Sentinel type account abnormal behavior risk assessment method and system

By real-time monitoring and analyzing account behavior characteristics, and building and optimizing risk assessment models, it solves the problem that traditional technologies are difficult to deal with changing attack methods and neglecting external risk information, real-time, dynamic assessment and high-accuracy identification of account risks.

CN120197047AInactive Publication Date: 2025-06-24SHANDONG XUNYUN INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510259307.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional risk assessment technology for abnormal behavior in accounts is difficult to cope with changing attack methods, and relies on internal account data, ignores external risk information, resulting in one-sided risk assessment results.

Method used

The sentinel-style risk assessment method for abnormal behavior of accounts is adopted. By obtaining and monitoring account behavior characteristics in real time, a baseline of account behavior patterns is constructed, the deviation between account behavior and baseline is monitored and calculated in real time, potential abnormal behavior patterns are identified, and the risk assessment model is optimized through adaptive adjustment of parameters.

Benefits of technology

Real-time and dynamic assessment of account risk status is realized, potential security threats are discovered in a timely manner, and the accuracy and sensitivity of risk identification are improved, ensuring the comprehensiveness and accuracy of risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197047A_ABST
    Figure CN120197047A_ABST
Patent Text Reader

Abstract

The invention provides a sentry type account abnormal behavior risk assessment method and system, and relates to the technical field of account security, and the method comprises the steps: 1, obtaining and monitoring various behavior characteristics of an account in real time, the behavior characteristics comprise login time, login device identifiers, login addresses, the number of login devices, the number of login addresses and types of installed application programs of the login devices; 2, performing real-time processing and analysis on the behavior characteristics acquired in real time by using a classification algorithm, and constructing an account behavior mode baseline; and step 3, monitoring and calculating the deviation degree between the account behavior and the account behavior mode base line in real time, and identifying a potential abnormal behavior mode by comparing the difference degree between the current behavior and the base line. According to the invention, the account behavior is monitored and analyzed in real time and the risk assessment model is dynamically adjusted, so that the abnormal transaction behavior is effectively identified and early warned, and the account security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of account security, and particularly to a sentinel - type account abnormal behavior risk assessment method and system. Background Art

[0002] Traditional account abnormal behavior risk assessment technologies rely on preset fixed rules for pattern matching, making it difficult to cope with constantly changing attack methods. As attackers' technologies continue to advance, they may adopt new attack methods or bypass existing detection rules, resulting in the failure of traditional technologies.

[0003] For example, some hackers may use advanced persistent threat (APT) attack means, through carefully constructed malware or phishing attacks, to bypass traditional rule - based detection mechanisms and successfully steal account information or perform other malicious operations.

[0004] Traditional technologies only rely on internal data such as the account's own transaction behavior and login habits for analysis, while ignoring the importance of external risk information. This may lead to one - sided risk assessment results and be unable to comprehensively reflect the true risk status of the account.

[0005] For example, an account may seemingly exhibit normal transaction behavior, but if the account is associated with known malicious IP addresses, domain names, or accounts, then it may actually face a relatively high risk. However, if the risk assessment technology only relies on account internal data, this potential risk may not be detected in a timely manner.

[0006] Traditional risk assessment models are often trained for specific attack scenarios or data distributions and lack sufficient generalization ability. When faced with new attack methods or changes in data distributions, the model may produce false positives (misjudging normal behavior as abnormal) or false negatives (failing to detect real abnormal behavior in a timely manner).

[0007] For example, a risk assessment model trained based on historical transaction data may not be able to accurately identify new types of fraud transaction patterns. Or, during peak trading periods such as holidays, due to temporary changes in transaction behavior patterns, the model may misjudge normal trading peaks as abnormal behavior. Summary of the Invention

[0008] The technical problem to be solved by the present invention is to provide a sentinel - type account abnormal behavior risk assessment method and system that can evaluate the risk status of an account in real - time and dynamically, and timely detect potential security threats.

[0009] To solve the above - mentioned technical problem, the technical solution of the present invention is as follows:

[0010] In a first aspect, a sentinel - type account abnormal behavior risk assessment method, the method includes:

[0011] Step 1: Obtain and monitor various behavioral characteristics of the account in real time. The behavioral characteristics include login time, login device identifier, login address, number of login devices, number of login addresses, and types of installed applications on the login devices.

[0012] Step 2: Use a classification algorithm to process and analyze the real-time obtained behavioral characteristics in real time, and construct a baseline of account behavior patterns.

[0013] Step 3: Monitor and calculate the deviation degree between the account behavior and the baseline of account behavior patterns in real time. By comparing the difference degree between the current behavior and the baseline, identify potential abnormal behavior patterns.

[0014] Step 4: According to the abnormal behavior patterns, historical transaction data, and account behavioral characteristics, construct a sentry-style monitoring framework, and use the sentry-style monitoring framework to monitor and analyze the transaction behavior of the account in real time. By comparing with the preset normal behavior patterns, identify abnormal transaction behaviors.

[0015] Step 5: According to the abnormal transaction behaviors, construct a risk assessment model, and through adaptive adjustment of parameters, optimize the risk assessment model in real time to obtain an optimized risk assessment model.

[0016] Step 6: Dynamically evaluate the risk level of the account according to the optimized risk assessment model to obtain an evaluation result. If the evaluation result ≥ the preset abnormal threshold, trigger an early warning mechanism.

[0017] Furthermore, using a classification algorithm to process and analyze the real-time obtained behavioral characteristics in real time, and construct a baseline of account behavior patterns, including:

[0018] Take historical data, including the behavioral characteristics of users and the corresponding account behavior patterns, as the training set.

[0019] Use the K-nearest neighbor classification algorithm to train the training set to obtain a trained K-nearest neighbor classification model.

[0020] Evaluate the trained K-nearest neighbor classification model by calculating the accuracy rate and recall rate indexes of the trained K-nearest neighbor classification model to obtain an evaluation result, including the classification accuracy, false alarm rate, and missed alarm rate performance indexes of the trained K-nearest neighbor classification model.

[0021] According to the evaluation result, use the trained K-nearest neighbor classification model to process and analyze the real-time user behavioral characteristics to obtain the classification result of the account behavior, that is, judge it as a normal mode or an abnormal mode.

[0022] For the account behavior in the normal mode, extract the corresponding behavioral characteristics and save the behavioral characteristics as the baseline of account behavior patterns.

[0023] Furthermore, the deviation degree between the account behavior and the baseline of the account behavior pattern is monitored and calculated in real time. By comparing the difference degree between the current behavior and the baseline, potential abnormal behavior patterns are identified, including:

[0024] Extract behavioral features from the real-time monitored account behavior data, and use the Manhattan distance algorithm to calculate the deviation degree between the real-time behavioral features and the baseline of the account behavior pattern;

[0025] Preset a deviation threshold, and compare the deviation degree between the real-time behavioral features and the baseline of the account behavior pattern with the deviation threshold; when the deviation degree between the real-time behavioral features and the baseline of the account behavior pattern > the deviation threshold, mark the corresponding behavior as a potential abnormal behavior pattern.

