Method, device, electronic device and storage medium for generating a label library

By building a composite tag library and utilizing Internet log data and subject library generation methods, risky users can be automatically identified, solving the problems of low efficiency and accuracy of manual identification in existing technologies and achieving efficient and accurate risky user identification.

CN118734306BActive Publication Date: 2025-09-09EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410772471.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-09-09
Estimated Expiration
2044-06-14

AI Technical Summary

Technical Problem

The existing method of relying on manual identification of risky users results in low identification efficiency and accuracy.

Method used

By obtaining Internet log data, determining network security event data, building a subject library, and generating a composite tag library based on the subject library and preset target risk scenarios, the composite tag is used to determine whether the user's Internet behavior is risky.

Benefits of technology

It improves the accuracy and efficiency of risky user identification, provides convenient and efficient identification tools, and promotes the modernization of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118734306B_ABST
    Figure CN118734306B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a method, device, electronic device and storage medium for generating a label library, and relates to the field of computer technology. The method includes: obtaining Internet access log data, and determining network security event data from the Internet access log data; determining a theme library based on the network security event data; and generating a composite label library of a target risk scenario based on the theme library and a preset target risk scenario. In the technical solution provided by the embodiment of the present application, the generation function of the composite label library is realized. Each composite label in the composite label library can determine whether the user's Internet access behavior is risky, and the identification function of risky users is realized. There is no need to rely on manual abnormality identification, which improves the accuracy and efficiency of identifying risky users. At the same time, it provides a more convenient and efficient identification tool, and promotes the modernization of network security management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of computer technology, and in particular to a method, device, electronic device, and storage medium for generating a tag library. Background Art

[0002] With the rapid development of the Internet, the Internet is flooded with various risky websites that may cause serious losses to users.

[0003] Currently, risky users are identified by manually detecting risky data from massive amounts of mobile Internet data. However, this method of manually identifying risky users takes a long time and cannot guarantee the accuracy of identification, resulting in low efficiency and accuracy of identification. Summary of the Invention

[0004] The embodiments of the present application provide a method, device, electronic device, and storage medium for generating a label library, which implement a label library generation method and can identify risky users based on the label library to solve the problem of low efficiency and accuracy in the existing technology that relies on manual abnormality identification.

[0005] In a first aspect, an embodiment of the present application provides a method for generating a tag library, the method comprising:

[0006] Obtaining Internet access log data and determining network security event data from the Internet access log data, wherein the network security event data is log data with network security risks, and one network security event data corresponds to one risk type and multiple log elements;

[0007] Determine a subject library based on network security event data, where a subject library includes several subjects, each of which is a log element or a risk type;

[0008] Based on the theme library and the preset target risk scenario, a composite tag library of the target risk scenario is generated, wherein the composite tag library includes at least one composite tag, and a composite tag includes at least one theme associated with the target risk scenario. The composite tag is used to determine whether the user's online behavior is risky.

[0009] In an embodiment of the present application, Internet access log data can be obtained, and network security event data can be determined from the Internet access log data; a theme library can be determined based on the network security event data; and a composite label library of the target risk scenario can be generated based on the theme library and the preset target risk scenario. In the above technical solution, online log data can be obtained, for example, mobile online log data can be obtained, and then log data with network security risks can be extracted from the online log data. The log data with network security risks and their corresponding risk types can be combined into network security event data. Then, a theme library can be determined based on the network security event data. For example, data can be extracted from the network security event data according to each preset theme extraction rule to obtain each theme library. Then, a preset target risk scenario is obtained, and a composite tag library for the target risk scenario is generated based on the theme library and the target risk scenario, thereby realizing the generation function of the composite tag library. Each composite tag in the composite tag library can determine whether the user's online behavior is risky, realizing the identification function of risky users, eliminating the need to rely on manual anomaly identification, improving the accuracy and efficiency of risky user identification, and thus solving the problem of low identification efficiency and accuracy caused by relying on manual anomaly identification in the prior art. In addition, the composite tag library generated based on the theme library and the target risk scenario can be directly associated with specific risk types and log elements, so that the composite tag library can be quickly matched according to the user's online log data, thereby improving the efficiency and accuracy of risky user identification, thereby providing a more convenient and efficient identification tool and promoting the modernization of network security management.

[0010] In a second aspect, an embodiment of the present application provides a device for generating a tag library, the device comprising:

[0011] A first determination module is configured to obtain Internet access log data and determine network security event data from the Internet access log data, wherein the network security event data is log data with network security risks, and one network security event data corresponds to one risk type and multiple log elements;

[0012] A second determination module is configured to determine a subject library based on the network security event data, wherein a subject library includes a plurality of subjects, and a subject is a log element or a risk type;

[0013] A generation module is used to generate a composite tag library of target risk scenarios based on a theme library and preset target risk scenarios, wherein the composite tag library includes at least one composite tag, and a composite tag includes at least one theme associated with the target risk scenario. The composite tag is used to determine whether the user's online behavior is risky.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, the electronic device comprising:

[0015] at least one processor; and a memory communicatively coupled to the at least one processor;

[0016] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor so that the at least one processor can execute the method for generating a label library in any embodiment of the present application.

[0017] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a processor to implement the method for generating a label library of any embodiment of the present application when executed.

[0018] The description of the second, third and fourth aspects in this application can refer to the detailed description of the first aspect; and the beneficial effects described in the second, third and fourth aspects can refer to the analysis of the beneficial effects of the first aspect, which will not be repeated here.

[0019] In this application, the name of the label library generation device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear with other names. As long as the functions of each device or functional module are similar to those of this application, they are within the scope of the claims of this application and their equivalents.

