Account risk detection method and device, computer device, and storage medium

By detecting account alert events, vulnerability events, and valuable information, the risk level of an account is comprehensively assessed, solving the problem of insufficient accuracy in account risk detection in existing technologies and achieving more comprehensive risk detection.

CN115955331BActive Publication Date: 2026-05-29TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2022-11-30
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, the accuracy of account risk detection is not high enough, mainly because the factors considered are relatively simple.

Method used

By detecting alarm events and vulnerability events associated with an account, and combining this with the account's value information, including permission information and real-name information, the risk level of the account is assessed. The system comprehensively considers the account's login behavior, login environment, and the value of the account itself, and uses multi-dimensional analysis to improve detection accuracy.

Benefits of technology

It enriches the influencing factors of risk detection, improves the accuracy and comprehensiveness of account risk detection, and can more accurately assess the risk level of an account.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115955331B_ABST
    Figure CN115955331B_ABST
Patent Text Reader

Abstract

The application discloses a kind of account risk detection method, device, computer equipment and storage medium, belong to computer technical field.The method comprises: detecting and account associated alarm event, alarm event refers to the event that the login behavior of account exists exception;Detecting and account associated fragile event, fragile event refers to the event that there is security risk in the login environment of account;Value information of account is obtained, value information indicates the value of account, value information includes at least one of permission information or real-name information, permission information indicates the authority that account has, and real-name information refers to the information associated with user that account is bound;By evaluating the severity of alarm event, the severity of fragile event and the importance of value information, determine risk detection result.The application considers the login behavior, login environment and value information of account, and according to the value of account by evaluating the authority and real-name condition of account, improve the accuracy of risk detection to account.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to an account risk detection method, apparatus, computer equipment, and storage medium. Background Technology

[0002] With the development of computer technology and internet technology, cybersecurity has become an increasingly important issue. In a network environment that provides various business services, users can register accounts to conduct business online, but this also exposes them to the risk of account attacks or theft. Therefore, detecting whether an account is at risk is crucial.

[0003] In related technologies, the risk of an account is determined by detecting whether there is abnormal login behavior. However, because the factors considered are relatively singular, the accuracy of risk detection is not high enough. Summary of the Invention

[0004] This application provides an account risk detection method, apparatus, computer device, and storage medium, which can improve the accuracy of account risk detection. The technical solution is as follows:

[0005] On the one hand, an account risk detection method is provided, the method comprising:

[0006] Detect alarm events associated with the account, where the alarm event refers to an event in which the login behavior of the account is abnormal;

[0007] Detect vulnerability events associated with the account, whereby a vulnerability event refers to an event that poses a security risk in the account's login environment;

[0008] Obtain the value information of the account, the value information representing the value of the account, the value information including at least one of permission information or real-name information, the permission information representing the permissions the account has, and the real-name information referring to user-related information bound to the account;

[0009] The risk detection result of the account is determined by assessing the severity of the alert event, the severity of the vulnerability event, and the importance of the valuable information. The risk detection result indicates the degree of risk faced by the account.

[0010] On the other hand, an account risk detection device is provided, the device comprising:

[0011] The alarm event detection module is used to detect alarm events associated with the account. The alarm event refers to an event in which the login behavior of the account is abnormal.

[0012] The vulnerability event detection module is used to detect vulnerability events associated with the account, whereby a vulnerability event refers to an event that poses a security risk in the account's login environment;

[0013] The information acquisition module is used to acquire the value information of the account, the value information representing the value of the account, the value information including at least one of permission information or real-name information, the permission information representing the permissions possessed by the account, and the real-name information referring to user-related information bound to the account;

[0014] The risk detection module is used to determine the risk detection result of the account by assessing the severity of the alarm event, the severity of the vulnerability event, and the importance of the valuable information. The risk detection result indicates the degree of risk faced by the account.

[0015] Optionally, the risk detection module includes:

[0016] An alarm parameter determination unit is used to perform parameter conversion on the alarm level to which the alarm event belongs according to an alarm parameter conversion rule to obtain alarm parameters. The alarm parameters represent the severity of the alarm event, and the alarm parameter conversion rule indicates that the alarm parameters are positively correlated with the alarm level.

[0017] The vulnerability parameter determination unit is used to perform parameter transformation on the vulnerability level to which the vulnerability event belongs according to the vulnerability parameter transformation rule to obtain vulnerability parameters. The vulnerability parameters represent the severity of the vulnerability event, and the vulnerability parameter transformation rule indicates that the vulnerability parameters are positively correlated with the vulnerability level.

[0018] The value parameter determination unit is used to perform parameter conversion on the value information according to the value parameter conversion rules to obtain value parameters, wherein the value parameters represent the importance of the account;

[0019] The risk parameter determination unit is used to perform parameter transformation on the alarm parameter, the vulnerability parameter and the value parameter according to the risk parameter transformation rule to obtain the risk parameter, the risk parameter being the risk detection result, and the risk parameter transformation rule indicating that the risk parameter is positively correlated with the alarm parameter, the vulnerability parameter and the value parameter.

[0020] Optionally, the number of alarm events is multiple, and the alarm parameter determination unit is used for:

[0021] The alarm level corresponding to the event type to which the alarm event belongs is determined as the alarm level to which the alarm event belongs, and each alarm level corresponds to at least one event type;

[0022] For each alarm level, according to the alarm parameter conversion rule, the level value of the alarm level and the number of alarm events belonging to the alarm level are converted to obtain the first influence parameter of the alarm level. The alarm parameter conversion rule indicates that the first influence parameter is positively correlated with the level value and the number. The first influence parameter represents the degree of influence of the alarm events belonging to the alarm level.

[0023] According to the alarm parameter conversion rule, the sum of the first influence parameters of multiple alarm levels is converted to obtain the alarm parameter. The alarm parameter conversion rule indicates that the alarm parameter is positively correlated with the sum of the influence parameters of the multiple alarm levels.

[0024] Optionally, the number of vulnerable events is multiple, and the vulnerability parameter determination unit is used for:

[0025] The vulnerability level corresponding to the event type to which the vulnerability event belongs is determined as the vulnerability level to which the vulnerability event belongs, and each vulnerability level corresponds to at least one event type;

[0026] According to the vulnerability parameter conversion rule, the level values ​​of the vulnerability levels to which multiple vulnerability events belong are converted to obtain the second impact parameters of the multiple vulnerability events. The vulnerability parameter conversion rule indicates that the second impact parameters are positively correlated with the level values, and the second impact parameters represent the degree of impact of the vulnerability events.

[0027] According to the vulnerability parameter transformation rule, the second influence parameters of multiple vulnerable events are transformed to obtain the vulnerability parameter, and the vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second influence parameter.

[0028] Optionally, the vulnerability parameter determination unit is used for:

[0029] Among the multiple vulnerable events, a target vulnerable event and a non-target vulnerable event are identified. The target vulnerable event is the vulnerable event with the smallest sequence number, and the non-target vulnerable events are all vulnerable events other than the target vulnerable event. The sequence number is obtained by arranging the multiple vulnerable events in descending order according to the second influence parameter.

[0030] For each of the non-target vulnerable events, the second influence parameter and the sequence number of the non-target vulnerable event are transformed according to the vulnerability parameter transformation rule to obtain a third influence parameter. The vulnerability parameter transformation rule indicates that the third influence parameter is positively correlated with the second influence parameter and negatively correlated with the second influence parameter.

[0031] According to the vulnerability parameter transformation rule, the second influence parameter of the target vulnerability event and the third influence parameter of each non-target vulnerability event are transformed to obtain the vulnerability parameter. The vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second influence parameter and the third influence parameter.

[0032] Optionally, the value information includes the permission information and the real-name information; the value parameter determination unit is used for:

[0033] According to the value parameter conversion rule, the first quantity indicated by the permission information is converted to obtain the permission parameter. The value parameter conversion rule indicates that the permission parameter is positively correlated with the first quantity, and the first quantity represents the number of permissions that the account has.

[0034] According to the value parameter conversion rule, the second quantity indicated by the real-name information is converted to obtain the real-name parameter. The value parameter conversion rule indicates that the real-name parameter is positively correlated with the second quantity. The second quantity represents the number of real-name items that the account has. A real-name item represents a type of information related to the user that is bound to the account.

[0035] According to the value parameter conversion rule, the permission parameter and the real name parameter are converted to obtain the value parameter. The value parameter conversion rule indicates that the value parameter is positively correlated with the permission parameter and the real name parameter.

[0036] Optionally, the vulnerability event detection module is used to:

[0037] The device operation log associated with the account is used to identify events that indicate a security vulnerability on the device logged into that account; the device operation log is the operation log of the device logged into the account; or,

[0038] The client operation log associated with the account is used to identify events that indicate a security vulnerability in the client that logged into the account. The client operation log is the operation log of the client that logged into the account.

