Service rights and interests fraudulent use risk monitoring method and device, storage medium and product

By receiving the client's equity request and historical operation data on the server, we judge whether risk level detection is needed, and using the pre-trained model to output the user risk level for identity verification, we solve the problem of poor accuracy in the risk monitoring of service equity in the prior art, and improve the accuracy and efficiency of monitoring.

CN120125253APending Publication Date: 2025-06-10PEOPLE'S INSURANCE COMPANY OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510188851.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the prior art, there is a problem of poor accuracy in monitoring risk of service rights.

Method used

By receiving the rights request sent by the client on the server, obtaining the client's historical operation data, and determining whether risk level detection is required. If necessary, input historical operation data to the pre-trained risk level detection model for processing, output the user risk level, and generate verification prompt information based on this level for identity verification.

Benefits of technology

It improves the accuracy of risk monitoring of service equity, reduces the call rate of pre-trained risk level detection model, improves the processing efficiency of the model, and realizes identity verification based on user risk level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120125253A_ABST
    Figure CN120125253A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a service right and interest illegal use risk monitoring method and device, a storage medium and a product, which are applied to a server side, and the method comprises the following steps: receiving a right and interest request sent by a client side; wherein the rights and interests request comprises target service rights and interests and an identifier of the client; acquiring historical operation data of the client according to the identifier of the client; according to the right request and the historical operation data, whether risk level detection needs to be carried out is judged; if the risk level detection needs to be carried out, outputting a user risk level according to the historical operation data; sending the user risk level to a client, so that the client generates verification prompt information according to the user risk level; if an identity verification result sent by the client is received, judging whether identity verification is passed or not; if the identity verification is passed, sending service contents corresponding to the target service rights and interests; if the identity verification is not passed, false use risk prompt information is sent; the problem of poor accuracy of monitoring of the service right and interest fraudulent use risk is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular, to a method, device, storage medium, and product for monitoring the risk of unauthorized use of service rights and interests. Background Art

[0002] The service rights and interests system is used to manage the membership rights and interests of users. The system includes a client and a server. After a user registers as a member through the client, the member user can enjoy the service content of various service rights and interests. At the same time, for the requests of service rights and interests applied by the member user through the client, monitoring is required to avoid the risk of unauthorized use of service rights and interests by others.

[0003] In the prior art, the server usually judges the requests of member users according to fixed rules set based on manual experience. When the request behavior of a member user is determined to be an unauthorized use behavior, the user account of the member user will be processed.

[0004] The solution of the prior art is determined by fixed rules set based on manual experience. Therefore, there is a problem of poor accuracy in monitoring the risk of unauthorized use of service rights and interests. Summary of the Invention

[0005] The method, device, storage medium, and product for monitoring the risk of unauthorized use of service rights and interests provided by the embodiments of this application are used to solve the problem of poor accuracy in monitoring the risk of unauthorized use of service rights and interests.

[0006] In a first aspect, an embodiment of the present application provides a method for monitoring the risk of unauthorized use of service rights and interests, which is applied to a server and includes: receiving a rights and interests request sent by a client; where the rights and interests request includes a target service right and the identifier of the client; obtaining the historical operation data of the client according to the identifier of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage; judging whether it is necessary to perform a risk level detection according to the rights and interests request and the historical operation data; if it is not necessary to perform a risk level detection, sending the service content corresponding to the target service right to the client; if it is necessary to perform a risk level detection, inputting the historical operation data into a pre-trained risk level detection model for processing, and outputting a user risk level; sending the user risk level to the client, so that the client generates a verification prompt message according to the user risk level, where the verification prompt message is used to prompt the user to perform an identity verification; if the identity verification result sent by the client is received, judging whether the identity verification passes according to the identity verification result; if the identity verification passes, sending the service content corresponding to the target service right to the client according to the user risk level; if the identity verification fails, sending the unauthorized use risk prompt message to the client according to the user risk level.

[0007] In a possible implementation manner, the historical operation data includes historical rights and interests requests and historical portrait data; the judging whether it is necessary to perform a risk level detection according to the rights and interests request and the historical operation data includes: obtaining the cumulative number of rights and interests requests according to the number of historical rights and interests requests and the rights and interests request; determining a rights and interests request target threshold from the rights and interests request thresholds according to the historical portrait data; if the cumulative number of rights and interests requests is less than or equal to the rights and interests request target threshold, it is not necessary to perform a risk level detection; if the cumulative number of rights and interests requests is greater than the rights and interests request target threshold, it is necessary to perform a risk level detection.

[0008] In a possible implementation manner, the historical operation data includes historical entitlement requests and historical portrait data; the historical entitlement requests include the number of times the user's mobile phone number is changed, the number of times the user logs in from a different location, the number of suspected abnormal applications of the user, and the number of times the user's password is modified; inputting the historical operation data into a pre-trained risk level detection model for processing and outputting the user risk level includes: obtaining a first weighted value, a second weighted value, a third weighted value, and a fourth weighted value according to the historical portrait data and the reference portrait data; performing weighted calculation on the number of times the user's mobile phone number is changed according to the first weighted value to obtain a weighted number of times the user's mobile phone number is changed; performing weighted calculation on the number of times the user logs in from a different location according to the second weighted value to obtain a weighted number of times the user logs in from a different location; performing weighted calculation on the number of suspected abnormal applications of the user according to the third weighted value to obtain a weighted number of suspected abnormal applications of the user; performing weighted calculation on the number of times the user's password is modified according to the fourth weighted value to obtain a weighted number of times the user's password is modified; the pre-trained risk level detection model performs clustering analysis processing on the weighted number of times the user's mobile phone number is changed, the weighted number of times the user logs in from a different location, the weighted number of suspected abnormal applications of the user, and the weighted number of times the user's password is modified according to the reference detection data, and outputs the user risk level; wherein, the reference detection data includes the number of times the mobile phone number is changed, the number of times of logging in from a different location, the number of suspected abnormal applications, and the number of times the password is modified.

