Risk operation identification method, behavior record acquisition method and weight distribution method

Through natural language processing technology and adaptive weight adjustment model, multi-dimensional behavior data is extracted from SMS behavior records, abnormal coefficients and risk operation scores are calculated, and the problem of the failure of existing technology to identify social platform fraud is solved, and the effective identification and prevention of abnormal behaviors of Internet accounts is achieved.

CN119941266AActive Publication Date: 2025-05-06CHINA UNICOM DIGITAL TECNOLOGY CO LTD +2

Patent Information

Application Number
CN202411795389.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-06
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

Existing fraud identification technology cannot effectively identify fraud activities conducted through social platforms, especially on Internet platforms, where fraudsters use social media accounts to commit fraud, making it difficult for victims to identify their true identities.

Method used

Through a risk operation identification method, natural language processing technology is used to extract the basic information database from SMS behavior records, extract multi-dimensional behavior data of the target mobile phone number, calculate multiple abnormal coefficients, and calculate the risk operation score through the adaptive weight adjustment model to predict the risk operation probability of users when registering an application.

Benefits of technology

It has achieved effective identification and prevention of fraud activities conducted through social platforms, improved the ability to identify abnormal behaviors of Internet accounts, enhanced the accuracy of risk operation prediction, and protected user safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119941266A_ABST
    Figure CN119941266A_ABST
Patent Text Reader

Abstract

The invention provides a risk operation identification method, a behavior record acquisition method and a weight distribution method, and relates to the technical field of Internet. The risk operation identification method comprises the following steps: when a short message behavior record is obtained, obtaining a basic information base according to the short message behavior record through a natural language processing technology; extracting the multi-dimensional behavior data of the target mobile phone number from a large network information acquisition module, and obtaining a plurality of abnormal coefficients of the target mobile phone number according to the multi-dimensional behavior data and a preset entity mapping relationship among the multi-dimensional behavior data; inputting at least one of the plurality of abnormal coefficients into a preset adaptive weight adjustment model to obtain a plurality of weights output by the adaptive weight adjustment model; and calculating a risk operation score of the target mobile phone number according to the plurality of abnormal coefficients and the plurality of weights. The technical problem that an existing fraud recognition technology cannot effectively recognize fraud activities conducted through a social platform can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a risk operation identification method, a behavior record acquisition method, and a weight distribution method. Background Art

[0002] With the rapid development of social networks and instant messaging platforms, fraudsters have gradually turned to Internet platforms to carry out fraudulent activities. Compared with traditional communication methods such as telephone and text messages, Internet fraud uses more hidden, widespread and low-cost social platforms. Fraudsters register fake social accounts and use instant messaging tools such as WeChat to commit fraud. Victims often find it difficult to identify their true identities and are deceived.

[0003] Existing fraud identification technologies focus on traditional telephone communications and text messaging channels. For fraudulent activities conducted through phone calls or text messages, existing technologies can identify some abnormal situations and issue warnings in a timely manner by analyzing call records, text message content, and call patterns. Operators also use certain anti-fraud measures to monitor and intercept suspicious phone and text message behaviors, thereby effectively curbing some fraudulent activities.

[0004] The above fraud identification technologies do not have the ability to monitor and analyze the behavior of Internet accounts, nor can they effectively identify fraudulent activities conducted through social platforms. Summary of the invention

[0005] The present application provides a risk operation identification method, a behavior record acquisition method and a weight distribution method to solve the technical problem that existing fraud identification technology cannot effectively identify fraud activities conducted through social platforms.

[0006] In a first aspect, the present application provides a method for identifying risky operations, which is applied to a correlation analysis module and includes:

[0007] When the SMS behavior record is obtained, a basic information database is obtained according to the SMS behavior record through natural language processing technology; wherein the basic information database includes the target mobile phone number and the target application registered by the target mobile phone number through SMS; the SMS behavior record is obtained by the large network information collection module according to the SMS registration behavior keywords;

[0008] Extracting the multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtaining multiple abnormal coefficients of the target mobile phone number based on the multi-dimensional behavior data and the preset entity mapping relationship between the multi-dimensional behavior data; wherein each of the abnormal coefficients is used to indicate the abnormal probability of the behavior data of the corresponding dimension;

[0009] Inputting at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model;

[0010] The risk operation score of the target mobile phone number is calculated based on the multiple abnormal coefficients and the multiple weights, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application according to the risk operation score.

[0011] In one possible design, the multiple abnormality coefficients include a device behavior abnormality coefficient, a communication behavior abnormality coefficient, a network behavior abnormality coefficient, and an account registration behavior abnormality coefficient.

[0012] In a possible design, inputting at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model includes:

[0013] Input the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient and the account registration behavior abnormality coefficient into a preset adaptive weight adjustment model, and obtain a first weight corresponding to the device behavior abnormality coefficient, a second weight corresponding to the communication behavior abnormality coefficient, and a third weight corresponding to the network behavior abnormality coefficient output by the adaptive weight adjustment model;

[0014] The step of calculating the risk operation score of the target mobile phone number according to the multiple abnormal coefficients and the multiple weights includes:

[0015] Performing weighted calculation on the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient, and the first weight, the second weight, and the third weight to obtain a weighted score;

[0016] A risk operation score is calculated based on the weighted score and the account registration behavior abnormality coefficient; wherein the risk operation score is equal to the product of the weighted score and the account registration behavior abnormality coefficient.

[0017] In one possible design, the multi-dimensional behavior data includes user information data, device access data, call calling and called data, SMS sending and receiving data, server access data and account registration data;

[0018] The method of obtaining a plurality of abnormal coefficients of the target mobile phone number based on the multi-dimensional behavior data and the preset entity mapping relationship between the multi-dimensional behavior data includes:

[0019] Obtaining the device behavior abnormality coefficient according to the user information data, the device access data, and a first mapping relationship between the user information data and the device access data;

[0020] Obtaining the communication behavior abnormality coefficient according to the user information data, the call calling and called data, the text message sending and receiving data, and a second mapping relationship between the user information data, the call calling and called data, and the text message sending and receiving data;

[0021] Obtaining the network behavior abnormality coefficient according to the user information data, the server access data, and a third mapping relationship between the user information data and the server access data;

[0022] The account registration behavior abnormality coefficient is obtained according to the user information data, the SMS sending and receiving data, the account registration data, and a fourth mapping relationship among the user information data, the SMS sending and receiving data, and the account registration data.

[0023] In a possible design, after calculating the risk operation score of the target mobile phone number according to the multiple abnormal coefficients and the multiple weights, the method further includes:

[0024] When the risk operation score is greater than a preset score threshold, the target mobile phone number is marked; wherein the marked target mobile phone number is used to indicate that the user corresponding to the target mobile phone number performs a risk operation when registering the target application.

[0025] In a possible design, when the SMS behavior record is obtained, a basic information database is obtained according to the SMS behavior record by using natural language processing technology, including:

[0026] By using the natural language processing technology, the SMS behavior record is converted into structured text;

[0027] Through entity recognition technology, the mobile phone number, SMS type and application of each SMS in the structured SMS behavior record are identified and extracted;

[0028] By applying text classification technology, according to the mobile phone number, SMS type and application of each SMS, SMS of registration type is screened out;

[0029] The basic information database is obtained according to the SMS type being a registration type SMS.

[0030] In a possible design, obtaining the basic information database according to the SMS type being a registration type SMS includes:

[0031] By using a preset industry SMS library, a first SMS content including SMS registration behavior is screened out from the SMS of the registration type; wherein the industry SMS library stores keywords for application registration;

[0032] According to a preset application whitelist, a second SMS content is screened out from the first SMS content, and the basic information library is obtained according to the second SMS content.

[0033] In a second aspect, the present application provides a behavior record acquisition method, which is applied to a large network information collection module, including:

[0034] According to the SMS registration behavior keywords, SMS are periodically screened to obtain SMS behavior records; wherein the SMS registration behavior keywords are issued by the feature issuing module; the SMS behavior records are used in the risk operation identification method provided in the first aspect of the present application;

[0035] The SMS behavior record is sent to the correlation analysis module.

[0036] In a third aspect, the present application provides a weight allocation method, which is applied to a cloud platform, in which the adaptive weight adjustment model in the risk operation identification method provided in the first aspect of the present application is deployed, including:

[0037] When obtaining at least one abnormal coefficient input by the association analysis module, assigning an initial weight to each abnormal coefficient;

[0038] Adjusting the multiple initial weights to obtain the weight of each abnormal coefficient;

[0039] The weight of each abnormal coefficient is sent to the association analysis module.