[0039] Optionally, the alarm event detection module is used to:

[0040] Detect candidate alarm events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point;

[0041] Determine the current event state of any detected candidate alarm event, including a processed state and an unprocessed state;

[0042] Among the detected candidate alarm events, the alarm events that are in the unprocessed state are identified.

[0043] Optionally, the vulnerability event detection module is used to:

[0044] Detect candidate vulnerable events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point;

[0045] Determine the current event state of any detected candidate vulnerability event, including a processed state and an unprocessed state;

[0046] Among the detected candidate vulnerable events, the vulnerable events that are in the unprocessed state are identified.

[0047] On the other hand, a computer device is provided, the computer device including a processor and a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor to perform the operations performed by the account risk detection method as described above.

[0048] On the other hand, a computer-readable storage medium is provided, wherein at least one computer program is stored therein, the at least one computer program being loaded and executed by a processor to perform the operations performed by the account risk detection method as described above.

[0049] On the other hand, a computer program product is provided, including a computer program that is loaded and executed by a processor to perform the operations performed by the account risk detection method described above.

[0050] The solution provided in this application comprehensively considers the account's login behavior, login environment, and the account's intrinsic value when detecting whether an account is at risk. It systematically analyzes information from these three perspectives, enriching the influencing factors considered when detecting account risks. Furthermore, it assesses the account's value based on its permissions and real-name authentication status, making the information covered by account risk detection more comprehensive and improving the accuracy of account risk detection. Attached Figure Description

[0051] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1This is a schematic diagram of an implementation environment provided in an embodiment of this application;

[0053] Figure 2 This is a flowchart of an account risk detection method provided in an embodiment of this application;

[0054] Figure 3 This is a flowchart of another account risk detection method provided in the embodiments of this application;

[0055] Figure 4 This is a flowchart of another account risk detection method provided in the embodiments of this application;

[0056] Figure 5 This is a schematic diagram of the structure of an account risk detection device provided in an embodiment of this application;

[0057] Figure 6 This is a schematic diagram of another account risk detection device provided in the embodiments of this application;

[0058] Figure 7 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application;

[0059] Figure 8 This is a schematic diagram of the structure of a server provided in an embodiment of this application. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0061] It is understood that the terms "first," "second," etc., used in this application may be used to describe various concepts herein, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of this application, a first influence parameter may be referred to as a second influence parameter, and similarly, a second influence parameter may be referred to as a first influence parameter.

[0062] "At least one" refers to one or more event types. For example, at least one event type can be any integer number of event types greater than or equal to one, such as one event type, two event types, three event types, etc. "Multiple" refers to two or more event types. For example, multiple event types can be any integer number of event types greater than or equal to two, such as two event types, three event types, etc. "Each" refers to each of the at least one event type. For example, each event type refers to each of the multiple event types. If the multiple event types are three event types, then each event type refers to each of the three event types.

[0063] It is understood that in the embodiments of this application, data such as user information are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0064] Figure 1 This is a schematic diagram of an implementation environment provided in an embodiment of this application. See also... Figure 1 The implementation environment includes at least one terminal 101 ( Figure 1 (Taking 3 as an example) and server 102. Terminal 101 and server 102 are directly or indirectly connected via wired or wireless communication.

[0065] In this embodiment, server 102 detects alarm events and vulnerability events associated with the account logged in by terminal 101, and obtains the value information of the account. Based on the alarm events, vulnerability events and value information, server 102 determines the risk detection result of the account and sends the risk detection result to terminal 101 so that terminal 101 can determine the current risk level of the account and take countermeasures.

[0066] In one possible implementation, terminal 101 can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, smart voice interaction device, smart home appliance, vehicle terminal, aircraft, etc., but is not limited to these. In another possible implementation, server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0067] The account risk detection method provided in this application can be applied to any scenario for risk detection of accounts.

[0068] For example, an enterprise can establish a risk control system, an equipment management system, and an information system. The risk control system detects alarm events associated with accounts registered within the enterprise, such as abnormal login behavior. The equipment management system detects vulnerability events associated with accounts, such as security vulnerabilities in the account's login environment. The information system collects valuable information associated with accounts, such as account permission information and real-name information. Using the method provided in this application's embodiments, based on the detected alarm events, vulnerability events, and collected valuable information, the risk detection result of the account can be determined, allowing for timely processing and elimination of security risks when they are detected.

[0069] Figure 2 This is a flowchart of an account risk detection method provided in an embodiment of this application. This embodiment is executed by a computer device. See also... Figure 2 The method includes:

[0070] 201. Alarm events related to computer equipment detection and account association. An alarm event refers to an event in which the account's login behavior is abnormal.

[0071] An account refers to an account bound to user-related information, including username, contact information, email address, and ID card number. This account can be any account; for example, if the computer device is a server, the account is one registered on that server. If the computer device is a terminal, the account is one used to log in on that terminal. Alternatively, the account can be one that is notified to the computer device by other devices, etc. This application embodiment does not limit this.

[0072] Account-related alerts refer to events indicating abnormal login behavior. When such behavior is unusual, the account is more likely to be compromised, such as through account theft. In other words, an alert indicates a threat to the account, which can be described by various attributes such as the threat actor, motive, method, capability, and frequency. Account threats can be direct or indirect attacks that compromise the account's confidentiality, integrity, and availability. These threats can be accidental or deliberate.

[0073] 202. Vulnerability events related to computer equipment detection and account association. Vulnerability events refer to events in the account's login environment that pose security risks.

[0074] Among them, account-related vulnerability events refer to events where there are security risks in the account's login environment. Security risks refer to unmet security requirements or the existence of weak links that may be threatened, such as the presence of viruses or high-risk vulnerabilities in the login environment.

[0075] 203. Computer devices obtain the value information of an account. The value information represents the value of the account. The value information includes at least one of permission information or real-name information. Permission information represents the permissions that the account has. Real-name information refers to information related to the user that is bound to the account.

[0076] Value information includes at least one of permission information or real-name information. The higher the permissions an account has, the higher its value; the lower the permissions, the lower its value. The more user-related information an account is linked to, the higher its value; the less user-related information an account is linked to, the lower its value. Therefore, account value information represents the account's value, which refers to the account's importance. In this embodiment, the account's value is measured by its permission information or real-name information.

[0077] 204. Computer devices determine the risk assessment result of an account by evaluating the severity of alert events, the severity of vulnerability events, and the importance of valuable information. The risk assessment result indicates the level of risk faced by the account.

[0078] The higher the severity of an alert event associated with an account, the higher the risk level of that account; conversely, the lower the severity of an alert event associated with an account, the lower the risk level. Similarly, the higher the severity of a vulnerability event associated with an account, the higher the risk level; and the lower the severity of a vulnerability event associated with an account, the lower the risk level. The higher the importance of the account's valuable information, the higher the likelihood of the account being attacked, and thus the higher the risk level; conversely, the lower the importance of the account's information, the lower the likelihood of the account being attacked, and thus the lower the risk level. Therefore, the level of risk faced by an account depends on the severity of alert events, the severity of vulnerability events, and the importance of valuable information. Thus, after acquiring alert events, vulnerability events, and valuable information, computer equipment comprehensively considers these three factors to determine the risk detection result of the account, that is, to determine the level of risk faced by the account.

[0079] The method provided in this application comprehensively considers the account's login behavior, login environment, and value information of the account itself when detecting whether an account is facing risks. It systematically analyzes information from three perspectives, enriching the influencing factors considered when detecting account risks. Furthermore, it evaluates the value of the account based on its permissions and real-name registration, making the information covered by account risk detection more comprehensive and improving the accuracy of account risk detection.

[0080] In the above Figure 2 Based on the illustrated embodiment, the computer device determines alarm parameters based on alarm events, vulnerability parameters based on vulnerability events, and value parameters based on value information. Then, it determines risk parameters based on the alarm parameters, vulnerability parameters, and value parameters; these risk parameters constitute the risk detection result. The specific process is detailed below. Figure 3 The example shown. Figure 3 This is a flowchart of an account risk detection method provided in an embodiment of this application. This embodiment is executed by a computer device. See also... Figure 3 The method includes:

[0081] 301. Alarm events related to computer equipment detection and account association. An alarm event refers to an event in which the account's login behavior is abnormal.

[0082] In this embodiment, the alarm event is a concept proposed for accounts. When an account's login behavior is abnormal, an alarm event associated with the account is detected. For example, the alarm event includes the account logging in more than a first preset number of times within a first preset time period. Or the alarm event includes the account being logged in by an unused device, etc. Optionally, a frequently used device refers to a device that logs in to the account more than a second preset number of times within a second preset time period, and an unused device refers to any device other than a frequently used device.

