Safety risk control analysis method and device based on large model

Through the security risk control analysis method based on large models, the access behavior data of the target account is automatically processed, and analysis results and behavior labels are generated, which solves the accuracy and efficiency of traditional risk control methods, and achieves higher risk identification accuracy and system security.

CN120128366APending Publication Date: 2025-06-10QIZHI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510235429.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Traditional risk control methods rely on rules engines and basic statistical models, require manual in-depth intervention, are susceptible to subjective factors, have limited processing speed, and are difficult to accurately identify large-scale access behavioral data, reducing the accuracy of risk identification.

Method used

The security risk control analysis method based on the big model is adopted, and the access behavior data of the target account is obtained, characteristic information is extracted, and input it into the preset AI analysis model for processing, and analysis results and behavior labels are generated, and risk treatment plans are determined based on the labels to achieve automated risk identification and control.

Benefits of technology

It improves the accuracy and processing efficiency of risk identification, reduces the need for manual review, and can accurately control security for specific accounts, significantly improving the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128366A_ABST
    Figure CN120128366A_ABST
Patent Text Reader

Abstract

The invention discloses a security risk control analysis method and device based on a large model, and relates to the technical field of security risk control. The method comprises the following steps: acquiring first behavior data corresponding to a target account; feature extraction is carried out on the first behavior data to obtain target feature information, and the target feature information comprises single-day access data volume information, target IP address information, equipment fingerprint information and access time information; inputting the target feature information into a preset AI analysis model for processing to obtain a first analysis result; determining a first behavior label according to the first analysis result, and determining a risk processing scheme based on the first behavior label; and binding the first behavior tag with the target account, and performing security management and control on the target account corresponding to the user according to the risk processing scheme. By implementing the technical scheme provided by the invention, the problems existing in the traditional risk control means are effectively solved, and the accuracy and processing efficiency of risk identification are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security risk control technology, and particularly to a security risk control analysis method and device based on a large model. Background Art

[0002] With the rapid progress of Internet technology, the trends of network data crawling and fraud behavior have shown a significant growth, which poses a severe challenge to the information security of enterprises. Accurately identifying abnormal user behavior has become the key to preventing malicious attacks and data crawling and protecting enterprises from being infringed.

[0003] Traditional risk control means mainly rely on rule engines and basic statistical models. Their operation mechanism is to monitor the access behavior of each user, transfer the monitored data to the staff, and then manually review these data one by one. However, since the entire process requires in-depth manual intervention, the manual review process is susceptible to subjective factors and has limited processing speed, making it difficult to accurately identify large-scale access behavior data, thus reducing the accuracy of risk identification.

[0004] Therefore, there is an urgent need for a security risk control analysis method and device based on a large model that can solve the above technical problems. Summary of the Invention

[0005] This application provides a security risk control analysis method and device based on a large model. This method effectively solves the problems existing in traditional risk control means and improves the accuracy and processing efficiency of risk identification.

[0006] In a first aspect, this application provides a security risk control analysis method based on a large model, which is applied to a server. The method includes: obtaining first behavior data corresponding to a target account, where the target account is a personal account corresponding to a user logging in to a target website, and the first behavior data is access behavior data of the target account to the target website; extracting features from the first behavior data to obtain target feature information, where the target feature information includes daily access data volume information, target IP address information, device fingerprint information, and access time information; inputting the target feature information into a preset AI analysis model for processing to obtain a first analysis result; determining a first behavior label according to the first analysis result, and determining a risk handling plan based on the first behavior label; binding the first behavior label to the target account, and performing security control on the target account corresponding to the user according to the risk handling plan.

[0007] By adopting the above technical solution, the first-line behavior data of the target account is automatically obtained, greatly reducing the need for manual review. Key target feature information is extracted from the first-line behavior data, and then the target feature information is processed through a preset AI analysis model to obtain a first analysis result. The preset AI analysis model can accurately identify user behavior patterns. Based on the first analysis result, a first behavior label is determined, and different risk control measures can be flexibly taken according to the first behavior label. The first behavior label is bound to the target account, enabling precise security control for specific accounts, effectively solving the problems existing in traditional risk control means, and improving the accuracy of risk identification.

[0008] Optionally, before inputting the target feature information into the preset AI analysis model for processing to obtain a first analysis result, it is necessary to construct the preset AI analysis model, which specifically includes: obtaining a data sample set, where the data sample set is manually labeled data samples, and the data sample set includes normal access data and abnormal access data; using an initial model to train the sample data set to obtain a sample feature set, extracting each sub-feature information from the sample feature set, obtaining preset conditions corresponding to multiple sub-feature information, and summarizing the multiple preset conditions into a preset condition library; constructing the preset AI analysis model according to the preset condition library.

[0009] By adopting the above technical solution, training with a manually labeled data sample set ensures that the features learned by the model are real and reliable. The data sample set contains normal access data and abnormal access data. Through training, the model can identify new data samples that have not been seen but meet the preset conditions, extract each sub-feature information from the sample feature set, and obtain the preset conditions corresponding to these sub-features. Summarizing the multiple preset conditions into a preset condition library and constructing the preset AI analysis model based on the preset condition library can be customized according to different business requirements and security tests.

[0010] Optionally, inputting the target feature information into the preset AI analysis model for processing to obtain a first analysis result specifically includes: when the target feature information is the daily access data volume information, obtaining a preset access data volume from the preset condition library; judging whether the target access data volume is less than or equal to the preset access data volume, where the target access data volume is extracted from the daily access data volume information; when the target access data volume is greater than the preset access data volume, determining to classify the daily access data volume information into the first set, and outputting the first set as the first analysis result.

[0011] By adopting the above technical solution, comparing the target access data volume with the preset access data volume can accurately identify abnormal access behaviors beyond the normal range. Through an automated judgment process, it is possible to quickly process a large amount of daily access data volume information, improving data processing efficiency. When the target access data volume is greater than the preset access data volume, the daily access data volume information is summarized into the first set and output with the first analysis result.

