Malicious behavior interception system for shopping mall seckilling activity
By designing a malicious behavior interception system in the mall flash sale event, using the combination technology of front-end and back-end modules to monitor and intercept users' malicious behavior, the problem of malicious purchases in the flash sale event is solved, and the user experience and merchant interests are protected.
Patent Information
- Application Number
- CN202510337821.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-01
AI Technical Summary
During the mall flash sale event, malicious users seized inventory through program scripts, resulting in real users being unable to shop normally, affecting the user experience and merchant economic benefits.
Design a malicious behavior interception system for shopping mall flash sale activities, including front-end interception module and back-end interception module. The front-end module monitors and intercepts users' malicious behavior by triggering components such as restriction units, man-machine verification units, and product verification units. The back-end module conducts in-depth analysis and restrictions through components such as behavior analysis units, risk control verification units.
Effectively intercept and restrict malicious behaviors of illegal users, prevent rush to buy goods, maintain the fair playing environment for users, protect the interests of merchants, ensure the authenticity and effectiveness of order data, and improve the reliability and effectiveness of mall flash sale activities.
Smart Images

Figure CN120235680A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of Internet service processing, and particularly relates to a malicious behavior interception system for mall flash sale activities. Background Art
[0002] With the rapid development of the Internet, online marketing and shopping have become an important part of modern people's lives. As a new e-commerce marketing model, the flash sale activity in the mall is a rush purchase activity that sells goods at ultra-low prices through time-limited and quantity-limited purchases. The essence of this activity is to create an atmosphere of "the lowest price" to generate concurrent purchases at the same time, thereby increasing the average order value and the number of customer visits. And during the activity, if a user places an order but does not pay, the inventory quota of the goods will also be reserved for the user for a period of time, and the order will only be automatically cancelled and the inventory released after the expiration.
[0003] However, if there is a behavior of maliciously seizing inventory using program scripts during the high concurrency period of the activity, it means that real users cannot shop normally, and the occupation of commodity inventory also leads to the problem that the goods cannot be sold normally during the activity. This not only affects the user's consumption experience but also seriously affects the economic benefits of the merchant. Summary of the Invention
[0004] In view of the above-mentioned disadvantages of the prior art, the purpose of the present invention is to provide a method for intercepting malicious behaviors during mall flash sale activities, which can intercept illegal user requests, prevent illegal users from snapping up goods through cheating means, maintain a fair competition environment for users to purchase goods, protect the interests of merchants, and ensure the authenticity and validity of order data.
[0005] To achieve the above object and other related objects, the present invention provides a malicious behavior interception system for mall flash sale activities, including: a front-end interception module for monitoring and intercepting malicious behaviors of users after they enter the mall flash sale activity page; a back-end interception module for deeply analyzing users who enter the mall flash sale activity page and restricting their operation behaviors; wherein, the front-end interception module includes: a trigger restriction unit for restricting the trigger times and frequencies of users' snapping up of any commodity, and prohibiting users from snapping up the commodity when the trigger times and / or frequencies of snapping up any commodity exceed a preset first threshold; a human-machine verification unit for performing human-machine verification on users who have successfully snapped up any commodity, and prohibiting users from placing an order for the commodity they have successfully snapped up after the verification fails; a commodity verification unit for verifying the correlation between the user and the commodity they place an order for, as well as the order quantity of the commodity, and canceling the user's order process for the commodity when the correlation between the user and the commodity they place an order for is low and the order quantity of the commodity exceeds a preset second threshold.
[0006] According to a specific embodiment of the present invention, the backend interception module includes: a behavior analysis unit, configured to call the behavior data of a user within a preset time range from a large database and perform analysis to identify users with abnormal behaviors; a risk control verification unit, configured to call the identity information of a user from the large database and perform verification to identify high-risk users; and a first restriction unit, configured to impose operation restrictions on users with abnormal behaviors and high-risk users.
[0007] According to a specific embodiment of the present invention, the behavior analysis unit is further configured to analyze the abnormal behaviors of a user from multiple dimensions to obtain abnormal values for each dimension, and comprehensively evaluate the malicious degree of the user's behavior based on the abnormal values of each dimension; the first restriction unit is further configured to restrict the operation behaviors of the user corresponding to the malicious degree.
