Content attack processing method and apparatus, storage medium, and electronic device
By automatically detecting and blocking the information publishing behavior of target users, the problem of poor real-time performance in the identification and processing of content attacks in existing technologies has been solved. This enables real-time and automated content attack processing, reducing platform security risks and improving processing efficiency.
Patent Information
- Application Number
- CN202211740863.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2042-12-30
AI Technical Summary
Existing technologies have poor real-time capabilities for identifying and processing content attacks, requiring significant manpower and time, resulting in high platform security risks.
By automatically detecting the information posting behavior of target users, determining whether they meet the preset user violation conditions, and if so, blocking them, including determining the violation assessment results of business lines and user violations, the system achieves automated content attack identification and processing.
It enables real-time identification and processing of content attacks, reducing platform security risks, saving manpower, and improving processing efficiency.
Smart Images

Figure CN115987679B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a content attack processing method and device, a storage medium and an electronic device. BACKGROUND
[0002] With the development of information technology, various enterprises and institutions usually provide various information publishing platforms to users, such as forums, exchange blocks of clients, video platforms and the like. In the operation process of the information publishing platform, content attack initiated by network water army is one of common attack behaviors. The content attack refers to that a malicious user publishes a large amount of spam content or publishes a large amount of spam content, so as to cause a large amount of garbage content or illegal content on the platform.
[0003] At present, the staff usually queries the information publishing content in each platform in the database regularly to check whether there is an exception in the publishing content or quantity, so as to determine whether the content attack is suffered. If the content attack is suffered, the manual processing is performed, such as manually shielding the user and the like.
[0004] With the change of Internet environment, the frequency of content attack is higher and higher. Based on the existing processing mode, the staff only performs attack identification manually at the predetermined time, which is difficult to identify the content attack behavior in real time, the real-time performance of attack processing is poor, and the security risk of the platform is high. Secondly, for the identification and processing of the attack, a large amount of manpower and time is consumed, and the processing efficiency is low. SUMMARY
[0005] Therefore, the embodiments of the present application provide a content attack processing method to solve the problem that the content attack needs to be identified and processed manually in the existing processing mode, the real-time performance is poor, the risk is high, and the time and labor are consumed.
[0006] The embodiments of the present application also provide a content attack processing device to ensure the implementation and application of the above method in practice.
[0007] To achieve the above object, the embodiments of the present application provide the following technical scheme:
[0008] A content attack processing method comprises:
[0009] In the case of needing to perform content attack detection, a target user to be detected is determined;
[0010] A plurality of information publishing behaviors corresponding to the target user are determined;
[0011] A business line set corresponding to the target user is determined, and the business line set comprises at least one publishing business line;
[0012] In the plurality of information publishing behaviors, each information publishing behavior corresponding to each of the publishing business lines is determined;
[0013] For each of the publishing business lines, a violation assessment result corresponding to the publishing business line is determined according to the information publishing behaviors corresponding to the publishing business line, and the violation assessment result represents whether the publishing business line meets a preset business line violation condition;
[0014] According to the violation assessment results corresponding to each of the publishing business lines, it is determined whether the target user meets a preset user violation condition;
[0015] If the target user meets the preset user violation condition, the target user is determined as a violation user initiating content attack;
[0016] The violation user is subjected to a containment treatment, and a content attack processing process is completed.
[0017] The above method can optionally include the following steps:
[0018] A preset quantity threshold corresponding to the publishing business line is determined;
[0019] An information publishing quantity corresponding to the publishing business line is determined, and the information publishing quantity is the total number of the information publishing behaviors corresponding to the publishing business line;
[0020] The information publishing quantity and the preset quantity threshold are compared in size;
[0021] If the information publishing quantity is greater than the preset quantity threshold, a first preset result is taken as the violation assessment result corresponding to the publishing business line, and the first preset result represents that the publishing business line meets the preset business line violation condition.
[0022] The above method can optionally include the following steps:
[0023] If the information publishing quantity is less than or equal to the preset quantity threshold, a second preset result is taken as the violation assessment result corresponding to the publishing business line, and the second preset result represents that the publishing business line does not meet the preset business line violation condition.
[0024] The above method can optionally include the following steps:
[0025] It is determined whether there is at least one violation assessment result corresponding to the publishing business line, which represents that the publishing business line meets the preset business line violation condition.
[0026] If at least one of the publishing business lines corresponding to the violation assessment result represents that the publishing business line meets the preset business line violation condition, it is determined that the target user meets the preset user violation condition.