[0012] Optionally, after determining whether the target access data volume is less than or equal to the preset access data volume, the method further includes: when the target access data volume is less than or equal to the preset access data volume, determining to summarize the daily access data volume information into the second set and obtaining the target feature information as the target IP address information; obtaining a preset IP address table from the preset condition library and judging whether the target IP address information exists in the preset IP address table; if the target IP address information exists in the preset IP address table, summarizing the target IP address information into the first set.

[0013] By adopting the above technical solution, first judging the daily access data volume and then judging the target IP address information realizes multi-level security protection. When the target access data volume is within the normal range but the target IP address information is determined to be abnormal, the target IP address is summarized into the first set and output in the form of the first analysis result, facilitating subsequent in-depth analysis of abnormal access behaviors and improving processing efficiency.

[0014] Optionally, determining a first behavior label according to the first analysis result and determining a risk handling plan based on the first behavior label specifically includes: obtaining the target number from the first set, where the target number is the total number corresponding to the target feature information in the first set; judging whether the target number is less than a preset first threshold; when the target number is less than the preset first threshold, determining that the target account corresponds to a normal access state, continuing to monitor the target account according to the normal access state, and outputting the normal access state as the first behavior label.

[0015] By adopting the above technical solution, counting the total number of target feature information in the first set, that is, the target number, can accurately evaluate the access state of the target account. When the target number is less than the preset first threshold, it can be judged that the target account is in a normal access state, which helps to reduce false alarms and missed reports. When the target account is determined to be in a normal access state, the resource allocation can be optimized according to this judgment result.

[0016] Optionally, determine the first behavior label based on the first analysis result, and determine the risk handling solution based on the first behavior label. Specifically, it includes: obtaining the target number from the first set, where the target number is the total number corresponding to the target feature information in the first set; determining whether the target number is less than the preset first threshold; when the target number is less than the preset first threshold, determine that the target account corresponds to a normal access status, continue to monitor the target account according to the normal access status, and output the normal access status as the first behavior label. The preset first threshold is less than the preset second threshold.

[0017] By adopting the above technical solution, when the target number is greater than or equal to the preset first threshold and less than the preset second threshold, it is determined that the target account corresponds to the first abnormal access status. For the first abnormal access status, a two-factor authentication solution is adopted to confirm the user's identity and reduce potential risks. For the second abnormal access status, a deny access solution is adopted to directly intercept the access request of the target account to prevent potential security threats. By refining the abnormal access status and formulating corresponding risk control measures, the security of the system can be significantly improved.

[0018] Optionally, after binding the first behavior label to the target account and performing security control on the target account corresponding to the user according to the risk handling solution, the method further includes: at intervals of a preset time, obtaining the second behavior data and the first behavior label corresponding to the target account; extracting the second behavior data, and inputting the extracted behavior information into a preset AI analysis model for processing to obtain a second analysis result; determining the second behavior label according to the second analysis result; determining whether the second behavior label is consistent with the first behavior label; when the second behavior label is not consistent with the first behavior label, replacing the first behavior label with the second behavior label, binding the second behavior label to the target account, and generating a user access link diagram according to the second behavior label.

[0019] By adopting the above technical solution, obtaining the behavior data of the target account again at intervals of a preset time can continuously monitor the behavior status of the target account, which helps to timely detect changes in the behavior status of the target account and ensure that the system can quickly respond to abnormal situations. Using the preset AI analysis model to process the second behavior data to obtain the second analysis result and determining the second behavior label according to this result. By comparing whether the second behavior label is consistent with the first behavior label, it can be verified whether the previous behavior judgment is accurate. When it is found that the second behavior label is not consistent with the first behavior label, updating the label in time and binding it to the target account helps to improve the accuracy of user behavior analysis.

[0020] In the second aspect of the present application, a security risk control analysis device based on a large model is provided. The device is a server, and the server includes an acquisition unit, a processing unit, and a determination unit; the acquisition unit acquires first behavior data corresponding to a target account. The target account is a personal account corresponding to a user logging in to a target website, and the first behavior data is access behavior data of the target account to the target website; the processing unit extracts features from the first behavior data to obtain target feature information, and the target feature information includes single-day access data volume information, target IP address information, device fingerprint information, and access time information; the target feature information is input into a preset AI analysis model for processing to obtain a first analysis result; the determination unit determines a first behavior label according to the first analysis result, and determines a risk handling plan based on the first behavior label; binds the first behavior label to the target account, and performs security control on the target account corresponding to the user according to the risk handling plan.

[0021] Optionally, the acquisition unit is used to acquire a data sample set, which is a manually labeled data sample set and includes normal access data and abnormal access data; the processing unit is used to train the sample data set using an initial model to obtain a sample feature set, extract each sub-feature information from the sample feature set, obtain preset conditions corresponding to multiple sub-feature information, and summarize the multiple preset conditions into a preset condition library; construct a preset AI analysis model according to the preset condition library.

[0022] Optionally, when the target feature information is single-day access data volume information, the acquisition unit is used to acquire a preset access data volume from the preset condition library; the processing unit is used to determine whether the target access data volume is less than or equal to the preset access data volume, and the target access data volume is extracted from the single-day access data volume information; when the target access data volume is greater than the preset access data volume, the determination unit is used to determine that the single-day access data volume information is summarized into the first set and output the first set as the first analysis result.

[0023] Optionally, when the target access data volume is less than or equal to the preset access data volume, the determination unit is used to determine that the single-day access data volume information is summarized into the second set and obtain that the target feature information is the target IP address information; the acquisition unit is used to acquire a preset IP address table from the preset condition library and determine whether the target IP address information exists in the preset IP address table; if the target IP address information exists in the preset IP address table, the target IP address information is summarized into the first set.

[0024] Optionally, the obtaining unit is configured to obtain a target number from the first set, where the target number is the total number corresponding to the target feature information in the first set; the processing unit is configured to determine whether the target number is less than a preset first threshold; the determining unit is configured to, when the target number is less than the preset first threshold, determine that the target account corresponds to a normal access state, continue to monitor the target account according to the normal access state, and output the normal access state as a first behavior label.

