A detection system and method for abnormal user behavior based on micro-batch risk management

Through a detection system based on micro-batch risk control, user dynamic accounting information can be obtained and encrypted in real time, and analysis rules are dynamically adjusted, which solves the timeliness and accuracy of user abnormal behavior monitoring in the marketing system, real-time, flexible and safe user behavior monitoring is achieved.

CN119761826BActive Publication Date: 2025-08-12北京领雁科技股份有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411916075.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-08-12
Estimated Expiration
2044-12-24

AI Technical Summary

Technical Problem

In the existing marketing system, the monitoring of abnormal user behaviors has problems such as insufficient timeliness, slow response, data lag, limited processing capability, delayed strategy adjustment, limited prediction capability and user privacy exposure.

Method used

The detection system based on microbatch risk control is adopted, real-time dynamic account information is obtained through the metadata management module and encrypted and processed. The real-time monitoring rule management module is used to dynamically adjust the analysis rules, and combine the event-driven mechanism and Flink streaming data processing to realize real-time data analysis and abnormal behavior recognition.

Benefits of technology

Real-time improvement, accuracy improvement, flexibility improvement, security improvement and efficiency improvement have been achieved, and abnormal behavior of users can be identified in a timely manner, adapt to market changes, protect user privacy and support precise marketing strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119761826B_ABST
    Figure CN119761826B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of marketing risk monitoring technology, and in particular to a system and method for detecting abnormal user behavior based on micro-batch risk management. The system includes a metadata management module, a real-time monitoring rule management module, a real-time data analysis module, and an analysis result management module. By introducing technical means such as streaming data processing, event-driven mechanisms, privacy computing technology, and anomaly detection based on mathematical and statistical models, this application effectively addresses the problems of insufficient timeliness, slow response, and data lag in existing methods of regularly analyzing user account information. This application achieves advantages such as real-time monitoring, rapid response, accurate identification, and flexible configuration, thereby providing strong support for enterprises to build a more complete monitoring system for abnormal marketing user behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of marketing risk monitoring, and in particular to a detection system and method for abnormal user behavior based on micro-batch risk management. Background Art

[0002] Monitoring and identifying abnormal user behavior is crucial in building marketing systems. By integrating user account activity information from multiple channels and regularly analyzing it according to pre-set monitoring rules, an efficient monitoring system can accurately identify and flag bad actors such as "scammers" and blacklisted individuals. This ensures the fairness and integrity of marketing activities and effectively mitigates the financial risks associated with malicious behavior. Furthermore, monitoring systems can enhance consumer satisfaction and loyalty, facilitate data-driven marketing strategy development, ensure regulatory compliance, flexibly respond to market dynamics, promote fair market competition, and strengthen the security of marketing systems.

[0003] In the existing technical solutions, in the marketing decision-making scenario, the method of regularly performing analysis based on preset monitoring rules has the following disadvantages.

[0004] Lack of timeliness: Regularly analyzed user account information cannot provide immediate feedback, resulting in losses by the time abnormal user behavior is identified.

[0005] Slow response: Regularly analyzed user account information cannot be used to take timely action on rapidly changing fraudulent activities, resulting in a lack of immediate response capabilities.

[0006] Data lag: Relying on historical user account information for analysis may not accurately reflect current market conditions and user behavior.

[0007] Processing capacity limitations: Traditional monitoring systems are usually unable to process large amounts of real-time data, limiting the depth and breadth of analysis.

[0008] Policy adjustment delay: There is a time lag between the conversion of analysis results and the adjustment of monitoring rules, which affects the timeliness and effectiveness of monitoring rules.

[0009] Limited predictive capabilities: The lack of ability to predict future trends and behaviors through real-time data limits the ability to foresee market changes.

[0010] User privacy exposure: Sensitive data is directly exposed in the analysis process of monitoring rules, which is prone to the risk of sensitive data leakage.

[0011] The formulation of monitoring rules lacks effective data support: When formulating monitoring rules, some thresholds are often defined based on experience and lack effective data support, which affects the accuracy of the analysis results.

[0012] To this end, a detection system and method for abnormal user behavior based on micro-batch risk management is proposed. Summary of the Invention

[0013] Based on this, it is necessary to provide a detection system and method for abnormal user behavior based on micro-batch risk management to address the above technical problems.

[0014] According to a first aspect of the present invention, a detection system for abnormal user behavior based on micro-batch risk management is provided, the system comprising: a metadata management module for constructing a dynamic mapping relationship between query conditions and fields of docking channel data based on initialization data script technology or page configuration technology, obtaining real-time user dynamic account information, and storing the real-time user dynamic account information in a streaming database; and using privacy computing technology to encrypt the real-time user dynamic account information stored in the target database to obtain encrypted user dynamic account information, and store the encrypted user dynamic account information in the target database; a real-time monitoring rule management module for creating and dynamically adjusting real-time analysis rules, and storing the real-time analysis rules in a cache database; and an event-driven The dynamic mechanism publishes the real-time analysis rules created or dynamically adjusted in the cache database; the real-time data analysis module is used to use Flink to read the user's real-time account movement information from the streaming database, and obtain the real-time analysis rules from the cache database, and determine whether the user's real-time account movement information exceeds the real-time analysis rules. If so, the user's real-time account movement information is determined to be abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the user's real-time account movement information is marked, and the marked user's real-time account movement information is stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection is terminated and the next detection is continued; the analysis result management module is used to visualize the user's encrypted account movement information.

