A method and device for obtaining a user network behavior portrait and a storage medium
By aggregating user device identifiers and application account information, obtaining their associated data streams and filtering noise, the problem of completeness of user network behavior profiles under unknown user identities is solved, achieving accurate positioning and data accuracy under unknown user identities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-28
- Publication Date
- 2026-03-27
AI Technical Summary
Existing technologies cannot obtain complete data on user network behavior when the user's identity is unknown, resulting in significant discrepancies in the constructed user network behavior profiles.
By acquiring device identifiers and application account information from the data stream set, users are aggregated, their associated data streams are obtained, and network behavior profiles are acquired within a preset time window. Traffic noise filtering and identity identification are used to ensure data integrity and accuracy.
Accurately locating users in the network and obtaining complete user behavior data when the user's identity is unknown improves the accuracy and completeness of user network behavior profiles.
Smart Images

Figure CN116319397B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network monitoring, and in particular to a method and device for obtaining a user network behavior portrait and a storage medium. BACKGROUND
[0002] With the continuous development of Internet technology, the behavior of users accessing the network presents a diversified feature, and the emergence of a large amount of network traffic also brings potential security risks, which puts forward higher requirements for obtaining a user behavior portrait in the network.
[0003] In the prior art, to obtain a user network behavior portrait, the specific user identity is usually known in advance, for example, the identification information of the user to be monitored is known, and then the network behavior of the user is monitored according to the identification information; or when the specific user identity is unknown, the network behavior under the identification is monitored according to the user identification obtained from the traffic.
[0004] However, such a monitoring method, for the network with unknown specific user identity, even if an identification information is extracted from the traffic, the traffic data under the identification information can only reflect part of the behavior data of the user, and the complete behavior data of the user cannot be obtained, so there is a large difference in the user network behavior portrait constructed. SUMMARY
[0005] The present application provides a method and device for obtaining a user network behavior portrait, an electronic device and a storage medium, to solve the problem of missing network behavior data when constructing a user network behavior portrait.
[0006] According to an aspect of the present application, a method for obtaining a user network behavior portrait is provided, comprising:
[0007] obtaining a data stream set within a first preset time; wherein each data stream in the data stream set includes an application type, and the data stream under a first type application in the application type includes account information;
[0008] obtaining each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application;
[0009] obtaining the associated data stream of each aggregated user, and obtaining the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0010] The acquisition of the associated data flow of each of the aggregated users includes: taking the remaining data flow in the at least one belonging device except the data flow related to the non-belonging account and the data flow in the at least one non-belonging device related to the belonging account as the associated data flow of the current aggregated user. By acquiring the data flow in the belonging device which does not include the account information, the data flow generated by the belonging account in the belonging device, and the data flow generated by the belonging account in the non-belonging device, the integrity of the network behavior data of each aggregated user is ensured, and in particular, the loss of the associated data flow in the non-belonging device and the mis-matching of the non-associated data flow in the belonging device are avoided.
[0011] The acquisition of each of the aggregated users according to the device identifier of each of the data flow and the account information of at least one first application in the first type of application includes: determining a target first application in the first type of application according to at least one of the number of data flows, the number of accounts, and whether the account information has an identity identifier; acquiring each of the aggregated users according to the device identifier of each of the data flow and the account information of the target first application; and re-aggregating the account information of the non-target first application in the first type of application with each of the aggregated users according to the device identifier of each of the data flow and the account information of the target first application. The number of data flows and the number of accounts both reflect the application range of the first application, and the more the number is, the larger the application range is, and the more the number of aggregated users acquired is, so as to represent each user in the network to the greatest extent, and the account information containing the identity identifier can not only be used as the aggregation basis of the user, but also directly represent the user identity. In addition, the account of the other first application and the electronic device not aggregated are continuously aggregated to acquire new aggregated users, further expand the monitoring range of the current network, and ensure the integrity of the monitoring objects in the current network; at the same time, the electronic device already aggregated can also continuously acquire the complete user behavior data of the aggregated user through the re-aggregation with the account of the other first application.
[0012] In the method, the obtaining of each aggregated user according to the device identifier of each data flow and the account information of the target first application further comprises: determining whether there is a remaining device identifier that is not aggregated; and if it is determined that there is a remaining device identifier that is not aggregated, re-aggregating the account information of a non-target first application in the first type of application with each aggregated user and the remaining device identifier according to the device identifier of each data flow and the account information of the target first application. The re-aggregating the account information of a non-target first application in the first type of application with each aggregated user according to the device identifier of each data flow and the account information of the target first application comprises: if it is determined that there is no remaining device identifier that is not aggregated, re-aggregating the account information of a non-target first application in the first type of application with each aggregated user according to the device identifier of each data flow and the account information of the target first application. In this way, the aggregation of multiple application accounts and devices is realized, the complete user behavior data is obtained, and the accuracy of obtaining the aggregated user is further improved with the help of the device login relationship of different application accounts.
