Methods, devices, equipment, media, and program products for identifying abnormal access objects.

By analyzing users' basic attributes, online behavior, and location behavior characteristics, and utilizing susceptible population classification models and registration queries, potential fraudulent websites and applications can be identified, solving the problem of insufficient identification in existing technologies and improving the identification rate.

CN119210791BActive Publication Date: 2025-10-31CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411217993.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-02
Publication Date
2025-10-31
Estimated Expiration
2044-09-02

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately identify potential fraudulent websites and applications, resulting in insufficient proactive or targeted coverage.

Method used

By acquiring users' basic attribute characteristics, online behavior characteristics, and location behavior characteristics, and using a susceptible population classification model to analyze user groups, combined with a list of access objects, screening and registration queries are conducted to identify potential fraudulent websites and applications.

Benefits of technology

It improves the identification rate of fraudulent websites and applications, and can effectively identify potential fraudulent websites and applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210791B_ABST
    Figure CN119210791B_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, device, medium, and program product for identifying abnormal access objects, belonging to the field of object identification. The method for identifying abnormal access objects includes: obtaining the basic attribute characteristics, internet behavior characteristics, and location behavior characteristics of each user in a first user set; inputting the basic attribute characteristics, internet behavior characteristics, and location behavior characteristics of each user into a susceptible population classification model to determine susceptible and non-susceptible populations in the first user set; obtaining a first list of access objects accessed by susceptible populations and a second list of access objects accessed by non-susceptible populations; and based on the first and second access object lists, determining target abnormal access objects, including fraudulent websites and / or fraudulent applications. This method can effectively identify potential fraudulent websites and / or fraudulent applications, improving the identification rate of fraudulent websites and / or fraudulent applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of object recognition, and in particular relates to a method, apparatus, device, medium and program product for identifying abnormal access objects. Background Technology

[0002] With the widespread use of smartphones and broadband networks, various illegal applications and websites have become important tools for fraud. Online fraud has shown a trend towards diversification in methods, expansion of monetary amounts involved, and a wider range of victims, seriously impacting the property security of the public.

[0003] To identify and combat various fraudulent websites and applications, existing technical solutions and methods primarily target the websites and applications themselves, performing various related identifications for judgment. These include: 1) domain name identification; 2) domain name registration checks; 3) domain name index searches; 4) whether sensitive information such as bank card information is required; 5) application risk checks by the National Anti-Fraud Center; 6) extracting fingerprint features from suspected websites and comparing them with official fingerprint features; and 7) using deep semantic understanding to identify websites or applications, etc. However, identifying fraudulent websites and applications based solely on their nature has limitations in terms of proactiveness or targeted coverage, and cannot accurately identify potential fraudulent websites and applications. Summary of the Invention

[0004] This application provides a method, apparatus, device, medium, and program product for identifying abnormal access objects, which can identify potential fraudulent websites and / or fraudulent applications, thereby improving the identification rate of fraudulent websites and / or fraudulent applications.

[0005] In a first aspect, embodiments of this application provide a method for identifying abnormal access objects, the method comprising:

[0006] Obtain the basic attribute characteristics, online behavior characteristics, and location behavior characteristics of each user in the first user set;

[0007] The basic attribute features, online behavior features, and location behavior features of each user are input into the susceptible population classification model to determine the susceptible and non-susceptible populations in the first user set. The susceptible population classification model is trained based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded.

[0008] Get the first list of access objects accessed by vulnerable groups and the second list of access objects accessed by non-vulnerable groups;

[0009] Based on the first access object list and the second access object list, target abnormal access objects are identified, including fraudulent websites and / or fraudulent applications.

[0010] In some embodiments of this application, the training methods for the susceptible population classification model include:

[0011] Extract the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T.

[0012] A training dataset containing positive and negative samples is generated based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T.

[0013] A pre-defined classification model is trained based on the training dataset to obtain a classification model for susceptible populations.

[0014] In some embodiments of this application, the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T, are extracted, including:

[0015] Retrieves a collection of abnormal access objects, which includes multiple abnormal access objects;

[0016] Get the second set of users who have accessed the abnormal access objects in the abnormal access object set;

[0017] Using a deep packet inspection server, the O-domain logs are parsed to extract the location status sequence, action status sequence, and abnormal object status sequence of each defrauded user in the second user set within their respective target time period. The O-domain logs include network data.

