Link detection method and device, electronic equipment and storage medium
By extracting the log information of the target link and constructing the association relationship between the log information and combining the abnormal detection model, the problems of high cost and low efficiency of detecting abnormal links in the prior art are solved, and efficient and low-cost abnormal link detection are achieved.
Patent Information
- Application Number
- CN202311514622.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-13
AI Technical Summary
When detecting abnormal links in a website, the prior art requires obtaining web page content, resulting in high storage and calculation costs and low detection efficiency.
By obtaining the log information of the target link, extracting features such as access records and propagation records, constructing an association relationship, using the trained anomaly detection model for detection, and determining whether the link is an abnormal link.
Detect abnormal links without obtaining web content, saving storage and computing costs, and improving detection efficiency and universality.
Smart Images

Figure CN119988772A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence, and more specifically, to a link detection method, device, electronic device, and storage medium. Background Art
[0002] With the development of Internet technology, more and more websites have emerged, and the websites provide a wealth of web pages. Since web pages have a strong timeliness, there will inevitably be a certain number of abnormal links in the web pages of a large number of websites included in search engines. The existence of abnormal links in the website will reduce the experience of visiting users and will also cause the website to be downgraded by search engines. Therefore, it is very necessary to perform link detection on the website.
[0003] At present, the conventional link detection method is to crawl the webpage content of the website, identify the video, image or text in the webpage content, determine whether the link contains abnormal information, such as whether it contains pornographic information, and thus determine whether the link is an abnormal link. The existing webpage detection method requires obtaining the webpage content, especially the storage cost and computing cost for video content are high, and the detection efficiency is low. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a link detection method, device and electronic device. The technical solutions provided by the embodiments of the present application are as follows:
[0005] In one aspect, an embodiment of the present application provides a method for link detection, the method comprising:
[0006] Obtaining log information of the target link to be detected; wherein the log information includes access records and propagation records of the target link;
[0007] By extracting features from the log information, a target link feature of the target link is obtained; the target link feature includes at least one of access object information, propagation object information, and access path information of the target link;
[0008] Constructing association relationships for target link features to obtain features to be detected; the association relationships include at least one of access relationships, propagation relationships, and jump relationships; the features to be detected include at least some of the link access features, link propagation object features, and link jump features of the target link;
[0009] The trained anomaly detection model is used to detect the target link based on the features to be detected, and the anomaly detection result of the target link is obtained.
[0010] In some possible implementations, the link access feature includes an access popularity change feature; and the link propagation object feature is obtained based on the following method:
[0011] Querying the object of the propagation target link in the target link feature to obtain at least one link propagation object of the propagation target link;
[0012] For each link propagation object, query the first link access record and the first link propagation record associated with the link propagation object;
[0013] Based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object;
[0014] Based on the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0015] In some possible implementations, the link jump feature is obtained based on the following method:
[0016] Query the access time of each link contained in each access path;
[0017] Calculate the access time interval between every two adjacent links based on the access time of each link;
[0018] A link jump feature of the target link is generated based on each access time interval corresponding to each access path.
[0019] In some possible implementations, obtaining the object abnormality level of the link propagation object based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, includes:
[0020] For each link propagation object, taking the access record corresponding to the link propagation object marked as an abnormal link in the first link access record as the second link access record;
[0021] Using the propagation record of the link propagation object for the abnormal link in the first link propagation record as the second link propagation record;
[0022] Based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, the object abnormality level of the link propagation object is acquired.
[0023] In some possible implementations, based on the degree of association between the second link access record and the abnormal link, and the degree of association between the second link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object includes:
[0024] Counting the number of times the link propagation object accesses the abnormal link in the second link access record, and counting the number of times the link propagation object propagates at least one abnormal link in the second link propagation record;
[0025] Querying a first interval range where the number of accesses and the number of propagation are located, and querying a first probability of the link propagation object being associated with the abnormal link based on the first interval range;
[0026] Obtaining object attribute information of the link propagation object, generating label information of the link propagation object based on the object attribute information, and querying a second probability associated with the abnormal link corresponding to the label information;
[0027] The total probability of the link propagation object being associated with the abnormal link is calculated based on the first probability and the second probability, and the object abnormality level corresponding to the total probability is queried.
[0028] In some possible implementations, generating a link propagation object feature based on an object anomaly level of each link propagation object. Generating a link propagation object feature based on an object anomaly level of each link propagation object includes:
[0029] Based on the object anomaly level of each link propagation object, count the number of levels included in the object anomaly level corresponding to the target link, and the propagation number of each object anomaly level to the target link;
[0030] Based on the number of levels of the object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated.
[0031] In some possible implementations, based on the number of object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated, including:
[0032] Taking the target link as the link node and the link propagation object as the object node, and connecting each link node and the object node based on the propagation relationship between the target link and at least one link propagation object to obtain a first propagation relationship graph;
[0033] Inquiring in the propagation record the propagation time of each link propagation object propagation target link and the propagation quantity of each link propagation object propagation target link;
[0034] Add the propagation time of the propagation target link of each link propagation object, the propagation quantity of the propagation target link of each link propagation object, and the object abnormality level of each link propagation object to the information of each link propagation object in the first propagation relationship graph to obtain a second propagation relationship graph;
[0035] Generate relationship diagram annotation information based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link, add the relationship diagram annotation information to the second propagation relationship diagram to obtain a third propagation relationship diagram, and use the third propagation relationship diagram as the link propagation object feature.
[0036] In some possible implementations, the following further includes:
[0037] The link with which the target link has at least one common link propagation object is used as an associated link of the target link;
[0038] If the target link has at least one associated link, query the link type of at least one associated link;
[0039] If the link type of at least one associated link is found, the link propagation object characteristics are determined based on the object anomaly level of each link propagation object, including:
[0040] Based on the link type of the at least one associated link found and the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0041] In some possible implementations, generating a link jump feature of a target link based on each access time interval corresponding to each access path includes:
[0042] For each access path, query the first number of upstream links of the target link in each link included in the access path;
[0043] If the first number is greater than or equal to the preset number, and each access time interval corresponding to the access path is less than or equal to the preset time interval, then the jump type of the target link corresponding to the access path is an abnormal jump type;
[0044] A sample jump feature is generated based on the jump type of the target link corresponding to each access path, the first number of upstream links in each access path corresponding to the target link, and each access time interval corresponding to each access path.
[0045] In some possible implementations, the anomaly detection model is trained based on the following method:
[0046] Obtaining sample log information of a plurality of sample links; wherein, for each sample link, the sample log information includes a sample access record and a sample propagation record for the sample link;
[0047] For each sample link, obtain the sample link access feature, the sample link propagation object feature and the sample link jump feature of the sample link based on the sample log information;
[0048] Based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the initial anomaly detection model is trained to obtain a trained anomaly detection model.
[0049] In some possible implementations, based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, before training the initial anomaly detection model, the method further includes:
[0050] Based on the importance of the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link;
[0051] Based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, an initial anomaly detection model is trained to obtain a trained anomaly detection model, including:
[0052] Based on the screening features, the initial anomaly detection model is trained to obtain a trained anomaly detection model;
[0053] The target link features are associated with each other to obtain the features to be detected, including:
[0054] Based on the screening features, the target link features are associated with each other to obtain the features to be detected.
[0055] In some possible implementations, based on the importance of the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, including:
[0056] Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model;
[0057] Based on the importance ranking of each feature among the sample link access feature, the sample link propagation object feature and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature and the sample link jump feature.
[0058] In some possible implementations, the sample link access feature, the sample link propagation object feature, and the sample link jump feature each include at least one sub-feature;
[0059] Based on the importance ranking of each feature in the sample link access feature, the sample link propagation object feature, and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature, and the sample link jump feature, including:
[0060] Based on the importance ranking of each sub-feature output by the trained importance assessment model, a preset number of sub-features with the highest importance ranking among the sub-features are used as screening features.
[0061] In some possible implementations, the method further includes:
[0062] Based on the importance ranking of each feature, obtain the first feature with the highest importance among the features to be detected;
[0063] If the first feature does not conform to the normal feature value range, the target link is an abnormal link of the abnormal detection result;
[0064] The trained anomaly detection model is used to detect the target link based on the features to be detected, and the anomaly detection results of the target link are obtained, including:
[0065] If the first feature is within the normal feature value range, the target link is detected based on the feature to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link.
[0066] In some possible implementations, the target link is detected based on the features to be detected by using a trained anomaly detection model to obtain an anomaly detection result of the target link, including:
[0067] The features other than the first feature among the features to be detected are taken as the second features;
[0068] The trained anomaly detection model is used to detect the target link based on the second feature to obtain the anomaly detection result of the target link.
[0069] On the other hand, an embodiment of the present application provides a link detection device,
[0070] An acquisition module, used to acquire log information of a target link to be detected; wherein the log information includes access records and propagation records of the target link;
[0071] A feature extraction module is used to obtain target link features of the target link by extracting features from the log information; the target link features include at least one of access object information, propagation object information and access path information of the target link;
[0072] A feature construction module is used to construct an association relationship for target link features to obtain features to be detected; the association relationship includes at least one of an access relationship, a propagation relationship and a jump relationship; the features to be detected include at least part of the link access feature, the link propagation object feature and the link jump feature of the target link;
[0073] The detection module is used to detect the target link based on the features to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link.