[0040] In a fourth aspect, the present application provides an association analysis module, including:

[0041] The basic information database acquisition module is used to obtain the basic information database according to the SMS behavior record by natural language processing technology when the SMS behavior record is obtained; wherein the basic information database includes the target mobile phone number and the target application registered by the target mobile phone number through SMS; the SMS behavior record is obtained by the large network information collection module according to the SMS registration behavior keywords;

[0042] An abnormal coefficient acquisition module is used to extract the multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtain multiple abnormal coefficients of the target mobile phone number according to the multi-dimensional behavior data and the preset entity mapping relationship between the multi-dimensional behavior data; wherein each of the abnormal coefficients is used to indicate the abnormal probability of the behavior data of the corresponding dimension;

[0043] A weight acquisition module, used for inputting at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model;

[0044] The risk operation score acquisition module is used to calculate the risk operation score of the target mobile phone number based on the multiple abnormal coefficients and the multiple weights, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application based on the risk operation score.

[0045] In a fifth aspect, the present application provides a large network information collection module, including:

[0046] A short message behavior record acquisition module, used to periodically filter short messages according to short message registration behavior keywords to obtain short message behavior records; wherein the short message registration behavior keywords are issued by the feature issuing module; the short message behavior records are used in the association analysis module provided in the fourth aspect of the present application;

[0047] The SMS behavior record sending module is used to send the SMS behavior record to the correlation analysis module.

[0048] In a sixth aspect, the present application provides a cloud platform, in which the adaptive weight adjustment model in the association analysis module provided in the fourth aspect of the present application is deployed, including:

[0049] An initial weight acquisition module, used to assign an initial weight to each abnormal coefficient when acquiring at least one abnormal coefficient input by the association analysis module;

[0050] An initial weight adjustment module, used to adjust the multiple initial weights to obtain the weight of each abnormal coefficient;

[0051] The weight sending module is used to send the weight of each abnormal coefficient to the association analysis module.

[0052] In a seventh aspect, the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;

[0053] The memory stores computer-executable instructions;

[0054] The processor executes the computer-executable instructions stored in the memory to implement the risk operation identification method provided in the first aspect of the present application, the behavior record acquisition method provided in the second aspect of the present application, or the weight allocation method provided in the third aspect of the present application.

[0055] In an eighth aspect, the present application provides a computer-readable storage medium, which stores computer execution instructions. When the computer execution instructions are executed by a processor, they are used to implement the risk operation identification method provided in the first aspect of the present application, the behavior record acquisition method provided in the second aspect of the present application, or the weight allocation method provided in the third aspect of the present application.

[0056] In the ninth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the risk operation identification method provided in the first aspect of the present application, the behavior record acquisition method provided in the second aspect of the present application, or the weight allocation method provided in the third aspect of the present application.

[0057] The present application provides a risk operation identification method, a behavior record acquisition method and a weight allocation method, the risk operation identification method comprising: when acquiring SMS behavior records, obtaining a basic information database according to the SMS behavior records through natural language processing technology; extracting multi-dimensional behavior data of a target mobile phone number from a large network information acquisition module, and obtaining multiple abnormal coefficients of the target mobile phone number according to the multi-dimensional behavior data and the entity mapping relationship between preset multi-dimensional behavior data; inputting at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model; calculating a risk operation score of the target mobile phone number according to the multiple abnormal coefficients and the multiple weights, so as to predict the risk operation probability of a user corresponding to the target mobile phone number when registering a target application according to the risk operation score. Based on the above method, the following technical effects are achieved: natural language processing technology is used to automatically identify and extract key information in text messages, avoiding the complexity and inefficiency of manual analysis and classification; multiple abnormality coefficients of the target mobile phone number can be obtained through multi-dimensional behavior data and the entity mapping relationship between preset multi-dimensional behavior data, so as to facilitate operational risk prediction based on multiple abnormality coefficients; the optimal weights obtained through the model are applied to the risk operation score scoring, which can enhance the scoring effect and the accuracy of risk operation prediction; after obtaining multiple abnormality coefficients and multiple weights, the risk operation score can be calculated, and the risk operation score is used to reveal the prediction of abnormal Internet behavior of the corresponding user, which is subsequently used for the closure of number cards for fraud governance and the tracing of black and gray production number cards; relying on some SMS characteristics of operators, the abnormal behavior identification of Internet accounts can be carried out without the need for internal account content and information. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0059] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0060] Figure 1 Schematic diagram of the process of the risk operation identification method provided in the embodiment of the present application Figure 1 ;

[0061] Figure 2 A schematic diagram of a process for obtaining a basic information database provided in an embodiment of the present application;

[0062] Figure 3 Schematic diagram of the process of the risk operation identification method provided in the embodiment of the present application Figure 2 ;

[0063] Figure 4 A schematic diagram of a process for identifying anomalies in an Internet account provided in an embodiment of the present application;

[0064] Figure 5 A schematic diagram of the structure of the association analysis module provided in the embodiment of the present application;

[0065] Figure 6 A schematic diagram of the structure of a large network information collection module provided in an embodiment of the present application;

[0066] Figure 7 A schematic diagram of the structure of the cloud platform provided in the embodiment of the present application;

[0067] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0068] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0069] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation methods described in the following exemplary embodiments do not represent all implementation methods consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the attached claims, rather than all embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0070] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit the difference. It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way. In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more.

[0071] It should be noted that the "at..." in the embodiments of the present application can be the instant when a certain situation occurs, or it can be a period of time after a certain situation occurs, and the embodiments of the present application do not specifically limit this. In addition, the risk operation identification method, behavior record acquisition method and weight allocation method provided in the embodiments of the present application are only examples, and the risk operation identification method, behavior record acquisition method and weight allocation method can also include more or less content.

[0072] It should be noted that the user information (including but not limited to user device information and user personal information) and data (including but not limited to data used for analysis, stored data and displayed data) involved in one or more embodiments of the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and corresponding operation entrances shall be provided for users to choose to authorize or refuse.

[0073] In order to clearly describe the technical solutions of the embodiments of the present application, some terms and technologies involved in the embodiments of the present application are briefly introduced below:

[0074] Natural Language Processing (NLP): A part of artificial intelligence that aims to enable computers to understand, analyze, and generate natural language. It includes steps such as text preprocessing, text vectorization, text analysis, and machine translation. Its core task is to enable machines to understand the grammar, semantics, and context of human language. Among them, text preprocessing includes steps such as word segmentation, stop word removal, special character removal, and stemming or part-of-speech restoration, which aims to prepare clean text data for subsequent analysis.

[0075] Named Entity Recognition (NER) is an important task in natural language processing technology. It is mainly used to identify proper nouns such as names of people, places and organizations in texts. It mainly includes processing steps such as data annotation, feature extraction, and entity classification and recognition. It aims to help computers extract structured information from texts and provide a basis for subsequent understanding and analysis.

[0076] Applying text classification technology: It is another important task in natural language processing technology, which aims to classify text into different categories. It includes steps such as data collection and annotation, text preprocessing, feature extraction, model training, and classification and prediction, which are used to assign text to predetermined categories. Through machine learning algorithms such as Support Vector Machine (SVM) and Long Short-Term Memory (LSTM), large amounts of text data can be automatically processed and analyzed.

[0077] National SMS Gateway: Also known as SMS service gateway, it refers to a network architecture that transmits SMS messages from sender to receiver through a unified technical platform. It connects mobile operators, Internet service providers and users, allowing enterprises or individuals to send SMS to users across the country through a simple interface.

[0078] In order to clearly understand the technical solution of the present application, the solution of the prior art is first introduced in detail.

[0079] Existing fraud identification technology focuses on traditional telephone communication and SMS channels. Through in-depth analysis of telephone communication and SMS behaviors, it can effectively identify abnormal patterns and promptly warn of potential fraud behaviors.

[0080] In terms of telephone communications, existing fraud detection technologies usually identify potential fraudulent behavior by analyzing call records, call duration, frequency, and geographic locations of both parties. For example, the system can detect abnormal situations where certain numbers frequently call high-risk areas, or call the same number multiple times in a short period of time. These behaviors are usually associated with fraudulent activities, and fraudsters often use high-frequency and abrupt calling patterns to lure victims.

