A method and system for identifying and preventing securities account opening network traffic
By identifying customer account opening information and updating the current limit threshold according to the current limit factor, the problems of poor system stability and single current limit threshold in complex network environments are solved, effectively identifying and preventing illegal network traffic, ensuring system stability and account opening efficiency.
Patent Information
- Application Number
- CN202510038186.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-10
AI Technical Summary
In the face of complex network environments, the system stability and current limit threshold are single, making it difficult to effectively identify and prevent illegal network traffic.
By obtaining customer account opening information, identifying whether the customer is an illegal traffic customer, and guiding the customer to open an account authentication based on the comparison results of the traffic of the flow limit factor and the current limit threshold. At the same time, the current limit threshold is updated based on the current limit factor weight to improve the flexibility of the current limit strategy.
Effective identification and interception of illegal network traffic is achieved, and the stability of the system and account opening efficiency are ensured through the current limiting strategy of multiple current limiting factors and the dynamic update of the current limiting threshold.
Smart Images

Figure CN119475101B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of financial technology, and in particular to a method and system for identifying and preventing securities account opening network traffic. Background Art
[0002] In network communications, the network layer has mature flow control solutions through congestion control algorithms. However, in the field of financial technology, business scenarios are complex, data sources are intricate, and financial security attacks are emerging in an endless stream. For different business scenarios, more flexible, accurate, and intelligent network traffic identification and prevention methods are needed. On the one hand, it is necessary to identify the legitimacy of the traffic, and on the other hand, it is necessary to prevent network shocks. The existing flow control scenarios lack hierarchical control of complex network environments, and the setting and updating of flow control parameters are not smart enough.
[0003] Based on the requirements of system steady-state robustness and stability, it is hoped that the system can maintain basic normal operation capabilities in the face of unpredictable network traffic without causing drastic fluctuations or loss of control. Currently, there are multiple patents in the field of financial technology that compare the flow limit value based on factors such as transaction request response time, channel information, and target method to protect traffic, but such methods are not perfect.
[0004] In a transaction flow limiting method and device, storage medium and electronic device (patent number: CN 115375457 A), the flow limiting rules of multiple dimensions are preset for transaction requests entering the bank system. When the channel information, transaction system information, institution information and transaction type information included in the transaction request meet the corresponding flow limiting rules, the flow limiting of the transaction request is realized. This method is mainly aimed at the trusted traffic in the transaction system, not the complex traffic of the Internet, and the flow limiting rule table is manually updated after being preset, which is not flexible.
[0005] There are also multi-channel current limiting methods and devices, computer storage media, and electronic equipment features (patent number: CN116962522 A) that use fixed forwarding methods, target calling methods, and channel names to read current limiting values, and set different current limiting values for different parameter values in the target calling method. This method simply limits the current limit from the calling method, does not consider complex traffic, and lacks a mechanism to update the current limiting factor. Summary of the invention
[0006] The present invention provides a method and system for identifying and preventing securities account opening network traffic, which are used to solve the technical problems of poor system stability and single current limiting threshold setting in the prior art when facing a complex network environment.
[0007] According to one aspect of the present invention, a method for identifying and preventing securities account opening network traffic is provided, comprising:
[0008] Get current customer account opening information;
[0009] Identify the account opening information to identify whether the current customer is an illegal traffic customer;
[0010] When it is identified that the customer is not an illegal traffic customer, guiding the customer to perform account opening authentication according to a comparison result of the traffic of at least one traffic limiting factor in the account opening information and the traffic limiting threshold corresponding to the traffic limiting factor;
[0011] The current limiting threshold is updated at least based on the preset current limiting factor weight for use in the next stage of account opening authentication.
[0012] Optionally, the customer account opening information includes one or more of the account opening channel, account opening activity, source IP, operation site, QR code number, and customer terminal unique identifier.
[0013] Optionally, the account opening information is identified to identify whether the current customer is an illegal traffic customer, including
[0014] Using a machine learning-based method to extract multiple features from the account opening information;
[0015] Based on the multiple features in the account opening information, the probability that the current customer is an illegal traffic customer is calculated.
[0016] Optionally, the extracting multiple features from the account opening information by using a machine learning-based method; and calculating the probability that the current customer is an illegal traffic customer based on the multiple features in the account opening information, including:
[0017] The GBDT algorithm model is used as the architecture of the abnormal information recognition algorithm. The binary CART regression tree is used in each iteration of the algorithm. The loss function uses the logarithmic loss function that fits the binary scenario. The negative gradient is used instead of the residual in the fitting process.
[0018] The characteristic variables used in the GBDT algorithm model include but are not limited to: customer activity number, customer channel number, customer application area IP, customer gender, customer age, customer place of origin, customer occupation, customer income range, account opening application time, IP overlap, application area overlap;
[0019] The output is the probability that the customer is an illegal traffic customer.