[0015] Optionally, the metadata management module includes: a dynamic mapping relationship construction sub-module, which is used to construct a dynamic mapping relationship between the query conditions and the fields of the docking channel data based on the initialization data script technology or the page configuration technology; a streaming database sub-module, which is used to obtain the user's real-time account information based on the dynamic mapping relationship between the query conditions and the fields of the docking channel data, and store the user's real-time account information in the streaming database; an encryption processing sub-module, which is used to use privacy computing technology to encrypt the user's real-time account information stored in the target database, obtain the user's encrypted account information, and store the user's encrypted account information in the target database.

[0016] Optionally, the dynamic mapping relationship construction submodule includes: an initialization data script submodule, which is used to generate an SQL script containing query conditions based on the data type and English name field, write the SQL script into the streaming database, and execute the SQL script in the streaming database to build a dynamic mapping relationship between the query conditions and the fields of the docking channel data; a page configuration submodule, which is used to select the required query conditions based on the data type and English name field in the visual display interface, and build a dynamic mapping relationship between the query conditions and the fields of the docking channel data.

[0017] Optionally, the encryption processing submodule includes: an encryption rule construction submodule, which is used to construct multiple types of encryption rules according to the encrypted content value required by laws and regulations or encryption requirements, and each encryption rule corresponds to one type of encrypted content value; a sensitive data checking submodule, which is used to check the initial status of all information fields in the user's real-time account information according to the encrypted content value required by laws and regulations or encryption requirements, and obtain the checking status of each information field, the checking status includes whether it has been checked as sensitive data or not checked as sensitive data, and configure corresponding encryption rules for the information fields that have been checked as sensitive data, and desensitize the information fields that have been checked as sensitive data according to the configured encryption rules. The desensitization processing submodule is used to adopt the sensitive rules and machine learning model weighing technology to identify and process the information fields that are not checked as sensitive data, obtain the sensitivity score of the information fields that are not checked as sensitive data, compare the sensitive score with the preset score threshold, and judge whether the sensitivity score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rules are configured. The information field that is not checked as sensitive data is desensitized according to the configured encryption rules to obtain the encrypted dynamic account information of the second user. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

[0018] Optionally, the desensitizing processing submodule includes: a sensitive rule identification submodule, which is used to extract multiple types of sensitive rules according to the encrypted content value required by regulations or encryption requirements, and each of the sensitive rules forms a mapping relationship with a type of encrypted content value and a type of encryption rule; a first processing submodule, which is used to calculate the matching degree of all sensitive rules based on the information field that is not checked as sensitive data using the edit distance algorithm to obtain the matching degree of each sensitive rule, sort the matching degrees of the sensitive rules from high to low, and select the maximum matching degree; a second processing submodule, which is used to vectorize the information field that is not checked as sensitive data to obtain an information vector, input the information vector into a sensitivity assessment model, and output a sensitivity score corresponding to the information vector, and the sensitivity assessment model is based on quantified historical data The historical data set is generated after training the set, and the historical data set is constructed based on the quantified historical information fields and the corresponding sensitive rules; a comparison submodule is used to compare the maximum value of the matching degree with the sensitivity score, and determine whether the maximum value of the matching degree exceeds the sensitivity score. If so, the maximum value of the matching degree is used as the sensitive score, and if not, the sensitive score is used as the sensitive score; and the sensitive score is compared with a preset score threshold to determine whether the sensitive score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rule is configured. The information field that is not checked as sensitive data is desensitized by the configured encryption rule to obtain the second user's encrypted dynamic account information. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

[0019] Optionally, the real-time monitoring rule management module includes: a first management submodule, which is used to create real-time analysis rules according to the target business scenario requirements and behavior monitoring types, and store the created real-time analysis rules in the cache database; wherein, the target business scenario requirements and behavior monitoring types include "wool party" behavior types and high-risk operation behavior types; a second management submodule, which is used to analyze and calculate the historical user encrypted dynamic account information stored in the target database based on a mathematical and statistical model, obtain multiple statistical indicator values, and screen out at least one target statistical indicator value from the multiple statistical indicator values according to the target business scenario requirements and behavior monitoring types, obtain a target statistical indicator combination strategy, dynamically adjust the real-time analysis rules according to the target statistical indicator combination strategy, and store the dynamically adjusted real-time analysis rules in the cache database; an event-driven submodule, which is used to publish the real-time analysis rules created or dynamically adjusted in the cache database based on an event-driven mechanism.

[0020] Optionally, the real-time data analysis module includes: an acquisition submodule, used to use Flink to read the user's real-time account movement information from the streaming database, and obtain real-time analysis rules from the cache database; a judgment submodule, used to judge whether the user's real-time account movement information exceeds the real-time analysis rules. If so, the user's real-time account movement information is determined to be abnormal behavior data, and the user's real-time account movement information is marked according to the target business scenario requirements and behavior monitoring type, and the marked user's real-time account movement information is stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection is ended and the next detection is continued.

[0021] Optionally, the streaming database is one of MQ and Kafka.

[0022] Optionally, the cache database is one of Redis, MySQL, and HBase.