[0025] Optionally, when the target number is greater than or equal to the preset first threshold, the processing unit is configured to determine whether the target number is less than a preset second threshold; when the target number is less than the preset second threshold, determine that the target account corresponds to a first abnormal access state, determine an authentication scheme according to the first abnormal access state, where the authentication scheme is to perform secondary login verification on the user corresponding to the target account, output the first abnormal access state as a first behavior label, and output the authentication scheme as a risk handling scheme; when the target number is greater than or equal to the preset second threshold, determine that the target account corresponds to a second abnormal access state, determine a denial of access scheme according to the second abnormal access state, where the denial of access scheme is to intercept the access request of the target account, output the second abnormal access behavior as a first behavior label, and output the denial of access scheme as a risk handling scheme, and the preset first threshold is less than the preset second threshold.

[0026] Optionally, the obtaining unit is configured to obtain second behavior data and a first behavior label corresponding to the target account at preset time intervals; the processing unit is configured to extract the second behavior data and input the extracted behavior information into a preset AI analysis model for processing to obtain a second analysis result; determine a second behavior label according to the second analysis result; determine whether the second behavior label is consistent with the first behavior label; when the second behavior label is not consistent with the first behavior label, replace the first behavior label with the second behavior label, bind the second behavior label to the target account, and generate a user access link diagram according to the second behavior label.

[0027] In a third aspect of the present application, an electronic device is provided. The electronic device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory, so that an electronic device executes the method according to any one of the above in the present application.

[0028] In a fourth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions, and when the instructions are executed, the method according to any one of the above in the present application is executed.

[0029] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. Automatically obtain the first-line behavior data of the target account, greatly reducing the need for manual review. Extract key target feature information from the first-line behavior data, and then process the target feature information through a preset AI analysis model to obtain a first analysis result. The preset AI analysis model can accurately identify user behavior patterns. Based on the first analysis result, determine the first behavior label, and be able to flexibly adopt different risk control measures according to the first behavior label. Bind the first behavior label to the target account, enabling precise security control for specific accounts, effectively solving the problems existing in traditional risk control means and improving the accuracy of risk identification.

[0030] 2. Re-obtain the behavior data of the target account at preset time intervals, which can continuously monitor the behavior status of the target account, helping to promptly detect changes in the behavior status of the target account and ensuring that the system can quickly respond to abnormal situations. Use the preset AI analysis model to process the second behavior data to obtain a second analysis result, and determine the second behavior label based on this result. By comparing whether the second behavior label is consistent with the first behavior label, it is possible to verify whether the previous behavior judgment is accurate. When it is found that the second behavior label is inconsistent with the first behavior label, update the label in a timely manner and bind it to the target account, which helps to improve the accuracy of user behavior analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 is a schematic flowchart of a security risk control analysis method based on a large model provided by an embodiment of the present application; Figure 2 is a schematic structural diagram of a security risk control analysis device based on a large model provided by an embodiment of the present application; Figure 3 is a schematic structural diagram of an electronic device disclosed by an embodiment of the present application.

[0032] Description of the reference numerals: 201, acquisition unit; 202, processing unit; 203, confirmation unit; 300, electronic device; 301, processor; 302, memory; 303, user interface; 304, network interface; 305, communication bus. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] In order to enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.

[0034] In the description of the embodiments of the present application, words such as "for example" or "for instance" are used to give examples, illustrations or explanations. Any embodiment or design solution described as "for example" or "for instance" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "for example" or "for instance" is intended to present relevant concepts in a specific manner.

[0035] In the description of the embodiments of the present application, the term "a plurality of" means two or more. For example, a plurality of systems means two or more systems, and a plurality of screen terminals means two or more screen terminals. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0036] With the rapid progress of Internet technology, network data crawling and fraud behaviors have shown a significant growth trend, which poses a severe challenge to the information security of enterprises. Accurately identifying abnormal user behaviors has become the key to preventing malicious attacks and data crawling and protecting enterprises from infringement.

[0037] Traditional risk control means mainly rely on rule engines and basic statistical models. Their operation mechanism is to monitor the access behaviors of each user, transfer the monitored data to the staff, and then manually review these data one by one. However, since the entire process requires deep human intervention, and the manual review process is vulnerable to subjective factors and has limited processing speed, it is difficult to accurately identify large-scale access behavior data, thus reducing the accuracy of risk identification.

[0038] Therefore, how to solve the problems existing in traditional risk control means. A security risk control analysis method based on a large model provided by the embodiments of the present application is applied to a server. The server of the present application can be a platform that provides business security access detection services for Internet companies. Figure 1 is a schematic flowchart of a security risk control analysis method based on a large model provided by the embodiments of the present application. Refer to Figure 1 , and this method includes the following steps S101 - step S105.

[0039] S101: Obtain the first behavior data corresponding to the target account. The target account is the personal account corresponding to the user's login to the target website, and the first behavior data is the access behavior data of the target account to the target website.

[0040] In the above S101, when the user logs in to the target website, the server captures the user's login information, including the username, password (usually encrypted), and possibly other verification information. By verifying the user's login information, the server confirms the user's identity and identifies the corresponding target account. Once the user successfully logs in, the server begins to record the user's access behavior data. This data may include the links clicked by the user on the website, the pages viewed, the time spent, the transactions conducted, etc. The data collection method may involve API calls, web crawler technology, or the built-in logging system of the website. The collected access behavior data is stored in a database for subsequent analysis and processing.

[0041] S102: Extract features from the first behavior data to obtain target feature information, where the target feature information includes single-day access data volume information, target IP address information, device fingerprint information, and access time information.