[0020] Optionally, the flow limiting factor includes at least a user account, an account opening channel, an account opening activity, a QR code number, and a UUID; the comparison result of the flow of the flow limiting factor in the account opening information and the flow limiting threshold corresponding to the flow limiting factor guides the customer to perform account opening authentication, including:
[0021] Comparing the flow data of the plurality of flow limiting factors with the flow limiting thresholds corresponding to the flow limiting factors respectively;
[0022] If the flow data of the plurality of flow limiting factors are all less than the corresponding flow limiting threshold, the customer is guided to enter into two-way video authentication;
[0023] If the traffic data of the current limiting factor is greater than or equal to the current limiting threshold, the customer is guided to enter the one-way video authentication and an alarm signal is triggered.
[0024] Optionally, the current limiting threshold includes a manual threshold and the update threshold, and the updating of the current limiting threshold based at least on a preset current limiting factor weight for use in the next stage of account opening authentication includes:
[0025] Calculating the weight of the current limiting factor based on a preset current limiting factor weight allocation formula;
[0026] The artificial threshold is updated at least based on the weight of the current limiting factor, and the updated threshold is updated at least based on the weight of the current limiting factor and a preset threshold update formula for use in the next stage of account opening authentication.
[0027] Optionally, updating the artificial threshold at least based on the weight of the current limiting factor comprises:
[0028] When the alarm signal is received, the manual threshold is adjusted based at least on the weight of the current limiting factor corresponding to the triggered alarm signal, the flow data, and the manpower load.
[0029] Optionally, updating the update threshold based at least on the weight of the current limiting factor and a preset threshold update formula includes:
[0030] The threshold of the flow limiting factor is related to the product of the weight of the flow limiting factor, the average number of accounts opened per day, the volatility coefficient and the market activity.
[0031] The calculating the weight of the current limiting factor based on a preset current limiting factor weight allocation formula includes:
[0032] The same type of current limiting factors includes multiple sub-current limiting factors;
[0033] Obtain weighted coefficients and evaluation scores of multiple sub-current limiting factors;
[0034] The current limiting factor weight is related to the product of the weighting coefficient of each of the sub-current limiting factors and the evaluation score.
[0035] According to another aspect of the present invention, a system for identifying and preventing securities account opening network traffic is provided, comprising:
[0036] An information acquisition unit, used to acquire current customer account opening information;
[0037] An identification unit, used to identify the account opening information to identify whether the current customer is an illegal traffic customer;
[0038] An authentication unit, configured to guide the customer to perform account opening authentication according to a comparison result of the flow of at least one flow limiting factor in the account opening information and a flow limiting threshold corresponding to the flow limiting factor when it is identified that the customer is not an illegal flow customer;
[0039] A threshold updating unit is used to update the current limiting threshold based on at least a preset current limiting factor weight for use in the next stage of account opening authentication.
[0040] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0041] at least one processor; and
[0042] a memory communicatively connected to the at least one processor; wherein,
[0043] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method for identifying and preventing securities account opening network traffic described in any embodiment of the present invention.
[0044] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the method for identifying and preventing securities account opening network traffic as described in any embodiment of the present invention when executed.
[0045] The technical solution of the embodiment of the present invention identifies the current customer's account opening information to determine whether the current customer is an illegal traffic customer, and effectively intercepts illegal traffic customers; through the flow limiting strategy of multiple flow limiting factors, this solution can comprehensively consider multiple indicator variables, making traffic control more reasonable, and by updating the flow limiting threshold according to the weight of the flow limiting factor, the flow limiting strategy of this solution is more flexible, so as to better cope with the changing network environment, and ensure the stability of the system and account opening efficiency.
[0046] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0048] Figure 1 This is a flow chart of a method for identifying and preventing securities account opening network traffic according to Embodiment 1 of the present invention;
[0049] Figure 2 This is a flow chart of a method for identifying and preventing securities account opening network traffic provided according to Embodiment 2 of the present invention;
[0050] Figure 3 is a flow chart of an illegal traffic identification algorithm provided according to Embodiment 2 of the present invention;
[0051] Figure 4 It is a flow chart of a specific embodiment of a method for identifying and preventing securities account opening network traffic according to the present invention;
[0052] Figure 5 This is a system block diagram of a securities account opening network traffic identification and prevention system provided according to Embodiment 3 of the present invention;
[0053] Figure 6 It is a system block diagram of a specific implementation of a securities account opening network traffic identification and prevention system according to the present invention;
[0054] Figure 7 It is a structural schematic diagram of an electronic device that implements the method for identifying and preventing securities account opening network traffic in embodiment 4 of the present invention. DETAILED DESCRIPTION
[0055] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0056] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0057] When users open an account with a brokerage, they generally have to enter information, undergo video witnessing, and perform manual verification. Each step is handled by a different system or module, and data needs to flow and interact between systems. Some systems have clear upper limits on process processing volume, such as video witnessing nodes. If the number of processes that need to be processed at the same time greatly exceeds the processing limit, it is necessary to control the reported traffic to prevent customers from waiting in line for too long.
