Network fraud threat identification method and device based on big data analysis
Through the method based on big data analysis, detection assets are generated and multiple detections are carried out, combined with data analysis of the big data platform, the problem of difficulty in identifying and protecting online fraud in the existing technology is solved, and more efficient user protection and loss reduction are achieved.
Patent Information
- Application Number
- CN202411284912.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-13
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-09-13
AI Technical Summary
It is difficult for the existing technology to effectively identify and protect online fraud threats, especially new types of online fraud methods, which makes it difficult for users to identify and protect, causing great losses.
Using a method based on big data analysis, we use the method to generate detection assets and send them to multiple detection probes to determine whether the network assets are suspicious assets. If they are suspicious assets, further matching and analysis will be carried out, and network data will be obtained using the big data platform to determine whether the assets to be identified are Internet fraud assets.
It improves users' ability to identify and protect network assets, reduces the losses caused by network fraud, avoids the process of users needing to judge whether network assets are suspicious by themselves, and improves user experience.
Smart Images

Figure CN118972153B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network fraud threat identification method, device, electronic device and readable storage medium based on big data analysis. Background Art
[0002] In recent years, the fraud methods of criminals have been constantly updated, and the fraud methods have become more and more hidden and confusing. In the early telecommunications fraud process, the fraudsters only relied on calling the victims to commit fraud, and the success rate of the fraud was usually low. With the popularization of the Internet, telecommunications fraud began to combine with the Internet and developed into network fraud. In the process of network fraud, fraudsters jointly implement fraud through calling, phishing, illegal fundraising platforms, PC remote control Trojans and other means, which has increased the success rate of fraud to a certain extent. In recent years, with the rapid development of mobile smart terminals, network fraud has once again completed the evolution of fraud methods, using Android Trojans, illegal fundraising platform APPs, etc. in the fraud process, resulting in ordinary users being unable to identify and protect against the fraudulent websites they visit, resulting in user victims.
[0003] Nowadays, traditional threat detection systems collect network boundary traffic in a mirroring manner, parse the traffic, and restore files; identify threats through technologies such as intrusion rules, threat intelligence matching, and sandbox files, thereby ensuring the security of user systems. The current threat intelligence is a data set that collects, evaluates, and applies related security threats, threat actors, attack exploits, malware, vulnerabilities, and vulnerability indicators. However, many fraudulent websites are websites registered by normal users and do not contain threats such as attack exploits and malware. Therefore, the use of traditional threat detection and threat intelligence technologies cannot detect new network threats - network fraud threats, which causes great losses to users. Summary of the invention
[0004] In view of this, the embodiments of the present application provide a method, device, electronic device and readable storage medium for identifying network fraud threats based on big data analysis, which are convenient for reducing the losses suffered by users due to network fraud.
[0005] In a first aspect, an embodiment of the present application provides a method for identifying network fraud threats based on big data analysis, comprising: generating a detection asset based on network fraud assets in a preset fraud threat asset database; sending the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detection asset; in the case where the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent; wherein each detection probe corresponds to a host; receiving the asset to be identified; matching the asset to be identified with the network fraud assets in the preset fraud threat asset database; if the match is successful, determining that the asset to be identified is a network fraud asset; if the match is unsuccessful, calling the interface of the big data platform to obtain network data corresponding to the asset to be identified from the big data platform; and determining whether the asset to be identified is a network fraud asset based on the network data.
[0006] According to a specific implementation method of an embodiment of the present application, generating detection assets based on network fraud assets in a preset fraud threat asset database includes: generating multiple detection assets based on network fraud assets in a preset fraud threat asset database; wherein, sending the detection assets to multiple detection probes includes: dividing the multiple detection assets into multiple detection asset groups; circulating the multiple detection asset groups among the multiple detection probes in the form of data streams; wherein, circulating the multiple detection asset groups among the multiple detection probes in the form of data streams includes: sending the multiple detection asset groups in the form of data streams to a first detection probe in a plurality of detection probe cycles, and flowing from the first detection probe in sequence to other detection probes among the multiple detection probes except the first detection probe.
[0007] According to a specific implementation method of an embodiment of the present application, the network data includes first information used to indicate that the asset to be identified is a network fraud asset, second information used to indicate that the asset to be identified is not a network fraud asset, attributes of the big data platform, the source of the first information, and the source of the second information; wherein, determining whether the asset to be identified is a network fraud asset based on the network data includes: determining whether the asset to be identified is a network fraud asset based on the number of the first information, the number of the second information, the attributes of the big data platform, the source of the first information, and the source of the second information.
[0008] According to a specific implementation method of an embodiment of the present application, determining whether the asset to be identified is a network fraud asset based on the number of the first information, the number of the second information, the attributes of the big data platform, the source of the first information and the source of the second information includes: judging whether the number of the first information is greater than the number of the second information; if the number of the first information is greater than the number of the second information, determining a credible value corresponding to the first information based on the attributes of the big data platform and the source of the first information; determining whether the asset to be identified is a network fraud asset based on the credible value, the source of the first information and the source of the second information.