[0083] In one possible implementation, the computer device is equipped with a risk control system that detects alarm events associated with an account. Specifically, this risk control system can access the account's login logs, which record the account's login activities. By analyzing these login logs, the risk control system identifies alarm events associated with the account.

[0084] In another possible implementation, the computer device has multiple preset alarm levels, each corresponding to at least one event type. The alarm level can be determined based on the event type to which the alarm event belongs. For example, there could be 10 alarm levels; the higher the level value, the more severe the alarm event belonging to that level; conversely, the lower the level value, the less severe the alarm event belonging to that level.

[0085] In another possible implementation, the computer device detects candidate alarm events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration prior to the current time. The computer device determines the current event status of any detected candidate alarm event, including processed and unprocessed statuses, and identifies the alarm events in the unprocessed status among the detected candidate alarm events.

[0086] Alarm events are categorized into processed and unprocessed events. Processed alarm events indicate that corresponding measures have been taken to reduce the likelihood of the account being threatened by the alarm event. For example, if the alarm event is that the account was logged in from an unused device, then prohibiting that unused device from logging in reduces the likelihood of the account being threatened by that unused device, thus processing the alarm event. Unprocessed alarm events indicate that no corresponding measures have been taken for the alarm event, meaning the account still faces the possibility of being threatened by the alarm event.

[0087] In this embodiment of the application, considering that the account is no longer threatened by the alarm event after the alarm event has been processed, the risk level faced by the account is no longer affected by the alarm event. Therefore, when determining the alarm event, only alarm events that have not yet been processed are considered, and alarm events that have already been processed are not considered. This is beneficial to ensure the accuracy of the risk detection results determined based on the alarm events.

[0088] 302. The computer equipment performs parameter conversion on the alarm level to which the alarm event belongs, according to the alarm parameter conversion rules, to obtain alarm parameters. The alarm parameters represent the severity of the alarm event, and the alarm parameter conversion rules indicate that the alarm parameters are positively correlated with the alarm level.

[0089] The higher the alarm level, the more severe the alarm event; the lower the alarm level, the less severe the alarm event. This alarm parameter represents the severity of the alarm event. The higher the alarm parameter for an account, the higher the likelihood of that account being attacked; the lower the alarm parameter, the lower the likelihood of that account being attacked. Since the alarm parameter conversion rule indicates a positive correlation between the alarm parameter and the alarm level, after parameter conversion according to this rule, the higher the alarm level, the larger the alarm parameter, and vice versa.

[0090] In one possible implementation, there are multiple alarm events, and the computer device has multiple preset alarm levels. Each alarm level corresponds to at least one event type. The computer device determines the alarm level to which the alarm event belongs by identifying the alarm level corresponding to the event type. For each alarm level, the computer device performs parameter conversion on the alarm level value and the number of alarm events belonging to the alarm level according to an alarm parameter conversion rule to obtain a first influence parameter of the alarm level. This alarm parameter conversion rule indicates that the first influence parameter is positively correlated with the level value and the number of events, and the first influence parameter represents the degree of influence of the alarm events belonging to the alarm level. The computer device also performs parameter conversion on the sum of the first influence parameters of multiple alarm levels according to the alarm parameter conversion rule to obtain an alarm parameter. This alarm parameter conversion rule indicates that the alarm parameter is positively correlated with the sum of the influence parameters of multiple alarm levels.

[0091] For each alarm level, the impact of at least one alarm event belonging to that level depends on two factors: the alarm level's numerical value, which indicates the severity of the alarm, and the number of alarm events belonging to that level. Therefore, the alarm parameter conversion rule instructs that a first influence parameter for the alarm level be determined based on the alarm level's numerical value and the number of alarm events belonging to that level. This alarm parameter is positively correlated with the sum of the influence parameters for multiple alarm levels. That is, the larger the alarm level's numerical value, the larger the first influence parameter; the smaller the alarm level's numerical value, the smaller the first influence parameter. Similarly, the larger the number of alarm events belonging to the alarm level, the larger the first influence parameter; and the smaller the number of alarm events belonging to the alarm level, the smaller the first influence parameter.

[0092] Once the computer equipment determines the primary influence parameter for each alarm level, considering that the alarm parameter is affected by the severity of multiple alarm levels, the alarm parameter conversion rule instructs that the alarm parameter be determined based on the sum of the primary influence parameters for multiple alarm levels, and the alarm parameter is positively correlated with the sum of the influence parameters for multiple alarm levels. That is, the larger the sum of the primary influence parameters for multiple alarm levels, the larger the alarm parameter; the smaller the sum of the primary influence parameters for multiple alarm levels, the smaller the alarm parameter.

[0093] In this embodiment, alarm events are classified, and alarm parameters are determined based on the alarm level and the number of alarm events belonging to each alarm level to assess the possibility of an account being attacked, thereby improving the accuracy and precision of alarm parameters.

[0094] In one possible implementation, for each alarm level, the computer device determines a risk index influence base for that alarm level, where the risk index influence base has a first target value as its base and the alarm level value as its exponent. The computer device determines an alarm frequency influence coefficient for that alarm level, which is calculated using the arctangent trigonometric function on a target quantity, where the target quantity refers to the number of alarm events belonging to that alarm level. The computer device multiplies an adjustment coefficient, the risk index influence base, and the alarm frequency influence coefficient to obtain a first influence parameter for that alarm level. The computer device determines the sum of the first influence parameters for multiple alarm levels and uses the logarithm of a second target value with the sum of the first influence parameters as its base as the alarm parameter. In this embodiment, the alarm parameter is determined in the above manner, ensuring that the higher the alarm level and the greater the number of alarm events, the larger the alarm parameter, thereby accurately assessing the likelihood of an account being attacked and improving the precision and accuracy of the alarm parameter.

[0095] Optionally, the alarm levels are divided into 8 levels, with the number of alarm events belonging to these 8 alarm levels being n1, n2, n3, n4, n5, n6, n7, and n8, respectively. The computer equipment uses the following formula to determine the alarm parameters.

[0096]

[0097] Where t represents the alarm parameter, i represents the alarm level value, i is a positive integer, and ni represents the number of alarm events belonging to alarm level i. For alarm frequency impact coefficient, 2 i This serves as the base for the risk index. The alarm parameters obtained using the above formula range from (0, 10], with a minimum granularity of 0.01.

[0098] In one possible implementation, the computer device determines the alarm parameter as the level value of the alarm level to which the alarm event belongs. Alternatively, when there are multiple alarm events, the computer device determines the alarm parameter as the average of the level values ​​of the alarm levels to which the multiple alarm events belong.

[0099] Based on the above possible implementation methods, it can be seen that the alarm parameters corresponding to an account are determined by the alarm events. By processing the alarm events associated with the account, the alarm parameters corresponding to the account can be reduced, and alarm events with higher severity have a greater impact on the alarm parameters corresponding to the account.

[0100] It should also be noted that this application embodiment only illustrates the detection of alarm events associated with an account. If no alarm event associated with an account is detected, the computer device determines the alarm parameter corresponding to the account to a preset character, which indicates that no alarm event associated with the account has been detected. For example, the preset character is N / A. Specifically, if the alarm parameter corresponding to the account is 0, it means that the probability of the account being threatened by an alarm event is 0. If the alarm parameter corresponding to the account is N / A, it means that it is uncertain whether the account is threatened by an alarm event.

[0101] 303. Vulnerability events related to computer equipment detection and account association. Vulnerability events refer to events in the account's login environment that pose security risks.

[0102] In this embodiment, a vulnerability event associated with an account refers to an event where there is a security risk in the account's login environment. The account's login environment refers to the host machine of the account, such as the terminal, server, or client used to log in to the account. A security risk in the login environment means that the security requirements of the login environment are not met, making the account's operating environment vulnerable and potentially leading to an attack. For example, a security risk in the login environment includes the presence of viruses, unpatched vulnerabilities, or failure to configure verification information according to specifications.

[0103] In one possible implementation, the computer device is equipped with a device management system that detects vulnerability events associated with an account. Specifically, the device management system can obtain the operational logs of the login environment for that account, which record the operational status of the login environment. By analyzing these operational logs, the device management system identifies vulnerability events associated with the account.

[0104] In one possible implementation, the login environment's operational logs include device operational logs and client operational logs. The device operational logs are the operational logs of the device associated with the login account, which can be a terminal or a server. The client operational logs are the operational logs of the client associated with the login account. The computer device identifies events indicating security vulnerabilities in the login account's device from the device operational logs associated with the account; or, it identifies events indicating security vulnerabilities in the login account's client from the client operational logs associated with the account.