[0081] In terms of SMS channels, existing fraud identification technology can effectively identify false information by analyzing SMS content, sending frequency and sending numbers. For example, SMS content with fake website links, misleading text and emergency prompts are often characteristics of fraud. Through natural language processing technology, the system can automatically detect abnormal patterns in SMS and issue warnings or automatically intercept in a timely manner when fraud risks are identified.

[0082] With the rapid development of social networks and instant messaging platforms, fraudsters have gradually turned their targets to Internet platforms. Compared with traditional means of communication such as telephone and text messages, Internet fraud is more concealed, widespread and low-cost. Fraudsters register fake social media accounts and use instant messaging tools such as WeChat to gradually gain the trust of victims and commit fraud by disguising their identities and fictitious situations. The anonymity and concealment of these platforms allow fraudsters to cleverly hide their true identities, making it difficult for victims to identify their true faces. With the popularity of social platforms, victims are often in a state of information overload. In addition, some people lack awareness of prevention and are easily deceived by carefully designed fraudulent means and thus fall for fraud. Since Internet fraud spreads quickly and is difficult to prevent, victims often find it difficult to detect and respond in a timely manner, resulting in serious economic losses.

[0083] Existing fraud identification technology does not have the capability to monitor and analyze the behavior of Internet accounts, nor can it effectively identify fraudulent activities conducted through social platforms.

[0084] Therefore, in order to address the technical problem that the existing fraud identification technology cannot effectively identify fraud activities conducted through social platforms, the research found that in order to solve this problem, ① through the SMS behavior records, obtain the SMS library including the registered mobile phone number; ② based on the registered mobile phone number, obtain multi-dimensional behavior data; ③ based on the multi-dimensional behavior data, obtain the abnormality coefficient; ④ obtain the weight corresponding to the abnormality coefficient; ⑤ through the abnormality coefficient and the weight corresponding to the abnormality coefficient, obtain the risk operation score, and make risk operation judgments based on the risk operation score.

[0085] Based on the above creative findings, the technical solution of the present application is proposed.

[0086] The following introduces the application scenarios of the risk operation identification method provided in the embodiments of the present application.

[0087] The application scenarios of the risk operation identification method provided in the embodiment of the present application include:

[0088] 1) False winning and prize claiming fraud: Fraudsters send false winning information to victims through instant messaging platforms such as WeChat, inducing them to provide personal information or fees to claim prizes. The proposed risk operation identification method can detect these false information by analyzing user registration behavior, thereby effectively identifying and preventing such fraud;

[0089] 2) Online loan fraud: Fraudsters provide fake online loan services to victims through instant messaging tools such as WeChat, inducing them to provide personal information. The proposed risk operation identification method can timely prevent users from clicking on unknown links or transferring funds by analyzing the registration behavior of fraudsters.

[0090] 3) Social engineering attacks: Through social platforms such as WeChat, fraudsters often use social engineering methods to trick victims into revealing personal information or account passwords. The proposed risk operation identification method can help identify potential social engineering attacks and provide risk warnings in advance by analyzing the account registration history and interaction patterns of unfamiliar contacts.

[0091] 4) Abnormal links and virus transmission: Fraudsters send abnormal links through instant messaging platforms to trick victims into clicking on them and infecting them with viruses or leaking their account information. The proposed risk operation identification method can determine whether there is an operational risk by analyzing the historical registration behavior records of an account, thereby preventing victims from clicking on abnormal links.

[0092] The embodiments of the present application are introduced below in conjunction with the drawings in the specification.

[0093] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0094] Figure 1 Schematic diagram of the process of the risk operation identification method provided in the embodiment of the present application Figure 1 This embodiment provides a risk operation identification method, which is applied to the association analysis module. The risk operation identification method provided by this embodiment includes the following steps:

[0095] S101. When the SMS behavior records are obtained, a basic information database is obtained according to the SMS behavior records through natural language processing technology.

[0096] In this embodiment, the basic information database includes the target mobile phone number and the target application registered by the target mobile phone number through SMS; the SMS behavior record is obtained by the large network information collection module according to the SMS registration behavior keywords.

[0097] Specifically, when a user registers an application using a mobile phone number, the user first needs to enter the mobile phone number in the application and submit a registration request. The application will then send a request to the national SMS gateway, requesting that a verification code be sent to the user's mobile phone. After the national SMS gateway receives the request, it will send the verification code to the user's mobile phone. After the user's mobile phone receives the verification code, it will enter the corresponding verification code in the application for verification. If the verification code is correct, it means that the application verification has passed and the registration is successful.

[0098] During this process, the user's mobile phone number is the target mobile phone number, and the application registered by the user is the target application. The national SMS gateway will record the registration behavior keywords, including but not limited to the target mobile phone number, target application, occurrence time, SMS sending status and login registration status.

[0099] Figure 2 The following is a flow chart of obtaining a basic information database provided in the embodiment of the present application. Figure 2 As shown, the large network information collection module extracts user terminal information, SMS record data, original communication records and other data from the registration behavior keywords recorded by the national SMS gateway as needed, forms SMS behavior records, and feeds back the SMS behavior records to the correlation analysis module.

[0100] The association analysis module combines pattern recognition or natural language processing technology to extract the target mobile phone number, target application, occurrence time and login registration status from the SMS behavior records to obtain a basic information database.

[0101] The obtained basic information database is shown in Table 1.

[0102] Natural language processing technology is used to automatically identify and extract key information from text messages, avoiding the complexity and inefficiency of manual analysis and classification.

[0103] Table 1

[0104]

[0105] S102. Extract multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtain multiple abnormal coefficients of the target mobile phone number based on the multi-dimensional behavior data and the entity mapping relationship between the preset multi-dimensional behavior data.

[0106] In this embodiment, each abnormality coefficient is used to indicate the abnormal probability of the behavior data of the corresponding dimension.

[0107] Specifically, based on the target mobile phone number in the basic account database, the corresponding user terminal, communication behavior records, and network behavior record information are extracted from the large network information collection module, and multi-dimensional behavior data such as name, mobile phone number, and age are formed with the user as the main attribute - mobile device usage set - call active / passive behavior set - SMS receiving / sending behavior set - website visiting behavior set - Internet account registration behavior set, etc.

[0108] Through the entity mapping relationship between multi-dimensional behavior data and preset multi-dimensional behavior data, multiple abnormal coefficients of the target mobile phone number can be obtained, so as to facilitate operational risk prediction based on the multiple abnormal coefficients.

[0109] S103. Input at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model.

[0110] In this embodiment, after obtaining multiple abnormal coefficients, it is necessary to obtain the optimal weights in the corresponding abnormal coefficients. The optimal weights are adjusted by a preset adaptive weight adjustment model, which is a pre-trained model. Through this model, the optimal weights in the corresponding abnormal coefficients can be obtained.

[0111] Applying the optimal weights obtained through the model to the risk operation score can enhance the scoring effect and the accuracy of risk operation prediction.

[0112] S104. Calculate a risk operation score of the target mobile phone number based on the multiple abnormal coefficients and the multiple weights, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application program based on the risk operation score.

[0113] Specifically, in this embodiment, after obtaining multiple abnormal coefficients and multiple weights, the risk operation score can be calculated. The risk operation score is used to reveal the prediction of the abnormal Internet behavior of the corresponding user, and is subsequently used for the closure of account cards for fraud governance and the tracing of black and gray production account cards.

[0114] The risk operation identification method of the embodiment of the present application relies on some SMS features of the operator and can carry out abnormal behavior identification of Internet accounts without the need for internal account content and information.

[0115] The entire technology is not limited to log methods such as SMS extraction records and other similar content.

[0116] Based on the risk operation identification method of the embodiment of the present application, by processing large-scale data in the industry SMS library, detecting abnormal registration behavior, generating a basic information database, realizing the prediction of abnormal users and active discovery of fraudulent behavior, and improving the level of network security prevention.

