A method and apparatus for identifying risks in mini-programs

By combining edge-side and cloud-based risk identification technologies, the system obtains the identifiers and page information of mini-programs, solving various risk identification challenges on payment platforms, improving risk identification efficiency and resource utilization, and enhancing user privacy and platform security.

CN118673498BActive Publication Date: 2025-11-14ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410695079.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-30
Publication Date
2025-11-14
Estimated Expiration
2044-05-30

AI Technical Summary

Technical Problem

As the application scope of mini-programs expands, risks such as user privacy and security, quality control, compliance, and transaction risks arise. Existing technologies struggle to effectively identify and manage these risks, leading to security and compliance issues for payment platforms.

Method used

By obtaining the identification information of the mini-program and the page information, risk databases are used for on-device risk identification, combined with cloud-based risk identification, to achieve risk identification and management of mini-program pages.

Benefits of technology

It improves the efficiency of risk identification and resource utilization, enhances the security of user privacy data, ensures the compliance and security of mini programs, and reduces duplicate identification and resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118673498B_ABST
    Figure CN118673498B_ABST
Patent Text Reader

Abstract

This specification discloses one or more embodiments of a method and apparatus for identifying risks in a mini-program. The method first obtains first information for risk identification of a target mini-program. If corresponding page information is found in a risk database based on the obtained first information, the method obtains the endpoint risk identification result corresponding to the page information from the risk database. If the endpoint risk identification result indicates that a preset risk exists in the page information, the method performs risk identification on the page information based on the first information, obtains the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result. If no endpoint risk identification result corresponding to the page information is obtained from the risk database, the method calls the unvisited page corresponding to the page information in the terminal operating environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information has a preset risk.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of internet risk control technology, and in particular to a method and device for identifying risks in mini-programs. Background Technology

[0002] With the development of internet technology, mini-programs are being used more and more widely. The diverse and ready-to-use services provided by mini-programs (such as shopping, ordering food, and travel services) can effectively improve the application scenarios of the payment platform on which the mini-program is located, increase user activity and dwell time on the payment platform, and also provide the payment platform on which the mini-program is located with powerful digital tools and interfaces.

[0003] Correspondingly, as the application scope of mini-programs becomes increasingly widespread, various risks associated with them are also gradually increasing, such as user privacy and security risks, quality control risks, compliance risks, and transaction risks. With people placing greater emphasis on their privacy data and the security risk management needs of payment platforms hosting mini-programs, there is a need to provide a method for identifying mini-program risks in order to implement corresponding risk management measures for mini-programs operating on payment platforms. Summary of the Invention

[0004] On one hand, one or more embodiments of this specification provide a method for identifying program risks, including: acquiring first information for risk identification of a target mini-program, the first information including identification information of the target mini-program and identification information of page information in the target mini-program. If corresponding page information is found in a risk database based on the acquired first information, a terminal-side risk identification result corresponding to the page information is obtained from the risk database, the terminal-side risk identification result being determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, risk identification is performed on the page information based on the first information, a cloud-based risk identification result corresponding to the page information is obtained, and a risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If no terminal-side risk identification result corresponding to the page information is obtained from the risk database, an unaccessed page corresponding to the page information in the terminal operating environment required for the target mini-program to run is invoked, information of the unaccessed page is captured, and it is determined whether there is a preset risk in the page information.

[0005] On the other hand, one or more embodiments of this specification provide a program risk identification device, including: an information acquisition module, which acquires first information for risk identification of a target mini-program, the first information including identification information of the target mini-program and identification information of page information in the target mini-program; a terminal-side risk identification result acquisition module, which, if the corresponding page information is found in a risk database based on the acquired first information, acquires a terminal-side risk identification result corresponding to the page information from the risk database, the terminal-side risk identification result being a risk identification result determined by the terminal device where the target mini-program is located for the page information; a first risk identification module, which, if the terminal-side risk identification result indicates that there is a preset risk in the page information, performs risk identification on the page information based on the first information, acquires a cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result; and a second risk identification module, which, if the terminal-side risk identification result corresponding to the page information is not acquired from the risk database, calls an unaccessed page corresponding to the page information in the terminal operating environment required for the target mini-program to run, captures information of the unaccessed page, and determines whether there is a preset risk in the page information.

[0006] Furthermore, one or more embodiments of this specification provide a program risk identification system, including: a terminal and a cloud server, wherein the terminal collects page information generated during a user's access to a target mini-program, performs terminal-side risk identification based on the page information, obtains a terminal-side risk identification result corresponding to the page information, performs privacy protection processing on the terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program, and sends the privacy-protected terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program to a risk database; the cloud server obtains first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program, and if based on the obtained first information... If the information finds the corresponding page information in the risk database, then the terminal-side risk identification result corresponding to the page information is obtained from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, then the page information is risk identified based on the first information, and the cloud-based risk identification result corresponding to the page information is obtained. The risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If the terminal-side risk identification result corresponding to the page information is not obtained from the risk database, then the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unvisited page is captured, and it is determined whether there is a preset risk in the page information.

[0007] Furthermore, one or more embodiments of this specification provide an electronic device, including: a processor; and a memory arranged to store computer-executable instructions, which, when executed, enable the processor to: acquire first information for risk identification of a target mini-program, the first information including identification information of the target mini-program and identification information of page information in the target mini-program. If corresponding page information is found in a risk database based on the acquired first information, a terminal-side risk identification result corresponding to the page information is obtained from the risk database, the terminal-side risk identification result being determined by the terminal device where the target mini-program resides for the page information. If the terminal-side risk identification result indicates that a preset risk exists in the page information, risk identification is performed on the page information based on the first information, a cloud-based risk identification result corresponding to the page information is obtained, and a risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If no terminal-side risk identification result corresponding to the page information is obtained from the risk database, an unaccessed page corresponding to the page information in the terminal operating environment required for the target mini-program to run is invoked, information of the unaccessed page is captured, and it is determined whether the page information has a preset risk.

[0008] Furthermore, one or more embodiments of this specification provide a storage medium for storing a computer program, which can be executed by a processor to implement the following process: Obtaining first information for risk identification of a target mini-program, the first information including identification information of the target mini-program and identification information of page information within the target mini-program. If corresponding page information is found in a risk database based on the obtained first information, then obtaining a terminal-side risk identification result corresponding to the page information from the risk database, the terminal-side risk identification result being a risk identification result determined by the terminal device where the target mini-program resides for the page information. If the terminal-side risk identification result indicates that a preset risk exists in the page information, then performing risk identification on the page information based on the first information, obtaining a cloud-based risk identification result corresponding to the page information, and determining the risk identification result corresponding to the page information based on the cloud-based risk identification result. If no terminal-side risk identification result corresponding to the page information is obtained from the risk database, then calling an unaccessed page corresponding to the page information in the terminal operating environment required for the target mini-program to run, capturing information from the unaccessed page, and determining whether the page information has a preset risk. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in one or more embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is a schematic flowchart of a method for identifying risks in a mini-program according to an embodiment of this specification;

[0011] Figure 2 This is a schematic diagram illustrating the implementation principle of a mini-program risk identification according to an embodiment of this specification;

[0012] Figure 3 This is a flowchart illustrating the application of a WeChat mini-program risk identification method according to an embodiment of this specification.