[0023] According to a second aspect of the present invention, a method for detecting abnormal user behavior based on micro-batch risk management is provided, comprising: constructing a dynamic mapping relationship between query conditions and fields of docking channel data according to initialization data script technology or page configuration technology through a metadata management module, obtaining real-time user dynamic account information, and storing the real-time user dynamic account information in a streaming database; and adopting privacy computing technology to encrypt the real-time user dynamic account information stored in a target database to obtain encrypted user dynamic account information, and store the encrypted user dynamic account information in the target database; creating and dynamically adjusting real-time analysis rules through a real-time monitoring rule management module, and storing the real-time analysis rules in a cache database; and based on an event-driven mechanism System, publish the real-time analysis rules created or dynamically adjusted in the cache database; use Flink through the real-time data analysis module to read the user's real-time account movement information from the streaming database, and obtain the real-time analysis rules from the cache database, and judge whether the user's real-time account movement information exceeds the real-time analysis rules. If so, the user's real-time account movement information is determined to be abnormal behavior data, and the user's real-time account movement information is marked according to the target business scenario requirements and behavior monitoring type. The marked user's real-time account movement information is stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, end the current detection and continue to the next detection; visualize the user's encrypted account movement information through the analysis result management module.

[0024] The beneficial effects of the present application are as follows: the present application provides a detection system and method for abnormal user behavior based on micro-batch risk management, which has the following beneficial effects: 1. Improved real-time performance: (1) Real-time data processing: Compared with the existing method of periodically analyzing user account information, the present application adopts streaming data processing, which can capture and process data in real time, immediately identify abnormal user behavior, avoid losses caused by analysis delays, and greatly improve timeliness; (2) Real-time effectiveness of rules: The created or dynamically adjusted real-time analysis rules can be synchronized to the real-time data analysis module through the event-driven mechanism. The real-time data analysis module obtains the real-time analysis rules in real time during the execution process, ensuring that the real-time analysis rules take effect immediately without waiting for the next analysis cycle, further improving the response speed; 2. Improved accuracy: (1) Latest data analysis: By processing the latest data in real time, this application can more accurately reflect the current market conditions and user behavior, avoiding data lag problems, thereby improving the accuracy and timeliness of analysis; (2) Dynamic adjustment rules: The target statistical indicator combination strategy can be dynamically adjusted according to the real-time business scenario requirements and behavior monitoring types to adapt to the ever-changing market environment, and can more accurately identify abnormal user behavior, effectively improving the accuracy of identification; (3) Anomaly detection based on mathematical statistics models: Compared with the existing empirically defined monitoring rules, the accuracy of real-time analysis rules is improved; 3. Enhanced flexibility: (1) Flexible configuration: Metadata management The management module supports flexible configuration of the dynamic mapping relationship between the fields of the docking channel data and the query conditions, so as to obtain the real-time account information of the user, which improves the flexibility of the system; (2) Custom rules: The real-time monitoring rule management module supports the definition of different real-time analysis rules according to the needs of different business scenarios and behavior monitoring types, and supports the addition and dynamic adjustment of real-time analysis rules to adapt to the needs of different business scenarios; 4. Security improvement: (1) Shorten the risk exposure time: Through real-time monitoring and rapid response, this system can effectively shorten the risk exposure time, reduce the probability of risk occurrence, ensure user experience, and improve system security; (2) Data support: The real-time account information of users who exceed the real-time analysis rules will be recorded in the target database to It can provide data support for marketing and other scenarios, helping companies to develop more accurate marketing strategies and reduce risks; (3) The introduction of privacy computing technology can realize the encryption of users' real-time dynamic account information stored in the target database to improve the security and compliance of the system; 5. Efficiency improvement: Using an event-driven mechanism, the creation and dynamic adjustment of real-time analysis rules are used as publishing events. In the event monitoring processing logic, the real-time analysis rule update function can be realized, and according to the system configuration, a variety of real-time analysis rule update methods can be realized, such as data updates of different cache databases such as Redis, MySQL, and HBase, which shortens the effective time of real-time analysis rules and further improves the overall efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 is an exemplary system architecture diagram to which the present application can be applied.

[0026] Figure 2 It is a structural diagram of an embodiment of a detection system for abnormal user behavior based on micro-batch risk management according to the present application.

[0027] Figure 3 This is a flowchart of an embodiment of a method for detecting abnormal user behavior based on micro-batch risk management according to the present application. DETAILED DESCRIPTION

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.

[0029] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0030] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0031] like Figure 1 As shown, system architecture 100 may include terminal devices 101, 102, 103, a network 104, and a server 105. Network 104 is a medium for providing communication links between terminal devices 101, 102, 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0032] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0033] Terminal devices 101, 102, and 103 can be various electronic devices with display screens and support web browsing, including but not limited to smartphones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III, Moving Picture Experts Group Audio Layer 3), MP4 (Moving Picture Experts Group Audio Layer IV, Moving Picture Experts Group Audio Layer 4) players, laptop computers, desktop computers, etc.

[0034] The server 105 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal devices 101 , 102 , and 103 .

[0035] It should be noted that the detection system for abnormal user behavior based on micro-batch risk management provided in the embodiment of the present application is generally set in the server / terminal device, and accordingly, the detection method for abnormal user behavior based on micro-batch risk management is generally executed by the server / terminal device.

[0036] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0037] Continue to refer Figure 2 , showing a schematic diagram of an embodiment of a system 200 for detecting abnormal user behavior based on micro-batch risk management according to the present application. By introducing technologies such as streaming data processing, event-driven mechanisms, privacy computing technology, and anomaly detection based on mathematical and statistical models, this system effectively addresses the issues of insufficient timeliness, slow response, and data lag associated with existing methods of periodically analyzing user account information. It achieves advantages such as real-time monitoring, rapid response, accurate identification, and flexible configuration, thereby providing strong support for enterprises to build a more comprehensive monitoring system for abnormal marketing user behavior. The system specifically includes: a metadata management module 201, a real-time monitoring rule management module 202, a real-time data analysis module 203, and an analysis result management module 204.