[0027] The above method, optionally, further comprises:
[0028] If each of the publishing business lines corresponding to the violation assessment result represents that the publishing business line does not meet the preset business line violation condition, it is determined that the target user does not meet the preset user violation condition.
[0029] The above method, optionally, the containment processing of the user in violation comprises:
[0030] According to the plurality of information publishing behaviors corresponding to the user in violation, a target violation type corresponding to the user in violation is determined from a plurality of preset violation types;
[0031] A target containment level corresponding to the target violation type is determined from a plurality of preset containment levels;
[0032] A account containment operation corresponding to the target containment level is determined;
[0033] The account containment operation is executed for the user in violation to achieve containment processing of the user in violation.
[0034] The above method, optionally, further comprises:
[0035] Published information corresponding to the user in violation is determined in a database;
[0036] The published information corresponding to the user in violation is deleted in the database.
[0037] A content attack processing apparatus, comprising:
[0038] A first determination unit configured to determine a target user to be detected in a case where content attack detection is required;
[0039] A second determination unit configured to determine a plurality of information publishing behaviors corresponding to the target user;
[0040] A third determination unit configured to determine a business line set corresponding to the target user, the business line set comprising at least one publishing business line;
[0041] A fourth determination unit configured to determine, in the plurality of information publishing behaviors, each information publishing behavior corresponding to each of the publishing business lines;
[0042] The fifth determining unit is configured to determine, for each of the publishing business lines, a violation evaluation result corresponding to the publishing business line according to the information publishing behaviors corresponding to the publishing business line, the violation evaluation result indicating whether the publishing business line meets a preset business line violation condition;
[0043] The judging unit is configured to judge whether the target user meets a preset user violation condition according to the violation evaluation results corresponding to the publishing business lines.
[0044] The sixth determining unit is configured to determine the target user as a violation user initiating a content attack if the target user meets the preset user violation condition.
[0045] The containment unit is configured to perform containment processing on the violation user to complete a content attack processing procedure.
[0046] A storage medium includes stored instructions, wherein the instructions, when executed, control a device in which the storage medium is located to perform the content attack processing method described above.
[0047] An electronic device includes a memory and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to perform the content attack processing method described above.
[0048] The content attack processing method provided by the embodiment of the present application includes: determining a target user to be detected in a case where content attack detection is needed; determining a plurality of information publishing behaviors corresponding to the target user; determining a business line set corresponding to the target user, wherein the business line set includes at least one publishing business line; determining, in the plurality of information publishing behaviors, each information publishing behavior corresponding to each publishing business line; determining, for each publishing business line, a violation evaluation result corresponding to the publishing business line according to the information publishing behaviors corresponding to the publishing business line, the violation evaluation result indicating whether the publishing business line meets a preset business line violation condition; judging whether the target user meets a preset user violation condition according to the violation evaluation results; determining the target user as a violation user initiating a content attack if the target user meets the preset user violation condition; and performing containment processing on the violation user to complete a content attack processing procedure. The method provided by the embodiment of the present application can automatically collect information publishing behaviors of a user, judge whether the user is a violation user initiating a content attack based on the information publishing behaviors, and automatically contain the violation user. The method can identify a user initiating a content attack in real time during the running of an information publishing platform and perform containment processing on the user, thereby preventing a malicious user from continuing to initiate an attack. The real-time performance of the attack processing is good, which is conducive to reducing the security risk of the platform. The processing procedure does not need manual intervention, which can save manpower and time, and improve processing efficiency. Attached Figure Description
[0049] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0050] Figure 1 A flowchart illustrating a content attack handling method provided in an embodiment of the present invention;
[0051] Figure 2 Another method flowchart for a content attack handling method provided in an embodiment of the present invention;
[0052] Figure 3 This is a schematic diagram of the structure of a content attack processing device provided in an embodiment of the present invention;
[0053] Figure 4 This is another structural schematic diagram of a content attack processing device provided in an embodiment of the present invention;
[0054] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] In this application, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0057] This invention provides a method for handling content attacks. This method can be applied to a content attack defense system, and its execution entity can be the system's server. The method flowchart is shown below. Figure 1 As shown, it includes:
[0058] S101: In the case where content attack detection needs to be performed, a target user to be detected is determined;
[0059] In the method provided by the embodiment of the application, a time period for content attack detection can be set in advance, for example, detection is performed once every minute. The content attack defense system can collect all information publishing data on each information publishing platform in the organization in real time. When the detection time point is reached, the target user to be detected can be determined according to the information publishing situation in each information publishing platform in the organization. The user who publishes a large number of information on the platform in a predetermined time period can be marked as a target user, and if there are multiple target users, each target user can be identified through a subsequent process.