[0074] In some possible implementations, the link access feature includes an access heat change feature; the feature construction module obtains the link propagation object in the following manner:
[0075] Querying the object of the propagation target link in the target link feature to obtain at least one link propagation object of the propagation target link;
[0076] For each link propagation object, query the first link access record and the first link propagation record associated with the link propagation object;
[0077] Based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object;
[0078] Based on the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0079] In some possible implementations, the feature construction module obtains the link jump feature in the following manner:
[0080] Query the access time of each link contained in each access path;
[0081] Calculate the access time interval between every two adjacent links based on the access time of each link;
[0082] A link jump feature of the target link is generated based on each access time interval corresponding to each access path.
[0083] In some possible implementations, when the feature construction module obtains the object anomaly level of the link propagation object based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, it is specifically used to:
[0084] For each link propagation object, taking the access record corresponding to the link propagation object marked as an abnormal link in the first link access record as the second link access record;
[0085] Using the propagation record of the link propagation object for the abnormal link in the first link propagation record as the second link propagation record;
[0086] Based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, the object abnormality level of the link propagation object is acquired.
[0087] In some possible implementations, when the feature construction module obtains the object anomaly level of the link propagation object based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, it is specifically used to:
[0088] Counting the number of times the link propagation object accesses the abnormal link in the second link access record, and counting the number of times the link propagation object propagates at least one abnormal link in the second link propagation record;
[0089] Querying a first interval range where the number of accesses and the number of propagation are located, and querying a first probability of the link propagation object being associated with the abnormal link based on the first interval range;
[0090] Obtaining object attribute information of the link propagation object, generating label information of the link propagation object based on the object attribute information, and querying a second probability associated with the abnormal link corresponding to the label information;
[0091] The total probability of the link propagation object being associated with the abnormal link is calculated based on the first probability and the second probability, and the object abnormality level corresponding to the total probability is queried.
[0092] In some possible implementations, when the feature construction module generates the link propagation object feature based on the object anomaly level of each link propagation object, the feature construction module is specifically used to:
[0093] Based on the object anomaly level of each link propagation object, count the number of levels included in the object anomaly level corresponding to the target link, and the propagation number of each object anomaly level to the target link;
[0094] Based on the number of levels of the object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated.
[0095] In some possible implementations, when the feature construction module generates the link propagation object feature based on the number of object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, it is specifically used to:
[0096] Taking the target link as the link node and the link propagation object as the object node, and connecting each link node and the object node based on the propagation relationship between the target link and at least one link propagation object to obtain a first propagation relationship graph;
[0097] Inquiring in the propagation record the propagation time of each link propagation object propagation target link and the propagation quantity of each link propagation object propagation target link;
[0098] Add the propagation time of the propagation target link of each link propagation object, the propagation quantity of the propagation target link of each link propagation object, and the object abnormality level of each link propagation object to the information of each link propagation object in the first propagation relationship graph to obtain a second propagation relationship graph;
[0099] Generate relationship diagram annotation information based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link, add the relationship diagram annotation information to the second propagation relationship diagram to obtain a third propagation relationship diagram, and use the third propagation relationship diagram as the link propagation object feature.
[0100] In some possible implementations, a third acquisition module is further included, which is used to:
[0101] The link with which the target link has at least one common link propagation object is used as an associated link of the target link;
[0102] If the target link has at least one associated link, query the link type of at least one associated link;
[0103] If the link type of at least one associated link is found, the second acquisition module generates the link propagation object feature based on the object anomaly level of each link propagation object, specifically for:
[0104] Based on the link type of the at least one associated link found and the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0105] In some possible implementations, when the feature construction module generates the link jump feature of the target link based on each access time interval corresponding to each access path, it is specifically used to:
[0106] For each access path, query the first number of upstream links of the target link in each link included in the access path;
[0107] If the first number is greater than or equal to the preset number, and each access time interval corresponding to the access path is less than or equal to the preset time interval, then the jump type of the target link corresponding to the access path is an abnormal jump type;
[0108] A sample jump feature is generated based on the jump type of the target link corresponding to each access path, the first number of upstream links in each access path corresponding to the target link, and each access time interval corresponding to each access path.
[0109] In some possible implementations, a training module is further included for:
[0110] Obtaining sample log information of a plurality of sample links; wherein, for each sample link, the sample log information includes a sample access record and a sample propagation record for the sample link;
[0111] For each sample link, obtain the sample link access feature, the sample link propagation object feature and the sample link jump feature of the sample link based on the sample log information;
[0112] Based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the initial anomaly detection model is trained to obtain a trained anomaly detection model.
[0113] In some possible implementations, a screening module is further included for:
[0114] Based on the importance of the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link;
[0115] The training module trains the initial anomaly detection model based on at least part of the sample link access features, sample link propagation object features, and sample link jump features of each sample link to obtain a trained anomaly detection model, specifically for:
[0116] Based on the screening features, the initial anomaly detection model is trained to obtain a trained anomaly detection model;
[0117] When the detection module constructs the association relationship between the target link features and obtains the features to be detected, it is specifically used to:
[0118] Based on the screening features, the target link features are associated with each other to obtain the features to be detected.
[0119] In some possible implementations, the screening module is specifically used to screen out screening features whose importance meets preset conditions from the sample link access features, sample link propagation object features, and sample link jump features of each sample link based on the importance of the sample link access features, sample link propagation object features, and sample link jump features of each sample link:
[0120] Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model;
[0121] Based on the importance ranking of each feature among the sample link access feature, the sample link propagation object feature and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature and the sample link jump feature.
[0122] In some possible implementations, the sample link access feature, the sample link propagation object feature, and the sample link jump feature each include at least one sub-feature;
[0123] The screening module is specifically used to sort out the screening features from the sample link access features, the sample link propagation object features and the sample link jump features based on the importance ranking of each feature in the sample link access features, the sample link propagation object features and the sample link jump features output by the trained importance evaluation model:
[0124] Based on the importance ranking of each sub-feature output by the trained importance assessment model, a preset number of sub-features with the highest importance ranking among the sub-features are used as screening features.
[0125] In some possible implementations, a determination module is further included, which is used to:
[0126] Based on the importance ranking of each feature, obtain the first feature with the highest importance among the features to be detected;
[0127] If the first feature does not conform to the normal feature value range, the target link is an abnormal link of the abnormal detection result;
[0128] When the detection module detects the target link based on the features to be detected through the trained anomaly detection model and obtains the anomaly detection result of the target link, it is specifically used for:
[0129] If the first feature is within the normal feature value range, the target link is detected based on the feature to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link.
[0130] In some possible implementations, when the detection module detects the target link based on the feature to be detected by using the trained anomaly detection model to obtain the anomaly detection result of the target link, it is specifically used to:
[0131] The features other than the first feature among the features to be detected are taken as the second features;
[0132] The trained anomaly detection model is used to detect the target link based on the second feature to obtain the anomaly detection result of the target link.
[0133] On the other hand, an embodiment of the present application further provides an electronic device, which includes a memory and a processor, wherein a computer program is stored in the memory, and the processor executes the computer program to implement the method provided in any optional embodiment of the present application.
[0134] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method provided in any optional embodiment of the present application is implemented.
[0135] On the other hand, an embodiment of the present application further provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the method provided in any optional embodiment of the present application.
[0136] The beneficial effects of the technical solution provided by the embodiment of the present application are as follows:
[0137] Through the log information of the target link to be detected, at least part of the link access features, link propagation object features and link jump features of the target link are obtained to obtain the features to be detected, and then the target link is detected based on the features to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link. The anomaly detection result of the target link can be determined without obtaining the page content corresponding to the target link, which can effectively save storage costs and computing costs and improve the detection efficiency of abnormal links.
[0138] In addition, the abnormal detection result of the target link can be determined without obtaining the page content corresponding to the target link. Detection can be performed on different types of target links, effectively improving the versatility of link detection.
[0139] Furthermore, by screening the sample link access features, sample link propagation object features and sample link jump features of each sample link, the screening features are obtained, and then the initial anomaly detection model is trained using the screening features to obtain a trained anomaly detection model, which can reduce the amount of calculation of redundant features and effectively improve the accuracy and efficiency of model training.
[0140] Furthermore, the sample link access feature, the sample link propagation object feature and the sample link jump feature are divided into more fine-grained sub-features, and then the sub-features are sorted. This can distinguish the importance of each sub-feature at a finer granularity and improve the accuracy of the trained anomaly detection model. BRIEF DESCRIPTION OF THE DRAWINGS
[0141] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in describing the embodiments of the present application are briefly introduced below.