[0038] The metadata management module 201 is used to construct a dynamic mapping relationship between query conditions and fields of docking channel data based on initialization data script technology or page configuration technology, obtain real-time user account information, and store the real-time user account information in a streaming database; and use privacy computing technology to encrypt the real-time user account information stored in the target database to obtain encrypted user account information, and store the encrypted user account information in the target database.

[0039] According to one embodiment of the present application, the metadata management module 201 specifically includes: a dynamic mapping relationship construction sub-module, which is used to construct a dynamic mapping relationship between the query conditions and the fields of the docking channel data based on the initialization data script technology or the page configuration technology; a streaming database sub-module, which is used to obtain the user's real-time account information based on the dynamic mapping relationship between the query conditions and the fields of the docking channel data, and store the user's real-time account information in the streaming database; an encryption processing sub-module, which is used to use privacy computing technology to encrypt the user's real-time account information stored in the target database, obtain the user's encrypted account information, and store the user's encrypted account information in the target database.

[0040] According to one embodiment of the present application, the dynamic mapping relationship construction sub-module includes: an initialization data script sub-module, which is used to generate an SQL script containing query conditions based on the data type and English name field, write the SQL script to the streaming database, and execute the SQL script in the streaming database to build a dynamic mapping relationship between the query conditions and the fields of the docking channel data; a page configuration sub-module, which is used to select the required query conditions based on the data type and English name field in the visual display interface, and build a dynamic mapping relationship between the query conditions and the fields of the docking channel data.

[0041] According to one embodiment of the present application, constructing a dynamic mapping relationship between query conditions and fields of docking channel data by initializing a data script submodule may include the following steps.

[0042] Prepare the SQL script: (1) Common data is the cardholder field information, represented by "C_", such as "C_ field", which is generated by batch index interception; (2) Queue data field information is represented by "Q_", such as "Q_ field", which is the upstream data provided in the row and used for event definition; (3) Aggregate data field information (product), distinguished by type, paramType=y.

[0043] 2. Execute SQL script: Execute SQL script in the streaming database.

[0044] 3. Data query: Provides a query interface to query the three types of inserted data based on the English name field.

[0045] According to one embodiment of the present application, a dynamic mapping relationship between query conditions and fields of docking channel data is constructed through a page configuration submodule, including the following steps: in a visual display interface, multiple candidate lists (i.e., query conditions) are set, each candidate list includes a field description of a data type and a corresponding English name field, and the required query conditions can be selected by checking the required query conditions to construct a dynamic mapping relationship between the query conditions and fields of docking channel data.

[0046] According to one embodiment of the present application, the streaming database submodule is one of MQ and Kafka.

[0047] According to one embodiment of the present application, the encryption processing submodule includes: an encryption rule construction submodule, which is used to construct multiple types of encryption rules according to the encrypted content value required by laws and regulations or encryption requirements, and each encryption rule corresponds to one type of encrypted content value; a sensitive data checking submodule, which is used to check the initial status of all information fields in the user's real-time account information according to the encrypted content value required by laws and regulations or encryption requirements, and obtain the checking status of each information field, the checking status including whether it has been checked as sensitive data or not checked as sensitive data, and configure corresponding encryption rules for the information fields that have been checked as sensitive data, and check the information fields that have been checked as sensitive data according to the configured encryption rules. Desensitization processing is performed to obtain the encrypted dynamic account information of the first user; a desensitization processing sub-module is used to adopt sensitive rules and machine learning model weighing technology to identify and process the information fields that are not checked as sensitive data, obtain the sensitivity score of the information fields that are not checked as sensitive data, compare the sensitivity score with the preset score threshold, and determine whether the sensitivity score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rules are configured. The information field that is not checked as sensitive data is desensitized according to the configured encryption rules to obtain the encrypted dynamic account information of the second user. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

[0048] According to one embodiment of the present application, the desensitization processing submodule includes: a sensitive rule identification submodule, which is used to extract multiple types of sensitive rules according to the encrypted content value required by regulations or encryption requirements, and each of the sensitive rules forms a mapping relationship with a type of encrypted content value and a type of encryption rule; a first processing submodule, which is used to calculate the matching degree of all sensitive rules based on the information field that is not checked as sensitive data, using the edit distance algorithm to obtain the matching degree of each sensitive rule, sort the matching degrees of the sensitive rules from high to low, and select the maximum matching degree; a second processing submodule, which is used to vectorize the information field that is not checked as sensitive data to obtain an information vector, input the information vector into the sensitivity assessment model, and output the sensitivity score of the corresponding information vector. The sensitivity assessment model is based on the quantized historical data. The historical data set is generated after training, and the historical data set is constructed based on the quantified historical information fields and the corresponding sensitive rules; a comparison submodule is used to compare the maximum value of the matching degree with the sensitivity score, and determine whether the maximum value of the matching degree exceeds the sensitivity score. If so, the maximum value of the matching degree is used as the sensitive score; if not, the sensitive score is used as the sensitive score; and the sensitive score is compared with a preset score threshold to determine whether the sensitive score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rule is configured. The information field that is not checked as sensitive data is desensitized by the configured encryption rule to obtain the second user's encrypted account information. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

[0049] According to one embodiment of the present application, the real-time account information of users that have completed the detection can be used in multiple scenarios such as subsequent marketing, equity distribution, and user analysis. The present application also provides a method for encrypting the real-time account information of users using privacy computing technology, which includes the following steps.