[0060] S102: A plurality of information publishing behaviors corresponding to the target user are determined;
[0061] In the method provided by the embodiment of the application, each information publishing behavior corresponding to the target user can be obtained from the information publishing data collected by the system, that is, the behavior of the target user publishing information on each information publishing platform. The information publishing behavior can specifically include user IP, information publishing time, information publishing channel, information type, and information content. The user IP refers to the IP address of the target user, the information publishing time refers to the time when the target user publishes the corresponding information, the information publishing channel refers to the business line of the target user publishing the corresponding information, for example, a video platform, a comment area of a video platform, website article publishing, a website article comment area, and the like. The information type refers to the form of the information published by the target user, for example, text, pictures, videos, and the like. The information content is the specific content of the information published by the target user, for example, published articles, comments, video files, and the like.
[0062] S103: A business line set corresponding to the target user is determined, and the business line set includes at least one publishing business line;
[0063] In the method provided by the embodiment of the present application, according to the information publishing channel corresponding to each information publishing behavior, the publishing business line involved by the target user is integrated, the publishing business line represents a business line involved in information publishing, and the specific type content can be the same as the information publishing channel, which can refer to the examples of the information publishing channel in the foregoing. For example, the target user has thirty information publishing behaviors, ten information publishing behaviors of which are in the comment area of a video platform, and twenty information publishing behaviors of which are in the comment area of a website article, so that the target user is involved in two publishing business lines, namely, the comment area of the video platform and the comment area of the website article. All the publishing business lines involved by the target user form a business line set. The publishing business line involved by the target user can be only one (publishing information through only one channel) or multiple (publishing information through multiple channels), which is determined by the actual information publishing situation and does not affect the function of the method provided by the embodiment of the present application.
[0064] S104: determining, in the plurality of information publishing behaviors, each information publishing behavior corresponding to each publishing business line;
[0065] In the method provided by the embodiment of the present application, for each publishing business line, the publishing business line can be compared with the information publishing channel of each information publishing behavior respectively, if the information publishing channel currently compared matches the publishing business line, the information publishing behavior corresponding to the information publishing channel is determined as the information publishing behavior corresponding to the publishing business line. The information publishing behavior corresponding to each publishing business line is the information publishing behavior of the target user in the publishing business line.
[0066] It should be noted that in the specific implementation process, the information publishing behavior corresponding to the publishing business line can be multiple or only one, which is determined by the actual publishing situation and does not affect the function of the method provided by the embodiment of the present application.
[0067] S105: for each publishing business line, determining a rule violation evaluation result corresponding to the publishing business line according to each information publishing behavior corresponding to the publishing business line, the rule violation evaluation result representing whether the publishing business line meets a preset business line rule violation condition;
[0068] In the method provided by the embodiment of the present application, the business line rule violation condition can be set in advance according to the actual detection requirement, when the information publishing data of the user in a publishing business line meets the condition requirement, it is considered that the user has a rule violation behavior in the publishing business line and has the possibility of content attack. Specifically, the business line rule violation condition can be set based on the information publishing quantity, for example, the quantity reaching a threshold value is considered to meet the condition, the business line rule violation condition can be set based on the information content, for example, the information content containing a preset keyword is considered to meet the condition, and the like.
[0069] In the method provided by the embodiment of the application, whether each publishing business line meets the preset business line violation condition can be determined according to each information publishing behavior corresponding to each publishing business line, and the determination result of each publishing business line is used as a violation evaluation result corresponding to each publishing business line, and each violation evaluation result represents whether the corresponding publishing business line meets the preset business line violation condition, that is, the violation evaluation result indicates that the publishing business line meets the preset business line violation condition or the publishing business line does not meet the preset business line violation condition.
[0070] S106: determining whether the target user meets a preset user violation condition according to the violation evaluation result corresponding to each publishing business line;
[0071] In the method provided by the embodiment of the application, the user violation condition can be set according to actual detection requirements, and when the violation evaluation result corresponding to each publishing business line of the user meets the condition requirement, it is considered that the user has a violation behavior, and the behavior belongs to content attack. For example, the condition can be set based on the number of violation evaluation results representing that the publishing business line meets the business line violation condition.
[0072] In the method provided by the embodiment of the application, whether the target user meets the preset user violation condition can be determined based on the result content of each violation evaluation result.