[0026] Furthermore, the calculation formula for the deviation degree between the real-time behavioral features and the baseline of the account behavior pattern:

[0027]

[0028] where D represents the deviation degree; α represents the abnormal amplification coefficient; n represents the total number of features; i represents the index of the feature dimension; λ represents the time decay coefficient; w i represents the weight of the i-th feature dimension; x i represents the i-th element of the real-time behavioral feature vector x; y i represents the i-th element of the account behavior pattern baseline vector y; z i represents the normalization coefficient of the i-th feature dimension; p represents the penalty term coefficient; β represents the behavior pattern stability coefficient; T represents the total number of time windows; t represents the index of the time window; α (t) represents the abnormal amplification coefficient of the t-th time window; λ (t) represents the time decay coefficient of the t-th time window; represents the weight of the i-th feature dimension of the t-th time window; represents the i-th element of the real-time behavioral feature vector x of the t-th time window; represents the i-th element of the account behavior pattern baseline vector y of the t-th time window; represents the normalization coefficient of the i-th feature dimension of the t-th time window; p (t) represents the penalty term coefficient of the t-th time window.

[0029] Furthermore, based on the abnormal behavior pattern, historical transaction data, and account behavior characteristics, a sentinel monitoring framework is constructed, and the sentinel monitoring framework is used to monitor and analyze the transaction behavior of the account in real time. By comparing with the preset normal behavior pattern, abnormal transaction behaviors are identified, including:

[0030] Encode and store abnormal behavior patterns to obtain an abnormal behavior pattern library, and collect historical transaction data, including transaction time, transaction amount, transaction object, and transaction location information. Extract the behavior characteristics of the account from the historical transaction data, including transaction frequency, transaction amount distribution, and transaction location distribution;

[0031] Design a monitoring framework and integrate the abnormal behavior pattern library, historical transaction data, and account behavior characteristics into the monitoring framework for setting comparison rules;

[0032] The monitoring framework receives the transaction data of the account in real time and compares the transaction data with the preset normal behavior pattern to obtain a comparison result, including the matching degree or difference degree between the transaction behavior and the normal behavior pattern;

[0033] Identify abnormal transaction behaviors based on the comparison result and comparison rules.

[0034] Furthermore, based on the abnormal transaction behaviors, construct a risk assessment model and optimize the risk assessment model in real time by adaptively adjusting parameters to obtain an optimized risk assessment model, including:

[0035] Set risk labels for each abnormal transaction behavior to obtain a dataset of abnormal transaction behaviors with risk labels;

[0036] Construct a risk assessment model based on the dataset of abnormal transaction behaviors with risk labels and initialize the risk assessment model, including setting the regularization coefficient and learning rate;

[0037] Divide the dataset of abnormal transaction behaviors with risk labels into a training set and a validation set;

[0038] Use the training set to train the risk assessment model, and during the training process, adjust the parameters of the risk assessment model through the grid search method to obtain a trained risk assessment model;

[0039] Use the validation set to continuously test the trained risk assessment model, monitor the performance changes of the trained risk assessment model, and obtain a performance analysis result;

[0040] Evaluate the performance of the trained risk assessment model according to the performance analysis result; if the performance of the trained risk assessment model deteriorates, adaptively adjust the parameters of the trained risk assessment model according to the data distribution change or the emergence of new types of abnormal behaviors, including updating the feature weights and adjusting the regularization coefficient, and finally obtain an optimized risk assessment model.

[0041] Furthermore, dynamically evaluate the risk level of the account according to the optimized risk assessment model to obtain an evaluation result; if the evaluation result ≥ the preset abnormal threshold, trigger an early warning mechanism, including:

[0042] Collect account transaction data in real time, including transaction amount, transaction time, and transaction object information;

[0043] Input the account transaction data into an optimized risk assessment model to dynamically assess the risk level of the account, calculate the risk degree of the account, and obtain a risk assessment result;

[0044] Compare the risk assessment result with a preset abnormal threshold. If the risk assessment result ≥ the preset abnormal threshold, trigger an early warning mechanism, including sending an alarm message and recording an abnormal log.

[0045] In a second aspect, a sentinel-based account abnormal behavior risk assessment system includes:

[0046] A real-time monitoring module for obtaining and monitoring various behavior characteristics of an account in real time. The behavior characteristics include login time, login device identifier, login address, number of login devices, number of login addresses, and types of installed applications on the login devices;

[0047] A baseline construction module for using a classification algorithm to perform real-time processing and analysis on the behavior characteristics obtained by the real-time monitoring module, and constructing and updating an account behavior pattern baseline;

[0048] A deviation calculation module for monitoring and calculating the deviation of the current account behavior from the account behavior pattern baseline in real time, and identifying potential abnormal behavior patterns by comparing the difference degree between the current behavior and the baseline;

[0049] A sentinel monitoring module for constructing a sentinel-based monitoring framework based on abnormal behavior patterns, historical transaction data, and account behavior characteristics, and using the sentinel-based monitoring framework to monitor and analyze the transaction behavior of the account in real time to identify abnormal transaction behaviors;

[0050] A risk assessment model construction module for constructing a risk assessment model based on abnormal transaction behaviors, and adjusting model parameters through an adaptive mechanism to optimize the risk assessment model in real time;

[0051] A risk assessment and early warning module for dynamically assessing the risk level of the account according to the optimized risk assessment model. If the assessment result ≥ the preset abnormal threshold, trigger an early warning mechanism to generate and send an early warning signal.

[0052] In a third aspect, a computing device includes:

[0053] One or more processors;

[0054] A storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the described method.

[0055] In a fourth aspect, a computer-readable storage medium stores a program which, when executed by a processor, implements the method described above.

[0056] The above solution of the present invention has at least the following beneficial effects:

[0057] By obtaining and monitoring various behavioral characteristics of an account in real time, including multi-dimensional information such as login time, login device identifier, login address, etc., it ensures comprehensive coverage of account behavior. Using classification algorithms to process and analyze the real-time obtained behavioral characteristics in real time, a baseline of account behavior patterns is constructed, providing an accurate and timely benchmark for subsequent abnormal behavior identification.

[0058] By monitoring and calculating the deviation degree between account behavior and the baseline of account behavior patterns in real time, potential abnormal behavior patterns can be accurately identified, effectively improving the accuracy and sensitivity of risk identification. The construction of the sentry-style monitoring framework, combined with historical transaction data and account behavioral characteristics, further enhances the ability to identify abnormal transaction behaviors, ensuring the comprehensiveness and accuracy of risk assessment.