[0013] The obtaining of the associated data flow of each aggregated user comprises: performing noise filtering on the data flow set according to at least one of a traffic noise list, a traffic data volume threshold, a traffic occurrence time, and a traffic event volume threshold. The noise filtering on the data flow set according to the traffic noise list, the traffic data volume threshold, the traffic occurrence time, and the traffic event volume threshold reduces the number of data flows to be processed, avoids misclassification of noise traffic as user behavior data, and improves the accuracy of the obtained user behavior portrait.
[0014] If the application type further comprises a second type of application, and the account information of at least one target second application in the second type of application is related to an identity identifier, the obtaining of each aggregated user according to the device identifier of each data flow and the account information of at least one first application in the first type of application further comprises: aggregating the account information of at least one target second application in the second type of application with each aggregated user according to the device identifier of each data flow, to obtain the identity identifier of each aggregated user. The account information of each second application under the second type of application can be aggregated with each aggregated user. Based on the above aggregation result, the complete associated data flow of the aggregated user in a non-owned device can be obtained, misclassification of a non-associated data flow in an owned device is avoided, the real identity information of each aggregated user can be further obtained, and information matching of the aggregated user and the real user is realized.
[0015] The data stream set comprises a fixed network data stream set and a non-fixed network data stream set; the obtaining of each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application comprises: obtaining each aggregated user in the fixed network according to the device identifier of each data stream in the fixed network data stream set and the account information of at least one first application in the first type application; and aggregating each data stream in the non-fixed network data stream set with each aggregated user in the fixed network. In this way, the user network behavior data in the same period under the conditions of the fixed network and the non-fixed network is obtained, the integrity of the user network behavior data is ensured, the problem of misallocation of non-fixed network data streams caused by the opening of a hotspot and the like is avoided, and the accuracy of the obtained user network behavior data is improved.
[0016] According to another aspect of the present application, a device for obtaining a user network behavior portrait is provided, comprising:
[0017] a data stream set obtaining module, configured to obtain a data stream set in a first preset time; wherein each data stream in the data stream set comprises an application type, and the data stream under a first type application in the application type comprises account information;
[0018] an aggregated user obtaining module, configured to obtain each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application;
[0019] a user portrait obtaining module, configured to obtain the associated data stream of each aggregated user, and obtain the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0020] According to another aspect of the present application, an electronic device is provided, comprising:
[0021] at least one processor; and
[0022] a memory in communication with the at least one processor; wherein
[0023] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the method for obtaining a user network behavior portrait according to any one of the embodiments of the present application.
[0024] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to execute the method for obtaining a user network behavior portrait according to any one of the embodiments of the present application when executed.
[0025] The technical scheme of the embodiment of the present application, after obtaining the data stream set within the first preset time, obtains each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application, and obtains the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and the preset time window, so that each user in the network is accurately located under the premise of unknown user identity and user quantity, the aggregation of real users in the network is ensured, complete user behavior data is obtained, and the accuracy of the constructed user network behavior portrait is improved.
[0026] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0027] In order to more clearly illustrate the technical scheme in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0028] Figure 1 is a flow chart of a user network behavior portrait acquisition method according to an embodiment of the present application;
[0029] Figure 2 is a flow chart of a user network behavior portrait acquisition method according to an embodiment of the present application;
[0030] Figure 3 is a flow chart of a user network behavior portrait acquisition method according to an embodiment of the present application;
[0031] Figure 4 is a structural schematic diagram of a user network behavior portrait acquisition device according to an embodiment of the present application;
[0032] Figure 5 is a structural schematic diagram of an electronic device for implementing the user network behavior portrait acquisition method of the embodiment of the present application. DETAILED DESCRIPTION
[0033] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application in order to make the technical personnel in the technical field better understand the technical solutions. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by the ordinary skilled in the art without creative work should belong to the scope of protection of the present application.
[0034] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0035] Embodiment one
[0036] Figure 1 A flowchart of a user network behavior portrait acquisition method provided by the first embodiment of the present application, the present embodiment can be applied to acquiring the user portrait of a user based on the network behavior of the user, the method can be executed by a user network behavior portrait acquisition device, the user network behavior portrait acquisition device can be realized in the form of hardware and / or software, and the user network behavior portrait acquisition device is configured in an electronic device. As shown in the figure, the method comprises: Figure 1
[0037] S101, acquiring a data stream set within a first preset time; wherein each data stream in the data stream set comprises an application type, and the data stream under a first type application in the application type comprises account information.