[0073] S107: if the target user meets the preset user violation condition, the target user is determined as a violation user initiating content attack;
[0074] In the method provided by the embodiment of the application, if it is determined that the target user meets the preset user violation condition, the target user is marked as a violation user, and the violation user is a malicious user identified as initiating content attack.
[0075] If the target user does not meet the preset user violation condition, it is considered that the target user does not have a violation behavior, the target user is not marked, does not need to be processed, and the processing process is ended.
[0076] S108: performing containment processing on the violation user to complete the content attack processing process.
[0077] In the method provided by the embodiment of the application, the violation user (that is, the target user determined as a violation user) can be subjected to containment processing according to a preset containment strategy, for example, account mute, IP ban, and the like.
[0078] Based on the method provided in this embodiment of the invention, when content attack detection is required, the following steps are taken: First, a target user to be detected is identified. Then, multiple information publishing behaviors and a set of business lines corresponding to the target user are determined, with the business line set including at least one publishing business line. Within each information publishing behavior, the information publishing behavior corresponding to each publishing business line is determined. For each publishing business line, based on the various information publishing behaviors corresponding to that publishing business line, a violation assessment result is determined, indicating whether the publishing business line meets preset business line violation conditions. Based on each violation assessment result, it is determined whether the target user meets preset user violation conditions. If so, the target user is identified as a violating user initiating a content attack. The violating user is then blocked, completing the content attack handling process. Applying the method provided in this embodiment of the invention, user information publishing behaviors can be automatically collected, and based on these behaviors, it can be determined whether the user is a violating user initiating a content attack, and the violating user can be automatically blocked. Users initiating content attacks can be identified and blocked in real-time during the operation of the information publishing platform, preventing malicious users from continuing to launch attacks. The real-time nature of the attack handling is good, which helps reduce the platform's security risks. The process requires no human intervention, saving manpower and time, and improving processing efficiency.
[0079] exist Figure 1 Based on the method shown, this embodiment of the invention provides another method for handling content attacks, see reference. Figure 2 The flowchart shown illustrates the process in step S105 of the method provided in this embodiment of the invention, which involves determining the violation assessment result corresponding to each information publishing behavior of the publishing business line. This process includes:
[0080] S201: Determine the preset quantity threshold corresponding to this release business line;
[0081] In the method provided by this invention, a preset quantity threshold is pre-set for each of all publishing service lines involved in the system. Different publishing service lines may have different preset quantity thresholds, set according to actual business needs. The preset quantity threshold corresponding to the current publishing service line can be determined from the pre-set information.
[0082] S202: Determine the number of information releases corresponding to the release business line, wherein the number of information releases is the total number of all information release behaviors corresponding to the release business line;
[0083] In the method provided by the embodiments of the present invention, the number of information publishing behaviors corresponding to the current publishing business line is counted, that is, the total number of information publishing behaviors corresponding to the publishing business line is counted, and the statistical result is used as the number of information publishing behaviors corresponding to the publishing business line.
[0084] S203: comparing the information publishing quantity with the preset quantity threshold;
[0085] In the method provided by the embodiment of the application, the information publishing quantity corresponding to the current publishing business line is compared with the corresponding preset quantity threshold, and the comparison can be realized by a product method or a difference method.
[0086] S204: if the information publishing quantity is greater than the preset quantity threshold, a first preset result is taken as the violation evaluation result corresponding to the publishing business line, and the first preset result represents that the publishing business line meets the preset business line violation condition.
[0087] In the method provided by the embodiment of the application, two evaluation results are preset, the first preset result represents that the publishing business line meets the preset business line violation condition, and the second preset result represents that the publishing business line does not meet the preset business line violation condition. If the information publishing quantity is greater than the preset quantity threshold, the first preset result is determined as the violation evaluation result corresponding to the current publishing business line, that is, the violation evaluation result corresponding to the publishing business line represents that the publishing business line meets the preset business line violation condition.
[0088] On the basis of the method provided in the above embodiment, the method provided by the embodiment of the application further comprises:
[0089] If the information publishing quantity is less than or equal to the preset quantity threshold, a second preset result is taken as the violation evaluation result corresponding to the publishing business line, and the second preset result represents that the publishing business line does not meet the preset business line violation condition.
[0090] In the method provided by the embodiment of the application, if the information publishing quantity does not exceed the preset quantity threshold, the second preset result is determined as the violation evaluation result corresponding to the current publishing business line, that is, the violation evaluation result corresponding to the publishing business line represents that the publishing business line does not meet the preset business line violation condition.
