Data release risk early warning and intelligent management and control method and system
Through the fusion of dynamic baseline models and multi-dimensional data, the pain points of traditional data delivery risk detection models in adaptability and maintenance costs are solved, more accurate abnormal detection and risk warning are achieved, and the security and stability of data delivery are improved.
Patent Information
- Application Number
- CN202510526269.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The pain points of traditional data delivery risk detection models in adaptability and maintenance costs are difficult to cope with periodic fluctuations in traffic or new attack modes, and require frequent manual adjustment of rules, which is difficult to scale.
Through dynamically generating benchmarks, multi-dimensional data fusion and continuous optimization mechanisms, a dynamic baseline model is established, traffic characteristics, user behavior and environmental characteristics data are collected in real time, abnormal detection is carried out and risk warning signals are generated, and the control actions in the preset strategy library are matched, and feedback effects are monitored.
It realizes more accurate abnormal detection and risk warning, reduces manual intervention, improves processing efficiency, effectively reduces advertisers' ineffective expenditures, and improves the security and stability of data delivery.
Smart Images

Figure CN120047189A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data delivery, and particularly to a method and system for data delivery risk early warning and intelligent control. Background Art
[0002] Data delivery risk refers to various uncertain factors that may be encountered during data delivery and may cause damage to the delivery effect and the interests of advertisers, including false clicks, malicious traffic brushing, etc., that is, non-genuine advertisement click behaviors generated by robot programs or manual operations. Traditional data delivery risk detection often relies on static rules or historical mean thresholds, making it difficult to cope with traffic periodic fluctuations or new attack patterns, and frequent manual rule adjustments are required, making it difficult to scale. Based on the above technical problems, this application solves the pain points of traditional models in terms of adaptability and maintenance cost through dynamic benchmark generation, multi-dimensional data fusion, and continuous optimization mechanisms. Summary of the Invention
[0003] To solve the pain points of traditional data delivery risk detection models in terms of adaptability and maintenance cost, this application provides a method and system for data delivery risk early warning and intelligent control.
[0004] The first invention object of this application is achieved through the following technical solutions: A method for data delivery risk early warning and intelligent control, including the steps of: Real-time collecting traffic feature data, user behavior data, and environmental feature data of data delivery; Establishing a dynamic baseline model, generating benchmark range data of normal delivery behaviors based on historical data and industry standards, where the benchmark range data includes click-through rate threshold data and time period distribution rule data; Using the dynamic baseline model to perform anomaly detection on user behavior data and environmental feature data, and generating risk early warning signals; When receiving a risk early warning signal, identifying the risk type and generating a corresponding risk level, where the risk type includes false clicks, machine traffic brushing, traffic hijacking, and new unknown risks; Matching control actions in a preset policy library based on the risk type and risk level, and executing the control actions; Monitoring the feedback effect and continuously optimizing the parameters of the dynamic baseline model.
[0005] By adopting the above technical solutions, the dynamic baseline model can set the range of normal behavior based on historical data and industry standards, making anomaly detection more accurate, and can detect abnormal behavior in real time and generate early warning signals. The matching of the preset strategy library and the execution of control actions realize intelligent risk control, reduce manual intervention, and improve processing efficiency. By identifying and intercepting malicious behaviors such as false clicks and machine brushing, it effectively reduces advertisers' invalid expenditures and improves the security and stability of data delivery.
[0006] In a preferred example of the present application, the step of establishing a dynamic baseline model and generating a benchmark range data of normal delivery behavior based on historical data and industry standards specifically includes the following steps: Extract historical data from the past several months and remove abnormal data; Fit Poisson distribution to hourly flow and generate confidence intervals for period flow; Calculate click-through rate threshold data using the quantile method, combine the click-through rate threshold data with the confidence interval of the time period traffic, and generate benchmark range data; Automatically retrain baseline models at preset intervals, integrate the latest data and industry reports, and set baseline deviation warnings.
[0007] By adopting the above technical solution, the calculated click-through rate threshold is combined with the confidence interval of the time period traffic to generate a more comprehensive baseline range data to quantify the normal behavior range. This data set takes into account the changes in both traffic and click-through rate, avoiding the limitations of a single mean. The baseline model is retrained regularly with the latest data to maintain the timeliness and accuracy of the model. During the retraining process, not only the latest internal data is used, but also industry reports and market trends are combined to obtain a more comprehensive perspective, define the standards for baseline deviation, and issue a warning when the actual data deviates from the baseline range predicted by the baseline model, indicating that there may be anomalies.