[0008] According to a specific embodiment of the present invention, the behavior analysis unit analyzes the abnormal behaviors of a user from multiple dimensions to obtain abnormal values for each dimension, including: the behavior analysis unit compares the behavior differences between the user and other users to identify whether the user's behavior is abnormal, and calculates the corresponding abnormal value according to a preset first weight parameter and the accumulated number of abnormal behaviors.
[0009] According to a specific embodiment of the present invention, the behavior analysis unit analyzes the abnormal behaviors of a user from multiple dimensions to obtain abnormal values for each dimension, including: the behavior analysis unit verifies whether there is an association between the abnormal behaviors of the user, determines the associated abnormal behaviors as malicious behaviors, and calculates the corresponding abnormal value according to a preset second weight parameter and the accumulated number of malicious behaviors.
[0010] According to a specific embodiment of the present invention, the behavior analysis unit is further configured to analyze the behavior indicators of a user from multiple dimensions to comprehensively evaluate the malicious degree of the user's behavior; the first restriction unit is further configured to restrict the operation behaviors of the user corresponding to the malicious degree.
[0011] According to a specific embodiment of the present invention, the behavior indicators include: the access indicators and operation indicators of the user; wherein, the access indicators include: the access frequency of the page and the residence time of the page; the operation indicators include: the trigger frequency of commodity rush purchase, the operation time interval of the page, and the operation order of the page.
[0012] According to a specific embodiment of the present invention, the backend interception module further includes: an order verification unit, configured to verify whether the order indicators of a user meet the standards to screen out orders that do not meet the standards; a second restriction unit, configured to cancel the orders of the user that do not meet the standards; wherein, the order indicators include: the detailed information of the order, the submission quantity of the order, the submission time distribution of the order, and the matching situation between the order and the inventory.
[0013] According to a specific embodiment of the present invention, the backend interception module further includes: a network verification unit, configured to verify whether the user's network metrics meet the standards to identify high-risk users; wherein, the network metrics include: the change frequency of the IP address, the time of entering the mall flash sale activity, the login source of the mall flash sale activity, and the current login status.
[0014] According to a specific embodiment of the present invention, the frontend interception module further includes: an order placement restriction unit, configured to identify whether the user carries an authorization identifier when placing an order, and prohibit the user without the authorization identifier from placing an order; wherein, the risk control verification unit is further configured to assign an authorization identifier to the user who passes the verification.
[0015] The present invention provides a malicious behavior interception system, which intercepts and restricts illegal users or the malicious behaviors of users through direct interception and in-depth analysis, prevents illegal users from snapping up goods by cheating means, maintains a fair competition environment and consumption rights and interests of normal users, thereby enhancing the experience of normal users, protecting the interests of enterprises, and greatly improving the reliability and effectiveness of the mall flash sale activity. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic structural diagram of a specific embodiment of a malicious behavior interception system for a mall flash sale activity provided by the present invention; Figure 2 It is a schematic structural diagram of a specific embodiment of the frontend interception module in a malicious behavior interception system for a mall flash sale activity provided by the present invention; Figure 3 It is a schematic structural diagram of a specific embodiment of the backend interception module in a malicious behavior interception system for a mall flash sale activity provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] To facilitate the understanding of the present application, the present application will be described more comprehensively below with reference to the relevant drawings. Embodiments of the present application are given in the drawings. However, the present application can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present application more thorough and comprehensive.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used in the specification of the present application herein are only for the purpose of describing specific embodiments and are not intended to limit the present application.
[0019] The following describes the embodiments of the present invention through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0020] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.
[0021] Please refer to Figure 1 、 2 A malicious behavior interception system for a mall flash sale activity as shown in Figures 1, 2, and 3 includes: a front-end interception module 10, which can be used to monitor the malicious behavior of users after they enter the mall flash sale activity page and make interceptions; and a back-end interception module 20, which can be used to deeply analyze the users who enter the mall flash sale activity page, such as behavior analysis, identity analysis, etc., to restrict the operation behaviors of abnormal users. It can be understood that the front-end interception module 10 can reflect the malicious behavior of users, so as to achieve real-time interception of malicious behavior during the mall flash sale activity. For example, when the click frequency of a user's purchase is too high and has exceeded the normal human range, the user can be blocked from purchasing accordingly, and so on. The back-end interception module 20 can specifically analyze the potential risks of users through user portraits, so as to predict whether users will have malicious behavior and restrict the operations of abnormal users to prevent the occurrence of malicious behavior in advance. For example, after analyzing a certain user as a high-risk user, their order placement can be prohibited or the order placement quantity can be restricted, so as to maintain the consumption experience of normal users.