[0018] Obtain the third user set within the longest target time period T from the deep message detection server, and use the deep message detection server to parse the O domain logs to extract the location state sequence, action state sequence, and normal object state sequence of each non-deceived user within the third user set within the longest target time period T.

[0019] The online behavior characteristics of each defrauded user are determined based on the action state sequence and abnormal object state sequence of each defrauded user. The location behavior characteristics of each defrauded user are determined based on the location state sequence of each defrauded user. The online behavior characteristics of each non-defrauded user are determined based on the action state sequence and normal object state sequence of each non-defrauded user. The location behavior characteristics of each non-defrauded user are determined based on the location state sequence of each non-defrauded user.

[0020] Using a deep message inspection server, the B-domain data is parsed to extract the basic attribute features of each deceived user in the second user set and the basic attribute features of each undeceived user in the third user set. The B-domain data includes user data.

[0021] In some embodiments of this application, a training dataset containing positive and negative samples is generated based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T. This dataset includes:

[0022] The basic attribute features, online behavior features, and location behavior features are normalized according to the longest target time period T to form M-dimensional features, where M is a positive integer.

[0023] Based on a preset ratio of positive to negative samples, a training dataset with a total sample data size of T*M is constructed.

[0024] In some embodiments of this application, determining the target abnormal access object based on a first access object list and a second access object list includes:

[0025] Based on the first list of accessed objects and the second list of accessed objects, a third list of accessed objects that meets the preset conditions is obtained.

[0026] Perform a record check on each access object in the third access object list and determine the query results for each access object;

[0027] Access objects whose query results show that they have failed the filing verification are identified as target abnormal access objects.

[0028] In some embodiments of this application, a third list of access objects that meets preset conditions is obtained by filtering based on a first list of access objects and a second list of access objects, including:

[0029] The intersection of the first and second access object lists is filtered out from the first access object list to obtain the third access object list;

[0030] or,

[0031] Sort the accessed objects in the second accessed object list according to the number of accesses from most to least, to obtain a sorted second accessed object list; filter out the accessed objects in the first accessed object list that rank at the top of the sorted second accessed object list by a predetermined proportion, to obtain a third accessed object list.

[0032] In some embodiments of this application, after identifying access objects whose query results show they have failed the filing query as target abnormal access objects, the method further includes:

[0033] Add the target abnormal access object to the abnormal access object collection.

[0034] Secondly, embodiments of this application provide an identification device for abnormal access objects, the device comprising:

[0035] The first acquisition module is used to acquire the basic attribute characteristics, internet behavior characteristics, and location behavior characteristics of each user in the first user set.

[0036] The first determination module is used to input the basic attribute features, online behavior features, and location behavior features of each user into the susceptible population classification model to determine the susceptible and non-susceptible populations in the first user set. The susceptible population classification model is trained based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded.

[0037] The second acquisition module is used to acquire the first access object list accessed by the susceptible population and the second access object list accessed by the non-susceptible population.

[0038] The second determination module is used to determine the target abnormal access object based on the first access object list and the second access object list. The target abnormal access object includes fraudulent websites and / or fraudulent applications.

[0039] Thirdly, embodiments of this application provide an identification device for abnormal access objects, the device including: a processor and a memory storing computer program instructions;

[0040] The processor implements the method for identifying abnormally accessed objects in any of the above embodiments when executing computer program instructions.

[0041] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the abnormal access object identification method of any of the above embodiments.

[0042] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the abnormal access object identification method of any of the above embodiments.

[0043] According to the methods, apparatus, devices, media, and program products for identifying abnormal access targets provided in the embodiments of this application, by analyzing the basic attribute characteristics, online behavior characteristics, and location behavior characteristics of users through a susceptible population classification model, it is possible to determine whether a user is a susceptible or non-susceptible population. By using a first list of access targets accessed by susceptible populations and a second list of access targets accessed by non-susceptible populations, target abnormal access targets can be identified. These target abnormal access targets include fraudulent websites and / or fraudulent applications. Thus, by analyzing the access patterns of susceptible populations to fraudulent websites and / or fraudulent applications, potential fraudulent websites and / or fraudulent applications can be effectively identified, improving the identification rate of fraudulent websites and / or fraudulent applications. Attached Figure Description

[0044] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0045] Figure 1 This is a schematic diagram of the structure of the abnormal access object identification system provided in the embodiments of this application;