[0042] In the above S102, obtain the access behavior records of the user on the target website through the target account, collect the access behavior records to obtain the first behavior data. Then extract features from the first behavior data, extract the key data metrics in the first behavior data. At this time, the key data metrics refer to the single-day access data volume, IP address, device fingerprint verification, and access time distribution, etc., and remove other data metrics to obtain the target feature information. The single-day access data volume information is to calculate the total data volume of the user accessing the website in a day, which may include the number of pages visited, the size of the files downloaded, etc. The target IP address information is to record the IP address used by the user when accessing the website. This helps to identify the user's geographical location and network environment. The device fingerprint information is a technology used to uniquely identify the user's device. The device fingerprint is generated by collecting the user's device information (such as operating system, browser type, screen resolution, etc.). The access time information is to record the specific time when the user accesses the website, including the start time and end time of the access. This helps to analyze the user's access habits and behavior patterns.

[0043] S103: Input the target feature information into a preset AI analysis model for processing to obtain a first analysis result.

[0044] In the above S103, before inputting the target feature information into the preset AI analysis model for processing to obtain the first analysis result, it is necessary to construct the preset AI analysis model, which specifically includes: obtaining a data sample set. The data sample set is artificially labeled data samples, and the data sample set includes normal access data and abnormal access data; using the initial model to train the sample data set to obtain a sample feature set, extracting each sub-feature information from the sample feature set, obtaining the preset conditions corresponding to multiple sub-feature information, and summarizing the multiple preset conditions into a preset condition library; constructing the preset AI analysis model according to the preset condition library. Specifically, the data sample set should contain normal access data and abnormal access data. These data can be collected through various methods, such as network logs, user behavior records, security detection systems, etc. The collected data is artificially labeled to distinguish normal access data and abnormal access data. The labeling process needs to be carried out by personnel with professional knowledge and experience to ensure the accuracy and consistency of the labeling. The labeling results should form clear data labels for subsequent processing and analysis. The labeled data is sorted into a unified format and stored in the data sample set. An appropriate initial model can be selected for training according to business requirements and data characteristics. The initial model can be a simple machine learning algorithm, such as logistic regression, decision tree, etc. Before training, the data is preprocessed, including data cleaning (removing outliers, missing values, etc.), data normalization (converting data with different dimensions to the same scale), etc. Preprocessing can improve the training efficiency and accuracy of the model. The preprocessed sample data set is used to train the initial model. During the training process, it is necessary to continuously adjust the model parameters to optimize the model performance. Methods such as cross-validation can be used to evaluate the generalization ability of the model. After training is completed, the sample feature set is extracted from the model. These feature sets reflect the key information in the data samples. The sample feature set is further analyzed and processed to extract each sub-feature information. The extracted each sub-feature information is analyzed to understand its specific meaning and importance. According to business requirements and security policies, determine the preset conditions corresponding to each sub-feature information. The preset conditions refer to the rules or thresholds used to judge whether user behavior is normal or abnormal. According to the analysis results of the sub-feature information, determine the preset conditions corresponding to each sub-feature information. These conditions can be numerical ranges, time relationships, address matches, etc. Summarize the multiple preset conditions into a preset condition library. The preset condition library is a set containing all preset conditions, which is used for the construction and judgment of the subsequent AI analysis model. According to the preset condition library, design an appropriate AI analysis model. The model can be an algorithm based on machine learning or deep learning, such as support vector machine, neural network, etc. Use the sample data set to train the AI analysis model. During the training process, it is necessary to continuously adjust the model parameters and structure to optimize the model performance. After the model training is completed, use an independent validation data set to test and verify the model. This can evaluate the accuracy and generalization ability of the model.Deploy the trained AI analysis model to the actual application scenario. In actual applications, the preset AI analysis model will make real-time judgments and analyses on user behaviors according to the preset condition library, and output corresponding results or suggestions. Provide training on the data sample set to obtain each sub-feature information, and obtain the preset conditions corresponding to each sub-feature, aggregate multiple preset conditions into a preset condition library, and then build a preset AI risk analysis model based on the preset condition library. When the target feature information is subsequently input into the preset AI risk model for processing, since the preset condition library is stored in the preset AI analysis model, the target feature information can be matched with the preset conditions in the preset condition library. After finding the preset conditions with the same target feature information, the target feature information is compared with the preset conditions to judge the user's behavior.

[0045] In addition, after building the preset AI analysis model, the target feature information is input into the preset AI analysis model for processing to obtain the first analysis result, which specifically includes: when the target feature information is the single-day access data volume information, obtain the preset access data volume from the preset condition library; determine whether the target access data volume is less than or equal to the preset access data volume, where the target access data volume is extracted from the single-day access data volume information; when the target access data volume is greater than the preset access data volume, determine to classify the single-day access data volume information into the first set, and output the first set as the first analysis result. Specifically, when the target feature information is the single-day access data volume information, input the single-day access data volume information into the preset AI analysis model for processing, that is, access the preset condition library and search for the preset condition corresponding to this feature information in the preset condition library. At this time, the focus is on the single-day access data volume information, and search for the preset condition corresponding to the single-day access data volume information in the preset condition library, that is, the preset access data volume. In the preset condition library, it is necessary to be able to accurately retrieve the preset condition related to the single-day access data volume information. Once the relevant preset condition is found, it needs to be extracted for use in the subsequent judgment step. The extracted preset access data volume will be used as a threshold to determine whether the target access data volume is abnormal. Before making the judgment, it is necessary to extract the target access data volume from the single-day access data volume information. Next, the extracted target access data volume needs to be compared with the preset access data volume. This comparison operation is a simple numerical comparison to determine whether the target access data volume exceeds the preset threshold. According to the comparison result, a judgment needs to be made: if the target access data volume is less than or equal to the preset access data volume, it may indicate that the user's access behavior is normal; if the target access data volume is greater than the preset access data volume, it may indicate that the user's access behavior is abnormal. If the judgment result is that the target access data volume is greater than the preset access data volume, it is necessary to classify the single-day access data volume information into a specific set, that is, the first set. The first set is used to store all the target feature information determined to be abnormal in the first behavior data of the target account. After subsequent judgments on all the target feature information in the first behavior data, the first set is output as the first analysis result. For example, when the single-day access data volume corresponding to the target account A is 200 and the preset data volume is set to 150, at this time the target access data volume is greater than the preset data volume, that is, it is defaulted that the data index of the single-day access data volume in the target account A is abnormal at this time, and the single-day access data volume information is classified into the first set for subsequent output as the first analysis result. The first analysis result includes the number of abnormal behavior information in the target account.