[0059] Based on the abnormal transaction behaviors, a risk assessment model is constructed, and by adaptively adjusting parameters, the risk assessment model is optimized in real time, enabling the model to better fit the actual risk situation, improving the accuracy and reliability of risk assessment. This adaptive optimization mechanism ensures the continuous effectiveness of the risk assessment model, which can evolve continuously with changes in the network environment and the progress of attack methods.

[0060] According to the optimized risk assessment model, the risk level of the account is dynamically evaluated, ensuring the real-time and accuracy of risk assessment. A preset abnormal threshold is set, and when the evaluation result reaches or exceeds this threshold, the warning mechanism is triggered to timely remind relevant personnel to take corresponding measures, effectively preventing potential risk events. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 is a schematic flowchart of a sentry-style account abnormal behavior risk assessment method provided by an embodiment of the present invention.

[0062] Figure 2 is a schematic diagram of a sentry-style account abnormal behavior risk assessment system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0063] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0064] As Figure 1 shown, an embodiment of the present invention provides a sentinel - type account abnormal behavior risk assessment method, and the method includes the following steps:

[0065] Step 1: Obtain and monitor various behavioral characteristics of the account in real - time. The behavioral characteristics include login time, login device identifier, login address, number of login devices, number of login addresses, and types of installed applications on the login device.

[0066] Step 2: Use a classification algorithm to perform real - time processing and analysis on the behavior characteristics obtained in real - time, and construct a baseline of the account behavior pattern.

[0067] Step 3: Monitor and calculate the deviation degree between the account behavior and the baseline of the account behavior pattern in real - time. By comparing the difference degree between the current behavior and the baseline, identify potential abnormal behavior patterns.

[0068] Step 4: According to the abnormal behavior pattern, historical transaction data, and account behavior characteristics, construct a sentinel - type monitoring framework, and use the sentinel - type monitoring framework to monitor and analyze the transaction behavior of the account in real - time. By comparing with a preset normal behavior pattern, identify abnormal transaction behaviors.

[0069] Step 5: According to the abnormal transaction behavior, construct a risk assessment model, and optimize the risk assessment model in real - time by adaptively adjusting parameters to obtain an optimized risk assessment model.

[0070] Step 6: Dynamically evaluate the risk level of the account according to the optimized risk assessment model to obtain an evaluation result. If the evaluation result ≥ a preset abnormal threshold, trigger an early - warning mechanism.

[0071] In the embodiment of the present invention, by obtaining and monitoring multi - dimensional behavioral characteristics of the account in real - time and combining with a classification algorithm to construct a baseline of the account behavior pattern, it can more comprehensively reflect the normal behavior pattern of the account. Monitoring the deviation degree between the account behavior and the baseline in real - time can timely discover and identify potential abnormal behavior patterns, improving the accuracy and sensitivity of risk identification.

[0072] The construction of the sentinel - type monitoring framework makes the monitoring of the account transaction behavior more real - time and effective. By comparing with a preset normal behavior pattern, abnormal transaction behaviors can be quickly identified, providing strong support for timely taking risk prevention and control measures.

[0073] Construct a risk assessment model based on abnormal trading behaviors and perform real-time optimization by adaptively adjusting parameters, making the risk assessment model more in line with the actual situation and improving the accuracy and reliability of risk assessment. The optimized risk assessment model can more accurately reflect the risk status of the account and provide a more powerful basis for risk management and decision-making.

[0074] Dynamically evaluate the risk level of the account using the optimized risk assessment model, which can reflect the risk changes of the account in real time. By setting a preset abnormal threshold, when the assessment result reaches or exceeds the threshold, the early warning mechanism is triggered in a timely manner to remind relevant personnel to take corresponding measures and effectively prevent and control risks.

[0075] Accurate and real-time risk identification and assessment can reduce false alarms and missed reports, and reduce interference with the normal operations of users. Effective risk prevention and control measures can ensure the security of user accounts and enhance users' trust and satisfaction with the platform.

[0076] In a preferred embodiment of the present invention, in step 1 above, various behavioral characteristics of the account are obtained and monitored in real time. The behavioral characteristics include login time, login device identifier, login address, number of login devices, number of login addresses, and types of installed applications on the login device, and may include:

[0077] In an embodiment of the present invention, the time of each user login is recorded by the time stamp on the server side. The login device is identified using device fingerprint technology (such as User-Agent string, browser fingerprint, operating system information, etc.), the geographical location information of the user's login is obtained by IP address resolution, the number of times the same account logs in on different devices or the number of devices logged in simultaneously is counted, and the number of times the same account logs in from different addresses is counted. The collected behavioral characteristic data is transmitted from the client side to the server side using a secure transmission protocol (such as HTTPS).

[0078] In a preferred embodiment of the present invention, in step 2 above, the behavioral characteristics obtained in real time are processed and analyzed in real time using a classification algorithm to construct a baseline of account behavior patterns, which may include:

[0079] Step 221, using historical data, including the behavioral characteristics of the user and the corresponding account behavior patterns, as a training set;

[0080] Step 222, training the training set using the K-nearest neighbor classification algorithm to obtain a trained K-nearest neighbor classification model;

[0081] Step 223: Evaluate the trained K-nearest neighbor classification model by calculating the accuracy rate and recall rate metrics of the trained K-nearest neighbor classification model to obtain an evaluation result, including performance metrics such as the classification accuracy, false positive rate, and false negative rate of the trained K-nearest neighbor classification model;

[0082] Step 224: According to the evaluation result, use the trained K-nearest neighbor classification model to process and analyze the real-time user behavior characteristics to obtain the classification result of the account behavior, that is, determine whether it is in the normal mode or the abnormal mode;

[0083] Step 225: For the account behavior in the normal mode, extract the corresponding behavior characteristics and save the behavior characteristics as the account behavior pattern baseline.

[0084] In the embodiment of the present invention, historical user behavior characteristic data is extracted from the database, including login time, login device identifier, login address, etc., and at the same time, the corresponding account behavior pattern labels, such as "normal" or "abnormal", are extracted.

[0085] Step 222: Determine the implementation method of the K-nearest neighbor algorithm, such as using KNeighborsClassifier in the scikit-learn library of Python. Select an appropriate value of K (the number of neighbors), which is determined by grid search, and set the distance metric method, such as Manhattan distance. Use the training set data to train the K-nearest neighbor algorithm to obtain the trained K-nearest neighbor classification model.

[0086] Step 223: Determine the metrics of the evaluation model, such as accuracy rate, recall rate, false positive rate, false negative rate, etc. Use the test set data (if available) or cross-validation method to evaluate the trained K-nearest neighbor classification model, calculate and record the evaluation result, including performance metrics such as classification accuracy, false positive rate, false negative rate, etc. Analyze the performance of the model according to the evaluation result and judge whether it is necessary to adjust the parameters.