[0046] Figure 2 A flowchart illustrating a method for identifying abnormal access objects provided in an embodiment of this application;

[0047] Figure 3 A flowchart illustrating another method for identifying abnormal access objects provided in an embodiment of this application;

[0048] Figure 4 A flowchart illustrating another method for identifying abnormal access objects provided in this application embodiment;

[0049] Figure 5 A schematic diagram of the structure of the abnormal access object identification device provided in the embodiments of this application;

[0050] Figure 6 This is a schematic diagram of the structure of the device for identifying abnormal access objects provided in an embodiment of this application. Detailed Implementation

[0051] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0052] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0053] With the widespread use of smartphones and broadband networks, various illegal applications and websites have become important tools for fraud. Online fraud has shown a trend towards diversification in methods, expansion of monetary amounts involved, and a wider range of victims, seriously impacting the property security of the public.

[0054] To identify and combat various fraudulent websites and applications, existing technical solutions and methods focus on the websites and applications themselves, performing various related identifications for judgment, specifically including:

[0055] 1) Identification through domain name; 2) Domain name registration query; 3) Domain name search; 4) Whether sensitive information such as bank card information is required; 5) Risk query of applications from the National Anti-Fraud Center; 6) Extracting fingerprint features of suspected websites and comparing them with official fingerprint features; 7) Identifying websites or applications through deep semantic understanding, etc. However, identifying fraudulent websites and applications based on the websites and applications themselves has limitations in terms of initiative or targeted coverage, and cannot accurately identify potential fraudulent websites and applications.

[0056] To address the aforementioned issues, embodiments of this application provide a method, apparatus, device, medium, and program product for identifying abnormal access objects, which can identify potential fraudulent websites and / or fraudulent applications, thereby improving the identification rate of fraudulent websites and / or fraudulent applications.

[0057] Before introducing the method, apparatus, device, medium, and program product for identifying abnormal access objects in this application, let me first introduce a system for identifying abnormal access objects. Figure 1 This is a schematic diagram of the structure of the abnormal access object identification system provided in this application embodiment. The abnormal access object identification system includes: an abnormal access object directory unit 101, a deep message detection server 102, a feature constructor 103, an O-domain data unit 104, a B-domain data unit 105, a classification model server 106, an access object data unit 107, a dashboard comparison server 108, a suspected abnormal access object data unit 109, and a filing verification query server 110. The abnormal access object directory unit 101 stores a set of abnormal access objects. The deep message detection server 102 is used to parse the O-domain data and B-domain data. The feature constructor 103 is used to obtain the basic attribute features of each user, etc. The classification model server 106 trains a susceptible population classification model and identifies susceptible and non-susceptible populations based on network behavior characteristics and location behavior characteristics. The access object data unit 107 stores the access objects of susceptible and non-susceptible populations. The big data comparison server 108 determines a third access object list containing suspected abnormal access objects based on the first access object list of susceptible populations and the second access object list of non-susceptible populations. The suspected abnormal access object data unit 109 stores suspected abnormal access objects. The filing verification query server 110 performs filing verification queries on suspected abnormal access objects to determine abnormal access objects.

[0058] Figure 2 A flowchart illustrating a method for identifying abnormal access objects provided in an embodiment of this application;

[0059] Below, in conjunction with Figure 2 This application describes a method for identifying abnormal access objects based on embodiments. The method for identifying abnormal access objects includes:

[0060] S210, Obtain the basic attribute characteristics, internet behavior characteristics, and location behavior characteristics of each user in the first user set;

[0061] S220: Input the basic attribute features, online behavior features, and location behavior features of each user into the susceptible population classification model to determine the susceptible and non-susceptible populations in the first user set. The model is trained based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded.

[0062] S230, Obtain the first list of access objects accessed by vulnerable groups and the second list of access objects accessed by non-vulnerable groups;

[0063] S240, based on the first access object list and the second access object list, determine the target abnormal access object, which includes fraudulent websites and / or fraudulent applications.

[0064] According to the abnormal access object identification method provided in this application, by analyzing the user's basic attribute characteristics, online behavior characteristics, and location behavior characteristics through a susceptible population classification model, it is possible to determine whether the user is a susceptible or non-susceptible population. By using a first list of access objects accessed by susceptible populations and a second list of access objects accessed by non-susceptible populations, target abnormal access objects can be identified. These target abnormal access objects include fraudulent websites and / or fraudulent applications. Thus, by analyzing the access patterns of susceptible populations to fraudulent websites and / or fraudulent applications, potential fraudulent websites and / or fraudulent applications can be effectively identified, improving the identification rate of fraudulent websites and / or fraudulent applications.

