A false quantity data screening method for device ID and a storage medium
Patent Information
- Application Number
- CN202311457306.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-03
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2043-11-03
AI Technical Summary
[0013] In summary, the process involves obtaining a list of IDs to be identified, verifying their authenticity based on their checksums, and marking successfully verified IDs as first intermediate IDs. The process then involves obtaining the target software interaction information corresponding to each first intermediate ID, marking first intermediate IDs whose target software interaction information meets a preset time range as second intermediate IDs, marking second intermediate IDs whose device hardware and user information meet a first preset condition as third intermediate IDs, and marking third intermediate IDs that meet the second preset condition as fourth intermediate IDs. Clustering is then performed on the fourth intermediate IDs, and fourth intermediate IDs whose clusters contain more than a preset threshold are considered active traffic. By filtering IDs layer by layer, those with incorrect checksums, those that haven't been used in a long time, virtual machines, and devices specifically used for traffic manipulation are removed, thus more accurately obtaining active traffic.
Smart Images

Figure CN117473231B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet technology, and in particular to a method, electronic device, and storage medium for screening fake data. Background Technology
[0002] Currently, when promoting an app, it is necessary to find a suitable platform and an effective audience. Generally, multiple channels are used for data analysis to determine whether there is a large amount of fake data. The premise of various data analyses is to obtain accurate data. If the data is not accurate enough, it is meaningless to analyze it. Therefore, screening for fake data is particularly important; how to identify fake data is the prerequisite for carrying out various tasks. Summary of the Invention
[0003] To address the aforementioned technical problems, the present invention adopts the following technical solution: a method for screening fake data, wherein the method is used to filter out fake data based on device ID to obtain the activity level of the target APP, wherein the device where the target APP is located integrates a target SDK for collecting device information, the device information including at least the software information installed on the device, the interaction information between the device user and the target software of the target APP, the device hardware information and the device version information, and the device ID has a check bit;
[0004] The method includes the following steps:
[0005] S100, Obtain the list of IDs to be identified, A = {A1, A2, ..., A...} i A m}, A i It is the i-th ID to be identified, where i ranges from 1 to m, and m is the number of IDs to be identified;
[0006] S200, based on A i Check bit pair A i Perform authenticity verification and mark the successfully verified IDs to be identified as the first intermediate IDs to obtain the list of first intermediate IDs;
[0007] S300, obtain the target software interaction information corresponding to the first intermediate ID. If the latest opening time of the target software corresponding to the first intermediate ID is within a preset time range, mark the first intermediate ID as the second intermediate ID, thereby obtaining the second intermediate ID list. The target software interaction information records the latest opening time of the target APP.
[0008] S400, obtain the device hardware information and the device installed software information corresponding to the second intermediate ID, and when the device hardware information and the device installed software information corresponding to the second intermediate ID both meet the first preset condition, mark the second intermediate ID as the third intermediate ID, thereby obtaining the list of third intermediate IDs;
[0009] S500, obtain the version information of the third intermediate ID, and when the version information of the third intermediate ID meets the second preset condition, mark the third intermediate ID as the fourth intermediate ID, thereby obtaining the fourth intermediate ID;
[0010] S600 performs clustering calculation on the fourth intermediate ID and obtains the number of fourth intermediate IDs contained in each cluster after clustering. When the number of fourth intermediate IDs contained in a cluster is greater than a preset threshold, the fourth intermediate IDs under that cluster are marked as dummy data.
[0011] A non-transitory computer-readable storage medium storing at least one instruction or at least one program, characterized in that the at least one instruction or the at least one program is loaded and executed by a processor to implement the spoofing data screening method for device ID as described above.
[0012] The present invention has at least the following beneficial effects:
[0013] In summary, the process involves obtaining a list of IDs to be identified, verifying their authenticity based on their checksums, and marking successfully verified IDs as first intermediate IDs. The process then involves obtaining the target software interaction information corresponding to each first intermediate ID, marking first intermediate IDs whose target software interaction information meets a preset time range as second intermediate IDs, marking second intermediate IDs whose device hardware and user information meet a first preset condition as third intermediate IDs, and marking third intermediate IDs that meet the second preset condition as fourth intermediate IDs. Clustering is then performed on the fourth intermediate IDs, and fourth intermediate IDs whose clusters contain more than a preset threshold are considered active traffic. By filtering IDs layer by layer, those with incorrect checksums, those that haven't been used in a long time, virtual machines, and devices specifically used for traffic manipulation are removed, thus more accurately obtaining active traffic. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a flowchart of a method for screening fake data for device IDs, provided as an embodiment of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] This invention provides a method for screening fake data based on device ID. The method is used to filter out fake data based on device ID to obtain the activity level of a target APP. The device where the target APP is located integrates a target SDK for collecting device information. The device information includes at least the software information installed on the device, the interaction information between the device user and the target software of the target APP, the device hardware information, and the device version information. The device ID has a check bit.