[0087] Step 224: Real-time obtain the user behavior characteristic data, input the behavior characteristics into the trained K-nearest neighbor classification model, and obtain the classification result of the account behavior.

[0088] Step 225: Extract the account behavior characteristics judged to be in the normal mode from the classification result, and save the extracted normal mode behavior characteristics to the database or file as the account behavior pattern baseline.

[0089] Suppose there is an e-commerce platform that needs to monitor users' login behaviors to identify abnormal logins:

[0090] First, extract the user's login behavior characteristics in the past month from the logging system, including login time, device identifier, IP address, etc. At the same time, extract the corresponding account behavior pattern tags, such as "normal login" or "abnormal login" (based on known security events or manual annotation).

[0091] Use the KNeighborsClassifier algorithm in the scikit-learn library, set the K value to 5, and the distance metric to Manhattan distance. Use the training set data to train the model and the test set data to evaluate the model. Calculate metrics such as accuracy, recall, false positive rate, and false negative rate. Assume that the evaluation results show that the model performance is good, the accuracy reaches 95%, and the false positive rate and false negative rate are both lower than 5%.

[0092] Whenever a user attempts to log in, obtain their login behavior characteristics in real time, input the characteristics into the trained K-nearest neighbor classification model, and obtain the classification result. If the classification result is "normal login", extract the user's behavior characteristics and save them to the database as the account behavior pattern baseline for this user.

[0093] By using historical data to train the K-nearest neighbor classification model, it is possible to more accurately identify normal and abnormal patterns of account behavior. Applying the model in real time to classify new behavior characteristics can timely detect potential abnormal behaviors. Obtaining and processing user behavior characteristics in real time ensures the real-time nature of monitoring. By comparing with the account behavior pattern baseline, it is possible to more effectively identify abnormal behaviors. By evaluating and optimizing the K-nearest neighbor classification model, the false positive rate and false negative rate can be reduced, the accuracy of risk identification can be improved, and the impact of false positives and false negatives on user experience and platform operation can be reduced. As user behavior changes and new security threats emerge, the K-nearest neighbor classification model can be dynamically adjusted and optimized. By continuously updating the training set and retraining the model, the continuous effectiveness of risk identification can be ensured.

[0094] In a preferred embodiment of the present invention, in step 3 above, the deviation degree between the account behavior and the account behavior pattern baseline is monitored and calculated in real time. By comparing the difference degree between the current behavior and the baseline, potential abnormal behavior patterns can be identified, which may include:

[0095] Step 311, extract behavior characteristics from the real-time monitored account behavior data, and use the Manhattan distance algorithm to calculate the deviation degree between the real-time behavior characteristics and the account behavior pattern baseline; the calculation formula for the deviation degree between the real-time behavior characteristics and the account behavior pattern baseline:

[0096]

[0097]

[0098] where D represents the deviation degree; α represents the anomaly amplification coefficient; n represents the total number of features; i represents the index of the feature dimension; λ represents the time decay coefficient; w i represents the weight of the i-th feature dimension; x i represents the i-th element of the real-time behavior feature vector x; y i represents the i-th element of the account behavior pattern baseline vector y; z i represents the normalization coefficient of the i-th feature dimension; p represents the penalty term coefficient; β represents the behavior pattern stability coefficient; T represents the total number of time windows; t represents the index of the time window; α (t) represents the anomaly amplification coefficient of the t-th time window; λ (t) represents the time decay coefficient of the t-th time window; represents the weight of the i-th feature dimension in the t-th time window; represents the i-th element of the real-time behavior feature vector x in the t-th time window; represents the i-th element of the account behavior pattern baseline vector y in the t-th time window; represents the normalization coefficient of the i-th feature dimension in the t-th time window; p (t) represents the penalty term coefficient of the t-th time window;

[0099] Step 312, preset a deviation threshold, and compare the deviation degree between the real-time behavior feature and the account behavior pattern baseline with the deviation threshold; when the deviation degree between the real-time behavior feature and the account behavior pattern baseline > the deviation threshold, mark the corresponding behavior as a potential abnormal behavior pattern.

[0100] In the embodiment of the present invention, features are extracted from the real-time monitored account behavior data to form a feature vector x, where x i represents the value of the i-th feature dimension. According to historical data or predefined patterns, a baseline feature vector y is formed, where y i represents the baseline value of the i-th feature dimension. For each feature dimension i, calculate the normalization coefficient z i , which is used to standardize the feature values.

[0101] The anomaly amplification coefficient α is set to 2.0, and the influence degree of abnormal behaviors is adjusted according to business requirements. Set the time decay coefficient λ to 0.9, consider the influence of historical behaviors on the current deviation degree, and give higher weights to the newer data. Set the weight w for each feature dimension i, Set according to the feature importance. For example, w1 = 1.5, w2 = 1.0, w3 = 0.5, which reflects the contribution of the feature to the deviation degree. Set the penalty term coefficient p to 0.1 to impose an additional penalty on the deviation degree to suppress excessive deviation. Considering the stability of the behavior pattern, set the corresponding coefficient β to 0.3. Considering the stability of the behavior pattern, give a certain weight to the historical deviation degree. Determine that the number of historical time windows T to be considered is 5, that is, consider the historical behavior data of the recent 5 time windows.

[0102] For each feature dimension i, calculate the absolute difference |x i -y i | between the real-time behavior feature and the baseline feature. Divide the absolute difference by the normalization coefficient z i , obtain the normalized difference, multiply it by the time decay coefficient λ = 0.9 and the feature dimension weight w i (such as w1 = 1.5), to obtain the deviation degree contribution of this feature dimension. Accumulate the deviation degree contributions of all feature dimensions to obtain the first part of the real-time deviation degree

[0103] Calculate the sum of squares of the absolute differences of all feature dimensions, multiply it by the penalty term coefficient p = 0.1 to obtain the penalty term. Add the first part of the real-time deviation degree to the penalty term, and then multiply by the anomaly amplification coefficient α = 2.0 to obtain the real-time deviation degree

[0104] For each time window t, repeat the calculation process of the real-time deviation degree, using the real-time behavior feature vector of the corresponding time window baseline feature vector normalization coefficient anomaly amplification coefficient α (t) , time decay coefficient λ (t) , feature dimension weight and penalty term coefficient p (t) . Accumulate the deviation degrees of each time window and divide by the total number of time windows T to obtain the average historical deviation degree.

[0105] Multiply the average historical deviation degree by β to obtain the contribution of the historical deviation degree. Add the contribution of the real-time deviation degree to the contribution of the historical deviation degree to obtain the total deviation degree D.

