Method and apparatus for detecting abnormal account

By receiving account detection requests, obtaining and comparing task execution sequences, and identifying abnormal accounts, this technology solves the problem of recognition failure caused by false data feedback in existing technologies, and improves the accuracy of abnormal account identification.

CN116150719BActive Publication Date: 2026-04-10ZHUHAI KINGSOFT ONLINE GAME TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHUHAI KINGSOFT ONLINE GAME TECH CO LTD
Filing Date
2023-01-09
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately identify violating accounts, and the problem of identification failures is caused by receiving false data.

Method used

By receiving account detection requests, the system obtains the task execution sequence of the task, determines the target task execution sequence, compares it with each task execution sequence, and adds accounts that meet the preset comparison results to the abnormal account set.

Benefits of technology

This system enables the identification of abnormal accounts through the execution sequence of target tasks, avoiding identification failures caused by false data feedback and improving the accuracy of abnormal account identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116150719B_ABST
    Figure CN116150719B_ABST
Patent Text Reader

Abstract

The application provides an abnormal account detection method and device, wherein the abnormal account detection method comprises the following steps: receiving an account detection request for a target application, determining a target to-be-detected task based on the account detection request; acquiring an account set for executing the target to-be-detected task, and collecting a task execution sequence corresponding to each account in the account set; counting the number of tasks corresponding to each task execution sequence, and creating a target task execution sequence based on each task number; comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence; and adding an account corresponding to a current task execution sequence with a comparison result meeting a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to an abnormal account detection method. The present application also relates to an abnormal account detection device, a computing device and a computer readable storage medium. BACKGROUND

[0002] With the development of Internet technology, application software brings more convenience to users' life. However, some people automatically complete the tasks in the application through scripts, and give the reward transactions generated by the execution of the tasks to other users for profit, causing damage to the application software environment and economic imbalance in the application software, and affecting the use experience of normal users.

[0003] In order to solve the above problems, the current method is to judge whether the login IP, user identity information and application use time information are abnormal to determine whether the user account is a violation account. However, most of the data used to determine whether the account is illegal need to be transmitted from the user device to the server. The illegal personnel uploads the fake data to the service to evade the above illegal judgment method, resulting in incorrect judgment.

[0004] Therefore, there is an urgent need for a violation account detection method that can more accurately determine violation accounts. SUMMARY

[0005] Therefore, the embodiments of the present application provide an abnormal account detection method to solve the technical defects in the prior art. The embodiments of the present application also provide an abnormal account detection device, a computing device and a computer readable storage medium.

[0006] According to a first aspect of the embodiments of the present application, an abnormal account detection method is provided, comprising:

[0007] receiving an account detection request for a target application, determining a target to-be-detected task based on the account detection request;

[0008] obtaining a set of accounts that execute the target to-be-detected task, and collecting a task execution sequence corresponding to each account in the set of accounts;

[0009] counting the number of tasks executed by each task execution sequence, and creating a target task execution sequence based on the number of tasks executed by each task execution sequence;

[0010] comparing the target task execution sequence with each task execution sequence to obtain a comparison result corresponding to each task execution sequence;

[0011] adding the account corresponding to the task execution sequence whose comparison result meets a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.

[0012] According to a second aspect of the embodiments of the present application, an abnormal account detection device is provided, comprising:

[0013] a receiving module configured to receive an account detection request for a target application, and determine a target to-be-detected task based on the account detection request;

[0014] a collecting module configured to obtain a set of accounts performing the target to-be-detected task, and collect a task execution sequence corresponding to each account in the set of accounts;

[0015] a counting module configured to count a task execution number corresponding to each task execution sequence, and create a target task execution sequence based on each task execution number;

[0016] a comparing module configured to compare the target task execution sequence with each task execution sequence, and obtain a comparison result corresponding to each task execution sequence;

[0017] an adding module configured to add an account corresponding to a task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.

[0018] According to a third aspect of the embodiments of the present application, a computing device is provided, comprising:

[0019] a memory and a processor;

[0020] the memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions to implement the steps of the abnormal account detection method.

[0021] According to a fourth aspect of the embodiments of the present application, a computer readable storage medium is provided, which stores computer executable instructions, and the instructions are executed by a processor to implement the steps of the abnormal account detection method.

[0022] The application provides an abnormal account detection method, receiving an account detection request for a target application, determining a target to-be-detected task based on the account detection request, so as to determine an abnormal account based on the target to-be-detected task; obtaining an account set for executing the target to-be-detected task, and collecting a task execution sequence corresponding to each account in the account set, for determining an execution order of each account when executing the target to-be-detected task; counting a task execution quantity corresponding to each task execution sequence, and creating a target task execution sequence based on each task execution quantity, for comparing with each task execution sequence to determine a task execution sequence corresponding to an abnormal account; comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence; and adding an account corresponding to a current task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.

[0023] By creating a target task execution sequence based on a task execution order of a target to-be-detected task, and comparing the target task execution sequence with a current task execution sequence, an abnormal account is determined through the target task execution sequence, that is, a user violation behavior is determined by recognizing similar user usage behaviors, so that the problem of failure in recognizing a violation behavior caused by feedback of false data is avoided, and the accuracy of abnormal account recognition is improved. BRIEF DESCRIPTION OF DRAWINGS

[0024] Figure 1 FIG. 1 is a scene diagram of an abnormal account detection method according to an embodiment of the application;

[0025] Figure 2 FIG. 2 is a flowchart of an abnormal account detection method according to an embodiment of the application;

[0026] Figure 3 FIG. 3 is a processing flowchart of an abnormal account detection method applied to a game G according to an embodiment of the application;

[0027] Figure 4 FIG. 4 is a structural diagram of an abnormal account detection method device according to an embodiment of the application;

[0028] Figure 5 FIG. 5 is a structural block diagram of a computing device according to an embodiment of the application. DETAILED DESCRIPTION

[0029] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the application. However, the application can be practiced in many different ways beyond the specific embodiments described herein, and it is understood that similar modifications can be made by one skilled in the art without departing from the scope of the application, so the application is not limited to the specific implementations disclosed below.

[0030] The terminology used in this disclosure of one or more embodiments is for the purpose of describing particular embodiments only and is not intended to be limiting of one or more embodiments. As used in this disclosure and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0031] It should be understood that although the terms first, second, etc. can be employed in this disclosure of one or more embodiments to describe various information, these information should not be limited to these terms. These terms are only used to differentiate one piece of information from another piece of information. For example, a first can be termed a second, and, similarly, a second can be termed a first, without departing from the scope of one or more embodiments.

[0032] First, the noun terms related to one or more embodiments of the application are explained.

[0033] Game account: a personal exclusive credential when logging into a game.

[0034] Sequence: objects arranged in a line.

[0035] Game studio: refers to making various scripts for games or even cracking games, using a large number of high-end configuration computers to run external script for games, and establishing high-end configuration computer rooms to realize automatic playing of game characters.

[0036] In this application, a method for detecting abnormal account is provided. This application also relates to an abnormal account detection device, a computing device, and a computer readable storage medium, which are described in detail one by one in the following embodiments.