[0050] First, in the metadata management module 201, a "Is it sensitive data?" checkbox is set to check the initial status of all information fields in the user's real-time account information. According to regulations, encrypted content values that must not be easily disclosed or have confidentiality requirements can be checked as sensitive data for the corresponding information fields and configured with corresponding encryption rules. For example, the middle four digits of the mobile phone number field are obfuscated to ensure that these sensitive fields can be accurately identified and protected during the processing. For information fields that are not checked as sensitive data, sensitive data that may exist in their content can be desensitized using sensitivity rules and machine learning model weighing technology.

[0051] Secondly, based on the encrypted content values required by regulations or encryption needs, multiple types of sensitive rules are extracted. For example, the sensitive rule corresponding to the ID card number is a continuous 18-digit number. Common sensitive rules include, but are not limited to, identity identification (such as ID card number, passport number, driver's license number, etc.), financial data (such as bank account number, transaction amount, payment slip number, etc.), and private contact (such as mobile phone number, email address, home address, etc.). The Levenshtein distance algorithm is used to measure the degree of match between the information field content and each sensitive rule, and the matching degree of each sensitive rule is obtained. The maximum value of all matching degrees is taken as the evaluation of the fit between the information field content and each sensitive rule. It should be noted that the Levenshtein distance algorithm used in this application is a prior art and will not be described in detail here.

[0052] Next, the information fields are vectorized and converted into a data format that can be efficiently identified and analyzed by machine learning models. This information vector is then fed into the sensitivity assessment model to generate a sensitivity score, which comprehensively reflects the characteristic performance and value assessment of the vectorized data in the sensitivity assessment model. The sensitivity assessment model is generated through training based on a quantized historical dataset, which is constructed based on the quantized historical information fields and corresponding sensitivity rules.

[0053] Finally, by weighing the maximum value of the matching degree and the sensitivity score, the maximum value of the two is taken as the sensitivity score for the final judgment. If the sensitivity score is greater than the preset score threshold (such as 65%), the information field is determined to be sensitive data, and the corresponding encryption rules are configured. The information field is desensitized through the configured encryption rules to achieve the goal of "calculable but invisible", so that the monitoring result data can provide strong security data support for marketing, customer labeling and other scenarios.

[0054] The real-time monitoring rule management module 202 is used to create and dynamically adjust real-time analysis rules and store the real-time analysis rules in the cache database; and publish the real-time analysis rules created or dynamically adjusted in the cache database based on an event-driven mechanism.

[0055] According to one embodiment of the present application, the real-time monitoring rule management module 202 includes: a first management sub-module, which is used to create real-time analysis rules according to the target business scenario requirements and behavior monitoring types, and store the created real-time analysis rules in the cache database; wherein, the target business scenario requirements and behavior monitoring types include "cash-back party" behavior types and high-risk operation behavior types; a second management sub-module, which is used to analyze and calculate the historical user encrypted dynamic account information stored in the target database based on a mathematical and statistical model, obtain multiple statistical indicator values, and screen out at least one target statistical indicator value from the multiple statistical indicator values according to the target business scenario requirements and behavior monitoring types, obtain a target statistical indicator combination strategy, dynamically adjust the real-time analysis rules according to the target statistical indicator combination strategy, and store the dynamically adjusted real-time analysis rules in the cache database; an event-driven sub-module, which is used to publish the real-time analysis rules created or dynamically adjusted in the cache database based on an event-driven mechanism.

[0056] According to one embodiment of the present application, behavior monitoring types are classified in detail according to the needs of the target business scenario, including but not limited to "wool party" behavior types and high-risk operation behavior types. For each behavior monitoring type, the query conditions to be monitored will be clearly defined, and corresponding maintenance and updates will be performed in the metadata management module 201. Taking the "wool party" behavior type as an example, it is usually focused on monitoring the user's active browsing pages, number of clicks, page dwell time, activity participation frequency, and use of activity rights and interests and other real-time dynamic account information. Therefore, reasonable real-time analysis rules will be set for these monitoring data fields. Alarm thresholds of the rule, such as, when it is detected that the user's activity participation frequency exceeds 5 times and the activity page dwell time is less than 1 second, the system will mark the user's real-time dynamic account information, that is, mark the user as a "wool party" user, and store the user's real-time dynamic account information in the "wool party" database. In addition, taking high-risk operation behavior types as an example, when it is detected that the time difference of the user's commonly used device changes is less than 1 day and the IP address information when logging in to the account changes more than 3 times a day, the system will mark the user's real-time account information, that is, mark the user as a high-risk user, and store the user's real-time account information in a high-risk database. These real-time account information of users stored in the "wool party" database or the high-risk database can provide strong data support for subsequent marketing, equity distribution, user analysis and other scenarios. For example, in a marketing campaign, the participation qualifications of "wool party" users and high-risk users can be eliminated to ensure the fairness and effectiveness of the campaign.

