Account unauthorized swiping prevention method and device, electronic equipment and storage medium
By obtaining and analyzing the operations, equipment and transfer characteristics in user transfer requests, determining the risk level of account stolen brushing, and taking corresponding anti-theft brushing control measures, the problem of inability to effectively predict and control account stolen brushing in the existing technology is solved, and the security of the account is improved.
Patent Information
- Application Number
- CN202510161280.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-16
AI Technical Summary
There is a lack of effective risk prediction and risk control methods for financial accounts in the prior art, which cannot guarantee the security of the account, especially when the risk level of being stolen, there is a lack of effective intervention control.
By obtaining the user's transfer request for the logged-in account, it is determined whether the receiving device is a non-trusted device. If so, the risk level of the account being stolen by the operation characteristics, equipment characteristics and transfer characteristics is determined, and the anti-theft control method is determined based on the risk level to improve the security of the account.
It realizes the prediction of the risk level of the account being stolen and timely anti-theft control, reduces the risk of the account being stolen, avoids the dilemma of recovery, and improves the security of user accounts.
Smart Images

Figure CN120013537A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to artificial intelligence technology, and in particular to a method, device, electronic device and storage medium for preventing account fraud. Background Art
[0002] With the widespread popularity of financial technology applications, most of our financial activities rely on electronic accounts. In order to protect the safety of users' funds, risk prevention and control of accounts has become very important.
[0003] The prior art lacks effective risk prediction and risk control methods for financial accounts, which makes it impossible to ensure the security of accounts. In addition, there is a lack of effective intervention and control when the risk level of stolen credit cards is high. Summary of the invention
[0004] The present application provides a method, device, electronic device and storage medium for preventing account fraud, so as to predict the risk level of account fraud, and timely perform anti-fraud control on account transfer behavior according to the risk level of fraud, thereby improving the security of the account.
[0005] In a first aspect, an embodiment of the present application provides an account fraud prevention method, the account fraud prevention method comprising:
[0006] Get the user's transfer request to transfer money to the logged-in account;
[0007] Determining whether the receiving device that receives the transfer request is an untrusted device;
[0008] If yes, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics;
[0009] Determine the account's anti-fraud control method based on the risk level of fraudulent use.
[0010] In a second aspect, the embodiment of the present application further provides an account fraud prevention device, the account fraud prevention device comprising:
[0011] A transfer request acquisition module is used to obtain a transfer request from a user to transfer money to a logged-in account;
[0012] A receiving device judgment module, used to determine whether the receiving device that receives the transfer request is an untrusted device;
[0013] A risk level determination module is used to determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics.
[0014] The anti-fraud control mode determination module is used to determine the anti-fraud control mode of the account according to the risk level of fraudulent use.
[0015] In a third aspect, an embodiment of the present application further provides an electronic device, the electronic device comprising:
[0016] one or more processors;
[0017] A storage device for storing one or more programs;
[0018] When one or more programs are executed by one or more processors, the one or more processors implement any one of the account fraud prevention methods provided in the embodiments of the present application.
[0019] In a fourth aspect, an embodiment of the present application further provides a storage medium comprising computer executable instructions, which, when executed by a computer processor, are used to execute any one of the account fraud prevention methods provided in the embodiments of the present application.
[0020] The present application obtains a transfer request from a user to transfer money to a logged-in account; determines whether the receiving device receiving the transfer request is an untrusted device; if so, determines the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics. When the account is logged in on an untrusted device, the risk level of being stolen is determined from multiple angles based on the operation characteristics, device characteristics and transfer characteristics, thereby improving the accuracy of the prediction of the account being stolen; determines the anti-theft control method of the account according to the risk level of being stolen, reduces the risk of the account being stolen through anti-theft control, and even prevents the account from being stolen, and timely performs anti-theft control during the account transfer process to avoid the dilemma of difficulty in recovering the account after the account is stolen, thereby improving the user's account security. Therefore, through the technical solution of the present application, the problem of being unable to effectively predict the risk of the account being stolen, and the problem of being unable to ensure the security of the account due to the lack of effective intervention control when the risk occurs is solved, and the risk level of the account being stolen is predicted, and the anti-theft control of the account transfer behavior is timely performed according to the risk level of being stolen, thereby improving the security of the account. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 This is a flow chart of an account fraud prevention method in Example 1 of the present application;
[0022] Figure 2 This is a flow chart of an account fraud prevention method in Embodiment 2 of the present application;
[0023] Figure 3 This is a flow chart of an account fraud prevention method in Embodiment 3 of the present application;
[0024] Figure 4 This is a schematic diagram of the structure of an account fraud prevention device in Embodiment 4 of the present application;
[0025] Figure 5 It is a structural diagram of an electronic device in Embodiment 5 of the present application. DETAILED DESCRIPTION
[0026] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0027] It should be noted that the terms "first" and "second" etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0028] Embodiment 1
[0029] Figure 1 A flowchart of an account fraud prevention method provided in Example 1 of the present application. This embodiment can be applied to risk prediction of account transfer behavior in financial applications, and to anti-fraud control when risks exist. The method can be executed by an account fraud prevention device, which can be implemented in software and / or hardware and specifically configured in an electronic device system in which financial applications are installed, such as a server.