[0105] In this embodiment of the application, by collecting the operation logs in the login environment of the account, and detecting the vulnerability events associated with the account based on the operation logs, the factors considered in the risk detection of the account are enriched, providing sufficient data support for risk detection and helping to improve the accuracy of risk detection of the account.

[0106] In one possible implementation, the computer device detects candidate vulnerable events associated with an account within a preset time period, where the preset time period refers to the time period within a preset duration prior to the current time. The computer device determines the current event state of any detected candidate vulnerable event, including a processed state and an unprocessed state, and identifies the vulnerable events in the unprocessed state among the detected candidate vulnerable events.

[0107] Vulnerability events are categorized into those that have been addressed and those that have not. A addressed vulnerability means that corresponding measures have been taken to reduce the likelihood of the account being threatened by that vulnerability. For example, if the vulnerability is a flaw in the login environment, fixing the vulnerability reduces the likelihood of the account being threatened, thus addressing the vulnerability. An unaddressed vulnerability means that no corresponding measures have been taken, meaning the account still faces the possibility of being threatened by that vulnerability.

[0108] In this embodiment of the application, considering that the account is no longer threatened by the vulnerability event after the vulnerability event has been dealt with, the risk level faced by the account is no longer affected by the vulnerability event. Therefore, when determining the vulnerability event, only the vulnerability events that have not yet been dealt with are considered, and the vulnerability events that have been dealt with are not considered. This is beneficial to ensure the accuracy of the risk detection results determined based on the vulnerability events.

[0109] 304. According to the vulnerability parameter conversion rules, computer equipment performs parameter conversion on the vulnerability level to which the vulnerability event belongs, and obtains vulnerability parameters. The vulnerability parameters represent the severity of the vulnerability event, and the vulnerability parameter conversion rules indicate that the vulnerability parameters are positively correlated with the vulnerability level.

[0110] The higher the vulnerability level, the more severe the vulnerability event; conversely, the lower the vulnerability level, the less severe the vulnerability event. This vulnerability parameter represents the severity of the vulnerability event. A higher vulnerability parameter for an account increases the likelihood of the account being attacked, while a lower vulnerability parameter decreases the likelihood of the account being attacked. Since the vulnerability parameter conversion rule indicates a positive correlation between the vulnerability parameter and the vulnerability level, after parameter conversion according to this rule, a higher vulnerability level corresponds to a larger vulnerability parameter, and vice versa.

[0111] In one possible implementation, there are multiple vulnerable events. The computer device has multiple preset vulnerability levels, each corresponding to at least one event type. The computer device determines the vulnerability level to which the vulnerable event belongs by assigning the event type to it. The computer device then performs parameter transformation on the vulnerability level values ​​of the multiple vulnerable events according to a vulnerability parameter transformation rule, obtaining a second influence parameter for each vulnerable event. The vulnerability parameter transformation rule indicates that the second influence parameter is positively correlated with the vulnerability level value, and the second influence parameter represents the degree of influence of the vulnerable event. Finally, the computer device performs parameter transformation on the second influence parameter of the multiple vulnerable events according to the vulnerability parameter transformation rule, obtaining a vulnerability parameter. The vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second influence parameter.

[0112] The impact of each vulnerability event is related to the level value of its corresponding vulnerability level, which represents the severity of that vulnerability. Therefore, the vulnerability parameter transformation rule instructs the determination of a second impact parameter for each vulnerability event based on its level value. After determining the second impact parameter for each vulnerability event, considering that the vulnerability parameter is affected by the severity of multiple vulnerability events, the vulnerability parameter transformation rule also instructs the determination of a vulnerability parameter based on the second impact parameters of multiple vulnerability events, and the vulnerability parameter is positively correlated with the second impact parameter. That is, the larger the second impact parameter, the larger the vulnerability parameter; conversely, the smaller the second impact parameter, the smaller the vulnerability parameter.

[0113] In this embodiment, vulnerability events are classified, and vulnerability parameters are determined based on the level of vulnerability to assess the likelihood of an account being attacked, thereby improving the accuracy and precision of vulnerability parameters.

[0114] Optionally, the computer device determines vulnerability parameters based on a second influence parameter of multiple vulnerability events. This includes: the computer device identifying target vulnerability events and non-target vulnerability events from the multiple vulnerability events. The target vulnerability event is the vulnerability event with the smallest sequence number, and the non-target vulnerability events are all other vulnerability events besides the target vulnerability event. The sequence number is obtained by arranging the multiple vulnerability events in descending order according to the second influence parameter. For each non-target vulnerability event, the computer device performs parameter transformation on the second influence parameter and sequence number of the non-target vulnerability event according to a vulnerability parameter transformation rule to obtain a third influence parameter. The vulnerability parameter transformation rule indicates that the third influence parameter is positively correlated with the second influence parameter and negatively correlated with the second influence parameter. The computer device then performs parameter transformation on the second influence parameter of the target vulnerability event and the third influence parameter of each non-target vulnerability event according to the vulnerability parameter transformation rule to obtain vulnerability parameters. The vulnerability parameter transformation rule indicates that the vulnerability parameters are positively correlated with both the second and third influence parameters.

[0115] In this embodiment, the target vulnerability event is the vulnerability event with the highest severity. Therefore, when determining vulnerability parameters based on the target vulnerability event, the second influence parameter of the target vulnerability event is directly considered, without considering the ranking of the target vulnerability event. For non-target vulnerability events, since the severity of non-target vulnerability events is relatively small, when determining vulnerability parameters based on non-target vulnerability events, the second influence parameter and the sequence number of the non-target vulnerability event are considered. Therefore, the computer device determines the third influence parameter based on the second influence parameter and the sequence number of the non-target vulnerability event. This is equivalent to using the sequence number of the non-target vulnerability event to weight the second influence parameter of the non-target vulnerability event to obtain the third influence parameter. The subsequent vulnerability parameters are determined based on the weighted third influence parameter.

[0116] In one possible implementation, for non-target vulnerable events, the computer device determines a convergence coefficient, which is the reciprocal of a value with base e and exponent of the sequence number of the non-target vulnerable event. The computer device determines an influence base, which is equal to the ratio of the second influence coefficient to the target value. The computer device determines an adjustment parameter, which is a value with base e as the number of vulnerable events and logarithm e as the influence base. The computer device determines a third influence parameter by multiplying the second influence parameter, the convergence coefficient, and the adjustment parameter. The computer device determines the vulnerability parameter by summing the second influence parameter of the target vulnerable event and the third influence parameter of each non-target vulnerable event. In this embodiment, the vulnerability parameter is determined in the above manner, so that the higher the vulnerability level and the greater the number of vulnerable events, the larger the vulnerability parameter, thereby accurately assessing the likelihood of an account being attacked and improving the precision and accuracy of the vulnerability parameter.

[0117] Optionally, the vulnerability level is divided into 8 levels, and the number of vulnerability events is n, where n is a positive integer. The second influence parameters of the n vulnerability events are arranged in descending order as a1, a2, a3...an.

[0118] The following formula is used to determine the vulnerability parameters of computer equipment.

[0119]

[0120] Where v represents the vulnerability parameter, i represents the sequence number of the vulnerability event, and ai represents the second influence parameter of the vulnerability event with sequence number i. For example, a1 represents the second influence parameter of the vulnerability event with sequence number 1, which is also the second influence parameter of the target vulnerability event. represents the convergence coefficient, and ai / represents the influence base. The vulnerability parameter obtained using the above formula has a value range of (0,10], with a minimum granularity of 0.01. e represents the natural constant.

[0121] In one possible implementation, the computer device determines the vulnerability parameter as the numerical value of the vulnerability level to which the vulnerable event belongs. Alternatively, when there are multiple vulnerable events, the computer device determines the vulnerability parameter as the average value of the vulnerability levels to which the multiple vulnerable events belong.

[0122] Based on the above possible implementation methods, it can be seen that the vulnerability parameter corresponding to the account is determined by the vulnerability event. By handling the vulnerability event associated with the account, the vulnerability parameter corresponding to the account can be reduced, and the vulnerability event with higher severity has a greater impact on the vulnerability parameter corresponding to the account.

[0123] It should also be noted that this application embodiment only illustrates the case of detecting a vulnerability event associated with an account. If no vulnerability event associated with an account is detected, the computer device determines the vulnerability parameter corresponding to the account as a preset character. This preset character indicates that no vulnerability event associated with the account has been detected; for example, the preset character is N / A. Specifically, if the vulnerability parameter corresponding to the account is 0, it means that the probability of the account being threatened by a vulnerability event is 0. If the vulnerability parameter corresponding to the account is N / A, it means that it is uncertain whether the account is threatened by a vulnerability event.