[0009] According to a specific implementation method of the embodiment of the present application, determining whether the asset to be identified is a network fraud asset based on the credibility value, the source of the first information and the source of the second information includes: determining the correlation value between the source of the first information and the source of the second information based on the credibility value and the correlation value; determining a selection index corresponding to the first information based on the credibility value and the correlation value; if the selection index is greater than or equal to a preset threshold, determining that the asset to be identified is a network fraud asset; if the selection index is less than the preset threshold, determining that the asset to be identified is not a network fraud asset.
[0010] According to a specific implementation of the embodiment of the present application, the selection index is calculated according to the following formula:
[0011]
[0012] in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of related values.
[0013] According to a specific implementation manner of an embodiment of the present application, before obtaining the asset to be identified, the method further includes: receiving an installation package of an application; determining network assets related to the application based on the installation package of the application, and using the network assets as the asset to be identified.
[0014] According to a specific implementation method of an embodiment of the present application, determining the network assets related to the application based on the installation package of the application includes: simulating the installation of the installation package of the application; monitoring whether the behavior of connecting to the network assets occurs during the simulated installation of the installation package of the application; if so, determining to use the connected network assets as the network assets related to the application.
[0015] According to a specific implementation method of an embodiment of the present application, determining the network assets related to the application based on the installation package of the application also includes: simulating the execution of the simulated application; monitoring whether the behavior of connecting to the network assets occurs during the execution of the simulated application; if so, determining to use the connected network assets as the network assets related to the application.
[0016] According to a specific implementation manner of the embodiment of the present application, the assets to be identified include: mailboxes, domain names, uniform resource locators and / or interconnection protocols between networks.
[0017] In a second aspect, an embodiment of the present application provides a network fraud threat identification device based on big data analysis, including: a generation module, which is used to generate a detection asset based on a network fraud asset in a preset fraud threat asset database; a sending module, which is used to send the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detection asset; in the case where the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent; wherein each detection probe corresponds to a host; a receiving module, which is used to receive the asset to be identified; a matching module, which is used to match the asset to be identified with the network fraud asset in the preset fraud threat asset database; a first determination module, which is used to determine that the asset to be identified is a network fraud asset if the match is successful; a calling module, which is used to call the interface of the big data platform if the match is unsuccessful, so as to obtain network data corresponding to the asset to be identified from the big data platform; a second determination module, which is used to determine whether the asset to be identified is a network fraud asset based on the network data.
[0018] According to a specific implementation method of an embodiment of the present application, the generation module is specifically used to: generate multiple detection assets according to the network fraud assets in a preset fraud threat asset database; wherein, the sending module is specifically used to: divide the multiple detection assets into multiple detection asset groups; circulate the multiple detection asset groups among multiple detection probes in the form of data streams; wherein, the sending module is specifically used to: send the multiple detection asset groups in the form of data streams to the first detection probe in a plurality of detection probe cycles, and flow from the first detection probe in sequence to other detection probes in the plurality of detection probes except the first detection probe.
[0019] According to a specific implementation method of an embodiment of the present application, the network data includes first information used to indicate that the asset to be identified is a network fraud asset, second information used to indicate that the asset to be identified is not a network fraud asset, attributes of the big data platform, the source of the first information, and the source of the second information; wherein, the second determination module includes: a determination submodule, used to determine whether the asset to be identified is a network fraud asset based on the number of the first information, the number of the second information, the attributes of the big data platform, the source of the first information, and the source of the second information.
[0020] According to a specific implementation method of an embodiment of the present application, the determination submodule is specifically used to: determine whether the number of the first information is greater than the number of the second information; if the number of the first information is greater than the number of the second information, determine the trust value corresponding to the first information according to the attributes of the big data platform and the source of the first information; determine whether the asset to be identified is a network fraud asset according to the trust value, the source of the first information and the source of the second information.
[0021] According to a specific implementation method of an embodiment of the present application, the determination submodule is specifically used to: determine the correlation value between the source of the first information and the source of the second information according to the source of the first information and the source of the second information; determine the selection index corresponding to the first information according to the credibility value and the correlation value; if the selection index is greater than or equal to a preset threshold, determine that the asset to be identified is a network fraud asset; if the selection index is less than the preset threshold, determine that the asset to be identified is not a network fraud asset.
[0022] According to a specific implementation of the embodiment of the present application, the determination submodule calculates the selection index according to the following formula:
[0023]
[0024] in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of related values.
[0025] According to a specific implementation method of an embodiment of the present application, the device also includes: a receiving module, used to receive an installation package of an application before the acquisition module acquires the asset to be identified; a third determination module, used to determine the network assets related to the application based on the installation package of the application, and use the network assets as the asset to be identified.
[0026] According to a specific implementation method of an embodiment of the present application, the third determination module is specifically used to: simulate the installation of the installation package of the application; monitor whether the behavior of connecting to the network assets occurs during the simulation of the installation package of the application; if it occurs, determine to use the connected network assets as network assets related to the application.
[0027] According to a specific implementation method of an embodiment of the present application, the third determination module is further specifically used to: simulate the execution of the simulated application; monitor whether the behavior of connecting to network assets occurs during the execution of the simulated application; if so, determine to use the connected network assets as network assets related to the application.