[0117] The present application provides a risk operation identification method, which includes: when obtaining SMS behavior records, obtaining a basic information database according to the SMS behavior records through natural language processing technology; extracting multi-dimensional behavior data of a target mobile phone number from a large network information collection module, and obtaining multiple abnormality coefficients of the target mobile phone number according to the multi-dimensional behavior data and the entity mapping relationship between preset multi-dimensional behavior data; inputting at least one of the multiple abnormality coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model; and calculating a risk operation score of the target mobile phone number according to the multiple abnormality coefficients and the multiple weights, so as to predict the probability of risk operation of a user corresponding to the target mobile phone number when registering a target application according to the risk operation score. Based on the above method, the following technical effects are achieved: natural language processing technology is used to automatically identify and extract key information in text messages, avoiding the complexity and inefficiency of manual analysis and classification; multiple abnormality coefficients of the target mobile phone number can be obtained through multi-dimensional behavior data and the entity mapping relationship between preset multi-dimensional behavior data, so as to facilitate operational risk prediction based on multiple abnormality coefficients; the optimal weights obtained through the model are applied to the risk operation score scoring, which can enhance the scoring effect and the accuracy of risk operation prediction; after obtaining multiple abnormality coefficients and multiple weights, the risk operation score can be calculated, and the risk operation score is used to reveal the prediction of abnormal Internet behavior of the corresponding user, which is subsequently used for the closure of number cards for fraud governance and the tracing of black and gray production number cards; relying on some SMS characteristics of operators, the abnormal behavior identification of Internet accounts can be carried out without the need for internal account content and information.

[0118] Figure 3 Schematic diagram of the process of the risk operation identification method provided in the embodiment of the present application Figure 2 In this embodiment Figure 1 Based on the embodiments provided, the risk operation identification method is further explained. Figure 3 As shown, the risk operation identification method of this embodiment includes:

[0119] S201. When the SMS behavior records are obtained, a basic information database is obtained according to the SMS behavior records through natural language processing technology.

[0120] In this embodiment, the effect of S201 is similar to the effect of S101 in the above embodiment of the present invention, and will not be described in detail here.

[0121] S202. Extract the multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtain the device behavior anomaly coefficient, communication behavior anomaly coefficient, network behavior anomaly coefficient and account registration behavior anomaly coefficient of the target mobile phone number based on the multi-dimensional behavior data and the entity mapping relationship between the preset multi-dimensional behavior data.

[0122] In this embodiment, the multiple abnormality coefficients include a device behavior abnormality coefficient, a communication behavior abnormality coefficient, a network behavior abnormality coefficient, and an account registration behavior abnormality coefficient.

[0123] Specifically, the device behavior anomaly coefficient is mainly generated based on the mobile device usage set, and the key indicators are the International Mobile Equipment Identity (IMEI), the commonly used base station number / location area code (LAC_CI), whether the IMEI is shared, and whether one card is used for multiple terminals.

[0124] The communication behavior anomaly coefficient is mainly generated by the active / passive call behavior set and the SMS receiving / sending behavior set. The key indicators are the number of calling calls within the period, the number of called calls within the period, the number of SMS sent within the period, and the number of SMS received within the period.

[0125] The network behavior anomaly coefficient is mainly generated by the set of website access behavior. The key indicators are traffic data within the period, the number of URLs visited within the period, the proportion of other access traffic, the number of abnormal domain names visited, and whether the proxy address is visited.

[0126] The account registration behavior anomaly coefficient is mainly generated by the SMS receiving / sending behavior set and the Internet account registration behavior set. The key indicators are the number of registered applications within the period, whether the application is registered with different numbers with the same IMEI, whether the same application is registered with the same base station number, and the proportion of registered SMS in received SMS.

[0127] In this embodiment, the effect of S202 is similar to the effect of S102 in the above embodiment of the present invention, and will not be described in detail here.

[0128] S203. Input the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient and the account registration behavior abnormality coefficient into a preset adaptive weight adjustment model to obtain a first weight corresponding to the device behavior abnormality coefficient, a second weight corresponding to the communication behavior abnormality coefficient, and a third weight corresponding to the network behavior abnormality coefficient output by the adaptive weight adjustment model.

[0129] In this embodiment, to calculate the risk operation score, it is necessary to obtain a first weight corresponding to the device behavior abnormality coefficient, a second weight corresponding to the communication behavior abnormality coefficient, and a third weight corresponding to the network behavior abnormality coefficient. The above content is implemented based on a preset adaptive weight adjustment model.

[0130] In this embodiment, the effect of S203 is similar to the effect of S103 in the above embodiment of the present invention, and will not be described in detail here.

[0131] S204: Perform weighted calculation on the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient, and the first weight, the second weight, and the third weight to obtain a weighted score.

[0132] S205. Calculate a risk operation score based on the weighted score and the account registration behavior abnormality coefficient, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application according to the risk operation score.

[0133] In this embodiment, after obtaining the device behavior abnormality coefficient, communication behavior abnormality coefficient, network behavior abnormality coefficient, account registration behavior abnormality coefficient, first weight, second weight and third weight, directional modeling is required to finally obtain the risk operation score.

[0134] Optionally, in this embodiment, the calculation formula of the risk operation score F is as follows:

[0135]

[0136] Among them, A is the device behavior abnormality coefficient, B is the communication behavior abnormality coefficient, C is the network behavior abnormality coefficient, D is the account registration behavior abnormality coefficient, weight A is the first weight, weight B is the second weight, weight C The third weight.

[0137] The ranges of A, B, C and D are between 0 and 1, and the risk operation score F is the risk operation score calculation of the user registration behavior at the current moment.

[0138] In this embodiment, the effect of the risk operation score is similar to the effect of S104 in the above embodiment of the present invention, and will not be repeated here.

[0139] In a possible design, the multi-dimensional behavior data in S202 includes user information data, device access data, call calling and called data, SMS sending and receiving data, server access data and account registration data, then S202 further includes the following steps:

[0140] S301. Obtain a device behavior abnormality coefficient according to user information data, device access data, and a first mapping relationship between the user information data and the device access data.

[0141] In this embodiment, the user information data includes basic user information such as user name, registration time, device usage history, geographic location, login time, device type and operating system, as well as user behavior data such as user operation records on the device, access time and frequency, and functions used.

[0142] Device access data refers to the record of a device's interaction with a network or platform, typically including the device's Internet Protocol Address (IP), device identification number (ID), device model, operating system version, login timestamp and device geographic location, device connection and disconnection times, and connection frequency.

[0143] The first mapping relationship between the user information data and the device access data refers to establishing a connection between the user information data and the device access data.

[0144] The device behavior anomaly coefficient is used to indicate the probability of abnormal device behavior, which is a quantitative indicator. Specifically, the following situations can be regarded as abnormal device behavior: the same user suddenly changes the device; the user usually logs in with a certain device, but uses another device at a certain time, and the login time and login location of the device do not match the user's usual mode; the IP address of the user's usual login is significantly different from the IP address in the device access data, including but not limited to the above three situations.

[0145] S302: Obtain a communication behavior abnormality coefficient according to the user information data, the caller and called party data, the text message sending and receiving data, and the second mapping relationship between the user information data, the caller and called party data, and the text message sending and receiving data.

[0146] In this embodiment, the call calling and called data refer to the records of calls initiated by the user (calling) and calls received (called), usually including the calling and called phone numbers, call duration, call time and call frequency.

[0147] SMS sending and receiving data refers to the user's sending and receiving of SMS messages, usually including the sending number, receiving number, SMS sending time and SMS receiving time.

[0148] The second mapping relationship among the user information data, the caller and called party data and the text message sending and receiving data refers to establishing a connection between the user information data, the caller and called party data and the text message sending and receiving data.

[0149] The communication behavior abnormality coefficient is used to indicate the probability of abnormal communication behavior, which is a quantitative indicator. Specifically, the following situations can be regarded as abnormal communication behavior: users frequently make calls or send a large number of text messages at night; users make calls to numbers that they do not contact frequently and send text messages frequently; users' call frequency or text message sending and receiving volume in a certain period of time are significantly different from their normal mode, including but not limited to the above three situations.

[0150] S303: Obtain a network behavior abnormality coefficient according to the user information data, the server access data, and a third mapping relationship between the user information data and the server access data.

[0151] In this embodiment, the server access data refers to the data generated when a user accesses a server, including access time, request type, accessed pages, and request frequency.

[0152] The third mapping relationship between the user information data and the server access data refers to establishing a connection between the user information data and the server access data.

[0153] The network behavior anomaly coefficient is used to indicate the probability of abnormal network behavior, which is a quantitative indicator. Specifically, the following situations can be regarded as abnormal network behavior: a user frequently accesses the server from different geographical locations within a short period of time; a user's access frequency to the server exceeds the normal range, including but not limited to the above two situations.

[0154] S304. Obtain an abnormal coefficient of account registration behavior according to the user information data, the SMS sending and receiving data, the account registration data, and a fourth mapping relationship between the user information data, the SMS sending and receiving data, and the account registration data.

[0155] In this embodiment, the account registration data refers to the relevant information when the user registers an account, mainly including the timestamp of the registration, the mobile phone number or email address used in the registration process, and the information entered during the registration.