[0091] In Figure 1 On the basis of the method shown in the above embodiment, in the method provided by the embodiment of the application, the process of judging whether the target user meets the preset user violation condition according to the violation evaluation result corresponding to each publishing business line in step S106 comprises:
[0092] determining whether there is at least one violation evaluation result corresponding to the publishing business line, which represents that the publishing business line meets the preset business line violation condition;
[0093] If there is at least one of the publishing business line corresponding to the violation assessment result representing that the publishing business line meets the preset business line violation condition, it is determined that the target user meets the preset user violation condition.
[0094] In the method provided by the embodiment of the application, it is determined whether there is a violation assessment result representing that the publishing business line corresponding to the violation assessment result meets the preset business line violation condition in each violation assessment result. If there is, it is considered that the target user meets the preset user violation condition.
[0095] On the basis of the method provided by the above embodiment, the method provided by the embodiment of the application further comprises:
[0096] If the violation assessment result corresponding to each of the publishing business lines represents that the publishing business line does not meet the preset business line violation condition, it is determined that the target user does not meet the preset user violation condition.
[0097] In the method provided by the embodiment of the application, if there is no violation assessment result representing that the publishing business line meets the business line violation condition, it is considered that the target user does not meet the preset user violation condition.
[0098] In Figure 1 On the basis of the method shown in the above embodiment, the method provided by the embodiment of the application comprises the following steps:
[0099] According to the plurality of information publishing behaviors corresponding to the violation user, a target violation type corresponding to the violation user is determined from a plurality of preset violation types;
[0100] In the method provided by the embodiment of the application, a plurality of violation types can be set in advance according to business requirements, such as malicious flooding, publishing content violating laws and regulations, publishing aggressive remarks, etc. Based on a preset intelligent recognition algorithm, the information content of each information publishing behavior of the violation user is recognized to identify the violation type corresponding to each information publishing behavior from a plurality of preset violation types, and the recognition result is taken as the target violation type corresponding to the violation user. For example, through content recognition, the information content of each information publishing behavior has high similarity, and then the type of malicious flooding is matched as the corresponding violation type.
[0101] A target containment level corresponding to the target violation type is determined from a plurality of preset containment levels.
[0102] The method provided in the embodiment of the application can set multiple containment levels in advance according to service requirements, for example, high, medium and low levels. An association between each violation type and a containment level is set in advance, that is, each violation type corresponds to a containment level. According to the pre-set information, the containment level corresponding to the target violation type can be matched in each containment level, and the containment level is taken as a target containment level.
[0103] An account containment operation corresponding to the target containment level is determined.
[0104] The method provided in the embodiment of the application can set an account containment operation corresponding to each containment level in advance, for example, the account containment operation corresponding to a high-level containment level can be permanent account suspension, the account containment operation corresponding to a medium-level containment level can be three-month speech ban, and the account containment operation corresponding to a low-level containment level can be one-month speech ban. Further, the account containment operation can further distinguish the containment range, for example, the containment range can be all-platform containment or containment of a certain publication business line.
[0105] The method provided in the embodiment of the application can determine an account containment operation corresponding to a target containment level according to pre-set information.
[0106] The account containment operation is performed on the violation user to realize containment processing of the violation user.
[0107] The method provided in the embodiment of the application can perform an account containment operation on a violation user through a pre-set operation execution script. For example, a script template for speech ban operation is set in advance, an account of a violation user is filled into the script template, and the account containment operation can be performed by executing the script template filled with the account.
[0108] On the basis of the method shown in Figure 1 The method provided in the embodiment of the application further includes the following steps:
[0109] The published information corresponding to the violation user is determined in a database.
[0110] The published information corresponding to the violation user is deleted in the database.
[0111] The method provided in the embodiment of the application can find the published information corresponding to a violation user, that is, the information content published by the violation user on an information publishing platform, according to the account ID or IP information of the violation user in the database of the information publishing platform. The published information corresponding to the violation user in the database is deleted through a pre-set database data deletion script.
[0112] In the implementation process, the deleted published information can be the published content involved in each information publishing behavior of the user in violation of the rules, or can be all information content published by the user in violation of the rules (including historical published content not involved in each information publishing behavior mentioned in the embodiments), the information range to be deleted can be set according to actual needs, and the published information is determined in the database according to the predetermined information range, without affecting the implementation function of the method provided in the embodiments of the application.
[0113] Based on the method provided in the embodiments of the application, the published information involved in the content attack can be automatically deleted without manual intervention, the manual workload can be saved, and the processing efficiency is further improved.