[0013] Figure 4 This is a schematic block diagram of a mini-program risk identification device according to an embodiment of this specification;

[0014] Figure 5 This is a schematic block diagram of a mini-program risk identification system according to an embodiment of this specification;

[0015] Figure 6 This is a schematic block diagram of an electronic device according to an embodiment of this specification. Detailed Implementation

[0016] This specification provides one or more embodiments of a method and apparatus for identifying risks in mini-programs.

[0017] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this document.

[0018] like Figure 1As shown in the embodiments of this specification, a method for identifying risks in a mini-program is provided. The executing entity of this method can be a server (such as a cloud server). This server can be a single independent server or a server cluster composed of multiple servers. The server can be a backend server in fields such as finance or online shopping, or a backend server of an application. The method specifically includes the following steps:

[0019] In step S102, first information for risk identification of the target mini-program is obtained. The first information includes the identification information of the target mini-program and the identification information of the page information in the target mini-program.

[0020] With the development of internet payment platforms, the importance of mini-programs is becoming increasingly prominent. For example, mini-programs can enhance user stickiness, expand the service ecosystem, realize monetization channels, and improve market competitiveness for payment platforms. The diverse and readily available services offered by mini-programs (such as shopping, food ordering, and travel services) effectively increase the application scenarios of the payment platform hosting the mini-program, increase user activity and dwell time on the platform, and provide powerful digital tools and interfaces. This helps payment platforms achieve rapid online business development and digital transformation. Therefore, mini-programs are an indispensable part of the comprehensive service capabilities and market competition strategies of payment platforms.

[0021] Correspondingly, as the application scope of mini-programs becomes increasingly widespread, various risks associated with them are also gradually increasing. These risks include: user privacy and security risks (e.g., unauthorized users stealing user information or committing fraud through malicious software or phishing programs), quality control risks (e.g., with the rapid increase in mini-program data, low-quality or infringing mini-programs may affect the quality of the platform on which the mini-program resides), compliance risks (e.g., based on different legal and regulatory requirements for internet finance and e-commerce in different geographical regions, mini-programs must comply with local regulations, otherwise they may face risks such as fines and removal from app stores), and transaction risks (e.g., when conducting goods transactions or service reservations through mini-programs, there may be transaction disputes, refund issues, or service quality problems, all of which will affect user experience and the platform's reputation). With people paying increasing attention to their privacy data and the growing need for security risk management on payment platforms hosting mini-programs, a method for identifying mini-program risks is needed to implement corresponding risk management measures for mini-programs operating on payment platforms, thereby reducing risks and maintaining the orderly operation of mini-programs.

[0022] Mini-programs operating on payment platforms fall under the private domain operation of the mini-program entity. Information exposed based on user behavior (such as browsing, clicking, and transaction behavior) and access operations within the mini-program constitutes the privacy information of both the user and the mini-program entity. By using payment platforms to identify and control risks associated with mini-programs, user privacy data can be effectively protected. Specifically, exposure occurs when a user opens a page within a mini-program (presented to the client). Each time a user opens a page, it is considered an exposure to that page. Pages that are never opened by the client are considered unexposed pages.

[0023] The risk types of the mini-programs in the embodiments of this specification can be content risks, such as: the mini-program containing content that violates laws and regulations, the mini-program publishing infringing content, and the mini-program publishing false advertisements, etc.; or they can be experiential risks, such as user privacy and security risks, quality control risks, and transaction risks, as mentioned above.

[0024] The target mini-program is the mini-program to be risk-identified. The first information used for risk identification of the target mini-program includes its identifier and the identifier of its page information. The identifier of the target mini-program can be a mini-program ID, and the identifier of its page information can be a specific page ID. In this embodiment, the risk control level for the target mini-program is at the page level (i.e., the risk unit is at the page level). If any page in the target mini-program is found to contain risk information, corresponding risk control measures are taken, the service of the target mini-program is suspended, and rectification is carried out. Therefore, the focus of risk identification is based on the page information of the mini-program; specifically, it can be determined whether the target mini-program has any preset risks based on the information of each page in the target mini-program.

[0025] Page information refers to the specific content information of a page in a mini-program. It can be text information on the page, interactive button icons, images, or images containing text content.

[0026] In practice, the first information can be obtained based on data in the risk database, according to a preset time period, to initiate the subsequent risk identification process (e.g., daily inspection scenario for risk identification of mini-programs). Alternatively, the first information can be obtained based on a risk identification request sent by the terminal to initiate the subsequent risk identification process (e.g., the terminal sends a risk identification request to the risk database and performs risk identification based on data in the risk database, or the terminal sends a risk identification request to the cloud server). This specification does not limit the implementation of this method.

[0027] In step S104, if the corresponding page information is found in the risk database based on the first information obtained, the terminal risk identification result corresponding to the page information is obtained from the risk database. The terminal risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information.

[0028] The risk database stores the mapping relationship between historical page information and edge-side risk identification results. Specifically, it can include: the identification information of the mini-program, the identification information of each page in the mini-program, and the edge-side risk identification result corresponding to each page in each mini-program. For example, if mini-program A contains page information 1 and page information 2, then the risk database can include: the identification information ID-A of mini-program A, the identification information ID-A-1 of page information 1 in mini-program A, the identification information ID-A-2 of page information 2 in mini-program A, the edge-side risk identification result A1 of page information 1 in mini-program A, and the edge-side risk identification result A2 of page information 2 in mini-program A.

[0029] The first information obtained in the embodiments of this specification includes the identification information of the target mini-program and the identification information of the page information in the target mini-program. It is not necessary to obtain the original data of the target mini-program. Moreover, the risk database stores the terminal identification results of the mini-program and the identification information of the mini-program and the page information in the mini-program corresponding to the terminal identification results, rather than the original data related to the target mini-program. Furthermore, the first information can be further processed for privacy protection before storage. Therefore, it can effectively improve the user's privacy and security.