[0008] In a preferred example of the present application, the step of using the dynamic baseline model to perform anomaly detection on user behavior data and environmental feature data and generate a risk warning signal specifically includes the following steps: Compare the user behavior data with the click rate threshold data, and when a sudden increase in user clicks is detected within a preset time range, associate the user behavior data with a time series anomaly flag; Build a user behavior Markov chain. When a user's low-probability path is detected, associate the user behavior data with the behavior chain anomaly marker. When it is identified that the same IP in the environmental feature data is associated with a device ID greater than a preset number, the environmental feature data is associated with an environmental aggregation anomaly flag; Generate risk warning signals based on time series anomaly identification, behavior chain anomaly identification and environment aggregation anomaly identification.
[0009] By adopting the above technical solution, the actual click-through rate is compared with the normally expected click-through rate threshold. If the number of clicks rises sharply within a short period of time and exceeds the normal range, this may indicate abnormal behavior. If the user's behavior path is an unlikely event in the Markov chain, it may also indicate abnormal behavior. If multiple device IDs are associated with the same IP address, this may indicate that someone is using a proxy server or VPN for fraudulent behavior. When the above abnormal situations are detected, different abnormal identifiers are respectively associated, and a comprehensive risk warning signal is generated, thereby providing a basis for subsequent risk assessment and control actions, and helping to improve the security of advertising placement.
[0010] In a preferred example of the present application: the risk warning signal includes a low-risk signal, a medium-risk signal, and a high-risk signal. The step of generating a risk warning signal based on the time-series abnormal identifier, the behavior chain abnormal identifier, and the environmental aggregation abnormal identifier specifically includes the steps: Generate a low-risk signal when a single-dimensional abnormal identifier is recognized; Generate a medium-risk signal when multi-dimensional abnormal identifiers are recognized; Generate a high-risk signal when it is recognized that the IP comes from a data center and there is zero conversion for clicks.
[0011] By adopting the above technical solution, a single-dimensional abnormality may be caused by normal fluctuations or other non-malicious factors. Therefore, it is marked as a low risk, indicating that attention is needed but no immediate strong measures need to be taken. Multi-dimensional abnormalities may indicate more complex or serious problems. Therefore, it is marked as a medium risk. If an IP address comes from a data center, this may indicate that someone is using an automated tool for fraudulent clicks. In this case, a high-risk signal is generated, indicating highly suspicious behavior. Through this hierarchical warning mechanism, the system can take corresponding response measures according to the severity of the risk, thereby more effectively managing and controlling the data placement risk.
[0012] In a preferred example of the present application: after the step of matching the control action in the preset policy library based on the risk type and risk level and executing the control action, the following steps are further included: Set a whitelist according to the advertiser contract, and do not execute the control action when the whitelist information is recognized; When the frequency of recognizing high-risk signals of the same type exceeds the preset threshold, force manual review before executing the control action.
[0013] By adopting the above technical solution, before performing a control action, it is checked whether the current advertiser or advertisement content is in the whitelist. If whitelist information is recognized, the system will not perform any control actions and continue to process according to the normal process. The whitelist mechanism protects the key activities of advertisers from being misintercepted. When the frequency of identifying the same type of high-risk signal exceeds the preset threshold, an artificial review mechanism is triggered to avoid the spread of automated misjudgments, and the preset policy library is updated according to the situation to improve the accuracy of subsequent automatic decision-making.
[0014] In a preferred example of the present application: the step of continuously optimizing the dynamic baseline model parameters by monitoring the feedback effect specifically includes the steps: Sending the control result information as a label to the training set, where the control result information includes successful interception information and misjudgment information; Supplementary new attack samples for new unknown risks in the risk type through manual annotation and sending them to the training set.
[0015] By adopting the above technical solution, the successful interception information helps the model learn how to more accurately identify malicious behaviors, while the misjudgment information helps the model understand which behaviors are misclassified as abnormal, so as to avoid similar mistakes in future predictions. For new unknown risks, professional personnel are required to analyze and annotate to determine the characteristics of these risks, and add new attack samples to the training set, so as to continuously learn and improve from actual operations.