[0038] The flow is also a network flow, which is a one-way message flow transmitted from a source IP (Internet Protocol) address to a destination IP address; each network flow includes five-tuple information, i.e., a source port number, a destination port number, a source IP address, a destination IP address, and a protocol type; the data flow in the example of the present application is data information of each flow recorded in a form of a flow table after extracting a characteristic field of a network flow of a network device (for example, a router) and performing field analysis, which can be stored in a database in a specified data format, for example, an XDR (External Data Representation) format (i.e., an external data format); that is, after a session of the network flow ends or a session timeout, a flow table session of the network flow is output as data in an XDR format, and then saved in the database.
[0039] In particular, the XDR data can be independently indexed according to a date and an application type, so as to facilitate query and acquisition of the data flow. In addition to the five-tuple information, each data flow also includes device identification and timestamp information; the device identification is identification of a sending device or a receiving device of the network flow, specifically, for an uplink network flow, identification of the sending device is acquired, and for a downlink network flow, identification of the receiving device is acquired; a MAC (Media Access Control) address (i.e., a hardware address) or a device serial number in the network flow can be used as the device identification; the timestamp information is a triggering time of the network flow.
[0040] After the network flow is acquired, an application type thereof can be acquired through feature recognition technology, association recognition technology, or behavior recognition technology, for example, the acquired network flow is classified by application through a pre-constructed service perception feature library; a specific classification of the application type can be set as needed; for example, the application type can include social entertainment, internet access, business service, network architecture, and general software, and the social entertainment can specifically include instant messaging, the business service can specifically include an electronic mailbox, and the internet access can specifically include website browsing and other sub-classifications.
[0041] The first type of application is an application whose network behavior depends on account information, such as the instant messaging application and the email application in the technical solution described above, which both need to use the account information in the application as the access basis; and the website browsing does not need to depend on specific account information; therefore, in the embodiment of the application, the instant messaging application can be taken as the first type of application. After each network flow is obtained, if it is determined that the application type of the network flow is the first type of application, the specific application category (i.e., the specific application name) and the specific account information are continuously obtained and added to the flow table. Therefore, each data flow in the data flow set obtained by the database records the application type of each data flow, and for the application containing the account information, the name of the specific application and the account information under the application are also recorded.
[0042] S102, obtaining each aggregated user according to the device identifier of each data flow and the account information of at least one first application in the first type of application.
[0043] Taking the instant messaging application as the first type of application, the pre-specified first application is determined as the target first application in the instant messaging application; the account information of all target first applications in the data flow is extracted, and the user is aggregated according to the association between the account information of the target first application and the device identifier; for example, the target first application is application A, for an account A1 in application A, if the data flow involving the account A1 is all related to a device A1, and there is no data flow of other accounts of application A in the device A1, then the account A1 and the device A1 can be aggregated as one aggregated user, that is, one first application account and one device are aggregated as one user.
[0044] If the data flow involving the account A1 is related to devices B1 and B2, and there is no data flow of other accounts of application A in the devices B1 and B2, then the account A1 and the devices B1 and B2 can be aggregated, that is, one first application account and multiple devices are aggregated as one user; if the data flow of the account A1 and the account A2 is only related to the device A1, and there is no data flow of other accounts of application A in the device A1, then the account A1 and the account A2 and the device A1 can be aggregated as one user, that is, multiple first application accounts and one device are aggregated as one user.
[0045] If the data stream of the account A1 is only related to the device B1 and the device B2, the data stream of the account A2 is also only related to the device B1 and the device B2, and there is no data stream of other accounts of the application A in the device B1 and the device B2, the account A1 and the account A2 can be aggregated with the device A1 and the device A2 as one user, that is, a plurality of first application accounts and a plurality of devices are aggregated as one user. Thus, the number of specific users in the network traffic within the first preset time is obtained.
[0046] Meanwhile, due to the existence of temporary login phenomenon, that is, in the devices belonging to the user A, there can be a case that the user B temporarily uses and logs in the account of the user B himself, and the use time of the above-mentioned temporary login is usually short, therefore, the aggregation relationship between the account and the device can also be determined according to the data stream quantity or the data stream quantity proportion of each account on each device; for example, if the data stream quantity of an account on a device is greater than a first quantity threshold, or the data stream quantity of the account on the device accounts for a proportion of the data stream quantity on all devices, which is greater than the first quantity threshold, it can be determined that the account and the current device have an aggregation relationship; otherwise, it is determined as temporary login, and the account and the current device are not aggregated.