[0020] These and other aspects of the present application will become more readily apparent from the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 This is a flowchart of a method for generating a tag library provided in an embodiment of the present application;

[0023] Figure 2 This is another flowchart of the method for generating a tag library provided in an embodiment of the present application;

[0024] Figure 3 This is a schematic diagram of the structure of a device for generating a label library provided in an embodiment of the present application;

[0025] Figure 4 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0027] It should be noted that the terms "first," "second," "target," and "original" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products, or apparatus.

[0028] Figure 1 This is a flow chart of the method for generating a tag library provided in an embodiment of the present application. This embodiment can be applied to scenarios where a composite tag library for identifying risky users needs to be constructed from mobile Internet log data. The method for generating a tag library provided in this embodiment can be executed by a tag library generation device provided in an embodiment of the present application, which can be implemented in software and / or hardware. In a specific embodiment, the tag library generation device can be integrated into an electronic device, for example, the electronic device can be a computer, a smart phone, or a tablet. The execution subject of this method can be an electronic device, see Figure 1 The tag library generation method of this embodiment includes but is not limited to the following steps:

[0029] S110: Obtain Internet access log data, and determine network security event data from the Internet access log data.

[0030] Among them, Internet log data is a record of user behavior during online activities, which may include when, where, through what device or application the user performed specific network operations. This data is of great significance for understanding user behavior, optimizing network services and ensuring network security.

[0031] Optionally, the Internet access log data may be mobile Internet access log data (i.e., a record of user behavior generated in network activities through a mobile device). The Internet access log data may include multiple log elements. Exemplarily, the log elements may be a mobile phone number, an access uniform resource locator (URL), a source Internet Protocol address (IP address), a destination IP address, Internet access time, an International Mobile Equipment Identity (IMEI), etc.

[0032] Network security event data is log data with network security risks. One network security event data corresponds to one risk type and multiple log elements.

[0033] Specifically, when it is necessary to build a composite tag library for identifying risky users, Internet access log data can be obtained. For example, you can cooperate with mobile network operators to obtain mobile Internet access log data of multiple users, and then perform data cleaning on the obtained Internet access log data. For example, remove some log data that is defaulted to safe websites. This can reduce the amount of data for subsequent analysis and improve the efficiency of tag library generation.

[0034] Afterwards, network security event data can be determined from the Internet access log data. For example, log data with network security risks (recorded as risk log data) can be extracted from the Internet access log data, and the risk type to which the risk log data belongs can be determined. Then, the risk log data and the corresponding risk type can be combined into network security event data to obtain network security event data.

[0035] It should be noted that network security event data includes all log elements in the Internet log data.

[0036] S120. Determine a subject library based on network security incident data.

[0037] Among them, the subject library is used to collect, organize and store relevant information of a specific subject, which can better understand and master a certain subject, and facilitate the retrieval and use of relevant information; the subject library can be one or more, and a subject library can include several subjects, and the subject can be a log element or a risk type.

[0038] Specifically, after obtaining the network security event data, a theme library can be determined based on the network security event data. For example, preset theme extraction rules pre-set for each theme library can be obtained, and then data extraction is performed on the network security event data according to each preset theme extraction rule to obtain the theme library corresponding to the preset theme extraction rule. Among them, the preset theme extraction rule is a pre-set theme extraction rule that can represent all themes that need to be extracted from the network security event data. In this case, the theme is a log element or risk type in the network security event data, which is used to form a theme library. The user can adjust and set the preset theme extraction rule according to actual use needs. The embodiment of the present application does not specifically limit this.

[0039] For example, if the preset topic extraction rule of the event theme library is that the extracted topics include mobile phone numbers, risk types, and online time, then the topics of the event theme library include mobile phone numbers, risk types, and online time. At this time, any network security event data can be selected as the current network security event data, and the data corresponding to the mobile phone number, the data corresponding to the risk type, and the data corresponding to the online time are extracted from the current network security event data. These data are then combined into one data in the event theme library. Afterwards, other network security event data can be selected as the current network security event data, and the above steps are repeated to obtain the data corresponding to the event theme library. If the preset topic extraction rule of the URL theme library is that the extracted topics include mobile phone numbers, accessed URLs, and online time, then the topics of the URL theme library include mobile phone numbers, accessed URLs, and online time. At this time, any network security event data can be selected as the current network security event data, and the data corresponding to the mobile phone number, the data corresponding to the accessed URL, and the data corresponding to the online time are extracted from the current network security event data. These data are then combined into one data in the URL theme library. Afterwards, other network security event data can be selected as the current network security event data, and the above steps are repeated to obtain the data corresponding to the URL theme library.

[0040] S130: Generate a composite tag library of target risk scenarios based on the theme library and preset target risk scenarios.

[0041] The target risk scenario is a pre-set risk scenario used to characterize a series of specific behaviors that pose a cybersecurity risk. Users can adjust and set the target risk scenario based on actual usage needs, and this embodiment of the application does not specifically limit this. For example, the target risk scenario can include each risk behavior and business process corresponding to the target risk scenario.

[0042] The compound tag library may include at least one compound tag. A compound tag may include at least one topic associated with a target risk scenario. The compound tag is used to determine whether a user's online behavior is risky.