[0058] For example, if in practice there are M witnesses in the background, and the average witnessing time is n minutes per person, if within n minutes, the number of people waiting to enter the video witnessing is > 3M, then the new user needs to wait at least 2n minutes. At this time, the page will display the estimated waiting time and guide the customer to the one-way video of the guidance plan in a friendly manner. Another example is that the information submitted by the account opening customer needs to be manually reviewed and rechecked by the operation staff before the account can be opened in batches, which is a bottleneck.
[0059] The technical solution of the embodiment of the present invention identifies the current customer's account opening information to determine whether the current customer is an illegal traffic customer, and effectively intercepts illegal traffic customers; through the flow limiting strategy of multiple flow limiting factors, this solution can comprehensively consider multiple indicator variables, making traffic control more reasonable, and by updating the flow limiting threshold according to the weight of the flow limiting factor, the flow limiting strategy of this solution is more flexible, so as to better cope with the changing network environment, and ensure the stability of the system and account opening efficiency.
[0060] Embodiment 1
[0061] Figure 1 A flowchart of a method for identifying and preventing securities account opening network traffic is provided for the first embodiment of the present invention. Figure 1 As shown, the method includes:
[0062] S101. Obtain current customer account opening information.
[0063] During the account opening process, customers are required to upload personal information, and the account opening system will receive the customer's account opening information to identify the customer information. Customer information may include account opening channels, account opening activities, source IP, operation site, QR code number, customer terminal unique identifier, etc. Among them, account opening channels refer to long-term fixed account opening sites, including offline business departments, branches and online official websites, official WeChat accounts, self-owned apps, third-party cooperation apps, etc. Account opening activities are used to describe activities held by a company and a certain account opening channel within a certain period of time. There is a validity period limit, and account opening activities can be held multiple rounds. Customer information that has passed the system check is forwarded to the account opening system for account opening; the source IP refers to the customer's IP address; the QR code number can be the number of the QR code scanned by the customer to open an account; the customer terminal unique identifier can be the unique identifier UUID of the customer terminal.
[0064] S102: Identify the account opening information to identify whether the current customer is an illegal traffic customer.
[0065] The system can identify the account opening information, including but not limited to the customer's account opening channel, account opening activities, source IP, operation site, QR code number, customer terminal unique identification, etc., to determine whether the customer is an illegal customer. If the identification result is an illegal customer, the system intercepts the customer's account opening request and ends the account opening process; if the identification result is not an illegal customer, the customer enters the account opening system. In this embodiment, the method for identifying the customer's account opening information can be to conduct a comprehensive analysis based on multiple factors in the account opening information to determine the probability that the customer is an illegal customer. The probability threshold can be set in advance. If the probability that the customer is an illegal customer is greater than the probability threshold, it can be determined whether the customer is an illegal traffic customer.
[0066] S103: When it is identified that the customer is not an illegal traffic customer, the customer is guided to perform account opening authentication based on a comparison result of the traffic of at least one traffic limiting factor in the account opening information and a traffic limiting threshold corresponding to the traffic limiting factor.
[0067] When it is identified that the customer is not an illegal traffic customer, the account opening system is entered to further guide the customer to open an account. Among them, the flow limiting factors may include user account, account opening channel, account opening activity, QR code number, UUID, etc., and the flow of the flow limiting factor is the number of account opening appointments made by the same customer's user account within a certain period of time, the number of account opening appointments made through the same account opening channel within a period of time, the number of account opening appointments made through the same account opening activity within a period of time, the number of account opening appointments made through the same QR code number within a period of time, and the number of times the appointment interface is entered through the unique identifier UUID within a period of time.
[0068] In addition, the flow of each flow limiting factor corresponds to a different flow limiting threshold. The flow of the flow limiting factor can be compared with its corresponding flow limiting threshold to guide the customer to enter two-way authentication or single authentication. It should be noted that two-way authentication refers to manual video witnessing, and the customer materials can be manually reviewed once to complete the account opening authentication; while single authentication is the identification and authentication of customer materials by the system. There may be problems with unclear customer materials or errors in customer materials, so manual review is required later. If there are problems with the review, the customer needs to upload the materials again. Therefore, if the current flow is small or the manpower load is small, customers can be guided to perform two-way authentication; if the current flow is large or the manpower load is large, customers need to be guided to perform one-way authentication.