[0124] 305. Computer devices obtain the value information of an account. The value information represents the value of the account. The value information includes permission information and real-name information. Permission information represents the permissions that the account has, and real-name information refers to the information related to the user that is bound to the account.

[0125] In this embodiment of the application, the value of an account is measured by the account's permission information or real-name information, and the value of an account refers to the importance of the account.

[0126] In one possible implementation, the computer device is equipped with an information system for collecting account-related information, such as permission information and real-name information. This information system can be a B / S (Browser / Server) system or a C / S (Client / Server) system that has accounts.

[0127] 306. Computer equipment performs parameter conversion on value information according to the value parameter conversion rules to obtain value parameters, which represent the importance of the account.

[0128] The higher the account's value parameter, the greater the account's importance; the lower the account's value parameter, the less important the account.

[0129] In one possible implementation, the computer device performs parameter conversion on a first quantity indicated by permission information according to a value parameter conversion rule to obtain permission parameters. The value parameter conversion rule indicates that the permission parameters are positively correlated with the first quantity, where the first quantity represents the number of permissions the account possesses. Following the value parameter conversion rule, the device performs parameter conversion on a second quantity indicated by real-name information to obtain real-name parameters. The value parameter conversion rule indicates that the real-name parameters are positively correlated with the second quantity, where the second quantity represents the number of real-name items the account possesses, where each real-name item represents a piece of user-related information bound to the account. Finally, following the value parameter conversion rule, the device performs parameter conversion on both the permission parameters and the real-name parameters to obtain value parameters. The value parameter conversion rule indicates that the value parameters are positively correlated with both the permission parameters and the real-name parameters.

[0130] The more permissions an account has, the more important the account is, and the larger the permission parameter will be. Conversely, the fewer permissions an account has, the less important the account is, and the smaller the permission parameter will be. For example, if an account has system administration permissions, security and confidentiality permissions, and security audit permissions, and the account has only one type of permission, the permission parameter will be set to 1; if the account has only two types of permissions, the permission parameter will be set to 3; and if the account has only three types of permissions, the permission parameter will be set to 10.

[0131] The more real-name information an account has, the more complete the account is, and the higher the real-name parameter. Conversely, the fewer real-name information an account has, the less complete the account is, and the lower the real-name parameter. For example, account real-name status can be categorized as unverified, partially verified, and verified. Unverified means the account has only completed registration and possesses only virtual information such as a username, which cannot definitively identify the user. Partially verified means the account has been linked to contact information and an email address, providing clear identification. Verified means the account has undergone real-name verification, which can be achieved through various methods, such as linking the user's real name and ID card number. If an account is unverified, the real-name parameter is set to 1; if it is partially verified, the parameter is set to 3; and if it is verified, the parameter is set to 10.

[0132] Computer devices determine their value parameters based on permission parameters and real-name authentication parameters. Specifically, a larger permission parameter results in a larger value parameter, and a smaller permission parameter results in a smaller value parameter. Similarly, a larger real-name authentication parameter results in a larger value parameter, and a smaller real-name authentication parameter results in a smaller value parameter.

[0133] In one possible implementation, the computer device determines the sum of the account's permission parameters and real-name authentication parameters, and then rounds down the ratio of this sum to 2 to obtain the account's value parameter. This method of determining the value parameter ensures that the more permissions and real-name authentication items an account has, the higher its value parameter will be. Furthermore, it constrains the account's value parameter to a specific value, facilitating subsequent processing and reducing computational load.

[0134] Optionally, the computer device uses the following formula to determine the account's value parameters.

[0135] Value = round((e impot +e Integrity ) / 2)

[0136] Among them, e impot This indicates the account's permission parameters, such as values ​​of 1, 3, or 10. Integrity This represents the account's real-name authentication parameter, for example, the real-name authentication parameter can be 1, 3 or 10. Value represents the value parameter, for example, the value parameter can be an integer between 1 and 10.

[0137] 307. The computer equipment performs parameter conversion on alarm parameters, vulnerability parameters, and value parameters according to the risk parameter conversion rules to obtain risk parameters. The risk parameters are the risk detection results. The risk parameter conversion rules indicate that the risk parameters are positively correlated with alarm parameters, vulnerability parameters, and value parameters.

[0138] After determining the alarm parameters, vulnerability parameters, and value parameters, the computer equipment transforms these parameters according to risk parameter conversion rules to obtain the risk parameter, which is the risk detection result. This risk parameter measures the degree of risk faced by the account based on the alarm events, vulnerability events, and account value information associated with the account. The higher the risk parameter, the higher the degree of risk faced by the account; the lower the risk parameter, the lower the degree of risk faced by the account. Specifically, the lower the alarm parameters, vulnerability parameters, and value parameters, the lower the risk parameter; and the higher the alarm parameters, vulnerability parameters, and value parameters, the higher the risk parameter.

[0139] In one possible implementation, the computer device performs parameter conversion on the alarm parameter and vulnerability parameter according to risk parameter conversion rules to obtain a first risk parameter, which represents the probability that the account will be attacked. The computer device then performs parameter conversion on the vulnerability parameter and value parameter according to the same rules to obtain a second risk parameter, which represents the severity of the loss suffered by the account after being attacked. Finally, the computer device performs parameter conversion based on the first and second risk parameters according to the risk parameter conversion rules to obtain the account's overall risk parameters.

[0140] Optionally, the computer device uses the following formula to determine the first risk parameter: Where P represents the first risk parameter, T represents the alarm parameter, and V represents the vulnerability parameter. The values ​​of T and V are integers between 0 and 10, and the value of P is in the range of (0, 10] with a precision of 0.01.

[0141] Optionally, the computer device uses the following formula to determine the second risk parameter: Where L represents the second risk parameter, V represents the vulnerability parameter, and Value represents the value parameter. Value and V are integers between 0 and 10, and L is in the range of (0, 10] with a precision of 0.01.

[0142] In one possible implementation, the computer device determines the risk parameters in the following manner after determining at least one of alarm parameters, vulnerability parameters, or value parameters.

[0143] (1) When the computer device obtains alarm parameters, vulnerability parameters, and value parameters, the computer device takes the square root of the product of the alarm parameters and the value parameters to obtain a first value, takes the square root of the product of the vulnerability parameters and the value parameters to obtain a second value, and determines the product of the first value and the second value as the risk parameter. Optionally, the computer device uses the following formula to determine the risk parameter.

[0144]

[0145] Where R represents the risk parameter, T represents the alarm parameter, V represents the vulnerability parameter, and Value represents the value parameter.

[0146] (2) If the computer device only obtains vulnerability parameters and value parameters, but not alarm parameters, the computer device determines the risk parameter as the product of the vulnerability parameters and value parameters. Optionally, the computer device uses the following formula to determine the risk parameter.

[0147] R = V * Value

[0148] Where R represents the risk parameter, represents the vulnerability parameter, and Value represents the value parameter.

[0149] (3) If the computer device only obtains alarm parameters and value parameters, but not vulnerability parameters, the computer device determines the risk parameter as the product of the alarm parameters and value parameters. Optionally, the computer device uses the following formula to determine the risk parameter.

[0150] R = T * Value

[0151] Where R represents the risk parameter, represents the alarm parameter, and Value represents the value parameter.

[0152] (4) If the computer device does not obtain alarm parameters and vulnerability parameters, the computer device will set the risk parameter to a preset character, such as N / A. Wherein, if the risk parameter corresponding to the account is 0, it means that the account is not facing any risk. If the risk parameter corresponding to the account is N / A, it means that the degree of risk faced by the account is uncertain.

[0153] The method provided in this application comprehensively considers the account's login behavior, login environment, and value information of the account itself when detecting whether an account is facing risks. It systematically analyzes information from three perspectives, enriching the influencing factors considered when detecting account risks. Furthermore, it evaluates the value of the account based on its permissions and real-name registration, making the information covered by account risk detection more comprehensive and improving the accuracy of account risk detection.

[0154] Figure 4 This is a flowchart of another account risk detection method provided in the embodiments of this application, such as... Figure 4 As shown, the method includes the following steps.

[0155] Step 1: Obtain alarm events from the risk control system and calculate alarm parameters based on the alarm events. Store the alarm parameters if the calculation is successful, and record a failure message if the calculation fails. The risk control system detects alarm events. The computer equipment identifies the alarm events associated with the account from the alarm events detected by the risk control system and converts the parameters according to the alarm parameter conversion rules to obtain the alarm parameters. Optionally, if no alarm event associated with the account is detected, the calculation of the alarm parameters is deemed unsuccessful due to the lack of data required for calculation.