[0028] According to a specific implementation manner of the embodiment of the present application, the assets to be identified include: mailboxes, domain names, uniform resource locators and / or interconnection protocols between networks.
[0029] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; a power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the network fraud threat identification method based on big data analysis described in any of the aforementioned implementation methods.
[0030] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the network fraud threat identification method based on big data analysis as described in any of the aforementioned implementation methods.
[0031] The network fraud threat identification method, device, electronic device and readable storage medium based on big data analysis of this embodiment generate detection assets according to network fraud assets in a preset fraud threat asset database, and send the detection assets to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset according to the detection asset. When the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent. When the asset to be identified is received, the asset to be identified is matched with the network fraud asset in the preset fraud threat asset database. If the match is successful, the asset to be identified is determined to be a network fraud asset. If the match is unsuccessful, the big data is called. The interface of the platform is used to obtain network data corresponding to the asset to be identified from the big data platform, and determine whether the asset to be identified is a network fraud asset based on the network data. In this embodiment, the asset to be identified is first matched with the database. If the match is successful, it can be determined that the asset to be identified is a network fraud asset. If the match is unsuccessful, the network data corresponding to the asset to be identified is obtained from the big data platform, and based on the network data, it is determined whether the asset to be identified is a network fraud asset, thereby providing a method for detecting whether a network asset is a network fraud asset. Therefore, it not only saves the process of users having to judge whether the network asset is a suspicious network asset by themselves, thereby improving the user experience, but also facilitates reducing the losses caused by network fraud to users. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0033] Figure 1 A flowchart of a method for identifying network fraud threats based on big data analysis provided in one embodiment of the present application;
[0034] Figure 2 A flowchart of a method for identifying network fraud threats based on big data analysis provided in a specific embodiment of the present application;
[0035] Figure 3 A schematic diagram of the structure of a network fraud threat identification device based on big data analysis provided in one embodiment of the present application;
[0036] Figure 4 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0037] The embodiments of the present application are described in detail below in conjunction with the accompanying drawings. It should be clear that the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0038] In order to enable those skilled in the art to better understand the technical concept, implementation plan and beneficial effects of the embodiments of the present application, specific embodiments are described in detail below.
[0039] Figure 1 A flowchart of a method for identifying network fraud threats based on big data analysis is provided in an embodiment of the present application. Figure 1 As shown, the network fraud threat identification method based on big data analysis of this embodiment may include:
[0040] S101. Generate detection assets based on network fraud assets in a preset fraud threat asset database.
[0041] A similar network asset can be generated from a network fraud asset in the database as a detection asset, or a network asset can be generated from multiple network fraud assets in the database as a detection asset. Specifically, a network asset can be determined as a detection asset in accordance with a preset method for multiple network fraud assets. If two network fraud assets are network domain names, one of the domain names can be used as a subdomain of the other domain name, thereby forming a new network asset, and the new network asset is used as a detection asset.
[0042] It is understandable that the detected assets may also include confirmed online fraud assets.
[0043] There may be many ways to generate detection assets in this embodiment, and this application does not limit this.
[0044] S102, sending the detected asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detected asset; if the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent.
[0045] Each detection probe corresponds to a host.
[0046] Each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detection asset generated in step S101. When the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent. In this way, the user is saved from the process of judging whether the network asset is a suspicious network asset, thereby improving the user experience and avoiding the problem of missing a network fraud asset and causing losses due to the user's manual judgment of whether the network asset is a suspicious network asset.
[0047] S103: Receive assets to be identified.
[0048] The asset to be identified may be a suspicious network asset that needs to be further verified or identified.
[0049] The assets to be identified may be email addresses, domain names, Uniform Resource Locators (URLs) and / or Internet Protocols (IPs) for interconnecting networks.
[0050] S104: Match the asset to be identified with the network fraud assets in a preset fraud threat asset database.
[0051] The network assets included in the fraud threat asset database are all network fraud assets, which can be crawled from the website through web crawler technology, crawling the real-time updated network fraud clues, and extracting the asset information related to network fraud after secondary data cleaning, such as QQ number, email address, QQ username information, network fraud label time, etc.
[0052] The network fraud assets may also be determined by existing methods of determining network fraud assets and placed into the fraud threat asset database.
[0053] S105. If the match is successful, it is determined that the asset to be identified is a network fraud asset.
[0054] If the asset to be identified is the same as any network fraud asset in the preset fraud threat asset database, then the asset to be identified is a network fraud asset.
[0055] S106: If the match is unsuccessful, call the interface of the big data platform to obtain network data corresponding to the asset to be identified from the big data platform.
[0056] If the asset to be identified does not match any network fraud asset in the preset fraud threat asset database, the corresponding network data can be obtained from the big data platform, specifically, the network data can be obtained by calling the interface of the big data platform. The big data platform can be the existing Internet.
[0057] In some cases, the establishment of a preset fraud threat asset database and network assets obtained through the big data platform can include three data sources: data accumulated in the company's own system, data collected and crawled online, and data purchased from third parties. After intelligent processing and cleaning, these data can be used for subsequent data analysis and mining, and the information collected about assets with network fraud behavior characteristics (email addresses, IP addresses, website addresses, APPs, etc.) can be converted into network fraud threat intelligence, so that it has the ability to detect and identify network fraud behavior labels.
