal business detection and processing, covering the entire business chain and enhancing the precision and effectiveness of processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115905367B_ABST
    Figure CN115905367B_ABST
Patent Text Reader

Abstract

The application provides a data processing method and device, electronic equipment, storage medium and program product, and relates to the technical fields of cloud technology, cloud storage, big data and the like. An object relationship graph is constructed by taking each object as a node and taking the association relationship data in the object data of each object as an edge, so as to obtain a full-amount relationship graph including multiple objects. At least one target link propagated by each target application is obtained by filtering the target application from multiple application programs. Seed objects are filtered from each object based on each target application and target link, and diffusion is performed from the seed objects as a starting point to obtain at least two role sets. Furthermore, multiple subgraphs composed of each role object in the object relationship graph are clustered to obtain multiple business groups, and different role objects in each business group are processed respectively, so that the accuracy and effectiveness of processing are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical fields of cloud technology, cloud storage, big data, etc., and specifically to a data processing method, apparatus, electronic device, storage medium, and program product. Background Technology

[0002] With the development of internet technology, some illegal business activities have spread on the internet; for example, online gambling. These online gambling operations often use a large number of social media accounts for promotion to attract users to participate in illegal online gambling activities.

[0003] In related technologies, the common approach is to simply proliferate known illegal accounts to identify groups of accounts forming a large number of accounts. For example, by utilizing a known gambling account environment, more accounts within the same environment are identified and treated as a single, abnormal group. However, the scope of these methods is limited, and the identification results are poor. Therefore, a more effective data processing method is urgently needed in this field to identify and process illegal business activities. Summary of the Invention

[0004] This application provides a data processing method, apparatus, electronic device, storage medium, and program product. The technical solution is as follows:

[0005] On the one hand, a data processing method is provided, the method comprising:

[0006] Obtain the object data of each object, and construct an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge;

[0007] Based on the basic data of at least one application, at least one target application is selected from the at least one application, and at least one target link propagated by the at least one target application is obtained by traversing the propagation data of the at least one target application. The target link is used to link to network resources for illegal business activities.

[0008] Based on the at least one target application and target link, seed objects that meet the target conditions are selected from each object, and role diffusion is carried out starting from the seed objects to obtain at least two role sets. Each role set includes multiple role objects that belong to the same type of business role in multiple illegal business chains. An illegal business chain includes role objects that belong to at least two types of business roles.

[0009] Cluster the at least one subgraph formed by each set of roles in the object relationship graph to obtain at least one business group. A business group includes role objects of at least two types of business roles on at least one illegal business chain.

[0010] For each business group, each role object is processed based on its business role within that business group.

[0011] On the other hand, a data processing apparatus is provided, the apparatus comprising:

[0012] The construction module is used to obtain the object data of each object and construct an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge.

[0013] The first determining module is used to filter out at least one target application from the at least one application based on the basic data of at least one application, and to obtain at least one target link propagated by the at least one target application from the propagation data of the at least one target application, wherein the target link is used to link to network resources for illegal business activities.

[0014] The second determining module is used to select seed objects that meet the target conditions from the objects based on the at least one target application and target link, and to perform role diffusion starting from the seed objects to obtain at least two role sets. Each role set includes multiple role objects that belong to the same type of business role in multiple illegal business chains. An illegal business chain includes role objects that belong to at least two types of business roles.

[0015] The group segmentation module is used to cluster at least one subgraph composed of each set of roles in the object relationship graph to obtain at least one business group. A business group includes role objects of at least two types of business roles on at least one illegal business chain.

[0016] The processing module is used to process each role object based on the business role of each role object in each business group.

[0017] In one possible implementation, the seed object is a downstream business role object;

[0018] The second determining module includes:

[0019] An extraction unit is used to extract downstream business keywords from the application name of the at least one target application;

[0020] The first determining unit is used to select at least one downstream role object that meets the target conditions from the various objects based on downstream business keywords, downstream role keywords and target links.

[0021] The second determining unit is used to start from the at least one downstream role object and perform role diffusion according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles. The at least one role propagation condition represents the business association relationship between various types of business roles in the illegal business chain.

[0022] In one possible implementation, the second determining unit is configured to:

[0023] According to the first role propagation condition, at least one operational role object that has a business relationship with the downstream role object is selected from each of the first associated objects of the at least one downstream role object. The first role propagation condition represents the business relationship between the downstream business role and the operational business role.

[0024] According to the second role propagation condition, at least one upstream role object that has a business relationship with the operation role object is selected from each of the second associated objects of the at least one operation role object. The second role propagation condition represents the business relationship between the operation business role and the upstream business role.

[0025] In one possible implementation, the propagation condition for the second role includes the existence of a transaction relationship with the operational business role;

[0026] The second determining unit is specifically used for:

[0027] For each operational role object, obtain at least one interaction data between the operational role object and each of the second associated objects;

[0028] The target recognition model is used to identify the transaction relationships of each interactive data, and at least one transaction relationship data with a transaction relationship is selected from each interactive data. At least one second associated object corresponding to the at least one transaction relationship data is identified as the upstream role object.

[0029] In one possible implementation, the first role propagation condition includes being an associated object of a downstream role object and being located within the target location range of the downstream role object;

[0030] The second determining unit is specifically used for:

[0031] Identify at least one first associated object for each downstream role object;

[0032] For each downstream role object, based on the geographical location of the downstream role object and each first associated object, the initial operation role object located within the target location range of the downstream role object is selected from each first associated object of the downstream role object;

[0033] According to the pre-configured operation object diffusion conditions, diffusion is carried out with the initial operation role object as the diffusion center to obtain at least one operation role object. The operation object diffusion conditions represent the business relationship between each operation role object.

[0034] In one possible implementation, the first determining unit is used for:

[0035] Based on the downstream business keywords and downstream role keywords, at least one candidate object is obtained from each of the objects, and the object identification information of the at least one candidate object includes the downstream business keywords and downstream role keywords;

[0036] Based on the at least one target link, select objects from the at least one candidate objects to send data including the initial downstream role object of any target link;

[0037] Based on the downstream business keywords, downstream role keywords, and pre-configured downstream object diffusion conditions, diffusion is carried out with the initial downstream role object as the diffusion center to obtain at least one downstream role object. The downstream object diffusion conditions characterize the business association relationship between each downstream role object.

[0038] In one possible implementation, the object data of each object includes at least one of the object's device identifier, network address, or interaction data with associated objects;

[0039] The association data between the various objects includes at least one of the following: the same device identifier, the same network address, or interaction data.

[0040] In one possible implementation, the group partitioning module is used for:

[0041] Based on the corresponding object nodes of each role object in the object relationship graph, and the edges between each object node, at least one subgraph is obtained.

[0042] Cluster the at least one subgraph to obtain the at least one business group.

[0043] In one possible implementation, the processing module is configured to:

[0044] For the role objects of various business roles in the illegal business chain, determine the processing strategies that match each business role;

[0045] For each type of business role in each business group, a processing strategy matching the type of business role is adopted to process the role objects of the corresponding business roles in the business group.

[0046] In one possible implementation, at least two types of business roles in a business chain include upstream roles, operational roles, and downstream roles;

[0047] The processing module is used for:

[0048] For any business group, monitor the transaction interaction data between each upstream role object and the operation role in the business group;

[0049] The system extracts potential downstream accounts from the transaction interaction data and then blocks these accounts.