[0069] S104. Update the current limiting threshold at least based on the preset current limiting factor weight for use in the next stage of account opening authentication.
[0070] Since the flow size may change with the change of the flow limiting factor, the system needs to be able to regularly adjust the corresponding flow threshold to cope with the real-time changes in account opening flow. This embodiment assigns different weights to the flow limiting factors, and can also update the flow limiting threshold according to the manpower load or the flow size change of the flow limiting factor. For example, when the flow limiting factor is a channel, the flow limiting threshold can be adjusted in combination with factors such as the weight of the channel, the flow size of the channel, the manpower load, and the market activity of the securities market. Among them, the calculation of the weight of each channel can be by scoring each channel, setting a weighting coefficient for each channel to represent its importance, and calculating the weight coefficient of each channel based on the score and weighting coefficient of each channel.
[0071] The technical solution of the embodiment of the present invention identifies the current customer's account opening information to determine whether the current customer is an illegal traffic customer, and effectively intercepts illegal traffic customers; through the flow limiting strategy of multiple flow limiting factors, this solution can comprehensively consider multiple indicator variables, making traffic control more reasonable, and by updating the flow limiting threshold according to the weight of the flow limiting factor, the flow limiting strategy of this solution is more flexible, so as to better cope with the changing network environment, and ensure the stability of the system and account opening efficiency.
[0072] Embodiment 2
[0073] Figure 2 This is a flow chart of a method for identifying and preventing securities account opening network traffic provided by Embodiment 2 of the present invention. Figure 2 As shown, the method includes:
[0074] S201. Obtain the current customer account opening information.
[0075] S202: Using a machine learning-based method to extract multiple features from the account opening information.
[0076] S203. Based on the multiple features in the account opening information, calculate the probability that the current customer is an illegal traffic customer.
[0077] In this embodiment, multiple features in the account opening information can be extracted based on machine learning methods. For example, using a variety of machine learning methods such as random forests and GBDT, using ensemble learning methods, using multiple weak classifiers to combine into a strong classifier, to improve the ability to identify abnormal traffic. These classifiers can be trained based on different dimensional features of traffic to obtain invalid channel customer identifiers in the customer dimension. At the same time, the illegal traffic identification model is also regularly updated to adapt to changes in user traffic to ensure accurate identification of abnormal traffic.
[0078] In a specific implementation, a GBDT algorithm model is used as the architecture of an abnormal information identification algorithm, a binary CART regression tree is used in each iteration of the algorithm, a logarithmic loss function suitable for the binary scenario is used as the loss function, and a negative gradient is used instead of a residual in the fitting process; the feature variables used in the GBDT algorithm model include but are not limited to: customer activity number, customer channel number, customer application area IP, customer gender, customer age, customer place of origin, customer occupation, customer income range, account opening application time, IP overlap, and application area overlap; the output is the probability that the customer is an illegal traffic customer.
[0079] like Figure 3 In the illegal traffic identification algorithm shown in the figure, for the first classifier, the first classification is performed based on the customer's data, and it is predicted that the customer has a 70% chance of being an illegal traffic customer, and the calculated error is 30%; the second weak classifier fits the residual and predicts that the residual has a 60% chance of being an illegal traffic customer, and the error is 30%×(1-60%)=12%; the third weak classifier fits the residual again and predicts that the residual has a 50% chance of being an illegal traffic customer, and the test error is 12%×(1-50%)=6%; the fourth weak classifier continues to fit the residual and predicts that the residual has a 40% chance of being an illegal traffic customer, and the error is 6%×(1-40%)=3.6%; assuming that the iteration has been completed at this time, the calculated probability that the customer is an illegal traffic customer is: 1×0.7+0.3×0.6+0.12×0.5+0.06×0.4=96.4%. Finally, there is a 95%+ confidence that the customer is an illegal traffic customer. It can be set that when the probability that a customer is an illegal traffic customer is greater than 95%, the customer is considered to be an illegal traffic customer; when the probability that a customer is an illegal traffic customer is less than 5%, the customer is considered not to be an illegal traffic customer.
[0080] S204: When it is identified that the customer is not an illegal traffic customer, the traffic data of the plurality of flow limiting factors are respectively compared with the flow limiting thresholds corresponding to the flow limiting factors.
[0081] S205. If the flow data of the plurality of flow limiting factors are all less than the corresponding flow limiting thresholds, the customer is guided to enter into two-way video authentication.
[0082] S206: If the flow data of the flow limiting factor is greater than or equal to the flow limiting threshold, the customer is guided to enter the one-way video authentication and an alarm signal is triggered.