[0030] See also Figure 1 The account anti-fraud method shown includes the following steps:
[0031] S110: Obtain a transfer request from a user to transfer funds to a logged-in account.
[0032] Before making a transfer, the user needs to log in to the account first. After completing the account login, click the corresponding transfer button to generate a transfer request. At this time, the account fraud prevention module can obtain the user's transfer request for the logged-in account. Exemplarily, the account fraud prevention module can be located in a risk control platform for risk control.
[0033] S120: Determine whether the receiving device that receives the transfer request is an untrusted device.
[0034] An untrusted device may be a device that has not been device-bound. Similarly, a device that has been device-bound may be a trusted device. Whether the receiving device is an untrusted device may be determined by querying whether the login account is device-bound with the device ID of the receiving device. The device ID may be a unique ID of the device.
[0035] Device binding can be to bind a device to an account. When a user logs in to a financial application on a new device, the user needs to perform some additional verification to bind the device to ensure that the object operated by the new device is operated by the user as much as possible. For example, device binding can include at least one of SMS verification, biometric information and card password verification, etc., which is not specifically limited in this application.
[0036] When logging in with a trusted device, you can log in directly through simple steps such as static passwords, biometrics, or gestures, which greatly simplifies the login steps and improves the user experience. Users can manually unbind the current device in the app, and can also set the switch for the device protection function. For users who turn on the device protection function, a forced verification operation will be added to the device binding process to increase the reliability of the verification. Exemplarily, the forced verification operation can be a biometric verification, for example, a forced verification operation can be a face verification. However, after the device is bound, there is still a very low possibility that the account operation is not the user's own operation after the criminal steals the user's information.
[0037] S130: If yes, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics.
[0038] If yes, that is, the receiving device is an untrusted device, the possibility of fraudulent use is high at this time, and further risk level assessment of fraudulent use is required to determine the corresponding anti-fraud control method.
[0039] The operation feature may be an operation feature of the user, and is used to assess the risk level of fraudulent card fraud from the perspective of the user's operation feature. Exemplarily, the operation feature may include the purpose of the operation and whether identity authentication is performed. For example, the operation feature may include whether to directly enter the transfer interface after logging in, and whether to perform biometric verification, etc.
[0040] The device feature may be a device binding feature of the user's logged-in device, which is used to assess the risk level of fraudulent card fraud from the perspective of the device binding feature. For example, the device feature may include whether the device has been device-bound.
[0041] The transfer feature may be a feature of the amount of the transfer, which is used to assess the risk level of fraudulent card transactions from the perspective of the transfer element features. For example, the transfer feature may include the amount of the transfer, and whether the recipient of the transfer is a frequently used account.
[0042] The risk level of the account being stolen can be the risk level of the account transfer operation being not performed by the user, which can be used to determine the corresponding anti-theft control method according to the risk of being stolen to ensure the security of the account. Exemplarily, the risk level of the account being stolen can be determined based on a deep learning model or a mathematical model, etc., according to the operation characteristics, device characteristics and transfer characteristics. For example, the corresponding weights can be determined for the operation characteristics, device characteristics and transfer characteristics through a deep learning model, and then the risk level of the account being stolen can be determined through a preset mathematical model.
[0043] For example, a risk score can be obtained based on the operation characteristics, device characteristics and transfer characteristics, and the corresponding risk level of fraudulent card transactions can be determined based on the score range corresponding to the preset risk level. For example, the risk score can be a number from 0 to 1, and the larger the value, the greater the risk. The correspondence between the score range and the risk level can be as follows: when the score value is 0-0.3, the risk level is the third risk level; when the score value is 0.3-0.8, the risk level is the second risk level; when the score value is 0.8-1.0, the risk level is the first risk level.
[0044] S140: Determine an anti-fraud control method for the account based on the risk level of fraudulent use of the account.