[0050] On the other hand, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the above-described data processing method.

[0051] On the other hand, a computer-readable storage medium is provided that stores a computer program thereon, which, when executed by a processor, implements the above-described data processing method.

[0052] On the other hand, a computer program product is provided, including a computer program that, when executed by a processor, implements the above-described data processing method.

[0053] The beneficial effects of the technical solutions provided in this application are:

[0054] The data processing method provided in this application constructs an object relationship graph by using each object as a node and the relational data in the object data of each object as edges, to obtain a full relationship graph including multiple objects; it filters target applications from multiple applications and traverses to obtain at least one target link propagated by each target application; based on each target application and target link, it filters seed objects from each object and expands from the seed objects to obtain at least two role sets, thereby effectively mining role objects of at least two types of business roles in an illegal business chain, improving the accuracy of illegal business mining; furthermore, it clusters multiple subgraphs formed by each role object in the object relationship graph to obtain multiple business groups, so that different role objects in each business group can be processed separately, thereby enabling the processing scope to cover the entire business chain including upstream and downstream, improving the processing scope and range, and enhancing the accuracy and effectiveness of processing. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.

[0056] Figure 1 A schematic diagram illustrating an implementation environment for a data processing method provided in this application embodiment;

[0057] Figure 2 A flowchart illustrating a data processing method provided in an embodiment of this application;

[0058] Figure 3 A flowchart illustrating a data processing method provided in an embodiment of this application;

[0059] Figure 4 A schematic diagram of an object relationship diagram provided in an embodiment of this application;

[0060] Figure 5 A schematic diagram of a tag propagation process provided in an embodiment of this application;

[0061] Figure 6 A schematic diagram of a single sub-graph provided for an embodiment of this application;

[0062] Figure 7 This is a schematic diagram illustrating a clustering method for dividing a group, as provided in an embodiment of this application.

[0063] Figure 8 A schematic diagram of a data processing flow provided in an embodiment of this application;

[0064] Figure 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;

[0065] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0066] The embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions of the embodiments of this application.

[0067] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. The terms “comprising” and “including” as used in the embodiments of this application mean that the corresponding feature can be implemented as the presented feature, information, data, step, or operation, but do not exclude implementation as other features, information, data, steps, or operations supported by this art.

[0068] It is understood that in the specific implementation of this application, any data related to the object, such as object data, object device identifier, network address, interaction data with associated objects, object identifier information, transaction interaction data, transaction relationship data, and object geographical location, is involved. When the above embodiments of this application are applied to specific products or technologies, permission or consent from the object is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0069] Figure 1 This is a schematic diagram illustrating the implementation environment of a data processing method provided in this application. For example... Figure 1 As shown, the implementation environment includes an electronic device 101 and a data providing device 102. The electronic device 101 and the data providing device 102 communicate via a network connection.

[0070] The electronic device 101 can be used to identify target objects that are conducting or engaging in illegal business, and further analyze the business roles of these target objects in the illegal business chain to obtain a hierarchical business group including multiple business roles, thereby effectively identifying and processing objects of various business roles in the business group.

[0071] The data providing device 102 can provide the electronic device 101 with object data of various objects in the network, basic data of various applications, etc., so that the electronic device 101 can construct an object relationship graph including all objects and use the basic data to identify target applications, so as to obtain network resource links that the target applications spread for illegal business, i.e., target links. This allows the electronic device 101 to use the target applications and target links to filter seed objects, and from the seed objects, to propagate at least two role sets, each role set including multiple role objects belonging to the same type of business role; and to cluster at least one subgraph formed by each role object in the object relationship graph to obtain at least one business group, so as to effectively process each role object by adopting different processing strategies for each business role in the business group.

[0072] The electronic device 101 can be a server, security management device, cloud security computing center, cloud computing center device, or terminal device, etc. The data providing device 102 can be a backend server for various application platforms. For example, various applications can include, but are not limited to: social applications, live streaming applications, game applications, content publishing platforms, content interaction platforms, forums, audio and video applications, payment applications, short video applications, shopping applications, or any application that supports interaction between objects, etc.

[0073] For example, a server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server or server cluster that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The aforementioned networks can include, but are not limited to, wired networks and wireless networks. Wired networks include local area networks (LANs), metropolitan area networks (MANs), and wide area networks (WANs). Wireless networks include Bluetooth, Wi-Fi, and other networks that enable wireless communication. Terminals can be smartphones (such as Android phones, iOS phones, etc.), tablets, laptops, digital broadcast receivers, MIDs (Mobile Internet Devices), PDAs (Personal Digital Assistants), desktop computers, in-vehicle terminals (such as in-vehicle navigation terminals, in-vehicle computers, etc.), smart speakers, smartwatches, etc. Electronic device 101 and data providing device 102 can be directly or indirectly connected via wired or wireless communication, or the connection can be determined based on the actual application scenario requirements, and is not limited here.

[0074] Figure 2 This is a flowchart illustrating a data processing method provided in an embodiment of this application. The executing entity of this method can be an electronic device. This electronic device can be a server, a cloud computing center device, or a security management device, etc. Figure 2 As shown, the method includes the following steps.

[0075] Step 201: The electronic device acquires the object data of each object, and constructs an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge.

[0076] In this application, the object relationship graph includes each object within each object and the relationships between each object. The object data of each object includes at least one of the following: object identifier, network address, or interaction data with associated objects. The relationship data between objects includes, but is not limited to: the same device identifier, the same network address, or the existence of interaction data; if two objects have relationship data, then the two objects have the same device identifier, the same network address, or interaction data. In this step, the electronic device can construct the object relationship graph using each object as a node and the relationships between objects as edges.

[0077] In one possible implementation, the electronic device may first construct the object relationship graph using the object data of each object. For example, such as... Figure 3 As shown, step 201 may include steps 2011 to 2012:

[0078] Step 2011: The electronic device acquires the object data of each object.

[0079] In this step, the object data includes at least one of the following: the object's device identifier, network address, or interaction data with associated objects. Associated objects of an object may include, but are not limited to: associated objects that are friends with the object, associated objects that are following the object, or associated objects with which the object has interactive data. Interaction data may include, but is not limited to: friend request messages when adding friends, interactive comment messages, message messages, or conversation messages. The device identifier can be a device ID, which may include, but is not limited to, IMEI (International Mobile Equipment Identity), OAID (Open Anonymous Device Identifier), etc.

[0080] In one possible example, the objects may include various objects from a social application. The electronic device can then obtain object data for these objects from the social application's backend server. This object data may include, but is not limited to, information such as the accounts of both parties in the chat, device IDs, network addresses, friend request messages, and time. For example, in scenarios involving the detection of gambling activities, considering the time-sensitive nature of gambling-related accounts, this application can obtain friend request logs from the most recent three months. Furthermore, in scenarios involving the detection of online gambling, suspicious accounts are primarily found in newly added friend relationships. Therefore, the interaction data can be friend request messages, thereby improving the accuracy of detecting and processing gambling activities in a targeted manner; it also greatly simplifies subsequent mapping and related calculations. It should be noted that in the specific embodiments of this application, any object-related data, such as object data, accounts, device IDs, network addresses, friend request messages, time, and relationship data between objects, is involved. When the above embodiments of this application are applied to specific products or technologies, permission or consent from the object is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.