[0037] First, referring to Figure 1 The scene diagram of the abnormal account detection method is shown in the figure, a account detection request for a target game application is received, and a to-be-detected task h is determined based on the account detection request, wherein the to-be-detected task h is to collect 4 grasses in a specified area, which is a task completion; a game account in the target application that is executing the to-be-detected task h is obtained, including Figure 1game account 1, game account 2, game account 3; determine the task execution sequence generated by each game account when performing the task, such as the task execution sequence corresponding to game account 1 "coordinate point 1 -> coordinate point 3 -> coordinate point 4 -> coordinate point 5", the task execution sequence corresponding to game account 2 "coordinate point 3 -> coordinate point 2 -> coordinate point 1 -> coordinate point 4", and the task execution sequence corresponding to game account 3 "coordinate point 2 -> coordinate point 3 -> coordinate point 2 -> coordinate point 1", etc.; wherein the coordinate point in the sequence refers to the coordinate point of the grass set in the game map; during the process of collecting the task execution sequence, if it is determined that the obtained coordinate point is inconsistent with the coordinate point of the grass set in the database, the data is regarded as invalid data, that is, the game account corresponding to the data is a violation account.

[0038] After determining each task execution sequence, the number of task executions corresponding to each task execution sequence is determined, including the number of starting coordinate points, the number of task execution sequences, and the number of task execution paths. Based on the number of task executions, the target task execution sequence is constructed, specifically, according to the number of task executions a, the number of task executions b, and the number of task executions c, the target task execution sequence is constructed, that is, according to the number of task executions, the starting point with a larger number is determined, and further according to the task execution sequence, the next coordinate point corresponding to the starting point is determined, until the target task execution sequence "coordinate point 1 -> coordinate point 3 -> coordinate point 4 -> coordinate point 5" meeting the requirements is obtained. The target task execution sequence is compared with each task execution sequence, specifically, the target task execution sequence is compared with sequence 1 corresponding to game account 1, sequence 2 corresponding to game account 2, and sequence 3 corresponding to game account 3, respectively, to obtain the comparison result corresponding to each task execution sequence, including comparison result 1, comparison result 2, and comparison result 3. The number of sequences of task execution sequences with comparison results is counted, and in the case that the number of sequences is greater than a preset threshold, it indicates that the target task execution sequence is successfully reconstructed. The successfully reconstructed target task execution sequence can be used to determine whether the game account performing the to-be-detected task h exists a violation; if the game account exists in multiple different task corresponding abnormal account sets, a violation mark is added to the game account, so as to further process such abnormal accounts in the future.

[0039] The abnormal account detection method of the present application creates a target task execution sequence based on the task execution sequence of the target to-be-detected task, and compares the target task execution sequence with the current task execution sequence, which realizes the determination of abnormal accounts through the target task execution sequence, that is, the determination of game violation behavior through the identification of similar game behaviors, avoids the problem of identification failure caused by feedback of false data, and improves the accuracy of abnormal account identification.

[0040] Figure 2An embodiment of the application provides a flowchart of an abnormal account detection method, which specifically comprises the following steps.

[0041] Step 202: receiving an account detection request for a target application, and determining a target to-be-detected task based on the account detection request.

[0042] The account detection request refers to a request for detecting whether an abnormal account exists in the target application; the abnormal account refers to an application account of an abnormal user created by a studio; the target application refers to an application containing the target to-be-detected task, for example, a game application, a navigation application, a shopping application, an instant messaging application, etc.; the target to-be-detected task refers to a task containing a fixed coordinate point set in a task execution process; in actual application, not all application tasks are suitable for the method of the application; for example, if the refresh of collected items in a collection task is too fast, a new virtual item will appear in time after a user character collects the item, and the studio does not need to pick up different collection points, but only needs to continuously pick up the collection point at the original position; the method of the application needs to select the refresh time of the collected items, and a task exceeding a preset time threshold, for example, a virtual tree needs to be updated after 3 hours after being collected, if a character A collects the tree, a character B cannot collect the tree from the position, and therefore the character B needs to collect the tree from another position to complete the collection task.

[0043] Specifically, after the application server receives the account detection request for the target application, the account detection request is parsed to obtain the target to-be-detected task contained in the account detection request; in actual application, after the account detection request is parsed, a to-be-detected task set can be obtained, and each to-be-detected task in the to-be-detected task set is regarded as the target to-be-detected task.

[0044] In a specific embodiment of the application, after the server receives the account detection request for the navigation application A, the account detection request is parsed to obtain a to-be-detected task set corresponding to the navigation application A, and a plant collection task in the to-be-detected task set is regarded as the target to-be-detected task.

[0045] By receiving the account detection request for the target application and determining the to-be-detected task based on the account detection request, the abnormal account in the target application can be determined based on the data corresponding to the to-be-detected task.

[0046] Step 204: obtaining an account set for executing the target to-be-detected task, and collecting a task execution sequence corresponding to each account in the account set.

[0047] After the target to-be-detected task is determined, the data corresponding to the target to-be-detected task is collected to determine the abnormal account in the target application.

[0048] The account set refers to a set of accounts performing the target task to be detected. The task execution sequence refers to a sequence of position information determined by the application role in the process of performing the target task to be detected. For example, the target task to be detected is to collect 5 trees in the execution area, and the time points at which the user corresponding to the account collects each tree and the positions of each tree form the task execution sequence.

[0049] Specifically, accounts performing the target task to be detected in a preset time period are obtained to form an account set. The task execution position corresponding to each account in the account set is determined to form a task collection sequence corresponding to each account.

[0050] In actual application, the task execution position corresponding to each account refers to a fixed position of a virtual object in an application map. For example, when a role successfully picks up a task item, the current pickup record reported contains role information and the coordinates of the item. In order to ensure the accuracy of the task execution position, after the task execution position is collected, the task execution position is compared with the fixed position of the virtual object recorded in the application database. If the application database does not contain the task execution position, it is considered that the task execution position is false data tampered by the studio, and it needs to be deleted as invalid data. That is, the account corresponding to the task execution position is a violation account.

[0051] In a specific embodiment of the present application, application accounts performing a vegetable collection task in a time period H are obtained to form an account set. The task execution sequence corresponding to each account in the account set is determined.

[0052] In actual application, the method of collecting the task execution sequence corresponding to each account in the account set can include:

[0053] A target application account is determined in the account set.

[0054] A task coordinate point set corresponding to the target task to be detected performed by the target application account is obtained, wherein the task coordinate point set includes each task coordinate point and the collection time point of each task coordinate point.

[0055] Based on each task coordinate point and the collection time point of each task coordinate point, a task execution sequence corresponding to the target application account is generated.

[0056] The target application account refers to any one of the application accounts in the account set corresponding to the application. The task coordinate point set refers to a set composed of a task coordinate point and a collection time point corresponding to the task coordinate point. The task coordinate point refers to a coordinate point determined by the target application account in the process of performing the target task to be detected. The collection time point refers to the time point at which the task coordinate point is collected.

[0057] Specifically, a target application account is determined in the application account set, and each application account in the application account set can be determined as the target application account; a task coordinate point corresponding to execution of a target to-be-detected task by each target application account is obtained to form a task coordinate point set corresponding to each target application account; and a task execution sequence corresponding to the target application account is generated according to the task coordinate point corresponding to the target application account and a time point at which the task coordinate point is collected.

[0058] In a specific embodiment of the present application, a target application account is determined in an application account set corresponding to a plant to-be-detected task; a task coordinate point corresponding to execution of the plant to-be-detected task by the target application account is obtained to form a task coordinate point set; and a task execution sequence is formed by including the task coordinate point corresponding to the target application account and a collection time point corresponding to each task coordinate point in the task coordinate point set.