[0046] Further, when the target access data volume is less than or equal to the preset access data volume, it is determined to summarize the single-day access data volume information into the second set, and the target feature information is obtained as the target IP address information; the preset IP address table is obtained from the preset condition library, and it is judged whether the target IP address information exists in the preset IP address table; if the target IP address information exists in the preset IP address table, the target IP address information is summarized into the first set. Specifically, it is judged whether the target access data volume is less than or equal to the preset access data volume. This judgment is based on the target access data volume extracted from the single-day access data volume information before and the preset access data volume obtained from the preset condition library. If the judgment result is true (that is, the target access data volume is less than or equal to the preset access data volume), the single-day access data volume information needs to be summarized into a new set, that is, the second set. The second set is used to store all target feature information judged to be normal. After summarizing the single-day access data volume information into the second set, the next target feature information, that is, the target IP address information, needs to be obtained. Since the target feature information is the target IP address information at this time, the preset condition library needs to be accessed again to obtain the preset conditions related to the IP address. In the preset condition library, the preset IP address table needs to be accurately retrieved. The preset IP address table is composed of pre-stored high-risk IP addresses. The high-risk IP addresses are collected and obtained through a third-party software. Before obtaining them, the authorization of the third-party software has been obtained. After finding the preset IP address table, it needs to be extracted for use in the subsequent judgment steps. The extracted target IP address information needs to be matched with the IP addresses in the preset IP address table. This matching operation may involve comparing the IP addresses one by one to judge whether the target IP address exists in the preset IP address table. According to the matching result, a judgment needs to be made: if the target IP address information exists in the preset IP address table, it may indicate that the access behavior of this IP address needs to be specially concerned or processed. If the judgment result is true (that is, the target IP address information exists in the preset IP address table), the system needs to summarize the target IP address information into the first set mentioned above. The first set is used to store all information judged to be abnormal or requiring special attention, including the abnormal data that may have been summarized based on the single-day access data volume information before. When the target IP address information does not exist in the preset IP address table, it is determined to summarize the target IP address information into the second set.

[0047] Furthermore, according to the above processing procedures for the single-day access data volume information and the target IP address information, the device fingerprint information and the access time information are further judged in sequence. The judgment objects become the device fingerprint information and the access time information. Then, according to the judgment results, the device fingerprint information and the access time information are classified into their respective corresponding sets, which facilitates the subsequent output of the first set as the first analysis result. This helps to timely detect and handle potential security risks or abnormal behaviors, and improve the security and stability of the system.

[0048] S104: Determine the first behavior label according to the first analysis result, and determine the risk handling plan based on the first behavior label.

[0049] In the above S104, after obtaining the first analysis result, different behavior labels need to be defined according to the behavior recognition requirements. The behavior labels include normal behavior labels and abnormal behavior labels, etc. Determine the first behavior label according to the first analysis result, and determine the risk handling plan based on the first behavior label, which specifically includes: obtaining the number of targets from the first set, where the number of targets is the total number corresponding to the target feature information in the first set; judging whether the number of targets is less than the preset first threshold; when the number of targets is less than the preset first threshold, determine that the target account corresponds to the normal access state, continue to monitor the target account according to the normal access state, and output the normal access state as the first behavior label. The preset first threshold is less than the preset second threshold. Specifically, in obtaining the first analysis result, since the first analysis result is the first set mentioned above, and the first set is a set containing all the abnormal target feature information in the target account, count the number of abnormal indicators in the first set, that is, one target feature information represents one abnormal indicator, to obtain the number of targets, and the number of targets represents the total number corresponding to all the abnormal indicators in the target account. Compare the statistically obtained number of targets with the preset first threshold, and the preset first threshold is determined based on business logic, historical data or expert experience, and is used as the boundary for distinguishing normal access and abnormal access. If the number of targets is less than the threshold, it is determined that the target account is in the "normal access state". Develop a monitoring strategy for the normal access state. This may include continuing to collect access data of the target account, regularly updating the statistics of the target feature information, etc. According to the monitoring strategy, continuously monitor the target account. This may involve technical means such as real-time data processing and scheduled task execution. The first behavior label is used to identify the access state of the account. In this scenario, the first behavior label is the "normal access state". Output the first behavior label. For example, if the number of abnormal indicators in the first set is 1 and the preset first threshold is set to 2, at this time the number of targets is less than the preset first threshold, and it is defaulted that the access behavior of the target account is in the normal access state, and the normal access state is output as the first behavior label.