[0114] In order to better illustrate the method provided in the embodiments of the application, another content attack processing method is provided in the embodiments of the application, and the method provided in the embodiments of the application is briefly described in combination with an actual application scenario. The content attack processing process provided in the embodiments of the application mainly includes:
[0115] The user publishing business line and the corresponding threshold are configured through a unified configuration center;
[0116] All user publishing behaviors and content are collected, and the violation is identified through the publishing behavior of each user (go to the event center and process asynchronously);
[0117] The violation user is automatically and accurately calculated in quasi-real time through a unified asynchronous computing center, and the violation user is blocked;
[0118] A background management system is constructed in advance, the current blocked user situation can be visualized through the background management system, and the background management and control configuration center and the specific user can be configured.
[0119] The method provided in the embodiments of the application prevents attacks by configuring a threshold, and realizes flexibility of configuration by configuring a business line. Different businesses are configured differently. Once attacked, the number of user published information reaches the corresponding threshold, the user is automatically marked as a dangerous user, and corresponding processing is performed according to the corresponding configuration. The processing means does not need to be online, and takes effect immediately, which is convenient and flexible.
[0120] With Figure 1 Corresponding to the content attack processing method shown in FIG. 8, the embodiments of the application further provide a content attack processing device for implementing the method shown in FIG. 8, and a structure diagram is shown in FIG. 9, which includes: Figure 1 Figure 3
[0121] The first determination unit 301 is configured to determine a target user to be detected in a case where content attack detection is needed.
[0122] The second determining unit 302 is configured to determine a plurality of information publishing behaviors corresponding to the target user.
[0123] The third determining unit 303 is configured to determine a service line set corresponding to the target user, wherein the service line set comprises at least one publishing service line.
[0124] The fourth determining unit 304 is configured to determine, in the plurality of information publishing behaviors, an information publishing behavior corresponding to each of the publishing service lines.
[0125] The fifth determining unit 305 is configured to determine, for each of the publishing service lines, a violation evaluation result corresponding to the publishing service line according to the information publishing behavior corresponding to the publishing service line, wherein the violation evaluation result represents whether the publishing service line meets a preset service line violation condition.
[0126] The judging unit 306 is configured to judge whether the target user meets a preset user violation condition according to the violation evaluation result corresponding to each of the publishing service lines.
[0127] The sixth determining unit 307 is configured to determine the target user as a violation user initiating a content attack if the target user meets the preset user violation condition.
[0128] The containment unit 308 is configured to perform containment processing on the violation user to complete a content attack processing procedure.
[0129] The device provided in the embodiment of the present application can be used to determine a target user to be detected in a case of content attack detection, determine a plurality of information publishing behaviors and a service line set corresponding to the target user, wherein the service line set comprises at least one publishing service line, determine an information publishing behavior corresponding to each of the publishing service lines in the plurality of information publishing behaviors, determine, for each of the publishing service lines, a violation evaluation result corresponding to the publishing service line according to the information publishing behavior corresponding to the publishing service line, wherein the violation evaluation result represents whether the publishing service line meets a preset service line violation condition, judge whether the target user meets a preset user violation condition according to the violation evaluation result, and determine the target user as a violation user initiating a content attack if the target user meets the preset user violation condition. The device provided in the embodiment of the present application can automatically collect information publishing behaviors of a user, judge whether the user is a violation user initiating a content attack based on the information publishing behaviors, and automatically perform containment processing on the violation user. The device can be used to identify a user initiating a content attack and perform containment processing on the user in real time during the running of an information publishing platform, thereby preventing a malicious user from continuing to initiate an attack. The real-time performance of attack processing is good, which is conducive to reducing the security risk of the platform. The processing procedure does not need manual intervention, which can save manpower and time, and improve processing efficiency.
[0130] Another content attack processing device is provided in the embodiments of the present application, a structural schematic diagram of which is shown in Figure 4 The device provided in the embodiments of the present application is based on the device shown in Figure 3 The device provided in the embodiments of the present application is based on the device shown in
[0131] The first determining sub-unit 309 is configured to determine a preset quantity threshold corresponding to the publishing business line.
[0132] The second determining sub-unit 310 is configured to determine an information publishing quantity corresponding to the publishing business line, the information publishing quantity being a total quantity of each information publishing behavior corresponding to the publishing business line.
[0133] The comparing sub-unit 311 is configured to compare the information publishing quantity with the preset quantity threshold.
[0134] The third determining sub-unit 312 is configured to, if the information publishing quantity is greater than the preset quantity threshold, take a first preset result as a violation evaluation result corresponding to the publishing business line, the first preset result representing that the publishing business line meets the preset business line violation condition.
