Methods, devices, equipment, and storage media for handling abnormal accounts
By receiving access request messages from target accounts, and determining whether to allow them to access the network based on the account's login information and online time, this solves the problem of decreased user experience caused by instant dialing and dial-up accounts in existing technologies, and achieves accurate identification and reasonable handling of instant dialing and dial-up accounts.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2024-01-24
- Publication Date
- 2026-05-26
AI Technical Summary
Existing technologies typically block network access after identifying abnormal accounts that use instant dialing or dialing quickly, leading to a decline in user experience.
By receiving access request messages from the target account, the system determines whether to allow network access based on the account's login information and online duration. It distinguishes between instant dial-up and second-dial dial-up accounts, making accurate judgments based on login count and IP address usage.
It improves the accuracy of identifying instant dialing and dial-up accounts, avoids unnecessary network blocking, and enhances the user experience.
Smart Images

Figure CN117914606B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device and storage medium for handling abnormal accounts. Background Technology
[0002] With the rapid development of the internet, an increasing number of malicious individuals are using techniques like "second-dialing" and "instant dialing" to commit illicit activities. Second-dialing technology utilizes the principle of dial-up internet access—that is, reconnecting to the network based on a broadband account obtains a new Internet Protocol (IP) address—allowing for the rapid switching of IP addresses to carry out malicious actions. Instant dialing technology can acquire a large number of IP addresses within a short period using the same broadband account for malicious purposes.
[0003] Existing technologies typically prohibit broadband accounts from accessing the network once they are identified as abnormal accounts using instant dialing or dial-up technologies, thus reducing the user experience. Summary of the Invention
[0004] This application provides a method, apparatus, device, and storage medium for handling abnormal accounts, to at least solve the problem that existing technologies prohibit abnormal accounts from accessing the network, thus reducing user experience. The technical solution of this application is as follows:
[0005] Firstly, a method for handling abnormal accounts is provided. This method includes: receiving an access request message sent by the target account. If the target account is a dial-up account, it is determined whether to allow the target account to access the network based on the target account's first login information within a current preset time period. A dial-up account indicates an account that accesses the network more than a first preset number of times within the first preset time period. The first login information includes: the number of login attempts and the account login status, which includes: logged-in and not logged-in states. If the target account is a second-switch account, it is determined whether to allow the target account to access the network based on the target account's second login information within the current preset time period. A second-switch account indicates an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: the number of login attempts, a first IP address, and internet access duration. The first IP address indicates the IP address assigned to the target account during the last login, and the internet access duration indicates the duration the target account accessed the network based on the first IP address.
[0006] In one possible implementation, determining whether to allow a target account to access the network based on the target account's first login information within the current preset time period includes: sending an access denial message to the target account if the number of logins within the current preset time period is greater than or equal to a third preset number, and the account's login status within the current preset time period is logged in. The access denial message indicates that the target account's access to the network is denied. If the number of logins within the current preset time period is greater than or equal to the third preset number, and the account's login status within the current preset time period is not logged in, sending a first access allow message to the target account. The first access allow message indicates that the target account is allowed to access the network based on a second IP address, where the second IP address is any one of a plurality of preset IP addresses. If the number of logins within the current preset time period is less than the third preset number, sending a first access allow message to the target account.
[0007] In one possible implementation, determining whether to allow the target account to access the network based on the target account's second login information within the current preset time period includes: sending a second access permission message to the target account if the number of logins within the current preset time period is greater than or equal to a fourth preset number of logins and the online time duration within the current preset time period is less than a first preset time duration. The second access permission message indicates that the target account is allowed to access the network based on the first IP address. Sending a first access permission message to the target account if the number of logins within the current preset time period is greater than or equal to the fourth preset number of logins and the online time duration within the current preset time period is greater than or equal to the first preset time duration. Sending a first access permission message to the target account if the number of logins within the current preset time period is less than the fourth preset number of logins.
[0008] In one possible implementation, after receiving the access request message from the target account, the method for handling the abnormal account further includes: obtaining the target account's first IP address and online duration within the current preset time period. If the online duration exceeds a second preset duration, a third access permission message is sent to the target account. The third access permission message indicates that access to the network based on the first IP address is denied, but access to the network based on a third IP address is allowed. The third IP address is any IP address other than the first IP address from a plurality of preset IP addresses.
[0009] Secondly, an apparatus for handling abnormal accounts is provided, comprising a receiving unit and a processing unit. The receiving unit is used to receive access request messages sent by a target account. The processing unit is used to, when the target account is a dial-up account, determine whether to allow the target account to access the network based on the target account's first login information within a current preset time period. A dial-up account indicates an account that accesses the network more than a first preset number of times within the first preset time period. The first login information includes: login count and account login status, which includes: logged-in status and not logged-in status. The processing unit is also used to, when the target account is a second-switch account, determine whether to allow the target account to access the network based on the target account's second login information within the current preset time period. A second-switch account indicates an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: login count, a first IP address, and internet access duration. The first IP address indicates the IP address assigned to the target account during the last login, and the internet access duration indicates the duration the target account accessed the network based on the first IP address.