[0058] Threat intelligence can be generally divided into internal threat intelligence and external threat intelligence according to different sources. Internal threat intelligence generally comes from internal security event information in the target system, which can be obtained by purifying relevant information in security devices such as intrusion detection systems (IDS). The sources of external threat intelligence mainly include commercial threat intelligence, that is, commercial threat information sold or shared by security vendors in the form of products, and open source threat intelligence, that is, open source threat intelligence shared on public platforms.
[0059] S107. Determine whether the asset to be identified is a network fraud asset based on network data.
[0060] The network data corresponding to the asset to be identified obtained from the big data platform may be data that directly identifies the asset to be identified as a network fraud asset. For example, the asset to be identified and its corresponding threat label are obtained from the big data platform. The obtained network data may also include both network data that identifies safe and network data that identifies unsafe. These data need to be processed and analyzed by big data to determine whether the asset to be identified is network fraud data.
[0061] In this embodiment, according to the network fraud assets in the preset fraud threat asset database, a detection asset is generated, and the detection asset is sent to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset according to the detection asset. When the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent. When the asset to be identified is received, the asset to be identified is matched with the network fraud assets in the preset fraud threat asset database. If the match is successful, the asset to be identified is determined to be a network fraud asset. If the match is unsuccessful, the interface of the big data platform is called to obtain network data corresponding to the asset to be identified from the big data platform, and determine whether the asset to be identified is a network fraud asset according to the network data. In this embodiment, the asset to be identified is first matched with the database. If the match is successful, it can be determined that the asset to be identified is a network fraud asset. If the match is unsuccessful, the network data corresponding to the asset to be identified is obtained from the big data platform, and determine whether the asset to be identified is a network fraud asset according to the network data. Therefore, it not only saves the process of users having to judge whether the network asset is a suspicious network asset by themselves, thereby improving the user experience, but also facilitates reducing the losses caused by network fraud to users.
[0062] In one embodiment, generating detection assets according to network fraud assets in a preset fraud threat asset database in step S101 may include:
[0063] S101a. Generate multiple detection assets based on the network fraud assets in the preset fraud threat asset database.
[0064] In this embodiment, sending the detected asset to multiple detection probes in step S102 may include:
[0065] S102a. Divide a plurality of detection assets into a plurality of detection asset groups.
[0066] Multiple detection assets may be grouped in pairs to form multiple detection asset groups; or multiple detection assets may be grouped in three to form multiple detection asset groups.
[0067] It is understandable that the number of detection assets in each detection asset group may be the same or different.
[0068] S102b, circulate the multiple detection asset groups among the multiple detection probes in the form of data streams.
[0069] The step S102b of circulating the plurality of detection asset groups in the form of data streams among the plurality of detection probes may include:
[0070] A1. Send multiple detection asset groups in the form of data streams to a first detection probe in a plurality of detection probe cycles, and sequentially flow from the first detection probe to other detection probes in the plurality of detection probes except the first detection probe.
[0071] If there are three detection probes, namely A, B and C, multiple detection asset groups are sent to detection probe A in the form of data streams, and multiple detection asset groups flow from detection probe A to detection probe B in sequence, and then flow to detection probe C after passing through detection probe B.
[0072] After flowing through detection probe C, it flows to detection probe A and detection probe B.
[0073] If a new detection asset is generated, a new detection asset group can be generated, added to the data stream, and circulated among multiple detection probes with other detection asset groups.
[0074] In some examples, the network data may include first information indicating that the asset to be identified is a network fraud asset, second information indicating that the asset to be identified is not a network fraud asset, attributes of the big data platform, the source of the first information, and the source of the second information.
[0075] For example, the big data platform contains information indicating that mailbox A is an online fraud asset, namely the first information, and the big data platform contains information indicating that mailbox A is not an online fraud asset, namely the second information, and the first information may be a threat label, such as "online fraud threat label", and the second information may be a "safety label". The sources of the first information and the second information may be the annotations of netizens or other websites.
[0076] The attributes of a big data platform may include security level, platform type, platform establishment time, etc.
[0077] In this embodiment, determining whether the asset to be identified is a network fraud asset according to the network data in step S107 may include:
[0078] S107a. Determine whether the asset to be identified is a network fraud asset based on the number of first information, the number of second information, the attributes of the big data platform, the source of the first information, and the source of the second information.
[0079] In a specific example, determining whether the asset to be identified is a network fraud asset according to the number of first information, the number of second information, the attribute of the big data platform, the source of the first information, and the source of the second information in step S107a may include:
[0080] B1. Determine whether the number of the first information is greater than the number of the second information.
[0081] B2. If the number of the first information is greater than the number of the second information, determine the trust value corresponding to the first information according to the attributes of the big data platform and the source of the first information.
[0082] If the number of the first information is greater than the number of the second information, in this embodiment, the credibility value corresponding to the first information is further determined.
[0083] The trust value corresponding to the first information can be determined through the correspondence between the attributes of the big data platform, the information source and the trust value.
[0084] B3. Determine whether the asset to be identified is a network fraud asset based on the credibility value, the source of the first information, and the source of the second information.