[0047] In addition, if the account A1 has a traffic record in the device A2, but the data stream quantity is small (that is, less than or equal to the first quantity threshold), and the data stream quantity of the account A1 in the device A1 is large (that is, greater than the first quantity threshold), and there is a traffic record of the account A2 in the device A1, and there is no traffic record of the account A1 in the device A2, it also indicates that the account A1 is only temporarily logged in in the device A2, and the account A1 and the device A2 cannot be aggregated as one user, obviously, the account A1 and the account A2 cannot be aggregated with the device A1 and the device A2 as one user.
[0048] In particular, if the first type application includes a plurality of first applications, after the target first application is aggregated with each device, the account information of the remaining non-target first application can be aggregated with each device based on the same manner, so as to bind the account information of each first application with the corresponding device respectively.
[0049] S103, acquiring the associated data stream of each aggregated user, and respectively acquiring the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0050] The data stream excluding the account information in the device to which the aggregation user belongs is related to the aggregation user, and the data stream of the account (including the account of the target first application and the account of the non-target first application) to which the aggregation user belongs in each device (including the device to which the aggregation user belongs and the device to which the aggregation user does not belong) is the actual attribution flow of the aggregation user, that is, the associated data stream.
[0051] According to the timestamp information, the associated data stream of each aggregation user is sorted, and after the sorting is completed, the data stream is aggregated according to the application type of each associated data stream to obtain the user behavior record on the timeline; for example, user A uses application A from 0 o'clock to 0 o'clock 10 minutes; uses application B from 0 o'clock 5 minutes to 0 o'clock 15 minutes; obviously, a user can use multiple applications at the same time; after the timeline information of each aggregation user is determined, the behavior data of the user in each window can be determined according to a preset time window.
[0052] Different time windows obtain different user network behavior portraits; for example, 15 minutes is taken as a time window; user A uses application A and application B in the first time window, and uses application B in the second time window; and 5 minutes is taken as a time window; user A uses application A in the first time window, uses application A and application B in the second time window, and uses application B in the third time window. The user behavior portrait obtained based on the above technical solution can not only ensure the network behavior supervision of each user, monitor the occurrence of abnormal network behavior, and improve network security, but also can be used to help each user improve work efficiency.
[0053] Optionally, in the embodiment of the application, the associated data stream of each aggregation user is obtained, including: taking the remaining data stream in at least one belonging device except the data stream related to the non-belonging account and the data stream in at least one non-belonging device related to the belonging account as the associated data stream of the current aggregation user.
[0054] Specifically, the device belonging to the current aggregation user is a device having a home relationship with the current aggregation user, i.e., a device belonging to the current aggregation user according to the aggregation relationship; the device not belonging to the current aggregation user is a device not having a home relationship with the current aggregation user, i.e., a device belonging to another aggregation user according to the aggregation relationship; if the device belonging to the current aggregation user includes traffic generated by temporary login of another user, it is obvious that the part of traffic should belong to the actual user and cannot belong to the device owner; similarly, traffic generated by temporary login of the current aggregation user to another user's device should belong to the current aggregation user and cannot belong to the device owner; therefore, for each aggregation user, the data flow related to the aggregation user includes a data flow not including account information in the device belonging to the aggregation user, a data flow generated by an account in the device belonging to the aggregation user, and a data flow generated by an account in the device not belonging to the aggregation user; by obtaining the data flow not including the account information in the device belonging to the aggregation user, the data flow generated by the account in the device belonging to the aggregation user, and the data flow generated by the account in the device not belonging to the aggregation user, the integrity of the network behavior data of each aggregation user is ensured, and in particular, loss of the associated data flow in the device not belonging to the aggregation user and mis-matching of the non-associated data flow in the device belonging to the aggregation user are avoided.
[0055] Optionally, in the embodiment of the application, the obtaining of the associated data flow of each aggregation user specifically includes: performing noise filtering on the data flow set according to at least one of a traffic noise list, a traffic data volume threshold, a traffic generation time, and a traffic event volume threshold. Specifically, the traffic noise list defines a plurality of application types (for example, input method type applications or system security type applications) or a plurality of specific application names (for example, application C); the above type applications usually generate traffic due to software version upgrade and are not traffic generated by user active triggering behavior, therefore, if the application type of the current data flow is the application type defined in the traffic noise list or the application name is the specific application defined in the traffic noise list, the above data flow is regarded as noise traffic and is not an associated data flow of the user behavior portrait.