[0043] Specifically, after obtaining the subject library, the pre-set target risk scenario can be obtained, and based on the subject library and the target risk scenario, a composite label library corresponding to the target risk scenario can be generated. Specifically, the target risk scenario can be deeply understood, and the risk behaviors, business processes involved, and potential security threats that may occur in the target risk scenario can be identified. Then, each subject library can be analyzed to determine which subject libraries are closely related to the target risk scenario, and an associated subject library can be obtained. Then, based on the content of the target risk scenario and the associated subject library, multiple composite labels can be constructed, one of which can more accurately describe one or more key features or behavior patterns in the target risk scenario. For example, logical operators (such as "and" and "or" can be used to combine topics related to the target risk scenario in the associated subject library to form multiple composite labels. Afterwards, the recognition accuracy and effectiveness of the composite label can be verified using historical data or simulated log data, and the composition and rules of the composite label can be adjusted and optimized based on the verification results to ensure that it can accurately identify and mark risk behaviors. Finally, all constructed composite labels are organized into a composite label library, and a clear definition and description is provided for each composite label for subsequent use and understanding.

[0044] Optionally, after obtaining the composite tag library, the composite tag library can be regularly reviewed and updated as the business environment and security standards change, that is, new composite tags can be added in a timely manner to respond to emerging risk scenarios, while composite tags that are no longer applicable can be deleted or modified.

[0045] The technical solution of the embodiment of the present application can obtain Internet access log data and determine network security event data from the Internet access log data; determine a theme library based on the network security event data; and generate a composite label library of the target risk scenario based on the theme library and the preset target risk scenario. In the above technical solution, online log data can be obtained, for example, mobile online log data can be obtained, and then log data with network security risks can be extracted from the online log data. The log data with network security risks and their corresponding risk types can be combined into network security event data. Then, a theme library can be determined based on the network security event data. For example, data can be extracted from the network security event data according to each preset theme extraction rule to obtain each theme library. Then, a preset target risk scenario is obtained, and a composite tag library for the target risk scenario is generated based on the theme library and the target risk scenario, thereby realizing the generation function of the composite tag library. Each composite tag in the composite tag library can determine whether the user's online behavior is risky, realizing the identification function of risky users, eliminating the need to rely on manual anomaly identification, improving the accuracy and efficiency of risky user identification, and thus solving the problem of low identification efficiency and accuracy caused by relying on manual anomaly identification in the prior art. In addition, the composite tag library generated based on the theme library and the target risk scenario can be directly associated with specific risk types and log elements, so that the composite tag library can be quickly matched according to the user's online log data, thereby improving the efficiency and accuracy of risky user identification, thereby providing a more convenient and efficient identification tool and promoting the modernization of network security management.

[0046] The following further describes a method for generating a tag library provided by an embodiment of the present application. Figure 2 This is another flow chart of the method for generating a tag library provided by an embodiment of the present application. This embodiment of the present application is optimized based on the above embodiments.

[0047] See also Figure 2 The method of this embodiment includes but is not limited to the following steps:

[0048] S210: Obtain Internet access log data.

[0049] The implementation process and technical principle of S210 are the same as those of S110 , and reference may be made to the description of the above step S110 , which will not be repeated here.

[0050] S220: Match the Internet access log data with a preset event rule library to obtain network security event data.

[0051] The preset event rule base is a pre-set rule base used to characterize relevant information about websites that pose network security risks. Network security event data can be determined from Internet access log data based on the preset event rule base. Users can adjust and configure the preset event rule base based on actual usage needs. This embodiment of the present application does not specifically limit this. For example, the preset event rule base may include the URL, IP address, and risk type of the risky website.

[0052] Specifically, after obtaining the Internet access log data, a pre-set preset event rule library can be obtained, and the Internet access log data can be matched with the preset event rule library to obtain network security event data. For example, the access URL in the Internet access log data can be matched with the URL in the preset event rule library. If the access URL in the Internet access log data matches the URL in the preset event rule library, it indicates that the Internet access log data is log data with network security risks. At this time, the risk type of the Internet access log data can be determined according to the risk type in the preset event rule library, and the Internet access log data and its corresponding risk type are combined into network security event data; or, the destination IP address in the Internet access log data can be matched with the IP address in the preset event rule library. If the destination IP address in the Internet access log data matches the IP address in the preset event rule library, it indicates that the Internet access log data is log data with network security risks. At this time, the risk type of the Internet access log data can be determined according to the risk type in the preset event rule library, and the Internet access log data and its corresponding risk type are combined into network security event data.

[0053] Optionally, before determining the network security event data from the Internet log data, it can be determined whether the Internet log data has information corresponding to the log element; if the log element includes a mobile phone number, and the Internet log data does not have information corresponding to the mobile phone number, the location information of the mobile phone number is determined based on the preset mobile phone number location correspondence; if the log element includes an IP address, and the Internet log data does not have information corresponding to the IP address, the location information of the IP address is determined based on the preset IP location correspondence.

[0054] The log element includes at least one of a mobile phone number and an Internet Protocol (IP) address. The preset mobile phone number-location correspondence is a preset mobile phone number-location correspondence, used to represent the correspondence between the mobile phone number and the location information. The preset IP-location correspondence is a preset IP-location correspondence, used to represent the correspondence between the IP address and the location information.

[0055] Optionally, a correspondence between mobile phone numbers and their locations can be established in advance: by cooperating with mobile network operators, the operator's database can be queried in advance to obtain the correspondence between mobile phone numbers and their location information, and then based on the correspondence between mobile phone numbers and their location information, a correspondence between mobile phone numbers and their location information can be established to facilitate subsequent backfilling of the mobile phone number's location information.

[0056] Optionally, an IP location correspondence can be established in advance: a public IP address library or API interface can be used in advance to obtain the correspondence between the IP address and the location information, and then an IP location correspondence can be established based on the correspondence between the IP address and the location information, to facilitate subsequent backfilling of the IP address location information.