[0010] In one possible implementation, the processing unit is specifically configured to: send an access denial message to the target account when the number of login attempts within the current preset time period is greater than or equal to a third preset number of attempts, and the account login status within the current preset time period is logged in. The access denial message indicates that the target account's access to the network is denied. When the number of login attempts within the current preset time period is greater than or equal to a third preset number of attempts, and the account login status within the current preset time period is not logged in, send a first access permission message to the target account. The first access permission message indicates that the target account is allowed to access the network based on a second IP address, where the second IP address is any one of a plurality of preset IP addresses. When the number of login attempts within the current preset time period is less than a third preset number of attempts, send a first access permission message to the target account.
[0011] In one possible implementation, the processing unit is specifically configured to: send a second access permission message to the target account when the number of login attempts within the current preset time period is greater than or equal to a fourth preset number of attempts, and the online time duration within the current preset time period is less than a first preset time duration. The second access permission message indicates that the target account is allowed to access the network based on a first IP address. When the number of login attempts within the current preset time period is greater than or equal to a fourth preset number of attempts, and the online time duration within the current preset time period is greater than or equal to a first preset time duration, a first access permission message is sent to the target account. When the number of login attempts within the current preset time period is less than a fourth preset number of attempts, a first access permission message is sent to the target account.
[0012] In one possible implementation, the aforementioned abnormal account processing device further includes an acquisition unit and a sending unit. The acquisition unit is used to acquire the first IP address of the target account within a current preset time period and the internet access duration within the current preset time period. The sending unit is used to send a third access permission message to the target account if the internet access duration exceeds a second preset time period. The third access permission message indicates that access to the network based on the first IP address is denied, but access to the network based on a third IP address is allowed. The third IP address is any IP address other than the first IP address from a plurality of preset IP addresses.
[0013] Thirdly, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions. The processor is configured to execute instructions to implement the methods described in the first aspect and any possible implementation thereof.
[0014] Fourthly, a computer-readable storage medium is provided, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the methods described in the first aspect and any possible implementation thereof.
[0015] Fifthly, a computer program product is provided, comprising computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the first aspect and any possible implementation thereof.
[0016] The technical solution of the first aspect provided by this application brings at least the following beneficial effects: Existing technologies, when a broadband account is identified as an abnormal account implementing instant dialing technology, prohibit that abnormal account from accessing the network, thus reducing user experience. This application receives an access request message sent by the target account. Then, if the target account is an instant dialing account, it determines whether to allow the target account to access the network based on the target account's first login information within the current preset time period. Here, an instant dialing account refers to an account that accesses the network more than a first preset number of times within the first preset time period. The first login information includes: login count and account login status, which includes: logged-in status and not logged-in status. Since the login count can determine whether the target account is logging in for the first time within the current preset time period, and the account login status can determine whether the target account is logged in or not within the current preset time period, it is possible to determine whether the target account's access request message is an abnormal behavior implemented through instant dialing technology, thereby accurately determining whether to allow the target account to access the network. This avoids the situation where existing technologies prohibit instant dialing accounts from accessing the network, improving user experience.
[0017] Simultaneously, when the target account is a dial-up account, the system determines whether to allow the target account to access the network based on the target account's second login information within the current preset time period. A dial-up account indicates an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: login count, first IP address, and online time duration. The first IP address represents the IP address assigned to the target account during the last login, and the online time duration represents the duration the target account spent accessing the network based on the first IP address. Since the login count determines whether this is the target account's first login within the current preset time period, and the first IP address and online time duration determine whether the target account's online time based on the first IP address exceeds a certain limit, this system can accurately determine whether the target account's current access request message constitutes abnormal behavior through dial-up technology, thus accurately determining whether to allow the target account to access the network. This avoids the situation where existing technologies prohibit dial-up accounts from accessing the network, improving the user experience.
[0018] It should be noted that the technical effects of any of the implementation methods in aspects two through five can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.
[0019] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application, and do not constitute an undue limitation of this application.
[0021] Figure 1 This is a schematic diagram of the structure of a broadband dial-up system according to an exemplary embodiment;
[0022] Figure 2 This is a schematic diagram illustrating the structure of yet another broadband dial-up system according to an exemplary embodiment;
[0023] Figure 3 This is a schematic diagram illustrating the structure of an abnormal account processing system according to an exemplary embodiment;
[0024] Figure 4 This is a flowchart illustrating a method for handling abnormal accounts according to an exemplary embodiment;
[0025] Figure 5 This is a flowchart illustrating yet another method for handling abnormal accounts according to an exemplary embodiment;
[0026] Figure 6 This is a flowchart illustrating yet another method for handling abnormal accounts according to an exemplary embodiment;
[0027] Figure 7 This is a flowchart illustrating yet another method for handling abnormal accounts according to an exemplary embodiment;
[0028] Figure 8 This is a flowchart illustrating yet another method for handling abnormal accounts according to an exemplary embodiment;
[0029] Figure 9 This is a block diagram illustrating an apparatus for processing abnormal accounts according to an exemplary embodiment;
[0030] Figure 10 This is a block diagram illustrating an electronic device according to an exemplary embodiment. Detailed Implementation
[0031] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0032] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0033] Before providing a detailed introduction to the methods for handling abnormal accounts provided in this application, let's briefly introduce the technical background involved in this application.