[0057] According to one embodiment of the present application, by providing a data analysis method based on mathematical statistics models, it is possible to rigorously and scientifically analyze historical encrypted user account information, establish a normal range model, and obtain multiple statistical indicators, such as mean, median, and standard deviation, to provide data support for the dynamic adjustment of real-time analysis rules. Taking transaction amount analysis as an example, it is necessary to focus on multi-dimensional real-time user account information, including transaction amount data such as user consumption, transfer, and top-up amounts, as well as the number of transactions within different time spans (e.g., one day, one week, and one month) (i.e., transaction frequency data). In actual business scenarios, when setting alarm thresholds for real-time analysis rules for wool-dang users, the number of activity page views, number of hotspot clicks, and page dwell time monitoring items can refer to the median combined with a small range of fluctuations (e.g., median ± 15% of the median) to set the alarm threshold range for the real-time analysis rule. This method aligns with the behavioral habits of most users and reduces anomaly misjudgments. For example, when setting alarm thresholds for real-time analysis rules for high-risk users, an appropriate statistical indicator combination strategy can be selected based on business robustness requirements. If the business focuses on preventing large abnormal transactions, the normal high value can be defined as the upper limit of the mean plus several times the standard deviation (such as the mean + 3 times the standard deviation). Since extremely large transactions tend to increase the standard deviation, this method can be used to identify rare high-value anomalies. If a universal intermediate state measurement is pursued, the median combined with a small range of fluctuations (such as the median ± 10% of the median) can be used to set the alarm threshold range of the real-time analysis rules to meet the regular recharge and consumption habits of most users and reduce abnormal misjudgments.

[0058] According to one embodiment of the present application, the created or dynamically adjusted real-time analysis rules will be synchronously stored in the cache database, which can support multiple options, including but not limited to Redis, MySQL, HBase, etc. Based on the event-driven mechanism (the event-driven mechanism can adopt the event-driven mechanism provided by the SpringBoot framework), the creation, dynamic adjustment and other operations of the real-time analysis rules are used as published events. In the event monitoring processing logic, the real-time analysis rule update function can be implemented to ensure that the newly added / modified real-time analysis rules take effect immediately.

[0059] The real-time data analysis module 203 is used to read the user's real-time account activity information from the streaming database using Flink, and obtain the real-time analysis rules from the cache database to determine whether the user's real-time account activity information exceeds the real-time analysis rules. If so, the user's real-time account activity information is determined to be abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the user's real-time account activity information is marked and stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection is terminated and the next detection is continued.

[0060] According to one embodiment of the present application, the real-time data analysis module 203 includes: an acquisition submodule, which is used to use Flink to read the user's real-time account movement information from the streaming database and obtain the real-time analysis rules from the cache database; a judgment submodule, which is used to judge whether the user's real-time account movement information exceeds the real-time analysis rules. If so, the user's real-time account movement information is determined to be abnormal behavior data, and the user's real-time account movement information is marked according to the target business scenario requirements and behavior monitoring type, and the marked user's real-time account movement information is stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection is ended and the next detection is continued.

[0061] According to one embodiment of the present application, the present application deploys a Flink engineering package developed based on the Java language on a Flink cluster, using Kafka as a data source. Each time new user real-time account movement information is received, the real-time analysis rules are obtained from the cache database, and it is determined whether the user's real-time account movement information exceeds the real-time analysis rules. If it exceeds, the user's real-time account movement information is determined to be abnormal behavior data, and the user's real-time account movement information is recorded in the relevant database according to the behavior monitoring type to which the user's real-time account movement information belongs.

[0062] The analysis result management module 204 is used to visually display the user's encrypted account information.

[0063] According to embodiments of the present disclosure, any multiple modules of the metadata management module 201, the real-time monitoring rule management module 202, the real-time data analysis module 203, and the analysis result management module 204 can be combined into a single module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the metadata management module 201, the real-time monitoring rule management module 202, the real-time data analysis module 203, and the analysis result management module 204 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or can be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the metadata management module 201, the real-time monitoring rule management module 202, the real-time data analysis module 203 and the analysis result management module 204 can be at least partially implemented as a computer program module, which can perform corresponding functions when executed.

[0064] The electronic device according to an embodiment of the present application includes a processor, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage portion into a random access memory (RAM). The processor may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a dedicated microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor may also include onboard memory for caching purposes. The processor may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present application.

[0065] The RAM stores various programs and data required for the operation of the electronic device. The processor, ROM, and RAM are connected to each other via a bus. The processor executes the programs in the ROM and / or RAM to perform the various operations of the method flow according to the embodiments of the present application. It should be noted that the programs may also be stored in one or more memories other than ROM and RAM. The processor may also execute the programs stored in the one or more memories to perform the various operations of the method flow according to the embodiments of the present application.

[0066] According to an embodiment of the present application, the electronic device may further include an input / output (I / O) interface, which is also connected to the bus. The electronic device may further include one or more of the following components connected to the I / O interface: an input portion including a keyboard, a mouse, etc.; an output portion including a cathode ray tube (CRT), a liquid crystal display (LCD), a speaker, etc.; a storage portion including a hard disk, etc.; and a communication portion including a network interface card such as a LAN card or a modem. The communication portion performs communication processing via a network such as the Internet. A drive is also connected to the I / O interface as needed. Removable media, such as magnetic disks, optical disks, magneto-optical disks, semiconductor memories, etc., are installed in the drive as needed, so that computer programs read therefrom can be installed into the storage portion as needed.

[0067] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of this application is implemented.

[0068] According to embodiments of the present application, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present application, a computer-readable storage medium may include the ROM and / or RAM described above, and / or one or more memories other than ROM and RAM.

[0069] The present application also includes a computer program product comprising a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to cause the computer system to implement the item recommendation method provided in the present application.