[0056] The traffic data volume threshold defines the data volume in a unit of time; normal network behavior of a user usually generates a large data volume, if the data volume in a unit of time is low, it is possible that one or more applications in the system and the corresponding server have a regular communication behavior and are not active triggering behavior of the user, therefore, the above data flow can also be regarded as noise traffic;
[0057] The flow occurrence time is the time when the flow passes through the network device, and the flow event is the number of data packets in the flow. If the flow occurs within a specific time period, for example, from 3 a.m. to 5 a.m., or the number of flow events is too low, it may be caused by automatic update of the application software. In particular, if the number of flow events in the above-mentioned specific time period is small, each data stream in the time period can be regarded as noise flow. Through the noise flow list, the flow data volume threshold, the flow occurrence time, and the flow event volume threshold, the noise filtering of the data stream set reduces the number of data streams to be processed, avoids misclassification of noise flow as user behavior data, and improves the accuracy of the obtained user behavior portrait.
[0058] Optionally, in the embodiment of the application, if the application type further includes a second type of application, and the account information of at least one target second application in the second type of application is related to the identity, and the identity of each aggregated user is obtained according to the device identifier of each data stream and the account information of at least one first application in the first type of application, specifically further comprising: associating the account information of at least one target second application in the second type of application with each aggregated user according to the device identifier of each data stream, to obtain the identity of each aggregated user.
[0059] Specifically, taking the above technical solution as an example, the first type of application can include an instant messaging application, and the second type of application can include an electronic mailbox application. Although the instant messaging application has a wide range of uses, its account information may not be associated with the user's identity. However, in the electronic mailbox, especially in a designated type of work mailbox, the mailbox account often uses the user's real name or name abbreviation as a prefix, and the mailbox account itself reflects the user's real information. Therefore, the account information of each second application under the second type of application can be aggregated with each aggregated user, and based on the above aggregation result, not only can the complete associated data stream of the aggregated user in the non-owned device be obtained, avoiding the misclassification of the non-associated data stream in the owned device, but also the real identity information of each aggregated user can be further obtained, realizing the information matching of the aggregated user and the real user.
[0060] The technical solution of the embodiment of the application obtains the data stream set within the first preset time, obtains each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type of application, and respectively obtains the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and the preset time window, so that each user in the network can be accurately located under the premise of unknown user identity and user quantity, ensuring the aggregation of the real user in the network, and the complete user behavior data obtained improves the accuracy of the user network behavior portrait constructed.
[0061] Embodiment Two
[0062] Figure 2 A flowchart of a method for obtaining a user network behavior portrait according to Embodiment Two of the present application is shown in FIG. 2. The relationship between this embodiment and the above-mentioned embodiment is that the account information of a plurality of first applications in the first type of applications is aggregated with the device identifiers. As shown in FIG. 2, the method comprises the following steps. Figure 2
[0063] S201: Obtain a data stream set within a first preset time; each data stream in the data stream set comprises an application type, and the data stream under the first type of application in the application type comprises account information.
[0064] S202: Determine a target first application in the first type of applications according to at least one of the number of data streams, the number of accounts, and whether the account information has an identity identifier.
[0065] The number of data streams and the number of accounts both reflect the scope of application of the first application. The greater the number, the greater the scope of application, and the more the number of aggregated users obtained, so as to represent each user in the network to the greatest extent. Therefore, the first application with the largest number of data streams or accounts can be taken as the target first application. In addition, the account information of some instant messaging applications is composed of the real name or identifier of the user. The account information can not only be used as an aggregation basis for the user, but also directly represent the identity of the user. Therefore, the first application whose account information has an identity identifier can be taken as the target first application.
[0066] In particular, the target first application can also be determined according to the number of data streams, the number of accounts, and whether the account information has an identity identifier. That is, if the account information of the current first application has an identity identifier, and the number of data streams or the number of accounts is greater than a preset number threshold, the current first application is taken as the target first application. If the account information of the current first application has an identity identifier, and the number of data streams or the number of accounts is less than or equal to the preset number threshold, the first application with the largest number of data streams or accounts is taken as the target first application.
[0067] S203: Obtain each aggregated user according to the device identifier of each data stream and the account information of the target first application.
[0068] S204: Aggregate the account information of the non-target first application in the first type of applications with each aggregated user again according to the device identifier of each data stream and the account information of the target first application.
[0069] As described in the above technical solution, after the target first application is aggregated with the electronic device, not only the data stream in the electronic device to which the aggregated user belongs can be obtained, but also the account of the target first application to which the aggregated user belongs in the data stream in the non-belonging device can be obtained. Similarly, based on the above technical solution, the account of the other first application can be further aggregated with the electronic device, and thus the account of the other first application to which the aggregated user belongs in the data stream in the non-belonging device can be obtained.