[0050] Further, when the number of targets is greater than or equal to a preset first threshold, determine whether the number of targets is less than a preset second threshold; when the number of targets is less than the preset second threshold, determine the first abnormal access status corresponding to the target account, and determine the identity verification scheme according to the first abnormal access status. The identity verification scheme is to perform secondary login verification on the user corresponding to the target account. Output the first abnormal access status as the first behavior label and output the identity verification scheme as the risk handling scheme; when the number of targets is greater than or equal to the preset second threshold, determine the second abnormal access status corresponding to the target account, and determine the access rejection scheme according to the second abnormal access status. The access rejection scheme is to intercept the access request of the target account. Output the second abnormal access behavior as the first behavior label and output the access rejection scheme as the risk handling scheme. Specifically, compare the number of targets with the preset first threshold. If the number of targets is greater than or equal to the preset first threshold, it indicates that there may be abnormal behavior and further judgment is required. After determining that the number of targets is greater than or equal to the preset first threshold, next compare the number of targets with the preset second threshold. This preset second threshold is usually greater than the preset first threshold and is used to further classify the severity of abnormal behavior. If the number of targets is less than the preset second threshold, it indicates that the severity of the abnormal behavior is relatively low and it can be classified as the first abnormal access status. An identity verification scheme will be determined according to the first abnormal access status, usually performing secondary login verification on the user corresponding to the target account to increase security. Output the first abnormal access status as the first behavior label and output the identity verification scheme as the risk handling scheme. For example, set the preset first threshold to 2, set the preset second threshold to 3, and the number of targets is 2. At this time, the number of targets is equal to the preset first threshold but less than the preset second threshold. Confirm that the user access behavior of the target account corresponds to the first abnormal state. When the user logs in to the target account, in addition to entering the account information and password information, the user will also trigger an additional verification scheme. The additional verification scheme includes a verification code, that is, by sending verification information to the mobile phone number pre-stored in the target account. After the user device corresponding to the mobile phone number receives the verification information, input the verification information received on the user device into the corresponding verification page to complete the risk handling measures for the target account.

[0051] Furthermore, if the number of targets is greater than or equal to a preset second threshold, it indicates a relatively high severity of abnormal behavior, and it can be classified as a second abnormal access state. In the second abnormal access state, a denial of access scheme will be determined according to this state, usually intercepting the access request of the target account to prevent potential security risks. Output the second abnormal access behavior as the first behavior label, and output the denial of access scheme as the risk handling scheme. The preset first threshold and the preset second threshold need to be set according to the actual situation, usually considering factors such as historical data, business requirements, and security policies. When implementing the denial of access scheme, it is necessary to ensure the accuracy and timeliness of the interception, and at the same time, relevant notifications and explanations need to be provided to users or administrators. For example, when the number of targets is 3 and the preset second threshold is set to 3, when the number of targets is equal to the preset second threshold, it is determined that the target account corresponds to the second abnormal access state, and it is defaulted that the access behavior of the target account has a relatively high security risk. It is necessary to intercept the access request of the target account and prohibit the target account from accessing the target website to prevent potential security risks.

[0052] S105: Bind the first behavior label to the target account and perform security control on the target account corresponding to the user according to the risk handling scheme.

[0053] In the above S105, after analyzing the first behavior data of the target account to obtain the first behavior label, the first behavior label is bound to the target account for subsequent security control and data analysis. According to the risk handling scheme, corresponding security control measures are implemented on the target account. This may include real-time monitoring of user behavior, triggering a security verification mechanism, restricting user operations, etc. Continuously monitor user behavior and the effect of security control, collect feedback in a timely manner, and adjust the strategy. It can effectively identify and manage the access behavior risks of target accounts, improving the security and user experience of the website.

[0054] In addition, subsequently monitor the access behaviors of each account on the target website, analyze the access behaviors, promptly discover user accounts with abnormal behaviors, and replace the behavior tags of the user accounts so that the behavior tags on each user account match the actual access behaviors. Specifically, it includes: at an interval of a preset time, obtain the second behavior data and the first behavior tag corresponding to the target account; extract the second behavior data, and input the extracted behavior information into a preset AI analysis model for processing to obtain a second analysis result; determine the second behavior tag according to the second analysis result; judge whether the second behavior tag is consistent with the first behavior tag; when the second behavior tag is inconsistent with the first behavior tag, replace the first behavior tag with the second behavior tag, bind the second behavior tag to the target account, and generate a user access link graph according to the second behavior tag. Specifically, a preset time interval needs to be set, and this time interval can be set according to factors such as business requirements and system performance. For example, it can be set to every hour, every day, or every week, etc. After the preset time interval arrives, it is necessary to obtain the behavior data of the target account during this time period, that is, the second behavior data. This data may include the login time, login location, accessed pages, operation behaviors, etc. of the target account. At the same time, it is necessary to obtain the first behavior tag determined for the target account before. This tag may represent the state corresponding to the historical access behavior of the target account. It is necessary to extract the second behavior data and screen out the key information related to the behavior of the target account. This information may include the login IP address, the accessed page URL, the operation type, etc. The extracted behavior information will be input into a preset AI analysis model. This model may be an algorithm based on machine learning or deep learning for intelligent analysis and processing of behavior data. The AI analysis model will process the input behavior information and output a second analysis result. The second analysis result is the number of abnormal indicators in the behavior feature information. Then, analyze and interpret the second analysis result to determine the current behavior tag of the target account. This tag may be a classification tag, such as "normal access", "abnormal access", etc. According to the analysis result, a second behavior tag will be determined for the target account. This tag will be used to represent the behavior characteristics or state of the target account during the current time period. It is necessary to compare the second behavior tag with the first behavior tag to judge whether they are consistent. This comparison process may involve the analysis of the semantics, classification, or descriptive content of the tags. According to the comparison result, it can be judged whether the behavior of the target account has changed. If the second behavior tag is inconsistent with the first behavior tag, it indicates that the behavior of the target account may have become abnormal or changed. When the second behavior tag is inconsistent with the first behavior tag, it is necessary to replace the first behavior tag with the second behavior tag. This replacement process will update the behavior tag of the target account to reflect its current behavior characteristics or state.For example, the label of the first line is the normal access status. At this time, the label of the second line is the first abnormal access status. At this time, the behavior label of the target account is replaced from the normal access status to the first abnormal access status, and it is assumed that the target account corresponds to the first abnormal access status at this time. At the same time, it is necessary to bind the updated second-line label to the target account. This binding process will ensure the correlation and consistency between the target account and its behavior label. Then, different risk handling measures are adopted for the target account according to different behavior labels. Finally, a user access link graph can be generated based on the second-line label. This graph will show the behavior path and correlation of the target account at different time periods, which helps to analyze the behavior pattern and potential risks of the target account.

[0055] The embodiment of the present application also provides a security risk control analysis device based on a large model. Figure 2 It is a schematic structural diagram of a security risk control analysis device based on a large model provided by the embodiment of the present application. Refer to Figure 2 The device is a server, and the server includes an acquisition unit 201, a processing unit 202, and a determination unit 203.