[0085] In this embodiment, when it is determined that the number of first information is greater than the number of second information, the credibility value corresponding to the first information is determined, and then it is further determined whether the asset to be identified is a network fraud asset, so that the obtained result is more accurate.
[0086] In one example, determining whether the asset to be identified is a network fraud asset based on the trust value, the source of the first information, and the source of the second information in step B3 may include:
[0087] B31. Determine a correlation value between the source of the first information and the source of the second information according to the source of the first information and the source of the second information.
[0088] The correlation value between the source of the first information and the source of the second information may be determined according to the correspondence between the first information source, the second information source and the correlation value.
[0089] B32. Determine a selection index corresponding to the first information based on the credibility value and the correlation value.
[0090] The larger the credibility value and the correlation value are, the larger the selection index corresponding to the first information is.
[0091] B33. If the selected index is greater than or equal to the preset threshold, the asset to be identified is determined to be a network fraud asset.
[0092] If the selected index is greater than a preset threshold, the asset to be identified is determined to be a network fraud asset corresponding to the first information.
[0093] B34. If the selected index is less than the preset threshold, it is determined that the asset to be identified is not an online fraud asset.
[0094] If the selected index is less than a preset threshold, the asset to be identified is determined to be a network fraud asset corresponding to the second information.
[0095] In a specific example, the selection index can be calculated according to the following formula:
[0096]
[0097] in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of related values.
[0098] The first information can be obtained from multiple sources, each of which corresponds to a trust value, such as the trust value of website A is a, and the trust value of website B is b.
[0099] If the first information comes from websites A and B, and the attributes of website A include two, and the attributes of website B include one, then =3, =2.
[0100] The first information comes from three websites, namely A, B and C, and the second information comes from two websites, namely D and E. The correlation value between website A and website D is a, the correlation value between website A and website E is b, the correlation value between website B and website D is c, the correlation value between website B and website E is d, and website C is not correlated with website D or E. Then the number of correlation values is is 4.
[0101] The weight coefficients in the above embodiments can be determined by the corresponding relationship between each value and the weight coefficient.
[0102] To improve the security of users using the application, in some examples, before obtaining the asset to be identified, the method of this embodiment may further include:
[0103] S108: Receive the installation package of the application.
[0104] The application may be an application used on an electronic product. In some examples, the application is an application on a mobile terminal such as a mobile phone. Correspondingly, the installation package of the application is an apk installation package.
[0105] S109: Determine network assets related to the application program according to the installation package of the application program, and use the network assets as assets to be identified.
[0106] The network assets associated with the application may include the network assets connected during the installation of the application and / or the network assets that the application needs to connect to in order to implement corresponding functions during use.
[0107] In one embodiment, determining the network assets related to the application according to the installation package of the application in step S109 may include:
[0108] S109a, simulating the installation of an installation package of an application.
[0109] S109b: monitoring whether there is any behavior of connecting to network assets during the process of simulating the installation of the installation package of the application.
[0110] S109c: If so, determine to use the connected network asset as a network asset related to the application.
[0111] After receiving the installation package of the application, in order to obtain the network assets corresponding to the application, the network assets connected to the application during the application installation process can be obtained by simulating the installation of the application installation package, thereby determining the network assets related to the application.
[0112] In one embodiment, determining the network assets related to the application according to the installation package of the application in step S109 may also include:
[0113] S109d, simulate and execute the simulation application.
[0114] S109e: monitor whether there is any behavior of connecting to network assets during the execution of the simulated application.
[0115] S109f. If so, determine to use the connected network asset as a network asset related to the application.
[0116] In order to obtain the network assets corresponding to the application, the network assets to which the application is connected during the execution of the application can also be obtained by simulating the execution of the application, thereby determining the network assets related to the application.
[0117] From big data, we can form a knowledge base of email addresses, domain names, URLs, IP addresses, APPs, etc. that have network fraud behaviors. When users encounter suspicious email addresses, domain names, URLs, IP addresses, APPs, etc., they can query and check on the threat intelligence platform that can search for network fraud and identify network fraud behaviors.
[0118] There are various forms of online fraud, such as sending phishing links through SMS, email, chat tools and other channels to implement phishing fraud, impersonating customer service, leaders, public security, procuratorial and judicial organs, etc. to attract traffic through phone calls, and promoting APPs through transmission, etc. In some specific examples, after receiving information suspected of fraudulent behavior, the application phone number, suspicious link, and APP of the embodiment of the present application are used for retrieval and analysis. In the fraud threat asset database, the information to be retrieved is matched with the big data information related to online fraud, and clues related to online fraud are output, so as to help users quickly analyze and judge online fraud threats, identify online fraud risks, and thus reduce losses caused by online fraud.
[0119] For example, when a user receives a suspicious email sent from a forged email address during daily office work, by extracting the relevant suspicious link address information from the email content and searching it in a threat intelligence platform with network fraud detection capabilities, the "network fraud behavior label" can quickly help the user identify whether the content of the received email contains network fraud behavior and prevent the user from being defrauded.
[0120] The solution of the present application is described in detail below with a specific embodiment.