[0059] By determining the task execution sequence corresponding to each account in the account set, the task execution state of each account can be determined.

[0060] Step 206: The number of tasks executed corresponding to each task execution sequence is counted, and a target task execution sequence is created based on the number of tasks executed.

[0061] The number of tasks executed refers to a number determined by counting the sequence characteristics of each task execution sequence; the target task execution sequence refers to a task execution sequence created based on the number of tasks executed; it should be noted that the target task execution sequence is not a task execution sequence selected from the task execution sequence corresponding to each account, but a task execution sequence reconstructed based on the number of tasks executed; therefore, the task execution sequence corresponding to the account may or may not be consistent with the target task execution sequence.

[0062] Specifically, the method of counting the number of tasks executed corresponding to each task execution sequence can include:

[0063] determining the task execution path, the task execution subsequence, and the task execution order corresponding to each task execution sequence;

[0064] The number of paths corresponding to each task execution path is counted, and the number of task execution subsequences corresponding to each task execution subsequence and the number of task execution orders corresponding to each task execution order are determined based on the number of paths.

[0065] The task execution path refers to a path determined based on a coordinate point in the task execution sequence, for example, the task execution path corresponding to the task execution sequence a is "target point 1->target point 2->target point 5"; the task execution subsequence refers to a subsequence determined based on a starting coordinate point of task execution, for example, the task execution path of the task execution sequence b is "target point 1->target point 3->target point 7->target point 4->target point 6", that is, the starting coordinate point is target point 1, and the task execution subsequence can be "target point 1" and "target point 1->target point 3" determined based on the starting coordinate point, and can also be "target point 1->target point 3->target point 7", etc.; if the task execution path of the task execution sequence b is [[target point 1->target point 3]->target point 7->target point 4->target point 6], that is, the starting coordinate point is [target point 1->target point 3], the task execution subsequence can be [[target point 1->target point 3]->target point 7], etc.; the task execution order refers to each execution order contained in the task execution sequence; for example, the task execution path of the task execution sequence c is "target point 1->target point 3->target point 7", and the task execution order corresponding to the task execution sequence includes "target point 1->target point 3" and "target point 3->target point 7".

[0066] The task execution quantity corresponding to each task execution order includes: path quantity, task execution subsequence quantity and task execution order quantity; after determining the task execution path, the task execution subsequence and the task execution order corresponding to each task execution sequence, the number corresponding to each task execution path, the task execution subsequence and the task execution order is counted respectively; the path quantity refers to the number corresponding to each task execution path, for example, the number corresponding to the task execution path a is 10, the number corresponding to the task execution path b is 50, etc.; the task execution subsequence quantity refers to the number corresponding to each task execution subsequence, for example, the number of the task execution subsequence "target point 1" is 10000, and the number of the task execution subsequence "target point 1->target point 3" is 20000; the task execution order quantity refers to the number corresponding to each task execution order, for example, the number of the task execution order "target point 1->target point 3" is 20000, and the number of the task execution order "target point 2->target point 3" is 15000, etc.

[0067] After determining the task execution quantity, the method for creating a target task execution sequence based on each task execution quantity can include:

[0068] determining a target task execution subsequence in the task execution subsequence;

[0069] In a case where the number of task execution sub-sequences in the target task execution sub-sequence is greater than a task execution sub-sequence number threshold, a target task execution sequence is created based on the target task execution sub-sequence.

[0070] The target task sub-sequence refers to a starting task execution sub-sequence selected from each task execution sub-sequence, for example, the target task sub-sequence can be coordinate point a, or coordinate point a->coordinate point b, etc. The task execution sub-sequence number threshold refers to a minimum value of the number of task execution sub-sequences, and a task execution sub-sequence less than the number threshold cannot be used to create a target task execution sequence. If there are multiple target task execution sub-sequences corresponding to the number of task execution sub-sequences greater than the task execution sub-sequence number threshold, one can be arbitrarily selected to create a target task execution sequence.

[0071] In a preferred embodiment of the present application, each task execution sub-sequence can also be sorted based on the number of task execution sub-sequences, and the task execution sub-sequence with the largest number of task execution sub-sequences is selected to create a target task execution sequence. For example, the number of task execution sub-sequences with starting coordinate point l is 100, the number of task execution sub-sequences with starting coordinate point m is 200, and the number of task execution sub-sequences with starting coordinate point h is 500. The starting coordinate point h is selected as the target task execution sub-sequence to create a target task execution sequence.

[0072] In a specific embodiment of the present application, the target task execution sub-sequence a1 and the corresponding task execution sub-sequence number 100000 are determined. The task execution sub-sequence number is compared with the preset task execution sub-sequence threshold 90000, and it is determined that the task execution sub-sequence number is greater than the preset task execution sub-sequence threshold. A target task execution sequence is created based on the target task execution sub-sequence a1.

[0073] Further, the method of creating a target task execution sequence based on the target task execution sub-sequence can include:

[0074] An initial task execution sub-sequence is determined according to the target task execution sub-sequence.

[0075] A task execution order set corresponding to the initial task execution sub-sequence is determined.

[0076] A target task execution order with a number of task execution orders greater than a task execution order threshold is selected from the task execution order set, and a target coordinate point corresponding to the target task execution order is determined.

[0077] The target coordinate point is added to the initial task execution sub-sequence.

[0078] The step of determining the task execution sequence set corresponding to the initial task execution subsequence is continuously performed until the number of target points of the initial task execution subsequence is equal to the preset threshold of the number of target points, and a target task execution sequence is obtained.

[0079] In the formula, the initial task subsequence refers to a subsequence used to generate a target task execution sequence; the task execution sequence set refers to a set composed of task execution sequences determined based on the last coordinate point of the initial task execution subsequence. For example, if the initial execution subsequence is “target point 1->target point 3”, the task execution sequence can be “target point 3->target point 7”, “target point 3->target point 5”, or “target point 1->target point 3->target point 7”, “target point 1->target point 3->target point 5”, and the like; the task execution sequence threshold refers to the minimum value of the number of task execution sequences, and a task execution sequence smaller than the number threshold cannot be used to create a target task execution sequence; the number of target points refers to the number of target coordinate points contained in the current initial task execution subsequence; and the preset threshold of the number of target points refers to a threshold of the number of target coordinate points contained in each initial task execution subsequence. If the threshold is exceeded, the creation of the target task execution sequence is ended.

[0080] In actual application, the task execution sequence set corresponding to the initial task execution subsequence is determined, and a target task execution sequence with a number of task execution sequences greater than the task execution sequence threshold is selected from the task execution sequence set. If the task execution sequence set does not contain a target task execution sequence with a number of task execution sequences greater than the task execution sequence threshold, the number of target points corresponding to the current initial task execution subsequence is determined. If the number of target points is less than the preset threshold of the number of target points, a target task execution sequence is selected from the task execution sequence with a number of task execution sequences less than or equal to the task execution sequence threshold, for example, a target task execution sequence with the maximum number of task execution sequences is selected as the target task execution sequence, a target coordinate point corresponding to the target task execution sequence is further determined, and the target coordinate point is added to the initial task execution subsequence.