[0030] It is important to note that the endpoint risk identification results in the risk database include both those with pre-defined risks and those without. By retrieving corresponding page information from the risk database settings and performing risk identification based on the endpoint risk identification results in the database, further risk identification can be avoided for pages in the risk database that indicate no pre-defined risks. This avoids duplicate identification, significantly reducing the number of mini-programs and their corresponding page information requiring risk identification, effectively improving the efficiency of risk identification, saving resources, and increasing resource utilization.

[0031] If the page information of the target mini-program in step S102 is stored in the risk database, the corresponding risk identification result of the page information can be determined based on the mapping relationship between the historical page information in the risk database and the risk identification result on the terminal side.

[0032] Among them, the risk identification result on the terminal side is the risk identification result determined by the terminal device based on the page information, which can be understood as the first layer of risk identification process in the mini program risk identification process.

[0033] In step S106, if the risk identification result on the terminal side indicates that there is a preset risk in the page information, then the risk identification of the page information is performed based on the first information, the cloud risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud risk identification result.

[0034] If the endpoint risk identification result indicates that a preset risk exists in the page information, then the first-level risk identification result is "preset risk exists," and the second-level risk identification process continues: based on the first information, risk identification is performed on the page information to obtain the corresponding cloud-based risk identification result. If the endpoint risk identification result indicates that no preset risk exists in the page information, then the first-level risk identification result is "no preset risk exists," and the second-level risk identification process is rejected.

[0035] If the page information is risk identified based on the first information, and the cloud risk identification result corresponding to the page information is obtained (i.e., the second-level risk identification process is executed), then the risk identification result corresponding to the page information is determined based on the cloud risk identification result. That is, the cloud risk identification result is used as the risk identification result of the current page information in the target mini-program.

[0036] In implementation, the method of identifying risks in page information based on the first information and obtaining the corresponding cloud-based risk identification results can be based on risk identification experience, with risks identified manually to determine the cloud-based risk identification results. Alternatively, it can be based on preset risk identification algorithms, such as statistical analysis algorithms or machine learning algorithms like logistic regression, to identify risks in page information on the cloud server and determine the cloud-based risk identification results. Or, it can be based on a pre-trained risk identification model to identify risks in page information and obtain the corresponding cloud-based risk identification results.

[0037] In step S108, if the risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target applet to run is called, the information of the unvisited page is captured, and it is determined whether the page information has a preset risk.

[0038] If the risk identification result corresponding to the page information is not obtained from the risk database, it can be understood that the page information of the target mini-program in step S102 is not stored in the risk database, the page has not been exposed on the user terminal, and the page information is the page information of the page that the user terminal has not accessed. Then, according to step S108 of the embodiment of this specification, the unaccessed page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unaccessed page is captured, and it is determined whether the page information has a preset risk.

[0039] In implementation, the terminal operating environment required for the target mini-program to run can be an offline real device inspection operating environment. That is, the server (such as a cloud server) controls the test equipment (such as a test mobile phone) in the test room to run pre-written automated test scripts and automatically open the page information of the target mini-program, thereby simulating the process of the target mini-program being accessed on the client, that is, simulating user behavior.

[0040] By calling the unvisited pages of the target mini-program, capturing the information of the unvisited pages (i.e., the page information of the unvisited pages), and determining whether the page information (i.e. the page information in the target mini-program in step S102) has any preset risks, it is possible to directly determine whether the current page information corresponding to the target mini-program has any preset risks on the cloud server.

[0041] This specification provides a method for identifying risks in a mini-program. The method is applied to a cloud server. First, it acquires first information for risk identification of the target mini-program. Second, if corresponding page information is found in a risk database based on the acquired first information, it retrieves the endpoint risk identification result corresponding to the page information from the risk database. The endpoint risk identification result is the risk identification result determined by the terminal device where the target mini-program resides for the page information. If the endpoint risk identification result indicates that a preset risk exists in the page information, it performs risk identification on the page information based on the first information, acquires the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result. Finally, if no endpoint risk identification result corresponding to the page information is retrieved from the risk database, it calls the unvisited page corresponding to the page information in the terminal operating environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information has a preset risk. In this way, after obtaining the first information, by searching the risk database for the corresponding terminal-side risk identification result for the page information, and determining whether to further identify risks on the cloud server based on the terminal-side risk identification, it is possible to avoid identifying risks for page information in the risk database that indicates no preset risks exist, thereby effectively improving the efficiency of risk identification and resource utilization. Moreover, the risk identification result in this embodiment is a combination of the terminal-side risk identification result and the cloud-based risk identification result. The terminal-side risk identification result comes from the terminal device. When the terminal device reports the risk identification result and its corresponding first information to the cloud server, it can better protect the privacy of user information running in the mini-program (such as IP address, device identifier, browsing behavior, and other sensitive data), thereby effectively improving data security. Furthermore, by utilizing the terminal-side risk identification result, terminal resources can be fully utilized, combining the terminal and the cloud, avoiding the direct transmission of large amounts of information to the cloud server, thus reducing the data processing pressure on the cloud server. Therefore, it can also effectively improve resource utilization and enhance the cloud server's real-time analysis and processing capabilities for risk data. By utilizing the results of edge-side risk identification, edge-side risk identification is performed every time a user accesses the mini-program on their device, effectively improving the coverage of risk identification and thus enhancing data security. Furthermore, the embodiments in this specification call upon the unvisited pages corresponding to the page information in the terminal operating environment required for the target mini-program to run, enabling automated risk identification on the cloud server, which helps improve the efficiency of risk identification.

[0042] In this embodiment of the specification, the risk database in step S104 is set on a cloud server and is used to store historical end-side risk identification results, the identification information of the mini-program corresponding to the historical end-side risk identification results, and the identification information of the page information in the mini-program.

[0043] The risk database is hosted on a cloud server. After the terminal device containing the target mini-program performs risk identification on the target mini-program, it obtains the terminal risk identification result and transmits the terminal risk identification result, along with the corresponding mini-program's identification information and the identification information of the page information within the mini-program, to the cloud server after privacy protection processing. The risk database can temporarily store historical terminal-side risk identification results, the identification information of the mini-program corresponding to the historical terminal-side risk identification results, and the identification information of the page information within the mini-program.

[0044] In the embodiments of this specification, the processing of step S106 can be varied. The following provides an optional processing method, which can be referred to in the following steps S1062-S1068.

[0045] In step S1062, the page corresponding to the target mini-program is determined based on the first information.

[0046] Based on the identifier information of the target mini-program in the first information and the identifier information of the page information in the target mini-program, a unique page (i.e. the page corresponding to the target mini-program) can be determined.

[0047] In step S1064, the page corresponding to the target mini-program in the terminal running environment required for the target mini-program to run is called, and the page corresponding to the target mini-program is parsed to extract the page information of the page corresponding to the target mini-program.