[0034] Figure 1 This is a schematic diagram of a broadband dial-up system. Figure 1 As shown, the broadband dial-up system 10 includes: a user terminal 11, an optical modem 12, and a server 13. The user terminal 11 is connected to the optical modem 12, and the optical modem 12 communicates with the server 13 through a point-to-point protocol over Ethernet (PPPoE) tunnel. The server 13 includes: a first preset server module 131 and a second preset server module 132.
[0035] User terminal 11 is used to send a network connection request message to optical modem 12.
[0036] The optical modem 12 stores the broadband account and password of the user terminal 11. After receiving a network connection request message from the user terminal 11, it sends a data packet to the server 13 through the PPPoE tunnel. The data packet includes the broadband account and password of the user terminal 11.
[0037] Server 13 receives data packets sent by optical modem 12 and forwards the data packets to the first preset server module 131.
[0038] The first preset server module 131 responds to the data packet by verifying the broadband account and password in the data packet. After the data packet is verified, the first preset server module 131 sends a request allocation message to the second preset server module 132.
[0039] In response to the request allocation message, the second preset server module 132 determines the IP address to be allocated to the user terminal 11. The second preset server module 132 sends the IP address allocated to the user terminal 11 to the optical modem 12 so that the user terminal 11 can access the network based on the allocated IP address.
[0040] For example, server 13 can be a broadband remote access server (BRAS), the first preset server module 131 can be a remote authentication dial in user service (RADIUS) module, and the second preset server module 132 can be a dynamic host configuration protocol (DHCP) module.
[0041] An optical modem is a device that runs dial-up software and is usually a terminal box provided by the operator.
[0042] A BRAS (Bandwidth Management System) is a network device used to manage and control bandwidth access. BRAS is typically installed at the core node of an Internet service provider (ISP). It allows user terminals to access the network through different access methods (such as digital subscriber line (DSL), fiber optic, and satellite). BRAS also provides authentication, authorization, accounting, and flow control functions to ensure the quality and security of network connections for bandwidth access users. A BRAS comprises five main functional components: user access identification, connection management, user management, address allocation and management, and service control.
[0043] RADIUS is a distributed, client / server architecture communication protocol that protects networks from unauthorized access. It is commonly used in network environments that require high security but also allow remote user access. As a standard protocol, RADIUS is supported by most devices, making it the most widely used protocol in practical networks. RADIUS uses the User Datagram Protocol (UDP) as its transport protocol, providing good real-time performance. It also supports retransmission and backup server mechanisms, offering good reliability. Its implementation is relatively simple and suitable for multi-threaded architectures. RADIUS supports the three components of the 3A (authentication, authorization, and accounting) framework: authentication, authorization, and accounting.
[0044] DHCP is an application layer protocol that uses UDP. DHCP is also a network management protocol used to centrally and dynamically manage and configure the IP addresses of user terminals.
[0045] PPPoE is a link-layer protocol that encapsulates the Point-to-Point Protocol (PPP) within Ethernet. PPPoE establishes PPP sessions and encapsulates PPP packets into PPPoE packets by providing point-to-point connections over Ethernet. The PPPoE standard conforms to RFC 2516.
[0046] Instant dialing: Using customized automatic dialing software, users frequently go online and offline within a short period of time to assign different IP addresses to the same user terminal.
[0047] Instant dialing: Using customized automatic dialing software, a large number of users with the same account can be connected to the internet at once to obtain simultaneous online access and thus instantly obtain a large number of IP addresses for the same account.
[0048] Normal account: dial-up on demand, and there is no IP address switching of the user terminal during the access to Internet resources.
[0049] Instant dial-up accounts: Because current dial-up internet rules require a new IP address for each disconnected connection and reconnection, frequently logging in and out within a short period can assign different IP addresses to the same user. Therefore, accounts that switch networks multiple times in a short period are called instant dial-up accounts.
[0050] Instant dialing accounts: Accounts that allow simultaneous network connections based on the same account within a short period of time to obtain simultaneous online access and thus acquire the IP addresses of a large number of user terminals are called instant dialing accounts.
[0051] Before providing a detailed introduction to the methods for handling abnormal accounts provided in this application, let's first briefly introduce the implementation environment (implementation architecture) involved in this application.
[0052] The abnormal account handling method provided in this application embodiment can be applied to broadband dial-up systems. Figure 2 This is a schematic diagram of another broadband dial-up system. Figure 2 As shown, the broadband dial-up system 10 includes: a user terminal 11, an optical modem 12, and a server 13. The user terminal 11 is connected to the optical modem 12, and the optical modem 12 communicates with the server 13 through a PPPoE tunnel. The server 13 includes: a first preset server module 131, a second preset server module 132, a data acquisition module 133, a processing module 134, and a controller module 135.
[0053] User terminal 11 is used to send a network connection request message to optical modem 12.
[0054] The optical modem 12 stores the broadband account and password of the user terminal 11, and after receiving a network connection request message from the user terminal 11, sends a data packet to the server 13 through a PPPoE tunnel. The data packet includes the broadband account and password of the user terminal 11, the first login information of the broadband account within the current preset time period, and the second login information of the broadband account within the current preset time period.
[0055] Server 13 is used to receive data packets sent by optical modem 12 and forward data packets to acquisition module 133.
[0056] The acquisition module 133 is used to receive data packets and store them in the acquisition module 133. The acquisition module 133 is also used to send the acquired data packets to the processing module 134.