[0081] The above steps are further performed until the number of target points corresponding to the initial task execution subsequence is equal to the preset threshold of the number of target points. At this time, if the task execution sequence set corresponding to the current initial task execution subsequence does not contain a target task execution sequence with a number of task execution sequences greater than the task execution sequence threshold, the initial task execution subsequence with the number of target points equal to the preset threshold of the number of target points is taken as the target task execution sequence. If the task execution sequence set corresponding to the current initial task execution subsequence contains a target task execution sequence with a number of task execution sequences greater than the task execution sequence threshold, a target coordinate point is continuously added to the initial task execution subsequence until the task execution sequence set corresponding to the initial task execution subsequence does not contain a target task execution sequence with a number of task execution sequences greater than the task execution sequence threshold.

[0082] In a preferred embodiment of the present application, the task execution sequences can be sorted according to the number of task execution sequences, and each time the target task execution sequence with the largest number of task execution sequences is selected to create a target task execution sequence, until the number of target points of the initial task execution subsequence is greater than or equal to the preset target point number threshold.

[0083] In a specific embodiment of the present application, the initial task execution subsequence is determined to be [abcde], and the preset target point number threshold is 6; based on the task execution sequence [de], it is determined that the task execution sequence set contains the task execution sequence [de]->[c] and the task execution sequence [de]->[f]; since the initial task execution subsequence contains the target point c, and the target point in the reconstruction sequence cannot be repeated, the task execution sequence [abcdef] is formed based on the target point f; since the current number of target points of the task execution sequence [abcdef] is 6, which is equal to the preset target point number threshold 6, and the task execution sequence set corresponding to the task execution sequence [abcdef] does not contain a target task execution sequence greater than the task execution sequence threshold, the [abcdef] is taken as the target task execution sequence.

[0084] The target coordinate point refers to the coordinate point in the non-initial task execution subsequence contained in the target task execution sequence. For example, the initial task execution subsequence is "target point 1->target point 3", and the corresponding target task execution sequence is determined to be "target point 3->target point 5", and the target point 5 is the target coordinate point.

[0085] Specifically, the target task execution subsequence is taken as the current initial task execution subsequence; the task execution sequence set corresponding to the initial task subsequence is determined, and the task sequence execution set contains the task execution sequence corresponding to the initial task subsequence and the corresponding number of task execution sequences; the target task execution sequence greater than the task execution sequence threshold is screened in the task sequence execution set, and the target coordinate point corresponding to the target task execution sequence is determined; the target coordinate point is connected with the current initial task execution subsequence to obtain a new initial task execution subsequence, until the number of target points corresponding to the new initial task execution subsequence is equal to the preset target point number threshold, then it is further determined whether the task execution sequence set corresponding to the new initial task execution subsequence contains the target task execution sequence with the number of task execution sequences greater than the task execution sequence threshold, if yes, the target coordinate point is continuously added in the new initial task execution subsequence. If not, the initial task execution subsequence at this time is taken as the target task execution sequence.

[0086] In an embodiment of the present application, in the target task subsequence a, b, c, the initial task subsequence a is determined: "target point 1->target point 3"; the initial task subsequence a corresponding task execution order set is determined, the task execution order set includes: "target point 1->target point 3->target point 5" and the order quantity 10000, "target point 1->target point 3->target point 6" and the order quantity 20000, and "target point 1->target point 3->target point 4" and the order quantity 30000; the task execution order threshold is determined as 25000, and the task execution order "target point 1->target point 3->target point 4" is taken as the target task execution order, that is, the target point 4 is the target coordinate point; the target point 4 is added to the initial task subsequence a to obtain "target point 1->target point 3->target point 4"; the task execution order set corresponding to "target point 1->target point 3->target point 4" and the order quantity corresponding to each task execution sequence are further determined; the target point quantity corresponding to the sequence "target point 1->target point 3->target point 4" is equal to the preset target point quantity 4, and the task execution order set in the sequence "target point 1->target point 3->target point 4" does not contain the task execution order quantity greater than 25000, so "target point 1->target point 3->target point 4" is taken as the target task execution sequence.

[0087] Further, in the case where the target point quantity of the initial task execution subsequence is equal to the preset target point quantity threshold, it is necessary to compare the current initial task execution subsequence with each task execution sequence corresponding to each account in the account set respectively, so as to determine whether the initial task execution subsequence can be taken as the target task execution sequence based on the comparison result.

[0088] That is, in actual application, the method for obtaining the target task execution sequence can include:

[0089] determining the initial task execution path corresponding to the initial task execution subsequence, and the task execution path corresponding to each task execution sequence;

[0090] comparing the initial task path with the task execution sequence of each task execution sequence respectively, and determining the comparison result corresponding to each task execution sequence;

[0091] counting the task execution sequence quantity with a successful comparison result;

[0092] in the case where the task execution sequence quantity is greater than the preset sequence quantity threshold, the initial task execution subsequence is taken as the target task execution sequence.

[0093] The initial task execution path refers to a path determined based on coordinate points in the initial task execution subsequence; the task execution quantity refers to a quantity of task execution sequences in which the comparison result is comparison success; and the preset sequence quantity threshold refers to a threshold of the task execution quantity.

[0094] Specifically, the method for comparing the initial task execution path with each task execution sequence respectively to determine the comparison result corresponding to each task execution sequence can include:

[0095] determining a target task execution path corresponding to the target task execution sequence and a task execution path corresponding to each task execution sequence;

[0096] comparing the target task execution path with each task execution path respectively to determine a sequence type corresponding to each task execution sequence;

[0097] in a case where the task execution sequence is of a first type, determining that the comparison result corresponding to the task execution sequence is comparison success, wherein the first type includes a same type, a loop type, a first jump point type, and a sequence missing type;

[0098] in a case where the task execution sequence is of a second type, determining that the comparison result corresponding to the task execution sequence is comparison failure, wherein the second type includes a second jump point type and a jump point frequency type.

[0099] The sequence type refers to a type of the target task execution sequence determined through path comparison; the first type of task execution sequence refers to a task execution sequence matched with the target task execution sequence; and the second task execution sequence refers to a task execution sequence not matched with the target task sequence.

[0100] The first type includes the same type, the loop type, the first jump point type, and the sequence missing type; and the second type includes the second jump point type and the jump point frequency type. The first type and the second type are further described based on Table 1 as follows:

[0101] Table 1

[0102]

[0103] The actual task execution sequence refers to a task execution sequence corresponding to a target task to be detected. The sequence type is of the first type in the following cases: the target task execution sequence

ABCDEF

ABCDEF

ABCDEF

BCDEFA

ABCDE

ABDABC

ABCDE

ABCDEF

[0104] The sequence type is of the second type in the following cases: in the comparison between the target task execution sequence

ABCDEF

ADEFAD

ABCDEF

ACEACE

[0105] By comparing, the sequence type corresponding to each task execution sequence is determined, and the comparison result is determined based on the sequence type, so that the number of task execution sequences successfully compared is determined based on the comparison result, and then the target task execution sequence is determined based on the number of task execution sequences.

[0106] After determining the comparison result corresponding to each task execution sequence, the number of task execution sequences with a successful comparison result is counted; in the case where the number of task execution sequences is greater than a preset sequence number threshold, it is determined that the initial task sub-sequence currently constructed can match a certain number of task sub-sequences, that is, the initial task sub-sequence currently constructed can be used as the target task execution sequence.