[0081] For example, the object data of the two parties in the chat is shown in Table 1 below:

[0082] Table 1

[0083]

[0084] As shown in Table 1, Account 1 and Account 2 can be two related accounts that are friends with each other. The identification information of the objects can include the account and nickname in Table 1. This interaction data can be a friend request message, for example, when Account 1 sends a friend request message to Account 2.

[0085] In some embodiments, the electronic device may also perform data cleaning on the initially acquired object data. The data cleaning process may include the following steps (1)-(3):

[0086] Step (1): Filter out missing data in the object data of each obtained object.

[0087] For example, the initially acquired object data may contain many incomplete records; for instance, some object data may have empty IP fields or unavailable device ID fields. This data needs to be discarded because it cannot form the corresponding edges in the graph. However, a record in the log data from step 1, excluding the missing information, still needs to be transformed into the fields required for graph construction.

[0088] Step (2): Filter out data in the object data of each object that is not related to the business scenario.

[0089] Scenario conditions can be set for the current business scenario to filter out object data from the initially acquired object data that does not meet the scenario conditions. For example, if the current business scenario is the mining and processing of gambling business, an account might have a short usage time and few associated accounts. Accordingly, scenario conditions can be set for the current business scenario, including but not limited to: account usage time not exceeding a pre-configured time threshold and the number of associated accounts not exceeding a pre-configured account number threshold. For example, based on these scenario conditions, accounts that have been used for a long time and add a large number of friends every day can be filtered out. Similarly, an account's network address or device that is consistently active and associated with a large number of accounts also does not meet these scenario conditions and can be filtered out. Based on this, the filtered accounts, network addresses, or device IDs can be added to a filter library. This filter library contains object data from a large number of objects that do not meet the scenario conditions of the current business scenario. The filter library can then be used to filter object data, for example, filtering out data from each object's object data that is covered by the filter library.

[0090] Step (3): Store the object data of each object after filtering in steps (1)-(2) according to the pre-configured format.

[0091] For example, the object data filtered by steps (1)-(2) can be organized and stored in the database according to the storage format in Table 2 below.

[0092] Table 2

[0093]

[0094] As shown in Table 2 above, the association relationships can include: the same network address, the same device ID, being friends, etc. Correspondingly, the association value is the value of the corresponding association relationship. For example, the association value for being friends can be a friend request message.

[0095] Step 2012: The electronic device constructs an object relationship graph with each object as a node and the relationship data between each object as edges.

[0096] The relationship data between the objects includes at least one of the following: the same device identifier, the same network address, or interaction data.

[0097] For example, the electronic device can construct a graph using the object account in the object identification information of an object as a node and the association value of the relationship between objects as an edge. The attributes of the nodes can include the object name in the object identification information of the corresponding object. Figure 4 This is a schematic diagram of a portion of an object-relationship diagram. For example... Figure 4 As shown, the attributes of each node can include nickname (e.g., Li Si), and the edges between each node. For example, if an edge represents a friend relationship in an association, the attribute value of the edge is a friend request message (e.g., Hello); if an edge represents the same network address in an association, the attribute value of the edge can include the network address value and the corresponding network address location; if an edge represents the same device in an association, the attribute value of the edge is the device ID.

[0098] It should be noted that this step involves constructing a graph using object data. The number of nodes in the constructed object relationship graph is on the order of the earth; for example, the number of nodes involved in the object relationship graph may be on the order of billions, and the number of edges may be on the order of 10 billion. This object relationship graph is a complete object relationship graph containing a large number of objects, many of which are irrelevant to the business scenario, meaning the graph contains a lot of distracting information. Therefore, steps 202-205 can be used to prune this object relationship graph to precisely focus on specific parts of the graph before mining business groups, thereby improving the accuracy and efficiency of business group mining.

[0099] Step 202: The electronic device, based on the basic data of at least one application, filters out at least one target application from the at least one application, and obtains at least one target link propagated by the at least one target application by traversing the propagation data of the at least one target application.

[0100] This target link is used to link to network resources used for illegal activities.

[0101] The electronic device can acquire basic data of at least one application; identify each application based on the basic data of the at least one application, filter out at least one target application among the applications; and acquire the propagation data of each target application, traverse the propagation data of each target application, and filter out at least one target link in the propagation data of each target application.

[0102] For example, the basic data may include at least one of the application's icon and the application's text description information. For instance, if the basic data includes application icons, the electronic device can calculate the similarity between the icons of each application and each illegal business icon in the pre-configured icon library based on the icons of each application and a pre-configured icon library. Based on the similarity between each icon and each illegal business icon, applications with similarity exceeding a preset threshold are identified as target applications. For example, the preset threshold can be configured as needed, such as 0.8, 0.9, etc. The icon library includes multiple pre-configured illegal business icons for target applications. As another example, if the basic data also includes the application's text description information, the electronic device can calculate the similarity between the graphic and textual data of each application and the graphic and textual data of each target application in the icon library to identify applications with similarity exceeding a preset threshold as target applications. The graphic and textual data of the application may include icons and text description information, and the text description information may include, but is not limited to, the application's name and installation package name.

[0103] In one possible example, the basic data can be shown in Table 3 below:

[0104] Table 3

[0105]

[0106] As shown in Table 3, the basic data of an application may include, but is not limited to: application (App) name, application installation package name (package name), installation package size, application certificate, application icon, links distributed by the application, devices associated with the application, and application installation time. Among these, links can be URLs (uniform resource locators).

[0107] In one possible example, the electronic device installs and runs various target applications via an emulator, then captures the data packets transmitted by each target application through packet capture, and extracts at least one link from the captured data packets, thereby obtaining the URLs propagated in each illegal business app. For example, at least one target link can be filtered from the various links propagated by each target application in the following two ways:

[0108] Method 1: Electronic devices acquire multiple links spread by each target application, count the number of applications associated with each link, and identify the links that have more than a pre-configured threshold of associated applications and include pre-configured keywords as target links.

[0109] For example, URLs spread within gambling apps tend to cluster; many gambling apps may share the same gambling-related URL, a phenomenon not observed in ordinary, non-gambling apps. Therefore, by counting the number of apps associated with each URL, URLs exceeding a certain threshold (e.g., 10) are considered suspicious. Data linked to these suspicious URLs is then crawled and matched against pre-configured keywords to filter out gambling-related URLs. These pre-configured keywords can be set based on business scenarios and may include keywords used to identify the current business context, such as "gambling."

[0110] Method 2: The electronic device periodically captures the URLs of known applications in the illegal business database by packet sniffing. The data linked by these URLs is then matched against pre-configured keywords to identify at least one target link. "Known applications" refers to applications identified as target applications and already added to the illegal business database.

[0111] Of course, you can also obtain the target application through reverse association using at least one target link. For example, an application associated with a gambling-related URL can be linked to a gambling app.

[0112] In one possible approach, multiple suspicious devices with known applications from the illegal business database installed can be identified, along with other applications installed on these suspicious devices. The number of devices with each other application installed on these suspicious devices can be counted, and the target application can be filtered out from these other applications. For example, based on the behavioral pattern that users with gambling habits are likely to install the same gambling apps, multiple suspicious devices with gambling apps from the illegal business database can be found. Apps installed by multiple users with gambling habits can be counted. Apps installed by more than 10 but less than 100 users with gambling habits are likely to be suspicious gambling apps, and further manual review can be conducted to confirm the final gambling apps. The filtering condition of more than 10 but less than 100 apps can remove pre-installed apps and very common apps, resulting in a more accurate set of suspicious apps.