[0045] Multiple risk levels can be set for fraudulent use to determine different anti-fraudulent use control methods for the account, so as to take corresponding risk control methods to deal with the risk of fraudulent use. Anti-fraudulent use control can be a control method to prevent the account from being fraudulently used to protect the user's account security and avoid property loss. Exemplarily, anti-fraudulent use control can include suspending transactions and adding review processes, etc., which are not specifically limited in this application. For example, when the risk level of fraudulent use is high, the transaction can be stopped directly; when the risk level of fraudulent use is low, the review process can be added.
[0046] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data comply with relevant laws, regulations and standards in relevant regions.
[0047] With the rapid development of financial technology, financial technology applications have been widely popularized. Therefore, risk control of financial accounts is crucial, and effective measures must be taken to protect users' financial security, data privacy and system stability. Among these risk control measures, user financial security control is the top priority. In the process of handling customer complaints from financial institutions, incidents involving financial security will always have a higher priority. Among them, in the description of user complaints, it is not uncommon for funds to be stolen due to non-personal operations. Although there are fewer cases of penetrating the login verification of financial applications, once the funds are stolen, it will be very difficult to recover the stolen funds, which greatly affects the user experience. Therefore, it is necessary to determine the risk level of customer fraud at the first time and perform anti-fraud control from the bank's financial application side.
[0048] The technical solution of this embodiment is to obtain a transfer request from a user to transfer money to the logged-in account; determine whether the receiving device that receives the transfer request is an untrusted device; if so, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics. When the account is logged in on an untrusted device, the risk level of being stolen is determined from multiple angles based on the operation characteristics, device characteristics and transfer characteristics, thereby improving the accuracy of the risk level prediction of the account being stolen; determine the anti-theft control method of the account according to the risk level of being stolen, reduce the risk of the account being stolen through anti-theft control, and even prevent it from being stolen, and timely perform anti-theft control during the account transfer process to avoid the dilemma of difficulty in recovering the account after being stolen, thereby improving the user's account security. Therefore, through the technical solution of this application, the problem of being unable to effectively predict the risk of account being stolen, and the problem of being unable to ensure the security of the account due to lack of effective intervention control when risks occur is solved, and the risk level of the account being stolen is predicted, and the anti-theft control of the account transfer behavior is timely performed according to the risk level of being stolen, thereby improving the security of the account.
[0049] Embodiment 2
[0050] Figure 2 This is a flow chart of a method for preventing account fraud provided in Example 2 of the present application. The technical solution of this embodiment is further refined on the basis of the above technical solution.
[0051] Furthermore, "determining the risk level of the account for stolen credit card fraud based on the operation characteristics, device characteristics and transfer characteristics" is refined as: "inputting the operation characteristics, device characteristics and transfer characteristics into the trained risk model to obtain the risk score of the account for stolen credit card fraud; the trained risk model includes weights corresponding to the operation characteristics, device characteristics and transfer characteristics obtained through supervised training based on historical operation characteristics, historical device characteristics, historical transfer characteristics and historical stolen credit card fraud results; determining the risk level of the account for stolen credit card fraud based on the preset correspondence between the risk score and the risk level of stolen credit card fraud" to determine the risk level of the account for stolen credit card fraud.
[0052] See also Figure 2 A method for preventing account fraud is shown, comprising:
[0053] S210: Obtain a transfer request from a user to transfer funds to a logged-in account.
[0054] S220: Determine whether the receiving device that receives the transfer request is an untrusted device.
[0055] S230: If yes, input the operation characteristics, device characteristics and transfer characteristics into the trained risk model to obtain the risk score of the account being stolen.
[0056] The trained risk model includes the weights corresponding to the operation characteristics, device characteristics and transfer characteristics obtained through supervised training based on historical operation characteristics, historical device characteristics, historical transfer characteristics and historical fraud results.
[0057] The trained risk model can be a pre-set mathematical model for determining the risk level of an account being stolen. The historical operation characteristics, historical device characteristics, historical transfer characteristics, and historical stolen card results can be obtained in advance based on the log data of historical transactions as labeled sample data, and the preset weight determination model is supervised and trained to determine the weights corresponding to the operation characteristics, device characteristics, and transfer characteristics. The weights of the corresponding parameters in the trained risk model are input into the risk model with the numerical values of the operation characteristics, device characteristics, and transfer characteristics, and the risk score of the account being stolen can be obtained. The preset weight determination model can be a deep learning model or a mathematical model, and this application does not make specific restrictions on this. For example, the preset weight determination model can be a linear regression model.
[0058] In an optional embodiment, the operation characteristics, device characteristics and transfer characteristics are input into a trained risk model to obtain a risk score for account fraud, including: inputting the operation characteristics, device characteristics and transfer characteristics into the risk model; the risk model multiplies the values of the operation characteristics, device characteristics and transfer characteristics with the corresponding weights to obtain a risk score for account fraud.