[0107] In the case where the number of task execution sequences is less than or equal to the preset sequence number threshold, it is determined that the current target task execution sequence fails to be constructed; then, the starting point in the current initial task sub-sequence and the number corresponding to the starting point need to be deleted, the target point with the largest number of target points is determined as a new starting point from each remaining target point, the target task execution sequence is reconstructed, and the specific construction process is consistent with the method described above, which will not be described here.

[0108] In a specific embodiment of this application, if the number of task execution sequences corresponding to the initial execution subsequence c is determined to be 300, which is less than the preset sequence number threshold of 500, then the starting point 1 in the initial execution subsequence c is determined, and the starting point 1 and the corresponding number of starting points are deleted. Then, the starting point 2 with the largest number is selected to reconstruct the target task execution sequence.

[0109] In another specific embodiment of this application, if the number of task execution sequences corresponding to the initial execution subsequence d is determined to be 800, which is greater than the preset sequence number threshold of 500, then it is determined that the initial execution subsequence d can be used as the target task execution sequence for construction.

[0110] In a preferred embodiment, to ensure the accuracy of identifying violating accounts based on the target task execution sequence, further judgment can be made on the initial task execution sub-sequences where the number of task execution sequences exceeds a preset sequence number threshold. Specific methods may include:

[0111] Based on the task execution path corresponding to each task execution sequence that is successfully matched, each task execution sequence is classified to obtain a sequence classification set;

[0112] In the sequence classification set, a target sequence classification is determined whose number of sequences corresponding to the sequence classification is less than a preset classification number threshold;

[0113] The sequence ratio is determined based on the number of sequences corresponding to each target sequence category and the number of task execution sequences.

[0114] If the sequence ratio is less than the preset sequence ratio, the initial task execution subsequence will be used as the target task execution sequence.

[0115] Here, the sequence classification set refers to the set of sequence classifications corresponding to the task execution sequence; the number of sequences refers to the number of task execution sequences corresponding to the sequence classification; the target sequence classification refers to the sequence classification whose number of sequence classifications is less than a preset threshold; and the sequence ratio refers to the ratio determined by the sum of the number of sequences corresponding to each target sequence classification and the number of task execution sequences.

[0116] Specifically, after determining that the initial task execution sub-sequence has a target point quantity equal to a preset target point quantity threshold, it is determined that each task sub-sequence has a comparison result of comparison success; each task sub-sequence is classified according to a task execution path corresponding to the task sub-sequence to obtain a sequence classification set; a sequence quantity corresponding to each sequence classification in the sequence classification set is counted, and a target sequence classification with a sequence quantity less than a preset classification quantity threshold is determined; a sum of the sequence quantities corresponding to each target sequence classification is calculated, and a sequence ratio is determined according to the sum of the sequence quantities and a task execution sequence quantity; in the case that the sequence ratio is less than a preset sequence ratio, it is indicated that the initial task execution sub-sequence determines that the task sub-sequence has a high degree of repetition, and therefore, the current initial task execution sub-sequence can be used as a target task execution sequence; if the sequence ratio is less than the preset sequence ratio, it is considered that the current target task execution sequence fails to be created, that is, the current initial task sub-sequence cannot match a sequence with a violation problem, and a new reconstruction sequence needs to be formed.

[0117] In a specific embodiment of the present application, it is determined that the initial task execution sub-sequence e has a task execution sequence quantity greater than a preset sequence quantity threshold, then the task execution paths corresponding to the 310 task execution sequences with a comparison result of comparison success are determined, including 2 sequences with a path of 1-2-3, 300 sequences with a path of 2-3-4, and 8 sequences with a path of 3-4-2, that is, three types of sequences are obtained; it is determined that the preset classification quantity threshold is 10, then the sequences with a path of 1-2-3 and the sequences with a path of 3-4-2 are target sequence classifications; it is determined that the total quantity of sequences corresponding to the target sequence classifications is 2+8=10, and then the sequence ratio is calculated as 10 / 310; since the sequence ratio 10 / 310 is less than the preset sequence ratio 15 / 310, the initial task execution sub-sequence e is used as a target task execution sequence.

[0118] Further, in actual applications, a task execution sequence that can complete a target to-be-detected task can include multiple types, for example, task execution sequence 1-2-3-4, task execution sequence 2-3-5-4, and task execution sequence 3-4-5-6-7 can all complete the task of collecting 4 props, therefore, after a target task execution sequence is determined, a new target task execution sequence can be created for the target to-be-detected task, so that the subsequent target to-be-detected task can determine whether there is an abnormal account based on multiple target task execution sequences, and thus the accuracy of abnormal account determination is improved.

[0119] In actual applications, after the initial task execution sub-sequence is used as a target task execution sequence, it further includes:

[0120] Each task execution sequence and a task execution quantity corresponding to each task execution sequence are deleted.

[0121] Specifically, after determining the target task execution sequence corresponding to the target task to be detected in the preset time period and determining the comparison result corresponding to each task execution sequence, the recorded compared task execution sequence, the target task execution sequence and the task execution quantity in the database are deleted, so as to subsequently construct the target task execution sequence for the next time.

[0122] It should be noted that, in order to prevent the process of creating the target task execution sequence from entering a dead loop, the target coordinate point that has been added to the target task execution sequence will not be added again in the case of creating the same target task execution sequence.

[0123] By creating the target task execution sequence, it is determined whether the account has a violation problem based on the target task execution sequence.

[0124] Step 208: comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence.

[0125] After determining the target task execution sequence, it is determined whether other accounts corresponding to the target task to be detected have a violation condition based on the target task execution sequence.

[0126] The current task execution sequence refers to the current task execution sequence corresponding to the target task to be detected, which is different from the task execution sequence corresponding to each account in the account set collected above.

[0127] The method of comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence comprises:

[0128] determining a target task execution path corresponding to the target task execution sequence and a current task execution path corresponding to each task execution sequence;

[0129] comparing the target task execution path with the task execution path corresponding to each current task execution sequence respectively to determine a sequence type corresponding to each current task execution sequence;

[0130] in the case that the current task execution sequence is of a first type, determining that the comparison result corresponding to the current task execution sequence is comparison success, wherein the first type includes the same type, the loop type, the first jump point type and the sequence missing type;

[0131] in the case that the current task execution sequence is of a second type, determining that the comparison result corresponding to the current task execution sequence is comparison failure, wherein the second type includes the second jump point type and the jump point number type.

[0132] Specifically, a current task execution sequence corresponding to the target task to be detected is determined, and the target task execution sequence is compared with each current task execution sequence. The comparison process can be implemented on the server that generates the target task execution sequence, that is, after the server generates the target task execution sequence, the current task execution sequence is obtained, so that the comparison process is implemented. Alternatively, the server that generates the target task execution sequence sends the target task execution sequence to the client, and the client completes the comparison process based on the current task execution sequence. The present application does not make specific limitations.

[0133] The method of comparing the target task execution sequence with each current task execution sequence is consistent with the method of comparing the initial task execution subsequence with each task execution sequence described above, and will not be repeated here.

[0134] The sequence type of the task execution sequence is determined through comparison, and the comparison result is determined based on the sequence type, so as to subsequently determine the abnormal account based on the comparison result.

[0135] Step 210: Adding the account corresponding to the current task execution sequence that meets the preset comparison result to the abnormal account set corresponding to the target task to be detected.