[0057] Processing module 134 receives data packets and determines whether the broadband account is an abnormal account based on the network usage information in the data packets. Processing module 134 also sends the account category of the broadband account to controller module 135. Account categories include: normal account, instant dial-up account, and quick dial-up account.
[0058] The controller module 135 receives the broadband account type from the processing module 134. When the account type is a normal account, the controller module 135 sends the broadband account and password to the first preset server module 131. When the account type is a dial-up account, the controller module 135 determines whether to allow the broadband account to access the network based on the number of login attempts and the account login status.
[0059] The controller module 135 is also used to determine whether to allow the broadband account to access the network when the account type is a dial-up account, based on the number of logins of the broadband account, the IP address assigned to the broadband account during the last login, and the duration of internet access.
[0060] The first preset server module 131 is used to receive broadband account and password, and to verify the broadband account and password. After the broadband account is verified, the first preset server module 131 sends a request allocation message to the second preset server module 132.
[0061] In response to the request allocation message, the second preset server module 132 determines the IP address to be allocated to the user terminal 11. The second preset server module 132 sends the IP address allocated to the user terminal 11 to the optical modem 12 so that the user terminal 11 can access the network based on the allocated IP address.
[0062] The abnormal account processing method provided in this application embodiment can also be applied to an abnormal account processing system. Figure 3 This diagram illustrates one possible structure of the system for handling this abnormal account. For example... Figure 3 As shown, the abnormal account processing system 20 includes an abnormal account processing device 21 and an electronic device 22. The abnormal account processing device 21 is connected to the electronic device 22. The abnormal account processing device 21 and the electronic device 22 can be connected by a wired connection or a wireless connection. This embodiment of the application does not limit the connection in this way.
[0063] The abnormal account processing device 21 can be used to interact with the electronic device 22, for example, to receive access request messages sent by the electronic device 22.
[0064] The abnormal account processing device 21 can also be used to process the obtained access request messages. For example, if the target account is a dial-up account, it can determine whether to allow the target account to access the network based on the first login information of the target account within the current preset time period.
[0065] The abnormal account processing device 21 can also be used to determine whether to allow the target account to access the network based on the second login information of the target account within the current preset time period when the target account is a dial-up account.
[0066] Electronic device 22 can be used to interact with abnormal account processing device 21, for example, by sending an access request message to abnormal account processing device 21.
[0067] Optionally, the electronic device can be a physical machine, such as a desktop computer, mobile phone, tablet computer, laptop computer, ultra-mobile personal computer (UMPC), netbook, personal digital assistant (PDA), and other terminal devices. The electronic device can also be a server or a server cluster composed of multiple servers.
[0068] Optionally, the abnormal account processing device 21 can also implement the functions to be performed by a virtual machine (VM) deployed on a physical machine.
[0069] It should be noted that the abnormal account processing device 21 and the electronic device 22 can be independent devices or integrated into the same device; this application does not make specific limitations in this regard.
[0070] When the abnormal account processing device 21 and the electronic device 22 are integrated into the same device, the communication method between the abnormal account processing device 21 and the electronic device 22 is the communication between internal modules of the device. In this case, the communication process between the two is the same as the communication process between the abnormal account processing device 21 and the electronic device 22 when they are independent of each other.
[0071] In the following embodiments provided in this application, the abnormal account processing device 21 and electronic device 22 are described as being set up independently of each other.
[0072] To facilitate understanding, the following section, in conjunction with the accompanying drawings, provides a detailed explanation of the methods for handling abnormal accounts provided in this application.
[0073] Figure 4 This is a flowchart illustrating a method for handling abnormal accounts according to an exemplary embodiment. This method can be applied to electronic devices or to an abnormal account handling device connected to an electronic device. Furthermore, this method can also be applied to devices similar to electronic devices or abnormal account handling devices. The following description uses the application of this method to an electronic device as an example to illustrate the method. Figure 4 As shown, the method for handling this abnormal account includes the following steps:
[0074] S301. The electronic device receives an access request message sent by the target account.
[0075] For example, the access request message includes the target account, password, the target account's first login information within the current preset time period, and the target account's second login information within the current preset time period.
[0076] S302. When the target account is a dial-up account, the electronic device determines whether to allow the target account to access the network based on the first login information of the target account within the current preset time period.
[0077] The "instant dial account" refers to an account that accesses the network more than a first preset number of times within a first preset time period. The first login information includes: login count and account login status. Account login status includes: logged-in and not logged-in.
[0078] As one possible implementation, when the target account is a dial-up account, the electronic device obtains the first login information of the target account within the current preset time period, and determines whether to allow the target account to access the network based on the first login information.
[0079] For example, an instant dial account is used to represent an account that accesses the network more than a first preset number of times (e.g., 10 times) within a first preset time period (e.g., 5 milliseconds). A second dial account is used to represent an account that switches networks more than a second preset number of times (e.g., 100 times) within a second preset time period (e.g., 1 hour).
[0080] The specific implementation of this step can be found in the subsequent description of the embodiments of this application, and will not be repeated here.
[0081] S303. When the target account is a dial-up account, the electronic device determines whether to allow the target account to access the network based on the second login information of the target account within the current preset time period.