[0057] Specifically, in one implementation method, when the log element includes a mobile phone number, it is determined whether the Internet access log data has information corresponding to the mobile phone number. If the Internet access log data does not have information corresponding to the mobile phone number, the preset mobile phone number location correspondence relationship is queried based on the mobile phone number to obtain the location information of the mobile phone number, and the location information of the mobile phone number is stored in the corresponding Internet access log data.

[0058] In another implementation, when the log element includes an IP address, it is determined whether the Internet access log data has information corresponding to the IP address. At this time, the IP address includes the source IP address and the destination IP address. If the Internet access log data does not have information corresponding to the IP address, the preset IP location correspondence relationship is queried based on the IP address to obtain the location information of the IP address, and the location information of the IP address is stored in the corresponding Internet access log data.

[0059] In another implementation, when the log elements include a mobile phone number and an IP address, it is determined whether the Internet access log data has information corresponding to the mobile phone number and information corresponding to the IP address. If the Internet access log data does not have information corresponding to the mobile phone number, the preset mobile phone number location correspondence is queried based on the mobile phone number to obtain the location information of the mobile phone number, and the location information of the mobile phone number is stored in the corresponding Internet access log data; if the Internet access log data does not have information corresponding to the IP address, the preset IP location correspondence is queried based on the IP address to obtain the location information of the IP address, and the location information of the IP address is stored in the corresponding Internet access log data; if the Internet access log data does not have information corresponding to the mobile phone number and information corresponding to the IP address, the preset mobile phone number location correspondence is queried based on the mobile phone number to obtain the location information of the mobile phone number, and the preset IP location correspondence is queried based on the IP address to obtain the location information of the IP address, and then the location information of the mobile phone number and the location information of the IP address are stored in the corresponding Internet access log data.

[0060] In the embodiment of the present application, based on the preset mobile phone number location correspondence and the preset IP location correspondence, the backfill function of the location information is realized, which can ensure the integrity of the data and provide a more comprehensive information basis for subsequent risk analysis, thereby improving the accuracy of identifying risky users. At the same time, it can avoid repeated query operations of this type in the subsequent risk analysis process, reduce the consumption of computing resources, and improve the efficiency of overall data processing and analysis, thereby improving the efficiency of identifying risky users.

[0061] S230. Determine a subject library based on network security event data.

[0062] The implementation process and technical principle of S230 are the same as those of S120. Please refer to the description of the above step S120 and will not be repeated here.

[0063] S240. Determine a tag library based on the theme library.

[0064] Among them, the tag library is a collection used to store and organize tags. In the field of risk management and security, the tag library may contain tags related to risk scenarios, risk types, user behaviors, etc., which are used to identify and analyze potential security risks; the tag library can include at least one dynamic tag, and a dynamic tag can include multiple topics. Dynamic tags are used to characterize dynamic attributes in risk scenarios, which can more accurately identify and respond to potential security risks.

[0065] Specifically, after obtaining the subject library, the tag library can be determined based on the subject library. For example, when the tag library includes at least one dynamic tag, the subject library related to network security risks in the subject library (recorded as a risk-related subject library) can be determined. Then, the various preset dynamic extraction rules set in advance for the tag library can be obtained, and then according to each preset dynamic extraction rule, data extraction is performed on the risk-related subject library respectively to obtain the dynamic tags corresponding to the preset dynamic extraction rules, and the dynamic tags are combined into a tag library. Among them, the preset dynamic extraction rules are preset dynamic tag extraction rules that are used to characterize all topics that need to be extracted from the subject library. Dynamic tags can be determined. Users can adjust and set the preset dynamic extraction rules according to actual usage needs. The embodiments of the present application do not make specific limitations on this.

[0066] Exemplarily, if the preset dynamic extraction rule of dynamic tag 1 is that the access order of risk types is to visit risk type 1 first and then visit risk type 2, then the subject of dynamic tag 1 includes mobile phone number, risk type, and Internet access time corresponding to the risk type. At this time, any mobile phone number can be selected from the event theme library as the current mobile phone number, and the risk type and Internet access time corresponding to the current mobile phone number can be extracted from the event theme library. Then, the risk type of the current mobile phone number is sorted according to the Internet access time, and it is determined whether the access order of risk types is to visit risk type 1 first and then visit risk type 2. If so, the current mobile phone number, risk type 1, risk type 2, Internet access time of risk type 1 and Internet access time of risk type 2 are combined into one data of dynamic tag 1; thereafter, other mobile phone numbers can be selected from the event theme library as the current mobile phone number, and the above process can be repeated to determine the data belonging to dynamic tag 1. If the preset dynamic extraction rule of dynamic tag 2 is that the number of visits to URL3 is greater than 5, then the subject of dynamic tag 2 includes mobile phone number, visit URL and Internet time. At this time, any mobile phone number can be selected from the URL subject library as the current mobile phone number, and the visit URL and Internet time corresponding to the current mobile phone number can be extracted from the URL subject library. Then, the number of visits to URL3 by the current mobile phone number is determined according to the Internet time, and it is determined whether the number of visits to URL3 is greater than 5. If so, the current mobile phone number, the visit URL3 and the Internet time corresponding to the visit URL3 (the Internet time at this time includes multiple Internet times of the current mobile phone number) are determined as a data of dynamic tag 2; thereafter, other mobile phone numbers can be selected from the URL subject library as the current mobile phone number, and the above process is repeated to determine the data belonging to dynamic tag 2.

[0067] S250: Generate a composite label library of the target risk scenario based on the label library and the target risk scenario.