[0009] In a possible implementation manner, obtaining the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data and the reference portrait data includes: classifying the historical portrait data to obtain the historical portrait data of the first type of data source and the historical portrait data of the second type of data source; judging the magnitude relationship between the data volume of the historical portrait data of the first type of data source and the data volume of the historical portrait data of the second type of data source; if the data volume of the historical portrait data of the first type of data source is greater than the data volume of the historical portrait data of the second type of data source, obtaining the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the first type of data source and the reference portrait data of the first type of data source in the reference portrait data; if the data volume of the historical portrait data of the second type of data source is greater than or equal to the data volume of the historical portrait data of the first type of data source, obtaining the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the second type of data source and the reference portrait data of the second type of data source in the reference portrait data.

[0010] In a possible implementation manner, the method further includes: updating the pre-trained risk level detection model according to the server status information of the server.

[0011] In a possible implementation manner, updating the pre-trained risk level detection model according to the server status information of the server includes: generating the total user access volume according to the server status information; if the total user access volume is greater than a preset access volume threshold, updating the pre-trained risk level detection model.

[0012] In a possible implementation manner, while sending the service content corresponding to the target service right to the client according to the user risk level, the method further includes: sending risk level prompt information corresponding to the user risk level to the client.

[0013] In a second aspect, an embodiment of the present application provides a risk monitoring device for misappropriation of service rights, which is applied to a server and includes:

[0014] A receiving module, configured to receive a right request sent by a client; the right request includes a target service right and an identifier of the client;

[0015] A first processing module, configured to obtain historical operation data of the client according to the identifier of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage; determine whether risk level detection is required according to the right request and the historical operation data; if risk level detection is not required, send the service content corresponding to the target service right to the client; if risk level detection is required, input the historical operation data into a pre-trained risk level detection model for processing, and output a user risk level;

[0016] A second processing module, configured to send the user risk level to the client, so that the client generates verification prompt information according to the user risk level, where the verification prompt information is used to prompt the user to perform identity verification; if the identity verification result sent by the client is received, determine whether the identity verification passes according to the identity verification result; if the identity verification passes, send the service content corresponding to the target service right to the client according to the user risk level; if the identity verification fails, send the misappropriation risk prompt information to the client according to the user risk level.

[0017] In a possible implementation, the historical operation data includes historical entitlement requests and historical portrait data; when determining whether risk level detection is required according to the entitlement request and the historical operation data, the first processing module is specifically configured to: obtain the cumulative number of entitlement requests based on the number of the historical entitlement requests and the entitlement request; determine an entitlement request target threshold from entitlement request thresholds according to the historical portrait data; if the cumulative number of entitlement requests is less than or equal to the entitlement request target threshold, risk level detection is not required; if the cumulative number of entitlement requests is greater than the entitlement request target threshold, risk level detection is required.

[0018] In a possible implementation, the historical operation data includes historical entitlement requests and historical portrait data; the historical entitlement requests include the number of user mobile phone number changes, the number of user logins from other locations, the number of user suspected abnormal applications, and the number of user password modifications; when the historical operation data is input into a pre-trained risk level detection model for processing and the user risk level is output, the first processing module is specifically configured to: obtain a first weighted value, a second weighted value, a third weighted value, and a fourth weighted value according to the historical portrait data and the reference portrait data; perform weighted calculation on the number of user mobile phone number changes according to the first weighted value to obtain a weighted number of user mobile phone number changes; perform weighted calculation on the number of user logins from other locations according to the second weighted value to obtain a weighted number of user logins from other locations; perform weighted calculation on the number of user suspected abnormal applications according to the third weighted value to obtain a weighted number of user suspected abnormal applications; perform weighted calculation on the number of user password modifications according to the fourth weighted value to obtain a weighted number of user password modifications; the pre-trained risk level detection model performs cluster analysis processing on the weighted number of user mobile phone number changes, the weighted number of user logins from other locations, the weighted number of user suspected abnormal applications, and the weighted number of user password modifications according to the reference detection data, and outputs the user risk level; wherein, the reference detection data includes the number of mobile phone number changes, the number of logins from other locations, the number of suspected abnormal applications, and the number of password modifications.

[0019] In a possible implementation manner, when obtaining the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data and the reference portrait data, the first processing module is specifically configured to: classify the historical portrait data to obtain the historical portrait data of the first type of data source and the historical portrait data of the second type of data source; determine the magnitude relationship between the data volume of the historical portrait data of the first type of data source and the data volume of the historical portrait data of the second type of data source; if the data volume of the historical portrait data of the first type of data source is greater than the data volume of the historical portrait data of the second type of data source, obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the first type of data source and the reference portrait data of the first type of data source in the reference portrait data; if the data volume of the historical portrait data of the second type of data source is greater than or equal to the data volume of the historical portrait data of the first type of data source, obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the second type of data source and the reference portrait data of the second type of data source in the reference portrait data.

[0020] In a possible implementation manner, the apparatus is further configured to: update the pre-trained risk level detection model according to the server status information of the server.

[0021] In a possible implementation manner, when updating the pre-trained risk level detection model according to the server status information of the server, the apparatus is specifically configured to: generate the total user access volume according to the server status information; if the total user access volume is greater than a preset access volume threshold, update the pre-trained risk level detection model.

[0022] In a possible implementation manner, when sending the service content corresponding to the target service right to the client according to the user risk level, the second processing module is further configured to: send risk level prompt information corresponding to the user risk level to the client.

[0023] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;

[0024] The memory stores computer execution instructions;

[0025] The processor executes the computer execution instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementation manners of the first aspect.

[0026] Fourthly, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the above first aspect and / or various possible implementation manners of the first aspect.

[0027] Fifthly, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the above first aspect and / or various possible implementation manners of the first aspect.