[0016] In a preferred example of the present application: after the step of continuously optimizing the dynamic baseline model parameters by monitoring the feedback effect, the following steps are further included: Real-time monitoring of the historical effects of different control actions and dynamically adjusting the priorities of control actions according to the historical effects.
[0017] By adopting the above technical solution, continuously tracking and recording the performance of different control actions over a period of time in the past, such as the number of times they successfully intercepted risks, the number of misjudgments caused, the impact on the delivery effect, etc. Prioritizing the control actions with the best effects can make more effective use of resources and improve the overall control efficiency. For control actions that may lead to misjudgments, reducing their priorities can reduce interference with normal delivery behaviors. By continuously evaluating and adjusting control actions, continuously learn and adapt to the new risk environment.
[0018] The second above-mentioned invention object of the present application is achieved by the following technical solution: A data delivery risk early warning and intelligent control system, including: An identification module for real-time collecting traffic feature data, user behavior data, and environmental feature data of data delivery; A dynamic baseline model construction module for establishing a dynamic baseline model and generating benchmark range data for normal delivery behaviors based on historical data and industry standards; A risk early warning module for performing anomaly detection on user behavior data and environmental feature data and generating risk early warning signals; A control implementation module for, when receiving a risk early warning signal, matching control actions in a preset policy library based on the risk type and risk level and executing the control actions; A feedback module for monitoring the feedback effect and continuously optimizing the parameters of the dynamic baseline model.
[0019] By adopting the above technical solutions, through the collaborative work of the identification module, the dynamic baseline model construction module, the risk early warning module, the control implementation module, and the feedback module, the device realizes the rapid identification and classification of data delivery risks, takes effective control actions, and improves the security and stability of data delivery.
[0020] The above object three of the present application is achieved through the following technical solutions: A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above data delivery risk early warning and intelligent control method are implemented.
[0021] The above object four of the present application is achieved through the following technical solutions: A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the above data delivery risk early warning and intelligent control method are implemented.
[0022] In summary, the present application includes at least one of the following beneficial technical effects: 1. The dynamic baseline model solves the pain points of traditional models in terms of adaptability, comprehensiveness, and maintenance cost through dynamic generation of benchmarks, multi-dimensional data fusion, and continuous optimization mechanisms. Based on a hybrid method of statistics and machine learning, it can reduce misjudgments, perform periodic updates and deviation early warnings, can quickly respond to environmental changes, and the feedback closed-loop design supports continuous learning of new risks, providing a more efficient, flexible, and sustainable technical path for data delivery risk prevention and control; 2. Anomaly in a single dimension may be caused by normal fluctuations or other non-malicious factors, so it is marked as low risk, indicating that attention is needed but immediate strong measures are not required. Anomaly in multiple dimensions may indicate more complex or serious problems, so it is marked as medium risk. If an IP address comes from a data center, this may indicate that someone is using an automated tool for fraudulent clicks. In this case, a high-risk signal is generated, indicating highly suspicious behavior. Through this hierarchical early warning mechanism, the system can take corresponding response measures according to the severity of the risk, while considering traffic characteristics (time period distribution), user behavior (conversion path), and environmental characteristics (IP association), improving the comprehensiveness of anomaly detection, and thus more effectively managing and controlling data delivery risks; 3. Before executing the control action, check whether the current advertiser or advertisement content is in the whitelist. If the whitelist information is identified, the system will not execute any control action and continue to process according to the normal process. The whitelist mechanism protects the key activities of advertisers from being affected by misinterception. When the frequency of identifying the same type of high-risk signal exceeds the preset threshold, the manual review mechanism is triggered to avoid the spread of automated misjudgment and update the preset policy library according to the situation, improving the accuracy of subsequent automatic decision-making; 4. Continuously track and record the performance of different control actions over a period of time, such as the number of times they successfully intercept risks, the number of misjudgments caused, and the impact on the delivery effect, etc. Prioritizing the control actions with the best effect can make more effective use of resources and improve the overall control efficiency. For control actions that may lead to misjudgments, reducing their priority can reduce the interference to normal delivery behavior. By continuously evaluating and adjusting control actions, the system can continuously learn and adapt to the new risk environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a flowchart of an embodiment of a method for early warning and intelligent control of data delivery risk in the present application; Figure 2 is an implementation flowchart of step S20 in an embodiment of a method for early warning and intelligent control of data delivery risk in the present application; Figure 3 is an implementation flowchart of step S30 in an embodiment of a method for early warning and intelligent control of data delivery risk in the present application; Figure 4 is a schematic diagram of a system for early warning and intelligent control of data delivery risk in the present application; Figure 5 is a principle block diagram of a computer device in the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The present application will be further described in detail below with reference to the accompanying drawings.