[0059] For example, the trained risk model can be shown as follows:
[0060]
[0061] Among them, R is the risk score of the account being stolen; t is the time difference from logging in with an untrusted device to making a transfer; p is the ratio of the transfer amount to the available balance of the account; d is whether the device is rebound to the original device of the login account, if so, d = -1, otherwise d = 0; f is whether biometric information recognition is used, if so, f = 1, otherwise f = 0; k1, k2, k3 and k4 are constants, indicating the weights corresponding to each parameter, and μ is a constant.
[0062] The operation characteristics, device characteristics and transfer characteristics are input into the trained risk model. The trained risk model obtains the numerical values corresponding to the operation characteristics, device characteristics and transfer characteristics. The numerical values of the operation characteristics, device characteristics and transfer characteristics are multiplied by the corresponding weights to obtain a weighted result as the risk score of the account being stolen. Through weighted multiplication, the influence of the operation characteristics, device characteristics and transfer characteristics on the risk score of the account being stolen is balanced, thereby improving the accuracy of the risk score of the account being stolen.
[0063] In an optional embodiment, the operation characteristics include at least the time difference between the operation of logging in with an untrusted device and performing a transfer and the category of biometric information identification usage; the device characteristics include at least the device relationship between the login account and the re-binding of the original device; the transfer characteristics include at least the ratio of the transfer amount to the available balance in the account.
[0064] In the process of card fraud, the criminals need to log in to their own devices through a series of verifications such as device binding, and then conduct transfer transactions to transfer the funds in the customer's account to the illegal account in full. The whole process must be completed in the shortest possible time to prevent the customer from noticing or reporting the card and account lost after discovering that they have been logged in. That is, when the untrusted device is logged in and bound, the shorter the time interval between transfer and remittance transactions, the greater the possibility that the transaction is a fraudulent card.
[0065] Therefore, the operation feature includes the time difference between the untrusted device logging in and the transfer. Exemplarily, the time difference between the untrusted device logging in and the transfer can be determined by the timestamp of the corresponding operation step in the corresponding log of the account.
[0066] Biometric information recognition can be considered as a verification method with a higher security level, including steps such as liveness detection. The probability of biometric information recognition being cracked is also relatively low, so if the biometric information recognition step is included in the login verification process, it can be considered that the user's account is relatively safe. Therefore, the operation characteristics include the biometric information recognition usage category. Specifically, the biometric information recognition usage category includes use and non-use. Exemplarily, the biometric information can include at least one of facial feature information, fingerprint feature information, and iris feature information.
[0067] Based on the time difference between logging in with an untrusted device and making a transfer and whether biometric information recognition is used, the risk of account fraud is predicted from the perspective of the user's account operation behavior characteristics, thereby improving the accuracy of predicting the risk level of fraud.
[0068] The device relationship between the login account and the original device to be rebound may be whether the device is rebound to the original device of the login account. Specifically, the device relationship between the login account and the original device to be rebound may include devices that are rebound to the original device and devices that are not rebound to the original device. Device characteristics can be used to eliminate the interference of the original device rebinding on the judgment of the stolen card situation. The user can unbind his account from the original device through the financial application, and then rebind the original device. In this case, the possibility of the customer being stolen will be greatly reduced, and the transfer transaction after binding will also be considered relatively safe. Therefore, consider the device characteristics to avoid misjudgment of account theft and improve the accuracy of predicting the risk level of stolen card.
[0069] The higher the proportion of the transfer amount to the total amount of the user, the greater the possibility that the transfer may be a fraudulent transaction. Therefore, the higher the proportion of the transfer amount to the total amount of the user, the greater the possibility that the transaction is a fraudulent transaction. Therefore, the transfer characteristics at least include the ratio of the transfer amount to the available balance of the account.
[0070] The operation characteristics include at least the time difference between logging in with an untrusted device and making a transfer and the category of biometric information identification used; the device characteristics include at least the device relationship between the login account and the re-binding of the original device; the transfer characteristics include at least the ratio of the transfer amount to the available balance in the account. The detailed characteristics such as the device binding transaction, transfer and remittance transaction and operation time required in the fraudulent credit card process are captured to form an effective judgment on the risk score of the customer's credit card fraud and improve the accuracy of subsequent predictions of the risk level of credit card fraud.
[0071] In an optional embodiment, before inputting the operation characteristics, device characteristics and transfer characteristics into the trained risk model to obtain the risk level of the account being stolen, it also includes: obtaining historical operation characteristics, historical device characteristics, historical transfer characteristics and historical stolen card results; using the historical stolen card results as sample labels for the corresponding historical operation characteristics, historical device characteristics and historical transfer characteristics to obtain labeled sample data; inputting the labeled sample data into a linear regression model to obtain the corresponding weights of the operation characteristics, device characteristics and transfer characteristics.