[0048] The terminal operating environment required for the target mini-program to run here can refer to the offline real device inspection operating environment in step S108 above. The difference between the two steps is that step S108 is based on the scenario where the terminal risk identification result corresponding to the page information is not obtained from the risk database (applicable to unvisited pages not exposed by the user terminal), while step S1064 is based on the scenario where the terminal risk identification result corresponding to the page information exists in the risk database, and the risk identification result indicates that there is a preset risk in the page information (applicable to pages with preset risks that have been exposed by the user terminal).

[0049] The page corresponding to the target mini-program is parsed to extract its page information, i.e., to capture the page information. In implementation, a preset algorithm can be used to capture image screenshots of the page corresponding to the target mini-program, and image element analysis can be performed based on these screenshots to obtain the page information. Alternatively, a pre-trained image parsing model can be used to first capture image screenshots of the page corresponding to the target mini-program, and then image element analysis can be performed based on these screenshots to obtain the page information. Parsing the page in step S1064 reconstructs the page structure, providing more comprehensive information for subsequent risk identification and risk management, and improving the accuracy of risk identification.

[0050] The image parsing model can be trained based on historical image samples, historical page information corresponding to the historical image samples, and a preset first loss function.

[0051] In step S1066, the extracted page information is input into the pre-trained second risk identification model to obtain the cloud risk identification result of the page corresponding to the target mini-program. The second risk identification model is a model trained based on historical page information and a preset loss function.

[0052] The second risk identification model in the embodiments of this specification can be a classification model, and the preset loss function can be the cross-entropy loss function. The second risk identification model can effectively improve the accuracy of risk identification.

[0053] In step S1068, the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result.

[0054] In the embodiments of this specification, the second risk identification model in step S1066 can be determined based on the extracted page information. Depending on the page information, the second risk identification model can be a text recognition model, an image recognition model, a multimodal model based on text and images, or a combination of any two or three of the text recognition model, image recognition model, and multimodal model.

[0055] In this embodiment of the specification, the page information in step S102 includes one or more of the following: page text information, image information, and page layout information. The image information can be a screenshot, an image composed of interactive button icons, or other visual images (such as object images). The page layout information includes: page layout (position, size, spacing, etc. of text and images), navigation design, and overall visual hierarchy of the page.

[0056] In this embodiment of the specification, after determining the risk identification result corresponding to the page information based on the cloud risk identification result in step S106, it may further include step S110: if the risk identification result corresponding to the page information indicates that there is a preset risk in the page information, then update the historical end-side risk identification result corresponding to the page information in the risk database based on the cloud risk identification result.

[0057] In implementation, if the risk identification result corresponding to the page information indicates the existence of a preset risk, cloud-based risk identification is initiated. This involves identifying risks in the page information based on the initial information to obtain cloud-based risk identification results. Furthermore, historical endpoint risk identification results can be updated based on the cloud-based risk identification results, thereby updating the risk database and automatically overwriting the historical endpoint risk identification results corresponding to the previous timestamp. This improves both the accuracy of the data stored in the risk database and its resource utilization.

[0058] In the embodiments of this specification, after step S104 above, the following step S112 may also be included.

[0059] In step S112, if the risk identification result on the terminal side indicates that there is no preset risk in the page information, then risk identification of the page information is rejected, and the risk identification result corresponding to the page information is determined according to the risk identification result on the terminal side.

[0060] If the historical endpoint risk identification results in the risk database indicate that there is no preset risk in the page information, the second-level risk identification process is rejected, and the risk identification result corresponding to the page information is determined based on the endpoint risk identification results. This can be understood as follows: if the historical endpoint risk identification results in the risk database indicate that there is no preset risk in the page information, the risk identification result corresponding to the current page information remains unchanged, i.e., it remains the historical endpoint risk identification result. This approach can save cloud server resources used for risk identification, thereby improving resource utilization.

[0061] In the embodiments of this specification, after step S108, the following steps S114-S118 may also be included.

[0062] In step S114, an evidence collection request based on the existence of a target mini-program with a preset risk is received. The evidence collection request includes the identification information of the target page to be evidenced and / or the page information of the target page to be evidenced.

[0063] A request for evidence collection based on a target mini-program with pre-existing risks can be understood as the cloud server receiving a complaint or other unusual event, triggering risk identification and processing on the cloud server. The evidence collection request can be screenshots related to the complaint (i.e., page information of the target page to be evidenced) or page identifier information related to the complaint.

[0064] In step S116, based on the identification information of the target page and / or the page information of the target page to be verified, the target page in the terminal running environment required for the target applet to run is invoked to capture the information of the target page.

[0065] In step S118, the information of the captured target page is output as the response information corresponding to the evidence collection request.

[0066] Through the above steps S114-S118, the evidence information of the target mini-program is determined based on the identification information or page information of the target page in the target mini-program, thereby providing evidence for subsequent risk control and management, and improving the reliability of risk identification and risk control and the efficiency of data processing.

[0067] The processing of step S104 above can be varied. The following provides an optional processing method. For details, please refer to the processing of steps S1042-S1044.

[0068] In step S1042, if the first information is information obtained based on a trigger from a cloud server, then the corresponding page information is searched from the risk database based on the obtained first information.

[0069] The first piece of information is information obtained based on triggers from the cloud server. It can be understood as the business side in the cloud server triggering routine inspections or a new risk identification task.

[0070] In step S1044, if the corresponding page information is found in the risk database based on the acquired first information, the end-side risk identification result corresponding to the page information is obtained from the risk database.

[0071] Furthermore, the above-mentioned step S104 also includes the following steps S1046-S1048.

[0072] In step S1046, if the first information is information obtained from the risk identification request generated by the terminal based on the privacy-protected risk identification result and the first information after privacy protection processing, then the risk identification request is used to determine whether the terminal risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program.

[0073] If a risk identification device deployed on a user's terminal device detects a pre-defined risk in the page information of a target mini-program running on the user's terminal device, the terminal sends a risk identification request to the cloud server. This risk identification request includes the privacy-processed identification information of the target mini-program, the privacy-processed identification information of the page information in the target mini-program, and the corresponding privacy-processed terminal-side risk identification result (or the mapping relationship between the page information and the terminal-side risk identification result).

[0074] For cloud servers, after receiving a risk identification request from the terminal, they can obtain the identification information of the target mini-program corresponding to the current risk identification result on the terminal side, as well as the identification information of the page information in the target mini-program (i.e., the first information) based on the risk identification request.