[0156] Step 2: Retrieve vulnerability events from the device management system and calculate vulnerability parameters based on these events. Store the vulnerability parameters if the calculation is successful, and record a failure message if the calculation fails. The device management system detects vulnerability events. The computer device identifies the vulnerability events associated with the account from those detected by the system and performs parameter conversion according to the vulnerability parameter conversion rules to determine the vulnerability level of the vulnerability event, thus obtaining the vulnerability parameters. Optionally, if no vulnerability events associated with the account are detected, the calculation of the vulnerability parameters is deemed unsuccessful due to the lack of data required for calculation.

[0157] Step 3: Obtain value information from the information system and calculate value parameters based on the value information. Store the value parameter if the calculation is successful, and record a failure message if the calculation fails. The information system collects account value information, and the computer device obtains the account's value information from the device management system and performs parameter conversion according to the value parameter conversion rules to obtain the value parameters. Optionally, if the account's value information is not obtained, the calculation of the value parameter is directly determined to be unsuccessful due to the lack of data required for calculation.

[0158] Step 4: Calculate the risk parameters based on the alarm parameters, vulnerability parameters, and value parameters. The computer equipment performs parameter conversion on the alarm parameters, vulnerability parameters, and value parameters according to the risk parameter conversion rules to obtain the risk parameters.

[0159] In this embodiment, the login behavior, login environment, and value information of an account are analyzed through complex data collection to detect account risks. This method has strong versatility and is applicable to accounts registered in various systems, resulting in more accurate risk detection results.

[0160] Figure 5 This is a schematic diagram of the structure of an account risk detection device provided in an embodiment of this application. See also... Figure 5 The device includes:

[0161] The alarm event detection module 501 is used to detect alarm events associated with an account, which refers to an event in which the login behavior of the account is abnormal.

[0162] The vulnerability event detection module 502 is used to detect vulnerability events associated with the account. A vulnerability event refers to an event that poses a security risk in the login environment of the account.

[0163] The information acquisition module 503 is used to acquire the value information of the account, which represents the value of the account. The value information includes at least one of permission information or real-name information. The permission information represents the permissions that the account has, and the real-name information refers to the user-related information bound to the account.

[0164] Risk detection module 504 is used to determine the risk detection result of the account by assessing the severity of the alarm event, the severity of the vulnerability event, and the importance of the valuable information. The risk detection result indicates the level of risk faced by the account.

[0165] The account risk detection device provided in this application comprehensively considers the account's login behavior, login environment, and value information of the account itself when detecting whether an account is facing risks. It systematically analyzes information from three perspectives, enriching the influencing factors considered when detecting account risks. Furthermore, it evaluates the value of the account based on the account's permissions and real-name registration, making the information covered by account risk detection more comprehensive and improving the accuracy of account risk detection.

[0166] Optionally, see Figure 6 The risk detection module 504 includes:

[0167] The alarm parameter determination unit 514 is used to convert the alarm level to which the alarm event belongs according to the alarm parameter conversion rule to obtain alarm parameters. The alarm parameters represent the severity of the alarm event, and the alarm parameter conversion rule indicates that the alarm parameters are positively correlated with the alarm level.

[0168] The vulnerability parameter determination unit 524 is used to perform parameter transformation on the vulnerability level to which the vulnerability event belongs according to the vulnerability parameter transformation rule to obtain the vulnerability parameter. The vulnerability parameter represents the severity of the vulnerability event, and the vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the vulnerability level.

[0169] The value parameter determination unit 534 is used to perform parameter conversion on the value information according to the value parameter conversion rule to obtain the value parameter, which represents the importance of the account.

[0170] The risk parameter determination unit 544 is used to perform parameter transformation on the alarm parameter, the vulnerability parameter and the value parameter according to the risk parameter transformation rule to obtain the risk parameter. The risk parameter is the risk detection result. The risk parameter transformation rule indicates that the risk parameter is positively correlated with the alarm parameter, the vulnerability parameter and the value parameter.

[0171] Optionally, see Figure 6 The number of alarm events is multiple, and the alarm parameter determination unit 514 is used for:

[0172] The alarm level corresponding to the event type to which the alarm event belongs is determined as the alarm level to which the alarm event belongs. Each alarm level corresponds to at least one event type.

[0173] For each alarm level, the alarm level value and the number of alarm events belonging to the alarm level are converted according to the alarm parameter conversion rule to obtain the first influence parameter of the alarm level. The alarm parameter conversion rule indicates that the first influence parameter is positively correlated with the level value and the number. The first influence parameter represents the degree of influence of the alarm events belonging to the alarm level.

[0174] According to the alarm parameter conversion rule, the sum of the first influence parameters of multiple alarm levels is converted to obtain the alarm parameter. The alarm parameter conversion rule indicates that the alarm parameter is positively correlated with the sum of the influence parameters of the multiple alarm levels.

[0175] Optionally, see Figure 6 The number of vulnerable events is multiple, and the vulnerability parameter determination unit 524 is used for:

[0176] The vulnerability level corresponding to the event type to which the vulnerability event belongs is determined as the vulnerability level to which the vulnerability event belongs. Each vulnerability level corresponds to at least one event type.

[0177] According to the vulnerability parameter conversion rule, the level values ​​of the vulnerability levels to which multiple vulnerable events belong are converted to obtain the second impact parameters of multiple vulnerable events. The vulnerability parameter conversion rule indicates that the second impact parameters are positively correlated with the level values, and the second impact parameters represent the degree of impact of the vulnerable event.

[0178] According to the vulnerability parameter transformation rule, the second impact parameters of multiple vulnerable events are transformed to obtain the vulnerability parameter. The vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second impact parameter.

[0179] Optionally, see Figure 6 The vulnerability parameter determination unit 524 is used for:

[0180] Among multiple vulnerable events, the target vulnerable event and the non-target vulnerable event are identified. The target vulnerable event is the vulnerable event with the smallest sequence number, and the non-target vulnerable event is any vulnerable event other than the target vulnerable event. The sequence number is obtained by arranging the multiple vulnerable events in descending order according to the second influence parameter.

[0181] For each non-target vulnerable event, according to the vulnerability parameter transformation rule, the second influence parameter and the sequence number of the non-target vulnerable event are transformed to obtain the third influence parameter. The vulnerability parameter transformation rule indicates that the third influence parameter is positively correlated with the second influence parameter and negatively correlated with the third influence parameter.

[0182] According to the vulnerability parameter transformation rule, the second influence parameter of the target vulnerability event and the third influence parameter of each non-target vulnerability event are transformed to obtain the vulnerability parameter. The vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second influence parameter and the third influence parameter.

[0183] Optionally, see Figure 6 The value information includes the permission information and the real-name information; the value parameter determination unit 534 is used for:

[0184] According to the value parameter conversion rule, the first quantity indicated by the permission information is converted to obtain the permission parameter. The value parameter conversion rule indicates that the permission parameter is positively correlated with the first quantity, and the first quantity represents the number of permissions that the account has.

[0185] According to the value parameter conversion rule, the second quantity indicated by the real-name information is converted to obtain the real-name parameter. The value parameter conversion rule indicates that the real-name parameter is positively correlated with the second quantity. The second quantity represents the number of real-name items that the account has. A real-name item represents a type of information related to the user that is bound to the account.

[0186] According to the value parameter conversion rule, the permission parameter and the real name parameter are converted to obtain the value parameter. The value parameter conversion rule indicates that the value parameter is positively correlated with the permission parameter and the real name parameter.

[0187] Optionally, see Figure 6 The vulnerability event detection module 502 is used for:

[0188] The device operation logs associated with this account identify events that indicate security vulnerabilities on the devices logged into that account; these logs are the operation logs of the devices logged into this account. Alternatively,

[0189] The client operation log associated with the account identifies events that indicate security vulnerabilities in the client that logged into the account. This client operation log is the operation log of the client that logged into the account.

[0190] Optionally, see Figure 6 The alarm event detection module 501 is used for:

[0191] Detect candidate alarm events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time.

[0192] Determine the current event status of any detected candidate alarm event, which includes processed and unprocessed status;

[0193] Among the detected candidate alarm events, identify the alarm events that are in the unprocessed state.

[0194] Optionally, see Figure 6 The vulnerability event detection module 502 is used for:

[0195] Detect candidate vulnerable events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time.

[0196] Determine the current event state of any detected candidate vulnerability event, including processed and unprocessed states;

[0197] Among the detected candidate vulnerable events, identify the vulnerable events that are in the unprocessed state.

[0198] It should be noted that the account risk detection device provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the computer device can be divided into different functional modules to complete all or part of the functions described above. In addition, the account risk detection device and the account risk detection method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0199] This application also provides a computer device, which includes a processor and a memory. The memory stores at least one computer program, which is loaded and executed by the processor to perform the operations performed in the account risk detection method of the above embodiments.