[0022] Specifically, the front-end interception module 10 includes: a trigger restriction unit 11, a human-machine verification unit 12, an order placement restriction unit 13, and a product verification unit 14. Among them, the trigger restriction unit 11 can be used to restrict the trigger times and frequencies of a user's purchase of any product, so as to prohibit the user from purchasing the product when the trigger times and / or frequencies of the purchase of any product exceed a preset first threshold. For example, at the moment when a flash sale activity of a certain product is launched, a large number of users will frequently click the purchase button in order to successfully place an order for the product. During this purchase stage, the trigger restriction unit 11 monitors and intercepts, so as to intercept users whose click times or click frequencies of purchases within a short period of time far exceed the normal values and prohibit them from purchasing. In a specific embodiment, the trigger restriction unit 11 can be implemented by using js script technology.
[0023] The human-machine verification unit 12 can be used to perform human-machine verification on users who have successfully purchased any product, so as to prohibit the user from placing an order for the successfully purchased product after the verification fails. For example, for a product, after a user successfully purchases it, the user will correspondingly place an order for the product. Before placing the order, in order to further prevent the rapid operation of automated scripts or robot programs, it can be intercepted by means of human-machine verification. For example, a graphic verification code can be popped up and the user is required to enter the correct content, or other verification methods, etc. Therefore, during this stage between purchase and order placement, the human-machine verification unit 12 monitors and intercepts.
[0024] Furthermore, the order placement restriction unit 13 can strengthen the control of users, so that users must carry an authorization identifier to place an order normally. The authorization identifier is assigned by the back-end interception module 20 after in-depth analysis of the user, and is assigned to low-risk users or normal users. For example, the back-end interception module 20 will identify whether the user has logged in to an account, and after verifying that the logged-in account of the user is legal, an authorization identifier is assigned. The authorization identifier can include encrypted information of the user (user ID, valid time of the logged-in account, channel for entering the mall flash sale activity, etc.). When the order placement restriction unit 13 identifies that the user is carrying the authorization identifier, even if the user passes the verification of the human-machine verification unit 12, the user will still be prohibited from placing an order.
[0025] In addition, the merchandise verification unit 14 can be used to verify the relevance between the user and the merchandise he / she places an order for, as well as the order quantity of the merchandise, so as to cancel the user's order process for the merchandise when the relevance between the user and the merchandise he / she orders is low and the order quantity of the merchandise exceeds a preset threshold. It can be understood that by verifying the relevance between the user and the merchandise he / she snaps up, such as whether the user has browsed the merchandise before, or whether there are similar or relevant merchandise in the shopping cart, etc., to judge the rationality of the user snapping up the merchandise. When the verification shows low relevance between the user and the merchandise and the order quantity for the merchandise is abnormal, that is, the order quantity is large, there may be a phenomenon where illegal users snap up a large number of merchandise through cheating means. Correspondingly, at this stage after the order is placed, the merchandise verification unit 14 is used for monitoring and intercepting. Even if the order may have been created, the order can be cancelled, or the order can be cancelled before the user makes a payment, that is, all order processes for the merchandise are cancelled, so as to release the merchandise snapped up by the user in a certain quantity back to the merchandise inventory.
[0026] Thus, it can be seen that the front-end interception module 10 can monitor the malicious behaviors of users throughout the whole process, so as to promptly stop them after detecting malicious behaviors at any stage, thereby safeguarding the consumption rights and experience feelings of normal users. Specifically, in practical applications, js buried point codes can be embedded in the front-end page to detect various operation behaviors of users, such as entering the mall to browse merchandise, clicking on the merchandise details, clicking on the purchase button, etc., and transmitted to the large database for storage through the remote api method to cooperate with the normal operation of the front-end interception module 10. There are no excessive restrictions on this. Those skilled in the art, without departing from the spirit of the present invention, the modifications and retouches made to the embodiments of the present invention still fall within the scope of the invention application patent of the present invention.
[0027] Secondly, the back-end interception module 20 includes: a behavior analysis unit 21, a risk control verification unit 22, a network verification unit 23, a first restriction unit 24, an order verification unit 25, and a second restriction unit 26. Among them, the behavior analysis unit 21 can be used to deeply analyze the behavior data of the user by calling it from the large database. For example, it can call the behavior data of the user before and during the flash sale activity in the mall to create a user portrait, so as to identify the potential risks of the user and restrict the operation behavior of the user.