[0113] Step 203: Based on the at least one target application and target link, the electronic device selects seed objects that meet the target conditions from each object, and uses the seed object as the starting point to diffuse roles, thereby obtaining at least two role sets.

[0114] Each role set includes multiple role objects belonging to the same type of business role across multiple illegal business chains. An illegal business chain includes role objects belonging to at least two types of business roles. In this step, the electronic device can, based on at least one target application and at least one target link, select seed objects that meet the target conditions from the various objects, and use these seed objects as the starting point for role propagation to obtain a first role set. Then, starting from this first role set, it continues to propagate roles according to at least one role propagation condition to obtain a second role set. The first role set includes role objects propagated using at least one target link corresponding to any one of the target applications. At least one role propagation condition characterizes the business relationship between the first role set and the second role set.

[0115] These at least two types of business roles can include downstream business roles, operational business roles, and upstream business roles. For example, in a gambling-related business scenario, a downstream business role refers to a role that directly provides services to gambling users downstream of the illegal business chain, such as agent customer service or official customer service, where official customer service directly connects with gambling users. For example, an operational business role is a role that connects upstream and downstream business roles. It can conduct transactions with upstream business roles and also promote products or services to downstream business roles. For example, the business of an operational business role can include investment promotion, platform operation, platform development, and business cooperation. For example, an upstream business role is upstream in the illegal business chain and is used to provide various materials to downstream business roles, including servers, website creation, app development, payment channels, and advertising.

[0116] In one possible implementation, the electronic device may first identify the downstream role object, and then identify two other types of role objects. Accordingly, step 203 may include steps 2031 to 2032:

[0117] Step 2031: The electronic device extracts downstream business keywords from the application name of the at least one target application; based on the downstream business keywords, downstream role keywords and target links, it selects at least one downstream role object that meets the target conditions from each object.

[0118] In one possible example, the target condition may include: the object identification information includes downstream business keywords and downstream role keywords, and a target link has been sent. Based on the downstream business keywords and downstream role keywords, the electronic device filters at least one candidate object from the various objects, the object identification information of the at least one candidate object including the downstream business keywords and downstream role keywords; based on the at least one target link, the electronic device filters from the at least one candidate object an initial downstream role object whose object sending data includes any target link; based on the downstream business keywords, downstream role keywords, and pre-configured downstream object diffusion conditions, the electronic device diffuses with the initial downstream role object as the diffusion center to obtain the at least one downstream role object, the downstream object diffusion conditions representing the business association relationship between the various downstream role objects.

[0119] The downstream business keywords include the name keywords of the target application. This electronic device can extract the name keywords of the target application and the downstream role keywords. For example, using the name of the gambling app and the downstream business keyword "customer service," multiple candidate objects whose names contain both the gambling app's name and the keyword "customer service" can be selected from various objects. From these candidate objects, the initial downstream role object that has sent the gambling URL can be selected, thus obtaining the downstream gambling customer service representative. This initial downstream role object can also be called the seed object.

[0120] For example, business relationship data between some downstream role objects may include: the same device and the same location. For instance, the downstream object diffusion condition can be based on the propagation rule of "same device + same location". For example, the seed object is diffused through the diffusion condition of "same device + same location", that is, based on the diffusion condition of "same device + same location", at least one account that is on the same device and located in the same geographical area as the seed object is obtained as a downstream business number, thereby obtaining more downstream gambling customer service accounts; in addition, during diffusion, the object name of the diffused downstream role object also includes downstream business keywords such as "customer service" and the name of the gambling APP.

[0121] Step 2032: The electronic device starts from the at least one downstream role object and performs role diffusion according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles. The at least one role propagation condition represents the business relationship between various business roles in the illegal business chain.

[0122] The at least one role propagation condition may include business relationships from downstream role objects to operational business roles, and business relationships from operational business roles to upstream roles. In this step, the computer device may, based on the downstream role object, determine, through the at least one role propagation condition, at least one operational role object belonging to an operational business role and at least one upstream role object belonging to an upstream business role.

[0123] In one possible implementation, step 2032 may include the following steps B1-B2:

[0124] Step B1: According to the first role propagation conditions, the electronic device selects at least one operational role object that has a business relationship with the downstream role object from each of the first associated objects of the at least one downstream role object.

[0125] The first role propagation condition represents the business relationship between downstream business roles and operational business roles.

[0126] For example, the first role propagation condition includes being an associated object of a downstream role object and located within the target location range of the downstream role object. Then step B1 includes: the electronic device determining at least one first associated object for each downstream role object; for each downstream role object, the electronic device, based on the geographical location of the downstream role object and each first associated object, filtering out initial operational role objects located within the target location range of the downstream role object from each of the first associated objects of the downstream role object; the electronic device, according to pre-configured operational object diffusion conditions, diffusion with the initial operational role object as the diffusion center to obtain the at least one operational role object.

[0127] The diffusion condition of the operational object represents the business relationship between various operational role objects.

[0128] For example, the first role propagation condition may include being an associated object of a downstream role object and located within the target location range of the downstream role object. This target location range may be a geographical area that is the same as or close to the location of the downstream role object.

[0129] For example, the propagation conditions of the first role may include a propagation rule based on "friends + same location". That is, the downstream business account obtains multiple friend objects of the downstream customer service business account through the propagation rule of "friends + same location", and selects at least one initial operation role object within the same location range from the multiple friend objects.

[0130] The conditions for operational diffusion can include the same device and the same location. For example, the conditions for operational object diffusion can be based on "same device + same location," in which case the electronic device can also acquire more operational role objects that are on the same device and in the same location as the initial operational role object, according to the operational object diffusion conditions. For example, based on the text description information of each operational role object, sub-roles under each operational business role can be further distinguished. For example, operational business roles can also include sub-roles such as platform development, business cooperation, and investment promotion. For example, the text description information can include account nicknames, profile information, object tags, etc.

[0131] Step B2: According to the second role propagation condition, the electronic device filters out at least one upstream role object that has a business relationship with the operation role object from each of the second associated objects of the at least one operation role object. The second role propagation condition represents the business relationship between the operation business role and the upstream business role.

[0132] In one possible implementation, the second role propagation condition includes the existence of a transaction relationship with the operational business role. For example, for each operational role object, the electronic device acquires at least one interaction data point between the operational role object and each of the second associated objects; the electronic device uses a target recognition model to identify the transaction relationship between each interaction data point, filters out at least one transaction relationship data point in each interaction data point, and identifies at least one second associated object corresponding to the at least one transaction relationship data point as the upstream role object.

[0133] For example, a transaction relationship refers to the act of purchasing materials from an upstream role object through an operational business role, such as purchasing potential customer service accounts or purchasing server equipment. The electronic device can use a pre-trained target recognition model to identify at least one interaction data point between the operational role object and each of the second associated objects, in order to determine whether a transaction relationship exists in the interaction data. For example, it can identify whether the type of interaction data is transaction relationship data; and based on the recognition results, it can determine the upstream role object with which the operational role object has a transaction relationship. For example, the interaction data may include friend request messages. That is, the electronic device can model and determine the relationship based on friend request messages between accounts. For example, it can input friend request messages into the target recognition model and output the message type of the friend request message. This message type can be divided into transaction relationship data and non-transaction relationship data. If it is transaction relationship data, the corresponding second associated object is the upstream role object.