[0018] Specifically, as those skilled in the art will know, any format of the check bit in the prior art is within the scope of protection of this invention, and will not be elaborated further here.
[0019] The method includes the following steps:
[0020] S100, Obtain the list of IDs to be identified, A = {A1, A2, ..., A...} i A m}, A i It is the i-th ID to be identified, where i ranges from 1 to m, and m is the number of IDs to be identified.
[0021] Specifically, the ID to be identified refers to the device ID that is to be determined whether the data is fake. Specifically, the device ID is the unique identifier of the device.
[0022] S200, based on A i Check bit pair A i Perform authenticity verification and mark the successfully verified IDs as the first intermediate IDs to obtain the first intermediate ID list.
[0023] Specifically, verification is performed using a check digit. IDs that fail verification are identified as fake data and are removed.
[0024] S300, obtain the target software interaction information corresponding to the first intermediate ID. If the latest opening time of the target software corresponding to the first intermediate ID is within a preset time range, mark the first intermediate ID as the second intermediate ID, thereby obtaining the second intermediate ID list. The target software interaction information records the latest opening time of the target APP.
[0025] Specifically, by matching the first intermediate ID with the device ID stored in the database, the device information corresponding to the first intermediate ID is obtained, thereby obtaining the target APP interaction information, device hardware information, device user information and device version information corresponding to the first intermediate ID. The device information corresponding to the device ID stored in the database is collected through the target SDK.
[0026] Specifically, the target APP interaction information record includes the latest opening time of the target APP. The activity of the target APP is determined by the latest opening time of the target APP. If the latest opening time of the target APP exceeds a preset time range, it may have not been opened for a long time. In this case, the first intermediate ID is considered to be inactive with the target APP and is considered to be fake traffic. If the latest opening time of the target APP cannot be detected, it is considered that the first intermediate ID has not opened the target APP and is considered to be fake traffic. If the latest opening time of the target APP corresponding to the first intermediate ID is within the preset time range, the first intermediate ID is considered to be active with the target APP and is marked as the second intermediate ID.
[0027] Furthermore, the preset time range can be determined according to actual needs; for example, the preset time range is one year.
[0028] S400: Obtain the device hardware information and the device installed software information corresponding to the second intermediate ID. When both the device hardware information and the device installed software information corresponding to the second intermediate ID meet the first preset condition, mark the second intermediate ID as the third intermediate ID, thereby obtaining the list of third intermediate IDs.
[0029] Specifically, the device hardware information and device user information are used to determine whether the device corresponding to the second intermediate ID is a fake machine. A fake machine is a device that is not used normally, such as a simulator or a device specifically used for inflating traffic. Fake machines are eliminated to obtain the third intermediate ID.
[0030] Specifically, the software information installed on the device meets the first preset condition, including: call logs, contacts, SMS messages, and photo albums are all not empty; the installed software includes at least one software from the first preset software list, but does not include any software from the second preset software list; wherein the number of installed software in the first preset software list is greater than the preset number of installations; and the software in the second preset software list is software from any emulator, such as APIDemos or DevTools. The first preset software refers to commonly used software on the device, such as the top 10 installed apps. In one embodiment, the software in the first preset software list is a communication app with a large number of installations, such as QQ or WeChat; it can also be an entertainment app, such as TikTok.
[0031] Specifically, the device hardware includes: a card slot, a communication card inserted into the card slot, a battery, installed sensors, and other hardware in the device.
[0032] Furthermore, the device hardware information meeting the first preset condition includes: the device has a card slot and a communication card inserted into the card slot; the battery temperature and power level change continuously over time; the installed sensors belong to the third preset sensor list; and other hardware in the device does not conform to the fourth preset simulator name list. The sensors in the third preset sensor list are sensors installed on the mobile device. The fourth preset simulator name is a preset simulator name, such as a static field of the `android.os.Build` class.
[0033] Furthermore, the third preset sensor list includes: temperature sensor, gravity sensor, gyroscope, pressure sensor, WIFI, GPS, Bluetooth, light sensor, pedometer, proximity sensor, accelerometer, and magnetic field sensor. This can be understood as determining whether a device is genuine by detecting its unique hardware sensors.