[0156] The fourth mapping relationship between the user information data, the SMS sending and receiving data and the account registration data refers to establishing a connection between the user information data, the SMS sending and receiving data and the account registration data.

[0157] The account registration behavior abnormality coefficient is used to indicate the probability of abnormal account registration behavior, which is a quantitative indicator. Specifically, the following situations can be regarded as abnormal account registration behavior: a mobile phone number frequently registers multiple accounts in a short period of time; a user registers multiple accounts in a certain area, and the SMS sending and receiving in the area is abnormal; the SMS receiving time of a user during registration is unreasonable with the registration time, including but not limited to the above three situations.

[0158] In a possible design, after S205, the following steps are further included:

[0159] S401. When the risk operation score is greater than a preset score threshold, mark the target mobile phone number; wherein the marked target mobile phone number is used to indicate that the user corresponding to the target mobile phone number performs a risk operation when registering a target application.

[0160] In this embodiment, a risk operation score is obtained based on the operation steps of the above embodiment. The risk operation score is an important indicator, indicating whether the user has the risk of fraud through the registered account when registering the target application. If the score exceeds the preset score threshold, it means that the operation or user may have a high risk and needs further attention or restriction.

[0161] When the risk operation score is greater than the preset score threshold, abnormal registration behavior is identified and the following processing can be performed:

[0162] 1) Establish a monitoring system to analyze and detect new registration behavior data in real time, and promptly detect abnormal registration activities that deviate from the normal pattern. Once abnormal registration behavior is identified, the system will immediately trigger an early warning mechanism and take necessary restrictive measures;

[0163] 2) Require additional verification. Users will be asked to perform two-factor authentication when registering, such as confirming their identity via email, or even being asked to upload identity documents;

[0164] 3) Submit the user’s registration information to the risk control team for manual review and further investigation. The manual review may include telephone follow-up and collection of more personal information;

[0165] 4) Restrict account operations. After the user completes registration, the system may restrict certain high-risk operations, such as large transfers and modification of account information, until the user's identity and the legality of the operation are confirmed. The above processing methods are only examples, and no specific processing methods are restricted here.

[0166] 5) Relevant departments can take certain measures to effectively combat illegal fraud, such as freezing suspected fraud accounts to prevent further illegal activities; conducting in-depth investigations into the flow of funds between accounts to cut off financial sources; cooperating with relevant agencies to provide sufficient evidence support to assist in tracking and arresting criminals; at the same time, strengthening user education to enhance the public's awareness and prevention of such fraudulent methods, and forming an anti-fraud network with the participation of the whole society.

[0167] By determining whether the risk operation score is greater than the preset score threshold, potential risk operations can be effectively identified and prevented, protecting the security of the platform and other users.

[0168] In a possible design, S201 further includes the following steps:

[0169] S501: When the SMS behavior record is obtained, the SMS behavior record is converted into structured text through natural language processing technology.

[0170] In this embodiment, natural language processing technology plays an important role in analyzing SMS content and identifying potential fraudulent behavior. By applying natural language processing technology, the complexity of human language can be deeply understood and processed, thereby extracting information that is crucial to identifying abnormal user registration behavior. First, natural language processing technology can be used for text preprocessing, including word segmentation, removal of stop words and punctuation, and stem extraction or word form restoration. This process converts the original SMS text into structured and clean data, ready for subsequent analysis.

[0171] S502: Using entity recognition technology, identify and extract the mobile phone number, SMS type, and application of each SMS message in the structured SMS behavior record.

[0172] In this embodiment, entity recognition technology can be applied to identify and extract key information of each text message in the structured text message behavior record, such as mobile phone number, text message type, and application program. These entities usually carry important contextual information, which is very helpful for understanding text message types and identifying potential fraud patterns.

[0173] S503: By applying text classification technology, according to the mobile phone number, SMS type and application program of each SMS, SMS of registration type are screened out.

[0174] In this embodiment, by applying text classification technology, text messages can be classified into different categories, such as login, registration, promotion, notification, suspicious or normal communication. Machine learning or deep learning methods can train models in this process to identify and predict the categories of text messages, thereby helping to identify possible fraudulent behavior. At this time, the text messages obtained are of the registration type and are the text messages obtained after preliminary screening.

[0175] Through S501, S502, and S503, a powerful system can be built to analyze SMS types, extract key information, and identify patterns and tendencies that may be associated with fraudulent behavior. Such processing can not only improve the ability to identify abnormal user registration behavior, but also enhance the prevention and response to potential fraudulent activities.

[0176] S504: Obtain a basic information database according to the SMS type being a registration type SMS.

[0177] In this embodiment, after the short messages of the registration type are preliminarily screened out through S501, S502 and S503, a basic information database can be obtained based on the short messages of the registration type.

[0178] In this embodiment, the effect of S504 is similar to the effect of S201 in the above embodiment of the present invention, and will not be described in detail here.

[0179] In a possible design, S504 further includes the following steps:

[0180] S601. Filter out first SMS content including SMS registration behavior from SMS of registration type through a preset industry SMS library.

[0181] In this embodiment, the industry SMS library stores keywords for application registration, and the first SMS content is a registration SMS screened by the preset industry SMS library.

[0182] When building a basic Internet information account database, facing the massive amount of data that pours in every day, up to 1 billion information flows, adopting an efficient keyword filtering mechanism is a necessary step for screening. This step relies on the industry SMS library, which contains words and phrases closely related to the application registration and login process. Through intelligent matching of these keywords, the system can quickly filter out SMS content that may contain registration behavior information from the huge ocean of data, that is, in this embodiment, the industry SMS library is used to further filter out registration SMS from the SMS of the registration type previously obtained. The work basis of this stage is the key login and registration information of multiple popular and emerging applications that have been widely collected and continuously updated before, ensuring the accuracy and timeliness of the screening.

[0183] S602: Filter out second SMS content from the first SMS content according to a preset application whitelist, and obtain a basic information library according to the second SMS content.

[0184] In this embodiment, the preset application whitelist includes common applications with a large user base, niche applications with a small user base but that may become new targets of fraud, and some platforms that may be used to implement social fraud, through which fraudsters can register accounts to carry out social fraud. Correspondingly, there are some applications that have a small probability of becoming social frauds by fraudsters through registered accounts, such as applications related to music and art, although there are also registration behaviors. The second SMS content is the SMS content that has been screened by the preset application whitelist, that is, the SMS content that contains registration behaviors and fraudsters can carry out social fraud by registering target application accounts.

[0185] Specifically, in order to further refine the analysis, the first SMS content is imported into a high-performance network security and information security management cluster (Network Security Cluster) system, which has a highly intelligent classification algorithm and can accurately classify the filtered SMS messages. The classification criteria not only cover common applications with a large user base, but also include niche applications with a small user base that may become new targets for fraud. In addition, some platforms that may be used to implement social fraud will also be classified, such as login requests related to Face Time or other instant messaging applications. Through this classification process, the system can more accurately identify potential abnormal behaviors, such as frequent registration attempts, operations during abnormal time periods, or login requests from known high-risk areas. The system will record the registration behavior characteristics and related metadata of the SMS information in detail and form a basic information database. The basic information database includes not only basic information such as timestamps, origins, and device types used, but also advanced analysis results such as user behavior sequence analysis and anomaly detection indicators, providing first-hand information for subsequent in-depth analysis.

[0186] The behavioral characteristics of users in the process of registering and logging into the application under different fraud scenarios are segmented to generate refined risk tags. Relevant departments can quickly locate high-risk accounts or behavior patterns based on the prompts of risk tags and adopt preset security strategies.

[0187] Combined with existing fraud scenarios, cluster analysis and sequence pattern mining techniques are used to identify behavioral features that are significantly different from the regular registration process. Supervised learning, such as logistic regression, decision trees, random forests, or neural networks, is used to train models to distinguish between normal and suspicious registration behaviors.