[0083] When it is determined that the customer is not an illegal traffic customer, the account opening process begins. In the account opening process, the flow of the current flow limiting factor reaches the threshold in real time based on the number of customer requests:
[0084] For example, when the traffic of multiple flow limiting factors of a customer is less than the corresponding flow limiting factor threshold, it means that the customer is not an illegal traffic customer, and the customer can be guided to perform a two-way video witnessing process; when the number of reservations made by the user account within x1 minutes exceeds the preset value a1, the customer can be guided to perform a one-way video witnessing process; the number of reservations made by the current channel within x2 minutes exceeds the flow limiting threshold a2, the customer can be guided to perform a one-way video witnessing process; the number of reservations made within x3 minutes in this round of account opening activities exceeds the flow limiting threshold a3, the customer can be guided to perform a one-way video witnessing process; when the number of times the marketing personnel's QR code is scanned to enter the reservation page exceeds the preset value a4 within x4 minutes, the customer can be guided to perform a one-way video witnessing process; the customer terminal unique identifier UUID is obtained as the operation site. If the UUID is scanned to enter the reservation page more than the preset value a5 within x5 minutes, the customer can be guided to perform a one-way video witnessing process; if the IP address requested by the customer has been blacklisted (actually most of them are overseas IPs), the request will be intercepted and the account opening process will be ended.
[0085] During the account opening process, the detection before the bottleneck node gives traffic feedback and suggestions, and generates a traffic warning signal. Before the bottleneck node (video witness), if the number of people entering the system at the current step is greater than 3 times the number of backstage witnesses in the cache, the customer is guided to the one-way video and an alarm signal is generated.
[0086] It should be noted that the flow limiting threshold may include a manual threshold and an update threshold, wherein the manual threshold may be adjusted by staff, while the update threshold is adjusted regularly according to changes in the flow of the flow limiting factor.
[0087] S207: Calculate the weight of the current limiting factor based on a preset current limiting factor weight allocation formula.
[0088] In a specific embodiment, the same type of current limiting factor includes multiple sub-current limiting factors;
[0089] Obtain weighted coefficients and evaluation scores of multiple sub-current limiting factors;
[0090] The current limiting factor weight is related to the product of the weighting coefficient of each of the sub-current limiting factors and the evaluation score.
[0091] In this embodiment, the flow limiting factors include user accounts, account opening channels, account opening activities, QR code numbers, UUIDs, etc., and the sub-flow limiting factors represent different user accounts, different account opening channels, different account opening activities, different QR code numbers, and different UUIDs. Each sub-flow limiting factor can be scored, and a weighted coefficient can be assigned to each sub-flow limiting factor according to its importance.
[0092] In a specific implementation, for the sub-limiting factors of the channel type, the scoring card model can be applied to the channel evaluation scenario of the brokerage to obtain the evaluation score of each channel. Among them, the scoring card model has been very maturely applied in the credit scenario. Its principle can be briefly described as follows: after dividing the overall sample into two types of good and bad samples, the logistic regression method is used to obtain the probability that each sample may be a bad sample, and then this probability is converted into a standard score between 300-1000 points through transformation.
[0093] In one embodiment, the channels are first scored. It is assumed that channel A scores a, channel B scores b, and channel C scores c. Secondly, considering the number of accounts opened in the channel, the duration of cooperation, and other factors, the importance of each channel will vary. Therefore, it is necessary to formulate an importance coefficient for each channel. It is assumed that the coefficient of channel A is α, the coefficient of channel B is β, and the coefficient of channel C is γ. Then the final weight coefficient of channel A is , the weight coefficient of channel B is , the weight coefficient of channel C is Assuming that the number of accounts opened is limited to D, the final flow allowed to enter channel A is , the final flow allowed to enter channel B is , the final flow allowed to enter channel C is .
[0094] This step applies the scoring card model in the credit scenario to the brokerage's customer acquisition scenario. During the model training process, a large number of data related to the brokerage's channel customer acquisition scenario were used, including channel investment ratio, channel effective household rate, channel account opening number, channel effective household number, channel customer communication rate, channel customer deposit rate, etc. At the same time, by identifying the channel performance in different time periods as different channel individuals, the channel data within one year is split into 12 different samples, thereby increasing the richness of the samples and solving the problem of small channel sample size, making the model more generalizable.
[0095] S208. When the alarm signal is received, the manual threshold is adjusted based at least on the weight of the current limiting factor corresponding to the triggered alarm signal, the flow data, and the manpower load.
[0096] In one embodiment, if the trigger factor threshold alarm is sounded, the business operations personnel can manually temporarily adjust the manual threshold based on the weight of the flow limiting factor corresponding to the flow limiting factor, traffic data, and manpower load. Specifically, when the system service load (CPU, memory, database IO) is relatively abundant, the manual threshold can be manually increased to clear the alarm for key channels, popular account opening activities, and account opening QR code numbers for offline marketing personnel.