[0028] The method, device, storage medium and product for monitoring the risk of unauthorized use of service rights and interests provided by the embodiments of the present application are applied to the server side. By receiving the rights and interests request sent by the client; wherein the rights and interests request includes the target service rights and interests and the identifier of the client; according to the identifier of the client, obtaining the historical operation data of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server side for storage; according to the rights and interests request and the historical operation data, determining whether it is necessary to perform a risk level detection; if it is not necessary to perform a risk level detection, sending the service content corresponding to the target service rights and interests to the client; if it is necessary to perform a risk level detection, inputting the historical operation data into a pre-trained risk level detection model for processing, and outputting a user risk level; sending the user risk level to the client, so that the client generates a verification prompt message according to the user risk level, wherein the verification prompt message is used to prompt the user to perform identity verification; if the identity verification result sent by the client is received, determining whether the identity verification passes according to the identity verification result; if the identity verification passes, sending the service content corresponding to the target service rights and interests to the client according to the user risk level; if the identity verification fails, sending the unauthorized use risk prompt message to the client according to the user risk level. The server side receives the rights and interests request of the user applying for the target service rights and interests sent by the client, as well as the client identifier included in the rights and interests request; realizes obtaining the corresponding historical operation data of the client according to the identifier of the client, and then determines whether it is necessary to perform a risk level detection according to the rights and interests request and the historical operation data, reduces the call rate of the pre-trained risk level detection model, and further improves the processing efficiency of the pre-trained risk level detection model, and provides the model processing resources of the pre-trained risk level detection model for the historical operation data that needs to perform a risk level detection; further, the pre-trained risk level detection model outputs a user risk level according to the historical operation data to realize verifying the identity of the user based on the user risk level; and then the server side determines whether the identity verification passes according to the identity verification result sent by the client; if the identity verification passes, the server side sends the service content corresponding to the target service rights and interests to the client according to the user risk level; if the identity verification fails, the server side sends the unauthorized use risk prompt message to the client according to the user risk level; solves the problem of poor accuracy in monitoring the risk of unauthorized use of service rights and interests caused by the existing technical solutions. Brief Description of the Drawings

[0029] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0030] Figure 1Schematic diagram of the scenario for monitoring the risk of unauthorized use of service rights provided by this application;

[0031] Figure 2 Flowchart of the method for monitoring the risk of unauthorized use of service rights provided by an embodiment of this application;

[0032] Figure 3 Schematic diagram of the structure of the device for monitoring the risk of unauthorized use of service rights provided by an embodiment of this application;

[0033] Figure 4 Schematic diagram of the structure of the electronic device provided by this application.

[0034] Through the above-mentioned drawings, specific embodiments of this application have been shown, and more detailed descriptions will be given later. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed implementation manners

[0035] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application. On the contrary, they are merely examples of the devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0036] In the technical solution of this application, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and data involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0037] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. And the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant regions, and corresponding operation entrances are provided for the user to choose to authorize or refuse.

[0038] The application scenarios of the embodiments of this application are explained below:

[0039] Figure 1 Schematic diagram of the scenario for monitoring the risk of unauthorized use of service rights provided by this application, as Figure 1As shown in the figure, the specific application scenario of this application is that when a user applies for service rights and interests through a client, the server evaluates the risk of unauthorized use of the service rights and interests based on the rights and interests request sent by the client, and then determines whether to provide the service corresponding to the service rights and interests to the user according to the evaluation result. The execution subject of the method provided in the embodiments of this application can be an electronic control unit, a terminal device, or a server. Taking the server as the execution subject for illustration, a server-side is deployed in the server. Based on the method for monitoring the risk of unauthorized use of service rights and interests provided in the embodiments of this application, the server-side processes the rights and interests request sent by the client received to determine the user risk level of the user, and then further verifies the user according to the user risk level. If the verification is passed, the service content corresponding to the target service rights and interests is sent to the client based on the user risk level. If the verification fails, a risk prompt message for unauthorized use is sent to the client based on the user risk level, that is, the monitoring of the risk of unauthorized use of service rights and interests is realized.

[0040] Combined with the above scenario, it can be seen that in the prior art, the server-side usually judges the requests of member users according to fixed rules set based on manual experience. When the request behavior of a member user is determined to be an act of unauthorized use of rights and interests, the user account of the member user will be processed. Since the solution of the prior art is determined based on fixed rules set based on manual experience, there is a problem of poor accuracy in monitoring the risk of unauthorized use of service rights and interests.

[0041] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the accompanying drawings.

[0042] Figure 2 It is a flowchart of the method for monitoring the risk of unauthorized use of service rights and interests provided in an embodiment of this application. As Figure 2 shown, the execution subject of the method for monitoring the risk of unauthorized use of service rights and interests provided in this embodiment can be an electronic control unit, a terminal device, or a server. Exemplarily, in this embodiment, the server is used as the execution subject of the method in this embodiment for illustration. A server-side is deployed in the server. The method for monitoring the risk of unauthorized use of service rights and interests provided in this embodiment is applied to the server-side and includes the following steps:

[0043] Step S101, receive the rights and interests request sent by the client; where the rights and interests request includes the target service rights and interests and the identifier of the client.

[0044] Exemplarily, a system for providing service rights and interests to users includes a server side and a client side. The server side is deployed on a server, and the client side is deployed on a terminal device on the user side. After the user operates through the client on the terminal device to apply for service rights and interests, the client generates a corresponding rights and interests request; further, the server side can receive the rights and interests request sent by the client; wherein, the rights and interests request includes the target service rights and interests and the identifier of the client, and the target service rights and interests are used to indicate the service rights and interests selected by the user from two or more service rights and interests, and the identifier of the client is used to indicate the corresponding client.

[0045] Step S102, according to the identifier of the client, obtain the historical operation data of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server side for storage.

[0046] Exemplarily, after the server side obtains the identifier of the client, the server side, according to the identifier of the client, obtains the historical operation data of the corresponding client from the storage unit of the server side; wherein, the historical operation data is the historical operation record of the user recorded by the client and sent to the server side for storage; further, for example, the historical operation record of the user includes changing the bound mobile phone number and applying for service rights and interests. Specifically, for example, the client implements recording the operation records of the user changing the bound mobile phone number and applying for service rights and interests, and uploads the operation records to the server side, and the server side then stores the operation records (i.e., historical operation records) of the user sent by the client; further, after the server side receives the identifier of the client, it can obtain the corresponding historical operation data of the client from the storage unit according to the identifier of the client.