[0142] Figure 1 A schematic diagram of an application environment of a link detection method provided in an example;
[0143] Figure 2 A flowchart of a link detection method provided in an embodiment of the present application;
[0144] Figure 3 A schematic diagram of a first propagation relationship diagram of a target link provided for an example of the present application;
[0145] Figure 4 A schematic diagram of a second propagation relationship graph of a target link provided for an example of the present application;
[0146] Figure 5 A propagation relationship diagram between multiple links and multiple propagation objects in an example provided for an example of the present application;
[0147] Figure 6 A schematic diagram of a scheme for determining each access time interval provided for an example of the present application;
[0148] Figure 7 A schematic diagram of a scheme for obtaining screening features provided for an example of the present application;
[0149] Figure 8 A schematic diagram of a link detection solution provided in an embodiment of the present application;
[0150] Fig. 9 A schematic diagram of the structure of a link detection device provided in an embodiment of the present application;
[0151] Fig.10 A schematic diagram of the structure of an electronic device applicable to an embodiment of the present application. DETAILED DESCRIPTION
[0152] The embodiments of the present application are described below in conjunction with the drawings in the present application. It should be understood that the implementation methods described below in conjunction with the drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions of the embodiments of the present application.
[0153] It will be understood by those skilled in the art that, unless specifically stated, the singular forms "one", "said", and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application refer to that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude the implementation as other features, information, data, steps, operations, elements, components and / or combinations thereof supported by the technical field. It should be understood that when we say that an element is "connected" or "coupled" to another element, the one element may be directly connected or coupled to the other element, or it may refer to that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein indicates at least one of the items defined by the term, for example, "A and / or B" may be implemented as "A", or as "B", or as "A and B". When describing multiple (two or more) items, if the relationship between the multiple items is not clearly defined, the multiple items may refer to one, multiple or all of the multiple items. For example, the description of "parameter A includes A1, A2, A3" can be implemented as parameter A including A1 or A2 or A3, and can also be implemented as parameter A including at least two of the three items A1, A2, A3.
[0154] Conventional video link detection logic uses an image model to obtain the web page content corresponding to the link, such as randomly intercepting a few frames of the linked video, and then performing image model detection to determine whether it contains pornographic information, thereby determining whether the corresponding video link is a pornographic link. This method has two problems: first, obtaining web page content, especially video content, consumes extremely high resources such as bandwidth, storage, and computing; second, due to the large number of links, it takes a long time to obtain web page content, especially video content, resulting in a high processing delay for abnormal links.
[0155] The present application determines the abnormal detection result of the target link to be detected by constructing at least part of the link access features, link propagation object features and link jump features of the target link to be detected. There is no need to obtain the web page content, thus saving storage costs, computing costs, etc.; secondly, since there is no need to obtain the web page content, the scope of processing for abnormal links is wider, the magnitude of processing for abnormal links is higher, and the timeliness of detection is also improved.
[0156] The link detection method of the present application can be implemented based on machine learning (ML) in artificial intelligence (AI).
[0157] Artificial intelligence is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines so that machines have the functions of perception, reasoning and decision-making.
[0158] Artificial intelligence technology is a comprehensive discipline that covers a wide range of fields, including both hardware-level and software-level technologies. Basic artificial intelligence technologies generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, large abnormal link detection technology, operation / interaction systems, mechatronics and other technologies. Artificial intelligence software technology mainly includes computer vision technology, abnormal link detection technology, natural language processing technology, and machine learning / deep learning.
[0159] The key technologies of speech technology include automatic speech recognition technology (ASR), text-to-speech technology (TTS) and voiceprint recognition technology. Enabling computers to listen, see, speak and feel is the future development direction of human-computer interaction, among which speech has become one of the most promising human-computer interaction methods in the future. Large model technology has brought changes to the development of speech technology. Pre-trained models such as WavLM and UniSpeech that use the Transformer architecture have strong generalization and versatility, and can excellently complete abnormal link detection tasks in various directions.
[0160] Machine Learning (ML) is a multi-disciplinary interdisciplinary subject involving probability theory, statistics, approximation theory, convex analysis, algorithm complexity theory and other disciplines. It specializes in studying how computers simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent. Its applications are spread across all areas of artificial intelligence. Machine learning and deep learning usually include artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and learning by teaching. The pre-trained model is the latest development of deep learning, which integrates the above technologies.
[0161] With the research and advancement of artificial intelligence technology, artificial intelligence technology has been studied and applied in many fields, such as common smart homes, smart wearable devices, virtual assistants, smart speakers, smart marketing, driverless cars, autonomous driving, drones, digital twins, virtual humans, robots, artificial intelligence generated content (AIGC), conversational interaction, smart medical care, smart customer service, game AI, etc. It is believed that with the development of technology, artificial intelligence technology will be applied in more fields and play an increasingly important role.
[0162] The solution provided in the embodiments of the present application involves technologies such as artificial intelligence link detection, which is specifically explained through the following embodiments.
[0163] The following describes several optional embodiments to illustrate the technical solution provided by the present application and the technical effects produced by the technical solution of the present application. It should be noted that the following implementations can refer to, draw on or combine with each other, and the same terms, similar features and similar implementation steps in different implementations will not be described repeatedly.
[0164] In the specific implementation of this application, any object-related data such as object attribute information, access records, and communication records are involved. When the embodiments of this application are applied to specific products or technologies, it is necessary to obtain the permission or consent of the object, and the collection, use, and processing of the relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. In other words, if any of the above-mentioned object-related data is involved in the embodiments of this application, these data must be obtained with the authorization and consent of the object and in compliance with the relevant laws, regulations, and standards of the country and region.
[0165] The link detection method provided in the embodiment of the present application can be executed by any computer device, and optionally, can be executed by a server, wherein the server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0166] Figure 1A schematic diagram of the application environment of the link detection method provided in the embodiment of the present application. The application environment may include a server 101 and a terminal 102. Specifically, the server 101 obtains an access request for a target link sent by the terminal 102, and the server 101 obtains log information of the target link to be detected in response to the access request; wherein the log information includes an access record and a propagation record of the target link; the server 101 obtains at least part of the link access features, link propagation object features, and link jump features of the target link based on the log information, and obtains the features to be detected; the server 101 detects the target link based on the features to be detected through a trained anomaly detection model, and determines the anomaly detection result of the target link; the server 101 returns the anomaly detection result of the target link to the terminal 102.
[0167] In the above application scenarios, a trained anomaly detection model is set in the server, and the server performs abnormal link detection. In other application scenarios, the terminal can perform abnormal link detection.
[0168] It can be understood by technicians in this technical field that the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server or server cluster that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The terminal can be a smart phone (such as Android phones, iOS phones, etc.), a tablet computer, a laptop computer, a digital broadcast receiver, a MID (Mobile Internet Devices), a PDA (personal digital assistant), a desktop computer, a smart home appliance, a vehicle-mounted terminal (such as a vehicle-mounted navigation terminal, a vehicle-mounted computer, etc.), a smart speaker, a smart watch, etc. The terminal and the server can be directly or indirectly connected by wired or wireless communication, but are not limited to this. The embodiments of the present invention can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, assisted driving, etc. It can also be determined based on the actual application scenario requirements, and is not limited here.
[0169] The terminal (also referred to as a user terminal or user device) may be a smart phone, a tablet computer, a laptop computer, a desktop computer, an intelligent voice interaction device (such as an intelligent speaker), a wearable electronic device (such as a smart watch), a vehicle terminal, a smart home appliance (such as a smart TV), an AR / VR device, an aircraft, etc., but is not limited thereto. The embodiments of the present invention may be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, assisted driving, etc.
[0170] In some possible implementations, a link detection method is provided, which can be executed by a server.
[0171] Figure 2 A flow chart of a link detection method provided by an embodiment of the present application is shown. Taking the execution subject as a server as an example, the link detection method provided by the present application may include the following steps:
[0172] Step S201, obtaining log information of the target link to be detected.
[0173] The log information includes the access record and propagation record of the target link.
[0174] Specifically, the access record may include object identifiers of multiple link access objects that access the target link, the access time of each link access object accessing the target link, and the like.
[0175] In an example, the access record may be shown in Table 1 below:
[0176] Table 1 Access records of target links
[0177] Object Identification Time Visited Links 1 20xx-05-10xxx:x1:10 www.xxx.com / js / xxx.js 2 20xx-05-10xxx:x2:20 www.xxx.com / js / xxx.js
[0178] The propagation record may include the object identifiers of multiple link propagation objects of the propagation target link, the propagation time of each link access object propagation target link, the identifier of the propagated object of the target link, the propagated community identifier, etc.
[0179] In the specific implementation process, the communication object identifier may include the identifier of the terminal of the communication link, and may also identify the account identifier of the communication object; similarly, the access object identifier may include the identifier of the terminal of the access link, and may also identify the account identifier of the access object.
[0180] Step S202: extracting features from the log information to obtain target link features of the target link.
[0181] The target link feature includes at least one of access object information, propagation object information and access path information of the target link.
[0182] Among them, the access object information includes the object accessing the target link, the time when the object accesses the target link, etc.; the propagation object information includes the object propagating the target link, the time when the object propagates the target link, etc.; the access path information includes at least one access path of the target link.
[0183] Specifically, the access object information, the propagation object information and the access path information may be obtained, or part of the access object information, the propagation object information and the access path information may be obtained.
[0184] Step S203, constructing an association relationship for the target link feature to obtain a feature to be detected.
[0185] The association relationship includes at least one of an access relationship, a propagation relationship and a jump relationship.
[0186] The features to be detected include at least some of the link access features, link propagation object features, and link jump features of the target link;
[0188] The link access feature may include an access popularity change feature.