[0065] Regarding the above S210, the first user set can be internet users within a set time window [T1, T2] (e.g., 22:00-06:00), or it can be other time periods; this application does not impose any restrictions.

[0066] A deep packet inspection server can be used to parse the O-domain logs to obtain the user's spatiotemporal location state sequence, action state sequence, and access object state sequence. The location state sequence includes being on the go, at home, or at work; the action state sequence includes making phone calls, call activity, downloading / registering, receiving registration / activation SMS messages, initiating payments, and receiving payment verification SMS messages; and the access object state sequence includes daily accessible time periods, daily online / accessible times, and daily offline / inaccessible times. The action state sequence and access object state sequence are used as internet browsing behavior features, and the location state sequence is used as location behavior features.

[0067] The O domain, also known as the operation support system data domain, contains network data such as signaling, alarms, faults, and network resources. By parsing the O domain logs, users can obtain spatiotemporal related location status sequences, action status sequences, and access object status sequences.

[0068] Basic attribute characteristics include age, gender, occupation, etc., and users' basic attribute characteristics can be obtained by parsing B-domain data using a deep message inspection server.

[0069] The B domain, also known as the business domain or the data domain of the business support system, contains user data and business data, such as user consumption habits, terminal information, ARPU (Average Revenue Per User) grouping, business content, and target audience. By parsing the B domain data, the basic attribute characteristics of users can be obtained.

[0070] Regarding S220 above, since the susceptible population classification model is trained on the basic attribute features, online behavior features, and location behavior features of each deceived user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undeceived user in the third user set within the longest target time period T, the users in the first user set can be classified based on the susceptible population classification model to obtain susceptible and unsustainable populations, that is, potential deceived users and undeceived users.

[0071] Regarding S230 above, since the vulnerable and non-vulnerable groups are determined by analyzing users' online behavior, after identifying the vulnerable and non-vulnerable groups, a first list of access objects accessed by the vulnerable groups and a second list of access objects accessed by the non-vulnerable groups can be obtained. Access objects may include websites and / or applications. Then, based on the first and second access object lists, abnormal access objects are determined. Specifically, the first and second access object lists can be obtained by analyzing users' online logs.

[0072] Regarding S240 above, after obtaining the first access object list and the second access object list, the target abnormal access object can be determined based on the first access object list and the second access object list.

[0073] Specifically, a third list of access objects that meets preset conditions can be obtained by filtering based on the first list of access objects and the second list of access objects.

[0074] Perform a record check on each access object in the third access object list and determine the query results for each access object;

[0075] Access objects whose query results show that they have failed the filing verification are identified as target abnormal access objects.

[0076] The process involves filtering based on the first and second access object lists to obtain a third access object list that meets preset conditions, including:

[0077] The intersection of the first and second access object lists is filtered out from the first access object list to obtain the third access object list;

[0078] or,

[0079] Sort the accessed objects in the second accessed object list according to the number of accesses from most to least, to obtain a sorted second accessed object list; filter out the accessed objects in the first accessed object list that rank at the top of the sorted second accessed object list by a predetermined proportion, to obtain a third accessed object list.

[0080] In this way, the comparison server can be used to compare and calculate the first access object list and the second access object list. Objects that have been accessed by non-susceptible people in the first access object list can be filtered out, and the remaining ones can be used as the third access object list. Since non-susceptible people have also accessed these access objects, it means that the probability of these access objects being abnormal is small. Therefore, these access objects are filtered out, and we only need to care about those objects that have not been accessed by non-susceptible people.

[0081] Alternatively, the top 5% of the second list of visitors who have been visited by non-vulnerable individuals in the first list of visitors can be filtered out, and the remaining visitors can be used as the third list of visitors. The preset percentage can be, for example, 95%, and can be set as needed. The remaining 5% of visitors are visited by non-vulnerable individuals less frequently and have lower reference value, so they can be disregarded as normal visitors. Therefore, visitors who are in the first list of visitors and are in the bottom 5% of the second list of visitors do not need to be filtered.

[0082] After obtaining the list of third-party access objects, the ICP / IP address / domain information filing management system can be used to perform a filing query on each website and / or application in the list, and verify whether the website content is consistent with the filing entity. If the filing query fails or the filing information is inconsistent, it is identified as a fraudulent website and / or fraudulent application.