[0134] For example, the electronic device can use pre-annotated request messages as sample data to iteratively train an initial BERT network to obtain the target recognition model. This target recognition model is used to identify the message type of the input message.

[0135] like Figure 5 As shown, taking a gambling scenario as an example, when spreading roles based on target applications and target links, the spread can start from a seed object and follow specific rules. For example, the seed object can spread through the "same device + same location" propagation rule to obtain multiple downstream business accounts, which are downstream role objects; then, the downstream business accounts can spread through the "friend + same location" propagation rule to obtain the core operation platform operation role, which is the operation role object; then, the core operation can spread through the "friend + buying and selling relationship" propagation rule to obtain the upstream role object, which is the upstream industry chain. Thus, by analyzing the role information and business relationships of multiple business roles on a business chain, starting from a simple seed object, multiple role objects of multiple business roles on a business chain can be mined, improving the accuracy and efficiency of illegal business mining. This enables subsequent targeted and effective handling of different business roles, improving the actual processing efficiency and accuracy.

[0136] It should be noted that the electronic device can iteratively execute the diffusion process in steps 2031-2032. For example, in step 2031, after the electronic device performs one diffusion based on downstream business keywords and pre-configured downstream object diffusion conditions, it can continue to perform another diffusion based on downstream business keywords and pre-configured downstream object diffusion conditions, using at least one downstream role object as the diffusion center, to obtain at least one downstream role object. For example, in step B1, after the electronic device performs step B1 once and obtains at least one operational role object, it can again perform diffusion according to the operational object diffusion conditions, using at least one operational role object as the diffusion center, to obtain at least one diffused operational role object again. The electronic device can repeat the diffusion until a preset condition is met, at which point diffusion stops. The preset condition may include, but is not limited to, the following: the number of diffusions exceeds a preset number, or the number of object increments corresponding to the diffusion exceeds a target increment. For example, the preset number of diffusions can be a fixed 3 times; or diffusion can stop when the number of objects increased by a very large order of magnitude (e.g., more than 1000) occurs during a certain diffusion.

[0137] Step 204: The electronic device clusters at least one subgraph formed by the various role sets in the object relationship graph to obtain at least one business group.

[0138] A business group includes role objects of at least two types of business roles on at least one illegal business chain.

[0139] The electronic device obtains at least one subgraph based on the corresponding object nodes in the object relationship graph for each role object, and the edges between the object nodes; the electronic device then clusters this at least one subgraph to obtain at least one business group. For example... Figure 6 As shown, the electronic device, through steps 2031-2032, obtains multiple subgraphs through multiple role diffusions to achieve the effect of pruning the object relationship graph. For example... Figure 6 The single subgraph shown may include downstream business numbers, core operations, and upstream industry chains. Multiple subgraphs can together form a large graph that can be clustered.

[0140] For example, the electronic device can use a clustering algorithm to cluster the various subgraphs. For instance, the fastunfolding algorithm can be used to divide the various subgraphs into communities, resulting in multiple business groups. Each business group can include role objects of multiple types of business roles on one illegal business chain, or it can include multiple types of business role objects on two or more illegal business chains.

[0141] For example, each business group is a multi-layered network gambling syndicate, such as... Figure 7 As shown, based on the complexity of the business chain, the group types of each business group can include the following two types: The first type: a single business chain group, which is a simple group, for example, a group that only includes groups derived from a single type of gambling app, and whose gambling customer service personnel are all from a single gambling business chain. The second type: a multi-business chain group, which is a complex group, for example, a large group operating multiple gambling sub-groups, which may include customer service personnel from multiple business chains.

[0142] Step 205: For each business group, the electronic device processes each role object based on the business role of each role object in that business group.

[0143] In this step, the electronic device can employ different strategies to process different business roles. For example, for various business roles within an illegal business chain, the electronic device determines a processing strategy matching each role. For each business group, the electronic device uses a matching strategy to process the corresponding business role within that group. For instance, for multi-layered online gambling syndicates, targeted processing strategies can be easily formulated based on different business roles. For example, downstream customer service accounts can be blocked; for core operational roles, their data can be monitored in real time to uncover more agent accounts and downstream business accounts; and for upstream business roles in the industry chain, their data can be further processed to obtain precise clues, which can then be provided to relevant departments to assist in offline processing.

[0144] In one possible implementation, at least two types of business roles in a business chain include upstream roles, operational roles, and downstream roles. For example, for any business group, the electronic device monitors the transaction interaction data between each upstream role and the operational role within that business group. The electronic device then mines potential downstream accounts from this transaction interaction data and suspends those accounts. For instance, before a customer service account is put into use, the user typically purchases a large number of accounts from an upstream account seller, and then the core operations team allocates these accounts for use by the next level of customer service staff. Therefore, by using core operational accounts and upstream industry chain accounts, a large number of potential customer service accounts can be detected in advance through correlation analysis before an account is put into use.

[0145] It should be noted that by identifying role objects of at least two types of business roles in the business chain and dividing them into multiple business groups, different strategies corresponding to different business roles can be adopted to process the role objects of different business roles in each business group in a targeted manner. For example, based on the accounts of online gambling gangs with complex multi-layered role structures, different strategies can be applied to different roles. This allows the processing scope to cover the entire upstream and downstream business chain of online gambling, rather than just dealing with a single dimension and a single strategy for gambling-related accounts. This improves the accuracy of processing and expands the scope and range of processing.

[0146] Figure 8 This is a schematic diagram of a data processing flow provided for this application. Figure 8As shown, in the application scenario of mining and processing gambling business activities, object data of each object is extracted and cleaned to construct an object relationship graph. Furthermore, by acquiring basic data from multiple applications, target applications are identified, and at least one target link is obtained by traversing the propagation data of the target application; for example, a gambling APK can be identified and the propagated gambling URL can be obtained, based on which information about the gambling ring can be obtained. Electronic devices can undergo multiple role diffusions in the object relationship graph based on target applications and target links, i.e., tag propagation. Tags are used to mark different business roles. During the diffusion process, seed objects can be mined based on target applications and target links. For example, at least one seed object can be mined based on downstream business keywords, downstream role keywords, and target links. If a seed object, i.e., a downstream role object, exists, the diffusion continues from the seed object to obtain more downstream role objects. Then, starting from each downstream role object, further role diffusion is performed according to the first role propagation condition to obtain operational role objects. If core operational roles exist, the role diffusion is further performed using the second role propagation condition to obtain upstream role objects. These upstream role objects can be accounts in the upstream industry chain, thus identifying three types of business roles in a gambling business chain: upstream roles, operational roles, and downstream roles. Role diffusion then ends. Based on the role objects of the multiple business roles discovered during the role diffusion process, multiple subgraphs composed of these role objects can be obtained from the object relationship graph. The fast unfolding clustering algorithm is used to divide these subgraphs into communities, resulting in multiple business groups. Each business group can be a gambling syndicate, allowing for targeted strategy processing of different business roles within the syndicate, improving actual processing efficiency and expanding the processing scope.