[0070] When the computer program is executed by the processor, the above functions defined in the system / device of the embodiment of the present application are performed. According to the embodiment of the present application, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0071] In one embodiment, the computer program may be stored on a tangible storage medium, such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal over a network medium, downloaded and installed via a communication component, and / or installed from a removable medium. The program code contained in the computer program may be transmitted using any suitable network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0072] In such an embodiment, the computer program can be downloaded and installed from a network via the communication portion, and / or installed from a removable medium. When the computer program is executed by the processor, the above-mentioned functions defined in the system of the embodiment of the present application are performed. According to the embodiment of the present application, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0073] According to an embodiment of the present application, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0074] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a method for detecting abnormal user behavior based on micro-batch risk management. Figure 2 The system embodiment shown corresponds to the embodiment shown.

[0075] like Figure 3 As shown, the present embodiment describes a method for detecting abnormal user behavior based on micro-batch risk management, which includes the following steps.

[0076] S1. Through the metadata management module, based on the initialization data script technology or page configuration technology, a dynamic mapping relationship between the query conditions and the fields of the docking channel data is constructed to obtain the user's real-time account information, and store the user's real-time account information in the streaming database; and using privacy computing technology, the user's real-time account information stored in the target database is encrypted to obtain the user's encrypted account information, and the user's encrypted account information is stored in the target database.

[0077] S2. Create and dynamically adjust real-time analysis rules through the real-time monitoring rule management module, and store the real-time analysis rules in the cache database; and publish the real-time analysis rules created or dynamically adjusted in the cache database based on the event-driven mechanism.

[0078] S3. The real-time data analysis module uses Flink to read the user's real-time account activity information from the streaming database, and obtains the real-time analysis rules from the cache database to determine whether the user's real-time account activity information exceeds the real-time analysis rules. If so, the user's real-time account activity information is determined to be abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the user's real-time account activity information is marked and stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection ends and the next detection continues.

[0079] S4. Visually display the user's encrypted account information through the analysis result management module.

[0080] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0081] The above content is a further detailed description of the present invention in conjunction with specific embodiments, and the specific implementation of the present invention cannot be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A detection system for abnormal user behavior based on micro-batch risk management, characterized by: The system includes: The metadata management module is used to construct a dynamic mapping relationship between query conditions and fields of docking channel data based on initialization data script technology or page configuration technology, obtain real-time user account information, and store the real-time user account information in a streaming database; and use privacy computing technology to encrypt the real-time user account information stored in the target database to obtain encrypted user account information, and store the encrypted user account information in the target database; The real-time monitoring rule management module is used to create and dynamically adjust real-time analysis rules and store them in the cache database; and based on the event-driven mechanism, publish the real-time analysis rules created or dynamically adjusted in the cache database; The real-time data analysis module uses Flink to read real-time user account information from the streaming database and obtain real-time analysis rules from the cache database. It determines whether the real-time user account information exceeds the real-time analysis rules. If so, it is determined that the real-time user account information is abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the real-time user account information is marked and stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection ends and the next detection continues. Analysis result management module, used to visualize user encrypted account information; The metadata management module includes: An encryption processing submodule, configured to encrypt the user's real-time account information stored in the target database using privacy computing technology to obtain encrypted user account information and store the encrypted user account information in the target database; The encryption processing submodule includes: An encryption rule construction submodule is used to construct multiple types of encryption rules according to the encrypted content value required by laws and regulations or encryption requirements, each encryption rule corresponding to a type of encrypted content value; A sensitive data selection submodule is configured to select the initial status of all information fields in the user's real-time account information based on the encrypted content value required by regulations or encryption requirements, obtain the selection status of each information field, wherein the selection status includes whether the information field is selected as sensitive data or not selected as sensitive data, configure corresponding encryption rules for the information fields selected as sensitive data, and perform desensitization processing on the information fields selected as sensitive data using the configured encryption rules to obtain the first user's encrypted account information; The desensitization processing submodule is used to use sensitive rules and machine learning models to identify and process information fields that are not checked as sensitive data, obtain the sensitivity score of the information fields that are not checked as sensitive data, compare the sensitivity score with the preset score threshold, and determine whether the sensitivity score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rules are configured. The information field that is not checked as sensitive data is desensitized according to the configured encryption rules to obtain the encrypted account information of the second user. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

2. A detection system for abnormal user behavior based on micro-batch risk management according to claim 1, characterized in that: The metadata management module also includes: The dynamic mapping relationship construction submodule is used to construct the dynamic mapping relationship between the query conditions and the fields of the docking channel data based on the initialization data script technology or page configuration technology; The streaming database submodule is used to obtain real-time user account information based on the query conditions and the dynamic mapping relationship between the fields of the docking channel data, and store the real-time user account information in the streaming database.

3. A detection system for abnormal user behavior based on micro-batch risk management according to claim 2, characterized in that: The dynamic mapping relationship construction submodule includes: The initialization data script submodule is used to generate an SQL script containing query conditions based on the data type and English name field, write the SQL script to the streaming database, and execute the SQL script in the streaming database to build a dynamic mapping relationship between the query conditions and the fields of the docking channel data; The page configuration submodule is used to select the required query conditions based on the data type and English name field in the visual display interface, and to build a dynamic mapping relationship between the query conditions and the fields of the docking channel data.