[0121] See also Figure 2 The network fraud threat identification method based on big data analysis of this embodiment may include:
[0122] The threat intelligence platform (the platform that implements this application solution) calls the interface (API) to obtain open source intelligence. The sources of open source intelligence include technical blogs, community forums, social media and third-party open source intelligence, and the query results can be returned from the open source intelligence.
[0123] The threat intelligence platform can also obtain data from the enterprise security center intelligence platform through web crawlers.
[0124] For mobile application installation packages apk, users can upload the installation packages to the threat intelligence platform and the results will be returned to the users.
[0125] The network fraud threat labels generated by the threat intelligence platform can include network assets, social accounts,
[0126] Application and annotation times.
[0127] The network fraud threat identification method based on big data analysis of the present application generates a detection asset according to the network fraud assets in the preset fraud threat asset database, and sends the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset according to the detection asset; in the case of determining that the network asset is a suspicious asset, the network asset is determined as an asset to be identified and sent, and the asset to be identified is matched with the network fraud assets in the preset fraud threat asset database. If the match is successful, the asset to be identified is determined to be a network fraud asset. If the match is unsuccessful, the interface of the big data platform is called to obtain network data corresponding to the asset to be identified from the big data platform, and determine whether the asset to be identified is a network fraud asset according to the network data. In this embodiment, the asset to be identified is first matched with the database. If the match is successful, it can be determined that the asset to be identified is a network fraud asset. If the match is unsuccessful, the network data corresponding to the asset to be identified is obtained from the big data platform, and determine whether the asset to be identified is a network fraud asset according to the network data, thereby providing a method for detecting whether a network asset is a network fraud asset, which not only saves the process of users having to judge whether the network asset is a suspicious network asset by themselves, improves the user experience, but also facilitates reducing the user from suffering from network fraud. The losses caused by this can be specifically that multiple detection asset groups can be sent in the form of data streams to the first detection probe in the multiple detection probe loops, and the data streams can flow from the first detection probe to the other detection probes except the first detection probe in the multiple detection probes in sequence. When determining whether the asset to be identified is a network fraud asset, it is determined whether the number of the first information is greater than the number of the second information. If the number of the first information is greater than the number of the second information, the credible value corresponding to the first information is determined according to the attributes of the big data platform and the source of the first information. According to the credible value, the source of the first information and the source of the second information, it is determined whether the asset to be identified is a network fraud asset. Furthermore, according to The source of the first information and the source of the second information are used to determine the correlation value between the source of the first information and the source of the second information. According to the credible value and the correlation value, a selection index corresponding to the first information is determined. If the selection index is greater than or equal to a preset threshold, the asset to be identified is determined to be a network fraud asset. If the selection index is less than the preset threshold, the asset to be identified is not a network fraud asset. For applications, in order to improve the security of users using applications, the corresponding network assets are determined by simulating the installation of the application's installation package or simulating the execution of the application. The network asset is further identified as an asset to be identified using the solution of the present application to determine whether it is a network fraud asset.
[0128] Figure 3 A schematic diagram of the structure of a network fraud threat identification device based on big data analysis provided in an embodiment of the present application is shown in FIG. Figure 3As shown, the network fraud threat identification device based on big data analysis of this embodiment includes: a generating module 11, which is used to generate a detection asset according to the network fraud assets in the preset fraud threat asset database; a sending module 12, which is used to send the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset according to the detection asset; in the case where the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent; wherein each detection probe corresponds to a host; a receiving module 13, which is used to receive the asset to be identified; a matching module 14, which is used to match the asset to be identified with the network fraud asset in the preset fraud threat asset database; a first determining module 15, which is used to determine that the asset to be identified is a network fraud asset if the match is successful; a calling module 16, which is used to call the interface of the big data platform if the match is unsuccessful, so as to obtain the network data corresponding to the asset to be identified from the big data platform; a second determining module 17, which is used to determine whether the asset to be identified is a network fraud asset according to the network data.
[0129] The device of this embodiment can be used to perform Figure 1 The technical solution of the method embodiment shown has similar implementation principles and technical effects, which will not be repeated here.
[0130] The device of this embodiment generates a detection asset based on the network fraud assets in the preset fraud threat asset database, and sends the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detection asset. When the network asset is determined to be a suspicious asset, the network asset is determined as an asset to be identified and sent. When the asset to be identified is received, the asset to be identified is matched with the network fraud asset in the preset fraud threat asset database. If the match is successful, the asset to be identified is determined to be a network fraud asset. If the match is unsuccessful, the interface of the big data platform is called to obtain the asset from the big data platform. The network data corresponding to the asset to be identified is used to determine whether the asset to be identified is a network fraud asset based on the network data. In this embodiment, the asset to be identified is first matched with the database. If the match is successful, it can be determined that the asset to be identified is a network fraud asset. If the match is unsuccessful, the network data corresponding to the asset to be identified is obtained from the big data platform, and based on the network data, it is determined whether the asset to be identified is a network fraud asset, thereby providing a method for detecting whether a network asset is a network fraud asset. As a result, it not only saves the user from having to judge whether the network asset is a suspicious network asset, thereby improving the user experience, but also helps to reduce the loss caused by network fraud to the user.