[0147] The data processing method provided in this application constructs an object relationship graph by using each object as a node and the relational data in the object data of each object as edges, to obtain a full relationship graph including multiple objects; it filters target applications from multiple applications and traverses to obtain at least one target link propagated by each target application; based on each target application and target link, it filters seed objects from each object and expands from the seed objects to obtain at least two role sets, thereby effectively mining role objects of at least two types of business roles in an illegal business chain, improving the accuracy of illegal business mining; furthermore, it clusters multiple subgraphs formed by each role object in the object relationship graph to obtain multiple business groups, so that different role objects in each business group can be processed separately, thereby enabling the processing scope to cover the entire business chain including upstream and downstream, improving the processing scope and range, and enhancing the accuracy and effectiveness of processing.

[0148] The data processing method provided in this application involves technical fields such as cloud technology, big data, and cloud security. Cloud computing is a computing model that distributes computing tasks across a resource pool composed of a large number of computers, enabling various application systems to obtain computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." From the user's perspective, the resources in the "cloud" are infinitely scalable, readily available, on-demand, expandable, and pay-as-you-go.

[0149] As a provider of fundamental cloud computing capabilities, a cloud resource pool (referred to as a cloud platform, generally called an IaaS (Infrastructure as a Service) platform) is established. Various types of virtual resources are deployed in the resource pool for external customers to choose from. The cloud resource pool mainly includes: computing devices (virtualized machines containing operating systems), storage devices, and network devices.

[0150] Cloud storage is a new concept that extends and develops from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as a storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of storage devices of various types (storage devices are also called storage nodes) in the network to work together through application software or application interfaces to provide data storage and business access functions to the outside world.

[0151] Big data refers to data sets that cannot be captured, managed, and processed within a certain timeframe using conventional software tools. It represents massive, rapidly growing, and diverse information assets that require new processing models to achieve stronger decision-making, insightful discovery, and process optimization capabilities. With the advent of the cloud era, big data has attracted increasing attention. Big data requires specialized technologies to effectively process large amounts of data within a tolerable timeframe. Technologies suitable for big data include massively parallel processing databases, data mining, distributed file systems, distributed databases, cloud computing platforms, the internet, and scalable storage systems.

[0152] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a large network of clients, it detects anomalies in software behavior on the network, obtains the latest information on Trojans and malware on the internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.

[0153] The main research directions in cloud security include: 1. Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control network-wide security events and risks; 3. Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services.

[0154] Figure 9 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application. Figure 9 As shown, the device includes:

[0155] Module 901 is used to obtain the object data of each object and construct an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge.

[0156] The first determining module 902 is used to filter out at least one target application from the at least one application based on the basic data of at least one application, and to obtain at least one target link propagated by the at least one target application from the propagation data of the at least one target application. The target link is used to link to network resources for illegal business.

[0157] The second determining module 903 is used to select seed objects that meet the target conditions from the objects based on the at least one target application and target link, and to perform role diffusion starting from the seed objects to obtain at least two role sets. Each role set includes multiple role objects that belong to the same type of business role in multiple illegal business chains. An illegal business chain includes role objects that belong to at least two types of business roles.

[0158] The group segmentation module 904 is used to cluster at least one subgraph composed of each set of roles in the object relationship graph to obtain at least one business group. A business group includes role objects of at least two types of business roles on at least one illegal business chain.

[0159] The processing module 905 is used to process each role object based on the business role of each role object in each business group.

[0160] In one possible implementation, the seed object is a downstream business role object;

[0161] The second determining module includes:

[0162] An extraction unit is used to extract downstream business keywords from the application name of the at least one target application.

[0163] The first determining unit is used to select at least one downstream role object that meets the target conditions from the various objects based on downstream business keywords, downstream role keywords and target links.

[0164] The second determining unit is used to start from the at least one downstream role object and perform role diffusion according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles. The at least one role propagation condition represents the business relationship between various business roles in the illegal business chain.

[0165] In one possible implementation, the second determining unit is used for:

[0166] According to the first role propagation condition, at least one operational role object that has a business relationship with the downstream role object is selected from each of the first associated objects of the at least one downstream role object. The first role propagation condition represents the business relationship between the downstream business role and the operational business role.

[0167] According to the second role propagation condition, at least one upstream role object that has a business relationship with the operation role object is selected from each of the second associated objects of the at least one operation role object. The second role propagation condition represents the business relationship between the operation business role and the upstream business role.

[0168] In one possible implementation, the conditions for the second role to propagate include the existence of a transactional relationship with the operational business role;

[0169] The second determining unit is specifically used for:

[0170] For each operational role object, obtain at least one interaction data between the operational role object and each of the second associated objects;

[0171] The target recognition model is used to identify the transaction relationships in each interaction data, and at least one transaction relationship data with a transaction relationship is selected from each interaction data. The at least one second associated object corresponding to the at least one transaction relationship data is identified as the upstream role object.

[0172] In one possible implementation, the propagation condition of the first role includes being an associated object of the downstream role object and being located within the target location range of the downstream role object;

[0173] The second determining unit is specifically used for:

[0174] Identify at least one first associated object for each downstream role object;

[0175] For each downstream role object, based on the geographical location of the downstream role object and each first associated object, the initial operation role object located within the target location range of the downstream role object is selected from each first associated object of the downstream role object;

[0176] According to the pre-configured operational object diffusion conditions, the initial operational role object is used as the diffusion center to diffuse and obtain at least one operational role object. The operational object diffusion conditions represent the business relationship between each operational role object.

[0177] In one possible implementation, the first determining unit is used for:

[0178] Based on the downstream business keywords and downstream role keywords, at least one candidate object is selected from each of the objects. The object identification information of the at least one candidate object includes the downstream business keywords and downstream role keywords.

[0179] Based on the at least one target link, select objects from the at least one candidate objects to send data including the initial downstream role object of any target link;

[0180] Based on the downstream business keyword, downstream role keyword, and pre-configured downstream object diffusion conditions, diffusion is carried out with the initial downstream role object as the diffusion center to obtain at least one downstream role object. The downstream object diffusion conditions characterize the business relationship between each downstream role object.

[0181] In one possible implementation, the object data of each object includes at least one of the object's device identifier, network address, or interaction data with associated objects;

[0182] The relationship data between these objects includes at least one of the following: the same device identifier, the same network address, or interaction data.

[0183] In one possible implementation, the group partitioning module is used for:

[0184] Based on the corresponding object nodes of each role object in the object relationship graph, and the edges between each object node, at least one subgraph is obtained.

[0185] Cluster the at least one subgraph to obtain the at least one business group.

[0186] In one possible implementation, the processing module is used for:

[0187] For the role objects of various business roles in the illegal business chain, determine the processing strategies that match each business role;

[0188] For each type of business role in each business group, a processing strategy matching the type of business role is adopted to process the corresponding role object in the business group.

[0189] In one possible implementation, at least two types of business roles in a business chain include upstream roles, operational roles, and downstream roles;

[0190] This processing module is used for:

[0191] For any business group, monitor the transaction interaction data between each upstream role object and the operation role in that business group;

[0192] The system extracts potential downstream accounts from the transaction interaction data and then blocks those accounts.

[0193] The data processing method provided in this application constructs an object relationship graph by using each object as a node and the relational data in the object data of each object as edges, to obtain a full relationship graph including multiple objects; it filters target applications from multiple applications and traverses to obtain at least one target link propagated by each target application; based on each target application and target link, it filters seed objects from each object and expands from the seed objects to obtain at least two role sets, thereby effectively mining role objects of at least two types of business roles in an illegal business chain, improving the accuracy of illegal business mining; furthermore, it clusters multiple subgraphs formed by each role object in the object relationship graph to obtain multiple business groups, so that different role objects in each business group can be processed separately, thereby enabling the processing scope to cover the entire business chain including upstream and downstream, improving the processing scope and range, and enhancing the accuracy and effectiveness of processing.