[0082] The "second-dialing account" refers to an account that switches networks more than a second preset number of times within a second preset time period. The second login information includes: login count, first IP address, and internet access duration. The first IP address represents the IP address assigned to the target account during the last login, and the internet access duration represents the duration the target account accessed the network based on the first IP address.
[0083] As one possible implementation, when the target account is a dial-up account, the electronic device obtains the second login information of the target account within the current preset time period, and determines whether to allow the target account to access the network based on the second login information.
[0084] The specific implementation of this step can be found in the subsequent description of the embodiments of this application, and will not be repeated here.
[0085] Understandably, existing technologies, once a broadband account is identified as an abnormal account using instant dialing or dial-up technology, prohibit that abnormal account from accessing the network, thus degrading the user experience. This application receives access request messages from the target account. Then, if the target account is an instant dialing account, it determines whether to allow the target account to access the network based on the target account's first login information within the current preset time period. Here, an instant dialing account refers to an account that accesses the network more than a first preset number of times within the first preset time period. The first login information includes: login count and account login status, which includes logged-in and not logged-in states. Since the login count can determine whether the target account is logging in for the first time within the current preset time period, and the account login status can determine whether the target account is logged in or not within the current preset time period, it is possible to determine whether the target account's access request message is an abnormal behavior using instant dialing technology, thereby accurately determining whether to allow the target account to access the network. This avoids the situation where existing technologies prohibit instant dialing accounts from accessing the network, improving the user experience.
[0086] Simultaneously, when the target account is a dial-up account, the system determines whether to allow the target account to access the network based on the target account's second login information within the current preset time period. A dial-up account indicates an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: login count, first IP address, and online time duration. The first IP address represents the IP address assigned to the target account during the last login, and the online time duration represents the duration the target account spent accessing the network based on the first IP address. Since the login count determines whether this is the target account's first login within the current preset time period, and the first IP address and online time duration determine whether the target account's online time based on the first IP address exceeds a certain limit, this system can accurately determine whether the target account's current access request message constitutes abnormal behavior through dial-up technology, thus accurately determining whether to allow the target account to access the network. This avoids the situation where existing technologies prohibit dial-up accounts from accessing the network, improving the user experience.
[0087] In some embodiments, when the target account is a dial-up account, in order to determine whether to allow the target account to access the network, such as... Figure 5 As shown, the above S302 can be implemented in the following way:
[0088] S401. The electronic device determines whether the number of login attempts within the current preset time period is greater than or equal to the third preset number of login attempts.
[0089] It should be noted that the third preset number of times is two.
[0090] S402. If the number of login attempts of the electronic device within the current preset time period is greater than or equal to the third preset number of login attempts, and the account login status within the current preset time period is logged in, an access denial message is sent to the target account.
[0091] The access denied message is used to indicate that access to the network by the target account is denied.
[0092] As one possible implementation, if the electronic device logs in more than or equal to a third preset number of times within the current preset time period, it obtains the login status of the target account within the current preset time period. Then, if the electronic device's login status within the current preset time period is "already logged in," it sends an access denied message to the target account. Furthermore, the electronic device stores the target account's login request information.
[0093] For example, the login request information for the target account includes: the time when the target account sent the access request message and the access denied message.
[0094] S403. If the number of login attempts of the electronic device within the current preset time period is greater than or equal to the third preset number of login attempts, and the account login status within the current preset time period is not logged in, a first permission message is sent to the target account.
[0095] The first permission message indicates that the target account is allowed to access the network based on the second IP address, which is any one of a plurality of preset IP addresses.
[0096] As one possible implementation, if the electronic device logs in more than or equal to a third preset number of times within the current preset time period, it obtains the login status of the target account within the current preset time period. Then, if the account is not logged in within the current preset time period, the electronic device determines any one of multiple preset IP addresses as the second IP address. Next, the electronic device sends a first access permission message to the target account, allowing the target account to access the network based on the second IP address. Furthermore, the electronic device stores the target account's login request information.
[0097] For example, the login request information for the target account includes: the time when the target account sends the access request message and the first permission message.
[0098] S404. If the number of login attempts of the electronic device within the current preset time period is less than the third preset number of attempts, a first permission message is sent to the target account.
[0099] Understandably, logging in multiple times allows us to determine if a target account is logging in for the first time. If it is, allowing the target account to access the network avoids the common practice of blocking instant-access accounts, thus improving user experience. Conversely, allowing network access when the target account is not logging in for the first time and is in an offline state, and denying network access when the target account is not logging in for the first time, effectively prevents the target account from becoming an instant-access account within the current preset time period. This improves user experience while preventing abnormal behavior based on the target account.
[0100] In some embodiments, when the target account is a dial-up account, in order to determine whether to allow the target account to access the network, such as... Figure 6 As shown, the above S302 can be implemented in the following way:
[0101] S501. The electronic device determines whether the number of logins within the current preset time period is greater than or equal to the fourth preset number.
[0102] It should be noted that the fourth preset number of attempts is two.
[0103] S502. If the number of login attempts of the electronic device within the current preset time period is greater than or equal to the fourth preset number of login attempts, and the online time duration within the current preset time period is less than the first preset time duration, a second access permission message is sent to the target account.
[0104] The second permission message is used to indicate that the target account is allowed to access the network based on the first IP address.