[0034] Furthermore, if any item in the device hardware information of the second intermediate ID does not meet the preset conditions, the second intermediate ID will be identified as fake data. This can be understood as the hardware corresponding to the device hardware information being a necessary condition for a real device. For example, if the temperature sensor of the second intermediate ID is not installed, the device corresponding to the second intermediate ID is considered to be a fake device, and the device ID will not be recorded as active traffic.
[0035] In one embodiment of the present invention, the device is also identified as a fake device by extracting static fields of the device's android.os.Build class. For example, if the generic_x86 / sdk_x86 field is detected, the device is identified as a fake device.
[0036] S500, obtain the version information of the third intermediate ID, and when the version information of the third intermediate ID meets the second preset condition, mark the third intermediate ID as the fourth intermediate ID, thereby obtaining the fourth intermediate ID.
[0037] Specifically, the device version information includes at least the device model, device manufacturer information, system version number, and baseband version number. The model, manufacturer information, system version number, and baseband version number are used to determine whether the device has been flashed.
[0038] Specifically, by examining the device's boot screen, it is determined whether the device model and manufacturer information displayed on the boot screen match the device itself, and whether the system version number and baseband version number match, thereby determining whether it is a flashing device.
[0039] In one embodiment of the present invention, if the device model and manufacturer information displayed on the device's startup interface do not match the device itself, it is considered to be a flashing device; if the system version number and baseband version number of the detected device do not match, it is considered to be a flashing device.
[0040] In another embodiment of the present invention, if the device model and manufacturer information displayed on the device's startup interface do not match the device itself, and the system version number and baseband version number of the detected device do not match, it is considered to be a flashing device.
[0041] Furthermore, the security characteristics of the device, such as whether the device cannot update system patches or whether certain applications cannot be used, are used to determine whether it is a flashing device.
[0042] In summary, in practical applications, devices that generate fake traffic data are often those that have been flashed. Therefore, this invention determines whether a device is a flashed device by judging its model, manufacturer information, system version number, baseband version number, etc., and eliminates flashed devices to obtain more accurate active traffic.
[0043] S600 performs clustering calculation on the fourth intermediate ID and obtains the number of fourth intermediate IDs contained in each cluster after clustering. When the number of fourth intermediate IDs contained in a cluster is greater than a preset threshold, the fourth intermediate IDs under that cluster are marked as dummy data.
[0044] The present invention also includes marking the fourth intermediate IDs under a cluster as active traffic when the number of fourth intermediate IDs contained in a cluster is not greater than a preset number threshold, wherein the active traffic is used to characterize the activity level of the target APP.
[0045] Specifically, the clustering calculation is used to identify devices that specialize in inflating traffic. Based on information such as location, clustering calculation is performed on the fourth intermediate ID to identify devices that specialize in inflating traffic, which are then removed to obtain the traffic to be activated. The active traffic is used to characterize the activity level of the target APP. The greater the active traffic, the higher the activity level of the target APP.
[0046] In summary, the process involves obtaining a list of IDs to be identified, verifying their authenticity based on their checksums, and marking successfully verified IDs as first intermediate IDs. The process then involves obtaining the target software interaction information corresponding to each first intermediate ID, marking first intermediate IDs whose target software interaction information meets a preset time range as second intermediate IDs, marking second intermediate IDs whose device hardware and user information meet a first preset condition as third intermediate IDs, and marking third intermediate IDs that meet the second preset condition as fourth intermediate IDs. Clustering is then performed on the fourth intermediate IDs, and fourth intermediate IDs whose clusters contain more than a preset threshold are considered active traffic. By filtering IDs layer by layer, those with incorrect checksums, those that haven't been used in a long time, virtual machines, and devices specifically used for traffic manipulation are removed, thus more accurately obtaining active traffic.
[0047] Furthermore, the device information also includes basic information, which includes at least: device geographical location, device IP, device model, and timestamp, wherein the timestamp is the time information of collecting the device's current geographical location, IP, and device model.
[0048] Furthermore, the S600 includes the following steps:
[0049] S601, obtain the basic information corresponding to the fourth intermediate ID, and obtain the basic information vector list B = {B1, B2, ..., B...} based on the basic information corresponding to the fourth intermediate ID. j B n}, B j It is the basic information vector corresponding to the j-th fourth intermediate ID, where j ranges from 1 to n, and n is the number of fourth intermediate IDs.