[0028] Specifically, on the one hand, the behavior analysis unit 21 can analyze the abnormal behavior of the user from multiple dimensions, evaluate the malicious degree of the user behavior by synthesizing the analysis results of each dimension, and the first restriction unit 24 can restrict the operation behavior of the user according to the malicious degree. In a specific embodiment, first, the behavior analysis unit 21 can compare the behavior differences between the user and other users to identify whether the user's behavior is abnormal. For example, a normal user usually has a relatively natural operation process, such as first browsing the product details and then considering whether to participate in the flash sale, while a cheating user may skip some normal steps, use scripts and tools to place an order from a non-product page, and frequently try to submit orders, etc., so as to accumulate the number of abnormal behaviors, and calculate the abnormal value of the user behavior in this dimension according to the first weight parameter and the number of abnormal behaviors preset for this dimension. Secondly, the behavior analysis unit 21 can also check whether there is a correlation between the abnormal behaviors of the user to string together the relevant abnormal behaviors. For example, a certain user's IP address is frequently changed, but the logged-in account remains unchanged, and a large number of abnormal flash sale operations are performed in a short period of time, which may mean there is cheating behavior; or there is an unreasonable correlation between the user's order submission behavior and the inventory change situation, such as the order submission quantity far exceeds the normal purchasable inventory limit and there is no reasonable explanation. Therefore, by correlating multiple abnormal behaviors of the user, it can be determined that the user has generated malicious behavior, and the number of malicious behaviors is accumulated. Correspondingly, the abnormal value of the user behavior in this dimension can be calculated according to the second weight parameter and the number of malicious behaviors preset for this dimension. In addition, the behavior data of the user can also be analyzed based on other dimensions. For example, statistics on the user's behavior performance at different time periods, such as whether there are abnormally frequent page visits or pre-operation behaviors before the start of the flash sale activity, whether the order submission time is too concentrated and does not conform to the operation speed of normal users during the activity, and whether there are abnormal related operations after the activity ends, etc., and then string together the behaviors of multiple time periods for comprehensive analysis to confirm the abnormal value of the user behavior in this dimension. There are no excessive restrictions on this. Those skilled in the art, without departing from the spirit of the present invention, the modifications and refinements made to the embodiments of the present invention still fall within the scope of the invention application patent of the present invention.
[0029] Based on the above, by dividing the corresponding weight parameters for different dimensions, and then synthesizing all dimensions to analyze the malicious degree of the user behavior, and making different operation behavior restrictions for users with different malicious degrees. For example, for users with a higher malicious degree, their purchase of goods can be restricted accordingly, or they can be prohibited from entering the mall flash sale activity page, while for users with a lower malicious degree, a warning can be initially given, or the quantity of goods they can purchase can be restricted. There are no excessive restrictions on this. Those skilled in the art, without departing from the spirit of the present invention, the modifications and refinements made to the embodiments of the present invention still fall within the scope of the invention application patent of the present invention.
[0030] On the other hand, the behavior analysis unit 21 can also analyze the user's behavior indicators from multiple dimensions, and then evaluate the malicious degree of the user's behavior by combining the analysis results of each dimension. Similarly, the first restriction unit 24 can restrict the user's operation behavior according to the malicious degree. Specifically, the behavior analysis unit 21 can analyze the user's access indicators and operation indicators, wherein the access indicators include: the page access frequency (the number of times the user visits and refreshes the flash sale related pages during the activity, and pays attention to abnormal data) and the page residence time (the user stays on the product details page, and pays attention to the user who clicks to place an order without staying), etc., and the operation indicators include: the trigger frequency of the product rush purchase (the number and frequency of the user clicking the flash sale button), the page operation time interval (the user's operation time between different pages), and the page operation sequence (the user's page operation sequence before placing an order), etc. Correspondingly, the abnormal value of the user's behavior can be analyzed according to the access indicator, and the abnormal value of the user's behavior can be analyzed according to the operation indicator, and then the abnormal value of multiple dimensions can be comprehensively evaluated to evaluate the malicious degree of the user's behavior. Similarly, different weight parameters can be set for different dimensions, and then the corresponding abnormal value can be calculated according to the indicator parameter and the weight parameter.
[0031] Therefore, based on the user's behavior indicators, the user's maliciousness can be analyzed, and then his operation behavior can be restricted. This will not be elaborated in detail.