[0047] Step S103, according to the rights and interests request and the historical operation data, determine whether risk level detection is required.

[0048] Exemplarily, the server side, according to the historical operation data, determines the service rights and interests applied for by the user and the corresponding application times within the current statistical period, and then, in combination with the rights and interests request for the service rights and interests applied for currently, determines the total number of applications for this service rights and interests within the current statistical period; further, in combination with the preset request threshold corresponding to this service rights and interests, it can be determined whether risk level detection is required; for example, if the total number of applications is greater than the preset request threshold, risk level detection is required, and if the total number of applications is less than or equal to the preset request threshold, risk level detection is not required.

[0049] In another possible implementation manner, the historical operation data includes historical rights and interests requests and historical portrait data; the specific implementation manner of step S103 includes:

[0050] Step S1031, according to the number of historical rights and interests requests and the rights and interests request, obtain the cumulative number of rights and interests requests.

[0051] Step S1032: Determine the target threshold for the rights and interests request from the rights and interests request thresholds according to the historical portrait data.

[0052] Exemplarily, the server adds the number of the current rights and interests request and the number of historical rights and interests requests to obtain the cumulative number of rights and interests requests; then, according to the historical portrait data, it matches the corresponding target threshold for the rights and interests request from the rights and interests request thresholds. For example, the rights and interests request thresholds include a first threshold, a second threshold, and a third threshold. The first threshold corresponds to the first portrait data, the second threshold corresponds to the second portrait data, and the third threshold corresponds to the third portrait data. Then, it calculates the similarity between the historical portrait data and the first portrait data, the second portrait data, and the third portrait data respectively, and determines the rights and interests request threshold corresponding to the portrait data with the highest similarity as the target threshold for the rights and interests request. For example, if the similarity between the historical portrait data and the second portrait data is the highest, then the second threshold corresponding to the second portrait data is determined as the target threshold for the rights and interests request.

[0053] Step S1033: Judge the size relationship between the cumulative number of rights and interests requests and the target threshold for the rights and interests request.

[0054] Step S1034: If the cumulative number of rights and interests requests is less than or equal to the target threshold for the rights and interests request, there is no need to perform a risk level detection.

[0055] Step S1035: If the cumulative number of rights and interests requests is greater than the target threshold for the rights and interests request, a risk level detection is required.

[0056] Exemplarily, after obtaining the target threshold for the rights and interests request, it immediately judges the size relationship between the cumulative number of rights and interests requests and the target threshold for the rights and interests request. If the cumulative number of rights and interests requests is less than or equal to the target threshold for the rights and interests request, there is no need to perform a risk level detection; if the cumulative number of rights and interests requests is greater than the target threshold for the rights and interests request, a risk level detection is required.

[0057] In the steps of this embodiment, the method of determining the corresponding target threshold for the rights and interests request through the historical portrait data improves the accuracy of judging whether a risk level detection is required.

[0058] Step S104: If a risk level detection is not required, send the service content corresponding to the target service rights and interests to the client.

[0059] Exemplarily, when the server determines that a risk level detection is not required according to the judgment result, the server directly sends the service content corresponding to the target service rights and interests to the client; thus, the client provides the service content corresponding to the target service rights and interests to the user.

[0060] Step S105, if risk level detection is required, input the historical operation data into the pre-trained risk level detection model for processing, and output the user risk level.

[0061] Exemplarily, when the server determines that risk level detection is required according to the judgment result, the server inputs the historical operation data into the pre-trained risk level detection model for processing, and then outputs the user risk level; specifically, for example, the pre-trained risk level detection model processes the historical operation data, that is, processes the user's historical operation records, and then realizes the risk identification of the user, and can output the corresponding user risk level.

[0062] Demonstratively, the pre-trained risk level detection model is obtained by training with an unsupervised clustering algorithm and a supervised classification algorithm. For example, first, the historical operation data used for model training is clustered by the unsupervised clustering algorithm to obtain a cluster clustering result. Further, the cluster clustering result is labeled to obtain labeled training data. Then, the model is trained with supervised classification using the labeled training data, and the model parameters are adjusted according to the training results to obtain the pre-trained risk level detection model; among them, the unsupervised clustering algorithms include the Kmeans clustering algorithm, the DBSCAN clustering algorithm, the hierarchical clustering algorithm, and the Gaussian mixture clustering algorithm, and the supervised classification trainer includes the XGBoost classification trainer.

[0063] In a possible implementation manner, the historical operation data includes historical entitlement requests and historical portrait data; the historical entitlement requests include the number of user mobile phone number changes, the number of user logins from other locations, the number of suspected abnormal applications of the user, and the number of user password modifications. The specific implementation manner of step S105 includes:

[0064] Step S1051, obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data and the reference portrait data.

[0065] Exemplarily, the server determines corresponding weighting coefficients according to the matching relationship between the reference portrait data and the historical portrait data, that is, obtains the first weighting value, the second weighting value, the third weighting value, and the fourth weighting value; specifically, for example, the reference portrait data includes the first reference portrait data, the second reference portrait data, and the third reference portrait data. The first reference portrait data corresponds to the first type of first weighting value, the first type of second weighting value, the first type of third weighting value, and the first type of fourth weighting value. The second reference portrait data corresponds to the second type of first weighting value, the second type of second weighting value, the second type of third weighting value, and the second type of fourth weighting value. The third reference portrait data corresponds to the third type of first weighting value, the third type of second weighting value, the third type of third weighting value, and the third type of fourth weighting value. Calculate the correlation degree (matching relationship) between the first reference portrait data and the historical portrait data, the second reference portrait data and the historical portrait data, and the third reference portrait data and the historical portrait data respectively. If the correlation degree between the second reference portrait data and the historical portrait data is the highest, then the second type of first weighting value, the second type of second weighting value, the second type of third weighting value, and the second type of fourth weighting value corresponding to the second reference portrait data are determined as the weighting coefficients, that is, the second type of first weighting value is determined as the first weighting value, the second type of second weighting value is determined as the second weighting value, the second type of third weighting value is determined as the third weighting value, and the second type of fourth weighting value is determined as the fourth weighting value.