[0056] The acquisition unit 201 acquires the first behavior data corresponding to the target account. The target account is the personal account corresponding to the user's login to the target website, and the first behavior data is the access behavior data of the target account to the target website.

[0057] The processing unit 202 extracts features from the first behavior data to obtain target feature information. The target feature information includes the daily access data volume information, the target IP address information, the device fingerprint information, and the access time information; the target feature information is input into a preset AI analysis model for processing to obtain a first analysis result.

[0058] The determination unit 203 determines the first behavior label according to the first analysis result, and determines a risk handling plan based on the first behavior label; binds the first behavior label to the target account, and performs security control on the target account corresponding to the user according to the risk handling plan.

[0059] In a possible implementation manner, the acquisition unit 201 is used to acquire a data sample set. The data sample set is an artificially labeled data sample, and the data sample set includes normal access data and abnormal access data; the processing unit 202 is used to train the sample data set using an initial model to obtain a sample feature set, extract each sub-feature information from the sample feature set, obtain the preset conditions corresponding to the multiple sub-feature information, and summarize the multiple preset conditions into a preset condition library; construct a preset AI analysis model according to the preset condition library.

[0060] In a possible implementation, the obtaining unit 201 is configured to obtain a preset access data volume from a preset condition library when the target feature information is the daily access data volume information; the processing unit 202 is configured to determine whether the target access data volume is less than or equal to the preset access data volume, where the target access data volume is extracted from the daily access data volume information; the determining unit 203 is configured to, when the target access data volume is greater than the preset access data volume, determine to classify the daily access data volume information into the first set and output the first set as the first analysis result.

[0061] In a possible implementation, the determining unit 203 is configured to, when the target access data volume is less than or equal to the preset access data volume, determine to classify the daily access data volume information into the second set and obtain that the target feature information is the target IP address information; the obtaining unit 201 is configured to obtain a preset IP address table from the preset condition library and determine whether the target IP address information exists in the preset IP address table; if the target IP address information exists in the preset IP address table, classify the target IP address information into the first set.

[0062] In a possible implementation, the obtaining unit 201 is configured to obtain a target number from the first set, where the target number is the total number corresponding to the target feature information in the first set; the processing unit 202 is configured to determine whether the target number is less than a preset first threshold; the determining unit 203 is configured to, when the target number is less than the preset first threshold, determine that the target account corresponds to a normal access state, continue to monitor the target account according to the normal access state, and output the normal access state as the first behavior label.

[0063] In a possible implementation, the processing unit 202 is configured to, when the target number is greater than or equal to the preset first threshold, determine whether the target number is less than a preset second threshold; when the target number is less than the preset second threshold, determine that the target account corresponds to a first abnormal access state, determine an identity verification scheme according to the first abnormal access state, where the identity verification scheme is to perform secondary login verification on the user corresponding to the target account, output the first abnormal access state as the first behavior label, and output the identity verification scheme as the risk handling scheme; when the target number is greater than or equal to the preset second threshold, determine that the target account corresponds to a second abnormal access state, determine a rejection access scheme according to the second abnormal access state, where the rejection access scheme is to intercept the access request of the target account, output the second abnormal access behavior as the first behavior label, and output the rejection access scheme as the risk handling scheme, and the preset first threshold is less than the preset second threshold.

[0064] In a possible implementation, the obtaining unit 201 is configured to obtain the second behavior data and the first behavior label corresponding to the target account at preset time intervals; the processing unit 202 is configured to extract the second behavior data and input the extracted behavior information into a preset AI analysis model for processing to obtain a second analysis result; determine the second behavior label according to the second analysis result; determine whether the second behavior label is consistent with the first behavior label; when the second behavior label is inconsistent with the first behavior label, replace the first behavior label with the second behavior label, bind the second behavior label to the target account, and generate a user access link diagram according to the second behavior label.

[0065] It should be noted that: when the device provided in the above embodiment realizes its functions, only the division of the above function modules is used for illustration. In actual applications, the above functions can be allocated to different function modules according to needs, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be seen in the method embodiment, which will not be repeated here.

[0066] This application also discloses an electronic device. Refer to Figure 3 , Figure 3 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of this application. The electronic device 300 may include: at least one processor 301, at least one network interface 304, a user interface 303, a memory 302, and at least one communication bus 305.

[0067] Among them, the communication bus 305 is used to realize the connection and communication between these components.

[0068] Among them, the user interface 303 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 303 may further include a standard wired interface and a wireless interface.

[0069] Among them, the network interface 304 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0070] Among them, the processor 301 may include one or more processing cores. The processor 301 connects various parts within the entire server through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 302, and by calling the data stored in the memory 302, it performs various functions of the server and processes data. Optionally, the processor 301 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 301 may integrate one or a combination of several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, and application requests, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 301 and may be implemented separately by a single chip.

[0071] Among them, the memory 302 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 302 includes a non-transitory computer-readable storage medium. The memory 302 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 302 may include a program storage area and a data storage area. Among them, the program storage area can store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area can store the data involved in the above-mentioned various method embodiments. Optionally, the memory 302 may also be at least one storage device located far from the aforementioned processor 301.

[0072] As Figure 3 shown, the memory 302, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for security risk control analysis based on a large model.

[0073] In Figure 3In the electronic device 300 shown, the user interface 303 is mainly used to provide an interface for the user to input and obtain the data input by the user; and the processor 301 can be used to call the application program stored in the memory 302 for security risk control analysis based on the large model. When executed by one or more processors, the electronic device executes one or more of the methods described in the foregoing embodiments.

[0074] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0075] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0076] In the several embodiments provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some service interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0077] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0078] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0079] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned memory includes various media that can store program codes, such as USB flash drives, mobile hard disks, magnetic disks, or optical discs.