[0105] As one possible implementation, if the electronic device logs in more than or equal to a fourth preset number of times within the current preset time period, it obtains the target account's online time duration and first IP address within the current preset time period. Then, if the electronic device's online time duration within the current preset time period is less than the first preset time duration, it sends a second access permission message to the target account, allowing the target account to access the network based on the first IP address. Furthermore, the electronic device stores the target account's login request information.
[0106] For example, the login request information for the target account includes: the time when the target account sends the access request message and the second access permission message.
[0107] It should be noted that the first preset duration is used to indicate the short usage time of the target account accessing the network based on the same broadband account.
[0108] For example, the first preset duration can be 2 hours.
[0109] S503. If the number of login attempts of the electronic device within the current preset time period is greater than or equal to the fourth preset number of login attempts, and the online time within the current preset time period is greater than or equal to the first preset time period, a first permission message is sent to the target account.
[0110] As one possible implementation, if the electronic device logs in more than or equal to a fourth preset number of times within the current preset time period, it obtains the target account's online time duration and a first IP address within the current preset time period. Then, if the electronic device's online time duration within the current preset time period is greater than or equal to the first preset duration, it determines any one of multiple preset IP addresses as a second IP address. Next, the electronic device sends a first access permission message to the target account, allowing the target account to access the network based on the second IP address. Furthermore, the electronic device stores the target account's login request information.
[0111] For example, the login request information for the target account includes: the time when the target account sends the access request message and the first permission message.
[0112] S504. If the number of login attempts of the electronic device within the current preset time period is less than the fourth preset number, a first permission message is sent to the target account.
[0113] Understandably, the number of login attempts can determine whether a target account is logging in for the first time. If it is, the target account is allowed to access the network, avoiding the situation where existing technology blocks accounts that use "second-dialing" (or similar services) from accessing the network, thus improving user experience. Simultaneously, the first IP address represents the IP address assigned to the target account during the last login, and the online time represents the duration the target account spent accessing the network using that first IP address. Therefore, even if the target account is not logging in for the first time, the online time can be used to determine if the duration of access using the first IP address exceeds the minimum online time limit. Furthermore, if the online time does not exceed the minimum online time limit, the target account is allowed to access the network using the first IP address, thus preventing the target account from obtaining multiple new IP addresses by frequently sending access request messages, i.e., preventing the target account from becoming a "second-dialing" account within the current preset time period. Therefore, while prohibiting abnormal behavior based on the target account, the user experience is improved.
[0114] In some embodiments, to prevent the target account from obtaining a quasi-static IP address (i.e., a fixed IP address), such as Figure 7 As shown in the embodiments of this application, the method for handling abnormal accounts further includes the following steps:
[0115] S601. The electronic device obtains the target account's first IP address and online time within the current preset time period.
[0116] S602. When the electronic device is online for a duration exceeding the second preset duration, a third access permission message is sent to the target account.
[0117] The third allow access message is used to indicate that the target account is denied access to the network based on the first IP address, but is allowed to access the network based on the third IP address. The third IP address is any IP address other than the first IP address among a plurality of preset IP addresses.
[0118] As one possible implementation, when the online time of an electronic device exceeds a second preset time, it determines any one of the multiple preset IP addresses other than the first IP address as the third IP address and sends a third access permission message to the target account, so that the target account can access the network based on the third IP address.
[0119] It should be noted that the second preset duration is longer than the first preset duration. The second preset duration is used to indicate the maximum usage time of the target account accessing the network based on the same broadband account.
[0120] For example, the second preset duration can be 24 hours.
[0121] Understandably, since the online time is defined as the duration the target account accesses the network using the first IP address, if the online time exceeds the second preset duration, any IP address other than the first IP address will be sent to the target account. This prevents the target account from using the first IP address for an extended period, thus preventing the first IP address from becoming a static IP address.
[0122] In some embodiments, when the target account is a normal account (an account other than a dial-up or instant dial-up account), such as Figure 8 As shown, the method provided in this application embodiment further includes the following steps:
[0123] S701. The electronic device receives an access request message sent by the target account.
[0124] The access request message includes the target username and password.
[0125] S702. When the target account is a legitimate account, the electronic device verifies the validity of the target account.
[0126] S703. If the target account is valid, the electronic device sends a first access permission message to the target account.
[0127] As one possible implementation, if the target account is valid, the electronic device determines any one of a plurality of preset IP addresses as the second IP address. Then, the electronic device sends a first access permission message to the target account, enabling the target account to access the network based on the second IP address. Furthermore, the electronic device stores the target account's login request information.
[0128] For example, the login request information for the target account includes: the time when the target account sends the access request message and the first permission message.
[0129] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the abnormal account processing device or electronic device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0130] This application embodiment can, based on the above method, exemplarily divide the abnormal account processing device or electronic device into functional modules. For example, the abnormal account processing device or electronic device may include various functional modules corresponding to each functional division, or two or more functions may be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; in actual implementation, there may be other division methods.
[0131] Figure 9 This is a block diagram illustrating an abnormal account processing apparatus 800 according to an exemplary embodiment. Figure 9 As shown, the abnormal account processing device 800 includes a receiving unit 801, a processing unit 802, an acquisition unit 803, and a sending unit 804.
[0132] The receiving unit 801 is used to receive access request messages sent by the target account.