[0097] S209: Update the update threshold based at least on the weight of the current limiting factor and a preset threshold update formula for use in the next stage of account opening authentication.
[0098] In a specific implementation, the threshold of the flow limiting factor is related to the product of the weight of the flow limiting factor, the average number of accounts opened per day, the volatility coefficient, and the market activity.
[0099] The system updates the factor flow limiting threshold in the interception configuration table regularly and at the end of the day according to the flow control strategy and market activity algorithm. The flow limiting factor corresponds to the flow limiting type, channel number, including activity number, QR code number, etc. Taking the channel as an example, the update threshold = channel weight ratio × monthly average daily account opening number (trading day) × volatility coefficient f (default 1.5) × market activity (1.0). Among them, the volatility coefficient f takes into account the normal fluctuation of single channel daily account opening, and the market activity defaults to 1.0. After comparing the changes in market sentiment in the past week and the past month, the stock fund trading volume and turnover rate and other factors, it is concluded that if there is no detailed fluctuation in the overall market, the parameter changes less. The update time of the update threshold can be updated once a day, once a month, or you can set the update time according to your needs.
[0100] The technical solution of the embodiment of the present invention includes flow limiting factors such as network IP, customer non-sensitive identity information, operation site, and third-party channels into monitoring, and identifies and intercepts abnormal traffic based on the algorithm capability of the machine learning model. The multi-factor traffic control strategy covers as many indicator variables of channel evaluation as possible while also taking into account the depth of cooperation with the channel, so that the multi-channel traffic control strategy can be applied to different complex account opening scenarios. In addition, due to the use of mathematical models, the channel performance after the daily close can also correct the coefficients of each factor in the strategy of the next day so that the strategy is in a state of daily dynamic update. In addition, the present invention also sets some over-the-counter factors for adjusting the multi-factor traffic control strategy. At the end of the day, the market activity is updated according to the market sentiment index, stock fund trading volume and market liquidity, and the traffic control threshold is optimized, thereby ensuring the security and stability of the system, and improving the efficiency of account opening and the use of traffic.
[0101] In a specific embodiment, Figure 4 A method for identifying and preventing network traffic for securities account opening is shown. After the customer enters the account opening process, the customer's account opening information is first identified according to the illegal traffic identification algorithm of machine learning to determine the probability that the customer is an illegal traffic customer. When the probability of judging that the customer is an illegal traffic customer is greater than or equal to 95%, the account opening request is interrupted; when the probability of judging that the customer is an illegal traffic customer is less than 95%, the traffic information is reported to the account opening system, and the account opening system performs the account opening process. The account opening system will guide the customer to enter the two-way video authentication or single video authentication based on the comparison result of the traffic of the customer's flow limiting factor and the traffic threshold of the corresponding flow limiting factor. When the two-way video authentication or single video authentication passes, it will enter the manual review. In the manual review stage, the staff can manually temporarily adjust the manual threshold based on the weight of the flow limiting factor corresponding to different flow limiting factors, traffic data, and manpower load. After the manual review is completed, the customer's account opening is completed. After the account opening task of each day is completed, the system can adjust the update threshold based on the weight of the flow limiting factor, the average number of accounts opened per day, the volatility coefficient f, and the market activity for the account opening process of the next working day.
[0102] Embodiment 3
[0103] Figure 5 This is a schematic diagram of the structure of a securities account opening network traffic identification and prevention system provided in Embodiment 3 of the present invention. Figure 5 As shown, the device comprises:
[0104] Information acquisition unit 501, used to acquire current customer account opening information;
[0105] An identification unit 502 is used to identify the account opening information to identify whether the current customer is an illegal traffic customer;
[0106] The authentication unit 503 is used to guide the customer to perform account opening authentication according to the comparison result of the flow of at least one flow limiting factor in the account opening information and the flow limiting threshold corresponding to the flow limiting factor when it is identified that the customer is not an illegal flow customer;
[0107] The threshold updating unit 504 is used to update the current limiting threshold based on at least a preset current limiting factor weight for use in the next stage of account opening authentication.
[0108] In one embodiment, the identification unit 502 is further configured to extract multiple features from the account opening information using a machine learning-based method;
[0109] Based on the multiple features in the account opening information, the probability that the current customer is an illegal traffic customer is calculated.