[0080] The above are only exemplary embodiments of the present disclosure, and the scope of the present disclosure cannot be limited thereby. That is, all equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure. After considering the specification and the disclosure of the practical truth, those skilled in the art will easily think of other implementation manners of the present disclosure. This application aims to cover any variations, uses, or adaptive changes of the present disclosure, and these variations, uses, or adaptive changes follow the general principles of the present disclosure and include the common general knowledge or conventional technical means in the technical field not recorded in the present disclosure.

Claims

1. A security risk control analysis method based on a large model, characterized in that: Applied in a server, the method comprises: Acquire first behavior data corresponding to a target account, where the target account is a personal account corresponding to a user logging into a target website, and the first behavior data is access behavior data of the target account to the target website; Extracting features from the first behavior data to obtain target feature information, wherein the target feature information includes daily access data volume information, target IP address information, device fingerprint information, and access time information; Inputting the target feature information into a preset AI analysis model for processing to obtain a first analysis result; Determine a first behavior tag according to the first analysis result, and determine a risk handling plan based on the first behavior tag; The first behavior tag is bound to the target account, and security management and control is performed on the target account corresponding to the user according to the risk handling plan.

2. The method according to claim 1, characterized in that Before the target feature information is input into the preset AI analysis model for processing to obtain the first analysis result, the preset AI analysis model needs to be constructed, which specifically includes: Acquire a data sample set, where the data sample set is a manually annotated data sample, and the data sample set includes normal access data and abnormal access data; The sample data set is trained using the initial model to obtain a sample feature set, each sub-feature information is extracted from the sample feature set, a plurality of preset conditions corresponding to the sub-feature information are obtained, and the plurality of preset conditions are aggregated into a preset condition library; The preset AI analysis model is constructed according to the preset condition library.

3. The method according to claim 2, characterized in that The inputting the target feature information into a preset AI analysis model for processing to obtain a first analysis result specifically includes: When the target characteristic information is the single-day access data volume information, obtaining a preset access data volume from the preset condition library; Determine whether a target access data volume is less than or equal to the preset access data volume, the target access data volume being extracted from the single-day access data volume information; When the target access data volume is greater than the preset access data volume, it is determined to summarize the single-day access data volume information into a first set, and the first set is output as the first analysis result.

4. The method according to claim 3, characterized in that After determining whether the target access data amount is less than or equal to the preset access data amount, the method further includes: When the target access data volume is less than or equal to the preset access data volume, determining to summarize the single-day access data volume information into a second set, and obtaining the target feature information as the target IP address information; Obtain a preset IP address table from the preset condition library, and determine whether the target IP address information exists in the preset IP address table; If the target IP address information exists in the preset IP address table, the target IP address information is summarized into the first set.

5. The method according to claim 3, characterized in that: The determining of a first behavior tag according to the first analysis result, and determining a risk handling solution based on the first behavior tag specifically includes: Obtaining the number of targets from the first set, where the number of targets is the total number of targets corresponding to the target feature information in the first set; Determine whether the target number is less than a preset first threshold; When the target number is less than the preset first threshold, it is determined that the target account corresponds to a normal access state, the target account is continuously monitored according to the normal access state, and the normal access state is output as the first behavior label.

6. The method according to claim 5, characterized in that After determining whether the target number is less than a preset first threshold, the method further includes: When the target number is greater than or equal to the preset first threshold, determining whether the target number is less than a preset second threshold; When the target number is less than the preset second threshold, determining that the target account corresponds to a first abnormal access state, determining an identity authentication scheme according to the first abnormal access state, the identity authentication scheme being a secondary login verification of the user corresponding to the target account, outputting the first abnormal access state as the first behavior label, and outputting the identity authentication scheme as the risk handling scheme; When the target number is greater than or equal to a preset second threshold, it is determined that the target account corresponds to a second abnormal access state, and a denial of access plan is determined based on the second abnormal access state. The denial of access plan is to intercept the access request of the target account, output the second abnormal access behavior as the first behavior label, and output the denial of access plan as the risk handling plan. The preset first threshold is less than the preset second threshold.

7. The method according to claim 1, characterized in that After binding the first behavior tag to the target account and performing security management and control on the target account corresponding to the user according to the risk handling solution, the method further includes: At preset time intervals, obtaining the second behavior data and the first behavior label corresponding to the target account; Extracting the second behavior data, and inputting the extracted behavior information into the preset AI analysis model for processing to obtain a second analysis result; Determine a second behavior label according to the second analysis result; Determining whether the second behavior label is consistent with the first behavior label; When the second behavior tag is inconsistent with the first behavior tag, the first behavior tag is replaced with the second behavior tag, the second behavior tag is bound to the target account, and a user access link graph is generated according to the second behavior tag.

8. A security risk control analysis device based on a large model, characterized in that: The device is a server, and the server comprises an acquisition unit (201), a processing unit (202) and a determination unit (203); The acquisition unit (201) acquires first behavior data corresponding to a target account, the target account being a personal account corresponding to a user logging into a target website, and the first behavior data being access behavior data of the target account to the target website; The processing unit (202) extracts features from the first behavior data to obtain target feature information, wherein the target feature information includes daily access data volume information, target IP address information, device fingerprint information, and access time information; and inputs the target feature information into a preset AI analysis model for processing to obtain a first analysis result; The determining unit (203) determines a first behavior tag according to the first analysis result, and determines a risk handling solution based on the first behavior tag; The first behavior tag is bound to the target account, and security management and control is performed on the target account corresponding to the user according to the risk handling plan.

9. An electronic device, characterized in that: The electronic device (300) comprises a processor (301), a memory (302), a user interface (303) and a network interface (304), wherein the memory (302) is used to store instructions, the user interface (303) and the network interface (304) are used to communicate with other devices, and the processor (301) is used to execute the instructions stored in the memory (302) so that the electronic device (300) executes the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed, the method according to any one of claims 1 to 7 is executed.

Citation Information

Cited By

  • Digital asset security assessment method based on block chain

    CN120781390A