[0136] Specifically, the method of adding the account corresponding to the current task execution sequence that meets the preset comparison result to the abnormal account set corresponding to the target task to be detected includes:

[0137] Adding the account corresponding to the current task execution sequence with a successful comparison result to the abnormal account set corresponding to the target task to be detected.

[0138] The abnormal account set refers to a set composed of abnormal accounts. The current task execution sequence with a successful comparison result is determined as a sequence generated by a non-normal user using an application to complete a task, so as to further determine the application account corresponding to the current task execution sequence, so as to add the application account to the abnormal account set corresponding to the target task to be detected.

[0139] Further, in order to ensure the accuracy of detection, a plurality of target tasks to be detected in the target application can be determined. If the target application account is determined as an abnormal account in the plurality of target tasks to be detected, a violation identifier is added to the target application account.

[0140] Specifically, the method of determining whether the account violates in another target task to be detected can include:

[0141] A reference task to be detected corresponding to the target application is determined, and a reference account set performing the reference task to be detected is obtained.

[0142] collect a reference task execution sequence corresponding to each reference account in the reference account set;

[0143] count the number of task executions corresponding to each reference task execution sequence, and create a target reference task execution sequence based on each task execution number;

[0144] Compare the target reference task execution sequence with each current task execution sequence to obtain a reference comparison result corresponding to each current task execution sequence;

[0145] Add the account corresponding to the current task execution sequence that meets the preset comparison result to the abnormal account set corresponding to the reference task to be detected.

[0146] Wherein, the reference task to be detected refers to a task different from the target task to be detected in the target application; the reference task to be detected is also a task containing a fixed coordinate point set in the execution process; the reference account set refers to a set composed of reference accounts executing the reference task to be detected; the target reference task execution sequence refers to a sequence created based on the task execution number corresponding to each reference task execution sequence.

[0147] Specifically, the method of determining abnormal accounts based on the reference task to be detected is consistent with the method of determining abnormal accounts based on the target task to be detected, which will not be repeated here.

[0148] Further, after being added to the abnormal account set corresponding to the target task to be detected, it can also include:

[0149] Determine the task to be detected account in the abnormal account set corresponding to the target task to be detected;

[0150] In the case that the task to be detected account exists in the abnormal account set corresponding to the reference task to be detected, add a violation mark to the task to be detected account.

[0151] Wherein, the task to be detected account refers to any one of the abnormal accounts; if the corresponding reference account is obtained in the abnormal account set corresponding to the reference task to be detected, that is, there are same accounts in the abnormal account set corresponding to the target task to be detected and the abnormal account set corresponding to the reference task to be detected, then the account is added to the violation mark; further, the account can be sent to the client of the account, or the normal use of the account can be prohibited, etc.

[0152] In addition to the above two task determination methods of abnormal accounts based on the target application, a plurality of target tasks to be detected of multiple target applications can also be determined at the same time, and whether the account exists in violation can be determined based on the detection results corresponding to the plurality of tasks to be detected, so as to improve the accuracy of abnormal account detection.

[0153] The application provides an abnormal account detection method. The abnormal account detection method is applied to a game G. The abnormal account detection method comprises the following steps: receiving an account detection request for the game G, and determining a virtual prop collection task based on the account detection request; obtaining a set of game accounts for executing the virtual prop collection task, and collecting a task execution sequence corresponding to each game account in the set of game accounts; counting a task execution quantity corresponding to each task execution sequence; creating a target task execution sequence based on each task execution quantity; comparing the target task execution sequence with a current task execution sequence corresponding to each virtual prop collection task, and obtaining a comparison result corresponding to each current task execution sequence; and adding a game account corresponding to a current task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the virtual prop collection task.

[0154] The application is described below in combination with the accompanying Figure 3 The application provides an abnormal account detection method. The abnormal account detection method is applied to a game G. The abnormal account detection method comprises the following steps: receiving an account detection request for the game G, and determining a virtual prop collection task based on the account detection request; obtaining a set of game accounts for executing the virtual prop collection task, and collecting a task execution sequence corresponding to each game account in the set of game accounts; counting a task execution quantity corresponding to each task execution sequence; creating a target task execution sequence based on each task execution quantity; comparing the target task execution sequence with a current task execution sequence corresponding to each virtual prop collection task, and obtaining a comparison result corresponding to each current task execution sequence; and adding a game account corresponding to a current task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the virtual prop collection task. Figure 3 The application provides an abnormal account detection method. The abnormal account detection method is applied to a game G. The abnormal account detection method comprises the following steps: receiving an account detection request for the game G, and determining a virtual prop collection task based on the account detection request; obtaining a set of game accounts for executing the virtual prop collection task, and collecting a task execution sequence corresponding to each game account in the set of game accounts; counting a task execution quantity corresponding to each task execution sequence; creating a target task execution sequence based on each task execution quantity; comparing the target task execution sequence with a current task execution sequence corresponding to each virtual prop collection task, and obtaining a comparison result corresponding to each current task execution sequence; and adding a game account corresponding to a current task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the virtual prop collection task.

[0155] Step 302: receiving an account detection request for the game G, and determining a virtual prop collection task based on the account detection request.

[0156] Step 304: obtaining a set of game accounts for executing the virtual prop collection task, and collecting a task execution sequence corresponding to each game account in the set of game accounts.

[0157] Specifically, the task execution coordinate point corresponding to each game account is obtained, that is, the coordinate point of the virtual prop passed through by the task execution; it is judged whether the collected coordinate point is consistent with the record in the database, and if not, the coordinate point data is deleted.

[0158] Step 306: counting the task execution quantity corresponding to each task execution sequence.

[0159] Step 308: creating a target task execution sequence based on each task execution quantity.

[0160] Step 310: comparing the target task execution sequence with a current task execution sequence corresponding to each virtual prop collection task, and obtaining a comparison result corresponding to each current task execution sequence.

[0161] Step 312: adding a game account corresponding to a current task execution sequence satisfying a preset comparison result to an abnormal account set corresponding to the virtual prop collection task.

[0162] Specifically, each to-be-detected task corresponding to the game G is determined, and a violation identifier is added to the abnormal account based on the abnormal account set corresponding to each to-be-detected task.

[0163] By creating a target task execution sequence based on a task execution sequence of a target to-be-detected task, and comparing the target task execution sequence with a current task execution sequence, the abnormal account is determined through the target task execution sequence, that is, the game violation behavior is determined by identifying similar game behaviors, the problem of failure to identify the violation caused by the feedback of false data by the studio is avoided, and the accuracy of the abnormal account identification is improved.

[0164] Corresponding to the method embodiments, the application further provides an abnormal account detection device embodiment, Figure 4 The structure of an abnormal account detection device provided by an embodiment of the application is shown. As shown in Figure 4 The device comprises:

[0165] The receiving module 402 is configured to receive an account detection request for a target application, and determine a target to-be-detected task based on the account detection request;

[0166] The collecting module 404 is configured to obtain a set of accounts that execute the target to-be-detected task, and collect a task execution sequence corresponding to each account in the set of accounts;

[0167] The statistical module 406 is configured to count a task execution number corresponding to each task execution sequence, and create a target task execution sequence based on each task execution number;

[0168] The comparison module 408 is configured to compare the target task execution sequence with each current task execution sequence, and obtain a comparison result corresponding to each current task execution sequence;

[0169] The adding module 410 is configured to add an account corresponding to a current task execution sequence that meets a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.