[0070] In particular, when the account information of the other first application is aggregated with the aggregated user, in addition to the association relationship between the account information and the electronic device, the association relationship between the account information of the other first application and the account information of the target first application can also be used for aggregation. For example, if the target first application (for example, application B1) and the other first application (for example, application B2) have a common login device, and also have non-common login devices, but the number of data streams generated in the non-common login devices is small, and the number of data streams generated in the common login devices is large, it can also be determined that the application B1 and the application B2 are the same aggregated user. Thus, not only the aggregation of multiple application accounts and devices is realized to facilitate the acquisition of complete user behavior data, but also the acquisition accuracy of the aggregated user is further improved by means of the device login relationship of different application accounts.
[0071] S205, acquiring the associated data stream of each aggregated user, and respectively acquiring the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0072] Optionally, in the embodiment of the application, after the aggregated user is acquired according to the device identifier of each data stream and the account information of the target first application, the method further includes: determining whether there is a remaining device identifier that has not been aggregated; if it is determined that there is a remaining device identifier that has not been aggregated, re-aggregating the account information of the non-target first application in the first type application with each aggregated user and the remaining device identifier according to the device identifier of each data stream and the account information of the target first application; and re-aggregating the account information of the non-target first application in the first type application with each aggregated user according to the device identifier of each data stream and the account information of the target first application, including: if it is determined that there is no remaining device identifier that has not been aggregated, re-aggregating the account information of the non-target first application in the first type application with each aggregated user according to the device identifier of each data stream and the account information of the target first application.
[0073] Specifically, the target first application has a wide range of application, but it cannot guarantee that each real user in the network has login behavior under the application, therefore, after the target first application and the device identifier are aggregated, there may be electronic devices that are not aggregated, therefore, the account of the other first application and the electronic devices that are not aggregated are further aggregated to obtain new aggregated users, further expand the monitoring range of the current network, and ensure the integrity of the monitoring objects in the current network, and the aggregated electronic devices can also be re-aggregated with the account of the other first application to continue to obtain the complete user behavior data of the aggregated users.
[0074] The technical scheme of the embodiment of the application reflects the application range of the first application through the number of data streams and the number of accounts, the more the number, the larger the application range, and the more the number of aggregated users obtained, to represent each user in the network to the greatest extent, the account information containing the identity identifier can not only be used as an aggregation basis for the user, but also directly represent the user identity, in addition, the account of the other first application and the electronic devices that are not aggregated are further aggregated to obtain new aggregated users, further expand the monitoring range of the current network, and ensure the integrity of the monitoring objects in the current network, and the aggregated electronic devices can also be re-aggregated with the account of the other first application to continue to obtain the complete user behavior data of the aggregated users.
[0075] Embodiment three
[0076] Figure 3 A flowchart of a user network behavior portrait acquisition method provided by the third embodiment of the application, the relationship between the present embodiment and the above-mentioned embodiments is that after the aggregated users under the fixed network are obtained, the non-fixed network data stream set and the above-mentioned aggregated users are further aggregated. As shown in the figure, Figure 3 The method comprises the following steps:
[0077] S301, obtaining a data stream set within a first preset time; wherein each data stream in the data stream set comprises an application type, and the data stream under the first type application in the application type comprises account information; the data stream set comprises a fixed network data stream set and a non-fixed network data stream set.
[0078] S302, obtaining each aggregated user in the fixed network according to the device identifier of each data stream in the fixed network data stream set and the account information of at least one first application in the first type application.
[0079] S303, aggregating each data stream in the non-fixed network data stream set with each aggregated user in the fixed network.
[0080] The fixed network data stream set can be obtained through a router in a local area network, and the non-fixed network data stream set can be obtained through a base station. For a data stream under a non-fixed network, when an electronic device (for example, device A) opens a hotspot, another electronic device (for example, device B) accesses the base station through the hotspot of device A. Since device B obtains data information through the traffic in device A, the traffic obtained by the base station side substantially only contains the device identifier of device A and does not contain the device identifier of device B. Therefore, if user aggregation is directly performed based on the non-fixed network data stream set, the data stream generated by device B accessing the hotspot will be mistakenly considered as being generated by device A opening the hotspot, and thus the behavior data of the aggregated users corresponding to device A obtained will be deviated.
[0081] Therefore, when the aggregated users under the fixed network are obtained through the fixed network data stream set, each data stream in the non-fixed network data stream set is first distributed to a corresponding aggregated user according to the account information of each first application in the first type application, and then distributed to the corresponding aggregated user according to the device identifier, so as to realize the acquisition of user network behavior data under the fixed network and the non-fixed network in the same period. Not only the integrity of the user network behavior data is ensured, but also the misallocation problem of the non-fixed network data stream caused by the opening of the hotspot and the like is avoided, and the accuracy of the acquired user network behavior data is improved.