[0050] S602, Traverse B, Calculate B j The distance to each cluster center in the cluster center list, if B j If the distance to the center of a cluster is less than a preset distance threshold, then B... j Add to the cluster center; otherwise, add B. j As a cluster center, it is added to the cluster center list; wherein, the cluster center list is initialized by randomly selecting a basic information vector as the cluster center.
[0051] Specifically, the cluster center list is initialized by randomly selecting one or more basic information vectors as cluster centers.
[0052] S603, Traverse the list of cluster centers and obtain the number of basic information vectors S = {S1, S2, ..., S...} under each cluster center. g ,…,S z}, S g It is the number of basic information vectors under the g-th cluster center, where g ranges from 1 to z, and z is the number of cluster centers.
[0053] S604, if S g If the number exceeds a preset threshold, then S g The fourth intermediate ID is marked as dummy data.
[0054] In summary, the basic information corresponding to the fourth intermediate ID is obtained, and a list of basic information vectors corresponding to the fourth intermediate ID is obtained based on this information. The list of basic information vectors is traversed, and the distance between any basic information vector and the cluster center is calculated. If the distance is less than a preset distance threshold, the basic information vector is added to that cluster center; otherwise, the basic information vector is used as the cluster center. The number of basic information vectors under each cluster center is obtained. If the number of basic information vectors under any cluster center is greater than a preset number threshold, the fourth intermediate ID under that cluster center is marked as dummy data; otherwise, it is considered active data, thus obtaining active data. This invention performs clustering calculations based on geographic location, IP address, and device model, clustering third intermediate IDs with the same geographic location, IP address, and device model together. Third intermediate IDs under clusters exceeding a preset number threshold are marked as dummy data, thereby removing fourth intermediate IDs with too many identical attributes in the same area, resulting in more accurate acquisition of active data.
[0055] Furthermore, in another embodiment of the present invention, the following steps are also included:
[0056] S001, Obtain A i The target interaction time period T with the target APP, specifically, the A i The interaction time with the target app is determined by user input.
[0057] S002, obtain A within the preset time period where T is located. i A list of interaction time periods with other software installed on devices besides the target app, C = {C1, C2, ..., C...} x C q}, C x It is A iThe preset time period is the interaction time with the xth software installed on other devices besides the target app, where x ranges from 1 to q, and q is the number of software installed on other devices besides the target app. Specifically, the preset time period is one day.
[0058] S003, iterate through C, if T and C x There is an overlap in time, so it is believed that A i This is false data.
[0059] In summary, the method involves obtaining the target interaction time period between the ID to be identified and the target APP, and obtaining the interaction time period between the ID to be identified and other installed software on other devices within the same day (T). If the target interaction time period overlaps with the interaction time period of other installed software, the ID to be identified is considered fake data. This method of judging based on interaction time can determine whether the ID to be identified has interacted within the interaction time provided by the user, and can be used to determine the activity frequency of the ID to be identified, thus more accurately filtering fake data in different time periods.
[0060] Embodiments of the present invention also provide a non-transitory computer-readable storage medium that can be disposed in an electronic device to store at least one instruction or at least one program related to implementing a method in the method embodiments, wherein the at least one instruction or the at least one program is loaded and executed by the processor to implement the method provided in the above embodiments.
[0061] Embodiments of the present invention also provide an electronic device, including a processor and the aforementioned non-transitory computer-readable storage medium.
[0062] Embodiments of the present invention also provide a computer program product including program code, which, when the program product is run on an electronic device, causes the electronic device to perform the steps of the methods described above in various exemplary embodiments of the present invention.
[0063] While specific embodiments of the invention have been described in detail by way of example, those skilled in the art should understand that the above examples are for illustrative purposes only and are not intended to limit the scope of the invention. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the invention. The scope of the invention is defined by the appended claims.