[0170] Optionally, the device further comprises a comparison sub-module configured to:

[0171] determine a reference to-be-detected task corresponding to the target application, and obtain a reference account set that executes the reference to-be-detected task;

[0172] Collect a reference task execution sequence corresponding to each reference account in the reference account set;

[0173] Count a task execution number corresponding to each reference task execution sequence, and create a target reference task execution sequence based on each task execution number;

[0174] Compare the target reference task execution sequence with each current task execution sequence, and obtain a reference comparison result corresponding to each current task execution sequence;

[0175] The reference comparison result satisfies the preset comparison result. The current task execution sequence corresponding to the account is added to the abnormal account set corresponding to the reference to be detected task.

[0176] Optionally, the apparatus further comprises an adding submodule configured to:

[0177] Determine the to-be-detected account in the abnormal account set corresponding to the target to-be-detected task;

[0178] In a case where the to-be-detected account has a corresponding reference account in the abnormal account set corresponding to the reference to-be-detected task, add a violation identifier to the to-be-detected account.

[0179] Optionally, the collection module 404 is further configured to:

[0180] Determine a target application account in the account set;

[0181] Obtain a task coordinate point set corresponding to the target to-be-detected task executed by the target application account, wherein the task coordinate point set comprises each task coordinate point and a collection time point of each task coordinate point;

[0182] Generate a task execution sequence corresponding to the target application account based on each task coordinate point and the collection time point of each task coordinate point.

[0183] Optionally, the statistical module 406 is further configured to:

[0184] Determine a task execution path, a task execution subsequence, and a task execution order corresponding to each task execution sequence;

[0185] Statistically determine a path quantity corresponding to each task execution path, and determine a task execution subsequence quantity corresponding to each task execution subsequence and a task execution order quantity corresponding to each task execution order based on the path quantity.

[0186] Optionally, the statistical module 406 is further configured to:

[0187] Determine a target task execution subsequence in the task execution subsequence;

[0188] In a case where the task execution subsequence quantity of the target task execution subsequence is greater than a task execution subsequence quantity threshold, create a target task execution sequence based on the target task execution subsequence.

[0189] Optionally, the statistical module 406 is further configured to:

[0190] Determine an initial task execution subsequence according to the target task execution subsequence;

[0191] determine a task execution order set corresponding to the initial task execution subsequence;

[0192] select a target task execution order in the task execution order set, where a number of task execution orders is greater than a task execution order threshold, and determine a target coordinate point corresponding to the target task execution order;

[0193] add the target coordinate point to the initial task execution subsequence;

[0194] continue to perform the step of determining the task execution order set corresponding to the initial task execution subsequence until a number of target points of the initial task execution subsequence is equal to a preset target point number threshold, and obtain a target task execution sequence.

[0195] Optionally, the statistical module 406 is further configured to:

[0196] determine an initial task execution path corresponding to the initial task execution subsequence and a task execution path corresponding to each task execution sequence;

[0197] compare the initial task path with each task execution sequence respectively, and determine a comparison result corresponding to each task execution sequence;

[0198] count a number of task execution sequences with a comparison success result;

[0199] in a case where the number of task execution sequences is greater than a preset sequence number threshold, take the initial task execution subsequence as a target task execution sequence.

[0200] Optionally, the comparison module 408 is further configured to:

[0201] determine a target task execution path corresponding to the target task execution sequence and a current task execution path corresponding to each current task execution sequence;

[0202] compare the target task execution path with the task execution path corresponding to each current task execution sequence respectively, and determine a sequence type corresponding to each current task execution sequence;

[0203] in a case where the current task execution sequence is a first type, determine that a comparison result corresponding to the current task execution sequence is a comparison success, where the first type includes a same type, a loop type, a first jump point type and a sequence missing type;

[0204] in a case where the current task execution sequence is a second type, determine that a comparison result corresponding to the current task execution sequence is a comparison failure, where the second type includes a second jump point type and a jump point number type.

[0205] Optionally, the adding module 410 is further configured to:

[0206] add the account corresponding to the current task execution sequence with a successful comparison result to the abnormal account set corresponding to the target task to be detected.

[0207] Optionally, the device further comprises a deleting sub-module configured to:

[0208] delete each task execution sequence and the task execution quantity corresponding to each task execution sequence.

[0209] The abnormal account detection device provided in the present application comprises a receiving module configured to receive an account detection request for a target application and determine a target task to be detected based on the account detection request; a collecting module configured to obtain an account set performing the target task to be detected and collect a task execution sequence corresponding to each account in the account set; a statistical module configured to count a task execution quantity corresponding to each task execution sequence and create a target task execution sequence based on each task execution quantity; a comparison module configured to compare the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence; and an adding module configured to add an account corresponding to a current task execution sequence with a preset comparison result to an abnormal account set corresponding to the target task to be detected.

[0210] By creating a target task execution sequence based on the task execution order of the target task to be detected and comparing the target task execution sequence with a current task execution sequence, the abnormal account is determined through the target task execution sequence, i.e., the application use violation behavior is determined by identifying similar application use behaviors, the problem of failure to identify the violation behavior caused by the feedback of false data is avoided, and the accuracy of the abnormal account identification is improved.

[0211] The above is a schematic scheme of the abnormal account detection device of the present embodiment. It should be noted that the technical scheme of the abnormal account detection device belongs to the same concept as the technical scheme of the abnormal account detection method described above, and the details of the technical scheme of the abnormal account detection device that are not described in detail can be referred to the description of the technical scheme of the abnormal account detection method described above. In addition, each component in the device embodiment should be understood as a functional module that must be established to realize each step of the program flow or each step of the method. Each functional module is not limited by actual functional division or separation. The device claim defined by such a group of functional modules should be understood as a functional module architecture of the computer program for realizing the solution mainly recorded in the specification, and should not be understood as an entity device for realizing the solution mainly through hardware.

[0212] Figure 5 A structural block diagram of a computing device 500 according to an embodiment of the present application is shown. The components of the computing device 500 include, but are not limited to, a memory 510 and a processor 520. The processor 520 is connected with the memory 510 through a bus 530, and a database 550 is used to save data.

[0213] The computing device 500 also includes an access device 540 that enables the computing device 500 to communicate via one or more networks 560. Examples of these networks include the public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 540 can include one or more of any type of network interface (e.g., network interface card (NIC)) such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a near field communication (NFC) interface, and the like, either wired or wireless.

[0214] In an embodiment of the present application, the above-mentioned components of the computing device 500 and other components not shown in the figure can be connected with each other, for example, through a bus. It should be understood that, Figure 5 the computing device structure block diagram shown is merely for the purpose of example, and is not a limitation on the scope of the present application. Other components can be added or replaced by those skilled in the art as needed. Figure 5 the computing device structure block diagram shown is merely for the purpose of example, and is not a limitation on the scope of the present application. Other components can be added or replaced by those skilled in the art as needed.

[0215] The computing device 500 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smart watch, smart glasses, etc.), or other type of mobile device, or a stationary computing device such as a desktop computer or PC. The computing device 500 can also be a mobile or stationary server.

[0216] The processor 520 is configured to execute computer-executable instructions of the method for detecting an abnormal account.

[0217] The above is a schematic scheme of a computing device according to the present embodiment. It should be noted that the technical scheme of the computing device belongs to the same concept as the technical scheme of the method for detecting an abnormal account described above, and the details of the technical scheme of the computing device that are not described in detail can be referred to the description of the technical scheme of the method for detecting an abnormal account.