[0072] Linear regression is a basic machine learning algorithm that is widely used in fields such as data analysis, prediction, and modeling. The goal of linear regression is to find a set of parameters that minimizes the error between the modeled predicted value and the actual observed value. Exemplarily, the error between the modeled predicted value and the actual observed value can be calculated using the least squares method. Linear regression can be divided into simple linear regression and multivariate linear regression. In this application, since multiple indicators such as operation characteristics, device characteristics, and transfer characteristics need to be considered, a multivariate linear regression algorithm is used.
[0073] The historical operation features, historical device features, historical transfer features, and historical fraudulent credit card results are obtained through historical logs. The historical fraudulent credit card results are used as sample labels for the historical operation features, historical device features, and historical transfer features. Specifically, the historical fraudulent credit card results may include fraudulent credit card and non-fraudulent credit card. The historical fraudulent credit card results are used as sample labels for the corresponding historical operation features, historical device features, and historical transfer features to obtain labeled sample data.
[0074] Inputting labeled sample data into a linear regression model to obtain weights corresponding to operation features, device features, and transfer features can improve the accuracy of the weights corresponding to operation features, device features, and transfer features.
[0075] In an alternative embodiment, the linear regression model may be optimized by least squares estimation.
[0076] The least squares method is an optimization method that solves the weights corresponding to the operating characteristics, device characteristics, and transfer characteristics of the linear regression model by minimizing the sum of squares of errors.
[0077] The weights corresponding to the operation characteristics, device characteristics and transfer characteristics are very important for the rationality of the risk model. The historical operation characteristics, historical device characteristics, historical transfer characteristics and historical fraudulent card results can be obtained through the fraudulent card logs and fraudulent card false alarm logs in the database and the logs of transfer after normal binding to ensure the sample balance of subsequent labeled sample data. Exemplarily, all labeled sample data can be divided into two categories. The sample data with label R = 0 can be the case of transfer after normal binding and the case of no fraudulent card in the report event, for example, Data1 (R, t, p, d, f) = (0, 120 (s), 30 (%), -1, 1) and so on; the sample data with label R = 1 can be the case of fraudulent card in the report event, for example, Data2 (R, t, p, d, f) = (1, 60 (s), 100 (%), 0, 0) and so on.
[0078] The multiple linear regression equation can be as follows:
[0079]
[0080] Substitute the R value and the corresponding time difference t between the untrusted device login and the transfer, the ratio p of the transfer amount to the available balance of the account, the device relationship d between the login account and the original device, and the value of the biometric information identification usage category f into the multivariate linear regression equation, that is, y1, x i1 、x i2 、x i3 and x i4 , we can use the multivariate linear regression algorithm of machine learning to calculate the least squares estimator Q value when β is 0 0-n The value of is the value of k1, k2, k3, k4 and μ in the trained risk model.
[0081] By optimizing the linear regression model through least squares estimation and determining the weights corresponding to the operation characteristics, equipment characteristics and transfer characteristics, the weights corresponding to the operation characteristics, equipment characteristics and transfer characteristics can be accurately determined, thereby improving the accuracy of the risk model output.
[0082] S240: Determine the risk level of the account being subject to fraudulent use of the account according to a preset correspondence between the risk score and the risk level of fraudulent use of the account.
[0083] The preset correspondence between the risk score and the risk level of the credit card fraud can be a range of risk scores corresponding to the preset risk level. For example, if the value calculated by the risk score of the credit card fraud can be normalized to the range of 0-1, the credit card fraud risk can be divided into multiple levels according to the specific situation. For example, the credit card fraud risk can be divided into three levels. If the credit card fraud risk score value is in the range of 0-0.3, it is considered to be a low risk situation, and the risk level is the third level; if it is in the range of 0.3-0.8, it is considered to be a medium risk situation, and the risk level is the second level; if it is in the range of 0.8-1.0, it is considered to be a high risk situation, and the risk level is the first level; for different risk levels, different anti-theft control methods can be adopted to perform different anti-theft control.
[0084] S250: Determine the anti-fraud control method for the account according to the risk level of fraudulent use of the account.
[0085] The technical solution of this embodiment obtains the risk score of account fraud by inputting operation characteristics, device characteristics and transfer characteristics into a trained risk model; the weights corresponding to the operation characteristics, device characteristics and transfer characteristics in the trained risk model are obtained through supervised training based on historical operation characteristics, historical device characteristics, historical transfer characteristics and historical fraud results; the risk level of the account fraud is determined according to a preset correspondence between the risk score and the risk level of fraud, and the risk score of the fraud is comprehensively evaluated by combining multiple factors such as operation characteristics, device characteristics and transfer characteristics, thereby improving the comprehensiveness of subsequent prediction of the risk level of fraud, and then improving the accuracy of the prediction, and determining the risk score through the trained risk model is simple to implement, and the efficiency of determining the risk level of fraud is improved.