[0025] In the following embodiments, Figures 1-3 As shown, the present application discloses a data delivery risk warning and intelligent management method, which specifically includes the following steps: S10: collect traffic characteristic data, user behavior data and environmental characteristic data of data delivery in real time; S20: Establish a dynamic baseline model to generate benchmark range data of normal delivery behavior based on historical data and industry standards, wherein the benchmark range data includes click rate threshold data and time period distribution law data; S30: Use the dynamic baseline model to detect anomalies in user behavior data and environmental feature data, and generate risk warning signals; S40: When a risk warning signal is received, the risk type is identified and a corresponding risk level is generated, wherein the risk type includes false clicks, machine-generated traffic, traffic hijacking, and new unknown risks; S50: matching the control actions in the preset policy library based on the risk type and risk level, and executing the control actions; S60: Monitor feedback effects and continuously optimize dynamic baseline model parameters.
[0026] In this embodiment, traffic characteristics include request volume, click-through rate, conversion rate, and exposure frequency; user behavior includes click interval, page dwell time, and conversion path depth; environmental characteristics include device ID, IP geographic location, network type (cellular / WiFi), and browser User-Agent.
[0027] Specifically, the traffic characteristic data, user behavior data and environmental characteristic data of data delivery are collected in real time to establish a dynamic baseline model, which can be continuously adjusted according to historical data and industry standards to reflect normal advertising delivery behavior and generate benchmark range data, including click-through rate thresholds and time period distribution patterns. The time period distribution pattern refers to the pattern of when the advertisement is clicked during the day. By comparing the real-time data with the expected value of the baseline model, behaviors that do not conform to the normal pattern are identified and risk warning signals are issued. Risk warning signals are received and risk types are identified, and risks are divided into different levels according to the severity of the risk and the possible impact. A policy library containing various response measures is preset to match corresponding control actions for different risk types and levels. The control actions taken are tracked and their effects are evaluated. According to the control effects and new data, the baseline model parameters are adjusted to maintain the accuracy and effectiveness of the model.
[0028] In one embodiment, step S20 specifically includes the steps of: S21: extract historical data of the past several months and remove abnormal data; S22: Fitting Poisson distribution to hourly flow and generating confidence intervals for flow in the period; S23: Calculate the click-through rate threshold data by the quantile method, combine the click-through rate threshold data with the time period traffic confidence interval, and generate the baseline range data; S24: Automatically retrain the baseline model at a preset period, fuse the latest data with the industry report, and set the baseline deviation warning.
[0029] In this embodiment, outliers are filtered by the 3σ principle or the isolation forest algorithm to eliminate abnormal data; the click-through rate threshold data is calculated by the quantile method, that is, the normal range = the 25% - 75% quantiles of the historical click-through rate.
[0030] Specifically, load the advertising placement data of the past 6 months, group by advertising type (search advertising, in-feed advertising), eliminate abnormal data, fit the hourly traffic to a Poisson distribution to generate the time period traffic confidence interval, predict the periodic fluctuations (such as holiday traffic patterns) through the LSTM model, identify the outliers in the long-term trend, which is superior to the traditional time series analysis; calculate the click-through rate threshold data by the quantile method, combine the click-through rate threshold data with the time period traffic confidence interval to generate the baseline range data, automatically retrain the baseline model weekly, fuse the latest 7-day data with the industry report, and set the baseline deviation warning, and trigger manual review when the KL divergence between the new data distribution and the baseline > 0.1.