4. The system for detecting abnormal user behavior based on micro-batch risk management according to claim 1 is characterized in that: The desensitization processing submodule includes: A sensitive rule identification submodule is used to extract multiple types of sensitive rules based on the encrypted content value required by regulations or encryption requirements, and each sensitive rule is mapped to a type of encrypted content value and a type of encryption rule; The first processing submodule is configured to calculate the matching degree of all sensitive rules using an edit distance algorithm based on information fields that are not selected as sensitive data, obtain the matching degree of each sensitive rule, sort the matching degrees of the sensitive rules from high to low, and select the one with the maximum matching degree; A second processing submodule is configured to vectorize information fields not selected as sensitive data to obtain information vectors, input the information vectors into a sensitivity assessment model, and output a sensitivity score corresponding to the information vector. The sensitivity assessment model is generated by training based on a quantized historical data set, which is constructed based on the quantized historical information fields and corresponding sensitivity rules. The comparison submodule is used to compare the maximum value of the matching degree with the sensitivity score to determine whether the maximum value of the matching degree exceeds the sensitivity score. If so, the maximum value of the matching degree is used as the sensitivity score; if not, the sensitivity score is used as the sensitivity score; and the sensitivity score is compared with a preset score threshold to determine whether the sensitivity score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rules are configured. The information field that is not checked as sensitive data and is determined to be sensitive data is desensitized according to the configured encryption rules to obtain the encrypted account information of the second user. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

5. The system for detecting abnormal user behavior based on micro-batch risk management according to claim 1 is characterized in that: The real-time monitoring rule management module includes: A first management submodule is configured to create real-time analysis rules based on target business scenario requirements and behavior monitoring types, and store the created real-time analysis rules in a cache database; wherein the target business scenario requirements and behavior monitoring types include "wool party" behavior types and high-risk operation behavior types; The second management submodule is configured to analyze and calculate historical user encrypted dynamic account information stored in the target database based on a mathematical statistics model to obtain multiple statistical indicator values. Based on the target business scenario requirements and behavior monitoring type, at least one target statistical indicator value is selected from the multiple statistical indicator values to obtain a target statistical indicator combination strategy. Based on the target statistical indicator combination strategy, the real-time analysis rules are dynamically adjusted, and the dynamically adjusted real-time analysis rules are stored in the cache database. The event-driven submodule is used to publish real-time analysis rules created or dynamically adjusted in the cache database based on the event-driven mechanism.

6. The system for detecting abnormal user behavior based on micro-batch risk management according to claim 1 is characterized in that: The real-time data analysis module includes: The acquisition submodule is used to read real-time user account information from the streaming database using Flink and obtain real-time analysis rules from the cache database; The judgment submodule is used to determine whether the user's real-time account movement information exceeds the real-time analysis rules. If so, the user's real-time account movement information is determined to be abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the user's real-time account movement information is marked, and the marked user's real-time account movement information is stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection is terminated and the next detection is continued.

7. The system for detecting abnormal user behavior based on micro-batch risk management according to claim 1 is characterized in that: The streaming database is one of MQ and Kafka.

8. The system for detecting abnormal user behavior based on micro-batch risk management according to claim 1 is characterized in that: The cache database is one of Redis, MySQL, and HBase.

9. A method for detecting abnormal user behavior based on micro-batch risk management, characterized in that: include: The metadata management module constructs a dynamic mapping relationship between query conditions and fields of docking channel data using initialization data script technology or page configuration technology to obtain real-time user account information and store it in a streaming database. Furthermore, privacy computing technology is used to encrypt the real-time user account information stored in the target database to obtain encrypted user account information, which is then stored in the target database. Create and dynamically adjust real-time analysis rules through the real-time monitoring rule management module, and store the real-time analysis rules in the cache database; And based on the event-driven mechanism, publish the real-time analysis rules created or dynamically adjusted in the cache database; The real-time data analysis module uses Flink to read real-time user account information from the streaming database and obtain real-time analysis rules from the cache database. It determines whether the real-time user account information exceeds the real-time analysis rules. If so, it is determined that the real-time user account information is abnormal behavior data. According to the target business scenario requirements and behavior monitoring type, the real-time user account information is marked and stored in the target database corresponding to the target business scenario requirements and behavior monitoring type. If not, the current detection ends and the next detection continues. Visually display user encrypted account information through the analysis result management module; The metadata management module includes: An encryption processing submodule is used to encrypt the user's real-time account information stored in the target database using privacy computing technology to obtain the user's encrypted account information and store the encrypted account information in the target database; The encryption processing submodule includes: An encryption rule construction submodule is used to construct multiple types of encryption rules according to the encrypted content value required by laws and regulations or encryption requirements, each encryption rule corresponding to a type of encrypted content value; A sensitive data selection submodule is configured to select the initial status of all information fields in the user's real-time account information based on the encrypted content value required by regulations or encryption requirements, obtain the selection status of each information field, wherein the selection status includes whether the information field is selected as sensitive data or not selected as sensitive data, configure corresponding encryption rules for the information fields selected as sensitive data, and perform desensitization processing on the information fields selected as sensitive data using the configured encryption rules to obtain the first user's encrypted account information; The desensitization processing submodule is used to use sensitive rules and machine learning models to identify and process information fields that are not checked as sensitive data, obtain the sensitivity score of the information fields that are not checked as sensitive data, compare the sensitivity score with the preset score threshold, and determine whether the sensitivity score exceeds the preset score threshold. If so, the information field that is not checked as sensitive data is determined to be sensitive data, and the corresponding encryption rules are configured. The information field that is not checked as sensitive data is desensitized according to the configured encryption rules to obtain the encrypted account information of the second user. If not, the current decryption processing operation is terminated and the next decryption processing operation is continued.

Citation Information

Patent Citations

  • Abnormal identity recognition method and device

    CN113887911A

  • Object recognition method, device and equipment, readable storage medium and program product

    CN115829073A