[0106] Step 312, Preset a deviation degree threshold TH according to business requirements and security policies. Compare the calculated deviation degree D with the preset threshold TH. If D > TH, mark the corresponding behavior as a potential abnormal behavior pattern and record these potential abnormal behavior patterns.

[0107] The deviation formula comprehensively considers the differences between real-time behavior characteristics and baseline characteristics, feature weights, time decay, penalty terms, and the stability of behavior patterns. Based on the Manhattan distance algorithm, it calculates the absolute differences in each feature dimension and takes into account weights and normalization coefficients. The time window allows for considering the impact of historical behavior on the current deviation, enabling a more comprehensive assessment of the abnormality of account behavior. Parameters such as the anomaly amplification coefficient, time decay coefficient, penalty term coefficient, and behavior pattern stability coefficient provide flexibility to adapt to different business scenarios and security requirements. By comprehensively considering various factors to calculate the deviation, potential abnormal patterns in account behavior can be identified more accurately. By setting reasonable deviation thresholds and combining other security measures, the false alarm and missed alarm rates can be reduced, and the effectiveness of monitoring can be improved. Real-time monitoring and identification of potential abnormal behavior patterns help to detect and respond to account security risks in a timely manner, protecting user assets and privacy security. By collecting and analyzing account behavior data, data support can be provided for security decision-making, helping to optimize security policies and processes.

[0108] In a preferred embodiment of the present invention, step 4, according to the abnormal behavior pattern, historical transaction data, and account behavior characteristics, constructs a sentinel-based monitoring framework, and uses the sentinel-based monitoring framework to monitor and analyze the transaction behavior of the account in real time. By comparing with the preset normal behavior pattern, identifying abnormal transaction behavior may include:

[0109] Step 411, encodes and stores the abnormal behavior pattern to obtain an abnormal behavior pattern library, and collects historical transaction data, including transaction time, transaction amount, transaction object, and transaction location information. Extracts the behavior characteristics of the account from the historical transaction data, including transaction frequency, transaction amount distribution, and transaction location distribution;

[0110] Step 412, designs a monitoring framework, and integrates the abnormal behavior pattern library, historical transaction data, and account behavior characteristics into the monitoring framework for setting comparison rules;

[0111] Step 413, the monitoring framework receives the transaction data of the account in real time, and compares the transaction data with the preset normal behavior pattern to obtain a comparison result, including the matching degree or difference degree between the transaction behavior and the normal behavior pattern;

[0112] Step 414, identifies abnormal transaction behavior according to the comparison result and the comparison rules.

[0113] In the embodiments of the present invention, cases of abnormal transaction behaviors are collected from channels such as historical security events, user reports, system logs, etc., and the cases are classified, such as fraudulent transactions, illegal fund transfers, abnormal logins, etc. Each abnormal case is analyzed to extract key features, such as an abnormally large transaction amount, an abnormal transaction time, a transaction location inconsistent with the frequently used location of the account, etc. Structured languages (such as JSON, XML) are used to describe the abnormal behaviors, including triggering conditions, behavior patterns, impact degrees, etc. A unique identifier is assigned to each abnormal behavior pattern, and the encoded abnormal behavior patterns are stored in a database or a file system to construct an abnormal behavior pattern library.

[0114] Historical transaction data of accounts is collected from the transaction platform database. The data includes transaction time, transaction amount, transaction objects (such as merchant ID, payee account number), transaction location (such as IP address, geographical location), etc. The transaction frequency of each account is calculated, such as the average daily transaction times, the average monthly transaction times. The transaction amount distribution is analyzed, such as the amount range, average value, median, standard deviation, etc. The transaction location distribution is statistically analyzed, such as the frequently used transaction location, the proportion of off-site transactions, the frequency of change of transaction location, etc.

[0115] Step 412: Design the overall structure of the sentinel monitoring framework, including a data collection layer, a data processing layer, an anomaly detection layer, an alarm layer, etc., and determine the interfaces and data flows between the layers.

[0116] Data collection layer: Implement the real-time data collection function to obtain the latest transaction data of accounts from the systems of transaction platforms or financial institutions.

[0117] Data processing layer: Perform preprocessing operations on the collected data, such as data cleaning, formatting, feature extraction, etc.

[0118] Anomaly detection layer: Compare the preprocessed transaction data with the patterns in the abnormal behavior pattern library, and calculate the matching degree or difference degree between the transaction behavior and the normal behavior pattern.

[0119] Alarm layer: According to the comparison result and the preset comparison rules, judge whether there is an abnormal transaction behavior. If an abnormal behavior is identified, trigger the alarm mechanism to notify relevant personnel for handling.

[0120] Integrate the abnormal behavior pattern library and the account behavior characteristics into the data processing layer and the anomaly detection layer of the monitoring framework to provide basic data and rule support for anomaly detection.

[0121] Step 413: The monitoring framework receives the transaction data of accounts in real time through the data collection layer, and the data processing layer preprocesses the received transaction data. The anomaly detection layer compares the preprocessed transaction data with the preset normal behavior pattern, calculates the matching degree or difference degree between the transaction behavior and the normal behavior pattern, and generates a comparison result.

[0122] Step 414: Determine whether the transaction behavior is abnormal according to the comparison result and the preset comparison rules. If the difference degree between the transaction behavior and the normal behavior pattern exceeds the preset threshold, it is determined as an abnormal transaction behavior.

[0123] If an abnormal transaction behavior is identified, the alarm layer triggers an alarm mechanism. The alarm methods include SMS notification, email notification, system log recording, etc. The alarm content should include detailed information about the abnormal transaction behavior, account information, transaction time, etc.

[0124] Suppose there is an e-commerce platform that needs to monitor users' transaction behaviors to identify fraudulent transactions:

[0125] The abnormal behavior pattern library contains various fraudulent transaction patterns, such as purchasing a large number of high-priced goods in a short period of time, using a stolen credit card for transactions, etc. Collect the transaction data of users on the platform, including transaction time, amount, product ID, user IP address, etc.

[0126] The average transaction amount of user A is 500 yuan, and mainly purchases daily necessities. The transaction locations of user A are mainly concentrated in the local area and several common cities. Receive the transaction data of user A in real time, and compare the received transaction data with the patterns in the abnormal behavior pattern library. If it is found that user A has purchased high-priced goods with a total price exceeding 100,000 yuan in a short period of time, and the transaction location does not match the user's usual location, it is determined as an abnormal transaction behavior, trigger the alarm mechanism, and notify the platform customer service and risk control department to conduct investigations and handling.