[0200] Optionally, the computer device is provided as a terminal. Figure 7 A schematic diagram of the structure of a terminal 700 provided in an exemplary embodiment of this application is shown.

[0201] Terminal 700 includes a processor 701 and a memory 702.

[0202] Processor 701 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. Processor 701 may be implemented using at least one hardware form selected from DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). Processor 701 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 701 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, processor 701 may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.

[0203] The memory 702 may include one or more computer-readable storage media, which may be non-transitory. The memory 702 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, the non-transitory computer-readable storage media in the memory 702 are used to store at least one computer program, which is used by the processor 701 to implement the account risk detection method provided in the method embodiments of this application.

[0204] In some embodiments, the terminal 700 may also optionally include a peripheral device interface 703 and at least one peripheral device. The processor 701, memory 702, and peripheral device interface 703 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 703 via a bus, signal line, or circuit board. Optionally, the peripheral device includes at least one of a radio frequency circuit 704, a display screen 705, a camera assembly 706, and an audio circuit 707.

[0205] Peripheral device interface 703 can be used to connect at least one I / O (Input / Output) related peripheral device to processor 701 and memory 702. In some embodiments, processor 701, memory 702 and peripheral device interface 703 are integrated on the same chip or circuit board; in some other embodiments, any one or two of processor 701, memory 702 and peripheral device interface 703 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.

[0206] The radio frequency (RF) circuit 704 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 704 communicates with communication networks and other communication devices via electromagnetic signals. The RF circuit 704 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. Optionally, the RF circuit 704 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The RF circuit 704 can communicate with other devices through at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: metropolitan area networks (MANs), various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks (WLANs), and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF circuit 704 may also include circuitry related to NFC (Near Field Communication), which is not limited in this application.

[0207] Display screen 705 is used to display a UI (User Interface). This UI may include graphics, text, icons, videos, and any combination thereof. When display screen 705 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 701 for processing. In this case, display screen 705 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 705, disposed on the front panel of terminal 700; in other embodiments, there may be at least two display screens 705, disposed on different surfaces of terminal 700 or in a folded design; in other embodiments, display screen 705 may be a flexible display screen, disposed on a curved or folded surface of terminal 700. Furthermore, display screen 705 may be configured as a non-rectangular irregular shape, i.e., a non-rectangular screen. Display screen 705 may be made of materials such as LCD (Liquid Crystal Display) or OLED (Organic Light-Emitting Diode).

[0208] The camera assembly 706 is used to acquire images or videos. Optionally, the camera assembly 706 includes a front-facing camera and a rear-facing camera. The front-facing camera is disposed on the front panel of the terminal 700, and the rear-facing camera is disposed on the back of the terminal 700. In some embodiments, there are at least two rear-facing cameras, which are any one of a main camera, a depth-sensing camera, a wide-angle camera, and a telephoto camera, to achieve background blurring by fusion of the main camera and the depth-sensing camera, panoramic shooting by fusion of the main camera and the wide-angle camera, VR (Virtual Reality) shooting, or other fusion shooting functions. In some embodiments, the camera assembly 706 may also include a flash. The flash may be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cool light flash, which can be used for light compensation at different color temperatures.

[0209] The audio circuit 707 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, converting the sound waves into electrical signals that are input to the processor 701 for processing, or input to the radio frequency circuit 704 for voice communication. For stereo sound acquisition or noise reduction purposes, multiple microphones may be used, each located at a different part of the terminal 700. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert the electrical signals from the processor 701 or the radio frequency circuit 704 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into audible sound waves but also into inaudible sound waves for purposes such as distance measurement. In some embodiments, the audio circuit 707 may also include a headphone jack.

[0210] Those skilled in the art will understand that Figure 7 The structure shown does not constitute a limitation on terminal 700, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.

[0211] Optionally, the computer device is provided as a server. Figure 8 This is a schematic diagram of a server structure provided in an embodiment of this application. The server 800 can vary significantly due to different configurations or performance. It may include one or more Central Processing Units (CPUs) 801 and one or more memories 802. The memory 802 stores at least one computer program, which is loaded and executed by the processor 801 to implement the methods provided in the various method embodiments described above. Of course, the server may also have wired or wireless network interfaces, a keyboard, and input / output interfaces for input and output. The server may also include other components for implementing device functions, which will not be elaborated upon here.

[0212] This application also provides a computer-readable storage medium storing at least one computer program, which is loaded and executed by a processor to perform the operations of the account risk detection method described above.

[0213] This application also provides a computer program product, including a computer program loaded and executed by a processor to perform the operations performed by the account risk detection method of the above embodiments. In some embodiments, the computer program involved in this application may be deployed and executed on a single computer device, or on multiple computer devices located in one location, or on multiple computer devices distributed across multiple locations and interconnected via a communication network. These multiple computer devices distributed across multiple locations and interconnected via a communication network can constitute a blockchain system.

[0214] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0215] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present application should be included within the protection scope of the present application.

Claims

1. A method for detecting account risk, characterized in that, The method includes: The system detects alarm events associated with the account, where the alarm events are abnormal login behaviors of the account; it also detects vulnerability events associated with the account, where the vulnerability events are security risks in the login environment of the account; and it obtains the value information of the account, where the value information represents the value of the account and includes at least one of permission information or real-name information, where the permission information represents the permissions possessed by the account and the real-name information refers to user-related information bound to the account. A second influence parameter is determined for a plurality of vulnerable events, the second influence parameter representing the degree of influence of the vulnerable event; a target vulnerable event and a non-target vulnerable event are determined among the plurality of vulnerable events, the target vulnerable event being the vulnerable event with the smallest sequence number, and the non-target vulnerable events being the vulnerable events other than the target vulnerable event, the sequence number being obtained by arranging the plurality of vulnerable events in descending order according to the second influence parameter; According to the vulnerability parameter transformation rule, the second impact parameter and the sequence number of each of the non-target vulnerable events are transformed to obtain a third impact parameter. The vulnerability parameter transformation rule indicates that the third impact parameter is positively correlated with the second impact parameter and negatively correlated with the sequence number. According to the vulnerability parameter transformation rule, the second impact parameter of the target vulnerable event and the third impact parameter of each of the non-target vulnerable events are transformed to obtain a vulnerability parameter. The vulnerability parameter represents the severity of multiple vulnerable events. The vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with the second impact parameter and the third impact parameter. Based on the severity of the alarm event, the importance of the valuable information, and the vulnerability parameter, the risk detection result of the account is determined, and the risk detection result indicates the degree of risk faced by the account.

2. The method according to claim 1, characterized in that, The process of determining the risk detection result of the account based on the severity of the alarm event, the importance of the valuable information, and the vulnerability parameter includes: According to the alarm parameter conversion rule, the alarm level to which the alarm event belongs is converted to obtain alarm parameters. The alarm parameters represent the severity of the alarm event, and the alarm parameter conversion rule indicates that the alarm parameters are positively correlated with the alarm level. According to the value parameter conversion rules, the value information is converted to obtain value parameters, which represent the importance of the account. According to the risk parameter conversion rule, the alarm parameter, the vulnerability parameter, and the value parameter are converted to obtain the risk parameter, which is the risk detection result. The risk parameter conversion rule indicates that the risk parameter is positively correlated with the alarm parameter, the vulnerability parameter, and the value parameter.

3. The method according to claim 2, characterized in that, The number of alarm events is multiple. The alarm parameters are obtained by converting the alarm levels of the alarm events according to alarm parameter conversion rules, including: The alarm level corresponding to the event type to which the alarm event belongs is determined as the alarm level to which the alarm event belongs, and each alarm level corresponds to at least one event type; For each alarm level, the alarm level value and the number of alarm events belonging to the alarm level are converted according to the alarm parameter conversion rule to obtain the first influence parameter of the alarm level. The alarm parameter conversion rule indicates that the first influence parameter is positively correlated with the alarm level value and the number. The first influence parameter represents the degree of influence of the alarm events belonging to the alarm level. According to the alarm parameter conversion rule, the sum of the first influence parameters of multiple alarm levels is converted to obtain the alarm parameter. The alarm parameter conversion rule indicates that the alarm parameter is positively correlated with the sum of the influence parameters of the multiple alarm levels.

4. The method according to claim 1, characterized in that, The number of vulnerable events is multiple, and the determination of the second impact parameter of the multiple vulnerable events includes: The vulnerability level corresponding to the event type to which the vulnerability event belongs is determined as the vulnerability level to which the vulnerability event belongs, and each vulnerability level corresponds to at least one event type; According to the vulnerability parameter conversion rule, the level values ​​of the vulnerability levels to which the multiple vulnerability events belong are converted to obtain the second impact parameters of the multiple vulnerability events. The vulnerability parameter conversion rule indicates that the second impact parameters are positively correlated with the level values, and the second impact parameters represent the degree of impact of the vulnerability events.