[0066] It can be understood that since the historical rights and interests requests in the embodiments of the present application include four types of data, the number of weighting coefficients is four; the present application does not specifically limit the number of data types included in the historical rights and interests requests, so the number of weighting coefficients can be less than four or more than four.

[0067] Step S1052: Perform weighted calculation on the number of times the user's mobile phone number is changed according to the first weighting value to obtain the weighted number of times the user's mobile phone number is changed.

[0068] Step S1053: Obtain the weighted number of times of off-site login of the user according to the second weighting value.

[0069] Step S1054: Obtain the weighted number of suspected abnormal applications of the user according to the third weighting value.

[0070] Step S1055: Obtain the weighted number of times the user's password is modified according to the fourth weighting value.

[0071] Exemplarily, after the server determines the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value, the corresponding historical rights requests can be weighted and corrected according to the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value, and then the corresponding weighted mobile phone number change times, weighted off-site login times, weighted suspected abnormal application numbers, and weighted user password modification times are obtained; that is, the weighted mobile phone number change times are obtained by weighted calculation of the user mobile phone number change times according to the first weighted value, the weighted off-site login times are obtained according to the second weighted value for the user off-site login times, the weighted suspected abnormal application numbers are obtained according to the third weighted value for the user suspected abnormal application numbers, and the weighted user password modification times are obtained according to the fourth weighted value for the user password modification times.

[0072] Step S1056, the pre-trained risk level detection model performs clustering analysis on the weighted mobile phone number change times, weighted off-site login times, weighted suspected abnormal application numbers, and weighted user password modification times according to the reference detection data, and outputs the user risk level; wherein, the reference detection data includes the mobile phone number change times, off-site login times, suspected abnormal application numbers, and password modification times.

[0073] Exemplarily, after obtaining the weighted mobile phone number change times, weighted off-site login times, weighted suspected abnormal application numbers, and weighted user password modification times, the server calls the pre-trained risk level detection model to perform clustering analysis on the weighted mobile phone number change times, weighted off-site login times, weighted suspected abnormal application numbers, and weighted user password modification times based on the reference monitoring data, and then outputs the user risk level; wherein, the reference detection data includes the mobile phone number change times, off-site login times, suspected abnormal application numbers, and password modification times.

[0074] Further, in a possible implementation manner, the specific implementation manner of step S1051 includes:

[0075] Step S10511, classify the historical portrait data to obtain the historical portrait data of the first type of data source and the historical portrait data of the second type of data source.

[0076] Step S10512, determine the size relationship between the data volume of the historical portrait data of the first type of data source and the data volume of the historical portrait data of the second type of data source.

[0077] Step S10513, if the data volume of the historical portrait data of the first type of data source is greater than the data volume of the historical portrait data of the second type of data source, then obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the first type of data source and the reference portrait data of the first type of data source in the reference portrait data.

[0078] Step S10514, if the data volume of the historical portrait data of the second type of data source is greater than or equal to the data volume of the historical portrait data of the first type of data source, then based on the historical portrait data of the second type of data source and the reference portrait data of the second type of data source in the reference portrait data, obtain the first weighting value, the second weighting value, the third weighting value, and the fourth weighting value.

[0079] Exemplarily, the server classifies the historical portrait data based on the different data sources of the historical portrait data, and then obtains the historical portrait data of the first type of data source and the historical portrait data of the second type of data source; further, compares the sizes of the data volumes of the historical portrait data of the first type of data source and the historical portrait data of the second type of data source. If the data volume of the historical portrait data of the first type of data source is greater than the data volume of the historical portrait data of the second type of data source, then based on the first type of data source corresponding to the historical portrait data of the first type of data source, determine the reference portrait data of the first type of data source in the reference portrait data, and then based on the correlation degree (matching relationship) between the historical portrait data of the first type of data source and the reference portrait data of the first type of data source in the reference portrait data, obtain the first weighting value, the second weighting value, the third weighting value, and the fourth weighting value; if the data volume of the historical portrait data of the second type of data source is greater than or equal to the data volume of the historical portrait data of the first type of data source, then based on the second type of data source corresponding to the historical portrait data of the second type of data source, determine the reference portrait data of the second type of data source in the reference portrait data, and then based on the correlation degree (matching relationship) between the historical portrait data of the second type of data source and the reference portrait data of the second type of data source in the reference portrait data, obtain the first weighting value, the second weighting value, the third weighting value, and the fourth weighting value.

[0080] In the steps of this embodiment, by classifying the historical portrait data according to different data sources, the historical portrait data of the first type of data source and the historical portrait data of the second type of data source are obtained; further, based on the size relationship of the data volumes, analyze the correlation degree between the historical portrait data of the data source with the large data volume and the data of the corresponding data source in the reference portrait data, and then determine the corresponding first weighting value, second weighting value, third weighting value, and fourth weighting value, which improves the accuracy of determining the first weighting value, second weighting value, third weighting value, and fourth weighting value, provides accurate data for subsequent steps, and further improves the accuracy of the result output by the pre-trained risk level detection model.

[0081] Step S106, send the user risk level to the client, so that the client generates a verification prompt message according to the user risk level, where the verification prompt message is used to prompt the user to perform identity verification.