[0068] Among them, the target risk scenario may include at least one risk step; the risk step is a specific link or operation in the target risk scenario that may cause risks or problems.

[0069] Specifically, after obtaining the label library, a composite label library of the target risk scenario can be generated based on the label library and the target risk scenario. That is, when the label library includes at least one dynamic label, a composite label library of the target risk scenario can be generated based on multiple dynamic labels in the label library and the target risk scenario.

[0070] Furthermore, when the tag library includes at least one dynamic tag, a composite tag library of the target risk scenario is generated according to the tag library and the target risk scenario, including:

[0071] Sa1. Extract the target dynamic label corresponding to each risk step from the label library.

[0072] Among them, the target dynamic label is a dynamic label used to characterize the risk step, which can reflect the characteristics of the risk step in real time.

[0073] Specifically, any risk step in the target risk scenario can be selected as the current risk step, and then the current risk step can be matched with the dynamic label in the label library to obtain a dynamic label used to characterize the current risk step, and the dynamic label can be determined as the target dynamic label; thereafter, other risk steps in the target risk scenario can be selected as the current risk step, and the above steps can be repeated to obtain the target dynamic labels corresponding to each risk step.

[0074] Sa2. Combine all target dynamic tags according to preset combination rules to obtain a composite tag library.

[0075] The preset combination rule is a pre-set rule that represents the rule for combining various target dynamic tags. It can generate a composite tag library corresponding to the target risk scenario. Users can adjust and set the preset combination rule based on actual usage needs. This embodiment of the present application does not specifically limit this. For example, the preset combination rule can be a combination based on all risk steps in the target risk scenario, or a combination based on some risk steps in the target risk scenario.

[0076] Specifically, after obtaining the target dynamic tag, the pre-set combination rules can be obtained, and all target dynamic tags can be combined according to the preset combination rules to obtain multiple compound tags, and each compound tag can be named for easy subsequent use and understanding; then, multiple compound tags can be combined into a compound tag library.

[0077] Alternatively, you can use lines or a binary tree to represent the relationship between target dynamic tags. Lines can intuitively show the direct relationship between target dynamic tags, while a binary tree can express more complex hierarchical structures and logical relationships.

[0078] Exemplarily, if the preset combination rules of compound tag 1 are risk step 1, risk step 2 and risk step 3, and target dynamic tag 1 corresponds to risk step 1, target dynamic tag 2 corresponds to risk step 2, and target dynamic tag 3 corresponds to risk step 3, then the subject of compound tag 1 is the union of the subjects in target dynamic tag 1, target dynamic tag 2 and target dynamic tag 3. These subjects are associated with the target risk scenarios, and these subjects can be used to identify whether the user's Internet behavior is risky. At this time, according to the preset combination rules, target dynamic tag 1, target dynamic tag 2 and target dynamic tag 3 can be selected and combined from each target dynamic tag, and the intersection of the mobile phone numbers in target dynamic tag 1, target dynamic tag 2 and target dynamic tag 3 can be determined to obtain the mobile phone numbers that involve risk step 1, risk step 2 and risk step 3 at the same time (recorded as risk mobile phone numbers), and the information of each risk mobile phone number in target dynamic tag 1, target dynamic tag 2 and target dynamic tag 3 is combined into a data of compound tag 1, thereby obtaining the data belonging to compound tag 1.

[0079] In an embodiment of the present application, the target dynamic label corresponding to each risk step is extracted from the label library, and all the target dynamic labels are combined according to the preset combination rules to obtain a composite label library, thereby realizing the determination function of the composite label library. Through the risk steps and the preset combination rules, the risk identification accuracy of the composite label can be improved, thereby improving the identification accuracy of the risk number, and the flexibility of the dynamic label enables the composite label to adapt to the needs of different risk scenarios, ensuring the continuity and effectiveness of risk management; at the same time, through the organization and management of the composite label library, it is possible to more conveniently retrieve, analyze and utilize risk-related data and information, thereby improving the accuracy and speed of risk identification, and improving the overall efficiency of risk management.

[0080] Optionally, the tag library also includes at least one static tag, and a static tag includes multiple topics. The static tag is used to characterize the static attributes in the network security event data. At this time, the static tags in the tag library can be determined based on the topic library, that is, the topic library related to the static attributes in the topic library (recorded as a static topic library) can be determined, such as the location topic library (that is, the topic includes the mobile phone number and the location of the mobile phone number), the IMEI topic library (that is, the topic includes the mobile phone number and the IMEI), and according to each preset static extraction rule, the static topic library is respectively extracted for data to obtain the static tags corresponding to the preset static extraction rules, and the static tags are combined into a tag library. Among them, the preset static extraction rules are pre-set static tag extraction rules, which are used to characterize all topics that need to be extracted from the topic library. Static tags can be determined, and users can adjust and set the preset static extraction rules according to actual use needs. The embodiment of the present application does not make specific restrictions on this. For example, the subject of static tag 1 can include mobile phone number and mobile phone number location, and the subject of static tag 2 can include mobile phone number and IMEI.

[0081] Furthermore, when the label library includes at least one dynamic label and at least one static label, generating a composite label library of the target risk scenario according to the label library and the target risk scenario includes:

[0082] Sb1. Extract the target dynamic label corresponding to each risk step from the label library.

[0083] The implementation process and technical principles of Sb1 are the same as those of Sa1. Please refer to the description of the above step Sa1 and will not be repeated here.

[0084] Sb2. Combine all target dynamic tags according to the preset combination rules to obtain a candidate tag library.