[0075] In implementation, the terminal-side risk identification results can be obtained based on a preset first risk identification model. Specifically, page information is input into the pre-trained first risk identification model to identify risks in the page information, thus obtaining the terminal-side risk identification results for the page corresponding to the target mini-program. The principle of the terminal's first risk identification model is the same as that of the cloud server's second risk identification model. Risk identification models of the same type but different sizes can be used. Typically, the first risk identification model deployed on the terminal has a smaller capacity (e.g., about 1MB per model), reducing resource consumption and improving user experience. The second risk identification model deployed on the cloud server has a larger capacity (e.g., about 1GB per model), resulting in stronger risk identification performance and more accurate and reliable identification results.

[0076] In the embodiments of this specification, during the process of obtaining the terminal-side risk identification result based on the first risk identification model, it is ensured that user privacy is respected and protected during the identification process. Data related to user personal information (such as sensitive information such as addresses and phone numbers) will be identified and removed in real time. If the terminal-side risk identification result is confirmed to have a preset risk, the relevant mini-program ID, page ID, and terminal-side risk identification result need to undergo privacy protection processing (e.g., encryption processing) before the privacy-protected data is transmitted to the cloud server.

[0077] In step S1048, if the terminal-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then based on the first information corresponding to the terminal-side risk identification result, risk identification is performed on the page information, the cloud-based risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result.

[0078] In implementation, the method of identifying risks in page information based on the first information corresponding to the risk identification results on the terminal side and obtaining the cloud risk identification results corresponding to the page information can refer to the processing in step S106, and will not be repeated here.

[0079] In the embodiments of this specification, the processing of step S1048 can be varied. The following provides an optional processing method, which can be referred to in the processing of step A1.

[0080] In step A1, the page information is input into the pre-trained second risk identification model to identify risks in the page information, thereby obtaining the cloud-based risk identification result of the page corresponding to the target mini-program.

[0081] The second risk identification model here is based on the same principle as the second risk identification model in step S1066, and will not be described again here.

[0082] In the embodiments of this specification, the risk identification process triggered by the risk identification request of the terminal may include the following steps S10410-S10412 after executing the above step S1046.

[0083] In step S10410, if the end-side risk identification result indicates that there is no preset risk in the page information corresponding to the target mini-program, then risk identification of the page information corresponding to the target mini-program is refused, and based on the risk identification request, the end-side risk identification result after privacy protection processing and the first information after privacy protection processing are determined.

[0084] If the client-side risk identification result indicates that there is no preset risk in the page information corresponding to the target mini-program, then risk identification for the page information corresponding to the target mini-program will be refused. This can be understood as follows: if the client-side risk identification result indicates that there is no preset risk in the page information corresponding to the target mini-program, then the risk identification result for the page information is determined based on the client-side risk identification result. This approach avoids identifying risks based on client-side risk identification results that do not contain preset risks, thereby effectively improving the resource utilization of cloud servers.

[0085] In step S10412, based on the privacy-protected risk identification results of the end-side risk identification and the privacy-protected first information, the historical end-side risk identification results corresponding to the page information in the risk database are updated, and the cloud-based risk identification results have a higher priority than the end-side risk identification results.

[0086] It should be noted that in the embodiments of this specification, the cloud-based risk identification results have a higher priority than the edge-based risk identification results. If risk identification is initiated on the cloud server side, the risk identification result corresponding to the page information is determined based on the cloud-based risk identification results, and the risk database is updated accordingly. If risk identification is not initiated on the cloud server side, the risk identification result corresponding to the page information is determined based on the edge-based risk identification results, and the risk database is updated accordingly (in the case of daily inspections conducted according to a preset time period, the edge-based risk identification results in the risk database remain unchanged). Because the risk identification scale of the cloud server is larger, prioritizing cloud-based risk identification results over edge-based risk identification results can further improve the accuracy and reliability of the risk identification results.

[0087] The schematic diagram illustrating the principle of risk identification in the mini-program embodiments of this specification can be found in [reference needed]. Figure 2 ,Depend on Figure 2 As can be seen, taking terminal-triggered and cloud server-triggered application scenarios as examples, the risk identification results in both scenarios are stored in the risk database. Specifically, the new report business can be understood as a new risk identification task triggered by the business side in the cloud server; the in-process inspection business can be understood as a risk identification task performed according to a preset time period for daily inspections; and the targeted URL inspection snapshot evidence collection business can be understood as a task to determine the evidence information of the target mini-program based on complaint cases. When the entire private domain page is exposed on the user side (i.e., the client) (the risk identification process triggered by the terminal risk identification request), the terminal-side risk identification process is initiated. The business side refers to the business side in the cloud server. After obtaining the first information, the business side provides a URL (Uniform Resource Locator) for subsequent processes and then performs risk identification processing based on the URL. Since the risk database stores terminal-side risk identification results with preset risks (black samples) and terminal-side risk identification results without preset risks (white samples), when the business side obtains the first information, it can directly search the terminal-side risk identification results of the current page information in the risk data to determine its risk status.

[0088] For a flowchart illustrating the methods described in the embodiments of this specification in practical applications, please refer to [link / reference needed]. Figure 3 , Figure 3 This demonstrates the risk identification process for private domain mini-programs using a combined edge-cloud approach. When a user browses a mini-program page through a terminal (client), the terminal can collect page information and utilize its built-in risk identification algorithm to assess the page's risks, detecting potential risks such as content security vulnerabilities, fraudulent activities, or illegal operations, thus obtaining the edge-side risk identification result. If the edge-side risk identification result indicates the presence of a preset risk, the relevant mini-program ID and page ID are reported to the cloud server (server). Subsequently, the cloud server conducts a real-device inspection of the corresponding mini-program and its page information based on the reported mini-program ID and page ID, and verifies the risk. After confirming the risk, the relevant mini-program operator will undergo corresponding handling measures.

[0089] This specification provides a method for identifying risks in a mini-program. The method is applied to a cloud server. First, it acquires first information for risk identification of the target mini-program. Second, if corresponding page information is found in a risk database based on the acquired first information, it retrieves the endpoint risk identification result corresponding to the page information from the risk database. The endpoint risk identification result is the risk identification result determined by the terminal device where the target mini-program resides for the page information. If the endpoint risk identification result indicates that a preset risk exists in the page information, it performs risk identification on the page information based on the first information, acquires the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result. Finally, if no endpoint risk identification result corresponding to the page information is retrieved from the risk database, it calls the unvisited page corresponding to the page information in the terminal operating environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information has a preset risk. In this way, after obtaining the first information, by searching the risk database for the corresponding terminal-side risk identification result for the page information, and determining whether to further identify risks on the cloud server based on the terminal-side risk identification, it is possible to avoid identifying risks for page information in the risk database that indicates no preset risks exist, thereby effectively improving the efficiency of risk identification and resource utilization. Moreover, the risk identification result in this embodiment is a combination of the terminal-side risk identification result and the cloud-based risk identification result. The terminal-side risk identification result comes from the terminal device. When the terminal device reports the risk identification result and its corresponding first information to the cloud server, it can better protect the privacy of user information running in the mini-program (such as IP address, device identifier, browsing behavior, and other sensitive data), thereby effectively improving data security. Furthermore, by utilizing the terminal-side risk identification result, terminal resources can be fully utilized, combining the terminal and the cloud, avoiding the direct transmission of large amounts of information to the cloud server, thus reducing the data processing pressure on the cloud server. Therefore, it can also effectively improve resource utilization and enhance the cloud server's real-time analysis and processing capabilities for risk data. By utilizing the results of edge-side risk identification, edge-side risk identification is performed every time a user accesses the mini-program on their device, effectively improving the coverage of risk identification and thus enhancing data security. Furthermore, the embodiments in this specification call upon the unvisited pages corresponding to the page information in the terminal operating environment required for the target mini-program to run, enabling automated risk identification on the cloud server, which helps improve the efficiency of risk identification.