[0189] Specifically, the access popularity change feature may include a change in the number of objects accessing the target link within a preset time period, and a change type in the number of objects accessing the target link, and the change type may include a popularity mutation type or a popularity non-mutation type.
[0190] The heat mutation type may include that the change in the number of objects accessing the target link within a specified time period exceeds a specified number threshold.
[0191] In a specific implementation process, the access heat variation characteristics may be statistically determined based on the object identifiers of multiple link access objects that access the target link and the access time of each link access object to the target link.
[0192] In a specific implementation process, the link access feature may also include a link propagation quantity feature.
[0193] The link propagation quantity feature may include the number of objects to which the target link is propagated and the number of communities to which the link is propagated; a community may be a group of at least three persons, such as a chat group, and the like.
[0194] In one example, the link access characteristics may be as shown in Table 2 below:
[0195] Table 2 Link access feature table
[0196]
[0197] The rising heat of sliding forward n periods refers to the rising heat of the connection in the consecutive n periods before the current time. The period can be days, hours or weeks, etc., which are not limited here. The heat mutation can be represented by 1 or 0, 1 represents heat mutation, and 0 represents that it does not belong to the heat mutation type.
[0198] During the specific implementation process, the link access characteristics, link propagation object characteristics and link jump characteristics of the target link can be obtained to obtain the characteristics to be detected; or only some of the link access characteristics, link propagation object characteristics and link jump characteristics of the target link can be obtained, for example, only the link propagation object characteristics can be obtained as the characteristics to be detected. The specific process of determining the characteristics to be detected will be further elaborated in detail below.
[0199] Step S204: Detect the target link based on the features to be detected by using the trained anomaly detection model to obtain an anomaly detection result of the target link.
[0200] The abnormality detection result may include that the target link is an abnormal link, or that the target link is a normal link.
[0201] Specifically, the abnormal link may be a target link whose content is specific abnormal content, for example, including pornographic videos and the like.
[0202] In a specific implementation process, the anomaly detection model may output the probability that the target link is an abnormal link, and determine the anomaly detection result of the target link according to the probability that the target link is an abnormal link.
[0203] In the above embodiment, at least part of the link access features, link propagation object features and link jump features of the target link are obtained through the log information of the target link to be detected, and the features to be detected are obtained. Then, the target link is detected based on the features to be detected through the trained anomaly detection model to determine the anomaly detection result of the target link. The anomaly detection result of the target link can be determined without obtaining the page content corresponding to the target link, which can effectively save storage costs and computing costs and improve the detection efficiency of abnormal links.
[0204] In addition, the abnormal detection result of the target link can be determined without obtaining the page content corresponding to the target link. Detection can be performed on different types of target links, effectively improving the versatility of link detection.
[0205] In some possible implementations, the link propagation object feature is obtained based on the following method:
[0206] (1) querying the object of the propagation target link in the target link feature to obtain at least one link propagation object of the propagation target link;
[0207] (2) for each link propagation object, query the first link access record and the first link propagation record associated with the link propagation object;
[0208] (3) based on the degree of association between the first link access record and the abnormal link, and the degree of association between the first link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object;
[0209] (4) Generate link propagation object features based on the object anomaly level of each link propagation object.
[0210] The object anomaly level is used to represent the probability that the object is associated with an abnormal link.
[0211] Specifically, the higher the object anomaly level is, the higher the probability that the object propagates or accesses an abnormal link is.
[0212] In some possible implementations, the link jump feature is obtained based on the following method:
[0213] (1) Query the access time of each link contained in each access path;
[0214] (2) Calculate the access time interval between every two adjacent links based on the access time of each link;
[0215] (3) Generate link jump features of the target link based on the access time intervals corresponding to the access paths.
[0216] Specifically, the access path may include multiple links, and the links included in the access path are jumped in sequence, and finally jump to the target link.
[0217] Specifically, the access time interval between every two adjacent links can be obtained by subtracting the access time between adjacent links.
[0218] The specific process of determining the object abnormality level of the link propagation object will be further described below in conjunction with the embodiments.
[0219] In some possible implementations, based on the degree of association between the first link access record and the abnormal link, and the degree of association between the first link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object may include:
[0220] (1) For each link propagation object, the access record corresponding to the link propagation object marked as an abnormal link in the first link access record is used as the second link access record.
[0221] Among them, the first link access record may include information about all links visited by the link propagation object, the time of each link visited, etc.; the first link propagation record may include information about all links propagated by the link propagation object, the time of the propagated link, the identification of the propagated object, etc., and the propagated object may include individuals or communities.
[0222] (2) The propagation record of the link propagation object for the abnormal link in the first link propagation record is used as the second link propagation record.
[0223] Specifically, if among the links accessed by the link propagation object, there are abnormal links that have been detected as abnormal or marked as abnormal, then the second link access record marked as the abnormal link is extracted; similarly, if among the links propagated by the link propagation object, there are abnormal links that have been detected as abnormal or marked as abnormal, then the second link propagation record marked as the abnormal link is extracted.
[0224] (3) Based on the degree of association between the second link access record and the abnormal link, and the degree of association between the second link propagation record and the abnormal link, the object abnormality level of the link propagation object is obtained.
[0225] In some embodiments, a first anomaly evaluation value can be determined based on the number of visits to the abnormal link in the second link access record, and the first anomaly evaluation value can be used to indicate the degree of association between the second link access record and the abnormal link; a second anomaly evaluation value can be determined based on the number of propagations of the abnormal link in the second link propagation record, and the second anomaly evaluation value is used to indicate the degree of association between the second link propagation record and the abnormal link, and then the first anomaly evaluation value and the second anomaly evaluation value are combined to determine the abnormal level of the object.
[0226] In other embodiments, a third abnormality evaluation value may be determined based on a first ratio of the number of visits to the abnormal link in the second link access record to all the visited links, and the third abnormality evaluation value may also be used to indicate the degree of association between the second link access record and the abnormal link; a fourth abnormality evaluation value may be determined based on a second ratio of the number of propagation of the abnormal link in the second link propagation record to all the propagated links, and the fourth abnormality evaluation value may also be used to indicate the degree of association between the second link propagation record and the abnormal link, and then the third abnormality evaluation value and the fourth abnormality evaluation value may be combined to determine the abnormal level of the object.
[0227] In some possible implementations, obtaining the object abnormality level of the link propagation object based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link may include:
[0228] ① Counting the number of times the link propagation object accesses the abnormal link in the second link access record, and counting the number of times the link propagation object propagates at least one abnormal link in the second link propagation record;
[0229] ② Query the first interval range where the number of accesses and the number of propagation are located, and query the first probability of the link propagation object being associated with the abnormal link based on the first interval range;
[0230] ③ Obtain object attribute information of the link propagation object, generate label information of the link propagation object based on the object attribute information, and query the second probability associated with the abnormal link corresponding to the label information;
[0231] ④ Based on the first probability and the second probability, calculate the total probability of the link propagation object being associated with the abnormal link, and query the object abnormality level corresponding to the total probability.
[0232] Specifically, the greater the number of accesses and propagation times, the greater the first probability that the link propagation object is associated with the abnormal link.
[0233] In a specific implementation process, the first probability may be determined based on the total number of access times and the number of propagation times; or the first probability may be determined based on the weighted sum of the number of access times and the number of propagation times.
[0234] The object attribute information may include information such as the user's age and gender, and may also include information such as the user's search records and input records in a preset application.
[0235] Specifically, multiple interval ranges of access times and propagation times can be pre-set, multiple access times correspond to a first interval range, multiple propagation times set a second interval range, and a probability value can be pre-set for every two different first interval ranges and second interval ranges; or multiple interval ranges can be set for the sum of the access times and the propagation times, and different interval ranges correspond to different probability values.
[0236] During the specific implementation process, a trained label determination model can be used to determine the label information of the object, or information associated with the object portrait, based on the user's attribute information, and match the object's label information or portrait information with information such as abnormal labels to determine the second probability that the link propagation object is associated with the abnormal link.
[0237] In a specific implementation process, the object abnormality level may be determined based on a weighted sum of the first probability and the second probability, a total probability of the object being associated with the abnormal link, and then based on the total probability of the object being associated with the abnormal link.
[0238] Specifically, the total probability of an object being associated with an abnormal link is proportional to the object abnormality level, that is, the higher the total probability of an object being associated with an abnormal link, the higher the object abnormality level.
[0239] In some possible implementations, generating a link propagation object feature based on an object anomaly level of each link propagation object. Generating a link propagation object feature based on an object anomaly level of each link propagation object includes:
[0240] Based on the object anomaly level of each link propagation object, count the number of levels included in the object anomaly level corresponding to the target link, and the propagation number of each object anomaly level to the target link;
[0241] Based on the number of levels of the object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated.
[0242] Specifically, by counting the object anomaly level of each link propagation object, it is possible to determine how many different object anomaly levels are included in the multiple link propagation objects corresponding to the target link, as well as the propagation quantity of at least one link propagation object of each object anomaly level for the target link.
[0243] For example, the target link corresponds to 50 link propagation objects, of which 30 link propagation objects have an object anomaly level of A and 20 link propagation objects have an object anomaly level of B. Then the number of object anomaly levels corresponding to the target link is 2, the number of propagations corresponding to the object anomaly level A is 30, and the number of propagations corresponding to the object anomaly level B is 20.