[0032] Furthermore, the network verification unit 23 can verify whether the user's network indicators meet the standards to identify high-risk users. Specifically, the network indicators include: the frequency of IP address changes, the time of entering the mall flash sale activity, the login source of the mall flash sale activity, and the current login status, etc., and the first restriction unit 24 can also restrict the operation behavior of high-risk users.
[0033] At the same time, the risk control verification unit 22 can call the user's identity information from the big database for verification to identify high-risk users, such as users who have not logged in to their accounts, or who often place malicious orders resulting in low credit points, or whose accounts have not been authenticated by real names, etc., so as to deeply analyze whether the user's identity is abnormal to confirm potential risks. At the same time, after the user's identity is verified, an authorization mark will be given so that the user can place orders normally, and for users identified as high-risk, the first restriction unit 24 will restrict their operation behavior.
[0034] In addition, the order verification unit 25 can verify whether the user's order metrics meet the standards to screen out orders that do not meet the standards. Specifically, the order metrics include: the details of the order (detailed review of the order data submitted by the user, including information such as the quantity of similar orders, delivery address, payment method, etc.), the number of orders submitted (the number of abnormal orders submitted by the user during the flash sale event), the time distribution of order submissions (the time distribution of user order submissions), and the matching situation between orders and inventory (the matching situation between user orders and inventory limits during the event), and so on. Correspondingly, after analyzing the user's order metrics, the second restriction unit 26 cancels orders that do not meet the standards, such as orders for a large number of similar items or a large number of unpaid orders, and other abnormal orders, and releases the inventory of the corresponding items for the orders again to protect the consumption rights and experience of normal users.
[0035] It should be noted that, in actual implementation, the above-mentioned functional modules can be fully or partially integrated into a physical entity, or physically separated. And these units can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; or some units can be implemented in the form of software called by processing elements, and some units can be implemented in the form of hardware. In addition, all or part of these units can be integrated together or can be independently implemented. The processing element mentioned here can be an integrated circuit with signal processing capabilities. During the implementation process, each step of the above method or each of the above modules can be completed through the integrated logic circuit of the hardware in the control unit or the instructions in the form of software.
[0036] In summary, the present invention provides a malicious behavior interception system that intercepts and restricts illegal users or the malicious behaviors of users through direct interception and in-depth analysis, prevents illegal users from snapping up goods through cheating means, maintains a fair competition environment and consumption rights for normal users, thereby enhancing the experience of normal users, protecting the interests of enterprises, and greatly improving the reliability and effectiveness of the flash sale event in the mall.
[0037] In the description herein, many specific details are provided, such as examples of components and / or methods, to provide a complete understanding of the embodiments of the present application. However, those skilled in the art will recognize that the embodiments of the present application can be practiced without one or more of the specific details or by other devices, systems, components, methods, parts, materials, parts, etc. In other cases, well-known structures, materials, or operations are not specifically shown or described in detail to avoid obscuring aspects of the embodiments of the present application.
[0038] The foregoing description of the embodiments shown in this application (including that which is described in the abstract of the specification) is not intended to be exhaustive or to limit the application to the precise forms disclosed herein. Although specific embodiments of the application and examples of the application have been described herein for illustrative purposes only, various equivalent modifications will be apparent to and can be made by those of ordinary skill in the art within the spirit and scope of the application. As noted, these modifications can be made to the application in accordance with the foregoing description of the embodiments of the application, and these modifications will be within the spirit and scope of the application.
[0039] The systems and methods have been described generally herein to assist in understanding the details of the application. Additionally, various specific details have been given to provide a general understanding of embodiments of the application. However, one of ordinary skill in the relevant art will recognize that embodiments of the application may be practiced without one or more of the specific details, or with other devices, systems, components, methods, materials, parts, etc. In other instances, well-known structures, materials, and / or operations have not been shown or described in detail to avoid obscuring aspects of the embodiments of the application.
[0040] Accordingly, while the application has been described herein with reference to its specific embodiments, modifications, various changes and substitutions are also within the foregoing disclosure, and it is to be understood that in some instances, some features of the application will be employed without corresponding use of other features without departing from the scope and spirit of the claimed invention. Therefore, many modifications may be made to adapt a particular situation or material to the essential scope and spirit of the application. The application is not intended to be limited to the specific terms and / or the specific embodiments disclosed as the best mode contemplated for carrying out the application, but the application will include any and all embodiments and equivalents falling within the scope of the appended claims. Accordingly, the scope of the application is to be determined only by the appended claims.