[0083] Figure 3A flowchart illustrating another method for identifying abnormal access objects provided in an embodiment of this application;

[0084] Combination Figure 3 In some embodiments of this application, the training method for the susceptible population classification model includes:

[0085] S310, extract the basic attribute features, online behavior features and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features and location behavior features of each undefrauded user in the third user set within the longest target time period T.

[0086] S320: Generate a training dataset containing positive and negative samples based on the basic attribute features, online behavior features, and location behavior features of each deceived user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undeceived user in the third user set within the longest target time period T.

[0087] Specifically, the classification model server can normalize the basic attribute features, internet behavior features, and location behavior features according to the longest target time period T, forming M-dimensional features, where M is a positive integer;

[0088] Based on a preset ratio of positive to negative samples, a training dataset with a total sample data size of T*M is constructed.

[0089] For features that cannot be normalized, NULL values ​​are used for padding.

[0090] The preset positive to negative sample ratio can be 1:1.

[0091] S330: Train a pre-defined classification model based on the training dataset to obtain a susceptible population classification model.

[0092] Specifically, the classification model server can construct an LSTM-based autoencoder, train it using data from the training dataset based on a pre-defined batch strategy, and perform convergence iterations using mean squared error as the loss function to form an LSTM model. Then, based on the trained LSTM model, it iterates through each sample in the training set, recording predictions and losses to obtain a predicted threshold range. This allows for the selection of an appropriate threshold, thereby constructing a binary classification task model and forming a susceptible population classification model.

[0093] Figure 4 A flowchart illustrating another method for identifying abnormal access objects provided in this application embodiment;

[0094] Combination Figure 4In some embodiments of this application, the extraction of basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T, may include:

[0095] S410, obtain the collection of abnormal access objects, which includes multiple abnormal access objects.

[0096] Specifically, the names, domain names, or URLs of fraudulent websites and / or fraudulent applications can be obtained from the Ministry of Public Security, the Cyberspace Administration of China, the Ministry of Industry and Information Technology, or business systems, and a directory of fraudulent websites and / or fraudulent applications can be generated as a collection of abnormal access objects.

[0097] S420, Get the second set of users who have accessed the abnormal access objects in the abnormal access object set.

[0098] Specifically, a deep message inspection server can be used to parse the O-domain logs to obtain a set of all user mobile phone numbers that have accessed the fraudulent website or fraudulent application that has accessed the abnormal access object set, which is then passed to the feature constructor.

[0099] S430 uses a deep packet inspection server to parse the O-domain logs and extract the location status sequence, action status sequence, and abnormal object status sequence of each deceived user in the second user set within their respective target time period. The O-domain logs include network data.

[0100] The target time period is the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded.

[0101] Specifically, for each mobile phone number in the second user set, the feature constructor extracts the spatiotemporal related behavioral sequences (including but not limited to location state sequences (traveling, at home, at work), action state sequences (making calls, call status, downloading and registering, registration activation SMS, initiating payment, payment verification SMS, etc.), and application / website state sequences (daily accessible time periods, daily online accessible time, daily offline inaccessible time, etc.)) from the deep message detection server from the period from the first access to the fraudulent website or application to the last time the user was scammed. The feature constructor then calculates the longest target time period T from the spatiotemporal related behavioral sequences in the second user set.

[0102] S440: Obtain the third user set within the longest target time period T from the deep packet inspection server, and use the deep packet inspection server to parse the O domain logs to extract the location state sequence, action state sequence, and normal object state sequence of each non-deceived user within the third user set within the longest target time period T.

[0103] Specifically, the feature constructor, according to a set ratio strategy (e.g., 1:1), obtains the deduplicated user set of the large population within the time interval of the second user set from the deep message detection server, which is the third user set (which has no intersection with the second user set), and constructs the spatiotemporal related behavior sequence of the third user set for that time interval according to S330.

[0104] S450: Determine the online behavior characteristics of each defrauded user based on the action state sequence and abnormal object state sequence of each defrauded user; determine the location behavior characteristics of each defrauded user based on the location state sequence of each defrauded user; determine the online behavior characteristics of each non-defrauded user based on the action state sequence and normal object state sequence of each non-defrauded user; determine the location behavior characteristics of each non-defrauded user based on the location state sequence of each non-defrauded user.