[0086] Embodiment 3
[0087] Figure 3 This is a flow chart of a method for preventing account fraud provided in Example 3 of the present application. The technical solution of this embodiment is further refined on the basis of the above technical solution.
[0088] Furthermore, "determine the anti-theft control method for the account based on the risk level of stolen credit card fraud" is refined as: "If the risk level of stolen credit card fraud is the first level, the anti-theft control method for the account is to control the suspension of transactions; if the risk level of stolen credit card fraud is the second level, the anti-theft control method for the account is to control the addition of manual verification or password verification; if the risk level of stolen credit card fraud is the third level, the anti-theft control method for the account is to control the addition of biometric verification" to determine the anti-theft control method for the account.
[0089] See also Figure 3 A method for preventing account fraud is shown, comprising:
[0090] S310: Obtain a transfer request from a user to transfer funds to a logged-in account.
[0091] S320: Determine whether the receiving device that receives the transfer request is an untrusted device.
[0092] S330: If yes, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics.
[0093] S340: If the risk level of the fraudulent card is the first level, determine the anti-fraudulent card control method of the account as controlling the suspension of transactions.
[0094] If the risk level of fraudulent use is the first level, then the risk level of fraudulent use is high. The account will be controlled to suspend transactions and directly interrupt transactions to ensure that the account will not be fraudulently used and to protect the security of the account.
[0095] S350: If the risk level of fraudulent use is the second level, determine the anti-fraud control method for the account to be to increase manual verification or password verification.
[0096] Manual verification can be a manual video review. Password verification can be verified by a u-shield password device (a professional term, a password verifier) that cannot be simulated. If the risk level of the stolen card is the second level, the control account will be manually verified or password verified. The u-shield password device verification is a verification method with a higher degree of security. When the risk level of the stolen card is the second level, the risk level of the stolen card is medium. Adding a u-shield password device verification with a higher degree of security will effectively increase the difficulty of theft and ensure the security of the account.
[0097] S360: If the risk level of fraudulent use of the account is the third level, determine that the anti-fraudulent use control method of the account is to control the addition of biometric verification.
[0098] Exemplarily, the biometric information may be at least one of facial feature information, fingerprint feature information, and iris feature information, which is not specifically limited in this application. If the risk level of fraudulent card use is the third level, the risk level of fraudulent card use is low, and the account is controlled to perform biometric verification to confirm whether the operation is performed by the user himself, to prevent the account from being fraudulently used, and to improve the security of the account.
[0099] Under the current circumstances, the financial application side only controls the entire process by verifying the login device binding, and there is no control over the subsequent transfer transactions. In extreme cases, if the financial application side does not exercise any control, the transfer operation of the stolen customer account by the illegal personnel may be successfully stolen, causing huge losses to the customer.
[0100] The technical solution of this embodiment is as follows: if the risk level of the credit card fraud is the first level, the anti-theft control mode of the account is determined to be to control the suspension of transactions; if the risk level of the credit card fraud is the second level, the anti-theft control mode of the account is determined to control the addition of manual verification or password verification; if the risk level of the credit card fraud is the third level, the anti-theft control mode of the account is determined to control the addition of biometric verification. Different anti-theft control modes are set based on the risk level of the credit card fraud. When the risk level of the credit card fraud is low, verification is increased to reduce the risk of the account being fraudulently used. When the risk level of the credit card fraud is high, transactions are suspended. This can effectively prevent the account from being fraudulently used, and timely perform anti-theft control during the account transfer process to avoid the dilemma of difficulty in recovering the money after the account is fraudulently used, thereby improving the user's account security, and improving the user experience by setting different anti-theft control modes instead of taking measures to suspend transactions altogether.
[0101] Embodiment 4
[0102] Figure 4 The figure shows a schematic diagram of the structure of an anti-fraud device for account swiping provided in the fourth embodiment of the present application. The present embodiment can be applied to the risk prediction of account transfer behavior in financial applications, and the anti-fraud control when there is a risk. The structure of the anti-fraud device for account swiping is as follows:
[0103] A transfer request acquisition module 410 is used to acquire a transfer request from a user to transfer money to a logged-in account;
[0104] A receiving device determination module 420 is used to determine whether the receiving device that receives the transfer request is an untrusted device;
[0105] The risk level determination module 430 is used to determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics.