[0131] Optionally, the generation module is specifically used to: generate multiple detection assets according to the network fraud assets in the preset fraud threat asset database; wherein the sending module is specifically used to: divide the multiple detection assets into multiple detection asset groups; and circulate the multiple detection asset groups among multiple detection probes in the form of data streams; wherein the sending module is specifically used to: send the multiple detection asset groups in the form of data streams to the first detection probe in the multiple detection probe cycle, and flow from the first detection probe to other detection probes in the multiple detection probes except the first detection probe in sequence.
[0132] Optionally, the network data includes first information used to indicate that the asset to be identified is a network fraud asset, second information used to indicate that the asset to be identified is not a network fraud asset, attributes of the big data platform, the source of the first information, and the source of the second information; wherein, the second determination module includes: a determination submodule used to determine whether the asset to be identified is a network fraud asset based on the number of the first information, the number of the second information, the attributes of the big data platform, the source of the first information, and the source of the second information.
[0133] Optionally, the determination submodule is specifically used to: determine whether the number of the first information is greater than the number of the second information; if the number of the first information is greater than the number of the second information, determine the trust value corresponding to the first information according to the attributes of the big data platform and the source of the first information; determine whether the asset to be identified is a network fraud asset according to the trust value, the source of the first information and the source of the second information.
[0134] Optionally, the determination submodule is specifically used to: determine the correlation value between the source of the first information and the source of the second information based on the source of the first information and the source of the second information; determine the selection index corresponding to the first information based on the credibility value and the correlation value; if the selection index is greater than or equal to a preset threshold, determine that the asset to be identified is a network fraud asset; if the selection index is less than the preset threshold, determine that the asset to be identified is not a network fraud asset.
[0135] Optionally, the determination submodule calculates the selection index according to the following formula:
[0136]
[0137] in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of related values.
[0138] Optionally, the device also includes: a receiving module, used to receive an installation package of an application before the acquisition module acquires the asset to be identified; a third determination module, used to determine network assets related to the application based on the installation package of the application, and use the network assets as the asset to be identified.
[0139] Optionally, the third determination module is specifically used to: simulate the installation of the installation package of the application; monitor whether the behavior of connecting to the network assets occurs during the simulation of the installation package of the application; if so, determine to use the connected network assets as network assets related to the application.
[0140] Optionally, the third determination module is further specifically used to: simulate the execution of the simulated application; monitor whether the behavior of connecting to network assets occurs during the execution of the simulated application; if so, determine to use the connected network assets as network assets related to the application.
[0141] Optionally, the assets to be identified include: mailboxes, domain names, uniform resource locators and / or interconnection protocols between networks.
[0142] The device of the above embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar and will not be repeated here.
[0143] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 4As shown, it may include: a shell 61, a processor 62, a memory 63, a circuit board 64 and a power supply circuit 65, wherein the circuit board 64 is arranged inside the space enclosed by the shell 61, and the processor 62 and the memory 63 are arranged on the circuit board 64; the power supply circuit 65 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 63 is used to store executable program codes; the processor 62 runs the program corresponding to the executable program code by reading the executable program code stored in the memory 63, and is used to execute any one of the network fraud threat identification methods based on big data analysis provided in the aforementioned embodiments, and therefore can also achieve corresponding beneficial technical effects, which have been described in detail in the previous text and will not be repeated here.
[0144] The above electronic devices exist in many forms, including but not limited to:
[0145] (1) Mobile communication devices: These devices are characterized by their mobile communication functions and their main purpose is to provide voice and data communications. These terminals include: smart phones (such as iPhone), multimedia phones, feature phones, and low-end phones.
[0146] (2) Ultra-mobile personal computer devices: These devices fall into the category of personal computers and have computing and processing capabilities, and generally also have mobile Internet access features. These terminals include: PDAs, MIDs, and UMPC devices, such as the iPad.
[0147] (3) Portable entertainment devices: These devices can display and play multimedia content. They include audio and video players (such as iPods), handheld game consoles, e-books, as well as smart toys and portable car navigation devices.
[0148] (4) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general-purpose computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0149] (5) Other electronic devices with data interaction functions.
[0150] Correspondingly, an embodiment of the present application also provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement any one of the network fraud threat identification methods based on big data analysis provided in the aforementioned embodiments, thereby also being able to achieve the corresponding technical effects, which have been described in detail in the previous text and will not be repeated here.
[0151] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0152] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0153] In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0154] For the convenience of description, the above device is described by dividing the functions into various units / modules. Of course, when implementing the present application, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.