[0085] The candidate tag library may include at least one candidate tag, and a candidate tag may include at least one topic associated with a target risk scenario. The candidate tag is used to determine whether the user's online behavior is risky.

[0086] It should be noted that the content of the candidate tag library is the same as that of the compound tag library in Sa2. Therefore, the steps for determining the candidate tag library in Sb2 are the same as those for determining the compound tag library in Sa2. Please refer to the description of step Sa2 above and it will not be repeated here.

[0087] Sb3. Determine a composite tag library based on the candidate tag library and the static tags.

[0088] Specifically, after obtaining the candidate tag library, a composite tag library can be determined based on the candidate tag library and each static tag, that is, the candidate tag is combined with the subject of the static tag, that is, the subject of the static tag is added to each candidate tag. For example, the mobile phone number location is added to each candidate tag, or the IMEI is added to each candidate tag to obtain each composite tag, thereby obtaining a composite tag library. At this time, the composite tags in the composite tag library include static attributes corresponding to the mobile phone number, such as the mobile phone number location or IMEI.

[0089] In an embodiment of the present application, the target dynamic label corresponding to each risk step is extracted from the label library, and all the target dynamic labels are combined according to the preset combination rules to obtain a candidate label library. Then, based on the candidate label library and the static labels, the composite label library is determined, thereby realizing the determination function of the composite label library. Through the combination of static labels and dynamic labels, the accuracy and comprehensiveness of the composite label library are improved, the pertinence and flexibility of risk management are enhanced, and the accuracy of identifying risky users is improved. At the same time, the composite label includes the static attributes of the mobile phone number, thereby improving the efficiency of identifying risky users.

[0090] Optionally, after obtaining the composite tag library, the administrator can select a certain number of mobile phone numbers from the composite tag library and verify whether the users of such mobile phone numbers are risky users, so as to determine the recognition accuracy of the composite tag library; if the recognition accuracy of the composite tag library is low, the recognition accuracy of the composite tag library can be improved by adding subject items of the composite tag.

[0091] S260: Obtain current log data of the target user.

[0092] The target user is the user whose network security risk needs to be determined. The current log data is the behavior record generated by the target user in network activities.

[0093] Specifically, after obtaining the composite tag library, the current log data of the target user can be obtained, that is, the mobile Internet access log data of the target user can be obtained in cooperation with the mobile network operator, thereby obtaining the current log data of the target user.

[0094] S270: Determine whether the target user's online behavior complies with the target risk scenario based on the current log data and the composite tag library of the target risk scenario.

[0095] Specifically, after obtaining the current log data of the target user, the current log data can be matched with the various topics in the composite tag library of the target risk scenario to determine whether the target user's online behavior meets the target risk scenario. If the target user's online behavior meets the target risk scenario, it indicates that the target user's online behavior has a network security risk, and S280 can be executed at this time; otherwise, it indicates that the target user's online behavior does not have a network security risk, and S290 can be executed at this time.

[0096] S280: If the target user's online behavior meets the target risk scenario, the target user is determined to be a risky user.

[0097] Among them, risky users are users whose online behavior poses network security risks.

[0098] Specifically, if the target user's online behavior meets the target risk scenario, the target user can be identified as a risky user, and then a warning message can be generated and displayed for the administrator to review; after that, the administrator can prompt the risky user in the warning message, for example: a phone call or text message can be used to remind the risky user that his or her online behavior is risky, so as to prevent serious losses to the risky user.

[0099] S290: If the target user's online behavior does not conform to the target risk scenario, the target user is determined to be a normal user.

[0100] Among them, normal users are users whose online behavior does not pose any network security risks.

[0101] Specifically, if the target user's online behavior does not conform to the target risk scenario, it indicates that the target user's online behavior does not pose a network security risk, and the target user can be determined as a normal user.

[0102] The technical solution of the embodiment of the present application can obtain Internet log data and match the Internet log data with a preset event rule library to obtain network security event data, thereby realizing the determination function of network security event data. By matching the Internet log data with the preset event rule library, the computing efficiency is improved, the implementation complexity is reduced, and the efficiency and accuracy of network security event data are improved, thereby providing data support for the subsequent generation of a composite label library. Then, a subject library can be determined based on the network security event data, and a label library can be determined based on the subject library, wherein the label library includes at least one dynamic label. Then, a composite label library of the target risk scenario is generated based on the dynamic label in the label library and the target risk scenario, thereby realizing the determination function of the composite label library. Through the label library and the target risk scenario, data related to a specific risk scenario can be quickly located, reducing the workload of manual screening and collating data, thereby improving the efficiency of risk management. Moreover, the composite label library determined based on the label library and the target risk scenario can be used according to the characteristics and needs of the specific risk scenario. Combining and associating relevant tags can make risk management more in line with actual scenarios and realize customized analysis. At the same time, the customized composite tag library can improve the accuracy of the composite tag library in identifying risks for target risk scenarios. Afterwards, the current log data of the target user can be obtained, and based on the current log data and the composite tag library of the target risk scenario, it can be judged whether the target user's Internet behavior meets the target risk scenario. If the target user's Internet behavior meets the target risk scenario, the target user will be identified as a risky user, realizing the risk user identification function. By comparing the current log data and the composite tag library in an automated manner, it is possible to quickly judge whether the user's Internet behavior meets the target risk scenario, and then quickly identify risky users, greatly reducing the workload of manual screening and judgment, and improving the efficiency of risk identification. Moreover, since the composite tag library is generated based on the target risk scenario, different risk judgment criteria can be customized according to different risk scenarios, making risk management more personalized and flexible, so that it can better adapt to the risk needs in different scenarios.