[0244] In one example, the link propagation object features may be represented by the following Table 3.
[0245] Table 3 Link propagation object feature table
[0246]
[0247] In some possible implementations, based on the number of object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated, including:
[0248] Taking the target link as the link node and the link propagation object as the object node, and connecting each link node and the object node based on the propagation relationship between the target link and at least one link propagation object to obtain a first propagation relationship graph;
[0249] Inquiring in the propagation record the propagation time of each link propagation object propagation target link and the propagation quantity of each link propagation object propagation target link;
[0250] Add the propagation time of the propagation target link of each link propagation object, the propagation quantity of the propagation target link of each link propagation object, and the object abnormality level of each link propagation object to the information of each link propagation object in the first propagation relationship graph to obtain a second propagation relationship graph;
[0251] Generate relationship diagram annotation information based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link, add the relationship diagram annotation information to the second propagation relationship diagram to obtain a third propagation relationship diagram, and use the third propagation relationship diagram as the link propagation object feature.
[0252] like Figure 3 As shown, Figure 3 This is a schematic diagram of the first propagation relationship diagram of a target link in an example. The target link (i.e., link A shown in the figure) may include link propagation object 1 (i.e., object 1 shown in the figure), link propagation object 2 (i.e., object 2 shown in the figure), link propagation object 3 (i.e., object 3 shown in the figure), and link propagation object 4 (i.e., object 4 shown in the figure).
[0253] like Figure 4 As shown, Figure 4 It is a schematic diagram of the second propagation relationship diagram of the target link in an example, wherein the link propagation object 1 is level one, represented by checkered shading in the figure, link propagation object 2 and link propagation object 3 are both level two, represented by dashed shading in the figure, link propagation object 3 is level three, and the object anomaly level one is greater than level two, and level two is greater than level three. The higher the object anomaly level, the higher the probability that the object is associated with an abnormal link.
[0254] In some possible implementations, the following further includes:
[0255] (1) A link that has at least one common link propagation object with the target link is regarded as an associated link of the target link.
[0256] Specifically, at least one link propagation object of the target link may be determined, and for each link propagation object, links other than the target link among the links propagated by the link propagation object may be determined, that is, associated links of the target link may be obtained.
[0257] (2) If the target link has at least one associated link, query the link type of at least one associated link.
[0258] Specifically, it is determined whether at least one associated link has been detected to be abnormal or whether it has been marked as an abnormal type.
[0259] like Figure 5 It is a propagation relationship diagram between multiple links and multiple propagation objects in an example. Figure 5 The target link (link A shown in the figure) may include multiple links (link B, link C, link D shown in the figure), as well as the propagation relationship between the propagation objects of each link, that is, the propagation relationship between objects 1 to 9 shown in the figure and multiple links. Figure 5As shown, there is a common link propagation object between link A and link D, namely object 1 and object 7 shown in the figure, and link D is an associated link of link A.
[0260] If the link type of at least one associated link is found, link propagation object features are generated based on the object anomaly level of each link propagation object, including:
[0261] Based on the link type of the at least one associated link found and the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0262] Specifically, based on the link type of at least one associated link, the total number of abnormal link types among all associated links can be determined, and the proportion of abnormal links in all associated links can be determined. Combined with these features and the object anomaly level of each link propagation object, link propagation object features can be constructed.
[0263] In some possible implementations, generating a link jump feature of a target link based on each access time interval corresponding to each access path may include:
[0264] (1) for each access path, query the first number of upstream links of the target link in each link included in the access path;
[0265] (2) If the first number is greater than or equal to the preset number, and the access time intervals corresponding to the access path are less than or equal to the preset time interval, then the jump type of the target link corresponding to the access path is an abnormal jump type;
[0266] (3) Generate sample jump features based on the jump type of the target link corresponding to each access path, the first number of upstream links in each access path corresponding to the target link, and the access time intervals corresponding to each access path.
[0267] The upstream link of the target link may include a direct upstream link of the target link or an indirect upstream link of the target link.
[0268] Specifically, the object may actively trigger a jump to the target link once or multiple times through the upstream link of the target link, or the object may automatically jump to the target link once or multiple times after entering the upstream link.
[0269] Specifically, the time interval between every two adjacent upstream links may be determined according to the access time of each upstream link.
[0270] like Figure 6As shown in the figure, the upstream link 1, i.e., URL (Uniform Resource Locator) 1 shown in the figure jumps to the upstream link 2 (URL2 shown in the figure), and then jumps in sequence to reach the target link, i.e., URLn shown in the figure, and determines the access time between each two adjacent links, i.e., the access time interval between two links with a direct jump relationship.
[0271] The above embodiment describes the specific process of obtaining the link propagation object features and the link jump features. The following will describe the training process of the anomaly detection model in conjunction with the embodiment.
[0272] In some possible implementations, the anomaly detection model is trained based on the following method:
[0273] (1) Obtain sample log information for multiple sample links.
[0274] For each sample link, the sample log information includes a sample access record and a sample propagation record for the sample link.
[0275] Specifically, the sample access record and sample propagation record of the sample link are similar to the access record and propagation record of the target link. The sample access record may include the sample object identifiers of multiple sample link access objects that access the sample link, the time when each sample link access object accesses the sample link, and the like.
[0276] In an example, the access record may be as shown in Table 4 below:
[0277]
[0278]
[0279] Among them, the sample propagation record may include the sample object identifiers of multiple sample link propagation objects of the propagated sample link, the sample link propagation time of each sample link access object, the identifier of the propagated object of the sample link, the propagated community identifier, etc.
[0280] (2) For each sample link, the sample link access feature, the sample link propagation object feature, and the sample link jump feature of the sample link are obtained based on the sample log information.
[0281] Specifically, the specific process of obtaining the sample link access feature, the sample link propagation object feature and the sample link jump feature is the same as the process of obtaining the corresponding features of the target link, and will not be repeated here.
[0282] It should be noted that during the training process, the sample link access features, sample link propagation object features, and sample link jump features of the sample link need to be obtained.
[0283] When detecting the target link, at least some of the link access features, link propagation object features, and link jump features of the target link can be obtained as needed. That is, it is not necessary to obtain all the features during online detection.
[0284] (3) Based on at least part of the features of the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, the initial anomaly detection model is trained to obtain a trained anomaly detection model.
[0285] Among them, each sample link is marked with a sample type, that is, it is known whether each sample link is an abnormal link or a non-abnormal link.
[0286] Specifically, for each sample link, based on at least part of the sample link access features, sample link propagation object features and sample link jump features, the input features of the sample link are obtained; the input features of each sample link are input into the initial anomaly detection model to obtain the prediction results corresponding to the initial anomaly detection model, and then based on the difference between the prediction results and the sample type, the training loss is determined, and if the training loss meets the preset conditions, the anomaly detection model is obtained; if the training loss does not meet the preset conditions, the parameters of the initial anomaly detection model are adjusted, and then the above process is repeated based on the updated initial anomaly detection model until the obtained training loss meets the preset conditions, and a trained anomaly detection model is obtained.
[0287] Specifically, iForest (Isolation Forest) can be used as an anomaly detection model. The basic idea of iForest is highly similar to that of random forest. The difference is that for a sample set with T decision trees, IForest will also randomly sample the training set. For each decision tree, IForest randomly selects a partition feature and a partition threshold for the partition feature.
[0288] In some possible implementations, before training the initial anomaly detection model based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the following further includes:
[0289] Based on the importance of the sample link access features, sample link propagation object features and sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, sample link propagation object features and sample link jump features of each sample link.
[0290] Specifically, the importance of each feature can be evaluated through the model, and based on the importance, filtering features can be selected from sample link access features, sample link propagation object features, and sample link jump features.
[0291] In a specific implementation process, based on the importance of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, sample link propagation object features, and sample link jump features of each sample link, which may include:
[0292] Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model;
[0293] Based on the importance ranking of each feature among the sample link access feature, the sample link propagation object feature and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature and the sample link jump feature.
[0294] Among them, the importance evaluation model may include an xgboost (distributed gradient boosting library) model; the preset evaluation indicators may include AUC (Area Under Curve, the area under the ROC curve). The larger the AUC, the greater the possibility that the model puts the positive example in front, which is used to measure the ranking ability of the model; the ROC (receiver operating characteristic) curve is a tool for evaluating the performance of classification models.
[0295] like Figure 7 As shown, the sample link access features, sample link propagation object features and sample link jump features of each sample link are obtained, that is, the sample preparation shown in the figure, and the obtained features are input into the xgboost model for training and fitting. After obtaining an xgboost model with an expected AUC, the trained xgboost model is obtained. At this time, the xgboost model outputs the importance ranking of each feature, and selects the top k features in terms of feature importance as screening features.
[0296] Specifically, based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the initial anomaly detection model is trained to obtain a trained anomaly detection model, including:
[0297] Based on the screening features, the initial anomaly detection model is trained to obtain a trained anomaly detection model.
[0298] Specifically, after screening the sample link access features, sample link propagation object features and sample link jump features of each sample link, screening features are obtained, and only the screening features are used to train the initial anomaly detection model.