[0188] With the help of terminal device information tracking, communication base station positioning technology, and complex time series analysis methods, abnormal registered accounts suspected of fraud can be clustered and analyzed to identify the fraud team network hidden behind a single abnormal account. First, by collecting and analyzing terminal device information, such as device model, operating system version, and unique device identifier, it can be found whether there are multiple accounts using the same or highly similar devices. This behavior pattern of sharing a small number of devices to register a large number of accounts is often a significant sign of fraud gangs creating accounts in batches; secondly, combined with communication base station positioning data, it can be detected whether multiple accounts use geographically adjacent base station signals to log in within a similar time period. From this spatial clustering, it can be inferred that the fraud team members may be located in the same physical location or use mobile devices to operate in a specific area. Activity patterns, further confirming the correlation between accounts and potential illegal collaboration. Time series analysis provides a way to gain insight into fraudulent behavior from a dynamic perspective. Through long-term analysis of data such as account activity time, login frequency, and operation mode, it can be inferred that fraudulent activities show specific trends and periodic patterns over time. For example, certain fraud activities may tend to increase in frequency around holidays, or follow certain periodic activity patterns. Capturing these patterns can help provide early warnings and develop response strategies.

[0189] Through the implementation of the above methods, the data in the industry SMS database can be effectively processed, potential abnormal registration behaviors can be identified, and the fraud team network hidden behind a single abnormal account can be identified, and certain measures can be taken to effectively combat illegal fraud. Provide reliable data support for risk management and monitoring, improve the ability to identify and prevent abnormal users and fraudulent behaviors, and provide important technical support for network security.

[0190] When monitoring and identifying registration behavior, while conducting intelligent semantic directional training and key field analysis on sample data, the monitoring data is subjected to intelligent monitoring (line expansion type) and basic monitoring (mainstream type), and combined with unknown rule analysis, the target data, i.e., registration data, is detected; when performing abnormal feature cluster analysis, the registration data is pre-processed, the account information is output, and after the account is classified, the fraud-related account is output to the Internet account information database, which gives risk labels, including quick registration, silent registration, centralized base stations, and centralized international mobile equipment identification codes, and then combined with a big data cluster including registration record basic data and user information basic data, the associated line expansion abnormal account is output and subjected to big data monitoring; when conducting an internal and external joint disposal closed loop, the Internet account can be sent to the operator-management bureau-Internet enterprise linkage mechanism platform for subsequent processing, the fraud-related clues can be sent to relevant agencies to crack down on their black and gray industries, and the illegal work numbers can also be sent to the operator side to manage their illegal work numbers.

[0191] The present application embodiment provides a behavior record acquisition method, which is applied to a large network information collection module, including:

[0192] S701. Periodically filter the SMS messages according to the SMS registration behavior keywords to obtain SMS behavior records.

[0193] In this embodiment, the SMS registration behavior keyword is issued by the feature issuing module.

[0194] S702: Send the SMS behavior record to the correlation analysis module.

[0195] The SMS behavior records obtained through this embodiment are used in the risk operation identification method of the above embodiment.

[0196] The embodiment of the present application provides a weight allocation method, which is applied to a cloud platform and includes:

[0197] S801. When at least one abnormal coefficient input by the association analysis module is obtained, an initial weight is assigned to each abnormal coefficient.

[0198] In this embodiment, the cloud platform is deployed with the adaptive weight adjustment model in the above embodiment.

[0199] For the initial weight of each abnormal coefficient, an initial value can be assigned to each initial weight by uniform distribution or by utilizing the experience of experts in the field.

[0200] S802: Adjust multiple initial weights to obtain the weight of each abnormal coefficient.

[0201] In this embodiment, in order to solve the problem that the importance of each abnormal coefficient may be inconsistent in different environments or time periods, an adaptive weight adjustment model is introduced to dynamically adjust the weights of various behaviors based on historical abnormal data. According to real-time or historical data, the weights of different features in the risk operation score are automatically adjusted, so that it can self-optimize in different environments and enhance the scoring effect.

[0202] S803. Send the weight of each abnormal coefficient to the association analysis module.

[0203] In this embodiment, after the weight of each abnormal coefficient is obtained based on the adaptive weight adjustment model, the weight of each abnormal coefficient is sent to the association analysis module, and the association analysis module combines the abnormal coefficient and the corresponding weight to make a risk operation judgment.

[0204] In a possible design, S802 further includes the following steps:

[0205] S901. Iteratively optimize the adaptive weight adjustment model and multiple initial weights through feedback mechanism and reinforcement learning until a predetermined number of iterations or reward accumulation threshold is reached.

[0206] In this embodiment, the weights are dynamically adjusted through a feedback mechanism and a reinforcement learning method.

[0207] The feedback mechanism includes model prediction effect, user feedback and system log data analysis to adjust weights and optimize the model. Prediction effect feedback refers to adjusting weights based on the contribution of each feature to the final prediction effect. If a feature plays a greater negative role in multiple wrong predictions, its weight will be reduced, otherwise its weight will be increased; user feedback refers to collecting manual review results. If a feature seriously affects the model scoring effect, the weight of the feature will be adjusted; automated log analysis refers to analyzing the abnormal behavior detection results in the system log and adjusting the weight based on the frequency and degree of abnormality.

[0208] Reinforcement learning refers to an adaptive dynamic optimization method that adjusts weights based on the performance of different features to minimize the error rate of scoring. It uses the Q-learning algorithm to store scores of different weight combinations through the Q table and updates the weights based on reward and penalty signals to find the optimal weight combination. The system iterates until the predetermined number of iterations or reward accumulation threshold is reached. Advanced algorithms such as reinforcement learning are used to enable the model to self-learn and evolve in practical applications, improving recognition accuracy and response speed.

[0209] The Q table is used to store the score of each weight combination (state) and its corresponding action; each state in the state space represents the current weight combination: , where state S t Refers to weight weightA t, weight weightB t and weight weightC t An action is the action that the system chooses to adjust a certain weight. ; Reward refers to the improvement of the model's scoring accuracy, or the reduction of mis-scoring as a reward or penalty signal. For example, if the new weight combination significantly increases the risk index of abnormal samples, a reward will be given; if the new weight combination reduces the risk value of abnormal samples, a penalty will be given.

[0210] Q-learning refers to adjusting the weight distribution of features based on feedback information to find the optimal weight combination. The optimal strategy is learned by updating the Q value function. The formula is:

[0211]

[0212] Among them, Q (S t , A t ) is in state S t Next take action A t The Q value of is the expected score of this weight combination; is the learning rate, which controls the magnitude of each update; R t+1 is the immediate reward for the current action; is the discount factor, indicating the importance of future rewards; For state S t+1 The maximum Q value of all possible actions A under .

[0213] S902. Using the multiple initial weights after iterative optimization as the weights of the corresponding abnormal coefficients.

[0214] In this embodiment, the adjusted weight is applied to the risk operation score, which can achieve self-optimization of the risk operation score and enhance the scoring effect.

[0215] Figure 4 A schematic diagram of a process for identifying abnormalities in an Internet account provided in an embodiment of the present application. Figure 4 As shown, the following is described as a specific embodiment:

[0216] S1001, the scheduling module starts the risk operation identification process based on the user registration behavior;

[0217] S1002, the feature delivery module delivers the latest registration behavior keywords to the large network information collection module;

[0218] S1003, the large network information collection module periodically collects the SMS information list, and forms SMS behavior records and feeds them back to the correlation analysis module;

[0219] S1004, the association analysis module combines pattern recognition or natural language processing technology to extract the target mobile phone number, target application, occurrence time and login registration status from the SMS behavior record to obtain a basic information database;

[0220] S1005. The large network information collection module obtains the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient and the account registration behavior abnormality coefficient based on the target mobile phone number in the basic information database, and feeds the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient and the account registration behavior abnormality coefficient back to the correlation analysis module;

[0221] S1006. The correlation analysis module combines the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient, the account registration behavior abnormality coefficient, the first weight corresponding to the device behavior abnormality coefficient, the second weight corresponding to the communication behavior abnormality coefficient and the third weight corresponding to the network behavior abnormality coefficient to obtain a risk operation score.

[0222] Figure 5 This is a schematic diagram of the structure of the association analysis module provided in the embodiment of the present application. Figure 5 As shown, in this embodiment, the association analysis module may be located in the electronic device. The association analysis module includes:

[0223] The basic information database acquisition module 501 is used to obtain the basic information database according to the SMS behavior record by natural language processing technology when the SMS behavior record is obtained; wherein the basic information database includes the target mobile phone number and the target application registered by the target mobile phone number through SMS; the SMS behavior record is obtained by the large network information collection module according to the SMS registration behavior keywords;

[0224] The abnormal coefficient acquisition module 502 is used to extract the multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtain multiple abnormal coefficients of the target mobile phone number according to the multi-dimensional behavior data and the entity mapping relationship between the preset multi-dimensional behavior data; wherein each abnormal coefficient is used to indicate the abnormal probability of the behavior data of the corresponding dimension;

[0225] The weight acquisition module 503 is used to input at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model;

[0226] The risk operation score acquisition module 504 is used to calculate the risk operation score of the target mobile phone number based on multiple abnormal coefficients and multiple weights, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application based on the risk operation score.