[0110] In one embodiment, the identification unit 502 is further used to adopt the GBDT algorithm model as the architecture of the abnormal information identification algorithm, and a binary CART regression tree is used in each iteration process of the algorithm iteration, and the loss function uses a logarithmic loss function that fits the binary scenario, and a negative gradient is used instead of a residual in the fitting process;
[0111] The characteristic variables used in the GBDT algorithm model include but are not limited to: customer activity number, customer channel number, customer application area IP, customer gender, customer age, customer place of origin, customer occupation, customer income range, account opening application time, IP overlap, application area overlap;
[0112] The output is the probability that the customer is an illegal traffic customer.
[0113] In one embodiment, the authentication unit 503 is further configured to compare the flow data of the plurality of flow limiting factors with the flow limiting thresholds corresponding to the flow limiting factors respectively;
[0114] If the flow data of the plurality of flow limiting factors are all less than the corresponding flow limiting threshold, the customer is guided to enter into two-way video authentication;
[0115] If the traffic data of the current limiting factor is greater than or equal to the current limiting threshold, the customer is guided to enter the one-way video authentication and an alarm signal is triggered.
[0116] In one embodiment, the threshold updating unit 504 is further configured to calculate the weight of the current limiting factor based on a preset current limiting factor weight allocation formula;
[0117] The artificial threshold is updated at least based on the weight of the current limiting factor, and the updated threshold is updated at least based on the weight of the current limiting factor and a preset threshold update formula for use in the next stage of account opening authentication.
[0118] In one embodiment, the threshold updating unit 504 is further configured to adjust the manual threshold based on at least the weight of the current limiting factor corresponding to the triggered alarm signal, the flow data, and the manpower load when the alarm signal is received.
[0119] In a specific embodiment, Figure 6 The identification and prevention system of securities account opening network traffic shown in the figure includes a traffic control module, a channel management module and an illegal customer identification module. Among them, the account opening information uploaded by the customer when applying for account opening can be uploaded to the traffic control module, the traffic control module can save the account opening data in the channel management module for storage, and the illegal customer identification module identifies the illegal customer according to the customer account opening information. During the account opening process, the traffic control module can compare the traffic data of the flow limiting factor with the flow limiting threshold (including the manual threshold and the update threshold). Only when the flow of the flow limiting factor is greater than the manual threshold and the update threshold, the customer will be guided to enter the two-way video authentication; and when the flow of the flow limiting factor is less than the manual threshold or one of the update thresholds, it will return to intercept and generate an alarm signal to the channel management module, and guide the customer to enter the one-way video authentication. The channel management module can receive the data uploaded by the traffic control module for data storage to obtain the current channel traffic. The staff can adjust the manual threshold manually and temporarily in the channel management module according to the traffic information corresponding to the current alarm signal, the weight of the flow limiting factor, and the manpower load. The channel management module can send the manual threshold to the traffic control module to adjust the flow limiting threshold. After the account opening task of each day is completed, the channel management module can adjust the update threshold according to the weight of the flow limiting factor, the average number of accounts opened per day, the fluctuation coefficient f and the market activity for the account opening process of the next working day. The illegal customer identification module can send the customer information after the account opening is completed and the illegal customer information to the flow control module for the subsequent identification of illegal traffic customers.
[0120] The message data processing resource scheduling device provided in the embodiment of the present invention can execute the message data processing resource scheduling device method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0121] Embodiment 4
[0122] Figure 7A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0123] like Figure 7 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0124] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0125] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a method for identifying and preventing securities account opening network traffic.
[0126] In some embodiments, a method for identifying and preventing securities account opening network traffic may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for identifying and preventing securities account opening network traffic described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute a method for identifying and preventing securities account opening network traffic in any other appropriate manner (e.g., by means of firmware).
[0127] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0128] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0129] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device, or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0130] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0131] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0132] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0133] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
[0134] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for identifying and preventing securities account opening network traffic, characterized in that: include: Get the current customer's account opening information; Identify the account opening information to identify whether the current customer is an illegal traffic customer; When it is identified that the customer is not an illegal traffic customer, the customer is guided to perform account opening authentication according to the comparison result of the traffic of at least one flow limiting factor in the account opening information and the flow limiting threshold corresponding to the flow limiting factor; the flow of the flow limiting factor is the number of account opening appointments made through the flow limiting factor within a period of time; Guiding the customer to perform account opening authentication according to a comparison result of the flow of the flow limiting factor in the account opening information and the flow limiting threshold corresponding to the flow limiting factor, including: Comparing the flow data of the plurality of flow limiting factors with the flow limiting thresholds corresponding to the flow limiting factors respectively; If the flow data of the plurality of flow limiting factors are all less than the corresponding flow limiting threshold, the customer is guided to enter into two-way video authentication; If the flow data of the flow limiting factor is greater than or equal to the flow limiting threshold, the customer is guided to enter the one-way video authentication; The current limiting threshold is updated at least based on the preset current limiting factor weight for use in the next stage of account opening authentication.