[0299] In the above embodiment, by screening the sample link access features, sample link propagation object features and sample link jump features of each sample link, the screening features are obtained, and then the initial anomaly detection model is trained using the screening features to obtain a trained anomaly detection model, which can reduce the amount of calculation of redundant features and effectively improve the accuracy and efficiency of model training.
[0300] The target link features are associated with each other to obtain the features to be detected, including:
[0301] Based on the screening features, the target link features are associated with each other to obtain the features to be detected.
[0302] Specifically, based on the screening features used in the training process, it is possible to determine which features are necessary when detecting the target link online, thereby obtaining features corresponding to the screening features from the target link features, and constructing corresponding association relationships to obtain features to be detected.
[0303] For example, if the sample link access feature, the sample link propagation object feature and the sample link jump feature are screened to obtain the sample link propagation object feature, then when detecting the target link, it is only necessary to obtain the link propagation object feature corresponding to the target link to obtain the feature to be detected.
[0304] In some possible implementations, the sample link access feature, the sample link propagation object feature, and the sample link jump feature each include at least one sub-feature;
[0305] Based on the importance ranking of each feature in the sample link access feature, the sample link propagation object feature, and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature, and the sample link jump feature, including:
[0306] Based on the importance ranking of each sub-feature output by the trained importance assessment model, a preset number of sub-features with the highest importance ranking among the sub-features are used as screening features.
[0307] Specifically, the sample link access feature, the sample link propagation object feature, and the sample link jump feature can be divided into more fine-grained sub-features, and then the sub-features are sorted. This can distinguish the importance of each sub-feature at a finer granularity and improve the accuracy of the trained anomaly detection model.
[0308] For example, the sample link access feature includes the sample access heat change feature and the sample link propagation quantity feature. The sample access heat change feature can be used as a sub-feature, and the sample link propagation quantity feature can be used as a sub-feature.
[0309] In some possible implementations, the method further includes:
[0310] (1) Based on the importance ranking of each feature, obtain the first feature with the highest importance among the features to be detected;
[0311] (2) If the first feature does not conform to the normal feature value range, the abnormal link of the abnormal detection result of the target link is an abnormal link.
[0312] Specifically, for the first feature with a higher importance ranking, the long-tail data can be analyzed and an abnormal threshold can be defined to distinguish abnormal points from normal points, thereby determining whether the target link is an abnormal link.
[0313] The trained anomaly detection model is used to detect the target link based on the features to be detected, and the anomaly detection results of the target link are obtained, including:
[0314] If the first feature is within the normal feature value range, the target link is detected based on the feature to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link.
[0315] Specifically, if the first feature is within the normal feature value range, the feature to be detected is further detected by the anomaly detection model to determine the final anomaly detection result.
[0316] In some possible implementations, the target link is detected based on the features to be detected by using a trained anomaly detection model to obtain an anomaly detection result of the target link, including:
[0317] The features other than the first feature among the features to be detected are taken as the second features;
[0318] The trained anomaly detection model is used to detect the target link based on the second feature to obtain the anomaly detection result of the target link.
[0319] Specifically, if the first feature is within the normal feature value range, the other features other than the first feature, that is, the second feature, can be further detected through the anomaly detection model to determine the anomaly detection result.
[0320] In order to more clearly illustrate the link detection method of the present application, it will be further elaborated below with reference to examples.
[0321] like Figure 8 As shown, in one example, the link detection method of the present application may include:
[0322] Get sample log information of multiple sample links;
[0323] For each sample link, determine a sample link access feature, a sample link propagation object feature, and a sample link jump feature of the sample link based on the sample log information;
[0324] Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model;
[0325] The importance ranking of each feature among the sample link access feature, the sample link propagation object feature, and the sample link jump feature based on the output of the trained importance evaluation model;
[0326] Filtering features from sample link access features, sample link propagation object features, and sample link jump features based on importance ranking;
[0327] Based on the screening features, the initial anomaly detection model is trained to obtain a trained anomaly detection model;
[0328] Based on the screening features and log information, the features to be detected are obtained;
[0329] Based on the importance ranking of each feature, determine the first feature with the highest importance from the features to be detected;
[0330] Determine whether the first feature is within a normal feature value range;
[0331] If yes, determining a second feature other than the first feature among the features to be detected;
[0332] Using the trained anomaly detection model, the target link is detected based on the second feature to determine an anomaly detection result of the target link;
[0333] If not, the target link is the anomaly detection result of the anomaly link.
[0334] The above-mentioned link detection method obtains at least part of the link access features, link propagation object features and link jump features of the target link through the log information of the target link to be detected, obtains the features to be detected, and then detects the target link based on the features to be detected through the trained anomaly detection model to determine the anomaly detection result of the target link. It is not necessary to obtain the page content corresponding to the target link to determine the anomaly detection result of the target link, which can effectively save storage costs and computing costs and improve the detection efficiency of abnormal links.
[0335] In addition, the abnormal detection result of the target link can be determined without obtaining the page content corresponding to the target link. Detection can be performed on different types of target links, effectively improving the versatility of link detection.
[0336] Furthermore, by screening the sample link access features, sample link propagation object features and sample link jump features of each sample link, the screening features are obtained, and then the initial anomaly detection model is trained using the screening features to obtain a trained anomaly detection model, which can reduce the amount of calculation of redundant features and effectively improve the accuracy and efficiency of model training.
[0337] Furthermore, the sample link access feature, the sample link propagation object feature and the sample link jump feature are divided into more fine-grained sub-features, and then the sub-features are sorted. This can distinguish the importance of each sub-feature at a finer granularity and improve the accuracy of the trained anomaly detection model.
[0338] like Fig. 9 As shown, in some possible implementations, a link detection device is provided, including:
[0339] The acquisition module 901 is used to acquire the log information of the target link to be detected; wherein the log information includes the access record and propagation record of the target link;
[0340] The feature extraction module 902 is used to obtain the target link feature of the target link by extracting the feature of the log information; the target link feature includes at least one of the access object information, propagation object information and access path information of the target link;
[0341] The feature construction module 903 is used to construct an association relationship for the target link feature to obtain the feature to be detected; the association relationship includes at least one of an access relationship, a propagation relationship and a jump relationship; the feature to be detected includes at least part of the link access feature, the link propagation object feature and the link jump feature of the target link;
[0342] The detection module 904 is used to detect the target link based on the features to be detected by using the trained anomaly detection model to obtain an anomaly detection result of the target link.
[0343] In some possible implementations, when acquiring the object abnormality level of the link propagation object based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, the feature construction module 903 is specifically used to:
[0344] For each link propagation object, taking the access record corresponding to the link propagation object marked as an abnormal link in the first link access record as the second link access record;
[0345] Using the propagation record of the link propagation object for the abnormal link in the first link propagation record as the second link propagation record;
[0346] Based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, the object abnormality level of the link propagation object is acquired.
[0347] In some possible implementations, when the feature construction module 903 obtains the object abnormality level of the link propagation object based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, it is specifically used to:
[0348] Counting the number of times the link propagation object accesses the abnormal link in the second link access record, and counting the number of times the link propagation object propagates at least one abnormal link in the second link propagation record;
[0349] Querying a first interval range where the number of accesses and the number of propagation are located, and querying a first probability of the link propagation object being associated with the abnormal link based on the first interval range;
[0350] Obtaining object attribute information of the link propagation object, generating label information of the link propagation object based on the object attribute information, and querying a second probability associated with the abnormal link corresponding to the label information;
[0351] The total probability of the link propagation object being associated with the abnormal link is calculated based on the first probability and the second probability, and the object abnormality level corresponding to the total probability is queried.
[0352] In some possible implementations, the feature construction module 903 generates the link propagation object feature based on the object anomaly level of each link propagation object. When generating the link propagation object feature based on the object anomaly level of each link propagation object, the feature construction module 903 is specifically used to:
[0353] Based on the object anomaly level of each link propagation object, count the number of levels included in the object anomaly level corresponding to the target link, and the propagation number of each object anomaly level to the target link;
[0354] Based on the number of levels of the object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, a link propagation object feature is generated.
[0355] In some possible implementations, when generating the link propagation object feature based on the number of levels of the object anomaly levels corresponding to the target link and the number of propagations of each object anomaly level to the target link, the feature construction module 903 is specifically used to:
[0356] Taking the target link as the link node and the link propagation object as the object node, and connecting each link node and the object node based on the propagation relationship between the target link and at least one link propagation object to obtain a first propagation relationship graph;
[0357] Inquiring in the propagation record the propagation time of each link propagation object propagation target link and the propagation quantity of each link propagation object propagation target link;
[0358] Add the propagation time of the propagation target link of each link propagation object, the propagation quantity of the propagation target link of each link propagation object, and the object abnormality level of each link propagation object to the information of each link propagation object in the first propagation relationship graph to obtain a second propagation relationship graph;
[0359] Generate relationship diagram annotation information based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link, add the relationship diagram annotation information to the second propagation relationship diagram to obtain a third propagation relationship diagram, and use the third propagation relationship diagram as the link propagation object feature.
[0360] In some possible implementations, a third acquisition module is further included, which is used to:
[0361] The link with which the target link has at least one common link propagation object is used as an associated link of the target link;
[0362] If the target link has at least one associated link, query the link type of at least one associated link;
[0363] If at least one link type of an associated link is found, the feature construction module 903 generates the link propagation object feature based on the object anomaly level of each link propagation object, specifically for:
[0364] Based on the link type of the at least one associated link found and the object anomaly level of each link propagation object, a link propagation object feature is generated.