Claims
1. A malicious behavior interception system for shopping mall flash sales, characterized in that: include: The front-end interception module is used to monitor and intercept malicious behaviors of users after they enter the mall's flash sale activity page; The back-end interception module is used to conduct in-depth analysis of users who enter the mall's flash sale activity page and restrict their operation behavior; Wherein, the front-end interception module includes: A trigger limiting unit, used to limit the number and frequency of triggers for a user to rush to buy any product, so as to prohibit the user from rushing to buy the product when the number and / or frequency of triggers for a rush to buy any product exceeds a preset first threshold; A human-machine verification unit is used to verify the human-machine verification of a user who has successfully purchased any product, so as to prohibit the user from placing an order for the successfully purchased product after the verification fails; The product verification unit is used to verify the correlation between the user and the products ordered by the user, as well as the order quantity of the products, so as to cancel the user's order process for the products when there is a low correlation between the user and the products ordered by the user and the order quantity of the products exceeds a preset second threshold.
2. The malicious behavior interception system for mall flash sales according to claim 1 is characterized in that: The back-end interception module includes: A behavior analysis unit is used to retrieve the behavior data of users within a preset time range from a large database and analyze it to identify users with abnormal behavior; The risk control verification unit is used to retrieve the user's identity information from the big database and perform verification to identify high-risk users; The first restriction unit is used to restrict operations of users with abnormal behaviors and high-risk users.
3. The malicious behavior interception system for mall flash sales according to claim 2 is characterized in that: The behavior analysis unit is also used to analyze the abnormal behavior of the user from multiple dimensions to obtain the abnormal value of each dimension, and comprehensively evaluate the maliciousness of the user behavior based on the abnormal value of each dimension; The first restriction unit is further used to restrict the user's operation behavior according to the degree of maliciousness.
4. The malicious behavior interception system for mall flash sales according to claim 3 is characterized in that: The behavior analysis unit analyzes the abnormal behavior of the user from multiple dimensions to obtain abnormal values of each dimension, including: The behavior analysis unit compares the behavior difference between the user and other users to identify whether the user's behavior is abnormal, and calculates the corresponding abnormal value according to a preset first weight parameter and the accumulated number of abnormal behaviors.
5. The malicious behavior interception system for mall flash sales according to claim 3 is characterized in that: The behavior analysis unit analyzes the abnormal behavior of the user from multiple dimensions to obtain abnormal values of each dimension, including: The behavior analysis unit verifies whether there is a correlation between the abnormal behaviors of the users, so as to identify the correlated abnormal behaviors as malicious behaviors, and calculates the corresponding abnormal value according to a preset second weight parameter and the accumulated number of malicious behaviors.
6. The malicious behavior interception system for mall flash sales according to claim 2 is characterized in that: The behavior analysis unit is also used to analyze the user's behavior indicators from multiple dimensions to comprehensively evaluate the maliciousness of the user's behavior; The first restriction unit is further used to restrict the user's operation behavior according to the degree of maliciousness.
7. The malicious behavior interception system for mall flash sales according to claim 6 is characterized in that: The behavior indicators include: user access indicators and operation indicators; The access index includes: page access frequency and page dwell time; The operation index includes: the trigger frequency of product rush purchase, the operation time interval of the page, and the operation sequence of the page.
8. The malicious behavior interception system for mall flash sales according to claim 2 is characterized in that: The back-end interception module also includes: The order verification unit is used to verify whether the user's order indicators meet the standards, so as to filter out orders that do not meet the standards; The second restriction unit is used to cancel the orders of users that do not meet the standards; The order indicators include: order details, order submission quantity, order submission time distribution, and order and inventory matching status.
9. The malicious behavior interception system for mall flash sales according to claim 2 is characterized in that: The back-end interception module also includes: A network verification unit is used to verify whether the user's network indicators meet the standards in order to identify high-risk users; The network indicators include: the frequency of IP address changes, the time of entering the mall flash sale activity, the login source of the mall flash sale activity, and the current login status.
10. The malicious behavior interception system for mall flash sales according to claim 2 is characterized in that: The front-end interception module also includes: The order restriction unit is used to identify whether the user carries the authorization identifier when placing an order, and prohibit the user who does not carry the authorization identifier from placing an order; The risk control verification unit is also used to assign an authorization identifier to users who have successfully verified.