[0090] In summary, specific embodiments of this subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing can be advantageous.

[0091] The above describes a method for identifying risks in mini-programs according to one or more embodiments of this specification. Based on the same idea, one or more embodiments of this specification also provide a device for identifying risks in mini-programs, such as... Figure 4 As shown.

[0092] The mini-program risk identification device includes: an information acquisition module 210, a terminal-side risk identification result acquisition module 220, a first risk identification module 230, and a second risk identification module 240, wherein:

[0093] The information acquisition module 210 acquires first information for risk identification of the target mini-program. The first information includes the identification information of the target mini-program and the identification information of the page information in the target mini-program.

[0094] The terminal-side risk identification result acquisition module 220, if it finds the corresponding page information in the risk database based on the acquired first information, then it obtains the terminal-side risk identification result corresponding to the page information from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information.

[0095] The first risk identification module 230, if the terminal risk identification result indicates that there is a preset risk in the page information, performs risk identification on the page information based on the first information, obtains the cloud risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud risk identification result.

[0096] If the second risk identification module 240 fails to obtain the terminal-side risk identification result corresponding to the page information from the risk database, it calls the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information has a preset risk.

[0097] In the embodiments of this specification, the first risk identification module 230 includes:

[0098] The page determination unit determines the page corresponding to the target mini-program based on the first information.

[0099] The parsing and processing unit calls the page corresponding to the target mini-program in the terminal running environment required for the target mini-program to run, and parses and processes the page corresponding to the target mini-program to extract the page information of the page corresponding to the target mini-program.

[0100] The cloud-based risk identification result acquisition unit inputs the extracted page information into the pre-trained second risk identification model to obtain the cloud-based risk identification result of the page corresponding to the target mini-program. The second risk identification model is a model trained based on historical page information and a preset loss function.

[0101] The risk identification result determination unit determines the risk identification result corresponding to the page information based on the cloud-based risk identification result.

[0102] In the embodiments of this specification, the second risk identification model of the cloud-based risk identification result acquisition unit includes one or more of the following: a text recognition model, an image recognition model, and a multimodal model based on text and images.

[0103] In the embodiments of this specification, the page information in the information acquisition module 210 includes one or more of the following: page text information, image information, and page layout information.

[0104] In this embodiment of the specification, the mini-program risk identification device further includes an update module. If the risk identification result corresponding to the page information indicates that there is a preset risk in the page information, the historical end-side risk identification result corresponding to the page information in the risk database is updated based on the cloud-based risk identification result.

[0105] In this embodiment of the specification, the mini-program risk identification device further includes: an evidence collection module, which outputs corresponding response information based on the evidence collection request of a template mini-program with preset risks. The evidence collection module includes:

[0106] The evidence collection request receiving unit receives evidence collection requests based on target mini-programs with preset risks. The evidence collection request includes the identification information of the target page to be evidenced and / or the page information of the target page to be evidenced.

[0107] The evidence collection unit, based on the identification information of the target page and / or the page information of the target page to be evidenced, calls the target page in the terminal running environment required for the target mini-program to run, and captures the information of the target page;

[0108] The output unit outputs the captured information from the target page as the response information corresponding to the evidence collection request.

[0109] In this embodiment of the specification, if the terminal-side risk identification result indicates that there is no preset risk in the page information, the first risk identification module 230 refuses to identify the risk of the page information and determines the risk identification result corresponding to the page information based on the terminal-side risk identification result.

[0110] In this embodiment of the specification, the end-side risk identification result acquisition module 220 includes:

[0111] The page information lookup unit, if the first information is information obtained based on a trigger from a cloud server, then searches for the corresponding page information in the risk database based on the obtained first information;

[0112] If the terminal-side risk identification result acquisition unit finds the corresponding page information in the risk database based on the acquired first information, it then obtains the terminal-side risk identification result corresponding to the page information from the risk database.

[0113] Corresponding to the terminal-side risk identification result acquisition module 220, the mini-program risk identification device also includes: a judgment module, which determines whether the terminal-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program based on the risk identification request generated by the terminal-side risk identification result after privacy protection processing and the first information after privacy protection processing.

[0114] The first risk identification module 230, if the end-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then performs risk identification on the page information based on the first information corresponding to the end-side risk identification result, obtains the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result.

[0115] In this embodiment of the specification, the first risk identification module 230, if the end-side risk identification result indicates that there is no preset risk in the page information corresponding to the target mini-program, refuses to perform risk identification on the page information corresponding to the target mini-program, and determines the end-side risk identification result after privacy protection processing and the first information after privacy protection processing based on the risk identification request; the update module updates the historical end-side risk identification result corresponding to the page information in the risk database based on the end-side risk identification result after privacy protection processing and the first information after privacy protection processing, and the cloud-based risk identification result has a higher priority than the end-side risk identification result.