[0031] In one embodiment, step S30 specifically includes the steps: S31: Compare the user behavior data with the click-through rate threshold data. When a sudden increase in the user click volume is identified within the preset time range, associate the user behavior data with the time series anomaly identifier; S32: Construct a user behavior Markov chain. When a low-probability path of the user is detected, associate the user behavior data with the behavior chain anomaly identifier; S33: When it is identified that the same IP in the environmental feature data is associated with more than the preset number of device IDs, associate the environmental feature data with the environmental aggregation anomaly identifier; S34: Generate a risk warning signal based on the time series anomaly identifier, the behavior chain anomaly identifier, and the environmental aggregation anomaly identifier.
[0032] In this embodiment, the low-probability path includes "exposure → click → immediately close". The number of device IDs associated with the same IP is identified through graph calculation (Neo4j). At the same time, considering the traffic characteristics (time period distribution), user behavior (conversion path), and environmental characteristics (IP association), the comprehensiveness of anomaly detection is improved.
[0033] Specifically, when it is detected that the user click volume exceeds 3 times the standard deviation of the baseline within 5 minutes, it is regarded as a sudden increase in the user click volume, and the user behavior data is associated with a time series anomaly identifier; a user behavior Markov chain is constructed. If the user's behavior path is an unlikely event in the Markov chain, it indicates abnormal behavior. When a low-probability path of the user is detected, the user behavior data is associated with a behavior chain anomaly identifier; when an abnormal cluster with more than 50 device IDs associated with the same IP is identified, this may indicate that someone is using a proxy server or VPN for fraudulent behavior, and the environmental feature data is associated with an environmental aggregation anomaly identifier; a comprehensive risk warning signal is generated by combining the above three anomaly identifiers.
[0034] In one embodiment, the risk warning signal includes a low-risk signal, a medium-risk signal, and a high-risk signal. Step S34 specifically includes the steps of: S341: Generate a low-risk signal when a single-dimensional anomaly identifier is identified; S342: Generate a medium-risk signal when multi-dimensional anomaly identifiers are identified; S343: Generate a high-risk signal when it is identified that the IP comes from a data center and the click conversion rate is zero.
[0035] In this embodiment, a data center is usually used to host servers rather than for normal user activities. If an IP address comes from a data center and the click conversion rate is zero, this may indicate that someone is using an automated tool for fraudulent clicks.
[0036] Specifically, when a single-dimensional anomaly identifier is identified, that is, when only one specific anomaly is detected in the user behavior data and the environmental feature data, a low-risk signal is generated; when multi-dimensional anomaly identifiers are identified, for example, both a sudden increase in the click-through rate and a low-probability event in the user behavior path are detected, a medium-risk signal is generated; when it is identified that the IP comes from a data center and the click conversion rate is zero, it indicates highly suspicious behavior, and at this time, a high-risk signal is generated.
[0037] In one embodiment, after step S50: Based on the risk type and risk level, match the control actions in the preset policy library and execute the control actions, the following steps are further included: S51: Set a whitelist according to the advertiser contract, and do not execute the control action when the whitelist information is identified; S52: When the frequency of identifying the same type of high-risk signal exceeds the preset threshold, force manual review before executing the control action.
[0038] In this embodiment, the preset policy library contains a series of predefined control actions matched to various risk types and risk levels, which are determined based on historical data and industry best practices. The control actions are specifically divided into: pausing the advertisement delivery, immediately stopping its display to prevent further losses or risks; reducing the advertisement budget to reduce potential financial risks; changing the delivery strategy, adjusting the advertisement delivery time, region, audience group, etc.; implementing interception, for known malicious traffic or behaviors, intercepting them through technical means; reducing the weight of traffic, for suspicious but uncertain traffic, reducing its weight in advertisement delivery to reduce its impact.
[0039] Specifically, according to the identified risk type and risk level, look up the corresponding control actions in the preset policy library, execute the corresponding control actions according to the matched policy, and set specific advertisers or advertisement content in the whitelist according to the contract content signed between the advertiser and the platform. Before executing the control actions, check whether the current advertiser or advertisement content is in the whitelist. If the whitelist information is identified, the system will not execute any control actions and continue to process according to the normal process. When it is detected that the same type of high-risk signal is triggered more than five times per hour, trigger the manual review mechanism. The review personnel collect all information related to the risk event, including the trigger reason, scope of influence, etc. The review personnel conduct a detailed assessment of the risk event and decide whether to execute, adjust or cancel the control actions recommended by the system. The review results and decisions are recorded, and the preset policy library is updated according to the situation to optimize the future automatic control process.