[0105] Specifically, the action state sequence and abnormal object state sequence of the defrauded user belong to the characteristics of the user's Internet access, so they are classified as the characteristics of the user's Internet access behavior. The location state sequence of the defrauded user belongs to the characteristics of the user's location, so they are classified as the characteristics of the user's location behavior. The characteristics of the undefrauded user are classified in the same way.

[0106] S460 uses a deep message inspection server to parse the B-domain data, extracting the basic attribute features of each deceived user in the second user set and the basic attribute features of each undeceived user in the third user set. The B-domain data includes user data.

[0107] Specifically, by using a deep message detection server to parse the data in domain B, the age, gender, and occupation of each defrauded user and each non-defrauded user can be obtained, which can be determined as basic attribute features. Of course, basic attribute features can also include other user features, such as user education level, etc., which this application does not restrict.

[0108] In this way, by using the deep message detection server, the O domain logs and B domain data can be parsed to accurately obtain the characteristics of various aspects of deceived and undeceived users. After obtaining the basic attribute characteristics, online behavior characteristics and location behavior characteristics of deceived and undeceived users, the feature builder passes them to the classification model server for model training.

[0109] In some embodiments of this application, after identifying access objects whose query results show they have failed the filing query as target abnormal access objects, the method for identifying abnormal access objects further includes:

[0110] Add the target abnormal access object to the abnormal access object collection.

[0111] In this way, by continuously adding the identified target abnormal access objects to the abnormal access object set, the abnormal access object set can be kept iteratively updated for further early warning processing.

[0112] Figure 5 A schematic diagram of the structure of the abnormal access object identification device provided in the embodiments of this application;

[0113] Combination Figure 5 This application introduces an abnormal access object identification device provided in its embodiments. The abnormal access object identification device includes:

[0114] The first acquisition module 501 is used to acquire the basic attribute characteristics, internet behavior characteristics and location behavior characteristics of each user in the first user set;

[0115] The first determining module 502 is used to input the basic attribute features, online behavior features and location behavior features of each user into the susceptible population classification model to determine the susceptible population and non-susceptible population in the first user set. The susceptible population classification model is trained based on the basic attribute features, online behavior features and location behavior features of each defrauded user in the second user set within their respective target time period and the basic attribute features, online behavior features and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time the defrauded user accessed the abnormal object to the last time they were defrauded.

[0116] The second acquisition module 503 is used to acquire the first access object list accessed by the susceptible population and the second access object list accessed by the non-susceptible population.

[0117] The second determination module 504 is used to determine the target abnormal access object based on the first access object list and the second access object list. The target abnormal access object includes fraudulent websites and / or fraudulent applications.

[0118] In some embodiments of this application, the device for identifying abnormal access objects further includes: a training module, which includes:

[0119] The feature extraction unit is used to extract the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T.

[0120] The sample generation unit is used to generate a training dataset containing positive and negative samples based on the basic attribute features, online behavior features and location behavior features of each deceived user in the second user set within their respective target time period, and the basic attribute features, online behavior features and location behavior features of each undeceived user in the third user set within the longest target time period T.

[0121] The training unit is used to train a pre-defined classification model based on the training dataset to obtain a susceptible population classification model.

[0122] In some embodiments of this application, the feature extraction unit is specifically used for:

[0123] Retrieves a collection of abnormal access objects, which includes multiple abnormal access objects;

[0124] Get the second set of users who have accessed the abnormal access objects in the abnormal access object set;

[0125] Using a deep packet inspection server, the O-domain logs are parsed to extract the location status sequence, action status sequence, and abnormal object status sequence of each defrauded user in the second user set within their respective target time period. The O-domain logs include network data.

[0126] Obtain the third user set within the longest target time period T from the deep message detection server, and use the deep message detection server to parse the O domain logs to extract the location state sequence, action state sequence, and normal object state sequence of each non-deceived user within the third user set within the longest target time period T.

[0127] The online behavior characteristics of each defrauded user are determined based on the action state sequence and abnormal object state sequence of each defrauded user. The location behavior characteristics of each defrauded user are determined based on the location state sequence of each defrauded user. The online behavior characteristics of each non-defrauded user are determined based on the action state sequence and normal object state sequence of each non-defrauded user. The location behavior characteristics of each non-defrauded user are determined based on the location state sequence of each non-defrauded user.