[0082] Exemplarily, after obtaining the user risk level output by the pre-trained risk level detection model at the server side, the server side immediately sends the user risk level to the client side, so that the client side generates a verification prompt message according to the user risk level, and then verifies the identity of the user. In a possible implementation manner, the user risk level includes a first-level risk, a second-level risk, and a third-level risk. The verification prompt message corresponding to the first-level risk is "Please confirm whether to perform face recognition", the verification prompt message corresponding to the second-level risk is "Please confirm whether to perform fingerprint recognition", and the verification prompt message corresponding to the third-level risk is "Please confirm whether to perform mobile phone verification code recognition". Furthermore, when the server side sends the user risk level to the client side, for example, the user risk level is a second-level risk, the client side generates the corresponding verification prompt message "Please confirm whether to perform fingerprint recognition" according to the "second-level risk" to prompt the user to perform identity verification through fingerprint recognition.

[0083] Step S107, if the identity verification result sent by the client side is received, determine whether the identity verification passes according to the identity verification result.

[0084] Exemplarily, if the server side receives the identity verification result sent by the client side, determine whether the identity verification passes according to the identity verification result, that is, if the identity verification result is that the identity verification is consistent, the identity verification passes; if the identity verification result is that the identity verification is inconsistent, the identity verification fails.

[0085] Step S108, if the identity verification result sent by the client side is not received, send a risk prompt message of identity theft to the client side.

[0086] Exemplarily, if the server side does not receive the identity verification result sent by the client side, it indicates that the user refuses to perform identity verification. Furthermore, the server side sends a risk prompt message of identity theft to the client side and does not send the service content corresponding to the target service right to the client side; furthermore, the client side does not provide the service content corresponding to the target service right to the user.

[0087] Step S109, if the identity verification passes, send the service content corresponding to the target service right to the client side according to the user risk level.

[0088] Exemplarily, if the user's identity verification is passed, the server sends the service content corresponding to the target service right applied for by the user to the client according to the user risk level output by the pre-trained risk level detection model, so as to enable the client to provide the service corresponding to the target service right to the user. Specifically, for example, if the target service right is "providing free music listening duration to the user", the corresponding service content is "providing the corresponding free music listening duration to the user based on the user risk level". For example, if the user risk level is level-one risk, the corresponding free music listening duration is 10 minutes; if the user risk level is level-two risk, the corresponding free music listening duration is 20 minutes; if the user risk level is level-three risk, the corresponding free music listening duration is 30 minutes. Furthermore, the server sends the service content corresponding to the target service right "providing the corresponding free music listening duration of 20 minutes to the user based on the user risk level 'level-two risk'" to the client according to the user risk level "level-two risk", and then enables the client to provide the service corresponding to the target service right to the user "Your free music listening duration is 20 minutes".

[0089] Furthermore, in a possible implementation manner, when sending the service content corresponding to the target service right to the client according to the user risk level, it further includes: sending risk level prompt information corresponding to the user risk level to the client. Specifically, for example, the risk level prompt information corresponding to the user risk level sent by the server to the client is "Your user risk level is level-two risk", and then the content displayed by the client to the user is "Your user risk level is level-two risk, and your free music listening duration is 20 minutes". By providing the prompt information corresponding to the user risk level to the user, it is convenient for the user to know their current user risk and improves the user experience.

[0090] Step S110, if the identity verification fails, send risk prompt information for impersonation to the client according to the user risk level.

[0091] Exemplarily, if the user's identity verification fails, the server sends the corresponding risk prompt information for impersonation to the client according to the user risk level. Specifically, for example, if the user risk level is level-one risk, the corresponding risk prompt information for impersonation sent by the server to the client is "The impersonation risk is level-one risk, and the face recognition identity verification fails"; if the user risk level is level-two risk, the corresponding risk prompt information for impersonation sent by the server to the client is "The impersonation risk is level-two risk, and the fingerprint recognition identity verification fails"; if the user risk level is level-three risk, the corresponding risk prompt information for impersonation sent by the server to the client is "The impersonation risk is level-three risk, and the mobile verification code recognition identity verification fails".

[0092] The method provided in this embodiment is applied to a server. The server receives a rights and interests request sent by a client. The rights and interests request includes a target service right and the identifier of the client. According to the identifier of the client, the server obtains the historical operation data of the client. The historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage. According to the rights and interests request and the historical operation data, the server determines whether risk level detection is required. If risk level detection is not required, the server sends the service content corresponding to the target service right to the client. If risk level detection is required, the historical operation data is input into a pre-trained risk level detection model for processing, and the user risk level is output. The user risk level is sent to the client so that the client generates a verification prompt message according to the user risk level. The verification prompt message is used to prompt the user to perform identity verification. If the identity verification result sent by the client is received, the server determines whether the identity verification passes according to the identity verification result. If the identity verification passes, the server sends the service content corresponding to the target service right to the client according to the user risk level. If the identity verification fails, the server sends a risk of impersonation prompt message to the client according to the user risk level. The server receives the rights and interests request for the client to apply for the target service right sent by the client and the client identifier included in the rights and interests request, obtains the corresponding historical operation data of the client according to the client identifier, and then determines whether risk level detection is required according to the rights and interests request and the historical operation data, reducing the call rate of the pre-trained risk level detection model, thereby improving the processing efficiency of the pre-trained risk level detection model and providing model processing resources of the pre-trained risk level detection model for the historical operation data that requires risk level detection. Further, the pre-trained risk level detection model outputs the user risk level according to the historical operation data to verify the identity of the user based on the user risk level. Then, the server determines whether the identity verification passes according to the identity verification result sent by the client. If the identity verification passes, the server sends the service content corresponding to the target service right to the client according to the user risk level. If the identity verification fails, the server sends a risk of impersonation prompt message to the client according to the user risk level, solving the problem of poor accuracy in monitoring the risk of service right impersonation in the prior art solution.

[0093] Further, in a possible implementation manner, the pre-trained risk level detection model is updated according to the server status information of the server. Specifically, for example, according to the server status information, the running duration of the server is determined. If the running duration of the server is greater than the preset running duration, the pre-trained risk level detection model is updated to prevent the accuracy of the pre-trained risk level detection model for detecting historical operation data from decreasing.