[0082] S304, obtaining the associated data stream of each aggregated user, and respectively obtaining the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0083] The technical scheme of the embodiment of the application, after obtaining each aggregated user in the fixed network according to the device identifier of each data stream in the fixed network data stream set and the account information of at least one first application in the first type application, aggregates each data stream in the non-fixed network data stream set with each aggregated user in the fixed network, so as to realize the acquisition of user network behavior data under the fixed network and the non-fixed network in the same period. Not only the integrity of the user network behavior data is ensured, but also the misallocation problem of the non-fixed network data stream caused by the opening of the hotspot and the like is avoided, and the accuracy of the acquired user network behavior data is improved.
[0084] Embodiment four
[0085] Figure 4 is a structural block diagram of a user network behavior portrait acquisition device provided by the fourth embodiment of the application. The device specifically comprises:
[0086] The data stream set acquisition module 401 is configured to acquire a data stream set within a first preset time, wherein each data stream in the data stream set comprises an application type, and the data stream under a first type application in the application type comprises account information.
[0087] The aggregated user acquisition module 402 is configured to acquire each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application.
[0088] The user portrait acquisition module 403 is configured to acquire the associated data stream of each aggregated user, and acquire the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and a preset time window.
[0089] The technical scheme of the embodiment of the application acquires the data stream set within the first preset time, acquires each aggregated user according to the device identifier of each data stream and the account information of at least one first application in the first type application, and acquires the network behavior portrait of each aggregated user according to the associated data stream of each aggregated user and the preset time window, so that each user in the network can be accurately located under the premise that the user identity and the number of users are unknown, the aggregated acquisition of the real user in the network is ensured, the complete user behavior data acquired is improved, and the accuracy of the user network behavior portrait constructed is improved.
[0090] Optionally, the user portrait acquisition module 403 is specifically configured to acquire, as the associated data stream of the current aggregated user, the remaining data stream in at least one belonging device except the data stream related to the non-belonging account, and the data stream related to the belonging account in at least one non-belonging device.
[0091] Optionally, the aggregated user acquisition module 402 is configured to determine a target first application in the first type application according to at least one of the number of data streams, the number of accounts, and whether the account information has an identity identifier, acquire each aggregated user according to the device identifier of each data stream and the account information of the target first application, and aggregate the account information of the non-target first application in the first type application with each aggregated user again according to the device identifier of each data stream and the account information of the target first application.
[0092] Optionally, the aggregated user obtaining module 402 is specifically configured to determine whether there is a remaining device identifier that has not been aggregated; if it is determined that there is a remaining device identifier that has not been aggregated, according to the device identifier of each data flow and the account information of the target first application, the account information of a non-target first application in the first type application is aggregated with each aggregated user and the remaining device identifier again; if it is determined that there is no remaining device identifier that has not been aggregated, according to the device identifier of each data flow and the account information of the target first application, the account information of a non-target first application in the first type application is aggregated with each aggregated user again.
[0093] Optionally, the user portrait obtaining module 403 is specifically configured to perform noise filtering on the data flow set according to at least one of a traffic noise list, a traffic data volume threshold, a traffic occurrence time and a traffic event volume threshold.
[0094] Optionally, if the application type further includes a second type application, and the account information of at least one target second application in the second type application is related to an identity, the aggregated user obtaining module 402 is specifically configured to aggregate the account information of at least one target second application in the second type application with each aggregated user according to the device identifier of each data flow, to obtain the identity of each aggregated user.
[0095] Optionally, the data flow set includes a fixed network data flow set and a non-fixed network data flow set.
[0096] The aggregated user obtaining module 402 is specifically configured to obtain each aggregated user in the fixed network according to the device identifier of each data flow in the fixed network data flow set and the account information of at least one first application in the first type application; and aggregate each data flow in the non-fixed network data flow set with each aggregated user in the fixed network.
[0097] The above device can execute the user network behavior portrait obtaining method provided by any embodiment of the application, has the corresponding function modules and beneficial effects of executing the method. Technical details not described in detail in the embodiment can be referred to the user network behavior portrait obtaining method provided by any embodiment of the application.
[0098] Embodiment five
[0099] Figure 5A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0100] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0101] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0102] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as methods for acquiring user network behavior profiles.
[0103] In some embodiments, the method of obtaining a user network behavior profile can be implemented as a computer program tangibly embodied in a computer readable storage medium, e.g., a memory device. In some embodiments, portions or all of the computer program can be loaded onto and / or installed on the heterogeneous hardware accelerator via a ROM and / or communication unit. When the computer program is loaded onto the RAM and executed by the processor, one or more steps of the method of obtaining a user network behavior profile described above can be performed. Alternatively, in other embodiments, the processor can be configured, by any other suitable means (e.g., by means of firmware), to perform the method of obtaining a user network behavior profile.