[0127] By real-time monitoring and analyzing the transaction behaviors of accounts, abnormal behaviors such as fraudulent transactions can be discovered and prevented in a timely manner, protecting the funds of users and the platform. The identification and prevention of abnormal behavior patterns help reduce economic losses caused by fraudulent behaviors and improve the profitability of the platform. By reducing the occurrence of abnormal behaviors such as fraudulent transactions, the trust and satisfaction of users with the platform are enhanced, and user stickiness is increased. According to the monitoring results and analysis data, continuously optimize the risk management strategy, improve the efficiency and accuracy of risk management, and reduce the platform operation risk. Meet the compliance requirements of regulatory agencies for the transaction behaviors of e-commerce platforms, provide support for the compliance operation of the platform, and enhance the market competitiveness of the platform.

[0128] In a preferred embodiment of the present invention, the above step 5, constructing a risk assessment model according to the abnormal transaction behavior and real-time optimizing the risk assessment model by adaptively adjusting parameters to obtain an optimized risk assessment model, may include:

[0129] Step 511: Set risk labels for each abnormal transaction behavior to obtain a dataset of abnormal transaction behaviors with risk labels;

[0130] Step 512: Construct a risk assessment model based on the abnormal transaction behavior dataset with risk labels, and initialize the risk assessment model, including setting the regularization coefficient and the learning rate;

[0131] Step 513: Divide the abnormal transaction behavior dataset with risk labels into a training set and a validation set;

[0132] Step 514: Use the training set to train the risk assessment model, and during the training process, adjust the parameters of the risk assessment model through the grid search method to obtain the trained risk assessment model;

[0133] Step 515: Continuously test the trained risk assessment model using the validation set, monitor the performance changes of the trained risk assessment model, and obtain the performance analysis results;

[0134] Step 516: Evaluate the performance of the trained risk assessment model according to the performance analysis results; if the performance of the trained risk assessment model deteriorates, adaptively adjust the parameters of the trained risk assessment model according to the change in data distribution or the emergence of new types of abnormal behaviors, including updating the feature weights and adjusting the regularization coefficient, and finally obtain the optimized risk assessment model.

[0135] In the embodiment of the present invention, a sentinel monitoring framework or other anomaly detection mechanisms are used to identify abnormal transaction behaviors in the transaction data. According to the nature, impact degree, and potential risks of the abnormal transaction behaviors, a series of risk labels are defined, such as "high fraud risk", "medium fraud risk", "low fraud risk", etc. Each identified abnormal transaction behavior is assigned a corresponding risk label to form an abnormal transaction behavior dataset with risk labels.

[0136] Step 512: Select a suitable machine learning model according to the characteristics of abnormal transaction behaviors and the requirements of risk assessment, such as logistic regression, and set the initial parameters of the model, including the regularization coefficient (used to control the complexity of the model and prevent overfitting), the learning rate (used to control the speed and convergence of model training), etc.

[0137] Step 513: Perform preprocessing operations such as cleaning, denoising, and feature selection on the abnormal transaction behavior dataset with risk labels. Divide the preprocessed dataset into a training set and a validation set, usually according to a certain ratio (such as 80% training set, 20% validation set).

[0138] Step 514: Train the risk assessment model using the training set. Adjust the model parameters through an iterative optimization algorithm (such as gradient descent) to enable the model to accurately predict the risk labels of abnormal transaction behaviors. During the training process, use the grid search method to traverse different parameter combinations to find the final parameter settings. The grid search will define a range of parameter values and try all possible combinations to find the final parameters.

[0139] Step 515: Test the trained risk assessment model using the validation set to evaluate the model's performance on unseen data. Monitor the performance changes of the model by calculating metrics such as accuracy, recall, and F1-score. At the same time, ROC curves, AUC values, etc. can be plotted to visually display the performance of the model.

[0140] Step 516: According to the performance analysis results, evaluate whether the performance of the trained risk assessment model meets the requirements. If the model performance deteriorates, the reasons need to be further analyzed. If the model performance deterioration is caused by changes in data distribution or the emergence of new types of abnormal behaviors, the model parameters need to be adaptively adjusted. This can include updating feature weights (to reflect the importance of new features), adjusting the regularization coefficient (to control the model complexity), etc. By continuously monitoring and evaluating the performance of the model, continuously adjusting and optimizing the model parameters, an optimized risk assessment model is finally obtained.

[0141] Suppose there is a banking system that needs to evaluate the fraud risk in credit card transactions:

[0142] Set risk labels for each abnormal credit card transaction (such as a large number of purchases in a short period, purchases in different locations, etc.), such as "high fraud risk", "medium fraud risk". Select the logistic regression model as the risk assessment model and initialize the regularization coefficient and learning rate. Divide the dataset of abnormal credit card transactions with risk labels into a training set and a validation set. Use the training set to train the logistic regression model and adjust parameters such as the regularization coefficient and learning rate through the grid search method. Use the validation set to test the trained logistic regression model and monitor metrics such as the accuracy and recall of the model. If it is found that the model performance deteriorates (such as a decrease in accuracy), analyze the reasons, which may be changes in data distribution or the emergence of new types of fraud behaviors. According to the analysis results, adaptively adjust the model parameters (such as updating feature weights, adjusting the regularization coefficient), and finally obtain an optimized risk assessment model.

[0143] By constructing and optimizing the risk assessment model, the risk level of abnormal transaction behaviors can be more accurately evaluated, providing a more reliable basis for decision-making. The model can adaptively adjust parameters to cope with changes in data distribution or the emergence of new types of abnormal behaviors, maintaining the stability and effectiveness of the model. The optimized risk assessment model can more accurately identify fraud behaviors, reduce false positive and false negative rates, and improve anti-fraud efficiency. By reducing the situations of misjudgment and mis-blocking of user accounts, the trust and satisfaction of users with the banking system are enhanced. The results of the risk assessment model can provide strong support for the risk management of banks, the formulation of anti-fraud strategies, etc., helping banks better cope with fraud risks.

[0144] In a preferred embodiment of the present invention, in step 6 above, according to the optimized risk assessment model, the risk level of the account is dynamically evaluated to obtain an evaluation result; if the evaluation result ≥ the preset abnormal threshold, the warning mechanism is triggered, which may include:

[0145] Step 611, collect account transaction data in real time, including transaction amount, transaction time, and transaction object information;

[0146] Step 612, input the account transaction data into the optimized risk assessment model, dynamically evaluate the risk level of the account, and calculate the risk degree of the account to obtain a risk assessment result; the calculation formula for the risk degree of the account is:

[0147] R represents the risk degree of the account; a represents the weight of the transaction amount; log e (X1 + 1) represents the logarithmic transformation of the transaction amount X1; e represents the base of the natural logarithm; X1 represents the transaction amount; b1 represents the weight of the transaction time; r(X2) represents the feature of the transaction time; c represents the weight vector of the transaction object information; H(X3) represents the feature of the transaction object information; λ represents the coefficient of the regularization term; k represents the number of categories of the transaction object information; I represents the index variable; c I represents the I-th element of the weight vector of the transaction object information; h represents the weight of the interaction term of the transaction amount and the transaction time; d represents the bias term;

[0148] Step 613, compare the risk assessment result with the preset abnormal threshold. If the risk assessment result ≥ the preset abnormal threshold, the warning mechanism is triggered, including sending an alarm message and recording an abnormal log.