[0218] An embodiment of the present application further provides a computer readable storage medium storing computer instructions, which are executed by a processor to implement the method for detecting an abnormal account.

[0219] The above is a schematic solution of the computer readable storage medium of the embodiment. It should be noted that the technical solution of the storage medium and the technical solution of the method for detecting an abnormal account belong to the same concept, and the details of the technical solution of the storage medium which are not described in detail can be referred to the description of the technical solution of the method for detecting an abnormal account.

[0220] The specific embodiments of the present application are described above. Other embodiments are within the scope of the appended claims. In some cases, acts or steps recited in the claims can be performed in a different order than the order in which the acts or steps are recited in the embodiments. In addition, the processes depicted in the accompanying figures do not necessarily require the particular order shown, or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous.

[0221] The computer instructions include computer program codes which can be in the form of source code, object code, executable files or some intermediate forms. The computer readable medium can include any entity or device capable of carrying the computer program codes, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the contents of the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0222] It should be noted that for the above-mentioned method embodiments, in order to facilitate description, they are all described as a combination of a series of acts, but those skilled in the art should know that the present application is not limited to the order of the acts described, because according to the present application, some steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the acts and modules involved are not necessarily essential to the present application.

[0223] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0224] The preferred embodiments of the application disclosed above are only to facilitate the explanation of the application. Alternative embodiments do not describe all the details and do not limit the application to the specific embodiments described. Obviously, many modifications and changes can be made according to the content of the application. The application selects and describes these embodiments in order to better explain the principles and practical applications of the application, so that those skilled in the art can well understand and utilize the application. The application is limited by the claims and their full scope and equivalents.

Claims

1. A method for detecting an abnormal account, characterized in that, The method comprises the following steps: receiving an account detection request for a target application, determining a target to-be-detected task based on the account detection request; obtaining a set of accounts for executing the target to-be-detected task, and collecting a task execution sequence corresponding to each account in the set of accounts; determining a task execution path, a task execution sub-sequence and a task execution order corresponding to each task execution sequence; counting the number of paths corresponding to each task execution path, determining the number of task execution sub-sequences corresponding to each task execution sub-sequence and the number of task execution orders corresponding to each task execution order based on the number of paths, and determining a target task execution sub-sequence in each task execution sequence, and creating a target task execution sequence based on the target task execution sub-sequence if the number of task execution sub-sequences of the target task execution sub-sequence is greater than a threshold value of the number of task execution sub-sequences; comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence; adding an account corresponding to a current task execution sequence that meets a preset comparison result to an abnormal account set corresponding to the target to-be-detected task.

2. The method of claim 1, wherein, Further comprising: determining a reference to-be-detected task corresponding to the target application, and obtaining a reference account set for executing the reference to-be-detected task; collecting a reference task execution sequence corresponding to each reference account in the reference account set; counting the number of task executions corresponding to each reference task execution sequence, and creating a target reference task execution sequence based on each task execution number; comparing the target reference task execution sequence with each current task execution sequence to obtain a reference comparison result corresponding to each current task execution sequence; adding an account corresponding to a current task execution sequence that meets a preset comparison result to an abnormal account set corresponding to the reference to-be-detected task.

3. The method of claim 2, wherein, After being added to the abnormal account set corresponding to the target to-be-detected task, further comprising: determining a to-be-detected account in the abnormal account set corresponding to the target to-be-detected task; adding a violation identifier to the to-be-detected account if the to-be-detected account has a corresponding reference account in the abnormal account set corresponding to the reference to-be-detected task.

4. The method of claim 1, wherein, Collecting a task execution sequence corresponding to each account in the set of accounts comprises: determining a target application account in the set of accounts; obtaining a set of task coordinate points corresponding to the target to-be-detected task executed by the target application account, wherein the set of task coordinate points includes each task coordinate point and a collection time point of each task coordinate point; generating a task execution sequence corresponding to the target application account based on each task coordinate point and the collection time point of each task coordinate point.

5. The method of claim 1, wherein, Creating a target task execution sequence based on the target task execution sub-sequence comprises: determining an initial task execution sub-sequence according to the target task execution sub-sequence; determining a set of task execution orders corresponding to the initial task execution sub-sequence; select a target task execution sequence from the task execution sequence set, the target task execution sequence having a number of task execution sequences greater than a threshold value of task execution sequences; add the target coordinate point corresponding to the target task execution sequence to the initial task execution subsequence; continue to perform the step of determining the task execution sequence set corresponding to the initial task execution subsequence until the number of target points of the initial task execution subsequence is equal to a preset target point number threshold value, and obtain a target task execution sequence.

6. The method of claim 5, wherein, obtaining a target task execution sequence includes: determining an initial task execution path corresponding to the initial task execution subsequence and a task execution path corresponding to each task execution sequence; comparing the initial task execution path with each task execution sequence respectively to determine a comparison result corresponding to each task execution sequence; counting the number of task execution sequences with a comparison success result; in a case where the number of task execution sequences is greater than a preset sequence number threshold value, regarding the initial task execution subsequence as a target task execution sequence.

7. The method of claim 1, wherein, comparing the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence, including: determining a target task execution path corresponding to the target task execution sequence and a current task execution path corresponding to each current task execution sequence; comparing the target task execution path with each current task execution path respectively to determine a sequence type corresponding to each current task execution sequence; in a case where the current task execution sequence is of a first type, determining that the comparison result corresponding to the current task execution sequence is a comparison success, wherein the first type includes a same type, a loop type, a first jump point type and a sequence missing type; in a case where the current task execution sequence is of a second type, determining that the comparison result corresponding to the current task execution sequence is a comparison failure, wherein the second type includes a second jump point type and a jump point number type.

8. The method of claim 6, wherein, after regarding the initial task execution subsequence as a target task execution sequence, further including: deleting each task execution sequence and a task execution number corresponding to each task execution sequence.

9. An abnormal account detecting apparatus characterized by comprising: including: a receiving module configured to receive an account detection request for a target application, and determine a target to-be-detected task based on the account detection request; a collecting module configured to obtain a set of accounts performing the target to-be-detected task, and collect a task execution sequence corresponding to each account in the set of accounts; a counting module configured to determine a task execution path, a task execution subsequence and a task execution sequence corresponding to each task execution sequence; count the number of paths corresponding to each task execution path, and based on the number of paths, determine a task execution subsequence number corresponding to each task execution subsequence and a task execution sequence number corresponding to each task execution sequence, and determine a target task execution subsequence in the task execution subsequence corresponding to each task execution sequence, in a case where the task execution subsequence number of the target task execution subsequence is greater than a task execution subsequence number threshold value, create a target task execution sequence based on the target task execution subsequence; The comparison module is configured to compare the target task execution sequence with each current task execution sequence to obtain a comparison result corresponding to each current task execution sequence; The adding module is configured to add an account corresponding to a current task execution sequence, for which the comparison result meets a preset comparison result, to an abnormal account set corresponding to the target task to be detected.

10. A computing device, comprising: Comprise: A memory and a processor; The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the steps of the method in any one of claims 1 to 8.

11. A computer-readable storage medium storing computer instructions, wherein, The instructions are executed by the processor to realize the steps of the method in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Abnormal account detection model training method and abnormal account detection method

    CN113521750A