[0094] Furthermore, according to the server status information of the server, the pre-trained risk level detection model is updated. The specific implementation methods include: generating the total user access volume according to the server status information; if the total user access volume is greater than the preset access volume threshold, the pre-trained risk level detection model is updated. Specifically, for example, the server counts the user access volume according to the server status information to generate the total user access volume, and then compares the total user access volume with the preset access volume threshold. If the total user access volume is greater than the preset access volume threshold, it indicates that the user access volume is large during this statistical period. Then, the pre-trained risk level detection model is updated to improve the detection accuracy of the pre-trained risk level detection model, especially the detection accuracy of the risk of high-concurrency user access behaviors.

[0095] Figure 3 The structural schematic diagram of the risk monitoring device for misappropriation of service rights provided by an embodiment of the present application is as Figure 3 shown. The risk monitoring device 3 for misappropriation of service rights provided in this embodiment is applied to the server and includes:

[0096] A receiving module 31, configured to receive a rights request sent by a client; the rights request includes a target service right and an identifier of the client;

[0097] A first processing module 32, configured to obtain historical operation data of the client according to the identifier of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage; according to the rights request and the historical operation data, determine whether risk level detection is required; if risk level detection is not required, send the service content corresponding to the target service right to the client; if risk level detection is required, input the historical operation data into the pre-trained risk level detection model for processing, and output the user risk level;

[0098] A second processing module 33, configured to send the user risk level to the client, so that the client generates a verification prompt message according to the user risk level, where the verification prompt message is used to prompt the user to perform identity verification; if the identity verification result sent by the client is received, determine whether the identity verification passes according to the identity verification result; if the identity verification passes, send the service content corresponding to the target service right to the client according to the user risk level; if the identity verification fails, send a misappropriation risk prompt message to the client according to the user risk level.

[0099] In a possible implementation manner, the historical operation data includes historical entitlement requests and historical portrait data; when determining whether risk level detection is required based on the entitlement request and the historical operation data, the first processing module 32 is specifically configured to: obtain the cumulative number of entitlement requests according to the number of historical entitlement requests and the entitlement request; determine the entitlement request target threshold from the entitlement request thresholds according to the historical portrait data; if the cumulative number of entitlement requests is less than or equal to the entitlement request target threshold, risk level detection is not required; if the cumulative number of entitlement requests is greater than the entitlement request target threshold, risk level detection is required.

[0100] In a possible implementation manner, the historical operation data includes historical entitlement requests and historical portrait data; the historical entitlement requests include the number of user mobile phone number changes, the number of user logins from other locations, the number of user suspected abnormal applications, and the number of user password modifications; when inputting the historical operation data into a pre-trained risk level detection model for processing and outputting the user risk level, the first processing module 32 is specifically configured to: obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data and the reference portrait data; perform weighted calculation on the number of user mobile phone number changes according to the first weighted value to obtain the weighted number of user mobile phone number changes; perform weighted calculation on the number of user logins from other locations according to the second weighted value to obtain the weighted number of user logins from other locations; perform weighted calculation on the number of user suspected abnormal applications according to the third weighted value to obtain the weighted number of user suspected abnormal applications; perform weighted calculation on the number of user password modifications according to the fourth weighted value to obtain the weighted number of user password modifications; the pre-trained risk level detection model performs clustering analysis processing on the weighted number of user mobile phone number changes, the weighted number of user logins from other locations, the weighted number of user suspected abnormal applications, and the weighted number of user password modifications according to the reference detection data, and outputs the user risk level; wherein, the reference detection data includes the number of mobile phone number changes, the number of logins from other locations, the number of suspected abnormal applications, and the number of password modifications.

[0101] In a possible implementation, when the first processing module 32 obtains the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value based on the historical portrait data and the reference portrait data, it is specifically used to: classify the historical portrait data to obtain the historical portrait data of the first category data source and the historical portrait data of the second category data source; determine the relationship between the data volume of the historical portrait data of the first category data source and the data volume of the historical portrait data of the second category data source; if the data volume of the historical portrait data of the first category data source is greater than the data volume of the historical portrait data of the second category data source, then obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value based on the historical portrait data of the first category data source and the reference portrait data of the first category data source in the reference portrait data; if the data volume of the historical portrait data of the second category data source is greater than or equal to the data volume of the historical portrait data of the first category data source, then obtain the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value based on the historical portrait data of the second category data source and the reference portrait data.

[0102] In a possible implementation manner, the service rights fraud risk monitoring device 3 is further used to update the pre-trained risk level detection model according to the server status information of the server.

[0103] In a possible implementation, when the service rights fraud risk monitoring device 3 updates the pre-trained risk level detection model according to the server status information of the server, it is specifically used to: generate the total user access volume according to the server status information; if the total user access volume is greater than the preset access volume threshold, update the pre-trained risk level detection model.

[0104] In a possible implementation, while sending the service content corresponding to the target service rights to the client according to the user risk level, the second processing module 33 is further used to send risk level prompt information corresponding to the user risk level to the client.

[0105] The receiving module 31, the first processing module 32 and the second processing module 33 are connected in sequence. The service rights fraud risk monitoring device 3 provided in this embodiment can execute the following steps: Figure 2 The technical solutions of any of the method embodiments shown have similar implementation principles and technical effects, which will not be described in detail here.

[0106] Figure 4 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 4 As shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 also includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected via a bus 504.

[0107] In a specific implementation process, at least one processor 501 executes computer-executable instructions stored in a memory 502, enabling at least one processor 501 to execute the above-described method.

[0108] For the specific implementation process of the processor 501, reference can be made to the above method embodiments. Their implementation principles and technical effects are similar, and thus will not be elaborated herein.

[0109] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU for short), or may also be other general-purpose processors, digital signal processors (DSP for short), application specific integrated circuits (ASIC for short), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.

[0110] The memory may include a high-speed random access memory (RAM), and may also include non-volatile memory (NVM), such as at least one disk memory.

[0111] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.

[0112] This application also provides a computer program product, including a computer program which, when executed by a processor, implements the above-described method.