[0149] In the embodiment of the present invention, transaction data is obtained in real time from the bank account system, and the data types include transaction amount (X1), transaction time (X2), and transaction object information (X3).

[0150] Step 612: Input the transaction data (X1, X2, X3) into the optimized risk assessment model, and calculate the risk level R of the account using the formula. a is the weight of the transaction amount, reflecting the impact of the transaction amount on the risk. log e (X1 + 1) is the logarithmic transformation of the transaction amount to handle the non - linear relationship of the amount data. b1 is the weight of the transaction time, reflecting the impact of the transaction time on the risk. r(X2) is the feature of the transaction time, which can be the encoding of the time period, the reciprocal of the time interval, etc. c is the weight vector of the transaction object information, reflecting the impact of different transaction objects on the risk. H(X3) is the feature of the transaction object information, which can be the category encoding of the transaction object, the historical transaction frequency, etc. λ is the coefficient of the regularization term, used to control the complexity of the model and prevent overfitting. k is the number of categories of the transaction object information. c I is the i - th element of the weight vector of the transaction object information. h is the weight of the interaction term between the transaction amount and the transaction time, reflecting the combined impact of the transaction amount and the transaction time on the risk. d is the bias term, used to adjust the overall risk level of the model. Calculate the risk level (R) of the account according to the formula, that is, the risk assessment result.

[0151] Step 613: Compare the risk assessment result (R) with the preset anomaly threshold. If R ≥ the preset anomaly threshold, trigger the warning mechanism, and the warning mechanism includes sending an alarm message to relevant personnel.

[0152] By collecting account transaction data in real - time and inputting it into the optimized risk assessment model, the risk level of the account can be accurately and timely evaluated. When the account risk level reaches or exceeds the preset anomaly threshold, the warning mechanism can be immediately triggered to notify relevant personnel to take countermeasures to reduce potential losses. The model considers multiple dimensions such as transaction amount, transaction time, and transaction object information, and can more comprehensively evaluate the risk level of the account, providing a more refined risk management strategy for the bank. By timely identifying and responding to abnormal risks, the situations of misjudgment and mis - blocking of user accounts are reduced, and the trust and satisfaction of users with the bank system are improved. By adjusting the regularization term and the bias term, the complexity of the model can be controlled, overfitting can be prevented, and the continuous optimization and performance improvement of the model can be promoted.

[0153] As Figure 2 shown, an embodiment of the present invention also provides a sentry - type account abnormal behavior risk assessment system, including:

[0154] A real - time monitoring module, used to obtain and monitor various behavior characteristics of the account in real - time, and the behavior characteristics include login time, login device identifier, login address, number of login devices, number of login addresses, and types of installed applications on the login devices;

[0155] A baseline construction module, which is used to perform real-time processing and analysis on the behavior characteristics obtained by the real-time monitoring module by using a classification algorithm, and construct and update the baseline of the account behavior pattern;

[0156] A deviation degree calculation module, which is used to monitor and calculate the deviation degree between the current behavior of the account and the baseline of the account behavior pattern in real time, and identify potential abnormal behavior patterns by comparing the difference degree between the current behavior and the baseline;

[0157] A sentry monitoring module, which is used to construct a sentry-style monitoring framework based on the abnormal behavior pattern, historical transaction data and account behavior characteristics, and use the sentry-style monitoring framework to monitor and analyze the transaction behavior of the account in real time to identify abnormal transaction behaviors;

[0158] A risk assessment model construction module, which is used to construct a risk assessment model based on the abnormal transaction behavior, and adjust the model parameters through an adaptive mechanism to optimize the risk assessment model in real time;

[0159] A risk assessment and early warning module, which is used to dynamically assess the risk level of the account according to the optimized risk assessment model. If the assessment result ≥ the preset abnormal threshold, an early warning mechanism is triggered to generate and send an early warning signal.

[0160] It should be noted that this system corresponds to the above method. All implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0161] An embodiment of the present invention also provides a computing device, including: a processor and a memory storing a computer program. When the computer program is run by the processor, it executes the method as described above. All implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0162] An embodiment of the present invention also provides a computer-readable storage medium storing instructions. When the instructions are run on a computer, the computer is made to execute the method as described above. All implementation manners in the above method embodiments are applicable to this embodiment and can also achieve the same technical effects.

[0163] The above is the preferred implementation manner of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle described in the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A sentinel account abnormal behavior risk assessment method, characterized in that: The method comprises: Step 1, obtaining and monitoring various behavior characteristics of the account in real time, wherein the behavior characteristics include login time, login device identification, login address, number of login devices, number of login addresses, and type of installed applications of the login device; Step 2: Use classification algorithms to process and analyze the behavioral features acquired in real time to build a baseline for account behavior patterns; Step 3: Monitor and calculate the deviation between account behavior and the account behavior pattern baseline in real time, and identify potential abnormal behavior patterns by comparing the difference between current behavior and the baseline; Step 4: Build a sentinel monitoring framework based on abnormal behavior patterns, historical transaction data, and account behavior characteristics, and use the sentinel monitoring framework to monitor and analyze account transaction behaviors in real time, and identify abnormal transaction behaviors by comparing them with preset normal behavior patterns; Step 5: construct a risk assessment model based on abnormal transaction behavior, and optimize the risk assessment model in real time by adaptively adjusting parameters to obtain an optimized risk assessment model; Step 6: According to the optimized risk assessment model, the risk level of the account is dynamically assessed to obtain an assessment result; if the assessment result is ≥ the preset abnormal threshold, the early warning mechanism is triggered.

2. The sentinel account abnormal behavior risk assessment method according to claim 1, characterized in that: Use classification algorithms to process and analyze behavioral features acquired in real time and build a baseline of account behavior patterns, including: Use historical data, including user behavior characteristics and corresponding account behavior patterns, as training sets; Use the K nearest neighbor classification algorithm to train the training set and obtain a trained K nearest neighbor classification model; The trained K nearest neighbor classification model is evaluated by calculating the accuracy and recall rate indicators of the trained K nearest neighbor classification model to obtain evaluation results, including the classification accuracy, false alarm rate, and false negative rate performance indicators of the trained K nearest neighbor classification model; According to the evaluation results, the trained K-nearest neighbor classification model is used to process and analyze the real-time user behavior characteristics to obtain the classification results of the account behavior, that is, to determine whether it is a normal mode or an abnormal mode; For normal account behaviors, corresponding behavioral features are extracted and saved as the account behavior pattern baseline.