[0116] This specification provides a mini-program risk identification device. First, an information acquisition module acquires first information for risk identification of a target mini-program. Second, if corresponding page information is found in a risk database based on the acquired first information, a terminal-side risk identification result acquisition module retrieves the corresponding terminal-side risk identification result from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program resides for the page information. If the terminal-side risk identification result indicates a preset risk in the page information, a first risk identification module performs risk identification on the page information based on the first information, obtains the corresponding cloud-based risk identification result, and determines the corresponding risk identification result based on the cloud-based risk identification result. Finally, if no terminal-side risk identification result is found in the risk database, a second risk identification module calls the unvisited page corresponding to the page information in the terminal operating environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information contains a preset risk. In this way, after obtaining the first information, by searching the risk database for the corresponding terminal-side risk identification result for the page information, and determining whether to further identify risks on the cloud server based on the terminal-side risk identification, it is possible to avoid identifying risks for page information in the risk database that indicates no preset risks exist, thereby effectively improving the efficiency of risk identification and resource utilization. Moreover, the risk identification result in this embodiment is a combination of the terminal-side risk identification result and the cloud-based risk identification result. The terminal-side risk identification result comes from the terminal device. When the terminal device reports the risk identification result and its corresponding first information to the cloud server, it can better protect the privacy of user information running in the mini-program (such as IP address, device identifier, browsing behavior, and other sensitive data), thereby effectively improving data security. Furthermore, by utilizing the terminal-side risk identification result, terminal resources can be fully utilized, combining the terminal and the cloud, avoiding the direct transmission of large amounts of information to the cloud server, thus reducing the data processing pressure on the cloud server. Therefore, it can also effectively improve resource utilization and enhance the cloud server's real-time analysis and processing capabilities for risk data. By utilizing the results of edge-side risk identification, edge-side risk identification is performed every time a user accesses the mini-program on their device, effectively improving the coverage of risk identification and thus enhancing data security. Furthermore, the embodiments in this specification call upon the unvisited pages corresponding to the page information in the terminal operating environment required for the target mini-program to run, enabling automated risk identification on the cloud server, which helps improve the efficiency of risk identification.

[0117] Those skilled in the art will understand that the aforementioned mini-program risk identification device can be used to implement the mini-program risk identification method described above. The detailed description therein should be similar to the method description above, and will not be repeated here to avoid being cumbersome.

[0118] This specification also provides one or more embodiments of a mini-program risk identification system, such as... Figure 5 As shown.

[0119] The mini-program risk identification system includes: terminal 310 and cloud server 320, wherein:

[0120] Terminal 310 collects page information generated during the user's access to the target mini-program, performs terminal-side risk identification based on the page information, obtains the terminal-side risk identification result corresponding to the page information, performs privacy protection processing on the terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program, and sends the privacy-protected terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program to the risk database.

[0121] The cloud server 320 acquires first information for risk identification of the target mini-program. The first information includes the identification information of the target mini-program and the identification information of the page information in the target mini-program. If the corresponding page information is found in the risk database based on the acquired first information, the terminal-side risk identification result corresponding to the page information is obtained from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, the risk identification of the page information is performed based on the first information, the cloud-based risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If the terminal-side risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unvisited page is captured, and it is determined whether there is a preset risk in the page information.

[0122] In the embodiments of this specification, the terminal generates a risk identification request based on the terminal-side risk identification result after privacy protection processing, the identification information of the target mini-program, and the identification information of the page information in the target mini-program, and sends the risk identification request to the cloud server.

[0123] The cloud server obtains the first information for risk identification of the target mini-program based on the risk identification request. The risk identification request is a request generated by the terminal based on the terminal-side risk identification result after privacy protection processing and the first information after privacy protection processing.

[0124] The cloud server determines whether the risk identification result on the client side indicates that there is a preset risk in the page information corresponding to the target mini-program based on the risk identification request. If the risk identification result on the client side indicates that there is a preset risk in the page information corresponding to the target mini-program, then the risk identification of the page information is performed based on the first information corresponding to the risk identification result on the client side, the cloud risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud risk identification result.

[0125] Based on the same idea, one or more embodiments of this specification also provide an electronic device, such as... Figure 6 As shown. Electronic devices can vary considerably due to differences in configuration or performance, and may include one or more processors 401 and memory 402. Memory 402 may store one or more application programs or data. Memory 402 may be temporary or persistent storage. The application programs stored in memory 402 may include one or more modules (not shown), each module may include a series of computer-executable instructions for the electronic device. Furthermore, processor 401 may be configured to communicate with memory 402 and execute the series of computer-executable instructions in memory 402 on the electronic device. The electronic device may also include one or more power supplies 403, one or more wired or wireless network interfaces 404, one or more input / output interfaces 405, and one or more keyboards 406.

[0126] Specifically, in this embodiment, the electronic device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for use in the electronic device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:

[0127] Obtain first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program;

[0128] If the corresponding page information is found in the risk database based on the first information obtained, the terminal risk identification result corresponding to the page information is obtained from the risk database. The terminal risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information.

[0129] If the risk identification result on the device side indicates that there is a preset risk in the page information, then the risk identification of the page information is performed based on the first information, the cloud risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud risk identification result.

[0130] If the risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called to capture the information of the unvisited page and determine whether the page information has a preset risk.

[0131] This specification provides one or more embodiments of a storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process:

[0132] Obtain first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program;

[0133] If the corresponding page information is found in the risk database based on the first information obtained, the terminal risk identification result corresponding to the page information is obtained from the risk database. The terminal risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information.

[0134] If the risk identification result on the device side indicates that there is a preset risk in the page information, then the risk identification of the page information is performed based on the first information, the cloud risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud risk identification result.

[0135] If the risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called to capture the information of the unvisited page and determine whether the page information has a preset risk.

[0136] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0137] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using a hardware physical module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0138] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, ASICs, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0139] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0140] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0141] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0142] This specification describes one or more embodiments of methods, apparatus (systems), and computer program products according to embodiments of this specification with reference to flowchart illustrations and / or block diagrams. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, produce a machine for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0143] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0144] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0145] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0146] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0147] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0148] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0149] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. This specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0150] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0151] The above description is merely one or more embodiments of this specification and is not intended to limit this application. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of one or more embodiments of this specification.

Claims

1. A method for identifying risks in mini-programs, applied to a cloud server, the method comprising: Obtain first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program; If the corresponding page information is found in the risk database based on the first information obtained, the terminal risk identification result corresponding to the page information is obtained from the risk database. The terminal risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, then the page information is risk identified based on the first information, the cloud-based risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If the risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unvisited page is captured, and it is determined whether the page information has a preset risk. The method further includes: If the first information is obtained from the risk identification request generated by the terminal based on the privacy-protected risk identification result and the first information after privacy protection processing, then based on the risk identification request, it is determined whether the terminal risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program; If the edge-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then based on the first information corresponding to the edge-side risk identification result, risk identification is performed on the page information, cloud-based risk identification result corresponding to the page information is obtained, and risk identification result corresponding to the page information is determined based on the cloud-based risk identification result.