2. The method for identifying and preventing securities account opening network traffic according to claim 1, characterized in that: The customer account opening information includes one or more of the account opening channel, account opening activity, source IP, operation site, QR code number, and customer terminal unique identifier.
3. The method for identifying and preventing securities account opening network traffic according to claim 1, characterized in that: Identify the account opening information to identify whether the current customer is an illegal traffic customer, including Using a machine learning-based method to extract multiple features from the account opening information; Based on the multiple features in the account opening information, the probability that the current customer is an illegal traffic customer is calculated.
4. The method for identifying and preventing securities account opening network traffic according to claim 3 is characterized in that: The method based on machine learning is used to extract multiple features from the account opening information; Based on multiple features in the account opening information, the probability that the current customer is an illegal traffic customer is calculated, including: The GBDT algorithm model is used as the architecture of the abnormal information recognition algorithm. The binary CART regression tree is used in each iteration of the algorithm. The loss function uses the logarithmic loss function that fits the binary scenario. The negative gradient is used instead of the residual in the fitting process. The characteristic variables used in the GBDT algorithm model include but are not limited to: customer activity number, customer channel number, customer application area IP, customer gender, customer age, customer place of origin, customer occupation, customer income range, account opening application time, IP overlap, application area overlap; The output is the probability that the customer is an illegal traffic customer.
5. The method for identifying and preventing securities account opening network traffic according to claim 1, characterized in that: The flow limiting factors include at least user account, account opening channel, account opening activity, QR code number, and UUID; when the flow data of the flow limiting factor is greater than or equal to the flow limiting threshold, an alarm signal is triggered.
6. The method for identifying and preventing securities account opening network traffic according to claim 5, characterized in that: The current limiting threshold includes a manual threshold and an update threshold, and the current limiting threshold is updated at least based on a preset current limiting factor weight for use in the next stage of account opening authentication, including: Calculating the weight of the current limiting factor based on a preset current limiting factor weight allocation formula; The artificial threshold is updated at least based on the weight of the current limiting factor, and the updated threshold is updated at least based on the weight of the current limiting factor and a preset threshold update formula for use in the next stage of account opening authentication.
7. The method for identifying and preventing securities account opening network traffic according to claim 6, characterized in that: The updating of the artificial threshold based at least on the weight of the current limiting factor comprises: When the alarm signal is received, the manual threshold is adjusted based at least on the weight of the current limiting factor corresponding to the triggered alarm signal, the flow data, and the manpower load.
8. The method for identifying and preventing securities account opening network traffic according to claim 6, characterized in that: Updating the update threshold based at least on the weight of the current limiting factor and a preset threshold update formula includes: The threshold of the flow limiting factor is related to the product of the weight of the flow limiting factor, the average number of accounts opened per day, the volatility coefficient and the market activity.
9. The method for identifying and preventing securities account opening network traffic according to claim 6, characterized in that: The calculating the weight of the current limiting factor based on a preset current limiting factor weight allocation formula includes: The same type of current limiting factors includes multiple sub-current limiting factors; Obtain weighted coefficients and evaluation scores of multiple sub-current limiting factors; The current limiting factor weight is related to the product of the weighting coefficient of each of the sub-current limiting factors and the evaluation score.
10. A securities account opening network traffic identification and prevention system, characterized in that: include: An information acquisition unit, used to acquire the current customer's account opening information; An identification unit, used to identify the account opening information to identify whether the current customer is an illegal traffic customer; An authentication unit is used to guide the customer to perform account opening authentication based on a comparison result between the flow of at least one flow limiting factor in the account opening information and the flow limiting threshold corresponding to the flow limiting factor when it is identified that the customer is not an illegal traffic customer; the flow of the flow limiting factor is the number of account opening appointments made through the flow limiting factor within a period of time; the authentication unit is also used to compare the flow data of multiple flow limiting factors with the flow limiting threshold corresponding to the flow limiting factor respectively; if the flow data of multiple flow limiting factors are all less than the corresponding flow limiting threshold, the customer is guided to enter into two-way video authentication; if there is a flow data of the flow limiting factor that is greater than or equal to the flow limiting threshold, the customer is guided to enter into one-way video authentication; A threshold updating unit is used to update the current limiting threshold based on at least a preset current limiting factor weight for use in the next stage of account opening authentication.
Citation Information
Patent Citations
Transaction traffic limiting method and device, storage medium and electronic equipment
CN115375457A
Multi-channel current limiting method and device, computer storage medium and electronic equipment
CN116962522A
Security marketing activity flow-limiting and anti-refreshing method and device
CN110415124A
Risk monitoring method and device based on account opening behavior, equipment and storage medium
CN118799046A