[0128] Using a deep message inspection server, the B-domain data is parsed to extract the basic attribute features of each deceived user in the second user set and the basic attribute features of each undeceived user in the third user set. The B-domain data includes user data.

[0129] In some embodiments of this application, the sample generation unit is specifically used for:

[0130] The basic attribute features, online behavior features, and location behavior features are normalized according to the longest target time period T to form M-dimensional features, where M is a positive integer.

[0131] Based on a preset ratio of positive to negative samples, a training dataset with a total sample data size of T*M is constructed.

[0132] In some embodiments of this application, the second determining module 504 includes:

[0133] The filtering unit filters based on the first access object list and the second access object list to obtain a third access object list that meets preset conditions.

[0134] The query unit performs a record query on each access object in the third access object list and determines the query result for each access object.

[0135] The unit is identified, and the access objects whose query results show that they have failed the filing query are identified as target abnormal access objects.

[0136] In some embodiments of this application, the screening unit is specifically used for:

[0137] The intersection of the first and second access object lists is filtered out from the first access object list to obtain the third access object list;

[0138] or,

[0139] Sort the accessed objects in the second accessed object list according to the number of accesses from most to least, to obtain a sorted second accessed object list; filter out the accessed objects in the first accessed object list that rank at the top of the sorted second accessed object list by a predetermined proportion, to obtain a third accessed object list.

[0140] In some embodiments of this application, the device for identifying abnormal access objects further includes:

[0141] Add a module to add the target abnormal access object to the abnormal access object collection.

[0142] According to the abnormal access object identification device provided in the embodiments of this application, by analyzing the user's basic attribute characteristics, online behavior characteristics, and location behavior characteristics through a susceptible population classification model, it can determine whether the user is a susceptible or non-susceptible population. By using a first list of access objects accessed by susceptible populations and a second list of access objects accessed by non-susceptible populations, target abnormal access objects can be identified. These target abnormal access objects include fraudulent websites and / or fraudulent applications. Thus, by analyzing the access patterns of susceptible populations to fraudulent websites and / or fraudulent applications, potential fraudulent websites and / or fraudulent applications can be effectively identified, improving the identification rate of fraudulent websites and / or fraudulent applications.

[0143] Figure 6 A schematic diagram of the structure of the identification device for abnormal access objects provided in the embodiments of this application;

[0144] The device for identifying abnormally accessed objects may include a processor 601 and a memory 602 storing computer program instructions.

[0145] Specifically, the processor 601 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0146] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 602 is non-volatile solid-state memory.

[0147] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.

[0148] The processor 601 implements the abnormal access object identification method in the above embodiments by reading and executing computer program instructions stored in the memory 602.

[0149] In one example, the device for identifying abnormally accessed objects may further include a communication interface 603 and a bus 610. For example, Figure 6 As shown, the processor 601, memory 602, and communication interface 603 are connected through bus 610 and complete communication with each other.

[0150] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0151] Bus 610 includes hardware, software, or both, that couples components of a device for determining base station configuration parameters together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 610 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0152] The device for identifying abnormal access objects executes the method for identifying abnormal access objects in the embodiments of this application, thereby achieving... Figure 2 , Figure 3 , Figure 4 Methods for identifying abnormal access objects.

[0153] Furthermore, in conjunction with the abnormal access object identification method in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the abnormal access object identification methods in the above embodiments.

[0154] In conjunction with the abnormal access object identification method in the above embodiments, this application also provides a computer program product, wherein when the instructions in the computer program product are executed by the processor of an electronic device, the electronic device executes the abnormal access object identification method of any of the above embodiments.

[0155] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0156] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0157] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0158] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0159] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A method for identifying abnormally accessed objects, characterized in that, The method includes: Obtain the basic attribute characteristics, online behavior characteristics, and location behavior characteristics of each user in the first user set; The basic attribute features, online behavior features, and location behavior features of each user are input into the susceptible population classification model to determine the susceptible and non-susceptible populations in the first user set. The susceptible population classification model is trained based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded. Obtain the first list of access objects accessed by the susceptible population and the second list of access objects accessed by the non-susceptible population; Based on the first list of access objects and the second list of access objects, target abnormal access objects are determined, including fraudulent websites and / or fraudulent applications.

2. The method for identifying abnormal access objects according to claim 1, characterized in that, The training methods for the susceptible population classification model include: Extract the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T. A training dataset containing positive and negative samples is generated based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. A preset classification model is trained based on the training dataset to obtain the susceptible population classification model.