[0040] In one embodiment, step S60 specifically includes the steps of: S61: Send the control result information as a label to the training set, where the control result information includes successful interception information and misjudgment information; S62: Supplement new attack samples for the new unknown risks in the risk type through manual annotation and send them to the training set.
[0041] In this embodiment, the new unknown risk is a risk type that the system has not yet identified or cannot classify, possibly because they are new attack means or abnormal behavior patterns.
[0042] Specifically, send the control result information as a label to the training set of the dynamic baseline model. The successful interception information helps the model learn how to more accurately identify malicious behaviors, while the misjudgment information helps the model understand which behaviors are wrongly classified as abnormal, so as to reduce similar errors in future predictions; since the new risks are unknown, professional personnel are required to analyze and annotate to determine the characteristics of these risks. Through manual annotation, these new risks are converted into available training samples and supplemented into the training dataset, so that the model can learn and identify these new risk types in future training cycles.
[0043] In one embodiment, after step S60, the following steps are further included: S63: Monitor the historical effects of different control actions in real time, and dynamically adjust the priorities of the control actions according to the historical effects.
[0044] In this embodiment, the monitoring can be automated and carried out through preset metrics and evaluation criteria. The historical effects of different control actions are the number of times each control action has successfully intercepted risks, the number of misjudgments caused, and the impact on the delivery effect within the past 30 days.
[0045] Specifically, continuously track and record the implementation effects of different control actions, and adjust the priorities of the control actions based on the historical effects in the past 30 days. For example, when the number of times a certain control action has successfully intercepted risks is significantly higher than that of other control actions, it may be promoted to the preferred measure. On the contrary, if a certain control action has poor effects or generates too many misjudgments, its priority may be reduced.
[0046] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0047] In one embodiment, a data delivery risk early warning and intelligent control system is provided, and this system corresponds one-to-one with a data delivery risk early warning and intelligent control method in the above embodiment. As Figure 4 shown, this system includes: An identification module, configured to collect traffic feature data, user behavior data, and environmental feature data of data delivery in real time; A dynamic baseline model construction module, configured to establish a dynamic baseline model and generate benchmark range data of normal delivery behavior based on historical data and industry standards; A risk early warning module, configured to perform anomaly detection on user behavior data and environmental feature data, and generate a risk early warning signal; A control implementation module, configured to, when receiving a risk early warning signal, match control actions in a preset policy library based on the risk type and risk level, and execute the control actions; A feedback module, configured to monitor the feedback effect and continuously optimize the parameters of the dynamic baseline model.
[0048] For the specific limitations of a data delivery risk warning and intelligent control system, reference can be made to the limitations of a data delivery risk warning and intelligent control method in the foregoing text, which will not be elaborated herein. Each module in the above data delivery risk warning and intelligent control system can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0049] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data delivery risk warning and intelligent control method.
[0050] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements a data delivery risk warning and intelligent control method; In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, it implements a data delivery risk warning and intelligent control method.
[0051] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0052] Those skilled in the art can clearly understand that for the convenience and conciseness of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to be completed by several functional units and modules as needed, that is, the internal structure of the device is divided into several functional units or modules to complete all or part of the functions described above.
[0053] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A data delivery risk warning and intelligent management method, characterized in that: Includes steps: Collect traffic characteristic data, user behavior data and environmental characteristic data of data delivery in real time; Establish a dynamic baseline model to generate benchmark range data of normal delivery behavior based on historical data and industry standards, the benchmark range data includes click rate threshold data and time period distribution law data; Use dynamic baseline models to detect anomalies in user behavior data and environmental feature data and generate risk warning signals; When a risk warning signal is received, the risk type is identified and a corresponding risk level is generated. The risk types include false clicks, machine-generated traffic, traffic hijacking, and new unknown risks. Based on the risk type and risk level, the control actions in the preset strategy library are matched and executed; Monitor feedback effects and continuously optimize dynamic baseline model parameters.