Claims
1. A method for screening fake data for device IDs, characterized in that, The method is used to filter out fake data based on device ID to obtain the activity level of the target APP. The device on which the target APP is located integrates a target SDK for collecting device information. The device information includes at least the software information installed on the device, the interaction information between the device user and the target software of the target APP, the device hardware information, and the device version information. The device ID has a check bit. The device information also includes basic information, which includes at least the following: device geographic location, device IP, device model, and timestamp. The timestamp is the time information of collecting the current geographic location, IP, and device model of the device. The method includes the following steps: S100, Obtain the list of IDs to be identified, A={A1, A2, ..., A...} i A m }, A i It is the i-th ID to be identified, where i ranges from 1 to m, and m is the number of IDs to be identified; S200, based on A i Check bit pair A i Perform authenticity verification and mark the successfully verified IDs to be identified as the first intermediate IDs to obtain the list of first intermediate IDs; S300, obtain the target software interaction information corresponding to the first intermediate ID. If the latest opening time of the target software corresponding to the first intermediate ID is within a preset time range, mark the first intermediate ID as the second intermediate ID, thereby obtaining the second intermediate ID list. The target software interaction information records the latest opening time of the target APP. S400, obtain the device hardware information and the device installed software information corresponding to the second intermediate ID, and when the device hardware information and the device installed software information corresponding to the second intermediate ID both meet the first preset condition, mark the second intermediate ID as the third intermediate ID, thereby obtaining the list of third intermediate IDs; S500, obtain the version information of the third intermediate ID, and when the version information of the third intermediate ID meets the second preset condition, mark the third intermediate ID as the fourth intermediate ID, thereby obtaining the fourth intermediate ID; S600: Perform clustering calculations on the fourth intermediate IDs and obtain the number of fourth intermediate IDs contained in each cluster. When the number of fourth intermediate IDs contained in a cluster is greater than a preset threshold, mark the fourth intermediate IDs in that cluster as dummy data. S600 includes the following steps: S601, obtain the basic information corresponding to the fourth intermediate ID, and sort the basic information corresponding to the fourth intermediate ID according to a preset order to obtain the basic information vector list B={B1, B2, ..., B...} of the fourth intermediate ID. j B n }, B j It is the basic information vector corresponding to the j-th fourth intermediate ID, where j ranges from 1 to n, and n is the number of fourth intermediate IDs; S602, Traverse B, Calculate B j The distance to each cluster center in the cluster center list, if B j If the distance to the center of a cluster is less than a preset distance threshold, then B... j Add to the cluster center; otherwise, add B. j As a cluster center, it is added to the cluster center list; wherein, the cluster center list is initialized by randomly selecting a basic information vector as the cluster center; S603, Traverse the list of cluster centers and obtain the number of basic information vectors S={S1, S2, ..., S...} under each cluster center. g ,…,S z }, S g It is the number of basic information vectors under the g-th cluster center, where g ranges from 1 to z, and z is the number of cluster centers; S604, if S g If the number exceeds a preset threshold, S g The fourth intermediate ID is marked as dummy data.
2. The method for screening fake data for device IDs according to claim 1, characterized in that, The software information installed on the device meets the first preset condition, including: call logs, contacts, SMS messages and photo album are not empty; the software installed on the device includes at least one software from the first preset software list, but does not include any software from the second preset software list; wherein, the number of software installed in the first preset software list is greater than the preset number of installations; and the software in the second preset software list is any software from an emulator.
3. The method for screening fake data for device IDs according to claim 1, characterized in that, The device hardware includes: a card slot, a communication card inserted into the card slot, a battery, installed sensors, and other hardware in the device.
4. The method for screening fake data for device IDs according to claim 3, characterized in that, The device hardware information meets the first preset condition, including: the device has a card slot and a communication card inserted into the card slot; the temperature and power of the battery change continuously over time; the installed sensor belongs to the third preset sensor list; and other hardware in the device does not conform to the fourth preset simulator name list. The sensors in the third preset sensor list are sensors installed on the mobile device.
5. The method for screening fake data for device IDs according to claim 1, characterized in that, The device version information includes at least the device model, device manufacturer information, system version number, and baseband version number.
6. The method for screening fake data for device IDs according to claim 4, characterized in that, If any item in the device hardware information of the second intermediate ID does not meet the first preset condition, the second intermediate ID will be identified as fake data.
7. The method for screening fake data for device IDs according to claim 1, characterized in that, It also includes the following steps: S001, Obtain A i The target interaction time period T with the target APP; S002, obtain A within the preset time period where T is located. i A list of interaction time periods with other installed software on devices besides the target app, C = {C1, C2, ..., C...} x C q }, C x It is A i The interaction time period with the xth software installed on other devices besides the target APP, where x ranges from 1 to q, and q is the number of software installed on other devices besides the target APP; S003, iterate through C, if T and C x There is an overlap in time, so it is believed that A i This is false data.
8. A non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores at least one instruction or at least one program segment, characterized in that, The at least one instruction or the at least one program segment is loaded and executed by the processor to implement the fake data screening method for device ID as described in any one of claims 1-7.
Citation Information
Patent Citations
Abnormal APP determination method, computer equipment and medium
CN114625609A
Method and apparatus for illegal user identification based on big data analysis, and electronic device
WO2020062690A1