[0155] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0156] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
Claims
1. A method for identifying network fraud threats based on big data analysis, characterized in that: include: Generate detection assets based on network fraud assets in a preset fraud threat asset database; Sending the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset based on the detection asset; In the case where the network asset is determined to be a suspicious asset, the network asset is determined to be an asset to be identified and sent; wherein each detection probe corresponds to a host; receiving the asset to be identified; or, Receive an installation package of an application; determine network assets related to the application according to the installation package of the application, and use the network assets as assets to be identified; Matching the asset to be identified with the network fraud assets in a preset fraud threat asset database; If the match is successful, it is determined that the asset to be identified is a network fraud asset; If the match is unsuccessful, calling the interface of the big data platform to obtain network data corresponding to the asset to be identified from the big data platform; Determine whether the number of the first information is greater than the number of the second information; wherein the first information is information in the network data used to indicate that the asset to be identified is a network fraud asset, and the second information is information in the network data used to indicate that the asset to be identified is not a network fraud asset; If the number of the first information is greater than the number of the second information, determining a trustworthy value corresponding to the first information according to the property of the big data platform and the source of the first information; Determining a correlation value between the source of the first information and the source of the second information according to the source of the first information and the source of the second information; According to the credibility value and the correlation value, a selection index corresponding to the first information is determined; wherein the selection index is calculated according to the following formula: ; in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of relevant values; If the selection index is greater than or equal to a preset threshold, the asset to be identified is determined to be a network fraud asset; If the selection index is less than the preset threshold, it is determined that the asset to be identified is not an online fraud asset.
2. The method according to claim 1, characterized in that The generating of detection assets according to the network fraud assets in the preset fraud threat asset database includes: Generate multiple detection assets based on network fraud assets in a preset fraud threat asset database; The sending of the detection asset to a plurality of detection probes includes: Dividing the plurality of detection assets into a plurality of detection asset groups; Circulating the plurality of detection asset groups among the plurality of detection probes in the form of data streams; Among them, the multiple detection asset groups are circulated among multiple detection probes in the form of data streams, including: sending the multiple detection asset groups in the form of data streams to the first detection probe in the multiple detection probe cycle, and flowing from the first detection probe to other detection probes in the multiple detection probes except the first detection probe in sequence.
3. The method according to claim 1, characterized in that The determining, according to the installation package of the application, network assets related to the application includes: Simulate installation of the installation package of the application; Monitoring whether there is any behavior of connecting to network assets during the process of simulating the installation of the installation package of the application; If so, the connected web asset is determined to be a web asset associated with the application.
4. The method according to claim 3, characterized in that The determining of network assets related to the application program according to the installation package of the application program further includes: simulating execution of the application; Monitor whether any actions of connecting to network assets occur during the execution of the application; If so, the connected web asset is determined to be a web asset associated with the application.
5. The method according to claim 1, characterized in that: The assets to be identified include: mailboxes, domain names, uniform resource locators and / or interconnection protocols between networks.
6. A network fraud threat identification device based on big data analysis, characterized in that: include: A generation module, used to generate detection assets based on network fraud assets in a preset fraud threat asset database; A sending module, used for sending the detection asset to multiple detection probes, so that each detection probe determines whether the network asset on the host corresponding to the detection probe is a suspicious asset according to the detection asset; In the case where the network asset is determined to be a suspicious asset, the network asset is determined to be an asset to be identified and sent; wherein each detection probe corresponds to a host; a first receiving module is used to receive the asset to be identified; or, The second receiving module is used to receive an installation package of an application; the first determining module is used to determine network assets related to the application according to the installation package of the application, and use the network assets as assets to be identified; A matching module, used for matching the asset to be identified with the network fraud assets in a preset fraud threat asset database; A first determination module, configured to determine that the asset to be identified is a network fraud asset if the match is successful; A calling module, configured to call an interface of a big data platform if the match is unsuccessful, so as to obtain network data corresponding to the asset to be identified from the big data platform; A judgment module, used to judge whether the number of first information is greater than the number of second information; wherein the first information is information in the network data used to indicate that the asset to be identified is a network fraud asset, and the second information is information in the network data used to indicate that the asset to be identified is not a network fraud asset; a second determination module, configured to determine a credible value corresponding to the first information according to an attribute of the big data platform and a source of the first information if the number of the first information is greater than the number of the second information; a third determining module, configured to determine a correlation value between the source of the first information and the source of the second information according to the source of the first information and the source of the second information; A fourth determination module is used to determine a selection index corresponding to the first information according to the credibility value and the correlation value; wherein the fourth determination module is specifically used to calculate the selection index according to the following formula: ; in, is the selected index, The source of the first information The credible value of an attribute, is the total number of attributes of the source corresponding to the first information, For the first information The trust value of the source, is the total number of sources of the first information, The source of the first information The weight coefficient of the credible value of each attribute, For the first information The weight coefficient of the credibility value of each source, is the weight coefficient of the average credible value of the attribute, is the weight coefficient of the average credibility value of the source corresponding to the first information, The source of the first information is associated with the source of the second information. The relevant values of the sources, is the weight coefficient of the credible value, is the weight coefficient of the correlation value between the source of the first information and the source of the second information, is the total number of relevant values; A fifth determination module, configured to determine that the asset to be identified is a network fraud asset if the selection index is greater than or equal to a preset threshold; The sixth determination module is used to determine that the asset to be identified is not an online fraud asset if the selection index is less than the preset threshold.
7. An electronic device, characterized in that: The electronic device comprises: a shell, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the shell, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs the program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the network fraud threat identification method based on big data analysis as described in any one of the preceding claims 1-5.
Citation Information
Patent Citations
Security threat processing method of portable mobile terminal
CN103632097A
System and method for preventing phone and short message frauds
CN103731832A