2. A data delivery risk early warning and intelligent management and control method according to claim 1, characterized in that: The step of establishing a dynamic baseline model to generate a benchmark range data of normal delivery behavior based on historical data and industry standards specifically includes the following steps: Extract historical data from the past several months and remove abnormal data; Fit Poisson distribution to hourly flow and generate confidence intervals for period flow; Calculate click-through rate threshold data using the quantile method, combine the click-through rate threshold data with the confidence interval of the time period traffic, and generate benchmark range data; Automatically retrain baseline models at preset intervals, integrate the latest data and industry reports, and set baseline deviation warnings.
3. According to claim 1, a data delivery risk early warning and intelligent management and control method is characterized in that: The step of using the dynamic baseline model to perform anomaly detection on user behavior data and environmental feature data and generate a risk warning signal specifically includes the following steps: Compare the user behavior data with the click rate threshold data, and when a sudden increase in user clicks is detected within a preset time range, associate the user behavior data with a time series anomaly flag; Build a user behavior Markov chain. When a user's low-probability path is detected, associate the user behavior data with the behavior chain anomaly marker. When it is identified that the same IP in the environmental feature data is associated with a device ID greater than a preset number, the environmental feature data is associated with an environmental aggregation anomaly flag; Generate risk warning signals based on time series anomaly identification, behavior chain anomaly identification and environment aggregation anomaly identification.
4. A data delivery risk early warning and intelligent management and control method according to claim 3, characterized in that: The risk warning signal includes a low risk signal, a medium risk signal and a high risk signal. The step of generating the risk warning signal based on the time sequence anomaly mark, the behavior chain anomaly mark and the environment aggregation anomaly mark specifically includes the following steps: A low-risk signal is generated when an abnormal signature of a single dimension is identified; When a multi-dimensional abnormal sign is identified, a medium-risk signal is generated; A high risk signal is generated when an IP is identified as coming from a data center and the click has zero conversions.
5. A data delivery risk early warning and intelligent management and control method according to claim 1, characterized in that: After the step of matching the control actions in the preset strategy library based on the risk type and risk level and executing the control actions, the step further includes: Set up a whitelist based on the advertiser contract, and do not perform control actions when whitelist information is identified; When the frequency of identifying the same type of high-risk signals exceeds the preset threshold, manual review is mandatory before executing the control action.
6. A data delivery risk early warning and intelligent management and control method according to claim 1, characterized in that: The step of monitoring the feedback effect and continuously optimizing the dynamic baseline model parameters specifically includes the following steps: Sending the control result information as a label to the training set, wherein the control result information includes successful interception information and misjudgment information; New unknown risks in risk types are supplemented with new attack samples through manual annotation and sent to the training set.
7. A data delivery risk early warning and intelligent management method according to claim 1, characterized in that: After the step of monitoring the feedback effect and continuously optimizing the dynamic baseline model parameters, the following steps are also included: Monitor the historical effects of different control actions in real time, and dynamically adjust the priority of control actions based on the historical effects.
8. A data delivery risk warning and intelligent management and control system, characterized in that: include: Identification module, used to collect traffic characteristic data, user behavior data and environmental characteristic data of data delivery in real time; Dynamic baseline model building module, used to build a dynamic baseline model and generate benchmark range data of normal delivery behavior based on historical data and industry standards; The risk warning module is used to detect anomalies in user behavior data and environmental feature data and generate risk warning signals; A control implementation module is used to match the control actions in the preset strategy library based on the risk type and risk level and execute the control actions when a risk warning signal is received; The feedback module is used to monitor the feedback effect and continuously optimize the dynamic baseline model parameters.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of a data release risk warning and intelligent management and control method as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, the steps of a data release risk warning and intelligent management and control method as described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Advertisement anti-cheating method and device
CN106651458A
Traffic data monitoring method and device and server
CN107124320A
Video file playback volume detection method and system
CN107529093A
Target object abnormal propagation detection method, apparatus and device, and storage medium
CN111899040A
User identification method and related product
WO2020257991A1
Cited By
Marketing mobile terminal safety monitoring and dynamic response method and system
CN120912250A
Marketing mobile terminal security monitoring and dynamic response method and system
CN120912250B
Offshore wind turbine generator health degree dynamic evaluation and early warning system
CN120974122A
Information system operation risk early warning method, system and equipment
CN120994425A
A method, system, and equipment for early warning of operational risks in information systems.
CN120994425B