[0135] The device provided in the embodiments of the present application is based on the device provided in the above embodiments, and further includes:
[0136] The fourth determining sub-unit is configured to, if the information publishing quantity is less than or equal to the preset quantity threshold, take a second preset result as the violation evaluation result corresponding to the publishing business line, the second preset result representing that the publishing business line does not meet the preset business line violation condition.
[0137] The device provided in the embodiments of the present application is based on the device provided in the above embodiments, and the judging unit 306 includes:
[0138] The fifth determining sub-unit is configured to determine whether there is at least one violation evaluation result corresponding to the publishing business line, representing that the publishing business line meets the preset business line violation condition.
[0139] The sixth determining sub-unit is configured to, if there is at least one violation evaluation result corresponding to the publishing business line, representing that the publishing business line meets the preset business line violation condition, determine that the target user meets the preset user violation condition.
[0140] The device provided in the embodiments of the present application is based on the device provided in the above embodiments, and further includes:
[0141] The seventh determining sub-unit is configured to determine that the target user does not meet the preset user violation condition if each of the violation evaluation results corresponding to each of the publishing business lines indicates that the publishing business line does not meet the preset business line violation condition.
[0142] On the basis of the device provided in the above embodiment, the device provided in the embodiment of the present application comprises the control unit 308, which comprises:
[0143] The eighth determining sub-unit is configured to determine a target violation type corresponding to the violation user from a plurality of violation types according to the plurality of information publishing behaviors corresponding to the violation user.
[0144] The ninth determining sub-unit is configured to determine a target control level corresponding to the target violation type from a plurality of control levels.
[0145] The tenth determining sub-unit is configured to determine an account control operation corresponding to the target control level.
[0146] The control sub-unit is configured to perform the account control operation on the violation user to realize control processing of the violation user.
[0147] On the basis of the device provided in the above embodiment, the device provided in the embodiment of the present application further comprises:
[0148] The seventh determining unit is configured to determine the published information corresponding to the violation user in a database.
[0149] The deleting unit is configured to delete the published information corresponding to the violation user in the database.
[0150] The embodiment of the present application further provides a storage medium, which comprises stored instructions, wherein when the instructions are executed, the device where the storage medium is located performs the content attack processing method as described above.
[0151] The embodiment of the present application further provides an electronic device, a structure diagram of which is shown in Figure 5 The electronic device specifically comprises a memory 401 and one or more than one instruction 402, wherein the one or more than one instruction 402 is stored in the memory 401 and is configured to perform the one or more than one instruction 402 by one or more than one processor 403 to perform the following operations:
[0152] In the case where content attack detection is needed, a target user to be detected is determined.
[0153] A plurality of information publishing behaviors corresponding to the target user are determined.
[0154] determine a business line set corresponding to the target user, the business line set comprising at least one publishing business line;
[0155] determine, in the plurality of information publishing behaviors, respective information publishing behaviors corresponding to each of the publishing business lines;
[0156] for each of the publishing business lines, determine a violation evaluation result corresponding to the publishing business line according to the respective information publishing behaviors corresponding to the publishing business line, the violation evaluation result representing whether the publishing business line meets a preset business line violation condition;
[0157] determine, according to the violation evaluation result corresponding to each of the publishing business lines, whether the target user meets a preset user violation condition;
[0158] if the target user meets the preset user violation condition, determine the target user as a violation user initiating content attack;
[0159] perform a containment treatment on the violation user to complete a content attack processing procedure.
[0160] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between each of the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the system or system embodiments, since it is basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments. The system and system embodiments described above are only illustrative, and the units described as separate components can be or can not be physically separated, and the components displayed as units can be or can not be physical units, that is, they can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0161] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in general terms. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0162] The foregoing description of the disclosed embodiments enables a person skilled in the art to make or use the application. Modifications of these embodiments will occur to persons of skill in the art, and that the appended claims are intended to cover all such modifications that do not depart from the true spirit and scope of the application. Therefore, the application is not limited to the embodiments shown but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for handling content attacks, characterized in that, include: When content attack detection is required, the target users to be detected are determined based on the information publishing situation on various information publishing platforms in the organization. The target users are those who have published multiple pieces of information on the platform within a predetermined time period. Determine multiple information publishing behaviors corresponding to the target user; the multiple information publishing behaviors include the target user's behavior of publishing information on various information publishing platforms; The set of business lines corresponding to the target user is determined based on multiple information publishing behaviors corresponding to the target user, and the set of business lines includes at least one publishing business line. Among the multiple information publishing behaviors, each information publishing behavior corresponding to each publishing business line is determined; For each of the aforementioned publishing business lines, based on the various information publishing behaviors corresponding to that publishing business line, a violation assessment result is determined for that publishing business line. The violation assessment result indicates whether the publishing business line meets the preset business line violation conditions. Based on the violation assessment results corresponding to each of the aforementioned publishing business lines, determine whether the target user meets the preset user violation conditions; If the target user meets the preset user violation conditions, then the target user is identified as the violating user who launched the content attack; The aforementioned users who violated the rules were blocked, thus completing the content attack handling process.