[0227] The association analysis module provided in this embodiment can be executed Figure 1 The technical solution of the risk operation identification method embodiment shown in the figure has the same implementation principle and technical effect as Figure 1 The risk operation identification method embodiments shown are similar and will not be described in detail here.

[0228] Meanwhile, the association analysis module provided by the present invention further refines the association analysis module based on the association analysis module provided by the previous embodiment.

[0229] Optionally, in this embodiment, the multiple abnormality coefficients in the abnormality coefficient acquisition module 502 include a device behavior abnormality coefficient, a communication behavior abnormality coefficient, a network behavior abnormality coefficient, and an account registration behavior abnormality coefficient.

[0230] Optionally, in this embodiment, when the weight acquisition module 503 inputs at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model, the device behavior abnormal coefficient, the communication behavior abnormal coefficient, the network behavior abnormal coefficient and the account registration behavior abnormal coefficient are input into a preset adaptive weight adjustment model to obtain a first weight corresponding to the device behavior abnormal coefficient, a second weight corresponding to the communication behavior abnormal coefficient, and a third weight corresponding to the network behavior abnormal coefficient output by the adaptive weight adjustment model;

[0231] Based on multiple abnormal coefficients and multiple weights, the risk operation score of the target mobile phone number is calculated, including:

[0232] Performing weighted calculation on the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient, and the first weight, the second weight, and the third weight to obtain a weighted score;

[0233] The risk operation score is calculated based on the weighted score and the account registration behavior abnormality coefficient; among which, the risk operation score is equal to the product of the weighted score and the account registration behavior abnormality coefficient.

[0234] Optionally, in this embodiment, the multi-dimensional behavior data in the abnormality coefficient acquisition module 502 includes user information data, device access data, call calling and called data, SMS sending and receiving data, server access data and account registration data. Then, when the abnormality coefficient acquisition module 502 obtains multiple abnormality coefficients of the target mobile phone number according to the multi-dimensional behavior data and the entity mapping relationship between the preset multi-dimensional behavior data, it obtains the device behavior abnormality coefficient according to the user information data, the device access data, and the first mapping relationship between the user information data and the device access data;

[0235] Obtaining a communication behavior abnormality coefficient according to the user information data, the caller and called party data, the text message sending and receiving data, and the second mapping relationship between the user information data, the caller and called party data, and the text message sending and receiving data;

[0236] Obtaining a network behavior abnormality coefficient according to the user information data, the server access data, and a third mapping relationship between the user information data and the server access data;

[0237] According to the user information data, the SMS sending and receiving data, the account registration data, and the fourth mapping relationship between the user information data, the SMS sending and receiving data and the account registration data, an account registration behavior abnormality coefficient is obtained.

[0238] Optionally, in this embodiment, after the risk operation score acquisition module 504 calculates the risk operation score of the target mobile phone number based on multiple abnormality coefficients and multiple weights, when the risk operation score is greater than a preset score threshold, the target mobile phone number is marked; wherein the marked target mobile phone number is used to indicate that the user corresponding to the target mobile phone number performs a risk operation when registering the target application.

[0239] Optionally, in this embodiment, when the basic information database acquisition module 501 acquires the SMS behavior record, it obtains the basic information database according to the SMS behavior record through natural language processing technology, and converts the SMS behavior record into structured text through natural language processing technology;

[0240] Through entity recognition technology, the mobile phone number, SMS type and application of each SMS in the structured SMS behavior record are identified and extracted;

[0241] By applying text classification technology, SMS messages of registration type are screened out based on the mobile phone number, SMS type and application of each SMS message;

[0242] According to the SMS type being a registration type, a basic information library is obtained.

[0243] Optionally, in this embodiment, when obtaining the basic information database according to the SMS of the registration type, the basic information database acquisition module 501 filters out the first SMS content including the SMS registration behavior from the SMS of the registration type through a preset industry SMS library; wherein the industry SMS library stores the keywords for application registration;

[0244] According to the preset application whitelist, the second SMS content is screened out from the first SMS content, and the basic information library is obtained according to the second SMS content.

[0245] Figure 6 This is a schematic diagram of the structure of the large network information collection module provided in the embodiment of the present application. Figure 6 As shown, in this embodiment, the large network information collection module can be located in the electronic device. The large network information collection module includes:

[0246] The SMS behavior record acquisition module 601 is used to periodically filter SMS messages according to the SMS registration behavior keywords to obtain SMS behavior records; wherein the SMS registration behavior keywords are issued by the feature issuing module; the SMS behavior records are used to Figure 5 The technical solution of the embodiment of the association analysis module shown;

[0247] The SMS behavior record sending module 602 is used to send the SMS behavior record to the correlation analysis module.

[0248] The large network information collection module provided in this embodiment can execute the technical solution of the above-mentioned behavior record acquisition method embodiment. Its implementation principle and technical effect are similar to those of the above-mentioned behavior record acquisition method embodiment, and will not be described in detail here.

[0249] Figure 7 This is a schematic diagram of the structure of the cloud platform provided in the embodiment of the present application. Figure 7 As shown, in this embodiment, the cloud platform can be located in the electronic device. An adaptive weight adjustment model is deployed in the cloud platform, and the adaptive weight adjustment model is used to Figure 5 The technical solution of the embodiment of the association analysis module shown in the figure, the cloud platform includes:

[0250] The initial weight acquisition module 701 is used to assign an initial weight to each abnormal coefficient when acquiring at least one abnormal coefficient input by the association analysis module;

[0251] An initial weight adjustment module 702 is used to adjust multiple initial weights to obtain the weight of each abnormal coefficient;

[0252] The weight sending module 703 is used to send the weight of each abnormal coefficient to the association analysis module.

[0253] The cloud platform provided in this embodiment can execute the technical solution of the above-mentioned weight allocation method embodiment. Its implementation principle and technical effect are similar to those of the above-mentioned weight allocation method embodiment, and will not be described in detail here.

[0254] At the same time, the cloud platform provided by the present invention further refines the cloud platform based on the cloud platform provided by the above embodiments.

[0255] Optionally, in this embodiment, when the initial weight adjustment module 702 adjusts the multiple initial weights to obtain the weight of each abnormal coefficient, iteratively optimizes the adaptive weight adjustment model and the multiple initial weights through a feedback mechanism and reinforcement learning until a predetermined number of iterations or a reward accumulation threshold is reached;

[0256] The multiple initial weights after iterative optimization are used as the weights of the corresponding abnormal coefficients.

[0257] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device is intended to be used in various electronic devices that can perform risk operation identification methods, behavior record acquisition methods or weight distribution methods, such as microcomputers, single-chip microcomputers and other suitable computers. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0258] like Figure 8 As shown, the electronic device includes: at least one processor 801 and a memory 802. The electronic device also includes a communication component 803. The processor 801, the memory 802 and the communication component 803 are connected via a bus 804.

[0259] In the specific implementation process, at least one processor 801 executes the computer execution instructions stored in the memory 802, so that at least one processor 801 executes the risk operation identification method, behavior record acquisition method or weight allocation method executed by the electronic device side as above.

[0260] The specific implementation process of processor 801 can refer to the above-mentioned risk operation identification method, behavior record acquisition method or weight allocation method embodiments, and their implementation principles and technical effects are similar, which will not be repeated in this embodiment.

[0261] In the above embodiment, it should be understood that the processor 801 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor 801 can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0262] The memory 802 may include a high-speed RAM memory, and may also include a non-volatile storage NVM, such as at least one disk storage.

[0263] The bus 804 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus 804 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus 804 in the drawings of the present application is not limited to only one bus or one type of bus.

[0264] The above functions implemented by the electronic device and the main control device introduce the scheme provided by the embodiment of the present application. It is understandable that in order to implement the above functions, the electronic device or the main control device includes a hardware structure and / or software module corresponding to each function. In combination with the units and algorithm steps of each example described in the embodiment disclosed in the embodiment of the present application, the embodiment of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present application.

[0265] The present application also provides a computer-readable storage medium, which stores computer-executable instructions. When a processor executes the computer-executable instructions, the above-mentioned risk operation identification method, behavior record acquisition method or weight allocation method is implemented.