[0365] In some possible implementations, when the feature construction module 903 generates the link jump feature of the target link based on each access time interval corresponding to each access path, it is specifically used to:
[0366] For each access path, query the first number of upstream links of the target link in each link included in the access path;
[0367] If the first number is greater than or equal to the preset number, and each access time interval corresponding to the access path is less than or equal to the preset time interval, then the jump type of the target link corresponding to the access path is an abnormal jump type;
[0368] A sample jump feature is generated based on the jump type of the target link corresponding to each access path, the first number of upstream links in each access path corresponding to the target link, and each access time interval corresponding to each access path.
[0369] In some possible implementations, a training module is further included for:
[0370] Obtaining sample log information of a plurality of sample links; wherein, for each sample link, the sample log information includes a sample access record and a sample propagation record for the sample link;
[0371] For each sample link, obtain the sample link access feature, the sample link propagation object feature and the sample link jump feature of the sample link based on the sample log information;
[0372] Based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the initial anomaly detection model is trained to obtain a trained anomaly detection model.
[0373] In some possible implementations, a screening module is further included for:
[0374] Based on the importance of the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link, screening features whose importance meets the preset conditions are screened out from the sample link access features, the sample link propagation object features, and the sample link jump features of each sample link;
[0375] The training module trains the initial anomaly detection model based on at least part of the sample link access features, sample link propagation object features, and sample link jump features of each sample link to obtain a trained anomaly detection model, specifically for:
[0376] Based on the screening features, the initial anomaly detection model is trained to obtain a trained anomaly detection model;
[0377] When the detection module constructs the association relationship between the target link features and obtains the features to be detected, it is specifically used to:
[0378] Based on the screening features, the target link features are associated with each other to obtain the features to be detected.
[0379] In some possible implementations, the screening module is specifically used to screen out screening features whose importance meets preset conditions from the sample link access features, sample link propagation object features, and sample link jump features of each sample link based on the importance of the sample link access features, sample link propagation object features, and sample link jump features of each sample link:
[0380] Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model;
[0381] Based on the importance ranking of each feature among the sample link access feature, the sample link propagation object feature and the sample link jump feature output by the trained importance evaluation model, the screening features are screened out from the sample link access feature, the sample link propagation object feature and the sample link jump feature.
[0382] In some possible implementations, the sample link access feature, the sample link propagation object feature, and the sample link jump feature each include at least one sub-feature;
[0383] The screening module is specifically used to sort out the screening features from the sample link access features, the sample link propagation object features and the sample link jump features based on the importance ranking of each feature in the sample link access features, the sample link propagation object features and the sample link jump features output by the trained importance evaluation model:
[0384] Based on the importance ranking of each sub-feature output by the trained importance assessment model, a preset number of sub-features with the highest importance ranking among the sub-features are used as screening features.
[0385] In some possible implementations, a determination module is further included, which is used to:
[0386] Based on the importance ranking of each feature, obtain the first feature with the highest importance among the features to be detected;
[0387] If the first feature does not conform to the normal feature value range, the target link is an abnormal link of the abnormal detection result;
[0388] When the detection module detects the target link based on the features to be detected through the trained anomaly detection model and obtains the anomaly detection result of the target link, it is specifically used for:
[0389] If the first feature is within the normal feature value range, the target link is detected based on the feature to be detected through the trained anomaly detection model to obtain the anomaly detection result of the target link.
[0390] In some possible implementations, when the detection module detects the target link based on the feature to be detected by using the trained anomaly detection model to obtain the anomaly detection result of the target link, it is specifically used to:
[0391] The features other than the first feature among the features to be detected are taken as the second features;
[0392] The trained anomaly detection model is used to detect the target link based on the second feature to obtain the anomaly detection result of the target link.
[0393] The above-mentioned link detection device obtains at least part of the link access features, link propagation object features and link jump features of the target link through the log information of the target link to be detected, obtains the features to be detected, and then detects the target link based on the features to be detected through the trained anomaly detection model to determine the anomaly detection result of the target link. It is not necessary to obtain the page content corresponding to the target link to determine the anomaly detection result of the target link, which can effectively save storage costs and computing costs and improve the detection efficiency of abnormal links.
[0394] In addition, the abnormal detection result of the target link can be determined without obtaining the page content corresponding to the target link. Detection can be performed on different types of target links, effectively improving the versatility of link detection.
[0395] Furthermore, by screening the sample link access features, sample link propagation object features and sample link jump features of each sample link, the screening features are obtained, and then the initial anomaly detection model is trained using the screening features to obtain a trained anomaly detection model, which can reduce the amount of calculation of redundant features and effectively improve the accuracy and efficiency of model training.
[0396] Furthermore, the sample link access feature, the sample link propagation object feature and the sample link jump feature are divided into more fine-grained sub-features, and then the sub-features are sorted. This can distinguish the importance of each sub-feature at a finer granularity and improve the accuracy of the trained anomaly detection model.
[0397] The device of the embodiments of the present application can execute the method provided by the embodiments of the present application, and the implementation principles are similar. The actions performed by each module in the device of each embodiment of the present application correspond to the steps in the method of each embodiment of the present application. For the detailed functional description of each module of the device, please refer to the description in the corresponding method shown in the previous text, which will not be repeated here.
[0398] An embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory. When the processor executes the computer program stored in the memory, the method in any optional embodiment of the present application can be implemented.
[0399] Fig.10 FIG. 1 is a schematic diagram showing a structure of an electronic device to which an embodiment of the present invention is applicable. Fig.10 As shown, the electronic device may be a server or a user terminal, and the electronic device may be used to implement the method provided in any embodiment of the present invention.
[0400] like Fig.10 As shown in FIG. 1 , the electronic device 1000 may mainly include at least one processor 1001 ( Fig.10 1002, a communication module 1003 and an input / output interface 1004, etc. Optionally, the components can be connected and communicated through a bus 1005. It should be noted that Fig.10 The structure of the electronic device 1000 shown in the figure is merely illustrative and does not constitute a limitation on the electronic device to which the method provided in the embodiment of the present application is applicable.
[0401] The memory 1002 may be used to store an operating system and an application program, etc. The application program may include a computer program that implements the method shown in the embodiment of the present invention when called by the processor 1001, and may also include a program for implementing other functions or services. The memory 1002 may be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and computer programs, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compressed optical disk, laser disk, optical disk, digital versatile disk, Blu-ray disk, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0402] The processor 1001 is connected to the memory 1002 via the bus 1005, and implements the corresponding functions by calling the application program stored in the memory 1002. Among them, the processor 1001 can be a CPU (Central Processing Unit), a general processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof, which can implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of the present invention. The processor 1001 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0403] The electronic device 1000 can be connected to the network through the communication module 1003 (which may include but is not limited to components such as a network interface) to communicate with other devices (such as a user terminal or a server, etc.) through the network to achieve data interaction, such as sending data to other devices or receiving data from other devices. Among them, the communication module 1003 may include a wired network interface and / or a wireless network interface, etc., that is, the communication module may include at least one of a wired communication module or a wireless communication module.
[0404] The electronic device 1000 can be connected to the required input / output devices, such as a keyboard, a display device, etc., through the input / output interface 1004. The electronic device 1000 itself can have a display device, and can also be connected to other display devices through the interface 1004. Optionally, a storage device, such as a hard disk, can also be connected through the interface 1004, so that data in the electronic device 1000 can be stored in the storage device, or data in the storage device can be read, and data in the storage device can also be stored in the memory 1002. It can be understood that the input / output interface 1004 can be a wired interface or a wireless interface. Depending on the actual application scenario, the device connected to the input / output interface 1004 can be a component of the electronic device 1000, or it can be an external device connected to the electronic device 1000 when needed.
[0405] The bus 1005 for connecting the components may include a path to transmit information between the above components. The bus 1005 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. According to different functions, the bus 1005 may be divided into an address bus, a data bus, a control bus, etc.
[0406] Optionally, for the solution provided by the embodiment of the present invention, the memory 1002 can be used to store a computer program for executing the solution of the present invention, and run by the processor 1001. When the processor 1001 runs the computer program, the action of the method or device provided by the embodiment of the present invention is implemented.
[0407] Based on the same principle as the method provided in the embodiment of the present application, the embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the corresponding content of the aforementioned method embodiment can be implemented.
[0408] An embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the corresponding content of the aforementioned method embodiment can be implemented.
[0409] It should be noted that the terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchangeable where appropriate, so that the embodiments of the application described herein can be implemented in an order other than that shown or described in the drawings.
[0410] It should be understood that, although each operation step is indicated by arrows in the flowchart of the embodiment of the present application, the implementation order of these steps is not limited to the order indicated by the arrows. Unless clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be performed in other orders according to demand. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on actual implementation scenarios. Some or all of these sub-steps or stages may be executed at the same time, and each sub-step or stage in these sub-steps or stages may also be executed at different times respectively. In different scenarios of execution time, the execution order of these sub-steps or stages may be flexibly configured according to demand, and the embodiment of the present application does not limit this.