2. The method according to claim 1, characterized in that, The determination of the violation assessment result corresponding to the publishing business line based on the various information publishing behaviors corresponding to the publishing business line includes: Determine the preset quantity threshold corresponding to this release business line; Determine the number of information releases corresponding to the publishing business line, wherein the number of information releases is the total number of all information release behaviors corresponding to the publishing business line; The number of information published is compared with the preset number threshold. If the number of information releases exceeds the preset threshold, the first preset result will be used as the violation assessment result for the release business line. The first preset result indicates that the release business line meets the preset business line violation conditions.
3. The method according to claim 2, characterized in that, Also includes: If the number of information published is less than or equal to the preset number threshold, the second preset result will be used as the violation assessment result for the publishing business line. The second preset result indicates that the publishing business line does not meet the preset business line violation conditions.
4. The method according to claim 1, characterized in that, The step of determining whether the target user meets the preset user violation conditions based on the violation assessment results corresponding to each of the published business lines includes: Determine whether there is a violation assessment result corresponding to at least one of the published business lines, indicating that the published business line meets the preset business line violation conditions; If at least one of the published business lines has a violation assessment result indicating that the published business line meets the preset business line violation conditions, then the target user is determined to meet the preset user violation conditions.
5. The method according to claim 4, characterized in that, Also includes: If the violation assessment results for each of the aforementioned publishing business lines indicate that the publishing business line does not meet the preset business line violation conditions, then it is determined that the target user does not meet the preset user violation conditions.
6. The method according to claim 1, characterized in that, The blocking of the violating users includes: Based on the multiple information publishing behaviors corresponding to the violating user, the target violation type corresponding to the violating user is determined from multiple preset violation types; Among a set of preset lockdown levels, determine the target lockdown level corresponding to the target violation type; Determine the account blocking operation corresponding to the target blocking level; The account blocking operation is performed on the violating user to achieve the blocking of the violating user.
7. The method according to claim 1, characterized in that, Also includes: Determine the published information corresponding to the offending user in the database; The published information corresponding to the offending user is deleted from the database.
8. A content attack processing device, characterized in that, include: The first determining unit is used to determine the target user to be detected based on the information publishing situation on each information publishing platform in the organization when content attack detection is required. The target user is a user who has published multiple pieces of information on the platform within a predetermined time period. The second determining unit is used to determine multiple information publishing behaviors corresponding to the target user; The multiple information publishing behaviors include the behavior of target users publishing information on various information publishing platforms; The third determining unit is used to determine the set of business lines corresponding to the target user based on multiple information publishing behaviors corresponding to the target user, wherein the set of business lines includes at least one publishing business line. The fourth determining unit is used to determine each information publishing behavior corresponding to each of the multiple information publishing behaviors in the context of each publishing business line. The fifth determining unit is used to determine the violation assessment result corresponding to each of the publishing business lines based on the various information publishing behaviors corresponding to the publishing business line. The violation assessment result indicates whether the publishing business line meets the preset business line violation conditions. The judgment unit is used to determine whether the target user meets the preset user violation conditions based on the violation assessment results corresponding to each of the published business lines; The sixth determining unit is used to determine the target user as a violating user who launched a content attack if the target user meets the preset user violation conditions; The blocking unit is used to block the violating users and complete the content attack handling process.
9. A storage medium, characterized in that, The storage medium includes stored instructions, wherein, when the instructions are executed, the device containing the storage medium is controlled to perform the content attack processing method as described in any one of claims 1 to 7.
10. An electronic device, characterized in that, It includes a memory, and one or more instructions, wherein one or more instructions are stored in the memory and configured to be executed by one or more processors as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Business data-based abnormal user generation content identification method and system
CN107256257A
Reporting content processing method and device, electronic equipment and storage medium
CN112699330A
Illegal behavior detection method and device and electronic equipment
CN113743522A