[0133] Processing unit 802 is used to determine whether to allow the target account to access the network based on the first login information of the target account within the current preset time period when the target account is an instant-dial account. An instant-dial account refers to an account that has accessed the network more than a first preset number of times within the first preset time period. The first login information includes: the number of login attempts and the account login status, which includes: logged-in status and not logged-in status.
[0134] The processing unit 802 is further configured to, when the target account is a dial-up account, determine whether to allow the target account to access the network based on the second login information of the target account within the current preset time period. A dial-up account refers to an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: login count, first IP address, and internet access duration. The first IP address represents the IP address assigned to the target account during the last login, and the internet access duration represents the duration the target account accessed the network based on the first IP address.
[0135] Optionally, if the target account is a dial-up account, in order to determine whether to allow the target account to access the network, such as... Figure 9 As shown, the processing unit 802 described above is specifically used for:
[0136] If the number of login attempts within the current preset time period is greater than or equal to the third preset number, and the account is logged in during the current preset time period, an access denial message will be sent to the target account. The access denial message is used to indicate that the target account's access to the network is denied.
[0137] If the number of login attempts within the current preset time period is greater than or equal to the third preset number of attempts, and the account's login status within the current preset time period is not logged in, a first access permission message is sent to the target account. The first access permission message indicates that the target account is allowed to access the network based on a second IP address, which is any one of a plurality of preset IP addresses.
[0138] If the number of login attempts within the current preset time period is less than the third preset number, a first access permission message is sent to the target account.
[0139] Optionally, if the target account is a dial-up account, in order to determine whether to allow the target account to access the network, such as... Figure 9 As shown, the processing unit 802 described above is specifically used for:
[0140] If the number of login attempts within the current preset time period is greater than or equal to the fourth preset number of attempts, and the online time duration within the current preset time period is less than the first preset time duration, a second access permission message is sent to the target account. The second access permission message is used to indicate that the target account is allowed to access the network based on the first IP address.
[0141] If the number of login attempts within the current preset time period is greater than or equal to the fourth preset number of attempts, and the online time within the current preset time period is greater than or equal to the first preset time, a first access permission message is sent to the target account.
[0142] If the number of login attempts within the current preset time period is less than the fourth preset number, send a first access permission message to the target account.
[0143] Optionally, to prevent the target account from obtaining a quasi-static IP address, such as Figure 9 As shown, the abnormal account processing device 800 provided in this application embodiment further includes: an acquisition unit 803 and a sending unit 804.
[0144] The acquisition unit 803 is used to acquire the first IP address of the target account within the current preset time period and the online time duration within the current preset time period.
[0145] The sending unit 804 is configured to send a third access permission message to the target account when the online time exceeds a second preset time. The third access permission message is used to indicate that the target account is denied access to the network based on the first IP address, but is allowed to access the network based on the third IP address, where the third IP address is any IP address other than the first IP address from a plurality of preset IP addresses.
[0146] Figure 10 A block diagram of an electronic device is shown according to an exemplary embodiment. (See diagram below.) Figure 10 As shown, the electronic device 900 includes, but is not limited to, a processor 901 and a memory 902.
[0147] The aforementioned memory 902 is used to store the executable instructions of the aforementioned processor 901. It is understood that the aforementioned processor 901 is configured to execute instructions to implement the abnormal account handling method in the above embodiments.
[0148] It should be noted that those skilled in the art will understand that Figure 10 The electronic device structure shown does not constitute a limitation on the electronic device; the electronic device may include, but is not limited to, other electronic devices. Figure 10 This may indicate more or fewer components, or combinations of certain components, or different component arrangements.
[0149] The processor 901 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in the memory 902, and by calling data stored in the memory 902, it performs various functions and processes data, thereby providing overall monitoring of the electronic device. The processor 901 may include one or more processing units. Optionally, the processor 901 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 901.
[0150] The memory 902 can be used to store software programs and various data. The memory 902 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, application programs required by at least one functional module (such as a receiving unit, processing unit, acquisition unit, and sending unit). Furthermore, the memory 902 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0151] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 902 including instructions, which can be executed by a processor 901 of an electronic device 900 to implement the abnormal account processing method in the above embodiments.
[0152] In actual implementation, Figure 9 The functions of the receiving unit 801, processing unit 802, acquisition unit 803, and transmitting unit 804 can all be provided by... Figure 10 The processor 901 calls the computer program stored in the memory 902 to implement the process. The specific execution process can be found in the description of the abnormal account handling method in the above embodiments, and will not be repeated here.
[0153] Optionally, the computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a read-only memory (ROM), random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device.
[0154] In an exemplary embodiment, this application also provides a computer program product including one or more instructions, which can be executed by the processor 901 of the electronic device 900 to perform the methods described above.
[0155] It should be noted that when one or more instructions in the computer-readable storage medium or computer program product are executed by the processor of an electronic device, they implement the various processes of the above method embodiments and achieve the same technical effect as the above method. To avoid repetition, they will not be described again here.