[0113] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0114] The above-readable storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium accessible by a general-purpose or special-purpose computer.

[0115] An exemplary readable storage medium is coupled to the processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium may also be a component of the processor. The processor and the readable storage medium may be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium may also exist as discrete components in a device.

[0116] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other may be indirect couplings or communication connections through some interfaces, devices, or units, and may be in electrical, mechanical, or other forms.

[0117] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0118] In addition, in each embodiment of the present invention, the functional units may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit.

[0119] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., all kinds of media that can store program codes.

[0120] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When this program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROMs, RAMs, magnetic disks, or optical discs, etc., all kinds of media that can store program codes.

[0121] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will easily think of other implementation manners of the present invention. The present invention is intended to cover any variations, uses, or adaptive changes of the present invention, and these variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A method for monitoring the risk of fraudulent use of service rights, characterized in that: Applied to the server, the method includes: Receive a rights request sent by a client; wherein the rights request includes a target service rights and an identifier of the client; According to the identifier of the client, historical operation data of the client is obtained; the historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage; Determining whether risk level detection is required based on the rights and interests request and the historical operation data; If risk level detection is not required, sending the service content corresponding to the target service rights to the client; If risk level detection is required, the historical operation data is input into a pre-trained risk level detection model for processing, and the user risk level is output; Sending the user risk level to the client, so that the client generates verification prompt information according to the user risk level, wherein the verification prompt information is used to prompt the user to perform identity verification; If the identity verification result sent by the client is received, judging whether the identity verification is passed according to the identity verification result; If the identity verification is passed, the service content corresponding to the target service rights is sent to the client according to the user risk level; If the identity verification fails, the fraud risk prompt information is sent to the client according to the user risk level.

2. The method according to claim 1, characterized in that The historical operation data includes historical rights requests and historical portrait data; The determining whether risk level detection is required according to the rights and interests request and the historical operation data includes: Obtaining a cumulative number of equity requests according to the number of historical equity requests and the equity request; Determining a target rights request threshold from a rights request threshold according to the historical profile data; If the number of the accumulated equity requests is less than or equal to the equity request target threshold, no risk level detection is required; If the number of the accumulated equity requests is greater than the equity request target threshold, a risk level detection is required.

3. The method according to claim 1, characterized in that The historical operation data includes historical rights and interests requests and historical portrait data; the historical rights and interests requests include the number of times the user's mobile phone number was changed, the number of times the user logged in from another location, the number of suspected abnormal applications by the user, and the number of times the user's password was modified; The inputting the historical operation data into a pre-trained risk level detection model for processing and outputting the user risk level comprises: Obtaining a first weighted value, a second weighted value, a third weighted value, and a fourth weighted value according to the historical portrait data and the reference portrait data; Performing weighted calculation on the number of times the user's mobile phone number is changed according to the first weighted value to obtain a weighted number of times the user's mobile phone number is changed; Obtaining a weighted number of remote logins according to the second weighted value for the number of remote logins of the user; According to the third weighted value, the number of suspected abnormal applications of the user is calculated to obtain a weighted number of suspected abnormal applications; Calculating the number of times the user password is modified according to the fourth weighted value to obtain a weighted number of times the user password is modified; The pre-trained risk level detection model performs cluster analysis on the weighted number of mobile phone number changes, the weighted number of off-site logins, the weighted number of suspected abnormal applications and the weighted number of user password modifications based on reference detection data, and outputs the user risk level; wherein the reference detection data includes the number of mobile phone number changes, the number of off-site logins, the number of suspected abnormal applications and the number of password modifications.

4. The method according to claim 3, characterized in that: The obtaining of the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data and the reference portrait data includes: Classify the historical portrait data to obtain historical portrait data of the first category data source and historical portrait data of the second category data source; Determine the relationship between the amount of the historical portrait data of the first category of data sources and the amount of the historical portrait data of the second category of data sources; If the data volume of the historical portrait data of the first category data source is greater than the data volume of the historical portrait data of the second category data source, then obtaining the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value according to the historical portrait data of the first category data source and the reference portrait data of the first category data source in the reference portrait data; If the data volume of the historical portrait data of the second category data source is greater than or equal to the data volume of the historical portrait data of the first category data source, then the first weighted value, the second weighted value, the third weighted value, and the fourth weighted value are obtained based on the historical portrait data of the second category data source and the reference portrait data of the second category data source in the reference portrait data.

5. The method according to claim 1, characterized in that The method further comprises: The pre-trained risk level detection model is updated according to the server status information of the server.

6. The method according to claim 5, characterized in that The updating of the pre-trained risk level detection model according to the server status information of the server includes: Generate a total amount of user visits based on the server status information; If the total user access volume is greater than a preset access volume threshold, the pre-trained risk level detection model is updated.

7. The method according to claim 1, characterized in that While sending the service content corresponding to the target service rights to the client according to the user risk level, the method further includes: Sending risk level prompt information corresponding to the user risk level to the client.

8. A device for monitoring the risk of fraudulent use of service rights, characterized in that: Applied to the server, the device comprises: A receiving module, configured to receive a rights request sent by a client; wherein the rights request includes the target service rights and the identifier of the client; The first processing module is used to obtain the historical operation data of the client according to the identifier of the client; the historical operation data is the historical operation record of the user recorded by the client and sent to the server for storage; according to the rights request and the historical operation data, it is judged whether risk level detection is required; if risk level detection is not required, the service content corresponding to the target service rights is sent to the client; if risk level detection is required, the historical operation data is input into the pre-trained risk level detection model for processing, and the user risk level is output; The second processing module is used to send the user risk level to the client, so that the client generates verification prompt information according to the user risk level, wherein the verification prompt information is used to prompt the user to perform identity verification; if the identity verification result sent by the client is received, it is judged whether the identity verification passes according to the identity verification result; if the identity verification passes, the service content corresponding to the target service rights is sent to the client according to the user risk level; if the identity verification fails, the fraud risk prompt information is sent to the client according to the user risk level.

9. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.