[0103] Figure 3 This is a schematic diagram of a structure of a device for generating a tag library provided in an embodiment of the present application, with reference to Figure 3 , the tag library generation device may include:

[0104] A first determining module 310 is configured to obtain online log data and determine network security event data from the online log data, wherein the network security event data is log data with network security risks, and each network security event data corresponds to a risk type and multiple log elements;

[0105] A second determination module 320 is configured to determine a subject library based on the network security event data, wherein a subject library includes a plurality of subjects, and a subject is a log element or a risk type;

[0106] The generation module 330 is used to generate a composite tag library of the target risk scenario based on the theme library and the preset target risk scenario, wherein the composite tag library includes at least one composite tag, and a composite tag includes at least one theme associated with the target risk scenario. The composite tag is used to determine whether the user's online behavior is risky.

[0107] In one embodiment, the generation module 330 is specifically configured to:

[0108] Determine a tag library based on the topic library; the tag library includes at least one dynamic tag, and a dynamic tag includes multiple topics. The dynamic tag is used to represent dynamic attributes in the risk scenario;

[0109] Based on the label library and the target risk scenario, a composite label library of the target risk scenario is generated.

[0110] In one embodiment, the target risk scenario includes at least one risk step. The generation module 330 generates a composite label library of the target risk scenario based on the label library and the target risk scenario, including:

[0111] Extract the target dynamic label corresponding to each risk step from the label library;

[0112] All target dynamic tags are combined according to the preset combination rules to obtain a composite tag library.

[0113] In one embodiment, the tag library further includes at least one static tag, each of which includes multiple topics and is used to characterize static attributes in network security event data; the target risk scenario includes at least one risk step; the generation module 330 generates a composite tag library for the target risk scenario based on the tag library and the target risk scenario, including:

[0114] Extract the target dynamic label corresponding to each risk step from the label library;

[0115] Combine all target dynamic tags according to the preset combination rules to obtain a candidate tag library;

[0116] Determine the composite tag library based on the candidate tag library and the static tags.

[0117] In one embodiment, the first determining module 310 determines network security event data from the Internet access log data, including:

[0118] Match the Internet log data with the preset event rule library to obtain network security event data.

[0119] In one embodiment, the label library generation device further includes a backfill module, which is specifically configured to:

[0120] Before determining the network security event data from the online log data, determining whether the online log data has information corresponding to a log element, the log element including at least one of a mobile phone number and an Internet Protocol (IP) address;

[0121] If the log element includes a mobile phone number, and the Internet access log data does not have information corresponding to the mobile phone number, then the location information of the mobile phone number is determined according to the preset mobile phone number location correspondence relationship;

[0122] If the log element includes an IP address, and the Internet access log data does not have information corresponding to the IP address, the location information of the IP address is determined according to a preset IP location correspondence relationship.

[0123] In one embodiment, the label library generation device further includes an identification module, which is specifically configured to:

[0124] After generating the composite tag library for the target risk scenario, obtain the current log data of the target user;

[0125] Based on the current log data and the composite tag library of the target risk scenario, determine whether the target user's online behavior meets the target risk scenario.

[0126] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional modules is used as an example for illustration. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the functional modules described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.

[0127] The device for generating a label library provided in this embodiment can be applied to the method for generating a label library provided in any of the above embodiments, and has corresponding functions and beneficial effects.

[0128] Figure 4 It is a structural diagram of an electronic device provided in an embodiment of the present application. Figure 4 A block diagram of an exemplary electronic device 11 suitable for implementing embodiments of the present application is shown. Figure 4 The electronic device 11 shown is only an example and should not bring any limitation to the functions and scope of use of this embodiment.

[0129] like Figure 4As shown, electronic device 11 is implemented as a general-purpose computing electronic device. Components of electronic device 11 may include, but are not limited to, one or more processors or processing units 16, system memory 28, and a bus 18 connecting various system components (including system memory 28 and processing unit 16).

[0130] Bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.

[0131] The electronic device 11 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 11, including volatile and non-volatile media, removable and non-removable media.

[0132] The system memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 11 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 34 may be configured to read and write non-removable, non-volatile magnetic media ( Figure 4 Not shown, often called a "hard drive"). Although Figure 4 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 via one or more data medium interfaces. The system memory 28 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of various embodiments of the present application.

[0133] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 42 generally implement the functions and / or methods of the embodiments described herein.

[0134] The electronic device 11 may also communicate with one or more external devices 14 (e.g., a keyboard, a pointing device, a display 24, etc.), one or more devices that enable a user to interact with the electronic device 11, and / or any device that enables the electronic device 11 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the electronic device 11 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20.

[0135] like Figure 4 As shown, the network adapter 20 communicates with other modules of the electronic device 11 via the bus 18. Figure 4 Not shown, other hardware and / or software modules may be used in conjunction with the electronic device 11, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0136] The processing unit 16 executes various functional applications and page displays by running programs stored in the system memory 28, for example, implementing a tag library generation method provided in this embodiment, which includes:

[0137] Obtaining Internet access log data and determining network security event data from the Internet access log data, wherein the network security event data is log data with network security risks, and one network security event data corresponds to one risk type and multiple log elements;

[0138] Determine a subject library based on network security event data, where a subject library includes several subjects, each of which is a log element or a risk type;

[0139] Based on the theme library and the preset target risk scenario, a composite tag library of the target risk scenario is generated, wherein the composite tag library includes at least one composite tag, and a composite tag includes at least one theme associated with the target risk scenario. The composite tag is used to determine whether the user's online behavior is risky.