5. The method according to claim 2, characterized in that, The value information includes the permission information and the real-name information; the step of converting the value information according to the value parameter conversion rules to obtain value parameters includes: According to the value parameter conversion rule, the first quantity indicated by the permission information is converted to obtain the permission parameter. The value parameter conversion rule indicates that the permission parameter is positively correlated with the first quantity, and the first quantity represents the number of permissions that the account has. According to the value parameter conversion rule, the second quantity indicated by the real-name information is converted to obtain the real-name parameter. The value parameter conversion rule indicates that the real-name parameter is positively correlated with the second quantity. The second quantity represents the number of real-name items that the account has. A real-name item represents a type of information related to the user that is bound to the account. According to the value parameter conversion rule, the permission parameter and the real name parameter are converted to obtain the value parameter. The value parameter conversion rule indicates that the value parameter is positively correlated with the permission parameter and the real name parameter.

6. The method according to any one of claims 1-5, characterized in that, The detection of vulnerable events associated with the account includes at least one of the following: The device operation log associated with the account is used to identify events that indicate a security vulnerability on the device logged into that account; the device operation log is the operation log of the device logged into the account; or, The client operation log associated with the account is used to identify events that indicate a security vulnerability in the client that logged into the account. The client operation log is the operation log of the client that logged into the account.

7. The method according to any one of claims 1-5, characterized in that, The detection of alarm events associated with the account includes: Detect candidate alarm events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point; Determine the current event state of any detected candidate alarm event, including a processed state and an unprocessed state; Among the detected candidate alarm events, the alarm events that are in the unprocessed state are identified.

8. The method according to any one of claims 1-5, characterized in that, The detection of vulnerable events associated with the account includes: Detect candidate vulnerable events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point; Determine the current event state of any detected candidate vulnerability event, the event state including a processed state and an unprocessed state; Among the detected candidate vulnerable events, the vulnerable events that are in the unprocessed state are identified.

9. An account risk detection device, characterized in that, The device includes: The alarm event detection module is used to detect alarm events associated with the account, wherein the alarm event is an event in which the login behavior of the account is abnormal; The vulnerability event detection module is used to detect vulnerability events associated with the account, where the vulnerability event is an event that indicates a security risk in the account's login environment; The information acquisition module is used to acquire the value information of the account, the value information representing the value of the account, the value information including at least one of permission information or real-name information, the permission information representing the permissions possessed by the account, and the real-name information referring to user-related information bound to the account; A risk detection module is used to determine a second impact parameter of multiple vulnerability events, the second impact parameter representing the degree of impact of the vulnerability event; and to determine a target vulnerability event and a non-target vulnerability event among the multiple vulnerability events, wherein the target vulnerability event is the vulnerability event with the smallest sequence number, and the non-target vulnerability event is the vulnerability event other than the target vulnerability event, and the sequence number is obtained by arranging the multiple vulnerability events in descending order according to the second impact parameter; The risk detection module is further configured to perform parameter transformation on the second impact parameter and sequence number of each non-target vulnerable event according to the vulnerability parameter transformation rule to obtain a third impact parameter. The vulnerability parameter transformation rule indicates that the third impact parameter is positively correlated with the second impact parameter and negatively correlated with the sequence number. The module is also configured to perform parameter transformation on the second impact parameter of the target vulnerable event and the third impact parameter of each non-target vulnerable event according to the vulnerability parameter transformation rule to obtain a vulnerability parameter. The vulnerability parameter represents the severity of multiple vulnerable events, and the vulnerability parameter transformation rule indicates that the vulnerability parameter is positively correlated with both the second impact parameter and the third impact parameter. The risk detection module is also used to determine the risk detection result of the account based on the severity of the alarm event, the importance of the value information, and the vulnerability parameter. The risk detection result indicates the degree of risk faced by the account.

10. The apparatus according to claim 9, characterized in that, The risk detection module includes: An alarm parameter determination unit is used to perform parameter conversion on the alarm level to which the alarm event belongs according to an alarm parameter conversion rule to obtain alarm parameters. The alarm parameters represent the severity of the alarm event, and the alarm parameter conversion rule indicates that the alarm parameters are positively correlated with the alarm level. The value parameter determination unit is used to perform parameter conversion on the value information according to the value parameter conversion rules to obtain value parameters, wherein the value parameters represent the importance of the account; The risk parameter determination unit is used to perform parameter transformation on the alarm parameter, the vulnerability parameter and the value parameter according to the risk parameter transformation rule to obtain the risk parameter, the risk parameter being the risk detection result, and the risk parameter transformation rule indicating that the risk parameter is positively correlated with the alarm parameter, the vulnerability parameter and the value parameter.

11. The apparatus according to claim 10, characterized in that, The number of alarm events is multiple, and the alarm parameter determination unit is used for: The alarm level corresponding to the event type to which the alarm event belongs is determined as the alarm level to which the alarm event belongs, and each alarm level corresponds to at least one event type; For each alarm level, according to the alarm parameter conversion rule, the level value of the alarm level and the number of alarm events belonging to the alarm level are converted to obtain the first influence parameter of the alarm level. The alarm parameter conversion rule indicates that the first influence parameter is positively correlated with the level value and the number. The first influence parameter represents the degree of influence of the alarm events belonging to the alarm level. According to the alarm parameter conversion rule, the sum of the first influence parameters of multiple alarm levels is converted to obtain the alarm parameter. The alarm parameter conversion rule indicates that the alarm parameter is positively correlated with the sum of the influence parameters of the multiple alarm levels.

12. The apparatus according to claim 9, characterized in that, The number of vulnerability events is multiple, and the risk detection module includes a vulnerability parameter determination unit, used for: The vulnerability level corresponding to the event type to which the vulnerability event belongs is determined as the vulnerability level to which the vulnerability event belongs, and each vulnerability level corresponds to at least one event type; According to the vulnerability parameter conversion rule, the level values ​​of the vulnerability levels to which the multiple vulnerability events belong are converted to obtain the second impact parameters of the multiple vulnerability events. The vulnerability parameter conversion rule indicates that the second impact parameters are positively correlated with the level values, and the second impact parameters represent the degree of impact of the vulnerability events.

13. The apparatus according to claim 10, characterized in that, The value information includes the permission information and the real-name information; the value parameter determination unit is used for: According to the value parameter conversion rule, the first quantity indicated by the permission information is converted to obtain the permission parameter. The value parameter conversion rule indicates that the permission parameter is positively correlated with the first quantity, and the first quantity represents the number of permissions that the account has. According to the value parameter conversion rule, the second quantity indicated by the real-name information is converted to obtain the real-name parameter. The value parameter conversion rule indicates that the real-name parameter is positively correlated with the second quantity. The second quantity represents the number of real-name items that the account has. A real-name item represents a type of information related to the user that is bound to the account. According to the value parameter conversion rule, the permission parameter and the real name parameter are converted to obtain the value parameter. The value parameter conversion rule indicates that the value parameter is positively correlated with the permission parameter and the real name parameter.

14. The apparatus according to any one of claims 9-13, characterized in that, The vulnerability event detection module is used for: The device operation log associated with the account is used to identify events that indicate a security vulnerability on the device logged into that account; the device operation log is the operation log of the device logged into the account; or, The client operation log associated with the account is used to identify events that indicate a security vulnerability in the client that logged into the account. The client operation log is the operation log of the client that logged into the account.

15. The apparatus according to any one of claims 9-13, characterized in that, The alarm event detection module is used for: Detect candidate alarm events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point; Determine the current event state of any detected candidate alarm event, including a processed state and an unprocessed state; Among the detected candidate alarm events, the alarm events that are in the unprocessed state are identified.

16. The apparatus according to any one of claims 9-13, characterized in that, The vulnerability event detection module is used for: Detect candidate vulnerable events associated with the account within a preset time period, where the preset time period refers to the time period within a preset duration before the current time point; Determine the current event state of any detected candidate vulnerability event, including a processed state and an unprocessed state; Among the detected candidate vulnerable events, the vulnerable events that are in the unprocessed state are identified.

17. A computer device, characterized in that, The computer device includes a processor and a memory, the memory storing at least one computer program, which is loaded and executed by the processor to perform the operations of the account risk detection method as described in any one of claims 1 to 8.

18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to perform the operations of the account risk detection method as described in any one of claims 1 to 8.

19. A computer program product, comprising a computer program, characterized in that, The computer program is loaded and executed by a processor to perform the operations of the account risk detection method as described in any one of claims 1 to 8.