3. The method for identifying abnormal access objects according to claim 2, characterized in that, The extraction of basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T, includes: Obtain a set of abnormal access objects, wherein the set of abnormal access objects includes multiple abnormal access objects; Obtain the second set of users who have accessed the abnormal access objects in the abnormal access object set; Using a deep packet inspection server, the O-domain logs are parsed to extract the location status sequence, action status sequence, and abnormal object status sequence of each defrauded user in the second user set within their respective target time period. The O-domain logs include network data. The third user set within the longest target time period T is obtained from the deep message detection server, and the O domain log is parsed using the deep message detection server to extract the location state sequence, action state sequence, and normal object state sequence of each non-deceived user within the third user set within the longest target time period T. Based on the action state sequence and abnormal object state sequence of each defrauded user, the online behavior characteristics of each defrauded user are determined; based on the location state sequence of each defrauded user, the location behavior characteristics of each defrauded user are determined; based on the action state sequence and normal object state sequence of each non-defrauded user, the online behavior characteristics of each non-defrauded user are determined; based on the location state sequence of each non-defrauded user, the location behavior characteristics of each non-defrauded user are determined. Using a deep message detection server, the B-domain data is parsed to extract the basic attribute features of each defrauded user in the second user set and the basic attribute features of each non-defrauded user in the third user set. The B-domain data includes user data.

4. The method for identifying abnormal access objects according to claim 3, characterized in that, The process of generating a training dataset containing positive and negative samples based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each undefrauded user in the third user set within the longest target time period T, includes: The basic attribute features, internet behavior features, and location behavior features are normalized according to the longest target time period T to form an M-dimensional feature, where M is a positive integer. Based on a preset ratio of positive to negative samples, a training dataset with a total sample data size of T*M is constructed.

5. The method for identifying abnormal access objects according to claim 1, characterized in that, The step of determining the target abnormal access object based on the first access object list and the second access object list includes: Based on the first list of accessed objects and the second list of accessed objects, a third list of accessed objects that meets preset conditions is obtained. For each access object in the third access object list, a filing query is performed to determine the query result for each access object; Access objects whose query results show that they have failed the filing verification are identified as target abnormal access objects.

6. The method for identifying abnormal access objects according to claim 5, characterized in that, The step of filtering based on the first access object list and the second access object list to obtain a third access object list that meets preset conditions includes: The third list of access objects is obtained by filtering out the intersection of the first list of access objects and the second list of access objects from the first list of access objects. or, The access objects in the second access object list are sorted from most to least accessed to obtain a sorted second access object list; access objects that are in the first access object list and rank at the top of the sorted second access object list by a predetermined proportion are filtered out from the first access object list to obtain the third access object list.

7. The method for identifying abnormal access objects according to claim 5, characterized in that, After identifying access objects whose query results show they have failed the registration check as target abnormal access objects, the method further includes: Add the target abnormal access object to the abnormal access object set.

8. A device for identifying abnormally accessed objects, characterized in that, The device includes: The first acquisition module is used to acquire the basic attribute characteristics, internet behavior characteristics, and location behavior characteristics of each user in the first user set. The first determining module is used to input the basic attribute features, online behavior features, and location behavior features of each user into the susceptible population classification model to determine the susceptible population and non-susceptible population in the first user set. The susceptible population classification model is trained based on the basic attribute features, online behavior features, and location behavior features of each defrauded user in the second user set within their respective target time period, and the basic attribute features, online behavior features, and location behavior features of each non-defrauded user in the third user set within the longest target time period T. The target time period is the time period corresponding to the period from the first time a defrauded user accesses the abnormal object to the last time they are defrauded. The second acquisition module is used to acquire the first access object list accessed by the susceptible population and the second access object list accessed by the non-susceptible population. The second determining module is used to determine target abnormal access objects based on the first access object list and the second access object list, wherein the target abnormal access objects include fraudulent websites and / or fraudulent applications.

9. A device for identifying abnormal access objects, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method for identifying abnormal access objects as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, constitute the method for identifying abnormal access objects as described in any one of claims 1 to 7.

11. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the method for identifying abnormal access objects as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Early warning method and device for network fraud, equipment and storage medium

    CN114048311A

  • Network abnormal behavior detection method and device, electronic equipment and storage medium

    CN116032501A