3. The sentinel account abnormal behavior risk assessment method according to claim 2, characterized in that: Monitor and calculate the deviation between account behavior and the account behavior pattern baseline in real time. By comparing the difference between current behavior and baseline, identify potential abnormal behavior patterns, including: Extract behavioral features from real-time monitored account behavior data, and use the Manhattan distance algorithm to calculate the deviation between the real-time behavioral features and the account behavior pattern baseline; A deviation threshold is preset, and the deviation between the real-time behavior feature and the account behavior pattern baseline is compared with the deviation threshold; when the deviation between the real-time behavior feature and the account behavior pattern baseline is greater than the deviation threshold, the corresponding behavior is marked as a potential abnormal behavior pattern.

4. The sentinel account abnormal behavior risk assessment method according to claim 3 is characterized in that: The calculation formula for the deviation between the real-time behavior characteristics and the account behavior pattern baseline is: Where D represents the deviation; α represents the abnormal amplification factor; n represents the total number of features; i represents the index of the feature dimension; λ represents the time attenuation coefficient; w i represents the weight of the i-th feature dimension; x i represents the i-th element of the real-time behavior feature vector x; y i represents the i-th element of the account behavior pattern baseline vector y; z i represents the normalization coefficient of the i-th feature dimension; p represents the penalty term coefficient; β represents the behavior pattern stability coefficient; T represents the total number of time windows; t represents the index of the time window; α (t) represents the abnormal amplification factor of the t-th time window; λ (t) represents the time decay coefficient of the t-th time window; Represents the weight of the i-th feature dimension in the t-th time window; represents the i-th element of the real-time behavior feature vector x of the t-th time window; y ( i t) The i-th element of the account behavior pattern baseline vector y in the t-th time window; represents the normalization coefficient of the i-th feature dimension in the t-th time window; p (t) Represents the penalty coefficient of the t-th time window.

5. The sentinel account abnormal behavior risk assessment method according to claim 4, characterized in that: Based on abnormal behavior patterns, historical transaction data and account behavior characteristics, a sentinel monitoring framework is constructed. The sentinel monitoring framework is used to monitor and analyze account transaction behaviors in real time. By comparing with the preset normal behavior patterns, abnormal transaction behaviors are identified, including: Abnormal behavior patterns are encoded and stored to obtain an abnormal behavior pattern library, and historical transaction data, including transaction time, transaction amount, transaction object, and transaction location information, are collected to extract account behavior characteristics from historical transaction data, including transaction frequency, transaction amount distribution, and transaction location distribution; Design a monitoring framework and integrate the abnormal behavior pattern library, historical transaction data, and account behavior characteristics into the monitoring framework to set comparison rules; The monitoring framework receives the transaction data of the account in real time, and compares the transaction data with the preset normal behavior pattern to obtain the comparison results, including the matching degree or difference degree between the transaction behavior and the normal behavior pattern; Identify abnormal trading behavior based on comparison results and comparison rules.

6. The sentinel account abnormal behavior risk assessment method according to claim 5, characterized in that: Based on abnormal transaction behaviors, a risk assessment model is constructed, and the risk assessment model is optimized in real time by adaptively adjusting parameters to obtain an optimized risk assessment model, including: Set a risk label for each abnormal transaction behavior to obtain a dataset of abnormal transaction behaviors with risk labels; Based on the abnormal transaction behavior dataset with risk labels, a risk assessment model is constructed and initialized, including setting the regularization coefficient and learning rate; Divide the abnormal trading behavior dataset with risk labels into a training set and a validation set; The risk assessment model is trained using the training set, and during the training process, the risk assessment model parameters are adjusted by a grid search method to obtain a trained risk assessment model; Use the validation set to continuously test the trained risk assessment model, monitor the performance changes of the trained risk assessment model, and obtain performance analysis results; According to the performance analysis results, the performance of the risk assessment model after training is evaluated; if the performance of the risk assessment model after training decreases, the parameters of the risk assessment model after training are adaptively adjusted according to the changes in data distribution or the emergence of new types of abnormal behaviors, including updating feature weights and adjusting regularization coefficients, to finally obtain the optimized risk assessment model.

7. The sentinel account abnormal behavior risk assessment method according to claim 6, characterized in that: According to the optimized risk assessment model, the risk level of the account is dynamically assessed to obtain the assessment result; if the assessment result is ≥ the preset abnormal threshold, the early warning mechanism is triggered, including: Collect account transaction data in real time, including transaction amount, transaction time, and transaction object information; Input the account transaction data into the optimized risk assessment model, dynamically assess the account risk level, calculate the account risk level, and obtain the risk assessment result; The risk assessment result is compared with the preset abnormality threshold. If the risk assessment result is ≥ the preset abnormality threshold, the early warning mechanism is triggered, including sending an alarm message and recording an abnormality log.

8. A sentinel account abnormal behavior risk assessment system, the system implementing the method according to any one of claims 1 to 7, characterized in that: include: A real-time monitoring module is used to obtain and monitor various behavior characteristics of the account in real time, including login time, login device identification, login address, number of login devices, number of login addresses, and type of installed applications on the login device; The baseline construction module is used to process and analyze the behavior features obtained by the real-time monitoring module in real time using the classification algorithm, and to construct and update the account behavior pattern baseline; Deviation calculation module, used to monitor and calculate the deviation between the current account behavior and the account behavior pattern baseline in real time, and identify potential abnormal behavior patterns by comparing the difference between the current behavior and the baseline; Sentinel monitoring module, which is used to build a sentinel monitoring framework based on abnormal behavior patterns, historical transaction data and account behavior characteristics, and use the sentinel monitoring framework to monitor and analyze account transaction behaviors in real time and identify abnormal transaction behaviors; The risk assessment model building module is used to build a risk assessment model based on abnormal transaction behaviors, adjust model parameters through an adaptive mechanism, and optimize the risk assessment model in real time; The risk assessment and early warning module is used to dynamically assess the risk level of the account based on the optimized risk assessment model. If the assessment result is ≥ the preset abnormal threshold, the early warning mechanism is triggered to generate and send an early warning signal.

9. A computing device, characterized in that include: one or more processors; A storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method as claimed in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program, which, when executed by a processor, implements the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Bank anti-call fraud data model construction method based on multi-feature fusion

    CN117993919A

  • Risk control early warning method and system based on bank flow analysis

    CN119273441A

Cited By

  • Account risk prediction method and system based on machine learning

    CN120450708A

  • A machine learning based account risk prediction method and system

    CN120450708B

  • Intelligent bidding method and system based on behavior pattern recognition

    CN120725770A

  • Multi-dimensional evaluation system for abnormal login risk of game account

    CN120860606A

  • Multi-dimensional evaluation system for game account abnormal login risk

    CN120860606B