[0194] The apparatus in this application embodiment can execute the method provided in this application embodiment, and the implementation principle is similar. The actions performed by each module in the apparatus of each embodiment of this application correspond to the steps in the method of each embodiment of this application. For detailed functional descriptions of each module of the apparatus, please refer to the descriptions in the corresponding methods shown above, which will not be repeated here.

[0195] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. For example... Figure 10As shown, the electronic device includes: a memory, a processor, and a computer program stored in the memory. The processor executes the computer program to implement the steps of the data processing method, which, compared with related technologies, enables:

[0196] The data processing method provided in this application constructs an object relationship graph by using each object as a node and the relational data in the object data of each object as edges, to obtain a full relationship graph including multiple objects; it filters target applications from multiple applications and traverses to obtain at least one target link propagated by each target application; based on each target application and target link, it filters seed objects from each object and expands from the seed objects to obtain at least two role sets, thereby effectively mining role objects of at least two types of business roles in an illegal business chain, improving the accuracy of illegal business mining; furthermore, it clusters multiple subgraphs formed by each role object in the object relationship graph to obtain multiple business groups, so that different role objects in each business group can be processed separately, thereby enabling the processing scope to cover the entire business chain including upstream and downstream, improving the processing scope and range, and enhancing the accuracy and effectiveness of processing.

[0197] In one alternative embodiment, an electronic device is provided, such as Figure 10 As shown, Figure 10 The illustrated electronic device 1000 includes a processor 1001 and a memory 1003. The processor 1001 and the memory 1003 are connected, for example, via a bus 1002. Optionally, the electronic device 1000 may further include a transceiver 1004, which can be used for data interaction between the electronic device and other electronic devices, such as sending and / or receiving data. It should be noted that in practical applications, the transceiver 1004 is not limited to one type, and the structure of the electronic device 1000 does not constitute a limitation on the embodiments of this application.

[0198] Processor 1001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 1001 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0199] Bus 1002 may include a pathway for transmitting information between the aforementioned components. Bus 1002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 1002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 10 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0200] The memory 1003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium capable of carrying or storing computer programs and capable of being read by a computer, without limitation herein.

[0201] The memory 1003 is used to store computer programs that execute the embodiments of this application, and the execution is controlled by the processor 1001. The processor 1001 is used to execute the computer programs stored in the memory 1003 to implement the steps shown in the foregoing method embodiments.

[0202] Electronic devices include, but are not limited to, servers, terminals, or cloud computing center equipment.

[0203] This application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement the steps and corresponding content of the aforementioned method embodiments.

[0204] This application also provides a computer program product, including a computer program that, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.

[0205] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. The terms “comprising” and “including” as used in the embodiments of this application mean that the corresponding feature can be implemented as the presented feature, information, data, step, or operation, but do not exclude implementation as other features, information, data, steps, or operations supported by this art.

[0206] The terms "first," "second," "third," "fourth," "1," "2," etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in a sequence other than that shown in the figures or text.

[0207] It should be understood that although arrows indicate various operation steps in the flowcharts of this application's embodiments, the order in which these steps are implemented is not limited to the order indicated by the arrows. Unless explicitly stated herein, in some implementation scenarios of this application's embodiments, the implementation steps in each flowchart can be executed in other orders as required. Furthermore, some or all steps in each flowchart, based on the actual implementation scenario, may include multiple sub-steps or multiple stages. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage can also be executed at different times. In scenarios where execution times differ, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and this application's embodiments do not limit this.

[0208] The above description is only an optional implementation method for some implementation scenarios of this application. It should be noted that for those skilled in the art, other similar implementation methods based on the technical concept of this application without departing from the technical concept of this application also fall within the protection scope of the embodiments of this application.

Claims

1. A data processing method, characterized in that, The method includes: Obtain the object data of each object, and construct an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge; Based on the basic data of at least one application, at least one target application is selected from the at least one application, and multiple links propagated by the at least one target application are obtained by traversing the propagation data of the at least one target application. The number of applications associated with each link is counted, and at least one link that has more than a pre-configured threshold for the number of associated applications and includes a pre-configured keyword is identified as a target link. The target link is used to link to network resources for illegal business. Extract downstream business keywords from the application name of the at least one target application; Based on downstream business keywords, downstream role keywords, and target links, at least one downstream role object that meets the target conditions is selected from the various objects as a seed object. Role diffusion is then carried out starting from the seed object to obtain at least two role sets. Each role set includes multiple role objects belonging to the same type of business role in multiple illegal business chains. An illegal business chain includes role objects belonging to at least two types of business roles. At least one of the role objects is used for diffusion of the same type of business role and / or for diffusion of different types of business roles that are upstream of the role object and have a business relationship with the role object on the illegal business chain. Cluster the at least one subgraph formed by each set of roles in the object relationship graph to obtain at least one business group. A business group includes role objects of at least two types of business roles on at least one illegal business chain. For each business group, each role object is processed based on its business role within that business group; The process of expanding the role starting from the seed object yields at least two role sets, including: Identify at least one first associated object for each downstream role object; For each downstream role object, based on the geographical location of the downstream role object and each first associated object, the initial operation role object located within the target location range of the downstream role object is selected from each first associated object of the downstream role object; Obtain at least one operational role object that is on the same device and in the same location as the initial operational role object, and obtain a role set; For each operational role object, obtain at least one interaction data between the operational role object and each of the second associated objects, the interaction data including friend request messages; The target recognition model is used to identify the transaction relationships of each interactive data, and at least one transaction relationship data with a transaction relationship is selected from each interactive data. At least one second associated object corresponding to the at least one transaction relationship data is identified as the upstream role object, thus obtaining another role set.

2. The method according to claim 1, characterized in that, Starting from the seed object, role diffusion is performed to obtain at least two role sets, including: Starting from the at least one downstream role object, role diffusion is carried out according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles. The at least one role propagation condition represents the business association relationship between various business roles in the illegal business chain. Alternatively, the method may further include: using at least one role object obtained through diffusion as the diffusion center, repeatedly diffusing according to the role propagation conditions corresponding to the role object to obtain at least one role object belonging to the same business role as the role object, wherein the repeated diffusion stops when a preset condition is reached, and the preset condition includes at least one of the following: the number of diffusions exceeds a preset number or the number of object increments corresponding to the diffusion exceeds a target increment.

3. The method according to claim 2, characterized in that, The process of using the at least one downstream role object as a starting point and performing role diffusion according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles includes: According to the first role propagation condition, at least one operational role object that has a business relationship with the downstream role object is selected from each of the first associated objects of the at least one downstream role object. The first role propagation condition represents the business relationship between the downstream business role and the operational business role. According to the second role propagation condition, at least one upstream role object that has a business relationship with the operation role object is selected from each of the second associated objects of the at least one operation role object. The second role propagation condition represents the business relationship between the operation business role and the upstream business role.

4. The method according to claim 3, characterized in that, The second role's propagation condition includes the existence of a transaction relationship with the operational business role.

5. The method according to claim 3, characterized in that, The first role propagation condition includes being an associated object of the downstream role object and being located within the target location range of the downstream role object.