[0106] The anti-fraud control mode determination module 440 is used to determine the anti-fraud control mode of the account according to the risk level of fraudulent use.
[0107] The technical solution of this embodiment is to obtain a transfer request from a user to transfer money to the logged-in account; determine whether the receiving device that receives the transfer request is an untrusted device; if so, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics. When the account is logged in on an untrusted device, the risk level of being stolen is determined from multiple angles based on the operation characteristics, device characteristics and transfer characteristics, thereby improving the accuracy of the prediction of the account being stolen; determine the anti-theft control method of the account according to the risk level of being stolen, reduce the risk of the account being stolen through anti-theft control, and even prevent it from being stolen, and timely perform anti-theft control during the account transfer process to avoid the dilemma of difficulty in recovering the account after being stolen, thereby improving the user's account security. Therefore, through the technical solution of this application, the problem of being unable to effectively predict the risk of account being stolen and the lack of effective intervention control when risks occur, and the problem of being unable to ensure the security of the account is solved, and the risk level of the account being stolen is predicted, and the anti-theft control of the account transfer behavior is timely performed according to the risk level of being stolen, thereby improving the security of the account.
[0108] Optionally, the risk level determination module 430 includes:
[0109] A risk score determination unit is used to input the operation characteristics, device characteristics and transfer characteristics into the trained risk model to obtain the risk score of the account being stolen; the trained risk model includes weights corresponding to the operation characteristics, device characteristics and transfer characteristics obtained through supervised training based on historical operation characteristics, historical device characteristics, historical transfer characteristics and historical stolen card results;
[0110] The risk level determination unit is used to determine the risk level of the account being fraudulently used based on a preset correspondence between the risk score and the risk level of fraudulently used credit cards.
[0111] Optionally, a risk score determination unit, including:
[0112] a numerical input subunit, used for inputting the operation feature, the device feature and the transfer feature into a risk model;
[0113] The weighted multiplication subunit is used for the risk model to multiply the values of the operation feature, the device feature and the transfer feature with the corresponding weights to obtain the risk score of the account being stolen.
[0114] Optionally, the risk level determination module 430 further includes:
[0115] A historical data acquisition unit, used to acquire historical operation characteristics, historical device characteristics, historical transfer characteristics and historical fraudulent card results;
[0116] A labeled sample data determination unit, used to use historical fraudulent card results as sample labels of corresponding historical operation features, historical device features, and historical transfer features to obtain labeled sample data;
[0117] The weight determination unit is used to input the labeled sample data into the linear regression model to obtain the weights corresponding to the operation characteristics, device characteristics and transfer characteristics.
[0118] Optionally, the operation characteristics include at least the time difference between the login of the untrusted device and the transfer and the category of biometric information identification usage; the device characteristics include at least the device relationship between the login account and the re-binding of the original device; the transfer characteristics include at least the ratio of the transfer amount to the available balance of the account.
[0119] Optionally, the anti-fraud control mode determination module 440 includes:
[0120] A transaction suspension control unit, for determining that the anti-fraud control mode of the account is to control the suspension of transactions if the risk level of the fraudulent card is the first level;
[0121] A verification and additional control unit is used to determine the anti-fraud control mode of the account as control-added manual verification or password verification if the risk level of fraudulent swiping is the second level;
[0122] The biometric verification control unit is used to determine the anti-fraud control method of the account to add biometric verification if the risk level of fraudulent use is the third level.
[0123] The account fraud prevention device provided in the embodiments of the present application can execute the account fraud prevention method provided in any embodiment of the present application, and has the corresponding functional modules and beneficial effects for executing the account fraud prevention method.
[0124] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium and a computer program product.
[0125] Embodiment 5
[0126] Figure 5 A schematic diagram of the structure of an electronic device provided in Embodiment 5 of the present application is shown in FIG. Figure 5 As shown, the electronic device includes a processor 510, a memory 520, an input device 530, and an output device 540; the number of the processor 510 in the electronic device can be one or more. Figure 5 A processor 510 is taken as an example; the processor 510, the memory 520, the input device 530 and the output device 540 in the electronic device can be connected via a bus or other means. Figure 5 The example of connecting through bus is taken in the following.
[0127] The memory 520, as a computer-readable storage medium, can be used to store software programs, computer executable programs and modules, such as program instructions / modules corresponding to the account fraud prevention method in the embodiment of the present application (for example, the transfer request acquisition module 410, the receiving device judgment module 420, the risk level determination module 430 and the fraud prevention control mode determination module 440). The processor 510 executes various functional applications and data processing of the electronic device by running the software programs, instructions and modules stored in the memory 520, that is, realizes the above-mentioned account fraud prevention method.