[0104] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0105] Computer programs used to implement the methods of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor of the machine, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0106] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0107] To provide for interaction with a user, the systems and techniques described here can be implemented on a heterogeneous hardware accelerator having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the heterogeneous hardware accelerator. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0108] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0109] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0110] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, each step described in the present application can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which is not limited herein.
[0111] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for obtaining a user's online behavior profile, characterized in that, include: Obtain a set of data streams within a first preset time period; wherein, each data stream in the set of data streams includes an application type, and the data streams under the first type of application in the application type all include account information; Based on the device identifier of each data stream and the account information of at least one first application in the first type of application, obtain each aggregated user; The step of obtaining each aggregated user based on the device identifier of each data stream and the account information of at least one first application in the first type of application includes: determining a target first application in the first type of application based on the number of data streams, the number of accounts, and whether the account information has an identity identifier; obtaining each aggregated user based on the device identifier of each data stream and the account information of the target first application; determining whether there are any remaining device identifiers that have not been aggregated; if it is determined that there are no remaining device identifiers that have not been aggregated, aggregating the account information of non-target first applications in the first type of application with each aggregated user again based on the device identifier of each data stream and the account information of the target first application; if it is determined that there are remaining device identifiers that have not been aggregated, aggregating the account information of non-target first applications in the first type of application with each aggregated user and the remaining device identifiers again based on the device identifier of each data stream and the account information of the target first application. Obtain the associated data streams of each aggregated user, and based on the associated data streams of each aggregated user and a preset time window, obtain the network behavior profiles of each aggregated user.
2. The method according to claim 1, characterized in that, The step of obtaining the associated data streams of each of the aggregated users includes: The remaining data streams from at least one affiliated device, excluding data streams related to non-affiliated accounts, and the data streams from at least one non-affiliated device related to the affiliated account, are used as the associated data streams for the current aggregated user.
3. The method according to claim 1, characterized in that, The acquisition of the associated data streams for each of the aggregated users specifically includes: The data stream set is noise filtered based on at least one of the following: a traffic noise list, a traffic data volume threshold, a traffic occurrence time, and a traffic event volume threshold.
4. The method according to claim 1, characterized in that, If the application type further includes a second type of application, and the account information of at least one target second application in the second type of application is related to an identity identifier, the step of obtaining each aggregated user based on the device identifier of each data stream and the account information of at least one first application in the first type of application specifically includes: Based on the device identifier of each data stream, the account information of at least one of the target second applications in the second type of application is aggregated with each of the aggregated users to obtain the identity identifier of each aggregated user.
5. The method according to claim 1, characterized in that, The data stream set includes a fixed network data stream set and a non-fixed network data stream set; The step of obtaining each aggregated user based on the device identifier of each data stream and the account information of at least one first application in the first type of application includes: Based on the device identifier of each data stream in the fixed network data stream set, and the account information of at least one first application in the first type of application, obtain each aggregated user in the fixed network. The data streams in the non-fixed network data stream set are aggregated with the aggregated users in the fixed network.
6. A device for acquiring user network behavior profiles, characterized in that, include: A data stream set acquisition module is used to acquire a data stream set within a first preset time period; wherein, each data stream in the data stream set includes an application type, and the data streams under the first type of application include account information; The aggregated user acquisition module is used to acquire each aggregated user based on the device identifier of each data stream and the account information of at least one first application in the first type of application; The aggregated user acquisition module is specifically used to determine a target first application in the first type of application based on the number of data streams, the number of accounts, and whether the account information has an identity identifier; to acquire each aggregated user based on the device identifier of each data stream and the account information of the target first application; to determine whether there are any remaining device identifiers that have not been aggregated; if it is determined that there are no remaining device identifiers that have not been aggregated, to aggregate the account information of non-target first applications in the first type of application with each aggregated user again based on the device identifier of each data stream and the account information of the target first application; if it is determined that there are remaining device identifiers that have not been aggregated, to aggregate the account information of non-target first applications in the first type of application with each aggregated user and the remaining device identifier again based on the device identifier of each data stream and the account information of the target first application. The user profile acquisition module is used to acquire the associated data streams of each aggregated user, and to acquire the network behavior profiles of each aggregated user based on the associated data streams of each aggregated user and a preset time window.
7. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the method for obtaining a user network behavior profile according to any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the method for obtaining a user network behavior profile as described in any one of claims 1-5.
Citation Information
Patent Citations
User identity recognition method and device, computer equipment and storage medium
CN111651741A
Information aggregation method and device, electronic equipment, storage medium and program product
CN113051313A