6. The method according to claim 1, characterized in that, The step of selecting at least one downstream role object that meets the target conditions from the various objects based on downstream business keywords, downstream role keywords, and target links includes: Based on the downstream business keywords and downstream role keywords, at least one candidate object is obtained from each of the objects, and the object identification information of the at least one candidate object includes the downstream business keywords and downstream role keywords; Based on at least one of the target links, select objects from the at least one candidate object to send data including the initial downstream role object of any target link; Based on the downstream business keywords, downstream role keywords, and pre-configured downstream object diffusion conditions, diffusion is carried out with the initial downstream role object as the diffusion center to obtain at least one downstream role object. The downstream object diffusion conditions characterize the business association relationship between each downstream role object.

7. The method according to claim 1, characterized in that, The object data of each object includes at least one of the following: the object's device identifier, network address, or interaction data with associated objects; The association data between the various objects includes at least one of the following: the same device identifier, the same network address, or interaction data.

8. The method according to claim 1, characterized in that, The process of clustering at least one subgraph formed by the various role sets in the object relationship graph to obtain at least one business group includes: Based on the corresponding object nodes of each role object in the object relationship graph, and the edges between each object node, at least one subgraph is obtained. Cluster the at least one subgraph to obtain the at least one business group.

9. The method according to claim 1, characterized in that, For each business group, based on the business roles of each role object within the business group, the following processing is performed on each role object: For the role objects of various business roles in the illegal business chain, determine the processing strategies that match each business role; For each type of business role in each business group, a processing strategy matching the type of business role is adopted to process the role objects of the corresponding business roles in the business group.

10. The method according to claim 1 or 9, characterized in that, A business chain must include at least two types of business roles: upstream role, operational role, and downstream role. For each business group, based on the business roles of each role object within the business group, the following processing is performed on each role object: For any business group, monitor the transaction interaction data between each upstream role object and the operation role in the business group; The system extracts potential downstream accounts from the transaction interaction data and then blocks these accounts.

11. A data processing apparatus, characterized in that, The device includes: The construction module is used to obtain the object data of each object and construct an object relationship graph with each object as a node and the relationship data in the object data of each object as an edge. The first determining module is used to filter at least one target application from the at least one application based on the basic data of at least one application, and to obtain multiple links propagated by the at least one target application from the propagation data of the at least one target application, count the number of applications associated with each link, and determine at least one link that has more than a pre-configured threshold number of associated applications and includes a pre-configured keyword as a target link, wherein the target link is used to link to network resources for illegal business. The second determining module is used to extract downstream business keywords from the application name of the at least one target application; based on the downstream business keywords, downstream role keywords and target links, at least one downstream role object that meets the target conditions is selected from each object as a seed object, and role diffusion is carried out starting from the seed object to obtain at least two role sets. Each role set includes multiple role objects belonging to the same type of business role in multiple illegal business chains. An illegal business chain includes role objects belonging to at least two types of business roles. At least one of the role objects is used for diffusion of the same type of business role and / or for diffusion of different types of business roles that are upstream of the role object and have a business relationship with the role object on the illegal business chain. The group segmentation module is used to cluster at least one subgraph composed of each set of roles in the object relationship graph to obtain at least one business group. A business group includes role objects of at least two types of business roles on at least one illegal business chain. The processing module is used to process each role object based on the business role of each role object in each business group. The second determining module includes: a second determining unit, used for: Identify at least one first associated object for each downstream role object; For each downstream role object, based on the geographical location of the downstream role object and each first associated object, the initial operation role object located within the target location range of the downstream role object is selected from each first associated object of the downstream role object; Obtain at least one operational role object that is on the same device and in the same location as the initial operational role object, and obtain a role set; For each operational role object, obtain at least one interaction data between the operational role object and each of the second associated objects, the interaction data including friend request messages; The target recognition model is used to identify the transaction relationships of each interactive data, and at least one transaction relationship data with a transaction relationship is selected from each interactive data. At least one second associated object corresponding to the at least one transaction relationship data is identified as the upstream role object, thus obtaining another role set.

12. The apparatus according to claim 11, characterized in that, The second determining unit is specifically used to: starting from the at least one downstream role object, perform role diffusion according to at least one role propagation condition to obtain role objects belonging to at least one type of business role other than downstream business roles, wherein the at least one role propagation condition represents the business association relationship between various types of business roles in the illegal business chain; Alternatively, the second determining module is further configured to: take at least one role object obtained by diffusion as the diffusion center, and repeatedly diffuse according to the role propagation conditions corresponding to the role object to obtain at least one role object that belongs to the same type of business role as the role object, and the repeated diffusion stops when a preset condition is reached, the preset condition including at least one of the following: the number of diffusions exceeds a preset number or the number of object increments corresponding to the diffusion exceeds a target increment.

13. The apparatus according to claim 12, characterized in that, The second determining unit is specifically used for: According to the first role propagation condition, at least one operational role object that has a business relationship with the downstream role object is selected from each of the first associated objects of the at least one downstream role object. The first role propagation condition represents the business relationship between the downstream business role and the operational business role. According to the second role propagation condition, at least one upstream role object that has a business relationship with the operation role object is selected from each of the second associated objects of the at least one operation role object. The second role propagation condition represents the business relationship between the operation business role and the upstream business role.

14. The apparatus according to claim 13, characterized in that, The second role's propagation condition includes the existence of a transaction relationship with the operational business role.

15. The apparatus according to claim 13, characterized in that, The first role propagation condition includes being an associated object of the downstream role object and being located within the target location range of the downstream role object.

16. The apparatus according to claim 12, characterized in that, The second determining module is specifically used for: Based on the downstream business keywords and downstream role keywords, at least one candidate object is obtained from each of the objects, and the object identification information of the at least one candidate object includes the downstream business keywords and downstream role keywords; Based on at least one of the target links, select objects from the at least one candidate object to send data including the initial downstream role object of any target link; Based on the downstream business keywords, downstream role keywords, and pre-configured downstream object diffusion conditions, diffusion is carried out with the initial downstream role object as the diffusion center to obtain at least one downstream role object. The downstream object diffusion conditions characterize the business association relationship between each downstream role object.

17. The apparatus according to claim 11, characterized in that, The object data of each object includes at least one of the following: the object's device identifier, network address, or interaction data with associated objects; The association data between the various objects includes at least one of the following: the same device identifier, the same network address, or interaction data.

18. The apparatus according to claim 11, characterized in that, The group partitioning module is specifically used for: Based on the corresponding object nodes of each role object in the object relationship graph, and the edges between each object node, at least one subgraph is obtained. Cluster the at least one subgraph to obtain the at least one business group.

19. The apparatus according to claim 11, characterized in that, The processing module is specifically used for: For the role objects of various business roles in the illegal business chain, determine the processing strategies that match each business role; For each type of business role in each business group, a processing strategy matching the type of business role is adopted to process the role objects of the corresponding business roles in the business group.

20. The apparatus according to claim 11 or 19, characterized in that, A business chain must include at least two types of business roles: upstream role, operational role, and downstream role. The processing module is specifically used for: For any business group, monitor the transaction interaction data between each upstream role object and the operation role in the business group; The system extracts potential downstream accounts from the transaction interaction data and then blocks these accounts.

21. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1 to 10.

22. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 10.

23. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 10.