[0411] The above is only an optional implementation method for some implementation scenarios of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of the present application, other similar implementation methods based on the technical ideas of the present application are also within the protection scope of the embodiments of the present application.
Claims
1. A link detection method, characterized in that: The method comprises: Obtaining log information of the target link to be detected; wherein the log information includes access records and propagation records of the target link; By performing feature extraction on the log information, a target link feature of the target link is obtained; the target link feature includes at least one of access object information, propagation object information and access path information of the target link; Constructing an association relationship for the target link feature to obtain a feature to be detected; the association relationship includes at least one of an access relationship, a propagation relationship, and a jump relationship; the feature to be detected includes at least part of the link access feature, the link propagation object feature, and the link jump feature of the target link; The target link is detected based on the feature to be detected by the trained anomaly detection model to obtain an anomaly detection result of the target link.
2. The method according to claim 1, characterized in that The link access feature includes an access heat change feature; the link propagation object feature is obtained based on the following method: Searching the target link feature for an object that propagates the target link, and obtaining at least one link propagation object that propagates the target link; For each link propagation object, query the first link access record and the first link propagation record associated with the link propagation object; Based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, obtaining the object abnormality level of the link propagation object; The link propagation object feature is generated based on the object anomaly level of each link propagation object.
3. The method according to claim 1, characterized in that The link jump feature is obtained based on the following method: Query the access time of each link contained in each access path; Calculate the access time interval between every two adjacent links based on the access time of each link; The link jump feature of the target link is generated based on each access time interval corresponding to each access path.
4. The method according to claim 2, characterized in that: The acquiring the object abnormality level of the link propagation object based on the association degree between the first link access record and the abnormal link, and the association degree between the first link propagation record and the abnormal link, comprises: For each link propagation object, taking the access record corresponding to the link propagation object marked as an abnormal link in the first link access record as the second link access record; Using the propagation record of the link propagation object for the abnormal link in the first link propagation record as the second link propagation record; Based on the degree of association between the second link access record and the abnormal link, and the degree of association between the second link propagation record and the abnormal link, the object abnormality level of the link propagation object is acquired.
5. The method according to claim 4, characterized in that The acquiring the object abnormality level of the link propagation object based on the association degree between the second link access record and the abnormal link, and the association degree between the second link propagation record and the abnormal link, comprises: Counting the number of times the link propagation object in the second link access record accesses the abnormal link, and counting the number of times the link propagation object in the second link propagation record propagates at least one of the abnormal links; querying a first interval range where the number of accesses and the number of propagation are located, and querying a first probability that the link propagation object is associated with an abnormal link based on the first interval range; Acquire object attribute information of the link propagation object, generate label information of the link propagation object based on the object attribute information, and query a second probability associated with the abnormal link corresponding to the label information; The total probability of the link propagation object being associated with the abnormal link is calculated based on the first probability and the second probability, and the object abnormality level corresponding to the total probability is queried.
6. The method according to claim 2, characterized in that The generating the link propagation object feature based on the object anomaly level of each link propagation object includes: Based on the object anomaly level of each link propagation object, counting the number of levels included in the object anomaly level corresponding to the target link, and the propagation number of each object anomaly level for the target link; The link propagation object feature is generated based on the number of levels of the object anomaly level corresponding to the target link and the propagation number of each object anomaly level for the target link.
7. The method according to claim 6, characterized in that The generating the link propagation object feature based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link includes: Taking the target link as a link node and the link propagation object as an object node, and connecting each link node and object node based on the propagation relationship between the target link and at least one link propagation object to obtain a first propagation relationship graph; Inquiring in the propagation record the propagation time of each link propagation object propagating the target link, and the propagation quantity of each link propagation object propagating the target link; Add the propagation time of each link propagation object propagating the target link, the propagation quantity of each link propagation object propagating the target link, and the object abnormality level of each link propagation object to the information of each link propagation object in the first propagation relationship graph to obtain a second propagation relationship graph; Generate relationship diagram annotation information based on the number of object anomaly levels corresponding to the target link and the propagation number of each object anomaly level for the target link, add the relationship diagram annotation information to the second propagation relationship diagram to obtain a third propagation relationship diagram, and use the third propagation relationship diagram as the link propagation object feature.
8. The method according to claim 2, characterized in that: Also includes: Using a link with at least one common link propagation object of the target link as an associated link of the target link; If the target link has at least one associated link, query the link type of the at least one associated link; If the link type of at least one associated link is found, the link propagation object feature is generated based on the object anomaly level of each link propagation object, including: The link propagation object feature is generated based on the link type of the at least one associated link that is queried and the object anomaly level of each link propagation object.
9. The method according to claim 3, characterized in that: The generating the link jump feature of the target link based on each access time interval corresponding to each access path includes: For each access path, querying a first number of upstream links of the target link in each link included in the access path; If the first number is greater than or equal to a preset number, and each access time interval corresponding to the access path is less than or equal to a preset time interval, then the jump type of the target link corresponding to the access path is an abnormal jump type; The sample jump feature is generated based on the jump type of the target link corresponding to each access path, the first number of upstream links in each access path corresponding to the target link, and each access time interval corresponding to each access path.
10. The method according to claim 1, characterized in that The anomaly detection model is trained based on the following method: Acquire sample log information of a plurality of sample links; wherein, for each sample link, the sample log information includes a sample access record and a sample propagation record for the sample link; For each sample link, obtaining a sample link access feature, a sample link propagation object feature, and a sample link jump feature of the sample link based on the sample log information; Based on at least part of the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial anomaly detection model is trained to obtain the trained anomaly detection model.
11. The method according to claim 10, characterized in that Before training the initial anomaly detection model based on at least some of the sample link access features, sample link propagation object features, and sample link jump features of each sample link, the method further includes: Based on the importance of the sample link access features, sample link propagation object features and sample link jump features of each sample link, screening features whose importance meets preset conditions are screened out from the sample link access features, sample link propagation object features and sample link jump features of each sample link; The training of the initial anomaly detection model based on at least part of the sample link access features, sample link propagation object features, and sample link jump features of each sample link to obtain the trained anomaly detection model includes: Based on the screening features, the initial anomaly detection model is trained to obtain the trained anomaly detection model; The step of constructing an association relationship between the target link features to obtain features to be detected includes: Based on the screening features, an association relationship is constructed for the target link features to obtain features to be detected.
12. The method according to claim 11, characterized in that The importance of the sample link access feature, the sample link propagation object feature, and the sample link jump feature of each sample link is based on the importance of the sample link access feature, the sample link propagation object feature, and the sample link jump feature of each sample link, and the screening feature whose importance meets the preset conditions is screened out from the sample link access feature, the sample link propagation object feature, and the sample link jump feature of each sample link, including: Based on the sample link access features, sample link propagation object features and sample link jump features of each sample link, the initial importance evaluation model is trained until it meets the preset evaluation indicators to obtain a trained importance evaluation model; Based on the importance ranking of each feature among the sample link access feature, the sample link propagation object feature and the sample link jump feature output by the trained importance evaluation model, the screening feature is screened out from the sample link access feature, the sample link propagation object feature and the sample link jump feature.
13. The method according to claim 12, characterized in that The sample link access feature, the sample link propagation object feature and the sample link jump feature each include at least one sub-feature; The importance ranking of each feature among the sample link access feature, the sample link propagation object feature, and the sample link jump feature based on the output of the trained importance evaluation model, and screening the screening feature from the sample link access feature, the sample link propagation object feature, and the sample link jump feature, comprises: Based on the importance ranking of each sub-feature output by the trained importance assessment model, a preset number of sub-features with the highest importance ranking among the sub-features are used as the screening features.
14. The method according to claim 12, characterized in that The method further comprises: Based on the importance ranking of each feature, obtaining a first feature with the highest importance among the features to be detected; If the first feature does not conform to the normal feature value range, the abnormal link of the abnormal detection result of the target link; The trained anomaly detection model detects the target link based on the feature to be detected to obtain an anomaly detection result of the target link, including: If the first feature is within the normal feature value range, the trained anomaly detection model detects the target link based on the feature to be detected to obtain an anomaly detection result of the target link.
15. The method according to claim 14, characterized in that The trained anomaly detection model detects the target link based on the feature to be detected to obtain an anomaly detection result of the target link, including: Using the features other than the first feature among the features to be detected as second features; The target link is detected based on the second feature by using a trained anomaly detection model to obtain an anomaly detection result of the target link.
16. A link detection device, characterized in that: The device comprises: An acquisition module, used to acquire log information of a target link to be detected; wherein the log information includes access records and propagation records of the target link; A feature extraction module, configured to obtain a target link feature of the target link by performing feature extraction on the log information; the target link feature includes at least one of access object information, propagation object information and access path information of the target link; A feature construction module, used to construct an association relationship for the target link feature to obtain a feature to be detected; the association relationship includes at least one of an access relationship, a propagation relationship and a jump relationship; the feature to be detected includes at least part of the link access feature, the link propagation object feature and the link jump feature of the target link; The detection module is used to detect the target link based on the to-be-detected features by using a trained anomaly detection model to obtain an anomaly detection result of the target link.
17. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein a computer program is stored in the memory, and the processor executes the computer program to implement the method according to any one of claims 1 to 15.
18. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 15 is implemented.