2. The method according to claim 1, wherein the risk database is set on a cloud server and is used to store historical end-side risk identification results, identification information of the mini-program corresponding to the historical end-side risk identification results, and identification information of page information in the mini-program, wherein the step of performing risk identification on the page information based on the first information, obtaining the cloud-based risk identification result corresponding to the page information, and determining the risk identification result corresponding to the page information based on the cloud-based risk identification result includes: Based on the first information, the page corresponding to the target mini-program is determined; The page corresponding to the target mini-program in the terminal running environment required for the target mini-program to run is invoked, and the page corresponding to the target mini-program is parsed and processed to extract the page information of the page corresponding to the target mini-program; The extracted page information is input into a pre-trained second risk identification model to obtain the cloud risk identification result of the page corresponding to the target mini-program. The second risk identification model is a model trained based on historical page information and a preset loss function. The risk identification result corresponding to the page information is determined based on the cloud-based risk identification result.

3. The method according to claim 2, wherein the second risk identification model includes one or more of a text recognition model, an image recognition model, and a multimodal model based on text and images; The page information includes one or more of the following: page text information, image information, and page layout information.

4. The method according to claim 1, further comprising: Receive an evidence collection request based on a target mini-program that has a preset risk, wherein the evidence collection request includes the identification information of the target page to be evidenced and / or the page information of the target page to be evidenced; Based on the identification information of the target page and / or the page information of the target page to be verified, the target page in the terminal operating environment required for the target mini-program to run is invoked, and the information of the target page is captured; The information captured from the target page is output as the response information corresponding to the evidence collection request.

5. The method according to claim 1, after determining the risk identification result corresponding to the page information based on the cloud-based risk identification result, the method further includes: If the risk identification result corresponding to the page information indicates that there is a preset risk in the page information, then the historical terminal risk identification result corresponding to the page information in the risk database is updated based on the cloud risk identification result.

6. The method according to claim 1, further comprising: If the endpoint risk identification result indicates that there is no preset risk in the page information, then risk identification of the page information is refused, and the risk identification result corresponding to the page information is determined based on the endpoint risk identification result.

7. The method according to claim 1, wherein if corresponding page information is found in the risk database based on the acquired first information, then obtaining the end-side risk identification result corresponding to the page information from the risk database includes: If the first information is obtained based on a trigger from a cloud server, then the corresponding page information is searched from the risk database based on the obtained first information. If the corresponding page information is found in the risk database based on the first information obtained, then the end-side risk identification result corresponding to the page information is obtained from the risk database.

8. The method according to claim 7, further comprising: If the edge risk identification result indicates that there is no preset risk in the page information corresponding to the target mini-program, then risk identification of the page information corresponding to the target mini-program is refused, and based on the risk identification request, the edge risk identification result after privacy protection processing and the first information after privacy protection processing are determined. Based on the edge-side risk identification results after privacy protection processing and the first information after privacy protection processing, the historical edge-side risk identification results corresponding to the page information in the risk database are updated, and the cloud-based risk identification results have a higher priority than the edge-side risk identification results.

9. A mini-program risk identification device, the device comprising: The information acquisition module acquires first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program; The terminal-side risk identification result acquisition module, if it finds the corresponding page information in the risk database based on the acquired first information, then acquires the terminal-side risk identification result corresponding to the page information from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. The first risk identification module, if the terminal-side risk identification result indicates that there is a preset risk in the page information, then performs risk identification on the page information based on the first information, obtains the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result; If the second risk identification module does not obtain the terminal-side risk identification result corresponding to the page information from the risk database, it calls the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run, captures the information of the unvisited page, and determines whether the page information has a preset risk. The device further includes: a judgment module, which determines whether the risk identification result of the terminal-side risk identification after privacy protection processing and the risk identification request generated by the first information after privacy protection processing are obtained based on the risk identification request. The first risk identification module, if the end-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then performs risk identification on the page information based on the first information corresponding to the end-side risk identification result, obtains the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result.

10. A mini-program risk identification system, comprising a terminal and a cloud server, wherein, The terminal collects page information generated during the user's access to the target mini-program, performs terminal-side risk identification based on the page information, obtains the terminal-side risk identification result corresponding to the page information, performs privacy protection processing on the terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program, and sends the privacy-protected terminal-side risk identification result, the identification information of the target mini-program, and the identification information of the page information in the target mini-program to the risk database. The cloud server acquires first information for risk identification of the target mini-program. The first information includes the identification information of the target mini-program and the identification information of the page information in the target mini-program. If the corresponding page information is found in the risk database based on the acquired first information, the terminal-side risk identification result corresponding to the page information is obtained from the risk database. The terminal-side risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, the risk identification of the page information is performed based on the first information, the cloud-based risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If the terminal-side risk identification result corresponding to the page information is not obtained from the risk database, the unaccessed page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unaccessed page is captured, and it is determined whether there is a preset risk in the page information. The terminal generates a risk identification request based on the terminal-side risk identification result after the privacy protection processing, the identification information of the target mini-program, and the identification information of the page information in the target mini-program, and sends the risk identification request to the cloud server. The cloud server obtains first information for risk identification of the target mini-program based on the risk identification request. The risk identification request is a request generated by the terminal based on the end-side risk identification result after privacy protection processing and the first information after privacy protection processing. The cloud server determines, based on the risk identification request, whether the end-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program. If the end-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then based on the first information corresponding to the end-side risk identification result, it performs risk identification on the page information, obtains the cloud-based risk identification result corresponding to the page information, and determines the risk identification result corresponding to the page information based on the cloud-based risk identification result.

11. An electronic device, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, enable the processor to: Obtain first information for risk identification of the target mini-program, the first information including the identification information of the target mini-program and the identification information of the page information in the target mini-program; If the corresponding page information is found in the risk database based on the first information obtained, the terminal risk identification result corresponding to the page information is obtained from the risk database. The terminal risk identification result is the risk identification result determined by the terminal device where the target mini-program is located for the page information. If the terminal-side risk identification result indicates that there is a preset risk in the page information, then the page information is risk identified based on the first information, the cloud-based risk identification result corresponding to the page information is obtained, and the risk identification result corresponding to the page information is determined based on the cloud-based risk identification result. If the risk identification result corresponding to the page information is not obtained from the risk database, the unvisited page corresponding to the page information in the terminal running environment required for the target mini-program to run is called, the information of the unvisited page is captured, and it is determined whether the page information has a preset risk. Also includes: If the first information is obtained from the risk identification request generated by the terminal based on the privacy-protected risk identification result and the first information after privacy protection processing, then based on the risk identification request, it is determined whether the terminal risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program; If the edge-side risk identification result indicates that there is a preset risk in the page information corresponding to the target mini-program, then based on the first information corresponding to the edge-side risk identification result, risk identification is performed on the page information, cloud-based risk identification result corresponding to the page information is obtained, and risk identification result corresponding to the page information is determined based on the cloud-based risk identification result.

Citation Information

Patent Citations

  • Applet risk identification method and device

    CN112148603A

  • Risk detection method, device and equipment for applet

    CN113568841A