[0266] The computer-readable storage medium mentioned above may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium may be any available medium that can be accessed by a general or special-purpose computer.

[0267] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. The readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). The processor and the readable storage medium can also exist as discrete components in an electronic device or a main control device.

[0268] The memory 802 is a non-transient computer-readable storage medium provided by the present invention. The non-transient computer-readable storage medium of the present invention stores computer instructions, which are used to enable a computer to execute the risk operation identification method, behavior record acquisition method or weight allocation method provided by the present invention.

[0269] The memory 802 is a non-transient computer-readable storage medium that can be used to store non-transient software programs, non-transient computer executable programs, and modules, such as the risk operation identification method, behavior record acquisition method, or weight allocation method in the embodiments of the present application (for example, Figure 5 The basic information base acquisition module 501, the abnormal coefficient acquisition module 502, the weight acquisition module 503 and the risk operation score acquisition module 504 are shown. Figure 6 The SMS behavior record acquisition module 601 and the SMS behavior record delivery module 602 shown, or Figure 7 The processor 801 executes various functional applications and data processing by running the non-transient software programs, instructions and modules stored in the memory 802, that is, the risk operation identification method, behavior record acquisition method or weight distribution method in the above method embodiment is implemented.

[0270] At the same time, this embodiment also provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the risk operation identification method, behavior record acquisition method or weight allocation method of the above-mentioned embodiment.

[0271] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required for the present application.

[0272] It should be further noted that, although the various steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0273] It should be understood that the above-mentioned device embodiments are only illustrative, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.

[0274] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present application may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.

[0275] If the integrated unit / module is implemented in the form of hardware, the hardware may be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, etc. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random-Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0276] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory, including a number of instructions for a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, disk or optical disk and other media that can store program codes.

[0277] In the above embodiments, the description of each embodiment has its own emphasis. For the part not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0278] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0279] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

[0280] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A method for identifying risky operations, characterized in that: The method is applied to the association analysis module, and the method includes: When the SMS behavior record is obtained, a basic information database is obtained according to the SMS behavior record through natural language processing technology; wherein the basic information database includes the target mobile phone number and the target application registered by the target mobile phone number through SMS; the SMS behavior record is obtained by the large network information collection module according to the SMS registration behavior keywords; Extracting the multi-dimensional behavior data of the target mobile phone number from the large network information collection module, and obtaining multiple abnormal coefficients of the target mobile phone number based on the multi-dimensional behavior data and the preset entity mapping relationship between the multi-dimensional behavior data; wherein each of the abnormal coefficients is used to indicate the abnormal probability of the behavior data of the corresponding dimension; Inputting at least one of the multiple abnormal coefficients into a preset adaptive weight adjustment model to obtain multiple weights output by the adaptive weight adjustment model; The risk operation score of the target mobile phone number is calculated based on the multiple abnormal coefficients and the multiple weights, so as to predict the risk operation probability of the user corresponding to the target mobile phone number when registering the target application according to the risk operation score.

2. The risk operation identification method according to claim 1, characterized in that: The multiple abnormality coefficients include a device behavior abnormality coefficient, a communication behavior abnormality coefficient, a network behavior abnormality coefficient and an account registration behavior abnormality coefficient.

3. The risk operation identification method according to claim 2, characterized in that: The step of inputting at least one of the plurality of abnormal coefficients into a preset adaptive weight adjustment model to obtain a plurality of weights output by the adaptive weight adjustment model comprises: Input the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient and the account registration behavior abnormality coefficient into a preset adaptive weight adjustment model, and obtain a first weight corresponding to the device behavior abnormality coefficient, a second weight corresponding to the communication behavior abnormality coefficient, and a third weight corresponding to the network behavior abnormality coefficient output by the adaptive weight adjustment model; The step of calculating the risk operation score of the target mobile phone number according to the multiple abnormal coefficients and the multiple weights includes: Performing weighted calculation on the device behavior abnormality coefficient, the communication behavior abnormality coefficient, the network behavior abnormality coefficient, and the first weight, the second weight, and the third weight to obtain a weighted score; A risk operation score is calculated based on the weighted score and the account registration behavior abnormality coefficient; wherein the risk operation score is equal to the product of the weighted score and the account registration behavior abnormality coefficient.

4. The risk operation identification method according to claim 2 or 3, characterized in that: The multi-dimensional behavior data includes user information data, device access data, call calling and called data, SMS sending and receiving data, server access data and account registration data; The method of obtaining a plurality of abnormal coefficients of the target mobile phone number based on the multi-dimensional behavior data and the preset entity mapping relationship between the multi-dimensional behavior data includes: Obtaining the device behavior abnormality coefficient according to the user information data, the device access data, and a first mapping relationship between the user information data and the device access data; Obtaining the communication behavior abnormality coefficient according to the user information data, the call calling and called data, the text message sending and receiving data, and a second mapping relationship between the user information data, the call calling and called data, and the text message sending and receiving data; Obtaining the network behavior abnormality coefficient according to the user information data, the server access data, and a third mapping relationship between the user information data and the server access data; The account registration behavior abnormality coefficient is obtained according to the user information data, the SMS sending and receiving data, the account registration data, and a fourth mapping relationship among the user information data, the SMS sending and receiving data, and the account registration data.

5. The risk operation identification method according to claim 1, characterized in that: After calculating the risk operation score of the target mobile phone number according to the multiple abnormal coefficients and the multiple weights, the method further includes: When the risk operation score is greater than a preset score threshold, the target mobile phone number is marked; wherein the marked target mobile phone number is used to indicate that the user corresponding to the target mobile phone number performs a risk operation when registering the target application.

6. The risk operation identification method according to claim 1, characterized in that: When the SMS behavior record is obtained, a basic information database is obtained according to the SMS behavior record through natural language processing technology, including: By using the natural language processing technology, the SMS behavior record is converted into structured text; Through entity recognition technology, the mobile phone number, SMS type and application of each SMS in the structured SMS behavior record are identified and extracted; By applying text classification technology, according to the mobile phone number, SMS type and application of each SMS, SMS of registration type is screened out; The basic information database is obtained according to the SMS type being a registration type SMS.

7. The risk operation identification method according to claim 6, characterized in that: The obtaining of the basic information database according to the SMS type being a registration type SMS includes: By using a preset industry SMS library, a first SMS content including SMS registration behavior is screened out from the SMS of the registration type; wherein the industry SMS library stores keywords for application registration; According to a preset application whitelist, a second SMS content is screened out from the first SMS content, and the basic information library is obtained according to the second SMS content.

8. A method for obtaining behavior records, characterized in that: The method is applied to a large network information collection module, and the method includes: According to the SMS registration behavior keywords, SMS are periodically screened to obtain SMS behavior records; wherein the SMS registration behavior keywords are issued by the feature issuing module; and the SMS behavior records are used in the risk operation identification method according to any one of claims 1 to 7; The SMS behavior record is sent to the correlation analysis module.

9. A weight allocation method, characterized in that: The method is applied to a cloud platform, and the adaptive weight adjustment model according to any one of claims 1 to 7 is deployed in the cloud platform, and the method includes: When obtaining at least one abnormal coefficient input by the association analysis module, assigning an initial weight to each abnormal coefficient; Adjusting the multiple initial weights to obtain the weight of each abnormal coefficient; The weight of each abnormal coefficient is sent to the association analysis module.

10. The weight allocation method according to claim 9, characterized in that: The step of adjusting the plurality of initial weights to obtain the weight of each abnormal coefficient includes: Iteratively optimizing the adaptive weight adjustment model and the plurality of initial weights through a feedback mechanism and reinforcement learning until a predetermined number of iterations or a reward accumulation threshold is reached; The multiple initial weights after iterative optimization are used as the weights of the corresponding abnormal coefficients.

Citation Information

Patent Citations

  • Mobile phone number risk monitoring method and mobile terminal

    CN107896287A

  • Bank anti-call fraud data model construction method based on multi-feature fusion

    CN117993919A

  • Non-supervision abnormal behavior detection method and system based on complex network

    CN118449718A

  • Fraud identification method and device, electronic equipment and storage medium

    CN118674465A

  • Network virtual user risk control method and system

    US20130276115A1

Cited By

  • Big data anti-fraud method based on multi-modal behavior characteristics

    CN120892896A

  • Communication risk detection method, system and device and storage medium

    CN121586003A

  • Risk control message intelligent matching system and method based on data analysis

    CN121598319A

  • A data analysis-based risk control message intelligent matching system and method

    CN121598319B