[0128] The memory 520 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system and at least one application required for a function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory 520 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 520 may further include a memory remotely arranged relative to the processor 510, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0129] The input device 530 may be used to receive input character information and generate key signal input related to user settings and function control of the electronic device. The output device 540 may include a display device such as a display screen.
[0130] Embodiment 6
[0131] Embodiment 6 of the present application also provides a storage medium containing computer executable instructions, which, when executed by a computer processor, are used to execute a method for preventing account fraud, the method comprising: obtaining a transfer request from a user to transfer money to a logged-in account; determining whether a receiving device that receives the transfer request is an untrusted device; if so, determining a risk level of the account being fraudulently charged based on operating characteristics, device characteristics, and transfer characteristics; and determining an anti-fraud control method for the account based on the risk level of the fraudulently charged account.
[0132] Of course, the storage medium containing computer executable instructions provided in the embodiment of the present application, whose computer executable instructions are not limited to the method operations described above, can also execute related operations in the account fraud prevention method provided in any embodiment of the present application.
[0133] Through the above description of the implementation method, the technicians in the relevant field can clearly understand that the present application can be implemented with the help of software and necessary general hardware, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application can be essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., including a number of instructions for an electronic device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0134] It is worth noting that in the embodiment of the above-mentioned account anti-fraud device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application.
[0135] Note that the above are only preferred embodiments of the present application and the technical principles used. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, readjustments and substitutions can be made by those skilled in the art without departing from the scope of protection of the present application. Therefore, although the present application is described in more detail through the above embodiments, the present application is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A method for preventing account fraud, characterized in that: include: Get the user's transfer request to transfer money to the logged-in account; Determining whether a receiving device that receives the transfer request is an untrusted device; If yes, determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics; Determine the anti-fraud control method for the account based on the risk level of the fraudulent card.
2. The method according to claim 1, characterized in that Determining the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics includes: The operation feature, the device feature and the transfer feature are input into a trained risk model to obtain a risk score of the account being stolen; the trained risk model includes weights corresponding to the operation feature, the device feature and the transfer feature obtained through supervised training based on historical operation features, historical device features, historical transfer features and historical stolen card results; The risk level of the account being fraudulently controlled is determined based on a preset correspondence between the risk score and the risk level of the fraudulent control.
3. The method according to claim 2, characterized in that The operation feature, the device feature, and the transfer feature are input into the trained risk model to obtain a risk score for account fraud, including: inputting the operation characteristics, the device characteristics and the transfer characteristics into a risk model; The risk model multiplies the values of the operation feature, the device feature and the transfer feature with the corresponding weights to obtain a risk score for account fraud.
4. The method according to claim 2, characterized in that: Before inputting the operation feature, the device feature and the transfer feature into the trained risk model to obtain the risk level of the account being stolen, the method further includes: Obtain historical operation characteristics, historical device characteristics, historical transfer characteristics, and historical fraudulent card results; The historical fraudulent card results are used as sample labels of the corresponding historical operation features, the historical device features, and the historical transfer features to obtain labeled sample data; The labeled sample data is input into a linear regression model to obtain weights corresponding to the operation feature, the device feature, and the transfer feature.
5. The method according to claim 1, characterized in that The operation characteristics at least include the time difference between the non-trusted device logging in and the transfer and the category of biometric information identification usage; the device characteristics at least include the device relationship between the login account and the original device that is re-bound; the transfer characteristics at least include the ratio of the transfer amount to the available balance in the account.
6. The method according to claim 1, characterized in that Determining the anti-fraudulent card control method of the account according to the risk level of the fraudulent card, includes: If the risk level of fraudulent card transactions is the first level, the anti-fraud control method for the account is to control and suspend transactions; If the risk level of fraudulent card transactions is the second level, the anti-fraud control method for the account is to add manual verification or password verification; If the risk level of fraudulent use is the third level, the anti-fraud control method for the account is to add biometric verification.
7. An account fraud prevention device, characterized in that: include: A transfer request acquisition module is used to obtain a transfer request from a user to transfer money to a logged-in account; A receiving device judgment module, used to determine whether the receiving device that receives the transfer request is an untrusted device; A risk level determination module is used to determine the risk level of the account being stolen based on the operation characteristics, device characteristics and transfer characteristics. The anti-fraud control mode determination module is used to determine the anti-fraud control mode of the account according to the risk level of the fraudulent card.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the account fraud prevention method as described in any one of claims 1-6 is implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the account fraud prevention method as described in any one of claims 1 to 6 is implemented.
10. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the account fraud prevention method according to any one of claims 1 to 6.