[0140] Of course, those skilled in the art will appreciate that the processor may also implement the technical solution of the tag library generation method provided in any embodiment of the present application.

[0141] The present application provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the method for generating a tag library provided in the present application is implemented, for example. The method includes:

[0142] Obtaining Internet access log data and determining network security event data from the Internet access log data, wherein the network security event data is log data with network security risks, and one network security event data corresponds to one risk type and multiple log elements;

[0143] Determine a subject library based on network security event data, where a subject library includes several subjects, each of which is a log element or a risk type;

[0144] Based on the theme library and the preset target risk scenario, a composite tag library of the target risk scenario is generated, wherein the composite tag library includes at least one composite tag, and a composite tag includes at least one theme associated with the target risk scenario. The composite tag is used to determine whether the user's online behavior is risky.

[0145] The computer storage medium of this embodiment can adopt any combination of one or more computer-readable media. Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable storage media can be, for example, but not limited to: electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or components, or any combination thereof. More specific examples (non-exhaustive list) of computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this document, computer-readable storage media can be any tangible medium containing or storing a program that can be used by an instruction execution system, device or device or used in combination with it.

[0146] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0147] Program code embodied on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0148] The computer program code for performing the operations of the present application can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0149] Those skilled in the art will appreciate that the modules or steps of the present application described above can be implemented using a general-purpose computing device. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Alternatively, they can be implemented using program code executable by a computer device, so that they can be stored in a storage device and executed by the computing device, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.

[0150] In addition, the acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0151] Note that the above are only preferred embodiments of the present application and the technical principles employed. Those skilled in the art will understand that the present application is not limited to the specific embodiments herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments and may include more other equivalent embodiments without departing from the inventive concept of the present application, and the scope of the present application is determined by the scope of the appended claims.

Claims

1. A method for generating a tag library, characterized in that: The method comprises: Obtaining online log data, and determining network security event data from the online log data, wherein the network security event data is log data with network security risks, and each network security event data corresponds to a risk type and multiple log elements; Determine a subject library based on the network security event data, wherein one subject library includes a plurality of subjects, and the subjects are the log elements or the risk types; Determining a tag library based on the topic library; the tag library includes at least one dynamic tag, each of which includes multiple topics, and the dynamic tag is used to characterize dynamic attributes in a risk scenario; generating a composite tag library for the target risk scenario based on the tag library and the target risk scenario, wherein the composite tag library includes at least one composite tag, each of which includes at least one topic associated with the target risk scenario, and the composite tag is used to determine whether the user's online behavior is risky; Among them, the target risk scenario includes at least one risk step, and a composite label library of the target risk scenario is generated according to the label library and the target risk scenario, including: extracting the target dynamic label corresponding to each risk step from the label library; combining all the target dynamic labels according to preset combination rules to obtain the composite label library.

2. The method for generating a label library according to claim 1, wherein: The tag library further includes at least one static tag, one static tag includes a plurality of the topics, and the static tag is used to characterize static attributes in the network security event data; Generating a composite label library of the target risk scenario based on the label library and the target risk scenario includes: Extracting the target dynamic label corresponding to each risk step from the label library; Combining all the target dynamic tags according to preset combination rules to obtain a candidate tag library; The composite tag library is determined according to the candidate tag library and the static tags.

3. The method for generating a label library according to claim 1, wherein: Determining network security event data from the Internet access log data includes: The Internet access log data is matched with a preset event rule library to obtain the network security event data.

4. The method for generating a label library according to claim 1, wherein: Before determining the network security event data from the Internet access log data, the method further includes: Determining whether the Internet access log data has information corresponding to the log element, wherein the log element includes at least one of a mobile phone number and an Internet Protocol (IP) address; If the log element includes a mobile phone number, and the Internet access log data does not have information corresponding to the mobile phone number, determining the location information of the mobile phone number according to a preset mobile phone number location correspondence relationship; If the log element includes an IP address, and the Internet access log data does not have information corresponding to the IP address, the location information of the IP address is determined according to a preset IP location correspondence relationship.

5. The method for generating a label library according to claim 1, wherein: After generating the composite tag library of the target risk scenario, the method further includes: Get the current log data of the target user; According to the current log data and the composite tag library of the target risk scenario, it is determined whether the online behavior of the target user meets the target risk scenario.

6. A device for generating a label library, characterized in that: The device comprises: a first determining module, configured to obtain online log data and determine network security event data from the online log data, wherein the network security event data is log data with network security risks, and each network security event data corresponds to a risk type and multiple log elements; A second determining module is configured to determine a subject library based on the network security event data, wherein one subject library includes a plurality of subjects, and the subject is the log element or the risk type; A generation module is configured to determine a tag library based on the topic library; the tag library includes at least one dynamic tag, each of which includes multiple topics, and the dynamic tag is used to characterize dynamic attributes in a risk scenario; and generate a composite tag library for the target risk scenario based on the tag library and the target risk scenario, wherein the composite tag library includes at least one composite tag, each of which includes at least one topic associated with the target risk scenario, and the composite tag is used to determine whether a user's online behavior is risky. Among them, the target risk scenario includes at least one risk step, and the generation module is specifically used to: extract the target dynamic label corresponding to each risk step from the label library; combine all the target dynamic labels according to preset combination rules to obtain the composite label library.

7. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for generating a label library according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for generating a label library according to any one of claims 1 to 5 when executed.

Citation Information

Patent Citations

  • User marking method, user marking system, electronic equipment and storage medium

    CN114662034A

  • Risk management and control method and device, electronic equipment and readable storage medium

    CN116563010A