[0156] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0157] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0158] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0159] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0160] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0161] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for handling abnormal accounts, characterized in that, The method includes: Receive access request messages sent by the target account; In the case that the target account is a dial-up account, it is determined whether to allow the target account to access the network based on the first login information of the target account within the current preset time period; the dial-up account is used to represent an account that accesses the network more than a first preset number of times within the first preset time period, and the first login information includes: login count and account login status, and the account login status includes: logged-in status and not logged-in status; If the target account is a dial-up account, the system determines whether to allow the target account to access the network based on the second login information of the target account within the current preset time period. The dial-up account is used to indicate an account that switches networks more than a second preset number of times within the second preset time period. The second login information includes: the number of logins, a first IP address, and the internet access duration. The first IP address is used to indicate the IP address assigned to the target account during the last login, and the internet access duration is used to indicate the duration of the target account's network access based on the first IP address. The step of determining whether to allow the target account to access the network based on the target account's first login information within the current preset time period includes: If the number of login attempts within the current preset time period is greater than or equal to a third preset number, and the account login status within the current preset time period is the logged-in status, an access denial message is sent to the target account; the access denial message is used to indicate that the target account is denied access to the network. If the number of login attempts within the current preset time period is greater than or equal to the third preset number of login attempts, and the account login status within the current preset time period is the non-login status, a first access permission message is sent to the target account; the first access permission message is used to indicate that the target account is allowed to access the network based on a second IP address, where the second IP address is any one of a plurality of preset IP addresses; If the number of login attempts within the current preset time period is less than the third preset number of login attempts, the first access permission message is sent to the target account. The step of determining whether to allow the target account to access the network based on the second login information of the target account within the current preset time period includes: If the number of login attempts within the current preset time period is greater than or equal to a fourth preset number of attempts, and the online time duration within the current preset time period is less than a first preset time duration, a second access permission message is sent to the target account; the second access permission message is used to indicate that the target account is allowed to access the network based on the first IP address; If the number of login attempts within the current preset time period is greater than or equal to the fourth preset number of login attempts, and the online time duration within the current preset time period is greater than or equal to the first preset time duration, the first access permission message is sent to the target account. If the number of login attempts within the current preset time period is less than the fourth preset number, the first permission message is sent to the target account.
2. The method according to claim 1, characterized in that, After receiving the access request message sent by the target account, the method further includes: Obtain the first IP address of the target account within the current preset time period and the online time duration within the current preset time period; If the online time exceeds the second preset time, a third access permission message is sent to the target account; the third access permission message is used to indicate that the target account is denied access to the network based on the first IP address, and the target account is allowed to access the network based on the third IP address, wherein the third IP address is any IP address other than the first IP address among the plurality of preset IP addresses.
3. A device for processing abnormal accounts, characterized in that, The device includes a receiving unit and a processing unit; The receiving unit is used to receive access request messages sent by the target account; The processing unit is configured to, when the target account is a dial-up account, determine whether to allow the target account to access the network based on the first login information of the target account within the current preset time period. The instant dial account is used to represent an account that accesses the network more than a first preset number of times within a first preset time period. The first login information includes: login count and account login status. The account login status includes: logged-in status and not logged-in status. The processing unit is further configured to, when the target account is a dial-up account, determine whether to allow the target account to access the network based on the second login information of the target account within the current preset time period; the dial-up account is used to indicate an account that switches networks more than a second preset number of times within the second preset time period; the second login information includes: the number of logins, a first IP address, and the internet access duration; the first IP address is used to indicate the IP address assigned to the target account during the last login, and the internet access duration is used to indicate the duration of the target account accessing the network based on the first IP address; The processing unit is specifically used for: If the number of login attempts within the current preset time period is greater than or equal to a third preset number, and the account login status within the current preset time period is the logged-in status, an access denial message is sent to the target account; the access denial message is used to indicate that the target account is denied access to the network. If the number of login attempts within the current preset time period is greater than or equal to the third preset number of login attempts, and the account login status within the current preset time period is the non-login status, a first access permission message is sent to the target account; the first access permission message is used to indicate that the target account is allowed to access the network based on a second IP address, where the second IP address is any one of a plurality of preset IP addresses; If the number of login attempts within the current preset time period is less than the third preset number of login attempts, the first access permission message is sent to the target account. The processing unit is specifically used for: If the number of login attempts within the current preset time period is greater than or equal to a fourth preset number of attempts, and the online time duration within the current preset time period is less than a first preset time duration, a second access permission message is sent to the target account; the second access permission message is used to indicate that the target account is allowed to access the network based on the first IP address; If the number of login attempts within the current preset time period is greater than or equal to the fourth preset number of login attempts, and the online time duration within the current preset time period is greater than or equal to the first preset time duration, the first access permission message is sent to the target account. If the number of login attempts within the current preset time period is less than the fourth preset number, the first permission message is sent to the target account.
4. The apparatus according to claim 3, characterized in that, The device further includes an acquisition unit and a transmission unit; The acquisition unit is used to acquire the first IP address of the target account within the current preset time period and the online time duration within the current preset time period; The sending unit is used to send a third access permission message to the target account when the online time exceeds a second preset time. The third allow access message is used to indicate that the target account is denied access to the network based on the first IP address, and the target account is allowed to access the network based on the third IP address, wherein the third IP address is any IP address other than the first IP address among the plurality of preset IP addresses.
5. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the method as described in any one of claims 1-2.
6. A computer-readable storage medium, characterized in that, When the computer-executable instructions stored in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is capable of performing the method as described in any one of claims 1-2.
7. A computer program product, characterized in that, The computer program product includes computer instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1-2.